Academy
Technical · Course T5

Lesson 3 of 5

Inside the section catalog

8 min read
In this lesson you'll learn to
  • Group the Android, Apple, and Windows section catalogs into a mental map
  • Name the platform-exclusive capabilities that differentiate WeGuard demos
  • Run the platform-type-plan triage for any missing section or tab

Open the Policy Settings tab and the sidebar lists everything a policy can control. The catalog differs per platform — and knowing its shape is what separates an admin who searches from an admin who navigates.

Android: nineteen sections, five jobs

Think of Android's sections in functional groups rather than alphabetically:

  • Device basicsGeneral (Wi-Fi, Bluetooth, camera, kiosk toggle, always-on display), Password, Security (app install rules, factory reset protection, USB, developer options), Advanced.
  • Threat protectionMalware Protection (Work Managed and Kiosk only) and Storage Encryption (screen capture, live view, external media).
  • Connectivity and costNetworking (Wi-Fi profiles, VPN enforcement) and Data Usage (thresholds and alerts).
  • Location-awareLocation Tracking, Geofence, Safe Drive (Kiosk only), Time Fencing.
  • ExperienceApp Management (private APKs, Play Store, system apps), Branding, Bookmarks, Admin Lock, Single App Kiosk and Layouts (Kiosk only), and QR Code (what gets baked into enrollment codes).

Apple: payloads plus a supervision-gated restriction wall

iOS/iPadOS policies organize into configuration payloads — Wi-Fi, VPN, SCEP and certificates, web clips, calendars, contacts, Google accounts, AirPrint, AirPlay, Global HTTP Proxy, DNS Proxy — plus the big Restrictions section, Passcode, Safari and Content Filter, Lock Screen, Wallpaper, Layouts, and Kiosk (Single App Mode). Section visibility follows the device class: a MacBook policy, an Apple TV policy (with Conference Room Display and TV Remote), and a Shared iPad policy each show their own relevant subset, and many restrictions light up only under supervision.

Windows: the enterprise extras

Beyond the shared basics (General, App Management, Password, Security, Storage Encryption, Networking, Geofence, Track, Branding), Windows brings four differentiators worth demoing:

  • Secure Browser — Chrome and Edge URL filtering, cookie and extension policy.
  • BitLocker — drive encryption enforcement with recovery keys.
  • Screen Time — login/logout history and usage per device.
  • WeShield — a whole endpoint-protection tab: antimalware, network protection, and device control for USB and peripherals.

And the escape hatch: the Advanced Settings tab accepts custom OMA-URI / CSP entries for anything Windows supports that WeGuard hasn't surfaced as a field, with CSP History showing every command's per-device delivery status. That extensibility answers the "but does it support X?" question with "yes, today."

The missing-section triage

When a section or tab someone expects isn't visible, check three things in order:

  1. Platform — does the capability exist here at all? Geofencing is Android and Windows only. Broadcast is Android only. WeShield is Windows only.
  2. Policy type — Kiosk-only sections (Safe Drive, Single App Kiosk, Layouts) vanish on other types; device-level restrictions hide on Work Profile because a container can't enforce them; iOS sections follow the device class.
  3. Plan — tabs like Broadcast, Alerts, Certificates, Contacts and features like transfers are gated by the customer's plan. If platform and type check out, the answer lives in the plan configuration — which makes this a commercial conversation, not a support ticket.

Run the triage in that order and "where did my section go?" becomes a thirty-second answer.

Knowledge check
1. An admin asks why the Geofence section is missing from their iOS policy. What's the answer?
2. Where do you configure a Windows setting WeGuard has no built-in field for?
3. A section is missing from a policy editor. What's the triage order?