Blueprint Capability Gaps: App PIN Lock, Call/SMS Allowlist, and Launcher Switching
Android
Title: App PIN lock, call/SMS allowlist, and launcher switching — Blueprint behavior and workaroundsWhen configuring kiosk-mode or shared devices using Blueprints, you may find that app PIN locks, SMS allowlisting, and on-device launcher switching do not behave as expected or are not available in the Blueprint settings.
Why this happens
Blueprints control device behavior at the policy level, not the application level. Per-app PIN enforcement and SMS filtering require OS-level hooks that Blueprints do not currently expose. Launcher switching is intentionally managed from the Esper Console rather than on-device to maintain central control over kiosk configurations.
App PIN lock
Blueprints do not support per-app PIN locks. The following alternatives provide equivalent access control depending on your use case.
- Disable the app entirely: In the Esper Console, navigate to Blueprints → Apps & Configuration, locate the app, and set its state to Disabled. This removes it from the home screen and prevents end users from launching it.
- Protect device settings using Esper Settings: Navigate to Blueprints → Device Settings → System Settings and enable Esper Settings. This gives authorized technicians PIN- or gesture-protected access to device configuration without exposing the full Android Settings app to end users.
- Deploy a third-party app-lock application: If per-app PIN protection is essential, navigate to Apps & Configuration → App Library, upload a trusted third-party app-lock application, and configure it as a managed app within the Blueprint. This delegates per-app PIN enforcement to that application.
Call and SMS allowlisting
Blueprints support call allowlisting for both incoming and outgoing calls. SMS allowlisting is not supported.
Configure a call allowlist
- Open the Esper Console and navigate to Blueprints, then select an existing blueprint or create a new one.
- Navigate to Connectivity → Phone & Messaging.
- Under Incoming Calls and Outgoing Calls, enable the allowlist toggle for each direction you want to restrict.
- Enter each phone number to allow. Any number not on the list will be blocked automatically.
- Save and publish the blueprint, then apply it to the target device group.
SMS allowlisting
SMS allowlisting is not available in Blueprints. If this is a requirement for your deployment, contact Esper Support to submit a feature request and describe your use case.
Launcher switching
Blueprints do not support PIN-triggered launcher switching directly on the device. All launcher changes must be made through the Esper Console.
- Switch launchers via the Esper Console: Navigate to Blueprints → Kiosk Settings → Launcher, toggle between Esper Launcher and Android Launcher, then save and publish the blueprint. The device will apply the new launcher once it syncs.
- Grant local configuration access without switching launchers: Navigate to Blueprints → Device Settings → System Settings and enable Esper Settings. This allows authorized technicians to access device configuration locally using a PIN or gesture, without requiring a launcher change.
If this doesn't resolve it
If call blocking is not working after the blueprint is applied, collect the following before contacting support:
- The blueprint name and the device group it is applied to
- A screenshot of the Phone & Messaging settings showing the allowlist configuration
- The device serial number or Esper Device ID
- The timestamp of the call attempt and the number that was not blocked
- A screenshot of the Activity Feed for the affected device showing the most recent blueprint sync
Contact Esper Support with this information.
Still need help?
If the steps above don't resolve the issue, submit a support ticket with your device model, Android version, Esper Agent version, and a description of what you've already tried — this helps the support team investigate without a follow-up.
Please sign in to leave a comment.
Comments
0 comments