Application: Portal Nomid MDM
Document: V2.0.0
Last updated: 14/07/2026
Editorial owner: Nomid MDM Documentation
Last editorial review: 14/07/2026
Editorial language: en-US
The Policies module defines how managed Android devices behave. Operators use it to control applications, Home Screen, the Nomid Settings app, network, device resources, security, remote access, geofencing, app schedules, contacts, data collection, and history.
Important: saving a policy creates the current revision and starts its distribution, which can change the behavior of every linked device. Before saving, confirm the active company, target device scope, required apps, and critical network, security, and remote access restrictions.

The table list is used to locate existing policies, check version, status, and the main configured resources. Use it when you need to compare policies, validate whether a policy includes apps, network, security, or advanced resources, and open the correct policy for editing.

The grid displays policies as summary cards. It is useful for environments with fewer policies or well-standardized names because it lets you visually identify the item before opening the details.

Search narrows the list by text and filters help locate policies by operational characteristic. Use these tools before creating a new policy to avoid duplicates and quickly find the policy applied to a group or scenario.

The summary shows the overall state of the open policy, including identification, current version, and configured modules. Use it as the review point before changing a policy already in use.

Each action has a different effect:
The current flow has no separate draft and publish stage. When you create or save a policy, the portal records a new current revision and starts its distribution:
To prove the result, confirm the new revision in History and, in Devices > Policy, compare Policy version with the current saved version and verify that Last sync occurred after the change. Also check Devices > History when you need to confirm device commands and responses.

Tabs organize the policy modules. Tab search speeds up navigation when the policy contains many configuration blocks.

The Home Screen tab controls the device's initial experience: launcher mode, app inventory, visual order, dock, appearance, allow and deny lists, Play Store behavior, and default applications. For the options shown in the new images, it replaces the old separation between Basic, Apps, and Launcher.

Launcher Mode defines who controls the device home screen. The selected mode changes which customizations are available below.

Nomid Launcher applies the premium Nomid launcher experience. When selected, the policy can control visible apps, order, dock, wallpaper, text color, and serial number display on the home screen.

Nomid Kiosk dedicates the device to a controlled app experience or a restricted set of apps. Use it when the operation requires focus, less navigation freedom, and lower risk of leaving the planned workflow.

System Default keeps the native Android experience. In this mode, the system does not apply Nomid launcher-specific customizations.

When System Default is active, the portal warns that Home Screen customization is unavailable. To configure appearance, dock, and app experience again, select Nomid Launcher or Nomid Kiosk.

The apps list defines which applications belong to the policy, which state each app has on the device, and which actions are available for each app. Use search to locate by name or package name and filters to review source, state, or visibility.

The Add App button opens the available inclusion methods:

Use Nomid Store when the app is already in the internal catalog. Selecting an item adds it to the policy and lets you adjust install state and visibility.

Use Play Store to approve and include Managed Google Play apps. After selecting the app, it becomes part of the policy and can receive Blocked, Optional, or Required state.

Create Web App creates, in the Managed Google Play context, a private web app for the organization from a title, URL, display mode, and icon. Display mode defines whether the page opens full screen, standalone, or with minimal UI, changing how native the experience feels on the device.

Add Secure Web App creates a web application controlled by the secure browser. Use it when access requires allowed domains, dedicated permissions, navigation restrictions, or different handling from a common web app.

Add app by package name adds the app by its Android identifier. Use it when the package name is known, for example com.example.app, and then confirm that icon, name, and source were resolved correctly.

App actions allow you to open settings, change state, control visibility, enable or disable, remove, or adjust advanced options depending on the app type. The available set can vary for Nomid apps, web apps, secure apps, or apps acting as launcher.

The app state defines the device result:

Layout & Dock defines which apps appear on the Home Screen, which source is displayed, app order, icon size, and docked apps. User Device respects the device order, while Policy Defined enforces the order configured in the policy.

Appearance controls wallpaper, text color, and serial number display on the Home Screen. Choose light or dark text according to the wallpaper contrast to keep field readability.

App Controls defines global rules for Play Store, default permission policy, relauncher, Play Protect, and individual grants. These settings determine whether the user can browse Play Store, how permissions are granted, and whether an app should be relaunched periodically.

Deny list blocks selected apps and preserves the rest according to the policy. Use it when only a few apps must be prevented.

Allow list allows only the selected apps and restricts the rest. Use it carefully, because an incomplete list can remove apps needed for operation, support, or connectivity.

Default Applications sets default apps for compatible Android roles, such as assistant, browser, call redirection, call screening, dialer, SMS, and wallet. The choice affects which app is automatically called for that role.

The Application Type selector chooses the role to configure. After selecting the type, add the allowed app and confirm the scope, such as fully managed device or work profile, when available.

The Settings App tab controls resources displayed in the Nomid Settings app installed on the device. It depends on the Nomid app being included in the policy.

Policy Password defines the password used to unlock protected controls inside Nomid Settings. Enter an explicit password that is unique to the operation and stored in an approved vault; leaving the field empty may trigger a fallback based on the device's last digits when that behavior is available, which should be treated as a temporary and weaker exception. When changing the password, save the policy, validate it on a pilot device, and record who received access.

Button Availability chooses which buttons appear in Nomid Settings and which require a password. The list includes Local, Android Settings, Checkup, Flashlight, Policy, Store, Device, Brightness, Bluetooth, Login, Wi-Fi, Secure Wi-Fi, Delay Relauncher, Portal QR, IMEI Barcode, and Serial Barcode.

Each button accepts three results:

The Network tab configures Wi-Fi networks, connectivity restrictions, APN, VPN, proxy, and advanced controls. Always test in a pilot group because a network error can interrupt communication, provisioning, and remote support.

Wi-Fi Networks adds networks that the device can use during provisioning and daily operation. Enter SSID, security type, password, and auto connect when the network should connect automatically.

Standard writes the network directly into the Android policy. Use it for conventional networks managed by policy.

Secure via Nomid uses Nomid-managed configuration for networks that require secure handling in the Nomid app. Use it when network access must be administered by the Nomid layer.

Wi-Fi Settings controls whether the user can add or change networks, use Wi-Fi Direct, keep Wi-Fi always enabled or disabled, and require a minimum security level before connecting.

Mobile & Sharing controls hotspot/tethering, USB data transfer, airplane mode, ultra wideband, and 2G. Use Not configured when no rule should be imposed, Always enabled/disabled when a state should be forced, and blocking options when the resource must be prevented by policy.

APN enables or disables custom APN settings for mobile connectivity. When enabled, choose an existing carrier or add a custom configuration.

Custom APN defines name, APN types, authentication, protocols, roaming, MCC/MNC, proxy, MMSC, MTU, MVNO, and other parameters. Validate these values with the carrier before applying because an incorrect APN can break mobile data.

VPN configures an always-on VPN app and can block traffic when the VPN is disconnected. Do not enable network blocking without validating the VPN app, or the device can lose connectivity.

Global Proxy routes network traffic through host, port, PAC URL, and exclusion list. Use it only when the proxy infrastructure is validated for managed devices.

Advanced Restrictions enables or blocks Bluetooth configuration, cell broadcast, hotspot, mobile network, VPN, credentials, network escape hatch, and network reset. These controls define whether the user can change critical connectivity settings.

The Device Settings tab controls general Android resources, lock screen, permissions, system updates, and user controls.

Device Controls enables or blocks camera, screen capture, fun settings, volume, Bluetooth, SMS, and first-use hints. Enabled controls allow use; disabled controls prevent or hide the resource depending on Android and manufacturer support.

Display & Lock controls brightness and time to lock. User Choice lets the user decide, Automatic uses automatic behavior, Fixed forces the policy value, and Enforced requires the configured timeout.

Default permission policy defines how permissions requested by apps are handled by default, such as prompting the user, granting, or denying according to the available option. The block also controls window creation and keyguard resources.

System updates (OTA) defines the Android update cadence:
Freeze Periods temporarily blocks updates during critical windows, such as inventory, events, commercial dates, or field operation.

User Controls defines whether the user can add or remove accounts, choose a user icon, and change wallpaper. Use it to balance local personalization and operational standardization.

The Hardware tab controls physical resources and power behavior.

Hardware Controls allows or blocks factory reset, safe boot, physical media mounting, debugging, account modification, and microphone. Disabling dangerous capabilities reduces the risk of policy bypass.

Power & Charging defines when the device stays awake while connected to power. Options include AC, USB, and wireless power sources; select the sources compatible with the use case.

The Security tab concentrates access, recovery, restrictions, app installation, integrity evaluation, enforcement rules, password, private key, accessibility, and input methods.

Access & Recovery defines PIN or SSO authentication, factory reset protection emails, and lock screen message. Use SSO when the operation depends on corporate identity and PIN when the local flow must stay simple and controlled.

Device Restrictions controls Bluetooth contact sharing, NFC Beam, USB transfer, outgoing calls, and data roaming. Enabled controls allow or preserve the feature; disabled controls restrict the corresponding behavior.

This block controls app auto-update, encryption, location sharing, location mode, and untrusted app installation. Use restrictive options to prevent installations outside the approved channel and keep location aligned with the operational purpose.

Security Evaluation Actions defines the automatic response when the device fails evaluations such as Unknown OS, Compromised OS, or Hardware-backed evaluation failed:
Before using Wipe and Remove automatically, define in writing the signal that triggers the rule, grace window, approvers, communication plan, and stop criteria. Offline devices may execute the action only after they communicate again, so monitor History and Devices until success, failure, or pending state is confirmed.

Enforcement Rules creates compliance rules by target, such as Applications. Configure time until block, block scope, time until wipe, and whether factory reset protection should be preserved after wipe.
When the rule includes blocking or wipe, apply it to a pilot group first and confirm the real effect on the device. An incorrect rule can block essential apps, interrupt connectivity, or trigger data removal at scale; keep rollback ready before saving the change.

Password Requirements defines scope, quality, expiration, maximum failed attempts, history, and password unlock period. Strong rules improve security, but can create additional support demand if applied without user communication.

Private Key Rule allows selected apps to use a private key for authentication. Define URI pattern, key alias, and allowed packages when corporate apps depend on certificates.

Permitted accessibility services defines which apps can use accessibility services. In the displayed configuration, Nomid apps such as Settings Up and Remote can be authorized to enable controlled operational resources.

This list uses the same app-selection pattern for permitted input methods. Include only approved keyboards or services to reduce the risk of improper data capture.

Permitted input methods restricts which keyboard apps can be used. Add by app already in policy, Play Store, Web App, or package name as needed.

The Remote Access tab configures whether the policy prepares the device for remote support. It does not replace the remote access procedure, but ensures the base app and settings are present in the policy.

When Enable Remote Access is enabled, the portal adds tech.nomid.remote as a required app and writes managed configurations. The displayed options control:
Ending a remote session does not replace policy revocation. If access was enabled only for support, disable temporary options, save and synchronize the policy, confirm on the device that the app and permissions returned to the standard state, and rotate shared passwords when applicable.
On the device, the app still needs to complete the initialization layer and required permissions from the remote access procedure, such as accessibility, overlay, and screen capture/control when applicable.

The Geofencing tab defines location-based rules for notification, audit, or operational automation.

Location Information defines the rule name and notification types. Use clear names because they appear in reviews and audits.

Coordinates & Map Visualization defines latitude, longitude, radius, and map preview. Enter accurate coordinates and adjust the radius according to operational tolerance, remembering that precision can vary by signal, environment, and device permissions.

The App Schedules tab creates app access windows by day and time. Use it to release applications only during working hours, shifts, training, or a specific operation.

Create a rule, add name and description, select apps, and define the schedule. The rule is only meaningful when target apps and allowed times are configured.

Packages chooses the apps affected by the rule. Add by Play Store, app already in policy, or package name.

Set Access Schedule defines windows by weekday. Active days allow apps during configured times; days without a window leave access blocked or outside the rule, depending on policy behavior.

The Contact List tab distributes contact lists to managed devices.

Contact Lists shows the lists already distributed by the policy and allows removing lists that should no longer sync to devices.

Add contact lists opens existing list selection. Choose one or more lists and apply them so they become distributed by the policy.

Create new lets you create a list by entering name, description, tags, and CSV file. After creation or selection, the list must be applied to become part of the policy.

The Data Collection tab defines which information devices report to the portal. Collect only what is necessary for support, security, and contracted operation.
Use these settings with data governance: define purpose, who can access the data, retention time, allowed export channel, and when collection should be turned off. Location, network, IMEI, serial, installed/removed apps, and security events may identify a person, asset, or operational routine, so they must not be sent outside approved corporate channels.

Application Reports defines the app report level, such as installed and removed apps. This visibility helps confirm compliance and investigate unexpected changes.

Device Data Included selects categories such as settings, hardware, network, software, display, memory, power, and system properties. Each enabled key increases portal visibility into the device.

Usage Statistics controls collection of app usage, mobile data, Wi-Fi data, and collection interval. Shorter intervals increase detail, but can increase battery and traffic consumption.

Location Collection defines time-based collection, minimum displacement, and the logical operator between criteria. Use Or to collect when any criterion is met and And to require all criteria together.

The History tab records policy changes, authors, dates, and versions. Use it before investigating unexpected behavior because many field issues start with a policy change.

The list lets you review chronological events and open details from previous versions. Use records for audit, support, and configuration comparison.

History actions have the following effects:
Before restoring, compare the revisions, confirm apps, network, launcher, and critical restrictions, validate the impact on linked devices, and use a pilot group first. After restoration, prove the version and latest synchronization in Devices > Policy.