The Authentication Policy option in the MobiControl Security Center dialog box allows administrators to set up device-side, password-based user authentication. This tab also allows administrators to create authentication actions, device-side scripts that execute when user authentication either succeeds or fails. For example, an administrator might create a script that locks the device for 30 minutes if authentication fails three times in a row. To enable Authentication Security for a device or group of devices, select Authentication Policy from the MobiControl Security Center. (Please see the Device Security and Control page.) ![]() Device Authentication Configuration dialog box For assistance with Override Settings Click Here. Administrators can configure an administrator password and a user password. When the administrator password is entered, the device is unlocked so that the administrator has complete access to the device. When a user password is entered, the user will have access to only those programs that the administrator has configured. An administrator can allow users to run all programs or only specific programs. Please see the Device Lockdown page and Application Run Control page for more details. ![]() Administrator Device Password prompt Administrator PasswordTo specify an administrator password, first ensure that the Enable Password Authentication box is checked, and then click the Configure button in the administrator password section. This will bring up the dialog box below. Enter the desired password in the two provided text boxes and click OK. The configuration of the Administrator password is a prerequisite for all the other security configurations. To get to this screen you must click on the Options button, then select Administrator and click OK. ![]() General tab of the Configure Password Settings dialog box Administrator Authentication Events and Actions![]() Advanced tab of the Configure Password Settings dialog box You can specify actions for administrator events. For example, you may wish to wipe all the data on the device if there are 10 consecutive failed log-in attempts. To create, edit, or remove an action, click on the Advanced tab of the Configure Password Settings dialog box. To add an action, click the Add button. MobiControl will prompt you for the event that will trigger the new action. This event can be either a successful login or a certain number of failed attempts. After you have made your selection, click OK to bring up the Action Configuration dialog box. Please see the Configuring Event Scripts page for more details. To edit an existing action, select the action from the list and click Edit. This will bring up a small menu that lets you choose whether to edit the event that triggers the action or the action itself. To delete an action, select it from the list and click Delete. User Password and PolicyTo specify a user password, first ensure that the Enable Password Authentication box is checked, and then click the Configure button in the user password section. You must specify an administrator password before you can specify a user password. MobiControl provides a dialog box similar to that used for administrator passwords. The User Password dialog box also allows you to specify a password policy. When you have configured a password or chosen Active Directory-based authentication, MobiControl will queue up the delivery of packages and settings targeted to the device, and only install the packages and settings once the user has been authenticated. A user password policy specifies whether or not users can change their passwords and what minimum complexity requirements those passwords must meet (if any). Complexity requirements can include minimum length and uppercase, lowercase, numeric, and special character requirements. There are four options with regard to user authentication:
User Password SettingsWhen Standard Authentication is selected, a password is specified for the user and complexity requirements for the user password is enforced, if the user password does not meet the complexity requirements, MobiControl will prompt you to change the user password within MobiControl Manager. ![]() User Password Settings dialog box Windows Active Directory AuthenticationWhen you choose Windows Active Directory-based authentication, the MobiControl Agent will directly authenticate the user's credentials with
the Active Directory server associated with the configured domain. The Active Directory Server requires SSL security to be enabled, and ports 636 and 443 to be open
between the Deployment Server and Active Directory Server. If your organization is using a non-standard port to communicate over SSL with
your Active Directory Server, then a colon " ![]() Configure Active Directory Settings dialog box ![]() Configure Active Directory Settings dialog box
User Authentication Events and ActionsYou can specify actions for user authentication events. For example, you may wish to wipe all the data on the device if there are 10 consecutive failed log-in attempts. To create, edit, or remove an action, click the Advanced tab of the Configure Password Settings dialog box. This will bring up the following screen: ![]() Password Settings (Advanced) ![]() Password Settings (Advanced) ![]() Password Settings (Advanced) To add an action, click the Add button. MobiControl will prompt you for the event that will trigger the new action. This event can be either a successful login or a certain number of failed attempts. After you have made your selection, click OK to bring up the Action Configuration dialog box. Please see the Configuring Event Scripts page for further details. To edit an existing action, select the action from the list and click Edit. This will bring up a small menu that lets you choose whether to edit the event that triggers the action or the action itself. To delete an action, select it from the list and click Delete. Custom BannerYou have the option of replacing the default banners that appear on your device with custom images(The default dimension is 214x36 Pixels and the image file must be of .BMP format). Next to the Login Screen drop-down menu, click on the Import button to browse to the desired .BMP file that you'd like to replace the default banner with. For the Device Lock Screen drop-down menu you can do the same. Simply click on the Import button to browse to your .BMP file and -once selected- it will be available as an option in the drop-down menu for the Device Lock Screen feature. Operating System IntegrationThe Display notification screen when device is locked(Pocket PC only) check box option configures the device to present clear indication of the device's locked status to users. Windows Mobile Authentication Plug-inWhen the Integrate with Windows Mobile device authentication subsystem option is selected, the MobiControl agent is registered with the operating system authentication subsystem, and replaces the standard password prompt with its custom password prompt. This provides maximum security for the device because the password prompt engages immediately on device startup, ensuring the device cannot be accessed without the user first providing the user or administrator password. With this option, the password prompt is automatically re-engaged when the operating system dictates the idle timeout has expired. This option is only applicable when both an administrator and a user password have been configured and the device is running the Windows Mobile 5 or later operating system. For devices running other operating systems, the password prompt is handled at the application layer and is not driven directly by the operating system. In some cases you may wish to disable this option to avoid the authentication plug-in from conflicting with other third-party security solutions that may be running on the mobile device. |
||||||||||||||||||||||||||||||