(IOS) Mobicontrol App requires new sign in when changing OU or updating management app. Bug or feature?

B
Brandon
State Garden

Every time the MobiControl management app updates you are required to sign in to the app, download a new profile, and manually accept and install it within the settings app to be able to access the management app.

I have also seen this behavior when changing profiles for various actions like managing an app or device features. Additionally after iOS updates this also seems to happen.

Is there any way around this / to force the ipad to authenticate without user interaction?

It's incredibly frustrating especially when troubleshooting with users to ask them to go in and access this. I have Safari disabled on locked down ipads that only access internal resources aside from OS updates and management and due to this there is no way to sign in after an agent update without removing the lock-down on these devices one by one.

This is beyond frustrating. There is already a MDM Profile installed on the device so the mdm should be able to identify and authenticate through the magic of said profile. Other MDM providers don't have this kind of limitation.

Anyone else frustrated by this? Experiencing the same issue? Used to this sort of thing with Soti Mobicontrol?

2 years ago
iOS
ANSWERS
RC
Raymond Chan Diamond Contributor
2 years ago

What is the firmware version and enrollment mode of your iOS device?

Did you mean MobiControl device agent app when you said  "MobiControl management app"?     Please show screenshot(s) related to "sign in to the app" as mentioned in your post.

What are included in the "new profile" to be downloaded when your MobiControl app gets updated?

B
Brandon
2 years ago

The iOS version does not seem to matter but I am running 16.7.1 on the iPad I currently have in front of me and have trivially reproduced it on.

The "Management app" is the MobiControl app. If this is unclear, it is this application specifically, newest version, straight from the official Apple app store: SOTI MobiControl on the App Store (apple.com)

Enrollment wise, I am using apple business manager managed devices for automated device enrollment. This is whole device enrollment from a fresh device, NOT user enrollment. During enrollment we require directory authentication. I am using Soti Identity which then forwards users to an azure active directory login screen like you'd get with any typical o365 environment.

In terms of images, take a look here: Imgur link

When I move a device from one OU to another with slightly different configuration profiles, I will get prompted almost immediately upon launching the mobicontrol app with the above screenshot steps. Once I install the new profile it then will open and show the typical console messages it has.

The specific things that are different between the two OUs are

1. a safari app policy which installs it if it was uninstalled

2. I have a Soti Surf profile that applies configuration to soti surf and the configuration is different between one OU and another. This is to test a soti surf kiosk mode switch.

This doesn't just happen in this one instance, this has happened many times over the course of months working with this horrendous platform, long before I was customizing soti surf or doing anything with Safari. 

M
MPMOD@SOTI Gold Contributor
2 years ago

Hi Brandon,

Thank you for posting on SOTI Pulse! 

What profile configurations do you have for these devices? What are these slightly different changes that you have on another device group?

Does this issue still happen even if the profile is very basic and has only one configuration?

Kind regards,

Technical Support Specialist | SOTI | +1 905.624.9828 | SOTI.net lDiscussion Forum | Log a Case Online l Facebook l LinkedIn l Twitter