How to create a dynamic App Whitelist with deployed Apps?

Hi everyone,

We're trying to avoid users can install and run

some other Apps different than the deployed ones.

We know App Run Control and Whitelist,

but cannot create manually a Whitelist for

every policy we create and assign, there's too many.

Is there any way to create a dynamic App whilelist containing

all the deployed Apps in a device?

Thank you very much in advance.

2 years ago
Android
ANSWERS
ZC
Zafer Cigdem Platinum Contributor
2 years ago

Hi,

I'm not sure which device Family you mention but for Android devices (Android classic or AE);

You may block installation of application by using Profile > Feature Control, similar to below screenshot

If they use Android Market place to install an application and you don't want to use Application Run Control, then you can start using Android Enterprise Binding instead of personal e-mails on Google Play, and you can also restrict using an additional Gmail account for installing apps from Android Marketplace as well, you can review here for this: SOTI Discussion Forum

I hope it helps.

Zafer

RS
Rafael Schäfer Platinum Contributor
2 years ago

And in addition to this you may need to disable the possibility to add a Google account to the device, so they also can't use a private playstore account to download/install apps.

I assume we are talking about fully managed devices where you provide apps via managed play store?
If that's the case you don't need to do whitelisting, only the apps you provide are available in the managed playstore then.

M
Maverick75
2 years ago

Hi Zafer, and Rafael!

First of all, Happy New Year!

Let me explain a little further why wer're trying to do this.

We already have 2 Google accounts on the managed smartphones: one is the automatic Google account created by SOTI MobiControl during the enrollment process, and the second one is the additional we add manually just to get Contacts backups and WhatsApp backups done using it.

This second Google account is like a backdoor to the users, so they can use it to install other Apps different than the first/automatic one.

Any idea how we can avoid users can install other Apps different from the managed/deployed from SOTI MobiControl?

Thanx in advance.

ZC
Zafer Cigdem Platinum Contributor
2 years ago

Hi Maverick,

Thank you very much, happy new year!

As far as I know, if you want to keep both Gmail accounts on the devices, and block users to install any app from Play store, then you may use Application Run Control. You can review here, Raymond already mentioned earlier:
SOTI Discussion Forum

I hope it helps. Thank you

Zafer

RS
Rafael Schäfer Platinum Contributor
2 years ago

In that case the Whitelist Zafer ist pointing to, would be required but be aware that if you provide an app with managed app config via MDM, the user could install it from private playstore as well without managed config then (as the bundleID is the same).

J
JJMOD@SOTI
2 years ago

Hi Maverick,

Thanks for posting on SOTI Pulse, Thanks Zafer and Rafael for responding to the post, your expertise and willingness to help are greatly appreciated!

Have you had an opportunity to test the suggested solutions by Zafer and Rafael, and has it successfully addressed your query?

If not, or If you have any additional questions or concerns, please don't hesitate to reach out. We're dedicated to providing assistance and support.

Kind regards,

Technical Support | SOTI Inc. |1.905.624.9828 | support@soti.net | www.soti.net |