mobiControl V 14.1 . Alert - Device Event : Un-enroll requested by user

N
ND
Telstra Corporation Ltd. (Australia Post)

How does this alert work ?   what is the use case.

7 years ago
Android
ANSWERS
RC
Raymond Chan Diamond Contributor
7 years ago (edited 7 years ago)

"Device un-enroll requested by user" event alert is not documented in the latest on-line manual,  nor is it functional in my tests on Android+ devices with latest v14.2 server.  Maybe I hadn't done the right thing to get this event triggered.

On the other hand, the related event alert, namely "Device unenrolled by user", has been implemented and working perfectly in v13.x and earlier.  I'll thus answer your questions with reference to this latter event instead.

- How does the alert work?

When the end-user of an enrolled device requests unenrollment while the device is ON-LINE, the device agent will notify/alert the server before it unenrolls itself from the system, after which the server will not get any more additional information from the device.

- Use Cases?

In the last 5 years,  I have never encountered a single customer asking for this feature for allowing a device end-user to initiate his/her device unenrollment remotely.   My wild guess on the possible use cases will be

   1. Corporate customer/guest needs to enroll his/her device temporarily (say for a few hours) to access corporate internal apps/data (e.g. content library/Soti-Hub)  while having an on-site meeting, and want to be able to get the device unenrolled towards the end of the meeting.

   2. EMM administrator needs to perform compatibility tests on a new device model, and want to leave a loophole to get the device unenrolled, just in cases unenrollment cannot be initiated from the web console and the device on hand cannot be forced into administrator mode.

IMPORTANT NOTE :

Self-service portal and other means allow the device end-user to initiate such enrollment.  Anyone who really need this feature should contact Soti support team directly to get information on how to do this.  I will not give such details in an open forum and STRONGLY suggest others in the know NOT to do so, as this can be potential loophole for hacking if MobiControl administrators forget to explicitly disallow such feature for all their devices managed in their servers.  This unenrollment-by-user feature, which is allowed by default for all devices, can be explicitly turned off by

1. unselecting all related permissions for Self-Service Portal in the Global Settings-> Security tab in the web console

AND

2. unchecking the "Prevent Un-enrollment from Device Agent" option in Advanced Configurations->Agent Settings tab of the device/device-group of interest.