Restrict Wi-Fi settings on managed Android devices using Admin Mode and Blueprint app visibility controls
Android
This article explains how to restrict Wi-Fi settings on your managed Android devices so that only authorized administrators can modify network configuration. By combining Esper Settings App controls with Blueprint app visibility settings, you can prevent standard users from changing Wi-Fi settings through the native Android Settings app.
Before you begin
You'll need:
- Access to the Esper Console as an administrator
- One or more Android devices enrolled in your Esper account
- An existing Blueprint, or permission to create one
- A strong Admin Mode password to secure administrator access
How to restrict Wi-Fi settings to Admin Mode only
You'll configure two settings in your Blueprint: restrict Wi-Fi controls in the Esper Settings App to Admin Mode, and hide the native Android Settings app from standard users.
Step 1: Configure Wi-Fi controls in the Esper Settings App
- In the Esper Console, go to Devices & Groups and select your target device or group.
- Open or create a Blueprint.
- Navigate to the Esper Settings App section.
- Find the Wi-Fi setting and set it to Admin Mode only. This hides Wi-Fi configuration from standard users.
- Save your changes.
Step 2: Hide the native Android Settings app
- In the same Blueprint, go to the Apps section.
- Find the native Android Settings app (package name:
com.android.settings). - Set its visibility to Hidden so it does not appear on the device launcher.
- Save your Blueprint.
Step 3: Set or verify your Admin Mode password
- In the Blueprint, locate the Admin Mode password setting.
- Set a strong password known only to authorized administrators.
- Apply the Blueprint to your target devices or groups by going to Devices & Groups → your device or group name → Blueprint → Apply.
Verify the configuration
After the Blueprint has been applied, test the following on an enrolled device:
- The native Android Settings app is no longer visible in the launcher or accessible to standard users.
- When a standard user opens the Esper Settings App, Wi-Fi options are hidden.
- When an authorized user enters Admin Mode with the correct password, Wi-Fi configuration controls become available.
- A user without the Admin Mode password cannot modify Wi-Fi settings through any accessible UI.
Troubleshooting
Native Settings app still appears after Blueprint is applied
Confirm that your Blueprint has fully converged on the device:
- Go to Devices & Groups → your device name → Blueprint.
- Check the sync status. If the Blueprint shows as pending or failed, investigate device connectivity and agent status.
Esper Settings App does not enforce Admin Mode on Wi-Fi
Update your Esper Settings App to the latest version. Older versions may not enforce Admin Mode scoping correctly.
Device uses a custom Settings app
Some device manufacturers (such as Samsung) use custom Settings apps with different package names. If the native Settings app remains accessible, you may need to hide additional Settings-related packages specific to your device manufacturer.
Device is in kiosk or single-app mode
If your Blueprint already configures the device in kiosk or single-app mode, the native Settings app may already be inaccessible. Verify whether this simpler configuration is sufficient for your deployment.
Important notes
- Admin Mode password security: Store your Admin Mode password securely and share it only with authorized administrators. If the password is lost, you must update and reapply your Blueprint remotely to reset it.
- UX-layer restriction: This approach restricts Wi-Fi changes at the user interface level. It does not use Android Device Policy Manager user restrictions.
Still need help?
If the steps above do not resolve your issue, contact Esper Support. Be sure to include your device model, the current Blueprint configuration, and any error messages you encountered.
Please sign in to leave a comment.
Comments
0 comments