Technical · Course T5Lesson 3 of 5
Inside the section catalog
8 min read- Group the Android, Apple, and Windows section catalogs into a mental map
- Name the platform-exclusive capabilities that differentiate WeGuard demos
- Run the platform-type-plan triage for any missing section or tab
Open the Policy Settings tab and the sidebar lists everything a policy can control. The catalog differs per platform — and knowing its shape is what separates an admin who searches from an admin who navigates.
Android: nineteen sections, five jobs
Think of Android's sections in functional groups rather than alphabetically:
- Device basics — General (Wi-Fi, Bluetooth, camera, kiosk toggle, always-on display), Password, Security (app install rules, factory reset protection, USB, developer options), Advanced.
- Threat protection — Malware Protection (Work Managed and Kiosk only) and Storage Encryption (screen capture, live view, external media).
- Connectivity and cost — Networking (Wi-Fi profiles, VPN enforcement) and Data Usage (thresholds and alerts).
- Location-aware — Location Tracking, Geofence, Safe Drive (Kiosk only), Time Fencing.
- Experience — App Management (private APKs, Play Store, system apps), Branding, Bookmarks, Admin Lock, Single App Kiosk and Layouts (Kiosk only), and QR Code (what gets baked into enrollment codes).
Apple: payloads plus a supervision-gated restriction wall
iOS/iPadOS policies organize into configuration payloads — Wi-Fi, VPN, SCEP and certificates, web clips, calendars, contacts, Google accounts, AirPrint, AirPlay, Global HTTP Proxy, DNS Proxy — plus the big Restrictions section, Passcode, Safari and Content Filter, Lock Screen, Wallpaper, Layouts, and Kiosk (Single App Mode). Section visibility follows the device class: a MacBook policy, an Apple TV policy (with Conference Room Display and TV Remote), and a Shared iPad policy each show their own relevant subset, and many restrictions light up only under supervision.
Windows: the enterprise extras
Beyond the shared basics (General, App Management, Password, Security, Storage Encryption, Networking, Geofence, Track, Branding), Windows brings four differentiators worth demoing:
- Secure Browser — Chrome and Edge URL filtering, cookie and extension policy.
- BitLocker — drive encryption enforcement with recovery keys.
- Screen Time — login/logout history and usage per device.
- WeShield — a whole endpoint-protection tab: antimalware, network protection, and device control for USB and peripherals.
And the escape hatch: the Advanced Settings tab accepts custom OMA-URI / CSP entries for anything Windows supports that WeGuard hasn't surfaced as a field, with CSP History showing every command's per-device delivery status. That extensibility answers the "but does it support X?" question with "yes, today."
The missing-section triage
When a section or tab someone expects isn't visible, check three things in order:
- Platform — does the capability exist here at all? Geofencing is Android and Windows only. Broadcast is Android only. WeShield is Windows only.
- Policy type — Kiosk-only sections (Safe Drive, Single App Kiosk, Layouts) vanish on other types; device-level restrictions hide on Work Profile because a container can't enforce them; iOS sections follow the device class.
- Plan — tabs like Broadcast, Alerts, Certificates, Contacts and features like transfers are gated by the customer's plan. If platform and type check out, the answer lives in the plan configuration — which makes this a commercial conversation, not a support ticket.
Run the triage in that order and "where did my section go?" becomes a thirty-second answer.