SOTI Surf is a secure mobile browser that allows you to supervise web access on your devices. Go to SOTI Surf for more information.
Use the SOTI Surf profile configuration to configure the SOTI Surf app to your specifications. Assigning the SOTI Surf configuration follows the same procedure as any other profile configuration. Go to Creating a Profile for instructions. SOTI Surf is under the SOTI apps section of the Add Profile dialog box. SOTI Surf is available only on MobiControl 13.2 or later for Android+, Android for Work, and iOS devices.
If necessary, administrators can block access to SOTI Surf content or wipe cached SOTI Surf data for specific devices or device groups without affecting or reassigning the profile configuration. See Android+ Actions or iOS Actions for more information. A log event is created and noted whenever an action is implemented. You can view Device log events in the Log subsection of the Information panel on the Devices tab.
The Lockdown profile configuration restricts access on a device to administrator-designated applications and websites. If you want URLs in Lockdown mode to open in the SOTI Surf secure browser, you must prefix the URL with surf:// when configuring the Lockdown menu item. For example, to open Wikipedia in SOTI Surf, you must enter: surf://www.wikipedia.org/ as the URL menu item. Note: surf:// will launch URLs in SOTI Surf even if SOTI Surf itself is not a designated Lockdown app.
The Lockdown configuration is only available on Android, Android+, and AfW (as Kiosk Mode) devices. It is recommended that you also place the SOTI Surf browser into Kiosk Mode when implementing the Lockdown configuration on your devices.
Every time a change is made to the profile targeting their device, device users are logged out of SOTI Surf and must re-launch the app.
Note
If you assign multiple SOTI Surf configurations to the same device, the most restrictive version of the setting applies. For example, in cases where the conflicting settings are a whitelist and a blacklist, the whitelist settings apply.
The Privacy features section allows you to manage the browsing experience of your device users on all websites and provides options for data leakage prevention. Click the Configure button within the Privacy section to modify privacy settings for SOTI Surf.
Note: In general, settings in the Privacy section are more restrictive when they are enabled. Exceptions are noted.
| Setting | Description |
|---|---|
| Disable Copy from Browser | When enabled, devices users are not able to copy content from within browser - both to other webpages and to apps outside of the browser.
Note: Enabling this option will also enable Disable Screen Capture when Browsing and Disable Sharing of Downloaded Files. Both options can be subsequently disabled without also disabling "Disable Copy from Browser". |
| Disable Screen Capture when Browsing | When enabled, device users cannot take screenshots of their device screen while SOTI Surf is the active app.
Available on Android devices only |
| Disable Downloading of Files | When enabled, device users cannot download any files from within the SOTI Surf app.
Enabling this option will also enable the Disable Sharing of Downloaded Files setting though it can be deselected independently of "Disable Downloading of Files". |
| Disable Sharing of Downloaded Files | When enabled, device users cannot share any files they have downloaded with another person or another app. |
| Disable Printing | When enabled, devices users cannot print any content from within browser
Note: Disable Printing will not disable Cloud Printing on sites such as Gmail, where Printing options are available. |
| Disable JavaScript | When enabled, JavaScript does not run on any webpages.
Available on Android devices only Note: Device users may experience limitations when navigating the internet due to the prevalence of JavaScript. |
| Disable Popups | When enabled, SOTI Surf prevents websites from opening any popup windows. Websites that use alerts or confirmation boxes are allowed but any websites that call new webpages are blocked.
Available on Android devices only |
| Disable Cookies | When enabled, websites cannot store any cookies on SOTI Surf.
Enabling this option will also enable the Clear Cookies on Launch setting. |
| Clear Cookies on Launch | When enabled, cookies from previous browser sessions will be cleared when the browser is relaunched.
Note: "Clear Cookies on Launch" can be enabled independently of "Disable Cookies" |
| Disable Website Cache | When enabled, the browser does not cache website data when the app closes or the user navigates away from a webpage. |
| Disable Auto Fill | When enabled, webpages with forms or fillable fields do not remember any previously entered information.
Available on Android devices only |
| Disable Safe Search | When enabled, the safe search filter (that is normally active on SOTI Surf) to block inappropriate or explicit images and videos is turned off. Device users can access all web content - if it is not blocked by other web filtering settings. Disable safe search applies to search results only.
Note: Disable Safe Search is more restrictive when it is unchecked. |
| Disable Access to Websites with invalid SSL certificate | When enabled, device users cannot access websites with SSL security certificate errors. |
| Open new tab in background | When enabled, when a device user clicks a link to open it in a new tab, the new tab will always open in the background.
Note: If multiple profiles are assigned to a device but have conflicting tab opening settings, the setting of the profile that was created first will apply. |
Search Engine: You can specify a default search engine for SOTI Surf. Any searches initiated from the Address bar are run through the specified search engine.
Search engine options are:
In multiple profile assignments conflict scenarios, the search engine from the profile that was assigned first will apply.
These settings control how device users access the internet or your corporate intranet.
Use Enterprise Resource Gateway (ERG) to route your web traffic through a proxy server and grant your users access to your internal network.
You must have configured ERG on a proxy server to use this feature. Refer to SOTI Surf and Installing SOTI apps Server for SOTI Surf for more information.
Once ERG is set up, you can link your server to the SOTI Surf app through the SOTI Surf configuration.
You can add multiple domains and specific websites to route through the proxy server. Import multiple domains at once by clicking Import.
Note: Imported domains must be in either .csv or .txt format. Each domain must occupy a new row.
It is possible to assign multiple profiles to the same device with different SOTI Surf configuration settings. If one profile has Enable Intranet Gateway enabled and another profile that targets the same device, does not, then only the enabled profile applies.
Also, if you assign multiple proxy servers to the same device through multiple profiles, the device will only use the settings of the first assigned proxy and ignore all subsequent proxy servers. However, if the multiple profiles contain the same proxy settings (as in the same IP address or FQDN and the same port number) then all the domains of each matching profile will be applicable.
Website Filtering allows you to block users from accessing certain websites based on specific URLs or website content. Websites can either be Blacklisted or Whitelisted. You cannot apply both a blacklist and a whitelist within the same profile configuration. If a device receives a blacklist and a whitelist from two different profiles, the whitelist will apply, overriding the blacklist. If a device receives multiple blacklists or multiple whitelists from different profiles, then the websites (and exceptions) from all profiles are unioned.
Toggle between Blacklist and Whitelist using the radio buttons. You can enter a URL that your device users will be redirected to when they try to access a blocked site. If a device receives multiple redirect URLs from different profiles, the URL from the profile that was assigned first will apply.
When a Blacklist is applied, any sites on the blacklist will redirect the device user to the Default URL for blocked websites or a blank page, depending on your settings.
A Whitelist is much more restrictive than a blacklist. The device user can only access the sites specified on the whitelist. Any attempt by the device user to access non-whitelisted sites will redirect the device user to the Default URL or a blank page, depending on your settings. Redirect URLs are automatically whitelisted.
If you leave the URL field empty, device users are redirected to a blank page.
Note: You can use asterisks (*) to block websites with multiple domains. For example, if you input google.*, google.com, google.ca and all other variations will be blocked.
.csv or a .txt file with a list of domains. Each domain must occupy a new row.For example, if you input google.* as the blacklisted domain and then add google.ca and google.fr to the exceptions list, your users can now access google.ca and google.fr but are still unable to access google.com, google.co.uk and other variations.
Note
If you choose to use an Intranet Gateway and you use website filtering, the website filter will not apply to any domains or websites specified in the intranet gateway.
If you want to block websites based on website content, switch to the Web Content tab in the Configure Website Filtering dialog box and check any content categories that you want to block your users from accessing. Some examples of blockable categories include:
There is also an Uncategorized option for the Web Content filter. When enabled, device users cannot access any website that does not have a website category assigned. Devices with blocked categories from multiple profiles will have all categories from all profiles applied.
You can add an exception to web content categories by adding the website to the exception list of a Blacklist web filter.
Other miscellaneous settings you can set for the SOTI Surf app.
You can set the home screen of SOTI Surf to open and navigate to a specific website or to display a curated set of website links that devices users click to take them straight to those pages. By default, the links for the home screen catalog are SOTI, Google, Yahoo!, and Bing.
To set up a home screen catalog:
To set a website as the home screen:
You can change the home screen catalog entries, the home screen website, or the corporate bookmarks at any time. Navigate to the appropriate dialog boxes and use the Delete, Edit, or Add buttons as necessary.
Note
The website configured as the home screen is automatically whitelisted.
If a device is assigned multiple profiles with SOTI Surf, there is the potential for conflicts between the configured settings. Conflicts are resolved in the following manner:
Kiosk mode places SOTI Surf in a state of reduced functionality. Device users have limited access to websites and SOTI Surf app settings. The address bar is disabled and users can only navigate forward through hyperlinks and backwards using the back button. The long-press context menu is also disabled.
You can restrict which features your device users have access to by checking Enable Kiosk Mode and then clicking Configure.
| Setting | Description |
|---|---|
| Hide App Bottom Bar | When enabled, device users cannot access the bottom bar of the SOTI Surf app, which includes the forward and backward navigation buttons, the home and the app menu icons.
Enabling this option will also enable the Hide App Menu and Clear Cookies with Home settings. Both options can be subsequently disabled without also disabling "Hide App Bottom Bar". |
| Hide App Menu | When enabled, device users cannot access the app menu. |
| Clear Cookies with Home | When enabled, browser cookies are cleared whenever the device user navigates to the home screen.
Note: This option is redundant if "Disable Cookies" in the Privacy settings is also enabled |
| Disable keyboard | When enabled, device users cannot activate the keyboard.
Note: Device users will be able to use the keyboard to log in and then it becomes disabled. |
If a device is assigned multiple kiosk mode settings, the most restrictive one will prevail.
You can set the SOTI Surf app to store its browsing history within a text file located in the device's internal storage. This file tracks all URLs browsed, including any attempts to access blocked websites. Entries are listed chronologically and include a URL and timestamp.
The browsing history file must be a .txt file.
Note: If a device is assigned multiple profiles with conflicting file locations for browsing histories, browsing history will be saved according to the settings of the first created profile.
You can set MobiControl to automatically retrieve the browsing history file from your SOTI Surf app and save it to the MobiControl server using a file sync rule.
You can specify where files are saved when they are downloaded in the SOTI Surf app. Once configured, device users are unable to change the download location.
Note: This is only applicable to downloads from sites that are not routed through ERG. Downloads from sites routed through ERG are saved in an application sandbox.
Note: If a device is assigned multiple profiles with conflicting download locations, downloads will be saved according to the settings of the first created profile.
You can specify over which types of networks the SOTI Surf app can access the internet. You can specify cellular networks (with or without roaming enabled on Android devices) or WiFi networks. SOTI Surf will only be able to browse the internet when the device is connected to the appropriate network.
If a device has multiple profiles with conflicting network settings, settings from all profiles will be unioned.
You can specify the length of the interval between when a configuration change is pushed to the device and when the app is forced to shut down and apply the update, requiring device users to log in again.
If a device has multiple profiles with conflicting app shut down times configured, the profile that was created first, applies.
LDAP Login allows device users to use their LDAP login information to log into the SOTI Surf browser. You must have Intranet Gateway settings configured to use this option.
If you enable LDAP login, you must also specify an inactivity timeout ranging from 0 to 999 minutes. The default time out period is 15 minutes. If you enter 0, there is no timeout.
If a device is targeted by multiple SOTI Surf configurations with conflicting Enable LDAP Login settings, the profile with LDAP enabled applies. If multiple profiles have LDAP enabled but differing inactivity timeouts, the timeout period specified in the profile that was applied first supersedes the subsequent profiles.