Android+ Device Lockdown


Device lockdown replaces the standard device home screen with a customizable home screen. Users have access only to authorized applications and websites, and are prevented from accessing all other applications and device controls.

Note:

Device lockdown is not supported on Sony devices running Android L and above.

Please see the Android+ Speed Lockdown page for more information about the Speed lockdown.


Lockdown Policy dialog box

By locking down devices, organizations can minimize the risk of unauthorized persons accessing information on their mobile devices. Administrators can control exactly which programs users are allowed to run, and which websites they are allowed to visit. This decreases the amount of down-time caused by users changing settings that may adversely affect the operation of the device or application software, and also decreases support costs. MobiControl allows running the mobile devices in a kiosk mode with a read-only access to provide critical information to the end users, without giving them access to change the settings.

When you create a Lockdown profile configuration, you must also create an Authentication profile configuration with a Device Administrator Password configured. This allows you to dismiss the Lockdown menu directly on the device. You can also choose to configure a User Password Policy. If a user password policy is not defined, device users can access the lockdown menu immediately after turning on the device. If a user password policy is defined, then device users must enter the password to access the lockdown menu.

Dismissing Lockdown from Devices

Once activated, Lockdown mode can be disabled in two different ways: you can revoke the lockdown profile configuration or you can disable it directly from the device. On a device with lockdown enabled, you can access the Administrator menu by swiping up from the bottom of the screen or pressing the back button of the device. Enter the administrator password specified in the Authentication profile configuration associated with the Lockdown profile configuration.

Advanced Lockdown Settings

You can override the standard activity suppression method using one of following choices:

Package Blocking

In versions of MobiControl prior to v13.3.0.3116, device lockdown was accomplished by preventing all application from launching or running in the background unless explicitly allowed by the active Lockdown policy. This service, called package blocking, could be overly restrictive and cause issues by inadvertently blocking system applications.

Post-v13.3.0.3116, Lockdown provides an alternative 'polling-based' method to prevent device users from accessing unauthorized applications. Polling-based lockdown monitors the devices for unapproved activities in the foreground and moves them to the background where the device user cannot access them. Note: On devices that are not running a platform-signed agent, the device user must accept a device side permission before the Lockdown policy applies.

Although both methods are available, the polling-based method is the default method. SOTI recommends that you only use package blocking after careful testing of the Lockdown configuration on all models and configurations of the devices in your deployment, and only where over-the-air updates are prevented. Enable package blocking by clicking the Advanced button in the Lockdown dialog box.

Samsung Package Disabling

Undesired activities are disabled at the package level. This method is only available for certain Samsung devices. The devices must be running Android 5.0+, have MDM5+ and have a 13.3.1+ MobiControl agent installed. This option is available as of MobiControl 13.3.0.3217.

Note

Some device features are not compatible with all MDM versions. Browse the tables available on our Vendor Compatibility Matrix page to determine which features are supported by your MDM version.

To configure lockdown settings for a device or group of devices, select Lockdown in the Add Profile dialog box.

Field Name Description
Enable lockdown menu Use this checkbox to enable or disable the device lockdown menu.
Device Program Menu The device program menu is a list of programs and websites to which the user has access. There are pre-configured HTML menu templates that can be edited or applied to the menu, and an option to enable or disable the launching of a menu item with keyboard shortcuts. Please see the Device Program Menu section below for details.
HTML menu template Select a menu template from the drop-down list. Please see the Templates section below or the Customizing Android+ Lockdown Menu Templates page for more information.

Add New Menu Item dialog box

Tip:

Device Program Menu

Use the New button to add menu items. Each entry consists of a user-friendly name and a complete file path to the executable, .lnk shortcut file, .cmd script file, or website address (URL). To adjust the position of the menu items, use the Move Up and Move Down buttons.

Field Name Description
Display Name This is the displayed name of the menu item that will appear on the device.
Package Name or Script File or URL

This is the path for the web address, or Package ID (Bundle Identifier) on the device. For instance, the Package ID (Bundle Identifier) for Google Maps is com.android.apps.maps. The package will automatically be prefixed with the Launch:// URI. If you are attempting to navigate to a web page, simply enter the URL, http://www.Company.com.

Movie:// - Allows videos to be played on the lockdown.

Dial:// - This will open the dialer, with a specified number. (for example: dial://5555555555)

Launch:// - Launch applications based on package ID.

Launchalways:// - Launch applications (based on package ID) that retain the ability to switch between applications without losing recent data. (for example: launchalways://com.android.chrome)

Launchalwayswithrecents:// - Launch applications (based on package ID) that retain the ability to switch between applications without losing recent data. The app is also added to the Recent Apps view (for example: launchalwayswithrecents://com.android.chrome)

File:// - Opens a file on the device (e.g. file:///%sdcard%content/document.pdf)

http:// - Opens a webpage from within the lockdown.

https:// - Opens a secured webpage from within the lockdown.

ftp:// - Opens FTP from within the lockdown.

browser:// - Opens a URL in browser using the HTTP protocol

browsers:// - Opens a URL in browser using HTTPS protocol

surf:// - Opens a URL in the SOTI Surf secure browser. The SOTI Surf app must be installed on the devices and configured with SOTI Surf profile configuration.

intent: - Opens an Android intent. (e.g. intent:#Intent;action=net.soti.mobicontrol.admin.PASSWORD_DIALOG;i.dialog_type=1;end or to open a specific web page in your device's browser, enter: intent:https://<URL>#Intent;action=android.intent.action.VIEW;end ). See Intent at Android Developers Reference for more information.

intent

action:// - Executes a MobiControl action. To change the device password, use action://CHANGE_DEVICE_PASSWORD. To configure WiFi, use action://CONFIGURE_WIFI.

script:// - Executes a script that resides on the device.

Image (optional)

Note:

If you wish to replace an image that had been previously imported, upload the new graphic file, maintaining the same file name as the old one. You will be asked to confirm the overwrite of the old file. Click Yes, and the new image will be in effect.

This is the name of the image file that you want to display in the lockdown menu with this menu entry. By selecting the image in this dialog box, it will be automatically delivered to the device along with the lockdown configuration. Select an image from the drop-down list, or click the image to select an image from your desktop computer.

In order to display this image in the lockdown menu, it is necessary for the HTML template to have a special <MCDispImgN> tag. Please see the Customizing Android+ Lockdown Menu Templates page for instructions on how to make this image appear in the Lockdown menu.

Use Application Icon Use the application icon in the lockdown.
In order to display this image in the lockdown menu, it is necessary for the HTML template to have a special <MCEXEIconN> tag. Please see the Customizing Android+ Lockdown Menu Templates page for instructions on how to make this image appear in the Lockdown menu.
Launch automatically on startup When this option is checked, the selected program will be automatically executed on startup (i.e. after a soft reset, or restart of the lockdown process).
Enable Single App Mode When this option is selected, the device will launch directly into the app, and device functionality will be limited to that application. Only one menu item within the profile configuration may have Single App Mode enabled.

Note: The Launch automatically on start-up option must be enabled to use this option.


Device lockdown page

Templates

The lockdown program menu is displayed as an HTML web page to the user. The Template drop-down box allows you to select an HTML template from a list of built in templates and your own customized templates.

You can easily create a customized lockdown template by copying an existing template and directly modifying HTML code in the built-in Lockdown Menu Template Editor available in MobiControl. (Please see the Customizing Android+ Lockdown Menu Templates page.) You can also use your favorite HTML editor. When editing the HTML file, be sure to preserve the special MobiControl Menu tags. These special tags are automatically replaced with the appropriate Program Menu entries by MobiControl.

Once you have selected the desired template and clicked the OK button, MobiControl will merge the menu items that you have configured with the selected template and generate a custom HTML menu page.

For further assistance, please contact us.

© SOTI Inc.
Contact us