IBM Security MaaS360

 View Only
  • 1.  Unlocking locked device

    Posted Thu July 25, 2019 04:29 AM
    I have locked a device from within the MaaS360 admin portal via:

    devices > inventory > 'view' the device > more (drop-down) > lock

    This has worked as expected, but I can't find an option to unlock the device again.  Is this by design or am I missing something?
    If it is by design, what do I do next - a full wipe of the device and reconfigure it again from scratch?

    ------------------------------
    Darren Cook
    ------------------------------


  • 2.  RE: Unlocking locked device

    Posted Thu July 25, 2019 10:30 AM

    Hi Darren - 

    The behavior here varies from device to device but there isn't an "unlock" command from the portal.  Generally the device gets unlocked using whatever the passcode on the device was.  If the reset passcode command was used on Android, the admin could define the new passcode depending on management style and OS version.  If it's a Mac device there is actually an unlock code that gets issued - if you don't have it, look in the device history and it should be listed there.

    Let me know if that answers the question



    ------------------------------
    Matt Shaver
    System Architect
    IBM
    mshaver@us.ibm.com
    ------------------------------



  • 3.  RE: Unlocking locked device

    Posted Thu July 25, 2019 10:44 AM
    Hi Matt,

    thanks for replying.  Fair enough, I couldn't find any way to enter the passcode and unlock the device (iPhone) again - I'll treat the 'lock' function as a 'device will need wiping & rebuilding if returned' option!

    Thanks again for your help,

    Darren.

    ------------------------------
    Darren Cook
    ------------------------------



  • 4.  RE: Unlocking locked device

    Posted Thu July 25, 2019 11:11 AM
    Pressing the home button (or swiping up) should present the option to unlock - unless the device is marked as lost.  Lost mode will lock and not give the user an ability to unlock.  In the portal the "Mark as Lost" option will change to "Mark as Found"  If the device is not "lost" but locked and no passcode option appears, I would try clearing passcode and just tap the home button to get back in to the device.  You shouldn't have to wipe the device to get back in except in very specific scenarios (most of which center around loss of network connectivity)

    ------------------------------
    Matt Shaver
    System Architect
    IBM
    mshaver@us.ibm.com
    ------------------------------



  • 5.  RE: Unlocking locked device

    Posted Fri July 26, 2019 04:49 AM
    I've wiped and re-configured the device now, but pressing the home button showed a screen with a message (set in the admin portal at time of applying the lock) and a single green 'Call' button that auto-dialled a predefined number (our company phone No).  I could not find any option to enter a PIN/code.
    Anyway, this is preferable to having an unlocked/unsecured phone if one gets lost/stolen, and I'll try clearing the passcode etc. if this happens again.

    Thanks for all your help :)

    ------------------------------
    Darren Cook
    ------------------------------



  • 6.  RE: Unlocking locked device

    Posted Wed March 11, 2020 12:36 PM
    Hello Matt, 

    I have a user who's Apple ipad cannot connect to WiFi for me to reset the passcode.The history only shows a passcode from 6 months ago and not the current one. The user changed the passcode when prompted on our 120 day policy, but cannot remember it. Has anything changed where we maybe can use a specific bypass code that is located in the portal to get past the lock screen? Just thought I'd ask to save the user's data. She's on the last try before wipe and the device is currently inactive on MaaS360. 

    Thanks in Advance! 

    Jason

    ------------------------------
    Jason Sparling
    ------------------------------



  • 7.  RE: Unlocking locked device

    Posted Wed March 11, 2020 03:13 PM
    Hi Jason,

    To my knowledge Apple doesn't give MDMs the ability to cache a secure override key locally on the device in scenarios where connectivity is lost.  The only option I can think of is that you might try finding an ethernet adapter for the iPad and tethering it to a physical network.  This should allow the device to receive MDM commands, including the remove passcode command.

    ------------------------------
    Matt Shaver
    System Architect
    IBM
    mshaver@us.ibm.com
    ------------------------------