Adaptive Device Enrollment via Localized Security Policies
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Enterprise Mobility Management (EMM) and Mobile Device Management (MDM) systems are inefficient due to blanket enrollment requirements that do not account for varying security needs of different user groups and require a dedicated agent application for enrollment, which slows down the process and can discourage employees from enrolling.
Innovation Solution
The system dynamically determines enrollment requirements based on the user device's operating system and organizational group, allowing direct enrollment without an agent application when possible, and provides a portal application for streamlined enrollment and management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If blanket enrollment requirements are applied to all devices, then security needs are met, but employee productivity decreases due to unnecessary enrollment steps
Solution Approach 1:
The patent applies different enrollment requirements to different organizational groups based on their specific security needs. High-security groups require full enrollment while low-security groups can use streamlined enrollment without dedicated agent applications, making the security approach localized to each group's actual requirements rather than applying a uniform blanket policy
2Reliability
If a dedicated agent application is required for enrollment, then enrollment can be performed, but the enrollment process becomes slower and more complex
Solution Approach 1:
The patent extracts the dedicated agent application requirement from the enrollment process for low-security organizational groups. Instead of requiring all devices to download and install separate enrollment applications, the system allows streamlined enrollment through existing applications for groups that don't require full management capabilities, eliminating unnecessary steps and time loss
Solution Approach 2:
The patent makes the enrollment system universal by enabling enrollment to occur through different pathways depending on needs: high-security groups use dedicated agent applications while low-security groups use existing applications. This multi-functionality allows the same enrollment infrastructure to serve both requirements without forcing all users through the more complex dedicated application path
3Reliability
If dedicated agent applications are injected into the enrollment process, then device management is enabled, but device complexity increases
Solution Approach 1:
The patent applies device management complexity locally rather than universally. High-security organizational groups receive full device management capabilities through dedicated agent applications, while low-security groups receive streamlined management through existing applications, reducing the complexity burden on devices that don't require full management functionality
4Reliability
If blanket enrollment requirements are applied, then security needs are met, but adaptability to different user groups decreases
Solution Approach 1:
The patent makes the enrollment system adaptive by applying localized security policies to different organizational groups. The system identifies which group a device belongs to and applies the appropriate enrollment requirements - full enrollment for high-security groups, streamlined enrollment for low-security groups - thereby adapting the security approach to each user group's actual needs rather than applying a one-size-fits-all policy
Data Source
Figure 1
Figure 2
Figure 2
AI summary
Examples described herein include systems and methods for dynamically determining enrollment requirements and enrolling a user device into a management system. The systems and methods can differ based on the type and version of operating system executing on the user device. With some operating systems, enrollment can be completed through a single application that performs other functionality, such providing single-sign-on access to enterprise resources. With other operating systems, enrollment can be completed by pausing the first application and requiring installation of an agent application to complete enrollment. The determination of how and when to enroll a user device can be done automatically and can be based on an organizational group to which the user belongs.