示例政策:工作资料设备
使用集合让一切井井有条
根据您的偏好保存内容并对其进行分类。
本页面包含适用于具有工作资料的设备的示例政策。
个人所有的设备
在为个人所有的设备配置工作资料后,Android Device Policy 会自动将政策设置应用于
仅限工作资料。这样就可以将相同的政策
具有工作资料的设备和完全受管设备。
// Applies to the work profile.
"passwordRequirements": {
"passwordMinimumLength": 6,
"passwordQuality": "ALPHABETIC"
},
"applications": [{
"defaultPermissionPolicy": "GRANT",
"installType": "FORCE_INSTALLED", // Auto-installs app in the work profile
"packageName": "com.google.android.gm"
},
{
"installType": "AVAILABLE", // Adds app to the work profile's managed Play Store
"packageName": "com.google.android.apps.docs"
}],
// Applies to the whole device.
"parentProfilePasswordRequirements": {
"passwordMinimumLength": 4,
"passwordQuality": "NUMERIC_COMPLEX"
}
公司自有设备
为公司自有设备配置工作资料后,
Android Device Policy 可自动为工作应用大多数政策设置
个人资料。尽管个人资料可以保护用户隐私,但企业可以
在个人资料以及整个系统中强制执行特定限制和设置
整个设备
workProfilewidgets
可让 IT 管理员更好地控制在设备主屏幕上显示哪些微件。
当前默认设置为禁止,但可以使用应用级 workProfileWidgets
和设备级 workProfileWidgetsDefault
API 来允许。
个人使用政策
企业可以在
公司自有设备(例如禁止安装特定应用)
停用摄像头,并设置用户可以暂停播放广告的时间长度限制
工作资料。如需了解详情,请参阅 personalUsagePolicies
。
设备级政策
此表中的政策适用于整个设备。
政策名称 |
|
|
frpAdminEmails |
deviceOwnerLockScreenInfo |
systemUpdate |
addUserDisabled |
bluetoothDisabled |
bluetoothConfigDisabled |
cellBroadcastsConfigDisabled |
mobileNetworksConfigDisabled |
tetheringConfigDisabled |
wifiConfigDisabled |
dataRoamingDisabled |
shareLocationDisabled |
smsDisabled |
usbFileTransferDisabled |
autoTimeRequired |
mountPhysicalMediaDisabled |
outgoingCallsDisabled |
setWallpaperDisabled |
unmuteMicrophoneDisabled |
|
|
政策示例
// Applies to the work profile
"passwordRequirements": {
"passwordMinimumLength": 6,
"passwordQuality": "ALPHABETIC"
},
"applications": [{
"defaultPermissionPolicy": "GRANT",
"installType": "FORCE_INSTALLED", // Auto-installs app in the work profile
"packageName": "com.google.android.gm"
},
{
"installType": "AVAILABLE", // Adds app to the work profile's managed Play Store
"packageName": "com.google.android.apps.docs"
}],
// Applies to the personal profile
"personalUsagePolicies": {
"personalPlayStoreMode": "BLACKLIST",
"personalApplicationPolicy": [{
"packageName": "com.example.app",
"installType": "BLOCKED"
}],
"maxDaysWithWorkOff": 3,
"cameraDisabled": true,
"screenCaptureDisabled": true
},
// Applies to the whole device.
"bluetoothDisabled": true,
"usbFileTransferDisabled": true
已知问题
在公司自有设备上,可能无法立即检索和更新个人使用政策(延迟不应超过 10 分钟);直到发生“未找到结果”屏幕。否则,用户可能会从手机启动到系统加载并应用个人使用政策,从 Play 商店安装任何应用。
应用个人使用政策后,等待十分钟,然后触发缓存更新(例如,通过选择应用),然后重新打开个人 Play 应用。此时,个人使用政策应该已正确应用。
如未另行说明,那么本页面中的内容已根据知识共享署名 4.0 许可获得了许可,并且代码示例已根据 Apache 2.0 许可获得了许可。有关详情,请参阅 Google 开发者网站政策。Java 是 Oracle 和/或其关联公司的注册商标。
最后更新时间 (UTC):2025-07-26。
[null,null,["最后更新时间 (UTC):2025-07-26。"],[[["\u003cp\u003eThis page provides example policies for managing work profiles on both personally-owned and company-owned devices.\u003c/p\u003e\n"],["\u003cp\u003eFor personally-owned devices, policies primarily affect the work profile, allowing for separate work and personal data management.\u003c/p\u003e\n"],["\u003cp\u003eCompany-owned devices offer more granular control, enabling policies for the work profile, personal profile, and the entire device.\u003c/p\u003e\n"],["\u003cp\u003eIT admins can control widget display on the home screen using \u003ccode\u003eworkProfilewidgets\u003c/code\u003e and \u003ccode\u003eworkProfileWidgetsDefault\u003c/code\u003e APIs.\u003c/p\u003e\n"],["\u003cp\u003eThere's a known issue with personal usage policy updates on company-owned devices, potentially causing a delay in policy enforcement.\u003c/p\u003e\n"]]],["The content details policies for devices with work profiles, distinguishing between personally-owned and company-owned scenarios. Policies applied to work profiles include password requirements and application management (forced installation or availability). Company-owned devices allow enterprises to also enforce select restrictions on personal profiles, such as blocking app installations, disabling the camera, and limiting work profile pauses. Additionally, device-wide policies cover settings like Bluetooth, USB file transfers, and more. There is a delay of applying personal usage policy. Work profile widgets are disabled by default.\n"],null,["# Example policies: Work profile devices\n\nThis page contains example policies for devices with work profiles.\n\nPersonally-owned devices\n------------------------\n\nAfter provisioning a [personally-owned device with a work profile](/android/management/provision-device#personally-owned_devices), Android Device Policy automatically applies policy settings to\nthe work profile only. This makes it possible to apply the same policy to\ndevices with work profiles and [fully managed devices](/android/management/policies/fully-managed-devices). \n\n```carbon\n// Applies to the work profile.\n\"passwordRequirements\": {\n \"passwordMinimumLength\": 6,\n \"passwordQuality\": \"ALPHABETIC\"\n},\n\"applications\": [{\n \"defaultPermissionPolicy\": \"GRANT\",\n \"installType\": \"FORCE_INSTALLED\", // Auto-installs app in the work profile\n \"packageName\": \"com.google.android.gm\"\n },\n {\n \"installType\": \"AVAILABLE\", // Adds app to the work profile's managed Play Store\n \"packageName\": \"com.google.android.apps.docs\"\n}],\n\n// Applies to the whole device.\n\"parentProfilePasswordRequirements\": {\n \"passwordMinimumLength\": 4,\n \"passwordQuality\": \"NUMERIC_COMPLEX\"\n}\n```\n\nCompany-owned devices\n---------------------\n\nAfter a provisioning a [company-owned device with a work profile](/android/management/provision-device#company-owned_devices_for_work_and_personal_use),\nAndroid Device Policy automatically applies most policy settings to the work\nprofile only. While the personal profile maintains user privacy, enterprises can\nenforce select restrictions and settings in the personal profile and across the\nwhole the device.\n\n### Work Profile Widgets\n\n`workProfilewidgets` provides greater control for IT admins over what widgets display on the home screen of a device.\nThis is currently set to disallowed as default but can be allowed using the application level [`workProfileWidgets`](/android/management/reference/rest/v1/enterprises.policies#workprofilewidgets) and device level [`workProfileWidgetsDefault`](/android/management/reference/rest/v1/enterprises.policies#crossprofilepolicies) APIs.\n\n### Personal usage policies\n\nEnterprise can enforce certain restrictions in the personal profile of a\ncompany-owned device, such as blocking the installation of specific apps,\ndisabling the camera, and setting a limit for how long a user can pause their\nwork profile. See [`personalUsagePolicies`](/android/management/reference/rest/v1/enterprises.policies#personalusagepolicies)\nfor more information.\n\n### Device-wide policies\n\nThe policies in this table apply to an entire device.\n\n| Policy name | | |\n|--------------------------------|--------------------------------|---------------------------|\n| `frpAdminEmails` | `deviceOwnerLockScreenInfo` | `systemUpdate` |\n| `addUserDisabled` | `bluetoothDisabled` | `bluetoothConfigDisabled` |\n| `cellBroadcastsConfigDisabled` | `mobileNetworksConfigDisabled` | `tetheringConfigDisabled` |\n| `wifiConfigDisabled` | `dataRoamingDisabled` | `shareLocationDisabled` |\n| `smsDisabled` | `usbFileTransferDisabled` | `autoTimeRequired` |\n| `mountPhysicalMediaDisabled` | `outgoingCallsDisabled` | `setWallpaperDisabled` |\n| `unmuteMicrophoneDisabled` | | |\n\n### Example policy\n\n```carbon\n// Applies to the work profile\n\"passwordRequirements\": {\n \"passwordMinimumLength\": 6,\n \"passwordQuality\": \"ALPHABETIC\"\n},\n\"applications\": [{\n \"defaultPermissionPolicy\": \"GRANT\",\n \"installType\": \"FORCE_INSTALLED\", // Auto-installs app in the work profile\n \"packageName\": \"com.google.android.gm\"\n },\n {\n \"installType\": \"AVAILABLE\", // Adds app to the work profile's managed Play Store\n \"packageName\": \"com.google.android.apps.docs\"\n}],\n\n// Applies to the personal profile\n\"personalUsagePolicies\": {\n \"personalPlayStoreMode\": \"BLACKLIST\",\n \"personalApplicationPolicy\": [{\n \"packageName\": \"com.example.app\",\n \"installType\": \"BLOCKED\"\n }],\n \"maxDaysWithWorkOff\": 3,\n \"cameraDisabled\": true,\n \"screenCaptureDisabled\": true\n},\n\n// Applies to the whole device.\n\"bluetoothDisabled\": true,\n\"usbFileTransferDisabled\": true\n```\n\n### Known Issue\n\nOn a company-owned device, retrieving and updating the personal usage policy may not be immediate (the delay should be no longer than ten minutes); until this has occured the \"No result found\" screen is displayed. Otherwise a user could install any app from the Play store, between phone start up and the personal usage policy being loaded and applied.\n\nAfter applying a personal usage policy, wait ten minutes, then trigger a cache update (e.g. by selecting an app) and then re-open the personal Play app. The personal usage policy should then have been applied correctly."]]