The following are the new features and enhancements introduced with this KCS 1.18 release:
Knox Mobile Enrollment (KME)
1. Role based access control (RBAC) improvements
This release introduces a new Role Based Access Control (RBAC) capability that allows customer (tenant) admins who are responsible for account creation (Super Admin) to assign more refined role permissions to individual admins as their specific enterprise requirements dictate. Though KME utilizes admin roles unique to that service, a Super Admin cuts across all supported services.
With the new RBAC service, existing customers will have their administrators migrated automatically with the next Knox Cloud Service release in Q1 2019. Administrators with their own unique set of permissions (manage administrators, delete devices etc.) will be assigned new roles that map to their current permissions. If needed, new roles beyond what the migrated admins are currently assigned can be created based on a list of permissions unique for each service.
The only role that cannot be assigned is the Super Admin role, which applies across all supported services. Only one person can assume a Super Admin role per company. Upon migration, the Super Admin role is assigned to the person who originally created the customer account. The Super Admin role receives every permission option available.
2. Different customer support information now available for each profile
To date, tenants can only use a single set of customer support information, regardless of the need to provide different support information to different profiles and users. Consequently, each end-user sees the same support content, even though the new KCS Customer API now supports different customer support information per profile.
With this release, when a profile is initially created an Admin is now prompted to input support contact information that can either be used across all profiles by default or just used with this one new profile. Existing customers can also be migrated to current Customer Support Info that then becomes the Default support information accessed in the top right hand menu. Additionally, an admin can edit the contact information within just that individual profile. The admin can also edit the Default support information, and have it available to new profiles upon creation, with no update made to existing profiles.
3. Knox Cloud Services on same device - device deletion concept
This feature introduces a new device deletion concept when KME is utilized with other Knox Cloud Services. If a device is only used with KME, its removal is a typical hard deletion, and the device is removed from both KME and the Reseller Portal.
However, if a device is used with both KME and another Knox Cloud service, like Knox Configure (KC), it is deleted from KME only (soft deletion), and remains in KC.