top of page
Writer's pictureairwatchhk

Android MAM mode

Updated: Feb 17, 2022

Workspace one provides various enrollment mode to cover different use cases. MAM allows an organization to enroll devices without MDM.

The process to get a device enrolled into MAM mode is exactly the same as to get a device enrolled into MDM mode using with the same WSO HUB app.

One of the MAM mode use cases is to distribute internal apps to BYOD devices. If apps are not ready to be published via Google Play store, MAM mode is the perfect alternative.

With the help from WSO Android SDK, an in-house developed Android app can be protected in app. For example, app level password policy is enforced in MAM mode. No device policy is involved in this case.


App security protections such as app password and DLP are powered by SDK. It is mandatory to embed WSO SDK into internal app to have a full app level protection.


Please note that when a MAM device is enterprise wiped, internal apps will still remain on the device but the associated app data will be wiped out.



Turning on MAM mode is straight forward. Please see following screen.


An MAM enrolled device is marked as “Hub Registered” while an MDM enrolled device is marked as “UEM Managed.



Internal app published for MAM enrolled devices cannot be marked as “Managed Access”. “Managed Access” app can only be available to MDM enrolled devices. Managed app can be removed by WSO and app removal is an MDM feature. Again, MAM removes app data instead the whole app when an enterprise wipe Is sent to a device.



An MAM enrolled device can get internal apps downloaded and installed from WSO without going to Google Play Store.


To enable app catalog inside of HUB app, you will have to make sure WSO Access integration has been setup properly.


Also make sure legacy catalog or HUB catalog is turned on




With the above settings, user can see his app catalog and administrator can see app inventory from UEM console.




When a MAM enrolled device user clicks to install an internal app, app is downloaded from UEM app catalog. In Contrast, non-internal public app is from the Google Play Store.






If an enterprise is running a BYOD program, privacy is always well protected. You should choose not to collect any sensitive information from a BYOD device by fine tuning the privacy policy.





Device Enrollment Demo:





Reference:




66 views0 comments

Recent Posts

See All

Comments


Post: Blog2_Post
bottom of page