MobiControl v14.4.3 Release Notes

14.4.3 Build 1153 (September 17, 2019)

MD5 Checksum: 1f4f95aae76239db80b14359da417713

Upgrade Observations

  • The SOTI MobiControl installer will warn on upgrade if it detects Profiles with the Webroot powered "Web Filter" and/or "Antivirus" device configurations. Future upgrades will not be allowed unless all "Web Filter" configurations are transitioned to "SOTI Surf", and all Android Plus device agents are upgraded to v13.5 or higher to continue support for Antivirus.

Features and Improvements

SOTI MobiControl v14.4.3 focuses on providing support for new EMM functionality introduced in iOS 13+.

User Enrollment

User Enrollment is a new type of MDM/EMM enrollment designed for BYOD. It secures company apps and accounts, while keeping the employee’s personal information private. EMM servers no longer get identifiable information about the employee’s personal apps or device. User Enrollment also creates a cryptographically isolated managed volume that keeps work accounts and apps separate and secure from personal accounts and apps. When the employee or IT administrator unenrolls the device, the managed volume and associated cryptographic keys are destroyed, ensuring no trace of company data, apps or passwords remain on the device. User enrollment requires the use of Managed Apple IDs, which are different from personal Apple IDs but co-exist with them. User enrollment requires iOS 13.1.

Customized Enrollment

Automated Device Enrollment (formerly, DEP Enrollment) has been a core feature for businesses to help expedite their staging process for Apple devices using Apple Business Manager with SOTI MobiControl. Starting with iOS 13, the enrollment process is now fully customizable. Using SOTI MobiControl, the user can be presented with a login webpage or be re-directed to an Identity Provider (IdP) for authentication. Once the user is authenticated, they can be presented with Terms and Conditions that they must accept before completing enrollment. Additionally, with iOS 13, DEP devices are always supervised, and enrollment is always mandatory.

Managed Associated Domains

Managed iOS apps can be associated with domains to provide support for new Single Sign On functionality introduced in iOS 13.

Profile Configurations

The Single App Mode profile configuration has been updated to support new configurations introduced in iOS 13:

  • Voice Control

New restrictions added in iOS 13 are reflected in the Restrictions profile configuration:

  • Disable Continuous Path Keyboard
  • Disable Wi-Fi Modification
  • Disable Find My Device
  • Disable Find My Friends

Starting with iOS 13, the following restrictions, which previously did not require supervision, now require supervision:

  • Disable Find My Friends App Modification
  • Disable Addition of Game Center Friends
  • Disable Installation of Apps
  • Disable Use of Camera
  • Disable iCloud Device Backup
  • Disable iCloud Document Syncing
  • Disable Cloud Keychain Sync
  • Disable Multiplayer Gaming
  • Disable Safari
  • Disable FaceTime
  • Disable Autofill

Bug Fixes

MC-74612 iOS devices are no longer automatically unenrolled after 7 days if their APNS token does not match the APNS token in database
MC-83160 Android devices were stuck in a Shared Device logout error when the SOTI MobiControl agent was pushed to the device through an app catalog rule
MCMR-15892 Console reported incorrect expiry data for DSE certificates
MCMR-18581 Making frequent calls to the /devices/search API caused memory leaks to occur
MCMR-18824 Remote control failed to load in environments with multiple Management Servers
MCMR-19048 Country specific apps did not appear in search results for Android application catalog rules
MCMR-19306 Certificate profiles failed to install on devices due to a hardcoded password that was configured in previous versions of SOTI MobiControl
MCMR-19552 “mac:” prefix did not return MAC address information when used in GET /devices/{deviceId} API call