Re: [Architecture] [EMM] Android agent auto enrollment

2016-02-01 Thread Inosh Perera
Hi Harshan/Chathura, @Harshan - As Ayyoob mentioned, we can use a custom grant type handler for retrieving tokens. @Chathura - The technician will login to the command line tool and carry out operations, this avoids the need to type credentials to the device each time we need to enroll. Since

Re: [Architecture] [EMM] Android agent auto enrollment

2016-02-01 Thread Dilan Udara Ariyaratne
Hi Inosh, Please find my questions regarding this process as follows. [1] How are we planning to get an OOT for each serial and in-case of an unenrollment, what is the process of getting a new OOT? [2] Here, are plainning to do an enrollment without associating a user? if not, how will be other

Re: [Architecture] [EMM] Android agent auto enrollment

2016-02-01 Thread Inosh Perera
Hi Dilan, [1] How are we planning to get an OOT for each serial and in-case of an unenrollment, what is the process of getting a new OOT? Enrollment in this kind of a scenario, will only be done by a specific user in a role, and those users only. If unenrolled, the device must be handed to the

Re: [Architecture] [EMM] Android agent auto enrollment

2016-01-27 Thread Harshan Liyanage
Hi, Is the service app signed by the vendor? if it so why don't we use the service app to get the serial number? Good point. I think that should be possible. If so we can skip steps 6 and 7. Thanks, Harshan Liyanage Software Engineer Mobile: *+94724423048* Email: hars...@wso2.com Blog :

Re: [Architecture] [EMM] Android agent auto enrollment

2016-01-27 Thread Harshan Liyanage
Hi Inosh, In the step 11, you have mentioned that the device sends authentication request, generate access and refresh tokens and send it to device. However you need client credentials (client key, secret) in-order to generate access tokens. How are you planing to get these client credentials

Re: [Architecture] [EMM] Android agent auto enrollment

2016-01-26 Thread Inosh Perera
Hi Milan, +1 Cant we use an embedded QR code reader or some other way to retrieve this token? Using QR code is possible and it would make the process usable in all many platforms oppose to ADB where only Android is able to work with. Although when it comes to COPE scenario, mostly it is Android

Re: [Architecture] [EMM] Android agent auto enrollment

2016-01-25 Thread Milan Perera
Hi Inosh, My concerns for the above proposed method as follows. AFAIU, in here what we are trying to do is to minimize the user interaction with the device as much as possible for the auto enrolment scenario. However according to above method, user should have to connect the device to a machine

[Architecture] [EMM] Android agent auto enrollment

2016-01-19 Thread Inosh Perera
Hi all, Following is a diagram of the flow and architecture of auto enrollment of EMM agent for Android devices. ​ Currently in COPE scenario, before distributing the device to employees; organisation doesn't have a means to enroll devices to EMM without manually typing username and