Mail program device admin rights in combination with Lockdown feature

RK
Robin K.
PP 2OOO BUSINESS INTEGRATION AG

Hi everybody,

we have configured the lockdown policies for one of our device groups.
we also have a policie to configure the mail client on the devices with the pre-installed Samsung mail app.
This app needs device administrator priviliges to be configured, but as soon as the lockdown policy is applied the user isn't able to grant the app the required rights.
Is there a way to configure the order in which the policies are applied or e.g. to grant the mail programm device administrator rights via SOTI?

We want to use this mail program in combination with the Lockdown feature.


Regards

Robin

6 years ago
Android
ANSWERS
G
GPMOD@SOTI
6 years ago

Hello Robin,

Could you please let us know if the devices are enrolled as Android Plus or Android Enterprise?

We do not have scripting capabilities for Android Plus devices.

Thank you,

RK
Robin K.
6 years ago

Hello,

these devices are enrolled as Android Plus.

RC
Raymond Chan Diamond Contributor
6 years ago

There is no support for script to grant app permission with Android Plus device agent.

If you can start remote session on your devices,  you can grant permission remotely by making required changes in Device's Settings within a RC session.

RK
Robin K.
6 years ago

Configuring the mail client on each device manually does not seem to be a viable solution.

We would have to disable lockdown mode, configure the mail client and then enable lockdown mode again.

What would be your recommended solution?

Using a mail client that does not require device admin rights?

Specifying the order in which the profiles are applied would be a possible solution as lockdown and mail settings are configured in different profiles.

Is there such a feature?

RC
Raymond Chan Diamond Contributor
6 years ago (edited 6 years ago)

Disabling/enabling lockdown mode, controlling the order in which profiles are applied, etc are doable, though the complexity depends  on how the devices are distributed or how many devices are there. 

However, the major issue is who will be granting the administrator permission for the mail client on the device Settings if the devices are all already deployed to end-users.  Can you clarify if you have any solution(s) for this?   If not,  your only option maybe is to use a mail client that doesn't need this permission granting step.

How many devices do you have?  Are they all already deployed to end-users?   Do they all share the same policies (profiles, rules and advanced configuration)?