Automated Device Grouping for MDM Policy Impact Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Unified endpoint management (UEM) solutions face challenges in identifying and addressing device deployment issues and predicting the impact of changes in mobile device management (MDM) policies across diverse devices with varying operating systems, hardware, and software configurations, particularly in bring-your-own-device environments.

Innovation Solution

A computing environment with an administrator console that allows administrators to define automations and conditional statements, validating them to determine the number of affected devices, providing real-time metrics and enabling granular decision-making through querying device profile databases.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If administrators manually review device information through the administrator console, then they can oversee device operations, but it becomes problematic to identify devices or deployment issues requiring attention among hundreds to thousands of devices

Engineering Contradiction:
Improvedevice oversight efficiencyVSAvoiddevice management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by automatically generating device groupings and deployment issue identifications before administrators need to review information. The management service proactively creates structured device groups based on enrollment criteria and pre-identifies deployment issues, so that when administrators access the console, the work is already organized and issues are flagged, eliminating manual sifting through hundreds of devices

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary layer between the raw device data and the administrator. This intermediary automatically processes device information, applies enrollment criteria, generates device groupings, and identifies deployment issues. This intermediary layer filters and structures the complex device data, presenting only relevant groupings and issues to administrators, thereby reducing the complexity of device management

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If MDM policies are applied across diverse devices with varying operating systems and configurations, then enterprise device security is improved, but it remains problematic to know the potential impact of policy changes

Engineering Contradiction:
Improvedevice securityVSAvoidpolicy impact information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system segments the diverse device population into distinct device groups based on enrollment criteria such as operating system type, device model, or configuration characteristics. By dividing the heterogeneous device fleet into homogeneous segments, the system can accurately determine policy impact for each group, allowing administrators to see exactly which segmented groups will be affected by policy changes rather than treating all devices uniformly

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the parameter of policy application from a blanket approach to a targeted approach by modifying enrollment criteria parameters. Administrators can define specific enrollment criteria parameters (operating system version, device type, configuration settings) that dynamically determine which device groups are affected by policy changes, providing precise visibility into policy impact based on these parameter variations

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10999720B2Defining automations for enrolled user devices
Publication Date: 2021.05.04 OMNISSA LLC
  • US10999720B2 patent drawing
  • US10999720B2 patent drawing
  • US10999720B2 patent drawing

AI summary

Various examples are described for defining automations for client devices enrolled with a management service. A computing environment can cause one or more user interfaces to be shown in a display of an administrator device that include at least one field for receiving a conditional statement to generate an automation associated with client devices enrolled with the management service. The computing environment can validate the conditional statement based on validation criteria and, in an instance in which the conditional statement has been validated, generate the automation based on the conditional statement, the automation causing the computing environment to perform a predetermined action automatically when the conditional statement is satisfied.