SOTI MobiControl

2026.0

·

Build 58828

·

November 12, 2025

Important Notes About This Release

  • Upgrading to or installing SOTI MobiControl 2026.0.0 requires the installation of SOTI XSight 2026.0.0. 
  • For fresh installations of SOTI MobiControl 2026.0.0, only 2026.0.0 device agents will be compatible by default. When upgrading from an earlier version, older agents will remain compatible. More information about allowing older agents can be found here.

Release Highlights

SOTI Stella: Your AI-Powered Assistant

Stella is your AI-powered assistant, built to make data interaction effortless. With Stella, you can work faster, cut down on manual tasks, and make confident, data-driven decisions. Stella’s core capabilities include:

  • Ask questions, uncover insights, and create reports through simple natural language queries.
  • Get real-time guidance and answers directly from SOTI Pulse.
  • Seamless updates through SOTI MobiControl, ensuring it remains secure, scalable, and equipped with the latest AI advancements.

Lockdown Reimagined: Supercharged with the SOTI ONE Platform

Take your Lockdown configuration for Android Enterprise to new heights by leveraging the SOTI ONE Platform and reimagine what’s possible for your workforce.

Streamline Your Lockdown Setup

Set up your mobile worker experience with ease using the new Lockdown Setup, a step-by-step wizard that helps you configure each setting with intent.

Configure Authenticated Lockdown

Easily configure an Authenticated Lockdown experience to personalize how devices should behave before and after user authentication through your identity provider of choice. Enable multiple roles with a single device and allow for seamless handoff between shared devices.

Leverage Conditional Lockdown

Ensure your devices remain secure, even during operational disruptions with Conditional Lockdown. Automatically activate Lockdown in real time when a device detects an unauthorized carrier, loses contact, exits a geofence or reaches a critical battery level.

Design Lockdown Home Screens

Create custom Home screens easily using SOTI Snap to deliver a branded, intuitive experience that is best tailored for your mobile workforce.

Streamline Device Access with NFC Tags

Enable fast, secure device access with NFC (near-field communication) tags associated with SOTI Identity users for a frictionless login experience.

Visualize Your Lockdown Operations

Monitor your mobile workforce operations by analyzing your SOTI Snap Lockdown app device utilization in SOTI XSight.

Locate Devices via Live View Device Action

As of SOTI MobiControl 2026.0.0, GPS-based device location will be managed exclusively through SOTI XSight. This functionality remains available to all SOTI MobiControl users, with no SOTI XSight license required. Rather than navigating to the Location tab in device or device group details, users will now use the Live View device action to access real-time location information for individual devices or entire groups directly within SOTI XSight Live View.

Analyze Collected Location Data in SOTI XSight

Review and interact with historical device movement data directly in SOTI XSight. Collected data points from location Data Collection policies are plotted on the map and connected in sequence, with details available at each point. This feature is available to all SOTI MobiControl users, and no SOTI XSight license is required.

Manage Geofences from Signal Policy and Lockdown Policy

Create and manage outdoor geofences directly within Signal Policy and Lockdown Policy in SOTI MobiControl. Define boundaries, enforce automated actions and maintain full oversight of geofence behavior from the same place you manage device policies. Geofence management now leverages Azure Maps for map services.

This update introduces a redesigned navigation experience with a modern, collapsible menu and customizable branding. Users can now access frequently used features faster, with fewer clicks, and benefit from a cleaner, more intuitive interface. The new system improves usability, reduces training time and enhances productivity across all users.

Dark Mode in Web Console

Users can now switch to Dark Mode for a more comfortable viewing experience, especially in low-light environments or during extended sessions. This feature reduces eye strain, enhances focus, and aligns with modern UI expectations.

Approval Process for Mission-Critical Profiles

Administrators can now easily enforce an approval workflow for changes to critical profiles. Any configuration, package, or assignment changes must be reviewed and approved before taking effect. This functionality empowers administrators to prevent accidental disruptions, ensure compliance and maintain operational continuity.

Streamline eSIM Management on Android

Manage your cellular configuration with eSIM (embedded SIM) policies and remotely provision eSIMs in bulk across Android 15 devices, enrolled as Android Enterprise, for fast and secure connectivity.

Optimize Wi-Fi Configurations on Android

Deliver smarter network connectivity with stronger security and compliance across your Android Enterprise devices.

  • Prioritize managed Wi-Fi networks so devices automatically connect to the most reliable options without manual intervention.
  • Enable WPA3 security to deploy stronger, encrypted Wi-Fi networks that meet compliance requirements.
  • Restrict unmanaged access by limiting connectivity only to managed Wi-Fi networks for better security and control.

Run Device-Side JavaScript Scripts on Android Using Signal Policies

Users can now easily execute JavaScript scripts directly on Android devices using Signal policies, even when the device is offline. This expands automation capabilities and enhances security by enabling real-time, device-initiated actions. This feature is especially useful for enforcing compliance or triggering remediation in disconnected environments.

Image Deployment on Non-Managed Devices and Image Repository

This feature introduces OS image deployment capabilities for non-managed Windows devices, enabling IT administrators to stage and deploy images across the entire network, even to devices not yet enrolled in SOTI MobiControl. With centralized management and credential handling, this feature boosts operational efficiency and ensures consistent device provisioning. Administrators can now streamline onboarding and reduce manual effort, improving scalability and deployment speed.

OS Version Upgrade and Edition Change in Update Policy

The update allows administrators to perform OS version upgrades (e.g., Windows 10 to Windows 11) and edition changes directly through update policies. This streamlines OS upgrade workflows, ensures fleet consistency, and reduces manual intervention, helping organizations maintain security and operational efficiency.

Licensing Changes to Remote Control

All Remote Control features will now be available with a SOTI MobiControl license. A SOTI XSight license will no longer be required for Device Snapshot, Task Manager, Video Recordings, Screen Annotations, Web Console and Remote Terminal.

New Features and Improvements

System Administration

Redesigned Device Details View

Administrators can now easily access critical device information through a streamlined, modern interface. The updated Device Details View consolidates key data and actions into a single, intuitive layout, reducing the need to navigate multiple tabs. This enhancement improves troubleshooting speed and boosts user satisfaction.

Permission to Assign/Revoke Profile Without Giving Ability to Edit Profiles

Administrators can now give users permission to assign or revoke profiles without granting them permission to edit them. This granular permission control enhances security, reduces the risk of misconfiguration, and simplifies role-based access management. It empowers organizations to delegate tasks more safely and efficiently.

Automatically Reinstall Profiles on Failure or Partial Install

Administrators can now configure profiles to automatically retry installation if they fail or are only partially applied. This feature reduces manual intervention, minimizes device downtime, and ensures consistent policy enforcement across the fleet.

Pause Deployments Outside Scheduled Windows

Administrators can now set deployments to automatically pause profile or app deployments outside of scheduled windows, giving them greater control over bandwidth and operational impact. This feature is ideal for environments with limited connectivity or strict maintenance windows, such as retail or logistics. It helps reduce downtime, improve deployment success rates, and align updates with business needs.

Enhanced Device Insights with Profile Indexing and Dashboard Charts

Profile property indexing in SOTI Search enables faster, more accurate queries, advanced filtering, and richer reporting. Building on this foundation, the Devices Dashboard now includes payload and category charts, providing real-time visibility into configuration health and helping identify issues more quickly. Together, these enhancements strengthen monitoring, decision-making, and operational efficiency.

Display Installed App Versions on Apps Dashboard

Users can now view the installed versions of applications across all devices directly from the Apps Dashboard. This real-time visibility helps identify outdated apps, streamline updates, and ensure consistency. The update reduces manual checks, enhances security, and improves app lifecycle management. 

Enhanced Scheduling Option for Enterprise Apps on Windows

This update introduces flexible scheduling for Windows app deployments, allowing installations to occur during off-peak hours. Administrators can now separate assignment and deployment times, reducing network congestion and improving system performance.

Integrate Device Group Tree with Apps Dashboard

The Apps Dashboard now includes a device group tree, allowing users to filter app data by specific groups. This contextual filtering improves visibility, simplifies app management, and supports more targeted decision-making. It enhances usability and reduces administrative overhead.

Integrate Device Group Tree with Certificates Dashboard

This feature extends device group filtering to the Certificate Dashboard, enabling administrators to view and manage certificates by group. It streamlines certificate oversight, reduces manual effort, and improves compliance tracking across large deployments.

Staggered Device Check-Ins

This update introduces the ability to stagger device check-ins across a defined interval, reducing server load and improving system responsiveness. Administrators can now avoid performance spikes during mass updates, ensuring smoother operations and more accurate real-time data. This feature enhances scalability and reduces infrastructure costs.

DigiCert One Platform Integration

This update introduces native integration with DigiCert ONE, enabling secure certificate provisioning and lifecycle management with the DigiCert ONE platform in SOTI MobiControl. Organizations can now migrate from legacy Symantec integrations to DigiCert’s modern platform without service disruption. This strengthens security, ensures compliance, and reduces operational risk through automated certificate handling.

Cisco ISE v3.0 Integration

SOTI MobiControl now supports Cisco ISE v3.0, enabling secure device authentication with modern features like MAC address randomization and certificate spoofing detection. This integration strengthens security by allowing only compliant devices to gain network access. The update allows organizations to align with Cisco’s latest security standards and reduce manual verification efforts.

Control Triggering of Signal Notifications

This feature introduces state-based alert triggering in Signal policies, ensuring notifications are only sent when a condition changes. Users can now avoid repeated alerts for ongoing issues, reducing noise and improving focus. The update enhances user experience and supports faster, more accurate incident response.

Enhanced Signal Device-Side Evaluation

This feature enables Android devices to locally evaluate multi-condition rules using the 'ALL' operator, without requiring server connection. Devices now independently assess multiple rule conditions at regular intervals, even without connectivity, ensuring continuous policy enforcement. Offloading this logic to devices reduces server traffic, boosts scalability, and ensures faster, more effective device actions.

Monitor SOTI MobiControl System Certificates Using Signal Policies

This update allows administrators to monitor system certificate expirations using Signal policies. Automated alerts can be configured to notify teams before certificates expire, reducing the risk of service interruptions. The feature improves security, compliance, and operational reliability.

Deleted Device History and Audit Report

This feature provides visibility into deleted devices by retaining metadata for up to 90 days and enabling audit reporting. Administrators can now track when and why devices were removed, improving accountability, security, and compliance. The update allows for faster investigations and supports audit readiness.

Compliance Policy Enhancements

Administrators can now define both compliant and non-compliant criteria in compliance policies, offering greater flexibility and clarity. This proactive approach simplifies policy creation, improves enforcement accuracy, and strengthens the organization’s security posture.

Using SOTI MobiControl Root Certificate for Mobile SSO

Administrators can now enable mobile Single Sign-On (SSO) using the built-in SOTI MobiControl Root Certificate, eliminating the need for an external Certificate Authority. This simplifies deployment, reduces infrastructure costs, and accelerates time to value. This feature is especially beneficial for smaller organizations or those in emerging markets seeking secure, scalable authentication without added complexity.

Optimized Event Log Management

Event log management in SOTI MobiControl has been enhanced with server-specific log level controls available through the web console. Administrators can queue updates for offline servers, monitor adjustments in real time, and ensure configurations persist across restarts with options for automatic restoration or time-based resets. These updates improve log management efficiency, reduce upgrade failures, and lower maintenance costs.

Fetch Custom Data on Demand Using APIs

SOTI MobiControl now supports real-time API access to custom device data, allowing administrators to retrieve information on demand. This eliminates delays caused by scheduled data collection and supports faster troubleshooting, automation, and decision-making. 

This update introduces advanced version parsing and comparison capabilities in SOTI Search, enabling accurate filtering and analysis of app and agent versions. Administrators can now use logical operators and custom delimiters to handle diverse version formats. This enhancement improves search accuracy, speeds up queries, and supports better decision-making across large device fleets.

Packages Enhancement – Ability to Use Pre-Existing Scripts

Administrators can now reuse existing scripts when creating packages, eliminating the need to upload them manually. This improves consistency, reduces errors, and accelerates deployment workflows. It also supports centralized script management for better governance.

Modernized User Interface for Windows Classic Enrollment Policy

This update introduces a modernized interface for managing Windows Classic enrollment policies directly within the main SOTI MobiControl console. Administrators can now create, edit, and manage these policies without switching to the legacy console, ensuring a consistent and streamlined experience. This enhancement boosts productivity, reduces errors, and simplifies onboarding by centralizing all enrollment workflows.

Android

Leverage Android 15 Features

Take advantage of the latest Android 15 capabilities across Work Managed, Work Profile and Corporate Owned Personally Enabled (COPE) deployments, ensuring readiness for newer devices in your mobile operations:

  • Disable Assist Content features on unapproved apps to prevent unintentional sharing of sensitive data.
  • Control the creation of private profiles on COPE devices and align with your corporate policy.
  • Restrict users from installing eSIM profiles to prevent unauthorized network connections.
  • Prevent the use of NFC to restrict unauthorized data transfer and device pairing.

Simplify App Management with App Policy

Make use of the new streamlined App Policy interface to quickly discover SOTI ONE and SOTI Snap apps and execute scripts before and after app installations to automate your setup and cleanup tasks.

Streamlined Zebra LifeGuard Workflows

Control your device updates with granular deployment options using Zebra LifeGuard for Android by setting the minimum battery level and charging status, and by allowing the device user to postpone installations for minimal disruption during business operations.

Simplified Microsoft Entra ID Device Registration

Easily re-register Android devices with Microsoft Entra ID without factory resets, and switch registration types from Microsoft User Mode to Microsoft Shared Device Mode seamlessly. 

Apple

New iOS Shared Device Experience

Users can now enjoy a unified login experience through the SOTI MobiControl iOS Agent, which supports both Microsoft SSO and Shared Device functionality, eliminating the need for a separate login app. This modernized approach improves security, simplifies deployment, and enhances user satisfaction with a streamlined, MSAL-compliant interface and restricted agent views.

Enable Custom Attribute Macros

This feature lets administrators dynamically reference custom attributes (e.g., store numbers) within iOS app configurations and profiles. It eliminates the need for multiple app versions by enabling a variable to adapt to different deployment contexts automatically. This streamlines deployment, reduces manual effort, and significantly improves scalability across large device fleets.

Firmware Policy Enhancements

The update allows administrators to enforce precise OS versions and schedule updates at specific local times across iOS, iPadOS, and macOS devices. This ensures consistent device states, minimizes workflow disruptions, and enhances security compliance. By automating update enforcement, IT teams reduce manual workload and maintain operational continuity.

Shared iPad for Business – Google Workspace with ABM Federation

Administrators can now integrate Google Workspace as an identity provider for Apple Business Manager, enabling seamless user authentication and profile assignments. This streamlines identity management, reduces credential complexity, and accelerates device provisioning. The result is a more scalable, automated, and user-friendly shared iPad experience.

Declarative Device Management Enhancement

This update introduces expanded Declarative Device Management (DDM) support, allowing real-time enforcement of a broader range of configurations, such as OS update settings, Disk Management etc., across iOS and macOS . Administrators can now apply updates instantly, automate compliance, and reduce manual intervention. This functionality will empower administrators to boost productivity, enhance security, and ensure consistent policy enforcement.

macOS App, DMG & PKG Metadata Extraction

This feature provides automated metadata extraction for macOS applications, eliminating the need for manual data entry during app uploads. It reduces errors, accelerates policy creation, and aligns macOS workflows with other platforms. IT teams benefit from improved efficiency, fewer support issues, and a more consistent deployment process.

Apple Intelligence Feature Control

SOTI MobiControl now enables administrators to allow or restrict selected Apple Intelligence features on devices for iOS/iPadOS and macOS devices.

Windows Modern

Wallpaper and Screen Saver Management

Administrators now can easily apply corporate wallpapers and screen savers across Windows Modern devices. This supports consistent branding, enhances security through idle-time controls, and simplifies configuration management at scale.

Local User Management – Group Level

Administrators can now manage local users at the group level, enabling bulk actions such as password changes, group assignments, and deletions for individual users or entire local user groups for selected Windows Modern devices. Administrators can also rename a local user for single or multiple devices. This feature streamlines user workflow management, reduces errors, and boosts operational efficiency.

Registry Management – HKCU

SOTI MobiControl now supports registry management for HKEY_CURRENT_USER (HKCU), enabling administrators to configure user-specific settings alongside system-wide configurations. This update simplifies profile deployment, ensures consistency, and reduces support tickets related to user environment issues.

BIOS Management

This feature lets administrators centrally manage supported BIOS settings, including password changes, boot order, and boot order sequence, across supported OEMs such as HP, Dell, Getac, Lenovo and Panasonic. By consolidating BIOS control into SOTI MobiControl, organizations can enhance security, enforce compliance and reduce manual configuration efforts.

Patch Dashboard – CVE Details

Administrators can now view detailed Common Vulnerabilities and Exposures (CVE) information directly within the Patch Dashboard. This functionality empowers administrators to prioritize critical patches based on vulnerability and severity, enhancing risk mitigation and compliance. With improved visibility and reporting, organizations can strengthen their security posture and streamline audit readiness.

SOTI Apps

SOTI VPN Management on Corporate Wi-Fi for Android & iOS

Automatically disable SOTI VPN when devices connect to trusted Wi-Fi networks, then re-enable it when they exit those networks. This smart, context-aware behavior reduces unnecessary data usage, boosts device performance, lowers backend infrastructure costs and strengthens policy enforcement flexibility.

SOTI VPN Analytics with SOTI XSight

Secure your corporate network by identifying destinations accessed by your users while connected to SOTI VPN. SOTI XSight collects user traffic data from SOTI VPN. Time of Day usage is available to ensure authorized destinations are accessed across SOTI VPN servers.

SOTI Surf - Support for Third-Party Proxies

Administrators can now easily configure third-party proxy settings directly within the SOTI Surf browser on Android without requiring the SOTI ERG server. This streamlines proxy setup, reduces infrastructure complexity and allows selective routing of browser traffic. It simplifies deployment and enhances flexibility for organizations with specific network security requirements.

SOTI Surf - Windows Enhancements

The update allows SOTI Surf for Windows to support enterprise-grade features, such as login authentication (LDAP and IDP), download management, tab improvements and ERG integration. These enhancements make SOTI Surf a viable and secure browser option for Windows environments, enabling centralized control and improving adoption across enterprise desktops.

SOTI Surf – Improved Logging Capabilities

This feature provides advanced logging for SOTI Surf, capturing detailed debug information, including errors, downloads and browser events. Administrators can now enable debug-level logging via the SOTI MobiControl web console, significantly improving visibility into browser behavior. This enhancement boosts troubleshooting efficiency and accelerates issue resolution.

Deprecations

Symantec Certificate Authority

In SOTI MobiControl version 2026.0.0, SOTI is deprecating the use of Symantec Certificate Authority (CA). Customers will no longer be able to configure new Symantec CA instances through the SOTI MobiControl web console or APIs, although existing configurations will continue to be visible. Customers are encouraged to migrate to DigiCert CA for a secure and supported certificate management solution. Symantec CA support will be fully removed in a future release of SOTI MobiControl.

Web Console Branding APIs

In SOTI MobiControl version 2026.0.0, the following web console branding REST API’s have been deprecated:

  • API to return branding configuration 
  • API to return login portal logo 
  • API to update branding configuration 

These API’s have been replaced with newly introduced equivalents that offer enhanced functionality and ongoing support. Customers are encouraged to migrate to the new APIs.

Location Tab for Devices and Device Groups

In SOTI MobiControl 2026.0.0, SOTI is deprecating the Location tab, previously accessible via the Device Dashboard for devices and device groups. These location-based features are consolidated under SOTI XSight, providing a unified and enhanced user experience. The only exception is geofences, which have been reintroduced through the Signal policy and Lockdown profiles. Geofences can now be managed directly when creating geofence-related conditions.

APIs

The following REST APIs were introduced in SOTI MobiControl 2026.0.0:

DigiCert One Platform Integration

  • Create a new DigiCert Certification Authority

Web console Branding

  • Return branding configuration
  • Return login portal logo
  • Update branding configuration
  • Delete branding configuration

Windows Classic Enrollment Policies

  • Create new Windows Classic Desktop enrollment policy
  • Get a Windows Classic Desktop enrollment policy
  • Update Windows Classic Desktop enrollment policy
  • Delete Windows Classic Desktop enrollment policy

Resolved Issues

MCMR‑34892 Resolved an issue with the HTTP Strict Transport Security (HSTS) max-age value configuration.
MCMR‑35295 Numeric type custom attributes did not support equal to (=) operator.
MCMR‑35354 Logging out of Microsoft Entra ID using the Shared Device Logout device action did not work in the SOTI MobiControl web Console.
MCMR‑35642 Incorrect Japanese translation for Signal related phrases.
MCMR‑35887 Incorrect Japanese translation.
MCMR‑35935 Android shared device Auto Logout is not logging out the user based on set time.
MCMR‑36181 Unable to enroll devices post-SOTI MobiControl upgrade from 15.4.3.1012 to 15.6.6.1010.
MCMR‑36561 Downloading CSV for devices listing produced blank values.
MCMR‑37066 Using “Uninstall Contents After Profile Revocation/Deletion” option did not retain packages on profile deletion.
MCMR‑37511 SOTI Mobicontrol installer failed to install Signal but showed successful overall.
MCMR‑38261 The Custom Deployment Schedule in the profile was not working in UTC time, but in the server's time zone.
MCMR‑38561 Generating or modifying “Shared Device User” reports failed after SOTI MobiControl upgrade to 2024.x and 2025.x.
MCMR‑38576 Location of multiple devices using the API failed because of a case-sensitivity issue in device IDs.
MCMR‑38856 Exporting a profile with an OEMconfig deleted all spaces between words.
MCMR‑38876 Windows Modern agent upgrade was failing and caused Windows Sync to fail.
MCMR‑38896 Devices were out of sync with time/date/year.
MCMR‑39108 Multiple registration token requests were sent to the SOTI MobiControl server from Microsoft Authenticator.
MCMR‑39200 Profiles were stuck on a “Pending Install” state.
MCMR‑39366 The Out of Contact report was duplicating header columns when generating a .csv file.
MCMR‑39440 After a Windows Modern agent upgrade, the App Catalog showed the error “An Unhandled exception occurred.”
MCMR‑39492 Implement Sync capability to Microsoft Entra ID Device Registration Status for Android devices.
MCMR‑39743 Terms & Conditions under Shared Devices was unresponsive.
MCMR‑39786 Incomplete details when generating device information reports.
MCMR‑39793 With an enabled location Group Policy Object (GPO), the agent could not communicate with the Deployment Server for Windows 11 24H2 devices.
MCMR‑39967 Installation failed during database upgrade while deploying the MobiControlDB DACPAC and registering database metadata.
MCMR‑40045 Compliant devices were being relocated by signal policies, despite conditions not being met.
MCMR‑40198 Resolved UI issue in Custom Attributes.
MCMR‑40382 Windows Modern devices were showing offline after an upgrade on the SOTI MobiControl web console.
MCMR‑40399 SOTI MobiControl agent crashed or disconnected when the device action "Sync Files Now" is used with SOTI XtremeHub.
MCMR‑40445 Viewing large count of policies took ~1 min.
MCMR‑40465 VPP Token was stuck in the “Saving” state.
MCMR‑40496 Compliance Status was being wrongly declared false.
MCMR‑40583 An assignment error occurred when updating a macOS default App Policy.
MCMR‑40765 Applications were not updating automatically using App Policy.