# User management

##### Add user disabled

Whether adding new users and profiles is disabled. For devices where managementMode is **DEVICE\_OWNER** this field is ignored and the user is never allowed to add or remove users.

##### Modify accounts disabled

Whether adding or removing accounts is disabled.

##### User credentials config disabled

Whether configuring user credentials is disabled.

##### Remove user disabled

Whether removing other users is disabled.

##### Set user icon disabled

Whether changing the user icon is disabled.

##### Set wallpaper disabled

Whether changing the wallpaper is disabled.

##### Work account setup authentication

Controls how users authenticate during work account setup. This option is available only for Android enterprises backed by a managed Google domain (Google Workspace).

During device setup/enrollment, this policy influences whether a work account sign-in is required, but the Google Admin Console setting **Authenticate Using Google** and the enrollment token type can still require authentication.

For already enrolled devices, this policy only applies if the device is managed by a managed Google Play account (i.e., enrolled without **Authenticate Using Google Enrollment**).

For more details and troubleshooting, refer to [**Authenticate Using Google enrollment**](https://enterprise.cerberusapp.com/docs/books/user-manual/page/authenticate-using-google-enrollment "Authenticate Using Google enrollment").

##### Blocked account types

Account types that can't be managed by the user. This option prevents device users from adding unapproved accounts.

Use **Add blocked account type** to add one or more account types.

Each entry has an **Account type** field (required). Enter a string such as **com.google**. Remove an entry using the delete action.