Mobile Device Management FAQ

Mobile Device Management (MDM) FAQ

   

Mobile Mentor offers MDM-as-a-service. Please find below some of the questions we are asked regularly about our service and the technical details of MDM-as-a-service.

Overview:

How does MDM-as-a-service work?
What do we need; on-premise install or SaaS?
What training and support is provided as part of the MDM service?
What MDM tool do you use?
What markets do you support globally?
Do you offer trial accounts?
What reports are provided to client?
Is there a self-service portal available for your MDM service customers?
Can the MDM portal be branded?
What is the enrolment process of devices?
How can we use MDM to mitigate roaming costs?
Can we use MDM to back-up the content on the device?
How does MDM complement / compete with iCloud?
What devices are supported (OS minimum requirements)? 
MDM vs Exchange vs BES – limitations
Does an on app client need to be installed?
What are the advantages of Secure Email Gateway?
Do you support App Catalogues?
Can you push/remotely remove apps?
What are the benefits for the end user in enrolling in MDM?
What native apps can be restricted?
What are the iOS5 restrictions for MDM?
Can you enforce mobile OS upgrades?
Can MDM automatically update the Exchange/Email password on the mobile device when it is updated on the users Exchange/Email account?
How do you manage roaming costs through MDM?
Can you blacklist or whitelist applications?
How do you integrate mobile policy within MDM?
How do you enforce mobile policy with MDM?

 

How does MDM-as-a-service work?

Mobile Mentor provides MDM as a service. This means we consult on mobile policy, set-up the management console, deploy to the initial group of devices, monitor security and roaming and report monthly on compliance with policy. 

We proactively monitor your mobile environment and continually optimise this through hardware management, cost control and user adherence to your mobile policy. Optionally your mobile users call us on your dedicated support number, and we action the request through the MDM tool.

 

What do we need; on-premise install or SaaS?

Our MDM solution is flexible enough to suit mobile fleets of all sizes. Both Software-as-a-Service (SaaS) and On-Premise installation options are available. SaaS provides flexibility and once your requirements have been scoped, we can activate your MDM environment almost instantly. We can also install the MDM software on one of your servers or supply an appliance if this is your preference. Contact us to discuss the installation options further.

 

What training and support is provided as part of the MDM service?

We can provide you with logins to your MDM portal. Our support team actively monitors and responds to user’s queries by utilising the MDM tool, and we are happy to share our knowledge should you want to view reports and have visibility of your mobile environment. Alternatively if you would prefer to leave our team to manage this for you, we will provide you with monthly service reports giving you greater visibility of your mobile environment, any security or policy breaches that we have acted on and other useful information.

 

What MDM tool do you use?

We select the best tool for our clients needs. We can support existing MDM platforms if you already have an MDM system in place.

 

What markets do you support globally?

We support our clients that are based in New Zealand and Australia.

 

Do you offer trial accounts?

Yes we can provide trial accounts. Contact us for more info. 

 

What reports are provided to client?

There are 50+ reports available, we understand your requirements and can recommend reports based on your mobile policy.

 

Is there a self-service portal available for your MDM service customers?

Yes this is available to all users, with two configuration options available. The URL is mntr.co/me

Basic Access (provided to customer with User Support)

• View Device info (Apps installed)
• Send Device query
• Find Device
• See support details

MDM Portal Basic Access - Mobile Mentor MDM-as-a-service

Full Access:

• Send Message to device via Email/SMS/APNs
• Remotely Lock device
• Find Device (message appears with noise on device)
• Clear Passcode
• Device Wipe
• Enterprise Wipe
• View Device Info (Apps installed)
• View GPS Location
• See support details

 

 

MDM Full Access to Self Service Portal

 

Can the MDM portal be branded?

Yes, we can brand our MDM platform in your company colours and with your logos and branding.

 

What is the enrolment process of devices?

We push an SMS or Email URL out to the user’s device, the user simply needs to click on this link and enter their enrolment password. Windows Mobile, Symbian, BlackBerry and Android require an on device client that is installed during the enrolment process. For new devices being deployed, we can intergrate the enrolment into our procurement processes or our mentoring services. 

 

How can we use MDM to mitigate roaming costs?

On iOS5 devices, we can remotely turn off Voice and Data roaming. We can receive alerts when other devices are roaming. On other devices we can pull a report to show devices that are currently roaming, and send a message to the device via MDM informing the user of roaming costs and how to disable data roaming.

 

Can we use MDM to back-up the content on the device?

No we can’t. We cannot back up any content from the device via MDM. BES can do this, iCloud can, Google Sync can on Android. MDM provides visibility and some governance of these devices.

 

How does MDM complement / compete with iCloud?

iCloud allows for iOS5 devices to wirelessly sync documents, photos, bookmarks, notes and device backup to the cloud, and if you use a iCloud mail account, it provides an exchange like sync for mail, contacts, calendars, notes and reminders.

MDM does not backup any device data. MDM can only prevent users from syncing documents and photos to an iCloud account, protecting any company documents stored on iDevices to a personal iCloud account.

 

What devices are supported? OS minimum requirements

  • Only BlackBerry OS 4.5, 4.6 and 4.7 are officially supported and require an on-device agent to be installed during enrollment.
  • Symbian (Nokia) devices with Series 60 version 5 are officially supported. These require an on-device agent to be installed during enrollment.
  • iOS version 4.0+. Doesn’t require an on device agent except if you want to show the device location via GPS and detect if device is jailbroken.
  • Android 2.2+. On device client required to be installed before enrolling.

 

MDM vs Exchange vs BES – limitations

Exchange allows remote wipe and security PIN enforcement across iOS, Android 2.2+, Windows Mobile and Phone 7, Nokia MfE.

MDM allows for increased visibility (device statistics across multiple OS), pushing of Web Clips, WiFi profiles, VPN, APN settings, roaming control (iOS5) and native device app restrictions (YouTube, app store etc).

BES provides 450+ IT policies that can be remotely enforced. BES also backs up and restores BlackBerry data (excluding SMS). This backup and restore functionality is similar to what is provided through iCloud on iOS5+ devices.

 

Does an on app client need to be installed?

The answer is ‘Yes’ for Android, BlackBerry and Symbian. Not required for iOS but does provide GPS and compromised device detection.

 

What are the advantages of Secure Email Gateway?

A secure email gateway is available for companies that want to report on and restrict specific mobile devices from accessing email through your exchange ActiveSync server. Contact us for further information on the solution.

 

Do you support App Catalogues?

Yes, App Catalogues can be pushed to iOS and Android devices. This list of applications can be customised to your needs. We can also make recommendations on applications, as we have a good understanding of productivity apps for each industry segment. App catalogues can also display internal applications that you want to distribute to groups of users.

MDM Service - App Catalogue - Mobile Mentor

 

 

Can you push/remotely remove apps?

Applications can be recommended for iOS and Android. Additionally on iOS5 it can prompt the user to install a certain app that is then removed when a corporate wipe is performed. Apps can be blacklisted and the user receives an SMS warning if they install a blacklisted app.

 

What are the benefits for the end user in enrolling in MDM?

End users have the reassurance that if their device is lost or stolen the data can be protected, and in some cases found. If a user forgets their password this can be cleared and they can enter a new password. Users also receive access to internal company apps, recommended apps, company email access and the reassurance their device is secure and is in line with the company mobile policy.

 

What native apps can be restricted?

On iOS we can restrict Camera, YouTube, iTunes, App Store and Safari.

 

What are the iOS5 restrictions for MDM?

iOS5 specific restrictions include the ability to remotely turn on and off voice and data roaming on devices, force iTunes encrypted backup, restrict iCloud backup and iCloud document sync, and restrict photostream (iOS5 automatic backup of photos).

 

Can you enforce mobile OS upgrades?

No, we can see what version of the OS the device has, and send a message to the user informing them how to upgrade. We can also assist with this process through our user support.

 

Can MDM automatically update the Exchange/Email password on the mobile device when it is updated on the users Exchange/Email account? 

Unfortunately not, MDM does not link directly to the Exchange server so has no visibility of users passwords. The user will still need to change the password on the device, but they will receive a popup prompt informing them that the current password on the device is incorrect. MDM can push the password down to the device, but this will need to be manually updated on the MDM platform everytime the users email password changes. 

 

How do you manage roaming costs through MDM?

We actively pull reports on users that are currently roaming, and can push messages to them informing them of best roaming practices. For iOS5 devices we can remotely turn on/off voice/data roaming.

MDM Service Roaming Status - Mobile Mentor

 

Can you blacklist or whitelist applications?

Yes we can blacklist and whitelist mobile applications. We can help define these apps and make recommendations in your mobile policy. 

 

How do you integrate mobile policy within MDM?

By understanding or working with you to create a well-defined mobile policy, we setup the necessary profiles and actively manage your mobile environment through our MDM tool. 

 

How do you enforce mobile policy with MDM?

We create profiles and actions based on the requirements in your mobile policy. MDM is the tool that creates the visibility and governance of your mobile environment.

 

MDM Service - Device Status - Mobile Mentor

Any other questions? Feel free to contact us.