pdf icon
Category Filter

Roles Matrix

Mobile Device Manager Plus lets administrators designate roles to users. Apart from a set of predefined roles, MDM supports customization of roles as per the needs of your organization. For each of these user-defined roles, the permission to access specific sections of MDM can be configured as Full control, Write, Read or No access, as given in the table below.

Module specific access

Enrollment
ACTION DESCRIPTION PERMISSIONS
FULL CONTROL WRITE READ
ENROLL DEVICE (Admin) Admin Enrollment methods (except EMM) like ZTE, ABM, Knox
ENROLL DEVICE (Invite) Invite Enrollment methods like Self Enrollment
ADD/MODIFY AD Upload and renew Directory Services
APN'S CONFIGURATION Add or remove Apple Push Notification Ceritificates
CONFIGURING ABM TOKEN Access the Public key and upload the server token
CONFIGURING ENROLLMENT SETTINGS Configure the MDM Server authentication protocol,Device policy
KNOX ENROLLMENT Confugure the Knox Profile in MDM Server
ZTE ENROLLMENT Access the ZTE configuration
ENROLL LAPTOP/SURFACE PRO Downloading enrollment tool,assigning users to devices
AZURE ENROLLMENT Setting up Azure Portal and adding devices
CHROMEBOOK ENROLLMENT Enrolling Chrome devices
CONFIGURE AGENT SETTNGS Configure the Andriod/iOS MEMDM App Settings
DEVICE ACTIONS Re-assign User,Enroll Additional Device,Deprovision
Profile Management
ACTION DESCRIPTION PERMISSIONS
FULL CONTROL WRITE READ
CREATE PROFILE Create profiles for iOS,Android,Windows,Chrome,macOS,tvOS devices
MODIFY/UPDATE PROFILE Update existing profiles
MOVE TO TRASH/ DLT TRASH Remove profiles
VIEW TRASH View removed profiles, restore profiles, delete profile permanently
DISTRIBUTE PROFILE Distribute published profiles to groups/devices
REMOVE ASSOCIATED PROFILE Disassociate redundant profiles from groups/devices
VIEW PROFILE DETAILS View the different policies and restrictions implemented by a profile
App Management
ACTION DESCRIPTION PERMISSIONS
FULL CONTROL WRITE READ
ADD/MODIFY APPS Add Enterprise and Store apps to App repository
DELETE APPS Moving apps from App Repository to Trash
DISTRIBUTE APPS Distributing Apps from app repository to groups/devices
CONFIGURE ABM/VPP Upload location token for adding apps from ABM portal
SYNC ABM/ VPP APPS Syncing apps added from ABM portal
UPDATE APPS Updating exisitng apps to latest app versions
AUTOMATE APP UPDATES Permission to setup automate app update policy
APPROVE SPECIFIC APP VERSION Approving a specific app version among multiple versions present
DELETE SPECIFIC APP VERSION Deleting an outdated app version from the server
ADD/ MODIFY APP PERMISSION Make changes to existing app permissions provided by the app developer
ADD/ MODIFY APP CONFIGURATION Make changes to existing app configuration provided by the app developer
ADD ENTERPRISE APPS Adding In-house/ Enterprise apps specifically
REMOVE MANAGED APPS Remove unwanted Apps from Server to trash
Deprovision
ACTION DESCRIPTION PERMISSIONS
FULL CONTROL WRITE READ
Factory reset device (Complete wipe) Wipe all the data present in the device.
Revoke MDM(Corporate wipe) Wipe only the corporate data present in the device.
Content Management
ACTION DESCRIPTION PERMISSIONS
FULL CONTROL WRITE READ
ADD/ UPDATE/ DELETE DOCS Add Documents to MDM Server
DISTRIBUTE DOCS Distribute docs via server to groups and devices
CREATE POLICIES Create policies to view or share documents
VIEW POLICIES View existing policies applied to devices
Group Management
ACTION DESCRIPTION PERMISSIONS
FULL CONTROL WRITE READ
VIEW GROUPS & DETAILS Sight group members, policies, app associations
CREATE GROUPS Create User group,Device group, AD User group
MODIFY GROUP DETAILS Modify the details of a group like title, description, members
DELETE GROUP Delete groups from server
ADD MEMBERS TO A GROUP Move devices to selected groups
MOVE MEMBERS BETWEEN GROUPS Move members from one group to another if required
REMOVE MEMBERS Remove members from groups they're no longer required
Inventory Management
ACTION DESCRIPTION PERMISSIONS
FULL CONTROL WRITE READ
EDIT DEVICE DETAILS Fill in details of devices which aren't collected automatically
DEVICE ACTIONS Push Device actons like Scan, Remote View, Complete Wipe etc
APP BLOCKLISTING Provision to block apps which don't follow organizational policies
SCHEDULE DEVICE SCAN Schedule Device scan frequency, timeline and tenure
GEO TRACKING Configure Geo Tracking Settings
BATTERY LEVEL TRACKING Configure Battery Level tracking setting
CREATE/ MODIFY FENCE POLICY Create New fence policy and configure complinace settings
CREATE /MODIFY/DELETE FENCE REPOSITORY Create & Edit Fence Repostiory
OS Update Management
ACTION DESCRIPTION PERMISSIONS
FULL CONTROL WRITE READ
CREATE POLICY Configure automate OS policy for all platforms
MODIFY POLICY Modify/update existing policy settings
DELETE POLICY Delete redundant/unwanted policies
ASSOCIATE/DISASSOCIATE POLICY Abiltiy to associate/ disassociate policies from groups
VIEW POLICIES Permission to read the Automate OS policies in effect
Remote Control
ACTION DESCRIPTION PERMISSIONS
FULL CONTROL WRITE READ
ADD ZOHO ASSIST ACCOUNT Edit login details
REMOTE CONTROL/ VIEW Execute Remote Control/Remote view actions on devices
VIEW REMOTE CONTROL DETAILS Access the Remote Control settings
Announcements
ACTION DESCRIPTION PERMISSIONS
FULL CONTROL WRITE READ
CREATE ANNOUNCEMENT Create a new announcement and publish it
UPDATE ANNOUNCEMENT Update an exisiting announcement if required
DELETE ANNOUNCEMENT Delete an unwanted announcement from repository
MODIFY ANNOUNCEMENT Modify exisiting announcement in Actions
DISTRIBUTE ANNOUNCEMENT Distribute Announcements in Action
REMOVE ASSOCIATED ANNOUNCEMENT Remove an announcement which is published and distributed
VIEW ANNOUNCEMENT DETAILS View granular information about an announcement like Distributed devices, Acknowledged users etc
Reports
ACTION DESCRIPTION PERMISSIONS
FULL CONTROL WRITE READ
VIEW PREDEFINED REPORTS Access and view reports collected by the system by default
CREATE SCHEDULED REPORTS Create scheduled reports for specific use cases
VIEW SCHEDULED REPORTS View data in the scheduled reports
CONFIGURE REPORT RETENTION PERIOD Retention period is the period until which the the reports are stored in the server
CREATE QUERY REPORT Create Query reports for specific functionalities
VIEW QUERY REPORT View the query reports created in the server
MODIFY QUERY REPORT Update or edit existing query reports
Jump To