iShield Protector
Knowledge Base

Documentation

Everything you need to understand and deploy iShield Protector.
Documentation

Platform Reference

Comprehensive guides for deploying and operating iShield Protector.

Mobile Device Management (MDM) is a software solution that enables organizations to securely manage, monitor, and control mobile devices — particularly Android smartphones and tablets — from a centralized platform. MDM provides IT administrators and business operators with the tools to: • Remotely configure device settings and policies • Push or restrict applications • Lock, unlock, or wipe devices remotely • Monitor device health, battery, and connectivity • Enforce compliance with corporate or regulatory policies iShield Protector is an enterprise-grade MDM solution purpose-built for Android, EMI financing, and large-scale distributor networks.

Android Device Owner (DO) is the highest privilege level available on Android devices. When an app is provisioned as Device Owner, it gains OS-level control that cannot be overridden by the end user. Device Owner capabilities include: • Silent app installation and removal without user prompts • Complete lock task mode (kiosk) with restricted navigation • Factory reset protection — prevents unauthorized factory reset • Comprehensive device policy enforcement • System app management • Network configuration and VPN enforcement iShield Protector uses Device Owner mode when deployed through QR provisioning or zero-touch enrollment. This is required for EMI lock enforcement and kiosk deployments.

iShield Protector supports multiple enrollment methods to suit different deployment scenarios: 1. QR Code Enrollment (Recommended) The administrator generates a QR code from the iShield dashboard. During Android setup wizard, the device user scans the QR code, which automatically installs the MDM agent and provisions Device Owner mode. 2. NFC Enrollment For bulk enrollments, NFC bump enrollment allows the provisioner device to transfer enrollment configuration to a factory-reset device. 3. Manual Enrollment For BYOD and supervised devices, the MDM agent can be installed from the Play Store and the device registered to the organization account. After enrollment, the device receives its initial policy set, gets linked to the assigned customer account, and begins reporting heartbeat telemetry to the iShield platform.

iShield Protector supports all Android devices running Android 8.0 (Oreo) or higher. Full Device Owner feature availability requires Android 9.0+. Tested and optimized OEM devices: • Samsung (Galaxy A, Galaxy M, Galaxy S series) • Xiaomi (Redmi, POCO, Mi series) • Realme (C, Note, Number series) • Vivo (Y, V, T series) • OPPO (A, F, Reno series) • OnePlus (Nord, number series) • Motorola (Moto G, Moto E series) • Generic Android One devices The OEM Survival Framework ensures the MDM agent persists across OEM-specific battery optimization and background process restrictions.

Different Android OEMs implement aggressive battery and background process management that can interfere with MDM agent persistence. iShield Protector includes an OEM Survival Framework that handles these cases automatically. Recommended configuration by OEM: Samsung: Disable Adaptive Battery for iShield. Enable Device Owner unrestricted mode via Knox policy. Xiaomi/POCO: Enable "No restrictions" in Battery Saver for iShield. Disable MIUI Optimization (optional) for maximum reliability. Realme/OPPO/Vivo: Grant "Allow background activity" and add iShield to the protected apps list in battery settings. OnePlus: Enable "Allow background activity" and set charging optimization to none for iShield. Note: With Device Owner mode active, these configurations can be enforced silently by the iShield platform without user intervention.

iShield Protector supports three primary deployment models: 1. Platform Owner Direct Model The Platform Owner manages all devices directly. Suitable for single-organization deployments. 2. Distributor Model The Platform Owner grants access to Distributors. Each Distributor manages their own customer pool and device fleet independently. Sub-Distributors can be created under Distributors. 3. Enterprise White-Label Model iShield Protector can be configured for enterprise white-labeling where the platform is branded under the enterprise's name for distributor and customer-facing interfaces. Each deployment model supports the full feature set. The choice of model determines the account hierarchy, not the technical capabilities available.