Console Security Settings


Use Console Security settings to manage user security settings for the Web Console. In the Console Security Manager, you can control access to the Web Console, integrate LDAP groups and link MobiControl to your Identity Providers (IdPs).

You can apply more granular permissions and restrictions for specific users or user groups within the Security tab.

The Console Security dialog window is divided into four tabs:

Access Control Policies

The Access Control Policies tab governs the user access settings for the Web Console. You can set password complexity requirements, determine how many times a user is allowed to attempt a login before they are locked out, and allow users to change or reset their passwords.

Note

These settings are only applicable to local MobiControl user accounts.

Setting Description
Lock accounts after x failed logins When enabled, Web Console users are locked out of their Web Console account if they fail to log into their account more than the specified number of attempts.
Allow users to change their account password When enabled, Web Console users can choose their own passwords for their account. MobiControl Web Console administrators will still be able to see passwords in the Security tab.
Allow users to reset forgotten passwords When enabled, Web Console users can reset their password by correctly answering a pre-arranged security question.

You can use one of MobiControl's default questions or create your own by clicking the Add button in the Password Security Questions section.

Once this setting is enabled, the next time the user logs into the web console, the user will be prompted to choose 3 questions and provide their answers. The user will be prompted every time they log in until they complete security questions.

User passwords must meet the following complexity requirements When enabled, you can set a minimum level of complexity for user passwords to encourage security when accessing the Web Console. Complexity requirements can be based on password length or mandatory character types.

LDAP Integration

When you integrate your LDAP groups with MobiControl you can leverage an existing set of credentials for authentication within MobiControl and to enroll your devices.

Go to LDAP Connections Manager for more information.

SAML SSO

You can incorporate MobiControl into your Single Sign On (SSO) solution to provide a single entry point for your users. MobiControl supports SAML 2.0 Identity Providers (IdPs). Click Enable SSO and choose an existing IDP connection from the dropdown or click the Manage button to configure a new IdP.

Go to IdP Connections settings for more information.

Endpoint Authentication

Configure authentication settings for other MobiControl endpoints such as the Self Service Portal and the iOS Profile Catalog.

If you are using LDAP or IdP groups for authentication, visit LDAP Connections Manager or IdP Connections to learn how to configure your groups.

Self Service Portal Authentication Options

iOS Profile Catalog Authentication Options

Setting up Endpoint Authentication

If you are using LDAP or IdP groups for authentication, visit LDAP Connections Manager or IdP Connections to learn how to configure your groups in MobiControl before setting up authentication for your endpoints.

  1. On the All Platforms tab, select the Servers tab.
  2. Under Global Settings, click the wrench icon beside Console Security Settings.
  3. Switch to the Endpoint Authentication tab.
  4. Double-click on the relevant dropdown under Authentication Source to determine how each endpoint handles authentication.
  5. Click OK to save your settings and close the dialog window.
© SOTI Inc.
Contact us