此 MCP 可以做什么
Reads enterprise Android device, application, policy, web-app, and enterprise resources through Android Management API.
工具
输入模式
{'type': 'object', 'properties': {'name': {'type': 'string', 'description': 'The name of the application in the form `enterprises/{enterpriseId}/applications/{package_name}`.'}, 'languageCode': {'type': 'string', 'description': 'The preferred language for localized application info, as a BCP47 tag (e.g. "en-US", "de"). If not specified the default language of the application will be used.'}}, 'description': 'Request to get info about an application.'}
输出模式
{'type': 'object', '$defs': {'AppVersion': {'type': 'object', 'properties': {'trackIds': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Track identifiers that the app version is published in. This does not include the production track (see production instead).'}, 'production': {'type': 'boolean', 'description': 'If the value is True, it indicates that this version is a production track.'}, 'versionCode': {'type': 'integer', 'format': 'int32', 'description': 'Unique increasing identifier for the app version.'}, 'versionString': {'type': 'string', 'description': 'The string used in the Play store by the app developer to identify the version. The string is not necessarily unique or localized (for example, the string could be "1.4").'}}, 'description': 'This represents a single version of the app.'}, 'AppTrackInfo': {'type': 'object', 'properties': {'trackId': {'type': 'string', 'description': 'The unmodifiable unique track identifier, taken from the `releaseTrackId` in the URL of the Play Console page that displays the app’s track information.'}, 'trackAlias': {'type': 'string', 'description': 'The track name associated with the `trackId`, set in the Play Console. The name is modifiable from Play Console.'}}, 'description': 'Id to name association of a app track.'}, 'ManagedProperty': {'type': 'object', 'properties': {'key': {'type': 'string', 'description': 'The unique key that the app uses to identify the property, e.g. "com.google.android.gm.fieldname".'}, 'type': {'enum': ['MANAGED_PROPERTY_TYPE_UNSPECIFIED', 'BOOL', 'STRING', 'INTEGER', 'CHOICE', 'MULTISELECT', 'HIDDEN', 'BUNDLE', 'BUNDLE_ARRAY'], 'type': 'string', 'description': 'The type of the property.', 'x-google-enum-descriptions': ['Not used.', 'A property of boolean type.', 'A property of string type.', 'A property of integer type.', 'A choice of one item from a set.', 'A choice of multiple items from a set.', "A hidden restriction of string type (the default value can be used to pass along information that can't be modified, such as a version code).", 'A bundle of properties', 'An array of property bundles.']}, 'title': {'type': 'string', 'description': 'The name of the property. Localized.'}, 'entries': {'type': 'array', 'items': {'$ref': '#/$defs/ManagedPropertyEntry'}, 'description': 'For `CHOICE` or `MULTISELECT` properties, the list of possible entries.'}, 'description': {'type': 'string', 'description': 'A longer description of the property, providing more detail of what it affects. Localized.'}, 'defaultValue': {'description': "The default value of the property. `BUNDLE_ARRAY` properties don't have a default value."}, 'nestedProperties': {'type': 'array', 'items': {'$ref': '#/$defs/ManagedProperty'}, 'description': 'For `BUNDLE_ARRAY` properties, the list of nested properties. A `BUNDLE_ARRAY` property is at most two levels deep.'}}, 'description': 'Managed property.'}, 'ManagedPropertyEntry': {'type': 'object', 'properties': {'name': {'type': 'string', 'description': 'The human-readable name of the value. Localized.'}, 'value': {'type': 'string', 'description': 'The machine-readable value of the entry, which should be used in the configuration. Not localized.'}}, 'description': 'An entry of a managed property.'}, 'ApplicationPermission': {'type': 'object', 'properties': {'name': {'type': 'string', 'description': 'The name of the permission. Localized.'}, 'description': {'type': 'string', 'description': 'A longer description of the permission, providing more detail on what it affects. Localized.'}, 'permissionId': {'type': 'string', 'description': 'An opaque string uniquely identifying the permission. Not localized.'}}, 'description': 'A permission required by the app.'}}, 'properties': {'name': {'type': 'string', 'description': 'The name of the app in the form enterprises/{enterprise}/applications/{package_name}.'}, 'title': {'type': 'string', 'description': 'The title of the app. Localized.'}, 'author': {'type': 'string', 'description': 'The name of the author of the apps (for example, the app developer).'}, 'iconUrl': {'type': 'string', 'description': 'A link to an image that can be used as an icon for the app. This image is suitable for use up to a pixel size of 512 x 512.'}, 'category': {'type': 'string', 'description': 'The app category (e.g. RACING, SOCIAL, etc.)'}, 'features': {'type': 'array', 'items': {'enum': ['APP_FEATURE_UNSPECIFIED', 'VPN_APP'], 'type': 'string', 'x-google-enum-descriptions': ['Unspecified.', 'The app is a VPN.']}, 'description': 'Noteworthy features (if any) of this app.'}, 'appTracks': {'type': 'array', 'items': {'$ref': '#/$defs/AppTrackInfo'}, 'description': 'Application tracks visible to the enterprise.'}, 'appPricing': {'enum': ['APP_PRICING_UNSPECIFIED', 'FREE', 'FREE_WITH_IN_APP_PURCHASE', 'PAID'], 'type': 'string', 'description': 'Whether this app is free, free with in-app purchases, or paid. If the pricing is unspecified, this means the app is not generally available anymore (even though it might still be available to people who own it).', 'x-google-enum-descriptions': ['Unknown pricing, used to denote an approved app that is not generally available.', 'The app is free.', 'The app is free, but offers in-app purchases.', 'The app is paid.']}, 'updateTime': {'type': 'string', 'format': 'date-time', 'readOnly': True, 'description': 'Output only. The approximate time (within 7 days) the app was last published.'}, 'appVersions': {'type': 'array', 'items': {'$ref': '#/$defs/AppVersion'}, 'description': 'Versions currently available for this app.'}, 'description': {'type': 'string', 'description': 'The localized promotional description, if available.'}, 'permissions': {'type': 'array', 'items': {'$ref': '#/$defs/ApplicationPermission'}, 'description': 'The permissions required by the app.'}, 'playStoreUrl': {'type': 'string', 'description': 'A link to the (consumer) Google Play details page for the app.'}, 'smallIconUrl': {'type': 'string', 'description': 'A link to a smaller image that can be used as an icon for the app. This image is suitable for use up to a pixel size of 128 x 128.'}, 'contentRating': {'enum': ['CONTENT_RATING_UNSPECIFIED', 'THREE_YEARS', 'SEVEN_YEARS', 'TWELVE_YEARS', 'SIXTEEN_YEARS', 'EIGHTEEN_YEARS'], 'type': 'string', 'description': 'The content rating for this app.', 'x-google-enum-descriptions': ['Unspecified.', 'Content suitable for ages 3 and above only.', 'Content suitable for ages 7 and above only.', 'Content suitable for ages 12 and above only.', 'Content suitable for ages 16 and above only.', 'Content suitable for ages 18 and above only.']}, 'recentChanges': {'type': 'string', 'description': 'A localised description of the recent changes made to the app.'}, 'screenshotUrls': {'type': 'array', 'items': {'type': 'string'}, 'description': 'A list of screenshot links representing the app.'}, 'fullDescription': {'type': 'string', 'description': 'Full app description, if available.'}, 'managedProperties': {'type': 'array', 'items': {'$ref': '#/$defs/ManagedProperty'}, 'description': 'The set of managed properties available to be pre-configured for the app.'}, 'availableCountries': {'type': 'array', 'items': {'type': 'string'}, 'description': 'The countries which this app is available in as per ISO 3166-1 alpha-2.'}, 'distributionChannel': {'enum': ['DISTRIBUTION_CHANNEL_UNSPECIFIED', 'PUBLIC_GOOGLE_HOSTED', 'PRIVATE_GOOGLE_HOSTED', 'PRIVATE_SELF_HOSTED'], 'type': 'string', 'description': 'How and to whom the package is made available.', 'x-google-enum-descriptions': ['Unspecified.', 'Package is available through the Play store and not restricted to a specific enterprise.', 'Package is a private app (restricted to an enterprise) but hosted by Google.', 'Private app (restricted to an enterprise) and is privately hosted.']}, 'minAndroidSdkVersion': {'type': 'integer', 'format': 'int32', 'description': 'The minimum Android SDK necessary to run the app.'}}, 'description': 'Information about an app.'}
输入模式
{'type': 'object', 'properties': {'name': {'type': 'string', 'description': 'The name of the device in the form `enterprises/{enterpriseId}/devices/{deviceId}`.'}}, 'description': 'Request to get a device.'}
输出模式
{'type': 'object', '$defs': {'User': {'type': 'object', 'properties': {'accountIdentifier': {'type': 'string', 'description': "A unique identifier you create for this user, such as `user342` or `asset#44418`. This field must be set when the user is created and can't be updated. This field must not contain personally identifiable information (PII). This identifier must be 1024 characters or less; otherwise, the update policy request will fail."}}, 'description': 'A user belonging to an enterprise.'}, 'Display': {'type': 'object', 'properties': {'name': {'type': 'string', 'description': 'Name of the display.'}, 'state': {'enum': ['DISPLAY_STATE_UNSPECIFIED', 'OFF', 'ON', 'DOZE', 'SUSPENDED'], 'type': 'string', 'description': 'State of the display.', 'x-google-enum-descriptions': ['This value is disallowed.', 'Display is off.', 'Display is on.', 'Display is dozing in a low power state', 'Display is dozing in a suspended low power state.']}, 'width': {'type': 'integer', 'format': 'int32', 'description': 'Display width in pixels.'}, 'height': {'type': 'integer', 'format': 'int32', 'description': 'Display height in pixels.'}, 'density': {'type': 'integer', 'format': 'int32', 'description': 'Display density expressed as dots-per-inch.'}, 'displayId': {'type': 'integer', 'format': 'int32', 'description': 'Unique display id.'}, 'refreshRate': {'type': 'integer', 'format': 'int32', 'description': 'Refresh rate of the display in frames per second.'}}, 'description': 'Device display information.'}, 'MemoryInfo': {'type': 'object', 'properties': {'totalRam': {'type': 'string', 'format': 'int64', 'description': 'Total RAM on device in bytes.'}, 'totalInternalStorage': {'type': 'string', 'format': 'int64', 'description': 'Total internal storage on device in bytes.'}}, 'description': 'Information about device memory and storage.'}, 'MemoryEvent': {'type': 'object', 'properties': {'byteCount': {'type': 'string', 'format': 'int64', 'description': 'The number of free bytes in the medium, or for `EXTERNAL_STORAGE_DETECTED`, the total capacity in bytes of the storage medium.'}, 'eventType': {'enum': ['MEMORY_EVENT_TYPE_UNSPECIFIED', 'RAM_MEASURED', 'INTERNAL_STORAGE_MEASURED', 'EXTERNAL_STORAGE_DETECTED', 'EXTERNAL_STORAGE_REMOVED', 'EXTERNAL_STORAGE_MEASURED'], 'type': 'string', 'description': 'Event type.', 'x-google-enum-descriptions': ['Unspecified. No events have this type.', 'Free space in RAM was measured.', 'Free space in internal storage was measured.', 'A new external storage medium was detected. The reported byte count is the total capacity of the storage medium.', 'An external storage medium was removed. The reported byte count is zero.', 'Free space in an external storage medium was measured.']}, 'createTime': {'type': 'string', 'format': 'date-time', 'description': 'The creation time of the event.'}}, 'description': 'An event related to memory and storage measurements. To distinguish between new and old events, we recommend using the `createTime` field.'}, 'NetworkInfo': {'type': 'object', 'properties': {'imei': {'type': 'string', 'description': 'IMEI number of the GSM device. For example, `A1000031212`.'}, 'meid': {'type': 'string', 'description': 'MEID number of the CDMA device. For example, `A00000292788E1`.'}, 'telephonyInfos': {'type': 'array', 'items': {'$ref': '#/$defs/TelephonyInfo'}, 'description': 'Provides telephony information associated with each SIM card on the device. Only supported on fully managed devices starting from Android 6.'}, 'wifiMacAddress': {'type': 'string', 'description': 'Wi-Fi MAC address of the device. For example, `7c:11:11:11:11:11`.'}, 'networkOperatorName': {'type': 'string', 'deprecated': True, 'description': 'Alphabetic name of current registered operator. For example, Vodafone.'}}, 'description': 'Device network info.'}, 'HardwareInfo': {'type': 'object', 'properties': {'brand': {'type': 'string', 'description': 'Brand of the device. For example, `Google`.'}, 'model': {'type': 'string', 'description': 'The model of the device. For example, `Asus Nexus 7`.'}, 'hardware': {'type': 'string', 'description': 'Name of the hardware. For example, `Angler`.'}, 'manufacturer': {'type': 'string', 'description': 'Manufacturer. For example, `Motorola`.'}, 'serialNumber': {'type': 'string', 'description': 'The device serial number. However, for personally-owned devices running Android 12 and above, this is the same as the `enterpriseSpecificId`.'}, 'euiccChipInfo': {'type': 'array', 'items': {'$ref': '#/$defs/EuiccChipInfo'}, 'readOnly': True, 'description': 'Output only. Information related to the eUICC chip.'}, 'enterpriseSpecificId': {'type': 'string', 'readOnly': True, 'description': 'Output only. ID that uniquely identifies a personally-owned device in a particular organization. On the same physical device when enrolled with the same organization, this ID persists across setups and even factory resets. This ID is available on personally-owned devices with a work profile on devices running Android 12 and above.'}, 'deviceBasebandVersion': {'type': 'string', 'description': 'Baseband version. For example, `MDM9625_104662.22.05.34p`.'}, 'cpuShutdownTemperatures': {'type': 'array', 'items': {'type': 'number', 'format': 'float'}, 'description': 'CPU shutdown temperature thresholds in Celsius for each CPU on the device.'}, 'gpuShutdownTemperatures': {'type': 'array', 'items': {'type': 'number', 'format': 'float'}, 'description': 'GPU shutdown temperature thresholds in Celsius for each GPU on the device.'}, 'skinShutdownTemperatures': {'type': 'array', 'items': {'type': 'number', 'format': 'float'}, 'description': 'Device skin shutdown temperature thresholds in Celsius.'}, 'cpuThrottlingTemperatures': {'type': 'array', 'items': {'type': 'number', 'format': 'float'}, 'description': 'CPU throttling temperature thresholds in Celsius for each CPU on the device.'}, 'gpuThrottlingTemperatures': {'type': 'array', 'items': {'type': 'number', 'format': 'float'}, 'description': 'GPU throttling temperature thresholds in Celsius for each GPU on the device.'}, 'skinThrottlingTemperatures': {'type': 'array', 'items': {'type': 'number', 'format': 'float'}, 'description': 'Device skin throttling temperature thresholds in Celsius.'}, 'batteryShutdownTemperatures': {'type': 'array', 'items': {'type': 'number', 'format': 'float'}, 'description': 'Battery shutdown temperature thresholds in Celsius for each battery on the device.'}, 'batteryThrottlingTemperatures': {'type': 'array', 'items': {'type': 'number', 'format': 'float'}, 'description': 'Battery throttling temperature thresholds in Celsius for each battery on the device.'}}, 'description': "Information about device hardware. The fields related to temperature thresholds are only available if `hardwareStatusEnabled` is true in the device's policy."}, 'SoftwareInfo': {'type': 'object', 'properties': {'androidVersion': {'type': 'string', 'description': 'The user-visible Android version string. For example, `6.0.1`.'}, 'androidBuildTime': {'type': 'string', 'format': 'date-time', 'description': 'Build time.'}, 'systemUpdateInfo': {'$ref': '#/$defs/SystemUpdateInfo', 'description': 'Information about a potential pending system update.'}, 'bootloaderVersion': {'type': 'string', 'description': 'The system bootloader version number, e.g. `0.6.7`.'}, 'androidBuildNumber': {'type': 'string', 'description': 'Android build ID string meant for displaying to the user. For example, `shamu-userdebug 6.0.1 MOB30I 2756745 dev-keys`.'}, 'securityPatchLevel': {'type': 'string', 'description': 'Security patch level, e.g. `2016-05-01`.'}, 'deviceKernelVersion': {'type': 'string', 'description': 'Kernel version, for example, `2.6.32.9-g103d848`.'}, 'primaryLanguageCode': {'type': 'string', 'description': 'An IETF BCP 47 language code for the primary locale on the device.'}, 'deviceBuildSignature': {'type': 'string', 'description': "SHA-256 hash of [`android.content.pm.Signature`](https://developer.android.com/reference/android/content/pm/Signature.html) associated with the system package, which can be used to verify that the system build hasn't been modified."}, 'androidDevicePolicyVersionCode': {'type': 'integer', 'format': 'int32', 'description': 'The Android Device Policy app version code.'}, 'androidDevicePolicyVersionName': {'type': 'string', 'description': 'The Android Device Policy app version as displayed to the user.'}}, 'description': 'Information about device software.'}, 'EuiccChipInfo': {'type': 'object', 'properties': {'eid': {'type': 'string', 'readOnly': True, 'description': 'Output only. The Embedded Identity Document (EID) that identifies the eUICC chip for each eUICC chip on the device. This is available on company owned devices running Android 13 and above.'}}, 'description': 'Information related to the eUICC chip.'}, 'KeyedAppState': {'type': 'object', 'properties': {'key': {'type': 'string', 'description': 'The key for the app state. Acts as a point of reference for what the app is providing state for. For example, when providing managed configuration feedback, this key could be the managed configuration key.'}, 'data': {'type': 'string', 'description': 'Optionally, a machine-readable value to be read by the EMM. For example, setting values that the admin can choose to query against in the EMM console (e.g. “notify me if the battery_warning data < 10”).'}, 'message': {'type': 'string', 'description': 'Optionally, a free-form message string to explain the app state. If the state was triggered by a particular value (e.g. a managed configuration value), it should be included in the message.'}, 'severity': {'enum': ['SEVERITY_UNSPECIFIED', 'INFO', 'ERROR'], 'type': 'string', 'description': 'The severity of the app state.', 'x-google-enum-descriptions': ['Unspecified severity level.', 'Information severity level.', 'Error severity level. This should only be set for genuine error conditions that a management organization needs to take action to fix.']}, 'createTime': {'type': 'string', 'format': 'date-time', 'description': 'The creation time of the app state on the device.'}, 'lastUpdateTime': {'type': 'string', 'format': 'date-time', 'description': 'The time the app state was most recently updated.'}}, 'description': 'Keyed app state reported by the app.'}, 'PostureDetail': {'type': 'object', 'properties': {'advice': {'type': 'array', 'items': {'$ref': '#/$defs/UserFacingMessage'}, 'description': 'Corresponding admin-facing advice to mitigate this security risk and improve the security posture of the device.'}, 'securityRisk': {'enum': ['SECURITY_RISK_UNSPECIFIED', 'UNKNOWN_OS', 'COMPROMISED_OS', 'HARDWARE_BACKED_EVALUATION_FAILED'], 'type': 'string', 'description': 'A specific security risk that negatively affects the security posture of the device.', 'x-google-enum-descriptions': ['Unspecified.', 'Play Integrity API detects that the device is running an unknown OS (basicIntegrity check succeeds but ctsProfileMatch fails).', 'Play Integrity API detects that the device is running a compromised OS (basicIntegrity check fails).', "Play Integrity API detects that the device does not have a strong guarantee of system integrity, if the `MEETS_STRONG_INTEGRITY` label doesn't show in the [device integrity field] (https://developer.android.com/google/play/integrity/verdicts#device-integrity-field)."]}}, 'description': 'Additional details regarding the security posture of the device.'}, 'TelephonyInfo': {'type': 'object', 'properties': {'iccId': {'type': 'string', 'readOnly': True, 'description': 'Output only. The ICCID associated with this SIM card.'}, 'configMode': {'enum': ['CONFIG_MODE_UNSPECIFIED', 'ADMIN_CONFIGURED', 'USER_CONFIGURED'], 'type': 'string', 'readOnly': True, 'description': 'Output only. The configuration mode of the SIM card on the device. This is applicable for eSIMs only. This is supported on all devices for Android 15 and above. This is always `CONFIG_MODE_UNSPECIFIED` for physical SIMs and for devices below Android 15.', 'x-google-enum-descriptions': ['The configuration mode is unspecified.', 'The admin has configured this SIM.', 'The user has configured this SIM.']}, 'carrierName': {'type': 'string', 'description': 'The carrier name associated with this SIM card.'}, 'phoneNumber': {'type': 'string', 'description': 'The phone number associated with this SIM card.'}, 'activationState': {'enum': ['ACTIVATION_STATE_UNSPECIFIED', 'ACTIVATED', 'NOT_ACTIVATED'], 'type': 'string', 'readOnly': True, 'description': 'Output only. Activation state of the SIM card on the device. This is applicable for eSIMs only. This is supported on all devices for Android 15 and above. This is always `ACTIVATION_STATE_UNSPECIFIED` for physical SIMs and for devices below Android 15.', 'x-google-enum-descriptions': ['Activation state is not specified.', 'The SIM card is activated.', 'The SIM card is not activated.']}}, 'description': 'Telephony information associated with a given SIM card on the device. This is supported for all SIM cards on fully managed devices on Android 6 and above. In addition, this is supported for admin-added eSIMs on all devices for Android 15 and above.'}, 'DeviceSettings': {'type': 'object', 'properties': {'adbEnabled': {'type': 'boolean', 'description': 'Whether [ADB](https://developer.android.com/studio/command-line/adb.html) is enabled on the device.'}, 'isEncrypted': {'type': 'boolean', 'description': 'Whether the storage encryption is enabled.'}, 'isDeviceSecure': {'type': 'boolean', 'description': 'Whether the device is secured with PIN/password.'}, 'encryptionStatus': {'enum': ['ENCRYPTION_STATUS_UNSPECIFIED', 'UNSUPPORTED', 'INACTIVE', 'ACTIVATING', 'ACTIVE', 'ACTIVE_DEFAULT_KEY', 'ACTIVE_PER_USER'], 'type': 'string', 'description': 'Encryption status from DevicePolicyManager.', 'x-google-enum-descriptions': ['Unspecified. No device should have this type.', 'Encryption is not supported by the device.', 'Encryption is supported by the device, but is not currently active.', 'Encryption is not currently active, but is currently being activated.', 'Encryption is active.', 'Encryption is active, but an encryption key is not set by the user.', 'Encryption is active, and the encryption key is tied to the user profile.']}, 'verifyAppsEnabled': {'type': 'boolean', 'description': 'Whether [Google Play Protect verification](https://support.google.com/accounts/answer/2812853) is enforced on the device.'}, 'unknownSourcesEnabled': {'type': 'boolean', 'description': 'Whether installing apps from unknown sources is enabled.'}, 'developmentSettingsEnabled': {'type': 'boolean', 'description': 'Whether developer mode is enabled on the device.'}}, 'description': 'Information about security related device settings on device.'}, 'HardwareStatus': {'type': 'object', 'properties': {'cpuUsages': {'type': 'array', 'items': {'type': 'number', 'format': 'float'}, 'description': 'CPU usages in percentage for each core available on the device. Usage is 0 for each unplugged core. Empty array implies that CPU usage is not supported in the system.'}, 'fanSpeeds': {'type': 'array', 'items': {'type': 'number', 'format': 'float'}, 'description': 'Fan speeds in RPM for each fan on the device. Empty array means that there are no fans or fan speed is not supported on the system.'}, 'createTime': {'type': 'string', 'format': 'date-time', 'description': 'The time the measurements were taken.'}, 'cpuTemperatures': {'type': 'array', 'items': {'type': 'number', 'format': 'float'}, 'description': 'Current CPU temperatures in Celsius for each CPU on the device.'}, 'gpuTemperatures': {'type': 'array', 'items': {'type': 'number', 'format': 'float'}, 'description': 'Current GPU temperatures in Celsius for each GPU on the device.'}, 'skinTemperatures': {'type': 'array', 'items': {'type': 'number', 'format': 'float'}, 'description': 'Current device skin temperatures in Celsius.'}, 'batteryTemperatures': {'type': 'array', 'items': {'type': 'number', 'format': 'float'}, 'description': 'Current battery temperatures in Celsius for each battery on the device.'}}, 'description': 'Hardware status. Temperatures may be compared to the temperature thresholds available in `hardwareInfo` to determine hardware health.'}, 'OncWifiContext': {'type': 'object', 'properties': {'wifiGuid': {'type': 'string', 'description': 'The GUID of non-compliant Wi-Fi configuration.'}}, 'description': 'Additional context for non-compliance related to Wi-Fi configuration.'}, 'SecurityPosture': {'type': 'object', 'properties': {'devicePosture': {'enum': ['POSTURE_UNSPECIFIED', 'SECURE', 'AT_RISK', 'POTENTIALLY_COMPROMISED'], 'type': 'string', 'description': "Device's security posture value.", 'x-google-enum-descriptions': ['Unspecified. There is no posture detail for this posture value.', 'This device is secure.', 'This device may be more vulnerable to malicious actors than is recommended for use with corporate data.', 'This device may be compromised and corporate data may be accessible to unauthorized actors.']}, 'postureDetails': {'type': 'array', 'items': {'$ref': '#/$defs/PostureDetail'}, 'description': 'Additional details regarding the security posture of the device.'}}, 'description': 'The security posture of the device, as determined by the current device state and the policies applied.'}, 'ApplicationEvent': {'type': 'object', 'properties': {'eventType': {'enum': ['APPLICATION_EVENT_TYPE_UNSPECIFIED', 'INSTALLED', 'CHANGED', 'DATA_CLEARED', 'REMOVED', 'REPLACED', 'RESTARTED', 'PINNED', 'UNPINNED'], 'type': 'string', 'description': 'App event type.', 'x-google-enum-descriptions': ['This value is disallowed.', 'The app was installed.', 'The app was changed, for example, a component was enabled or disabled.', 'The app data was cleared.', 'The app was removed.', 'A new version of the app has been installed, replacing the old version.', 'The app was restarted.', 'The app was pinned to the foreground.', 'The app was unpinned.']}, 'createTime': {'type': 'string', 'format': 'date-time', 'description': 'The creation time of the event.'}}, 'description': 'An app-related event.'}, 'DpcMigrationInfo': {'type': 'object', 'properties': {'previousDpc': {'type': 'string', 'readOnly': True, 'description': 'Output only. If this device was migrated from another DPC, this is its package name. Not populated otherwise.'}, 'additionalData': {'type': 'string', 'readOnly': True, 'description': 'Output only. If this device was migrated from another DPC, the `additionalData` field of the migration token is populated here.'}}, 'description': 'Information related to whether this device was migrated from being managed by another Device Policy Controller (DPC).'}, 'SystemUpdateInfo': {'type': 'object', 'properties': {'updateStatus': {'enum': ['UPDATE_STATUS_UNKNOWN', 'UP_TO_DATE', 'UNKNOWN_UPDATE_AVAILABLE', 'SECURITY_UPDATE_AVAILABLE', 'OS_UPDATE_AVAILABLE'], 'type': 'string', 'description': 'The status of an update: whether an update exists and what type it is.', 'x-google-enum-descriptions': ['It is unknown whether there is a pending system update. This happens when, for example, the device API level is less than 26, or if the version of Android Device Policy is outdated.', 'There is no pending system update available on the device.', 'There is a pending system update available, but its type is not known.', 'There is a pending security update available.', 'There is a pending OS update available.']}, 'updateReceivedTime': {'type': 'string', 'format': 'date-time', 'description': 'The time when the update was first available. A zero value indicates that this field is not set. This field is set only if an update is available (that is, updateStatus is neither UPDATE_STATUS_UNKNOWN nor UP_TO_DATE).'}}, 'description': 'Information about a potential pending system update.'}, 'ApplicationReport': {'type': 'object', 'properties': {'state': {'enum': ['APPLICATION_STATE_UNSPECIFIED', 'REMOVED', 'INSTALLED'], 'type': 'string', 'description': 'Application state.', 'x-google-enum-descriptions': ['App state is unspecified', 'App was removed from the device', 'App is installed on the device']}, 'events': {'type': 'array', 'items': {'$ref': '#/$defs/ApplicationEvent'}, 'description': 'The list of app events which have occurred in the last 30 hours.'}, 'displayName': {'type': 'string', 'description': 'The display name of the app.'}, 'packageName': {'type': 'string', 'description': 'Package name of the app.'}, 'versionCode': {'type': 'integer', 'format': 'int32', 'description': 'The app version code, which can be used to determine whether one version is more recent than another.'}, 'versionName': {'type': 'string', 'description': 'The app version as displayed to the user.'}, 'keyedAppStates': {'type': 'array', 'items': {'$ref': '#/$defs/KeyedAppState'}, 'description': 'List of keyed app states reported by the app.'}, 'userFacingType': {'enum': ['USER_FACING_TYPE_UNSPECIFIED', 'NOT_USER_FACING', 'USER_FACING'], 'type': 'string', 'description': 'Whether the app is user facing.', 'x-google-enum-descriptions': ['App user facing type is unspecified.', 'App is not user facing.', 'App is user facing.']}, 'signingKeyCerts': {'type': 'array', 'items': {'$ref': '#/$defs/ApplicationSigningKeyCert'}, 'readOnly': True, 'description': 'Output only. Signing key certificates of the app.'}, 'applicationSource': {'enum': ['APPLICATION_SOURCE_UNSPECIFIED', 'SYSTEM_APP_FACTORY_VERSION', 'SYSTEM_APP_UPDATED_VERSION', 'INSTALLED_FROM_PLAY_STORE', 'CUSTOM'], 'type': 'string', 'description': 'The source of the package.', 'x-google-enum-descriptions': ['The app was sideloaded from an unspecified source.', "This is a system app from the device's factory image.", 'This is an updated system app.', 'The app was installed from the Google Play Store.', 'The app was installed using the [AMAPI SDK command](https://developers.google.com/android/management/extensibility-sdk-integration). See also: `CUSTOM`']}, 'packageSha256Hash': {'type': 'string', 'description': "The SHA-256 hash of the app's APK file, which can be used to verify the app hasn't been modified. Each byte of the hash value is represented as a two-digit hexadecimal number."}, 'installerPackageName': {'type': 'string', 'description': 'The package name of the app that installed this app.'}, 'signingKeyCertFingerprints': {'type': 'array', 'items': {'type': 'string'}, 'deprecated': True, 'description': 'Deprecated. Use `signingKeyCerts` instead. The SHA-1 hash of each [`android.content.pm.Signature`](https://developer.android.com/reference/android/content/pm/Signature.html) associated with the app package. Each byte of each hash value is represented as a two-digit hexadecimal number.'}}, 'description': 'Information reported about an installed app.'}, 'UserFacingMessage': {'type': 'object', 'properties': {'defaultMessage': {'type': 'string', 'description': "The default message displayed if no localized message is specified or the user's locale doesn't match with any of the localized messages. A default message must be provided if any localized messages are provided."}, 'localizedMessages': {'type': 'object', 'description': 'A map containing pairs, where locale is a well-formed [BCP 47 language](https://www.w3.org/International/articles/language-tags/) code, such as en-US, es-ES, or fr.', 'additionalProperties': {'type': 'string'}}}, 'description': 'Provides a user-facing message with locale info. The maximum message length is 4096 characters.'}, 'NonComplianceDetail': {'type': 'object', 'properties': {'fieldPath': {'type': 'string', 'description': 'For settings with nested fields, if a particular nested field is out of compliance, this specifies the full path to the offending field. The path is formatted in the same way the policy JSON field would be referenced in JavaScript, that is: 1) For object-typed fields, the field name is followed by a dot then by a subfield name. 2) For array-typed fields, the field name is followed by the array index enclosed in brackets. For example, to indicate a problem with the `url` field in the `externalData` field in the 3rd application, the path would be `applications[2].externalData.url`'}, 'packageName': {'type': 'string', 'description': 'The package name indicating which app is out of compliance, if applicable.'}, 'settingName': {'type': 'string', 'description': 'The name of the policy setting. This is the JSON field name of a top-level [`Policy`](/android/management/reference/rest/v1/enterprises.policies#Policy) field.'}, 'currentValue': {'description': 'If the policy setting could not be applied, the current value of the setting on the device.'}, 'nonComplianceReason': {'enum': ['NON_COMPLIANCE_REASON_UNSPECIFIED', 'API_LEVEL', 'MANAGEMENT_MODE', 'USER_ACTION', 'INVALID_VALUE', 'APP_NOT_INSTALLED', 'UNSUPPORTED', 'APP_INSTALLED', 'PENDING', 'APP_INCOMPATIBLE', 'APP_NOT_UPDATED', 'DEVICE_INCOMPATIBLE', 'APP_SIGNING_CERT_MISMATCH', 'PROJECT_NOT_PERMITTED'], 'type': 'string', 'description': 'The reason the device is not in compliance with the setting.', 'x-google-enum-descriptions': ['This value is not used.', 'The setting is not supported in the API level of the Android version running on the device.', "The management mode (such as fully managed or work profile) doesn't support the setting.", 'The user has not taken required action to comply with the setting.', 'The setting has an invalid value.', 'The app required to implement the policy is not installed.', 'The policy is not supported by the version of Android Device Policy on the device.', 'A blocked app is installed.', "The setting hasn't been applied at the time of the report, but is expected to be applied shortly.", "The setting can't be applied to the app because the app doesn't support it, for example because its target SDK version is not high enough.", "The app is installed, but it hasn't been updated to the minimum version code specified by policy.", 'The device is incompatible with the policy requirements.', "The app's signing certificate does not match the setting value.", 'The Google Cloud Platform project used to manage the device is not permitted to use this policy.']}, 'installationFailureReason': {'enum': ['INSTALLATION_FAILURE_REASON_UNSPECIFIED', 'INSTALLATION_FAILURE_REASON_UNKNOWN', 'IN_PROGRESS', 'NOT_FOUND', 'NOT_COMPATIBLE_WITH_DEVICE', 'NOT_APPROVED', 'PERMISSIONS_NOT_ACCEPTED', 'NOT_AVAILABLE_IN_COUNTRY', 'NO_LICENSES_REMAINING', 'NOT_ENROLLED', 'USER_INVALID', 'NETWORK_ERROR_UNRELIABLE_CONNECTION', 'INSUFFICIENT_STORAGE'], 'type': 'string', 'description': "If `package_name` is set and the non-compliance reason is `APP_NOT_INSTALLED` or `APP_NOT_UPDATED`, the detailed reason the app can't be installed or updated.", 'x-google-enum-descriptions': ['This value is disallowed.', "An unknown condition is preventing the app from being installed. Some potential reasons are that the device doesn't have enough storage, the device network connection is unreliable, or the installation is taking longer than expected. The installation will be retried automatically.", 'The installation is still in progress.', 'The app was not found in Play.', 'The app is incompatible with the device.', 'The app has not been approved by the admin.', 'The app has new permissions that have not been accepted by the admin.', "The app is not available in the user's country.", 'There are no licenses available to assign to the user.', 'The enterprise is no longer enrolled with Managed Google Play or the admin has not accepted the latest Managed Google Play Terms of Service.', 'The user is no longer valid. The user may have been deleted or disabled.', "A network error on the user's device has prevented the install from succeeding. This usually happens when the device's internet connectivity is degraded, unavailable or there's a network configuration issue. Please ensure the device has access to full internet connectivity on a network that meets [`Android Enterprise Network Requirements`](https://support.google.com/work/android/answer/10513641). App install or update will automatically resume once this is the case.", "The user's device does not have sufficient storage space to install the app. This can be resolved by clearing up storage space on the device. App install or update will automatically resume once the device has sufficient storage."]}, 'specificNonComplianceReason': {'enum': ['SPECIFIC_NON_COMPLIANCE_REASON_UNSPECIFIED', 'PASSWORD_POLICIES_USER_CREDENTIALS_CONFIRMATION_REQUIRED', 'PASSWORD_POLICIES_PASSWORD_EXPIRED', 'PASSWORD_POLICIES_PASSWORD_NOT_SUFFICIENT', 'ONC_WIFI_INVALID_VALUE', 'ONC_WIFI_API_LEVEL', 'ONC_WIFI_INVALID_ENTERPRISE_CONFIG', 'ONC_WIFI_USER_SHOULD_REMOVE_NETWORK', 'ONC_WIFI_KEY_PAIR_ALIAS_NOT_CORRESPONDING_TO_EXISTING_KEY', 'PERMISSIBLE_USAGE_RESTRICTION', 'REQUIRED_ACCOUNT_NOT_IN_ENTERPRISE', 'NEW_ACCOUNT_NOT_IN_ENTERPRISE', 'DEFAULT_APPLICATION_SETTING_UNSUPPORTED_SCOPES', 'DEFAULT_APPLICATION_SETTING_FAILED_FOR_SCOPE', 'PRIVATE_DNS_HOST_NOT_SERVING'], 'type': 'string', 'description': 'The policy-specific reason the device is not in compliance with the setting.', 'x-google-enum-descriptions': ['Specific non-compliance reason is not specified. Fields in `specific_non_compliance_context` are not set.', 'User needs to confirm credentials by entering the screen lock. Fields in `specific_non_compliance_context` are not set. `nonComplianceReason` is set to `USER_ACTION`.', 'The device or profile password has expired. `passwordPoliciesContext` is set. `nonComplianceReason` is set to `USER_ACTION`.', 'The device password does not satisfy password requirements. `passwordPoliciesContext` is set. `nonComplianceReason` is set to `USER_ACTION`.', 'There is an incorrect value in ONC Wi-Fi configuration. `fieldPath` specifies which field value is incorrect. `oncWifiContext` is set. `nonComplianceReason` is set to `INVALID_VALUE`.', 'The ONC Wi-Fi setting is not supported in the API level of the Android version running on the device. `fieldPath` specifies which field value is not supported. `oncWifiContext` is set. `nonComplianceReason` is set to `API_LEVEL`.', 'The enterprise Wi-Fi network is missing either the root CA or domain name. `nonComplianceReason` is set to `INVALID_VALUE`.', 'User needs to remove the configured Wi-Fi network manually. This is applicable only on work profiles on personally-owned devices. `nonComplianceReason` is set to `USER_ACTION`.', 'Key pair alias specified via [`ClientCertKeyPairAlias`](https://chromium.googlesource.com/chromium/src/+/main/components/onc/docs/onc_spec.md#eap-type) field in `openNetworkConfiguration` does not correspond to an existing key installed on the device. `nonComplianceReason` is set to `INVALID_VALUE`.', 'This policy setting is restricted and cannot be set for this Google Cloud Platform project. More details (including how to enable usage of this policy setting) are available in the [Permissible Usage policy] (https://developers.google.com/android/management/permissible-usage). `nonComplianceReason` is set to `PROJECT_NOT_PERMITTED`.', 'Work account required by the `workAccountSetupConfig` policy setting is not part of the enterprise anymore. `nonComplianceReason` is set to `USER_ACTION`.', 'Work account added by the user is not part of the enterprise. `nonComplianceReason` is set to `USER_ACTION`.', 'The default application setting is applied to the scopes that are not supported by the management mode, even if the management mode itself is supported for the app type (e.g., a policy with `DEFAULT_BROWSER` app type and [`SCOPE_PERSONAL_PROFILE`] list sent to a fully managed device results in the scopes being inapplicable for the management mode). If the management mode is not supported for the app type, a `NonComplianceDetail` with `MANAGEMENT_MODE` is reported, without a `specificNonComplianceReason`. `nonComplianceReason` is set to `MANAGEMENT_MODE`.', 'The default application setting failed to apply for a specific scope. `defaultApplicationContext` is set. `nonComplianceReason` is set to `INVALID_VALUE` or `APP_NOT_INSTALLED`.', 'The specified host for private DNS is a valid hostname but was found to not be a private DNS server. `nonComplianceReason` is set to `INVALID_VALUE`.']}, 'specificNonComplianceContext': {'$ref': '#/$defs/SpecificNonComplianceContext', 'description': 'Additional context for `specific_non_compliance_reason`.'}}, 'description': 'Provides detail about non-compliance with a policy setting.'}, 'PasswordRequirements': {'type': 'object', 'properties': {'passwordScope': {'enum': ['SCOPE_UNSPECIFIED', 'SCOPE_DEVICE', 'SCOPE_PROFILE'], 'type': 'string', 'description': 'Optional. The scope that the password requirement applies to.', 'x-google-enum-descriptions': ['The scope is unspecified. The password requirements are applied to the work profile for work profile devices and the whole device for fully managed or dedicated devices.', 'The password requirements are only applied to the device.', 'The password requirements are only applied to the work profile.']}, 'passwordQuality': {'enum': ['PASSWORD_QUALITY_UNSPECIFIED', 'BIOMETRIC_WEAK', 'SOMETHING', 'NUMERIC', 'NUMERIC_COMPLEX', 'ALPHABETIC', 'ALPHANUMERIC', 'COMPLEX', 'COMPLEXITY_LOW', 'COMPLEXITY_MEDIUM', 'COMPLEXITY_HIGH'], 'type': 'string', 'description': 'Optional. The required password quality.', 'x-google-enum-descriptions': ['There are no password requirements.', 'The device must be secured with a low-security biometric recognition technology, at minimum. This includes technologies that can recognize the identity of an individual that are roughly equivalent to a 3-digit PIN (false detection is less than 1 in 1,000). This, when applied on personally owned work profile devices on Android 12 device-scoped, will be treated as `COMPLEXITY_LOW` for application. See `PasswordQuality` for details.', 'A password is required, but there are no restrictions on what the password must contain. This, when applied on personally owned work profile devices on Android 12 device-scoped, will be treated as `COMPLEXITY_LOW` for application. See `PasswordQuality` for details.', 'The password must contain numeric characters. This, when applied on personally owned work profile devices on Android 12 device-scoped, will be treated as `COMPLEXITY_MEDIUM` for application. See `PasswordQuality` for details.', 'The password must contain numeric characters with no repeating (4444) or ordered (1234, 4321, 2468) sequences. This, when applied on personally owned work profile devices on Android 12 device-scoped, will be treated as `COMPLEXITY_MEDIUM` for application. See `PasswordQuality` for details.', 'The password must contain alphabetic (or symbol) characters. This, when applied on personally owned work profile devices on Android 12 device-scoped, will be treated as `COMPLEXITY_HIGH` for application. See `PasswordQuality` for details.', 'The password must contain both numeric and alphabetic (or symbol) characters. This, when applied on personally owned work profile devices on Android 12 device-scoped, will be treated as `COMPLEXITY_HIGH` for application. See `PasswordQuality` for details.', 'The password must meet the minimum requirements specified in `passwordMinimumLength`, `passwordMinimumLetters`, `passwordMinimumSymbols`, etc. For example, if `passwordMinimumSymbols` is `2`, the password must contain at least two symbols. This, when applied on personally owned work profile devices on Android 12 device-scoped, will be treated as `COMPLEXITY_HIGH` for application. In this case, the requirements in `passwordMinimumLength`, `passwordMinimumLetters`, `passwordMinimumSymbols`, etc are not applied. See `PasswordQuality` for details.', 'Define the low password complexity band as: * pattern * PIN with repeating (4444) or ordered (1234, 4321, 2468) sequences This sets the minimum complexity band which the password must meet. Enforcement varies among different Android versions, management modes and password scopes. See `PasswordQuality` for details.', 'Define the medium password complexity band as: * PIN with no repeating (4444) or ordered (1234, 4321, 2468) sequences, length at least 4 * alphabetic, length at least 4 * alphanumeric, length at least 4 This sets the minimum complexity band which the password must meet. Enforcement varies among different Android versions, management modes and password scopes. See `PasswordQuality` for details.', 'Define the high password complexity band as: On Android 12 and above: * PIN with no repeating (4444) or ordered (1234, 4321, 2468) sequences, length at least 8 * alphabetic, length at least 6 * alphanumeric, length at least 6 This sets the minimum complexity band which the password must meet. Enforcement varies among different Android versions, management modes and password scopes. See `PasswordQuality` for details.']}, 'unifiedLockSettings': {'enum': ['UNIFIED_LOCK_SETTINGS_UNSPECIFIED', 'ALLOW_UNIFIED_WORK_AND_PERSONAL_LOCK', 'REQUIRE_SEPARATE_WORK_LOCK'], 'type': 'string', 'description': 'Optional. Controls whether a unified lock is allowed for the device and the work profile, on devices running Android 9 and above with a work profile. This can be set only if `password_scope` is set to `SCOPE_PROFILE`, the policy will be rejected otherwise. If user has not set a separate work lock and this field is set to `REQUIRE_SEPARATE_WORK_LOCK`, a `NonComplianceDetail` is reported with `nonComplianceReason` set to `USER_ACTION`.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `ALLOW_UNIFIED_WORK_AND_PERSONAL_LOCK`.', 'A common lock for the device and the work profile is allowed.', 'A separate lock for the work profile is required.']}, 'passwordHistoryLength': {'type': 'integer', 'format': 'int32', 'description': "Optional. The length of the password history. After setting this field, the user won't be able to enter a new password that is the same as any password in the history. A value of 0 means there is no restriction."}, 'passwordMinimumLength': {'type': 'integer', 'format': 'int32', 'description': 'Optional. The minimum allowed password length. A value of 0 means there is no restriction. Only enforced when `password_quality` is `NUMERIC`, `NUMERIC_COMPLEX`, `ALPHABETIC`, `ALPHANUMERIC`, or `COMPLEX`.'}, 'requirePasswordUnlock': {'enum': ['REQUIRE_PASSWORD_UNLOCK_UNSPECIFIED', 'USE_DEFAULT_DEVICE_TIMEOUT', 'REQUIRE_EVERY_DAY'], 'type': 'string', 'description': 'Optional. The length of time after a device or work profile is unlocked using a strong form of authentication (password, PIN, pattern) that it can be unlocked using any other authentication method (e.g. fingerprint, trust agents, face). After the specified time period elapses, only strong forms of authentication can be used to unlock the device or work profile.', 'x-google-enum-descriptions': ['Unspecified. Defaults to USE_DEFAULT_DEVICE_TIMEOUT.', 'The timeout period is set to the device’s default.', 'The timeout period is set to 24 hours.']}, 'passwordMinimumLetters': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Minimum number of letters required in the password. Only enforced when `password_quality` is `COMPLEX`.'}, 'passwordMinimumNumeric': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Minimum number of numerical digits required in the password. Only enforced when `password_quality` is `COMPLEX`.'}, 'passwordMinimumSymbols': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Minimum number of symbols required in the password. Only enforced when `password_quality` is `COMPLEX`.'}, 'passwordMinimumLowerCase': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Minimum number of lower case letters required in the password. Only enforced when `password_quality` is `COMPLEX`.'}, 'passwordMinimumNonLetter': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Minimum number of non-letter characters (numerical digits or symbols) required in the password. Only enforced when `password_quality` is `COMPLEX`.'}, 'passwordMinimumUpperCase': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Minimum number of upper case letters required in the password. Only enforced when `password_quality` is `COMPLEX`.'}, 'passwordExpirationTimeout': {'type': 'string', 'format': 'google-duration', 'description': 'Optional. Password expiration timeout.'}, 'maximumFailedPasswordsForWipe': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Number of incorrect device-unlock passwords that can be entered before a device is wiped. A value of 0 means there is no restriction.'}}, 'description': 'Requirements for the password used to unlock a device.'}, 'PowerManagementEvent': {'type': 'object', 'properties': {'eventType': {'enum': ['POWER_MANAGEMENT_EVENT_TYPE_UNSPECIFIED', 'BATTERY_LEVEL_COLLECTED', 'POWER_CONNECTED', 'POWER_DISCONNECTED', 'BATTERY_LOW', 'BATTERY_OKAY', 'BOOT_COMPLETED', 'SHUTDOWN'], 'type': 'string', 'description': 'Event type.', 'x-google-enum-descriptions': ['Unspecified. No events have this type.', 'Battery level was measured.', 'The device started charging.', 'The device stopped charging.', 'The device entered low-power mode.', 'The device exited low-power mode.', 'The device booted.', 'The device shut down.']}, 'createTime': {'type': 'string', 'format': 'date-time', 'description': 'The creation time of the event.'}, 'batteryLevel': {'type': 'number', 'format': 'float', 'description': 'For `BATTERY_LEVEL_COLLECTED` events, the battery level as a percentage.'}}, 'description': 'A power management event.'}, 'CommonCriteriaModeInfo': {'type': 'object', 'properties': {'commonCriteriaModeStatus': {'enum': ['COMMON_CRITERIA_MODE_STATUS_UNKNOWN', 'COMMON_CRITERIA_MODE_DISABLED', 'COMMON_CRITERIA_MODE_ENABLED'], 'type': 'string', 'description': 'Whether Common Criteria Mode is enabled.', 'x-google-enum-descriptions': ['Unknown status.', 'Common Criteria Mode is currently disabled.', 'Common Criteria Mode is currently enabled.']}, 'policySignatureVerificationStatus': {'enum': ['POLICY_SIGNATURE_VERIFICATION_STATUS_UNSPECIFIED', 'POLICY_SIGNATURE_VERIFICATION_DISABLED', 'POLICY_SIGNATURE_VERIFICATION_SUCCEEDED', 'POLICY_SIGNATURE_VERIFICATION_NOT_SUPPORTED', 'POLICY_SIGNATURE_VERIFICATION_FAILED'], 'type': 'string', 'readOnly': True, 'description': 'Output only. The status of policy signature verification.', 'x-google-enum-descriptions': ['Unspecified. The verification status has not been reported. This is set only if `statusReportingSettings.commonCriteriaModeEnabled` is false.', 'Policy signature verification is disabled on the device as `common_criteria_mode` is set to false.', 'Policy signature verification succeeded.', 'Policy signature verification is not supported, e.g. because the device has been enrolled with a CloudDPC version that does not support the policy signature verification.', 'The policy signature verification failed. The policy has not been applied.']}}, 'description': "Information about Common Criteria Mode—security standards defined in the [Common Criteria for Information Technology Security Evaluation](https://www.commoncriteriaportal.org/) (CC). This information is only available if [`statusReportingSettings.commonCriteriaModeEnabled`](/android/management/reference/rest/v1/enterprises.policies#statusreportingsettings) is `true` in the device's policy."}, 'DefaultApplicationInfo': {'type': 'object', 'properties': {'packageName': {'type': 'string', 'readOnly': True, 'description': 'Output only. The package name of the current default application.'}, 'defaultApplicationType': {'enum': ['DEFAULT_APPLICATION_TYPE_UNSPECIFIED', 'DEFAULT_ASSISTANT', 'DEFAULT_BROWSER', 'DEFAULT_CALL_REDIRECTION', 'DEFAULT_CALL_SCREENING', 'DEFAULT_DIALER', 'DEFAULT_HOME', 'DEFAULT_SMS', 'DEFAULT_WALLET'], 'type': 'string', 'readOnly': True, 'description': 'Output only. The default application type.', 'x-google-enum-descriptions': ['Unspecified. This value must not be used.', 'The assistant app type. This app type is only allowed to be set for `SCOPE_FULLY_MANAGED`. Supported on fully managed devices on Android 16 and above. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for other management modes. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 16.', 'The browser app type. Supported on Android 16 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 16.', 'The call redirection app type. This app type cannot be set for `SCOPE_PERSONAL_PROFILE`. Supported on Android 16 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 16.', 'The call screening app type. This app type cannot be set for `SCOPE_PERSONAL_PROFILE`. Supported on Android 16 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 16.', 'The dialer app type. Supported on fully managed devices on Android 14 and 15. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for other management modes. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 14. Supported on all management modes on Android 16 and above.', 'The home app type. This app type is only allowed to be set for `SCOPE_FULLY_MANAGED`. Supported on fully managed devices on Android 16 and above. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for other management modes. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 16.', 'The SMS app type. This app type cannot be set for `SCOPE_WORK_PROFILE`. Supported on company-owned devices on Android 16 and above. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for personally-owned devices. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 16.', 'The wallet app type. The default application of this type applies across profiles. On a company-owned device with a work profile, admins can set the scope to `SCOPE_PERSONAL_PROFILE` to set a personal profile pre-installed system app as the default, or to `SCOPE_WORK_PROFILE` to set a work profile app as the default. It is not allowed to specify both scopes at the same time. Due to a known issue, the user may be able to change the default wallet even when this is set on a fully managed device. Supported on company-owned devices on Android 16 and above. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for personally-owned devices. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 16.']}, 'defaultApplicationSettingAttempts': {'type': 'array', 'items': {'$ref': '#/$defs/DefaultApplicationSettingAttempt'}, 'readOnly': True, 'description': 'Output only. Details on the default application setting attempts, in the same order as listed in `defaultApplications`.'}}, 'description': 'The default application information for a specific `DefaultApplicationType`.'}, 'PasswordPoliciesContext': {'type': 'object', 'properties': {'passwordPolicyScope': {'enum': ['SCOPE_UNSPECIFIED', 'SCOPE_DEVICE', 'SCOPE_PROFILE'], 'type': 'string', 'description': 'The scope of non-compliant password.', 'x-google-enum-descriptions': ['The scope is unspecified. The password requirements are applied to the work profile for work profile devices and the whole device for fully managed or dedicated devices.', 'The password requirements are only applied to the device.', 'The password requirements are only applied to the work profile.']}}, 'description': 'Additional context for non-compliance related to password policies.'}, 'ApplicationSigningKeyCert': {'type': 'object', 'properties': {'signingKeyCertFingerprintSha256': {'type': 'string', 'format': 'byte', 'description': 'Required. The SHA-256 hash value of the signing key certificate of the app. This must be a valid SHA-256 hash value, i.e. 32 bytes.'}}, 'description': 'The application signing key certificate.'}, 'DefaultApplicationContext': {'type': 'object', 'properties': {'defaultApplicationScope': {'enum': ['DEFAULT_APPLICATION_SCOPE_UNSPECIFIED', 'SCOPE_FULLY_MANAGED', 'SCOPE_WORK_PROFILE', 'SCOPE_PERSONAL_PROFILE'], 'type': 'string', 'readOnly': True, 'description': 'Output only. The scope of non-compliant default application setting.', 'x-google-enum-descriptions': ['Unspecified. This value must not be used.', 'Sets the application as the default on fully managed devices.', 'Sets the application as the work profile default. Only supported for `DEFAULT_BROWSER`, `DEFAULT_CALL_REDIRECTION`, `DEFAULT_CALL_SCREENING`, `DEFAULT_DIALER` and `DEFAULT_WALLET`.', 'Sets the application as the personal profile default on company-owned devices with a work profile. Only pre-installed system apps can be set as the default. Only supported for `DEFAULT_BROWSER`, `DEFAULT_DIALER`, `DEFAULT_SMS` and `DEFAULT_WALLET`.']}}, 'description': 'Additional context for non-compliance related to default application settings.'}, 'SpecificNonComplianceContext': {'type': 'object', 'properties': {'oncWifiContext': {'$ref': '#/$defs/OncWifiContext', 'description': 'Additional context for non-compliance related to Wi-Fi configuration. See `ONC_WIFI_INVALID_VALUE` and `ONC_WIFI_API_LEVEL`'}, 'passwordPoliciesContext': {'$ref': '#/$defs/PasswordPoliciesContext', 'description': 'Additional context for non-compliance related to password policies. See `PASSWORD_POLICIES_PASSWORD_EXPIRED` and `PASSWORD_POLICIES_PASSWORD_NOT_SUFFICIENT`.'}, 'defaultApplicationContext': {'$ref': '#/$defs/DefaultApplicationContext', 'readOnly': True, 'description': 'Output only. Additional context for non-compliance related to default application settings. See `DEFAULT_APPLICATION_SETTING_FAILED_FOR_SCOPE`.'}}, 'description': 'Additional context for `SpecificNonComplianceReason`.'}, 'DefaultApplicationSettingAttempt': {'type': 'object', 'properties': {'packageName': {'type': 'string', 'readOnly': True, 'description': 'Output only. The package name of the attempted application.'}, 'attemptOutcome': {'enum': ['ATTEMPT_OUTCOME_UNSPECIFIED', 'SUCCESS', 'APP_NOT_INSTALLED', 'APP_SIGNING_CERT_MISMATCH', 'OTHER_FAILURE'], 'type': 'string', 'readOnly': True, 'description': 'Output only. The outcome of setting the app as the default.', 'x-google-enum-descriptions': ['Attempt outcome is unspecified. This is not used.', 'App is successfully set as the default.', 'Attempt failed as the app is not installed.', 'Attempt failed as the signing key certificate fingerprint of the app from Play Store or from `ApplicationPolicy.signingKeyCerts` does not match the one on the device.', 'Attempt failed due to other reasons.']}}, 'description': 'Details on a default application setting attempt.'}}, 'properties': {'name': {'type': 'string', 'description': 'The name of the device in the form `enterprises/{enterpriseId}/devices/{deviceId}`.'}, 'user': {'$ref': '#/$defs/User', 'description': 'The user who owns the device.'}, 'state': {'enum': ['DEVICE_STATE_UNSPECIFIED', 'ACTIVE', 'DISABLED', 'DELETED', 'PROVISIONING', 'LOST', 'PREPARING_FOR_MIGRATION', 'DEACTIVATED_BY_DEVICE_FINANCE'], 'type': 'string', 'description': 'The state to be applied to the device. This field can be modified by a patch request. Note that when calling `enterprises.devices.patch`, `ACTIVE` and `DISABLED` are the only allowable values. To enter the device into a `DELETED` state, call [`enterprises.devices.delete`](/android/management/reference/rest/v1/enterprises.devices/delete).', 'x-google-enum-descriptions': ['This value is disallowed.', 'The device is active.', 'The device is disabled.', 'The device was deleted. This state is never returned by an API call, but is used in the final status report when the device acknowledges the deletion. If the device is deleted via the API call, this state is published to Pub/Sub. If the user deletes the work profile or resets the device, the device state will remain unknown to the server.', 'The device is being provisioned. Newly enrolled devices are in this state until they have a policy applied.', 'The device is lost. This state is only possible on organization-owned devices.', 'The device is preparing for migrating to Android Management API. No further action is needed for the migration to continue.', 'This is a financed device that has been "locked" by the financing agent. This means certain policy settings have been applied which limit device functionality until the device has been "unlocked" by the financing agent. The device will continue to apply policy settings excluding those overridden by the financing agent. When the device is "locked", the state is reported in appliedState as `DEACTIVATED_BY_DEVICE_FINANCE`.']}, 'apiLevel': {'type': 'integer', 'format': 'int32', 'description': 'The API level of the Android platform version running on the device.'}, 'displays': {'type': 'array', 'items': {'$ref': '#/$defs/Display'}, 'description': "Detailed information about displays on the device. This information is only available if `displayInfoEnabled` is true in the device's policy."}, 'userName': {'type': 'string', 'description': 'The resource name of the user that owns this device in the form `enterprises/{enterpriseId}/users/{userId}`.'}, 'ownership': {'enum': ['OWNERSHIP_UNSPECIFIED', 'COMPANY_OWNED', 'PERSONALLY_OWNED'], 'type': 'string', 'description': 'Ownership of the managed device.', 'x-google-enum-descriptions': ['Ownership is unspecified.', 'Device is company-owned.', 'Device is personally-owned.']}, 'memoryInfo': {'$ref': '#/$defs/MemoryInfo', 'description': 'Memory information: contains information about device memory and storage.'}, 'policyName': {'type': 'string', 'description': "The name of the policy applied to the device, in the form `enterprises/{enterpriseId}/policies/{policyId}`. If not specified, the `policy_name` for the device's user is applied. This field can be modified by a patch request. You can specify only the `policyId` when calling `enterprises.devices.patch`, as long as the `policyId` doesn’t contain any slashes. The rest of the policy name is inferred."}, 'networkInfo': {'$ref': '#/$defs/NetworkInfo', 'description': "Device network information. This information is only available if `networkInfoEnabled` is true in the device's policy."}, 'appliedState': {'enum': ['DEVICE_STATE_UNSPECIFIED', 'ACTIVE', 'DISABLED', 'DELETED', 'PROVISIONING', 'LOST', 'PREPARING_FOR_MIGRATION', 'DEACTIVATED_BY_DEVICE_FINANCE'], 'type': 'string', 'description': 'The state currently applied to the device.', 'x-google-enum-descriptions': ['This value is disallowed.', 'The device is active.', 'The device is disabled.', 'The device was deleted. This state is never returned by an API call, but is used in the final status report when the device acknowledges the deletion. If the device is deleted via the API call, this state is published to Pub/Sub. If the user deletes the work profile or resets the device, the device state will remain unknown to the server.', 'The device is being provisioned. Newly enrolled devices are in this state until they have a policy applied.', 'The device is lost. This state is only possible on organization-owned devices.', 'The device is preparing for migrating to Android Management API. No further action is needed for the migration to continue.', 'This is a financed device that has been "locked" by the financing agent. This means certain policy settings have been applied which limit device functionality until the device has been "unlocked" by the financing agent. The device will continue to apply policy settings excluding those overridden by the financing agent. When the device is "locked", the state is reported in appliedState as `DEACTIVATED_BY_DEVICE_FINANCE`.']}, 'hardwareInfo': {'$ref': '#/$defs/HardwareInfo', 'description': 'Detailed information about the device hardware.'}, 'memoryEvents': {'type': 'array', 'items': {'$ref': '#/$defs/MemoryEvent'}, 'description': "Events related to memory and storage measurements in chronological order. This information is only available if `memoryInfoEnabled` is true in the device's policy. Events are retained for a certain period of time and old events are deleted."}, 'softwareInfo': {'$ref': '#/$defs/SoftwareInfo', 'description': "Detailed information about the device software. This information is only available if `softwareInfoEnabled` is true in the device's policy."}, 'deviceSettings': {'$ref': '#/$defs/DeviceSettings', 'description': "Device settings information. This information is only available if `deviceSettingsEnabled` is true in the device's policy."}, 'disabledReason': {'$ref': '#/$defs/UserFacingMessage', 'description': 'If the device state is `DISABLED`, an optional message that is displayed on the device indicating the reason the device is disabled. This field can be modified by a patch request.'}, 'enrollmentTime': {'type': 'string', 'format': 'date-time', 'description': 'The time of device enrollment.'}, 'managementMode': {'enum': ['MANAGEMENT_MODE_UNSPECIFIED', 'DEVICE_OWNER', 'PROFILE_OWNER'], 'type': 'string', 'description': 'The type of management mode Android Device Policy takes on the device. This influences which policy settings are supported.', 'x-google-enum-descriptions': ['This value is disallowed.', 'Device owner. Android Device Policy has full control over the device.', 'Profile owner. Android Device Policy has control over a managed profile on the device.']}, 'policyCompliant': {'type': 'boolean', 'description': 'Whether the device is compliant with its policy.'}, 'securityPosture': {'$ref': '#/$defs/SecurityPosture', 'description': "Device's security posture value that reflects how secure the device is."}, 'dpcMigrationInfo': {'$ref': '#/$defs/DpcMigrationInfo', 'readOnly': True, 'description': 'Output only. Information related to whether this device was migrated from being managed by another Device Policy Controller (DPC).'}, 'systemProperties': {'type': 'object', 'description': "Map of selected system properties name and value related to the device. This information is only available if `systemPropertiesEnabled` is true in the device's policy.", 'additionalProperties': {'type': 'string'}}, 'appliedPolicyName': {'type': 'string', 'description': 'The name of the policy currently applied to the device.'}, 'applicationReports': {'type': 'array', 'items': {'$ref': '#/$defs/ApplicationReport'}, 'description': "Reports for apps installed on the device. This information is only available when `application_reports_enabled` is true in the device's policy."}, 'lastPolicySyncTime': {'type': 'string', 'format': 'date-time', 'description': 'The last time the device fetched its policy.'}, 'enrollmentTokenData': {'type': 'string', 'description': 'If the device was enrolled with an enrollment token with additional data provided, this field contains that data.'}, 'enrollmentTokenName': {'type': 'string', 'description': 'If the device was enrolled with an enrollment token, this field contains the name of the token.'}, 'previousDeviceNames': {'type': 'array', 'items': {'type': 'string'}, 'description': 'If the same physical device has been enrolled multiple times, this field contains its previous device names. The serial number is used as the unique identifier to determine if the same physical device has enrolled previously. The names are in chronological order.'}, 'appliedPolicyVersion': {'type': 'string', 'format': 'int64', 'description': 'The version of the policy currently applied to the device.'}, 'lastStatusReportTime': {'type': 'string', 'format': 'date-time', 'description': 'The last time the device sent a status report.'}, 'nonComplianceDetails': {'type': 'array', 'items': {'$ref': '#/$defs/NonComplianceDetail'}, 'description': 'Details about policy settings that the device is not compliant with.'}, 'hardwareStatusSamples': {'type': 'array', 'items': {'$ref': '#/$defs/HardwareStatus'}, 'description': "Hardware status samples in chronological order. This information is only available if `hardwareStatusEnabled` is true in the device's policy."}, 'powerManagementEvents': {'type': 'array', 'items': {'$ref': '#/$defs/PowerManagementEvent'}, 'description': "Power management events on the device in chronological order. This information is only available if `powerManagementEventsEnabled` is true in the device's policy."}, 'commonCriteriaModeInfo': {'$ref': '#/$defs/CommonCriteriaModeInfo', 'description': "Information about Common Criteria Mode—security standards defined in the [Common Criteria for Information Technology Security Evaluation](https://www.commoncriteriaportal.org/) (CC). This information is only available if statusReportingSettings.commonCriteriaModeEnabled is `true` in the device's policy the device is company-owned."}, 'defaultApplicationInfo': {'type': 'array', 'items': {'$ref': '#/$defs/DefaultApplicationInfo'}, 'readOnly': True, 'description': "Output only. The default application information for the `DefaultApplicationType`. This information is only available if `defaultApplicationInfoReportingEnabled` is true in the device's policy. Available on Android 16 and above. All app types are reported on fully managed devices. `DEFAULT_BROWSER`, `DEFAULT_CALL_REDIRECTION`, `DEFAULT_CALL_SCREENING` and `DEFAULT_DIALER` types are reported for the work profiles on company-owned devices with a work profile and personally-owned devices. `DEFAULT_WALLET` is also reported for company-owned devices with a work profile, but will only include work profile information."}, 'appliedPasswordPolicies': {'type': 'array', 'items': {'$ref': '#/$defs/PasswordRequirements'}, 'description': 'The password requirements currently applied to the device. * This field exists because the applied requirements may be slightly different from those specified in `passwordPolicies` in some cases. * Note that this field does not provide information about password compliance. For non-compliance information, see `nonComplianceDetails`. * `NonComplianceDetail.fieldPath`, is set based on `passwordPolicies`, not based on this field.'}, 'lastPolicyComplianceReportTime': {'type': 'string', 'format': 'date-time', 'deprecated': True, 'description': 'Deprecated.'}}, 'description': "A device owned by an enterprise. Unless otherwise noted, all fields are read-only and can't be modified by `enterprises.devices.patch`."}
输入模式
{'type': 'object', 'properties': {'name': {'type': 'string', 'description': 'The name of the enterprise in the form `enterprises/{enterpriseId}`.'}}, 'description': 'Request to get an enterprise. Returns all available fields.'}
输出模式
{'type': 'object', '$defs': {'ContactInfo': {'type': 'object', 'properties': {'contactEmail': {'type': 'string', 'description': 'Email address for a point of contact, which will be used to send important announcements related to managed Google Play.'}, 'euRepresentativeName': {'type': 'string', 'description': 'The name of the EU representative.'}, 'euRepresentativeEmail': {'type': 'string', 'description': 'The email of the EU representative. The email is validated but not verified.'}, 'euRepresentativePhone': {'type': 'string', 'description': 'The phone number of the EU representative. The phone number is validated but not verified.'}, 'dataProtectionOfficerName': {'type': 'string', 'description': 'The name of the data protection officer.'}, 'dataProtectionOfficerEmail': {'type': 'string', 'description': 'The email of the data protection officer. The email is validated but not verified.'}, 'dataProtectionOfficerPhone': {'type': 'string', 'description': 'The phone number of the data protection officer The phone number is validated but not verified.'}}, 'description': 'Contact details for managed Google Play enterprises.'}, 'ExternalData': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': "The absolute URL to the data, which must use either the http or https scheme. Android Device Policy doesn't provide any credentials in the GET request, so the URL must be publicly accessible. Including a long, random component in the URL may be used to prevent attackers from discovering the URL."}, 'sha256Hash': {'type': 'string', 'description': "The base-64 encoded SHA-256 hash of the content hosted at url. If the content doesn't match this hash, Android Device Policy won't use the data."}}, 'description': 'Data hosted at an external location. The data is to be downloaded by Android Device Policy and verified against the hash.'}, 'SigninDetail': {'type': 'object', 'properties': {'qrCode': {'type': 'string', 'description': 'A JSON string whose UTF-8 representation can be used to generate a QR code to enroll a device with this enrollment token. To enroll a device using NFC, the NFC record must contain a serialized `java.util.Properties` representation of the properties in the JSON. This is a read-only field generated by the server.'}, 'tokenTag': {'type': 'string', 'description': 'An EMM-specified metadata to distinguish between instances of `SigninDetail`.'}, 'signinUrl': {'type': 'string', 'description': 'Sign-in URL for authentication when device is provisioned with a sign-in enrollment token. The sign-in endpoint should finish authentication flow with a URL in the form of https://enterprise.google.com/android/enroll?et= for a successful login, or https://enterprise.google.com/android/enroll/invalid for a failed login.'}, 'defaultStatus': {'enum': ['SIGNIN_DETAIL_DEFAULT_STATUS_UNSPECIFIED', 'SIGNIN_DETAIL_IS_DEFAULT', 'SIGNIN_DETAIL_IS_NOT_DEFAULT'], 'type': 'string', 'description': "Optional. Whether the sign-in URL should be used by default for the enterprise. The `SigninDetail` with `defaultStatus` set to SIGNIN_DETAIL_IS_DEFAULT is used for Google account enrollment method. Only one of an enterprise's signinDetails can have `defaultStatus` set to SIGNIN_DETAIL_IS_DEFAULT. If an `Enterprise` has at least one signinDetails and none of them have `defaultStatus` set to SIGNIN_DETAIL_IS_DEFAULT then the first one from the list is selected and has set `defaultStatus` to SIGNIN_DETAIL_IS_DEFAULT. If no signinDetails specified for the `Enterprise` then the Google Account device enrollment will fail.", 'x-google-enum-descriptions': ['Equivalent to `SIGNIN_DETAIL_IS_NOT_DEFAULT`.', 'The sign-in URL will be used by default for the enterprise.', 'The sign-in URL will not be used by default for the enterprise.']}, 'allowPersonalUsage': {'enum': ['ALLOW_PERSONAL_USAGE_UNSPECIFIED', 'PERSONAL_USAGE_ALLOWED', 'PERSONAL_USAGE_DISALLOWED', 'PERSONAL_USAGE_DISALLOWED_USERLESS'], 'type': 'string', 'description': 'Controls whether personal usage is allowed on a device provisioned with this enrollment token. For company-owned devices: * Enabling personal usage allows the user to set up a work profile on the device. * Disabling personal usage requires the user provision the device as a fully managed device. For personally-owned devices: * Enabling personal usage allows the user to set up a work profile on the device. * Disabling personal usage will prevent the device from provisioning. Personal usage cannot be disabled on personally-owned device.', 'x-google-enum-descriptions': ['Personal usage restriction is not specified', 'Personal usage is allowed', 'Personal usage is disallowed', 'Device is not associated with a single user, and thus both personal usage and corporate identity authentication are not expected. **Important:** This setting is mandatory for dedicated device enrollment and it is a breaking change. This change needs to be implemented before January 2025. For additional details see the [dedicated device provisioning guide](https://developers.google.com/android/management/provision-device#company-owned_devices_for_work_use_only). ']}, 'signinEnrollmentToken': {'type': 'string', 'description': 'An enterprise wide enrollment token used to trigger custom sign-in flow. This is a read-only field generated by the server.'}, 'googleAuthenticationOptions': {'$ref': '#/$defs/SigninDetailGoogleAuthenticationOptions', 'description': 'Optional. Options related to Google authentication during the enrollment.'}}, 'description': 'A resource containing sign in details for an enterprise. Use `enterprises` to manage `SigninDetail`s for a given enterprise. For an enterprise, we can have any number of `SigninDetail`s that is uniquely identified by combination of the following three fields (`signin_url`, `allow_personal_usage`, `token_tag`). One cannot create two `SigninDetail`s with the same (`signin_url`, `allow_personal_usage`, `token_tag`). (`token_tag` is an optional field). `Patch`: The operation updates the current list of `SigninDetails` with the new list of `SigninDetails`. * If the stored `SigninDetail` configuration is passed, it returns the same `signin_enrollment_token` and `qr_code`. * If we pass multiple identical `SigninDetail` configurations that are not stored, it will store the first one amongst those `SigninDetail` configurations. * if the configuration already exists we cannot request it more than once in a particular patch API call, otherwise it will give a duplicate key error and the whole operation will fail. * If we remove certain `SigninDetail` configuration from the request then it will get removed from the storage. We can then request another `signin_enrollment_token` and `qr_code` for the same `SigninDetail` configuration.'}, 'UserFacingMessage': {'type': 'object', 'properties': {'defaultMessage': {'type': 'string', 'description': "The default message displayed if no localized message is specified or the user's locale doesn't match with any of the localized messages. A default message must be provided if any localized messages are provided."}, 'localizedMessages': {'type': 'object', 'description': 'A map containing pairs, where locale is a well-formed [BCP 47 language](https://www.w3.org/International/articles/language-tags/) code, such as en-US, es-ES, or fr.', 'additionalProperties': {'type': 'string'}}}, 'description': 'Provides a user-facing message with locale info. The maximum message length is 4096 characters.'}, 'TermsAndConditions': {'type': 'object', 'properties': {'header': {'$ref': '#/$defs/UserFacingMessage', 'description': 'A short header which appears above the HTML content.'}, 'content': {'$ref': '#/$defs/UserFacingMessage', 'description': 'A well-formatted HTML string. It will be parsed on the client with android.text.Html#fromHtml.'}}, 'description': 'A terms and conditions page to be accepted during provisioning.'}, 'GoogleAuthenticationSettings': {'type': 'object', 'properties': {'googleAuthenticationRequired': {'enum': ['GOOGLE_AUTHENTICATION_REQUIRED_UNSPECIFIED', 'NOT_REQUIRED', 'REQUIRED'], 'type': 'string', 'readOnly': True, 'description': 'Output only. Whether users need to be authenticated by Google during the enrollment process. IT admin can specify if Google authentication is enabled for the enterprise for knowledge worker devices. This value can be set only via the Google Admin Console. Google authentication can be used with `signin_url` In the case where Google authentication is required and a `signin_url` is specified, Google authentication will be launched before `signin_url`. This value is overridden by `EnrollmentToken.googleAuthenticationOptions` and `SigninDetail.googleAuthenticationOptions`, if they are set.', 'x-google-enum-descriptions': ['This value is not used.', 'Google authentication is not required.', 'User is required to be successfully authenticated by Google.']}}, 'description': 'Contains settings for Google-provided user authentication.'}, 'SigninDetailGoogleAuthenticationOptions': {'type': 'object', 'properties': {'authenticationRequirement': {'enum': ['AUTHENTICATION_REQUIREMENT_UNSPECIFIED', 'OPTIONAL', 'REQUIRED'], 'type': 'string', 'description': 'Optional. Specifies whether user should authenticate with Google during enrollment. If this is set to any value other than `AUTHENTICATION_REQUIREMENT_UNSPECIFIED`, the enterprise-level setting `googleAuthenticationSettings` is ignored for devices enrolled with this sign-in detail.', 'x-google-enum-descriptions': ['The setting `googleAuthenticationSettings` for the enterprise that this sign-in detail belongs to is used to determine whether the user needs to authenticate with Google during enrollment.', 'Google authentication is optional for the user. This means the user can choose to skip Google authentication during enrollment.', 'Google authentication is required for the user. This means the user must authenticate with a Google account to proceed.']}}, 'description': 'Options for Google authentication during the enrollment. These options control whether the Google authentication screen is shown, and whether it can be skipped, at the start of the sign-in flow. More requirements can be enforced by `EnrollmentToken.googleAuthenticationOptions` on the EnrollmentToken that is created later.'}}, 'properties': {'logo': {'$ref': '#/$defs/ExternalData', 'description': 'An image displayed as a logo during device provisioning. Supported types are: image/bmp, image/gif, image/x-ico, image/jpeg, image/png, image/webp, image/vnd.wap.wbmp, image/x-adobe-dng.'}, 'name': {'type': 'string', 'description': 'The name of the enterprise which is generated by the server during creation, in the form `enterprises/{enterpriseId}`.'}, 'contactInfo': {'$ref': '#/$defs/ContactInfo', 'description': 'The enterprise contact info of an EMM-managed enterprise.'}, 'pubsubTopic': {'type': 'string', 'description': 'The topic which Pub/Sub notifications are published to, in the form `projects/{project}/topics/{topic}`. This field is only required if [Pub/Sub notifications are enabled](/android/management/notifications).'}, 'primaryColor': {'type': 'integer', 'format': 'int32', 'description': 'A color in RGB format that indicates the predominant color to display in the device management app UI. The color components are stored as follows: `(red << 16) | (green << 8) | blue`, where the value of each component is between 0 and 255, inclusive.'}, 'signinDetails': {'type': 'array', 'items': {'$ref': '#/$defs/SigninDetail'}, 'description': 'Sign-in details of the enterprise.'}, 'enterpriseType': {'enum': ['ENTERPRISE_TYPE_UNSPECIFIED', 'MANAGED_GOOGLE_DOMAIN', 'MANAGED_GOOGLE_PLAY_ACCOUNTS_ENTERPRISE'], 'type': 'string', 'readOnly': True, 'description': 'Output only. The type of the enterprise.', 'x-google-enum-descriptions': ['This value is not used.', 'The enterprise belongs to a [managed Google domain](https://developers.google.com/android/work/terminology#managed_google_domain).', 'The enterprise is a [managed Google Play Accounts enterprise](https://developers.google.com/android/work/terminology#managed_google_play_accounts_enterprise).']}, 'termsAndConditions': {'type': 'array', 'items': {'$ref': '#/$defs/TermsAndConditions'}, 'description': 'Terms and conditions that must be accepted when provisioning a device for this enterprise. A page of terms is generated for each value in this list.'}, 'enterpriseDisplayName': {'type': 'string', 'description': 'The name of the enterprise displayed to users. This field has a maximum length of 100 characters.'}, 'appAutoApprovalEnabled': {'type': 'boolean', 'deprecated': True, 'description': 'Deprecated and unused.'}, 'managedGoogleDomainType': {'enum': ['MANAGED_GOOGLE_DOMAIN_TYPE_UNSPECIFIED', 'TYPE_TEAM', 'TYPE_DOMAIN'], 'type': 'string', 'readOnly': True, 'description': 'Output only. The type of managed Google domain.', 'x-google-enum-descriptions': ['The managed Google domain type is not specified.', 'The managed Google domain is an email-verified team.', 'The managed Google domain is domain-verified.']}, 'enabledNotificationTypes': {'type': 'array', 'items': {'enum': ['NOTIFICATION_TYPE_UNSPECIFIED', 'ENROLLMENT', 'COMPLIANCE_REPORT', 'STATUS_REPORT', 'COMMAND', 'USAGE_LOGS', 'ENTERPRISE_UPGRADE'], 'type': 'string', 'x-google-enum-deprecated': [False, False, True, False, False, False, False], 'x-google-enum-descriptions': ['This value is ignored.', 'A notification sent when a device enrolls.', 'Deprecated.', 'A notification sent when a device issues a status report.', 'A notification sent when a device command has completed.', 'A notification sent when device sends `BatchUsageLogEvents`.', 'A notification sent for an enterprise upgrade. An enterprise upgrade is a process that upgrades a managed Google Play Accounts enterprise to a managed Google domain.']}, 'description': 'The types of Google Pub/Sub notifications enabled for the enterprise.'}, 'googleAuthenticationSettings': {'$ref': '#/$defs/GoogleAuthenticationSettings', 'description': 'Settings for Google-provided user authentication.'}, 'managedGooglePlayAccountsEnterpriseType': {'enum': ['MANAGED_GOOGLE_PLAY_ACCOUNTS_ENTERPRISE_TYPE_UNSPECIFIED', 'CUSTOMER_MANAGED', 'EMM_MANAGED'], 'type': 'string', 'readOnly': True, 'description': 'Output only. The type of a managed Google Play Accounts enterprise.', 'x-google-enum-descriptions': ['The managed Google Play Accounts enterprise type is not specified.', 'The enterprise is customer-managed', 'The enterprise is EMM-managed (deprecated).']}}, 'description': 'The configuration applied to an enterprise.'}
输入模式
{'type': 'object', 'properties': {'name': {'type': 'string', 'description': 'The name of the policy in the form `enterprises/{enterpriseId}/policies/{policyId}`.'}}, 'description': 'Request to get a policy.'}
输出模式
{'type': 'object', '$defs': {'Date': {'type': 'object', 'properties': {'day': {'type': 'integer', 'format': 'int32', 'description': "Day of a month. Must be from 1 to 31 and valid for the year and month, or 0 to specify a year by itself or a year and month where the day isn't significant."}, 'year': {'type': 'integer', 'format': 'int32', 'description': 'Year of the date. Must be from 1 to 9999, or 0 to specify a date without a year.'}, 'month': {'type': 'integer', 'format': 'int32', 'description': 'Month of a year. Must be from 1 to 12, or 0 to specify a year without a month and day.'}}, 'description': 'Represents a whole or partial calendar date, such as a birthday. The time of day and time zone are either specified elsewhere or are insignificant. The date is relative to the Gregorian Calendar. This can represent one of the following: * A full date, with non-zero year, month, and day values. * A month and day, with a zero year (for example, an anniversary). * A year on its own, with a zero month and a zero day. * A year and month, with a zero day (for example, a credit card expiration date). Related types: * google.type.TimeOfDay * google.type.DateTime * google.protobuf.Timestamp'}, 'Role': {'type': 'object', 'properties': {'roleType': {'enum': ['ROLE_TYPE_UNSPECIFIED', 'COMPANION_APP', 'KIOSK', 'MOBILE_THREAT_DEFENSE_ENDPOINT_DETECTION_RESPONSE', 'SYSTEM_HEALTH_MONITORING'], 'type': 'string', 'description': 'Required. The type of the role an app can have.', 'x-google-enum-descriptions': ['The role type is unspecified. This value must not be used.', 'The role type for companion apps. This role enables the app as a companion app with the capability of interacting with Android Device Policy offline. This is the recommended way to configure an app as a companion app. For legacy way, see `extensionConfig`. On Android 14 and above, the app with this role is exempted from power and background execution restrictions, suspension and hibernation. On Android 11 and above, the user control is disallowed for the app with this role. `userControlSettings` cannot be set to `USER_CONTROL_ALLOWED` for the app with this role. Android Device Policy notifies the companion app of any local command status updates if the app has a service with ``. See [Integrate with the AMAPI SDK](https://developers.google.com/android/management/sdk-integration) guide for more details on the requirements for the service.', 'The role type for kiosk apps. An app can have this role only if it has `installType` set to `REQUIRED_FOR_SETUP` or `CUSTOM`. Before adding this role to an app with `CUSTOM` install type, the app must already be installed on the device. The app having this role type is set as the preferred home intent and allowlisted for lock task mode. When there is an app with this role type, status bar will be automatically disabled. This is preferable to setting `installType` to `KIOSK`. On Android 11 and above, when an app has this role, the user control is disallowed for all apps. The IT admin can set `userControlSettings` to `USER_CONTROL_ALLOWED` to allow user control for specific apps.', 'The role type for Mobile Threat Defense (MTD) / Endpoint Detection & Response (EDR) apps. On Android 14 and above, the app with this role is exempted from power and background execution restrictions, suspension and hibernation. On Android 11 and above, the user control is disallowed and `userControlSettings` cannot be set to `USER_CONTROL_ALLOWED` for the app with this role.', 'The role type for system health monitoring apps. On Android 14 and above, the app with this role is exempted from power and background execution restrictions, suspension and hibernation. On Android 11 and above, the user control is disallowed and `userControlSettings` cannot be set to `USER_CONTROL_ALLOWED` for the app with this role.']}}, 'description': 'Role an app can have.'}, 'UsageLog': {'type': 'object', 'properties': {'enabledLogTypes': {'type': 'array', 'items': {'enum': ['LOG_TYPE_UNSPECIFIED', 'SECURITY_LOGS', 'NETWORK_ACTIVITY_LOGS'], 'type': 'string', 'x-google-enum-descriptions': ['This value is not used.', 'Enable logging of on-device security events, such as when the device password is incorrectly entered or removable storage is mounted. See `UsageLogEvent` for a complete description of the logged security events. Supported for fully managed devices on Android 7 and above. Supported for company-owned devices with a work profile on Android 12 and above, on which only security events from the work profile are logged. Can be overridden by the application delegated scope `SECURITY_LOGS`', 'Enable logging of on-device network events, such as DNS lookups and TCP connections. See `UsageLogEvent` for a complete description of the logged network events. Supported for fully managed devices on Android 8 and above. Supported for company-owned devices with a work profile on Android 12 and above, on which only network events from the work profile are logged. Can be overridden by the application delegated scope `NETWORK_ACTIVITY_LOGS`']}, 'description': 'Specifies which log types are enabled. Note that users will receive on-device messaging when usage logging is enabled.'}, 'uploadOnCellularAllowed': {'type': 'array', 'items': {'enum': ['LOG_TYPE_UNSPECIFIED', 'SECURITY_LOGS', 'NETWORK_ACTIVITY_LOGS'], 'type': 'string', 'x-google-enum-descriptions': ['This value is not used.', 'Enable logging of on-device security events, such as when the device password is incorrectly entered or removable storage is mounted. See `UsageLogEvent` for a complete description of the logged security events. Supported for fully managed devices on Android 7 and above. Supported for company-owned devices with a work profile on Android 12 and above, on which only security events from the work profile are logged. Can be overridden by the application delegated scope `SECURITY_LOGS`', 'Enable logging of on-device network events, such as DNS lookups and TCP connections. See `UsageLogEvent` for a complete description of the logged network events. Supported for fully managed devices on Android 8 and above. Supported for company-owned devices with a work profile on Android 12 and above, on which only network events from the work profile are logged. Can be overridden by the application delegated scope `NETWORK_ACTIVITY_LOGS`']}, 'description': 'Specifies which of the enabled log types can be uploaded over mobile data. By default logs are queued for upload when the device connects to WiFi.'}}, 'description': 'Controls types of device activity logs collected from the device and reported via [Pub/Sub notification](https://developers.google.com/android/management/notifications).'}, 'WifiSsid': {'type': 'object', 'properties': {'wifiSsid': {'type': 'string', 'description': 'Required. Wi-Fi SSID represented as a string.'}}, 'description': 'Represents a Wi-Fi SSID.'}, 'ApnPolicy': {'type': 'object', 'properties': {'apnSettings': {'type': 'array', 'items': {'$ref': '#/$defs/ApnSetting'}, 'description': "Optional. APN settings for override APNs. There must not be any conflict between any of APN settings provided, otherwise the policy will be rejected. Two `ApnSetting`s are considered to conflict when all of the following fields match on both: `numericOperatorId`, `apn`, `proxyAddress`, `proxyPort`, `mmsProxyAddress`, `mmsProxyPort`, `mmsc`, `mvnoType`, `protocol`, `roamingProtocol`. If some of the APN settings result in non-compliance of `INVALID_VALUE` , they will be ignored. This can be set on fully managed devices on Android 10 and above. This can also be set on work profiles on Android 13 and above and only with `ApnSetting`'s with `ENTERPRISE` APN type. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 10. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles on Android versions less than 13."}, 'overrideApns': {'enum': ['OVERRIDE_APNS_UNSPECIFIED', 'OVERRIDE_APNS_DISABLED', 'OVERRIDE_APNS_ENABLED'], 'type': 'string', 'description': 'Optional. Whether override APNs are disabled or enabled. See [`DevicePolicyManager.setOverrideApnsEnabled`](https://developer.android.com/reference/android/app/admin/DevicePolicyManager#setOverrideApnsEnabled) for more details.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `OVERRIDE_APNS_DISABLED`.', 'Override APNs disabled. Any configured `apnSettings` are saved on the device, but are disabled and have no effect. Any other APNs on the device remain in use.', 'Override APNs enabled. Only override APNs are in use, any other APNs are ignored. This can only be set on fully managed devices on Android 10 and above. For work profiles override APNs are enabled via `preferentialNetworkServiceSettings` and this value cannot be set. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 10. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.']}}, 'description': 'Access Point Name (APN) policy. Configuration for Access Point Names (APNs) which may override any other APNs on the device. See `OVERRIDE_APNS_ENABLED` and `overrideApns` for details.'}, 'ProxyInfo': {'type': 'object', 'properties': {'host': {'type': 'string', 'description': 'The host of the direct proxy.'}, 'port': {'type': 'integer', 'format': 'int32', 'description': 'The port of the direct proxy.'}, 'pacUri': {'type': 'string', 'description': 'The URI of the PAC script used to configure the proxy.'}, 'excludedHosts': {'type': 'array', 'items': {'type': 'string'}, 'description': 'For a direct proxy, the hosts for which the proxy is bypassed. The host names may contain wildcards such as *.example.com.'}}, 'description': 'Configuration info for an HTTP proxy. For a direct proxy, set the `host`, `port`, and `excluded_hosts` fields. For a PAC script proxy, set the `pac_uri` field.'}, 'ApnSetting': {'type': 'object', 'properties': {'apn': {'type': 'string', 'description': 'Required. Name of the APN. Policy will be rejected if this field is empty.'}, 'mmsc': {'type': 'string', 'description': 'Optional. MMSC (Multimedia Messaging Service Center) URI of the APN.'}, 'mtuV4': {'type': 'integer', 'format': 'int32', 'description': 'Optional. The default MTU (Maximum Transmission Unit) size in bytes of the IPv4 routes brought up by this APN setting. A value of 0 (default) means not set and negative values are rejected. Supported on Android 13 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 13.'}, 'mtuV6': {'type': 'integer', 'format': 'int32', 'description': 'Optional. The MTU (Maximum Transmission Unit) size of the IPv6 mobile interface to which the APN connected. A value of 0 (default) means not set and negative values are rejected. Supported on Android 13 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 13.'}, 'apnTypes': {'type': 'array', 'items': {'enum': ['APN_TYPE_UNSPECIFIED', 'ENTERPRISE', 'BIP', 'CBS', 'DEFAULT', 'DUN', 'EMERGENCY', 'FOTA', 'HIPRI', 'IA', 'IMS', 'MCX', 'MMS', 'RCS', 'SUPL', 'VSIM', 'XCAP'], 'type': 'string', 'x-google-enum-descriptions': ['Unspecified. This value is not used.', 'APN type for enterprise traffic. Supported on Android 13 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 13.', 'APN type for BIP (Bearer Independent Protocol). This can only be set on fully managed devices on Android 12 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 12. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.', 'APN type for CBS (Carrier Branded Services). This can only be set on fully managed devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.', 'APN type for default data traffic. This can only be set on fully managed devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.', 'APN type for DUN (Dial-up networking) traffic. This can only be set on fully managed devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.', 'APN type for Emergency PDN. This is not an IA apn, but is used for access to carrier services in an emergency call situation. This can only be set on fully managed devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.', "APN type for accessing the carrier's FOTA (Firmware Over-the-Air) portal, used for over the air updates. This can only be set on fully managed devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.", 'APN type for HiPri (high-priority) traffic. This can only be set on fully managed devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.', 'APN type for IA (Initial Attach) APN. This can only be set on fully managed devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.', 'APN type for IMS (IP Multimedia Subsystem) traffic. This can only be set on fully managed devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.', 'APN type for MCX (Mission Critical Service) where X can be PTT/Video/Data. This can only be set on fully managed devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.', 'APN type for MMS (Multimedia Messaging Service) traffic. This can only be set on fully managed devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.', 'APN type for RCS (Rich Communication Services). This can only be set on fully managed devices on Android 15 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 15. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.', 'APN type for SUPL (Secure User Plane Location) assisted GPS. This can only be set on fully managed devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.', 'APN type for VSIM (Virtual SIM) service. This can only be set on fully managed devices on Android 12 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 12. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.', 'APN type for XCAP (XML Configuration Access Protocol) traffic. This can only be set on fully managed devices on Android 11 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 11. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.']}, 'description': 'Required. Usage categories for the APN. Policy will be rejected if this field is empty or contains `APN_TYPE_UNSPECIFIED` or duplicates. Multiple APN types can be set on fully managed devices. `ENTERPRISE` is the only allowed APN type on work profiles. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for any other value on work profiles. APN types that are not supported on the device or management mode will be ignored. If this results in the empty list, the APN setting will be ignored, because `apnTypes` is a required field. A `NonComplianceDetail` with `INVALID_VALUE` is reported if none of the APN types are supported on the device or management mode.'}, 'authType': {'enum': ['AUTH_TYPE_UNSPECIFIED', 'NONE', 'PAP', 'CHAP', 'PAP_OR_CHAP'], 'type': 'string', 'description': 'Optional. Authentication type of the APN.', 'x-google-enum-descriptions': ['Unspecified. If `username` is empty, defaults to `NONE`. Otherwise, defaults to `PAP_OR_CHAP`.', 'Authentication is not required.', 'Authentication type for PAP.', 'Authentication type for CHAP.', 'Authentication type for PAP or CHAP.']}, 'mvnoType': {'enum': ['MVNO_TYPE_UNSPECIFIED', 'GID', 'ICCID', 'IMSI', 'SPN'], 'type': 'string', 'description': 'Optional. MVNO match type for the APN.', 'x-google-enum-descriptions': ['The MVNO type is not specified.', 'MVNO type for group identifier level 1.', 'MVNO type for ICCID.', 'MVNO type for IMSI.', 'MVNO type for SPN (service provider name).']}, 'password': {'type': 'string', 'description': 'Optional. APN password of the APN.'}, 'protocol': {'enum': ['PROTOCOL_UNSPECIFIED', 'IP', 'IPV4V6', 'IPV6', 'NON_IP', 'PPP', 'UNSTRUCTURED'], 'type': 'string', 'description': 'Optional. The protocol to use to connect to this APN.', 'x-google-enum-descriptions': ['The protocol is not specified.', 'Internet protocol.', 'Virtual PDP type introduced to handle dual IP stack UE capability.', 'Internet protocol, version 6.', 'Transfer of Non-IP data to external packet data network.', 'Point to point protocol.', 'Transfer of Unstructured data to the Data Network via N6.']}, 'username': {'type': 'string', 'description': 'Optional. APN username of the APN.'}, 'carrierId': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Carrier ID for the APN. A value of 0 (default) means not set and negative values are rejected.'}, 'proxyPort': {'type': 'integer', 'format': 'int32', 'description': 'Optional. The proxy port of the APN. A value of 0 (default) means not set and negative values are rejected.'}, 'displayName': {'type': 'string', 'description': 'Required. Human-readable name that describes the APN. Policy will be rejected if this field is empty.'}, 'mmsProxyPort': {'type': 'integer', 'format': 'int32', 'description': 'Optional. MMS (Multimedia Messaging Service) proxy port of the APN. A value of 0 (default) means not set and negative values are rejected.'}, 'networkTypes': {'type': 'array', 'items': {'enum': ['NETWORK_TYPE_UNSPECIFIED', 'EDGE', 'GPRS', 'GSM', 'HSDPA', 'HSPA', 'HSPAP', 'HSUPA', 'IWLAN', 'LTE', 'NR', 'TD_SCDMA', 'UMTS'], 'type': 'string', 'x-google-enum-descriptions': ['Unspecified. This value must not be used.', 'Radio technology EDGE.', 'Radio technology GPRS.', 'Radio technology GSM.', 'Radio technology HSDPA.', 'Radio technology HSPA.', 'Radio technology HSPAP.', 'Radio technology HSUPA.', 'Radio technology IWLAN.', 'Radio technology LTE.', 'Radio technology NR (New Radio) 5G.', 'Radio technology TD_SCDMA.', 'Radio technology UMTS.']}, 'description': 'Optional. Radio technologies (network types) the APN may use. Policy will be rejected if this field contains `NETWORK_TYPE_UNSPECIFIED` or duplicates.'}, 'proxyAddress': {'type': 'string', 'description': 'Optional. The proxy address of the APN.'}, 'alwaysOnSetting': {'enum': ['ALWAYS_ON_SETTING_UNSPECIFIED', 'NOT_ALWAYS_ON', 'ALWAYS_ON'], 'type': 'string', 'description': 'Optional. Whether User Plane resources have to be activated during every transition from CM-IDLE mode to CM-CONNECTED state for this APN. See 3GPP TS 23.501 section 5.6.13.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `NOT_ALWAYS_ON`.', 'The PDU session brought up by this APN should not be always on.', 'The PDU session brought up by this APN should always be on. Supported on Android 15 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 15.']}, 'mmsProxyAddress': {'type': 'string', 'description': 'Optional. MMS (Multimedia Messaging Service) proxy address of the APN which can be an IP address or hostname (not a URL).'}, 'roamingProtocol': {'enum': ['PROTOCOL_UNSPECIFIED', 'IP', 'IPV4V6', 'IPV6', 'NON_IP', 'PPP', 'UNSTRUCTURED'], 'type': 'string', 'description': 'Optional. The protocol to use to connect to this APN while the device is roaming.', 'x-google-enum-descriptions': ['The protocol is not specified.', 'Internet protocol.', 'Virtual PDP type introduced to handle dual IP stack UE capability.', 'Internet protocol, version 6.', 'Transfer of Non-IP data to external packet data network.', 'Point to point protocol.', 'Transfer of Unstructured data to the Data Network via N6.']}, 'numericOperatorId': {'type': 'string', 'description': 'Optional. The numeric operator ID of the APN. Numeric operator ID is defined as MCC (Mobile Country Code) + MNC (Mobile Network Code).'}}, 'description': 'An Access Point Name (APN) configuration for a carrier data connection. The APN provides configuration to connect a cellular network device to an IP data network. A carrier uses this setting to decide which IP address to assign, any security methods to apply, and how the device might be connected to private networks.'}, 'WipeAction': {'type': 'object', 'properties': {'preserveFrp': {'type': 'boolean', 'description': 'Whether the factory-reset protection data is preserved on the device. This setting applies to fully managed devices and work profiles on company-owned devices.'}, 'wipeAfterDays': {'type': 'integer', 'format': 'int32', 'description': 'Number of days the policy is non-compliant before the device or work profile is wiped. `wipeAfterDays` must be greater than `blockAfterDays`.'}}, 'description': 'An action to reset a company owned device or delete a work profile. Note: `blockAction` must also be specified.'}, 'BlockAction': {'type': 'object', 'properties': {'blockScope': {'enum': ['BLOCK_SCOPE_UNSPECIFIED', 'BLOCK_SCOPE_WORK_PROFILE', 'BLOCK_SCOPE_DEVICE'], 'type': 'string', 'description': 'Specifies the scope of this `BlockAction`. Only applicable to devices that are company-owned.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `BLOCK_SCOPE_WORK_PROFILE`.', 'Block action is only applied to apps in the work profile. Apps in the personal profile are unaffected.', 'Block action is applied to the entire device, including apps in the personal profile.']}, 'blockAfterDays': {'type': 'integer', 'format': 'int32', 'description': 'Number of days the policy is non-compliant before the device or work profile is blocked. To block access immediately, set to 0. `blockAfterDays` must be less than `wipeAfterDays`.'}}, 'description': 'An action to block access to apps and data on a fully managed device or in a work profile. This action also triggers a device or work profile to displays a user-facing notification with information (where possible) on how to correct the compliance issue. Note: `wipeAction` must also be specified.'}, 'SetupAction': {'type': 'object', 'properties': {'title': {'$ref': '#/$defs/UserFacingMessage', 'description': 'Title of this action.'}, 'launchApp': {'$ref': '#/$defs/LaunchAppAction', 'description': 'An action to launch an app. The app will be launched with an intent containing an extra with key `com.google.android.apps.work.clouddpc.EXTRA_LAUNCHED_AS_SETUP_ACTION` set to the boolean value `true` to indicate that this is a setup action flow. If `SetupAction` references an app, the corresponding `installType` in the application policy must be set as `REQUIRED_FOR_SETUP` or said setup will fail.'}, 'description': {'$ref': '#/$defs/UserFacingMessage', 'description': 'Description of this action.'}}, 'description': 'An action executed during setup.'}, 'FreezePeriod': {'type': 'object', 'properties': {'endDate': {'$ref': '#/$defs/Date', 'description': 'The end date (inclusive) of the freeze period. Must be no later than 90 days from the start date. If the end date is earlier than the start date, the freeze period is considered wrapping year-end. Note: `day` and `month` must be set. `year` should not be set as it is not used. For example, `{"month": 1,"date": 30}`.'}, 'startDate': {'$ref': '#/$defs/Date', 'description': 'The start date (inclusive) of the freeze period. Note: `day` and `month` must be set. `year` should not be set as it is not used. For example, `{"month": 1,"date": 30}`.'}}, 'description': 'A system freeze period. When a device’s clock is within the freeze period, all incoming system updates (including security patches) are blocked and won’t be installed. When the device is outside any set freeze periods, the normal policy behavior (automatic, windowed, or postponed) applies. Leap years are ignored in freeze period calculations, in particular: * If Feb. 29th is set as the start or end date of a freeze period, the freeze period will start or end on Feb. 28th instead. * When a device’s system clock reads Feb. 29th, it’s treated as Feb. 28th. * When calculating the number of days in a freeze period or the time between two freeze periods, Feb. 29th is ignored and not counted as a day. Note: For Freeze Periods to take effect, `SystemUpdateType` cannot be specified as `SYSTEM_UPDATE_TYPE_UNSPECIFIED`, because freeze periods require a defined policy to be specified.'}, 'SystemUpdate': {'type': 'object', 'properties': {'type': {'enum': ['SYSTEM_UPDATE_TYPE_UNSPECIFIED', 'AUTOMATIC', 'WINDOWED', 'POSTPONE'], 'type': 'string', 'description': 'The type of system update to configure.', 'x-google-enum-descriptions': ['Follow the default update behavior for the device, which typically requires the user to accept system updates.', 'Install automatically as soon as an update is available.', 'Install automatically within a daily maintenance window. This also configures Play apps to be updated within the window. This is strongly recommended for kiosk devices because this is the only way apps persistently pinned to the foreground can be updated by Play. If `autoUpdateMode` is set to `AUTO_UPDATE_HIGH_PRIORITY` for an app, then the maintenance window is ignored for that app and it is updated as soon as possible even outside of the maintenance window.', 'Postpone automatic install up to a maximum of 30 days. This policy does not affect security updates (e.g. monthly security patches).']}, 'endMinutes': {'type': 'integer', 'format': 'int32', 'description': "If the type is `WINDOWED`, the end of the maintenance window, measured as the number of minutes after midnight in device's local time. This value must be between 0 and 1439, inclusive. If this value is less than `start_minutes`, then the maintenance window spans midnight. If the maintenance window specified is smaller than 30 minutes, the actual window is extended to 30 minutes beyond the start time."}, 'startMinutes': {'type': 'integer', 'format': 'int32', 'description': "If the type is `WINDOWED`, the start of the maintenance window, measured as the number of minutes after midnight in the device's local time. This value must be between 0 and 1439, inclusive."}, 'freezePeriods': {'type': 'array', 'items': {'$ref': '#/$defs/FreezePeriod'}, 'description': 'An annually repeating time period in which over-the-air (OTA) system updates are postponed to freeze the OS version running on a device. To prevent freezing the device indefinitely, each freeze period must be separated by at least 60 days.'}}, 'description': 'Configuration for managing system updates **Note:** [Google Play system updates](https://source.android.com/docs/core/ota/modular-system) (also called Mainline updates) are automatically downloaded but require a device reboot to be installed. Refer to the mainline section in [Manage system updates](https://developer.android.com/work/dpc/system-updates#mainline) for further details.'}, 'ComplianceRule': {'type': 'object', 'properties': {'disableApps': {'type': 'boolean', 'description': 'If set to true, the rule includes a mitigating action to disable apps so that the device is effectively disabled, but app data is preserved. If the device is running an app in locked task mode, the app will be closed and a UI showing the reason for non-compliance will be displayed.'}, 'apiLevelCondition': {'$ref': '#/$defs/ApiLevelCondition', 'description': "A condition which is satisfied if the Android Framework API level on the device doesn't meet a minimum requirement."}, 'packageNamesToDisable': {'type': 'array', 'items': {'type': 'string'}, 'description': 'If set, the rule includes a mitigating action to disable apps specified in the list, but app data is preserved.'}, 'nonComplianceDetailCondition': {'$ref': '#/$defs/NonComplianceDetailCondition', 'description': 'A condition which is satisfied if there exists *any* matching [`NonComplianceDetail`](/android/management/reference/rest/v1/enterprises.devices#NonComplianceDetail) for the device.'}}, 'description': 'A rule declaring which mitigating actions to take when a device is not compliant with its policy. For every rule, there is always an implicit mitigating action to set `policy_compliant` to false for the [`Device`](/android/management/reference/rest/v1/enterprises.devices#Device) resource, and display a message on the device indicating that the device is not compliant with its policy. Other mitigating actions may optionally be taken as well, depending on the field values in the rule.'}, 'WifiSsidPolicy': {'type': 'object', 'properties': {'wifiSsids': {'type': 'array', 'items': {'$ref': '#/$defs/WifiSsid'}, 'description': 'Optional. List of Wi-Fi SSIDs that should be applied in the policy. This field must be non-empty when WifiSsidPolicyType is set to `WIFI_SSID_ALLOWLIST`. If this is set to a non-empty list, then a `NonComplianceDetail` detail with `API_LEVEL` is reported if the Android version is less than 13 and a `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for non-company-owned devices.'}, 'wifiSsidPolicyType': {'enum': ['WIFI_SSID_POLICY_TYPE_UNSPECIFIED', 'WIFI_SSID_DENYLIST', 'WIFI_SSID_ALLOWLIST'], 'type': 'string', 'description': 'Type of the Wi-Fi SSID policy to be applied.', 'x-google-enum-descriptions': ['Defaults to `WIFI_SSID_DENYLIST`. `wifiSsids` must not be set. There are no restrictions on which SSID the device can connect to.', 'The device cannot connect to any Wi-Fi network whose SSID is in `wifiSsids`, but can connect to other networks.', 'The device can make Wi-Fi connections only to the SSIDs in `wifiSsids`. `wifiSsids` must not be empty. The device will not be able to connect to any other Wi-Fi network.']}}, 'description': 'Restrictions on which Wi-Fi SSIDs the device can connect to. Note that this does not affect which networks can be configured on the device. Supported on company-owned devices running Android 13 and above.'}, 'CustomAppConfig': {'type': 'object', 'properties': {'userUninstallSettings': {'enum': ['USER_UNINSTALL_SETTINGS_UNSPECIFIED', 'DISALLOW_UNINSTALL_BY_USER', 'ALLOW_UNINSTALL_BY_USER'], 'type': 'string', 'description': 'Optional. User uninstall settings of the custom app.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `DISALLOW_UNINSTALL_BY_USER`.', 'User is not allowed to uninstall the custom app.', 'User is allowed to uninstall the custom app.']}}, 'description': 'Configuration for a custom app.'}, 'DisplaySettings': {'type': 'object', 'properties': {'screenTimeoutSettings': {'$ref': '#/$defs/ScreenTimeoutSettings', 'description': 'Optional. Controls the screen timeout settings.'}, 'screenBrightnessSettings': {'$ref': '#/$defs/ScreenBrightnessSettings', 'description': 'Optional. Controls the screen brightness settings.'}}, 'description': 'Controls for the display settings.'}, 'ExtensionConfig': {'type': 'object', 'properties': {'notificationReceiver': {'type': 'string', 'deprecated': True, 'description': "Fully qualified class name of the receiver service class for Android Device Policy to notify the extension app of any local command status updates. The service must be exported in the extension app's `AndroidManifest.xml` and extend [`NotificationReceiverService`](https://developers.google.com/android/management/reference/amapi/com/google/android/managementapi/notification/NotificationReceiverService) (see [Integrate with the AMAPI SDK](https://developers.google.com/android/management/sdk-integration) guide for more details)."}, 'signingKeyFingerprintsSha256': {'type': 'array', 'items': {'type': 'string'}, 'deprecated': True, 'description': 'Hex-encoded SHA-256 hashes of the signing key certificates of the extension app. Only hexadecimal string representations of 64 characters are valid. The signing key certificate fingerprints are always obtained from the Play Store and this field is used to provide additional signing key certificate fingerprints. However, if the application is not available on the Play Store, this field needs to be set. A `NonComplianceDetail` with `INVALID_VALUE` is reported if this field is not set when the application is not available on the Play Store. The signing key certificate fingerprint of the extension app on the device must match one of the signing key certificate fingerprints obtained from the Play Store or the ones provided in this field for the app to be able to communicate with Android Device Policy. In production use cases, it is recommended to leave this empty.'}}, 'description': 'Configuration to enable an app as an extension app, with the capability of interacting with Android Device Policy offline. For Android versions 11 and above, extension apps are exempt from battery restrictions so will not be placed into the [restricted App Standby Bucket](https://developer.android.com/topic/performance/appstandby#restricted-bucket). Extensions apps are also protected against users clearing their data or force-closing the application, although admins can continue to use the clear app data command on extension apps if needed for Android 11 and above.'}, 'LaunchAppAction': {'type': 'object', 'properties': {'packageName': {'type': 'string', 'description': 'Package name of app to be launched'}}, 'description': 'An action to launch an app.'}, 'PackageNameList': {'type': 'object', 'properties': {'packageNames': {'type': 'array', 'items': {'type': 'string'}, 'description': 'A list of package names.'}}, 'description': 'A list of package names.'}, 'PermissionGrant': {'type': 'object', 'properties': {'policy': {'enum': ['PERMISSION_POLICY_UNSPECIFIED', 'PROMPT', 'GRANT', 'DENY'], 'type': 'string', 'description': 'The policy for granting the permission.', 'x-google-enum-descriptions': ['Policy not specified. If no policy is specified for a permission at any level, then the `PROMPT` behavior is used by default.', 'Prompt the user to grant a permission.', 'Automatically grant a permission. On Android 12 and above, [`READ_SMS`](https://developer.android.com/reference/android/Manifest.permission#READ_SMS) and following sensor-related permissions can only be granted on fully managed devices: * [`ACCESS_FINE_LOCATION`](https://developer.android.com/reference/android/Manifest.permission#ACCESS_FINE_LOCATION) * [`ACCESS_BACKGROUND_LOCATION`](https://developer.android.com/reference/android/Manifest.permission#ACCESS_BACKGROUND_LOCATION) * [`ACCESS_COARSE_LOCATION`](https://developer.android.com/reference/android/Manifest.permission#ACCESS_COARSE_LOCATION) * [`CAMERA`](https://developer.android.com/reference/android/Manifest.permission#CAMERA) * [`RECORD_AUDIO`](https://developer.android.com/reference/android/Manifest.permission#RECORD_AUDIO) * [`ACTIVITY_RECOGNITION`](https://developer.android.com/reference/android/Manifest.permission#ACTIVITY_RECOGNITION) * [`BODY_SENSORS`](https://developer.android.com/reference/android/Manifest.permission#BODY_SENSORS)', 'Automatically deny a permission.']}, 'permission': {'type': 'string', 'description': 'The Android permission or group, e.g. `android.permission.READ_CALENDAR` or `android.permission_group.CALENDAR`.'}}, 'description': 'Configuration for an Android permission and its grant state.'}, 'DeviceRadioState': {'type': 'object', 'properties': {'wifiState': {'enum': ['WIFI_STATE_UNSPECIFIED', 'WIFI_STATE_USER_CHOICE', 'WIFI_ENABLED', 'WIFI_DISABLED'], 'type': 'string', 'description': 'Optional. Controls current state of Wi-Fi and if user can change its state.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `WIFI_STATE_USER_CHOICE`', 'User is allowed to enable/disable Wi-Fi.', 'Wi-Fi is on and the user is not allowed to turn it off. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 13.', 'Wi-Fi is off and the user is not allowed to turn it on. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 13.']}, 'airplaneModeState': {'enum': ['AIRPLANE_MODE_STATE_UNSPECIFIED', 'AIRPLANE_MODE_USER_CHOICE', 'AIRPLANE_MODE_DISABLED'], 'type': 'string', 'description': 'Optional. Controls whether airplane mode can be toggled by the user or not.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `AIRPLANE_MODE_USER_CHOICE`.', 'The user is allowed to toggle airplane mode on or off.', 'Airplane mode is disabled. The user is not allowed to toggle airplane mode on. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 9.']}, 'cellularTwoGState': {'enum': ['CELLULAR_TWO_G_STATE_UNSPECIFIED', 'CELLULAR_TWO_G_USER_CHOICE', 'CELLULAR_TWO_G_DISABLED'], 'type': 'string', 'description': 'Optional. Controls whether cellular 2G setting can be toggled by the user or not.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `CELLULAR_TWO_G_USER_CHOICE`.', 'The user is allowed to toggle cellular 2G on or off.', 'Cellular 2G is disabled. The user is not allowed to toggle cellular 2G on via settings. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 14.']}, 'ultraWidebandState': {'enum': ['ULTRA_WIDEBAND_STATE_UNSPECIFIED', 'ULTRA_WIDEBAND_USER_CHOICE', 'ULTRA_WIDEBAND_DISABLED'], 'type': 'string', 'description': 'Optional. Controls the state of the ultra wideband setting and whether the user can toggle it on or off.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `ULTRA_WIDEBAND_USER_CHOICE`.', 'The user is allowed to toggle ultra wideband on or off.', 'Ultra wideband is disabled. The user is not allowed to toggle ultra wideband on via settings. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 14.']}, 'minimumWifiSecurityLevel': {'enum': ['MINIMUM_WIFI_SECURITY_LEVEL_UNSPECIFIED', 'OPEN_NETWORK_SECURITY', 'PERSONAL_NETWORK_SECURITY', 'ENTERPRISE_NETWORK_SECURITY', 'ENTERPRISE_BIT192_NETWORK_SECURITY'], 'type': 'string', 'description': 'Optional. The minimum required security level of Wi-Fi networks that the device can connect to.', 'x-google-enum-descriptions': ['Defaults to `OPEN_NETWORK_SECURITY`, which means the device will be able to connect to all types of Wi-Fi networks.', 'The device will be able to connect to all types of Wi-Fi networks.', 'A personal network such as WEP, WPA2-PSK is the minimum required security. The device will not be able to connect to open wifi networks. This is stricter than `OPEN_NETWORK_SECURITY`. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 13.', 'An enterprise EAP network is the minimum required security level. The device will not be able to connect to Wi-Fi network below this security level. This is stricter than `PERSONAL_NETWORK_SECURITY`. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 13.', 'A 192-bit enterprise network is the minimum required security level. The device will not be able to connect to Wi-Fi network below this security level. This is stricter than `ENTERPRISE_NETWORK_SECURITY`. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 13.']}, 'userInitiatedAddEsimSettings': {'enum': ['USER_INITIATED_ADD_ESIM_SETTINGS_UNSPECIFIED', 'USER_INITIATED_ADD_ESIM_ALLOWED', 'USER_INITIATED_ADD_ESIM_DISALLOWED'], 'type': 'string', 'description': 'Optional. Controls whether the user is allowed to add eSIM profiles.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `USER_INITIATED_ADD_ESIM_ALLOWED`.', 'The user is allowed to add eSIM profiles.', 'Supported only on company-owned devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for personally-owned devices.']}}, 'description': 'Controls for device radio settings.'}, 'ApiLevelCondition': {'type': 'object', 'properties': {'minApiLevel': {'type': 'integer', 'format': 'int32', 'description': "The minimum desired Android Framework API level. If the device doesn't meet the minimum requirement, this condition is satisfied. Must be greater than zero."}}, 'description': "A compliance rule condition which is satisfied if the Android Framework API level on the device doesn't meet a minimum requirement. There can only be one rule with this type of condition per policy."}, 'ApplicationPolicy': {'type': 'object', 'properties': {'roles': {'type': 'array', 'items': {'$ref': '#/$defs/Role'}, 'description': 'Optional. Roles the app has. Apps having certain roles can be exempted from power and background execution restrictions, suspension and hibernation on Android 14 and above. The user control can also be disallowed for apps with certain roles on Android 11 and above. Refer to the documentation of each `RoleType` for more details. The app is notified about the roles that are set for it if the app has a notification receiver service with ``. The app is notified whenever its roles are updated or after the app is installed when it has nonempty list of roles. The app can use this notification to bootstrap itself after the installation. See [Integrate with the AMAPI SDK](https://developers.google.com/android/management/sdk-integration) and [Manage app roles](https://developers.google.com/android/management/app-roles) guides for more details on the requirements for the service. For the exemptions to be applied and the app to be notified about the roles, the signing key certificate fingerprint of the app on the device must match one of the signing key certificate fingerprints obtained from Play Store or one of the entries in `ApplicationPolicy.signingKeyCerts`. Otherwise, a `NonComplianceDetail` with `APP_SIGNING_CERT_MISMATCH` is reported. There must not be duplicate roles with the same `roleType`. Multiple apps cannot hold a role with the same `roleType`. A role with type `ROLE_TYPE_UNSPECIFIED` is not allowed.'}, 'disabled': {'type': 'boolean', 'description': 'Whether the app is disabled. When disabled, the app data is still preserved.'}, 'installType': {'enum': ['INSTALL_TYPE_UNSPECIFIED', 'PREINSTALLED', 'FORCE_INSTALLED', 'BLOCKED', 'AVAILABLE', 'REQUIRED_FOR_SETUP', 'KIOSK', 'CUSTOM'], 'type': 'string', 'description': 'The type of installation to perform.', 'x-google-enum-deprecated': [False, False, False, False, False, False, True, False], 'x-google-enum-descriptions': ['Unspecified. Defaults to AVAILABLE.', 'The app is automatically installed and can be removed by the user.', "The app is automatically installed regardless of a set maintenance window and can't be removed by the user.", "The app is blocked and can't be installed. If the app was installed under a previous policy, it will be uninstalled. This also blocks its instant app functionality.", 'The app is available to install.', "The app is automatically installed and can't be removed by the user and will prevent setup from completion until installation is complete.", "The app is automatically installed in kiosk mode: it's set as the preferred home intent and whitelisted for lock task mode. Device setup won't complete until the app is installed. After installation, users won't be able to remove the app. You can only set this `installType` for one app per policy. When this is present in the policy, status bar will be automatically disabled. On Android 11 and above, when an app has this install type, the user control is disallowed for all apps. The IT admin can set `userControlSettings` to `USER_CONTROL_ALLOWED` to allow user control for specific apps. If there is any app with `KIOSK` role, then this install type cannot be set for any app.", "The app can only be installed and updated via [AMAPI SDK command](https://developers.google.com/android/management/extensibility-sdk-integration). **Note:** * This only affects fully managed devices. * Play related fields `minimumVersionCode`, `accessibleTrackIds`, `autoUpdateMode`, `installConstraint` and `installPriority` cannot be set for the app. * The app isn't available in the Play Store. * The app installed on the device has `applicationSource` set to `CUSTOM`. * When the current `installType` is `CUSTOM`, the signing key certificate fingerprint of the existing custom app on the device must match one of the entries in `ApplicationPolicy.signingKeyCerts` . Otherwise, a `NonComplianceDetail` with `APP_SIGNING_CERT_MISMATCH` is reported. * Changing the `installType` from `CUSTOM` to another value must match the playstore version of the application signing key certificate fingerprint. Otherwise a `NonComplianceDetail` with `APP_SIGNING_CERT_MISMATCH` is reported. * Changing the `installType` to `CUSTOM` uninstalls the existing app if its signing key certificate fingerprint of the installed app doesn't match the one from the `ApplicationPolicy.signingKeyCerts` . * Removing the app from `applications` doesn't uninstall the existing app if it conforms to `playStoreMode`. * See also `customAppConfig`. * This is different from the [Google Play Custom App Publishing](https://developers.google.com/android/work/play/custom-app-api/get-started) feature."]}, 'packageName': {'type': 'string', 'description': 'The package name of the app. For example, `com.google.android.youtube` for the YouTube app.'}, 'autoUpdateMode': {'enum': ['AUTO_UPDATE_MODE_UNSPECIFIED', 'AUTO_UPDATE_DEFAULT', 'AUTO_UPDATE_POSTPONED', 'AUTO_UPDATE_HIGH_PRIORITY'], 'type': 'string', 'description': 'Controls the auto-update mode for the app.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `AUTO_UPDATE_DEFAULT`.', 'The default update mode. The app is automatically updated with low priority to minimize the impact on the user. The app is updated when all of the following constraints are met: * The device is not actively used. * The device is connected to an unmetered network. * The device is charging. * The app to be updated is not running in the foreground. The device is notified about a new update within 24 hours after it is published by the developer, after which the app is updated the next time the constraints above are met.', 'The app is not automatically updated for a maximum of 90 days after the app becomes out of date. 90 days after the app becomes out of date, the latest available version is installed automatically with low priority (see `AUTO_UPDATE_DEFAULT`). After the app is updated it is not automatically updated again until 90 days after it becomes out of date again. The user can still manually update the app from the Play Store at any time.', "The app is updated as soon as possible. No constraints are applied. The device is notified as soon as possible about a new update after it becomes available. *NOTE:* Updates to apps with larger deployments across Android's ecosystem can take up to 24h."]}, 'customAppConfig': {'$ref': '#/$defs/CustomAppConfig', 'description': 'Optional. Configuration for this custom app. `install_type` must be set to `CUSTOM` for this to be set.'}, 'delegatedScopes': {'type': 'array', 'items': {'enum': ['DELEGATED_SCOPE_UNSPECIFIED', 'CERT_INSTALL', 'MANAGED_CONFIGURATIONS', 'BLOCK_UNINSTALL', 'PERMISSION_GRANT', 'PACKAGE_ACCESS', 'ENABLE_SYSTEM_APP', 'NETWORK_ACTIVITY_LOGS', 'SECURITY_LOGS', 'CERT_SELECTION'], 'type': 'string', 'x-google-enum-descriptions': ['No delegation scope specified.', 'Grants access to certificate installation and management. This scope can be delegated to multiple applications.', 'Grants access to managed configurations management. This scope can be delegated to multiple applications.', 'Grants access to blocking uninstallation. This scope can be delegated to multiple applications.', 'Grants access to permission policy and permission grant state. This scope can be delegated to multiple applications.', 'Grants access to package access state. This scope can be delegated to multiple applications.', 'Grants access for enabling system apps. This scope can be delegated to multiple applications.', 'Grants access to network activity logs. Allows the delegated application to call [`setNetworkLoggingEnabled`](https://developer.android.com/reference/android/app/admin/DevicePolicyManager#setNetworkLoggingEnabled%28android.content.ComponentName,%20boolean%29), [`isNetworkLoggingEnabled`](https://developer.android.com/reference/android/app/admin/DevicePolicyManager#isNetworkLoggingEnabled%28android.content.ComponentName%29) and [`retrieveNetworkLogs`](https://developer.android.com/reference/android/app/admin/DevicePolicyManager#retrieveNetworkLogs%28android.content.ComponentName,%20long%29) methods. This scope can be delegated to at most one application. Supported for fully managed devices on Android 10 and above. Supported for a work profile on Android 12 and above. When delegation is supported and set, `NETWORK_ACTIVITY_LOGS` is ignored.', 'Grants access to security logs. Allows the delegated application to call [`setSecurityLoggingEnabled`](https://developer.android.com/reference/android/app/admin/DevicePolicyManager#setSecurityLoggingEnabled%28android.content.ComponentName,%20boolean%29), [`isSecurityLoggingEnabled`](https://developer.android.com/reference/android/app/admin/DevicePolicyManager#isSecurityLoggingEnabled%28android.content.ComponentName%29), [`retrieveSecurityLogs`](https://developer.android.com/reference/android/app/admin/DevicePolicyManager#retrieveSecurityLogs%28android.content.ComponentName%29) and [`retrievePreRebootSecurityLogs`](https://developer.android.com/reference/android/app/admin/DevicePolicyManager#retrievePreRebootSecurityLogs%28android.content.ComponentName%29) methods. This scope can be delegated to at most one application. Supported for fully managed devices and company-owned devices with a work profile on Android 12 and above. When delegation is supported and set, `SECURITY_LOGS` is ignored.', 'Grants access to selection of KeyChain certificates on behalf of requesting apps. Once granted, the delegated application will start receiving [`DelegatedAdminReceiver#onChoosePrivateKeyAlias`](https://developer.android.com/reference/android/app/admin/DelegatedAdminReceiver#onChoosePrivateKeyAlias%28android.content.Context,%20android.content.Intent,%20int,%20android.net.Uri,%20java.lang.String%29). Allows the delegated application to call [`grantKeyPairToApp`](https://developer.android.com/reference/android/app/admin/DevicePolicyManager#grantKeyPairToApp%28android.content.ComponentName,%20java.lang.String,%20java.lang.String%29) and [`revokeKeyPairFromApp`](https://developer.android.com/reference/android/app/admin/DevicePolicyManager#revokeKeyPairFromApp%28android.content.ComponentName,%20java.lang.String,%20java.lang.String%29) methods. This scope can be delegated to at most one application. `choosePrivateKeyRules` must be empty and `privateKeySelectionEnabled` has no effect if certificate selection is delegated to an application.']}, 'description': 'The scopes delegated to the app from Android Device Policy. These provide additional privileges for the applications they are applied to.'}, 'extensionConfig': {'$ref': '#/$defs/ExtensionConfig', 'deprecated': True, 'description': 'Configuration to enable this app as an extension app, with the capability of interacting with Android Device Policy offline. This field can be set for at most one app. If there is any app with `COMPANION_APP` role, this field cannot be set. The signing key certificate fingerprint of the app on the device must match one of the entries in `ApplicationPolicy.signingKeyCerts` or `ExtensionConfig.signingKeyFingerprintsSha256` (deprecated) or the signing key certificate fingerprints obtained from Play Store for the app to be able to communicate with Android Device Policy. If the app is not on Play Store and if `ApplicationPolicy.signingKeyCerts` and `ExtensionConfig.signingKeyFingerprintsSha256` (deprecated) are not set, a `NonComplianceDetail` with `INVALID_VALUE` is reported.'}, 'installPriority': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Amongst apps with `installType` set to: * FORCE_INSTALLED * PREINSTALLED this controls the relative priority of installation. A value of 0 (default) means this app has no priority over other apps. For values between 1 and 10,000, a lower value means a higher priority. Values outside of the range 0 to 10,000 inclusive are rejected.'}, 'lockTaskAllowed': {'type': 'boolean', 'deprecated': True, 'description': 'Whether the app is allowed to lock itself in full-screen mode. DEPRECATED. Use [InstallType](/android/management/reference/rest/v1/enterprises.policies#installtype) `KIOSK` or `kioskCustomLauncherEnabled` to configure a dedicated device.'}, 'signingKeyCerts': {'type': 'array', 'items': {'$ref': '#/$defs/ApplicationSigningKeyCert'}, 'description': 'Optional. Signing key certificates of the app. This field is required in the following cases: * The app has `installType` set to `CUSTOM` (i.e. a custom app). * The app has `roles` set to a nonempty list and the app does not exist on the Play Store. * The app has `extensionConfig` set (i.e. an extension app) but `ExtensionConfig.signingKeyFingerprintsSha256` (deprecated) is not set and the app does not exist on the Play Store. If this field is not set for a custom app, the policy is rejected. If it is not set when required for a non-custom app, a `NonComplianceDetail` with `INVALID_VALUE` is reported. For other cases, this field is optional and the signing key certificates obtained from Play Store are used. See following policy settings to see how this field is used: * `choosePrivateKeyRules` * `ApplicationPolicy.InstallType.CUSTOM` * `ApplicationPolicy.extensionConfig` * `ApplicationPolicy.roles`'}, 'permissionGrants': {'type': 'array', 'items': {'$ref': '#/$defs/PermissionGrant'}, 'description': 'Explicit permission grants or denials for the app. These values override the `default_permission_policy` and `permission_grants` which apply to all apps.'}, 'installConstraint': {'type': 'array', 'items': {'$ref': '#/$defs/InstallConstraint'}, 'description': 'Optional. The constraints for installing the app. You can specify a maximum of one `InstallConstraint`. Multiple constraints are rejected.'}, 'accessibleTrackIds': {'type': 'array', 'items': {'type': 'string'}, 'description': 'List of the app’s track IDs that a device belonging to the enterprise can access. If the list contains multiple track IDs, devices receive the latest version among all accessible tracks. If the list contains no track IDs, devices only have access to the app’s production track. More details about each track are available in [AppTrackInfo](/android/management/reference/rest/v1/enterprises.applications#apptrackinfo).'}, 'minimumVersionCode': {'type': 'integer', 'format': 'int32', 'description': 'The minimum version of the app that runs on the device. If set, the device attempts to update the app to at least this version code. If the app is not up-to-date, the device will contain a `NonComplianceDetail` with `non_compliance_reason` set to `APP_NOT_UPDATED`. The app must already be published to Google Play with a version code greater than or equal to this value. At most 20 apps may specify a minimum version code per policy.'}, 'workProfileWidgets': {'enum': ['WORK_PROFILE_WIDGETS_UNSPECIFIED', 'WORK_PROFILE_WIDGETS_ALLOWED', 'WORK_PROFILE_WIDGETS_DISALLOWED'], 'type': 'string', 'description': 'Specifies whether the app installed in the work profile is allowed to add widgets to the home screen.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `work_profile_widgets_default`', 'Work profile widgets are allowed. This means the application will be able to add widgets to the home screen.', 'Work profile widgets are disallowed. This means the application will not be able to add widgets to the home screen.']}, 'userControlSettings': {'enum': ['USER_CONTROL_SETTINGS_UNSPECIFIED', 'USER_CONTROL_ALLOWED', 'USER_CONTROL_DISALLOWED'], 'type': 'string', 'description': 'Optional. Specifies whether user control is permitted for the app. User control includes user actions like force-stopping and clearing app data. Certain types of apps have special treatment, see `USER_CONTROL_SETTINGS_UNSPECIFIED` and `USER_CONTROL_ALLOWED` for more details.', 'x-google-enum-descriptions': ['Uses the default behaviour of the app to determine if user control is allowed or disallowed. User control is allowed by default for most apps but disallowed for following types of apps: * extension apps (see `extensionConfig` for more details) * kiosk apps (see `KIOSK` install type for more details) * apps with `roles` set to a nonempty list * other critical system apps', 'User control is allowed for the app. Kiosk apps can use this to allow user control. For extension apps (see `extensionConfig` for more details), user control is disallowed even if this value is set. For apps with `roles` set to a nonempty list (except `roles` containing only `KIOSK` role), this value cannot be set. For kiosk apps (see `KIOSK` install type and `KIOSK` role type for more details), this value can be used to allow user control.', 'User control is disallowed for the app. This is supported on Android 11 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 11.']}, 'managedConfiguration': {'type': 'object', 'description': 'Managed configuration applied to the app. The format for the configuration is dictated by the [`ManagedProperty`](/android/management/reference/rest/v1/enterprises.applications#ManagedProperty) values supported by the app. Each field name in the managed configuration must match the `key` field of the `ManagedProperty`. The field value must be compatible with the `type` of the `ManagedProperty`: *type* *JSON value* `BOOL` `true` or `false` `STRING` string `INTEGER` number `CHOICE` string `MULTISELECT` array of strings `HIDDEN` string `BUNDLE_ARRAY` array of objects Note: string values cannot be longer than 65535 characters.', 'additionalProperties': {'description': 'Properties of the object.'}}, 'preferentialNetworkId': {'enum': ['PREFERENTIAL_NETWORK_ID_UNSPECIFIED', 'NO_PREFERENTIAL_NETWORK', 'PREFERENTIAL_NETWORK_ID_ONE', 'PREFERENTIAL_NETWORK_ID_TWO', 'PREFERENTIAL_NETWORK_ID_THREE', 'PREFERENTIAL_NETWORK_ID_FOUR', 'PREFERENTIAL_NETWORK_ID_FIVE'], 'type': 'string', 'description': 'Optional. ID of the preferential network the application uses. There must be a configuration for the specified network ID in `preferentialNetworkServiceConfigs`. If set to `PREFERENTIAL_NETWORK_ID_UNSPECIFIED`, the application will use the default network ID specified in `defaultPreferentialNetworkId`. See the documentation of `defaultPreferentialNetworkId` for the list of apps excluded from this defaulting. This applies on both work profiles and fully managed devices on Android 13 and above.', 'x-google-enum-descriptions': ['Whether this value is valid and what it means depends on where it is used, and this is documented on the relevant fields.', 'Application does not use any preferential network.', 'Preferential network identifier 1.', 'Preferential network identifier 2.', 'Preferential network identifier 3.', 'Preferential network identifier 4.', 'Preferential network identifier 5.']}, 'defaultPermissionPolicy': {'enum': ['PERMISSION_POLICY_UNSPECIFIED', 'PROMPT', 'GRANT', 'DENY'], 'type': 'string', 'description': 'The default policy for all permissions requested by the app. If specified, this overrides the policy-level `default_permission_policy` which applies to all apps. It does not override the `permission_grants` which applies to all apps.', 'x-google-enum-descriptions': ['Policy not specified. If no policy is specified for a permission at any level, then the `PROMPT` behavior is used by default.', 'Prompt the user to grant a permission.', 'Automatically grant a permission. On Android 12 and above, [`READ_SMS`](https://developer.android.com/reference/android/Manifest.permission#READ_SMS) and following sensor-related permissions can only be granted on fully managed devices: * [`ACCESS_FINE_LOCATION`](https://developer.android.com/reference/android/Manifest.permission#ACCESS_FINE_LOCATION) * [`ACCESS_BACKGROUND_LOCATION`](https://developer.android.com/reference/android/Manifest.permission#ACCESS_BACKGROUND_LOCATION) * [`ACCESS_COARSE_LOCATION`](https://developer.android.com/reference/android/Manifest.permission#ACCESS_COARSE_LOCATION) * [`CAMERA`](https://developer.android.com/reference/android/Manifest.permission#CAMERA) * [`RECORD_AUDIO`](https://developer.android.com/reference/android/Manifest.permission#RECORD_AUDIO) * [`ACTIVITY_RECOGNITION`](https://developer.android.com/reference/android/Manifest.permission#ACTIVITY_RECOGNITION) * [`BODY_SENSORS`](https://developer.android.com/reference/android/Manifest.permission#BODY_SENSORS)', 'Automatically deny a permission.']}, 'credentialProviderPolicy': {'enum': ['CREDENTIAL_PROVIDER_POLICY_UNSPECIFIED', 'CREDENTIAL_PROVIDER_ALLOWED', 'CREDENTIAL_PROVIDER_DISALLOWED'], 'type': 'string', 'description': 'Optional. Whether the app is allowed to act as a credential provider on Android 14 and above.', 'x-google-enum-descriptions': ['Unspecified. The behaviour is governed by `credentialProviderPolicyDefault`.', 'App is allowed to act as a credential provider.', 'App is not allowed to act as a credential provider.']}, 'connectedWorkAndPersonalApp': {'enum': ['CONNECTED_WORK_AND_PERSONAL_APP_UNSPECIFIED', 'CONNECTED_WORK_AND_PERSONAL_APP_DISALLOWED', 'CONNECTED_WORK_AND_PERSONAL_APP_ALLOWED'], 'type': 'string', 'description': 'Controls whether the app can communicate with itself across a device’s work and personal profiles, subject to user consent.', 'x-google-enum-descriptions': ['Unspecified. Defaults to CONNECTED_WORK_AND_PERSONAL_APPS_DISALLOWED.', 'Default. Prevents the app from communicating cross-profile.', 'Allows the app to communicate across profiles after receiving user consent.']}, 'alwaysOnVpnLockdownExemption': {'enum': ['ALWAYS_ON_VPN_LOCKDOWN_EXEMPTION_UNSPECIFIED', 'VPN_LOCKDOWN_ENFORCED', 'VPN_LOCKDOWN_EXEMPTION'], 'type': 'string', 'description': 'Specifies whether the app is allowed networking when the VPN is not connected and `alwaysOnVpnPackage.lockdownEnabled` is enabled. If set to `VPN_LOCKDOWN_ENFORCED`, the app is not allowed networking, and if set to `VPN_LOCKDOWN_EXEMPTION`, the app is allowed networking. Only supported on devices running Android 10 and above. If this is not supported by the device, the device will contain a `NonComplianceDetail` with `non_compliance_reason` set to `API_LEVEL` and a fieldPath. If this is not applicable to the app, the device will contain a `NonComplianceDetail` with `non_compliance_reason` set to `UNSUPPORTED` and a fieldPath. The fieldPath is set to `applications[i].alwaysOnVpnLockdownExemption`, where `i` is the index of the package in the `applications` policy.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `VPN_LOCKDOWN_ENFORCED`.', 'The app respects the always-on VPN lockdown setting.', 'The app is exempt from the always-on VPN lockdown setting.']}, 'managedConfigurationTemplate': {'$ref': '#/$defs/ManagedConfigurationTemplate', 'description': 'The managed configurations template for the app, saved from the [managed configurations iframe](/android/management/managed-configurations-iframe). This field is ignored if managed_configuration is set.'}}, 'description': 'Policy for an individual app. Note: Application availability on a given device cannot be changed using this policy if `installAppsDisabled` is enabled. The maximum number of applications that you can specify per policy is 3,000.'}, 'InstallConstraint': {'type': 'object', 'properties': {'chargingConstraint': {'enum': ['CHARGING_CONSTRAINT_UNSPECIFIED', 'CHARGING_NOT_REQUIRED', 'INSTALL_ONLY_WHEN_CHARGING'], 'type': 'string', 'description': 'Optional. Charging constraint.', 'x-google-enum-descriptions': ['Unspecified. Default to `CHARGING_NOT_REQUIRED`.', "Device doesn't have to be charging.", 'Device has to be charging.']}, 'deviceIdleConstraint': {'enum': ['DEVICE_IDLE_CONSTRAINT_UNSPECIFIED', 'DEVICE_IDLE_NOT_REQUIRED', 'INSTALL_ONLY_WHEN_DEVICE_IDLE'], 'type': 'string', 'description': 'Optional. Device idle constraint.', 'x-google-enum-descriptions': ['Unspecified. Default to `DEVICE_IDLE_NOT_REQUIRED`.', "Device doesn't have to be idle, app can be installed while the user is interacting with the device.", 'Device has to be idle.']}, 'networkTypeConstraint': {'enum': ['NETWORK_TYPE_CONSTRAINT_UNSPECIFIED', 'INSTALL_ON_ANY_NETWORK', 'INSTALL_ONLY_ON_UNMETERED_NETWORK'], 'type': 'string', 'description': 'Optional. Network type constraint.', 'x-google-enum-descriptions': ['Unspecified. Default to `INSTALL_ON_ANY_NETWORK`.', 'Any active networks (Wi-Fi, cellular, etc.).', 'Any unmetered network (e.g. Wi-FI).']}}, 'description': 'Amongst apps with `InstallType` set to: * FORCE_INSTALLED * PREINSTALLED this defines a set of restrictions for the app installation. At least one of the fields must be set. When multiple fields are set, then all the constraints need to be satisfied for the app to be installed.'}, 'UserFacingMessage': {'type': 'object', 'properties': {'defaultMessage': {'type': 'string', 'description': "The default message displayed if no localized message is specified or the user's locale doesn't match with any of the localized messages. A default message must be provided if any localized messages are provided."}, 'localizedMessages': {'type': 'object', 'description': 'A map containing pairs, where locale is a well-formed [BCP 47 language](https://www.w3.org/International/articles/language-tags/) code, such as en-US, es-ES, or fr.', 'additionalProperties': {'type': 'string'}}}, 'description': 'Provides a user-facing message with locale info. The maximum message length is 4096 characters.'}, 'WifiRoamingPolicy': {'type': 'object', 'properties': {'wifiRoamingSettings': {'type': 'array', 'items': {'$ref': '#/$defs/WifiRoamingSetting'}, 'description': 'Optional. Wi-Fi roaming settings. SSIDs provided in this list must be unique, the policy will be rejected otherwise.'}}, 'description': 'Wi-Fi roaming policy.'}, 'AlwaysOnVpnPackage': {'type': 'object', 'properties': {'packageName': {'type': 'string', 'description': 'The package name of the VPN app.'}, 'lockdownEnabled': {'type': 'boolean', 'description': 'Disallows networking when the VPN is not connected.'}}, 'description': 'Configuration for an always-on VPN connection.'}, 'DefaultApplication': {'type': 'object', 'properties': {'packageName': {'type': 'string', 'description': 'Required. The package name that should be set as the default application. The policy is rejected if the package name is invalid.'}}, 'description': 'Information about the application to be set as the default.'}, 'KioskCustomization': {'type': 'object', 'properties': {'statusBar': {'enum': ['STATUS_BAR_UNSPECIFIED', 'NOTIFICATIONS_AND_SYSTEM_INFO_ENABLED', 'NOTIFICATIONS_AND_SYSTEM_INFO_DISABLED', 'SYSTEM_INFO_ONLY'], 'type': 'string', 'description': 'Optional. Specifies whether system info and notifications are disabled in kiosk mode.', 'x-google-enum-descriptions': ['Unspecified, defaults to `INFO_AND_NOTIFICATIONS_DISABLED`.', "System info and notifications are shown on the status bar in kiosk mode. **Note:** For this policy to take effect, the device's home button must be enabled using [`kioskCustomization.systemNavigation`](/android/management/reference/rest/v1/enterprises.policies#SystemNavigation).", 'System info and notifications are disabled in kiosk mode.', 'Only system info is shown on the status bar.']}, 'deviceSettings': {'enum': ['DEVICE_SETTINGS_UNSPECIFIED', 'SETTINGS_ACCESS_ALLOWED', 'SETTINGS_ACCESS_BLOCKED'], 'type': 'string', 'description': 'Optional. Specifies whether the Settings app is allowed in kiosk mode.', 'x-google-enum-descriptions': ['Unspecified, defaults to `SETTINGS_ACCESS_ALLOWED`.', 'Access to the Settings app is allowed in kiosk mode.', 'Access to the Settings app is not allowed in kiosk mode.']}, 'systemNavigation': {'enum': ['SYSTEM_NAVIGATION_UNSPECIFIED', 'NAVIGATION_ENABLED', 'NAVIGATION_DISABLED', 'HOME_BUTTON_ONLY'], 'type': 'string', 'description': 'Optional. Specifies which navigation features are enabled (e.g. Home, Overview buttons) in kiosk mode.', 'x-google-enum-descriptions': ['Unspecified, defaults to `NAVIGATION_DISABLED`.', 'Home and overview buttons are enabled.', 'The home and Overview buttons are not accessible.', 'Only the home button is enabled.']}, 'powerButtonActions': {'enum': ['POWER_BUTTON_ACTIONS_UNSPECIFIED', 'POWER_BUTTON_AVAILABLE', 'POWER_BUTTON_BLOCKED'], 'type': 'string', 'description': 'Optional. Sets the behavior of a device in kiosk mode when a user presses and holds (long-presses) the Power button.', 'x-google-enum-descriptions': ['Unspecified, defaults to `POWER_BUTTON_AVAILABLE`.', 'The power menu (e.g. Power off, Restart) is shown when a user long-presses the Power button of a device in kiosk mode.', 'The power menu (e.g. Power off, Restart) is not shown when a user long-presses the Power button of a device in kiosk mode. Note: this may prevent users from turning off the device.']}, 'systemErrorWarnings': {'enum': ['SYSTEM_ERROR_WARNINGS_UNSPECIFIED', 'ERROR_AND_WARNINGS_ENABLED', 'ERROR_AND_WARNINGS_MUTED'], 'type': 'string', 'description': 'Optional. Specifies whether system error dialogs for crashed or unresponsive apps are blocked in kiosk mode. When blocked, the system will force-stop the app as if the user chooses the "close app" option on the UI.', 'x-google-enum-descriptions': ['Unspecified, defaults to `ERROR_AND_WARNINGS_MUTED`.', 'All system error dialogs such as crash and app not responding (ANR) are displayed.', 'All system error dialogs, such as crash and app not responding (ANR) are blocked. When blocked, the system force-stops the app as if the user closes the app from the UI.']}}, 'description': 'Settings controlling the behavior of a device in kiosk mode. To enable kiosk mode, set `kioskCustomLauncherEnabled` to `true` or specify an app in the policy with `installType` `KIOSK`.'}, 'PrivateDnsSettings': {'type': 'object', 'properties': {'privateDnsHost': {'type': 'string', 'description': 'Optional. The hostname of the DNS server. This must be set if and only if `private_dns_mode` is set to `PRIVATE_DNS_SPECIFIED_HOST`. Supported on Android 10 and above on fully managed devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported on other management modes. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 10. A `NonComplianceDetail` with `PENDING` is reported if the device is not connected to a network. A `NonComplianceDetail` with `nonComplianceReason` `INVALID_VALUE` and `specificNonComplianceReason` `PRIVATE_DNS_HOST_NOT_SERVING` is reported if the specified host is not a DNS server or not supported on Android. A `NonComplianceDetail` with `INVALID_VALUE` is reported if applying this setting fails for any other reason.'}, 'privateDnsMode': {'enum': ['PRIVATE_DNS_MODE_UNSPECIFIED', 'PRIVATE_DNS_USER_CHOICE', 'PRIVATE_DNS_AUTOMATIC', 'PRIVATE_DNS_SPECIFIED_HOST'], 'type': 'string', 'description': "Optional. The configuration mode for device's global private DNS settings. If this is set to `PRIVATE_DNS_SPECIFIED_HOST`, then `private_dns_host` must be set.", 'x-google-enum-descriptions': ['Unspecified. Defaults to `PRIVATE_DNS_USER_CHOICE`.', 'The user is allowed to configure private DNS.', 'Automatic private DNS mode. The device tries to use the network-provided DNS server over an encrypted connection before resorting to cleartext. The user is not allowed to modify this setting. Supported on Android 10 and above on fully managed devices and work profiles on company-owned devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported on other management modes. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 10. A `NonComplianceDetail` with `INVALID_VALUE` is reported if setting this fails for any other reason. **Note:** For work profiles on company-owned devices, setting this mode prevents the user from changing the setting, but the active private DNS setting is not modified. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported in this case.', 'The device only uses the DNS server specified in `private_dns_host`. The user is not allowed to modify this setting. If this is set, then `private_dns_host` must be set. Supported on Android 10 and above on fully managed devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported on other management modes. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 10.']}}, 'description': "Controls the device's private DNS settings."}, 'WifiRoamingSetting': {'type': 'object', 'properties': {'wifiSsid': {'type': 'string', 'description': 'Required. SSID of the Wi-Fi network.'}, 'wifiRoamingMode': {'enum': ['WIFI_ROAMING_MODE_UNSPECIFIED', 'WIFI_ROAMING_DISABLED', 'WIFI_ROAMING_DEFAULT', 'WIFI_ROAMING_AGGRESSIVE'], 'type': 'string', 'description': 'Required. Wi-Fi roaming mode for the specified SSID.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `WIFI_ROAMING_DEFAULT`.', 'Wi-Fi roaming is disabled. Supported on Android 15 and above on fully managed devices and work profiles on company-owned devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for other management modes. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 15.', 'Default Wi-Fi roaming mode of the device.', 'Aggressive roaming mode which allows quicker Wi-Fi roaming. Supported on Android 15 and above on fully managed devices and work profiles on company-owned devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for other management modes. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 15. A `NonComplianceDetail` with `DEVICE_INCOMPATIBLE` is reported if the device does not support aggressive roaming mode.']}}, 'description': 'Wi-Fi roaming setting.'}, 'CrossDevicePolicies': {'type': 'object', 'properties': {'nearbyAppStreaming': {'enum': ['NEARBY_APP_STREAMING_UNSPECIFIED', 'NEARBY_APP_STREAMING_USER_CHOICE', 'NEARBY_APP_STREAMING_DISABLED', 'NEARBY_APP_STREAMING_USER_CHOICE_SAME_MANAGED_ACCOUNT'], 'type': 'string', 'description': 'Optional. Manages video streaming of apps on the device for fully managed devices or in the work profile for devices with work profiles to nearby devices. This is supported on Android 13 and above.', 'x-google-enum-descriptions': ['Unspecified. Defaults to NEARBY_APP_STREAMING_USER_CHOICE_SAME_MANAGED_ACCOUNT.', 'The user is allowed to choose whether to stream apps to nearby devices.', 'Disables app streaming to nearby devices.', 'The user is allowed to choose whether to stream apps to other nearby devices which are signed in with the same authenticated managed account.']}, 'taskContinuityHandoff': {'enum': ['TASK_CONTINUITY_HANDOFF_UNSPECIFIED', 'TASK_CONTINUITY_HANDOFF_ALLOWED', 'TASK_CONTINUITY_HANDOFF_DISALLOWED'], 'type': 'string', 'description': 'Optional. Controls the [task continuity handoff](https://developer.android.com/partners/android-17/features#handoff) feature. This policy applies to the entire device for fully managed devices, and to the work profile for devices with a work profile. Requires Android 17 QPR1 or higher.', 'x-google-enum-descriptions': ['Defaults to `TASK_CONTINUITY_HANDOFF_ALLOWED`.', 'Allows the user to enable or disable the task continuity handoff feature in settings. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is lower than Android 17 QPR1.', 'The task continuity handoff feature is disallowed. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is lower than Android 17 QPR1.']}, 'nearbyNotificationStreaming': {'enum': ['NEARBY_NOTIFICATION_STREAMING_UNSPECIFIED', 'NEARBY_NOTIFICATION_STREAMING_USER_CHOICE', 'NEARBY_NOTIFICATION_STREAMING_DISABLED', 'NEARBY_NOTIFICATION_STREAMING_USER_CHOICE_SAME_MANAGED_ACCOUNT'], 'type': 'string', 'description': 'Optional. Manages streaming of notifications from apps on the device for fully managed devices or in the work profile for devices with work profiles to nearby devices. This is supported on Android 13 and above.', 'x-google-enum-descriptions': ['Unspecified. Defaults to NEARBY_NOTIFICATION_STREAMING_USER_CHOICE_SAME_MANAGED_ACCOUNT.', 'The user is allowed to choose whether to stream notifications to nearby devices.', 'Disables notification streaming to nearby devices.', 'The user is allowed to choose whether to stream notifications to other nearby devices which are signed in with the same authenticated managed account.']}}, 'description': 'Policies controlling cross-device communication.'}, 'ChoosePrivateKeyRule': {'type': 'object', 'properties': {'urlPattern': {'type': 'string', 'description': 'The URL pattern to match against the URL of the request. If not set or empty, it matches all URLs. This uses the regular expression syntax of `java.util.regex.Pattern`.'}, 'packageNames': {'type': 'array', 'items': {'type': 'string'}, 'description': 'The package names to which this rule applies. The signing key certificate fingerprint of the app is verified against the signing key certificate fingerprints provided by Play Store and `ApplicationPolicy.signingKeyCerts` . If no package names are specified, then the alias is provided to all apps that call [`KeyChain.choosePrivateKeyAlias`](https://developer.android.com/reference/android/security/KeyChain#choosePrivateKeyAlias%28android.app.Activity,%20android.security.KeyChainAliasCallback,%20java.lang.String[],%20java.security.Principal[],%20java.lang.String,%20int,%20java.lang.String%29) or any overloads (but not without calling `KeyChain.choosePrivateKeyAlias`, even on Android 11 and above). Any app with the same Android UID as a package specified here will have access when they call `KeyChain.choosePrivateKeyAlias`.'}, 'privateKeyAlias': {'type': 'string', 'description': 'The alias of the private key to be used.'}}, 'description': "Controls apps' access to private keys. The rule determines which private key, if any, Android Device Policy grants to the specified app. Access is granted either when the app calls [`KeyChain.choosePrivateKeyAlias`](https://developer.android.com/reference/android/security/KeyChain#choosePrivateKeyAlias%28android.app.Activity,%20android.security.KeyChainAliasCallback,%20java.lang.String[],%20java.security.Principal[],%20java.lang.String,%20int,%20java.lang.String%29) (or any overloads) to request a private key alias for a given URL, or for rules that are not URL-specific (that is, if `urlPattern` is not set, or set to the empty string or `.*`) on Android 11 and above, directly so that the app can call [`KeyChain.getPrivateKey`](https://developer.android.com/reference/android/security/KeyChain#getPrivateKey%28android.content.Context,%20java.lang.String%29), without first having to call `KeyChain.choosePrivateKeyAlias`. When an app calls `KeyChain.choosePrivateKeyAlias` if more than one `choosePrivateKeyRules` matches, the last matching rule defines which key alias to return."}, 'CrossProfilePolicies': {'type': 'object', 'properties': {'crossProfileCopyPaste': {'enum': ['CROSS_PROFILE_COPY_PASTE_UNSPECIFIED', 'COPY_FROM_WORK_TO_PERSONAL_DISALLOWED', 'CROSS_PROFILE_COPY_PASTE_ALLOWED'], 'type': 'string', 'description': 'Optional. Whether text copied from one profile (personal or work) can be pasted in the other profile.', 'x-google-enum-descriptions': ['Unspecified. Defaults to COPY_FROM_WORK_TO_PERSONAL_DISALLOWED', 'Default. Prevents users from pasting into the personal profile text copied from the work profile. Text copied from the personal profile can be pasted into the work profile, and text copied from the work profile can be pasted into the work profile.', 'Text copied in either profile can be pasted in the other profile.']}, 'crossProfileDataSharing': {'enum': ['CROSS_PROFILE_DATA_SHARING_UNSPECIFIED', 'CROSS_PROFILE_DATA_SHARING_DISALLOWED', 'DATA_SHARING_FROM_WORK_TO_PERSONAL_DISALLOWED', 'CROSS_PROFILE_DATA_SHARING_ALLOWED'], 'type': 'string', 'description': 'Optional. Whether data from one profile (personal or work) can be shared with apps in the other profile. Specifically controls simple data sharing via intents. Management of other cross-profile communication channels, such as contact search, copy/paste, or connected work & personal apps, are configured separately.', 'x-google-enum-descriptions': ['Unspecified. Defaults to DATA_SHARING_FROM_WORK_TO_PERSONAL_DISALLOWED.', 'Prevents data from being shared from both the personal profile to the work profile and the work profile to the personal profile.', 'Default. Prevents users from sharing data from the work profile to apps in the personal profile. Personal data can be shared with work apps.', 'Data from either profile can be shared with the other profile.']}, 'crossProfileAppFunctions': {'enum': ['CROSS_PROFILE_APP_FUNCTIONS_UNSPECIFIED', 'CROSS_PROFILE_APP_FUNCTIONS_DISALLOWED', 'CROSS_PROFILE_APP_FUNCTIONS_ALLOWED'], 'type': 'string', 'description': 'Optional. Controls whether personal profile apps can invoke app functions exposed by apps in the work profile.', 'x-google-enum-descriptions': ['Unspecified. If `appFunctions` is set to `APP_FUNCTIONS_ALLOWED`, defaults to `CROSS_PROFILE_APP_FUNCTIONS_ALLOWED`. If `appFunctions` is set to `APP_FUNCTIONS_DISALLOWED`, defaults to `CROSS_PROFILE_APP_FUNCTIONS_DISALLOWED`.', 'Personal profile apps are not allowed to invoke app functions exposed by apps in the work profile.', 'Personal profile apps can invoke app functions exposed by apps in the work profile. If this is set, `appFunctions` must not be set to `APP_FUNCTIONS_DISALLOWED`, otherwise the policy will be rejected.']}, 'workProfileWidgetsDefault': {'enum': ['WORK_PROFILE_WIDGETS_DEFAULT_UNSPECIFIED', 'WORK_PROFILE_WIDGETS_DEFAULT_ALLOWED', 'WORK_PROFILE_WIDGETS_DEFAULT_DISALLOWED'], 'type': 'string', 'description': 'Optional. Specifies the default behaviour for work profile widgets. If the policy does not specify `work_profile_widgets` for a specific application, it will behave according to the value specified here.', 'x-google-enum-descriptions': ['Unspecified. Defaults to WORK_PROFILE_WIDGETS_DEFAULT_DISALLOWED.', 'Work profile widgets are allowed by default. This means that if the policy does not specify `work_profile_widgets` as `WORK_PROFILE_WIDGETS_DISALLOWED` for the application, it will be able to add widgets to the home screen.', 'Work profile widgets are disallowed by default. This means that if the policy does not specify `work_profile_widgets` as `WORK_PROFILE_WIDGETS_ALLOWED` for the application, it will be unable to add widgets to the home screen.']}, 'showWorkContactsInPersonalProfile': {'enum': ['SHOW_WORK_CONTACTS_IN_PERSONAL_PROFILE_UNSPECIFIED', 'SHOW_WORK_CONTACTS_IN_PERSONAL_PROFILE_DISALLOWED', 'SHOW_WORK_CONTACTS_IN_PERSONAL_PROFILE_ALLOWED', 'SHOW_WORK_CONTACTS_IN_PERSONAL_PROFILE_DISALLOWED_EXCEPT_SYSTEM'], 'type': 'string', 'description': 'Optional. Whether personal apps can access contacts stored in the work profile. See also `exemptions_to_show_work_contacts_in_personal_profile`.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `SHOW_WORK_CONTACTS_IN_PERSONAL_PROFILE_ALLOWED`. When this is set, `exemptions_to_show_work_contacts_in_personal_profile` must not be set.', 'Prevents personal apps from accessing work profile contacts and looking up work contacts. When this is set, personal apps specified in `exemptions_to_show_work_contacts_in_personal_profile` are allowlisted and can access work profile contacts directly. Supported on Android 7.0 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 7.0.', 'Default. Allows apps in the personal profile to access work profile contacts including contact searches and incoming calls. When this is set, personal apps specified in `exemptions_to_show_work_contacts_in_personal_profile` are blocklisted and can not access work profile contacts directly. Supported on Android 7.0 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 7.0.', 'Prevents most personal apps from accessing work profile contacts including contact searches and incoming calls, except for the OEM default Dialer, Messages, and Contacts apps. Neither user-configured Dialer, Messages, and Contacts apps, nor any other system or play installed apps, will be able to query work contacts directly. When this is set, personal apps specified in `exemptions_to_show_work_contacts_in_personal_profile` are allowlisted and can access work profile contacts. Supported on Android 14 and above. If this is set on a device with Android version less than 14, the behaviour falls back to `SHOW_WORK_CONTACTS_IN_PERSONAL_PROFILE_DISALLOWED` and a `NonComplianceDetail` with `API_LEVEL` is reported.']}, 'exemptionsToShowWorkContactsInPersonalProfile': {'$ref': '#/$defs/PackageNameList', 'description': 'Optional. List of apps which are excluded from the `ShowWorkContactsInPersonalProfile` setting. For this to be set, `ShowWorkContactsInPersonalProfile` must be set to one of the following values: * `SHOW_WORK_CONTACTS_IN_PERSONAL_PROFILE_ALLOWED`. In this case, these exemptions act as a blocklist. * `SHOW_WORK_CONTACTS_IN_PERSONAL_PROFILE_DISALLOWED`. In this case, these exemptions act as an allowlist. * `SHOW_WORK_CONTACTS_IN_PERSONAL_PROFILE_DISALLOWED_EXCEPT_SYSTEM`. In this case, these exemptions act as an allowlist, in addition to the already allowlisted system apps. Supported on Android 14 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 14.'}}, 'description': 'Controls the data from the work profile that can be accessed from the personal profile and vice versa. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported if the device does not have a work profile.'}, 'PasswordRequirements': {'type': 'object', 'properties': {'passwordScope': {'enum': ['SCOPE_UNSPECIFIED', 'SCOPE_DEVICE', 'SCOPE_PROFILE'], 'type': 'string', 'description': 'Optional. The scope that the password requirement applies to.', 'x-google-enum-descriptions': ['The scope is unspecified. The password requirements are applied to the work profile for work profile devices and the whole device for fully managed or dedicated devices.', 'The password requirements are only applied to the device.', 'The password requirements are only applied to the work profile.']}, 'passwordQuality': {'enum': ['PASSWORD_QUALITY_UNSPECIFIED', 'BIOMETRIC_WEAK', 'SOMETHING', 'NUMERIC', 'NUMERIC_COMPLEX', 'ALPHABETIC', 'ALPHANUMERIC', 'COMPLEX', 'COMPLEXITY_LOW', 'COMPLEXITY_MEDIUM', 'COMPLEXITY_HIGH'], 'type': 'string', 'description': 'Optional. The required password quality.', 'x-google-enum-descriptions': ['There are no password requirements.', 'The device must be secured with a low-security biometric recognition technology, at minimum. This includes technologies that can recognize the identity of an individual that are roughly equivalent to a 3-digit PIN (false detection is less than 1 in 1,000). This, when applied on personally owned work profile devices on Android 12 device-scoped, will be treated as `COMPLEXITY_LOW` for application. See `PasswordQuality` for details.', 'A password is required, but there are no restrictions on what the password must contain. This, when applied on personally owned work profile devices on Android 12 device-scoped, will be treated as `COMPLEXITY_LOW` for application. See `PasswordQuality` for details.', 'The password must contain numeric characters. This, when applied on personally owned work profile devices on Android 12 device-scoped, will be treated as `COMPLEXITY_MEDIUM` for application. See `PasswordQuality` for details.', 'The password must contain numeric characters with no repeating (4444) or ordered (1234, 4321, 2468) sequences. This, when applied on personally owned work profile devices on Android 12 device-scoped, will be treated as `COMPLEXITY_MEDIUM` for application. See `PasswordQuality` for details.', 'The password must contain alphabetic (or symbol) characters. This, when applied on personally owned work profile devices on Android 12 device-scoped, will be treated as `COMPLEXITY_HIGH` for application. See `PasswordQuality` for details.', 'The password must contain both numeric and alphabetic (or symbol) characters. This, when applied on personally owned work profile devices on Android 12 device-scoped, will be treated as `COMPLEXITY_HIGH` for application. See `PasswordQuality` for details.', 'The password must meet the minimum requirements specified in `passwordMinimumLength`, `passwordMinimumLetters`, `passwordMinimumSymbols`, etc. For example, if `passwordMinimumSymbols` is `2`, the password must contain at least two symbols. This, when applied on personally owned work profile devices on Android 12 device-scoped, will be treated as `COMPLEXITY_HIGH` for application. In this case, the requirements in `passwordMinimumLength`, `passwordMinimumLetters`, `passwordMinimumSymbols`, etc are not applied. See `PasswordQuality` for details.', 'Define the low password complexity band as: * pattern * PIN with repeating (4444) or ordered (1234, 4321, 2468) sequences This sets the minimum complexity band which the password must meet. Enforcement varies among different Android versions, management modes and password scopes. See `PasswordQuality` for details.', 'Define the medium password complexity band as: * PIN with no repeating (4444) or ordered (1234, 4321, 2468) sequences, length at least 4 * alphabetic, length at least 4 * alphanumeric, length at least 4 This sets the minimum complexity band which the password must meet. Enforcement varies among different Android versions, management modes and password scopes. See `PasswordQuality` for details.', 'Define the high password complexity band as: On Android 12 and above: * PIN with no repeating (4444) or ordered (1234, 4321, 2468) sequences, length at least 8 * alphabetic, length at least 6 * alphanumeric, length at least 6 This sets the minimum complexity band which the password must meet. Enforcement varies among different Android versions, management modes and password scopes. See `PasswordQuality` for details.']}, 'unifiedLockSettings': {'enum': ['UNIFIED_LOCK_SETTINGS_UNSPECIFIED', 'ALLOW_UNIFIED_WORK_AND_PERSONAL_LOCK', 'REQUIRE_SEPARATE_WORK_LOCK'], 'type': 'string', 'description': 'Optional. Controls whether a unified lock is allowed for the device and the work profile, on devices running Android 9 and above with a work profile. This can be set only if `password_scope` is set to `SCOPE_PROFILE`, the policy will be rejected otherwise. If user has not set a separate work lock and this field is set to `REQUIRE_SEPARATE_WORK_LOCK`, a `NonComplianceDetail` is reported with `nonComplianceReason` set to `USER_ACTION`.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `ALLOW_UNIFIED_WORK_AND_PERSONAL_LOCK`.', 'A common lock for the device and the work profile is allowed.', 'A separate lock for the work profile is required.']}, 'passwordHistoryLength': {'type': 'integer', 'format': 'int32', 'description': "Optional. The length of the password history. After setting this field, the user won't be able to enter a new password that is the same as any password in the history. A value of 0 means there is no restriction."}, 'passwordMinimumLength': {'type': 'integer', 'format': 'int32', 'description': 'Optional. The minimum allowed password length. A value of 0 means there is no restriction. Only enforced when `password_quality` is `NUMERIC`, `NUMERIC_COMPLEX`, `ALPHABETIC`, `ALPHANUMERIC`, or `COMPLEX`.'}, 'requirePasswordUnlock': {'enum': ['REQUIRE_PASSWORD_UNLOCK_UNSPECIFIED', 'USE_DEFAULT_DEVICE_TIMEOUT', 'REQUIRE_EVERY_DAY'], 'type': 'string', 'description': 'Optional. The length of time after a device or work profile is unlocked using a strong form of authentication (password, PIN, pattern) that it can be unlocked using any other authentication method (e.g. fingerprint, trust agents, face). After the specified time period elapses, only strong forms of authentication can be used to unlock the device or work profile.', 'x-google-enum-descriptions': ['Unspecified. Defaults to USE_DEFAULT_DEVICE_TIMEOUT.', 'The timeout period is set to the device’s default.', 'The timeout period is set to 24 hours.']}, 'passwordMinimumLetters': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Minimum number of letters required in the password. Only enforced when `password_quality` is `COMPLEX`.'}, 'passwordMinimumNumeric': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Minimum number of numerical digits required in the password. Only enforced when `password_quality` is `COMPLEX`.'}, 'passwordMinimumSymbols': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Minimum number of symbols required in the password. Only enforced when `password_quality` is `COMPLEX`.'}, 'passwordMinimumLowerCase': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Minimum number of lower case letters required in the password. Only enforced when `password_quality` is `COMPLEX`.'}, 'passwordMinimumNonLetter': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Minimum number of non-letter characters (numerical digits or symbols) required in the password. Only enforced when `password_quality` is `COMPLEX`.'}, 'passwordMinimumUpperCase': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Minimum number of upper case letters required in the password. Only enforced when `password_quality` is `COMPLEX`.'}, 'passwordExpirationTimeout': {'type': 'string', 'format': 'google-duration', 'description': 'Optional. Password expiration timeout.'}, 'maximumFailedPasswordsForWipe': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Number of incorrect device-unlock passwords that can be entered before a device is wiped. A value of 0 means there is no restriction.'}}, 'description': 'Requirements for the password used to unlock a device.'}, 'PersonalUsagePolicies': {'type': 'object', 'properties': {'cameraDisabled': {'type': 'boolean', 'description': 'If true, the camera is disabled on the personal profile.'}, 'bluetoothSharing': {'enum': ['BLUETOOTH_SHARING_UNSPECIFIED', 'BLUETOOTH_SHARING_ALLOWED', 'BLUETOOTH_SHARING_DISALLOWED'], 'type': 'string', 'description': 'Optional. Whether bluetooth sharing is allowed.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `BLUETOOTH_SHARING_ALLOWED`.', 'Bluetooth sharing is allowed on personal profile. Supported on Android 8 and above. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported if this is set for a personal device.', 'Bluetooth sharing is disallowed on personal profile. Supported on Android 8 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 8. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported if this is set for a personal device.']}, 'maxDaysWithWorkOff': {'type': 'integer', 'format': 'int32', 'description': 'Controls how long the work profile can stay off. The minimum duration must be at least 3 days. Other details are as follows: - If the duration is set to 0, the feature is turned off. - If the duration is set to a value smaller than the minimum duration, the feature returns an error. *Note:* If you want to avoid personal profiles being suspended <https://developer.android.com/reference/android/app/admin/DevicePolicyManager#setPersonalAppsSuspended(android.content.ComponentName,%20boolean)> during long periods of off-time, you can temporarily set a large value for this parameter.'}, 'privateSpacePolicy': {'enum': ['PRIVATE_SPACE_POLICY_UNSPECIFIED', 'PRIVATE_SPACE_ALLOWED', 'PRIVATE_SPACE_DISALLOWED'], 'type': 'string', 'description': 'Optional. Controls whether a private space is allowed on the device.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `PRIVATE_SPACE_ALLOWED`.', 'Users can create a private space profile.', 'Users cannot create a private space profile. Supported only for company-owned devices with a work profile. Caution: Any existing private space will be removed.']}, 'crossDevicePolicies': {'$ref': '#/$defs/PersonalCrossDevicePolicies', 'description': 'Optional. Policies controlling cross-device communication in the personal profile.'}, 'personalApplications': {'type': 'array', 'items': {'$ref': '#/$defs/PersonalApplicationPolicy'}, 'description': 'Policy applied to applications in the personal profile.'}, 'personalPlayStoreMode': {'enum': ['PLAY_STORE_MODE_UNSPECIFIED', 'BLACKLIST', 'BLOCKLIST', 'ALLOWLIST'], 'type': 'string', 'description': 'Used together with personalApplications to control how apps in the personal profile are allowed or blocked.', 'x-google-enum-deprecated': [False, True, False, False], 'x-google-enum-descriptions': ['Unspecified. Defaults to `BLOCKLIST`.', 'All Play Store apps are available for installation in the personal profile, except those whose installType is BLOCKED in personalApplications.', 'All Play Store apps are available for installation in the personal profile, except those whose installType is BLOCKED in personalApplications.', 'Only apps explicitly specified in personalApplications with installType set to AVAILABLE are allowed to be installed in the personal profile.']}, 'screenCaptureDisabled': {'type': 'boolean', 'description': 'If `true`, screen capture is disabled for all users. This also blocks [Circle to Search](https://support.google.com/android/answer/14508957).'}, 'accountTypesWithManagementDisabled': {'type': 'array', 'items': {'type': 'string'}, 'description': "Account types that can't be managed by the user."}}, 'description': 'Policies controlling personal usage on a company-owned device with a work profile.'}, 'PolicyEnforcementRule': {'type': 'object', 'properties': {'wipeAction': {'$ref': '#/$defs/WipeAction', 'description': 'An action to reset a company owned device or delete a work profile. Note: `blockAction` must also be specified.'}, 'blockAction': {'$ref': '#/$defs/BlockAction', 'description': 'An action to block access to apps and data on a company owned device or in a work profile. This action also triggers a user-facing notification with information (where possible) on how to correct the compliance issue. Note: `wipeAction` must also be specified.'}, 'settingName': {'type': 'string', 'description': 'The top-level policy to enforce. For example, `applications` or `passwordPolicies`.'}}, 'description': 'A rule that defines the actions to take if a device or work profile is not compliant with the policy specified in `settingName`. In the case of multiple matching or multiple triggered enforcement rules, a merge will occur with the most severe action being taken. However, all triggered rules are still kept track of: this includes initial trigger time and all associated non-compliance details. In the situation where the most severe enforcement rule is satisfied, the next most appropriate action is applied.'}, 'ScreenTimeoutSettings': {'type': 'object', 'properties': {'screenTimeout': {'type': 'string', 'format': 'google-duration', 'description': 'Optional. Controls the screen timeout duration. The screen timeout duration must be greater than 0, otherwise it is rejected. Additionally, it should not be greater than `maximumTimeToLock`, otherwise the screen timeout is set to `maximumTimeToLock` and a `NonComplianceDetail` with `INVALID_VALUE` reason and `SCREEN_TIMEOUT_GREATER_THAN_MAXIMUM_TIME_TO_LOCK` specific reason is reported. If the screen timeout is less than a certain lower bound, it is set to the lower bound. The lower bound may vary across devices. If this is set, `screenTimeoutMode` must be `SCREEN_TIMEOUT_ENFORCED`. Supported on Android 9 and above on fully managed devices. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 9. Supported on work profiles on company-owned devices on Android 15 and above.'}, 'screenTimeoutMode': {'enum': ['SCREEN_TIMEOUT_MODE_UNSPECIFIED', 'SCREEN_TIMEOUT_USER_CHOICE', 'SCREEN_TIMEOUT_ENFORCED'], 'type': 'string', 'description': 'Optional. Controls whether the user is allowed to configure the screen timeout.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `SCREEN_TIMEOUT_USER_CHOICE`.', 'The user is allowed to configure the screen timeout. `screenTimeout` must not be set.', 'The screen timeout is set to `screenTimeout` and the user is not allowed to configure the timeout. `screenTimeout` must be set. Supported on Android 9 and above on fully managed devices. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 9. Supported on work profiles on company-owned devices on Android 15 and above.']}}, 'description': 'Controls the screen timeout settings.'}, 'OncCertificateProvider': {'type': 'object', 'properties': {'certificateReferences': {'type': 'array', 'items': {'type': 'string'}, 'description': ' This feature is not generally available.'}, 'contentProviderEndpoint': {'$ref': '#/$defs/ContentProviderEndpoint', 'description': ' This feature is not generally available.'}}, 'description': ' This feature is not generally available.'}, 'WorkAccountSetupConfig': {'type': 'object', 'properties': {'authenticationType': {'enum': ['AUTHENTICATION_TYPE_UNSPECIFIED', 'AUTHENTICATION_TYPE_NOT_ENFORCED', 'GOOGLE_AUTHENTICATED'], 'type': 'string', 'description': 'Optional. The authentication type of the user on the device.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `AUTHENTICATION_TYPE_NOT_ENFORCED`.', 'Authentication status of user on device is not enforced.', 'Requires device to be managed with a Google authenticated account.']}, 'requiredAccountEmail': {'type': 'string', 'description': 'Optional. The specific google work account email address to be added. This field is only relevant if `authenticationType` is `GOOGLE_AUTHENTICATED`. This must be an enterprise account and not a consumer account. Once set and a Google authenticated account is added to the device, changing this field will have no effect, and thus recommended to be set only once. The email address must be all lowercase.'}}, 'description': 'Controls the work account setup configuration, such as details of whether a Google authenticated account is required.'}, 'ContentProviderEndpoint': {'type': 'object', 'properties': {'uri': {'type': 'string', 'description': ' This feature is not generally available.'}, 'packageName': {'type': 'string', 'description': ' This feature is not generally available.'}, 'signingCertsSha256': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Required. This feature is not generally available.'}}, 'description': ' This feature is not generally available.'}, 'StatusReportingSettings': {'type': 'object', 'properties': {'memoryInfoEnabled': {'type': 'boolean', 'description': 'Whether [memory event](/android/management/reference/rest/v1/enterprises.devices#memoryevent) reporting is enabled.'}, 'displayInfoEnabled': {'type': 'boolean', 'description': 'Whether [displays](/android/management/reference/rest/v1/enterprises.devices#display) reporting is enabled. Report data is not available for personally owned devices with work profiles.'}, 'networkInfoEnabled': {'type': 'boolean', 'description': 'Whether [network info](/android/management/reference/rest/v1/enterprises.devices#networkinfo) reporting is enabled.'}, 'softwareInfoEnabled': {'type': 'boolean', 'description': 'Whether [software info](/android/management/reference/rest/v1/enterprises.devices#softwareinfo) reporting is enabled.'}, 'deviceSettingsEnabled': {'type': 'boolean', 'description': 'Whether [device settings](/android/management/reference/rest/v1/enterprises.devices#devicesettings) reporting is enabled.'}, 'hardwareStatusEnabled': {'type': 'boolean', 'description': 'Whether [hardware status](/android/management/reference/rest/v1/enterprises.devices#hardwarestatus) reporting is enabled. Report data is not available for personally owned devices with work profiles.'}, 'systemPropertiesEnabled': {'type': 'boolean', 'description': 'Whether system properties reporting is enabled.'}, 'applicationReportsEnabled': {'type': 'boolean', 'description': 'Whether [app reports](/android/management/reference/rest/v1/enterprises.devices#applicationreport) are enabled.'}, 'commonCriteriaModeEnabled': {'type': 'boolean', 'description': 'Whether Common Criteria Mode reporting is enabled. This is supported only on company-owned devices.'}, 'applicationReportingSettings': {'$ref': '#/$defs/ApplicationReportingSettings', 'description': 'Application reporting settings. Only applicable if application_reports_enabled is true.'}, 'powerManagementEventsEnabled': {'type': 'boolean', 'description': 'Whether [power management event](/android/management/reference/rest/v1/enterprises.devices#powermanagementevent) reporting is enabled. Report data is not available for personally owned devices with work profiles.'}, 'defaultApplicationInfoReportingEnabled': {'type': 'boolean', 'description': 'Optional. Whether `defaultApplicationInfo` reporting is enabled.'}}, 'description': 'Settings controlling the behavior of status reports.'}, 'ScreenBrightnessSettings': {'type': 'object', 'properties': {'screenBrightness': {'type': 'integer', 'format': 'int32', 'description': 'Optional. The screen brightness between 1 and 255 where 1 is the lowest and 255 is the highest brightness. A value of 0 (default) means no screen brightness set. Any other value is rejected. `screenBrightnessMode` must be either `BRIGHTNESS_AUTOMATIC` or `BRIGHTNESS_FIXED` to set this. Supported on Android 9 and above on fully managed devices. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 9. Supported on work profiles on company-owned devices on Android 15 and above.'}, 'screenBrightnessMode': {'enum': ['SCREEN_BRIGHTNESS_MODE_UNSPECIFIED', 'BRIGHTNESS_USER_CHOICE', 'BRIGHTNESS_AUTOMATIC', 'BRIGHTNESS_FIXED'], 'type': 'string', 'description': 'Optional. Controls the screen brightness mode.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `BRIGHTNESS_USER_CHOICE`.', 'The user is allowed to configure the screen brightness. `screenBrightness` must not be set.', 'The screen brightness mode is automatic in which the brightness is automatically adjusted and the user is not allowed to configure the screen brightness. `screenBrightness` can still be set and it is taken into account while the brightness is automatically adjusted. Supported on Android 9 and above on fully managed devices. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 9. Supported on work profiles on company-owned devices on Android 15 and above.', 'The screen brightness mode is fixed in which the brightness is set to `screenBrightness` and the user is not allowed to configure the screen brightness. `screenBrightness` must be set. Supported on Android 9 and above on fully managed devices. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 9. Supported on work profiles on company-owned devices on Android 15 and above.']}}, 'description': 'Controls for the screen brightness settings.'}, 'AdvancedSecurityOverrides': {'type': 'object', 'properties': {'mtePolicy': {'enum': ['MTE_POLICY_UNSPECIFIED', 'MTE_USER_CHOICE', 'MTE_ENFORCED', 'MTE_DISABLED'], 'type': 'string', 'description': 'Optional. Controls [Memory Tagging Extension (MTE)](https://source.android.com/docs/security/test/memory-safety/arm-mte) on the device. The device needs to be rebooted to apply changes to the MTE policy. On Android 15 and above, a `NonComplianceDetail` with `PENDING` is reported if the policy change is pending a device reboot.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `MTE_USER_CHOICE`.', 'The user can choose to enable or disable MTE on the device if the device supports this.', 'MTE is enabled on the device and the user is not allowed to change this setting. This can be set on fully managed devices and work profiles on company-owned devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for other management modes. A `NonComplianceDetail` with `DEVICE_INCOMPATIBLE` is reported if the device does not support MTE. Supported on Android 14 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 14.', 'MTE is disabled on the device and the user is not allowed to change this setting. This applies only on fully managed devices. In other cases, a `NonComplianceDetail` with `MANAGEMENT_MODE` is reported. A `NonComplianceDetail` with `DEVICE_INCOMPATIBLE` is reported if the device does not support MTE. Supported on Android 14 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 14.']}, 'developerSettings': {'enum': ['DEVELOPER_SETTINGS_UNSPECIFIED', 'DEVELOPER_SETTINGS_DISABLED', 'DEVELOPER_SETTINGS_ALLOWED'], 'type': 'string', 'description': 'Optional. Controls access to developer settings: developer options and safe boot. Replaces `safeBootDisabled` (deprecated) and `debuggingFeaturesAllowed` (deprecated). On personally-owned devices with a work profile, setting this policy will not disable safe boot. In this case, a `NonComplianceDetail` with `MANAGEMENT_MODE` is reported.', 'x-google-enum-descriptions': ['Unspecified. Defaults to DEVELOPER_SETTINGS_DISABLED.', 'Default. Disables all developer settings and prevents the user from accessing them.', 'Allows all developer settings. The user can access and optionally configure the settings.']}, 'commonCriteriaMode': {'enum': ['COMMON_CRITERIA_MODE_UNSPECIFIED', 'COMMON_CRITERIA_MODE_DISABLED', 'COMMON_CRITERIA_MODE_ENABLED'], 'type': 'string', 'description': 'Optional. Controls Common Criteria Mode—security standards defined in the [Common Criteria for Information Technology Security Evaluation](https://www.commoncriteriaportal.org/) (CC). Enabling Common Criteria Mode increases certain security components on a device, see `CommonCriteriaMode` for details. Warning: Common Criteria Mode enforces a strict security model typically only required for IT products used in national security systems and other highly sensitive organizations. Standard device use may be affected. Only enabled if required. If Common Criteria Mode is turned off after being enabled previously, all user-configured Wi-Fi networks may be lost and any enterprise-configured Wi-Fi networks that require user input may need to be reconfigured.', 'x-google-enum-descriptions': ['Unspecified. Defaults to COMMON_CRITERIA_MODE_DISABLED.', 'Default. Disables Common Criteria Mode.', 'Enables Common Criteria Mode.']}, 'untrustedAppsPolicy': {'enum': ['UNTRUSTED_APPS_POLICY_UNSPECIFIED', 'DISALLOW_INSTALL', 'ALLOW_INSTALL_IN_PERSONAL_PROFILE_ONLY', 'ALLOW_INSTALL_DEVICE_WIDE'], 'type': 'string', 'description': 'Optional. The policy for untrusted apps (apps from unknown sources) enforced on the device. Replaces `install_unknown_sources_allowed (deprecated).`', 'x-google-enum-descriptions': ['Unspecified. Defaults to DISALLOW_INSTALL.', 'Default. Disallow untrusted app installs on entire device.', "For devices with work profiles, allow untrusted app installs in the device's personal profile only.", 'Allow untrusted app installs on entire device.']}, 'contentProtectionPolicy': {'enum': ['CONTENT_PROTECTION_POLICY_UNSPECIFIED', 'CONTENT_PROTECTION_DISABLED', 'CONTENT_PROTECTION_ENFORCED', 'CONTENT_PROTECTION_USER_CHOICE'], 'type': 'string', 'description': 'Optional. Controls whether content protection, which scans for deceptive apps, is enabled. This is supported on Android 15 and above.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `CONTENT_PROTECTION_DISABLED`.', 'Content protection is disabled and the user cannot change this.', 'Content protection is enabled and the user cannot change this. Supported on Android 15 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 15.', 'Content protection is not controlled by the policy. The user is allowed to choose the behavior of content protection. Supported on Android 15 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 15.']}, 'googlePlayProtectVerifyApps': {'enum': ['GOOGLE_PLAY_PROTECT_VERIFY_APPS_UNSPECIFIED', 'VERIFY_APPS_ENFORCED', 'VERIFY_APPS_USER_CHOICE'], 'type': 'string', 'description': 'Optional. Whether [Google Play Protect verification](https://support.google.com/accounts/answer/2812853) is enforced. Replaces `ensureVerifyAppsEnabled` (deprecated).', 'x-google-enum-descriptions': ['Unspecified. Defaults to VERIFY_APPS_ENFORCED.', 'Default. Force-enables app verification.', 'Allows the user to choose whether to enable app verification.']}, 'personalAppsThatCanReadWorkNotifications': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Optional. Personal apps that can read work profile notifications using a [NotificationListenerService](https://developer.android.com/reference/android/service/notification/NotificationListenerService). By default, no personal apps (aside from system apps) can read work notifications. Each value in the list must be a package name.'}}, 'description': 'Advanced security settings. In most cases, setting these is not needed.'}, 'ApplicationSigningKeyCert': {'type': 'object', 'properties': {'signingKeyCertFingerprintSha256': {'type': 'string', 'format': 'byte', 'description': 'Required. The SHA-256 hash value of the signing key certificate of the app. This must be a valid SHA-256 hash value, i.e. 32 bytes.'}}, 'description': 'The application signing key certificate.'}, 'DefaultApplicationSetting': {'type': 'object', 'properties': {'defaultApplications': {'type': 'array', 'items': {'$ref': '#/$defs/DefaultApplication'}, 'description': 'Required. The list of applications that can be set as the default app for a given type. This list must not be empty or contain duplicates. The first app in the list that is installed and qualified for the `defaultApplicationType` (e.g. SMS app for `DEFAULT_SMS`) is set as the default app. The signing key certificate fingerprint of the app on the device must also match one of the signing key certificate fingerprints obtained from Play Store or one of the entries in `ApplicationPolicy.signingKeyCerts` in order to be set as the default. If the `defaultApplicationScopes` contains `SCOPE_FULLY_MANAGED` or `SCOPE_WORK_PROFILE`, the app must have an entry in `applications` with `installType` set to a value other than `BLOCKED`. A `NonComplianceDetail` with `APP_NOT_INSTALLED` reason and `DEFAULT_APPLICATION_SETTING_FAILED_FOR_SCOPE` specific reason is reported if *none* of the apps in the list are installed. A `NonComplianceDetail` with `INVALID_VALUE` reason and `DEFAULT_APPLICATION_SETTING_FAILED_FOR_SCOPE` specific reason is reported if at least one app is installed but the policy fails to apply due to other reasons (e.g. the app is not of the right type). When applying to `SCOPE_PERSONAL_PROFILE` on a company-owned device with a work profile, only pre-installed system apps can be set as the default. A `NonComplianceDetail` with `INVALID_VALUE` reason and `DEFAULT_APPLICATION_SETTING_FAILED_FOR_SCOPE` specific reason is reported if the policy fails to apply to the personal profile.'}, 'defaultApplicationType': {'enum': ['DEFAULT_APPLICATION_TYPE_UNSPECIFIED', 'DEFAULT_ASSISTANT', 'DEFAULT_BROWSER', 'DEFAULT_CALL_REDIRECTION', 'DEFAULT_CALL_SCREENING', 'DEFAULT_DIALER', 'DEFAULT_HOME', 'DEFAULT_SMS', 'DEFAULT_WALLET'], 'type': 'string', 'description': 'Required. The app type to set the default application.', 'x-google-enum-descriptions': ['Unspecified. This value must not be used.', 'The assistant app type. This app type is only allowed to be set for `SCOPE_FULLY_MANAGED`. Supported on fully managed devices on Android 16 and above. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for other management modes. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 16.', 'The browser app type. Supported on Android 16 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 16.', 'The call redirection app type. This app type cannot be set for `SCOPE_PERSONAL_PROFILE`. Supported on Android 16 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 16.', 'The call screening app type. This app type cannot be set for `SCOPE_PERSONAL_PROFILE`. Supported on Android 16 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 16.', 'The dialer app type. Supported on fully managed devices on Android 14 and 15. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for other management modes. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 14. Supported on all management modes on Android 16 and above.', 'The home app type. This app type is only allowed to be set for `SCOPE_FULLY_MANAGED`. Supported on fully managed devices on Android 16 and above. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for other management modes. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 16.', 'The SMS app type. This app type cannot be set for `SCOPE_WORK_PROFILE`. Supported on company-owned devices on Android 16 and above. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for personally-owned devices. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 16.', 'The wallet app type. The default application of this type applies across profiles. On a company-owned device with a work profile, admins can set the scope to `SCOPE_PERSONAL_PROFILE` to set a personal profile pre-installed system app as the default, or to `SCOPE_WORK_PROFILE` to set a work profile app as the default. It is not allowed to specify both scopes at the same time. Due to a known issue, the user may be able to change the default wallet even when this is set on a fully managed device. Supported on company-owned devices on Android 16 and above. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for personally-owned devices. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 16.']}, 'defaultApplicationScopes': {'type': 'array', 'items': {'enum': ['DEFAULT_APPLICATION_SCOPE_UNSPECIFIED', 'SCOPE_FULLY_MANAGED', 'SCOPE_WORK_PROFILE', 'SCOPE_PERSONAL_PROFILE'], 'type': 'string', 'x-google-enum-descriptions': ['Unspecified. This value must not be used.', 'Sets the application as the default on fully managed devices.', 'Sets the application as the work profile default. Only supported for `DEFAULT_BROWSER`, `DEFAULT_CALL_REDIRECTION`, `DEFAULT_CALL_SCREENING`, `DEFAULT_DIALER` and `DEFAULT_WALLET`.', 'Sets the application as the personal profile default on company-owned devices with a work profile. Only pre-installed system apps can be set as the default. Only supported for `DEFAULT_BROWSER`, `DEFAULT_DIALER`, `DEFAULT_SMS` and `DEFAULT_WALLET`.']}, 'description': 'Required. The scopes to which the policy should be applied. This list must not be empty or contain duplicates. A `NonComplianceDetail` with `MANAGEMENT_MODE` reason and `DEFAULT_APPLICATION_SETTING_UNSUPPORTED_SCOPES` specific reason is reported if *none* of the specified scopes can be applied to the management mode (e.g. a fully managed device receives a policy with only `SCOPE_PERSONAL_PROFILE` in the list).'}}, 'description': 'The default application setting for a `DefaultApplicationType`.'}, 'PersonalApplicationPolicy': {'type': 'object', 'properties': {'installType': {'enum': ['INSTALL_TYPE_UNSPECIFIED', 'BLOCKED', 'AVAILABLE'], 'type': 'string', 'description': 'The type of installation to perform.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `AVAILABLE`.', "The app is blocked and can't be installed in the personal profile. If the app was previously installed in the device, it will be uninstalled.", 'The app is available to install in the personal profile.']}, 'packageName': {'type': 'string', 'description': 'The package name of the application.'}}, 'description': 'Policies for apps in the personal profile of a company-owned device with a work profile.'}, 'PersistentPreferredActivity': {'type': 'object', 'properties': {'actions': {'type': 'array', 'items': {'type': 'string'}, 'description': "The intent actions to match in the filter. If any actions are included in the filter, then an intent's action must be one of those values for it to match. If no actions are included, the intent action is ignored."}, 'categories': {'type': 'array', 'items': {'type': 'string'}, 'description': 'The intent categories to match in the filter. An intent includes the categories that it requires, all of which must be included in the filter in order to match. In other words, adding a category to the filter has no impact on matching unless that category is specified in the intent.'}, 'receiverActivity': {'type': 'string', 'description': 'The activity that should be the default intent handler. This should be an Android component name, e.g. `com.android.enterprise.app/.MainActivity`. Alternatively, the value may be the package name of an app, which causes Android Device Policy to choose an appropriate activity from the app to handle the intent.'}}, 'description': 'A default activity for handling intents that match a particular intent filter. **Note:** To set up a kiosk, use [InstallType](/android/management/reference/rest/v1/enterprises.policies#installtype) to `KIOSK` rather than use persistent preferred activities.'}, 'PersonalCrossDevicePolicies': {'type': 'object', 'properties': {'taskContinuityHandoff': {'enum': ['TASK_CONTINUITY_HANDOFF_UNSPECIFIED', 'TASK_CONTINUITY_HANDOFF_ALLOWED', 'TASK_CONTINUITY_HANDOFF_DISALLOWED'], 'type': 'string', 'description': 'Optional. Controls the [task continuity handoff](https://developer.android.com/partners/android-17/features#handoff) feature for the personal profile on company-owned devices with a work profile. To disable Handoff device-wide on a company-owned device, both `crossDevicePolicies.taskContinuityHandoff` and this policy should be set to `TASK_CONTINUITY_HANDOFF_DISALLOWED`. Requires Android 17 QPR1 or higher.', 'x-google-enum-descriptions': ['Defaults to `TASK_CONTINUITY_HANDOFF_ALLOWED`.', 'Allows the user to enable or disable the task continuity handoff feature in settings. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is lower than Android 17 QPR1.', 'The task continuity handoff feature is disallowed. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is lower than Android 17 QPR1.']}}, 'description': 'Policies controlling cross-device communication in the personal profile.'}, 'ApplicationReportingSettings': {'type': 'object', 'properties': {'includeRemovedApps': {'type': 'boolean', 'description': 'Whether removed apps are included in application reports.'}}, 'description': 'Settings controlling the behavior of application reports.'}, 'DeviceConnectivityManagement': {'type': 'object', 'properties': {'apnPolicy': {'$ref': '#/$defs/ApnPolicy', 'description': 'Optional. Access Point Name (APN) policy. Configuration for Access Point Names (APNs) which may override any other APNs on the device. See `OVERRIDE_APNS_ENABLED` and `overrideApns` for details.'}, 'configureWifi': {'enum': ['CONFIGURE_WIFI_UNSPECIFIED', 'ALLOW_CONFIGURING_WIFI', 'DISALLOW_ADD_WIFI_CONFIG', 'DISALLOW_CONFIGURING_WIFI'], 'type': 'string', 'description': 'Controls Wi-Fi configuring privileges. Based on the option set, user will have either full or limited or no control in configuring Wi-Fi networks.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `ALLOW_CONFIGURING_WIFI` unless `wifiConfigDisabled` is set to true. If `wifiConfigDisabled` is set to true, this is equivalent to `DISALLOW_CONFIGURING_WIFI`.', 'The user is allowed to configure Wi-Fi. `wifiConfigDisabled` is ignored.', 'Adding new Wi-Fi configurations is disallowed. The user is only able to switch between already configured networks. Supported on Android 13 and above, on fully managed devices and work profiles on company-owned devices. If the setting is not supported, `ALLOW_CONFIGURING_WIFI` is set. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 13. `wifiConfigDisabled` is ignored.', "Disallows configuring Wi-Fi networks. The setting `wifiConfigDisabled` is ignored when this value is set. Supported on fully managed devices and work profile on company-owned devices, on all supported API levels. For fully managed devices, setting this removes all configured networks and retains only the networks configured using `openNetworkConfiguration` policy. For work profiles on company-owned devices, existing configured networks are not affected and the user is not allowed to add, remove, or modify Wi-Fi networks. **Note:** If a network connection can't be made at boot time and configuring Wi-Fi is disabled then network escape hatch will be shown in order to refresh the device policy (see `networkEscapeHatchEnabled`)."]}, 'usbDataAccess': {'enum': ['USB_DATA_ACCESS_UNSPECIFIED', 'ALLOW_USB_DATA_TRANSFER', 'DISALLOW_USB_FILE_TRANSFER', 'DISALLOW_USB_DATA_TRANSFER'], 'type': 'string', 'description': 'Controls what files and/or data can be transferred via USB. Supported only on company-owned devices.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `DISALLOW_USB_FILE_TRANSFER`.', 'All types of USB data transfers are allowed. `usbFileTransferDisabled` is ignored.', 'Transferring files over USB is disallowed. Other types of USB data connections, such as mouse and keyboard connection, are allowed. `usbFileTransferDisabled` is ignored.', 'When set, all types of USB data transfers are prohibited. Supported for devices running Android 12 or above with USB HAL 1.3 or above. If the setting is not supported, `DISALLOW_USB_FILE_TRANSFER` will be set. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 12. A `NonComplianceDetail` with `DEVICE_INCOMPATIBLE` is reported if the device does not have USB HAL 1.3 or above. `usbFileTransferDisabled` is ignored.']}, 'wifiSsidPolicy': {'$ref': '#/$defs/WifiSsidPolicy', 'description': 'Restrictions on which Wi-Fi SSIDs the device can connect to. Note that this does not affect which networks can be configured on the device. Supported on company-owned devices running Android 13 and above.'}, 'bluetoothSharing': {'enum': ['BLUETOOTH_SHARING_UNSPECIFIED', 'BLUETOOTH_SHARING_ALLOWED', 'BLUETOOTH_SHARING_DISALLOWED'], 'type': 'string', 'description': 'Optional. Controls whether Bluetooth sharing is allowed.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `BLUETOOTH_SHARING_DISALLOWED` on work profiles and `BLUETOOTH_SHARING_ALLOWED` on fully managed devices.', 'Bluetooth sharing is allowed. Supported on Android 8 and above. A `NonComplianceDetail` with `API_LEVEL` is reported on work profiles if the Android version is less than 8.', 'Bluetooth sharing is disallowed. Supported on Android 8 and above. A `NonComplianceDetail` with `API_LEVEL` is reported on fully managed devices if the Android version is less than 8.']}, 'tetheringSettings': {'enum': ['TETHERING_SETTINGS_UNSPECIFIED', 'ALLOW_ALL_TETHERING', 'DISALLOW_WIFI_TETHERING', 'DISALLOW_ALL_TETHERING'], 'type': 'string', 'description': 'Controls tethering settings. Based on the value set, the user is partially or fully disallowed from using different forms of tethering.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `ALLOW_ALL_TETHERING` unless `tetheringConfigDisabled` is set to true. If `tetheringConfigDisabled` is set to true, this is equivalent to `DISALLOW_ALL_TETHERING`.', 'Allows configuration and use of all forms of tethering. `tetheringConfigDisabled` is ignored.', 'Disallows the user from using Wi-Fi tethering. Supported on company owned devices running Android 13 and above. If the setting is not supported, `ALLOW_ALL_TETHERING` will be set. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 13. `tetheringConfigDisabled` is ignored.', 'Disallows all forms of tethering. Supported on fully managed devices and work profile on company-owned devices, on all supported android versions. The setting `tetheringConfigDisabled` is ignored.']}, 'wifiRoamingPolicy': {'$ref': '#/$defs/WifiRoamingPolicy', 'description': 'Optional. Wi-Fi roaming policy.'}, 'privateDnsSettings': {'$ref': '#/$defs/PrivateDnsSettings', 'description': 'Optional. The global private DNS settings.'}, 'wifiDirectSettings': {'enum': ['WIFI_DIRECT_SETTINGS_UNSPECIFIED', 'ALLOW_WIFI_DIRECT', 'DISALLOW_WIFI_DIRECT'], 'type': 'string', 'description': 'Controls configuring and using Wi-Fi direct settings. Supported on company-owned devices running Android 13 and above.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `ALLOW_WIFI_DIRECT`', 'The user is allowed to use Wi-Fi direct.', 'The user is not allowed to use Wi-Fi direct. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 13.']}, 'preferentialNetworkServiceSettings': {'$ref': '#/$defs/PreferentialNetworkServiceSettings', 'description': 'Optional. Preferential network service configuration. Setting this field will override `preferentialNetworkService`. This can be set on both work profiles and fully managed devices on Android 13 and above. See [5G network slicing](https://developers.google.com/android/management/5g-network-slicing) guide for more details.'}}, 'description': 'Covers controls for device connectivity such as Wi-Fi, USB data access, keyboard/mouse connections, and more.'}, 'ManagedConfigurationTemplate': {'type': 'object', 'properties': {'templateId': {'type': 'string', 'description': 'The ID of the managed configurations template. This value must be a numeric string containing exactly one or more digits (for example, `"123456"`).'}, 'configurationVariables': {'type': 'object', 'description': 'Optional, a map containing configuration variables defined for the configuration.', 'additionalProperties': {'type': 'string'}}}, 'description': 'The managed configurations template for the app, saved from the [managed configurations iframe](/android/management/managed-configurations-iframe).'}, 'NonComplianceDetailCondition': {'type': 'object', 'properties': {'packageName': {'type': 'string', 'description': "The package name of the app that's out of compliance. If not set, then this condition matches any package name."}, 'settingName': {'type': 'string', 'description': 'The name of the policy setting. This is the JSON field name of a top-level [`Policy`](/android/management/reference/rest/v1/enterprises.policies#Policy) field. If not set, then this condition matches any setting name.'}, 'nonComplianceReason': {'enum': ['NON_COMPLIANCE_REASON_UNSPECIFIED', 'API_LEVEL', 'MANAGEMENT_MODE', 'USER_ACTION', 'INVALID_VALUE', 'APP_NOT_INSTALLED', 'UNSUPPORTED', 'APP_INSTALLED', 'PENDING', 'APP_INCOMPATIBLE', 'APP_NOT_UPDATED', 'DEVICE_INCOMPATIBLE', 'APP_SIGNING_CERT_MISMATCH', 'PROJECT_NOT_PERMITTED'], 'type': 'string', 'description': 'The reason the device is not in compliance with the setting. If not set, then this condition matches any reason.', 'x-google-enum-descriptions': ['This value is not used.', 'The setting is not supported in the API level of the Android version running on the device.', "The management mode (such as fully managed or work profile) doesn't support the setting.", 'The user has not taken required action to comply with the setting.', 'The setting has an invalid value.', 'The app required to implement the policy is not installed.', 'The policy is not supported by the version of Android Device Policy on the device.', 'A blocked app is installed.', "The setting hasn't been applied at the time of the report, but is expected to be applied shortly.", "The setting can't be applied to the app because the app doesn't support it, for example because its target SDK version is not high enough.", "The app is installed, but it hasn't been updated to the minimum version code specified by policy.", 'The device is incompatible with the policy requirements.', "The app's signing certificate does not match the setting value.", 'The Google Cloud Platform project used to manage the device is not permitted to use this policy.']}}, 'description': 'A compliance rule condition which is satisfied if there exists *any* matching [`NonComplianceDetail`](/android/management/reference/rest/v1/enterprises.devices#NonComplianceDetail) for the device. A `NonComplianceDetail` matches a `NonComplianceDetailCondition` if *all* the fields which are set within the `NonComplianceDetailCondition` match the corresponding `NonComplianceDetail` fields.'}, 'PreferentialNetworkServiceConfig': {'type': 'object', 'properties': {'nonMatchingNetworks': {'enum': ['NON_MATCHING_NETWORKS_UNSPECIFIED', 'NON_MATCHING_NETWORKS_ALLOWED', 'NON_MATCHING_NETWORKS_DISALLOWED'], 'type': 'string', 'description': 'Optional. Whether apps this configuration applies to are blocked from using networks other than the preferential service. If this is set to `NON_MATCHING_NETWORKS_DISALLOWED`, then `fallbackToDefaultConnection` must be set to `FALLBACK_TO_DEFAULT_CONNECTION_DISALLOWED`.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `NON_MATCHING_NETWORKS_ALLOWED`.', 'Apps this configuration applies to are allowed to use networks other than the preferential service.', 'Apps this configuration applies to are disallowed from using other networks than the preferential service. This can be set on Android 14 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 14. If this is set, `fallbackToDefaultConnection` must be set to `FALLBACK_TO_DEFAULT_CONNECTION_DISALLOWED`, the policy will be rejected otherwise.']}, 'preferentialNetworkId': {'enum': ['PREFERENTIAL_NETWORK_ID_UNSPECIFIED', 'NO_PREFERENTIAL_NETWORK', 'PREFERENTIAL_NETWORK_ID_ONE', 'PREFERENTIAL_NETWORK_ID_TWO', 'PREFERENTIAL_NETWORK_ID_THREE', 'PREFERENTIAL_NETWORK_ID_FOUR', 'PREFERENTIAL_NETWORK_ID_FIVE'], 'type': 'string', 'description': 'Required. Preferential network identifier. This must not be set to `NO_PREFERENTIAL_NETWORK` or `PREFERENTIAL_NETWORK_ID_UNSPECIFIED`, the policy will be rejected otherwise.', 'x-google-enum-descriptions': ['Whether this value is valid and what it means depends on where it is used, and this is documented on the relevant fields.', 'Application does not use any preferential network.', 'Preferential network identifier 1.', 'Preferential network identifier 2.', 'Preferential network identifier 3.', 'Preferential network identifier 4.', 'Preferential network identifier 5.']}, 'fallbackToDefaultConnection': {'enum': ['FALLBACK_TO_DEFAULT_CONNECTION_UNSPECIFIED', 'FALLBACK_TO_DEFAULT_CONNECTION_ALLOWED', 'FALLBACK_TO_DEFAULT_CONNECTION_DISALLOWED'], 'type': 'string', 'description': 'Optional. Whether fallback to the device-wide default network is allowed. If this is set to `FALLBACK_TO_DEFAULT_CONNECTION_ALLOWED`, then `nonMatchingNetworks` must not be set to `NON_MATCHING_NETWORKS_DISALLOWED`, the policy will be rejected otherwise. Note: If this is set to `FALLBACK_TO_DEFAULT_CONNECTION_DISALLOWED`, applications are not able to access the internet if the 5G slice is not available.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `FALLBACK_TO_DEFAULT_CONNECTION_ALLOWED`.', 'Fallback to default connection is allowed. If this is set, `nonMatchingNetworks` must not be set to `NON_MATCHING_NETWORKS_DISALLOWED`, the policy will be rejected otherwise.', 'Fallback to default connection is not allowed.']}}, 'description': 'Individual preferential network service configuration.'}, 'PreferentialNetworkServiceSettings': {'type': 'object', 'properties': {'defaultPreferentialNetworkId': {'enum': ['PREFERENTIAL_NETWORK_ID_UNSPECIFIED', 'NO_PREFERENTIAL_NETWORK', 'PREFERENTIAL_NETWORK_ID_ONE', 'PREFERENTIAL_NETWORK_ID_TWO', 'PREFERENTIAL_NETWORK_ID_THREE', 'PREFERENTIAL_NETWORK_ID_FOUR', 'PREFERENTIAL_NETWORK_ID_FIVE'], 'type': 'string', 'description': 'Required. Default preferential network ID for the applications that are not in `applications` or if `ApplicationPolicy.preferentialNetworkId` is set to `PREFERENTIAL_NETWORK_ID_UNSPECIFIED`. There must be a configuration for the specified network ID in `preferentialNetworkServiceConfigs`, unless this is set to `NO_PREFERENTIAL_NETWORK`. If set to `PREFERENTIAL_NETWORK_ID_UNSPECIFIED` or unset, this defaults to `NO_PREFERENTIAL_NETWORK`. Note: If the default preferential network is misconfigured, applications with no `ApplicationPolicy.preferentialNetworkId` set are not able to access the internet. This setting does not apply to the following critical apps: * `com.google.android.apps.work.clouddpc` * `com.google.android.gms` `ApplicationPolicy.preferentialNetworkId` can still be used to configure the preferential network for them.', 'x-google-enum-descriptions': ['Whether this value is valid and what it means depends on where it is used, and this is documented on the relevant fields.', 'Application does not use any preferential network.', 'Preferential network identifier 1.', 'Preferential network identifier 2.', 'Preferential network identifier 3.', 'Preferential network identifier 4.', 'Preferential network identifier 5.']}, 'preferentialNetworkServiceConfigs': {'type': 'array', 'items': {'$ref': '#/$defs/PreferentialNetworkServiceConfig'}, 'description': 'Required. Preferential network service configurations which enables having multiple enterprise slices. There must not be multiple configurations with the same `preferentialNetworkId`. If a configuration is not referenced by any application by setting `ApplicationPolicy.preferentialNetworkId` or by setting `defaultPreferentialNetworkId`, it will be ignored. For devices on 4G networks, enterprise APN needs to be configured additionally to set up data call for preferential network service. These APNs can be added using `apnPolicy`.'}}, 'description': 'Preferential network service settings.'}}, 'properties': {'name': {'type': 'string', 'description': 'The name of the policy in the form `enterprises/{enterpriseId}/policies/{policyId}`.'}, 'version': {'type': 'string', 'format': 'int64', 'description': 'The version of the policy. This is a read-only field. The version is incremented each time the policy is updated.'}, 'usageLog': {'$ref': '#/$defs/UsageLog', 'description': 'Configuration of device activity logging.'}, 'funDisabled': {'type': 'boolean', 'description': 'Whether the user is allowed to have fun. Controls whether the Easter egg game in Settings is disabled.'}, 'smsDisabled': {'type': 'boolean', 'description': 'Whether sending and receiving SMS messages is disabled.'}, 'appFunctions': {'enum': ['APP_FUNCTIONS_UNSPECIFIED', 'APP_FUNCTIONS_DISALLOWED', 'APP_FUNCTIONS_ALLOWED'], 'type': 'string', 'description': 'Optional. Controls whether apps on the device for fully managed devices or in the work profile for devices with work profiles are allowed to expose app functions.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `APP_FUNCTIONS_ALLOWED`.', 'Apps on the device for fully managed devices or in the work profile for devices with work profiles are not allowed to expose app functions. If this is set, `crossProfileAppFunctions` must not be set to `CROSS_PROFILE_APP_FUNCTIONS_ALLOWED`, otherwise the policy will be rejected.', 'Apps on the device for fully managed devices or in the work profile for devices with work profiles are allowed to expose app functions.']}, 'applications': {'type': 'array', 'items': {'$ref': '#/$defs/ApplicationPolicy'}, 'description': 'Policy applied to apps. This can have at most 3,000 elements.'}, 'cameraAccess': {'enum': ['CAMERA_ACCESS_UNSPECIFIED', 'CAMERA_ACCESS_USER_CHOICE', 'CAMERA_ACCESS_DISABLED', 'CAMERA_ACCESS_ENFORCED'], 'type': 'string', 'description': 'Controls the use of the camera and whether the user has access to the camera access toggle.', 'x-google-enum-descriptions': ['If `camera_disabled` is true, this is equivalent to `CAMERA_ACCESS_DISABLED`. Otherwise, this is equivalent to `CAMERA_ACCESS_USER_CHOICE`.', 'The field `camera_disabled` is ignored. This is the default device behaviour: all cameras on the device are available. On Android 12 and above, the user can use the camera access toggle.', 'The field `camera_disabled` is ignored. All cameras on the device are disabled (for fully managed devices, this applies device-wide and for work profiles this applies only to the work profile). There are no explicit restrictions placed on the camera access toggle on Android 12 and above: on fully managed devices, the camera access toggle has no effect as all cameras are disabled. On devices with a work profile, this toggle has no effect on apps in the work profile, but it affects apps outside the work profile.', 'The field `camera_disabled` is ignored. All cameras on the device are available. On fully managed devices running Android 12 and above, the user is unable to use the camera access toggle. On devices which are not fully managed or which run Android 11 or below, this is equivalent to `CAMERA_ACCESS_USER_CHOICE`.']}, 'locationMode': {'enum': ['LOCATION_MODE_UNSPECIFIED', 'HIGH_ACCURACY', 'SENSORS_ONLY', 'BATTERY_SAVING', 'OFF', 'LOCATION_USER_CHOICE', 'LOCATION_ENFORCED', 'LOCATION_DISABLED'], 'type': 'string', 'description': 'The degree of location detection enabled.', 'x-google-enum-deprecated': [False, True, True, True, True, False, False, False], 'x-google-enum-descriptions': ['Defaults to `LOCATION_USER_CHOICE`.', 'On Android 8 and below, all location detection methods are enabled, including GPS, networks, and other sensors. On Android 9 and above, this is equivalent to `LOCATION_ENFORCED`.', 'On Android 8 and below, only GPS and other sensors are enabled. On Android 9 and above, this is equivalent to `LOCATION_ENFORCED`.', 'On Android 8 and below, only the network location provider is enabled. On Android 9 and above, this is equivalent to `LOCATION_ENFORCED`.', 'On Android 8 and below, location setting and accuracy are disabled. On Android 9 and above, this is equivalent to `LOCATION_DISABLED`.', 'Location setting is not restricted on the device. No specific behavior is set or enforced.', "Enable location setting on the device. **Important:** On Android 11 and above, work profiles on company-owned devices cannot directly enforce enabling of location services. When `LOCATION_ENFORCED` is set, then a `NonComplianceDetail` with `USER_ACTION` is reported. Compliance can only be restored once the user manually turns on location services through the device's Settings application. ", "Disable location setting on the device. **Important:** On Android 11 and above, work profiles on company-owned devices cannot directly enforce disabling of location services. When `LOCATION_DISABLED` is set, then a `nonComplianceDetail` with `USER_ACTION` is reported. Compliance can only be restored once the user manually turns off location services through the device's Settings application. "]}, 'setupActions': {'type': 'array', 'items': {'$ref': '#/$defs/SetupAction'}, 'description': 'Action to take during the setup process. At most one action may be specified.'}, 'systemUpdate': {'$ref': '#/$defs/SystemUpdate', 'description': 'The system update policy, which controls how OS updates are applied. If the update type is `WINDOWED`, the update window will automatically apply to Play app updates as well. **Note:** [Google Play system updates](https://source.android.com/docs/core/ota/modular-system) (also called Mainline updates) are automatically downloaded and require a device reboot to be installed. Refer to the mainline section in [Manage system updates](https://developer.android.com/work/dpc/system-updates#mainline) for further details.'}, 'backupService': {'enum': ['BACKUP_SERVICE_UNSPECIFIED', 'BACKUP_SERVICE_DISABLED', 'BACKUP_SERVICE_USER_CHOICE'], 'type': 'string', 'description': 'Optional. Controls whether the backup service is disabled. Supported only on fully managed devices running Android 8 and above.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `BACKUP_SERVICE_DISABLED`.', 'Backup service is disabled. The user is not allowed to change this setting. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 8 on a fully managed device.', 'The user can enable or disable the backup service. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 8 on a fully managed device.']}, 'playStoreMode': {'enum': ['PLAY_STORE_MODE_UNSPECIFIED', 'WHITELIST', 'BLACKLIST'], 'type': 'string', 'description': 'This mode controls which apps are available to the user in the Play Store and the behavior on the device when apps are removed from the policy.', 'x-google-enum-descriptions': ['Unspecified. Defaults to WHITELIST.', 'Only apps that are in the policy are available and any app not in the policy will be automatically uninstalled from the device.', "All apps are available and any app that should not be on the device should be explicitly marked as 'BLOCKED' in the `applications` policy."]}, 'wipeDataFlags': {'type': 'array', 'items': {'enum': ['WIPE_DATA_FLAG_UNSPECIFIED', 'WIPE_ESIMS'], 'type': 'string', 'x-google-enum-descriptions': ['This value must not be used.', 'For company-owned devices, setting this in `wipeDataFlags` will remove all eSIMs on the device when wipe is triggered due to any reason. On personally-owned devices, this will remove only managed eSIMs on the device (eSIMs which are added via the `ADD_ESIM` command). This is supported on devices running Android 15 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 15. For devices running on Android 16 or higher, managed eSIMs are always wiped when work profile is removed for personally-owned devices, whether this flag is provided or not.']}, 'description': 'Optional. Wipe flags to indicate what data is wiped when a device or profile wipe is triggered due to any reason (for example, non-compliance). This does not apply to the `enterprises.devices.delete` method. . This list must not have duplicates.'}, 'autofillPolicy': {'enum': ['AUTOFILL_POLICY_UNSPECIFIED', 'AUTOFILL_USER_CHOICE', 'AUTOFILL_DISABLED'], 'type': 'string', 'description': 'Optional. The policy for the autofill service.', 'x-google-enum-descriptions': ['Defaults to `AUTOFILL_USER_CHOICE`.', 'The user can choose and use an autofill service.', 'Autofill is disabled and the user is not allowed to change this setting. This is supported only on Android 8 and above.']}, 'cameraDisabled': {'type': 'boolean', 'deprecated': True, 'description': 'If `camera_access` is set to any value other than `CAMERA_ACCESS_UNSPECIFIED`, this has no effect. Otherwise this field controls whether cameras are disabled: If true, all cameras are disabled, otherwise they are available. For fully managed devices this field applies for all apps on the device. For work profiles, this field applies only to apps in the work profile, and the camera access of apps outside the work profile is unaffected.'}, 'frpAdminEmails': {'type': 'array', 'items': {'type': 'string'}, 'description': "Email addresses of device administrators for factory reset protection. When the device is factory reset, it will require one of these admins to log in with the Google account email and password to unlock the device. If no admins are specified, the device won't provide factory reset protection."}, 'printingPolicy': {'enum': ['PRINTING_POLICY_UNSPECIFIED', 'PRINTING_DISALLOWED', 'PRINTING_ALLOWED'], 'type': 'string', 'description': 'Optional. Controls whether printing is allowed. This is supported on devices running Android 9 and above. .', 'x-google-enum-descriptions': ['Unspecified. Defaults to `PRINTING_ALLOWED`.', 'Printing is disallowed. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 9.', 'Printing is allowed.']}, 'addUserDisabled': {'type': 'boolean', 'description': 'Whether adding new users and profiles is disabled. For devices where `managementMode` is `DEVICE_OWNER` this field is ignored and the user is never allowed to add or remove users.'}, 'complianceRules': {'type': 'array', 'items': {'$ref': '#/$defs/ComplianceRule'}, 'deprecated': True, 'description': 'Rules declaring which mitigating actions to take when a device is not compliant with its policy. When the conditions for multiple rules are satisfied, all of the mitigating actions for the rules are taken. There is a maximum limit of 100 rules. Use policy enforcement rules instead.'}, 'displaySettings': {'$ref': '#/$defs/DisplaySettings', 'description': 'Optional. Controls for the display settings.'}, 'minimumApiLevel': {'type': 'integer', 'format': 'int32', 'description': 'The minimum allowed Android API level.'}, 'autoTimeRequired': {'type': 'boolean', 'deprecated': True, 'description': 'Whether auto time is required, which prevents the user from manually setting the date and time. If [`autoDateAndTimeZone`](/android/management/reference/rest/v1/enterprises.policies#autodateandtimezone) is set, this field is ignored.'}, 'deviceRadioState': {'$ref': '#/$defs/DeviceRadioState', 'description': 'Optional. Covers controls for radio state such as Wi-Fi, bluetooth, and more.'}, 'encryptionPolicy': {'enum': ['ENCRYPTION_POLICY_UNSPECIFIED', 'ENABLED_WITHOUT_PASSWORD', 'ENABLED_WITH_PASSWORD'], 'type': 'string', 'description': 'Whether encryption is enabled', 'x-google-enum-descriptions': ['This value is ignored, i.e. no encryption required', 'Encryption required but no password required to boot', 'Encryption required with password required to boot']}, 'keyguardDisabled': {'type': 'boolean', 'description': 'If true, this disables the [Lock Screen](https://source.android.com/docs/core/display/multi_display/lock-screen) for primary and/or secondary displays. This policy is supported only in dedicated device management mode.'}, 'microphoneAccess': {'enum': ['MICROPHONE_ACCESS_UNSPECIFIED', 'MICROPHONE_ACCESS_USER_CHOICE', 'MICROPHONE_ACCESS_DISABLED', 'MICROPHONE_ACCESS_ENFORCED'], 'type': 'string', 'description': 'Controls the use of the microphone and whether the user has access to the microphone access toggle. This applies only on fully managed devices.', 'x-google-enum-descriptions': ['If `unmute_microphone_disabled` is true, this is equivalent to `MICROPHONE_ACCESS_DISABLED`. Otherwise, this is equivalent to `MICROPHONE_ACCESS_USER_CHOICE`.', 'The field `unmute_microphone_disabled` is ignored. This is the default device behaviour: the microphone on the device is available. On Android 12 and above, the user can use the microphone access toggle.', 'The field `unmute_microphone_disabled` is ignored. The microphone on the device is disabled (for fully managed devices, this applies device-wide). The microphone access toggle has no effect as the microphone is disabled.', 'The field `unmute_microphone_disabled` is ignored. The microphone on the device is available. On devices running Android 12 and above, the user is unable to use the microphone access toggle. On devices which run Android 11 or below, this is equivalent to `MICROPHONE_ACCESS_USER_CHOICE`.']}, 'passwordPolicies': {'type': 'array', 'items': {'$ref': '#/$defs/PasswordRequirements'}, 'description': 'Optional. Password requirement policies. Different policies can be set for work profile or fully managed devices by setting the `password_scope` field in the policy.'}, 'permissionGrants': {'type': 'array', 'items': {'$ref': '#/$defs/PermissionGrant'}, 'description': 'Explicit permission or group grants or denials for all apps. These values override the `default_permission_policy`.'}, 'safeBootDisabled': {'type': 'boolean', 'deprecated': True, 'description': 'Whether rebooting the device into safe boot is disabled.'}, 'bluetoothDisabled': {'type': 'boolean', 'description': 'Whether bluetooth is disabled. Prefer this setting over `bluetooth_config_disabled` because `bluetooth_config_disabled` can be bypassed by the user.'}, 'maximumTimeToLock': {'type': 'string', 'format': 'int64', 'description': 'Maximum time in milliseconds for user activity until the device locks. A value of 0 means there is no restriction.'}, 'statusBarDisabled': {'type': 'boolean', 'deprecated': True, 'description': 'Whether the status bar is disabled. This disables notifications, quick settings, and other screen overlays that allow escape from full-screen mode. DEPRECATED. To disable the status bar on a kiosk device, use [InstallType](/android/management/reference/rest/v1/enterprises.policies#installtype) `KIOSK` or `kioskCustomLauncherEnabled`.'}, 'vpnConfigDisabled': {'type': 'boolean', 'description': 'Whether configuring VPN is disabled.'}, 'alwaysOnVpnPackage': {'$ref': '#/$defs/AlwaysOnVpnPackage', 'description': 'Configuration for an always-on VPN connection. Use with `vpn_config_disabled` to prevent modification of this setting.'}, 'kioskCustomization': {'$ref': '#/$defs/KioskCustomization', 'description': 'Optional. Settings controlling the behavior of a device in kiosk mode. To enable kiosk mode, set `kioskCustomLauncherEnabled` to `true` or specify an app in the policy with `installType` `KIOSK`.'}, 'longSupportMessage': {'$ref': '#/$defs/UserFacingMessage', 'description': 'A message displayed to the user in the device administators settings screen.'}, 'removeUserDisabled': {'type': 'boolean', 'description': 'Whether removing other users is disabled.'}, 'stayOnPluggedModes': {'type': 'array', 'items': {'enum': ['BATTERY_PLUGGED_MODE_UNSPECIFIED', 'AC', 'USB', 'WIRELESS'], 'type': 'string', 'x-google-enum-descriptions': ['This value is ignored.', 'Power source is an AC charger.', 'Power source is a USB port.', 'Power source is wireless.']}, 'description': "The battery plugged in modes for which the device stays on. When using this setting, it is recommended to clear `maximum_time_to_lock` so that the device doesn't lock itself while it stays on."}, 'wifiConfigDisabled': {'type': 'boolean', 'deprecated': True, 'description': "Whether configuring Wi-Fi networks is disabled. Supported on fully managed devices and work profiles on company-owned devices. For fully managed devices, setting this to true removes all configured networks and retains only the networks configured using `openNetworkConfiguration`. For work profiles on company-owned devices, existing configured networks are not affected and the user is not allowed to add, remove, or modify Wi-Fi networks. If `configureWifi` is set to anything other than `CONFIGURE_WIFI_UNSPECIFIED`, this setting is ignored. **Note:** If a network connection can't be made at boot time and configuring Wi-Fi is disabled then network escape hatch will be shown in order to refresh the device policy (see `networkEscapeHatchEnabled`)."}, 'appAutoUpdatePolicy': {'enum': ['APP_AUTO_UPDATE_POLICY_UNSPECIFIED', 'CHOICE_TO_THE_USER', 'NEVER', 'WIFI_ONLY', 'ALWAYS'], 'type': 'string', 'description': 'Recommended alternative: `autoUpdateMode` which is set per app, provides greater flexibility around update frequency. When `autoUpdateMode` is set to `AUTO_UPDATE_POSTPONED` or `AUTO_UPDATE_HIGH_PRIORITY`, this field has no effect. The app auto update policy, which controls when automatic app updates can be applied.', 'x-google-enum-descriptions': ['The auto-update policy is not set. Equivalent to `CHOICE_TO_THE_USER`.', 'The user can control auto-updates.', 'Apps are never auto-updated.', 'Apps are auto-updated over Wi-Fi only.', 'Apps are auto-updated at any time. Data charges may apply.']}, 'assistContentPolicy': {'enum': ['ASSIST_CONTENT_POLICY_UNSPECIFIED', 'ASSIST_CONTENT_DISALLOWED', 'ASSIST_CONTENT_ALLOWED'], 'type': 'string', 'description': 'Optional. Controls whether [AssistContent](https://developer.android.com/reference/android/app/assist/AssistContent) is allowed to be sent to a privileged app such as an assistant app. AssistContent includes screenshots and information about an app, such as package name. This is supported on Android 15 and above.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `ASSIST_CONTENT_ALLOWED`.', 'Assist content is blocked from being sent to a privileged app. Supported on Android 15 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 15.', 'Assist content is allowed to be sent to a privileged app. Supported on Android 15 and above.']}, 'autoDateAndTimeZone': {'enum': ['AUTO_DATE_AND_TIME_ZONE_UNSPECIFIED', 'AUTO_DATE_AND_TIME_ZONE_USER_CHOICE', 'AUTO_DATE_AND_TIME_ZONE_ENFORCED'], 'type': 'string', 'description': 'Whether auto date, time, and time zone are enabled on a company-owned device. If this is set, then [`autoTimeRequired`](/android/management/reference/rest/v1/enterprises.policies#autoTimeRequired) is ignored.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `AUTO_DATE_AND_TIME_ZONE_USER_CHOICE`.', "Auto date, time, and time zone are left to user's choice.", 'Enforce auto date, time, and time zone on the device.']}, 'crossDevicePolicies': {'$ref': '#/$defs/CrossDevicePolicies', 'description': 'Optional. Policies controlling cross-device communication.'}, 'dataRoamingDisabled': {'type': 'boolean', 'description': 'Whether roaming data services are disabled.'}, 'installAppsDisabled': {'type': 'boolean', 'description': 'Whether user installation of apps is disabled.'}, 'setUserIconDisabled': {'type': 'boolean', 'description': 'Whether changing the user icon is disabled. This applies only on devices running Android 7 and above.'}, 'shortSupportMessage': {'$ref': '#/$defs/UserFacingMessage', 'description': 'A message displayed to the user in the settings screen wherever functionality has been disabled by the admin. If the message is longer than 200 characters it may be truncated.'}, 'adjustVolumeDisabled': {'type': 'boolean', 'description': 'Whether adjusting the master volume is disabled. Also mutes the device. The setting has effect only on fully managed devices.'}, 'crossProfilePolicies': {'$ref': '#/$defs/CrossProfilePolicies', 'description': 'Optional. Cross-profile policies applied on the device.'}, 'factoryResetDisabled': {'type': 'boolean', 'description': 'Whether factory resetting from settings is disabled.'}, 'networkResetDisabled': {'type': 'boolean', 'description': 'Whether resetting network settings is disabled. This applies only on fully managed devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for other management modes.'}, 'outgoingBeamDisabled': {'type': 'boolean', 'description': 'Whether using NFC to beam data from apps is disabled.'}, 'passwordRequirements': {'$ref': '#/$defs/PasswordRequirements', 'deprecated': True, 'description': 'Password requirements. The field `password_requirements.require_password_unlock` must not be set. DEPRECATED - Use `passwordPolicies`. **Note:** Complexity-based values of `PasswordQuality`, that is, `COMPLEXITY_LOW`, `COMPLEXITY_MEDIUM`, and `COMPLEXITY_HIGH`, cannot be used here. `unified_lock_settings` cannot be used here.'}, 'setWallpaperDisabled': {'type': 'boolean', 'description': 'Whether changing the wallpaper is disabled.'}, 'choosePrivateKeyRules': {'type': 'array', 'items': {'$ref': '#/$defs/ChoosePrivateKeyRule'}, 'description': "Rules for determining apps' access to private keys. See `ChoosePrivateKeyRule` for details. This must be empty if any application has `CERT_SELECTION` delegation scope."}, 'createWindowsDisabled': {'type': 'boolean', 'description': 'Whether creating windows besides app windows is disabled.'}, 'outgoingCallsDisabled': {'type': 'boolean', 'description': 'Whether outgoing calls are disabled.'}, 'permittedInputMethods': {'$ref': '#/$defs/PackageNameList', 'description': 'If present, only the input methods provided by packages in this list are permitted. If this field is present, but the list is empty, then only system input methods are permitted.'}, 'personalUsagePolicies': {'$ref': '#/$defs/PersonalUsagePolicies', 'description': 'Policies managing personal usage on a company-owned device.'}, 'screenCaptureDisabled': {'type': 'boolean', 'description': 'Whether screen capture is disabled. This also blocks [Circle to Search](https://support.google.com/android/answer/14508957).'}, 'shareLocationDisabled': {'type': 'boolean', 'description': 'Whether location sharing is disabled.'}, 'uninstallAppsDisabled': {'type': 'boolean', 'description': 'Whether user uninstallation of applications is disabled. This prevents apps from being uninstalled, even those removed using `applications`'}, 'usbMassStorageEnabled': {'type': 'boolean', 'deprecated': True, 'description': 'Whether USB storage is enabled. Deprecated.'}, 'modifyAccountsDisabled': {'type': 'boolean', 'description': 'Whether adding or removing accounts is disabled.'}, 'policyEnforcementRules': {'type': 'array', 'items': {'$ref': '#/$defs/PolicyEnforcementRule'}, 'description': 'Rules that define the behavior when a particular policy can not be applied on device'}, 'recommendedGlobalProxy': {'$ref': '#/$defs/ProxyInfo', 'description': 'The network-independent global HTTP proxy. Typically proxies should be configured per-network in `open_network_configuration`. However for unusual configurations like general internal filtering a global HTTP proxy may be useful. If the proxy is not accessible, network access may break. The global proxy is only a recommendation and some apps may ignore it.'}, 'workAccountSetupConfig': {'$ref': '#/$defs/WorkAccountSetupConfig', 'description': 'Optional. Controls the work account setup configuration, such as details of whether a Google authenticated account is required.'}, 'bluetoothConfigDisabled': {'type': 'boolean', 'description': 'Whether configuring bluetooth is disabled.'}, 'defaultPermissionPolicy': {'enum': ['PERMISSION_POLICY_UNSPECIFIED', 'PROMPT', 'GRANT', 'DENY'], 'type': 'string', 'description': 'The default permission policy for runtime permission requests.', 'x-google-enum-descriptions': ['Policy not specified. If no policy is specified for a permission at any level, then the `PROMPT` behavior is used by default.', 'Prompt the user to grant a permission.', 'Automatically grant a permission. On Android 12 and above, [`READ_SMS`](https://developer.android.com/reference/android/Manifest.permission#READ_SMS) and following sensor-related permissions can only be granted on fully managed devices: * [`ACCESS_FINE_LOCATION`](https://developer.android.com/reference/android/Manifest.permission#ACCESS_FINE_LOCATION) * [`ACCESS_BACKGROUND_LOCATION`](https://developer.android.com/reference/android/Manifest.permission#ACCESS_BACKGROUND_LOCATION) * [`ACCESS_COARSE_LOCATION`](https://developer.android.com/reference/android/Manifest.permission#ACCESS_COARSE_LOCATION) * [`CAMERA`](https://developer.android.com/reference/android/Manifest.permission#CAMERA) * [`RECORD_AUDIO`](https://developer.android.com/reference/android/Manifest.permission#RECORD_AUDIO) * [`ACTIVITY_RECOGNITION`](https://developer.android.com/reference/android/Manifest.permission#ACTIVITY_RECOGNITION) * [`BODY_SENSORS`](https://developer.android.com/reference/android/Manifest.permission#BODY_SENSORS)', 'Automatically deny a permission.']}, 'ensureVerifyAppsEnabled': {'type': 'boolean', 'deprecated': True, 'description': 'Whether app verification is force-enabled.'}, 'oncCertificateProviders': {'type': 'array', 'items': {'$ref': '#/$defs/OncCertificateProvider'}, 'description': ' This feature is not generally available.'}, 'statusReportingSettings': {'$ref': '#/$defs/StatusReportingSettings', 'description': 'Status reporting settings'}, 'tetheringConfigDisabled': {'type': 'boolean', 'deprecated': True, 'description': 'Whether configuring tethering and portable hotspots is disabled. If `tetheringSettings` is set to anything other than `TETHERING_SETTINGS_UNSPECIFIED`, this setting is ignored.'}, 'usbFileTransferDisabled': {'type': 'boolean', 'deprecated': True, 'description': 'Whether transferring files over USB is disabled. This is supported only on company-owned devices.'}, 'blockApplicationsEnabled': {'type': 'boolean', 'deprecated': True, 'description': 'This field has no effect.'}, 'debuggingFeaturesAllowed': {'type': 'boolean', 'deprecated': True, 'description': 'Whether the user is allowed to enable debugging features.'}, 'keyguardDisabledFeatures': {'type': 'array', 'items': {'enum': ['KEYGUARD_DISABLED_FEATURE_UNSPECIFIED', 'CAMERA', 'NOTIFICATIONS', 'UNREDACTED_NOTIFICATIONS', 'TRUST_AGENTS', 'DISABLE_FINGERPRINT', 'DISABLE_REMOTE_INPUT', 'FACE', 'IRIS', 'BIOMETRICS', 'SHORTCUTS', 'ALL_FEATURES'], 'type': 'string', 'x-google-enum-descriptions': ['This value is ignored.', 'Disable the camera on secure keyguard screens (e.g. PIN).', 'Disable showing all notifications on secure keyguard screens.', 'Disable unredacted notifications on secure keyguard screens.', 'Ignore trust agent state on secure keyguard screens.', 'Disable fingerprint sensor on secure keyguard screens.', 'On devices running Android 6 and below, disables text entry into notifications on secure keyguard screens. Has no effect on Android 7 and above.', 'Disable face authentication on secure keyguard screens.', 'Disable iris authentication on secure keyguard screens.', 'Disable all biometric authentication on secure keyguard screens.', 'Disable all shortcuts on secure keyguard screen on Android 14 and above.', 'Disable all current and future keyguard customizations.']}, 'description': 'Disabled keyguard customizations, such as widgets.'}, 'openNetworkConfiguration': {'type': 'object', 'description': 'Network configuration for the device. See [configure networks](/android/management/configure-networks) for more information.', 'additionalProperties': {'description': 'Properties of the object.'}}, 'skipFirstUseHintsEnabled': {'type': 'boolean', 'description': 'Flag to skip hints on the first use. Enterprise admin can enable the system recommendation for apps to skip their user tutorial and other introductory hints on first start-up.'}, 'unmuteMicrophoneDisabled': {'type': 'boolean', 'deprecated': True, 'description': 'If `microphone_access` is set to any value other than `MICROPHONE_ACCESS_UNSPECIFIED`, this has no effect. Otherwise this field controls whether microphones are disabled: If true, all microphones are disabled, otherwise they are available. This is available only on fully managed devices.'}, 'advancedSecurityOverrides': {'$ref': '#/$defs/AdvancedSecurityOverrides', 'description': 'Optional. Advanced security settings. In most cases, setting these is not needed.'}, 'androidDevicePolicyTracks': {'type': 'array', 'items': {'enum': ['APP_TRACK_UNSPECIFIED', 'PRODUCTION', 'BETA'], 'type': 'string', 'x-google-enum-descriptions': ['This value is ignored.', 'The production track, which provides the latest stable release.', 'The beta track, which provides the latest beta release.']}, 'deprecated': True, 'description': 'This setting is not supported. Any value is ignored.'}, 'credentialsConfigDisabled': {'type': 'boolean', 'description': 'Whether configuring user credentials is disabled.'}, 'deviceOwnerLockScreenInfo': {'$ref': '#/$defs/UserFacingMessage', 'description': 'The device owner information to be shown on the lock screen.'}, 'networkEscapeHatchEnabled': {'type': 'boolean', 'description': "Whether the network escape hatch is enabled. If a network connection can't be made at boot time, the escape hatch prompts the user to temporarily connect to a network in order to refresh the device policy. After applying policy, the temporary network will be forgotten and the device will continue booting. This prevents being unable to connect to a network if there is no suitable network in the last policy and the device boots into an app in lock task mode, or the user is otherwise unable to reach device settings. **Note:** Setting `wifiConfigDisabled` to true will override this setting under specific circumstances. Please see `wifiConfigDisabled` for further details. Setting `configureWifi` to `DISALLOW_CONFIGURING_WIFI` will override this setting under specific circumstances. Please see `DISALLOW_CONFIGURING_WIFI` for further details."}, 'defaultApplicationSettings': {'type': 'array', 'items': {'$ref': '#/$defs/DefaultApplicationSetting'}, 'description': 'Optional. The default application setting for supported types. If the default application is successfully set for at least one app type on a profile, users are prevented from changing *any* default applications on that profile. Only one `DefaultApplicationSetting` is allowed for each `DefaultApplicationType`. **Warning:** Do not configure this and `persistent_preferred_activities` for the same intent domain, such as web browsing. Setting both for the same intent domain can lead to unpredictable behavior. See [Default application settings](https://developers.google.com/android/management/default-application-settings) guide for more details.'}, 'kioskCustomLauncherEnabled': {'type': 'boolean', 'description': 'Whether the kiosk custom launcher is enabled. This replaces the home screen with a launcher that locks down the device to the apps installed via the `applications` setting. Apps appear on a single page in alphabetical order. Use [kioskCustomization](/android/management/reference/rest/v1/enterprises.policies#kioskcustomization) to further configure the kiosk device behavior.'}, 'mountPhysicalMediaDisabled': {'type': 'boolean', 'description': 'Whether the user mounting physical external media is disabled.'}, 'preferentialNetworkService': {'enum': ['PREFERENTIAL_NETWORK_SERVICE_UNSPECIFIED', 'PREFERENTIAL_NETWORK_SERVICE_DISABLED', 'PREFERENTIAL_NETWORK_SERVICE_ENABLED'], 'type': 'string', 'description': "Controls whether preferential network service is enabled on the work profile or on fully managed devices. For example, an organization may have an agreement with a carrier that all of the work data from its employees' devices will be sent via a network service dedicated for enterprise use. An example of a supported preferential network service is the enterprise slice on 5G networks. This policy has no effect if `preferentialNetworkServiceSettings` or `ApplicationPolicy.preferentialNetworkId` is set on devices running Android 13 or above.", 'x-google-enum-descriptions': ['Unspecified. Defaults to `PREFERENTIAL_NETWORK_SERVICES_DISABLED`.', 'Preferential network service is disabled on the work profile.', 'Preferential network service is enabled on the work profile. This setting is only supported on work profiles on devices running Android 12 or above. Starting with Android 13, fully managed devices are also supported.']}, 'privateKeySelectionEnabled': {'type': 'boolean', 'description': 'Allows showing UI on a device for a user to choose a private key alias if there are no matching rules in ChoosePrivateKeyRules. For devices below Android P, setting this may leave enterprise keys vulnerable. This value will have no effect if any application has `CERT_SELECTION` delegation scope.'}, 'wifiConfigsLockdownEnabled': {'type': 'boolean', 'deprecated': True, 'description': 'This is deprecated.'}, 'cellBroadcastsConfigDisabled': {'type': 'boolean', 'description': 'Whether configuring cell broadcast is disabled.'}, 'deviceConnectivityManagement': {'$ref': '#/$defs/DeviceConnectivityManagement', 'description': 'Covers controls for device connectivity such as Wi-Fi, USB data access, keyboard/mouse connections, and more.'}, 'installUnknownSourcesAllowed': {'type': 'boolean', 'deprecated': True, 'description': 'This field has no effect.'}, 'mobileNetworksConfigDisabled': {'type': 'boolean', 'description': 'Whether configuring mobile networks is disabled.'}, 'persistentPreferredActivities': {'type': 'array', 'items': {'$ref': '#/$defs/PersistentPreferredActivity'}, 'description': 'Default intent handler activities. **Warning:** Do not configure this and `default_application_settings` for the same intent domain, such as web browsing. Setting both for the same intent domain can lead to unpredictable behavior.'}, 'permittedAccessibilityServices': {'$ref': '#/$defs/PackageNameList', 'description': "Specifies permitted accessibility services. If the field is not set, any accessibility service can be used. If the field is set, only the accessibility services in this list and the system's built-in accessibility service can be used. In particular, if the field is set to empty, only the system's built-in accessibility servicess can be used. This can be set on fully managed devices and on work profiles. When applied to a work profile, this affects both the personal profile and the work profile."}, 'bluetoothContactSharingDisabled': {'type': 'boolean', 'description': 'Whether bluetooth contact sharing is disabled.'}, 'credentialProviderPolicyDefault': {'enum': ['CREDENTIAL_PROVIDER_POLICY_DEFAULT_UNSPECIFIED', 'CREDENTIAL_PROVIDER_DEFAULT_DISALLOWED', 'CREDENTIAL_PROVIDER_DEFAULT_DISALLOWED_EXCEPT_SYSTEM', 'CREDENTIAL_PROVIDER_DEFAULT_ALLOWED'], 'type': 'string', 'description': 'Optional. Controls which apps are allowed to act as credential providers on Android 14 and above. These apps store credentials, see [this](https://developer.android.com/training/sign-in/passkeys) and [this](https://developer.android.com/reference/androidx/credentials/CredentialManager) for details. See also `credentialProviderPolicy`.', 'x-google-enum-descriptions': ['Unspecified. Defaults to CREDENTIAL_PROVIDER_DEFAULT_DISALLOWED.', 'Apps with `credentialProviderPolicy` unspecified are not allowed to act as a credential provider.', 'Apps with `credentialProviderPolicy` unspecified are not allowed to act as a credential provider except for the OEM default credential providers. OEM default credential providers are always allowed to act as credential providers.', 'Apps with `credentialProviderPolicy` unspecified are allowed to act as a credential provider.']}, 'enterpriseDisplayNameVisibility': {'enum': ['ENTERPRISE_DISPLAY_NAME_VISIBILITY_UNSPECIFIED', 'ENTERPRISE_DISPLAY_NAME_VISIBLE', 'ENTERPRISE_DISPLAY_NAME_HIDDEN'], 'type': 'string', 'description': 'Optional. Controls whether the `enterpriseDisplayName` is visible on the device (e.g. lock screen message on company-owned devices).', 'x-google-enum-descriptions': ['Unspecified. Defaults to `ENTERPRISE_DISPLAY_NAME_VISIBLE`.', 'The enterprise display name is visible on the device. Supported on work profiles on Android 7 and above. Supported on fully managed devices on Android 8 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 7. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported on fully managed devices on Android 7.', 'The enterprise display name is hidden on the device.']}, 'accountTypesWithManagementDisabled': {'type': 'array', 'items': {'type': 'string'}, 'description': "Account types that can't be managed by the user."}}, 'description': 'A policy resource represents a group of settings that govern the behavior of a managed device and the apps installed on it.'}
输入模式
{'type': 'object', 'properties': {'name': {'type': 'string', 'description': 'The name of the web app in the form `enterprises/{enterpriseId}/webApps/{packageName}`.'}}, 'description': 'Request to get a web app.'}
输出模式
{'type': 'object', '$defs': {'WebAppIcon': {'type': 'object', 'properties': {'imageData': {'type': 'string', 'description': 'The actual bytes of the image in a base64url encoded string (c.f. RFC4648, section 5 "Base 64 Encoding with URL and Filename Safe Alphabet"). - The image type can be png or jpg. - The image should ideally be square. - The image should ideally have a size of 512x512. '}}, 'description': 'An icon for a web app. Supported formats are: png, jpg and webp.'}}, 'properties': {'name': {'type': 'string', 'description': 'The name of the web app, which is generated by the server during creation in the form `enterprises/{enterpriseId}/webApps/{packageName}`.'}, 'icons': {'type': 'array', 'items': {'$ref': '#/$defs/WebAppIcon'}, 'description': 'A list of icons for the web app. Must have at least one element.'}, 'title': {'type': 'string', 'description': 'The title of the web app as displayed to the user (e.g., amongst a list of other applications, or as a label for an icon).'}, 'startUrl': {'type': 'string', 'description': 'The start URL, i.e. the URL that should load when the user opens the application.'}, 'displayMode': {'enum': ['DISPLAY_MODE_UNSPECIFIED', 'MINIMAL_UI', 'STANDALONE', 'FULL_SCREEN'], 'type': 'string', 'description': 'The display mode of the web app.', 'x-google-enum-descriptions': ['Not used.', 'Opens the web app with a minimal set of browser UI elements for controlling navigation and viewing the page URL.', 'Opens the web app to look and feel like a standalone native application. The browser UI elements and page URL are not visible, however the system status bar and back button are visible.', 'Opens the web app in full screen without any visible controls. The browser UI elements, page URL, system status bar and back button are not visible, and the web app takes up the entirety of the available display area.']}, 'versionCode': {'type': 'string', 'format': 'int64', 'description': 'The current version of the app. Note that the version can automatically increase during the lifetime of the web app, while Google does internal housekeeping to keep the web app up-to-date.'}}, 'description': 'A web app.'}
输入模式
{'type': 'object', 'properties': {'parent': {'type': 'string', 'description': 'The name of the enterprise in the form `enterprises/{enterpriseId}`.'}, 'pageSize': {'type': 'integer', 'format': 'int32', 'description': 'The requested page size. If unspecified, at most 10 devices will be returned. The maximum value is 100; values above 100 will be coerced to 100. The limits can change over time.'}, 'pageToken': {'type': 'string', 'description': 'A token identifying a page of results returned by the server.'}}, 'description': 'Request to list devices for a given enterprise.'}
输出模式
{'type': 'object', '$defs': {'User': {'type': 'object', 'properties': {'accountIdentifier': {'type': 'string', 'description': "A unique identifier you create for this user, such as `user342` or `asset#44418`. This field must be set when the user is created and can't be updated. This field must not contain personally identifiable information (PII). This identifier must be 1024 characters or less; otherwise, the update policy request will fail."}}, 'description': 'A user belonging to an enterprise.'}, 'Device': {'type': 'object', 'properties': {'name': {'type': 'string', 'description': 'The name of the device in the form `enterprises/{enterpriseId}/devices/{deviceId}`.'}, 'user': {'$ref': '#/$defs/User', 'description': 'The user who owns the device.'}, 'state': {'enum': ['DEVICE_STATE_UNSPECIFIED', 'ACTIVE', 'DISABLED', 'DELETED', 'PROVISIONING', 'LOST', 'PREPARING_FOR_MIGRATION', 'DEACTIVATED_BY_DEVICE_FINANCE'], 'type': 'string', 'description': 'The state to be applied to the device. This field can be modified by a patch request. Note that when calling `enterprises.devices.patch`, `ACTIVE` and `DISABLED` are the only allowable values. To enter the device into a `DELETED` state, call [`enterprises.devices.delete`](/android/management/reference/rest/v1/enterprises.devices/delete).', 'x-google-enum-descriptions': ['This value is disallowed.', 'The device is active.', 'The device is disabled.', 'The device was deleted. This state is never returned by an API call, but is used in the final status report when the device acknowledges the deletion. If the device is deleted via the API call, this state is published to Pub/Sub. If the user deletes the work profile or resets the device, the device state will remain unknown to the server.', 'The device is being provisioned. Newly enrolled devices are in this state until they have a policy applied.', 'The device is lost. This state is only possible on organization-owned devices.', 'The device is preparing for migrating to Android Management API. No further action is needed for the migration to continue.', 'This is a financed device that has been "locked" by the financing agent. This means certain policy settings have been applied which limit device functionality until the device has been "unlocked" by the financing agent. The device will continue to apply policy settings excluding those overridden by the financing agent. When the device is "locked", the state is reported in appliedState as `DEACTIVATED_BY_DEVICE_FINANCE`.']}, 'apiLevel': {'type': 'integer', 'format': 'int32', 'description': 'The API level of the Android platform version running on the device.'}, 'displays': {'type': 'array', 'items': {'$ref': '#/$defs/Display'}, 'description': "Detailed information about displays on the device. This information is only available if `displayInfoEnabled` is true in the device's policy."}, 'userName': {'type': 'string', 'description': 'The resource name of the user that owns this device in the form `enterprises/{enterpriseId}/users/{userId}`.'}, 'ownership': {'enum': ['OWNERSHIP_UNSPECIFIED', 'COMPANY_OWNED', 'PERSONALLY_OWNED'], 'type': 'string', 'description': 'Ownership of the managed device.', 'x-google-enum-descriptions': ['Ownership is unspecified.', 'Device is company-owned.', 'Device is personally-owned.']}, 'memoryInfo': {'$ref': '#/$defs/MemoryInfo', 'description': 'Memory information: contains information about device memory and storage.'}, 'policyName': {'type': 'string', 'description': "The name of the policy applied to the device, in the form `enterprises/{enterpriseId}/policies/{policyId}`. If not specified, the `policy_name` for the device's user is applied. This field can be modified by a patch request. You can specify only the `policyId` when calling `enterprises.devices.patch`, as long as the `policyId` doesn’t contain any slashes. The rest of the policy name is inferred."}, 'networkInfo': {'$ref': '#/$defs/NetworkInfo', 'description': "Device network information. This information is only available if `networkInfoEnabled` is true in the device's policy."}, 'appliedState': {'enum': ['DEVICE_STATE_UNSPECIFIED', 'ACTIVE', 'DISABLED', 'DELETED', 'PROVISIONING', 'LOST', 'PREPARING_FOR_MIGRATION', 'DEACTIVATED_BY_DEVICE_FINANCE'], 'type': 'string', 'description': 'The state currently applied to the device.', 'x-google-enum-descriptions': ['This value is disallowed.', 'The device is active.', 'The device is disabled.', 'The device was deleted. This state is never returned by an API call, but is used in the final status report when the device acknowledges the deletion. If the device is deleted via the API call, this state is published to Pub/Sub. If the user deletes the work profile or resets the device, the device state will remain unknown to the server.', 'The device is being provisioned. Newly enrolled devices are in this state until they have a policy applied.', 'The device is lost. This state is only possible on organization-owned devices.', 'The device is preparing for migrating to Android Management API. No further action is needed for the migration to continue.', 'This is a financed device that has been "locked" by the financing agent. This means certain policy settings have been applied which limit device functionality until the device has been "unlocked" by the financing agent. The device will continue to apply policy settings excluding those overridden by the financing agent. When the device is "locked", the state is reported in appliedState as `DEACTIVATED_BY_DEVICE_FINANCE`.']}, 'hardwareInfo': {'$ref': '#/$defs/HardwareInfo', 'description': 'Detailed information about the device hardware.'}, 'memoryEvents': {'type': 'array', 'items': {'$ref': '#/$defs/MemoryEvent'}, 'description': "Events related to memory and storage measurements in chronological order. This information is only available if `memoryInfoEnabled` is true in the device's policy. Events are retained for a certain period of time and old events are deleted."}, 'softwareInfo': {'$ref': '#/$defs/SoftwareInfo', 'description': "Detailed information about the device software. This information is only available if `softwareInfoEnabled` is true in the device's policy."}, 'deviceSettings': {'$ref': '#/$defs/DeviceSettings', 'description': "Device settings information. This information is only available if `deviceSettingsEnabled` is true in the device's policy."}, 'disabledReason': {'$ref': '#/$defs/UserFacingMessage', 'description': 'If the device state is `DISABLED`, an optional message that is displayed on the device indicating the reason the device is disabled. This field can be modified by a patch request.'}, 'enrollmentTime': {'type': 'string', 'format': 'date-time', 'description': 'The time of device enrollment.'}, 'managementMode': {'enum': ['MANAGEMENT_MODE_UNSPECIFIED', 'DEVICE_OWNER', 'PROFILE_OWNER'], 'type': 'string', 'description': 'The type of management mode Android Device Policy takes on the device. This influences which policy settings are supported.', 'x-google-enum-descriptions': ['This value is disallowed.', 'Device owner. Android Device Policy has full control over the device.', 'Profile owner. Android Device Policy has control over a managed profile on the device.']}, 'policyCompliant': {'type': 'boolean', 'description': 'Whether the device is compliant with its policy.'}, 'securityPosture': {'$ref': '#/$defs/SecurityPosture', 'description': "Device's security posture value that reflects how secure the device is."}, 'dpcMigrationInfo': {'$ref': '#/$defs/DpcMigrationInfo', 'readOnly': True, 'description': 'Output only. Information related to whether this device was migrated from being managed by another Device Policy Controller (DPC).'}, 'systemProperties': {'type': 'object', 'description': "Map of selected system properties name and value related to the device. This information is only available if `systemPropertiesEnabled` is true in the device's policy.", 'additionalProperties': {'type': 'string'}}, 'appliedPolicyName': {'type': 'string', 'description': 'The name of the policy currently applied to the device.'}, 'applicationReports': {'type': 'array', 'items': {'$ref': '#/$defs/ApplicationReport'}, 'description': "Reports for apps installed on the device. This information is only available when `application_reports_enabled` is true in the device's policy."}, 'lastPolicySyncTime': {'type': 'string', 'format': 'date-time', 'description': 'The last time the device fetched its policy.'}, 'enrollmentTokenData': {'type': 'string', 'description': 'If the device was enrolled with an enrollment token with additional data provided, this field contains that data.'}, 'enrollmentTokenName': {'type': 'string', 'description': 'If the device was enrolled with an enrollment token, this field contains the name of the token.'}, 'previousDeviceNames': {'type': 'array', 'items': {'type': 'string'}, 'description': 'If the same physical device has been enrolled multiple times, this field contains its previous device names. The serial number is used as the unique identifier to determine if the same physical device has enrolled previously. The names are in chronological order.'}, 'appliedPolicyVersion': {'type': 'string', 'format': 'int64', 'description': 'The version of the policy currently applied to the device.'}, 'lastStatusReportTime': {'type': 'string', 'format': 'date-time', 'description': 'The last time the device sent a status report.'}, 'nonComplianceDetails': {'type': 'array', 'items': {'$ref': '#/$defs/NonComplianceDetail'}, 'description': 'Details about policy settings that the device is not compliant with.'}, 'hardwareStatusSamples': {'type': 'array', 'items': {'$ref': '#/$defs/HardwareStatus'}, 'description': "Hardware status samples in chronological order. This information is only available if `hardwareStatusEnabled` is true in the device's policy."}, 'powerManagementEvents': {'type': 'array', 'items': {'$ref': '#/$defs/PowerManagementEvent'}, 'description': "Power management events on the device in chronological order. This information is only available if `powerManagementEventsEnabled` is true in the device's policy."}, 'commonCriteriaModeInfo': {'$ref': '#/$defs/CommonCriteriaModeInfo', 'description': "Information about Common Criteria Mode—security standards defined in the [Common Criteria for Information Technology Security Evaluation](https://www.commoncriteriaportal.org/) (CC). This information is only available if statusReportingSettings.commonCriteriaModeEnabled is `true` in the device's policy the device is company-owned."}, 'defaultApplicationInfo': {'type': 'array', 'items': {'$ref': '#/$defs/DefaultApplicationInfo'}, 'readOnly': True, 'description': "Output only. The default application information for the `DefaultApplicationType`. This information is only available if `defaultApplicationInfoReportingEnabled` is true in the device's policy. Available on Android 16 and above. All app types are reported on fully managed devices. `DEFAULT_BROWSER`, `DEFAULT_CALL_REDIRECTION`, `DEFAULT_CALL_SCREENING` and `DEFAULT_DIALER` types are reported for the work profiles on company-owned devices with a work profile and personally-owned devices. `DEFAULT_WALLET` is also reported for company-owned devices with a work profile, but will only include work profile information."}, 'appliedPasswordPolicies': {'type': 'array', 'items': {'$ref': '#/$defs/PasswordRequirements'}, 'description': 'The password requirements currently applied to the device. * This field exists because the applied requirements may be slightly different from those specified in `passwordPolicies` in some cases. * Note that this field does not provide information about password compliance. For non-compliance information, see `nonComplianceDetails`. * `NonComplianceDetail.fieldPath`, is set based on `passwordPolicies`, not based on this field.'}, 'lastPolicyComplianceReportTime': {'type': 'string', 'format': 'date-time', 'deprecated': True, 'description': 'Deprecated.'}}, 'description': "A device owned by an enterprise. Unless otherwise noted, all fields are read-only and can't be modified by `enterprises.devices.patch`."}, 'Display': {'type': 'object', 'properties': {'name': {'type': 'string', 'description': 'Name of the display.'}, 'state': {'enum': ['DISPLAY_STATE_UNSPECIFIED', 'OFF', 'ON', 'DOZE', 'SUSPENDED'], 'type': 'string', 'description': 'State of the display.', 'x-google-enum-descriptions': ['This value is disallowed.', 'Display is off.', 'Display is on.', 'Display is dozing in a low power state', 'Display is dozing in a suspended low power state.']}, 'width': {'type': 'integer', 'format': 'int32', 'description': 'Display width in pixels.'}, 'height': {'type': 'integer', 'format': 'int32', 'description': 'Display height in pixels.'}, 'density': {'type': 'integer', 'format': 'int32', 'description': 'Display density expressed as dots-per-inch.'}, 'displayId': {'type': 'integer', 'format': 'int32', 'description': 'Unique display id.'}, 'refreshRate': {'type': 'integer', 'format': 'int32', 'description': 'Refresh rate of the display in frames per second.'}}, 'description': 'Device display information.'}, 'MemoryInfo': {'type': 'object', 'properties': {'totalRam': {'type': 'string', 'format': 'int64', 'description': 'Total RAM on device in bytes.'}, 'totalInternalStorage': {'type': 'string', 'format': 'int64', 'description': 'Total internal storage on device in bytes.'}}, 'description': 'Information about device memory and storage.'}, 'MemoryEvent': {'type': 'object', 'properties': {'byteCount': {'type': 'string', 'format': 'int64', 'description': 'The number of free bytes in the medium, or for `EXTERNAL_STORAGE_DETECTED`, the total capacity in bytes of the storage medium.'}, 'eventType': {'enum': ['MEMORY_EVENT_TYPE_UNSPECIFIED', 'RAM_MEASURED', 'INTERNAL_STORAGE_MEASURED', 'EXTERNAL_STORAGE_DETECTED', 'EXTERNAL_STORAGE_REMOVED', 'EXTERNAL_STORAGE_MEASURED'], 'type': 'string', 'description': 'Event type.', 'x-google-enum-descriptions': ['Unspecified. No events have this type.', 'Free space in RAM was measured.', 'Free space in internal storage was measured.', 'A new external storage medium was detected. The reported byte count is the total capacity of the storage medium.', 'An external storage medium was removed. The reported byte count is zero.', 'Free space in an external storage medium was measured.']}, 'createTime': {'type': 'string', 'format': 'date-time', 'description': 'The creation time of the event.'}}, 'description': 'An event related to memory and storage measurements. To distinguish between new and old events, we recommend using the `createTime` field.'}, 'NetworkInfo': {'type': 'object', 'properties': {'imei': {'type': 'string', 'description': 'IMEI number of the GSM device. For example, `A1000031212`.'}, 'meid': {'type': 'string', 'description': 'MEID number of the CDMA device. For example, `A00000292788E1`.'}, 'telephonyInfos': {'type': 'array', 'items': {'$ref': '#/$defs/TelephonyInfo'}, 'description': 'Provides telephony information associated with each SIM card on the device. Only supported on fully managed devices starting from Android 6.'}, 'wifiMacAddress': {'type': 'string', 'description': 'Wi-Fi MAC address of the device. For example, `7c:11:11:11:11:11`.'}, 'networkOperatorName': {'type': 'string', 'deprecated': True, 'description': 'Alphabetic name of current registered operator. For example, Vodafone.'}}, 'description': 'Device network info.'}, 'HardwareInfo': {'type': 'object', 'properties': {'brand': {'type': 'string', 'description': 'Brand of the device. For example, `Google`.'}, 'model': {'type': 'string', 'description': 'The model of the device. For example, `Asus Nexus 7`.'}, 'hardware': {'type': 'string', 'description': 'Name of the hardware. For example, `Angler`.'}, 'manufacturer': {'type': 'string', 'description': 'Manufacturer. For example, `Motorola`.'}, 'serialNumber': {'type': 'string', 'description': 'The device serial number. However, for personally-owned devices running Android 12 and above, this is the same as the `enterpriseSpecificId`.'}, 'euiccChipInfo': {'type': 'array', 'items': {'$ref': '#/$defs/EuiccChipInfo'}, 'readOnly': True, 'description': 'Output only. Information related to the eUICC chip.'}, 'enterpriseSpecificId': {'type': 'string', 'readOnly': True, 'description': 'Output only. ID that uniquely identifies a personally-owned device in a particular organization. On the same physical device when enrolled with the same organization, this ID persists across setups and even factory resets. This ID is available on personally-owned devices with a work profile on devices running Android 12 and above.'}, 'deviceBasebandVersion': {'type': 'string', 'description': 'Baseband version. For example, `MDM9625_104662.22.05.34p`.'}, 'cpuShutdownTemperatures': {'type': 'array', 'items': {'type': 'number', 'format': 'float'}, 'description': 'CPU shutdown temperature thresholds in Celsius for each CPU on the device.'}, 'gpuShutdownTemperatures': {'type': 'array', 'items': {'type': 'number', 'format': 'float'}, 'description': 'GPU shutdown temperature thresholds in Celsius for each GPU on the device.'}, 'skinShutdownTemperatures': {'type': 'array', 'items': {'type': 'number', 'format': 'float'}, 'description': 'Device skin shutdown temperature thresholds in Celsius.'}, 'cpuThrottlingTemperatures': {'type': 'array', 'items': {'type': 'number', 'format': 'float'}, 'description': 'CPU throttling temperature thresholds in Celsius for each CPU on the device.'}, 'gpuThrottlingTemperatures': {'type': 'array', 'items': {'type': 'number', 'format': 'float'}, 'description': 'GPU throttling temperature thresholds in Celsius for each GPU on the device.'}, 'skinThrottlingTemperatures': {'type': 'array', 'items': {'type': 'number', 'format': 'float'}, 'description': 'Device skin throttling temperature thresholds in Celsius.'}, 'batteryShutdownTemperatures': {'type': 'array', 'items': {'type': 'number', 'format': 'float'}, 'description': 'Battery shutdown temperature thresholds in Celsius for each battery on the device.'}, 'batteryThrottlingTemperatures': {'type': 'array', 'items': {'type': 'number', 'format': 'float'}, 'description': 'Battery throttling temperature thresholds in Celsius for each battery on the device.'}}, 'description': "Information about device hardware. The fields related to temperature thresholds are only available if `hardwareStatusEnabled` is true in the device's policy."}, 'SoftwareInfo': {'type': 'object', 'properties': {'androidVersion': {'type': 'string', 'description': 'The user-visible Android version string. For example, `6.0.1`.'}, 'androidBuildTime': {'type': 'string', 'format': 'date-time', 'description': 'Build time.'}, 'systemUpdateInfo': {'$ref': '#/$defs/SystemUpdateInfo', 'description': 'Information about a potential pending system update.'}, 'bootloaderVersion': {'type': 'string', 'description': 'The system bootloader version number, e.g. `0.6.7`.'}, 'androidBuildNumber': {'type': 'string', 'description': 'Android build ID string meant for displaying to the user. For example, `shamu-userdebug 6.0.1 MOB30I 2756745 dev-keys`.'}, 'securityPatchLevel': {'type': 'string', 'description': 'Security patch level, e.g. `2016-05-01`.'}, 'deviceKernelVersion': {'type': 'string', 'description': 'Kernel version, for example, `2.6.32.9-g103d848`.'}, 'primaryLanguageCode': {'type': 'string', 'description': 'An IETF BCP 47 language code for the primary locale on the device.'}, 'deviceBuildSignature': {'type': 'string', 'description': "SHA-256 hash of [`android.content.pm.Signature`](https://developer.android.com/reference/android/content/pm/Signature.html) associated with the system package, which can be used to verify that the system build hasn't been modified."}, 'androidDevicePolicyVersionCode': {'type': 'integer', 'format': 'int32', 'description': 'The Android Device Policy app version code.'}, 'androidDevicePolicyVersionName': {'type': 'string', 'description': 'The Android Device Policy app version as displayed to the user.'}}, 'description': 'Information about device software.'}, 'EuiccChipInfo': {'type': 'object', 'properties': {'eid': {'type': 'string', 'readOnly': True, 'description': 'Output only. The Embedded Identity Document (EID) that identifies the eUICC chip for each eUICC chip on the device. This is available on company owned devices running Android 13 and above.'}}, 'description': 'Information related to the eUICC chip.'}, 'KeyedAppState': {'type': 'object', 'properties': {'key': {'type': 'string', 'description': 'The key for the app state. Acts as a point of reference for what the app is providing state for. For example, when providing managed configuration feedback, this key could be the managed configuration key.'}, 'data': {'type': 'string', 'description': 'Optionally, a machine-readable value to be read by the EMM. For example, setting values that the admin can choose to query against in the EMM console (e.g. “notify me if the battery_warning data < 10”).'}, 'message': {'type': 'string', 'description': 'Optionally, a free-form message string to explain the app state. If the state was triggered by a particular value (e.g. a managed configuration value), it should be included in the message.'}, 'severity': {'enum': ['SEVERITY_UNSPECIFIED', 'INFO', 'ERROR'], 'type': 'string', 'description': 'The severity of the app state.', 'x-google-enum-descriptions': ['Unspecified severity level.', 'Information severity level.', 'Error severity level. This should only be set for genuine error conditions that a management organization needs to take action to fix.']}, 'createTime': {'type': 'string', 'format': 'date-time', 'description': 'The creation time of the app state on the device.'}, 'lastUpdateTime': {'type': 'string', 'format': 'date-time', 'description': 'The time the app state was most recently updated.'}}, 'description': 'Keyed app state reported by the app.'}, 'PostureDetail': {'type': 'object', 'properties': {'advice': {'type': 'array', 'items': {'$ref': '#/$defs/UserFacingMessage'}, 'description': 'Corresponding admin-facing advice to mitigate this security risk and improve the security posture of the device.'}, 'securityRisk': {'enum': ['SECURITY_RISK_UNSPECIFIED', 'UNKNOWN_OS', 'COMPROMISED_OS', 'HARDWARE_BACKED_EVALUATION_FAILED'], 'type': 'string', 'description': 'A specific security risk that negatively affects the security posture of the device.', 'x-google-enum-descriptions': ['Unspecified.', 'Play Integrity API detects that the device is running an unknown OS (basicIntegrity check succeeds but ctsProfileMatch fails).', 'Play Integrity API detects that the device is running a compromised OS (basicIntegrity check fails).', "Play Integrity API detects that the device does not have a strong guarantee of system integrity, if the `MEETS_STRONG_INTEGRITY` label doesn't show in the [device integrity field] (https://developer.android.com/google/play/integrity/verdicts#device-integrity-field)."]}}, 'description': 'Additional details regarding the security posture of the device.'}, 'TelephonyInfo': {'type': 'object', 'properties': {'iccId': {'type': 'string', 'readOnly': True, 'description': 'Output only. The ICCID associated with this SIM card.'}, 'configMode': {'enum': ['CONFIG_MODE_UNSPECIFIED', 'ADMIN_CONFIGURED', 'USER_CONFIGURED'], 'type': 'string', 'readOnly': True, 'description': 'Output only. The configuration mode of the SIM card on the device. This is applicable for eSIMs only. This is supported on all devices for Android 15 and above. This is always `CONFIG_MODE_UNSPECIFIED` for physical SIMs and for devices below Android 15.', 'x-google-enum-descriptions': ['The configuration mode is unspecified.', 'The admin has configured this SIM.', 'The user has configured this SIM.']}, 'carrierName': {'type': 'string', 'description': 'The carrier name associated with this SIM card.'}, 'phoneNumber': {'type': 'string', 'description': 'The phone number associated with this SIM card.'}, 'activationState': {'enum': ['ACTIVATION_STATE_UNSPECIFIED', 'ACTIVATED', 'NOT_ACTIVATED'], 'type': 'string', 'readOnly': True, 'description': 'Output only. Activation state of the SIM card on the device. This is applicable for eSIMs only. This is supported on all devices for Android 15 and above. This is always `ACTIVATION_STATE_UNSPECIFIED` for physical SIMs and for devices below Android 15.', 'x-google-enum-descriptions': ['Activation state is not specified.', 'The SIM card is activated.', 'The SIM card is not activated.']}}, 'description': 'Telephony information associated with a given SIM card on the device. This is supported for all SIM cards on fully managed devices on Android 6 and above. In addition, this is supported for admin-added eSIMs on all devices for Android 15 and above.'}, 'DeviceSettings': {'type': 'object', 'properties': {'adbEnabled': {'type': 'boolean', 'description': 'Whether [ADB](https://developer.android.com/studio/command-line/adb.html) is enabled on the device.'}, 'isEncrypted': {'type': 'boolean', 'description': 'Whether the storage encryption is enabled.'}, 'isDeviceSecure': {'type': 'boolean', 'description': 'Whether the device is secured with PIN/password.'}, 'encryptionStatus': {'enum': ['ENCRYPTION_STATUS_UNSPECIFIED', 'UNSUPPORTED', 'INACTIVE', 'ACTIVATING', 'ACTIVE', 'ACTIVE_DEFAULT_KEY', 'ACTIVE_PER_USER'], 'type': 'string', 'description': 'Encryption status from DevicePolicyManager.', 'x-google-enum-descriptions': ['Unspecified. No device should have this type.', 'Encryption is not supported by the device.', 'Encryption is supported by the device, but is not currently active.', 'Encryption is not currently active, but is currently being activated.', 'Encryption is active.', 'Encryption is active, but an encryption key is not set by the user.', 'Encryption is active, and the encryption key is tied to the user profile.']}, 'verifyAppsEnabled': {'type': 'boolean', 'description': 'Whether [Google Play Protect verification](https://support.google.com/accounts/answer/2812853) is enforced on the device.'}, 'unknownSourcesEnabled': {'type': 'boolean', 'description': 'Whether installing apps from unknown sources is enabled.'}, 'developmentSettingsEnabled': {'type': 'boolean', 'description': 'Whether developer mode is enabled on the device.'}}, 'description': 'Information about security related device settings on device.'}, 'HardwareStatus': {'type': 'object', 'properties': {'cpuUsages': {'type': 'array', 'items': {'type': 'number', 'format': 'float'}, 'description': 'CPU usages in percentage for each core available on the device. Usage is 0 for each unplugged core. Empty array implies that CPU usage is not supported in the system.'}, 'fanSpeeds': {'type': 'array', 'items': {'type': 'number', 'format': 'float'}, 'description': 'Fan speeds in RPM for each fan on the device. Empty array means that there are no fans or fan speed is not supported on the system.'}, 'createTime': {'type': 'string', 'format': 'date-time', 'description': 'The time the measurements were taken.'}, 'cpuTemperatures': {'type': 'array', 'items': {'type': 'number', 'format': 'float'}, 'description': 'Current CPU temperatures in Celsius for each CPU on the device.'}, 'gpuTemperatures': {'type': 'array', 'items': {'type': 'number', 'format': 'float'}, 'description': 'Current GPU temperatures in Celsius for each GPU on the device.'}, 'skinTemperatures': {'type': 'array', 'items': {'type': 'number', 'format': 'float'}, 'description': 'Current device skin temperatures in Celsius.'}, 'batteryTemperatures': {'type': 'array', 'items': {'type': 'number', 'format': 'float'}, 'description': 'Current battery temperatures in Celsius for each battery on the device.'}}, 'description': 'Hardware status. Temperatures may be compared to the temperature thresholds available in `hardwareInfo` to determine hardware health.'}, 'OncWifiContext': {'type': 'object', 'properties': {'wifiGuid': {'type': 'string', 'description': 'The GUID of non-compliant Wi-Fi configuration.'}}, 'description': 'Additional context for non-compliance related to Wi-Fi configuration.'}, 'SecurityPosture': {'type': 'object', 'properties': {'devicePosture': {'enum': ['POSTURE_UNSPECIFIED', 'SECURE', 'AT_RISK', 'POTENTIALLY_COMPROMISED'], 'type': 'string', 'description': "Device's security posture value.", 'x-google-enum-descriptions': ['Unspecified. There is no posture detail for this posture value.', 'This device is secure.', 'This device may be more vulnerable to malicious actors than is recommended for use with corporate data.', 'This device may be compromised and corporate data may be accessible to unauthorized actors.']}, 'postureDetails': {'type': 'array', 'items': {'$ref': '#/$defs/PostureDetail'}, 'description': 'Additional details regarding the security posture of the device.'}}, 'description': 'The security posture of the device, as determined by the current device state and the policies applied.'}, 'ApplicationEvent': {'type': 'object', 'properties': {'eventType': {'enum': ['APPLICATION_EVENT_TYPE_UNSPECIFIED', 'INSTALLED', 'CHANGED', 'DATA_CLEARED', 'REMOVED', 'REPLACED', 'RESTARTED', 'PINNED', 'UNPINNED'], 'type': 'string', 'description': 'App event type.', 'x-google-enum-descriptions': ['This value is disallowed.', 'The app was installed.', 'The app was changed, for example, a component was enabled or disabled.', 'The app data was cleared.', 'The app was removed.', 'A new version of the app has been installed, replacing the old version.', 'The app was restarted.', 'The app was pinned to the foreground.', 'The app was unpinned.']}, 'createTime': {'type': 'string', 'format': 'date-time', 'description': 'The creation time of the event.'}}, 'description': 'An app-related event.'}, 'DpcMigrationInfo': {'type': 'object', 'properties': {'previousDpc': {'type': 'string', 'readOnly': True, 'description': 'Output only. If this device was migrated from another DPC, this is its package name. Not populated otherwise.'}, 'additionalData': {'type': 'string', 'readOnly': True, 'description': 'Output only. If this device was migrated from another DPC, the `additionalData` field of the migration token is populated here.'}}, 'description': 'Information related to whether this device was migrated from being managed by another Device Policy Controller (DPC).'}, 'SystemUpdateInfo': {'type': 'object', 'properties': {'updateStatus': {'enum': ['UPDATE_STATUS_UNKNOWN', 'UP_TO_DATE', 'UNKNOWN_UPDATE_AVAILABLE', 'SECURITY_UPDATE_AVAILABLE', 'OS_UPDATE_AVAILABLE'], 'type': 'string', 'description': 'The status of an update: whether an update exists and what type it is.', 'x-google-enum-descriptions': ['It is unknown whether there is a pending system update. This happens when, for example, the device API level is less than 26, or if the version of Android Device Policy is outdated.', 'There is no pending system update available on the device.', 'There is a pending system update available, but its type is not known.', 'There is a pending security update available.', 'There is a pending OS update available.']}, 'updateReceivedTime': {'type': 'string', 'format': 'date-time', 'description': 'The time when the update was first available. A zero value indicates that this field is not set. This field is set only if an update is available (that is, updateStatus is neither UPDATE_STATUS_UNKNOWN nor UP_TO_DATE).'}}, 'description': 'Information about a potential pending system update.'}, 'ApplicationReport': {'type': 'object', 'properties': {'state': {'enum': ['APPLICATION_STATE_UNSPECIFIED', 'REMOVED', 'INSTALLED'], 'type': 'string', 'description': 'Application state.', 'x-google-enum-descriptions': ['App state is unspecified', 'App was removed from the device', 'App is installed on the device']}, 'events': {'type': 'array', 'items': {'$ref': '#/$defs/ApplicationEvent'}, 'description': 'The list of app events which have occurred in the last 30 hours.'}, 'displayName': {'type': 'string', 'description': 'The display name of the app.'}, 'packageName': {'type': 'string', 'description': 'Package name of the app.'}, 'versionCode': {'type': 'integer', 'format': 'int32', 'description': 'The app version code, which can be used to determine whether one version is more recent than another.'}, 'versionName': {'type': 'string', 'description': 'The app version as displayed to the user.'}, 'keyedAppStates': {'type': 'array', 'items': {'$ref': '#/$defs/KeyedAppState'}, 'description': 'List of keyed app states reported by the app.'}, 'userFacingType': {'enum': ['USER_FACING_TYPE_UNSPECIFIED', 'NOT_USER_FACING', 'USER_FACING'], 'type': 'string', 'description': 'Whether the app is user facing.', 'x-google-enum-descriptions': ['App user facing type is unspecified.', 'App is not user facing.', 'App is user facing.']}, 'signingKeyCerts': {'type': 'array', 'items': {'$ref': '#/$defs/ApplicationSigningKeyCert'}, 'readOnly': True, 'description': 'Output only. Signing key certificates of the app.'}, 'applicationSource': {'enum': ['APPLICATION_SOURCE_UNSPECIFIED', 'SYSTEM_APP_FACTORY_VERSION', 'SYSTEM_APP_UPDATED_VERSION', 'INSTALLED_FROM_PLAY_STORE', 'CUSTOM'], 'type': 'string', 'description': 'The source of the package.', 'x-google-enum-descriptions': ['The app was sideloaded from an unspecified source.', "This is a system app from the device's factory image.", 'This is an updated system app.', 'The app was installed from the Google Play Store.', 'The app was installed using the [AMAPI SDK command](https://developers.google.com/android/management/extensibility-sdk-integration). See also: `CUSTOM`']}, 'packageSha256Hash': {'type': 'string', 'description': "The SHA-256 hash of the app's APK file, which can be used to verify the app hasn't been modified. Each byte of the hash value is represented as a two-digit hexadecimal number."}, 'installerPackageName': {'type': 'string', 'description': 'The package name of the app that installed this app.'}, 'signingKeyCertFingerprints': {'type': 'array', 'items': {'type': 'string'}, 'deprecated': True, 'description': 'Deprecated. Use `signingKeyCerts` instead. The SHA-1 hash of each [`android.content.pm.Signature`](https://developer.android.com/reference/android/content/pm/Signature.html) associated with the app package. Each byte of each hash value is represented as a two-digit hexadecimal number.'}}, 'description': 'Information reported about an installed app.'}, 'UserFacingMessage': {'type': 'object', 'properties': {'defaultMessage': {'type': 'string', 'description': "The default message displayed if no localized message is specified or the user's locale doesn't match with any of the localized messages. A default message must be provided if any localized messages are provided."}, 'localizedMessages': {'type': 'object', 'description': 'A map containing pairs, where locale is a well-formed [BCP 47 language](https://www.w3.org/International/articles/language-tags/) code, such as en-US, es-ES, or fr.', 'additionalProperties': {'type': 'string'}}}, 'description': 'Provides a user-facing message with locale info. The maximum message length is 4096 characters.'}, 'NonComplianceDetail': {'type': 'object', 'properties': {'fieldPath': {'type': 'string', 'description': 'For settings with nested fields, if a particular nested field is out of compliance, this specifies the full path to the offending field. The path is formatted in the same way the policy JSON field would be referenced in JavaScript, that is: 1) For object-typed fields, the field name is followed by a dot then by a subfield name. 2) For array-typed fields, the field name is followed by the array index enclosed in brackets. For example, to indicate a problem with the `url` field in the `externalData` field in the 3rd application, the path would be `applications[2].externalData.url`'}, 'packageName': {'type': 'string', 'description': 'The package name indicating which app is out of compliance, if applicable.'}, 'settingName': {'type': 'string', 'description': 'The name of the policy setting. This is the JSON field name of a top-level [`Policy`](/android/management/reference/rest/v1/enterprises.policies#Policy) field.'}, 'currentValue': {'description': 'If the policy setting could not be applied, the current value of the setting on the device.'}, 'nonComplianceReason': {'enum': ['NON_COMPLIANCE_REASON_UNSPECIFIED', 'API_LEVEL', 'MANAGEMENT_MODE', 'USER_ACTION', 'INVALID_VALUE', 'APP_NOT_INSTALLED', 'UNSUPPORTED', 'APP_INSTALLED', 'PENDING', 'APP_INCOMPATIBLE', 'APP_NOT_UPDATED', 'DEVICE_INCOMPATIBLE', 'APP_SIGNING_CERT_MISMATCH', 'PROJECT_NOT_PERMITTED'], 'type': 'string', 'description': 'The reason the device is not in compliance with the setting.', 'x-google-enum-descriptions': ['This value is not used.', 'The setting is not supported in the API level of the Android version running on the device.', "The management mode (such as fully managed or work profile) doesn't support the setting.", 'The user has not taken required action to comply with the setting.', 'The setting has an invalid value.', 'The app required to implement the policy is not installed.', 'The policy is not supported by the version of Android Device Policy on the device.', 'A blocked app is installed.', "The setting hasn't been applied at the time of the report, but is expected to be applied shortly.", "The setting can't be applied to the app because the app doesn't support it, for example because its target SDK version is not high enough.", "The app is installed, but it hasn't been updated to the minimum version code specified by policy.", 'The device is incompatible with the policy requirements.', "The app's signing certificate does not match the setting value.", 'The Google Cloud Platform project used to manage the device is not permitted to use this policy.']}, 'installationFailureReason': {'enum': ['INSTALLATION_FAILURE_REASON_UNSPECIFIED', 'INSTALLATION_FAILURE_REASON_UNKNOWN', 'IN_PROGRESS', 'NOT_FOUND', 'NOT_COMPATIBLE_WITH_DEVICE', 'NOT_APPROVED', 'PERMISSIONS_NOT_ACCEPTED', 'NOT_AVAILABLE_IN_COUNTRY', 'NO_LICENSES_REMAINING', 'NOT_ENROLLED', 'USER_INVALID', 'NETWORK_ERROR_UNRELIABLE_CONNECTION', 'INSUFFICIENT_STORAGE'], 'type': 'string', 'description': "If `package_name` is set and the non-compliance reason is `APP_NOT_INSTALLED` or `APP_NOT_UPDATED`, the detailed reason the app can't be installed or updated.", 'x-google-enum-descriptions': ['This value is disallowed.', "An unknown condition is preventing the app from being installed. Some potential reasons are that the device doesn't have enough storage, the device network connection is unreliable, or the installation is taking longer than expected. The installation will be retried automatically.", 'The installation is still in progress.', 'The app was not found in Play.', 'The app is incompatible with the device.', 'The app has not been approved by the admin.', 'The app has new permissions that have not been accepted by the admin.', "The app is not available in the user's country.", 'There are no licenses available to assign to the user.', 'The enterprise is no longer enrolled with Managed Google Play or the admin has not accepted the latest Managed Google Play Terms of Service.', 'The user is no longer valid. The user may have been deleted or disabled.', "A network error on the user's device has prevented the install from succeeding. This usually happens when the device's internet connectivity is degraded, unavailable or there's a network configuration issue. Please ensure the device has access to full internet connectivity on a network that meets [`Android Enterprise Network Requirements`](https://support.google.com/work/android/answer/10513641). App install or update will automatically resume once this is the case.", "The user's device does not have sufficient storage space to install the app. This can be resolved by clearing up storage space on the device. App install or update will automatically resume once the device has sufficient storage."]}, 'specificNonComplianceReason': {'enum': ['SPECIFIC_NON_COMPLIANCE_REASON_UNSPECIFIED', 'PASSWORD_POLICIES_USER_CREDENTIALS_CONFIRMATION_REQUIRED', 'PASSWORD_POLICIES_PASSWORD_EXPIRED', 'PASSWORD_POLICIES_PASSWORD_NOT_SUFFICIENT', 'ONC_WIFI_INVALID_VALUE', 'ONC_WIFI_API_LEVEL', 'ONC_WIFI_INVALID_ENTERPRISE_CONFIG', 'ONC_WIFI_USER_SHOULD_REMOVE_NETWORK', 'ONC_WIFI_KEY_PAIR_ALIAS_NOT_CORRESPONDING_TO_EXISTING_KEY', 'PERMISSIBLE_USAGE_RESTRICTION', 'REQUIRED_ACCOUNT_NOT_IN_ENTERPRISE', 'NEW_ACCOUNT_NOT_IN_ENTERPRISE', 'DEFAULT_APPLICATION_SETTING_UNSUPPORTED_SCOPES', 'DEFAULT_APPLICATION_SETTING_FAILED_FOR_SCOPE', 'PRIVATE_DNS_HOST_NOT_SERVING'], 'type': 'string', 'description': 'The policy-specific reason the device is not in compliance with the setting.', 'x-google-enum-descriptions': ['Specific non-compliance reason is not specified. Fields in `specific_non_compliance_context` are not set.', 'User needs to confirm credentials by entering the screen lock. Fields in `specific_non_compliance_context` are not set. `nonComplianceReason` is set to `USER_ACTION`.', 'The device or profile password has expired. `passwordPoliciesContext` is set. `nonComplianceReason` is set to `USER_ACTION`.', 'The device password does not satisfy password requirements. `passwordPoliciesContext` is set. `nonComplianceReason` is set to `USER_ACTION`.', 'There is an incorrect value in ONC Wi-Fi configuration. `fieldPath` specifies which field value is incorrect. `oncWifiContext` is set. `nonComplianceReason` is set to `INVALID_VALUE`.', 'The ONC Wi-Fi setting is not supported in the API level of the Android version running on the device. `fieldPath` specifies which field value is not supported. `oncWifiContext` is set. `nonComplianceReason` is set to `API_LEVEL`.', 'The enterprise Wi-Fi network is missing either the root CA or domain name. `nonComplianceReason` is set to `INVALID_VALUE`.', 'User needs to remove the configured Wi-Fi network manually. This is applicable only on work profiles on personally-owned devices. `nonComplianceReason` is set to `USER_ACTION`.', 'Key pair alias specified via [`ClientCertKeyPairAlias`](https://chromium.googlesource.com/chromium/src/+/main/components/onc/docs/onc_spec.md#eap-type) field in `openNetworkConfiguration` does not correspond to an existing key installed on the device. `nonComplianceReason` is set to `INVALID_VALUE`.', 'This policy setting is restricted and cannot be set for this Google Cloud Platform project. More details (including how to enable usage of this policy setting) are available in the [Permissible Usage policy] (https://developers.google.com/android/management/permissible-usage). `nonComplianceReason` is set to `PROJECT_NOT_PERMITTED`.', 'Work account required by the `workAccountSetupConfig` policy setting is not part of the enterprise anymore. `nonComplianceReason` is set to `USER_ACTION`.', 'Work account added by the user is not part of the enterprise. `nonComplianceReason` is set to `USER_ACTION`.', 'The default application setting is applied to the scopes that are not supported by the management mode, even if the management mode itself is supported for the app type (e.g., a policy with `DEFAULT_BROWSER` app type and [`SCOPE_PERSONAL_PROFILE`] list sent to a fully managed device results in the scopes being inapplicable for the management mode). If the management mode is not supported for the app type, a `NonComplianceDetail` with `MANAGEMENT_MODE` is reported, without a `specificNonComplianceReason`. `nonComplianceReason` is set to `MANAGEMENT_MODE`.', 'The default application setting failed to apply for a specific scope. `defaultApplicationContext` is set. `nonComplianceReason` is set to `INVALID_VALUE` or `APP_NOT_INSTALLED`.', 'The specified host for private DNS is a valid hostname but was found to not be a private DNS server. `nonComplianceReason` is set to `INVALID_VALUE`.']}, 'specificNonComplianceContext': {'$ref': '#/$defs/SpecificNonComplianceContext', 'description': 'Additional context for `specific_non_compliance_reason`.'}}, 'description': 'Provides detail about non-compliance with a policy setting.'}, 'PasswordRequirements': {'type': 'object', 'properties': {'passwordScope': {'enum': ['SCOPE_UNSPECIFIED', 'SCOPE_DEVICE', 'SCOPE_PROFILE'], 'type': 'string', 'description': 'Optional. The scope that the password requirement applies to.', 'x-google-enum-descriptions': ['The scope is unspecified. The password requirements are applied to the work profile for work profile devices and the whole device for fully managed or dedicated devices.', 'The password requirements are only applied to the device.', 'The password requirements are only applied to the work profile.']}, 'passwordQuality': {'enum': ['PASSWORD_QUALITY_UNSPECIFIED', 'BIOMETRIC_WEAK', 'SOMETHING', 'NUMERIC', 'NUMERIC_COMPLEX', 'ALPHABETIC', 'ALPHANUMERIC', 'COMPLEX', 'COMPLEXITY_LOW', 'COMPLEXITY_MEDIUM', 'COMPLEXITY_HIGH'], 'type': 'string', 'description': 'Optional. The required password quality.', 'x-google-enum-descriptions': ['There are no password requirements.', 'The device must be secured with a low-security biometric recognition technology, at minimum. This includes technologies that can recognize the identity of an individual that are roughly equivalent to a 3-digit PIN (false detection is less than 1 in 1,000). This, when applied on personally owned work profile devices on Android 12 device-scoped, will be treated as `COMPLEXITY_LOW` for application. See `PasswordQuality` for details.', 'A password is required, but there are no restrictions on what the password must contain. This, when applied on personally owned work profile devices on Android 12 device-scoped, will be treated as `COMPLEXITY_LOW` for application. See `PasswordQuality` for details.', 'The password must contain numeric characters. This, when applied on personally owned work profile devices on Android 12 device-scoped, will be treated as `COMPLEXITY_MEDIUM` for application. See `PasswordQuality` for details.', 'The password must contain numeric characters with no repeating (4444) or ordered (1234, 4321, 2468) sequences. This, when applied on personally owned work profile devices on Android 12 device-scoped, will be treated as `COMPLEXITY_MEDIUM` for application. See `PasswordQuality` for details.', 'The password must contain alphabetic (or symbol) characters. This, when applied on personally owned work profile devices on Android 12 device-scoped, will be treated as `COMPLEXITY_HIGH` for application. See `PasswordQuality` for details.', 'The password must contain both numeric and alphabetic (or symbol) characters. This, when applied on personally owned work profile devices on Android 12 device-scoped, will be treated as `COMPLEXITY_HIGH` for application. See `PasswordQuality` for details.', 'The password must meet the minimum requirements specified in `passwordMinimumLength`, `passwordMinimumLetters`, `passwordMinimumSymbols`, etc. For example, if `passwordMinimumSymbols` is `2`, the password must contain at least two symbols. This, when applied on personally owned work profile devices on Android 12 device-scoped, will be treated as `COMPLEXITY_HIGH` for application. In this case, the requirements in `passwordMinimumLength`, `passwordMinimumLetters`, `passwordMinimumSymbols`, etc are not applied. See `PasswordQuality` for details.', 'Define the low password complexity band as: * pattern * PIN with repeating (4444) or ordered (1234, 4321, 2468) sequences This sets the minimum complexity band which the password must meet. Enforcement varies among different Android versions, management modes and password scopes. See `PasswordQuality` for details.', 'Define the medium password complexity band as: * PIN with no repeating (4444) or ordered (1234, 4321, 2468) sequences, length at least 4 * alphabetic, length at least 4 * alphanumeric, length at least 4 This sets the minimum complexity band which the password must meet. Enforcement varies among different Android versions, management modes and password scopes. See `PasswordQuality` for details.', 'Define the high password complexity band as: On Android 12 and above: * PIN with no repeating (4444) or ordered (1234, 4321, 2468) sequences, length at least 8 * alphabetic, length at least 6 * alphanumeric, length at least 6 This sets the minimum complexity band which the password must meet. Enforcement varies among different Android versions, management modes and password scopes. See `PasswordQuality` for details.']}, 'unifiedLockSettings': {'enum': ['UNIFIED_LOCK_SETTINGS_UNSPECIFIED', 'ALLOW_UNIFIED_WORK_AND_PERSONAL_LOCK', 'REQUIRE_SEPARATE_WORK_LOCK'], 'type': 'string', 'description': 'Optional. Controls whether a unified lock is allowed for the device and the work profile, on devices running Android 9 and above with a work profile. This can be set only if `password_scope` is set to `SCOPE_PROFILE`, the policy will be rejected otherwise. If user has not set a separate work lock and this field is set to `REQUIRE_SEPARATE_WORK_LOCK`, a `NonComplianceDetail` is reported with `nonComplianceReason` set to `USER_ACTION`.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `ALLOW_UNIFIED_WORK_AND_PERSONAL_LOCK`.', 'A common lock for the device and the work profile is allowed.', 'A separate lock for the work profile is required.']}, 'passwordHistoryLength': {'type': 'integer', 'format': 'int32', 'description': "Optional. The length of the password history. After setting this field, the user won't be able to enter a new password that is the same as any password in the history. A value of 0 means there is no restriction."}, 'passwordMinimumLength': {'type': 'integer', 'format': 'int32', 'description': 'Optional. The minimum allowed password length. A value of 0 means there is no restriction. Only enforced when `password_quality` is `NUMERIC`, `NUMERIC_COMPLEX`, `ALPHABETIC`, `ALPHANUMERIC`, or `COMPLEX`.'}, 'requirePasswordUnlock': {'enum': ['REQUIRE_PASSWORD_UNLOCK_UNSPECIFIED', 'USE_DEFAULT_DEVICE_TIMEOUT', 'REQUIRE_EVERY_DAY'], 'type': 'string', 'description': 'Optional. The length of time after a device or work profile is unlocked using a strong form of authentication (password, PIN, pattern) that it can be unlocked using any other authentication method (e.g. fingerprint, trust agents, face). After the specified time period elapses, only strong forms of authentication can be used to unlock the device or work profile.', 'x-google-enum-descriptions': ['Unspecified. Defaults to USE_DEFAULT_DEVICE_TIMEOUT.', 'The timeout period is set to the device’s default.', 'The timeout period is set to 24 hours.']}, 'passwordMinimumLetters': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Minimum number of letters required in the password. Only enforced when `password_quality` is `COMPLEX`.'}, 'passwordMinimumNumeric': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Minimum number of numerical digits required in the password. Only enforced when `password_quality` is `COMPLEX`.'}, 'passwordMinimumSymbols': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Minimum number of symbols required in the password. Only enforced when `password_quality` is `COMPLEX`.'}, 'passwordMinimumLowerCase': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Minimum number of lower case letters required in the password. Only enforced when `password_quality` is `COMPLEX`.'}, 'passwordMinimumNonLetter': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Minimum number of non-letter characters (numerical digits or symbols) required in the password. Only enforced when `password_quality` is `COMPLEX`.'}, 'passwordMinimumUpperCase': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Minimum number of upper case letters required in the password. Only enforced when `password_quality` is `COMPLEX`.'}, 'passwordExpirationTimeout': {'type': 'string', 'format': 'google-duration', 'description': 'Optional. Password expiration timeout.'}, 'maximumFailedPasswordsForWipe': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Number of incorrect device-unlock passwords that can be entered before a device is wiped. A value of 0 means there is no restriction.'}}, 'description': 'Requirements for the password used to unlock a device.'}, 'PowerManagementEvent': {'type': 'object', 'properties': {'eventType': {'enum': ['POWER_MANAGEMENT_EVENT_TYPE_UNSPECIFIED', 'BATTERY_LEVEL_COLLECTED', 'POWER_CONNECTED', 'POWER_DISCONNECTED', 'BATTERY_LOW', 'BATTERY_OKAY', 'BOOT_COMPLETED', 'SHUTDOWN'], 'type': 'string', 'description': 'Event type.', 'x-google-enum-descriptions': ['Unspecified. No events have this type.', 'Battery level was measured.', 'The device started charging.', 'The device stopped charging.', 'The device entered low-power mode.', 'The device exited low-power mode.', 'The device booted.', 'The device shut down.']}, 'createTime': {'type': 'string', 'format': 'date-time', 'description': 'The creation time of the event.'}, 'batteryLevel': {'type': 'number', 'format': 'float', 'description': 'For `BATTERY_LEVEL_COLLECTED` events, the battery level as a percentage.'}}, 'description': 'A power management event.'}, 'CommonCriteriaModeInfo': {'type': 'object', 'properties': {'commonCriteriaModeStatus': {'enum': ['COMMON_CRITERIA_MODE_STATUS_UNKNOWN', 'COMMON_CRITERIA_MODE_DISABLED', 'COMMON_CRITERIA_MODE_ENABLED'], 'type': 'string', 'description': 'Whether Common Criteria Mode is enabled.', 'x-google-enum-descriptions': ['Unknown status.', 'Common Criteria Mode is currently disabled.', 'Common Criteria Mode is currently enabled.']}, 'policySignatureVerificationStatus': {'enum': ['POLICY_SIGNATURE_VERIFICATION_STATUS_UNSPECIFIED', 'POLICY_SIGNATURE_VERIFICATION_DISABLED', 'POLICY_SIGNATURE_VERIFICATION_SUCCEEDED', 'POLICY_SIGNATURE_VERIFICATION_NOT_SUPPORTED', 'POLICY_SIGNATURE_VERIFICATION_FAILED'], 'type': 'string', 'readOnly': True, 'description': 'Output only. The status of policy signature verification.', 'x-google-enum-descriptions': ['Unspecified. The verification status has not been reported. This is set only if `statusReportingSettings.commonCriteriaModeEnabled` is false.', 'Policy signature verification is disabled on the device as `common_criteria_mode` is set to false.', 'Policy signature verification succeeded.', 'Policy signature verification is not supported, e.g. because the device has been enrolled with a CloudDPC version that does not support the policy signature verification.', 'The policy signature verification failed. The policy has not been applied.']}}, 'description': "Information about Common Criteria Mode—security standards defined in the [Common Criteria for Information Technology Security Evaluation](https://www.commoncriteriaportal.org/) (CC). This information is only available if [`statusReportingSettings.commonCriteriaModeEnabled`](/android/management/reference/rest/v1/enterprises.policies#statusreportingsettings) is `true` in the device's policy."}, 'DefaultApplicationInfo': {'type': 'object', 'properties': {'packageName': {'type': 'string', 'readOnly': True, 'description': 'Output only. The package name of the current default application.'}, 'defaultApplicationType': {'enum': ['DEFAULT_APPLICATION_TYPE_UNSPECIFIED', 'DEFAULT_ASSISTANT', 'DEFAULT_BROWSER', 'DEFAULT_CALL_REDIRECTION', 'DEFAULT_CALL_SCREENING', 'DEFAULT_DIALER', 'DEFAULT_HOME', 'DEFAULT_SMS', 'DEFAULT_WALLET'], 'type': 'string', 'readOnly': True, 'description': 'Output only. The default application type.', 'x-google-enum-descriptions': ['Unspecified. This value must not be used.', 'The assistant app type. This app type is only allowed to be set for `SCOPE_FULLY_MANAGED`. Supported on fully managed devices on Android 16 and above. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for other management modes. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 16.', 'The browser app type. Supported on Android 16 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 16.', 'The call redirection app type. This app type cannot be set for `SCOPE_PERSONAL_PROFILE`. Supported on Android 16 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 16.', 'The call screening app type. This app type cannot be set for `SCOPE_PERSONAL_PROFILE`. Supported on Android 16 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 16.', 'The dialer app type. Supported on fully managed devices on Android 14 and 15. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for other management modes. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 14. Supported on all management modes on Android 16 and above.', 'The home app type. This app type is only allowed to be set for `SCOPE_FULLY_MANAGED`. Supported on fully managed devices on Android 16 and above. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for other management modes. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 16.', 'The SMS app type. This app type cannot be set for `SCOPE_WORK_PROFILE`. Supported on company-owned devices on Android 16 and above. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for personally-owned devices. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 16.', 'The wallet app type. The default application of this type applies across profiles. On a company-owned device with a work profile, admins can set the scope to `SCOPE_PERSONAL_PROFILE` to set a personal profile pre-installed system app as the default, or to `SCOPE_WORK_PROFILE` to set a work profile app as the default. It is not allowed to specify both scopes at the same time. Due to a known issue, the user may be able to change the default wallet even when this is set on a fully managed device. Supported on company-owned devices on Android 16 and above. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for personally-owned devices. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 16.']}, 'defaultApplicationSettingAttempts': {'type': 'array', 'items': {'$ref': '#/$defs/DefaultApplicationSettingAttempt'}, 'readOnly': True, 'description': 'Output only. Details on the default application setting attempts, in the same order as listed in `defaultApplications`.'}}, 'description': 'The default application information for a specific `DefaultApplicationType`.'}, 'PasswordPoliciesContext': {'type': 'object', 'properties': {'passwordPolicyScope': {'enum': ['SCOPE_UNSPECIFIED', 'SCOPE_DEVICE', 'SCOPE_PROFILE'], 'type': 'string', 'description': 'The scope of non-compliant password.', 'x-google-enum-descriptions': ['The scope is unspecified. The password requirements are applied to the work profile for work profile devices and the whole device for fully managed or dedicated devices.', 'The password requirements are only applied to the device.', 'The password requirements are only applied to the work profile.']}}, 'description': 'Additional context for non-compliance related to password policies.'}, 'ApplicationSigningKeyCert': {'type': 'object', 'properties': {'signingKeyCertFingerprintSha256': {'type': 'string', 'format': 'byte', 'description': 'Required. The SHA-256 hash value of the signing key certificate of the app. This must be a valid SHA-256 hash value, i.e. 32 bytes.'}}, 'description': 'The application signing key certificate.'}, 'DefaultApplicationContext': {'type': 'object', 'properties': {'defaultApplicationScope': {'enum': ['DEFAULT_APPLICATION_SCOPE_UNSPECIFIED', 'SCOPE_FULLY_MANAGED', 'SCOPE_WORK_PROFILE', 'SCOPE_PERSONAL_PROFILE'], 'type': 'string', 'readOnly': True, 'description': 'Output only. The scope of non-compliant default application setting.', 'x-google-enum-descriptions': ['Unspecified. This value must not be used.', 'Sets the application as the default on fully managed devices.', 'Sets the application as the work profile default. Only supported for `DEFAULT_BROWSER`, `DEFAULT_CALL_REDIRECTION`, `DEFAULT_CALL_SCREENING`, `DEFAULT_DIALER` and `DEFAULT_WALLET`.', 'Sets the application as the personal profile default on company-owned devices with a work profile. Only pre-installed system apps can be set as the default. Only supported for `DEFAULT_BROWSER`, `DEFAULT_DIALER`, `DEFAULT_SMS` and `DEFAULT_WALLET`.']}}, 'description': 'Additional context for non-compliance related to default application settings.'}, 'SpecificNonComplianceContext': {'type': 'object', 'properties': {'oncWifiContext': {'$ref': '#/$defs/OncWifiContext', 'description': 'Additional context for non-compliance related to Wi-Fi configuration. See `ONC_WIFI_INVALID_VALUE` and `ONC_WIFI_API_LEVEL`'}, 'passwordPoliciesContext': {'$ref': '#/$defs/PasswordPoliciesContext', 'description': 'Additional context for non-compliance related to password policies. See `PASSWORD_POLICIES_PASSWORD_EXPIRED` and `PASSWORD_POLICIES_PASSWORD_NOT_SUFFICIENT`.'}, 'defaultApplicationContext': {'$ref': '#/$defs/DefaultApplicationContext', 'readOnly': True, 'description': 'Output only. Additional context for non-compliance related to default application settings. See `DEFAULT_APPLICATION_SETTING_FAILED_FOR_SCOPE`.'}}, 'description': 'Additional context for `SpecificNonComplianceReason`.'}, 'DefaultApplicationSettingAttempt': {'type': 'object', 'properties': {'packageName': {'type': 'string', 'readOnly': True, 'description': 'Output only. The package name of the attempted application.'}, 'attemptOutcome': {'enum': ['ATTEMPT_OUTCOME_UNSPECIFIED', 'SUCCESS', 'APP_NOT_INSTALLED', 'APP_SIGNING_CERT_MISMATCH', 'OTHER_FAILURE'], 'type': 'string', 'readOnly': True, 'description': 'Output only. The outcome of setting the app as the default.', 'x-google-enum-descriptions': ['Attempt outcome is unspecified. This is not used.', 'App is successfully set as the default.', 'Attempt failed as the app is not installed.', 'Attempt failed as the signing key certificate fingerprint of the app from Play Store or from `ApplicationPolicy.signingKeyCerts` does not match the one on the device.', 'Attempt failed due to other reasons.']}}, 'description': 'Details on a default application setting attempt.'}}, 'properties': {'devices': {'type': 'array', 'items': {'$ref': '#/$defs/Device'}, 'description': 'The list of devices.'}, 'nextPageToken': {'type': 'string', 'description': 'If there are more results, a token to retrieve next page of results.'}}, 'description': 'Response to a request to list devices for a given enterprise.'}
输入模式
{'type': 'object', 'required': ['projectId'], 'properties': {'view': {'enum': ['ENTERPRISE_VIEW_UNSPECIFIED', 'BASIC'], 'type': 'string', 'description': 'Specifies which Enterprise fields to return. This method only supports BASIC.', 'x-google-enum-descriptions': ['The API will default to the BASIC view for the List method.', 'Includes name and enterprise_display_name fields.']}, 'pageSize': {'type': 'integer', 'format': 'int32', 'description': 'The requested page size. The actual page size may be fixed to a min or max value.'}, 'pageToken': {'type': 'string', 'description': 'A token identifying a page of results returned by the server.'}, 'projectId': {'type': 'string', 'description': 'Required. The Cloud project ID of the EMM managing the enterprises.'}}, 'description': 'Request to list EMM-managed enterprises.'}
输出模式
{'type': 'object', '$defs': {'Enterprise': {'type': 'object', 'properties': {'logo': {'$ref': '#/$defs/ExternalData', 'description': 'An image displayed as a logo during device provisioning. Supported types are: image/bmp, image/gif, image/x-ico, image/jpeg, image/png, image/webp, image/vnd.wap.wbmp, image/x-adobe-dng.'}, 'name': {'type': 'string', 'description': 'The name of the enterprise which is generated by the server during creation, in the form `enterprises/{enterpriseId}`.'}, 'contactInfo': {'$ref': '#/$defs/ContactInfo', 'description': 'The enterprise contact info of an EMM-managed enterprise.'}, 'pubsubTopic': {'type': 'string', 'description': 'The topic which Pub/Sub notifications are published to, in the form `projects/{project}/topics/{topic}`. This field is only required if [Pub/Sub notifications are enabled](/android/management/notifications).'}, 'primaryColor': {'type': 'integer', 'format': 'int32', 'description': 'A color in RGB format that indicates the predominant color to display in the device management app UI. The color components are stored as follows: `(red << 16) | (green << 8) | blue`, where the value of each component is between 0 and 255, inclusive.'}, 'signinDetails': {'type': 'array', 'items': {'$ref': '#/$defs/SigninDetail'}, 'description': 'Sign-in details of the enterprise.'}, 'enterpriseType': {'enum': ['ENTERPRISE_TYPE_UNSPECIFIED', 'MANAGED_GOOGLE_DOMAIN', 'MANAGED_GOOGLE_PLAY_ACCOUNTS_ENTERPRISE'], 'type': 'string', 'readOnly': True, 'description': 'Output only. The type of the enterprise.', 'x-google-enum-descriptions': ['This value is not used.', 'The enterprise belongs to a [managed Google domain](https://developers.google.com/android/work/terminology#managed_google_domain).', 'The enterprise is a [managed Google Play Accounts enterprise](https://developers.google.com/android/work/terminology#managed_google_play_accounts_enterprise).']}, 'termsAndConditions': {'type': 'array', 'items': {'$ref': '#/$defs/TermsAndConditions'}, 'description': 'Terms and conditions that must be accepted when provisioning a device for this enterprise. A page of terms is generated for each value in this list.'}, 'enterpriseDisplayName': {'type': 'string', 'description': 'The name of the enterprise displayed to users. This field has a maximum length of 100 characters.'}, 'appAutoApprovalEnabled': {'type': 'boolean', 'deprecated': True, 'description': 'Deprecated and unused.'}, 'managedGoogleDomainType': {'enum': ['MANAGED_GOOGLE_DOMAIN_TYPE_UNSPECIFIED', 'TYPE_TEAM', 'TYPE_DOMAIN'], 'type': 'string', 'readOnly': True, 'description': 'Output only. The type of managed Google domain.', 'x-google-enum-descriptions': ['The managed Google domain type is not specified.', 'The managed Google domain is an email-verified team.', 'The managed Google domain is domain-verified.']}, 'enabledNotificationTypes': {'type': 'array', 'items': {'enum': ['NOTIFICATION_TYPE_UNSPECIFIED', 'ENROLLMENT', 'COMPLIANCE_REPORT', 'STATUS_REPORT', 'COMMAND', 'USAGE_LOGS', 'ENTERPRISE_UPGRADE'], 'type': 'string', 'x-google-enum-deprecated': [False, False, True, False, False, False, False], 'x-google-enum-descriptions': ['This value is ignored.', 'A notification sent when a device enrolls.', 'Deprecated.', 'A notification sent when a device issues a status report.', 'A notification sent when a device command has completed.', 'A notification sent when device sends `BatchUsageLogEvents`.', 'A notification sent for an enterprise upgrade. An enterprise upgrade is a process that upgrades a managed Google Play Accounts enterprise to a managed Google domain.']}, 'description': 'The types of Google Pub/Sub notifications enabled for the enterprise.'}, 'googleAuthenticationSettings': {'$ref': '#/$defs/GoogleAuthenticationSettings', 'description': 'Settings for Google-provided user authentication.'}, 'managedGooglePlayAccountsEnterpriseType': {'enum': ['MANAGED_GOOGLE_PLAY_ACCOUNTS_ENTERPRISE_TYPE_UNSPECIFIED', 'CUSTOMER_MANAGED', 'EMM_MANAGED'], 'type': 'string', 'readOnly': True, 'description': 'Output only. The type of a managed Google Play Accounts enterprise.', 'x-google-enum-descriptions': ['The managed Google Play Accounts enterprise type is not specified.', 'The enterprise is customer-managed', 'The enterprise is EMM-managed (deprecated).']}}, 'description': 'The configuration applied to an enterprise.'}, 'ContactInfo': {'type': 'object', 'properties': {'contactEmail': {'type': 'string', 'description': 'Email address for a point of contact, which will be used to send important announcements related to managed Google Play.'}, 'euRepresentativeName': {'type': 'string', 'description': 'The name of the EU representative.'}, 'euRepresentativeEmail': {'type': 'string', 'description': 'The email of the EU representative. The email is validated but not verified.'}, 'euRepresentativePhone': {'type': 'string', 'description': 'The phone number of the EU representative. The phone number is validated but not verified.'}, 'dataProtectionOfficerName': {'type': 'string', 'description': 'The name of the data protection officer.'}, 'dataProtectionOfficerEmail': {'type': 'string', 'description': 'The email of the data protection officer. The email is validated but not verified.'}, 'dataProtectionOfficerPhone': {'type': 'string', 'description': 'The phone number of the data protection officer The phone number is validated but not verified.'}}, 'description': 'Contact details for managed Google Play enterprises.'}, 'ExternalData': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': "The absolute URL to the data, which must use either the http or https scheme. Android Device Policy doesn't provide any credentials in the GET request, so the URL must be publicly accessible. Including a long, random component in the URL may be used to prevent attackers from discovering the URL."}, 'sha256Hash': {'type': 'string', 'description': "The base-64 encoded SHA-256 hash of the content hosted at url. If the content doesn't match this hash, Android Device Policy won't use the data."}}, 'description': 'Data hosted at an external location. The data is to be downloaded by Android Device Policy and verified against the hash.'}, 'SigninDetail': {'type': 'object', 'properties': {'qrCode': {'type': 'string', 'description': 'A JSON string whose UTF-8 representation can be used to generate a QR code to enroll a device with this enrollment token. To enroll a device using NFC, the NFC record must contain a serialized `java.util.Properties` representation of the properties in the JSON. This is a read-only field generated by the server.'}, 'tokenTag': {'type': 'string', 'description': 'An EMM-specified metadata to distinguish between instances of `SigninDetail`.'}, 'signinUrl': {'type': 'string', 'description': 'Sign-in URL for authentication when device is provisioned with a sign-in enrollment token. The sign-in endpoint should finish authentication flow with a URL in the form of https://enterprise.google.com/android/enroll?et= for a successful login, or https://enterprise.google.com/android/enroll/invalid for a failed login.'}, 'defaultStatus': {'enum': ['SIGNIN_DETAIL_DEFAULT_STATUS_UNSPECIFIED', 'SIGNIN_DETAIL_IS_DEFAULT', 'SIGNIN_DETAIL_IS_NOT_DEFAULT'], 'type': 'string', 'description': "Optional. Whether the sign-in URL should be used by default for the enterprise. The `SigninDetail` with `defaultStatus` set to SIGNIN_DETAIL_IS_DEFAULT is used for Google account enrollment method. Only one of an enterprise's signinDetails can have `defaultStatus` set to SIGNIN_DETAIL_IS_DEFAULT. If an `Enterprise` has at least one signinDetails and none of them have `defaultStatus` set to SIGNIN_DETAIL_IS_DEFAULT then the first one from the list is selected and has set `defaultStatus` to SIGNIN_DETAIL_IS_DEFAULT. If no signinDetails specified for the `Enterprise` then the Google Account device enrollment will fail.", 'x-google-enum-descriptions': ['Equivalent to `SIGNIN_DETAIL_IS_NOT_DEFAULT`.', 'The sign-in URL will be used by default for the enterprise.', 'The sign-in URL will not be used by default for the enterprise.']}, 'allowPersonalUsage': {'enum': ['ALLOW_PERSONAL_USAGE_UNSPECIFIED', 'PERSONAL_USAGE_ALLOWED', 'PERSONAL_USAGE_DISALLOWED', 'PERSONAL_USAGE_DISALLOWED_USERLESS'], 'type': 'string', 'description': 'Controls whether personal usage is allowed on a device provisioned with this enrollment token. For company-owned devices: * Enabling personal usage allows the user to set up a work profile on the device. * Disabling personal usage requires the user provision the device as a fully managed device. For personally-owned devices: * Enabling personal usage allows the user to set up a work profile on the device. * Disabling personal usage will prevent the device from provisioning. Personal usage cannot be disabled on personally-owned device.', 'x-google-enum-descriptions': ['Personal usage restriction is not specified', 'Personal usage is allowed', 'Personal usage is disallowed', 'Device is not associated with a single user, and thus both personal usage and corporate identity authentication are not expected. **Important:** This setting is mandatory for dedicated device enrollment and it is a breaking change. This change needs to be implemented before January 2025. For additional details see the [dedicated device provisioning guide](https://developers.google.com/android/management/provision-device#company-owned_devices_for_work_use_only). ']}, 'signinEnrollmentToken': {'type': 'string', 'description': 'An enterprise wide enrollment token used to trigger custom sign-in flow. This is a read-only field generated by the server.'}, 'googleAuthenticationOptions': {'$ref': '#/$defs/SigninDetailGoogleAuthenticationOptions', 'description': 'Optional. Options related to Google authentication during the enrollment.'}}, 'description': 'A resource containing sign in details for an enterprise. Use `enterprises` to manage `SigninDetail`s for a given enterprise. For an enterprise, we can have any number of `SigninDetail`s that is uniquely identified by combination of the following three fields (`signin_url`, `allow_personal_usage`, `token_tag`). One cannot create two `SigninDetail`s with the same (`signin_url`, `allow_personal_usage`, `token_tag`). (`token_tag` is an optional field). `Patch`: The operation updates the current list of `SigninDetails` with the new list of `SigninDetails`. * If the stored `SigninDetail` configuration is passed, it returns the same `signin_enrollment_token` and `qr_code`. * If we pass multiple identical `SigninDetail` configurations that are not stored, it will store the first one amongst those `SigninDetail` configurations. * if the configuration already exists we cannot request it more than once in a particular patch API call, otherwise it will give a duplicate key error and the whole operation will fail. * If we remove certain `SigninDetail` configuration from the request then it will get removed from the storage. We can then request another `signin_enrollment_token` and `qr_code` for the same `SigninDetail` configuration.'}, 'UserFacingMessage': {'type': 'object', 'properties': {'defaultMessage': {'type': 'string', 'description': "The default message displayed if no localized message is specified or the user's locale doesn't match with any of the localized messages. A default message must be provided if any localized messages are provided."}, 'localizedMessages': {'type': 'object', 'description': 'A map containing pairs, where locale is a well-formed [BCP 47 language](https://www.w3.org/International/articles/language-tags/) code, such as en-US, es-ES, or fr.', 'additionalProperties': {'type': 'string'}}}, 'description': 'Provides a user-facing message with locale info. The maximum message length is 4096 characters.'}, 'TermsAndConditions': {'type': 'object', 'properties': {'header': {'$ref': '#/$defs/UserFacingMessage', 'description': 'A short header which appears above the HTML content.'}, 'content': {'$ref': '#/$defs/UserFacingMessage', 'description': 'A well-formatted HTML string. It will be parsed on the client with android.text.Html#fromHtml.'}}, 'description': 'A terms and conditions page to be accepted during provisioning.'}, 'GoogleAuthenticationSettings': {'type': 'object', 'properties': {'googleAuthenticationRequired': {'enum': ['GOOGLE_AUTHENTICATION_REQUIRED_UNSPECIFIED', 'NOT_REQUIRED', 'REQUIRED'], 'type': 'string', 'readOnly': True, 'description': 'Output only. Whether users need to be authenticated by Google during the enrollment process. IT admin can specify if Google authentication is enabled for the enterprise for knowledge worker devices. This value can be set only via the Google Admin Console. Google authentication can be used with `signin_url` In the case where Google authentication is required and a `signin_url` is specified, Google authentication will be launched before `signin_url`. This value is overridden by `EnrollmentToken.googleAuthenticationOptions` and `SigninDetail.googleAuthenticationOptions`, if they are set.', 'x-google-enum-descriptions': ['This value is not used.', 'Google authentication is not required.', 'User is required to be successfully authenticated by Google.']}}, 'description': 'Contains settings for Google-provided user authentication.'}, 'SigninDetailGoogleAuthenticationOptions': {'type': 'object', 'properties': {'authenticationRequirement': {'enum': ['AUTHENTICATION_REQUIREMENT_UNSPECIFIED', 'OPTIONAL', 'REQUIRED'], 'type': 'string', 'description': 'Optional. Specifies whether user should authenticate with Google during enrollment. If this is set to any value other than `AUTHENTICATION_REQUIREMENT_UNSPECIFIED`, the enterprise-level setting `googleAuthenticationSettings` is ignored for devices enrolled with this sign-in detail.', 'x-google-enum-descriptions': ['The setting `googleAuthenticationSettings` for the enterprise that this sign-in detail belongs to is used to determine whether the user needs to authenticate with Google during enrollment.', 'Google authentication is optional for the user. This means the user can choose to skip Google authentication during enrollment.', 'Google authentication is required for the user. This means the user must authenticate with a Google account to proceed.']}}, 'description': 'Options for Google authentication during the enrollment. These options control whether the Google authentication screen is shown, and whether it can be skipped, at the start of the sign-in flow. More requirements can be enforced by `EnrollmentToken.googleAuthenticationOptions` on the EnrollmentToken that is created later.'}}, 'properties': {'enterprises': {'type': 'array', 'items': {'$ref': '#/$defs/Enterprise'}, 'description': 'The list of enterprises.'}, 'nextPageToken': {'type': 'string', 'description': 'If there are more results, a token to retrieve next page of results.'}}, 'description': 'Response to a request to list enterprises.'}
输入模式
{'type': 'object', 'properties': {'parent': {'type': 'string', 'description': 'The name of the enterprise in the form `enterprises/{enterpriseId}`.'}, 'pageSize': {'type': 'integer', 'format': 'int32', 'description': 'The requested page size. The actual page size may be fixed to a min or max value.'}, 'pageToken': {'type': 'string', 'description': 'A token identifying a page of results returned by the server.'}}, 'description': 'Request to list policies for a given enterprise.'}
输出模式
{'type': 'object', '$defs': {'Date': {'type': 'object', 'properties': {'day': {'type': 'integer', 'format': 'int32', 'description': "Day of a month. Must be from 1 to 31 and valid for the year and month, or 0 to specify a year by itself or a year and month where the day isn't significant."}, 'year': {'type': 'integer', 'format': 'int32', 'description': 'Year of the date. Must be from 1 to 9999, or 0 to specify a date without a year.'}, 'month': {'type': 'integer', 'format': 'int32', 'description': 'Month of a year. Must be from 1 to 12, or 0 to specify a year without a month and day.'}}, 'description': 'Represents a whole or partial calendar date, such as a birthday. The time of day and time zone are either specified elsewhere or are insignificant. The date is relative to the Gregorian Calendar. This can represent one of the following: * A full date, with non-zero year, month, and day values. * A month and day, with a zero year (for example, an anniversary). * A year on its own, with a zero month and a zero day. * A year and month, with a zero day (for example, a credit card expiration date). Related types: * google.type.TimeOfDay * google.type.DateTime * google.protobuf.Timestamp'}, 'Role': {'type': 'object', 'properties': {'roleType': {'enum': ['ROLE_TYPE_UNSPECIFIED', 'COMPANION_APP', 'KIOSK', 'MOBILE_THREAT_DEFENSE_ENDPOINT_DETECTION_RESPONSE', 'SYSTEM_HEALTH_MONITORING'], 'type': 'string', 'description': 'Required. The type of the role an app can have.', 'x-google-enum-descriptions': ['The role type is unspecified. This value must not be used.', 'The role type for companion apps. This role enables the app as a companion app with the capability of interacting with Android Device Policy offline. This is the recommended way to configure an app as a companion app. For legacy way, see `extensionConfig`. On Android 14 and above, the app with this role is exempted from power and background execution restrictions, suspension and hibernation. On Android 11 and above, the user control is disallowed for the app with this role. `userControlSettings` cannot be set to `USER_CONTROL_ALLOWED` for the app with this role. Android Device Policy notifies the companion app of any local command status updates if the app has a service with ``. See [Integrate with the AMAPI SDK](https://developers.google.com/android/management/sdk-integration) guide for more details on the requirements for the service.', 'The role type for kiosk apps. An app can have this role only if it has `installType` set to `REQUIRED_FOR_SETUP` or `CUSTOM`. Before adding this role to an app with `CUSTOM` install type, the app must already be installed on the device. The app having this role type is set as the preferred home intent and allowlisted for lock task mode. When there is an app with this role type, status bar will be automatically disabled. This is preferable to setting `installType` to `KIOSK`. On Android 11 and above, when an app has this role, the user control is disallowed for all apps. The IT admin can set `userControlSettings` to `USER_CONTROL_ALLOWED` to allow user control for specific apps.', 'The role type for Mobile Threat Defense (MTD) / Endpoint Detection & Response (EDR) apps. On Android 14 and above, the app with this role is exempted from power and background execution restrictions, suspension and hibernation. On Android 11 and above, the user control is disallowed and `userControlSettings` cannot be set to `USER_CONTROL_ALLOWED` for the app with this role.', 'The role type for system health monitoring apps. On Android 14 and above, the app with this role is exempted from power and background execution restrictions, suspension and hibernation. On Android 11 and above, the user control is disallowed and `userControlSettings` cannot be set to `USER_CONTROL_ALLOWED` for the app with this role.']}}, 'description': 'Role an app can have.'}, 'Policy': {'type': 'object', 'properties': {'name': {'type': 'string', 'description': 'The name of the policy in the form `enterprises/{enterpriseId}/policies/{policyId}`.'}, 'version': {'type': 'string', 'format': 'int64', 'description': 'The version of the policy. This is a read-only field. The version is incremented each time the policy is updated.'}, 'usageLog': {'$ref': '#/$defs/UsageLog', 'description': 'Configuration of device activity logging.'}, 'funDisabled': {'type': 'boolean', 'description': 'Whether the user is allowed to have fun. Controls whether the Easter egg game in Settings is disabled.'}, 'smsDisabled': {'type': 'boolean', 'description': 'Whether sending and receiving SMS messages is disabled.'}, 'appFunctions': {'enum': ['APP_FUNCTIONS_UNSPECIFIED', 'APP_FUNCTIONS_DISALLOWED', 'APP_FUNCTIONS_ALLOWED'], 'type': 'string', 'description': 'Optional. Controls whether apps on the device for fully managed devices or in the work profile for devices with work profiles are allowed to expose app functions.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `APP_FUNCTIONS_ALLOWED`.', 'Apps on the device for fully managed devices or in the work profile for devices with work profiles are not allowed to expose app functions. If this is set, `crossProfileAppFunctions` must not be set to `CROSS_PROFILE_APP_FUNCTIONS_ALLOWED`, otherwise the policy will be rejected.', 'Apps on the device for fully managed devices or in the work profile for devices with work profiles are allowed to expose app functions.']}, 'applications': {'type': 'array', 'items': {'$ref': '#/$defs/ApplicationPolicy'}, 'description': 'Policy applied to apps. This can have at most 3,000 elements.'}, 'cameraAccess': {'enum': ['CAMERA_ACCESS_UNSPECIFIED', 'CAMERA_ACCESS_USER_CHOICE', 'CAMERA_ACCESS_DISABLED', 'CAMERA_ACCESS_ENFORCED'], 'type': 'string', 'description': 'Controls the use of the camera and whether the user has access to the camera access toggle.', 'x-google-enum-descriptions': ['If `camera_disabled` is true, this is equivalent to `CAMERA_ACCESS_DISABLED`. Otherwise, this is equivalent to `CAMERA_ACCESS_USER_CHOICE`.', 'The field `camera_disabled` is ignored. This is the default device behaviour: all cameras on the device are available. On Android 12 and above, the user can use the camera access toggle.', 'The field `camera_disabled` is ignored. All cameras on the device are disabled (for fully managed devices, this applies device-wide and for work profiles this applies only to the work profile). There are no explicit restrictions placed on the camera access toggle on Android 12 and above: on fully managed devices, the camera access toggle has no effect as all cameras are disabled. On devices with a work profile, this toggle has no effect on apps in the work profile, but it affects apps outside the work profile.', 'The field `camera_disabled` is ignored. All cameras on the device are available. On fully managed devices running Android 12 and above, the user is unable to use the camera access toggle. On devices which are not fully managed or which run Android 11 or below, this is equivalent to `CAMERA_ACCESS_USER_CHOICE`.']}, 'locationMode': {'enum': ['LOCATION_MODE_UNSPECIFIED', 'HIGH_ACCURACY', 'SENSORS_ONLY', 'BATTERY_SAVING', 'OFF', 'LOCATION_USER_CHOICE', 'LOCATION_ENFORCED', 'LOCATION_DISABLED'], 'type': 'string', 'description': 'The degree of location detection enabled.', 'x-google-enum-deprecated': [False, True, True, True, True, False, False, False], 'x-google-enum-descriptions': ['Defaults to `LOCATION_USER_CHOICE`.', 'On Android 8 and below, all location detection methods are enabled, including GPS, networks, and other sensors. On Android 9 and above, this is equivalent to `LOCATION_ENFORCED`.', 'On Android 8 and below, only GPS and other sensors are enabled. On Android 9 and above, this is equivalent to `LOCATION_ENFORCED`.', 'On Android 8 and below, only the network location provider is enabled. On Android 9 and above, this is equivalent to `LOCATION_ENFORCED`.', 'On Android 8 and below, location setting and accuracy are disabled. On Android 9 and above, this is equivalent to `LOCATION_DISABLED`.', 'Location setting is not restricted on the device. No specific behavior is set or enforced.', "Enable location setting on the device. **Important:** On Android 11 and above, work profiles on company-owned devices cannot directly enforce enabling of location services. When `LOCATION_ENFORCED` is set, then a `NonComplianceDetail` with `USER_ACTION` is reported. Compliance can only be restored once the user manually turns on location services through the device's Settings application. ", "Disable location setting on the device. **Important:** On Android 11 and above, work profiles on company-owned devices cannot directly enforce disabling of location services. When `LOCATION_DISABLED` is set, then a `nonComplianceDetail` with `USER_ACTION` is reported. Compliance can only be restored once the user manually turns off location services through the device's Settings application. "]}, 'setupActions': {'type': 'array', 'items': {'$ref': '#/$defs/SetupAction'}, 'description': 'Action to take during the setup process. At most one action may be specified.'}, 'systemUpdate': {'$ref': '#/$defs/SystemUpdate', 'description': 'The system update policy, which controls how OS updates are applied. If the update type is `WINDOWED`, the update window will automatically apply to Play app updates as well. **Note:** [Google Play system updates](https://source.android.com/docs/core/ota/modular-system) (also called Mainline updates) are automatically downloaded and require a device reboot to be installed. Refer to the mainline section in [Manage system updates](https://developer.android.com/work/dpc/system-updates#mainline) for further details.'}, 'backupService': {'enum': ['BACKUP_SERVICE_UNSPECIFIED', 'BACKUP_SERVICE_DISABLED', 'BACKUP_SERVICE_USER_CHOICE'], 'type': 'string', 'description': 'Optional. Controls whether the backup service is disabled. Supported only on fully managed devices running Android 8 and above.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `BACKUP_SERVICE_DISABLED`.', 'Backup service is disabled. The user is not allowed to change this setting. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 8 on a fully managed device.', 'The user can enable or disable the backup service. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 8 on a fully managed device.']}, 'playStoreMode': {'enum': ['PLAY_STORE_MODE_UNSPECIFIED', 'WHITELIST', 'BLACKLIST'], 'type': 'string', 'description': 'This mode controls which apps are available to the user in the Play Store and the behavior on the device when apps are removed from the policy.', 'x-google-enum-descriptions': ['Unspecified. Defaults to WHITELIST.', 'Only apps that are in the policy are available and any app not in the policy will be automatically uninstalled from the device.', "All apps are available and any app that should not be on the device should be explicitly marked as 'BLOCKED' in the `applications` policy."]}, 'wipeDataFlags': {'type': 'array', 'items': {'enum': ['WIPE_DATA_FLAG_UNSPECIFIED', 'WIPE_ESIMS'], 'type': 'string', 'x-google-enum-descriptions': ['This value must not be used.', 'For company-owned devices, setting this in `wipeDataFlags` will remove all eSIMs on the device when wipe is triggered due to any reason. On personally-owned devices, this will remove only managed eSIMs on the device (eSIMs which are added via the `ADD_ESIM` command). This is supported on devices running Android 15 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 15. For devices running on Android 16 or higher, managed eSIMs are always wiped when work profile is removed for personally-owned devices, whether this flag is provided or not.']}, 'description': 'Optional. Wipe flags to indicate what data is wiped when a device or profile wipe is triggered due to any reason (for example, non-compliance). This does not apply to the `enterprises.devices.delete` method. . This list must not have duplicates.'}, 'autofillPolicy': {'enum': ['AUTOFILL_POLICY_UNSPECIFIED', 'AUTOFILL_USER_CHOICE', 'AUTOFILL_DISABLED'], 'type': 'string', 'description': 'Optional. The policy for the autofill service.', 'x-google-enum-descriptions': ['Defaults to `AUTOFILL_USER_CHOICE`.', 'The user can choose and use an autofill service.', 'Autofill is disabled and the user is not allowed to change this setting. This is supported only on Android 8 and above.']}, 'cameraDisabled': {'type': 'boolean', 'deprecated': True, 'description': 'If `camera_access` is set to any value other than `CAMERA_ACCESS_UNSPECIFIED`, this has no effect. Otherwise this field controls whether cameras are disabled: If true, all cameras are disabled, otherwise they are available. For fully managed devices this field applies for all apps on the device. For work profiles, this field applies only to apps in the work profile, and the camera access of apps outside the work profile is unaffected.'}, 'frpAdminEmails': {'type': 'array', 'items': {'type': 'string'}, 'description': "Email addresses of device administrators for factory reset protection. When the device is factory reset, it will require one of these admins to log in with the Google account email and password to unlock the device. If no admins are specified, the device won't provide factory reset protection."}, 'printingPolicy': {'enum': ['PRINTING_POLICY_UNSPECIFIED', 'PRINTING_DISALLOWED', 'PRINTING_ALLOWED'], 'type': 'string', 'description': 'Optional. Controls whether printing is allowed. This is supported on devices running Android 9 and above. .', 'x-google-enum-descriptions': ['Unspecified. Defaults to `PRINTING_ALLOWED`.', 'Printing is disallowed. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 9.', 'Printing is allowed.']}, 'addUserDisabled': {'type': 'boolean', 'description': 'Whether adding new users and profiles is disabled. For devices where `managementMode` is `DEVICE_OWNER` this field is ignored and the user is never allowed to add or remove users.'}, 'complianceRules': {'type': 'array', 'items': {'$ref': '#/$defs/ComplianceRule'}, 'deprecated': True, 'description': 'Rules declaring which mitigating actions to take when a device is not compliant with its policy. When the conditions for multiple rules are satisfied, all of the mitigating actions for the rules are taken. There is a maximum limit of 100 rules. Use policy enforcement rules instead.'}, 'displaySettings': {'$ref': '#/$defs/DisplaySettings', 'description': 'Optional. Controls for the display settings.'}, 'minimumApiLevel': {'type': 'integer', 'format': 'int32', 'description': 'The minimum allowed Android API level.'}, 'autoTimeRequired': {'type': 'boolean', 'deprecated': True, 'description': 'Whether auto time is required, which prevents the user from manually setting the date and time. If [`autoDateAndTimeZone`](/android/management/reference/rest/v1/enterprises.policies#autodateandtimezone) is set, this field is ignored.'}, 'deviceRadioState': {'$ref': '#/$defs/DeviceRadioState', 'description': 'Optional. Covers controls for radio state such as Wi-Fi, bluetooth, and more.'}, 'encryptionPolicy': {'enum': ['ENCRYPTION_POLICY_UNSPECIFIED', 'ENABLED_WITHOUT_PASSWORD', 'ENABLED_WITH_PASSWORD'], 'type': 'string', 'description': 'Whether encryption is enabled', 'x-google-enum-descriptions': ['This value is ignored, i.e. no encryption required', 'Encryption required but no password required to boot', 'Encryption required with password required to boot']}, 'keyguardDisabled': {'type': 'boolean', 'description': 'If true, this disables the [Lock Screen](https://source.android.com/docs/core/display/multi_display/lock-screen) for primary and/or secondary displays. This policy is supported only in dedicated device management mode.'}, 'microphoneAccess': {'enum': ['MICROPHONE_ACCESS_UNSPECIFIED', 'MICROPHONE_ACCESS_USER_CHOICE', 'MICROPHONE_ACCESS_DISABLED', 'MICROPHONE_ACCESS_ENFORCED'], 'type': 'string', 'description': 'Controls the use of the microphone and whether the user has access to the microphone access toggle. This applies only on fully managed devices.', 'x-google-enum-descriptions': ['If `unmute_microphone_disabled` is true, this is equivalent to `MICROPHONE_ACCESS_DISABLED`. Otherwise, this is equivalent to `MICROPHONE_ACCESS_USER_CHOICE`.', 'The field `unmute_microphone_disabled` is ignored. This is the default device behaviour: the microphone on the device is available. On Android 12 and above, the user can use the microphone access toggle.', 'The field `unmute_microphone_disabled` is ignored. The microphone on the device is disabled (for fully managed devices, this applies device-wide). The microphone access toggle has no effect as the microphone is disabled.', 'The field `unmute_microphone_disabled` is ignored. The microphone on the device is available. On devices running Android 12 and above, the user is unable to use the microphone access toggle. On devices which run Android 11 or below, this is equivalent to `MICROPHONE_ACCESS_USER_CHOICE`.']}, 'passwordPolicies': {'type': 'array', 'items': {'$ref': '#/$defs/PasswordRequirements'}, 'description': 'Optional. Password requirement policies. Different policies can be set for work profile or fully managed devices by setting the `password_scope` field in the policy.'}, 'permissionGrants': {'type': 'array', 'items': {'$ref': '#/$defs/PermissionGrant'}, 'description': 'Explicit permission or group grants or denials for all apps. These values override the `default_permission_policy`.'}, 'safeBootDisabled': {'type': 'boolean', 'deprecated': True, 'description': 'Whether rebooting the device into safe boot is disabled.'}, 'bluetoothDisabled': {'type': 'boolean', 'description': 'Whether bluetooth is disabled. Prefer this setting over `bluetooth_config_disabled` because `bluetooth_config_disabled` can be bypassed by the user.'}, 'maximumTimeToLock': {'type': 'string', 'format': 'int64', 'description': 'Maximum time in milliseconds for user activity until the device locks. A value of 0 means there is no restriction.'}, 'statusBarDisabled': {'type': 'boolean', 'deprecated': True, 'description': 'Whether the status bar is disabled. This disables notifications, quick settings, and other screen overlays that allow escape from full-screen mode. DEPRECATED. To disable the status bar on a kiosk device, use [InstallType](/android/management/reference/rest/v1/enterprises.policies#installtype) `KIOSK` or `kioskCustomLauncherEnabled`.'}, 'vpnConfigDisabled': {'type': 'boolean', 'description': 'Whether configuring VPN is disabled.'}, 'alwaysOnVpnPackage': {'$ref': '#/$defs/AlwaysOnVpnPackage', 'description': 'Configuration for an always-on VPN connection. Use with `vpn_config_disabled` to prevent modification of this setting.'}, 'kioskCustomization': {'$ref': '#/$defs/KioskCustomization', 'description': 'Optional. Settings controlling the behavior of a device in kiosk mode. To enable kiosk mode, set `kioskCustomLauncherEnabled` to `true` or specify an app in the policy with `installType` `KIOSK`.'}, 'longSupportMessage': {'$ref': '#/$defs/UserFacingMessage', 'description': 'A message displayed to the user in the device administators settings screen.'}, 'removeUserDisabled': {'type': 'boolean', 'description': 'Whether removing other users is disabled.'}, 'stayOnPluggedModes': {'type': 'array', 'items': {'enum': ['BATTERY_PLUGGED_MODE_UNSPECIFIED', 'AC', 'USB', 'WIRELESS'], 'type': 'string', 'x-google-enum-descriptions': ['This value is ignored.', 'Power source is an AC charger.', 'Power source is a USB port.', 'Power source is wireless.']}, 'description': "The battery plugged in modes for which the device stays on. When using this setting, it is recommended to clear `maximum_time_to_lock` so that the device doesn't lock itself while it stays on."}, 'wifiConfigDisabled': {'type': 'boolean', 'deprecated': True, 'description': "Whether configuring Wi-Fi networks is disabled. Supported on fully managed devices and work profiles on company-owned devices. For fully managed devices, setting this to true removes all configured networks and retains only the networks configured using `openNetworkConfiguration`. For work profiles on company-owned devices, existing configured networks are not affected and the user is not allowed to add, remove, or modify Wi-Fi networks. If `configureWifi` is set to anything other than `CONFIGURE_WIFI_UNSPECIFIED`, this setting is ignored. **Note:** If a network connection can't be made at boot time and configuring Wi-Fi is disabled then network escape hatch will be shown in order to refresh the device policy (see `networkEscapeHatchEnabled`)."}, 'appAutoUpdatePolicy': {'enum': ['APP_AUTO_UPDATE_POLICY_UNSPECIFIED', 'CHOICE_TO_THE_USER', 'NEVER', 'WIFI_ONLY', 'ALWAYS'], 'type': 'string', 'description': 'Recommended alternative: `autoUpdateMode` which is set per app, provides greater flexibility around update frequency. When `autoUpdateMode` is set to `AUTO_UPDATE_POSTPONED` or `AUTO_UPDATE_HIGH_PRIORITY`, this field has no effect. The app auto update policy, which controls when automatic app updates can be applied.', 'x-google-enum-descriptions': ['The auto-update policy is not set. Equivalent to `CHOICE_TO_THE_USER`.', 'The user can control auto-updates.', 'Apps are never auto-updated.', 'Apps are auto-updated over Wi-Fi only.', 'Apps are auto-updated at any time. Data charges may apply.']}, 'assistContentPolicy': {'enum': ['ASSIST_CONTENT_POLICY_UNSPECIFIED', 'ASSIST_CONTENT_DISALLOWED', 'ASSIST_CONTENT_ALLOWED'], 'type': 'string', 'description': 'Optional. Controls whether [AssistContent](https://developer.android.com/reference/android/app/assist/AssistContent) is allowed to be sent to a privileged app such as an assistant app. AssistContent includes screenshots and information about an app, such as package name. This is supported on Android 15 and above.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `ASSIST_CONTENT_ALLOWED`.', 'Assist content is blocked from being sent to a privileged app. Supported on Android 15 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 15.', 'Assist content is allowed to be sent to a privileged app. Supported on Android 15 and above.']}, 'autoDateAndTimeZone': {'enum': ['AUTO_DATE_AND_TIME_ZONE_UNSPECIFIED', 'AUTO_DATE_AND_TIME_ZONE_USER_CHOICE', 'AUTO_DATE_AND_TIME_ZONE_ENFORCED'], 'type': 'string', 'description': 'Whether auto date, time, and time zone are enabled on a company-owned device. If this is set, then [`autoTimeRequired`](/android/management/reference/rest/v1/enterprises.policies#autoTimeRequired) is ignored.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `AUTO_DATE_AND_TIME_ZONE_USER_CHOICE`.', "Auto date, time, and time zone are left to user's choice.", 'Enforce auto date, time, and time zone on the device.']}, 'crossDevicePolicies': {'$ref': '#/$defs/CrossDevicePolicies', 'description': 'Optional. Policies controlling cross-device communication.'}, 'dataRoamingDisabled': {'type': 'boolean', 'description': 'Whether roaming data services are disabled.'}, 'installAppsDisabled': {'type': 'boolean', 'description': 'Whether user installation of apps is disabled.'}, 'setUserIconDisabled': {'type': 'boolean', 'description': 'Whether changing the user icon is disabled. This applies only on devices running Android 7 and above.'}, 'shortSupportMessage': {'$ref': '#/$defs/UserFacingMessage', 'description': 'A message displayed to the user in the settings screen wherever functionality has been disabled by the admin. If the message is longer than 200 characters it may be truncated.'}, 'adjustVolumeDisabled': {'type': 'boolean', 'description': 'Whether adjusting the master volume is disabled. Also mutes the device. The setting has effect only on fully managed devices.'}, 'crossProfilePolicies': {'$ref': '#/$defs/CrossProfilePolicies', 'description': 'Optional. Cross-profile policies applied on the device.'}, 'factoryResetDisabled': {'type': 'boolean', 'description': 'Whether factory resetting from settings is disabled.'}, 'networkResetDisabled': {'type': 'boolean', 'description': 'Whether resetting network settings is disabled. This applies only on fully managed devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for other management modes.'}, 'outgoingBeamDisabled': {'type': 'boolean', 'description': 'Whether using NFC to beam data from apps is disabled.'}, 'passwordRequirements': {'$ref': '#/$defs/PasswordRequirements', 'deprecated': True, 'description': 'Password requirements. The field `password_requirements.require_password_unlock` must not be set. DEPRECATED - Use `passwordPolicies`. **Note:** Complexity-based values of `PasswordQuality`, that is, `COMPLEXITY_LOW`, `COMPLEXITY_MEDIUM`, and `COMPLEXITY_HIGH`, cannot be used here. `unified_lock_settings` cannot be used here.'}, 'setWallpaperDisabled': {'type': 'boolean', 'description': 'Whether changing the wallpaper is disabled.'}, 'choosePrivateKeyRules': {'type': 'array', 'items': {'$ref': '#/$defs/ChoosePrivateKeyRule'}, 'description': "Rules for determining apps' access to private keys. See `ChoosePrivateKeyRule` for details. This must be empty if any application has `CERT_SELECTION` delegation scope."}, 'createWindowsDisabled': {'type': 'boolean', 'description': 'Whether creating windows besides app windows is disabled.'}, 'outgoingCallsDisabled': {'type': 'boolean', 'description': 'Whether outgoing calls are disabled.'}, 'permittedInputMethods': {'$ref': '#/$defs/PackageNameList', 'description': 'If present, only the input methods provided by packages in this list are permitted. If this field is present, but the list is empty, then only system input methods are permitted.'}, 'personalUsagePolicies': {'$ref': '#/$defs/PersonalUsagePolicies', 'description': 'Policies managing personal usage on a company-owned device.'}, 'screenCaptureDisabled': {'type': 'boolean', 'description': 'Whether screen capture is disabled. This also blocks [Circle to Search](https://support.google.com/android/answer/14508957).'}, 'shareLocationDisabled': {'type': 'boolean', 'description': 'Whether location sharing is disabled.'}, 'uninstallAppsDisabled': {'type': 'boolean', 'description': 'Whether user uninstallation of applications is disabled. This prevents apps from being uninstalled, even those removed using `applications`'}, 'usbMassStorageEnabled': {'type': 'boolean', 'deprecated': True, 'description': 'Whether USB storage is enabled. Deprecated.'}, 'modifyAccountsDisabled': {'type': 'boolean', 'description': 'Whether adding or removing accounts is disabled.'}, 'policyEnforcementRules': {'type': 'array', 'items': {'$ref': '#/$defs/PolicyEnforcementRule'}, 'description': 'Rules that define the behavior when a particular policy can not be applied on device'}, 'recommendedGlobalProxy': {'$ref': '#/$defs/ProxyInfo', 'description': 'The network-independent global HTTP proxy. Typically proxies should be configured per-network in `open_network_configuration`. However for unusual configurations like general internal filtering a global HTTP proxy may be useful. If the proxy is not accessible, network access may break. The global proxy is only a recommendation and some apps may ignore it.'}, 'workAccountSetupConfig': {'$ref': '#/$defs/WorkAccountSetupConfig', 'description': 'Optional. Controls the work account setup configuration, such as details of whether a Google authenticated account is required.'}, 'bluetoothConfigDisabled': {'type': 'boolean', 'description': 'Whether configuring bluetooth is disabled.'}, 'defaultPermissionPolicy': {'enum': ['PERMISSION_POLICY_UNSPECIFIED', 'PROMPT', 'GRANT', 'DENY'], 'type': 'string', 'description': 'The default permission policy for runtime permission requests.', 'x-google-enum-descriptions': ['Policy not specified. If no policy is specified for a permission at any level, then the `PROMPT` behavior is used by default.', 'Prompt the user to grant a permission.', 'Automatically grant a permission. On Android 12 and above, [`READ_SMS`](https://developer.android.com/reference/android/Manifest.permission#READ_SMS) and following sensor-related permissions can only be granted on fully managed devices: * [`ACCESS_FINE_LOCATION`](https://developer.android.com/reference/android/Manifest.permission#ACCESS_FINE_LOCATION) * [`ACCESS_BACKGROUND_LOCATION`](https://developer.android.com/reference/android/Manifest.permission#ACCESS_BACKGROUND_LOCATION) * [`ACCESS_COARSE_LOCATION`](https://developer.android.com/reference/android/Manifest.permission#ACCESS_COARSE_LOCATION) * [`CAMERA`](https://developer.android.com/reference/android/Manifest.permission#CAMERA) * [`RECORD_AUDIO`](https://developer.android.com/reference/android/Manifest.permission#RECORD_AUDIO) * [`ACTIVITY_RECOGNITION`](https://developer.android.com/reference/android/Manifest.permission#ACTIVITY_RECOGNITION) * [`BODY_SENSORS`](https://developer.android.com/reference/android/Manifest.permission#BODY_SENSORS)', 'Automatically deny a permission.']}, 'ensureVerifyAppsEnabled': {'type': 'boolean', 'deprecated': True, 'description': 'Whether app verification is force-enabled.'}, 'oncCertificateProviders': {'type': 'array', 'items': {'$ref': '#/$defs/OncCertificateProvider'}, 'description': ' This feature is not generally available.'}, 'statusReportingSettings': {'$ref': '#/$defs/StatusReportingSettings', 'description': 'Status reporting settings'}, 'tetheringConfigDisabled': {'type': 'boolean', 'deprecated': True, 'description': 'Whether configuring tethering and portable hotspots is disabled. If `tetheringSettings` is set to anything other than `TETHERING_SETTINGS_UNSPECIFIED`, this setting is ignored.'}, 'usbFileTransferDisabled': {'type': 'boolean', 'deprecated': True, 'description': 'Whether transferring files over USB is disabled. This is supported only on company-owned devices.'}, 'blockApplicationsEnabled': {'type': 'boolean', 'deprecated': True, 'description': 'This field has no effect.'}, 'debuggingFeaturesAllowed': {'type': 'boolean', 'deprecated': True, 'description': 'Whether the user is allowed to enable debugging features.'}, 'keyguardDisabledFeatures': {'type': 'array', 'items': {'enum': ['KEYGUARD_DISABLED_FEATURE_UNSPECIFIED', 'CAMERA', 'NOTIFICATIONS', 'UNREDACTED_NOTIFICATIONS', 'TRUST_AGENTS', 'DISABLE_FINGERPRINT', 'DISABLE_REMOTE_INPUT', 'FACE', 'IRIS', 'BIOMETRICS', 'SHORTCUTS', 'ALL_FEATURES'], 'type': 'string', 'x-google-enum-descriptions': ['This value is ignored.', 'Disable the camera on secure keyguard screens (e.g. PIN).', 'Disable showing all notifications on secure keyguard screens.', 'Disable unredacted notifications on secure keyguard screens.', 'Ignore trust agent state on secure keyguard screens.', 'Disable fingerprint sensor on secure keyguard screens.', 'On devices running Android 6 and below, disables text entry into notifications on secure keyguard screens. Has no effect on Android 7 and above.', 'Disable face authentication on secure keyguard screens.', 'Disable iris authentication on secure keyguard screens.', 'Disable all biometric authentication on secure keyguard screens.', 'Disable all shortcuts on secure keyguard screen on Android 14 and above.', 'Disable all current and future keyguard customizations.']}, 'description': 'Disabled keyguard customizations, such as widgets.'}, 'openNetworkConfiguration': {'type': 'object', 'description': 'Network configuration for the device. See [configure networks](/android/management/configure-networks) for more information.', 'additionalProperties': {'description': 'Properties of the object.'}}, 'skipFirstUseHintsEnabled': {'type': 'boolean', 'description': 'Flag to skip hints on the first use. Enterprise admin can enable the system recommendation for apps to skip their user tutorial and other introductory hints on first start-up.'}, 'unmuteMicrophoneDisabled': {'type': 'boolean', 'deprecated': True, 'description': 'If `microphone_access` is set to any value other than `MICROPHONE_ACCESS_UNSPECIFIED`, this has no effect. Otherwise this field controls whether microphones are disabled: If true, all microphones are disabled, otherwise they are available. This is available only on fully managed devices.'}, 'advancedSecurityOverrides': {'$ref': '#/$defs/AdvancedSecurityOverrides', 'description': 'Optional. Advanced security settings. In most cases, setting these is not needed.'}, 'androidDevicePolicyTracks': {'type': 'array', 'items': {'enum': ['APP_TRACK_UNSPECIFIED', 'PRODUCTION', 'BETA'], 'type': 'string', 'x-google-enum-descriptions': ['This value is ignored.', 'The production track, which provides the latest stable release.', 'The beta track, which provides the latest beta release.']}, 'deprecated': True, 'description': 'This setting is not supported. Any value is ignored.'}, 'credentialsConfigDisabled': {'type': 'boolean', 'description': 'Whether configuring user credentials is disabled.'}, 'deviceOwnerLockScreenInfo': {'$ref': '#/$defs/UserFacingMessage', 'description': 'The device owner information to be shown on the lock screen.'}, 'networkEscapeHatchEnabled': {'type': 'boolean', 'description': "Whether the network escape hatch is enabled. If a network connection can't be made at boot time, the escape hatch prompts the user to temporarily connect to a network in order to refresh the device policy. After applying policy, the temporary network will be forgotten and the device will continue booting. This prevents being unable to connect to a network if there is no suitable network in the last policy and the device boots into an app in lock task mode, or the user is otherwise unable to reach device settings. **Note:** Setting `wifiConfigDisabled` to true will override this setting under specific circumstances. Please see `wifiConfigDisabled` for further details. Setting `configureWifi` to `DISALLOW_CONFIGURING_WIFI` will override this setting under specific circumstances. Please see `DISALLOW_CONFIGURING_WIFI` for further details."}, 'defaultApplicationSettings': {'type': 'array', 'items': {'$ref': '#/$defs/DefaultApplicationSetting'}, 'description': 'Optional. The default application setting for supported types. If the default application is successfully set for at least one app type on a profile, users are prevented from changing *any* default applications on that profile. Only one `DefaultApplicationSetting` is allowed for each `DefaultApplicationType`. **Warning:** Do not configure this and `persistent_preferred_activities` for the same intent domain, such as web browsing. Setting both for the same intent domain can lead to unpredictable behavior. See [Default application settings](https://developers.google.com/android/management/default-application-settings) guide for more details.'}, 'kioskCustomLauncherEnabled': {'type': 'boolean', 'description': 'Whether the kiosk custom launcher is enabled. This replaces the home screen with a launcher that locks down the device to the apps installed via the `applications` setting. Apps appear on a single page in alphabetical order. Use [kioskCustomization](/android/management/reference/rest/v1/enterprises.policies#kioskcustomization) to further configure the kiosk device behavior.'}, 'mountPhysicalMediaDisabled': {'type': 'boolean', 'description': 'Whether the user mounting physical external media is disabled.'}, 'preferentialNetworkService': {'enum': ['PREFERENTIAL_NETWORK_SERVICE_UNSPECIFIED', 'PREFERENTIAL_NETWORK_SERVICE_DISABLED', 'PREFERENTIAL_NETWORK_SERVICE_ENABLED'], 'type': 'string', 'description': "Controls whether preferential network service is enabled on the work profile or on fully managed devices. For example, an organization may have an agreement with a carrier that all of the work data from its employees' devices will be sent via a network service dedicated for enterprise use. An example of a supported preferential network service is the enterprise slice on 5G networks. This policy has no effect if `preferentialNetworkServiceSettings` or `ApplicationPolicy.preferentialNetworkId` is set on devices running Android 13 or above.", 'x-google-enum-descriptions': ['Unspecified. Defaults to `PREFERENTIAL_NETWORK_SERVICES_DISABLED`.', 'Preferential network service is disabled on the work profile.', 'Preferential network service is enabled on the work profile. This setting is only supported on work profiles on devices running Android 12 or above. Starting with Android 13, fully managed devices are also supported.']}, 'privateKeySelectionEnabled': {'type': 'boolean', 'description': 'Allows showing UI on a device for a user to choose a private key alias if there are no matching rules in ChoosePrivateKeyRules. For devices below Android P, setting this may leave enterprise keys vulnerable. This value will have no effect if any application has `CERT_SELECTION` delegation scope.'}, 'wifiConfigsLockdownEnabled': {'type': 'boolean', 'deprecated': True, 'description': 'This is deprecated.'}, 'cellBroadcastsConfigDisabled': {'type': 'boolean', 'description': 'Whether configuring cell broadcast is disabled.'}, 'deviceConnectivityManagement': {'$ref': '#/$defs/DeviceConnectivityManagement', 'description': 'Covers controls for device connectivity such as Wi-Fi, USB data access, keyboard/mouse connections, and more.'}, 'installUnknownSourcesAllowed': {'type': 'boolean', 'deprecated': True, 'description': 'This field has no effect.'}, 'mobileNetworksConfigDisabled': {'type': 'boolean', 'description': 'Whether configuring mobile networks is disabled.'}, 'persistentPreferredActivities': {'type': 'array', 'items': {'$ref': '#/$defs/PersistentPreferredActivity'}, 'description': 'Default intent handler activities. **Warning:** Do not configure this and `default_application_settings` for the same intent domain, such as web browsing. Setting both for the same intent domain can lead to unpredictable behavior.'}, 'permittedAccessibilityServices': {'$ref': '#/$defs/PackageNameList', 'description': "Specifies permitted accessibility services. If the field is not set, any accessibility service can be used. If the field is set, only the accessibility services in this list and the system's built-in accessibility service can be used. In particular, if the field is set to empty, only the system's built-in accessibility servicess can be used. This can be set on fully managed devices and on work profiles. When applied to a work profile, this affects both the personal profile and the work profile."}, 'bluetoothContactSharingDisabled': {'type': 'boolean', 'description': 'Whether bluetooth contact sharing is disabled.'}, 'credentialProviderPolicyDefault': {'enum': ['CREDENTIAL_PROVIDER_POLICY_DEFAULT_UNSPECIFIED', 'CREDENTIAL_PROVIDER_DEFAULT_DISALLOWED', 'CREDENTIAL_PROVIDER_DEFAULT_DISALLOWED_EXCEPT_SYSTEM', 'CREDENTIAL_PROVIDER_DEFAULT_ALLOWED'], 'type': 'string', 'description': 'Optional. Controls which apps are allowed to act as credential providers on Android 14 and above. These apps store credentials, see [this](https://developer.android.com/training/sign-in/passkeys) and [this](https://developer.android.com/reference/androidx/credentials/CredentialManager) for details. See also `credentialProviderPolicy`.', 'x-google-enum-descriptions': ['Unspecified. Defaults to CREDENTIAL_PROVIDER_DEFAULT_DISALLOWED.', 'Apps with `credentialProviderPolicy` unspecified are not allowed to act as a credential provider.', 'Apps with `credentialProviderPolicy` unspecified are not allowed to act as a credential provider except for the OEM default credential providers. OEM default credential providers are always allowed to act as credential providers.', 'Apps with `credentialProviderPolicy` unspecified are allowed to act as a credential provider.']}, 'enterpriseDisplayNameVisibility': {'enum': ['ENTERPRISE_DISPLAY_NAME_VISIBILITY_UNSPECIFIED', 'ENTERPRISE_DISPLAY_NAME_VISIBLE', 'ENTERPRISE_DISPLAY_NAME_HIDDEN'], 'type': 'string', 'description': 'Optional. Controls whether the `enterpriseDisplayName` is visible on the device (e.g. lock screen message on company-owned devices).', 'x-google-enum-descriptions': ['Unspecified. Defaults to `ENTERPRISE_DISPLAY_NAME_VISIBLE`.', 'The enterprise display name is visible on the device. Supported on work profiles on Android 7 and above. Supported on fully managed devices on Android 8 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 7. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported on fully managed devices on Android 7.', 'The enterprise display name is hidden on the device.']}, 'accountTypesWithManagementDisabled': {'type': 'array', 'items': {'type': 'string'}, 'description': "Account types that can't be managed by the user."}}, 'description': 'A policy resource represents a group of settings that govern the behavior of a managed device and the apps installed on it.'}, 'UsageLog': {'type': 'object', 'properties': {'enabledLogTypes': {'type': 'array', 'items': {'enum': ['LOG_TYPE_UNSPECIFIED', 'SECURITY_LOGS', 'NETWORK_ACTIVITY_LOGS'], 'type': 'string', 'x-google-enum-descriptions': ['This value is not used.', 'Enable logging of on-device security events, such as when the device password is incorrectly entered or removable storage is mounted. See `UsageLogEvent` for a complete description of the logged security events. Supported for fully managed devices on Android 7 and above. Supported for company-owned devices with a work profile on Android 12 and above, on which only security events from the work profile are logged. Can be overridden by the application delegated scope `SECURITY_LOGS`', 'Enable logging of on-device network events, such as DNS lookups and TCP connections. See `UsageLogEvent` for a complete description of the logged network events. Supported for fully managed devices on Android 8 and above. Supported for company-owned devices with a work profile on Android 12 and above, on which only network events from the work profile are logged. Can be overridden by the application delegated scope `NETWORK_ACTIVITY_LOGS`']}, 'description': 'Specifies which log types are enabled. Note that users will receive on-device messaging when usage logging is enabled.'}, 'uploadOnCellularAllowed': {'type': 'array', 'items': {'enum': ['LOG_TYPE_UNSPECIFIED', 'SECURITY_LOGS', 'NETWORK_ACTIVITY_LOGS'], 'type': 'string', 'x-google-enum-descriptions': ['This value is not used.', 'Enable logging of on-device security events, such as when the device password is incorrectly entered or removable storage is mounted. See `UsageLogEvent` for a complete description of the logged security events. Supported for fully managed devices on Android 7 and above. Supported for company-owned devices with a work profile on Android 12 and above, on which only security events from the work profile are logged. Can be overridden by the application delegated scope `SECURITY_LOGS`', 'Enable logging of on-device network events, such as DNS lookups and TCP connections. See `UsageLogEvent` for a complete description of the logged network events. Supported for fully managed devices on Android 8 and above. Supported for company-owned devices with a work profile on Android 12 and above, on which only network events from the work profile are logged. Can be overridden by the application delegated scope `NETWORK_ACTIVITY_LOGS`']}, 'description': 'Specifies which of the enabled log types can be uploaded over mobile data. By default logs are queued for upload when the device connects to WiFi.'}}, 'description': 'Controls types of device activity logs collected from the device and reported via [Pub/Sub notification](https://developers.google.com/android/management/notifications).'}, 'WifiSsid': {'type': 'object', 'properties': {'wifiSsid': {'type': 'string', 'description': 'Required. Wi-Fi SSID represented as a string.'}}, 'description': 'Represents a Wi-Fi SSID.'}, 'ApnPolicy': {'type': 'object', 'properties': {'apnSettings': {'type': 'array', 'items': {'$ref': '#/$defs/ApnSetting'}, 'description': "Optional. APN settings for override APNs. There must not be any conflict between any of APN settings provided, otherwise the policy will be rejected. Two `ApnSetting`s are considered to conflict when all of the following fields match on both: `numericOperatorId`, `apn`, `proxyAddress`, `proxyPort`, `mmsProxyAddress`, `mmsProxyPort`, `mmsc`, `mvnoType`, `protocol`, `roamingProtocol`. If some of the APN settings result in non-compliance of `INVALID_VALUE` , they will be ignored. This can be set on fully managed devices on Android 10 and above. This can also be set on work profiles on Android 13 and above and only with `ApnSetting`'s with `ENTERPRISE` APN type. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 10. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles on Android versions less than 13."}, 'overrideApns': {'enum': ['OVERRIDE_APNS_UNSPECIFIED', 'OVERRIDE_APNS_DISABLED', 'OVERRIDE_APNS_ENABLED'], 'type': 'string', 'description': 'Optional. Whether override APNs are disabled or enabled. See [`DevicePolicyManager.setOverrideApnsEnabled`](https://developer.android.com/reference/android/app/admin/DevicePolicyManager#setOverrideApnsEnabled) for more details.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `OVERRIDE_APNS_DISABLED`.', 'Override APNs disabled. Any configured `apnSettings` are saved on the device, but are disabled and have no effect. Any other APNs on the device remain in use.', 'Override APNs enabled. Only override APNs are in use, any other APNs are ignored. This can only be set on fully managed devices on Android 10 and above. For work profiles override APNs are enabled via `preferentialNetworkServiceSettings` and this value cannot be set. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 10. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.']}}, 'description': 'Access Point Name (APN) policy. Configuration for Access Point Names (APNs) which may override any other APNs on the device. See `OVERRIDE_APNS_ENABLED` and `overrideApns` for details.'}, 'ProxyInfo': {'type': 'object', 'properties': {'host': {'type': 'string', 'description': 'The host of the direct proxy.'}, 'port': {'type': 'integer', 'format': 'int32', 'description': 'The port of the direct proxy.'}, 'pacUri': {'type': 'string', 'description': 'The URI of the PAC script used to configure the proxy.'}, 'excludedHosts': {'type': 'array', 'items': {'type': 'string'}, 'description': 'For a direct proxy, the hosts for which the proxy is bypassed. The host names may contain wildcards such as *.example.com.'}}, 'description': 'Configuration info for an HTTP proxy. For a direct proxy, set the `host`, `port`, and `excluded_hosts` fields. For a PAC script proxy, set the `pac_uri` field.'}, 'ApnSetting': {'type': 'object', 'properties': {'apn': {'type': 'string', 'description': 'Required. Name of the APN. Policy will be rejected if this field is empty.'}, 'mmsc': {'type': 'string', 'description': 'Optional. MMSC (Multimedia Messaging Service Center) URI of the APN.'}, 'mtuV4': {'type': 'integer', 'format': 'int32', 'description': 'Optional. The default MTU (Maximum Transmission Unit) size in bytes of the IPv4 routes brought up by this APN setting. A value of 0 (default) means not set and negative values are rejected. Supported on Android 13 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 13.'}, 'mtuV6': {'type': 'integer', 'format': 'int32', 'description': 'Optional. The MTU (Maximum Transmission Unit) size of the IPv6 mobile interface to which the APN connected. A value of 0 (default) means not set and negative values are rejected. Supported on Android 13 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 13.'}, 'apnTypes': {'type': 'array', 'items': {'enum': ['APN_TYPE_UNSPECIFIED', 'ENTERPRISE', 'BIP', 'CBS', 'DEFAULT', 'DUN', 'EMERGENCY', 'FOTA', 'HIPRI', 'IA', 'IMS', 'MCX', 'MMS', 'RCS', 'SUPL', 'VSIM', 'XCAP'], 'type': 'string', 'x-google-enum-descriptions': ['Unspecified. This value is not used.', 'APN type for enterprise traffic. Supported on Android 13 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 13.', 'APN type for BIP (Bearer Independent Protocol). This can only be set on fully managed devices on Android 12 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 12. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.', 'APN type for CBS (Carrier Branded Services). This can only be set on fully managed devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.', 'APN type for default data traffic. This can only be set on fully managed devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.', 'APN type for DUN (Dial-up networking) traffic. This can only be set on fully managed devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.', 'APN type for Emergency PDN. This is not an IA apn, but is used for access to carrier services in an emergency call situation. This can only be set on fully managed devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.', "APN type for accessing the carrier's FOTA (Firmware Over-the-Air) portal, used for over the air updates. This can only be set on fully managed devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.", 'APN type for HiPri (high-priority) traffic. This can only be set on fully managed devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.', 'APN type for IA (Initial Attach) APN. This can only be set on fully managed devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.', 'APN type for IMS (IP Multimedia Subsystem) traffic. This can only be set on fully managed devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.', 'APN type for MCX (Mission Critical Service) where X can be PTT/Video/Data. This can only be set on fully managed devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.', 'APN type for MMS (Multimedia Messaging Service) traffic. This can only be set on fully managed devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.', 'APN type for RCS (Rich Communication Services). This can only be set on fully managed devices on Android 15 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 15. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.', 'APN type for SUPL (Secure User Plane Location) assisted GPS. This can only be set on fully managed devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.', 'APN type for VSIM (Virtual SIM) service. This can only be set on fully managed devices on Android 12 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 12. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.', 'APN type for XCAP (XML Configuration Access Protocol) traffic. This can only be set on fully managed devices on Android 11 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 11. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for work profiles.']}, 'description': 'Required. Usage categories for the APN. Policy will be rejected if this field is empty or contains `APN_TYPE_UNSPECIFIED` or duplicates. Multiple APN types can be set on fully managed devices. `ENTERPRISE` is the only allowed APN type on work profiles. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for any other value on work profiles. APN types that are not supported on the device or management mode will be ignored. If this results in the empty list, the APN setting will be ignored, because `apnTypes` is a required field. A `NonComplianceDetail` with `INVALID_VALUE` is reported if none of the APN types are supported on the device or management mode.'}, 'authType': {'enum': ['AUTH_TYPE_UNSPECIFIED', 'NONE', 'PAP', 'CHAP', 'PAP_OR_CHAP'], 'type': 'string', 'description': 'Optional. Authentication type of the APN.', 'x-google-enum-descriptions': ['Unspecified. If `username` is empty, defaults to `NONE`. Otherwise, defaults to `PAP_OR_CHAP`.', 'Authentication is not required.', 'Authentication type for PAP.', 'Authentication type for CHAP.', 'Authentication type for PAP or CHAP.']}, 'mvnoType': {'enum': ['MVNO_TYPE_UNSPECIFIED', 'GID', 'ICCID', 'IMSI', 'SPN'], 'type': 'string', 'description': 'Optional. MVNO match type for the APN.', 'x-google-enum-descriptions': ['The MVNO type is not specified.', 'MVNO type for group identifier level 1.', 'MVNO type for ICCID.', 'MVNO type for IMSI.', 'MVNO type for SPN (service provider name).']}, 'password': {'type': 'string', 'description': 'Optional. APN password of the APN.'}, 'protocol': {'enum': ['PROTOCOL_UNSPECIFIED', 'IP', 'IPV4V6', 'IPV6', 'NON_IP', 'PPP', 'UNSTRUCTURED'], 'type': 'string', 'description': 'Optional. The protocol to use to connect to this APN.', 'x-google-enum-descriptions': ['The protocol is not specified.', 'Internet protocol.', 'Virtual PDP type introduced to handle dual IP stack UE capability.', 'Internet protocol, version 6.', 'Transfer of Non-IP data to external packet data network.', 'Point to point protocol.', 'Transfer of Unstructured data to the Data Network via N6.']}, 'username': {'type': 'string', 'description': 'Optional. APN username of the APN.'}, 'carrierId': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Carrier ID for the APN. A value of 0 (default) means not set and negative values are rejected.'}, 'proxyPort': {'type': 'integer', 'format': 'int32', 'description': 'Optional. The proxy port of the APN. A value of 0 (default) means not set and negative values are rejected.'}, 'displayName': {'type': 'string', 'description': 'Required. Human-readable name that describes the APN. Policy will be rejected if this field is empty.'}, 'mmsProxyPort': {'type': 'integer', 'format': 'int32', 'description': 'Optional. MMS (Multimedia Messaging Service) proxy port of the APN. A value of 0 (default) means not set and negative values are rejected.'}, 'networkTypes': {'type': 'array', 'items': {'enum': ['NETWORK_TYPE_UNSPECIFIED', 'EDGE', 'GPRS', 'GSM', 'HSDPA', 'HSPA', 'HSPAP', 'HSUPA', 'IWLAN', 'LTE', 'NR', 'TD_SCDMA', 'UMTS'], 'type': 'string', 'x-google-enum-descriptions': ['Unspecified. This value must not be used.', 'Radio technology EDGE.', 'Radio technology GPRS.', 'Radio technology GSM.', 'Radio technology HSDPA.', 'Radio technology HSPA.', 'Radio technology HSPAP.', 'Radio technology HSUPA.', 'Radio technology IWLAN.', 'Radio technology LTE.', 'Radio technology NR (New Radio) 5G.', 'Radio technology TD_SCDMA.', 'Radio technology UMTS.']}, 'description': 'Optional. Radio technologies (network types) the APN may use. Policy will be rejected if this field contains `NETWORK_TYPE_UNSPECIFIED` or duplicates.'}, 'proxyAddress': {'type': 'string', 'description': 'Optional. The proxy address of the APN.'}, 'alwaysOnSetting': {'enum': ['ALWAYS_ON_SETTING_UNSPECIFIED', 'NOT_ALWAYS_ON', 'ALWAYS_ON'], 'type': 'string', 'description': 'Optional. Whether User Plane resources have to be activated during every transition from CM-IDLE mode to CM-CONNECTED state for this APN. See 3GPP TS 23.501 section 5.6.13.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `NOT_ALWAYS_ON`.', 'The PDU session brought up by this APN should not be always on.', 'The PDU session brought up by this APN should always be on. Supported on Android 15 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 15.']}, 'mmsProxyAddress': {'type': 'string', 'description': 'Optional. MMS (Multimedia Messaging Service) proxy address of the APN which can be an IP address or hostname (not a URL).'}, 'roamingProtocol': {'enum': ['PROTOCOL_UNSPECIFIED', 'IP', 'IPV4V6', 'IPV6', 'NON_IP', 'PPP', 'UNSTRUCTURED'], 'type': 'string', 'description': 'Optional. The protocol to use to connect to this APN while the device is roaming.', 'x-google-enum-descriptions': ['The protocol is not specified.', 'Internet protocol.', 'Virtual PDP type introduced to handle dual IP stack UE capability.', 'Internet protocol, version 6.', 'Transfer of Non-IP data to external packet data network.', 'Point to point protocol.', 'Transfer of Unstructured data to the Data Network via N6.']}, 'numericOperatorId': {'type': 'string', 'description': 'Optional. The numeric operator ID of the APN. Numeric operator ID is defined as MCC (Mobile Country Code) + MNC (Mobile Network Code).'}}, 'description': 'An Access Point Name (APN) configuration for a carrier data connection. The APN provides configuration to connect a cellular network device to an IP data network. A carrier uses this setting to decide which IP address to assign, any security methods to apply, and how the device might be connected to private networks.'}, 'WipeAction': {'type': 'object', 'properties': {'preserveFrp': {'type': 'boolean', 'description': 'Whether the factory-reset protection data is preserved on the device. This setting applies to fully managed devices and work profiles on company-owned devices.'}, 'wipeAfterDays': {'type': 'integer', 'format': 'int32', 'description': 'Number of days the policy is non-compliant before the device or work profile is wiped. `wipeAfterDays` must be greater than `blockAfterDays`.'}}, 'description': 'An action to reset a company owned device or delete a work profile. Note: `blockAction` must also be specified.'}, 'BlockAction': {'type': 'object', 'properties': {'blockScope': {'enum': ['BLOCK_SCOPE_UNSPECIFIED', 'BLOCK_SCOPE_WORK_PROFILE', 'BLOCK_SCOPE_DEVICE'], 'type': 'string', 'description': 'Specifies the scope of this `BlockAction`. Only applicable to devices that are company-owned.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `BLOCK_SCOPE_WORK_PROFILE`.', 'Block action is only applied to apps in the work profile. Apps in the personal profile are unaffected.', 'Block action is applied to the entire device, including apps in the personal profile.']}, 'blockAfterDays': {'type': 'integer', 'format': 'int32', 'description': 'Number of days the policy is non-compliant before the device or work profile is blocked. To block access immediately, set to 0. `blockAfterDays` must be less than `wipeAfterDays`.'}}, 'description': 'An action to block access to apps and data on a fully managed device or in a work profile. This action also triggers a device or work profile to displays a user-facing notification with information (where possible) on how to correct the compliance issue. Note: `wipeAction` must also be specified.'}, 'SetupAction': {'type': 'object', 'properties': {'title': {'$ref': '#/$defs/UserFacingMessage', 'description': 'Title of this action.'}, 'launchApp': {'$ref': '#/$defs/LaunchAppAction', 'description': 'An action to launch an app. The app will be launched with an intent containing an extra with key `com.google.android.apps.work.clouddpc.EXTRA_LAUNCHED_AS_SETUP_ACTION` set to the boolean value `true` to indicate that this is a setup action flow. If `SetupAction` references an app, the corresponding `installType` in the application policy must be set as `REQUIRED_FOR_SETUP` or said setup will fail.'}, 'description': {'$ref': '#/$defs/UserFacingMessage', 'description': 'Description of this action.'}}, 'description': 'An action executed during setup.'}, 'FreezePeriod': {'type': 'object', 'properties': {'endDate': {'$ref': '#/$defs/Date', 'description': 'The end date (inclusive) of the freeze period. Must be no later than 90 days from the start date. If the end date is earlier than the start date, the freeze period is considered wrapping year-end. Note: `day` and `month` must be set. `year` should not be set as it is not used. For example, `{"month": 1,"date": 30}`.'}, 'startDate': {'$ref': '#/$defs/Date', 'description': 'The start date (inclusive) of the freeze period. Note: `day` and `month` must be set. `year` should not be set as it is not used. For example, `{"month": 1,"date": 30}`.'}}, 'description': 'A system freeze period. When a device’s clock is within the freeze period, all incoming system updates (including security patches) are blocked and won’t be installed. When the device is outside any set freeze periods, the normal policy behavior (automatic, windowed, or postponed) applies. Leap years are ignored in freeze period calculations, in particular: * If Feb. 29th is set as the start or end date of a freeze period, the freeze period will start or end on Feb. 28th instead. * When a device’s system clock reads Feb. 29th, it’s treated as Feb. 28th. * When calculating the number of days in a freeze period or the time between two freeze periods, Feb. 29th is ignored and not counted as a day. Note: For Freeze Periods to take effect, `SystemUpdateType` cannot be specified as `SYSTEM_UPDATE_TYPE_UNSPECIFIED`, because freeze periods require a defined policy to be specified.'}, 'SystemUpdate': {'type': 'object', 'properties': {'type': {'enum': ['SYSTEM_UPDATE_TYPE_UNSPECIFIED', 'AUTOMATIC', 'WINDOWED', 'POSTPONE'], 'type': 'string', 'description': 'The type of system update to configure.', 'x-google-enum-descriptions': ['Follow the default update behavior for the device, which typically requires the user to accept system updates.', 'Install automatically as soon as an update is available.', 'Install automatically within a daily maintenance window. This also configures Play apps to be updated within the window. This is strongly recommended for kiosk devices because this is the only way apps persistently pinned to the foreground can be updated by Play. If `autoUpdateMode` is set to `AUTO_UPDATE_HIGH_PRIORITY` for an app, then the maintenance window is ignored for that app and it is updated as soon as possible even outside of the maintenance window.', 'Postpone automatic install up to a maximum of 30 days. This policy does not affect security updates (e.g. monthly security patches).']}, 'endMinutes': {'type': 'integer', 'format': 'int32', 'description': "If the type is `WINDOWED`, the end of the maintenance window, measured as the number of minutes after midnight in device's local time. This value must be between 0 and 1439, inclusive. If this value is less than `start_minutes`, then the maintenance window spans midnight. If the maintenance window specified is smaller than 30 minutes, the actual window is extended to 30 minutes beyond the start time."}, 'startMinutes': {'type': 'integer', 'format': 'int32', 'description': "If the type is `WINDOWED`, the start of the maintenance window, measured as the number of minutes after midnight in the device's local time. This value must be between 0 and 1439, inclusive."}, 'freezePeriods': {'type': 'array', 'items': {'$ref': '#/$defs/FreezePeriod'}, 'description': 'An annually repeating time period in which over-the-air (OTA) system updates are postponed to freeze the OS version running on a device. To prevent freezing the device indefinitely, each freeze period must be separated by at least 60 days.'}}, 'description': 'Configuration for managing system updates **Note:** [Google Play system updates](https://source.android.com/docs/core/ota/modular-system) (also called Mainline updates) are automatically downloaded but require a device reboot to be installed. Refer to the mainline section in [Manage system updates](https://developer.android.com/work/dpc/system-updates#mainline) for further details.'}, 'ComplianceRule': {'type': 'object', 'properties': {'disableApps': {'type': 'boolean', 'description': 'If set to true, the rule includes a mitigating action to disable apps so that the device is effectively disabled, but app data is preserved. If the device is running an app in locked task mode, the app will be closed and a UI showing the reason for non-compliance will be displayed.'}, 'apiLevelCondition': {'$ref': '#/$defs/ApiLevelCondition', 'description': "A condition which is satisfied if the Android Framework API level on the device doesn't meet a minimum requirement."}, 'packageNamesToDisable': {'type': 'array', 'items': {'type': 'string'}, 'description': 'If set, the rule includes a mitigating action to disable apps specified in the list, but app data is preserved.'}, 'nonComplianceDetailCondition': {'$ref': '#/$defs/NonComplianceDetailCondition', 'description': 'A condition which is satisfied if there exists *any* matching [`NonComplianceDetail`](/android/management/reference/rest/v1/enterprises.devices#NonComplianceDetail) for the device.'}}, 'description': 'A rule declaring which mitigating actions to take when a device is not compliant with its policy. For every rule, there is always an implicit mitigating action to set `policy_compliant` to false for the [`Device`](/android/management/reference/rest/v1/enterprises.devices#Device) resource, and display a message on the device indicating that the device is not compliant with its policy. Other mitigating actions may optionally be taken as well, depending on the field values in the rule.'}, 'WifiSsidPolicy': {'type': 'object', 'properties': {'wifiSsids': {'type': 'array', 'items': {'$ref': '#/$defs/WifiSsid'}, 'description': 'Optional. List of Wi-Fi SSIDs that should be applied in the policy. This field must be non-empty when WifiSsidPolicyType is set to `WIFI_SSID_ALLOWLIST`. If this is set to a non-empty list, then a `NonComplianceDetail` detail with `API_LEVEL` is reported if the Android version is less than 13 and a `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for non-company-owned devices.'}, 'wifiSsidPolicyType': {'enum': ['WIFI_SSID_POLICY_TYPE_UNSPECIFIED', 'WIFI_SSID_DENYLIST', 'WIFI_SSID_ALLOWLIST'], 'type': 'string', 'description': 'Type of the Wi-Fi SSID policy to be applied.', 'x-google-enum-descriptions': ['Defaults to `WIFI_SSID_DENYLIST`. `wifiSsids` must not be set. There are no restrictions on which SSID the device can connect to.', 'The device cannot connect to any Wi-Fi network whose SSID is in `wifiSsids`, but can connect to other networks.', 'The device can make Wi-Fi connections only to the SSIDs in `wifiSsids`. `wifiSsids` must not be empty. The device will not be able to connect to any other Wi-Fi network.']}}, 'description': 'Restrictions on which Wi-Fi SSIDs the device can connect to. Note that this does not affect which networks can be configured on the device. Supported on company-owned devices running Android 13 and above.'}, 'CustomAppConfig': {'type': 'object', 'properties': {'userUninstallSettings': {'enum': ['USER_UNINSTALL_SETTINGS_UNSPECIFIED', 'DISALLOW_UNINSTALL_BY_USER', 'ALLOW_UNINSTALL_BY_USER'], 'type': 'string', 'description': 'Optional. User uninstall settings of the custom app.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `DISALLOW_UNINSTALL_BY_USER`.', 'User is not allowed to uninstall the custom app.', 'User is allowed to uninstall the custom app.']}}, 'description': 'Configuration for a custom app.'}, 'DisplaySettings': {'type': 'object', 'properties': {'screenTimeoutSettings': {'$ref': '#/$defs/ScreenTimeoutSettings', 'description': 'Optional. Controls the screen timeout settings.'}, 'screenBrightnessSettings': {'$ref': '#/$defs/ScreenBrightnessSettings', 'description': 'Optional. Controls the screen brightness settings.'}}, 'description': 'Controls for the display settings.'}, 'ExtensionConfig': {'type': 'object', 'properties': {'notificationReceiver': {'type': 'string', 'deprecated': True, 'description': "Fully qualified class name of the receiver service class for Android Device Policy to notify the extension app of any local command status updates. The service must be exported in the extension app's `AndroidManifest.xml` and extend [`NotificationReceiverService`](https://developers.google.com/android/management/reference/amapi/com/google/android/managementapi/notification/NotificationReceiverService) (see [Integrate with the AMAPI SDK](https://developers.google.com/android/management/sdk-integration) guide for more details)."}, 'signingKeyFingerprintsSha256': {'type': 'array', 'items': {'type': 'string'}, 'deprecated': True, 'description': 'Hex-encoded SHA-256 hashes of the signing key certificates of the extension app. Only hexadecimal string representations of 64 characters are valid. The signing key certificate fingerprints are always obtained from the Play Store and this field is used to provide additional signing key certificate fingerprints. However, if the application is not available on the Play Store, this field needs to be set. A `NonComplianceDetail` with `INVALID_VALUE` is reported if this field is not set when the application is not available on the Play Store. The signing key certificate fingerprint of the extension app on the device must match one of the signing key certificate fingerprints obtained from the Play Store or the ones provided in this field for the app to be able to communicate with Android Device Policy. In production use cases, it is recommended to leave this empty.'}}, 'description': 'Configuration to enable an app as an extension app, with the capability of interacting with Android Device Policy offline. For Android versions 11 and above, extension apps are exempt from battery restrictions so will not be placed into the [restricted App Standby Bucket](https://developer.android.com/topic/performance/appstandby#restricted-bucket). Extensions apps are also protected against users clearing their data or force-closing the application, although admins can continue to use the clear app data command on extension apps if needed for Android 11 and above.'}, 'LaunchAppAction': {'type': 'object', 'properties': {'packageName': {'type': 'string', 'description': 'Package name of app to be launched'}}, 'description': 'An action to launch an app.'}, 'PackageNameList': {'type': 'object', 'properties': {'packageNames': {'type': 'array', 'items': {'type': 'string'}, 'description': 'A list of package names.'}}, 'description': 'A list of package names.'}, 'PermissionGrant': {'type': 'object', 'properties': {'policy': {'enum': ['PERMISSION_POLICY_UNSPECIFIED', 'PROMPT', 'GRANT', 'DENY'], 'type': 'string', 'description': 'The policy for granting the permission.', 'x-google-enum-descriptions': ['Policy not specified. If no policy is specified for a permission at any level, then the `PROMPT` behavior is used by default.', 'Prompt the user to grant a permission.', 'Automatically grant a permission. On Android 12 and above, [`READ_SMS`](https://developer.android.com/reference/android/Manifest.permission#READ_SMS) and following sensor-related permissions can only be granted on fully managed devices: * [`ACCESS_FINE_LOCATION`](https://developer.android.com/reference/android/Manifest.permission#ACCESS_FINE_LOCATION) * [`ACCESS_BACKGROUND_LOCATION`](https://developer.android.com/reference/android/Manifest.permission#ACCESS_BACKGROUND_LOCATION) * [`ACCESS_COARSE_LOCATION`](https://developer.android.com/reference/android/Manifest.permission#ACCESS_COARSE_LOCATION) * [`CAMERA`](https://developer.android.com/reference/android/Manifest.permission#CAMERA) * [`RECORD_AUDIO`](https://developer.android.com/reference/android/Manifest.permission#RECORD_AUDIO) * [`ACTIVITY_RECOGNITION`](https://developer.android.com/reference/android/Manifest.permission#ACTIVITY_RECOGNITION) * [`BODY_SENSORS`](https://developer.android.com/reference/android/Manifest.permission#BODY_SENSORS)', 'Automatically deny a permission.']}, 'permission': {'type': 'string', 'description': 'The Android permission or group, e.g. `android.permission.READ_CALENDAR` or `android.permission_group.CALENDAR`.'}}, 'description': 'Configuration for an Android permission and its grant state.'}, 'DeviceRadioState': {'type': 'object', 'properties': {'wifiState': {'enum': ['WIFI_STATE_UNSPECIFIED', 'WIFI_STATE_USER_CHOICE', 'WIFI_ENABLED', 'WIFI_DISABLED'], 'type': 'string', 'description': 'Optional. Controls current state of Wi-Fi and if user can change its state.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `WIFI_STATE_USER_CHOICE`', 'User is allowed to enable/disable Wi-Fi.', 'Wi-Fi is on and the user is not allowed to turn it off. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 13.', 'Wi-Fi is off and the user is not allowed to turn it on. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 13.']}, 'airplaneModeState': {'enum': ['AIRPLANE_MODE_STATE_UNSPECIFIED', 'AIRPLANE_MODE_USER_CHOICE', 'AIRPLANE_MODE_DISABLED'], 'type': 'string', 'description': 'Optional. Controls whether airplane mode can be toggled by the user or not.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `AIRPLANE_MODE_USER_CHOICE`.', 'The user is allowed to toggle airplane mode on or off.', 'Airplane mode is disabled. The user is not allowed to toggle airplane mode on. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 9.']}, 'cellularTwoGState': {'enum': ['CELLULAR_TWO_G_STATE_UNSPECIFIED', 'CELLULAR_TWO_G_USER_CHOICE', 'CELLULAR_TWO_G_DISABLED'], 'type': 'string', 'description': 'Optional. Controls whether cellular 2G setting can be toggled by the user or not.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `CELLULAR_TWO_G_USER_CHOICE`.', 'The user is allowed to toggle cellular 2G on or off.', 'Cellular 2G is disabled. The user is not allowed to toggle cellular 2G on via settings. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 14.']}, 'ultraWidebandState': {'enum': ['ULTRA_WIDEBAND_STATE_UNSPECIFIED', 'ULTRA_WIDEBAND_USER_CHOICE', 'ULTRA_WIDEBAND_DISABLED'], 'type': 'string', 'description': 'Optional. Controls the state of the ultra wideband setting and whether the user can toggle it on or off.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `ULTRA_WIDEBAND_USER_CHOICE`.', 'The user is allowed to toggle ultra wideband on or off.', 'Ultra wideband is disabled. The user is not allowed to toggle ultra wideband on via settings. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 14.']}, 'minimumWifiSecurityLevel': {'enum': ['MINIMUM_WIFI_SECURITY_LEVEL_UNSPECIFIED', 'OPEN_NETWORK_SECURITY', 'PERSONAL_NETWORK_SECURITY', 'ENTERPRISE_NETWORK_SECURITY', 'ENTERPRISE_BIT192_NETWORK_SECURITY'], 'type': 'string', 'description': 'Optional. The minimum required security level of Wi-Fi networks that the device can connect to.', 'x-google-enum-descriptions': ['Defaults to `OPEN_NETWORK_SECURITY`, which means the device will be able to connect to all types of Wi-Fi networks.', 'The device will be able to connect to all types of Wi-Fi networks.', 'A personal network such as WEP, WPA2-PSK is the minimum required security. The device will not be able to connect to open wifi networks. This is stricter than `OPEN_NETWORK_SECURITY`. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 13.', 'An enterprise EAP network is the minimum required security level. The device will not be able to connect to Wi-Fi network below this security level. This is stricter than `PERSONAL_NETWORK_SECURITY`. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 13.', 'A 192-bit enterprise network is the minimum required security level. The device will not be able to connect to Wi-Fi network below this security level. This is stricter than `ENTERPRISE_NETWORK_SECURITY`. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 13.']}, 'userInitiatedAddEsimSettings': {'enum': ['USER_INITIATED_ADD_ESIM_SETTINGS_UNSPECIFIED', 'USER_INITIATED_ADD_ESIM_ALLOWED', 'USER_INITIATED_ADD_ESIM_DISALLOWED'], 'type': 'string', 'description': 'Optional. Controls whether the user is allowed to add eSIM profiles.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `USER_INITIATED_ADD_ESIM_ALLOWED`.', 'The user is allowed to add eSIM profiles.', 'Supported only on company-owned devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for personally-owned devices.']}}, 'description': 'Controls for device radio settings.'}, 'ApiLevelCondition': {'type': 'object', 'properties': {'minApiLevel': {'type': 'integer', 'format': 'int32', 'description': "The minimum desired Android Framework API level. If the device doesn't meet the minimum requirement, this condition is satisfied. Must be greater than zero."}}, 'description': "A compliance rule condition which is satisfied if the Android Framework API level on the device doesn't meet a minimum requirement. There can only be one rule with this type of condition per policy."}, 'ApplicationPolicy': {'type': 'object', 'properties': {'roles': {'type': 'array', 'items': {'$ref': '#/$defs/Role'}, 'description': 'Optional. Roles the app has. Apps having certain roles can be exempted from power and background execution restrictions, suspension and hibernation on Android 14 and above. The user control can also be disallowed for apps with certain roles on Android 11 and above. Refer to the documentation of each `RoleType` for more details. The app is notified about the roles that are set for it if the app has a notification receiver service with ``. The app is notified whenever its roles are updated or after the app is installed when it has nonempty list of roles. The app can use this notification to bootstrap itself after the installation. See [Integrate with the AMAPI SDK](https://developers.google.com/android/management/sdk-integration) and [Manage app roles](https://developers.google.com/android/management/app-roles) guides for more details on the requirements for the service. For the exemptions to be applied and the app to be notified about the roles, the signing key certificate fingerprint of the app on the device must match one of the signing key certificate fingerprints obtained from Play Store or one of the entries in `ApplicationPolicy.signingKeyCerts`. Otherwise, a `NonComplianceDetail` with `APP_SIGNING_CERT_MISMATCH` is reported. There must not be duplicate roles with the same `roleType`. Multiple apps cannot hold a role with the same `roleType`. A role with type `ROLE_TYPE_UNSPECIFIED` is not allowed.'}, 'disabled': {'type': 'boolean', 'description': 'Whether the app is disabled. When disabled, the app data is still preserved.'}, 'installType': {'enum': ['INSTALL_TYPE_UNSPECIFIED', 'PREINSTALLED', 'FORCE_INSTALLED', 'BLOCKED', 'AVAILABLE', 'REQUIRED_FOR_SETUP', 'KIOSK', 'CUSTOM'], 'type': 'string', 'description': 'The type of installation to perform.', 'x-google-enum-deprecated': [False, False, False, False, False, False, True, False], 'x-google-enum-descriptions': ['Unspecified. Defaults to AVAILABLE.', 'The app is automatically installed and can be removed by the user.', "The app is automatically installed regardless of a set maintenance window and can't be removed by the user.", "The app is blocked and can't be installed. If the app was installed under a previous policy, it will be uninstalled. This also blocks its instant app functionality.", 'The app is available to install.', "The app is automatically installed and can't be removed by the user and will prevent setup from completion until installation is complete.", "The app is automatically installed in kiosk mode: it's set as the preferred home intent and whitelisted for lock task mode. Device setup won't complete until the app is installed. After installation, users won't be able to remove the app. You can only set this `installType` for one app per policy. When this is present in the policy, status bar will be automatically disabled. On Android 11 and above, when an app has this install type, the user control is disallowed for all apps. The IT admin can set `userControlSettings` to `USER_CONTROL_ALLOWED` to allow user control for specific apps. If there is any app with `KIOSK` role, then this install type cannot be set for any app.", "The app can only be installed and updated via [AMAPI SDK command](https://developers.google.com/android/management/extensibility-sdk-integration). **Note:** * This only affects fully managed devices. * Play related fields `minimumVersionCode`, `accessibleTrackIds`, `autoUpdateMode`, `installConstraint` and `installPriority` cannot be set for the app. * The app isn't available in the Play Store. * The app installed on the device has `applicationSource` set to `CUSTOM`. * When the current `installType` is `CUSTOM`, the signing key certificate fingerprint of the existing custom app on the device must match one of the entries in `ApplicationPolicy.signingKeyCerts` . Otherwise, a `NonComplianceDetail` with `APP_SIGNING_CERT_MISMATCH` is reported. * Changing the `installType` from `CUSTOM` to another value must match the playstore version of the application signing key certificate fingerprint. Otherwise a `NonComplianceDetail` with `APP_SIGNING_CERT_MISMATCH` is reported. * Changing the `installType` to `CUSTOM` uninstalls the existing app if its signing key certificate fingerprint of the installed app doesn't match the one from the `ApplicationPolicy.signingKeyCerts` . * Removing the app from `applications` doesn't uninstall the existing app if it conforms to `playStoreMode`. * See also `customAppConfig`. * This is different from the [Google Play Custom App Publishing](https://developers.google.com/android/work/play/custom-app-api/get-started) feature."]}, 'packageName': {'type': 'string', 'description': 'The package name of the app. For example, `com.google.android.youtube` for the YouTube app.'}, 'autoUpdateMode': {'enum': ['AUTO_UPDATE_MODE_UNSPECIFIED', 'AUTO_UPDATE_DEFAULT', 'AUTO_UPDATE_POSTPONED', 'AUTO_UPDATE_HIGH_PRIORITY'], 'type': 'string', 'description': 'Controls the auto-update mode for the app.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `AUTO_UPDATE_DEFAULT`.', 'The default update mode. The app is automatically updated with low priority to minimize the impact on the user. The app is updated when all of the following constraints are met: * The device is not actively used. * The device is connected to an unmetered network. * The device is charging. * The app to be updated is not running in the foreground. The device is notified about a new update within 24 hours after it is published by the developer, after which the app is updated the next time the constraints above are met.', 'The app is not automatically updated for a maximum of 90 days after the app becomes out of date. 90 days after the app becomes out of date, the latest available version is installed automatically with low priority (see `AUTO_UPDATE_DEFAULT`). After the app is updated it is not automatically updated again until 90 days after it becomes out of date again. The user can still manually update the app from the Play Store at any time.', "The app is updated as soon as possible. No constraints are applied. The device is notified as soon as possible about a new update after it becomes available. *NOTE:* Updates to apps with larger deployments across Android's ecosystem can take up to 24h."]}, 'customAppConfig': {'$ref': '#/$defs/CustomAppConfig', 'description': 'Optional. Configuration for this custom app. `install_type` must be set to `CUSTOM` for this to be set.'}, 'delegatedScopes': {'type': 'array', 'items': {'enum': ['DELEGATED_SCOPE_UNSPECIFIED', 'CERT_INSTALL', 'MANAGED_CONFIGURATIONS', 'BLOCK_UNINSTALL', 'PERMISSION_GRANT', 'PACKAGE_ACCESS', 'ENABLE_SYSTEM_APP', 'NETWORK_ACTIVITY_LOGS', 'SECURITY_LOGS', 'CERT_SELECTION'], 'type': 'string', 'x-google-enum-descriptions': ['No delegation scope specified.', 'Grants access to certificate installation and management. This scope can be delegated to multiple applications.', 'Grants access to managed configurations management. This scope can be delegated to multiple applications.', 'Grants access to blocking uninstallation. This scope can be delegated to multiple applications.', 'Grants access to permission policy and permission grant state. This scope can be delegated to multiple applications.', 'Grants access to package access state. This scope can be delegated to multiple applications.', 'Grants access for enabling system apps. This scope can be delegated to multiple applications.', 'Grants access to network activity logs. Allows the delegated application to call [`setNetworkLoggingEnabled`](https://developer.android.com/reference/android/app/admin/DevicePolicyManager#setNetworkLoggingEnabled%28android.content.ComponentName,%20boolean%29), [`isNetworkLoggingEnabled`](https://developer.android.com/reference/android/app/admin/DevicePolicyManager#isNetworkLoggingEnabled%28android.content.ComponentName%29) and [`retrieveNetworkLogs`](https://developer.android.com/reference/android/app/admin/DevicePolicyManager#retrieveNetworkLogs%28android.content.ComponentName,%20long%29) methods. This scope can be delegated to at most one application. Supported for fully managed devices on Android 10 and above. Supported for a work profile on Android 12 and above. When delegation is supported and set, `NETWORK_ACTIVITY_LOGS` is ignored.', 'Grants access to security logs. Allows the delegated application to call [`setSecurityLoggingEnabled`](https://developer.android.com/reference/android/app/admin/DevicePolicyManager#setSecurityLoggingEnabled%28android.content.ComponentName,%20boolean%29), [`isSecurityLoggingEnabled`](https://developer.android.com/reference/android/app/admin/DevicePolicyManager#isSecurityLoggingEnabled%28android.content.ComponentName%29), [`retrieveSecurityLogs`](https://developer.android.com/reference/android/app/admin/DevicePolicyManager#retrieveSecurityLogs%28android.content.ComponentName%29) and [`retrievePreRebootSecurityLogs`](https://developer.android.com/reference/android/app/admin/DevicePolicyManager#retrievePreRebootSecurityLogs%28android.content.ComponentName%29) methods. This scope can be delegated to at most one application. Supported for fully managed devices and company-owned devices with a work profile on Android 12 and above. When delegation is supported and set, `SECURITY_LOGS` is ignored.', 'Grants access to selection of KeyChain certificates on behalf of requesting apps. Once granted, the delegated application will start receiving [`DelegatedAdminReceiver#onChoosePrivateKeyAlias`](https://developer.android.com/reference/android/app/admin/DelegatedAdminReceiver#onChoosePrivateKeyAlias%28android.content.Context,%20android.content.Intent,%20int,%20android.net.Uri,%20java.lang.String%29). Allows the delegated application to call [`grantKeyPairToApp`](https://developer.android.com/reference/android/app/admin/DevicePolicyManager#grantKeyPairToApp%28android.content.ComponentName,%20java.lang.String,%20java.lang.String%29) and [`revokeKeyPairFromApp`](https://developer.android.com/reference/android/app/admin/DevicePolicyManager#revokeKeyPairFromApp%28android.content.ComponentName,%20java.lang.String,%20java.lang.String%29) methods. This scope can be delegated to at most one application. `choosePrivateKeyRules` must be empty and `privateKeySelectionEnabled` has no effect if certificate selection is delegated to an application.']}, 'description': 'The scopes delegated to the app from Android Device Policy. These provide additional privileges for the applications they are applied to.'}, 'extensionConfig': {'$ref': '#/$defs/ExtensionConfig', 'deprecated': True, 'description': 'Configuration to enable this app as an extension app, with the capability of interacting with Android Device Policy offline. This field can be set for at most one app. If there is any app with `COMPANION_APP` role, this field cannot be set. The signing key certificate fingerprint of the app on the device must match one of the entries in `ApplicationPolicy.signingKeyCerts` or `ExtensionConfig.signingKeyFingerprintsSha256` (deprecated) or the signing key certificate fingerprints obtained from Play Store for the app to be able to communicate with Android Device Policy. If the app is not on Play Store and if `ApplicationPolicy.signingKeyCerts` and `ExtensionConfig.signingKeyFingerprintsSha256` (deprecated) are not set, a `NonComplianceDetail` with `INVALID_VALUE` is reported.'}, 'installPriority': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Amongst apps with `installType` set to: * FORCE_INSTALLED * PREINSTALLED this controls the relative priority of installation. A value of 0 (default) means this app has no priority over other apps. For values between 1 and 10,000, a lower value means a higher priority. Values outside of the range 0 to 10,000 inclusive are rejected.'}, 'lockTaskAllowed': {'type': 'boolean', 'deprecated': True, 'description': 'Whether the app is allowed to lock itself in full-screen mode. DEPRECATED. Use [InstallType](/android/management/reference/rest/v1/enterprises.policies#installtype) `KIOSK` or `kioskCustomLauncherEnabled` to configure a dedicated device.'}, 'signingKeyCerts': {'type': 'array', 'items': {'$ref': '#/$defs/ApplicationSigningKeyCert'}, 'description': 'Optional. Signing key certificates of the app. This field is required in the following cases: * The app has `installType` set to `CUSTOM` (i.e. a custom app). * The app has `roles` set to a nonempty list and the app does not exist on the Play Store. * The app has `extensionConfig` set (i.e. an extension app) but `ExtensionConfig.signingKeyFingerprintsSha256` (deprecated) is not set and the app does not exist on the Play Store. If this field is not set for a custom app, the policy is rejected. If it is not set when required for a non-custom app, a `NonComplianceDetail` with `INVALID_VALUE` is reported. For other cases, this field is optional and the signing key certificates obtained from Play Store are used. See following policy settings to see how this field is used: * `choosePrivateKeyRules` * `ApplicationPolicy.InstallType.CUSTOM` * `ApplicationPolicy.extensionConfig` * `ApplicationPolicy.roles`'}, 'permissionGrants': {'type': 'array', 'items': {'$ref': '#/$defs/PermissionGrant'}, 'description': 'Explicit permission grants or denials for the app. These values override the `default_permission_policy` and `permission_grants` which apply to all apps.'}, 'installConstraint': {'type': 'array', 'items': {'$ref': '#/$defs/InstallConstraint'}, 'description': 'Optional. The constraints for installing the app. You can specify a maximum of one `InstallConstraint`. Multiple constraints are rejected.'}, 'accessibleTrackIds': {'type': 'array', 'items': {'type': 'string'}, 'description': 'List of the app’s track IDs that a device belonging to the enterprise can access. If the list contains multiple track IDs, devices receive the latest version among all accessible tracks. If the list contains no track IDs, devices only have access to the app’s production track. More details about each track are available in [AppTrackInfo](/android/management/reference/rest/v1/enterprises.applications#apptrackinfo).'}, 'minimumVersionCode': {'type': 'integer', 'format': 'int32', 'description': 'The minimum version of the app that runs on the device. If set, the device attempts to update the app to at least this version code. If the app is not up-to-date, the device will contain a `NonComplianceDetail` with `non_compliance_reason` set to `APP_NOT_UPDATED`. The app must already be published to Google Play with a version code greater than or equal to this value. At most 20 apps may specify a minimum version code per policy.'}, 'workProfileWidgets': {'enum': ['WORK_PROFILE_WIDGETS_UNSPECIFIED', 'WORK_PROFILE_WIDGETS_ALLOWED', 'WORK_PROFILE_WIDGETS_DISALLOWED'], 'type': 'string', 'description': 'Specifies whether the app installed in the work profile is allowed to add widgets to the home screen.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `work_profile_widgets_default`', 'Work profile widgets are allowed. This means the application will be able to add widgets to the home screen.', 'Work profile widgets are disallowed. This means the application will not be able to add widgets to the home screen.']}, 'userControlSettings': {'enum': ['USER_CONTROL_SETTINGS_UNSPECIFIED', 'USER_CONTROL_ALLOWED', 'USER_CONTROL_DISALLOWED'], 'type': 'string', 'description': 'Optional. Specifies whether user control is permitted for the app. User control includes user actions like force-stopping and clearing app data. Certain types of apps have special treatment, see `USER_CONTROL_SETTINGS_UNSPECIFIED` and `USER_CONTROL_ALLOWED` for more details.', 'x-google-enum-descriptions': ['Uses the default behaviour of the app to determine if user control is allowed or disallowed. User control is allowed by default for most apps but disallowed for following types of apps: * extension apps (see `extensionConfig` for more details) * kiosk apps (see `KIOSK` install type for more details) * apps with `roles` set to a nonempty list * other critical system apps', 'User control is allowed for the app. Kiosk apps can use this to allow user control. For extension apps (see `extensionConfig` for more details), user control is disallowed even if this value is set. For apps with `roles` set to a nonempty list (except `roles` containing only `KIOSK` role), this value cannot be set. For kiosk apps (see `KIOSK` install type and `KIOSK` role type for more details), this value can be used to allow user control.', 'User control is disallowed for the app. This is supported on Android 11 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 11.']}, 'managedConfiguration': {'type': 'object', 'description': 'Managed configuration applied to the app. The format for the configuration is dictated by the [`ManagedProperty`](/android/management/reference/rest/v1/enterprises.applications#ManagedProperty) values supported by the app. Each field name in the managed configuration must match the `key` field of the `ManagedProperty`. The field value must be compatible with the `type` of the `ManagedProperty`: *type* *JSON value* `BOOL` `true` or `false` `STRING` string `INTEGER` number `CHOICE` string `MULTISELECT` array of strings `HIDDEN` string `BUNDLE_ARRAY` array of objects Note: string values cannot be longer than 65535 characters.', 'additionalProperties': {'description': 'Properties of the object.'}}, 'preferentialNetworkId': {'enum': ['PREFERENTIAL_NETWORK_ID_UNSPECIFIED', 'NO_PREFERENTIAL_NETWORK', 'PREFERENTIAL_NETWORK_ID_ONE', 'PREFERENTIAL_NETWORK_ID_TWO', 'PREFERENTIAL_NETWORK_ID_THREE', 'PREFERENTIAL_NETWORK_ID_FOUR', 'PREFERENTIAL_NETWORK_ID_FIVE'], 'type': 'string', 'description': 'Optional. ID of the preferential network the application uses. There must be a configuration for the specified network ID in `preferentialNetworkServiceConfigs`. If set to `PREFERENTIAL_NETWORK_ID_UNSPECIFIED`, the application will use the default network ID specified in `defaultPreferentialNetworkId`. See the documentation of `defaultPreferentialNetworkId` for the list of apps excluded from this defaulting. This applies on both work profiles and fully managed devices on Android 13 and above.', 'x-google-enum-descriptions': ['Whether this value is valid and what it means depends on where it is used, and this is documented on the relevant fields.', 'Application does not use any preferential network.', 'Preferential network identifier 1.', 'Preferential network identifier 2.', 'Preferential network identifier 3.', 'Preferential network identifier 4.', 'Preferential network identifier 5.']}, 'defaultPermissionPolicy': {'enum': ['PERMISSION_POLICY_UNSPECIFIED', 'PROMPT', 'GRANT', 'DENY'], 'type': 'string', 'description': 'The default policy for all permissions requested by the app. If specified, this overrides the policy-level `default_permission_policy` which applies to all apps. It does not override the `permission_grants` which applies to all apps.', 'x-google-enum-descriptions': ['Policy not specified. If no policy is specified for a permission at any level, then the `PROMPT` behavior is used by default.', 'Prompt the user to grant a permission.', 'Automatically grant a permission. On Android 12 and above, [`READ_SMS`](https://developer.android.com/reference/android/Manifest.permission#READ_SMS) and following sensor-related permissions can only be granted on fully managed devices: * [`ACCESS_FINE_LOCATION`](https://developer.android.com/reference/android/Manifest.permission#ACCESS_FINE_LOCATION) * [`ACCESS_BACKGROUND_LOCATION`](https://developer.android.com/reference/android/Manifest.permission#ACCESS_BACKGROUND_LOCATION) * [`ACCESS_COARSE_LOCATION`](https://developer.android.com/reference/android/Manifest.permission#ACCESS_COARSE_LOCATION) * [`CAMERA`](https://developer.android.com/reference/android/Manifest.permission#CAMERA) * [`RECORD_AUDIO`](https://developer.android.com/reference/android/Manifest.permission#RECORD_AUDIO) * [`ACTIVITY_RECOGNITION`](https://developer.android.com/reference/android/Manifest.permission#ACTIVITY_RECOGNITION) * [`BODY_SENSORS`](https://developer.android.com/reference/android/Manifest.permission#BODY_SENSORS)', 'Automatically deny a permission.']}, 'credentialProviderPolicy': {'enum': ['CREDENTIAL_PROVIDER_POLICY_UNSPECIFIED', 'CREDENTIAL_PROVIDER_ALLOWED', 'CREDENTIAL_PROVIDER_DISALLOWED'], 'type': 'string', 'description': 'Optional. Whether the app is allowed to act as a credential provider on Android 14 and above.', 'x-google-enum-descriptions': ['Unspecified. The behaviour is governed by `credentialProviderPolicyDefault`.', 'App is allowed to act as a credential provider.', 'App is not allowed to act as a credential provider.']}, 'connectedWorkAndPersonalApp': {'enum': ['CONNECTED_WORK_AND_PERSONAL_APP_UNSPECIFIED', 'CONNECTED_WORK_AND_PERSONAL_APP_DISALLOWED', 'CONNECTED_WORK_AND_PERSONAL_APP_ALLOWED'], 'type': 'string', 'description': 'Controls whether the app can communicate with itself across a device’s work and personal profiles, subject to user consent.', 'x-google-enum-descriptions': ['Unspecified. Defaults to CONNECTED_WORK_AND_PERSONAL_APPS_DISALLOWED.', 'Default. Prevents the app from communicating cross-profile.', 'Allows the app to communicate across profiles after receiving user consent.']}, 'alwaysOnVpnLockdownExemption': {'enum': ['ALWAYS_ON_VPN_LOCKDOWN_EXEMPTION_UNSPECIFIED', 'VPN_LOCKDOWN_ENFORCED', 'VPN_LOCKDOWN_EXEMPTION'], 'type': 'string', 'description': 'Specifies whether the app is allowed networking when the VPN is not connected and `alwaysOnVpnPackage.lockdownEnabled` is enabled. If set to `VPN_LOCKDOWN_ENFORCED`, the app is not allowed networking, and if set to `VPN_LOCKDOWN_EXEMPTION`, the app is allowed networking. Only supported on devices running Android 10 and above. If this is not supported by the device, the device will contain a `NonComplianceDetail` with `non_compliance_reason` set to `API_LEVEL` and a fieldPath. If this is not applicable to the app, the device will contain a `NonComplianceDetail` with `non_compliance_reason` set to `UNSUPPORTED` and a fieldPath. The fieldPath is set to `applications[i].alwaysOnVpnLockdownExemption`, where `i` is the index of the package in the `applications` policy.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `VPN_LOCKDOWN_ENFORCED`.', 'The app respects the always-on VPN lockdown setting.', 'The app is exempt from the always-on VPN lockdown setting.']}, 'managedConfigurationTemplate': {'$ref': '#/$defs/ManagedConfigurationTemplate', 'description': 'The managed configurations template for the app, saved from the [managed configurations iframe](/android/management/managed-configurations-iframe). This field is ignored if managed_configuration is set.'}}, 'description': 'Policy for an individual app. Note: Application availability on a given device cannot be changed using this policy if `installAppsDisabled` is enabled. The maximum number of applications that you can specify per policy is 3,000.'}, 'InstallConstraint': {'type': 'object', 'properties': {'chargingConstraint': {'enum': ['CHARGING_CONSTRAINT_UNSPECIFIED', 'CHARGING_NOT_REQUIRED', 'INSTALL_ONLY_WHEN_CHARGING'], 'type': 'string', 'description': 'Optional. Charging constraint.', 'x-google-enum-descriptions': ['Unspecified. Default to `CHARGING_NOT_REQUIRED`.', "Device doesn't have to be charging.", 'Device has to be charging.']}, 'deviceIdleConstraint': {'enum': ['DEVICE_IDLE_CONSTRAINT_UNSPECIFIED', 'DEVICE_IDLE_NOT_REQUIRED', 'INSTALL_ONLY_WHEN_DEVICE_IDLE'], 'type': 'string', 'description': 'Optional. Device idle constraint.', 'x-google-enum-descriptions': ['Unspecified. Default to `DEVICE_IDLE_NOT_REQUIRED`.', "Device doesn't have to be idle, app can be installed while the user is interacting with the device.", 'Device has to be idle.']}, 'networkTypeConstraint': {'enum': ['NETWORK_TYPE_CONSTRAINT_UNSPECIFIED', 'INSTALL_ON_ANY_NETWORK', 'INSTALL_ONLY_ON_UNMETERED_NETWORK'], 'type': 'string', 'description': 'Optional. Network type constraint.', 'x-google-enum-descriptions': ['Unspecified. Default to `INSTALL_ON_ANY_NETWORK`.', 'Any active networks (Wi-Fi, cellular, etc.).', 'Any unmetered network (e.g. Wi-FI).']}}, 'description': 'Amongst apps with `InstallType` set to: * FORCE_INSTALLED * PREINSTALLED this defines a set of restrictions for the app installation. At least one of the fields must be set. When multiple fields are set, then all the constraints need to be satisfied for the app to be installed.'}, 'UserFacingMessage': {'type': 'object', 'properties': {'defaultMessage': {'type': 'string', 'description': "The default message displayed if no localized message is specified or the user's locale doesn't match with any of the localized messages. A default message must be provided if any localized messages are provided."}, 'localizedMessages': {'type': 'object', 'description': 'A map containing pairs, where locale is a well-formed [BCP 47 language](https://www.w3.org/International/articles/language-tags/) code, such as en-US, es-ES, or fr.', 'additionalProperties': {'type': 'string'}}}, 'description': 'Provides a user-facing message with locale info. The maximum message length is 4096 characters.'}, 'WifiRoamingPolicy': {'type': 'object', 'properties': {'wifiRoamingSettings': {'type': 'array', 'items': {'$ref': '#/$defs/WifiRoamingSetting'}, 'description': 'Optional. Wi-Fi roaming settings. SSIDs provided in this list must be unique, the policy will be rejected otherwise.'}}, 'description': 'Wi-Fi roaming policy.'}, 'AlwaysOnVpnPackage': {'type': 'object', 'properties': {'packageName': {'type': 'string', 'description': 'The package name of the VPN app.'}, 'lockdownEnabled': {'type': 'boolean', 'description': 'Disallows networking when the VPN is not connected.'}}, 'description': 'Configuration for an always-on VPN connection.'}, 'DefaultApplication': {'type': 'object', 'properties': {'packageName': {'type': 'string', 'description': 'Required. The package name that should be set as the default application. The policy is rejected if the package name is invalid.'}}, 'description': 'Information about the application to be set as the default.'}, 'KioskCustomization': {'type': 'object', 'properties': {'statusBar': {'enum': ['STATUS_BAR_UNSPECIFIED', 'NOTIFICATIONS_AND_SYSTEM_INFO_ENABLED', 'NOTIFICATIONS_AND_SYSTEM_INFO_DISABLED', 'SYSTEM_INFO_ONLY'], 'type': 'string', 'description': 'Optional. Specifies whether system info and notifications are disabled in kiosk mode.', 'x-google-enum-descriptions': ['Unspecified, defaults to `INFO_AND_NOTIFICATIONS_DISABLED`.', "System info and notifications are shown on the status bar in kiosk mode. **Note:** For this policy to take effect, the device's home button must be enabled using [`kioskCustomization.systemNavigation`](/android/management/reference/rest/v1/enterprises.policies#SystemNavigation).", 'System info and notifications are disabled in kiosk mode.', 'Only system info is shown on the status bar.']}, 'deviceSettings': {'enum': ['DEVICE_SETTINGS_UNSPECIFIED', 'SETTINGS_ACCESS_ALLOWED', 'SETTINGS_ACCESS_BLOCKED'], 'type': 'string', 'description': 'Optional. Specifies whether the Settings app is allowed in kiosk mode.', 'x-google-enum-descriptions': ['Unspecified, defaults to `SETTINGS_ACCESS_ALLOWED`.', 'Access to the Settings app is allowed in kiosk mode.', 'Access to the Settings app is not allowed in kiosk mode.']}, 'systemNavigation': {'enum': ['SYSTEM_NAVIGATION_UNSPECIFIED', 'NAVIGATION_ENABLED', 'NAVIGATION_DISABLED', 'HOME_BUTTON_ONLY'], 'type': 'string', 'description': 'Optional. Specifies which navigation features are enabled (e.g. Home, Overview buttons) in kiosk mode.', 'x-google-enum-descriptions': ['Unspecified, defaults to `NAVIGATION_DISABLED`.', 'Home and overview buttons are enabled.', 'The home and Overview buttons are not accessible.', 'Only the home button is enabled.']}, 'powerButtonActions': {'enum': ['POWER_BUTTON_ACTIONS_UNSPECIFIED', 'POWER_BUTTON_AVAILABLE', 'POWER_BUTTON_BLOCKED'], 'type': 'string', 'description': 'Optional. Sets the behavior of a device in kiosk mode when a user presses and holds (long-presses) the Power button.', 'x-google-enum-descriptions': ['Unspecified, defaults to `POWER_BUTTON_AVAILABLE`.', 'The power menu (e.g. Power off, Restart) is shown when a user long-presses the Power button of a device in kiosk mode.', 'The power menu (e.g. Power off, Restart) is not shown when a user long-presses the Power button of a device in kiosk mode. Note: this may prevent users from turning off the device.']}, 'systemErrorWarnings': {'enum': ['SYSTEM_ERROR_WARNINGS_UNSPECIFIED', 'ERROR_AND_WARNINGS_ENABLED', 'ERROR_AND_WARNINGS_MUTED'], 'type': 'string', 'description': 'Optional. Specifies whether system error dialogs for crashed or unresponsive apps are blocked in kiosk mode. When blocked, the system will force-stop the app as if the user chooses the "close app" option on the UI.', 'x-google-enum-descriptions': ['Unspecified, defaults to `ERROR_AND_WARNINGS_MUTED`.', 'All system error dialogs such as crash and app not responding (ANR) are displayed.', 'All system error dialogs, such as crash and app not responding (ANR) are blocked. When blocked, the system force-stops the app as if the user closes the app from the UI.']}}, 'description': 'Settings controlling the behavior of a device in kiosk mode. To enable kiosk mode, set `kioskCustomLauncherEnabled` to `true` or specify an app in the policy with `installType` `KIOSK`.'}, 'PrivateDnsSettings': {'type': 'object', 'properties': {'privateDnsHost': {'type': 'string', 'description': 'Optional. The hostname of the DNS server. This must be set if and only if `private_dns_mode` is set to `PRIVATE_DNS_SPECIFIED_HOST`. Supported on Android 10 and above on fully managed devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported on other management modes. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 10. A `NonComplianceDetail` with `PENDING` is reported if the device is not connected to a network. A `NonComplianceDetail` with `nonComplianceReason` `INVALID_VALUE` and `specificNonComplianceReason` `PRIVATE_DNS_HOST_NOT_SERVING` is reported if the specified host is not a DNS server or not supported on Android. A `NonComplianceDetail` with `INVALID_VALUE` is reported if applying this setting fails for any other reason.'}, 'privateDnsMode': {'enum': ['PRIVATE_DNS_MODE_UNSPECIFIED', 'PRIVATE_DNS_USER_CHOICE', 'PRIVATE_DNS_AUTOMATIC', 'PRIVATE_DNS_SPECIFIED_HOST'], 'type': 'string', 'description': "Optional. The configuration mode for device's global private DNS settings. If this is set to `PRIVATE_DNS_SPECIFIED_HOST`, then `private_dns_host` must be set.", 'x-google-enum-descriptions': ['Unspecified. Defaults to `PRIVATE_DNS_USER_CHOICE`.', 'The user is allowed to configure private DNS.', 'Automatic private DNS mode. The device tries to use the network-provided DNS server over an encrypted connection before resorting to cleartext. The user is not allowed to modify this setting. Supported on Android 10 and above on fully managed devices and work profiles on company-owned devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported on other management modes. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 10. A `NonComplianceDetail` with `INVALID_VALUE` is reported if setting this fails for any other reason. **Note:** For work profiles on company-owned devices, setting this mode prevents the user from changing the setting, but the active private DNS setting is not modified. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported in this case.', 'The device only uses the DNS server specified in `private_dns_host`. The user is not allowed to modify this setting. If this is set, then `private_dns_host` must be set. Supported on Android 10 and above on fully managed devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported on other management modes. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 10.']}}, 'description': "Controls the device's private DNS settings."}, 'WifiRoamingSetting': {'type': 'object', 'properties': {'wifiSsid': {'type': 'string', 'description': 'Required. SSID of the Wi-Fi network.'}, 'wifiRoamingMode': {'enum': ['WIFI_ROAMING_MODE_UNSPECIFIED', 'WIFI_ROAMING_DISABLED', 'WIFI_ROAMING_DEFAULT', 'WIFI_ROAMING_AGGRESSIVE'], 'type': 'string', 'description': 'Required. Wi-Fi roaming mode for the specified SSID.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `WIFI_ROAMING_DEFAULT`.', 'Wi-Fi roaming is disabled. Supported on Android 15 and above on fully managed devices and work profiles on company-owned devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for other management modes. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 15.', 'Default Wi-Fi roaming mode of the device.', 'Aggressive roaming mode which allows quicker Wi-Fi roaming. Supported on Android 15 and above on fully managed devices and work profiles on company-owned devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for other management modes. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 15. A `NonComplianceDetail` with `DEVICE_INCOMPATIBLE` is reported if the device does not support aggressive roaming mode.']}}, 'description': 'Wi-Fi roaming setting.'}, 'CrossDevicePolicies': {'type': 'object', 'properties': {'nearbyAppStreaming': {'enum': ['NEARBY_APP_STREAMING_UNSPECIFIED', 'NEARBY_APP_STREAMING_USER_CHOICE', 'NEARBY_APP_STREAMING_DISABLED', 'NEARBY_APP_STREAMING_USER_CHOICE_SAME_MANAGED_ACCOUNT'], 'type': 'string', 'description': 'Optional. Manages video streaming of apps on the device for fully managed devices or in the work profile for devices with work profiles to nearby devices. This is supported on Android 13 and above.', 'x-google-enum-descriptions': ['Unspecified. Defaults to NEARBY_APP_STREAMING_USER_CHOICE_SAME_MANAGED_ACCOUNT.', 'The user is allowed to choose whether to stream apps to nearby devices.', 'Disables app streaming to nearby devices.', 'The user is allowed to choose whether to stream apps to other nearby devices which are signed in with the same authenticated managed account.']}, 'taskContinuityHandoff': {'enum': ['TASK_CONTINUITY_HANDOFF_UNSPECIFIED', 'TASK_CONTINUITY_HANDOFF_ALLOWED', 'TASK_CONTINUITY_HANDOFF_DISALLOWED'], 'type': 'string', 'description': 'Optional. Controls the [task continuity handoff](https://developer.android.com/partners/android-17/features#handoff) feature. This policy applies to the entire device for fully managed devices, and to the work profile for devices with a work profile. Requires Android 17 QPR1 or higher.', 'x-google-enum-descriptions': ['Defaults to `TASK_CONTINUITY_HANDOFF_ALLOWED`.', 'Allows the user to enable or disable the task continuity handoff feature in settings. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is lower than Android 17 QPR1.', 'The task continuity handoff feature is disallowed. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is lower than Android 17 QPR1.']}, 'nearbyNotificationStreaming': {'enum': ['NEARBY_NOTIFICATION_STREAMING_UNSPECIFIED', 'NEARBY_NOTIFICATION_STREAMING_USER_CHOICE', 'NEARBY_NOTIFICATION_STREAMING_DISABLED', 'NEARBY_NOTIFICATION_STREAMING_USER_CHOICE_SAME_MANAGED_ACCOUNT'], 'type': 'string', 'description': 'Optional. Manages streaming of notifications from apps on the device for fully managed devices or in the work profile for devices with work profiles to nearby devices. This is supported on Android 13 and above.', 'x-google-enum-descriptions': ['Unspecified. Defaults to NEARBY_NOTIFICATION_STREAMING_USER_CHOICE_SAME_MANAGED_ACCOUNT.', 'The user is allowed to choose whether to stream notifications to nearby devices.', 'Disables notification streaming to nearby devices.', 'The user is allowed to choose whether to stream notifications to other nearby devices which are signed in with the same authenticated managed account.']}}, 'description': 'Policies controlling cross-device communication.'}, 'ChoosePrivateKeyRule': {'type': 'object', 'properties': {'urlPattern': {'type': 'string', 'description': 'The URL pattern to match against the URL of the request. If not set or empty, it matches all URLs. This uses the regular expression syntax of `java.util.regex.Pattern`.'}, 'packageNames': {'type': 'array', 'items': {'type': 'string'}, 'description': 'The package names to which this rule applies. The signing key certificate fingerprint of the app is verified against the signing key certificate fingerprints provided by Play Store and `ApplicationPolicy.signingKeyCerts` . If no package names are specified, then the alias is provided to all apps that call [`KeyChain.choosePrivateKeyAlias`](https://developer.android.com/reference/android/security/KeyChain#choosePrivateKeyAlias%28android.app.Activity,%20android.security.KeyChainAliasCallback,%20java.lang.String[],%20java.security.Principal[],%20java.lang.String,%20int,%20java.lang.String%29) or any overloads (but not without calling `KeyChain.choosePrivateKeyAlias`, even on Android 11 and above). Any app with the same Android UID as a package specified here will have access when they call `KeyChain.choosePrivateKeyAlias`.'}, 'privateKeyAlias': {'type': 'string', 'description': 'The alias of the private key to be used.'}}, 'description': "Controls apps' access to private keys. The rule determines which private key, if any, Android Device Policy grants to the specified app. Access is granted either when the app calls [`KeyChain.choosePrivateKeyAlias`](https://developer.android.com/reference/android/security/KeyChain#choosePrivateKeyAlias%28android.app.Activity,%20android.security.KeyChainAliasCallback,%20java.lang.String[],%20java.security.Principal[],%20java.lang.String,%20int,%20java.lang.String%29) (or any overloads) to request a private key alias for a given URL, or for rules that are not URL-specific (that is, if `urlPattern` is not set, or set to the empty string or `.*`) on Android 11 and above, directly so that the app can call [`KeyChain.getPrivateKey`](https://developer.android.com/reference/android/security/KeyChain#getPrivateKey%28android.content.Context,%20java.lang.String%29), without first having to call `KeyChain.choosePrivateKeyAlias`. When an app calls `KeyChain.choosePrivateKeyAlias` if more than one `choosePrivateKeyRules` matches, the last matching rule defines which key alias to return."}, 'CrossProfilePolicies': {'type': 'object', 'properties': {'crossProfileCopyPaste': {'enum': ['CROSS_PROFILE_COPY_PASTE_UNSPECIFIED', 'COPY_FROM_WORK_TO_PERSONAL_DISALLOWED', 'CROSS_PROFILE_COPY_PASTE_ALLOWED'], 'type': 'string', 'description': 'Optional. Whether text copied from one profile (personal or work) can be pasted in the other profile.', 'x-google-enum-descriptions': ['Unspecified. Defaults to COPY_FROM_WORK_TO_PERSONAL_DISALLOWED', 'Default. Prevents users from pasting into the personal profile text copied from the work profile. Text copied from the personal profile can be pasted into the work profile, and text copied from the work profile can be pasted into the work profile.', 'Text copied in either profile can be pasted in the other profile.']}, 'crossProfileDataSharing': {'enum': ['CROSS_PROFILE_DATA_SHARING_UNSPECIFIED', 'CROSS_PROFILE_DATA_SHARING_DISALLOWED', 'DATA_SHARING_FROM_WORK_TO_PERSONAL_DISALLOWED', 'CROSS_PROFILE_DATA_SHARING_ALLOWED'], 'type': 'string', 'description': 'Optional. Whether data from one profile (personal or work) can be shared with apps in the other profile. Specifically controls simple data sharing via intents. Management of other cross-profile communication channels, such as contact search, copy/paste, or connected work & personal apps, are configured separately.', 'x-google-enum-descriptions': ['Unspecified. Defaults to DATA_SHARING_FROM_WORK_TO_PERSONAL_DISALLOWED.', 'Prevents data from being shared from both the personal profile to the work profile and the work profile to the personal profile.', 'Default. Prevents users from sharing data from the work profile to apps in the personal profile. Personal data can be shared with work apps.', 'Data from either profile can be shared with the other profile.']}, 'crossProfileAppFunctions': {'enum': ['CROSS_PROFILE_APP_FUNCTIONS_UNSPECIFIED', 'CROSS_PROFILE_APP_FUNCTIONS_DISALLOWED', 'CROSS_PROFILE_APP_FUNCTIONS_ALLOWED'], 'type': 'string', 'description': 'Optional. Controls whether personal profile apps can invoke app functions exposed by apps in the work profile.', 'x-google-enum-descriptions': ['Unspecified. If `appFunctions` is set to `APP_FUNCTIONS_ALLOWED`, defaults to `CROSS_PROFILE_APP_FUNCTIONS_ALLOWED`. If `appFunctions` is set to `APP_FUNCTIONS_DISALLOWED`, defaults to `CROSS_PROFILE_APP_FUNCTIONS_DISALLOWED`.', 'Personal profile apps are not allowed to invoke app functions exposed by apps in the work profile.', 'Personal profile apps can invoke app functions exposed by apps in the work profile. If this is set, `appFunctions` must not be set to `APP_FUNCTIONS_DISALLOWED`, otherwise the policy will be rejected.']}, 'workProfileWidgetsDefault': {'enum': ['WORK_PROFILE_WIDGETS_DEFAULT_UNSPECIFIED', 'WORK_PROFILE_WIDGETS_DEFAULT_ALLOWED', 'WORK_PROFILE_WIDGETS_DEFAULT_DISALLOWED'], 'type': 'string', 'description': 'Optional. Specifies the default behaviour for work profile widgets. If the policy does not specify `work_profile_widgets` for a specific application, it will behave according to the value specified here.', 'x-google-enum-descriptions': ['Unspecified. Defaults to WORK_PROFILE_WIDGETS_DEFAULT_DISALLOWED.', 'Work profile widgets are allowed by default. This means that if the policy does not specify `work_profile_widgets` as `WORK_PROFILE_WIDGETS_DISALLOWED` for the application, it will be able to add widgets to the home screen.', 'Work profile widgets are disallowed by default. This means that if the policy does not specify `work_profile_widgets` as `WORK_PROFILE_WIDGETS_ALLOWED` for the application, it will be unable to add widgets to the home screen.']}, 'showWorkContactsInPersonalProfile': {'enum': ['SHOW_WORK_CONTACTS_IN_PERSONAL_PROFILE_UNSPECIFIED', 'SHOW_WORK_CONTACTS_IN_PERSONAL_PROFILE_DISALLOWED', 'SHOW_WORK_CONTACTS_IN_PERSONAL_PROFILE_ALLOWED', 'SHOW_WORK_CONTACTS_IN_PERSONAL_PROFILE_DISALLOWED_EXCEPT_SYSTEM'], 'type': 'string', 'description': 'Optional. Whether personal apps can access contacts stored in the work profile. See also `exemptions_to_show_work_contacts_in_personal_profile`.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `SHOW_WORK_CONTACTS_IN_PERSONAL_PROFILE_ALLOWED`. When this is set, `exemptions_to_show_work_contacts_in_personal_profile` must not be set.', 'Prevents personal apps from accessing work profile contacts and looking up work contacts. When this is set, personal apps specified in `exemptions_to_show_work_contacts_in_personal_profile` are allowlisted and can access work profile contacts directly. Supported on Android 7.0 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 7.0.', 'Default. Allows apps in the personal profile to access work profile contacts including contact searches and incoming calls. When this is set, personal apps specified in `exemptions_to_show_work_contacts_in_personal_profile` are blocklisted and can not access work profile contacts directly. Supported on Android 7.0 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 7.0.', 'Prevents most personal apps from accessing work profile contacts including contact searches and incoming calls, except for the OEM default Dialer, Messages, and Contacts apps. Neither user-configured Dialer, Messages, and Contacts apps, nor any other system or play installed apps, will be able to query work contacts directly. When this is set, personal apps specified in `exemptions_to_show_work_contacts_in_personal_profile` are allowlisted and can access work profile contacts. Supported on Android 14 and above. If this is set on a device with Android version less than 14, the behaviour falls back to `SHOW_WORK_CONTACTS_IN_PERSONAL_PROFILE_DISALLOWED` and a `NonComplianceDetail` with `API_LEVEL` is reported.']}, 'exemptionsToShowWorkContactsInPersonalProfile': {'$ref': '#/$defs/PackageNameList', 'description': 'Optional. List of apps which are excluded from the `ShowWorkContactsInPersonalProfile` setting. For this to be set, `ShowWorkContactsInPersonalProfile` must be set to one of the following values: * `SHOW_WORK_CONTACTS_IN_PERSONAL_PROFILE_ALLOWED`. In this case, these exemptions act as a blocklist. * `SHOW_WORK_CONTACTS_IN_PERSONAL_PROFILE_DISALLOWED`. In this case, these exemptions act as an allowlist. * `SHOW_WORK_CONTACTS_IN_PERSONAL_PROFILE_DISALLOWED_EXCEPT_SYSTEM`. In this case, these exemptions act as an allowlist, in addition to the already allowlisted system apps. Supported on Android 14 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 14.'}}, 'description': 'Controls the data from the work profile that can be accessed from the personal profile and vice versa. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported if the device does not have a work profile.'}, 'PasswordRequirements': {'type': 'object', 'properties': {'passwordScope': {'enum': ['SCOPE_UNSPECIFIED', 'SCOPE_DEVICE', 'SCOPE_PROFILE'], 'type': 'string', 'description': 'Optional. The scope that the password requirement applies to.', 'x-google-enum-descriptions': ['The scope is unspecified. The password requirements are applied to the work profile for work profile devices and the whole device for fully managed or dedicated devices.', 'The password requirements are only applied to the device.', 'The password requirements are only applied to the work profile.']}, 'passwordQuality': {'enum': ['PASSWORD_QUALITY_UNSPECIFIED', 'BIOMETRIC_WEAK', 'SOMETHING', 'NUMERIC', 'NUMERIC_COMPLEX', 'ALPHABETIC', 'ALPHANUMERIC', 'COMPLEX', 'COMPLEXITY_LOW', 'COMPLEXITY_MEDIUM', 'COMPLEXITY_HIGH'], 'type': 'string', 'description': 'Optional. The required password quality.', 'x-google-enum-descriptions': ['There are no password requirements.', 'The device must be secured with a low-security biometric recognition technology, at minimum. This includes technologies that can recognize the identity of an individual that are roughly equivalent to a 3-digit PIN (false detection is less than 1 in 1,000). This, when applied on personally owned work profile devices on Android 12 device-scoped, will be treated as `COMPLEXITY_LOW` for application. See `PasswordQuality` for details.', 'A password is required, but there are no restrictions on what the password must contain. This, when applied on personally owned work profile devices on Android 12 device-scoped, will be treated as `COMPLEXITY_LOW` for application. See `PasswordQuality` for details.', 'The password must contain numeric characters. This, when applied on personally owned work profile devices on Android 12 device-scoped, will be treated as `COMPLEXITY_MEDIUM` for application. See `PasswordQuality` for details.', 'The password must contain numeric characters with no repeating (4444) or ordered (1234, 4321, 2468) sequences. This, when applied on personally owned work profile devices on Android 12 device-scoped, will be treated as `COMPLEXITY_MEDIUM` for application. See `PasswordQuality` for details.', 'The password must contain alphabetic (or symbol) characters. This, when applied on personally owned work profile devices on Android 12 device-scoped, will be treated as `COMPLEXITY_HIGH` for application. See `PasswordQuality` for details.', 'The password must contain both numeric and alphabetic (or symbol) characters. This, when applied on personally owned work profile devices on Android 12 device-scoped, will be treated as `COMPLEXITY_HIGH` for application. See `PasswordQuality` for details.', 'The password must meet the minimum requirements specified in `passwordMinimumLength`, `passwordMinimumLetters`, `passwordMinimumSymbols`, etc. For example, if `passwordMinimumSymbols` is `2`, the password must contain at least two symbols. This, when applied on personally owned work profile devices on Android 12 device-scoped, will be treated as `COMPLEXITY_HIGH` for application. In this case, the requirements in `passwordMinimumLength`, `passwordMinimumLetters`, `passwordMinimumSymbols`, etc are not applied. See `PasswordQuality` for details.', 'Define the low password complexity band as: * pattern * PIN with repeating (4444) or ordered (1234, 4321, 2468) sequences This sets the minimum complexity band which the password must meet. Enforcement varies among different Android versions, management modes and password scopes. See `PasswordQuality` for details.', 'Define the medium password complexity band as: * PIN with no repeating (4444) or ordered (1234, 4321, 2468) sequences, length at least 4 * alphabetic, length at least 4 * alphanumeric, length at least 4 This sets the minimum complexity band which the password must meet. Enforcement varies among different Android versions, management modes and password scopes. See `PasswordQuality` for details.', 'Define the high password complexity band as: On Android 12 and above: * PIN with no repeating (4444) or ordered (1234, 4321, 2468) sequences, length at least 8 * alphabetic, length at least 6 * alphanumeric, length at least 6 This sets the minimum complexity band which the password must meet. Enforcement varies among different Android versions, management modes and password scopes. See `PasswordQuality` for details.']}, 'unifiedLockSettings': {'enum': ['UNIFIED_LOCK_SETTINGS_UNSPECIFIED', 'ALLOW_UNIFIED_WORK_AND_PERSONAL_LOCK', 'REQUIRE_SEPARATE_WORK_LOCK'], 'type': 'string', 'description': 'Optional. Controls whether a unified lock is allowed for the device and the work profile, on devices running Android 9 and above with a work profile. This can be set only if `password_scope` is set to `SCOPE_PROFILE`, the policy will be rejected otherwise. If user has not set a separate work lock and this field is set to `REQUIRE_SEPARATE_WORK_LOCK`, a `NonComplianceDetail` is reported with `nonComplianceReason` set to `USER_ACTION`.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `ALLOW_UNIFIED_WORK_AND_PERSONAL_LOCK`.', 'A common lock for the device and the work profile is allowed.', 'A separate lock for the work profile is required.']}, 'passwordHistoryLength': {'type': 'integer', 'format': 'int32', 'description': "Optional. The length of the password history. After setting this field, the user won't be able to enter a new password that is the same as any password in the history. A value of 0 means there is no restriction."}, 'passwordMinimumLength': {'type': 'integer', 'format': 'int32', 'description': 'Optional. The minimum allowed password length. A value of 0 means there is no restriction. Only enforced when `password_quality` is `NUMERIC`, `NUMERIC_COMPLEX`, `ALPHABETIC`, `ALPHANUMERIC`, or `COMPLEX`.'}, 'requirePasswordUnlock': {'enum': ['REQUIRE_PASSWORD_UNLOCK_UNSPECIFIED', 'USE_DEFAULT_DEVICE_TIMEOUT', 'REQUIRE_EVERY_DAY'], 'type': 'string', 'description': 'Optional. The length of time after a device or work profile is unlocked using a strong form of authentication (password, PIN, pattern) that it can be unlocked using any other authentication method (e.g. fingerprint, trust agents, face). After the specified time period elapses, only strong forms of authentication can be used to unlock the device or work profile.', 'x-google-enum-descriptions': ['Unspecified. Defaults to USE_DEFAULT_DEVICE_TIMEOUT.', 'The timeout period is set to the device’s default.', 'The timeout period is set to 24 hours.']}, 'passwordMinimumLetters': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Minimum number of letters required in the password. Only enforced when `password_quality` is `COMPLEX`.'}, 'passwordMinimumNumeric': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Minimum number of numerical digits required in the password. Only enforced when `password_quality` is `COMPLEX`.'}, 'passwordMinimumSymbols': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Minimum number of symbols required in the password. Only enforced when `password_quality` is `COMPLEX`.'}, 'passwordMinimumLowerCase': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Minimum number of lower case letters required in the password. Only enforced when `password_quality` is `COMPLEX`.'}, 'passwordMinimumNonLetter': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Minimum number of non-letter characters (numerical digits or symbols) required in the password. Only enforced when `password_quality` is `COMPLEX`.'}, 'passwordMinimumUpperCase': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Minimum number of upper case letters required in the password. Only enforced when `password_quality` is `COMPLEX`.'}, 'passwordExpirationTimeout': {'type': 'string', 'format': 'google-duration', 'description': 'Optional. Password expiration timeout.'}, 'maximumFailedPasswordsForWipe': {'type': 'integer', 'format': 'int32', 'description': 'Optional. Number of incorrect device-unlock passwords that can be entered before a device is wiped. A value of 0 means there is no restriction.'}}, 'description': 'Requirements for the password used to unlock a device.'}, 'PersonalUsagePolicies': {'type': 'object', 'properties': {'cameraDisabled': {'type': 'boolean', 'description': 'If true, the camera is disabled on the personal profile.'}, 'bluetoothSharing': {'enum': ['BLUETOOTH_SHARING_UNSPECIFIED', 'BLUETOOTH_SHARING_ALLOWED', 'BLUETOOTH_SHARING_DISALLOWED'], 'type': 'string', 'description': 'Optional. Whether bluetooth sharing is allowed.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `BLUETOOTH_SHARING_ALLOWED`.', 'Bluetooth sharing is allowed on personal profile. Supported on Android 8 and above. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported if this is set for a personal device.', 'Bluetooth sharing is disallowed on personal profile. Supported on Android 8 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 8. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported if this is set for a personal device.']}, 'maxDaysWithWorkOff': {'type': 'integer', 'format': 'int32', 'description': 'Controls how long the work profile can stay off. The minimum duration must be at least 3 days. Other details are as follows: - If the duration is set to 0, the feature is turned off. - If the duration is set to a value smaller than the minimum duration, the feature returns an error. *Note:* If you want to avoid personal profiles being suspended <https://developer.android.com/reference/android/app/admin/DevicePolicyManager#setPersonalAppsSuspended(android.content.ComponentName,%20boolean)> during long periods of off-time, you can temporarily set a large value for this parameter.'}, 'privateSpacePolicy': {'enum': ['PRIVATE_SPACE_POLICY_UNSPECIFIED', 'PRIVATE_SPACE_ALLOWED', 'PRIVATE_SPACE_DISALLOWED'], 'type': 'string', 'description': 'Optional. Controls whether a private space is allowed on the device.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `PRIVATE_SPACE_ALLOWED`.', 'Users can create a private space profile.', 'Users cannot create a private space profile. Supported only for company-owned devices with a work profile. Caution: Any existing private space will be removed.']}, 'crossDevicePolicies': {'$ref': '#/$defs/PersonalCrossDevicePolicies', 'description': 'Optional. Policies controlling cross-device communication in the personal profile.'}, 'personalApplications': {'type': 'array', 'items': {'$ref': '#/$defs/PersonalApplicationPolicy'}, 'description': 'Policy applied to applications in the personal profile.'}, 'personalPlayStoreMode': {'enum': ['PLAY_STORE_MODE_UNSPECIFIED', 'BLACKLIST', 'BLOCKLIST', 'ALLOWLIST'], 'type': 'string', 'description': 'Used together with personalApplications to control how apps in the personal profile are allowed or blocked.', 'x-google-enum-deprecated': [False, True, False, False], 'x-google-enum-descriptions': ['Unspecified. Defaults to `BLOCKLIST`.', 'All Play Store apps are available for installation in the personal profile, except those whose installType is BLOCKED in personalApplications.', 'All Play Store apps are available for installation in the personal profile, except those whose installType is BLOCKED in personalApplications.', 'Only apps explicitly specified in personalApplications with installType set to AVAILABLE are allowed to be installed in the personal profile.']}, 'screenCaptureDisabled': {'type': 'boolean', 'description': 'If `true`, screen capture is disabled for all users. This also blocks [Circle to Search](https://support.google.com/android/answer/14508957).'}, 'accountTypesWithManagementDisabled': {'type': 'array', 'items': {'type': 'string'}, 'description': "Account types that can't be managed by the user."}}, 'description': 'Policies controlling personal usage on a company-owned device with a work profile.'}, 'PolicyEnforcementRule': {'type': 'object', 'properties': {'wipeAction': {'$ref': '#/$defs/WipeAction', 'description': 'An action to reset a company owned device or delete a work profile. Note: `blockAction` must also be specified.'}, 'blockAction': {'$ref': '#/$defs/BlockAction', 'description': 'An action to block access to apps and data on a company owned device or in a work profile. This action also triggers a user-facing notification with information (where possible) on how to correct the compliance issue. Note: `wipeAction` must also be specified.'}, 'settingName': {'type': 'string', 'description': 'The top-level policy to enforce. For example, `applications` or `passwordPolicies`.'}}, 'description': 'A rule that defines the actions to take if a device or work profile is not compliant with the policy specified in `settingName`. In the case of multiple matching or multiple triggered enforcement rules, a merge will occur with the most severe action being taken. However, all triggered rules are still kept track of: this includes initial trigger time and all associated non-compliance details. In the situation where the most severe enforcement rule is satisfied, the next most appropriate action is applied.'}, 'ScreenTimeoutSettings': {'type': 'object', 'properties': {'screenTimeout': {'type': 'string', 'format': 'google-duration', 'description': 'Optional. Controls the screen timeout duration. The screen timeout duration must be greater than 0, otherwise it is rejected. Additionally, it should not be greater than `maximumTimeToLock`, otherwise the screen timeout is set to `maximumTimeToLock` and a `NonComplianceDetail` with `INVALID_VALUE` reason and `SCREEN_TIMEOUT_GREATER_THAN_MAXIMUM_TIME_TO_LOCK` specific reason is reported. If the screen timeout is less than a certain lower bound, it is set to the lower bound. The lower bound may vary across devices. If this is set, `screenTimeoutMode` must be `SCREEN_TIMEOUT_ENFORCED`. Supported on Android 9 and above on fully managed devices. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 9. Supported on work profiles on company-owned devices on Android 15 and above.'}, 'screenTimeoutMode': {'enum': ['SCREEN_TIMEOUT_MODE_UNSPECIFIED', 'SCREEN_TIMEOUT_USER_CHOICE', 'SCREEN_TIMEOUT_ENFORCED'], 'type': 'string', 'description': 'Optional. Controls whether the user is allowed to configure the screen timeout.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `SCREEN_TIMEOUT_USER_CHOICE`.', 'The user is allowed to configure the screen timeout. `screenTimeout` must not be set.', 'The screen timeout is set to `screenTimeout` and the user is not allowed to configure the timeout. `screenTimeout` must be set. Supported on Android 9 and above on fully managed devices. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 9. Supported on work profiles on company-owned devices on Android 15 and above.']}}, 'description': 'Controls the screen timeout settings.'}, 'OncCertificateProvider': {'type': 'object', 'properties': {'certificateReferences': {'type': 'array', 'items': {'type': 'string'}, 'description': ' This feature is not generally available.'}, 'contentProviderEndpoint': {'$ref': '#/$defs/ContentProviderEndpoint', 'description': ' This feature is not generally available.'}}, 'description': ' This feature is not generally available.'}, 'WorkAccountSetupConfig': {'type': 'object', 'properties': {'authenticationType': {'enum': ['AUTHENTICATION_TYPE_UNSPECIFIED', 'AUTHENTICATION_TYPE_NOT_ENFORCED', 'GOOGLE_AUTHENTICATED'], 'type': 'string', 'description': 'Optional. The authentication type of the user on the device.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `AUTHENTICATION_TYPE_NOT_ENFORCED`.', 'Authentication status of user on device is not enforced.', 'Requires device to be managed with a Google authenticated account.']}, 'requiredAccountEmail': {'type': 'string', 'description': 'Optional. The specific google work account email address to be added. This field is only relevant if `authenticationType` is `GOOGLE_AUTHENTICATED`. This must be an enterprise account and not a consumer account. Once set and a Google authenticated account is added to the device, changing this field will have no effect, and thus recommended to be set only once. The email address must be all lowercase.'}}, 'description': 'Controls the work account setup configuration, such as details of whether a Google authenticated account is required.'}, 'ContentProviderEndpoint': {'type': 'object', 'properties': {'uri': {'type': 'string', 'description': ' This feature is not generally available.'}, 'packageName': {'type': 'string', 'description': ' This feature is not generally available.'}, 'signingCertsSha256': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Required. This feature is not generally available.'}}, 'description': ' This feature is not generally available.'}, 'StatusReportingSettings': {'type': 'object', 'properties': {'memoryInfoEnabled': {'type': 'boolean', 'description': 'Whether [memory event](/android/management/reference/rest/v1/enterprises.devices#memoryevent) reporting is enabled.'}, 'displayInfoEnabled': {'type': 'boolean', 'description': 'Whether [displays](/android/management/reference/rest/v1/enterprises.devices#display) reporting is enabled. Report data is not available for personally owned devices with work profiles.'}, 'networkInfoEnabled': {'type': 'boolean', 'description': 'Whether [network info](/android/management/reference/rest/v1/enterprises.devices#networkinfo) reporting is enabled.'}, 'softwareInfoEnabled': {'type': 'boolean', 'description': 'Whether [software info](/android/management/reference/rest/v1/enterprises.devices#softwareinfo) reporting is enabled.'}, 'deviceSettingsEnabled': {'type': 'boolean', 'description': 'Whether [device settings](/android/management/reference/rest/v1/enterprises.devices#devicesettings) reporting is enabled.'}, 'hardwareStatusEnabled': {'type': 'boolean', 'description': 'Whether [hardware status](/android/management/reference/rest/v1/enterprises.devices#hardwarestatus) reporting is enabled. Report data is not available for personally owned devices with work profiles.'}, 'systemPropertiesEnabled': {'type': 'boolean', 'description': 'Whether system properties reporting is enabled.'}, 'applicationReportsEnabled': {'type': 'boolean', 'description': 'Whether [app reports](/android/management/reference/rest/v1/enterprises.devices#applicationreport) are enabled.'}, 'commonCriteriaModeEnabled': {'type': 'boolean', 'description': 'Whether Common Criteria Mode reporting is enabled. This is supported only on company-owned devices.'}, 'applicationReportingSettings': {'$ref': '#/$defs/ApplicationReportingSettings', 'description': 'Application reporting settings. Only applicable if application_reports_enabled is true.'}, 'powerManagementEventsEnabled': {'type': 'boolean', 'description': 'Whether [power management event](/android/management/reference/rest/v1/enterprises.devices#powermanagementevent) reporting is enabled. Report data is not available for personally owned devices with work profiles.'}, 'defaultApplicationInfoReportingEnabled': {'type': 'boolean', 'description': 'Optional. Whether `defaultApplicationInfo` reporting is enabled.'}}, 'description': 'Settings controlling the behavior of status reports.'}, 'ScreenBrightnessSettings': {'type': 'object', 'properties': {'screenBrightness': {'type': 'integer', 'format': 'int32', 'description': 'Optional. The screen brightness between 1 and 255 where 1 is the lowest and 255 is the highest brightness. A value of 0 (default) means no screen brightness set. Any other value is rejected. `screenBrightnessMode` must be either `BRIGHTNESS_AUTOMATIC` or `BRIGHTNESS_FIXED` to set this. Supported on Android 9 and above on fully managed devices. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 9. Supported on work profiles on company-owned devices on Android 15 and above.'}, 'screenBrightnessMode': {'enum': ['SCREEN_BRIGHTNESS_MODE_UNSPECIFIED', 'BRIGHTNESS_USER_CHOICE', 'BRIGHTNESS_AUTOMATIC', 'BRIGHTNESS_FIXED'], 'type': 'string', 'description': 'Optional. Controls the screen brightness mode.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `BRIGHTNESS_USER_CHOICE`.', 'The user is allowed to configure the screen brightness. `screenBrightness` must not be set.', 'The screen brightness mode is automatic in which the brightness is automatically adjusted and the user is not allowed to configure the screen brightness. `screenBrightness` can still be set and it is taken into account while the brightness is automatically adjusted. Supported on Android 9 and above on fully managed devices. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 9. Supported on work profiles on company-owned devices on Android 15 and above.', 'The screen brightness mode is fixed in which the brightness is set to `screenBrightness` and the user is not allowed to configure the screen brightness. `screenBrightness` must be set. Supported on Android 9 and above on fully managed devices. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 9. Supported on work profiles on company-owned devices on Android 15 and above.']}}, 'description': 'Controls for the screen brightness settings.'}, 'AdvancedSecurityOverrides': {'type': 'object', 'properties': {'mtePolicy': {'enum': ['MTE_POLICY_UNSPECIFIED', 'MTE_USER_CHOICE', 'MTE_ENFORCED', 'MTE_DISABLED'], 'type': 'string', 'description': 'Optional. Controls [Memory Tagging Extension (MTE)](https://source.android.com/docs/security/test/memory-safety/arm-mte) on the device. The device needs to be rebooted to apply changes to the MTE policy. On Android 15 and above, a `NonComplianceDetail` with `PENDING` is reported if the policy change is pending a device reboot.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `MTE_USER_CHOICE`.', 'The user can choose to enable or disable MTE on the device if the device supports this.', 'MTE is enabled on the device and the user is not allowed to change this setting. This can be set on fully managed devices and work profiles on company-owned devices. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for other management modes. A `NonComplianceDetail` with `DEVICE_INCOMPATIBLE` is reported if the device does not support MTE. Supported on Android 14 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 14.', 'MTE is disabled on the device and the user is not allowed to change this setting. This applies only on fully managed devices. In other cases, a `NonComplianceDetail` with `MANAGEMENT_MODE` is reported. A `NonComplianceDetail` with `DEVICE_INCOMPATIBLE` is reported if the device does not support MTE. Supported on Android 14 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 14.']}, 'developerSettings': {'enum': ['DEVELOPER_SETTINGS_UNSPECIFIED', 'DEVELOPER_SETTINGS_DISABLED', 'DEVELOPER_SETTINGS_ALLOWED'], 'type': 'string', 'description': 'Optional. Controls access to developer settings: developer options and safe boot. Replaces `safeBootDisabled` (deprecated) and `debuggingFeaturesAllowed` (deprecated). On personally-owned devices with a work profile, setting this policy will not disable safe boot. In this case, a `NonComplianceDetail` with `MANAGEMENT_MODE` is reported.', 'x-google-enum-descriptions': ['Unspecified. Defaults to DEVELOPER_SETTINGS_DISABLED.', 'Default. Disables all developer settings and prevents the user from accessing them.', 'Allows all developer settings. The user can access and optionally configure the settings.']}, 'commonCriteriaMode': {'enum': ['COMMON_CRITERIA_MODE_UNSPECIFIED', 'COMMON_CRITERIA_MODE_DISABLED', 'COMMON_CRITERIA_MODE_ENABLED'], 'type': 'string', 'description': 'Optional. Controls Common Criteria Mode—security standards defined in the [Common Criteria for Information Technology Security Evaluation](https://www.commoncriteriaportal.org/) (CC). Enabling Common Criteria Mode increases certain security components on a device, see `CommonCriteriaMode` for details. Warning: Common Criteria Mode enforces a strict security model typically only required for IT products used in national security systems and other highly sensitive organizations. Standard device use may be affected. Only enabled if required. If Common Criteria Mode is turned off after being enabled previously, all user-configured Wi-Fi networks may be lost and any enterprise-configured Wi-Fi networks that require user input may need to be reconfigured.', 'x-google-enum-descriptions': ['Unspecified. Defaults to COMMON_CRITERIA_MODE_DISABLED.', 'Default. Disables Common Criteria Mode.', 'Enables Common Criteria Mode.']}, 'untrustedAppsPolicy': {'enum': ['UNTRUSTED_APPS_POLICY_UNSPECIFIED', 'DISALLOW_INSTALL', 'ALLOW_INSTALL_IN_PERSONAL_PROFILE_ONLY', 'ALLOW_INSTALL_DEVICE_WIDE'], 'type': 'string', 'description': 'Optional. The policy for untrusted apps (apps from unknown sources) enforced on the device. Replaces `install_unknown_sources_allowed (deprecated).`', 'x-google-enum-descriptions': ['Unspecified. Defaults to DISALLOW_INSTALL.', 'Default. Disallow untrusted app installs on entire device.', "For devices with work profiles, allow untrusted app installs in the device's personal profile only.", 'Allow untrusted app installs on entire device.']}, 'contentProtectionPolicy': {'enum': ['CONTENT_PROTECTION_POLICY_UNSPECIFIED', 'CONTENT_PROTECTION_DISABLED', 'CONTENT_PROTECTION_ENFORCED', 'CONTENT_PROTECTION_USER_CHOICE'], 'type': 'string', 'description': 'Optional. Controls whether content protection, which scans for deceptive apps, is enabled. This is supported on Android 15 and above.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `CONTENT_PROTECTION_DISABLED`.', 'Content protection is disabled and the user cannot change this.', 'Content protection is enabled and the user cannot change this. Supported on Android 15 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 15.', 'Content protection is not controlled by the policy. The user is allowed to choose the behavior of content protection. Supported on Android 15 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 15.']}, 'googlePlayProtectVerifyApps': {'enum': ['GOOGLE_PLAY_PROTECT_VERIFY_APPS_UNSPECIFIED', 'VERIFY_APPS_ENFORCED', 'VERIFY_APPS_USER_CHOICE'], 'type': 'string', 'description': 'Optional. Whether [Google Play Protect verification](https://support.google.com/accounts/answer/2812853) is enforced. Replaces `ensureVerifyAppsEnabled` (deprecated).', 'x-google-enum-descriptions': ['Unspecified. Defaults to VERIFY_APPS_ENFORCED.', 'Default. Force-enables app verification.', 'Allows the user to choose whether to enable app verification.']}, 'personalAppsThatCanReadWorkNotifications': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Optional. Personal apps that can read work profile notifications using a [NotificationListenerService](https://developer.android.com/reference/android/service/notification/NotificationListenerService). By default, no personal apps (aside from system apps) can read work notifications. Each value in the list must be a package name.'}}, 'description': 'Advanced security settings. In most cases, setting these is not needed.'}, 'ApplicationSigningKeyCert': {'type': 'object', 'properties': {'signingKeyCertFingerprintSha256': {'type': 'string', 'format': 'byte', 'description': 'Required. The SHA-256 hash value of the signing key certificate of the app. This must be a valid SHA-256 hash value, i.e. 32 bytes.'}}, 'description': 'The application signing key certificate.'}, 'DefaultApplicationSetting': {'type': 'object', 'properties': {'defaultApplications': {'type': 'array', 'items': {'$ref': '#/$defs/DefaultApplication'}, 'description': 'Required. The list of applications that can be set as the default app for a given type. This list must not be empty or contain duplicates. The first app in the list that is installed and qualified for the `defaultApplicationType` (e.g. SMS app for `DEFAULT_SMS`) is set as the default app. The signing key certificate fingerprint of the app on the device must also match one of the signing key certificate fingerprints obtained from Play Store or one of the entries in `ApplicationPolicy.signingKeyCerts` in order to be set as the default. If the `defaultApplicationScopes` contains `SCOPE_FULLY_MANAGED` or `SCOPE_WORK_PROFILE`, the app must have an entry in `applications` with `installType` set to a value other than `BLOCKED`. A `NonComplianceDetail` with `APP_NOT_INSTALLED` reason and `DEFAULT_APPLICATION_SETTING_FAILED_FOR_SCOPE` specific reason is reported if *none* of the apps in the list are installed. A `NonComplianceDetail` with `INVALID_VALUE` reason and `DEFAULT_APPLICATION_SETTING_FAILED_FOR_SCOPE` specific reason is reported if at least one app is installed but the policy fails to apply due to other reasons (e.g. the app is not of the right type). When applying to `SCOPE_PERSONAL_PROFILE` on a company-owned device with a work profile, only pre-installed system apps can be set as the default. A `NonComplianceDetail` with `INVALID_VALUE` reason and `DEFAULT_APPLICATION_SETTING_FAILED_FOR_SCOPE` specific reason is reported if the policy fails to apply to the personal profile.'}, 'defaultApplicationType': {'enum': ['DEFAULT_APPLICATION_TYPE_UNSPECIFIED', 'DEFAULT_ASSISTANT', 'DEFAULT_BROWSER', 'DEFAULT_CALL_REDIRECTION', 'DEFAULT_CALL_SCREENING', 'DEFAULT_DIALER', 'DEFAULT_HOME', 'DEFAULT_SMS', 'DEFAULT_WALLET'], 'type': 'string', 'description': 'Required. The app type to set the default application.', 'x-google-enum-descriptions': ['Unspecified. This value must not be used.', 'The assistant app type. This app type is only allowed to be set for `SCOPE_FULLY_MANAGED`. Supported on fully managed devices on Android 16 and above. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for other management modes. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 16.', 'The browser app type. Supported on Android 16 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 16.', 'The call redirection app type. This app type cannot be set for `SCOPE_PERSONAL_PROFILE`. Supported on Android 16 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 16.', 'The call screening app type. This app type cannot be set for `SCOPE_PERSONAL_PROFILE`. Supported on Android 16 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 16.', 'The dialer app type. Supported on fully managed devices on Android 14 and 15. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for other management modes. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 14. Supported on all management modes on Android 16 and above.', 'The home app type. This app type is only allowed to be set for `SCOPE_FULLY_MANAGED`. Supported on fully managed devices on Android 16 and above. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for other management modes. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 16.', 'The SMS app type. This app type cannot be set for `SCOPE_WORK_PROFILE`. Supported on company-owned devices on Android 16 and above. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for personally-owned devices. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 16.', 'The wallet app type. The default application of this type applies across profiles. On a company-owned device with a work profile, admins can set the scope to `SCOPE_PERSONAL_PROFILE` to set a personal profile pre-installed system app as the default, or to `SCOPE_WORK_PROFILE` to set a work profile app as the default. It is not allowed to specify both scopes at the same time. Due to a known issue, the user may be able to change the default wallet even when this is set on a fully managed device. Supported on company-owned devices on Android 16 and above. A `NonComplianceDetail` with `MANAGEMENT_MODE` is reported for personally-owned devices. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 16.']}, 'defaultApplicationScopes': {'type': 'array', 'items': {'enum': ['DEFAULT_APPLICATION_SCOPE_UNSPECIFIED', 'SCOPE_FULLY_MANAGED', 'SCOPE_WORK_PROFILE', 'SCOPE_PERSONAL_PROFILE'], 'type': 'string', 'x-google-enum-descriptions': ['Unspecified. This value must not be used.', 'Sets the application as the default on fully managed devices.', 'Sets the application as the work profile default. Only supported for `DEFAULT_BROWSER`, `DEFAULT_CALL_REDIRECTION`, `DEFAULT_CALL_SCREENING`, `DEFAULT_DIALER` and `DEFAULT_WALLET`.', 'Sets the application as the personal profile default on company-owned devices with a work profile. Only pre-installed system apps can be set as the default. Only supported for `DEFAULT_BROWSER`, `DEFAULT_DIALER`, `DEFAULT_SMS` and `DEFAULT_WALLET`.']}, 'description': 'Required. The scopes to which the policy should be applied. This list must not be empty or contain duplicates. A `NonComplianceDetail` with `MANAGEMENT_MODE` reason and `DEFAULT_APPLICATION_SETTING_UNSUPPORTED_SCOPES` specific reason is reported if *none* of the specified scopes can be applied to the management mode (e.g. a fully managed device receives a policy with only `SCOPE_PERSONAL_PROFILE` in the list).'}}, 'description': 'The default application setting for a `DefaultApplicationType`.'}, 'PersonalApplicationPolicy': {'type': 'object', 'properties': {'installType': {'enum': ['INSTALL_TYPE_UNSPECIFIED', 'BLOCKED', 'AVAILABLE'], 'type': 'string', 'description': 'The type of installation to perform.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `AVAILABLE`.', "The app is blocked and can't be installed in the personal profile. If the app was previously installed in the device, it will be uninstalled.", 'The app is available to install in the personal profile.']}, 'packageName': {'type': 'string', 'description': 'The package name of the application.'}}, 'description': 'Policies for apps in the personal profile of a company-owned device with a work profile.'}, 'PersistentPreferredActivity': {'type': 'object', 'properties': {'actions': {'type': 'array', 'items': {'type': 'string'}, 'description': "The intent actions to match in the filter. If any actions are included in the filter, then an intent's action must be one of those values for it to match. If no actions are included, the intent action is ignored."}, 'categories': {'type': 'array', 'items': {'type': 'string'}, 'description': 'The intent categories to match in the filter. An intent includes the categories that it requires, all of which must be included in the filter in order to match. In other words, adding a category to the filter has no impact on matching unless that category is specified in the intent.'}, 'receiverActivity': {'type': 'string', 'description': 'The activity that should be the default intent handler. This should be an Android component name, e.g. `com.android.enterprise.app/.MainActivity`. Alternatively, the value may be the package name of an app, which causes Android Device Policy to choose an appropriate activity from the app to handle the intent.'}}, 'description': 'A default activity for handling intents that match a particular intent filter. **Note:** To set up a kiosk, use [InstallType](/android/management/reference/rest/v1/enterprises.policies#installtype) to `KIOSK` rather than use persistent preferred activities.'}, 'PersonalCrossDevicePolicies': {'type': 'object', 'properties': {'taskContinuityHandoff': {'enum': ['TASK_CONTINUITY_HANDOFF_UNSPECIFIED', 'TASK_CONTINUITY_HANDOFF_ALLOWED', 'TASK_CONTINUITY_HANDOFF_DISALLOWED'], 'type': 'string', 'description': 'Optional. Controls the [task continuity handoff](https://developer.android.com/partners/android-17/features#handoff) feature for the personal profile on company-owned devices with a work profile. To disable Handoff device-wide on a company-owned device, both `crossDevicePolicies.taskContinuityHandoff` and this policy should be set to `TASK_CONTINUITY_HANDOFF_DISALLOWED`. Requires Android 17 QPR1 or higher.', 'x-google-enum-descriptions': ['Defaults to `TASK_CONTINUITY_HANDOFF_ALLOWED`.', 'Allows the user to enable or disable the task continuity handoff feature in settings. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is lower than Android 17 QPR1.', 'The task continuity handoff feature is disallowed. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is lower than Android 17 QPR1.']}}, 'description': 'Policies controlling cross-device communication in the personal profile.'}, 'ApplicationReportingSettings': {'type': 'object', 'properties': {'includeRemovedApps': {'type': 'boolean', 'description': 'Whether removed apps are included in application reports.'}}, 'description': 'Settings controlling the behavior of application reports.'}, 'DeviceConnectivityManagement': {'type': 'object', 'properties': {'apnPolicy': {'$ref': '#/$defs/ApnPolicy', 'description': 'Optional. Access Point Name (APN) policy. Configuration for Access Point Names (APNs) which may override any other APNs on the device. See `OVERRIDE_APNS_ENABLED` and `overrideApns` for details.'}, 'configureWifi': {'enum': ['CONFIGURE_WIFI_UNSPECIFIED', 'ALLOW_CONFIGURING_WIFI', 'DISALLOW_ADD_WIFI_CONFIG', 'DISALLOW_CONFIGURING_WIFI'], 'type': 'string', 'description': 'Controls Wi-Fi configuring privileges. Based on the option set, user will have either full or limited or no control in configuring Wi-Fi networks.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `ALLOW_CONFIGURING_WIFI` unless `wifiConfigDisabled` is set to true. If `wifiConfigDisabled` is set to true, this is equivalent to `DISALLOW_CONFIGURING_WIFI`.', 'The user is allowed to configure Wi-Fi. `wifiConfigDisabled` is ignored.', 'Adding new Wi-Fi configurations is disallowed. The user is only able to switch between already configured networks. Supported on Android 13 and above, on fully managed devices and work profiles on company-owned devices. If the setting is not supported, `ALLOW_CONFIGURING_WIFI` is set. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 13. `wifiConfigDisabled` is ignored.', "Disallows configuring Wi-Fi networks. The setting `wifiConfigDisabled` is ignored when this value is set. Supported on fully managed devices and work profile on company-owned devices, on all supported API levels. For fully managed devices, setting this removes all configured networks and retains only the networks configured using `openNetworkConfiguration` policy. For work profiles on company-owned devices, existing configured networks are not affected and the user is not allowed to add, remove, or modify Wi-Fi networks. **Note:** If a network connection can't be made at boot time and configuring Wi-Fi is disabled then network escape hatch will be shown in order to refresh the device policy (see `networkEscapeHatchEnabled`)."]}, 'usbDataAccess': {'enum': ['USB_DATA_ACCESS_UNSPECIFIED', 'ALLOW_USB_DATA_TRANSFER', 'DISALLOW_USB_FILE_TRANSFER', 'DISALLOW_USB_DATA_TRANSFER'], 'type': 'string', 'description': 'Controls what files and/or data can be transferred via USB. Supported only on company-owned devices.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `DISALLOW_USB_FILE_TRANSFER`.', 'All types of USB data transfers are allowed. `usbFileTransferDisabled` is ignored.', 'Transferring files over USB is disallowed. Other types of USB data connections, such as mouse and keyboard connection, are allowed. `usbFileTransferDisabled` is ignored.', 'When set, all types of USB data transfers are prohibited. Supported for devices running Android 12 or above with USB HAL 1.3 or above. If the setting is not supported, `DISALLOW_USB_FILE_TRANSFER` will be set. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 12. A `NonComplianceDetail` with `DEVICE_INCOMPATIBLE` is reported if the device does not have USB HAL 1.3 or above. `usbFileTransferDisabled` is ignored.']}, 'wifiSsidPolicy': {'$ref': '#/$defs/WifiSsidPolicy', 'description': 'Restrictions on which Wi-Fi SSIDs the device can connect to. Note that this does not affect which networks can be configured on the device. Supported on company-owned devices running Android 13 and above.'}, 'bluetoothSharing': {'enum': ['BLUETOOTH_SHARING_UNSPECIFIED', 'BLUETOOTH_SHARING_ALLOWED', 'BLUETOOTH_SHARING_DISALLOWED'], 'type': 'string', 'description': 'Optional. Controls whether Bluetooth sharing is allowed.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `BLUETOOTH_SHARING_DISALLOWED` on work profiles and `BLUETOOTH_SHARING_ALLOWED` on fully managed devices.', 'Bluetooth sharing is allowed. Supported on Android 8 and above. A `NonComplianceDetail` with `API_LEVEL` is reported on work profiles if the Android version is less than 8.', 'Bluetooth sharing is disallowed. Supported on Android 8 and above. A `NonComplianceDetail` with `API_LEVEL` is reported on fully managed devices if the Android version is less than 8.']}, 'tetheringSettings': {'enum': ['TETHERING_SETTINGS_UNSPECIFIED', 'ALLOW_ALL_TETHERING', 'DISALLOW_WIFI_TETHERING', 'DISALLOW_ALL_TETHERING'], 'type': 'string', 'description': 'Controls tethering settings. Based on the value set, the user is partially or fully disallowed from using different forms of tethering.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `ALLOW_ALL_TETHERING` unless `tetheringConfigDisabled` is set to true. If `tetheringConfigDisabled` is set to true, this is equivalent to `DISALLOW_ALL_TETHERING`.', 'Allows configuration and use of all forms of tethering. `tetheringConfigDisabled` is ignored.', 'Disallows the user from using Wi-Fi tethering. Supported on company owned devices running Android 13 and above. If the setting is not supported, `ALLOW_ALL_TETHERING` will be set. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 13. `tetheringConfigDisabled` is ignored.', 'Disallows all forms of tethering. Supported on fully managed devices and work profile on company-owned devices, on all supported android versions. The setting `tetheringConfigDisabled` is ignored.']}, 'wifiRoamingPolicy': {'$ref': '#/$defs/WifiRoamingPolicy', 'description': 'Optional. Wi-Fi roaming policy.'}, 'privateDnsSettings': {'$ref': '#/$defs/PrivateDnsSettings', 'description': 'Optional. The global private DNS settings.'}, 'wifiDirectSettings': {'enum': ['WIFI_DIRECT_SETTINGS_UNSPECIFIED', 'ALLOW_WIFI_DIRECT', 'DISALLOW_WIFI_DIRECT'], 'type': 'string', 'description': 'Controls configuring and using Wi-Fi direct settings. Supported on company-owned devices running Android 13 and above.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `ALLOW_WIFI_DIRECT`', 'The user is allowed to use Wi-Fi direct.', 'The user is not allowed to use Wi-Fi direct. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 13.']}, 'preferentialNetworkServiceSettings': {'$ref': '#/$defs/PreferentialNetworkServiceSettings', 'description': 'Optional. Preferential network service configuration. Setting this field will override `preferentialNetworkService`. This can be set on both work profiles and fully managed devices on Android 13 and above. See [5G network slicing](https://developers.google.com/android/management/5g-network-slicing) guide for more details.'}}, 'description': 'Covers controls for device connectivity such as Wi-Fi, USB data access, keyboard/mouse connections, and more.'}, 'ManagedConfigurationTemplate': {'type': 'object', 'properties': {'templateId': {'type': 'string', 'description': 'The ID of the managed configurations template. This value must be a numeric string containing exactly one or more digits (for example, `"123456"`).'}, 'configurationVariables': {'type': 'object', 'description': 'Optional, a map containing configuration variables defined for the configuration.', 'additionalProperties': {'type': 'string'}}}, 'description': 'The managed configurations template for the app, saved from the [managed configurations iframe](/android/management/managed-configurations-iframe).'}, 'NonComplianceDetailCondition': {'type': 'object', 'properties': {'packageName': {'type': 'string', 'description': "The package name of the app that's out of compliance. If not set, then this condition matches any package name."}, 'settingName': {'type': 'string', 'description': 'The name of the policy setting. This is the JSON field name of a top-level [`Policy`](/android/management/reference/rest/v1/enterprises.policies#Policy) field. If not set, then this condition matches any setting name.'}, 'nonComplianceReason': {'enum': ['NON_COMPLIANCE_REASON_UNSPECIFIED', 'API_LEVEL', 'MANAGEMENT_MODE', 'USER_ACTION', 'INVALID_VALUE', 'APP_NOT_INSTALLED', 'UNSUPPORTED', 'APP_INSTALLED', 'PENDING', 'APP_INCOMPATIBLE', 'APP_NOT_UPDATED', 'DEVICE_INCOMPATIBLE', 'APP_SIGNING_CERT_MISMATCH', 'PROJECT_NOT_PERMITTED'], 'type': 'string', 'description': 'The reason the device is not in compliance with the setting. If not set, then this condition matches any reason.', 'x-google-enum-descriptions': ['This value is not used.', 'The setting is not supported in the API level of the Android version running on the device.', "The management mode (such as fully managed or work profile) doesn't support the setting.", 'The user has not taken required action to comply with the setting.', 'The setting has an invalid value.', 'The app required to implement the policy is not installed.', 'The policy is not supported by the version of Android Device Policy on the device.', 'A blocked app is installed.', "The setting hasn't been applied at the time of the report, but is expected to be applied shortly.", "The setting can't be applied to the app because the app doesn't support it, for example because its target SDK version is not high enough.", "The app is installed, but it hasn't been updated to the minimum version code specified by policy.", 'The device is incompatible with the policy requirements.', "The app's signing certificate does not match the setting value.", 'The Google Cloud Platform project used to manage the device is not permitted to use this policy.']}}, 'description': 'A compliance rule condition which is satisfied if there exists *any* matching [`NonComplianceDetail`](/android/management/reference/rest/v1/enterprises.devices#NonComplianceDetail) for the device. A `NonComplianceDetail` matches a `NonComplianceDetailCondition` if *all* the fields which are set within the `NonComplianceDetailCondition` match the corresponding `NonComplianceDetail` fields.'}, 'PreferentialNetworkServiceConfig': {'type': 'object', 'properties': {'nonMatchingNetworks': {'enum': ['NON_MATCHING_NETWORKS_UNSPECIFIED', 'NON_MATCHING_NETWORKS_ALLOWED', 'NON_MATCHING_NETWORKS_DISALLOWED'], 'type': 'string', 'description': 'Optional. Whether apps this configuration applies to are blocked from using networks other than the preferential service. If this is set to `NON_MATCHING_NETWORKS_DISALLOWED`, then `fallbackToDefaultConnection` must be set to `FALLBACK_TO_DEFAULT_CONNECTION_DISALLOWED`.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `NON_MATCHING_NETWORKS_ALLOWED`.', 'Apps this configuration applies to are allowed to use networks other than the preferential service.', 'Apps this configuration applies to are disallowed from using other networks than the preferential service. This can be set on Android 14 and above. A `NonComplianceDetail` with `API_LEVEL` is reported if the Android version is less than 14. If this is set, `fallbackToDefaultConnection` must be set to `FALLBACK_TO_DEFAULT_CONNECTION_DISALLOWED`, the policy will be rejected otherwise.']}, 'preferentialNetworkId': {'enum': ['PREFERENTIAL_NETWORK_ID_UNSPECIFIED', 'NO_PREFERENTIAL_NETWORK', 'PREFERENTIAL_NETWORK_ID_ONE', 'PREFERENTIAL_NETWORK_ID_TWO', 'PREFERENTIAL_NETWORK_ID_THREE', 'PREFERENTIAL_NETWORK_ID_FOUR', 'PREFERENTIAL_NETWORK_ID_FIVE'], 'type': 'string', 'description': 'Required. Preferential network identifier. This must not be set to `NO_PREFERENTIAL_NETWORK` or `PREFERENTIAL_NETWORK_ID_UNSPECIFIED`, the policy will be rejected otherwise.', 'x-google-enum-descriptions': ['Whether this value is valid and what it means depends on where it is used, and this is documented on the relevant fields.', 'Application does not use any preferential network.', 'Preferential network identifier 1.', 'Preferential network identifier 2.', 'Preferential network identifier 3.', 'Preferential network identifier 4.', 'Preferential network identifier 5.']}, 'fallbackToDefaultConnection': {'enum': ['FALLBACK_TO_DEFAULT_CONNECTION_UNSPECIFIED', 'FALLBACK_TO_DEFAULT_CONNECTION_ALLOWED', 'FALLBACK_TO_DEFAULT_CONNECTION_DISALLOWED'], 'type': 'string', 'description': 'Optional. Whether fallback to the device-wide default network is allowed. If this is set to `FALLBACK_TO_DEFAULT_CONNECTION_ALLOWED`, then `nonMatchingNetworks` must not be set to `NON_MATCHING_NETWORKS_DISALLOWED`, the policy will be rejected otherwise. Note: If this is set to `FALLBACK_TO_DEFAULT_CONNECTION_DISALLOWED`, applications are not able to access the internet if the 5G slice is not available.', 'x-google-enum-descriptions': ['Unspecified. Defaults to `FALLBACK_TO_DEFAULT_CONNECTION_ALLOWED`.', 'Fallback to default connection is allowed. If this is set, `nonMatchingNetworks` must not be set to `NON_MATCHING_NETWORKS_DISALLOWED`, the policy will be rejected otherwise.', 'Fallback to default connection is not allowed.']}}, 'description': 'Individual preferential network service configuration.'}, 'PreferentialNetworkServiceSettings': {'type': 'object', 'properties': {'defaultPreferentialNetworkId': {'enum': ['PREFERENTIAL_NETWORK_ID_UNSPECIFIED', 'NO_PREFERENTIAL_NETWORK', 'PREFERENTIAL_NETWORK_ID_ONE', 'PREFERENTIAL_NETWORK_ID_TWO', 'PREFERENTIAL_NETWORK_ID_THREE', 'PREFERENTIAL_NETWORK_ID_FOUR', 'PREFERENTIAL_NETWORK_ID_FIVE'], 'type': 'string', 'description': 'Required. Default preferential network ID for the applications that are not in `applications` or if `ApplicationPolicy.preferentialNetworkId` is set to `PREFERENTIAL_NETWORK_ID_UNSPECIFIED`. There must be a configuration for the specified network ID in `preferentialNetworkServiceConfigs`, unless this is set to `NO_PREFERENTIAL_NETWORK`. If set to `PREFERENTIAL_NETWORK_ID_UNSPECIFIED` or unset, this defaults to `NO_PREFERENTIAL_NETWORK`. Note: If the default preferential network is misconfigured, applications with no `ApplicationPolicy.preferentialNetworkId` set are not able to access the internet. This setting does not apply to the following critical apps: * `com.google.android.apps.work.clouddpc` * `com.google.android.gms` `ApplicationPolicy.preferentialNetworkId` can still be used to configure the preferential network for them.', 'x-google-enum-descriptions': ['Whether this value is valid and what it means depends on where it is used, and this is documented on the relevant fields.', 'Application does not use any preferential network.', 'Preferential network identifier 1.', 'Preferential network identifier 2.', 'Preferential network identifier 3.', 'Preferential network identifier 4.', 'Preferential network identifier 5.']}, 'preferentialNetworkServiceConfigs': {'type': 'array', 'items': {'$ref': '#/$defs/PreferentialNetworkServiceConfig'}, 'description': 'Required. Preferential network service configurations which enables having multiple enterprise slices. There must not be multiple configurations with the same `preferentialNetworkId`. If a configuration is not referenced by any application by setting `ApplicationPolicy.preferentialNetworkId` or by setting `defaultPreferentialNetworkId`, it will be ignored. For devices on 4G networks, enterprise APN needs to be configured additionally to set up data call for preferential network service. These APNs can be added using `apnPolicy`.'}}, 'description': 'Preferential network service settings.'}}, 'properties': {'policies': {'type': 'array', 'items': {'$ref': '#/$defs/Policy'}, 'description': 'The list of policies.'}, 'nextPageToken': {'type': 'string', 'description': 'If there are more results, a token to retrieve next page of results.'}}, 'description': 'Response to a request to list policies for a given enterprise.'}
输入模式
{'type': 'object', 'properties': {'parent': {'type': 'string', 'description': 'The name of the enterprise in the form `enterprises/{enterpriseId}`.'}, 'pageSize': {'type': 'integer', 'format': 'int32', 'description': 'The requested page size. This is a hint and the actual page size in the response may be different.'}, 'pageToken': {'type': 'string', 'description': 'A token identifying a page of results returned by the server.'}}, 'description': 'Request to list web apps for a given enterprise.'}
输出模式
{'type': 'object', '$defs': {'WebApp': {'type': 'object', 'properties': {'name': {'type': 'string', 'description': 'The name of the web app, which is generated by the server during creation in the form `enterprises/{enterpriseId}/webApps/{packageName}`.'}, 'icons': {'type': 'array', 'items': {'$ref': '#/$defs/WebAppIcon'}, 'description': 'A list of icons for the web app. Must have at least one element.'}, 'title': {'type': 'string', 'description': 'The title of the web app as displayed to the user (e.g., amongst a list of other applications, or as a label for an icon).'}, 'startUrl': {'type': 'string', 'description': 'The start URL, i.e. the URL that should load when the user opens the application.'}, 'displayMode': {'enum': ['DISPLAY_MODE_UNSPECIFIED', 'MINIMAL_UI', 'STANDALONE', 'FULL_SCREEN'], 'type': 'string', 'description': 'The display mode of the web app.', 'x-google-enum-descriptions': ['Not used.', 'Opens the web app with a minimal set of browser UI elements for controlling navigation and viewing the page URL.', 'Opens the web app to look and feel like a standalone native application. The browser UI elements and page URL are not visible, however the system status bar and back button are visible.', 'Opens the web app in full screen without any visible controls. The browser UI elements, page URL, system status bar and back button are not visible, and the web app takes up the entirety of the available display area.']}, 'versionCode': {'type': 'string', 'format': 'int64', 'description': 'The current version of the app. Note that the version can automatically increase during the lifetime of the web app, while Google does internal housekeeping to keep the web app up-to-date.'}}, 'description': 'A web app.'}, 'WebAppIcon': {'type': 'object', 'properties': {'imageData': {'type': 'string', 'description': 'The actual bytes of the image in a base64url encoded string (c.f. RFC4648, section 5 "Base 64 Encoding with URL and Filename Safe Alphabet"). - The image type can be png or jpg. - The image should ideally be square. - The image should ideally have a size of 512x512. '}}, 'description': 'An icon for a web app. Supported formats are: png, jpg and webp.'}}, 'properties': {'webApps': {'type': 'array', 'items': {'$ref': '#/$defs/WebApp'}, 'description': 'The list of web apps.'}, 'nextPageToken': {'type': 'string', 'description': 'If there are more results, a token to retrieve next page of results.'}}, 'description': 'Response to a request to list web apps for a given enterprise.'}
近期工具变更
类似的 MCP 服务器
agentView
Manages networked displays by creating, configuring, monitoring, and sending HTML, URLs, dashboards, and data-driven content to s…
UltraTech Pakistan
Lists UltraTech Pakistan IT services, retrieves service details, searches offerings, prepares quote requests, and calculates CCTV…
UniFi RMCP
Enables operating and managing networks through a UniFi Network controller.
Zhijiangyun Cloud (智匠云)
Supports GPU training, inference, benchmarking, and robot data collection for embodied-AI systems.
UniFi RMCP
Provides MCP and CLI operations for administering a UniFi Network controller.
deviceshelf-server
Queries and troubleshoots devices and services on a local network without using cloud services.
Unraid MCP
Provides MCP tools for interacting with an Unraid server through its GraphQL API.
Unraid RMCP
Performs Unraid GraphQL operations across NAS, Docker, virtual machine, and storage workflows.