Android Policy Settings

Written By Cindy Johnson (Super Administrator)

Updated at May 31st, 2020

Information on configuring policies for agents running on Android devices is presented in this article.

The policy for Android agents provides the ability to configure email alerts, set scan times, enforce the use of passcodes, and manage access to WiFi networks.

Configure email alerts 

The Email Scanning screen enables you to assign severity ratings to potentially harmful email addresses. When an email is received from a listed address, it is scanned for malicious content and treated according to the severity rating assigned to it.

To configure email scanning options:

  1. From Site Navigator, double-click the Android policy you want to configure.
  2. From the left pane of the Policy Properties screen, expand Email Alerts and click Scanning.
  3. To add emails to the list:
    1. From the right pane, click Add... to launch the Scanning Threat Detection Email Alert dialog. 
    2. Key in the potentially harmful email address in the Email Address field.
    3. From the Severity drop-down menu, select one of the following options:
      • Severe Risk
      • High Risk
      • Elevated Risk
      • Moderate Risk
      • Low Risk
    4. Click OK to close the dialog and return to the Email Scanning screen.
  4. To edit ratings and/or email addresses, select an entry from the list and click Edit...
  5. To delete email addresses, select one or more addresses using Ctrl or Shift keys and click Remove.
  6. Click Apply and OK.

Configure scan schedules and events

Device Management settings enable you to protect your Android device by running security scans according to a schedule or when triggered by an event.

To configure device management options:

  1. From Site Navigator, double-click the Android policy you want to configure.
  2. From the left pane of the Policy Properties screen, click Android Device Management.
  3. To scan applications or removable storage devices, select Automatically scan apps after they are installed, and memory cards when connected to devices or disconnected from computers.
  4. To run scans according to a schedule, select Schedule Scans and choose from:
    • Daily: run security scans everyday
    • Weekly: run security scans on one day of the week.

Important!

The following option (Step 5) must not be used unless instructed by a tech-support representative.

  1. To troubleshoot problems coming from agents installed on Android devices, VIPRE Endpoint Security allows you to gather all the activity logs in one location as a single file. Select Archive agent event files to enable log collection. Storing this file is useful for debugging and recommended to be used only when working with Technical Support.
  2. Click Apply and OK.

Configure enforcement of device passcode 

Device Passcode settings enable you to protect Android devices with an unlock passcode. From the Device Passcode screen, you can configure granular settings related to the passcode strength and complexity as well as other countermeasures that can prevent security breaches.

To configure Android device passcode settings:

  1. From Site Navigator, double-click the Android policy you want to configure.
  2. From the left pane of the Policy Properties screen, click Device Passcode.
  3. Configure the options described below:
  • Require passcode on device: enables passcode protection
  • Allow sequential or repeated characters in passcodes: allows users to input passcodes that contain repeated or sequential characters, such as 3333 and ABCD

Note! Using passcodes that contain repeated or sequential characters jeopardizes the security of your device. Such passcodes are easier to hack than complex passcodes, which normally contain a mixture of random alphanumeric and non-alphanumeric characters. 

  • Require alphanumeric value: forces device owners to use passwords that consists of alphabetical and numerical characters
  • Minimum passcode length: key in the minimum number of characters the passcode must contain
  • Minimum number of non-alphanumeric characterskey in the number of non-alphanumeric characters the passcode must contain. Non-alphanumeric characters include (but not limited to) !, $, %, ^, &, *, (, ),@, #
  • Maximum passcode age: specify the number of days that a passcode is valid for. When the password expires, the user is automatically asked to key in a new one
  • Maximum failed attempts before wiping all information from the device: deletes all the information on the iOS device, when the specified number of failed attempts is reached.

Important!

When this option is enabled, ensure that the device owner is aware that the number of attempts to unlock the device is limited.

  1. Click Apply and OK.


Configure Wi-Fi networks

The Wi-Fi Networks screen is used to manage wireless networks accessible by Android devices that are managed by the Android security policy.

To configure Wi-Fi networks settings:

  1. From Site Navigator, double-click the Android policy you want to configure.
  2. From the left pane of the Policy Properties screen, click Wi-Fi Networks.
  3. Click Add... to launch the Configure Wi-Fi dialog and add wireless networks to the list. 
  4. Configure the following options for each wireless network you want to add:
    1. Wi-Fi Network Name (SSID): key in the network name/SSID
    2. Connect automatically: automatically connect devices to the network when it is in range
    3. Network is hidden: specifies that the Wi-Fi Network Name (SSID) configured is hidden from broadcast
    4. Security Type: select the password encryption type of the wireless network you are adding
    5. Password: key in the password used to gain access to the wireless network
    6. Use proxy: if the wireless network you are adding routes web requests through a proxy server, select this option and click Configure Proxy..., to specify the proxy server address, port and optionally, authentication credentials.
    7. Click OK to close the dialog and return to the Wi-Fi Networks screen.
  5. To edit network settings, select the network and click Edit...
  6. To delete networks, select one or more networks using Ctrl or Shift keys and click Remove.
  7. Click Apply and OK.