XperiaTM in Business Xperia Configurator Cloud - The management tool by Sony Mobile Communications for swift and secure deployment of mobile devices

Page created by Holly Terry
 
CONTINUE READING
XperiaTM in Business Xperia Configurator Cloud - The management tool by Sony Mobile Communications for swift and secure deployment of mobile devices
Xperia in Business
                   TM

Xperia Configurator Cloud
The management tool by Sony Mobile Communications for swift and
secure deployment of mobile devices

April 2018
XperiaTM in Business Xperia Configurator Cloud - The management tool by Sony Mobile Communications for swift and secure deployment of mobile devices
Xperia Configurator Cloud

            ABOUT THIS DOCUMENT
            Products covered

            This document describes Xperia in Business enterprise services and features in Sony Mobile
            devices. Please refer to the tables in the Product overview document for details about
            supported products and software versions.

            Note: xxx in software versions denotes the number “001-999”.

            To find the software version of a device:

            •     Select About phone in Settings > System (Android 8.0)
            •     Select About phone in Settings (Android 7.1 or lower)

            Limitations to services and features

            Some of the services and features described in this document might not be supported in all
            countries/regions or by all networks and/or service providers in all areas. Please contact your
            network operator or service provider to determine availability of any specific service or feature
            and whether additional access or usage fees apply.

            Trademarks and acknowledgements

            All product and company names mentioned herein are the trademarks or registered trademarks
            of their respective owners. Any rights not expressly granted herein are reserved. All other
            trademarks are property of their respective owners.

            Visit www.sonymobile.com for more information.

            Document release date

            April 5, 2018

                This White paper is published by:              This document is published by Sony
                                                               Mobile Communications Inc., without any
                Sony Mobile Communications Inc.,               warranty*. Improvements and changes
                                                               to this text necessitated by typographical
                4-12-3 Higashi-Shinagawa, Shinagawa-ku,        errors, inaccuracies of current information
                Tokyo, 140-0002, Japan                         or improvements to programs and/or
                                                               equipment may be made by Sony Mobile
                www.sonymobile.com                             Communications Inc. at any time and
                                                               without notice. Such changes will, however,
                © Sony Mobile Communications Inc., 2009-       be incorporated into new editions of this
                2018.                                          document. Printed versions are to be
                                                               regarded as temporary reference copies
                All rights reserved. You are hereby granted    only.
                a license to download and/or print a copy
                of this document.                              *All implied warranties, including without
                                                               limitation the implied warranties of
                Any rights not expressly granted herein are    merchantability or fitness for a particular
                reserved.                                      purpose, are excluded. In no event shall
                                                               Sony or its licensors be liable for incidental
                First released version (April 2018)            or consequential damages of any nature,
                                                               including but not limited to lost profits or
                                                               commercial loss, arising out of the use of
                                                               the information in this document.

Xperia in Business White paper                                                                                  2
XperiaTM in Business Xperia Configurator Cloud - The management tool by Sony Mobile Communications for swift and secure deployment of mobile devices
Xperia Configurator Cloud

            Table of contents

            ABOUT THIS DOCUMENT........................................................................................................... 2

            INTRODUCTION........................................................................................................................ 4

            MARKET TRENDS AND STRATEGY.............................................................................................. 5

            WHO CAN USE IT?.................................................................................................................... 6

            GETTING STARTED.................................................................................................................... 6

            MASS DEPLOYMENT PROGRAM (MDP)....................................................................................... 7

            ENROLLING EXISTING AND BYOD DEVICES................................................................................. 8

            OVERRIDE AND RECONFIGURE YOUR DEVICE FLEET..................................................................11

            PUTTING THE IT ADMIN IN CONTROL........................................................................................11

            EMPOWERING THE MOBILE WORK FORCE................................................................................ 13

            DEPLOY A THIRD PARTY MDM SERVICE................................................................................... 13

            CLOUD AND DEVICE SECURITY................................................................................................ 14

            ANDROID ENTERPRISE WITH XCC............................................................................................ 16

            SYSTEM AND PLATFORM OVERVIEW....................................................................................... 17

            SUPPORT............................................................................................................................... 17

            COMPLIANT DEVICES.............................................................................................................. 18

            XPERIA CONFIGURATOR CLOUD FEATURE OVERVIEW............................................................... 18

            SUMMARY OF BENEFITS.......................................................................................................... 19

Xperia in Business White paper                                                                                                                          3
XperiaTM in Business Xperia Configurator Cloud - The management tool by Sony Mobile Communications for swift and secure deployment of mobile devices
Xperia Configurator Cloud

Xperia Configurator Cloud
                                 INTRODUCTION
                                 Xperia Configurator Cloud (XCC) is a cloud based tool that enables swift
                                 and secure mobile device management in an organization. Developed by
                                 Sony Mobile Communications, the tool provides an effective solution for
                                 configuring Sony Xperia devices.

                                 XCC enables institutions to create device policies for their employees and
                                 deploy these policies OTA (over-the-air). These device policies can be
                                 everything from enforcing needed security policies, like a six digit PIN, to
                                 productivity related features, like Microsoft Exchange (EAS) credentials, VPN
                                 / Wi-Fi settings, and application availability through Black and White lists.
                                 XCC also fully supports all Sony Xperia specific APIs, policies and settings
                                 that are extending the standard Android OS, for example disable camera
                                 and specific Bluetooth profiles.

                                 On top of this the XCC platform can be used for more advanced features like
                                 mass deployment, configuring single-purpose-devices (aka kiosk-mode),
                                 and provisioning of 3rd party MDM clients.

                                 XCC is delivered as a free service and it is released in all markets (excluding
                                 China and Japan as of August 2017).

Xperia in Business White paper                                                                                     4
XperiaTM in Business Xperia Configurator Cloud - The management tool by Sony Mobile Communications for swift and secure deployment of mobile devices
Xperia Configurator Cloud

                                 MARKET TRENDS AND STRATEGY
                                 A Mobile Device Management (MDM) solution enables an organization
                                 to manage and control a variegated range of device capabilities, data
                                 security and network connectivity. It also incorporates mobile application
                                 management, mobile content management, and identity management.
                                 Historically, most of the MDM solutions were designed to manage and
                                 protect smartphones, however, many them have now evolved to handle
                                 advanced mobile devices running on similar OS. Mobile Device Management
                                 has been a forte of frequent innovations and have evolved rapidly to protect
                                 almost every aspect of hardware and software on any mobile device. The
                                 global market for MDM solutions is anticipated to expand with a double
                                 digit growth rate throughout the forecast period.

                                 Configure anything – in the coming years we will experience mobile device
                                 management to move beyond smartphones and tablets, to also incorporate
                                 other devices like TVs, In-car systems, VR-devices, and eventually IoT. IoT
                                 will spark the second wave of growth in the market for MDM and EMM
                                 (Enterprise Mobility Management) platforms and services. Moreover, as
                                 MDM vendors enhance their security and adaptability features and extend
                                 them to other electronic devices such as TVs and smart watches, demand
                                 for other and more advanced mobile device management solutions is
                                 projected to continue to rise going forward.

                                 With increasing challenges & complications for IT teams, MDM tools
                                 have evolved with new features, like remote lock/wipe, geo-fencing, and
                                 others. Employers can now keep corporate data separate from personal on
                                 employee devices, prevent unauthorized app use, allow anytime, anywhere
                                 access to resources, and more. Apart from adding to the security strategy of
                                 the organization one of the most popular use cases that fuels the market for
                                 MDM solutions relates to application management, meaning to provide your
                                 employees with the right tools to be productive at work.

                                 To summarize, some key market drivers for implementing and deploying a
                                 MDM solution within your organization are:

                                   •   Smartphone penetration: Global penetration of smartphones
                                       and mobile internet encourage the growth of enterprise mobility.
                                       Businesses are realizing the significance of the use of mobile devices
                                       at work and the need to manage them to improve productivity and
                                       security.

                                   •   Need of real-time data: Mobility enables employers to deliver the
                                       required information to the right employee at the desired time.
                                       However, this involves the risk of data being unauthorized accessed
                                       and/or misused, which drives the need for device management tools.

                                   •   Business process automation: The use of mobile devices has enabled
                                       automated business processes, which result in reduced costs, faster
                                       turnarounds, and more benefits. An efficient automation needs
                                       managed and controlled use of mobile devices, further driving the
                                       MDM market.

                                 Based on these market findings and on where the market is heading in
                                 relation to smartphones, it will be critical to choose a flexible cloud based
                                 MDM solution going forward. This is also important to secure a future proof
                                 solution that is able to incorporate new use cases evolving, e.g. within IoT.
                                 Cloud platforms, like XCC, are highly adaptive to changing market conditions
                                 and provide efficient means of enforcing corporate guidelines in mobility.
                                 They are smart solutions for the second wave in MDM, and, not to forget,
                                 they are cost effective.

Xperia in Business White paper                                                                                  5
XperiaTM in Business Xperia Configurator Cloud - The management tool by Sony Mobile Communications for swift and secure deployment of mobile devices
Xperia Configurator Cloud

                                          WHO CAN USE IT?
                                          XCC has been designed to scale with your business, meaning that it will
                                          work equally well for small- to medium sized organizations up to large
                                          institutions with thousands of devices. As it is a cloud based platform
                                          it is well suitable for distributed organizations, both regionally and
                                          internationally. XCC is designed with a tree structure of administrators that
                                          can be assigned to manage all or parts of the organization’s device fleet.
                                          Going forward you will be able to assign different permission levels as
                                          needed and the administrator accounts can easily be transferred or re-
                                          assigned to map your organizational setup.

                                          The high level of security measures implemented both on the cloud and
                                          the device side makes XCC the perfect platform also for private or public
                                          organizations where safe-guarding corporate data is essential.

                                          There are two main target audiences for XCC:

                                            •   IT administrators, or any other assigned entities within the institution
                                                who manages the organization’s device fleet. The IT administrators
                                                will normally be the main account holders with the web tool and
                                                cloud platform, and in charge of creating and deploying device
                                                configurations.

                                            •   Employees, or the end-users of the service, who will receive and
                                                accept to install the configuration being pushed to their devices.

                                          When working with mobile device management it is important to know
                                          that it is not only about configuring new devices, but also to be able to
                                          re-configure and update your already enrolled devices. This is why XCC is
                                          designed not only to handle COPE (Company Owned Personally Enabled)
                                          devices via our Mass Deployment Program (MDP), but also to work equally
                                          well for deploying BYOD (Bring Your Own Device), CYOD (Choose Your Own
                                          Device) and COSU (Company Owned Single Use, “kiosk mode”) devices.

                                          GETTING STARTED
                                          Sony Xperia devices can be configured for corporate device enrollment
                                          using a variety of methods. End-users can manually setup the devices
                                          for work with a set of instructions from the IT department, however for
                                          most organizations this is quite a cumbersome, ineffective and non-user
                                          friendly solution. Instead XCC offers an automated process of deploying
                                          configurations using native XCC Configuration Profiles. The IT admin
                                          may also choose to provision a 3rd party MDM client to the device or a
                                          combination of both.

                                          In some deployments, an IT department may want to mass configure a
                                          set of devices with the same settings and apps before the devices are
                                          distributed to end users. This is often the case when the same device will
                                          be used by different people throughout the day, like in healthcare, logistics,
                                          and the services sector (hotels, restaurants etc). Other deployments require
XCC is featured in the ”Introduction to   the devices to be tightly managed and reset to a specific configuration on a
Xperia” – get to know it guide            regular basis.

                                          Regardless if the device will be personally assigned to a unique end-user, or
                                          if it will be used in a non-personal context, such as a single-purpose device,
                                          XCC can be used to deploy the required set of policies and settings. This can
                                          be done either directly as an out-of-the-box experience (new COPE devices)
                                          or at any later stage in the deployment process.

Xperia in Business White paper                                                                                             6
XperiaTM in Business Xperia Configurator Cloud - The management tool by Sony Mobile Communications for swift and secure deployment of mobile devices
Xperia Configurator Cloud

                                         XCC provides you with three main activities as an IT Administrator:

                                           •   Prepare your devices for work and deploy relevant configurations.
                                               Configurations can be unified across the whole organization or unique
                                               down to each individual device level.

                                           •   Assign devices for specific use cases or to make them personally
                                               enabled. Personally enabled means ensuring that a specific device
                                               and associated IMEI number is tied to an employee ID, including for
                                               example the corporate email account or server access.

                                           •   Supervise your organization’s entire device fleet. XCC provides you
                                               with detailed control and you are able to do continuous updates and
                                               modifications to match corporate guidelines and requirements from
                                               the mobile work force.

                                         The user interface of Xperia Configurator Cloud is accessible from the
                                         latest versions of most internet browsers. The tool works with Xperia
                                         devices that have an activated Xperia Configurator Cloud account. After
                                         you submit the information by clicking Sign up, you will receive an email
                                         with a link to activate your Xperia Configurator Cloud account. The link
                                         directs you to an account activation page. On the account activation page,
                                         submit your password and click Activate. This verifies your email address
                                         and takes you to the login page, where you can now login to your account.
MDP pane that will appear in the Setup   When you have finalized the sign up process you will be able to tailor your
wizard when choosing to include a six    account to fit your organizations needs in terms of number of sub users and
digit PIN                                administrators, number of configuration types etc.

                                         You are now ready to create your first device configuration. If you need
                                         more information you can download the Xperia Configurator Cloud
                                         User Manual from https://www.sonymobile.com/global-en/xperia/
                                         business/#service-and-support.

                                         MASS DEPLOYMENT PROGRAM (MDP)
                                         With mass deployment the hassle of physical unboxing of new devices
                                         for IT admins is removed. The user experience for the employee is also
                                         improved by reducing the number of interactions needed on the device to
                                         get enrolled.

                                         XCC’s MDP solution allows IT admins to have new devices automatically
                                         enrolled and configured at first startup. As soon as a device has been
                                         started for the first time and connects to the network, the device
                                         will check if its IMEI number is registered with a company and set for
                                         automatic configuration. At this point the IT admin has two options in the
                                         administrator console; either to deploy a generic configuration for all, or to
                                         add a six digit PIN verification that will appear in the setup wizard. The latter
                                         will not only deploy the configuration, but also tie the device to a particular
                                         employee ID.

                                         There are potential use cases when the six digit PIN verification is not
                                         needed, for example when implementing a single-purpose device, when
                                         using XCC to provision a 3rd party MDM client, or when deploying a generic
                                         profile with post-configuration and end-user registration via the Settings
                                         menu. To understand more about the use cases where a six digit PIN is
                                         not needed and how that will work for your organization please send your
                                         enquiry to the Sony Support desk.

Xperia in Business White paper                                                                                           7
XperiaTM in Business Xperia Configurator Cloud - The management tool by Sony Mobile Communications for swift and secure deployment of mobile devices
Xperia Configurator Cloud

                                       An important step in the MDP process is to get the actual IMEI numbers
  BYOD (Bring Your Own Device)         uploaded to your XCC account. This can be done in either of two ways:
  Employees bring their personal
                                         •   Download the XCC IT Admin app from Google Play and use the app to
  device and get full responsibility
                                             scan the barcode on the box containing the new Xperia smartphone.
  for choosing and supporting it.
                                         •   Acquire and import the list of IMEIs directly from an authorized Sony
  CYOD (Choose Your Own                      distribution partner.
  Device)
  Employees get to choose from a       Please note that MDP is valid only for new devices (COPE and COBO) or
  list of devices that the company     completely re-flashed devices. Using XCC for mass deployment is equal
  has approved.                        to using either Apple´s DEP (Device Enrollment Program) or Google’s Zero
                                       Touch program. This means that there are some important additional
                                       benefits that XCC delivers on top of MDP:
  COPE (Company-Owned,
  Personally-Enabled)                    •   Enrollment of already existing and BYOD devices.
  Employees are provided with a
  device chosen and paid for by          •   The 6 digit PIN verification, which allows the IT admin to easily assign a
  the company, but they can also             device and associated IMEI with a unique employee ID.
  use it for personal activities.
                                         •   Making use of and deploy the specific Sony Xperia APIs on top of
                                             generic Android for added functionality and increased security
  COBO (Company-Owned,                       measures.
  Business Only)
                                         •   XCC allows for having a mass deployment feature within your
  Employees are provided with a
                                             organization without the need of registering your company with
  device that is only allowed for
                                             Google.
  business use by the company.
                                       ENROLLING EXISTING AND BYOD DEVICES
  COSU (Company-Owned,
  Single-Use)                          It is a breeze to configure Sony Xperia devices with XCC and it allows for
  “Kiosk Mode” devices that fulfill    maximum flexibility in your workflow. After registration of your company
  a single use case, such as digital   details is done and your login credentials have been created no further
  signage, ticket printing, or         verifications are needed, since XCC is based on domain ownership. The
  inventory management.                domain ownership will provide an extra layer of security, making sure that
                                       there is a clear match between enrolled and registered IMEIs and the end-
                                       users and employee IDs.

                                       Once inside the tool you will directly be able to create your first User
                                       Configuration Profile (UCP). The UCP can be per individual, per unit, or
                                       companywide. The available configurations are structured and grouped in
                                       a dynamic UI overview pane, where you simply click your way through the
                                       different policies and settings you would like to include in your UCP. The list
                                       below is a high-level view of available parameters you can control.

Xperia in Business White paper                                                                                           8
XperiaTM in Business Xperia Configurator Cloud - The management tool by Sony Mobile Communications for swift and secure deployment of mobile devices
Xperia Configurator Cloud

                                            1. General / Password

                                            2. Restrictions

                                            3. WiFi

                                            4. Mail

                                            5. Exchange ActiveSync

                                            6. Digital certificates

                                            7. Security & Privacy

                                            8. Applications

                                            9. Shortcuts

                                          Being a cloud based platform you will always have access to the latest
                                          version of the service. This means that you can be sure your employees are
                                          all on the same configuration level regardless of device type. Harmonization
                                          of policies and settings across the organization is vital for any contemporary
                                          fleet management strategy. This is made possible from the fact that XCC is
                                          pre-loaded onto all Sony Xperia devices. XCC can be easily accessed at any
                                          time through Accounts in the Settings menu, where you can activate XCC as
                                          your device configuration solution.

                                          With your UCP created and saved onto the system, the next step is to assign
                                          the configuration to specific device IMEIs and in effect individual employees.
                                          This process is fully automated in the IT Admin console where the IT
                                          admin will initiate a notification being sent out to the employee that a new
                                          configuration is waiting to be installed. Once the employee has accepted
                                          the configuration to be installed, XCC will do an OTA installation on the end-
                                          user’s device.

     XCC account activation in the Set-
     tings menu

Xperia in Business White paper                                                                                         9
XperiaTM in Business Xperia Configurator Cloud - The management tool by Sony Mobile Communications for swift and secure deployment of mobile devices
Xperia Configurator Cloud

                                 This fully automated process allows for fast and seamless enrollment of
                                 your Xperia devices. The platform will inform the IT admin directly on the
                                 number of successful deployments that has been made and those that are
                                 still in progress.

                                 Having XCC pre-installed on all Xperia devices guarantees a stable service
                                 and hassle-free device deployment. Some of the key tasks performed by the
                                 pre-installed XCC application are:

                                   •   It will automatically check with the XCC platform for updates.

                                   •   Simplified account creation process for the end-user.

                                   •   Initiating your MDP enrollment of new devices.

                                   •   Receiving and managing profiles on the device.

                                   •   Optimized towards the Sony specific enterprise APIs.

                                   •   Analyzing the configuration files for increased security.

                                   •   Fast authentication and installation.

                                   •   Security based on platform enablers.

Xperia in Business White paper                                                                                10
Xperia Configurator Cloud

                                 OVERRIDE AND RECONFIGURE YOUR DEVICE FLEET
                                 Once the device has been enrolled it will also be assigned for remote control
                                 and parts or all of the device administrator rights has been handed over
                                 to the IT admin of the organization. If the employee decides to leave the
                                 company a wipe will be needed to remove the administrator. As mentioned
                                 initially, XCC supports all types of mobile device management models, from
                                 a strict corporate owned, business only model to a less strict model where
                                 the organization allows a separation between a private and a business part
                                 on the device.

                                 The transfer of administrator rights to the IT admin means that the IT admin
                                 easily can reconfigure the device fleet by issuing a new UCP that will replace
                                 and overwrite the existing configuration.

                                 As it is possible to have more than one MDM client running on the same
                                 device, although only one can be set as device owner and the subsequent
                                 being run as a managed profile, situations with conflicting policies and
                                 settings may occur. From this perspective XCC and Xperia devices have been
                                 designed to always put security first, meaning that if two policies are in
                                 conflict the configuration that provides the highest level of security, both
                                 towards the employee and the company, will override the other.

                                 PUTTING THE IT ADMIN IN CONTROL
                                 There are many reasons why having a mobile device management service
                                 makes good sense. Apart from contributing to greater business efficiency,
                                 OPEX savings and a higher degree of security / protection of corporate
                                 data, it also puts the IT department in control of the device fleet.

                                 The ability through XCC to monitor and track your device fleet is a key step
                                 towards harmonization of your overall mobility strategy, ensuring that all
                                 employees are compliant towards corporate security guidelines and that all
                                 are equipped with the right tools to be productive at work. Inside XCC the
                                 IT admin at any time can get real time information on deployment trends
                                 and what configurations has been implemented in different parts of the
                                 organization.

Xperia in Business White paper                                                                                11
Xperia Configurator Cloud

                                 KIOSK MODE
                                 Deploying as a single purpose device, so called kiosk mode, is growing in
                                 popularity. In many verticals like healthcare, logistics, hotels, and education
                                 kiosk mode is a common use case as the need for a personal device is
                                 limited or restricted by organizational policies. In these cases the device is
                                 shared among employees for a dedicated purpose, for example as a specific
                                 logistics app for a parcel delivery company, or an app for healthcare staff
                                 doing house calls with senior citizens. In hotels it is common to have a
                                 smartphone or tablet in the guest rooms locked to the hotel homepage and
                                 services menu.

                                 XCC can easily be used to set your Xperia devices into a single purpose
                                 device. Through the web tool a configuration can easily be created that for
                                 example removes or hides any of the three Android command buttons at
                                 the bottom of the screen.

                                 Policies can be set that block access to the Settings menu or any other part
                                 of the device, depending on the scope of the kiosk mode configuration you
                                 want to deploy. Several parameters can be set to meet your requirements;
                                 such as menus, softkeys, hardware buttons, privacy, app configuration and
                                 lock mode. Regardless if you are looking for a shared phone to be used
                                 in hotel rooms, displays or in a hospital environment, Xperia Configurator
                                 Cloud has it all covered out-of-the-box.

Xperia in Business White paper                                                                                 12
Xperia Configurator Cloud

                                 EMPOWERING THE MOBILE WORK FORCE
                                 XCC allows for easy access to approved and verified applications for work
                                 such as Microsoft Office, Adobe Acrobat, Dropbox, Salesforce or internal
                                 specific apps. Needless to say it will also swiftly set up your password and
                                 security restrictions, mail, VPN, Wi-Fi settings and more.

                                 Before getting started with empowering your workforce with various tools
                                 and productivity apps it is important to decide on a mobile device strategy
                                 that is in line with organizational objectives. Things you need to consider
                                 are:

                                   •   Do users (internal and external) need access to company information
                                       and resources while away from the network?

                                   •   Who is allowed to access company resources and information?

                                   •   Will mobile technology make it more efficient for end users to access
                                       company resources and information?

                                   •   How they are allowed to access information (ex. Mobile App, VPN)?

                                   •   How can you best streamline the access to these resources?

                                   •   What are the risks to accessing this information via mobile devices?

                                   •   What are the strategies to mitigate the risks?

                                 When you feel that you have these considerations covered you are all set to
                                 equip your employees with a selection of white listed apps, and if needed
                                 a black list for apps that cannot be installed on employee devices. The
                                 process for this is easily managed through the web tool. Inside the IT admin
                                 can white list apps (package names) both to be downloaded from Google
                                 Play or as self-hosted APK files on XCC. Note that downloading from Google
                                 Play will require the user to be signed in with a Google account.

                                 DEPLOY A THIRD PARTY MDM SERVICE
                                 Sony Mobile’s Xperia Configurator Cloud rather complements than
                                 competes with traditional MDM solutions and is a conscious result of direct
                                 customer requests. In contrast XCC has been designed from ground up to
                                 do one thing extremely well instead of spreading itself thin over the whole
                                 spectrum of device management. The focus is at all times to do device
                                 configuration, allowing the IT admin to fully utilize Sony Mobile’s Enterprise
                                 APIs. These are specific device policies that can be set on all Xperia devices
                                 that has the associated XCC phone enabler installed.

                                 In case your organization would like to deploy a 3rd party MDM this is easily
                                 done through XCC. This means that the user will have the MDM application
                                 installed on their device and will be able to do the final sign up via the MDM
                                 application. Deploying a MDM application is equal to deploying any other
                                 third party application. For specific use cases and capabilities of different
                                 MDMs we refer to their respective websites.

Xperia in Business White paper                                                                                  13
Xperia Configurator Cloud

                                 CLOUD AND DEVICE SECURITY
                                 Today being mobile in business is essential – and determining how
                                 your business manages mobile devices is important. There are cost
                                 considerations, user considerations, and management considerations.
                                 Maybe most important, security considerations should be an integral part of
                                 your mobile device strategy.

                                 When making a strategic decision in regards to your mobile device
                                 management strategy, you are ultimately determining why mobile is being
                                 implemented and what it will do to improve on your organization’s business
                                 processes. Don’t just assume that everyone needs access to their email.
                                 You need to think about mobile as an exposure – an entirely different attack
                                 vector that can be compromised. Your strategy should be the one that
                                 provides enough access to enable business to take place and support your
                                 business needs, while at the same time limiting your cyber risks.

                                 When determining your technical control policy over mobile devices, you
                                 need to understand the threats. Two obvious threats are unauthorized
                                 access and data leakage (either by mistake or intentionally by an authorized
                                 user). The less control you have over the device, the more control the user
                                 has which leads to a greater risk from threats that could be exploited.

                                 Safeguarding the employee:

                                   •   Multiple ways to safeguard your device

                                         • Fingerprint

                                         • 6 digit PIN

                                         • Pattern

                                   •   Remote block and wipe features

                                   •   Use two-step verification

                                   •   Default 256Bit encryption / Full file-level protection

                                   •   Control how data can be shared between apps

                                   •   Browse the web in Privacy mode

                                   •   Enforced device management and configurations can be applied via
                                       Xperia Configurator Cloud

                                   •   Regular SW security updates and 3rd party app scan on Google Play

                                   •   GDPR-compliant

                                 The other aspect of security relates to XCC itself as an MDM platform. XCC
                                 has been designed from ground up with security as a key cornerstone, both
                                 on the server side and on the device side. Several security measures have
                                 been implemented from a deployment perspective.

                                 On the device side:

                                   •   Email & password via company mail + confirmation link

                                   •   Unique PIN generated for every individual employee

                                   •   Google Cloud Messaging registration ID

Xperia in Business White paper                                                                              14
Xperia Configurator Cloud

                                   •   Configuration files are sent separately

                                   •   Installation result is sent back to the IT admin

                                 On the server side:

                                   •   reCaptcha

                                   •   https with unique API key

                                   •   AWS cloud platform security and monitoring features

                                   •   Web Application Firewall

                                   •   CloudWatch monitoring

                                   •   Secure File Transfer via SSH

                                   •   PEN-tests done regularly

                                   •   CloudTrail for Audit & Logging

                                 Several steps has been taken to ensure your enterprise mobility deployment
                                 is secure and corporate information is protected with end-to-end security
                                 extending to users, devices, applications, content, data, email and
                                 networks. XCC runs on the most prominent web servers available and
                                 with added smart security features all the way from the time of account
                                 registration to your day-to-day management of the service. We have added
                                 email verification schemes to ensure domain ownership and end-user
                                 sign off approval to give the IT Admin the tools needed to verify end-user
                                 authenticity.

                                 Furthermore, all standard means of secure communication is an integral
                                 part of our portal – secure client/server communication using the https
                                 protocol and Google Client Messaging for secure notifications on all our
                                 XCC eligible device models. Through our infrastructure partner Amazon we
                                 offer secure data storage on their cloud platform, topped with full Denial of
                                 Service and trusted methods for secure separation of company data.

                                 An important security concern is the handling of onboarding a device. Not
                                 only the platform needs to be safe, but the whole communication flow
                                 between the cloud platform and the end-user device, as well as the actual
                                 end-user approval process.

Xperia in Business White paper                                                                               15
Xperia Configurator Cloud

                                 The registration message is sent to XCC over https. From this point onwards
                                 authentication of the channel is done using a shared key (API key) between
                                 the device and XCC.

                                 The data sent is the following:

                                   •   Work email address (needs to match the domain of the admin).

                                   •   Device info, i.e. list of supported configuration APIs.

                                   •   Device name, e.g. “Xperia Z5”.

                                   •   Security PIN (used to verify that the user really is who he or she claims
                                       to be).

                                   •   GCM registration ID (used to send GCM messages to the device).

                                   •   IMEI.

                                   •   Approve/Cancel approval.

                                 In this way XCC helps organizations harness the power of mobility to
                                 transform their business dramatically with a cloud first approach and deliver
                                 it with a layered security all the way from the cloud platform to the device.

                                 ANDROID ENTERPRISE WITH XCC
                                 Native Android Enterprise features (former Android for Work) can easily co-
                                 exist with XCC. XCC will make sure that you from a MDM perspective take full
                                 advantage of all Xperia unique policies and settings that are not included
                                 in “vanilla” Android, such as disable camera or specific Bluetooth settings.
                                 Android Enterprise will thus work seamlessly with XCC, and provide the
                                 employee with needed features like separating business from private.

                                   •   Android separates business apps from personal apps so you can use
                                       your favorite Android device for both work and play.

                                   •   Put the power, flexibility and choice of Android Enterprise to work for
                                       you — anytime, from anywhere with best-in-class productivity apps.

                                   •   Set up a dedicated work profile for business content that never mixes
                                       with your personal stuff, so IT can’t see or erase your photos, emails, or
                                       other personal data.

                                 XCC will continue to evolve alongside Android Enterprise, meaning that
                                 new smart integration points between the two platforms will be developed
                                 going forward. As Android Enterprise matures XCC will adapt to avoid any

Xperia in Business White paper                                                                                   16
Xperia Configurator Cloud

                                 duplications in functionality and rather focus on delivering a greater value
                                 added on top of standard vanilla. This includes for example the newly
                                 announced Google Zero Touch program – a technology that will benefit
                                 both from an XCC and a generic Android perspective.

                                 SYSTEM AND PLATFORM OVERVIEW
                                 XCC is built on top of the globally renowned AWS platform. This ensures
                                 high reliability and scalability regardless in which region your organization
                                 have its operations. Availability is guaranteed at 99.95% and as was
                                 depicted in the security chapter above, the whole platform is continuously
                                 monitored to ensure the highest level of security both on the server and the
                                 device side.

                                 Once a new configuration has been created or a new user has been added
                                 the XCC has a smooth and secure onboarding experience. A multi-language
                                 supported email is created and sent off to the device owner, containing
                                 necessary deployment instructions. After end-user acceptance and
                                 installation is completed the XCC tool will receive an automatic notification
                                 of a successful deployment. In the illustration below you can see the flow
                                 of events and actions needed in each step, for more details on the subject
                                 please refer to the XCC User Manual that can be accessed via the Sony
                                 Mobile Xperia in Business website, https://www.sonymobile.com/global-
                                 en/xperia/business/#service-and-support.

                                 SUPPORT
                                 Sony Mobile provides support during business hours (8 to 5) local time, via
                                 email or phone. The response time is normally 4 hours and the solution time
                                 24 hours. Contact information can be found on:

                                 https://support.sonymobile.com/global-en/

                                 Xperia Configurator Cloud only supports Sony Xperia products. It is a
                                 100% free tool, but registration with the tool is required. Companies and
                                 organizations that use XCC must have a registered domain.

Xperia in Business White paper                                                                                  17
Xperia Configurator Cloud

                                 COMPLIANT DEVICES
                                 XCC is pre-installed on all Xperia devices released in 2016 and later. Different
                                 Xperia devices support different levels of the Enterprise API. For detailed
                                 information about the Enterprise API level supported by each Xperia device,
                                 see the Product Overview White Paper that can be found on:

                                 https://www.sonymobile.com/global-en/xperia/business/#service-and-
                                 support

                                 Device lists
                                 XCC is supported by*:

                                 •    Xperia XZ2                                      •    Xperia XA2 Ultra
                                 •    Xperia XZ2 Compact                              •    Xperia XA2
                                 •    Xperia XZ1                                      •    Xperia L2
                                 •    Xperia XZ1 Compact                              •    Xperia XA1 Plus
                                 •    Xperia XZs                                      •    Xperia XA1 Ultra
                                 •    Xperia XZ Premium                               •    Xperia XA1
                                 •    Xperia XZ                                       •    Xperia L1
                                 •    Xperia X Performance                            •    Xperia E5
                                 •    Xperia X                                        •    Xperia XA Ultra
                                 •    Xperia X Compact                                •    Xperia XA
                                 •    Xperia Z5
                                 •    Xperia Z5 Compact
                                 •    Xperia Z5 Premium
                                 *Dual SIM versions of the listed devices are also supported.

                                 Mass deployment is supported by*:

                                 •    Xperia XZ2                                      •    Xperia XA2
                                 •    Xperia XZ2 Compact                              •    Xperia XA2 Ultra
                                 •    Xperia XZ1                                      •    Xperia L1 **
                                 •    Xperia XZ1 Compact                              •    Xperia L2
                                 *Dual SIM versions of the listed devices are also supported.
                                 ** Support for Xperia L1 devices is limited to software build number 43.0.A.5.32, or later.

                                 Language support:

                                 English, French, German, Polish, Portuguese, and Spanish

                                 Sony Mobile’s Xperia Configurator Cloud platform is accessible from:

                                 https://xperiaconfiguratorcloud.sonymobile.com

Xperia in Business White paper                                                                                                 18
Xperia Configurator Cloud

                                 XPERIA CONFIGURATOR CLOUD FEATURE OVERVIEW
                                 Overview on included features, functionalities and benefits that are
                                 available in XCC. The list of features is updated regularly so for access to
                                 latest available status on the service please login to XCC and check for
                                 updates.

                                 Top features
                                   •   Sony Xperia APIs – Level 11

                                   •   https://www-support-downloads.sonymobile.com/support/offers/
                                       Xperia_in_Business-Product_Overview-March-2018.pdf

                                   •   MDP – Mass Deployment Program (Device enrollment)

                                   •   Kiosk mode – Single purpose device

                                   •   MDM deploy

                                   •   Statistics and analytics view

                                   •   Standard features

                                   •   Password & lockscreen requirements

                                   •   Restriction of usage of various functionality

                                   •   Black & white listing of apps as well as installation & uninstallation

                                   •   WiFi & VPN setup

                                   •   Mail & Exchange ActiveSync configuration

                                   •   Installation of digital certificates

                                   •   Security & Privacy

                                   •   Installation of applications

                                   •   Shortcuts

                                 SUMMARY OF BENEFITS
                                 Large enterprises / organizations:
                                   •   Easy deploy 3rd party MDM solutions

                                   •   Kiosk mode

                                   •   Works on all Xperia devices

                                   •   Security first

                                   •   Make the most of the Sony E-SDK and APIs

                                   •   Small- to medium sized business / organizations:

                                   •   It´s free

                                   •   Take control over your device fleet

                                   •   Empower your employees

                                   •   Scales with your business

                                   •   OTA

Xperia in Business White paper                                                                                  19
Xperia Configurator Cloud

                                 Employees:
                                   •   Easy set up

                                   •   Focus on the user experience

                                   •   Business ready out- of-the-box

                                   •   BYOD compliant

                                   •   Empowering a mobile workforce

                                 Carriers / Distributors:
                                   •   Easy to configure customer phones

                                   •   Mass deployment option

                                   •   Future proof

                                   •   Android compliant

Xperia in Business White paper                                                                    20
You can also read