⚠️ Legacy feature. Compliance Policies (along with Templates, which apply them) are a legacy Esper product. For new device configuration work, use Blueprints instead — Compliance Policies remain available for existing Template-based deployments. See Introduction to Compliance Policies: https://help.esper.io/hc/en-us/articles/12653153592977-Introduction-to-Compliance-Policies
Creates a new Compliance Policy for the enterprise.
Creates a Compliance Policy record defining a set of device restrictions/permissions that can subsequently be applied to Template-provisioned devices.
About Compliance Policies A Compliance Policy is a set of device-configuration permissions and restrictions — screen and unlock behavior (keyguard, safe boot), connectivity (USB, tethering, NFC), communication (SMS, outgoing/incoming calls, dialer), hardware (camera, screenshots), and system controls (factory reset, ADB, side-loading, Play Store, app uninstall, date/time configuration) — that gets applied to a device after it has already been provisioned through a Template. They're commonly used to make a post-provisioning change to a Kiosk-mode device, such as temporarily re-enabling the status bar or ADB to pull a bug report, without re-provisioning the device. Templates and Compliance Policies are legacy Esper products; Blueprints are the current, recommended way to define device configuration for new work.
Key Fields / Query Parameters
name— Required — name of the Policydescription— Free-text description of the policy's purposepolicy— The underlying Policy Data object — the actual restriction/permission toggles (e.g., cameraDisabled, adbDisabled, phonePolicy) applied to the deviceis_active— Whether the policy should be active immediately
Common Use Cases
- Temporarily re-enabling a restricted feature (e.g., status bar or ADB) on a Kiosk-mode device to pull a bug report
- Defining a restriction profile for a class of legacy Template-provisioned devices
- Making a post-provisioning configuration change without re-running the device through its Template
Best Practices
- Use Blueprints instead of creating a new Compliance Policy for any device not already on the legacy Template system
- Give the policy a clear, descriptive name so it's identifiable later among other Compliance Policies
- Test a new policy on a small device group before rolling it out broadly, since restriction changes can affect Kiosk-mode usability
Workflow
- Confirm the target devices are still on the legacy Template/Compliance Policy system (not yet migrated to Blueprints)
- Design the restriction/permission configuration to apply
- POST it to this endpoint with a name and description, then apply the resulting policy uuid to the relevant devices or groups
The request body to create an Enteprise Policy
- Mock serverhttps://develop-api.esper.io/_mock/openapi/enterprise/{enterprise_id}/policy/
- https://develop-api.esper.cloud/apihttps://develop-api.esper.cloud/api/enterprise/{enterprise_id}/policy/
curl -i -X POST \
'https://develop-api.esper.io/_mock/openapi/enterprise/{enterprise_id}/policy/' \
-H 'Authorization: Bearer <YOUR_TOKEN_HERE>' \
-H 'Content-Type: */*' \
-d '{
"enterprise": "string",
"name": "string",
"description": "string",
"policy": {
"keyguardDisabled": true,
"safeBootDisabled": true,
"statusBarDisabled": true,
"factoryResetDisabled": true,
"screenshotDisabled": true,
"usbConnectivityDisabled": true,
"smsDisabled": true,
"outgoingCallsDisabled": true,
"cameraDisabled": true,
"nfcBeamDisabled": true,
"disablePlayStore": true,
"usbFileTransferDisabled": true,
"tetheringDisabled": true,
"dateTimeConfigDisabled": true,
"appUninstallDisabled": true,
"googleAssistantDisabled": true,
"disableLocalAppInstall": true,
"adbDisabled": true,
"phonePolicy": {
"incomingNumbers": [
"string"
],
"outgoingNumbers": [
"string"
],
"dialer": "DEFAULT",
"allowUssdCodes": false
},
"frpGoogles": [
{
"type": "USER",
"email": "user@example.com",
"googleId": "string"
}
],
"googleAccountPermission": {
"maxAccount": 0,
"emails": [
"user@example.com"
],
"domains": [
"string"
]
},
"devicePasswordPolicy": {
"passwordQuality": "PASSWORD_QUALITY_ALPHABETIC"
},
"minimumPasswordLength": 4,
"permissionPolicy": "PERMISSION_POLICY_PROMPT",
"deviceUpdatePolicy": {
"type": "TYPE_INSTALL_AUTOMATIC",
"maintenanceStart": 0,
"maintenanceEnd": 0
},
"settingsAccessLevel": "SYSTEM",
"settingsAppPassword": "pa$$word"
},
"is_active": true
}'command request successfully created
Count of Devices with this policy applied
{ "uuid": "095be615-a8ad-4c33-8e9c-c7612fbf6c9f", "enterprise": "string", "url": "string", "name": "string", "description": "string", "device_count": 0, "google_policy_id": "string", "policy": { "keyguardDisabled": true, "safeBootDisabled": true, "statusBarDisabled": true, "factoryResetDisabled": true, "screenshotDisabled": true, "usbConnectivityDisabled": true, "smsDisabled": true, "outgoingCallsDisabled": true, "cameraDisabled": true, "nfcBeamDisabled": true, "disablePlayStore": true, "usbFileTransferDisabled": true, "tetheringDisabled": true, "dateTimeConfigDisabled": true, "appUninstallDisabled": true, "googleAssistantDisabled": true, "disableLocalAppInstall": true, "adbDisabled": true, "phonePolicy": { … }, "frpGoogles": [ … ], "googleAccountPermission": { … }, "devicePasswordPolicy": { … }, "minimumPasswordLength": 4, "permissionPolicy": "PERMISSION_POLICY_PROMPT", "deviceUpdatePolicy": { … }, "settingsAccessLevel": "SYSTEM", "settingsAppPassword": "pa$$word" }, "updated_on": "2019-08-24T14:15:22Z", "created_on": "2019-08-24T14:15:22Z", "is_active": true }