Using the File Encryption Payload to Secure Data
Apply File Encryption in SOTI MobiControl to secure mobile data using AES-256 encryption while ensuring seamless access for users.
Before you begin
- You must enable Authentication before enabling file encryption. See Authentication.
About this task
Use the SOTI MobiControl File Encryption profile configuration to secure files on your devices. This configuration employs policy-based encryption using FIPS 140-2 validated AES-256 encryption algorithms to protect mobile data. File Encryption profile configurations are available for:
- Android Classic
- Windows Mobile/CE
Configure file encryption when:
- Enforcing encryption without impacting user experience: Enable seamless background encryption without disrupting work-flows.
- Mobile applications need to encrypt and decrypt data in memory as needed.
- Protecting lost or stolen devices: Ensure sensitive files remain encrypted even if a device becomes compromised.
- Administrators require granular control on Android Classic devices to
encrypt external or internal storage.
Procedure
- From the main menu, navigate to .
-
Choose how you wish to add a profile your Android Classic or Windows Mobile/ CE
profile.
- Create new: Select a platform to create a new profile for it.
- Import: Add a profile from an earlier established environment.
- Give your profile an appropriate description.
-
Select File Encryption from the Security profile
configurations list.
The File Encryption configuration window appears.Note: The available configurations vary by platform.
- Select (Add) to specify file or folder paths for encryption or exclusion.
Results
The File Encryption policy is now applied to the selected devices. Files stored in the specified directories are automatically encrypted. Users can access encrypted files only if they meet the authentication requirements.
What to do next
End users do not need to take any action unless password authentication is required. If a user cannot access encrypted files, ensure they have the correct permissions. Verify that SOTI MobiControl deployed the encryption profile by reviewing Device Logs from the device information panel in the MC console.