Android OS Updates on Lockdown devices

RK
Robin K.
PP 2OOO BUSINESS INTEGRATION AG

Hello everybody,

we are currently using Samsung Galaxy Tab A SM-T585 devices.

SOTI Server is v.14.2.1.4394, Android Plus device Agent is Samsung ELM v13.6.0

After configuring Lockdown mode for those tablets, the users are no longer able to confirm the OS updates on the tablet.

From what i have read, it is not possible to force the OS updates from SOTI server side.

Is there a possibility to grant the user the right to run OS updates even in Lockdown mode, or is there any other way to ensure that OS updates can be done?

Right now we would have to disable Lockdown on the device, run the update and then enable Lockdown again.

Regards

Robin

6 years ago
Android
ANSWERS
G
GPMOD@SOTI
6 years ago

Hello Robin - Could you please confirm if we are talking about the OTA OS updates. The lockdown should not affect sending an update OTA.

Thank you

RC
Raymond Chan Diamond Contributor
6 years ago (edited 6 years ago)

On most Samsung device models, as long as "Download updates automatically"  and "scheduled software updates" options in the "Software update" tab of Settings have been enabled,  there shouldn't be any problem getting software update automatically even when the lockdown menu is active.

If the above really doesn't work on your model/firmware version, and if you really don't mind the end-user to be able to initiate firmware update, you can consider adding an extra lockdown menu item for software update :

  Launch://com.android.settings/.Settings$SoftwareUpdateSettingActivity

Whether or not this will create security loophole(s) to access other Settings tabs/pages depends heavily on the GUI design on your device.

I personally haven't recommended to any of my customers  to add such option in their lockdown menu or to allow major firmware upgrade 7/24.  In fact, unless there is more advanced mechanism such as the paid E-FOTA to precisely control which device upgrade to which firmware version,  allowing end-user to arbitrarily upgrade to any firmware available online may pose a big risk that the new firmware is not compatible with some of the corporate proprietary apps or with the device agent itself.  The worst scenario would be total device recall if the device gets out-of-control due to device agent compatibility issues.  In the case of app incompatibility, extra time and money may be needed to come up with an updated app version that is compatible with the new firmware.   There is no official mechanism to fallback to older firmware version on the device, nor is there any official channel to get genuine non-tempered flash firmware image from any Samsung support sites .  Even if one knows how to do the fallback with an official flash image via USB ADB,  it would be very time-consuming and costly to recall all affected devices and perform the fallback manually. 

Many recent Android device models have security patches separated from major firmware upgrade.   Allowing he former to be done when available is OK, but the latter should be blocked by default.  Thorough compatibility tests on each affected model/firmware combination should be done before allowing the new firmware upgrade to go ahead over-the-air under MDM control.

RK
Robin K.
6 years ago

Yes, we are talking about OTA OS updates.

It seems like this was a device specific error. The error in this case was the popup regarding the update disappearing from the status bar.

I got some other test devices and did not have any errors and all updates went smooth

RC
Raymond Chan Diamond Contributor
6 years ago

If you've confirmed the problem is device model specific, and you can't live with the workaround proposed in my previous post, you can officially report the problem to Soti support and or Samsung, and wait patiently to see if there will be any firmware fix release in the near future.