What's new in GoTo Resolve MDM
17 October, 2024 - Android Direct Boot – reset passcode and other updates
The reset passcode action is now supported in Android Direct Boot mode. This mode enables MDM to perform limited actions when a device is powered on but on the lock screen.
This feature is useful especially if the user forgets the passcode for a device. When the device is booted without Direct Boot mode enabled, its management is lost, and the passcode can't be reset from MDM.
- Direct Boot mode is fully supported on Android 10 and above.
- The device must have the Miradore client version 2.13.0 (build 425) to support actions in Direct Boot mode.
- The device must support file-based encryption. Some devices with Android 7 or above use full-disk encryption and don't support Direct Boot mode. Since Android 10, file-based encryption is required.
Ending support for Android 6
As announced earlier, we end the support for enrolling devices running Android 6.
We will continue to support a wide range of Android, iOS, macOS, and Windows OS versions, and our product team is currently preparing for new, upcoming operating systems, including Android 15.
We always recommend using the latest operating system for increased security and a better user experience.
Return to Service
The release fine-tunes our iOS Return to Service feature. In addition, to small UI enhancements, the Return to Service action is available via API v2.
Learn more about the Return to Service for iOS and iPadOS.
The Apple DEP device list now shows the assignment status of the enrollment profile correctly.
26 September, 2024 - Return to Service for iOS/iPadOS and update to the Report Builder and API
The latest release includes a new feature, an update to the Report Builder and API, and changes to the backend of our service.
Return to Service is a feature that enables IT admins to wipe and re-enroll iPhones/iPads with a single command without physically touching the devices. Along with the action, the previously selected settings for language, region, and Wi-Fi profile are sent to the device. Previously, these unskippable user selections had to be performed each time a device was wiped and re-enrolled. Being able to send a wipe command to a device and make it set itself back up again, optimizes and speeds up the process of returning a device to service.
The feature is available for devices running iOS/iPadOS 17 or above.
Learn more on how to use Return to Service for iOS and iPadOS.
Fetching Android Services info is now possible with the Report Builder and API. The attribute InvAndroidServices was added for the Device item.
6 March, 2024 - Alternative marketplace restriction for iOS (EU only) and fix to patch management issue on Mac devices
The latest release includes several updates to the product with the below-listed improvements that are visible to the users.
Apple introduces support for third-party app stores, the alternative app marketplaces, for the EU markets. From iOS version 17.4 onwards, iPhone supports app downloads from these platforms. However, this ability might raise some security concerns, which is why this product release brings a new configuration profile to deny the marketplace app installation.
To add a new iOS configuration, go to
. Choose Restrictions and select the Device functionality tab from there.- Fixed an issue with the patch management where, on some occasions, the update to macOS version 14.3.1 failed.
- Finetuned the design of the Subscription plan page.
- The Devices by category widget on Dashboard now supports more category values.
22 February, 2024 - New version for Android client and improvement to Custom configurations
We have released a new Android client, version 2.10.17 with some other enhancements.
The release fixes the following Android-related issues:
- Work profile creation failed, and a device was set to legacy management mode when enrolling the device with the client downloaded from the Google Play Store.
- The device serial number information in the Miradore client's UI wasn't shown properly on Samsung devices.
- Failed Knox restriction deployments for COPE devices got stuck in the Waiting status instead of Failed with an error description. This was an issue especially with Samsung devices.
The latest releases include a fix to a bug that caused issues in iOS Custom configurations when using certain variables.
25 January, 2024 - Knox Service Plugin Premium features and other changes
We have released Android client 2.10.12 that supports Knox Service Plugin Premium features. This release includes also changes to Android device enrollment and a few smaller enhancements.
It is now possible to configure Premium features in the Knox Service Plugin.
Starting from this release, enrolling devices for the Device Admin management is not possible. We don't support the management of these devices but the existing Device Admin devices can be managed in MDM until the end of their lifecycle.
API keys now show the creation dates in Infrastructure diagram.
4 January, 2024 - User management through REST API v2 and other enhancements
In this release, we added user management operations to REST API v2, we included improvements and fixes for the new Android and macOS client versions, bug fixes, and maintenance-related enhancements.
We support create, read, update, and delete operations for end user items through REST API v2.
- Previously, making patch blocklist changes while macOS was downloading a patch update caused the update to fail and caused issues in subsequent patch updates. We have fixed this issue.
- On the Free plan sites, we fixed a visual bug relating to the Customer Services icon.
14 December, 2023 - FileVault personal recovery key escrowing and other enhancements
This release includes improvements to the FileVault security feature, support for application deployment through REST API v2, improvements and fixes with new Android and macOS client versions, and other enhancements.
It is now possible to enable the escrowing of the FileVault personal recovery key for Mac devices running macOS 10.13 or above. The recovery key used to unlock the encrypted disk is sent to our server and stored in an encrypted format. The administrator can retrieve the personal recovery key from the device inventory information.
- We have improved the restart handling for the macOS patch deployment.
- We have added support for application deployment through REST API v2.
- Due to security concerns, we have removed the option to add the image URL for the macOS PKG applications. The previously submitted images have been replaced with the default icon.
- New Mac devices became suspended if you migrated data from a Mac device to the new Mac device using Time Machine backup or Migration Assistant.
- Issues with Android kiosk mode:
- Disabling the kiosk mode temporarily didn't work properly
- Kiosk mode did not start on the device without a SIM slot
- The Lock device command did not prompt the device lock screen passcode
Google has identified an issue with Android 14 where certain configuration settings on a device are permanently applied. The configurations are impacted if they are deployed before:
- The OS upgrade from Android 13 to Android 14
- The reboot of factory-shipped Android 14 device
We have implemented the workaround solution suggested by Google to prevent the permanent configuration settings when rebooting a device running Android 14.
Read more about the issue with management of Android 14 devices.
7 December, 2023 - Android client 2.10.0 and other enhancements
We have released Android client 2.10.0, which now fully supports Android 14. We have widened the enrollment option portfolio for Fully managed with work profile devices, fixed several Android-related bugs, and modified our Free plan.
We have added the following new features:
- We have released Android client 2.10.0, which now fully supports Android 14.
Note: Installing applications that target SDK23 (Android 6), or lower versions, is not supported on Android 14 devices.
- On Fully managed Android devices, administrators can block ultra-wideband communication by adding it to the configuration profile restrictions.
- For Fully managed with work profile (COPE) devices, we have added the Zero touch and Knox Mobile Enrollment (KME) enrollment options.
- We support setting different wallpapers on Android device home and lock screens.
We have fixed the following Android-related bugs:
- Enrolling Work profile management for Android devices was possible only if 'All the time' location access was selected.
- Android system applications that were installed on a device before the device was enrolled could not be managed and the managed configurations did not apply to them.
- If the undeploy operation was started for an app that was embedded in Android firmware, the undeployment did not finish and the status remained 'in progress'.
- The Android client's 'Disable kiosk mode' only worked with Samsung kiosk mode, now it works for generic kiosk mode as well.
- The deployment of an APK the application ID of which contained both upper and lower case letters got stuck in 'in progress' state.
- Previously, when using Zero Touch or KME enrollments, the Android client always enrolled devices in Fully managed mode, even if the Fully managed with work profile mode was selected.
- If font scaling was used on the client user interface, in some cases, the layout was incorrect.
- For COPE devices, deploying a passcode configuration profile for the lock screen with the default passcode failed when both 'Force unlock passcode' and 'Lock screen message' were enabled.
- Some conditions caused Android retirements fail.
27 November, 2023 - Windows enrollment beta improvements and other enhancements
We have implemented improvements for the Windows enrollment beta feature, and released a bug fix for adding macOS applications with scripts.
We have implemented the following updates:
- We have corrected a minor text alignment issue on the UI.
- We have added and updated animation for accordions.
- The selected device users are now sorted alphabetically by the email address.
In
, we have corrected a validation error.2 November, 2023 - GoTo Resolve MDM moved to single domain URL structure and other enhancements
GoTo Resolve MDM has moved to single domain URL structure to be more compliant with the requirements of certain browsers, to improve security, and to provide better service for our customers in the future.
The URL of GoTo Resolve MDM changed to single domain architecture, meaning that all customer sites are now under a single domain: https://mdm.gotoresolve.com.
- We fixed a minor bug in the logic that defines the text displayed on the empty Dashboard.
- We added the option to erase or keep the eSIM when retiring a shared iPad.