Dynamic Enrollment Level Detection for Application Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users in an enterprise setting face challenges in managing device enrollment levels for accessing various applications, as different applications require different levels of device management, leading to user reluctance in enrolling devices unless necessary, and a lack of transparency in understanding the required enrollment levels for accessing specific applications.
Innovation Solution
A management service determines the required enrollment level for a client device based on the application accessed, facilitating on-demand enrollment by authenticating user credentials and providing information about the enrollment requirements, allowing users to enroll their devices only when necessary for specific applications, thereby managing compliance with enterprise data security policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users enroll their devices with enterprise mobility management systems to access applications, then access to applications requiring device management is enabled, but user reluctance increases and device management overhead increases
Solution Approach 1:
The system dynamically determines and communicates enrollment level requirements based on the specific application being accessed. Instead of requiring full device enrollment for all applications, the system adapts the enrollment requirement to match the actual needs of each application, thereby reducing user reluctance while maintaining security.
Solution Approach 2:
The system provides feedback to users about the specific enrollment levels required for accessing different applications. This transparency allows users to understand why certain enrollment levels are necessary, reducing reluctance by fostering informed consent rather than forced enrollment.
2Loss of information
If the system provides detailed information about enrollment requirements for each application, then user transparency and understanding improve, but system complexity increases
Solution Approach 1:
The system segments application access into different enrollment levels (e.g., full device enrollment, partial device enrollment, no enrollment required). This segmentation allows the system to provide targeted information about specific enrollment requirements for each application category, improving user transparency without overwhelming complexity.
Solution Approach 2:
The system applies different information disclosure strategies based on the specific application and its enrollment requirements. Instead of a uniform complex interface, the system tailors the information presentation to match the specific needs of each application, reducing overall system complexity while maintaining detailed transparency where necessary.
Data Source
AI summary
Examples of detecting whether a device meets an enrollment level are disclosed. In one case, a method for providing access to an application on a client device includes receiving a request to access an application from the client device, determining an enrollment level associated with the application, and determining that multi-factor authentication is required for access to the application on the client device based on the enrollment level associated with the application. The method can also include initiating multi-factor authentication on the client device before access to the application is permitted. The method can also include determining that multi-factor authentication is successful on the client device, transmitting a management component to the client device, and installing the management component on the client device for enrollment as a managed device with a management service.


