Android Settings accessible via Messages app notification search: restrict app or apply targeted kiosk controls as workaround
Android
If your devices are configured to restrict access to Android Settings, you may have discovered that users can bypass this restriction through the Google Messages app's notification search feature. This article explains why this happens and provides you with practical workarounds to secure your devices.
Understanding the issue
On Android devices with the Google Messages app installed, users can navigate to Messages → Profile icon (top right) → Messages settings → Notifications, then tap the search icon (top right) to access the full Android Settings search interface. From there, they can reach restricted settings like Storage, Apps, Accessibility, and About Phone.
This behavior occurs because Android's notification settings surface—which is embedded in the Messages app—links directly to the system Settings search functionality. This is a platform-level Android behavior, not an Esper agent issue. Standard MDM restrictions that block direct access to the Settings app do not intercept Settings surfaces launched indirectly from other apps.
Before you begin
Choose your mitigation strategy based on your deployment needs:
- Option A: Disable Google Messages and deploy an alternative messaging app (recommended for most deployments)
- Option B: Tighten kiosk or allowlist controls to limit which apps users can access
Option A: Disable Google Messages and use a replacement app
- In the Esper Console, navigate to Devices & Groups → [Target Group or Device] → Blueprint
- Under Apps & Configuration, locate the Messages app (package:
com.google.android.apps.messaging) - Set its state to Disabled or Hidden to prevent end-user access
- In your test environment, validate an alternative SMS/messaging app and confirm it does not expose a similar notification settings → Settings search pathway
- Install your chosen replacement messaging app from the Play Store (private or managed)
- Push the updated Blueprint to your target devices
- Verify that the Messages app no longer appears in the app drawer and that the replacement app is functional
Option B: Apply kiosk or allowlist controls
- In the Blueprint, enable Kiosk Mode or configure an app allowlist that limits visible and launchable apps to only those required for your use case
- Ensure the Settings app itself is not in the allowlist
- Confirm that no allowlisted app exposes a similar indirect Settings pathway
- Apply the updated Blueprint to your target groups
- Verify by attempting the reproduction path (Messages → Profile → Settings → Notifications → Search) to confirm the pathway is no longer accessible
Important notes
Do not disable the Android Settings app itself (com.android.settings). Many system functions—such as Bluetooth, app permissions, and network configuration—and third-party apps depend on it. Disabling Settings will likely cause device instability or broken app behavior.
If you cannot disable Google Messages and cannot find a suitable replacement app, this remains a platform limitation. Android does not currently expose an API to block access to the Settings search surface when it is launched from within another app's settings flow.
Still need help?
If these workarounds do not resolve your issue or if you need assistance choosing the best strategy for your deployment, contact Esper Support.
Please sign in to leave a comment.
Comments
0 comments