Creating enrollment configurations in the MaaS360 Portal
You can create multiple enrollment configurations to provide different provisioning options for Android devices.
About this task
Each configuration consists of an EMM Device Policy Controller (DPC) that is installed on devices. You download the configuration in JSON format and copy the JSON-formatted text to the DPC extras while creating a profile in the zero-touch portal.
Procedure
- Do one of the following:
- From the MaaS360 Portal Home page, go to Setup > Settings > Directory and Enrollment > Enrollment Programs. In the Android section, click Configure against Android Enterprise Zero Touch Enrollment/KME enrollment.
- From the MaaS360 Portal Home page, go to Devices > Enrollments. In the Enrollments page, select Other Enrollment Options and then select Android Enterprise Zero Touch Enrollment/KME enrollment.
The Android Enterprise Zero Touch Enrollment/Knox Mobile Enrollment window is displayed. -
Complete the following fields:
Option Description Enrollment Email ID Provide an enrollment email ID. For bulk enrollments using device account, specify a common email address. Corporate ID Provide the Corporate Identifier that is defined in the Basic Enrollment Settings. Android Enterprise mode Select one of the following options: - Device Owner (DO) mode: Organization can exercise complete management control over the fully managed company-owned device. For more information, see Device Owner (DO) mode
- Work Profile on Corporate Owned: Organization only manages the data and apps in the work profle of the company-owned device. For more information, see Work profile on corporate-owned devices (WPCO)
Username Provide a default user name for authentication. For bulk enrollments using device account, specify a common username. Password Provide a password. Domain Provide the default domain. Ownership Select an ownership mode: - Corporate Owned: The pre-configured enterprise device is issued to an individual user.
- Corporate Shared: The pre-configured enterprise device is shared among multiple users where each user logs into a separate account and receives a distinct set of apps and files.
Userless Enrollment This option applies to Corporate Shared mode enrollments. If you select this option, the user-specific fields Enrollment Email ID, Username, Password, and Domain are unavailable. MaaS360 skips the user authentication during the enrollment process and enrolls the shared device in a signed-out state without attributing the device to a specific user. Managed Google Play Account Type Select an account type. Once an account type is selected, it cannot be modified at a later stage. - Device Account: The device account can be active only on one device at a time.
- User Account: The user account is active on a maximum of 10 devices and
provides access to the Managed Google Play account from all the devices enrolled by the
user.Note: You cannot enroll more than 10 devices using the same user account.
Disallow skipping of enrollment Prevents users from skipping mandatory screens that are required for device enrollment. Leave All System Apps Enabled Retains system apps such as Calculator and Clock on the device after enrollment. If this option is not selected, system apps are unavailable on the device. Note: This setting is not applicable for KME with DO. Use the setting on KME portal to leave all system apps enabled on a Samsung device.Prompt for Device Name Prompts the user or admin who is provisioning MaaS360 to assign a custom device name during enrollment. Note:- The combination of the custom device name and the device model number is used for the device name.
- If this option is not selected, the combination of the device ID and the device model number is used for the device name.
Prompt for Asset Number Prompts the user or admin who is provisioning MaaS360 to assign an asset number as a device name during enrollment. Note:- The combination of the asset number and the device model number is used for the device name.
- The custom device name takes precedence over the asset number.
- This option applies to device account-based Device Owner enrollments. This option is unavailable for user account-based enrollments.
Select Locale Applies the selected locale on the device. However, users can change the locale after device enrollment. Note: This option does not apply to KME + DO enrollments and is supported on Android 8.0 devices and later. Select Timezone Applies the selected time zone on the device. However, users can change the time zone after device enrollment. Note: This option does not apply to KME + DO enrollments and is supported on Android 8.0 devices and later. Additional Attributes Applies the actions defined in the form of key-value pairs to the device as a part of device enrollment. For more information, see Additional Android Enterprise enrollment attributes. -
Click Continue.
The JSON file that consists of DPC extras is available for download.
Note: For information on connecting to the zero-touch portal with zero-touch iframe, see Linking a zero-touch account to the MaaS360 Portal through zero-touch iframe - Do one of the following:
- Click Connect to Zero touch to link your zero-touch account with MaaS360 portal through zero-touch iframe. Zero-touch iframe allows you to apply configuration to zero-touch enabled devices from within the MaaS360 Portal. For more information, see Linking a zero-touch account to the MaaS360 Portal through zero-touch iframe
- Click Download to download the JSON file and then copy the JSON string
for Android Enterprise Zero touch enrollment.Note: The JSON file consists of enrollment configurations for both zero-touch and KME enrollments. You must use the JSON text that is available in the Google zero-touch enrollment section.
