Skip to content

Create a new Enterprise Policy
Stable

Request

⚠️ Legacy feature. Compliance Policies (along with Templates, which apply them) are a legacy Esper product. For new device configuration work, use Blueprints instead — Compliance Policies remain available for existing Template-based deployments. See Introduction to Compliance Policies: https://help.esper.io/hc/en-us/articles/12653153592977-Introduction-to-Compliance-Policies

Creates a new Compliance Policy for the enterprise.

Creates a Compliance Policy record defining a set of device restrictions/permissions that can subsequently be applied to Template-provisioned devices.

About Compliance Policies A Compliance Policy is a set of device-configuration permissions and restrictions — screen and unlock behavior (keyguard, safe boot), connectivity (USB, tethering, NFC), communication (SMS, outgoing/incoming calls, dialer), hardware (camera, screenshots), and system controls (factory reset, ADB, side-loading, Play Store, app uninstall, date/time configuration) — that gets applied to a device after it has already been provisioned through a Template. They're commonly used to make a post-provisioning change to a Kiosk-mode device, such as temporarily re-enabling the status bar or ADB to pull a bug report, without re-provisioning the device. Templates and Compliance Policies are legacy Esper products; Blueprints are the current, recommended way to define device configuration for new work.

Key Fields / Query Parameters

  • name — Required — name of the Policy
  • description — Free-text description of the policy's purpose
  • policy — The underlying Policy Data object — the actual restriction/permission toggles (e.g., cameraDisabled, adbDisabled, phonePolicy) applied to the device
  • is_active — Whether the policy should be active immediately

Common Use Cases

  • Temporarily re-enabling a restricted feature (e.g., status bar or ADB) on a Kiosk-mode device to pull a bug report
  • Defining a restriction profile for a class of legacy Template-provisioned devices
  • Making a post-provisioning configuration change without re-running the device through its Template

Best Practices

  • Use Blueprints instead of creating a new Compliance Policy for any device not already on the legacy Template system
  • Give the policy a clear, descriptive name so it's identifiable later among other Compliance Policies
  • Test a new policy on a small device group before rolling it out broadly, since restriction changes can affect Kiosk-mode usability

Workflow

  1. Confirm the target devices are still on the legacy Template/Compliance Policy system (not yet migrated to Blueprints)
  2. Design the restriction/permission configuration to apply
  3. POST it to this endpoint with a name and description, then apply the resulting policy uuid to the relevant devices or groups
Security
esper_cloud_api_apiKey
Path
enterprise_idstring, (uuid)required

ID of the enterprise

Body*/*required

The request body to create an Enteprise Policy

enterprisestring, (url)(Enterprise url)required

Url of the enterprise resource

namestring(Policy Name)required

Name of the Policy

descriptionstring(Policy Description)

Details regarding the Policy

policyobject(Policy Data)required
is_activeboolean(Policy Active status)

Is this policy currently active

cURL
curl -i -X POST \
  'https://develop-api.esper.io/_mock/openapi/enterprise/{enterprise_id}/policy/' \
  -H 'Authorization: Bearer <YOUR_TOKEN_HERE>' \
  -H 'Content-Type: */*' \
  -d '{
    "enterprise": "string",
    "name": "string",
    "description": "string",
    "policy": {
      "keyguardDisabled": true,
      "safeBootDisabled": true,
      "statusBarDisabled": true,
      "factoryResetDisabled": true,
      "screenshotDisabled": true,
      "usbConnectivityDisabled": true,
      "smsDisabled": true,
      "outgoingCallsDisabled": true,
      "cameraDisabled": true,
      "nfcBeamDisabled": true,
      "disablePlayStore": true,
      "usbFileTransferDisabled": true,
      "tetheringDisabled": true,
      "dateTimeConfigDisabled": true,
      "appUninstallDisabled": true,
      "googleAssistantDisabled": true,
      "disableLocalAppInstall": true,
      "adbDisabled": true,
      "phonePolicy": {
        "incomingNumbers": [
          "string"
        ],
        "outgoingNumbers": [
          "string"
        ],
        "dialer": "DEFAULT",
        "allowUssdCodes": false
      },
      "frpGoogles": [
        {
          "type": "USER",
          "email": "user@example.com",
          "googleId": "string"
        }
      ],
      "googleAccountPermission": {
        "maxAccount": 0,
        "emails": [
          "user@example.com"
        ],
        "domains": [
          "string"
        ]
      },
      "devicePasswordPolicy": {
        "passwordQuality": "PASSWORD_QUALITY_ALPHABETIC"
      },
      "minimumPasswordLength": 4,
      "permissionPolicy": "PERMISSION_POLICY_PROMPT",
      "deviceUpdatePolicy": {
        "type": "TYPE_INSTALL_AUTOMATIC",
        "maintenanceStart": 0,
        "maintenanceEnd": 0
      },
      "settingsAccessLevel": "SYSTEM",
      "settingsAppPassword": "pa$$word"
    },
    "is_active": true
  }'

Responses

command request successfully created

Bodyapplication/json
uuidstring, (uuid)(UUID)read-only

Unique Policy identifier

enterprisestring, (url)(Enterprise url)required

Url of the enterprise resource

urlstring, (url)(Policy URL)read-only

URL link to policy

namestring(Policy Name)required

Name of the Policy

descriptionstring(Policy Description)

Details regarding the Policy

device_countinteger(Number of Devices with this policy applied)read-only

Count of Devices with this policy applied

google_policy_idstring(Google policy id)read-only

Id of the Google policy

policyobject(Policy Data)required
updated_onstring, (date-time)(Updated On)read-only

Last-Updated Timestamp of Policy

created_onstring, (date-time)(Created on)read-only

Creation Timestamp of Policy

is_activeboolean(Policy Active status)

Is this policy currently active

Response
{ "uuid": "095be615-a8ad-4c33-8e9c-c7612fbf6c9f", "enterprise": "string", "url": "string", "name": "string", "description": "string", "device_count": 0, "google_policy_id": "string", "policy": { "keyguardDisabled": true, "safeBootDisabled": true, "statusBarDisabled": true, "factoryResetDisabled": true, "screenshotDisabled": true, "usbConnectivityDisabled": true, "smsDisabled": true, "outgoingCallsDisabled": true, "cameraDisabled": true, "nfcBeamDisabled": true, "disablePlayStore": true, "usbFileTransferDisabled": true, "tetheringDisabled": true, "dateTimeConfigDisabled": true, "appUninstallDisabled": true, "googleAssistantDisabled": true, "disableLocalAppInstall": true, "adbDisabled": true, "phonePolicy": { … }, "frpGoogles": [ … ], "googleAccountPermission": { … }, "devicePasswordPolicy": { … }, "minimumPasswordLength": 4, "permissionPolicy": "PERMISSION_POLICY_PROMPT", "deviceUpdatePolicy": { … }, "settingsAccessLevel": "SYSTEM", "settingsAppPassword": "pa$$word" }, "updated_on": "2019-08-24T14:15:22Z", "created_on": "2019-08-24T14:15:22Z", "is_active": true }