IBM Support

Notification runtime permission

Release Notes


Abstract

Android 13 introduces a new runtime notification permission, allowing users to focus on the most important notifications. The notification permission is turned off by default on Android 13 devices. Apps that are installed on Android 13 devices (or devices that upgraded to Android 13) will now request the notification permission before posting notifications. Users must explicitly grant the permission for the notifications to work.

Content

The notification permission is critical for MaaS360 apps to function properly.

  • MaaS360 core app 

    Show notifications for the following events: new app distribution, Out of compliance, admin messages, device password, expiration, and malware detection.

  • PIM apps 

    Shows notifications for new email, calendar, and meeting invites.

  • Docs

    Shows notifications when documents and content sources are distributed to users.

  • VPN 

    Shows the VPN connection status in the form of a persistent notification.

  • Browser 

    Shows the progress of active downloads and alerts from user-permitted websites.

  • Remote Control 

    Informs users about remote access sessions.

Tracking the notification permission in the Device Summary page

Administrators can track the devices that have the notification permission blocked in the Device Summary > Android Blocked Permissions section.

Android blocked permissions

Impact

Android Enterprise devices (DO, PO, and WPCO):

Since the notification permission is critical for MaaS360 apps to properly function, MaaS360 automatically grants the notification permission to core (agent) apps, PIM, Docs, Browser, VPN, and Remote control.

Granting the notification permission to managed apps

You can use security policies to remotely grant notification permission to managed apps.

  1. From the MaaS360 Portal Home page, navigate to Security > Policies.
  2. Open an Android MDM policy and then navigate to Android Enterprise Settings > Security > Configure Runtime App Permissions.
  3. Provide an App ID and then select Show Notifications in Permission.

    show notifications runtime
  4. Select Always Allow in Default runtime permission grant.

Blocking apps that use the notification permission

You can use security policies to remotely block apps that use notification permission. When the notification permission is blocked, all the apps that use that permission are disabled.

Follow these steps to block the notification permission for managed apps:

  1. From the MaaS360 Portal Home page, navigate to Security > Policies.
  2. Open an Android MDM policy and then navigate to Android Enterprise Settings > App Compliance > Configure Restricted Applications by App Permissions.
  3. In the Permissions dropdown, select Show Notifications.

Device Admin and SPS activated devices

Administrators cannot control notification permission from security policies. Users must explicitly grant notification permission from the corresponding app.

MaaS360 core (agent) app

The notification permission prompt is displayed the first time any of the container apps (PIM, Docs, Browser, App Catalog, etc.) is launched the first time after the enrollment.
 
agent 1 agent settings


PIM

MaaS360 displays a one-time notification prompt when the app is launched. If the permission is not granted, a notification request is displayed in the form of a yellow ribbon in the PIM app. Users can always change the notification permission preference from the General Settings screen.

PIM 2 PIM 2 PIM Set PIM Per


Docs

MaaS360 displays a one-time notification prompt when the Docs app is launched. If the permission is not granted, the notification request is displayed in the form of a yellow ribbon in the Docs app. Users can always change the notification permission preference from the Docs Settings screen.

Docs app launch Docs yellow ribbon Docs not set Docs not grant


VPN

MaaS360 displays a notification prompt when the app is launched.

VPN prompt VPN enable notification


Remote Control

MaaS360 displays a full screen notification request prompt when the app is launched.

remote control 1 rc 2


Browser

MaaS360 displays a one-time notification prompt when the app is launched. If the permission is not granted, MaaS360 displays a yellow alert in the new tab. Users can always change the notification permission preference from the Browser Settings.

browser 1 browser n2 b n3 Browser settings
 

    [{"Type":"MASTER","Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSYSXX","label":"IBM MaaS360"},"ARM Category":[{"code":"a8m0z00000006zaAAA","label":"APPS"},{"code":"a8m0z000000070YAAQ","label":"COMPLIANCE"}],"Platform":[{"code":"PF003","label":"Android"}],"Version":"All Versions"}]

    Document Information

    Modified date:
    25 July 2022

    UID

    ibm16606617