Roles Matrix
Mobile Device Manager Plus lets administrators designate roles to users. Apart from a set of predefined roles, MDM supports customization of roles as per the needs of your organization. For each of these user-defined roles, the permission to access specific sections of MDM can be configured as Full control, Write, Read or No access, as given in the table below.
Module specific access
Enrollment
ACTION | DESCRIPTION | PERMISSIONS | ||
---|---|---|---|---|
FULL CONTROL | WRITE | READ | ||
ENROLL DEVICE (Admin) | Admin Enrollment methods (except EMM) like ZTE, ABM, Knox | |||
ENROLL DEVICE (Invite) | Invite Enrollment methods like Self Enrollment | |||
ADD/MODIFY AD | Upload and renew Directory Services | |||
APN'S CONFIGURATION | Add or remove Apple Push Notification Ceritificates | |||
CONFIGURING ABM TOKEN | Access the Public key and upload the server token | |||
CONFIGURING ENROLLMENT SETTINGS | Configure the MDM Server authentication protocol,Device policy | |||
KNOX ENROLLMENT | Confugure the Knox Profile in MDM Server | |||
ZTE ENROLLMENT | Access the ZTE configuration | |||
ENROLL LAPTOP/SURFACE PRO | Downloading enrollment tool,assigning users to devices | |||
AZURE ENROLLMENT | Setting up Azure Portal and adding devices | |||
CHROMEBOOK ENROLLMENT | Enrolling Chrome devices | |||
CONFIGURE AGENT SETTNGS | Configure the Andriod/iOS MEMDM App Settings | |||
DEVICE ACTIONS | Re-assign User,Enroll Additional Device,Deprovision |
Profile Management
ACTION | DESCRIPTION | PERMISSIONS | ||
---|---|---|---|---|
FULL CONTROL | WRITE | READ | ||
CREATE PROFILE | Create profiles for iOS,Android,Windows,Chrome,macOS,tvOS devices | |||
MODIFY/UPDATE PROFILE | Update existing profiles | |||
MOVE TO TRASH/ DLT TRASH | Remove profiles | |||
VIEW TRASH | View removed profiles, restore profiles, delete profile permanently | |||
DISTRIBUTE PROFILE | Distribute published profiles to groups/devices | |||
REMOVE ASSOCIATED PROFILE | Disassociate redundant profiles from groups/devices | |||
VIEW PROFILE DETAILS | View the different policies and restrictions implemented by a profile |
App Management
ACTION | DESCRIPTION | PERMISSIONS | ||
---|---|---|---|---|
FULL CONTROL | WRITE | READ | ||
ADD/MODIFY APPS | Add Enterprise and Store apps to App repository | |||
DELETE APPS | Moving apps from App Repository to Trash | |||
DISTRIBUTE APPS | Distributing Apps from app repository to groups/devices | |||
CONFIGURE ABM/VPP | Upload location token for adding apps from ABM portal | |||
SYNC ABM/ VPP APPS | Syncing apps added from ABM portal | |||
UPDATE APPS | Updating exisitng apps to latest app versions | |||
AUTOMATE APP UPDATES | Permission to setup automate app update policy | |||
APPROVE SPECIFIC APP VERSION | Approving a specific app version among multiple versions present | |||
DELETE SPECIFIC APP VERSION | Deleting an outdated app version from the server | |||
ADD/ MODIFY APP PERMISSION | Make changes to existing app permissions provided by the app developer | |||
ADD/ MODIFY APP CONFIGURATION | Make changes to existing app configuration provided by the app developer | |||
ADD ENTERPRISE APPS | Adding In-house/ Enterprise apps specifically | |||
REMOVE MANAGED APPS | Remove unwanted Apps from Server to trash |
Deprovision
ACTION | DESCRIPTION | PERMISSIONS | ||
---|---|---|---|---|
FULL CONTROL | WRITE | READ | ||
Factory reset device (Complete wipe) | Wipe all the data present in the device. | |||
Revoke MDM(Corporate wipe) | Wipe only the corporate data present in the device. |
Content Management
ACTION | DESCRIPTION | PERMISSIONS | ||
---|---|---|---|---|
FULL CONTROL | WRITE | READ | ||
ADD/ UPDATE/ DELETE DOCS | Add Documents to MDM Server | |||
DISTRIBUTE DOCS | Distribute docs via server to groups and devices | |||
CREATE POLICIES | Create policies to view or share documents | |||
VIEW POLICIES | View existing policies applied to devices |
Group Management
ACTION | DESCRIPTION | PERMISSIONS | ||
---|---|---|---|---|
FULL CONTROL | WRITE | READ | ||
VIEW GROUPS & DETAILS | Sight group members, policies, app associations | |||
CREATE GROUPS | Create User group,Device group, AD User group | |||
MODIFY GROUP DETAILS | Modify the details of a group like title, description, members | |||
DELETE GROUP | Delete groups from server | |||
ADD MEMBERS TO A GROUP | Move devices to selected groups | |||
MOVE MEMBERS BETWEEN GROUPS | Move members from one group to another if required | |||
REMOVE MEMBERS | Remove members from groups they're no longer required |
Inventory Management
ACTION | DESCRIPTION | PERMISSIONS | ||
---|---|---|---|---|
FULL CONTROL | WRITE | READ | ||
EDIT DEVICE DETAILS | Fill in details of devices which aren't collected automatically | |||
DEVICE ACTIONS | Push Device actons like Scan, Remote View, Complete Wipe etc | |||
APP BLOCKLISTING | Provision to block apps which don't follow organizational policies | |||
SCHEDULE DEVICE SCAN | Schedule Device scan frequency, timeline and tenure | |||
GEO TRACKING | Configure Geo Tracking Settings | |||
BATTERY LEVEL TRACKING | Configure Battery Level tracking setting | |||
CREATE/ MODIFY FENCE POLICY | Create New fence policy and configure complinace settings | |||
CREATE /MODIFY/DELETE FENCE REPOSITORY | Create & Edit Fence Repostiory |
OS Update Management
ACTION | DESCRIPTION | PERMISSIONS | ||
---|---|---|---|---|
FULL CONTROL | WRITE | READ | ||
CREATE POLICY | Configure automate OS policy for all platforms | |||
MODIFY POLICY | Modify/update existing policy settings | |||
DELETE POLICY | Delete redundant/unwanted policies | |||
ASSOCIATE/DISASSOCIATE POLICY | Abiltiy to associate/ disassociate policies from groups | |||
VIEW POLICIES | Permission to read the Automate OS policies in effect |
Remote Control
ACTION | DESCRIPTION | PERMISSIONS | ||
---|---|---|---|---|
FULL CONTROL | WRITE | READ | ||
ADD ZOHO ASSIST ACCOUNT | Edit login details | |||
REMOTE CONTROL/ VIEW | Execute Remote Control/Remote view actions on devices | |||
VIEW REMOTE CONTROL DETAILS | Access the Remote Control settings |
Announcements
ACTION | DESCRIPTION | PERMISSIONS | ||
---|---|---|---|---|
FULL CONTROL | WRITE | READ | ||
CREATE ANNOUNCEMENT | Create a new announcement and publish it | |||
UPDATE ANNOUNCEMENT | Update an exisiting announcement if required | |||
DELETE ANNOUNCEMENT | Delete an unwanted announcement from repository | |||
MODIFY ANNOUNCEMENT | Modify exisiting announcement in Actions | |||
DISTRIBUTE ANNOUNCEMENT | Distribute Announcements in Action | |||
REMOVE ASSOCIATED ANNOUNCEMENT | Remove an announcement which is published and distributed | |||
VIEW ANNOUNCEMENT DETAILS | View granular information about an announcement like Distributed devices, Acknowledged users etc |
Reports
ACTION | DESCRIPTION | PERMISSIONS | ||
---|---|---|---|---|
FULL CONTROL | WRITE | READ | ||
VIEW PREDEFINED REPORTS | Access and view reports collected by the system by default | |||
CREATE SCHEDULED REPORTS | Create scheduled reports for specific use cases | |||
VIEW SCHEDULED REPORTS | View data in the scheduled reports | |||
CONFIGURE REPORT RETENTION PERIOD | Retention period is the period until which the the reports are stored in the server | |||
CREATE QUERY REPORT | Create Query reports for specific functionalities | |||
VIEW QUERY REPORT | View the query reports created in the server | |||
MODIFY QUERY REPORT | Update or edit existing query reports |
Jump To