Working with Oreo without PIN / Pattern
I am running hundreds of Android Oreo Zebra devices managed under AEDO and have seen some nuanced issues with certificates installing without a lock screen set, but I have not seen those issues with MX configurations applying. Assuming you're using AEDO for the devices, do you have the Zebra specific AE plugin installed as well?
To confirm Matt's answer, you currently will have to install the certificates using MX. We have certificate infrastructure set up for MobiControl to request AD certificates and assign them to devices on enrollment but it doesn't work on Oreo. SOTI says the Zebra Oreo devices do/can not support installation of certificates via MobiControl mechanisms. SOTI claims Zebra has changed something in 8 and they are apparently working with Zebra to find a resolution. I'm trying to work my Zebra contacts to get more information.
Hi Scott, That's excatly our Problem!
Thank you. Hopefully they'll find a solution :-(
Where is the exact problem?
We are using it without Pin/Pattern too, because the devices are protected by the Kiosk Mode and it works well on Android 7 and 8.
1. Scanning Stagenow Bypass
2. Scanning Stagenow Profile Barcodes
Android 7 to 8 device:
1. Applying zip to device
2. Running update
(3. !Factoryreset!) i'm not sure now but i think its needed because of work profile
4. Scanning Stagenow Bypass
5. Scanning Stagenow Profile Barcodes
BUT you need different Profiles in Mobicontrol!! Android Plus for Android 7 devices and Android Enterprise for Android 8 Devices.
Tipp: To use Android 8 and 7 in same folders in Mobicontrol, set filter criteria in profiles to specify it by OS Version.
The original post was referring specifically to installing device certificates to Zebra devices without assigning a PIN. Normally/Historically possible with Zebra but now not on Oreo, at least via MobiControl without MX intervention.
Even we had same situation. Good news that SOTI got the fix and they are due to release new agent. Happy days :) :)
good to hear that ;-)
Do you have any further Information in which Version this fix will be implemented? We tried it with Version 126.96.36.1993 today but no success. After I set the Pin with MobiControl the Certificate gets installed immidiately...
I assume it would be next Agent Release but not got the information on agent version yet. Once it's released will update the thread.
To meet our security standards we are putting pin code, installing certificate (AD user for each device) and then removing pin code when wifi is set up. We are good for the time while certificate is still valid. Other applications which uses certificates wont work as they will ask to set up pin code each time they try to access keystore.
Soti agent 14.1.3 arrived with this issue finally fixed. Big thank you to them.