Coexistence of Legacy and New Device Management Applications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing device management systems, such as System Center Configuration Manager (SCCM), prevent multiple management applications from co-existing on a single device, making it difficult for administrators to transition from a legacy management application to a new one due to differing policies and the inability for new applications to perform management functions.
Innovation Solution
A client device is configured to intercept and spoof terminate commands from legacy management applications, allowing new management applications to co-exist and eventually replace the legacy ones, while also enabling automatic enrollment of devices with a management service through provisioning, eliminating the need for end users to provide login credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a legacy management application (e.g., SCCM) is installed on a device, then device management functions are provided, but the application prevents other management applications from co-existing by updating the registry and terminating other management services
Solution Approach 1:
The patent introduces a registry key as an intermediary indicator that signals to the legacy management application whether another management application is present. This intermediary mechanism allows the legacy application to detect the presence of new management applications and adjust its behavior accordingly, enabling co-existence without direct conflict between the applications
Solution Approach 2:
Instead of the legacy management application actively preventing other applications from running, the system inverts the approach by having the legacy application check for the presence of other applications through registry indicators and voluntarily yield management rights when detected. This inversion transforms the conflict into a cooperative arrangement where the legacy application becomes aware of and accommodates new applications
2Adaptability or versatility
If administrators need to transition from a legacy management application to a new one, then updated management policies can be implemented, but the transition is difficult because the legacy application prevents the new application from performing management functions
Solution Approach 1:
The system performs preliminary actions by establishing registry indicators before the transition process begins. These indicators are pre-configured to signal the presence of new management applications, allowing the legacy application to proactively yield control and enabling a smooth transition without conflicts or errors during the migration process
Solution Approach 2:
The patent implements a feedback mechanism where the legacy management application continuously monitors registry indicators to detect the presence of new management applications. This feedback loop allows the legacy application to automatically adjust its behavior, terminate its own services, and yield control when a new application is detected, simplifying the transition process
3Ease of operation
If automatic enrollment is implemented to simplify the enrollment process, then end users do not need to provide login credentials, but the system must securely identify and enroll devices with a management service
Solution Approach 1:
The patent implements self-service enrollment where the device automatically enrolls with the management service without requiring user intervention. The system uses device identifiers and registry information to autonomously complete the enrollment process, provisioning the device with appropriate policies and protection mechanisms while maintaining security through automated authentication and enrollment verification
Data Source
AI summary
Various examples for managing a client device having multiple enrolled user accounts thereon are described. A computing device is directed to store a mapping of a client device to a plurality of user accounts active. The computing device communicates remotely with a management application on the client device to identify an active one of the user accounts from an operating system of the client device. In response to receipt of information associated with a first one of the user accounts active on the client device, the computing device enrolls the first one of the user accounts with a management service in association with the client device. In response to receipt of information associated with a second one of the user accounts active on the client device, the computing device enrolls the second one of the user accounts with the management service in association with the client device.


