IT administrators in security-conscious organizations have role-based security models implemented to restrict the access to various applications and operations for personnel. The roles often reflect current organizational structures and business groups hierarchy.
When using a powerful, feature-rich mobile device management solution like MobiControl, it may be desirable to limit access to MobiControl's functionality for some individuals or groups. For example, for a multi-tier support and help desk team, an organization may want to limit the access of tier-one help desk personnel to the MobiControl Web Console while added functionality and features might be available for tier-two personnel.
With the MobiControl Web Console, you can create new users and user groups with their own permission levels. You can also use your external directory services to access MobiControl with accounts based on LDAP or Identity Provider Connections (IdP) credentials.
A user can be a member of multiple user groups. If a Global Permission from one group conflicts with another, the Allow option is automatically inherited.
You can add multiple users or groups.
Optional: You can also associate the User Directory User/Group with a MobiControl user group and apply its permissions to the new User/Group.
You can add multiple groups.
Optional: You can also associate the IdP User Group with a MobiControl user group and apply those permissions to the new User/Group.
Note:
If a user has locked their account, you can unlock their account by unchecking the Lock the user's account option beside the Username and Password fields. This is only available for MobiControl user accounts, and not LDAP accounts.
The Global Permissions section lists the different permissions available in MobiControl Web Console. For example, if a certain user group should not be able to view device rules, click Deny in the View Rules section. Global Permissions can be modified on individual user accounts and user groups.
Note
The default value is set to deny if neither Deny nor Allow is selected.
| Global Permission | Description |
|---|---|
| MobiControl Access | Allow or deny access to the MobiControl options. If Allow is selected, every option below it will initially be set to Allow. If Deny is selected, every option below it will be set to Deny and disabled. |
| Web Console Access | Allow or deny access to the MobiControl Web Console. |
| Manage User Security | Allow or deny users the ability to manage users. |
| View Profiles | Allow or deny users the ability to access the Profiles tab under each device section. |
| Manage Profiles | Allow or deny users the ability to edit profiles. |
| Show Absolute Device Group Paths | Allow or deny a user the ability to see the full path of a device group in the case where that user does not have view permission for the ancestors of that device group. |
| Configure Devices/Device Groups | Allow or deny users the ability to access the Devices tab under each device section. |
| Manage Root Groups | Allow or deny users the ability to create root level device groups. |
| View Rules | Allow or deny users the ability to view the Rules tab. If Allow is selected, every rule option below it will initially be set to Allow. If Deny is selected, every rule option below it will be set to Deny and disabled. |
| Manage Add Devices Rules | Allow or deny users the ability to manage Add Devices rules. |
| Manage File Sync Rules | Allow or deny users the ability to manage File Sync rules. |
| Manage Device Relocation Rules | Allow or deny users the ability to manage Device Relocation rules. |
| Manage Data Collection Rules | Allow or deny users the ability to manage Data Collection rules. |
| Manage Alert Rules | Allow or deny users the ability to manage Alert rules. |
| Manage Telecom Expense Rules | Allow or deny users the ability to manage Telecom Expense rules. |
| Manage Application Catalog Rules | Allow or deny users the ability to manage Application Catalog rules. |
| View And Deploy Packages | Allow or deny users the ability to view the Packages tab and to add packages to a profile. |
| Manage Packages | Allow or deny users the ability to upload or delete packages. |
| Manage Servers and Global Settings | Allow or deny users the ability to change server and global settings for MobiControl. If Allow is selected, every child option below it will initially be set to Allow. If Deny is selected, every child option below it will be set to Deny and disabled. |
| Manage Console Security | Allow or deny users the ability to turn off Web Console security. |
| Configure Deployment Servers | Allow or deny users the ability to access the Servers tab. |
| Configure Secure Email Access Filter | Allow or deny users the ability to create or edit Secure Email Access Filter settings from the Servers tab. |
| Manage APNS Certificates | Allow or deny users the ability to upload new APNS certificates from the Servers tab. |
| Configure Database Maintenance | Allow or deny users the ability to access the Configure Logging and Alerts Maintenance dialog box from the Servers tab. |
| Manage Directory Connections | Allow or deny users the ability to create or edit LDAP or IdP connections from the Servers tab. |
| Manage Cloud Link Agents | Allow or deny users the ability to create a Cloud Link agent or download the Cloud Link agent installer from the Servers tab. |
| Manage Certificate Authorities | Allow or deny users the ability to create or edit Certificate Authorities certificates and templates from the Servers tab. |
| Revoke Certificates | Allow or deny users the ability to revoke certificates from the Devices tab. |
| Manage Terms and Conditions | Allow or deny users the ability to access the Terms and Conditions Manager dialog box from the Servers tab. |
| Manage Shared Files | Allow or deny users the ability to manage Shared File Browser from the Web Console. |
| Configure Printer Administration Servers | Allow or deny users the ability to create or edit Printer Administration Server (PAS) interfaces from the Servers tab. |
| Configure Apple Device Enrollment Program | Allow or deny users the ability to create or edit additions to the Apple DEP. |
| Manage DEP Device Assignments | Allow or deny users the ability to re-assign DEP-enrolled devices to different Add Devices rules. |
| Manage Android for Work Enterprise Bindings | Allow or deny users the ability to edit Android for Work Enterprise bindings. |
| Configure Content Library Policy | Allow or deny users the ability to access the Content Library tab. If Allow is selected, every child option below it will initially be set to Allow. If Deny is selected, every child option below it will be set to Deny and disabled. |
| Manage Content Library Policies | Allow or deny users the ability to create or edit Content Library policies from the Content Library tab. |
| Manage Files and Folders | Allow or deny users the ability to add or remove files from a Content Library on the Content Library tab. |
| Manage Library Path | Allow or deny users the ability to change the Content Library root folder reference from the Content Library tab. |
| View Installed Applications | Allow or deny users the ability to view the list of applications that are installed on a device from the Devices tab. |
| View non-Managed Installed Applications (iOS only) | Allow or deny users the ability to view non-managed applications that are installed on a device from the Devices tab (iOS only). |
| Manage KNOX Licenses | Allow or deny users the ability to access the KNOX License Manager. |
| Change MobiControl Registration Code | Allow or deny users the ability to change the MobiControl registration code. |
| Manage System and Device Alerts | Allow or deny users the ability to view and access alerts. |
| Generate and Print Reports | Allow or deny users the ability to access the Reports tab under each device section. |
| Manage Report Scheduler | Allow or deny users the ability to set up or change scheduled reports from the Reports tab. |
| Import Reports | Allow or deny users the ability to import new reports. |
| View Dashboard | Allow or deny users the ability to view the Web Console dashboard. |
| View iOS Activation Lock Hash | Allow or deny user the ability to view the iOS Activation Lock Hash. |
| Self Service Portal Access | Allow or deny users the ability to access the Self Service Portal. The Self Service Portal allows users to self-manage their enrolled devices. |
| Wipe | Allow or deny users the ability to wipe their devices from within the Self Service Portal. |
| Lock | Allow or deny users the ability to lock their devices from within the Self Service Portal. |
| Unenroll | Allow or deny users the ability to unenroll their devices from within the Self Service Portal. |
| Locate | Allow or deny users the ability to locate their devices from within the Self Service Portal. |
| Send Message | Allow or deny users the ability to send messages to their devices from within the Self Service Portal. |
| Set Passcode | Allow or deny users the ability to set or clear passcodes on their devices from within the Self Service Portal. |
| Check In | Allow or deny users the ability to check in their devices from within the Self Service Portal. |