Chrome allowlist not enforced in Kiosk Blueprint: re-converge and enable Full Screen
Android
If devices in your Kiosk Blueprint are allowing access to websites that should be blocked by your Chrome allowlist policy, the issue is likely caused by a web app that isn't configured for Full Screen mode, combined with a Blueprint that hasn't converged to your devices. Follow these steps to restore your restrictions.
Before you begin
Make sure you have:
- Access to the Esper Console with permissions to edit Blueprints and web apps
- The name of the web app used in your affected Blueprint
- A list of the device groups or individual devices experiencing the issue
Step 1: Enable Full Screen mode on your web app
- In the Esper Console, navigate to Apps → Play Store → Web Apps
- Select the web app that contains your Chrome allowlist policy
- Click Edit
- Set Display to Full Screen
- Click Save
Full Screen mode prevents users from opening new tabs or accessing the browser chrome, which closes a gap that allows users to bypass your allowlist restrictions.
Step 2: apply Blueprint again your Blueprint to affected devices
- In the Esper Console, navigate to Devices & Groups
- Select the Blueprint group containing the affected devices
- Select the Blueprint and choose Converge (or Apply Blueprint) at the group level
- When prompted, you'll see an option to "Include Provision Only Blueprint settings". Leave this unchecked unless you need to re-apply settings that only take effect during device provisioning
- Confirm the action
Re-converging at the group level pushes the updated Blueprint configuration to all devices in that group simultaneously. This is more efficient and reliable than converging devices individually.
Step 3: Validate the fix on a test device
- Remote into one of the affected devices
- Open the web app
- Attempt to navigate to a URL that should be blocked by your allowlist (for example,
instagram.com) - Confirm the site is inaccessible
- Confirm you cannot create a new tab or access browser controls
If the restricted site loads or you can create new tabs, proceed to the troubleshooting section below.
Troubleshooting
The allowlist is still not enforced after re-converging:
- Verify that your Chrome allowlist/blocklist JSON policy is correctly formatted in your Blueprint configuration. Review the raw JSON for syntax errors
- If you're unsure about the JSON format, contact Esper Support with your policy details
New tabs are still possible even in Full Screen mode:
- This may indicate a Chrome version or device manufacturer-specific behavior. Collect the following information and contact Esper Support: device model, Chrome version, and your Esper Agent version
Devices are unexpectedly exiting Kiosk mode:
- Treat this as a separate issue. Contact Esper Support with details about which devices are affected and when the exits occur
Still need help?
If you've completed these steps and your allowlist restrictions are still not enforced, or if you encounter any other issues, submit a support ticket. Include the device model, Chrome version, your Blueprint configuration, and details about which devices are affected.
Please sign in to leave a comment.
Comments
0 comments