Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Warning

This document is work in progress!

...

Open source EMM backed by enterprise support

Open source technology brings significant flexibility to your mobile projects. It enables you to get started quickly without time-consuming licensing or legal reviews, and it protects you from vendor lock-in. It gives you the flexibility to take the product in new directions, preserves full flexibility to commercialize your products, and ensures that the code is examined by many parties to ensure its reliability, security, and feature fit. WSO2 EMM is a leading open source vendor that provides enterprise support. To learn more about the benefits of open source, see Why Open Source for Your IoT and Mobile Projects?

...

With WSO2 EMM, you can:

  • Install the WSO2 EMM profile on the device. You can choose the BYOD or COPE enrollment path for the device.
  • Apply policies on devices so that they adhere to company security policies, such as disabling the device's camera when the device enters a certain geo area.
  • Customize the device enrollment process to enroll Corporate Owned, Single Use (COSU) and more.
  • Remotely control, upgrade the firmware, wipe data, transfer files, and much more.
  • Add geofences, monitor, and analyze device data using real-time analytics.
  • Group and manage devices in one go.


Image RemovedImage Added

Mobile Application Management (MAM)

...

Localtabgroup
Localtab
titlePolicies for Android devices
Panel
borderColor#11375B
bgColor#ffffff
borderWidth1

Policies for Android devices

The mobile device management administrator can add a new policy to a preferred device type, such as BYOD or COPE. The following policies are available for the Android platform.

PolicyDescription
Passcode policyDefine a password policy for the devices.
Anchor
restrictions
restrictions
Restrictions

Allow or disallow users from using the following features on Android devices. Most of the restrictions require the Android work profile to be set up, the system app installed, or the device to be a single-purpose device.

Info

Please note that the restrictions mentioned under device ownership application do not work for Samsung devices at the moment.

RestrictionsBYODWork
profile
System
Service
App
COSUDevice
Owner
App

Using the camera on the device.

Configuring user credentials.

XXX

Configuring VPN.

XXX

Restricting items copied to the clipboard from being posted on related profiles.

XXX

Enabling or accessing debugging features.

X

Installing applications.

XXX

Enabling the "Unknown Sources" setting.

X

Adding and removing accounts unless they are programmatically added by the Authenticator. For more information, see the details on adding an account directly.

Note
titleNote!

If you enabled this policy before configuring the Google Play Store with a Google Account, the following message is displayed when you open the Google Play app: “This change is not allowed by the device administrator”.

To use the Google Play Store with this policy, you need to set up the Google account and configure Google Play before applying this policy.

X

Restrict the use of Near Field Communication (NFC) to beam out data from apps.

X

Turning on location sharing.

X

Uninstalling applications.

X

Allows or disallow apps in the parent profile to handle web links from the managed profile.

X

Disabling application verification.

XX
Enabling the auto time feature in Settings > Date & Time.XX

Disabling the screen shot option on the device.

XX

Restricting the user from sending or receiving Short Message Service (SMS) messages.

XX

Adjusting the master volume.

XX

Configuring cell broadcasts.

XX
Configuring Bluetooth.XX

Configuring mobile networks.

XX
Transferring files over USB.XX

Changing Wi-Fi access.

XX

Device rebooting.

XX

Making outgoing phone calls.

XX

Mounting physical external media.

XX
Restricting windows beside the app window from being created.XX

Factory resetting the device from Settings.

XX

Removing other users.

XX

Adding new users and profiles.

XX

Resetting the network settings from Settings.

XX

Adjusting the microphone volume.

XX

Disabling the status bar on the device.

Info

This restriction is only supported in Android version 6.0 Marshmallow and higher.

XX
Encrypt storageEncrypt data on the device when the device is locked and make it readable when the passcode is entered.

Wi-Fi

Ability to configure the Wi-Fi access on a device. WSO2 EMM provides advanced Wi-Fi configuration settings, as shown below:
  • You are able to configure the Wi-Fi settings for the WEPWPA/WPS 2PSK, and 802.1 EAP security types. 
  • The 802.1 EAP security type works only for Android 4.3 and above.
  • WSO2 EMM supports the following EAP methods: PEAPTLSTTLSPWDSIM, and AKA.
  • If you want to provide the identity of the user that accesses the Wi-Fi through their Android device, you can provide [user] as the value for Identity, and it will provide the username used by the user to enroll their Android device with WSO2 EMM. This setting is only applicable for the following EAP methods: PEAPTLSTTLS, and PWD.
 
VPNAbility to specify the VPN and per-app VPN settings.
Work-Profile Configurations

Ability to separate the personal and work-related data on your device via the managed profile feature.

Info

For more information on how this works, see Data Containerization for Android Device.

Anchor
blacklisting
blacklisting
Application restrictions

Ability to blacklist and whitelist applications on the Android platform, as described below:

Blacklist applications

Prevents you from using the applications defined in the policy. For Android operation systems before Lollipop, when the user clicks a blacklisted application, a screen appears that prevents you from using the app. For the Lollipop Android operating systems and later, the blacklisted apps are hidden. Blacklisting can be used on both BYOD and COPE devices.

Whitelisting applications

Allows you to install only the applications defined in the policy. This feature requires another application, the WSO2 EMM System app, which is signed by the device firmware owner. Therefore, this app is generally used on COPE devices, but if you can get the WSO2 EMM System app signed via a firmware signing key, you can use it on BYOD devices, too.

Info

In addition to the above, you can enable application restrictions via the restrictions policy. The restrictions policy has two settings to restrict application installation and uninstallation. To use the restrictions policy, the WSO2 EMM application must have device owner privileges, or the device must have the WSO2 EMM System app installed.

Localtab
titlePolicies for iOS devices
Panel
borderColor#11375B
bgColor#ffffff
borderWidth1

Policies for iOS devices

The mobile device management administrator can restrict operations on Windows devices by adding a new policy. The following policies are available for the iOS platform.

PoliciesDescription

Passcode policy

Define a password policy for the devices.

Restrictions

Anchor
ios-restrictions
ios-restrictions

Restricts the usage of the camera and other functions. You can allow or disallow users from using the following features on the device:

  • Restrict users from installing applications on the device.
  • Prohibit users from adding friends to the Game Center.
  • Restrict users from removing applications from the device.
  • Restrict users from using Siri.
  • Prevent Siri from querying user-generated content from the web.
  • Prevent users from using Siri when the device is locked. Availability: iOS 5.1 and later. 

  • Restrict users from using the camera. If this operation is not allowed, the camera icon will be removed from the home screen.
  • Prevent users from backing up the device data to iCloud. Availability: iOS 5.0 and later. 

  • Disable documents and key-value syncing to iCloud. Availability: iOS 5.0 and later.

  • Disable Cloud keychain synchronization. Availability: iOS 7.0 and later. 

  • Prevent the device from automatically submitting diagnostic reports to Apple. Availability: iOS 6.0 and later. 

  • Hide explicit music or video content purchased from the iTunes Store. Explicit content is marked by content providers such as record labels when sold through the iTunes Store. 
  • Prevent the Touch ID from unlocking a device. Availability: iOS 7 and later. 

  • Disable the global background fetch activity when an iOS phone is roaming.
  • Prohibit in-app purchasing.
  • Prevent the Control Center from appearing on the Lock screen. Availability: iOS 7 and later. 

  • Disable host pairing with the exception of the supervision host. If no supervision host certificate has been configured, all pairing is disabled. Host pairing lets the administrator control which devices an iOS 7 device can pair with. Availability: iOS 7.0 and later.

  • Disable the 'Today view' in the Notification Center of the lock screen. Availability: iOS 7.0 and later. 

  • Prohibit multiplayer gaming.
  • Allow managed apps and the accounts to open only in other managed apps and accounts. Availability: iOS 7.0 and later.

  • Allow unmanaged apps and accounts to open only in other unmanaged apps and accounts. Availability: iOS 7.0 and later. 

  • Disable over-the-air PKI updates. Setting this restriction does not disable CRL and OCSP checks. Availability: iOS 7.0 and later. 

  • Disable Passbook notifications. Availability: iOS 7.0 and later. 

  • Disable Photo Streams. Availability: iOS 7.0 and later. 

  • Disable the Safari web browser application and remove the icon from the Home screen. This also prevents users from opening web clips. 
  • Disable Safari auto-fill.
  • Enable the Safari fraud warning.
  • Prevent Safari from executing JavaScript.
  • Prevent Safari from creating pop-up tabs.
  • Restrict users from saving a screenshot of the display.
  • Disable shared Photo Stream. Availability: iOS 6.0 and later. 

  • Disable video conferencing.
  • Disable voice dialing.
  • Disable the YouTube application and remove its icon from the home screen. Users will not be able to preview, purchase, or download content. Availability: iOS 7.0 and later. 

  • Force the use of the profanity filter assistant.
  • Encrypt all backups.
  • Force user to enter their iTunes password for each transaction. Availability: iOS 5.0 and later. 

  • Limit ad tracking. Availability: iOS 7.0 and later. 

  • Force all devices receiving AirPlay requests from the user's device to use a pairing password. Availability: iOS 7.1 and later. 

  • Force all devices sending AirPlay requests to the user's device to use a pairing password.

  • Prevent the managed applications from using cloud sync.
  • Disable Activity Continuation.
  • Prevent the backing up of enterprise books.
  • Prevent the syncing of notes and highlights in the enterprise books.
  • Allow the user to modify the touch ID.
  • Determine the conditions under which the device will accept cookies. The conditions are as follows:
    • Never
    • From visited sites only 
    • Always 
  • Force users to unlock their Apple Watch with a passcode once the watch has been removed from their wrist. Availability: iOS 8.3 and later. 

  • Restrict access to certain age groups based on the ratings. The ratings given are as follows:

    • Don't allow apps
    • 4+
    • 9+
    • 12+
    • 17+
    • Allow all apps
  • Restrict access to movies based on movie ratings. The ratings given are as follows:

    • Don't allow movies
    • G
    • PG
    • PG-13
    • R
    • NC-17
    • Allow all movies
  • Rate operations based on the region.
  • Restrict access to TV shows based on the ratings given. The ratings given are as follows:

    • Don't allow TV shows
    • TV-Y
    • TV-Y7
    • TV-G
    • TV-PG
    • TV-14
    • TV-MA
    • All TV shows
  • Allow the apps to be identified by the bundle IDs listed in the array to autonomously enter Single App Mode. Availability: iOS 7.0 and later. 

Wi-Fi

Configure the Wi-Fi access on a device.

Email

Configure settings for connecting to your POP or IMAP email accounts.
AirPlayConfigure settings for connecting to AirPlay destinations.
LDAPConfigure settings for connecting to LDAP servers.
CalendarConfigure settings for connecting to CalDAV servers.
Calendar SubscriptionConfigure settings for calendar subscriptions.
APNSpecify Access Point Names (APN).
Cellular NetworkSpecify Cellular Network Settings on an iOS device.
VPNSpecify the VPN and per-app VPN settings.
Localtab
titlePolicies for Windows devices
Panel
borderColor#11375B
bgColor#ffffff
borderWidth1

Policies for Windows devices

The mobile device management administrator can restrict operations on Windows devices by adding a new policy. The following policies are available for the Windows platform.

PoliciesDescription

Passcode policy

Define a password policy for the devices.
RestrictionsRestrict the usage of the camera.
Encrypt storageEncrypt data on the device when the device is locked and make it readable when the passcode is entered.

...