政策範例:工作資料夾裝置
透過集合功能整理內容
你可以依據偏好儲存及分類內容。
本頁將針對設有工作資料夾的裝置列出範例政策。
個人擁有的裝置
佈建設有工作資料夾的個人裝置後,Android Device Policy 會自動將政策設定套用到
工作資料夾。這樣您就能同時對
設有工作資料夾和全代管裝置的裝置。
// Applies to the work profile.
"passwordRequirements": {
"passwordMinimumLength": 6,
"passwordQuality": "ALPHABETIC"
},
"applications": [{
"defaultPermissionPolicy": "GRANT",
"installType": "FORCE_INSTALLED", // Auto-installs app in the work profile
"packageName": "com.google.android.gm"
},
{
"installType": "AVAILABLE", // Adds app to the work profile's managed Play Store
"packageName": "com.google.android.apps.docs"
}],
// Applies to the whole device.
"parentProfilePasswordRequirements": {
"passwordMinimumLength": 4,
"passwordQuality": "NUMERIC_COMPLEX"
}
公司擁有的裝置
佈建設有工作資料夾的公司裝置後,
Android Device Policy 會自動將大多數政策設定套用至工作
。雖然個人資料能保障使用者隱私,但企業
會在個人資料夾和
整個裝置。
workProfilewidgets
可讓 IT 管理員進一步控管裝置主畫面上顯示的小工具。
目前設為不允許,但可使用應用程式層級 workProfileWidgets
和裝置層級的 workProfileWidgetsDefault
API 來允許。
個人使用政策
企業可以在以下專案的個人設定檔中強制執行某些限制:
公司擁有的裝置,例如禁止安裝特定應用程式,
停用相機,以及設定使用者可暫停的時長
工作資料夾。查看「personalUsagePolicies
」
瞭解詳情
裝置通用政策
下表中的政策適用於整部裝置。
政策名稱 |
|
|
frpAdminEmails |
deviceOwnerLockScreenInfo |
systemUpdate |
addUserDisabled |
bluetoothDisabled |
bluetoothConfigDisabled |
cellBroadcastsConfigDisabled |
mobileNetworksConfigDisabled |
tetheringConfigDisabled |
wifiConfigDisabled |
dataRoamingDisabled |
shareLocationDisabled |
smsDisabled |
usbFileTransferDisabled |
autoTimeRequired |
mountPhysicalMediaDisabled |
outgoingCallsDisabled |
setWallpaperDisabled |
unmuteMicrophoneDisabled |
|
|
範例政策
// Applies to the work profile
"passwordRequirements": {
"passwordMinimumLength": 6,
"passwordQuality": "ALPHABETIC"
},
"applications": [{
"defaultPermissionPolicy": "GRANT",
"installType": "FORCE_INSTALLED", // Auto-installs app in the work profile
"packageName": "com.google.android.gm"
},
{
"installType": "AVAILABLE", // Adds app to the work profile's managed Play Store
"packageName": "com.google.android.apps.docs"
}],
// Applies to the personal profile
"personalUsagePolicies": {
"personalPlayStoreMode": "BLACKLIST",
"personalApplicationPolicy": [{
"packageName": "com.example.app",
"installType": "BLOCKED"
}],
"maxDaysWithWorkOff": 3,
"cameraDisabled": true,
"screenCaptureDisabled": true
},
// Applies to the whole device.
"bluetoothDisabled": true,
"usbFileTransferDisabled": true
已知問題
在公司擁有的裝置上,系統可能不會立即擷取及更新個人使用政策 (延遲時間應不超過十分鐘)。直到出現「找不到結果」為止螢幕就會顯示。否則,即使在使用者啟動手機,或是載入及套用個人使用政策之間,使用者都可以從 Play 商店安裝任何應用程式。
套用個人使用政策後,請等待 10 分鐘,然後觸發快取更新 (例如選取應用程式),然後重新開啟個人 Play 應用程式。這樣應該就能正確套用個人使用政策。
除非另有註明,否則本頁面中的內容是採用創用 CC 姓名標示 4.0 授權,程式碼範例則為阿帕契 2.0 授權。詳情請參閱《Google Developers 網站政策》。Java 是 Oracle 和/或其關聯企業的註冊商標。
上次更新時間:2025-07-26 (世界標準時間)。
[null,null,["上次更新時間:2025-07-26 (世界標準時間)。"],[[["\u003cp\u003eThis page provides example policies for managing work profiles on both personally-owned and company-owned devices.\u003c/p\u003e\n"],["\u003cp\u003eFor personally-owned devices, policies primarily affect the work profile, allowing for separate work and personal data management.\u003c/p\u003e\n"],["\u003cp\u003eCompany-owned devices offer more granular control, enabling policies for the work profile, personal profile, and the entire device.\u003c/p\u003e\n"],["\u003cp\u003eIT admins can control widget display on the home screen using \u003ccode\u003eworkProfilewidgets\u003c/code\u003e and \u003ccode\u003eworkProfileWidgetsDefault\u003c/code\u003e APIs.\u003c/p\u003e\n"],["\u003cp\u003eThere's a known issue with personal usage policy updates on company-owned devices, potentially causing a delay in policy enforcement.\u003c/p\u003e\n"]]],["The content details policies for devices with work profiles, distinguishing between personally-owned and company-owned scenarios. Policies applied to work profiles include password requirements and application management (forced installation or availability). Company-owned devices allow enterprises to also enforce select restrictions on personal profiles, such as blocking app installations, disabling the camera, and limiting work profile pauses. Additionally, device-wide policies cover settings like Bluetooth, USB file transfers, and more. There is a delay of applying personal usage policy. Work profile widgets are disabled by default.\n"],null,["# Example policies: Work profile devices\n\nThis page contains example policies for devices with work profiles.\n\nPersonally-owned devices\n------------------------\n\nAfter provisioning a [personally-owned device with a work profile](/android/management/provision-device#personally-owned_devices), Android Device Policy automatically applies policy settings to\nthe work profile only. This makes it possible to apply the same policy to\ndevices with work profiles and [fully managed devices](/android/management/policies/fully-managed-devices). \n\n```carbon\n// Applies to the work profile.\n\"passwordRequirements\": {\n \"passwordMinimumLength\": 6,\n \"passwordQuality\": \"ALPHABETIC\"\n},\n\"applications\": [{\n \"defaultPermissionPolicy\": \"GRANT\",\n \"installType\": \"FORCE_INSTALLED\", // Auto-installs app in the work profile\n \"packageName\": \"com.google.android.gm\"\n },\n {\n \"installType\": \"AVAILABLE\", // Adds app to the work profile's managed Play Store\n \"packageName\": \"com.google.android.apps.docs\"\n}],\n\n// Applies to the whole device.\n\"parentProfilePasswordRequirements\": {\n \"passwordMinimumLength\": 4,\n \"passwordQuality\": \"NUMERIC_COMPLEX\"\n}\n```\n\nCompany-owned devices\n---------------------\n\nAfter a provisioning a [company-owned device with a work profile](/android/management/provision-device#company-owned_devices_for_work_and_personal_use),\nAndroid Device Policy automatically applies most policy settings to the work\nprofile only. While the personal profile maintains user privacy, enterprises can\nenforce select restrictions and settings in the personal profile and across the\nwhole the device.\n\n### Work Profile Widgets\n\n`workProfilewidgets` provides greater control for IT admins over what widgets display on the home screen of a device.\nThis is currently set to disallowed as default but can be allowed using the application level [`workProfileWidgets`](/android/management/reference/rest/v1/enterprises.policies#workprofilewidgets) and device level [`workProfileWidgetsDefault`](/android/management/reference/rest/v1/enterprises.policies#crossprofilepolicies) APIs.\n\n### Personal usage policies\n\nEnterprise can enforce certain restrictions in the personal profile of a\ncompany-owned device, such as blocking the installation of specific apps,\ndisabling the camera, and setting a limit for how long a user can pause their\nwork profile. See [`personalUsagePolicies`](/android/management/reference/rest/v1/enterprises.policies#personalusagepolicies)\nfor more information.\n\n### Device-wide policies\n\nThe policies in this table apply to an entire device.\n\n| Policy name | | |\n|--------------------------------|--------------------------------|---------------------------|\n| `frpAdminEmails` | `deviceOwnerLockScreenInfo` | `systemUpdate` |\n| `addUserDisabled` | `bluetoothDisabled` | `bluetoothConfigDisabled` |\n| `cellBroadcastsConfigDisabled` | `mobileNetworksConfigDisabled` | `tetheringConfigDisabled` |\n| `wifiConfigDisabled` | `dataRoamingDisabled` | `shareLocationDisabled` |\n| `smsDisabled` | `usbFileTransferDisabled` | `autoTimeRequired` |\n| `mountPhysicalMediaDisabled` | `outgoingCallsDisabled` | `setWallpaperDisabled` |\n| `unmuteMicrophoneDisabled` | | |\n\n### Example policy\n\n```carbon\n// Applies to the work profile\n\"passwordRequirements\": {\n \"passwordMinimumLength\": 6,\n \"passwordQuality\": \"ALPHABETIC\"\n},\n\"applications\": [{\n \"defaultPermissionPolicy\": \"GRANT\",\n \"installType\": \"FORCE_INSTALLED\", // Auto-installs app in the work profile\n \"packageName\": \"com.google.android.gm\"\n },\n {\n \"installType\": \"AVAILABLE\", // Adds app to the work profile's managed Play Store\n \"packageName\": \"com.google.android.apps.docs\"\n}],\n\n// Applies to the personal profile\n\"personalUsagePolicies\": {\n \"personalPlayStoreMode\": \"BLACKLIST\",\n \"personalApplicationPolicy\": [{\n \"packageName\": \"com.example.app\",\n \"installType\": \"BLOCKED\"\n }],\n \"maxDaysWithWorkOff\": 3,\n \"cameraDisabled\": true,\n \"screenCaptureDisabled\": true\n},\n\n// Applies to the whole device.\n\"bluetoothDisabled\": true,\n\"usbFileTransferDisabled\": true\n```\n\n### Known Issue\n\nOn a company-owned device, retrieving and updating the personal usage policy may not be immediate (the delay should be no longer than ten minutes); until this has occured the \"No result found\" screen is displayed. Otherwise a user could install any app from the Play store, between phone start up and the personal usage policy being loaded and applied.\n\nAfter applying a personal usage policy, wait ten minutes, then trigger a cache update (e.g. by selecting an app) and then re-open the personal Play app. The personal usage policy should then have been applied correctly."]]