Mobile Console 4.43.x Release Notes

Prev Next

About this release

This document contains important information about this release. We recommend that you read the entire document.

Item

Description

Initial Release Date

August 2023

Trellix Mobile Console Release

Release 4.43.x

Document Revision Date

23 August 2023

System requirements

The recommended browser is Chrome, and the current version is supported.

  • The minimum OS version for our mobile app on Android is Android 6.

  • The minimum OS version for our mobile app on iOS is iOS 10.

What’s new

This table lists the new features provided in this release of the Trellix Mobile Console.

V4.43 - August 2023 Release

  • Labels for Threats: The Labels column on the Threat Log page has improvements to help customers further classify and filter threats. The label information is also included in the data export feature for threats.

  • Translation Improvements: Some user interface values in the user interface have improvements in the language translations.

  • Forensics Information: On the right side of the Threat Log page, where details are provided, a Forensics tab shows the threat forensic(s) and details for each event.

  • New Characteristics for Apps Policy: New policy characteristics exist when building App Policies. See the Mobile Console Configuration Guide for the list of current characteristics.

V4.43 - July 2023 Release

  • Performance Enhancements: General performance improvements.

  • Bug Fixes: General stability improvements.

2

V4.43 - June 2023 Release

  • Data Export Endpoint Field Clarification: The Protocol drop-down list has the value of "HTTPS," and the Endpoint field does not require the "https://" prefix value because the Protocol field has this information.

  • Technical PDF Report Enhancement: For this release, the technical PDF report has an additional red alert icon marking the permissions that are considered risky in the App Permissions Summary section.

  • New and Enhanced AppDirect REST APIs: This release includes enhanced and new AppDirect REST APIs. The POST for Create an Order now includes a new attribute. These APIs are new:

    • Resend User Activation Link by Email

    • Update Role Permissions

    • Get All Orders for a Tenant

    • Get an Order for a Tenant

    • Update the Suspended Status of an Order

  • Implemented New APIs for Local Device Groups: This release provides new APIs with the following capabilities for local device groups:

    • Create a local device group.

    • Update the activation limit.

    • Update the expiration date.

    • Retrieve the list of local device groups for a tenant.

  • Notification Email Addition for Users: With this release, a user can have an additional email address to receive notifications. This new email address is set on the Users page. Numerous REST APIs include the notificationEmail field in their responses and also in the request body, if applicable.

  • Additional Device Information in REST APIs: For the device REST APIs, the deviceGroupName and jailbroken fields are provided in the responses for additional device information.

  • Improvement to SOTI MobiControl MDM Integration: This release improves the check-in process for devices using the SOTI MobiControl integration by adding an API call for a forced device check-in. This new API call ensures that actions such as installing or removing a profile are not delayed when the Threat Level attribute is updated for devices managed by SOTI MobiControl.

  • Change for the Create a User for a Tenant REST API: The input language field is deprecated on the tenant API to create a user.

  • OS Risk/CVE REST APIs: This release has additional search APIs that retrieve various information about Common Vulnerabilities and Exposure (CVEs) associated with devices and OS versions.

  • Splunk Support for REST Endpoint Data Export: This release has additional field settings for the REST Endpoint data export feature to support Splunk. You can now specify an authorization type of an API key and select the format of Splunk.

  • Additional Device Details in REST API Responses: Some of the device REST APIs have new and altered fields in their responses.

  • Enable the SMS/MMS Message Filter Tutorial: This new option allows you to enable or disable the SMS/MMS message filter tutorial in the mobile app. Enabling this option allows the end user to activate this filter feature by following the tutorial. Disabling this option hides this tutorial in the mobile app. You can find this option on the Policies page under the Phishing and Web Content Policy tab. This option requires version 5.0 and above of Trellix Mobile Security.

  • Enable the iOS Safari Extension Tutorial: This new option allows you to enable or disable the iOS Safari browser extension tutorial in the mobile app. Enabling this option allows the end user to activate this Safari browser extension feature by following the tutorial. Disabling this option hides this tutorial in the mobile app. You can find this option on the Policies page under the Phishing and Web Content Policy tab. This option requires version 5.0 and above of Trellix Mobile Security.

  • Device Model Improvements for iOS: With this release, the device model field information for iOS contains more detail. This feature provides additional model details to identify the specific type of device when evaluating and resolving threats.

  • Insights Dashboard: The Insights page is now a full feature and no longer a preview functionality.

  • Improvements to Device Name for a SOTI MDM Integration: This release includes improvements to the Device Name value in the console depending on the Mask Imported User Information field selection when setting up the SOTI MDM integration.

  • Adding Android Apps to the List of Allowed Apps: This change affects the optional “Allow List MDM Managed Apps” feature for Ivanti MDM integrations. With this release, an app is allow listed based on the specific app versions of the managed apps found in the Ivanti MDM. This allows you to be more precise in allowing specific apps.

  • Improvements in the PDF Reports: This release provides an uplift to all existing PDF reports, such as the Executive Report.

  • Additional Malware Information: This release provides additional malware information in the PDF reports and the technical JSON report.

  • Requesting Android Notifications: With this release, you can request Android push notifications sent to the device on the General tab of the Manage page. This sends Android push notifications according to the policy settings when the device is inactive (but not pending activation).

  • New App Policy Characteristics: The app policy characteristics are added dynamically, and a new characteristic category of "Social Networks" has been added with this release.

  • Performance Enhancements: General performance improvements.

  • Bug Fixes: General stability improvements.

Dynamic Threats

This table lists the threat additions and changes that occurred dynamically within this release timeframe. These threats display on the Policy page of the Trellix Mobile Console. The iOS and Android columns indicate the minimum release required to support new or updated threats if applicable. The Status column indicates if the threat is new, updated, or deleted. The threat activation date for these aligns after the GA release of Trellix Mobile Security 5.1.x.

In the Trellix Mobile Console, these new threats now exist with this release by default, disabled for existing customer policies and enabled for any new policies for both existing and new tenants.

Threat

Description

Threat Activation Date

iOS

Android

Status

Android Debug Bridge (ADB) Wi‑Fi Enabled

Wireless Developer Options is an advanced configuration option intended for development purposes only. When enabled, the user has the option to change advanced settings remotely without a physical connection to the device, compromising the integrity of the device settings.

January 2023

---

4.16

New

Filesystem Mount Points Changed

Filesystem mounts are often changed as a part of regular device behavior but this can also occur as a part of a device attack. This is viewed as normal/low risk on its own but impacted devices should continue to be monitored for threats.

January 2023

Yes

Yes

New