Global Permissions
Global permissions determine the level of access and control that SOTI MobiControl users have within the SOTI MobiControl console. Administrators can edit permissions for users or user groups. If neither Allow nor Deny is explicitly set for a permission, the permission will default to Deny.
SOTI MobiControl Access | Allow or deny access to the SOTI MobiControl options. If Allow is selected, every option below it will initially be set to Allow. If Deny is selected, every option below it will be set to Deny and disabled. |
Web Console Access | Allow or deny access to the SOTI MobiControl console. |
Manage User Security | Allow or deny users the ability to manage users. |
View Profiles | Allow or deny users the ability to access the Profiles tab. |
Manage Profiles | Allow or deny users the ability to edit profiles. |
Show Absolute Device Group Paths | Allow or deny a user the ability to see the full path of a device group in the case where that user does not have view permission for the ancestors of that device group. |
Configure Devices/Device Groups | Allow or deny users the ability to add, remove or edit device groups. |
Manage Root Groups | Allow or deny users the ability to create root level device groups. |
View Rules | Allow or deny users the ability to view the Rules tab. If Allow is selected, every rule option below it will initially be set to Allow. If Deny is selected, every rule option below it will be set to Deny and disabled. |
Manage Add Devices Rules | Allow or deny users the ability to manage add devices rules. |
Manage File Sync Rules | Allow or deny users the ability to manage file sync rules. |
Manage Device Relocation Rules | Allow or deny users the ability to manage device relocation rules. |
Manage Data Collection Rules | Allow or deny users the ability to manage data collection rules. |
Manage Alert Rules | Allow or deny users the ability to manage alert rules. |
Manage Telecom Expense Rules | Allow or deny users the ability to manage telecom expense management rules. |
Manage App Policies | Allow or deny users the ability to manage app policies. |
View And Deploy Packages | Allow or deny users the ability to view the Packages tab and to add packages to a profile. |
Manage Packages | Allow or deny users the ability to upload or delete packages. |
Manage Servers and Global Settings | Allow or deny users the ability to change server and global settings for SOTI MobiControl. If Allow is selected, every child option below it will initially be set to Allow. If Deny is selected, every child option below it will be set to Deny and disabled. |
Manage Android Agents | Allow or deny users the ability to download Android device agents to the SOTI MobiControl database and set their compatibility status. |
Manage Console Security | Allow or deny users the ability to turn off console security. |
Manage Deployment and Management Servers | Allow or deny users the ability to access the context-menu actions on Deployment or Management servers in the Servers tab. |
Configure Secure Email Access Filter | Allow or deny users the ability to create or edit Secure Email Access Filter settings from the Servers tab. |
Manage APNS Certificates | Allow or deny users the ability to upload new APNS certificates from the Servers tab. |
Configure Database Maintenance | Allow or deny users the ability to access the Configure Logging and Alerts Maintenance dialog box from the Servers tab. |
Manage Directory Connections | Allow or deny users the ability to create or edit directory service or IdP connections on the Servers tab. |
Manage SOTI Cloud Link Agent | Allow or deny users the ability to create a SOTI Cloud Link Agent or download the SOTI Cloud Link Agent installer from the Servers tab. |
Manage Certificate Authorities | Allow or deny users the ability to create or edit Certificate Authorities certificates and templates from the Servers tab. |
Revoke Certificates | Allow or deny users the ability to revoke certificates. |
Manage Terms and Conditions | Allow or deny users the ability to access the Terms and Conditions Manager dialog box from the Servers tab. |
Manage Shared Files | Allow or deny users the ability to manage Shared File Browser from the console. |
Configure Printer Administration Servers | Allow or deny users the ability to create or edit Printer Administration Server (PAS) interfaces from the Servers tab. |
Configure Apple Device Enrollment Program | Allow or deny users the ability to create or edit additions to the Apple Automated Device Enrollment (ADE). |
Manage ADE Device Assignments | Allow or deny users the ability to reassign Apple devices enrolled in the ADE to new add devices rules. |
Manage Android Enterprise Enterprise Bindings | Allow or deny users the ability to edit Android Enterprise Enterprise bindings. |
Configure Content Library Policy | Allow or deny users the ability to access the Content Library tab. If Allow is selected, every child option below it will initially be set to Allow. If Deny is selected, every child option below it will be set to Deny and disabled. |
Manage Content Library Policies | Allow or deny users the ability to create or edit Content Library policies from the Content Library tab. |
Manage Files and Folders | Allow or deny users the ability to add or remove files from a Content Library on the Content Library tab. |
Manage Library Path | Allow or deny users the ability to change the Content Library root folder reference from the Content Library tab. |
View Installed Applications | Allow or deny users the ability to view the list of applications that are installed on a device. |
View non-Managed Installed Applications (iOS only) | Allow or deny users the ability to view non-managed applications that are installed on a device (iOS only). |
Manage Knox Licenses | Allow or deny users the ability to access the Knox License Manager.
Important: With the release of Samsung Knox 3.4, Samsung has deprecated Knox Workspace containers. As such, SOTI MobiControl v15.0 and on does not support the creation, modification or deployment of Samsung Knox containers to devices. If you have devices that were assigned a Samsung Knox container in a previous version of SOTI MobiControl and you have since upgraded to SOTI MobiControl v15.0 or later, the Knox container will remain on the device. However, you will be unable to modify the existing container or add new containers to devices.
Learn more about how the Samsung Knox Workspace container deprecation may affect you at Samsung Knox Workspace Container Deprecation |
Change SOTI MobiControl Registration Code | Allow or deny users the ability to change the SOTI MobiControl registration code. |
Manage System and Device Alerts | Allow or deny users the ability to view and access alerts. |
Generate and Print Reports | Allow or deny users the ability to access the Reports tab under each device section. |
Manage Report Scheduler | Allow or deny users the ability to set up or change scheduled reports from the Reports tab. |
Import Reports | Allow or deny users the ability to import new reports. |
View Dashboard | Allow or deny users the ability to view the console dashboard. |
View iOS Activation Lock Hash | Allow or deny users the ability to view the iOS Activation Lock Hash. |
Geofence Management | Allow or deny users the ability to create, edit, or delete geofences. |
Lookup Users and Group Membership | Allow or deny users the ability to retrieve user and group membership information. |
Manage Device Scripts | Allow or deny users the ability to create, rename, edit, or delete scripts. |
Self Service Portal Access | Allow or deny users the ability to access the Self Service Portal. The Self Service Portal allows users to self-manage their enrolled devices. |
Wipe | Allow or deny users the ability to wipe their devices from within the Self Service Portal. |
Lock | Allow or deny users the ability to lock their devices from within the Self Service Portal. |
Unenroll | Allow or deny users the ability to unenroll their devices from within the Self Service Portal. |
Locate | Allow or deny users the ability to locate their devices from within the Self Service Portal. |
Send Message | Allow or deny users the ability to send messages to their devices from within the Self Service Portal. |
Set Passcode | Allow or deny users the ability to set or clear passcodes on their devices from within the Self Service Portal. |
Check In | Allow or deny users the ability to check in their devices from within the Self Service Portal. |