Skip to main content
Guidance

Device security guidance

Guidance for organisations on how to choose, configure and use devices securely.

Page 3 of 37

Android

Android is a mobile operating system developed and released by Google for use in a variety of handheld devices, such as smartphones, tablets and wearables.

Whilst this guide may be relevant to a range of different Android versions, it was last tested on a device running Android 16 and configured in work managed mode.


Download Android configurations

You can download the NCSC's recommended settings for this platform from our GitHub repository

These configurations are recommended to ensure that the device is in a state that aligns with the NCSC’s device security principles.

As Google releases new features, configurations may be made available which manage or restrict additional functionality. The NCSC will not necessarily have reviewed all these new features or updated our recommended configurations, so IT admins should make their own risk assessment when managing such features. A key aspect of Android is that equipment manufacturers can add functionality on top of base Android and the NCSC will not have assessed manufacturer-specific features.


General recommendations

  • Choose supported devices

  • Enforce centralised management

  • Use Enterprise Mobility Management (EMM) with OEMConfig support

    • OEMConfig allows device manufacturers to offer device-specific configurations via apps on the Google Play store.  
    • IT admins can access the policies through the EMM console.
  • Enable logging and monitoring

  • Secure remote access

  • Manage work applications

    • Approve third-party apps for work use ('managed apps') centrally via an enterprise application catalogue. 
    • Deploy apps as ‘managed apps’ either:
      • automatically during device setup, or 
      • through the managed Google Play store
  • Configure Google account policies

  • Antivirus and security software


Work applications

  • Application management for secure and productive remote work

    Most organisations will want to offer their users a range of productivity and business applications so they can consume, create, and collaborate remotely. 

    We recommend using: 

    • built-in applications, or applications integrated into your corporate services

    These options enhance:

    • supply chain assurance
    •  implementation of technical controls
  • Managing third-party applications

    If your organisation uses third-party apps for work purposes, you should manage them through an enterprise application catalogue. This catalogue should:

    • contain pre-approved apps that users can install as needed
    • be delivered via your MDM solution 
    • ensure apps are deployed as 'managed' apps, granting them access to work data
  • High-privilege app considerations

    Exercise caution when approving high-privilege applications such as:

    • third-party keyboard app and network extensions

    These apps may access significant amounts of corporate data, and therefore pose a higher security risk.

  • Android device configurations

    • Work-only devices: the organisation’s private Google Play store will only allow installation of apps from a pre-defined allow list. 
    • Work-personal devices: apps installed from the public Google Play store are considered 'unmanaged' and do not have access to corporate data. 

    For more details on managing third-party applications and understanding associated risks, see our guidance on using third-party applications on devices


Device configuration

Once you have chosen your MDM service, defined your network architecture and established your application management approach, the next step is to deliver a device configuration policy. This policy will help to enforce your organisation’s technical controls across all managed Android devices. 

Your device configuration should include policies that manage:

Published

Reviewed

Version

2.1