Wi-Fi user control blocked by Blueprint + app permissions locked by admin after blueprint change: resolve via Blueprint Wi-Fi mode and app permission reconfiguration
Android
When a Blueprint change is applied to a device, users may find they can no longer manage Wi-Fi settings or that app permissions display a "blocked by administrator" message.
Why this happens
Blueprints continuously enforce the configuration state you define. If a Blueprint's Wi-Fi mode is set to active management, or if app permissions are explicitly denied, the Esper Agent re-applies those restrictions every time the Blueprint converges — overriding any changes users make locally.
Restore user control of Wi-Fi settings
- Open the Esper Console and navigate to Blueprints. Open the blueprint assigned to the affected device or group.
- Go to the Network section and locate Wi-Fi Management Mode. Set it to one of the following based on how much control you want to return to users:
- Provision Only — Wi-Fi credentials are applied once during provisioning; Esper stops managing them afterward.
- Ignore — Esper does not manage Wi-Fi at all; users have full control.
- Disable Use Only Saved Wi-Fi Access Points. This setting prevents users from connecting to any network not pre-configured in the Blueprint.
- Disable Strict Wi-Fi Access Point Synchronization. Without this change, Esper re-enforces your admin-defined access point list on every convergence cycle, immediately overriding user selections.
- In the Esper Settings section of the same blueprint, confirm that Wi-Fi is toggled on. This controls whether the Wi-Fi option is visible and accessible in the device's system Settings.
- If the blueprint includes a custom JSON payload, review it for any keys that restrict Wi-Fi access. Remove or correct those entries before saving.
- Select Save to publish the updated blueprint.
Restore app permissions
- In the same blueprint, navigate to Apps & Configuration and select the affected app.
- Under App Permissions, set each restricted permission — such as Camera, Location, or Storage — to Allow or Prompt. Setting a permission to Deny is what produces the "blocked by administrator" message users see.
- Select Save.
Apply the changes to devices
- Navigate to Devices & Groups and locate the affected devices. Devices showing an In Drift status will converge to the updated blueprint automatically.
- To trigger convergence immediately, select the device, then apply the updated blueprint manually. This is useful when you need changes applied without waiting for the next scheduled sync.
- Monitor device status in the Activity Feed until convergence completes and the status clears.
If this doesn't resolve it
If permissions still show as "blocked by administrator" after convergence, a second blueprint or a group-level override may be re-applying the restrictive policy. Before contacting support, collect the following:
- The name of the blueprint currently assigned to the affected device, visible under Devices & Groups → [Device Name] → Blueprint
- A screenshot of the permission state shown under App Info → Permissions on the device
- The device's Activity Feed entries from the time of the Blueprint change
Contact Esper Support with these details so the issue can be investigated further.
Still need help?
If you're still experiencing Wi-Fi connectivity issues or app permission problems after applying these Blueprint configurations, please submit a support ticket and include your Blueprint settings, the specific apps affected, and the sequence of changes you made to your device policies.
Please sign in to leave a comment.
Comments
0 comments