Device security guidance
Guidance for organisations on how to choose, configure and use devices securely.
Pages
Page 3 of 37
Android
Android is a mobile operating system developed and released by Google for use in a variety of handheld devices, such as smartphones, tablets and wearables.
Whilst this guide may be relevant to a range of different Android versions, it was last tested on a device running Android 16 and configured in work managed mode.
Download Android configurations
You can download the NCSC's recommended settings for this platform from our GitHub repository.
These configurations are recommended to ensure that the device is in a state that aligns with the NCSC’s device security principles.
As Google releases new features, configurations may be made available which manage or restrict additional functionality. The NCSC will not necessarily have reviewed all these new features or updated our recommended configurations, so IT admins should make their own risk assessment when managing such features. A key aspect of Android is that equipment manufacturers can add functionality on top of base Android and the NCSC will not have assessed manufacturer-specific features.
General recommendations
-
Choose supported devices
- Select Android devices that align with your organisation’s needs.
- Most Android devices receive software updates for up to 3 years after first release, with many brands pushing up to 7 years.
- Once a device reaches end-of-life, it will no longer receive security updates and should be replaced to maintain security standards.
- Note: update schedules vary by manufacturer. Manufacturers must publish how many years of support they will provide in order to comply with the Product Security and Telecommunications Infrastructure Act.
- Google provides a list of end of support dates for Pixel devices.
- For non-Google devices check directly with the manufacturer.
-
Enforce centralised management
- Devices should be organisation-managed to enforce consistent policies.
- Use a Mobile Device Management (MDM) service to apply technical controls.
-
Use Enterprise Mobility Management (EMM) with OEMConfig support
- OEMConfig allows device manufacturers to offer device-specific configurations via apps on the Google Play store.
- IT admins can access the policies through the EMM console.
-
Enable logging and monitoring
- Configure your MDM to support logging and monitoring for better visibility and compliance.
-
Secure remote access
- Implement one of our recommended network architectures to enable secure remote access to enterprise services.
- If you require a virtual private network (VPN), use a trusted third-party VPN app.
-
Manage work applications
- Approve third-party apps for work use ('managed apps') centrally via an enterprise application catalogue.
- Deploy apps as ‘managed apps’ either:
- automatically during device setup, or
- through the managed Google Play store
-
Configure Google account policies
- Decide how to enable enterprise-owned Google accounts on users' devices.
- Use on-device policies to manage access to specific Google features.
-
Antivirus and security software
- The NCSC does not recommend using third-party antivirus or other security software in managed Android environments.
Work applications
-
Application management for secure and productive remote work
Most organisations will want to offer their users a range of productivity and business applications so they can consume, create, and collaborate remotely.
We recommend using:
- built-in applications, or applications integrated into your corporate services
These options enhance:
- supply chain assurance
- implementation of technical controls
-
Managing third-party applications
If your organisation uses third-party apps for work purposes, you should manage them through an enterprise application catalogue. This catalogue should:
- contain pre-approved apps that users can install as needed
- be delivered via your MDM solution
- ensure apps are deployed as 'managed' apps, granting them access to work data
-
High-privilege app considerations
Exercise caution when approving high-privilege applications such as:
- third-party keyboard app and network extensions
These apps may access significant amounts of corporate data, and therefore pose a higher security risk.
-
Android device configurations
- Work-only devices: the organisation’s private Google Play store will only allow installation of apps from a pre-defined allow list.
- Work-personal devices: apps installed from the public Google Play store are considered 'unmanaged' and do not have access to corporate data.
For more details on managing third-party applications and understanding associated risks, see our guidance on using third-party applications on devices.
Device configuration
Once you have chosen your MDM service, defined your network architecture and established your application management approach, the next step is to deliver a device configuration policy. This policy will help to enforce your organisation’s technical controls across all managed Android devices.
Your device configuration should include policies that manage:
- external interfaces, including controlling access to wired and wireless peripherals (for example, disable USB accessories when the device is locked)
- the use of biometrics, which is the recommended method of authentication, but you may also wish to consider the use of passcodes, authentication policies and other credentials.
- which Google Cloud services to allow use of
- device OS and application updates, enabling automatic updates where appropriate


