Appium c# and Selendroid and real android device

Hi I am trying to automate an app that is on an android device that is running version 4.1.2. on windows 10 64bit using c#
I have set the following capabilities in my c# code

        Environment.SetEnvironmentVariable(AppiumServiceConstants.NodeBinaryPath, @"C:\Program Files (x86)\nodejs\node.exe");
        Environment.SetEnvironmentVariable(AppiumServiceConstants.AppiumBinaryPath, @"C:\Program Files (x86)\Appium\node_modules\appium\bin\appium.js");
        _service = new AppiumServiceBuilder().WithLogFile(new FileInfo(@"C:\Users\andre\Desktop\appium-log.txt")).Build();

        _service.Start();

        capabilities.SetCapability("automationName", "Selendroid");
        capabilities.SetCapability(CapabilityType.Platform, "Windows");
        capabilities.SetCapability("deviceName", "TC55");
        capabilities.SetCapability("platformName", "Android");
        capabilities.SetCapability("udid", "13329521650464");
        capabilities.SetCapability("platformVersion", "4.1.2");
        capabilities.SetCapability("fullReset", "True");
        capabilities.SetCapability("appPackage", "com.testapp");

this is the command I am attempting to start up
_driver = new AndroidDriver(_service, capabilities, TimeSpan.FromSeconds(180));

The error I get is as follows please can someone advise where I can set this permission.
System.InvalidOperationException was unhandled by user code
HResult=-2146233079
Message=A new session could not be created. (Original error: hasInternetPermissionFromManifest failed. Error: Command failed: C:\WINDOWS\system32\cmd.exe /s /c "“C:\Program Files (x86)\Android\android-sdk\build-tools\25.0.1\aapt.exe” dump badging "
ERROR: no dump file specified

I am using Appium 1.4.16.1
c# VS 2012

hi to add to this i have checked the permissions on the app via aapt dump badging and can see that the permission is set on the app. I can access the app via UI automator but cannot examine any of the controls, can examine built in controls such as settings.

Is it possible the app can be locked by a policy on the phone as part of a lockdown, similar to a group -policy type thing in windows?