Lock screen notifications - Android Enterprise Lockdown - Android 9

JC
Joel Cooke
SNP Security

Hi Team,

First time poster here, although I've been floating around the forums benefiting from the shared wisdom posted here for the last few months. I've run into a dead end with this particular issue, and i'm hoping i can get some advice on how to proceed.

We've run into an issue recently that seems to only affect Android 9 devices on the Android Enterprise configuration. 

The lock screen (when you first unlock the phone before swiping to unlock, or entering a PIN etc) doesn't seem to display notifications of any kind We've noticed that when the device is in lockdown mode, we can't see any notifications at all on the lock screen, in fact in order to see the notifications, we need to enter administrator mode, or send the "lockdown off" script via MobiControl. 

Some of our sites rely on system-generated messages sent to mobiles to give the staff instructions on where to check, and which routes to take etc.

When i take a look into the settings of the device, i can see that under the lock screen portion, the Notifications button is set to disabled, and is greyed out i.e. cannot be adjusted. 

Again, as this only affects Android 9 devices on Android Enterprise, i'm baffled at what i can do to resolve this.

! Some points on our configuration !

#: Lockdown config: Activity Suppression enabled. Disable Status Bar Expansion Enabled. Using Device Control.

#: Feature Control: Redact Notifications is not ticked. Disable all notifications is not ticked. Disable all system UI is ticked, although this didn't seem to have any effect on this problem either way.

#: We use the MobiControl Stage Programmer app with NFC for smartphones, and the QR Code for tablets.

#: Android Plus covers 80% of our fleet, with 20% of Enterprise devices distributed in the last 3 months.

#: I've configured the devices to land in a blank folder with no payloads, and once they are enrolled and ready, i'll manually drag the device into a folder with a profile targeted to said folder, which will push the profile/payloads.

#: We use the J5 Pro (Android 8.1), Galaxy A20 (9.0) and the Galaxy Tab a 2017 (8.1).

If the guard misses a message, this can be a massive compliance issue, so unless the guard keeps their device open on the SMS app, there's a good chance they'll miss it.

Has anyone else run into this issue before? Any assistance of advice provided would be sincerely appreciated.

Thanking you in advance,

Joell

6 years ago
Android
ANSWERS
RC
Raymond Chan Diamond Contributor
6 years ago

I'm not sure if your problem is present in any Android 9.0 device.  In your case, do you experience such problem in ALL your Samsung A20? And no such problem in ANY of your Samsung J5 Pro and Tab A 2017?  It is also possible that the problem is specific to Samsung A20 rather than  any device Android 9.x.

If your devices have lockdown menu and device's Settings is disallowed in user-mode and lockdown, then one simple solution is to manual change the settings in device-admin-mode before deploying the devices to end-users 

If your problematic devices have already been deployed to end-users, one possible approach is probably to check if there is any script command to enable the required notification on your Samsung devices.   Whether or not this works  may depend on the device model, firmware version as well as device agent version.

MR
Matt Rogers
6 years ago

I was just reading about this today, the issue maybe Secure Startup. Since Lollipop there have been changes to the encryption model used in Android, moving from a full disk encryption style to file level encryption. At one point secure startup was synonymous with the full disk encryption but nowadays the secure startup (where you are prompted for your password twice before having full access to the system) will block all notifications, access to phone, camera, fingerprint reader, etc so that you can't be knocked over the head and have your thumb placed on the reader to unlock the device-- you have to enter something you know (PIN, password) instead of simply something you have (fingerprint, face, etc).

In other words if Secure Startup is enabled and the initial password has not yet been entered the device will not display notifications and no SMS or calls will be received. Once this is entered following startup those features will work. If you lock the screen they will still work unless you actually lock down the device or restart it. Android offers a way to add "Lock down" (or words to that effect) to the Power options (Power down, restart, lock down) so that you can leave a device "on" but still unable to be operated without the password.

Hope that helps

Matt

JC
Joel Cooke
6 years ago

Hi Raymond,

That's a good point. We're using Samsung exclusively so it could simply be a problem with the handset/samsung firmware.

You are right, we are experiencing this issue with all of our Galaxy A20s, and we have no issues on the J5 Pro or the Tab A 2017. We noticed that the J5 Pro, when upgraded to Android 9, is effected by the problem explained in my previous post.

I will try your suggestion about the manual change in device admin mode, and see if that makes any difference. 

We do have some deployed already, however if we were to find a solution based around how we enrol/prepare devices that would save us a lot of strife moving forward.

I have got a list of scripts i use on a regular basis, however most of them have been from reading through these forums (some of them learned from your own advice!). What's the process for discovering scripts? Is there a list that i can refer to for Samsung devices?

JC
Joel Cooke
6 years ago

Thanks Matt for the advice.

I'll definitely look into this and get back to you!

Joel.