π New Android Policy Configuration: Private DNS Configuration
Shared by Karla
β’ March 02, 2026
Weβre excited to announce that you can now manage Private DNS settings on fully managed Android devices (Android 10 and above) through AMAPI. This feature allows you to control how devices connect to DNS servers securely and enforce network policies across your fleet.
Key Details
π Private DNS Mode Options:
-
USER_CHOICE: The user can configure private DNS.
-
AUTOMATIC: The device automatically uses the network-provided DNS over an encrypted connection. Users cannot modify this setting. Supported on fully managed devices and work profiles on company-owned devices.
-
SPECIFIED_HOST: The device uses only the DNS server specified in Private Dns Host. Users cannot change this setting. If you select this mode, Private Dns Host must be set.
π οΈ Private DNS Host:
- Optional field required only when Private DNS Mode is set to SPECIFIED_HOST.
- The hostname must correspond to a supported DNS server. Non-compliance is reported if the host is invalid, the device is not on a network, or other restrictions apply (e.g., unsupported Android version or management mode).
β οΈ Non-Compliance Details:
- Devices not meeting the requirements will report a NonComplianceDetail, specifying the reason (e.g., invalid host, unsupported management mode, Android version <10, or pending network connection).
This new setting helps you enforce secure network connections, control DNS usage, and maintain compliance across your Android fleet.