The mobile operating system Android is famous for its openness, allowing users to install software not only from the official store, but also by downloading files directly from the Internet. However, this freedom is a double-edged sword: it is through third-party APK files attackers that most often distribute malware, spyware and Trojans. A user, by accidentally clicking on a bright advertising link, can unnoticed turn his smartphone into a tool for mining or stealing personal data.

To avoid such threats, it is critically important to understand how the mechanism works application installations and what settings are responsible for filtering incoming traffic. Modern versions of Android, starting with 8.0 Oreo, have radically changed the approach to security, abandoning the global switch in favor of individual permission management for each browser or file manager. This has made the task more difficult for hackers, but also requires the owner of the gadget to be more attentive to privacy settings.

In this article we will analyze in detail the algorithms of actions that allow us to completely block the path for unauthorized software. We won't just go through the settings menu, but we'll also explain why standard measures may not be enough in certain scenarios for using the device. You will learn how to use built-in tools Google Play Protect, how to revoke rights from specific apps, and what hidden developer features can help strengthen protection.

The evolution of security in Android versions

In earlier versions of the operating system, for example, Android 5.0 Lollipop or 6.0 Marshmallow, there was a single global switch “Unknown sources”. The user only had to uncheck one box in the general settings, and the system automatically blocked the installation of any packages that were not digitally signed by the store Google Play. This was convenient, but less flexible, since it prohibited the installation of legal software even for those users who deliberately wanted to download the application from a trusted third-party repository.

Starting from Android 8.0, the security architecture has undergone significant changes. Now permission to install is given not to the system as a whole, but to a specific source application. This means that you can allow installation to the browser Chrome, but at the same time strictly prohibit it to the messenger Telegram or file manager. This approach significantly increases the level of protection, since even if malicious code gets into the system, it will not be able to arbitrarily initiate the installation of additional modules without explicit user confirmation for each specific case.

In recent versions, such as Android 13 and Android 14, Google has introduced additional levels of verification. Now, when you try to install an application from outside, the system not only asks for permission, but also automatically checks against threat databases. If a file is marked as dangerous, the installation is blocked at the kernel level, regardless of user settings. However, you should not rely only on automation, since new viruses appear faster than the signature databases are updated.

⚠️ Attention: The settings interface may differ slightly depending on the manufacturer’s shell (MIUI, One UI, ColorOS). If you do not find the item in the specified location, use the search in the settings by entering the request “special access” or “installing applications.”
Why did Google change the security policy?

The decision to switch to piece-by-piece permission was made after analyzing infection statistics. It turned out that 70% of malware entered the system through vulnerabilities in popular instant messengers and social network clients that had global permission to install. Limiting the rights for each application separately reduced this figure by almost three times.

Basic setting of blocking installation through the settings menu

The first and most obvious step is to check the current permissions for the applications that are most often used to download files. You need to go to the Settingssection, then select Applications or Applications and notifications. In some firmware, this item may be hidden inside the menu Security and privacy. Here we are not interested in the list of all apps, but in a special subsection responsible for extended rights.

Find the item called “Special access" or "Advanced settings". Inside this menu you should find the line “Install unknown applications”. By clicking on it, you will see a list of all apps that can theoretically initiate the installation of APK files. Your task is to go through this list and make sure that the switch opposite each item is in position Disabled. Pay special attention to browsers, email clients and instant messengers.

If you find that an application has an active permission, simply click on it and deactivate the option. The system may issue a warning that the device will become vulnerable, but in the context of our blocking task, this is exactly what is required. After completing these steps, no app will be able to silently install third-party software without your knowledge and additional confirmation through the system window.

  • 📱 Check browser permissions Chrome - this is the most common attack vector.
  • 📂 Don't forget about file managers, such as Files by Google or ES Explorer.
  • 💬 Messengers (WhatsApp, Viber) are often used to transmit infected installers.

☑️ Audit permissions

Done: 0 / 4

Using Google Play Protect for active protection

In addition to manual permission management, every certified Android device comes with a built-in powerful security scanner called Google Play Protect. This service runs in the background and scans all installed applications and also verifies files before installing them, even if they are downloaded externally. Activating and properly configuring this tool creates an additional layer of defense that is difficult for conventional malware to bypass.

To manage the service, open the application Google Play Market, click on your profile icon in the upper right corner and select Play Protect. In the menu that opens, make sure that the “Scan devices for security threats” switch is active. It is also recommended to enable the "Improve malware detection" option, which allows you to send data about suspicious applications to Google for analysis. This helps the system respond faster to new types of threats.

It is important to understand that Play Protect can block the installation of even those applications that are not viruses, but do not have a digital signature of the developer in the Google database. This often happens with modified versions of popular apps or software from independent developers. In such cases, the system will issue a red warning. If you are absolutely sure that the file is safe, you can continue with the installation by clicking "Install Anyway", but for the average user it is better to stick to the rule: a red warning means stop.

Verification status Value Recommended action
Green checkmark No threats detected You can continue installation
Yellow triangle The application has not been verified Install only from a trusted source
Red screen Dangerous app detected Cancel installation immediately
Gray icon Service disabled Enable Play Protect in settings
⚠️ Attention: If Google Play Protect constantly blocks the legal application you need (for example, a banking client from another region), do not disable the protection completely. It’s better to add the file to exceptions through the scanner menu to maintain the overall level of system security.
💡

Periodically run a manual scan through Play Protect, especially after visiting dubious sites or connecting to public Wi-Fi networks. It takes less than a minute, but can save your data.

Managing accessibility and administrator rights

Advanced malware often bypasses standard restrictions by using rights accessibility (Accessibility Services) or obtaining status device administrator. Having received such privileges, the virus can automatically click the “Allow” buttons in the installation windows, imitating user actions, or prohibit the removal of itself. Therefore, it is critical to control these settings.

Go to the Accessibility section in the main phone settings. Carefully review the list of loaded services. If you see an application there that you did not knowingly install, or a app with a suspicious name (for example, “Battery Saver” from an unknown developer), disable it immediately. Legitimate apps, such as password managers or screen readers for the visually impaired, should be familiar to you.

Also check the SecurityDevice administrator applicationssection. Typically, only system services (“Find Device”, “Google Play Services”) and corporate profiles are located here if the phone is used for work. The presence of a third-party application on this list is a red flag. It can block factory resets or installation of security updates, keeping the device in a vulnerable state.

Some users are faced with a situation where an attacker has already obtained administrator rights and is preventing them from being revoked. In this case, you may need to log in safe mode. To do this, you usually need to hold down the power button on the screen, and then hold down the “Power off” option for a long time until a request to restart in safe mode appears. In this mode, third-party administrators are not activated, allowing you to safely remove malware.

💡

Accessibility rights give applications full control over the screen and taps. Never give them to apps whose functionality does not require you to manage the interface for you.

Blocking through limited profile mode and guest mode

If your device is used by children or other family members who do not have sufficient technical literacy, the best solution would be to create a separate profile with limited rights. In Guest or Restricted profile default mode, installation of any applications without entering the PIN code or fingerprint of the owner of the main account is prohibited.

To activate this function, omit notification shade twice, click on the user icon in the corner and select “Add guest” or “Add profile”. In the settings of the created profile, you can strictly limit the ability to change system parameters. When a child or guest tries to download a game from a browser or install an APK file, the system will require authorization from the main user. This physically prevents inexperienced hands from accidentally installing viruses.

This method is especially effective for tablets, which are often used as family entertainment centers. You can configure your profile so that only pre-approved whitelisted apps are available. Any attempts to go beyond this list or download new content will be blocked at the system level, regardless of the “unknown sources” settings in the main profile.

  • 👤 Use Guest mode to temporarily transfer the phone to friends.
  • 🔒 Set up a Restricted profile for children with a strict content filter.
  • 👮 Main the account must be protected with a reliable biometric key.
📊 Who most often uses your smartphone besides you?
Children
Spouse
Colleagues
No one, only i

Additional measures: blocking via ADB and third-party launchers

For those who want to achieve the maximum level of control, there is the possibility of using USB debugging (ADB). This method allows you to disable the Android batch installer at the system level without rooting. By executing a command through a computer, you can make it so that when you try to install an APK file, the system will simply ignore the action or display an error, even if the settings have permission.

To do this, you need to connect the phone to the PC, enable USB debugging and enter the following command in the terminal:

adb shell pm disable-user --user 0 com.android.packageinstaller

This command deactivates the standard package installer. To restore the ability to install legal applications in the future, you will need to enter a command with the parameter enable instead of disable-user. This method is suitable for corporate devices or phones that are used as kiosks or terminals, where the installation of third-party software is strictly prohibited.

You can also use third-party launchers with parental controls or settings blocking functions. Some shells allow you to hide the “Settings” item itself or protect its entry with a password. If the user cannot get to the permissions menu, he will not be able to enable installation from unknown sources, even if he wants to. This creates a convenient barrier to accidental changes to the security configuration.

⚠️ Warning: Disabling system components via ADB requires caution. Incorrectly disabling critical services can lead to system instability or the inability to update legitimate applications through the store.
How to return the package installer if the install button does not work?

If you disabled the installer via ADB and forgot the enable command, try going to Settings → Applications → Show system processes. Find Package Installer and click Enable. If the item is inactive, you will need to reconnect to the PC.

Frequently asked questions (FAQ)

Is it possible to completely remove the ability to install APK files forever?

It is impossible to completely remove this ability without flashing the device, since this is a system function of Android. However, you can make the process as difficult as possible by revoking all permissions from applications, enabling strict Play Protect mode, and blocking access to settings via a password. The combination of these measures makes installing third-party software almost impossible for the average user.

Why does the phone itself offer to install the application after visiting the site?

This is a sign of aggressive advertising or the presence of a malicious script on the page. The browser cannot install the application itself; it only downloads the file and offers to open it. If you see a pop-up prompting you to install, simply close the browser tab and delete the downloaded file from your Downloads folder without clicking the Install button.

Is it safe to enable "Unknown Sources" for one specific application?

It is relatively safe as long as you trust that application and the source from which it downloads files. For example, you can temporarily allow installation for a file manager to install an APK from a flash drive, and then immediately disable the permission. The main rule is not to keep the permission always active for browsers or instant messengers.

What to do if, after installing the application, the phone starts to slow down?

Immediately remove the last installed application. Go to your battery settings and see which app is consuming the most resources in the background. If you can’t delete it (the button is inactive), it probably has received administrator rights - revoke them in the security section and try deleting again. In extreme cases, resetting to factory settings will help.