SOTI MobiControl

2025.0

·

Build 1032

·

October 29, 2024

Note:

SOTI MobiControl 2025.0 Build 1032 replaces the previous build(1031) posted on October 28, 2024.

Release Highlights

SOTI VPN for Android Enterprise & Windows Modern

SOTI VPN is an all-new secure tunnel that is simple to configure from the convenience of the SOTI MobiControl console. It has been specially designed for front-line worker use cases, providing them with a seamless user experience that requires no additional steps to initiate the VPN connection or provide authentication credentials, it’s all automated. On Android and Windows, SOTI VPN can be used to tunnel all device network traffic or traffic destined for specific IP ranges. Additionally, on Android, per-App VPN can be used to focus the VPN tunneling capability to only select apps.

Note:

SOTI VPN functionality is only available to customers who subscribe to SOTI Premium Plus or Enterprise Plus Service. 

Samsung Knox E-FOTA Policy

Administrators can now control Android operating system updates for their Samsung Knox devices using the Samsung Knox E-FOTA policy within SOTI MobiControl. With this single pane of glass experience, administrators can effortlessly ensure all their Samsung Knox devices are on the exact firmware version they need for reliable business operations. This centralized management approach simplifies the upgrade process and provides greater oversight and control over the device fleet.

Apps Dashboard

The Apps Dashboard centralizes app workflows, providing a consolidated view of app-related information with real-time status updates across devices. It simplifies the management of app configurations and policies, ensuring consistent deployment. The new one-click retry feature for failed installations further streamlines the process, minimizing downtime and simplifying issue resolution.

Certificates Dashboard

SOTI MobiControl administrators can now have a holistic overview of all their certificates in SOTI MobiControl. The Certificates Dashboard is engineered to streamline the tracking, monitoring, and management of device certificates in MobiControl. Not only does it enhance process efficiency, but it also eliminates renewal-related frustrations and proactively minimizes the risk of unnoticed renewal failures, ensuring smooth, uninterrupted device operation.

Enhanced Installer Experience

This update introduces a modern and intuitive user interface for the SOTI MobiControl installer, providing customers with clearer visibility of missing prerequisites and direct links for installation, streamlining the setup process. The enhanced installer also enables silent installations, reducing user interaction time and improving overall efficiency.

SOTI XSight Live View Device Action

You can now start a SOTI XSight Live View (Patent Pending) session directly from the SOTI MobiControl Devices Dashboard. The Live View device action provides real-time location and critical business insights for the selected devices in SOTI XSight Live View. This feature can be used for a single device, multiple devices, or a device group.

Profile Installation Priority

Users can now streamline profile deployment by assigning installation priorities, ensuring profiles are installed in a specific order on Android devices. If a high-priority profile fails, users can halt lower-priority installations automatically. This reduces the need for workarounds and minimizes human error during device staging, while improving standardization, traceability, and predictability in the provisioning process. This feature is supported only on Android agent 2025.0.0.

iOS & iPadOS Declarative Device Management

Declarative Device Management (DDM) configurations, activations and assets allow devices to react to state changes and apply management security policies without connecting to the SOTI MobiControl server.

Streamline Wi-Fi and Kiosk Mode Configurations for ChromeOS

Administrators can now efficiently configure Wi-Fi and Kiosk Mode settings for ChromeOS devices without requiring the Google Admin console, ensuring seamless connectivity, enhanced security and customized device experiences.

Enhanced Native Lockdown on Windows Modern

Administrators can now configure apps to run in Single-App mode, restricting user access to only essential business-critical applications. Device inactivity settings are customizable, enabling the display of digital signage content during idle periods. Additionally, enhanced CTRL+ALT+DEL options for improved administrators control and dark mode capabilities in native lockdown are now available.

Streamlined Windows Updates Control & Bandwidth Optimization

Introducing streamlined Windows Update management with bulk update approvals, a centralized view, and delivery optimization for faster update downloads. These enhancements reduce administrators' time and costs while, optimizing bandwidth usage.

New Features and Improvements

System Administration

Ability to Export and Import File Sync Policies

Administrators can now export File Sync policies from one SOTI MobiControl environment and import them into another. This feature facilitates the quick transfer of File Sync policies across multiple environments, reducing the need for repetitive manual copying and lowering the risk of human error.

Cloning File Sync Policies

Administrators can now clone file sync policies, making it easier and faster to replicate existing configurations across your organization. This new feature streamlines policy management by allowing you to create identical copies of your file sync policies with just a few clicks, ensuring consistency and saving time when setting up or modifying policies.

SOTI Identity Conditional Access Action in Compliance Policy

Compliance Policy’s new SOTI Identity Compliance Access action can be used to limit the third-party applications which users may access via SOTI Identity. This action is to be used in conjunction with SOTI Identity’s Secure Access Control policy.

Share Assignment Filters for Profiles & Policies

Administrators can now save and share assignment filters for easy reuse across multiple profiles and policies. Filters can be named, edited, and deleted, reducing the time spent on repetitive tasks and improving accuracy in filter application.

Microsoft Entra ID Support for Shared Devices for Android and iOS Microsoft Entra ID Support for Shared Devices for Android and iOS

Administrators can now directly configure Shared Devices to use an Entra ID directory. There is no longer the need for the additional configuration of an Entra ID (formerly Azure AD) identity provider (IdP) which acted as an intermediatory interface. This simplifies the configuration experience for administrators and also optimizes the real-time authentication experience for mobile device users.

Execute Script upon Shared Device Logout

This feature lets SOTI MobiControl administrators configure scripts that automatically run when a device user logs out from a shared device. Administrators can delete leftover documents and app-specific logs to protect user privacy and streamline troubleshooting.

Active Remote-Control Session Indicator

This feature gives users a visual indicator in the web console when a remote-control session is active on a device. Users can also see the duration of the session and identify who initiated it, enhancing the auditing process for administrators.

Support for Additional Signal Device Actions

Signal now supports the following device actions when a policy is triggered: blocking Exchange access, allowing/blocking SOTI Hub access, clearing SOTI Hub’s cache, and logging out Shared Devices.

Support for Outdoor Geofence in Signal Policies

Automated actions from Signal, such as relocating a device or triggering an alert, are now supported based on device’s entry or exit of an outdoor geofence.

Support for Cloud Link Agent Properties in Signal Policies

Administrators can monitor the status of their Cloud Link Agents using Signal Policies, allowing administrators to configure automated actions whenever a Cloud Link Agent related event occurs. This feature eliminates the need to manually monitor the health of Cloud Link Agents, which can lead to faster issue discovery and resolution.

Ability to Unenroll Associated Devices when an Active Directory User is Disabled

Administrators can now configure automated device actions of “unenroll device” or “disable device” whenever the assigned user is in a disabled state. This only applies to users belonging to Microsoft Active Directory. This setting can be configured in enrollment policies when the directory authentication is selected.

Bulk Deletion of Packages

Administrators can now perform bulk deletions of packages via the web console. This feature enables efficient removal of multiple unused or outdated packages at once, streamlining system maintenance.

Database Monitoring and Notifications for SQL Express

This update introduces real-time monitoring of SOTI MobiControl's database size, specifically for environments using SQL Express, to effectively manage the 10 GB size limit. SOTI MobiControl now provides proactive notifications when the database reaches a preset threshold of 90%. These notifications enable administrators to take timely action, preventing unexpected failures and reducing potential downtime.

Ability to Manage Device Scripts from Signal Policies

When configuring a Signal Policy's send script action, users can now access Script Manager. This feature enables efficient management of script operations, including adding, deleting, and modifying device scripts across various types supported in SOTI MobiControl, such as JavaScript, Legacy Script, PowerShell, and more. This streamlined process saves time and lets users perform these tasks seamlessly during Signal Policy configuration.

Support for Microsoft SQL Server 2022

SOTI MobiControl now supports Microsoft SQL Server 2022, enhancing security for enterprise customers. This update ensures IT policy compliance, reduces security vulnerabilities, and allows customers to utilize the latest SQL Server features.

Filter Profiles and Policies based on ‘Device Kind’

Administrators can now filter profiles, enrollment policies, and app policies by device type for more precise results, improving operational efficiency.

Custom Attribute Sorting in Device Details

Administrators can now sort Custom Attributes in ascending or descending order within Device Details, streamlining data organization and improving workflow efficiency.

Android Enterprise

Dynamic Admin Password

Administrators can now share to their device users a device-specific, one-time password generated by SOTI MobiControl to enter administrator mode on the Android agent. Once used, MobiControl automatically regenerates the device-specific administrator password, ensuring security and ease of use. This enhancement provides a secure and efficient way to allow administrative access on devices, improving overall device management and control.

Execute Scripts for Inactive Devices

Administrators can execute legacy scripts when a device is inactive via the Device Inactivity payload. This allows administrative scripts to be executed only when the device is idle and avoids mobile worker disruption.

Restrict Android MAC Randomization in Wi-Fi Profiles

Administrators can now disable Media Access Control (MAC) address from being randomized for a specific Wi-Fi Service Set Identifier (SSID) via the Wi-Fi payload in profiles. This allows devices to retain a static MAC address which a Network administrator can use to allow access to corporate Wi-Fi networks.

Import & Export Managed App Configurations for Android Apps

When configuring your Managed App settings, simply fill in the required fields and export the configuration. This allows you to easily apply the Managed App configuration to another App Policy targeting the same app.

Android Device Authentication per Shared Device User Session

Administrators can now enforce a unique 4 to 16-digit Android OS Personal Identification Number (PIN) requirement for their shared device users, ensuring devices are secured before completing the login process., This action maintains IT security policies while protecting the mobile worker’s data with a personalized PIN.

Enhanced Scripting Console for JavaScript Scripting

Administrators can now view suggestions for new namespaces and functions as they type their JavaScript script just as they would in an IDE (integrated developer environment). In addition, errors will be highlighted allowing the user to troubleshoot their scripts.

SOTI MobiControl Companion*

Administrators can now use the SOTI MobiControl Companion, an enterprise app that supports devices enrolled through Google's Android Management API (AMAPI) to provide a range of features that extend beyond the native AMAPI capabilities. These include Remote View, File Sync policy, Out of Contact management, and many more. This is applicable only for Android devices enrolled as Android Enterprise Work Profile and Corporate Personal via AMAPI.

Note:

SOTI MobiControl Companion requires SOTI MobiControl Server 2025.0.0 or later. SOTI MobiControl Companion will be released on the Google Play Store soon. 

iOS

Feature Control Profile Redesigned

Quickly search and navigate to over 90 Feature Control settings available in the profile.

5G Network Slicing

Assign specific network slices to managed apps on a carrier's 5G Standalone (SA) network. This ensures that all traffic for a designated managed app are routed to the slice identified by a specified Data Network Name (DNN) or App Category, which can be obtained from your carrier provider. Additionally, you can now enforce your iOS device to use mobile data.

Return to Service

Automatically reset the device, erase data, connect to Wi-Fi, and enroll in SOTI MobiControl.

Schedule App Policy Updates by Time and Day

As part of the App Policy, select the day and time for app updates to occur.

Advanced Configurations - Accessibility Settings

As part of Apple Advanced Configurations, administrators can now configure accessibility settings for their iOS devices.

iPadOS

User Targeting for Shared iPad

Restrict access to Shared iPad for Business devices to authenticated users only.

Advanced Configurations - Accessibility Settings

As part of Apple Advanced Configurations, administrators can now configure accessibility settings for their iPadOS devices. In addition to device assignment, you can assign this configuration to Shared iPad users as well.

macOS

Local User Account Setup During Automatic Device Enrollment

Create a managed administrator user account to enable zero-touch deployment for improved security and access to system settings and data.

Support for IKEv2

IKEv2 provides more efficient, advanced encryption and enhanced security protocols to establish a secure, encrypted VPN connection.

Platform Single Sign-On

End-users can sign in at the macOS login window, which will automatically authenticate them with the corporate Identity Provider and sign the user into apps and websites.

tvOS

Application Management

Automatically deploy and manage App Store applications with VPP support and Enterprise Applications for tvOS devices.

Windows Modern

App Policy Improvements – Microsoft Store & EXE Integration

You can now deploy Microsoft Store and .exe apps through the Windows Modern app policy. The improved user interface ensures a seamless and efficient app deployment experience.

App Catalog Support

New app catalog has been introduced, allowing users to view and install suggested apps while distinguishing between mandatory and optional ones. Administrators can now manage app visibility to ensure compliance and security.

Application Listing Improvements

Administrators can now remove apps from the app listing, block non-administrator users from installing apps, and view a complete list of installed applications. The app status system has been enhanced with a new "Failed" status for Windows Modern devices.

Lockdown Preview

Administrators can now preview configured Lockdown device screens directly from the web console, allowing for verification and accuracy checks before deployment.

Search for Health Attestation Attributes

Health attestation attributes are now available as search parameters in SOTI Search, allowing for more precise filtering and management of device security and compliance.

Real-time Logged-in User Visibility for Windows Modern Devices

Administrators can now view current logged-in user details on Windows Modern devices in real time on SOTI MobiControl web console, improving security and operational efficiency.

Local User Management for Windows Devices

Administrators can now create local users, define group memberships (Standard or Administrator), manage passwords and delete accounts on Windows Modern devices through the SOTI MobiControl web console, streamlining security and user management.

Enhanced Single App Kiosk Mode for Windows Devices

Administrators can now configure Microsoft Single-App Kiosk Mode with an improved UI, the ability to select from available applications, support for Microsoft Edge in digital signage, enhancing productivity and simplifying kiosk setup.

Microsoft Edge Browser Management for Windows Devices

Administrators can now control Microsoft Edge browser settings on managed devices via SOTI MobiControl, including password manager, allow/block lists, incognito mode, and homepage settings, enhancing security and governance.

Optimized Device Re-enrollment Process

After a Windows Modern device is re-imaged or reset, SOTI MobiControl checks device identifiers based on settings defined in Global Settings. If the criteria are met, a new device entry is not created, preventing duplicates and conserving licenses.

Device Reboot Management

Administrators can now manage and schedule device reboots, ensuring that security policies and configuration changes take effect promptly. This enhances device functionality and reduces the need for manual intervention.

Enhanced Defender Antivirus Management

Administrators now have a dedicated payload for Defender Antivirus, providing improved visibility and granular control over configurations. This update reduces security risks, ensures compliance, and streamlines antivirus management.

SOTI Surf

SOTI Surf for Windows

Administrators can now deploy SOTI Surf on Windows devices, providing a customized, secure and tailored browser experience on Windows Modern devices (versions 10 and 11) via a Windows SOTI MobiControl profile.

SOTI Surf Integration with SOTI XSight

Administrators can now enable a toggle from the SOTI MobiControl web console for Android Classic and Enterprise to collect browsing data, including web visits and errors. The collected data is accessible in SOTI XSight dashboards.

SOTI Hub

Access Content Library via SOTI Hub

SOTI Hub can now be used to access the files that are hosted in MobiControl’s Content Library. Content Library serves as a simple and convenient document repository for both on-premises and cloud customers for Android and iOS devices. By being built-in to MobiControl, administrators don’t have to worry about the complexities large scale document systems like Microsoft SharePoint, which is ideal when they have relatively few documents that need to be made available to MobiControl managed mobile devices.

Deprecations

Deprecation of Zebra Printers from SOTI MobiControl

Starting with SOTI MobiControl 2025.0.0, management and support for Zebra printers will be transitioned from SOTI MobiControl to SOTI Connect. For more details about this transition, please refer to the article here 

Deprecation of Windows Phone, Windows HoloLens

Starting with SOTI MobiControl 2025.0.0, the option to enroll Windows Phone and Windows HoloLens devices has been removed.

Deprecation of Windows Modern Enterprise App Deployment

Starting with SOTI MobiControl 2025.0.0, we are ending support for the enterprise app option within the Windows Modern app policy. Users will no longer be able to upload XAP file formats and cannot see or setup Enterprise app configurations under Global Settings.

Deprecation of Alert Rules

Starting with SOTI MobiControl 2025.0.0, Alert rules are deprecated. Upon upgrade from an earlier release version to 2025.0 pre-existing Alert Rules will be automatically converted to Signal Policies. After the upgrade, Administrators will receive an in-product notification with details of the conversion. Successfully converted policies appear in the Signal policies section. It is important to note that the converted policies will be initially disabled. Administrators must review and enable these policies for them to take effect.

Migration of Content Library

The administrative interface of Content Library, MobiControl’s built-in document repository, has been migrated from the web console’s legacy user interface to the modern interface. The configuration of document distribution to devices, which used to be performed via Content Library Policies, is now performed via the SOTI Hub profile payload. Device users who previously access the Content Library documents via the MobiControl Agent will now do so via the SOTI Hub app on Android and iOS devices.

Resolved Issues

MCMR‑34255 SOTI Surf catalog not loading with Wi-Fi toggle enabled, and disconnected from network
MCMR‑34262 Incorrect SIM card status logs in device and deployment server logs
MCMR‑34534 Device group selection for similar names during assignment
MCMR‑34859 Content Security Policy (CSP) not implemented, exposing to vulnerabilities
MCMR‑34861  Cookie not marked as secure and transmitted over https
MCMR‑35061 Devices not retrieving packages/files after Xtreme Hub relocation to another group
MCMR‑35200 Inconsistency in Managed App Config for enterprise apps Wireguard, and tunnel configurations for JYSK
MCMR‑35208 Web console resets when the word "API" is searched in profile granular permissions
MCMR‑35202 MCMR‑35348 Unable to build Windows CE/ Mobile agent in SOTI MobiControl 2024.0.0
MCMR‑35476  Data type value is not displayed in the log maintenance screen after upgrade from 15.6.5 to 2024.0.1
MCMR‑35516 User able to make JSON changes and exit the Lockdown in Linux
MCMR‑35562 Re-installation of an older version of an application, when a macOS device has a newer version
MCMR‑35604 Unable to drag device folders into other folders with a custom port configured for management service host
MCMR‑35666 SOTI Hub crashing on iOS devices
MCMR‑35757 Users not having Delete but Manage Groups permissions able to delete devices
MCMR‑35786 Syslog messages not being sent to the SOTI MobiControl server due to TLS 1.2 incompatibility
MCMR‑35891 Hostname appears as an IP address on Linux devices
MCMR‑35923 Performance issues on management server, slowness on deployment servers
MCMR‑36025 Device location history shows up if only automatic is selected on web console
MCMR‑36201 Inability to delete any device groups having zero devices and no profiles assigned
MCMR‑36250 SOTI Surf not launching the camera directly, after navigating to an internal URL
MCMR‑36293 Wi-Fi MAC address information not displayed on the device details page after a device reboot
MCMR‑36440 Certificates are only pushed and not installed on Linux
MCMR‑36443 SOTI Surf is incorrectly handling links when more than 10 websites exist per folder and more than 10 folders are present
MCMR‑36616 Unable to upload iOS font files larger than 2 MB
MCMR‑36791 Sending statistics to SOTI Services is failing on several MobiControl instances
MCMR‑36833 Downloaded CSV files are appearing empty
MCMR‑37120 Unable to delete File Sync policy having custom post-sync script
MCMR‑37159 Action buttons missing in the column view
MCMR‑37200 Package V2 API failing to upload a package having 4 or more periods or hyphens in the version
MCMR‑37255 Inaccurate Out of Contact report showing connected devices
MCMR‑37390 Inaccurate information in device connectivity activity report
MCMR‑37440 CSV file showing incorrect or empty Custom Attributes data

APIs

Update Package Version in Profile(s)

  • API to bulk update package version in profile(s)

Enrollment Policies

  • API to get all enrollment policies
  • API to download Enrollment Policies Summary listing
  • API to download Enrolled Device Summary listing
  • API to email Enrollment Policies Summary listing
  • API to email Enrolled Device Summary listing
  • API to update an action in selected enrollment policy
  • API to return the count of information, warnings and errors
  • API to return the list of enrollment policy logs
  • API to return the list of enrolled devices using a specific policy
  • API to return the list of enrolled devices count and pagination watermark using specific policy
  • API to return the list of all enrollment policies for a specific device group
  • API to download VPN Server Agent Installer file

Linux Enrollment Policies

  • API to delete the Linux enrollment policies
  • API to return the Linux enrollment policy details
  • API to update the specified Linux enrollment policy
  • API to create a new Linux enrollment policy
  • API to return the Linux enrollment policy INI config file
  • API to email Linux enrollment policy details
  • API to return the Linux enrollment policy Agent Installer

Android Enrollment Policies

  • API to create new Android enrollment policy
  • API to update and existing enrollment policy
  • API to delete an existing Android enrollment policy
  • API to return the Android enrollment policy details
  • API to email enrollment policy details
  • API to return the policy enrollment INI config file
  • API to return Android agent APK file
  • API to publish or update Android enrollment policy

iOS Enrollment Policies

  • API to create a new iOS Enrollment Policy
  • API to returns the details of specified iOS enrollment policy
  • API to delete the specified iOS enrollment policy
  • API to update the specified iOS enrollment policy
  • API to get SVG data for QR code configuration
  • API to email specified iOS enrollment Policy details
  • API to updates the specified iOS enrollment policy profile

macOS Enrollment Policies

  • API to create a new macOS enrollment policy
  • API to update the specified macOS enrollment policy
  • API to return the details of specified macOS enrollment policy
  • API to delete the specified macOS enrollment policy
  • API to update the specific macOS enrollment profile
  • API to email specific macOS enrollment policy details

Windows Modern Enrollment Policies

  • API to return the Windows Modern enrollment policy details
  • API to create a new Windows Modern enrollment policy
  • API to update the specified Windows Modern enrollment policy
  • API to delete the Windows Modern enrollment policy
  • API to download the Windows Enrollment provisioning package

Windows Local User Management

  • API to get the list of all local users on a Windows Modern device
  • API to return auto-generated password of a local user created using SOTI MobiControl

Windows Modern Update Management

  • API to return pending updates for a list of device IDs
  • API to return pending updates for a device group, including subgroups

Windows Modern Logged-in User

  • API to return details of a user logged into a Windows Modern device

Windows Classic Enrollment Policies

  • API to create new Windows Classic VPN Server enrollment policy
  • API to get a Windows Classic VPN Server enrollment policy
  • API to update Windows Classic VPN Server enrollment policy
  • API to Delete Windows Classic VPN Server enrollment policy

Dynamic Admin Password

  • API to decrypt the dynamically created admin password

Samsung Knox E-FOTA Policy

  • API to prepare the sign in URL for Samsung Knox E-FOTA
  • API to sync registration details between Samsung Knox E-FOTA and SOTI MobiControl
  • API to log user out of Samsung Knox E-FOTA from SOTI MobiControl
  • API to get the SOTI MobiControl device summary for Samsung Knox E-FOTA
  • API to get Samsung Knox E-FOTA license details
  • API to sync license information between Samsung Knox E-FOTA and SOTI MobiControl
  • API to delete Samsung Knox E-FOTA license
  • API to auto upload devices to Samsung Knox E-FOTA
  • API to get list of applicable Samsung Knox E-FOTA enrolled devices
  • API to get list of assigned devices
  • API to download and email the device report for a specific Samsung Knox E-FOTA policy
  • API to get the policy schema from Samsung
  • API to get the get the count of number of Samsung Knox E-FOTA policies
  • API to create, edit, delete and cancel the Samsung Knox E-FOTA policy
  • API to retrieve the list of Samsung Knox E-FOTA policy
  • API to get the specific Samsung Knox E-FOTA policy details
  • API to download and email Samsung Knox E-FOTA policy
  • API to get the Samsung Knox E-FOTA policy logs
  • API to retrieve the firmware for the Samsung Knox E-FOTA policy
  • API to retrieve the firmware version
  • API to assign the firmware to the Samsung device
  • API to assign the firmware to the device
  • API to get the assignment summary
  • API to save and receive webhooks notification configuration

Content Library in SOTI Hub

  • API to update and retrieve the root folder name and path for Content Library
  • API to upload and download files and folders from Content Library
  • API to retrieve and delete files and folders from Content Library
  • API to update a file to a newer version and make any version as the latest
  • API to check for existing files and filenames
  • API to add and search categories in Content Library
  • API to upload and delete categories in Content Library
  • API to move content from one folder to another
  • API to update metadata for a file or folder
  • API to get the summary of Content Library categories
  • API to get file references attached to the profile