Android MDM· By Venkatesh AGE

How to Stop Employees Installing Apps on Work Phones

Blocking apps on company Android phones by controlling what is available rather than policing what gets installed, plus how to handle the requests that follow.

The reliable way to stop employees installing apps on company Android phones is not to block individual apps. It is to replace the app store with a smaller one that contains only what you have approved. Everything else simply is not there to install.

This is a better approach than a blocklist for an obvious reason: a blocklist requires you to predict what people will install, and you will not. An approved catalogue requires you to know what your business uses, which you do.

How it works

On a managed company-owned Android device, the Play Store is replaced by Managed Google Play. It looks and behaves like the normal store, but it shows only apps your organisation has approved.

You put apps into three buckets.

Required. Installs automatically on every device in the group, without anyone tapping anything. This is where your job management app, your messaging tool and anything else the role depends on goes. A new phone arrives with these already on it.

Available. Appears in the store for the employee to install if they want. Useful for things some people need and others do not, like a scanner utility or a particular manufacturer’s app.

Not approved. Everything else. Not blocked with a warning; absent.

The result is that nobody has to be told not to install games, because there are no games. The full picture of what you can require, allow and block is on our app management page.

Sideloading, and your own app

The other route onto a phone is sideloading: installing an APK file directly rather than through the store.

A security policy can prevent installation from unknown sources, which closes this for practical purposes on a company device. That control is standard and worth having switched on.

If your business had its own app built, you do not need sideloading anyway. NounDesk publishes a company app privately through Managed Google Play: it is visible only to your devices, never appears in the public store, and installs like any other required app. That is the supported route, and it is a better one, because the app keeps updating through Google rather than being copied around by hand.

Deciding what to approve

Most small businesses over-think this. Start by listing what people actually use on a work phone in a normal week.

There is usually a job or dispatch app, a messaging tool, email and calendar, maps, a camera or scanning app, and one or two role-specific things. That is the required list for most roles, and it is shorter than people expect.

Then be deliberate about the grey area. Social media apps are the usual argument. A blanket ban feels decisive and generates constant friction; approving them undermines the point of a work phone. The middle answer that tends to hold is to approve nothing social by default and handle exceptions by role, so the marketing person who genuinely needs Instagram gets it and the delivery driver does not have a running argument about it.

Write down why each app is approved. In six months you will not remember, and the list will otherwise grow by accretion.

Groups matter more than you think

Do not run one app list for the whole business.

A technician’s phone, an office manager’s phone and a counter tablet want different things. Set up groups that match the roles you actually have, and attach the app list to the group rather than to individuals. Then adding a new technician is one action, not a configuration exercise. Our groups and employees page covers the structure.

Two or three groups is usually enough for a business under fifty devices. More than five and you are making work for yourself.

Handling the requests

Once you switch this on, people will ask for apps. This is a good sign; it means the control is working.

Agree a route for requests, even if it is just a message to you, and answer within a day or two. The failure mode is not that people ask for too much, it is that requests go unanswered, someone cannot do their job, and the whole scheme gets a reputation for obstruction.

Say yes more often than you expect to. The purpose is to keep unvetted software off devices that hold customer data, not to control how people spend their afternoon. An approved app that helps somebody work is not a failure of policy.

Tell people before you do it

A phone that silently loses its app store on a Tuesday morning generates a bad day.

Explain it first, in one paragraph: the phones are company devices, apps now come from an approved list, here is what you will find on it, here is how to ask for something else. Most people do not mind at all once they understand it is about the device rather than about them.

It also helps to say what management does not do. People assume app control means message reading. It does not, and saying so directly is worth the two sentences. Our security page lists what is and is not collected.

What to do this week

  1. Write the required list for your most common role. Just one role. It will be six to ten apps and it takes ten minutes.
  2. Look at one phone’s current app list. Whatever is on there that surprises you is the reason to do this.
  3. Decide the social media question before anyone asks, and write your answer down. Deciding it during an argument goes worse.

FAQ

Can I block one specific app rather than approving a whole list?

You can approve a catalogue and leave a particular app out of it, which has the same effect and holds up better. Maintaining a blocklist means guessing what people will try next.

Will employees know apps are being restricted?

Yes, and they should. The store shows a smaller catalogue. This is not something to hide, and explaining it up front avoids the assumption that something more invasive is happening.

Can people install apps from a website instead?

Not if the policy prevents installation from unknown sources, which is a standard setting on a company device.

What if the app we need is one we had built ourselves?

Publish it privately through Managed Google Play. It stays invisible to the public store and installs on your devices like anything else in your catalogue.

What if someone needs an app urgently on site?

Approve it from your phone. It takes a moment and the app appears on their device shortly afterwards. This is why an agreed request route matters more than the initial list.

Does this work across different phone brands?

Yes. App management runs through Managed Google Play and Android Enterprise, so behaviour is consistent on any device running Android 8 or newer.

Controlling the catalogue rather than chasing installations turns an ongoing argument into a one-time decision.

See how Managed Google Play works, or start a free trial.