Device restrictions¶
Platform-specific hardware and system restrictions configured per device mapping in the admin UI.
Linux (sync_linux_device_policy)¶
Polkit rules, Bluetooth rfkill, and terminal exec blocking for the active seat0 session user only.
| Category | Examples |
|---|---|
| Polkit | Block software install/uninstall, removable media, account changes, power actions, pkexec |
| Connectivity | Bluetooth disabled |
| Exec | Terminal/shell blocking via process monitor |
Catalog stored in /var/lib/guardian-agent/linux-device-policy.json. See Linux agent. For browser-specific security policies (like Incognito blocking and YouTube restricted mode), see Browser restrictions.
Android (sync_android_device_policy)¶
AMAPI-aligned fields pushed to Device Owner agents:
- Camera, microphone, screen capture
- App install/uninstall, factory reset protection
- Bluetooth, USB data transfer, developer settings
- Custom short/long support messages
Warning
Device-admin-only Android installs show a UI warning and skip most restrictions. Package suspension and lockout also require Device Owner or profile owner.
See Android agent.
Windows¶
Process and DNS enforcement cover most parental scenarios; dedicated device-policy UI parity with Linux is limited.
Cloud consoles¶
No hardware restriction sync for Nintendo/Xbox.