There's a new home for Articles. Find Articles on Our Product Support Page.
Hi all, I followed this link: SOTI Discussion Forum to complete AAD Integration so i can assign users to my devices. Unfortunatly, after the steps provided, the integration is not working. I checked all setting. Someone available to help me out? I can provide details if asked. Thanks in advance, Dave
Hi, i have some problemns with the registration from a Samsung Galaxy XCover 5 with Android 13. When i typed in the reistry URL from the Server, the device would registred with Saftey Net. I get a white screen after this will be done. We´re using MobiControl 15.6.1
Is there a way to enforce autologout of MS apps using the native android activity timer. We have shared devices that use MS apps, teams, outlook and another custom app that authenticates to Azure and we want to ensure that if a user forgets to log out that the device will after a period of time lapses.
Hi, I wonder if anyone is experiencing the same issue as me. We as a business manage multiple MobiControl instances for our customers ( AWS, AZURE ) We have one particular Azure server that cannot be accessed at least once a week and an error is displayed on the login page. This is slowing devices down as they are trying to reach DS which is down. We have changed the intervals on Retry Connection to 5 minutes but no improvement. SOTI Support has been contacted but the ticket is open for 2 months and this is still happening. Any suggestions will be appreciated.
Since there is no documentation on how to do this, I thought I’d share it with everyone. You should add Azure Directory first. See this guide: https://discussions.soti.net/thread/how-to-connect-mobicontrol-with-azure-ad In MobiControl – Global Settings – Services – Identity Provider Download the MobiControl Metadata File Go to Azure AD Portal Enterprise Applications New Application Search for and add MobiControl Set up single sign on – SAML Upload metadata file – upload the MobiControl Metadata File you downloaded from MobiControl Basic SAML Configuration should be like this: Identifier (Entity ID) - https://%DOMAIN%/mobicontrol Reply URL - https://%DOMAIN%/mobicontrol/sso/sp/handlelogon Sign On URL – https://%DOMAIN%/mobicontrol Logout Url - https://%DOMAIN%/MobiControl/sso/sp/handlelogout Example: Identifier (Entity ID) - https://s123456.mobicontrolcloud.com/mobicontrol Reply URL - https://s123456.mobicontrolcloud.com/mobicontrol/sso/sp/handlelogon Sign On URL - https://s123456.mobicontrolcloud.com/mobicontrol Logout Url - https://s123456.mobicontrolcloud.com/MobiControl/sso/sp/handlelogout SAML Signing Certificate Signing Options – Sign SAML response and assertion Signing Algorithm – SHA-256 Go to Azure AD Portal App Registrations Find MobiControl – if you do not see it, check under All Applications Manifest Search for “Group Membership Claims” – the value should be “1” with the “ Go to Azure AD Portal Enterprise Applications MobiControl Set up Single Sign On SAML Signing Certificate Download Federation Metadata XML Go to MobiControl Global settings – Services – Identity Provider Select + Name – can be anything Idp Metadata File – upload the Metadata XML you just downloaded Group Settings – Group From – Directory – add you directory Save Testing: Create a new iOS Enrolment User Enrolment Accounts Federated by Microsoft Azure AD – select the directory you just created Based on group membership Select the Azure Idp and search for a group. If you find it, your good to go.
Since there is absolutely no documentation on this I thought I’d share this with everyone. Log into Azure AD and create a group and add a user Enterprise Applications – New Application Search for and add MobiControl Go to the MobiControl application – Users and Groups Add the group you just created Go back to the Azure portal – App registrations Select MobiControl – if you can’t find it, check under «All applications» Certificate & Secrets New client secret Copy «Value» - this is the client secret and will only be shown once API permissions – add the following – note the difference between Application and Delegated ReadWrite.All > ApplicationDirectory.ReadWrite.All > ApplicationDirectory.Read.All > ApplicationGroup.Read.All > DelegatedUser.Read.All > DelegatedDirectory.ReadWrite.All > Delegated Click on «Grant admin consent for…» Go to MobiControl – Global Settings – Services – Directory Select + on Azure Directories Name – can be anything Microsoft Graph API Address – https://graph.microsoft.com Select + on Azure Tenant ID Name – can be anything Azure Tenant Name – this is the primary domain you see in the Azure AD Overview Azure Tenant ID – Tenant ID in the Azure AD Overview Metadata Endpoint Address – you’ll find this under App Registrations – Endpoints – Federation metadata document Select + on Application Name Application name – can be anything Client ID – you’ll find this under Enterprise Applications – MobiControl – Application ID Client secret – the value you copied on step 9 a Save To test, do the following: In MobiControl – Users and Permissions - Groups - + Search for the group you added earlier – if you find it, it works Search for additional groups in Azure to verify connection Troubleshooting: To troubleshoot, check MS log and search for the Client ID. There will most likely be an understandable error message.
Hi All, Has anyone managed to create a Azure logic App custom creator with SotiMobicontrol? From MS's documentation I should be able to test the API in Postman and then export from Postman in to Azure. Postman connects without any issues and posts back the data we're calling. If someone has done it, could they give me a helping hand? Thanks!
Our company is moving all of our on premise Windows Servers to Azure. What do I need to know before we move our SOTI Mobicontrol Windows server to Azure?
We're looking at leveraging the new User Enrollment feature of iOS 13 and are having a tough time connecting our on-prem MobiControl instance to our Azure AD. We have followed the instructions here (https://www.soti.net/mc/help/v14.0/en/console/system/ldap/azure_authenticate_mc.html) but are confused about number 3 ("Configure permissions for the application"). In Azure, we have granted "Directory.Read.All" permissions for the app and we are fairly certain we have entered everything correctly but we cannot get it to work. When searching the directory (through the Security tab), we get "The server could not complete your request. An internal error occurred." In the ManagementService logs it looks like it is failing while trying to acquire a token. Has anyone had similar issues? We have already synced to AD using a traditional LDAP connection, but we would like to figure out how to connect to Azure as well.
Hi, Is it possible to use Azure SQL service (https://azure.microsoft.com/en-us/services/sql-database/) as database for MobiControl? If it works, will it also be supported by Soti Support? Thanks Leroy
Top-tier experts who are delivering outstanding content. Should have more than 7000 points.
Experts who are consistent with great content. Should have more than 1000 points
Highly experienced members with valuable inputs. Should have more than 700 points
Beginners taking the initiative. Should have more than 500 points