Add an Android Restrictions Library Item
To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the Library Overview article.Navigate to Library
Add Library Item
Select Android Restrictions
Configure restrictions
Save Configuration
Android Restrictions Reference
These controls mirror what Iru exposes from the Android Management API. Pick the ones that match your policy.Access work contacts from personal profile apps
Access work contacts from personal profile apps
- Allow: Personal apps can use work contacts unless you list specific apps to block.
- Deny: Personal apps cannot use work contacts unless you list specific apps to allow.
- Allow for system apps only: System apps can use work contacts; you maintain a list of any other apps that may use them.
Add exception
Add exception
com.android.chrome), click Add for each row, then click Done. You can also click + Add app on the restriction to add another row to the table.The line above the table is Except deny for if Allow is selected, Except allow for if Deny is selected, or and if Allow for system apps only is selected. Each row lists App name and Package name.Cross profile data sharing
Cross profile data sharing
- Allow: Apps can share data between the work profile and the personal profile.
- Deny: Apps cannot share data between profiles.
- Deny work to personal: Apps cannot share data from the work profile to the personal profile.
Disallow cross profile copy & paste
Disallow cross profile copy & paste
- Unchecked: Text can be copied and pasted both ways between profiles.
- Checked: Text copied from the personal profile cannot be pasted into the work profile, and text copied from the work profile cannot be pasted into the personal profile.
Disallow camera access
Disallow camera access
Disallow screen capture
Disallow screen capture
Disallow private space
Disallow private space
Limit number of days work profile can be paused
Limit number of days work profile can be paused
Disallow work profile widgets
Disallow work profile widgets
Disallow work profile app functions
Disallow work profile app functions
Disallow apps from unknown sources
Disallow apps from unknown sources
Disallow Android Developer Mode
Disallow Android Developer Mode
Default app permissions
Default app permissions
- Prompt: Ask the end user to allow or deny each permission request.
- Grant: Automatically allow permission requests.
- Deny: Automatically deny permission requests.
Credential managers
Credential managers
- Block all (default): No credential managers are available in the work profile unless you allow a specific app. This matches the Android Management API default.
- Allow system app credential managers: Pre-loaded OEM default credential managers (for example Google Password Manager or Samsung Pass) are available. Third-party credential managers stay blocked unless you allow them individually.

Require sign-in with managed Google Account
Require sign-in with managed Google Account
- Any managed Google Account: The end user can sign in with any managed Google Account from your organization’s managed Google domain.
- A specific managed Google Account: The end user must sign in with a specific account. Enter a managed Google Account email, or type
$to use a global variable such as$EMAIL. Use a lowercase email address.
- Block the entire device or Block the work profile a set number of days after non-compliance. Set days to
0to block immediately. - Erase the entire device a set number of days after non-compliance.