In Android Pie? Core Themes for Android Pie
Total Page:16
File Type:pdf, Size:1020Kb
What’s New in Android Pie? Core themes for Android Pie Managed Dedicated Security Devices Devices Keystore Work Profile Shared use devices Encryption & device Fully managed Kiosk & rugged integrity devices devices Device provisioning Lock task mode What’s new in Managed Devices Work profile user experience Current Android Pie experience improvements Apps mixed together Apps separated into work and personal Hard to parse tabs duplicate apps Clear and labelled segregation of Disconnected from managed & non- Android system UI managed spaces Feels integrated into Android system UI Turn off work toggle easily discoverable User education Updated elements Improved user education upon profile creation Updated badge UI to match Material Design and Android system updates Ability to toggle off the work profile brought directly into the work tab Work profile clearly labelled as managed Turn Off EMMs can set work profile policy to turn the work profile on or programmatically off at set times or on demand Simplified switching Simple profile between the switching personal and work version of the same app What’s new in Dedicated Devices In Android Pie, we focused on 3 dedicated device needs 1 2 3 Provisioning Locking devices Enabling proper login concepts thousands Into a consistent for shared use of devices experience when devices at scale shared Seamless Bundled QR reader QR provisioning and support for WiFi configurations Support for APN Expanded provisioning configuration and control of more settings (e.g. timezone, airplane mode) New Policy Settings in Android Pie Prevent changes to date, time, & timezone Set timezone & time (Device Owner only) Block use of airplane mode Prevent apps from using metered data Prevent changes to location providers Disable ambient display for notifications Prevent changes to brightness Set freeze periods to postpone pending OTA firmware updates Prevent changes to screen timeout Disable printing (at framework level) Locking a device to multiple apps Current Android Pie experience improvements “LockTask” mode LockTask can support supports only a single multiple apps with an app included launcher App developer must Any app can be put declare support for into lock-task mode lock-task mode Greater UI flexibility Partners must with options to show develop custom or hide status bar launcher icons, power menu, home, recents and notifications Shared devices Public sessions - user data erased at the end of every session (i.e. kiosks) Shift worker devices - multiple employees share devices, with data preserved between sessions but fully separated at all times. Postpone OTA updates Postpone platform updates for up to 90 days (e.g. holidays) Mandatory 60 day cooling-off after postpone period What’s new in Android 9 security Key security enhancements Separate work Data leakage Verified device Security & challenge improvements access network logging Admins can Prevent the New APIs to work Unique IDs for require different sharing of data with keys and network and PINs and across work & certificates used security events. timeouts for personal profiles to securely Expanded coverage personal and - including via identify devices of security-related work profiles adb actions. ...and more! goo.gl/nh5bpM Device Admin deprecation Announced in December 2017 APIs marked as deprecated in P Will be removed entirely in following release Rudimentary local administration Outdated security Device admin: model Why is it going away for Malware abuse Enterprise? OEM API challenges DA vs AE Enrollment Device Admin Android Enterprise Manual Download, Zero-touch (8.0+) Sideloading (unsafe) QR Code (7.0) Barcode NFC (6.0) (on some OEMs) DPC Identifier (6.0) DA vs AE Applications Device Admin Android Enterprise No Google Play Google Play is most integration reliable and robust app delivery service App Wrapping Silent installs through Unknown Sources managed Google Play Private app publishing Alpha/Beta publishing Managed App Config DA vs AE Flexibility Device Admin Android Enterprise “One Size Fits All” Flexible Range rigid management of Management options: - Managed Profile - Managed Device - Managed Device w/ Managed Profile DA vs AE Device Management Device Admin Android Enterprise Limited Device Extensive Controls Controls Consistent across all OEM API Reliance OEMs Battery Intensive Native Device Android Enterprise Android Admin + Device Admin Enterprise Only Pre-Lollipop Lollipop Marshmallow Nougat Oreo Pie Next release 2.3.3 - 4.4 5.0 - 5.1 6.0 7.0 - 7.1 8.0 - 8.1 9 DA policy built Support for Support for Improvements New device- Advanced AE continued for rudimentary work profile fully managed for work wide policies policies, support & local admin tasks device profiles & fully & support for enhanced dedicated managed personally security, device use devices enabled work & UX polish cases devices DA API Remove warnings enterprise DA API support Conclusion Lots of great features in Android Pie Managed Dedicated Security Devices Devices.