IBM Support

MaaS360 10.69 Cloud Release

Release Notes


Abstract

Release notes for MaaS360 Cloud version 10.69. Release date July 27th, 2018.

Content

iOS / macOS MDM

Push iOS update to a device, Device Groups, User Groups >>

In Push iOS Update, an option is added to download and install the latest iOS OS version that is available for a specific device, Device Groups, and User Groups for devices enrolled in MaaS360. 

Support for uploading multiple MobileConfig files from iOS and macOS policy settings >>

MaaS360 extends support to add multiple MobileConfigs files for iOS and macOS devices by using iOS and macOS policy settings. Previously, MaaS360 supported adding only one MobileConfig file from policy settings. Customers can add multiple payloads in the MobileConfig files by creating any new MobileConfigs as needed.

Publishing Identity Certificate from Cloud Extender to devices from Certificate Credentials policy setting >>

MaaS360 extends support to send Identity Certificates to the devices individually to the device keychain for iOS and macOS devices. To support this capability, MaaS360 introduces configuration of Identity Certificate from Certificate Credentials in Policy settings. Contact IBM MaaS360 Customer Support team to enable Identity Certificate credentials setting for your customer account.

Configure Active Directory account for macOS device by using policy setting >>

MaaS360 supports Active Directory configuration in User Settings under macOS policy. On publishing the policy, Payload with Active Directory settings gets installed on the device.

App addition status and license information for auto uploading of Volume Purchase Program apps >>

MaaS360 introduces new attribute App Addition Status in the Volume Purchase Program (VPP) page that displays the auto upload status for a VPP token. Additionally, View option is introduced for every VPP token name that is listed in the VPP page that guides to the VPP Token Details page.  For a VPP token, all iOS apps that are associated with the token with license information, auto app addition status, and auto upload failure reason are displayed in the Token Details.

Revamping user interface of Device Enrollment Program profile configuration workflow >>

MaaS360 revamps the user interface for Device Enrollment Program (DEP) workflow. The revamp introduces a new tab for configuring Profile and for items that can be skipped for configuration during iOS and macOS DEP device enrollment process. The function of the DEP workflow remains unchanged.

Support to upload shell scripts as an app from MaaS360 Packager >>

Administrators can now use MaaS360 Packager to upload shell scripts to MaaS360 App Catalog as an app. When the app is available in the App Catalog, shell scripts can be distributed just like any other app.

Execution of shell scripts on macOS devices as an action >>

MaaS360 adds support for a new dynamic action for enrolled macOS devices, allowing the administrators to remotely push shell scripts to macOS devices for execution right from the device view. Note:The shell scripts are not executed if the device is offline. The shell script execution is only supported on MaaS360 for macOS agent version 2.35.100.003.

Android

Recommendation to adopt Android Enterprise

Android in the enterprise is a Google-led initiative that brings together Android and Play to enable users to work the way they want, using the devices and apps they love, while giving IT admins the security and management features they need. Google recommends customers using Android platform to leverage Android Enterprise for their enterprise deployments as opposed to traditional Device Administrator based deployments. MaaS360 is encouraging customers to sign-up for and try Android Enterprise. Signing up for Android Enterprise does not impact existing enrolled devices. Future enrollments have the option to chose between traditional Device Administrator based management and Android Enterprise based management.

Android Enterprise and Samsung Knox harmonization >> 

Background: Android Enterprise and Samsung Knox are being harmonized to work together on Samsung devices.

MaaS360 adds support for Samsung Harmonization. With this feature, MaaS360 allows administrators to leverage Samsung Knox APIs for corporate-owned Samsung devices enrolled in DO mode in addition to already supported Android Enterprise API’s. In 10.69, MaaS360 adds this capability as new policies for Samsung devices with a new support tag DO with KNOX under Android Enterprise in Android MDM Policy. Note: For existing DO enrollments on Samsung devices, users can enable ELM License from Corporate Settings to use this feature. The devices that enroll after 6.25 release are eligible for this feature by default. Supported on Samsung devices running Android OS version 6+.

Enrollment of Work-Managed devices using Samsung KME >>

MaaS360 provides support for KME-based Device Owner mode (Android Enterprise) enrollments. With this feature, organizations can pre-configure work-managed devices through Samsung KME so that devices automatically enroll into MaaS360 in DO mode after the first boot or on device reset. Note: Supports only Device Owner (DO) mode enrollment and applicable only on Samsung devices with Knox 2.8+.

Support to schedule download of Android app updates for corporate apps >>

MaaS360 adds support to schedule download of Android app upgrades for a set time and date to prevent business interruptions. Previously, administrators could only set the upgrade time and date for actual app upgrade installation purpose and not necessarily for the download. In this case, the upgrade date must be greater than upgrade download time. Note: If the download of app upgrade is not scheduled, the download is initiated as soon as the administrator pushes upgrade for the app.

Support for enforcement of device enrollment for DO mode >>

MaaS360 enhances the QR code and Zero Touch enrollment workflows with an option to prevent the users from skipping the device enrollments. In the previous versions, users could skip mandatory screens that were required for enrollments.

Support to easily identify devices that have power saving mode enabled >>

When managed devices enter power saving mode, some features like background data and location services are restricted and MaaS360 agent cannot receive important updates from the MaaS360 portal. To overcome this issue, MaaS360 adds support to identify managed devices that have power saving mode enabled in the device view. Administrators can also use the advanced search to filter all the devices that entered the power saving mode.

Support to schedule device and group-level actions on Zebra and Bluebird devices >>

MaaS360 allows administrators to schedule various actions on Bluebird and Zebra devices to take place during a window of time that does not affect the employee productivity. In this release, MaaS360 adds scheduling support for OS download, upgrade, and copy file actions.

Windows

BETA-User management for Windows 10 Bulk Provisioning Tool >>

MaaS360 extends Windows 10 Bulk Provisioning Tool capabilities for bulk associating users by using device hostname in the bulk upload .csv file.

Export option for Patch Management reports >>

MaaS360 provides an export option for existing Patch Management workflows so that administrators can download global patch reports. The Patch Management function is accessible from the Security tab in the MaaS360 portal. The workflows OS Patches (Windows), OS Patches (macOS), App Updates (Windows), and App Updates (macOS) supports the export options. The reports are exportable both as a .csv file and excel file. The reports provide overall Patch Compliance status in an environment by listing all patches or app updates that can e missing on any of the devices. The report also provides data about affected devices count against each patch. A list of devices that are missing a specific patch or app update can also be obtained by clicking count of missing devices in the patch management reports.

Support for automatic retry of failed Windows package installations >>

MaaS360 adds auto-retry support to combat failed Windows packages scheduled for instant installations. With this support, when the instant installation for an app fails, MaaS360 automatically attempts the reinstallation of Windows packages thrice over a period of five minutes until the installation is successful. Note: Supported for .msi, .exe, and scripts type of applications.

Support to define app installation preconditions with relevance criteria >>

MaaS360 allows administrators to define app installation relevance criteria or pre-requisites for Windows enterprise app installations. With this feature, the enterprise apps are installed only on the devices that pass the predefined relevance criteria. This will address scenarios where the app installations failed previously because some of the prerequisites required for successful installation are not met. The apps will be picked up for installation only if install relevance criteria is met.

App Management

App Approval & Publication Process Workflow enhancements >>

MaaS360 adds support to allow the administrators to enable App Approval workflow right from the MaaS360 portal. App Approval & Publication Process Workflow allows administrators to set up quality standards and guidelines for publishing apps to enterprise app store. From the moment a mobile app is conceptualized to the time it is received by an IT administrator and to the time it published to the production users, IT administrators are engaged in a series of processes where they would need to complete the security, compliance and devops processes in order to ensure that the app meets the quality and compliance standards set by the organisation. These steps can be added in a streamlined fashion into the MaaS360 App Approval Workflow.  All the applications can be made to pass these requirements before they are being promoted to the App Catalog. 

A new role called "App Approver" is also added to primary administrators by default. This role can be assigned to authorized administrators such as Security officers/compliance officers to grant them privileges to review (accept/reject) apps submitted for approval.

Distribution of Android Enterprise apps for alpha and beta testing >>

MaaS360 adds support for the distribution of pre-release versions of public and private channel Android Enterprise apps for internal testing purposes. The alpha and beta testing tracks allow administrators to receive early feedback from users and fix issues before releasing the app to production.

Email notifications on new permission requests for Android Enterprise apps >>

If automatic re-approval is not enabled for Android Enterprise apps, MaaS360 administrators will receive email notifications when new permissions are requested by that app. Based on this notification, administrators can log in to the MaaS360 portal and easily approve the new permissions right from the MaaS360 App Catalog. The apps that require an administrator to accept new permissions are distinguished with a red exclamation mark over the app icon.

Support to submit macOS apps for approval >>

MaaS360 extends app approval workflow support to macOS apps. With this support, administrators can submit iTunes and enterprise apps for app approval before promoting those apps to App Catalog. Previously, the App Approval workflow was limited to Android, Windows, and iOS apps.

Installation of enterprise apps on App Catalog agent with support to view installation progress >>

MaaS360 enhances macOS App Catalog agent to handle installations of custom enterprise apps with the support to view installation status on a progress bar. Previously, the enterprise apps were installed via MDM. 

Cloud Extender

Delete users without active Cloud Extender devices >>

Maas360 enables admins to delete users without any active Cloud Extender devices

Platform

Permanently delete Apple School Manager user accounts in MaaS360 portal >>

MaaS360 supports automated method of permanent deletion of Apple School Manager (ASM) users and extends support for deletion of Local Education users both manually from the MaaS360 portal and also automated method. The automated method refers to deactivating the ASM user account from ASM  portal. The ASM user account is automatically removed from the MaaS360 portal based on the duration set for permanent deletion.

Engage Professional Services >>

Maas360 adds Engage Professional Services link to the existing Help menu.

Track the re-activation or re-registration time of a device >>

Maas360 introduces an attribute to capture the last activation time for a device enabling admin to capture time of registration for re-enrolled devices.

Customers and Partners

Add or update Primary Administrator for a MaaS360 customer and partner account >>

MaaS360 allows Administrators with relevant permissions to mark an administrator as a Primary Administrator for a customer and partner account.

New and improved UI for Maas360 customer and partner administrators >>

The revamped UI will be official for all customer and partner administrators upon login.

Analytics

Business Dashboards for Apps >>

MaaS360 extends the availability of Business Dashboards for Apps (Apps Inventory) to new and existing customers. The reporting data provides overview and trends statistics in Business Dashboards for Apps for managed and non-managed apps. The dashboards provide an overview for all apps along with usage, execution trends & statistics for enterprise apps which have MaaS360 SDK in them. Contact IBM MaaS360 Customer Support Team to avail Business Dashboards for Apps. Customers must be on the new MaaS360 portal user interface to view Business Dashboards for Apps.

Business Dashboards for Apps availability for SPS only mode MaaS360 customers >>

MaaS360 extends Business Dashboards for Apps (Apps Inventory) availability for SPS only mode customers. The Business Dashboards for Apps are accessible from Reports menu in the MaaS360 portal for all enterprise apps with MaaS360 SDK in them. Contact IBM MaaS360 Customer Support Team to avail Business Dashboards for Apps. On accessing Business Dashboards for Apps, SPS mode customers can view Usage Overview, Execution Overview, usage Trends, and Execution Trends reports.

General availability of Business Template Based Policy and Community Based Policy to all MaaS360 customers >>

MaaS360 introduces Business Template Based policy and Community Based policy to all customers. The function enables customers to add policy based on business use case needs and community insights.

Azure Active Directory integration

Beta feature: Azure Active Directory device status update>>

MaaS360 introduces a new customer property called Azure AD Device Status Updates. This feature allows administrators to synchronize compliance status in MaaS360 with the Azure Device Directory for Windows 10 devices that are enrolled through the Windows OOBE enrollment mode. You must contact IBM Support to enable this feature for your account.

Azure AD and On-Premises AD mixed-mode support>>

MaaS360 introduces support for Azure Authentication and AD/LDAP Authentication mixed-mode setup.

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSYSXX","label":"IBM MaaS360"},"Component":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
29 August 2018

UID

ibm10729729