Overview
The Android Cross Profile Policy controls how apps, data, contacts, clipboard content, and widgets interact between a device’s managed work profile and personal profile.
Organizations can use this policy to reduce the risk of work data entering personal apps while allowing approved cross-profile workflows.
Requirements
Android Enterprise enrollment with a work profile
Android 9 or later
A Swif policy assigned to the applicable work-profile devices
Some settings require newer Android versions:
Setting | Minimum version |
Cross Profile Copy Paste | Android 9 |
Cross Profile Data Sharing | Android 9 |
Cross Profile App Functions | Android 11 |
Work Profile Widgets Default | Android 12 |
Contact application exemptions | Android 14 |
Settings that are unsupported by a device’s Android version may not be applied and may generate a policy noncompliance status.
Available settings
Cross Profile App Functions
Controls whether apps in the personal profile can invoke supported functions exposed by apps in the work profile.
Unspecified: Follows the device’s broader App Functions policy.
Disallowed: Personal apps cannot invoke app functions exposed by work apps.
Allowed: Personal apps can invoke app functions exposed by work apps.
If this setting is allowed while the broader App Functions policy is disallowed, Android may reject the conflicting policy.
Cross Profile Copy Paste
Controls whether users can copy text between their work and personal profiles.
Unspecified: Uses the Android default, which prevents copying from work apps into personal apps.
Copy from work to personal disallowed: Work content cannot be pasted into personal apps. Users can still copy personal content into work apps.
Allowed: Text can be copied and pasted in both directions.
For most organizations, blocking copy and paste from work to personal provides a useful balance between data protection and productivity.
Cross Profile Data Sharing
Controls data sharing through Android actions such as opening a document, sharing an image, opening a link in a browser, or opening a location in a map application.
Unspecified: Uses the Android default, which blocks sharing from work apps to personal apps while allowing personal data to be shared with work apps.
Disallowed: Blocks data sharing in both directions.
Sharing from work to personal disallowed: Blocks work data from being shared with personal apps while allowing personal data to be shared with work apps.
Allowed: Permits data sharing in both directions.
This setting does not control clipboard content, contact access, or cross-profile app functions. Configure those controls separately.
Show Work Contacts in Personal Profile
Controls whether personal applications can search, display, or use contacts stored in the work profile, including for contact searches and incoming-call identification.
Unspecified: Uses the Android default, which allows personal apps to access work contacts.
Disallowed: Prevents personal apps from accessing work contacts.
Allowed: Allows personal apps to access work contacts.
Disallowed except system apps: Allows access only for the device manufacturer’s default Phone, Messages, and Contacts apps. This option requires Android 14 or later.
Allowing a personal app to access a work contact does not guarantee that the contact will remain within that app. The application may be able to transfer or share the information elsewhere.
Work-contact application exemptions
On Android 14 and later, administrators can enter personal-app package names that are exempt from the selected work-contact setting.
The exemption list behaves differently depending on the main contact setting:
When work contacts are allowed, the exemption list acts as a blocklist. Listed apps cannot access work contacts.
When work contacts are disallowed, the list acts as an allowlist. Only listed personal apps can access work contacts.
When work contacts are disallowed except system apps, listed apps are allowed in addition to the approved default system apps.
Enter each application’s Android package name, such as:
com.google.android.contactscom.whatsapp
Do not configure exemptions when Show Work Contacts in Personal Profile is left unspecified.
Work Profile Widgets Default
Controls whether users can place widgets from work-profile applications on the device’s home screen.
Unspecified: Uses the Android default, which disallows work-profile widgets.
Allowed: Work apps can provide home-screen widgets unless an application-specific policy blocks them.
Disallowed: Work-profile widgets are blocked unless an application-specific policy explicitly allows them.
Application-specific widget settings take precedence over this default setting.
Configure the policy in Swif
Open Policy Management in the Swif console.
Create a policy or edit an existing Android policy.
Locate Android Cross Profile Policy.
Configure the required cross-profile settings.
If using work-contact exemptions, enter the applicable Android package names.
Save the policy and assign it to the appropriate work-profile devices or device groups.
Allow the devices to check in and receive the updated policy.
Test the resulting behavior on a representative device before deploying the policy broadly.
Recommended security baseline
Organizations that prioritize work-data protection can start with the following configuration:
Block copying from the work profile to the personal profile.
Block sharing data from work apps to personal apps.
Disallow personal-app access to work contacts, with approved exceptions when required.
Disallow work-profile widgets unless there is a specific business need.
Disallow cross-profile app functions unless an approved application workflow depends on them.
Adjust these recommendations to account for employee workflows, organizational risk, and compliance requirements.
Troubleshooting
The policy is not applied
Confirm that:
The device has an active Android Enterprise work profile.
The device is running a supported Android version.
The correct Swif policy is assigned to the device.
The device has checked in since the policy was updated.
A contact exemption is not working
Contact exemptions require Android 14 or later. Verify that the package name is correct and that Show Work Contacts in Personal Profile is explicitly set to Allowed, Disallowed, or Disallowed except system apps.
A work widget is still allowed or blocked unexpectedly
Check whether an application-specific widget policy is configured. Application-specific settings take precedence over the Work Profile Widgets Default setting.
Data sharing is blocked, but copying still works
Cross-profile data sharing and copy-and-paste are separate controls. Configure both settings to achieve the intended restriction.