To configure rules for assigning protection levels in Kaspersky Security Center:
In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Policies & profiles. In the list of group policies that opens, click the name of the policy that you want to configure.
In the policy properties window, select Application settings.
Select Android and go to the KES for Android settings section.
On the Severity settings for device protection level card, click Settings.
The Severity settings for device protection level window opens.
Enable the settings using the Severity settings for device protection level toggle switch.
Select the OK, Warning, or Critical protection level for each of the following conditions:
Drop-down list where you can select the protection level of a mobile device on which real-time protection is not running.
Real-time protection lets you detect threats in files being opened, as well as scan new apps and stop device infections in real time.
Real-time protection may fail to run for the following reasons:
The user declined to use Kaspersky Security Network on the mobile device in the Anti-Malware settings of Kaspersky Endpoint Security for Android.
The user did not grant the app access to manage all files.
If real-time protection is not running, you can also configure restrictions on operation of the mobile device in the Compliance Control settings of the policy.
The Web Protection Statement has not been accepted.
If Web Protection and Web Control are not running, you can also configure restrictions on the operation of the mobile device in the Compliance Control settings of the policy.
Drop-down list where you can select the protection level of a mobile device on which App Control is not running.
App Control lets you block apps from running on mobile devices if those apps do not meet the corporate security requirements.
App Control may not run if the user did not enable the app as an Accessibility feature on devices running Android 5 or later.
If App Control is not running, you can also configure restrictions on the operation of the mobile device in the Compliance Control settings of the policy.
Drop-down list where you can select the protection level of a mobile device if the version of the Kaspersky Security Network Statement accepted by the administrator does not match the version accepted by the device user. Statistics not listed in the version of the Statement accepted by the user are not sent to Kaspersky Security Network.
Drop-down list where you can select the protection level of a mobile device if the version of the Statement regarding data processing for marketing purposes accepted by the administrator does not match the version accepted by the device user. Data is not transferred to third-party services.
The list of third-party services can be found in the Statement regarding data processing for marketing purposes.
Click OK.
Click Save to save the changes you have made.
Mobile device settings are changed after the next device synchronization with Kaspersky Security Center.
For more information about default values, reasons, and conditions for assigning protection levels, please refer to the Mobile device protection levels section.