Dynamic Job for Windows/CE/Mobile Devices
Dynamic Jobs, enabling Administrators to create job assignments that adapt to the unique capabilities of each device. By tailoring tasks or actions to specific devices, the organization can maximize efficiency and achieve better results. For Windows/Windows CE/Windows Mobile devices, the following dynamic jobs are available:
Refresh - Refresh the devices in the Device Grid. This option will sync the device’s latest information with the SureMDM console.
Remote - This option allows you to remotely connect to an enrolled device.
Powershell - Click PowerShell to launch the command prompt.
Apps - Displays all system and installed applications on a device. SureMDM collects all the information about the installed applications (app name, username, version, package name, app size, etc.). Admins can remotely uninstall the application(s) of a device.
Apps contain the following sections: Downloaded Apps, System Apps, All Apps. These sections display applications based on their category. The following options are available for the applications listed in each section:
- Advanced - Displays the advanced settings prompt for further configuration.
- Security Code to Unlock Applications - Enter the security code which is required to unlock restricted or locked applications on the device.
- Permission - This option displays the list of permissions granted to the application.
- Uninstall - This option allows you to uninstall the selected application from the device.
- Clear Data - This option clears all app data and stored information for the selected application.
- Refresh - This option refreshes the application list.
- Lock - Enable this option to lock the application, preventing users from accessing it.
- Run at startup - Enable this option to automatically run the application when the device starts. You can also specify the startup delay in seconds.
- Advanced - Displays the advanced settings prompt for further configuration.
SureLock - This option allows you to push and apply the settings of the SureLock Application to a device.
Reboot Devices - This option allows you to reboot your device.
Lock Device - This option allows you to remotely lock the device.
Send Message - This option allows yout to send an instant message to enrolled devices.
Wipe Devices - This option allows you to erase all the data from your device.
Data Usage - This option allows you to track data usage information remotely based on your connectivity preference (Mobile Data / Wi-Fi Data) for a specific period of time.
OS Updates - This option lists status of all Windows Updates on the device.
System Scan - This option allows you to run the scan on the selected device.
BitLocker Encryption Status - This option can be used to rotate the BitLocker key at any time, without relying on a predefined schedule.
To rotate the BitLocker key, use the Rotate BitLocker option. Once the rotation is completed:
- The updated BitLocker key will be displayed in the Recovery Keys section along with its status.
- The previous BitLocker key will be retained in the Historical Keys section for reference.
Shut Down - This option allows you to shut down your device remotely.
User Accounts - Displays all the local accounts on a device and their details.
SureMDM LAPS - This option allows retrieving latest password of admin accounts and review current LAPS configuration.
Deploy Google Chrome - This option allows administrators to silently install the latest stable and enterprise-ready version of Google Chrome on managed Windows devices.
Profile Insights - This option displays a summary of profiles deployed to a device, including their deployment status and the number of payloads. If no profile is deployed, a prompt is shown to create and deploy a profile. Once deployed, profiles appear in the Profile Insights dynamic job, allowing administrators to view key details without opening each profile.
BIOS Management - Allows administrators to view and manage device BIOS configurations and security credentials. This dynamic job contains the following tabs:
All BIOS Settings: Displays a read-only view of all BIOS settings detected directly from the device. This tab helps administrators review the current BIOS configuration and verify setting values reported by the device.
BIOS Credentials: Allows administrators to manage BIOS password records. This tab is divided into two sub-tabs:
Active: Displays currently enforced BIOS passwords (such as Power-On Password and Hard Disk Drive Password depending on the OEM) and allows administrators to set or clear passwords on the device.
noteFor Lenovo, configuring both the Power-On Password and Hard Disk Drive Password may require additional device restarts to successfully apply the password changes.
Historical: Displays historical records of BIOS password changes and configuration logs.
noteThe Historical tab should also be considered an audit trail for BIOS configuration redeployments. This applies even when passwords are not changed, as long as changes are made to the BIOS configuration or the configuration is redeployed.
SureMDM Deployed Configuration: Displays BIOS settings that were deployed through Security > BIOS Management and successfully applied to the device. Only settings enforced via SureMDM are shown in this tab.
Bitdefender Management - Allows administrators to view real-time security telemetry, monitor agent health, and execute remote management commands on devices onboarded with Bitdefender Endpoint Security Tools (BEST). This dynamic job contains the following tabs:
Endpoint Details: Displays real-time telemetry reported by the Bitdefender agent, including device, agent, policy, security, and management information. This tab includes 40+ parameters, such as General, Policy, MalwareStatus, Agent, Group, Modules, and RiskScore.
infoThe Endpoint Details tab contains additional parameters beyond those listed above. The available information may vary based on the Bitdefender agent version and the endpoint configuration.
Actions: Allows administrators to execute remote operations and threat response commands directly on the endpoint. This tab includes the following available actions:
- Set Endpoint Label: Assigns custom administrative tags to the endpoint.
- Kill Process: Remotely terminates running processes on the device.
- Assign Policy: Enforces a specific Bitdefender security policy on the endpoint.
- Move Endpoint to a Custom Group: Reassigns the device to a specified group in Bitdefender GravityZone.
- Malware Scan: Triggers an immediate on-demand malware scan on the device. The scan can be performed using either Quick Scan or Full Scan, depending on the required scan scope.