IBM Security MaaS360

 View Only
  • 1.  Is moving to Android Enterprise reqd for Samsung Device Administrator managed devices?

    Posted Tue May 26, 2020 09:57 AM
    Hi!

    We are currently managing iPhones and Samsung devices with MaaS360, more or less just enforcing the use of a passcode and setting up access to corporate mail through ActiveSync.

    Android Enterprise is currently not configured, and if I check 'Container Type' of actively managed Samsung devices it says 'Samsung Device Administrator'. On the other hand, inactive devices and devices in 'Pending Control Removal' state show up with 'Container Type' equal 'Device Administrator'.

    Customer is planning on enrolling new Samsung devices, and a few of the Samsung devices are already version 10.

    Is moving to Android Enterprise required in order to manage this customer's Samsung devices?

    What if customer wants to implement MaaS360 Secure Mail and Secure Browser, will that be supported or will you have to move to Android Enterprise for that type of functionality?

    ------------------------------
    Arne Halsteinslid
    ------------------------------


  • 2.  RE: Is moving to Android Enterprise reqd for Samsung Device Administrator managed devices?
    Best Answer

    Posted Wed May 27, 2020 01:35 AM
    Hi Arne,

    See  Device Admin policy features that will no longer be supported on Android 10+ with MaaS360 app version 7.10

    Moving forward....
    •DA Enrollments will continue to work, but there are no workarounds for the above restrictions, other than migrating to an Android Enterprise scenario. KME enrollments will continue to work as well.
    •New Customers will need to setup Android Enterprise without which Android Enrollments will not proceed.
    •Already enrolled DA devices will continue to work, however, the devices will lose API functionalities on upgrade to 10/Target.

    Make your move to Android Enterprise with MaaS360: Checklists, Resources, and Webinar

    Let me know if this helped.



    ------------------------------
    ETHAN
    ------------------------------



  • 3.  RE: Is moving to Android Enterprise reqd for Samsung Device Administrator managed devices?

    Posted Wed May 27, 2020 02:10 AM
    Thank you Ethan for your answer!

    The reason for asking this question is the fact that the devices show up as 'Samsung Device Administrator' managed, not 'Device Administrator' managed, which is a bit confusing.

    Does this mean the Samsung specific policies (SAFE) will continue to work while everything else on the list will not?

    From what I understand, moving to Android Enterprise will also be required in order to enroll new Samsung devices into MaaS360 management, is this correct?

    ------------------------------
    Arne Halsteinslid
    ------------------------------



  • 4.  RE: Is moving to Android Enterprise reqd for Samsung Device Administrator managed devices?

    Posted Wed May 27, 2020 04:51 AM
    Edited by Eamonn O'Mahony Wed May 27, 2020 04:51 AM
    Hi Arne
    Effectively there are features in Android 10 that you will no longer be able to control if you do not move to Android Enterprise, these restrictions will grow over time so it is best if you migrate when possible. 
    I recommend you start with https://www.securitylearningacademy.com where there is a lot of training content regarding AE. 
    Samsung's general position is that if they sell a device with OS level X then they will  allow upgrades to X+2. 
    This means that far back as devices with Android 8 should be able to upgrade to Android 10, meaning that a lot of your existing enrolled devices may be upgraded, in which case you will lose a number of control capabilities. 
    Migration options are also discussed on the AE content we provide meaning that for a specific use case (Profile Owner), you could do a migration from existing Device Admin enrollment. 
    Best

    ------------------------------
    Eamonn O'Mahony
    Technical Account Manager
    IBM Ireland
    Dublin
    ------------------------------



  • 5.  RE: Is moving to Android Enterprise reqd for Samsung Device Administrator managed devices?

    IBM Champion
    Posted Wed May 27, 2020 07:05 AM
    I can respond to one part of your post, based on some painful experiences:   It really is a best practice to enroll devices using Android for work/Android Enterprise immediately. 

    Google is actively depracating api's in addition to functionality tied to the old "Device Administrator" and you are only postponing the inevitable by delaying the use of Android Enterprise. 

    We have a number of customers who did not do this.  Many have definitive requirements for the "Device Owner" Profile functionality delivered in MaaS and had to fully factory reset devices deployed in the field.  Not pretty.  Others chose to deploy using "Work Profile" to avoid the dreaded wipe requirement but had to give up certain security requirements as a result.  Better to have newly deployed devices enrolled using AE out of the box than have to deal with this later, as well. 

    Our experience is such also, that because the original testing of AE was done on GOOGLE Pixels using a clean Android 10 o/s, other challenges arise as you attempt to manage other Android Vendor devices.  Samsung is consistent however because the o/s i s open source to all, every Android vendor's tweaks to the o/s cause inconsistencies in functionality.  MDM's make all best efforts to accommodate but it is a moving target.  We advise our customers to standardize on Samsung to minimize the pain. 

    Bottom line, don't wait.   Google is trying to replicate Apple's long standing method of delivering a consistent security/enrollment process with the o/s with the goal of leveling the field for all Android Device Vendors, but have a long way to go still.

    ------------------------------
    Mitch Lauer
    ConnecTel Wireless
    Pittsburgh, PA
    412-339-5765
    mlauer@ConnecTelWireless.com
    ------------------------------



  • 6.  RE: Is moving to Android Enterprise reqd for Samsung Device Administrator managed devices?

    Posted Wed May 27, 2020 07:37 AM
    Thank you all for some very valuable advice!

    No doubt moving to AE ASAP is the way to go.

    ------------------------------
    Arne Halsteinslid
    ------------------------------