Skip to content

Device restrictions

Platform-specific hardware and system restrictions configured per device mapping in the admin UI.

Linux (sync_linux_device_policy)

Polkit rules, Bluetooth rfkill, and terminal exec blocking for the active seat0 session user only.

Category Examples
Polkit Block software install/uninstall, removable media, account changes, power actions, pkexec
Connectivity Bluetooth disabled
Exec Terminal/shell blocking via process monitor

Catalog stored in /var/lib/guardian-agent/linux-device-policy.json. See Linux agent. For browser-specific security policies (like Incognito blocking and YouTube restricted mode), see Browser restrictions.

Android (sync_android_device_policy)

AMAPI-aligned fields pushed to Device Owner agents:

  • Camera, microphone, screen capture
  • App install/uninstall, factory reset protection
  • Bluetooth, USB data transfer, developer settings
  • Custom short/long support messages

Warning

Device-admin-only Android installs show a UI warning and skip most restrictions. Package suspension and lockout also require Device Owner or profile owner.

See Android agent.

Windows

Process and DNS enforcement cover most parental scenarios; dedicated device-policy UI parity with Linux is limited.

Cloud consoles

No hardware restriction sync for Nintendo/Xbox.