Can SOTI allow for an app to create a work profile?

J
Julia
schneider6878

I am trying to see if we can use SOTI for some of our android tablet and have them use intune company portal app to access our comnpany apps?   The app requires the creation of a managed work profile, and when i tried it says it is not able to set up a work profile.  I see that there is work profile that SOTI creates on the device, is that why and is there a way around that?   

 

28 days ago
SOTI MobiControl
ANSWERS
AS
Alin Sfiriac
28 days ago

Not possible. 

If you want to use apps that require MS account, you can connect your Mobicontrol to your MS tenant, and register your devices. Also connect Mobicontrol as 3rd party device compliance partner, in your intune instance. The devices will appear on your Entra, as managed via intune (MS bug). You will not be able to see them in intune. 

You can create the same apps that you have in intune, in your Mobicontrol app policies.

If you use app protection policies, you can create a dedicated app protection policy for SOTI devices, and assign it for a group of users who will use these devices.

RS
Rafael Schäfer
27 days ago (edited 27 days ago)

Ensure you enroll the device the right way:

  • work profile if you want BYOD
  • corporate personal if you want COPE

In there, you define the used managed Google account (if wanted) and via that you can just via app policy assign apps from playstore including the company portal.

But for SSO and so on, you can of course in addition connect Soti to Intune (https://pulse.soti.net/support/soti-mobicontrol/help/?V=2026.0&T=console/system/microsoft_365_integration/add_mc_to_microsoft_intune_and_compliance_partner_configuration).

AS
Alin Sfiriac
26 days ago

What Julia wanted is not possible.

The device is already enrolled in Mobicontrol. When you try to sign-in in Company portal on Android, it tries to enroll the device in intune, which fails since the device is already managed by another mdm. 

@Julia , have a look over MAM Without Enrollment from Microsoft, and the link that Rafael mentioned

A
AKMOD@SOTI
11 days ago

Hi @Julia ,

Thanks for posting on SOTI Pulse, Thanks Rafael and Alin for responding to the post, your expertise and willingness to help are greatly appreciated!

Have you had an opportunity to test the suggested solutions by Alin, and has it successfully addressed your query?

If not, or If you have any additional questions or concerns, please don't hesitate to reach out. We're dedicated to providing assistance and support.

Indeed use MAM without enrollment.

Effectively Microsoft will see an unmanaged device accesssing the tenant (even though Soti is a third party MDM solution running on the device. You don't need tot set SOTI as an compliancy authority (you would only do this if you want to use Conditional Access for checking the MDM state as set by SOTI).

The user needs an Intune license on the Intune tenant, otherwise MAM will not work for the user.

Then you can use Intune MAM to distribute the Intune Applications to the Android device. On Android the company hub needs to be present, on iOS you need authenticator. You NEED NOT log in to the company hub. The Company hub is needed only to distribute the MAM settings and for registering the device in Entra ID. It acts as a brooker for MAM in that case.

In intune you create MAM configuration and App protection settings for the apps you want to deploy. Select the Google Play store within Intune to handpick the apps that you want to configure and protect.

In Intune you need to assign security groups to MAM applications (users need to be a member of the Entra ID securty group).

Once you have done this the user (on the device) needs to download the mobile MAM app he/she wants to use on the Android device (through the Google play store on the device). If it is a Microsoft app the user needs to login onto the app. the app wil see that MAM policies are enforced for this user on the tenant. The user will be noticed that the device needs to register in the Microsoft Entra ID and that security will be enforced on the app itself. THIS IS NOT AN INTUNE ENROLLMENT. The registration proces is needed for all devices accessing a tenant and will allways take place.

In this way you can have an Android device have a SOTI workprofile in combination with Intune MAM functionallity. You can even do this with MAM apps distributed through the SOTI workprofile. The company hub would then reside within the Workprofile, but you would not login to the Company hub in that case.

Hope this gives some context on working with SOTI in conjunction with Microsoft MAM.

 

A
AKMOD@SOTI
3 days ago

Hi @Julia ,

Hope you have gone through Geoffrey's response. Thanks Geoffrey for responding to the post, your expertise and willingness to help are greatly appreciated!

Kindly let me know if Geoffrey's suggested solution helped you successfully configure an Android device with a SOTI Work Profile in combination with Intune MAM functionality.

If not, or If you have any additional questions or concerns, please don't hesitate to reach out. We're dedicated to providing assistance and support.

Also, if geoffrey's response has helped you in solving your inquiry, I would request you to mark the particular comment as "is solution", so others may benefit from this information.