Modern Android does not normally use one master “Unknown sources” switch. Permission is granted to the specific app that starts the installation—such as Chrome, Samsung Internet, Files, My Files, WhatsApp or Telegram.
Fastest Method: Search Android Settings
- Open Settings.
- Tap the search field and enter Install unknown apps.
- Open the matching result.
- Tap the source app you used—for example Chrome, Files, My Files or a messaging app.
- Turn off Allow from this source.
- Return to the list and check whether any other app still shows “Allowed.” Revoke anything that does not need installation access.
This method is more reliable than memorising one path because manufacturers reorganise Settings between Android versions.
Generic Android Path
On many Android phones, the route is:
Settings → Apps → Special app access → Install unknown apps → select the source app → turn off Allow from this source.
If “Special app access” is not visible, open the three-dot menu in the Apps screen or use Settings search.
Samsung Galaxy
Common Samsung paths include:
Settings → Security and privacy → More security settings → Install unknown apps.
On older One UI versions, it may appear under Settings → Apps → Special access. Select each browser, file manager or messaging app and ensure the permission is off unless there is a current need.
Xiaomi, Redmi and POCO
Xiaomi’s official support documentation gives this route:
Settings → Additional settings → Privacy → Special app access → Install unknown apps.
Select the app that opened the APK and switch its permission off. Xiaomi’s exact wording can differ between MIUI and HyperOS versions, so Settings search remains the safest fallback. See the official Xiaomi support answer.
OPPO and realme
Depending on the ColorOS or realme UI version, check one of these areas:
- Settings → Security/Privacy → More security → Installation sources, or
- Settings → Apps → Special app access → Install unknown apps.
Do not assume revoking Chrome is enough. If the APK was opened from File Manager, WhatsApp or Telegram, that app may hold the permission.
Why You Should Turn It Off Again
The permission does not make an app malicious by itself. It gives that source the ability to request installation of additional packages. Leaving it enabled increases the chance that a misleading download, chat attachment or pop-up can reach the Android installer with fewer warnings.
Google’s restricted settings guidance warns that harmful apps may ask users to change sensitive settings without a sensible reason. A calculator, wallpaper or simple game should not need accessibility control, device administration or unexplained installation privileges.
Do These Five Checks After Sideloading
1. Delete the downloaded APK
Once the legitimate app is installed and working, remove the installer file from Downloads, messaging media and trash. Keeping old APKs creates confusion and makes accidental reinstallation easier.
2. Run a Google Play Protect scan
Open Google Play Store → profile icon → Play Protect → Scan. Google says Play Protect checks apps from Google Play and can also scan potentially harmful apps from other sources. Keep Scan apps with Play Protect enabled.
3. Review the new app’s permissions
Go to Settings → Apps → the new app → Permissions. Deny access that is not required for the feature you use. A game rarely needs SMS, call logs, accessibility control or permission to install more apps.
4. Check sensitive special access
Review Accessibility, Device admin apps, Notification access, Display over other apps, VPN and Usage access. Remove unexpected access before entering passwords or opening banking apps.
5. Install Android and Google Play system updates
Security patches close known vulnerabilities. Google’s malware-removal guidance recommends checking Android, security and Google Play system updates as part of cleanup.
If the Switch Is Greyed Out
- Work or school device: an administrator may control installation policy.
- Child or supervised account: Family Link or another supervision policy may block the setting.
- Restricted setting warning: Android 13 and newer may require a separate decision for sensitive settings on sideloaded apps.
- Manufacturer security feature: an additional security control may block third-party installation.
Do not disable Play Protect or device management merely to bypass a restriction. Confirm why the restriction exists and obtain administrator approval where applicable.
If You Cannot Remember Which App Installed the APK
Open the full Install unknown apps list and inspect every entry marked Allowed. Common sources are browsers, file managers, cloud storage clients and messaging apps. Turn off all unnecessary entries. The installed app itself usually does not need this permission unless it legitimately installs other packages.
What This Setting Does Not Do
- It does not uninstall an APK you already installed.
- It does not remove malware already present on the phone.
- It does not prevent Google Play Store installations.
- It does not replace a Play Protect scan or permission review.
If the phone shows unexplained advertisements, unknown admin apps, unusual data use or account activity, follow our Android spyware removal guide.
Frequently Asked Questions
Should I disable unknown sources after installing an APK?
Yes. Revoke permission from the source app when the installation is complete. You can temporarily grant it again for a future trusted installation.
Can I still update the sideloaded app?
That depends on the developer’s update method. You may need to grant installation permission again for a legitimate manual update. Verify the source and package signature before updating.
Is turning off this permission enough to stay safe?
No. Keep Play Protect enabled, review permissions, update Android and obtain APKs only from a developer or distributor you can verify.


