Category Filter

Roles Matrix

Mobile Device Manager Plus lets administrators designate roles to users. Apart from a set of predefined roles, MDM supports customization of roles as per the needs of your organization. For each of these user-defined roles, the permission to access specific sections of MDM can be configured as Full control, Write, Read or No access, as given in the table below.

The below actions can be performed as per the permissions assigned for the created role.
For example Enroll Device action can only be performed by an Admin who have Full control permission. Visit our Permission Guide for more details.

Module specific access

Enrollment
ACTIONDESCRIPTIONPERMISSIONS
FULL CONTROLWRITEREAD
ENROLL DEVICE (Admin)Admin Enrollment methods (except EMM) like ZTE, ABM, Knox
ENROLL DEVICE (Invite)Invite Enrollment methods like Self Enrollment
ADD/MODIFY ADUpload and renew Directory Services
APN'S CONFIGURATIONAdd or remove Apple Push Notification Ceritificates
CONFIGURING ABM TOKENAccess the Public key and upload the server token
CONFIGURING ENROLLMENT SETTINGSConfigure the MDM Server authentication protocol,Device policy
KNOX ENROLLMENTConfugure the Knox Profile in MDM Server
ZTE ENROLLMENTAccess the ZTE configuration
ENROLL LAPTOP/SURFACE PRODownloading enrollment tool,assigning users to devices
AZURE ENROLLMENTSetting up Azure Portal and adding devices
CHROMEBOOK ENROLLMENTEnrolling Chrome devices
CONFIGURE AGENT SETTNGSConfigure the Andriod/iOS MEMDM App Settings
DEVICE ACTIONSRe-assign User,Enroll Additional Device,Deprovision
Profile Management
ACTIONDESCRIPTIONPERMISSIONS
FULL CONTROLWRITEREAD
CREATE PROFILECreate profiles for iOS,Android,Windows,Chrome,macOS,tvOS devices
MODIFY/UPDATE PROFILEUpdate existing profiles
MOVE TO TRASH/ DLT TRASHRemove profiles
VIEW TRASHView removed profiles, restore profiles, delete profile permanently
DISTRIBUTE PROFILEDistribute published profiles to groups/devices
REMOVE ASSOCIATED PROFILEDisassociate redundant profiles from groups/devices
VIEW PROFILE DETAILSView the different policies and restrictions implemented by a profile
App Management
ACTIONDESCRIPTIONPERMISSIONS
FULL CONTROLWRITEREAD
ADD/MODIFY APPSAdd Enterprise and Store apps to App repository
DELETE APPSMoving apps from App Repository to Trash
DISTRIBUTE APPSDistributing Apps from app repository to groups/devices
CONFIGURE ABM/VPPUpload location token for adding apps from ABM portal
SYNC ABM/ VPP APPSSyncing apps added from ABM portal
UPDATE APPSUpdating exisitng apps to latest app versions
AUTOMATE APP UPDATESPermission to setup automate app update policy
APPROVE SPECIFIC APP VERSIONApproving a specific app version among multiple versions present
DELETE SPECIFIC APP VERSIONDeleting an outdated app version from the server
ADD/ MODIFY APP PERMISSIONMake changes to existing app permissions provided by the app developer
ADD/ MODIFY APP CONFIGURATIONMake changes to existing app configuration provided by the app developer
ADD ENTERPRISE APPSAdding In-house/ Enterprise apps specifically
REMOVE MANAGED APPSRemove unwanted Apps from Server to trash
Deprovision
ACTIONDESCRIPTIONPERMISSIONS
FULL CONTROLWRITEREAD
Factory reset device (Complete wipe) Wipe all the data present in the device.
Revoke MDM(Corporate wipe)Wipe only the corporate data present in the device.
Content Management
ACTIONDESCRIPTIONPERMISSIONS
FULL CONTROLWRITEREAD
ADD/ UPDATE/ DELETE DOCSAdd Documents to MDM Server
DISTRIBUTE DOCSDistribute docs via server to groups and devices
CREATE POLICIESCreate policies to view or share documents
VIEW POLICIESView existing policies applied to devices
Group Management
ACTIONDESCRIPTIONPERMISSIONS
FULL CONTROLWRITEREAD
VIEW GROUPS & DETAILSSight group members, policies, app associations
CREATE GROUPSCreate User group,Device group, AD User group
MODIFY GROUP DETAILSModify the details of a group like title, description, members
DELETE GROUPDelete groups from server
ADD MEMBERS TO A GROUPMove devices to selected groups
MOVE MEMBERS BETWEEN GROUPSMove members from one group to another if required
REMOVE MEMBERSRemove members from groups they're no longer required
Inventory Management
ACTIONDESCRIPTIONPERMISSIONS
FULL CONTROLWRITEREAD
EDIT DEVICE DETAILSFill in details of devices which aren't collected automatically
DEVICE ACTIONSPush Device actons like Scan, Remote View, Complete Wipe etc
APP BLOCKLISTINGProvision to block apps which don't follow organizational policies
SCHEDULE DEVICE SCANSchedule Device scan frequency, timeline and tenure
GEO TRACKINGConfigure Geo Tracking Settings
Note: With Geo Tracking (Full Control) enabled, admins can control the access to location tracking settings based on the specific roles.
BATTERY LEVEL TRACKINGConfigure Battery Level tracking setting
CREATE/ MODIFY FENCE POLICYCreate New fence policy and configure complinace settings
CREATE /MODIFY/DELETE FENCE REPOSITORYCreate & Edit Fence Repostiory
OS Update Management
ACTIONDESCRIPTIONPERMISSIONS
FULL CONTROLWRITEREAD
CREATE POLICYConfigure automate OS policy for all platforms
MODIFY POLICYModify/update existing policy settings
DELETE POLICYDelete redundant/unwanted policies
ASSOCIATE/DISASSOCIATE POLICYAbiltiy to associate/ disassociate policies from groups
VIEW POLICIESPermission to read the Automate OS policies in effect
Remote Control
ACTIONDESCRIPTIONPERMISSIONS
FULL CONTROLWRITEREAD
ADD ZOHO ASSIST ACCOUNTEdit login details
REMOTE CONTROL/ VIEWExecute Remote Control/Remote view actions on devices
VIEW REMOTE CONTROL DETAILSAccess the Remote Control settings
Announcements
ACTIONDESCRIPTIONPERMISSIONS
FULL CONTROLWRITEREAD
CREATE ANNOUNCEMENTCreate a new announcement and publish it
UPDATE ANNOUNCEMENTUpdate an exisiting announcement if required
DELETE ANNOUNCEMENTDelete an unwanted announcement from repository
MODIFY ANNOUNCEMENTModify exisiting announcement in Actions
DISTRIBUTE ANNOUNCEMENTDistribute Announcements in Action
REMOVE ASSOCIATED ANNOUNCEMENTRemove an announcement which is published and distributed
VIEW ANNOUNCEMENT DETAILSView granular information about an announcement like Distributed devices, Acknowledged users etc
Reports
ACTIONDESCRIPTIONPERMISSIONS
FULL CONTROLWRITEREAD
VIEW PREDEFINED REPORTSAccess and view reports collected by the system by default
CREATE SCHEDULED REPORTSCreate scheduled reports for specific use cases
VIEW SCHEDULED REPORTSView data in the scheduled reports
CONFIGURE REPORT RETENTION PERIODRetention period is the period until which the the reports are stored in the server
Query Reports
ACTIONDESCRIPTIONPERMISSIONS
FULL CONTROLWRITEREAD
CREATE QUERY REPORTCreate Query reports for specific functionalities
VIEW QUERY REPORTView the query reports created in the server
MODIFY QUERY REPORTUpdate or edit existing query reports

 

Jump To