New features summary
These are cumulative release notes. If a release does not appear in this section, then there were no associated new features and enhancements.
-
Enhanced Patch Compliance Messaging: Users now receive a clear message when device registration fails due to an outdated security patch level. The message reflects the compliance threshold configured in Device Registration settings and explains the remediation required to complete registration.
- Android 17 Day-Zero support: We introduce day-zero support for Android 17. Ivanti Go for Android is now optimized to operate smoothly on devices running the latest Android 17 OS.
-
Integrated Tunnel Support: Tunnel functionality is now available directly within the Go Client app through app restriction configuration, providing the same tunneling experience without requiring a standalone Tunnel app. This feature is supported only on newly registered devices.
- SIM State Change Detection and Reporting: The Android Go client now detects SIM card insertion/removal events on managed devices.
When a SIM state change is detected:The client updates active subscription information in device details/check-in data.
A Force Device Check (FDC) is triggered so the server receives the updated SIM/subscription state promptly.
This improves visibility and compliance monitoring for SIM-related changes on managed devices.
-
MGPA to Google Account Device Migration: In this release, support has been added to migrate existing devices registered with Managed Google Play Accounts (MGPA) to Google accounts by using a BTE token. This enhancement helps organizations transition enrolled devices to the new account model while maintaining uninterrupted device management.
A new Key Value Pair is added to enable this feature: feature.android.bte.enterprise.upgrade.and.device.migration.enabled
Supported Platforms-
Managed Device with Work Profile: Android 12+
-
Device Owner: Android 9+
-
Profile Owner: Android 9+
-
Settings Access in Single App Kiosk Mode: Single App Kiosk mode now supports secure access to Settings without displaying additional apps or exit options. This allows authorized users to access kiosk settings when needed while the designated kiosk app is in full-screen mode. To access Settings in Single App Kiosk mode, press and hold both Volume Up and Volume Down button for 3 seconds. A new KVP is added to enable this feature feature.android.kiosk.single.app.allow.settings.enabled.
-
-
Global Proxy Configuration for Device Traffic: In this release, administrators can configure a Global Proxy to route device network traffic through a designated proxy server. This setting provides a centralized method for managing proxy configurations across devices.
-
The Global Proxy setting is applied as a recommendation, and some applications may choose to bypass or ignore the configured proxy.
-
When configured, the Global Proxy setting takes precedence over network-specific proxy settings.
-
This feature is supported only for Work Managed Device mode.
-
-
Update to Target SDK: The Target SDK has been updated to 36.
-
Support for QR-Based AOSP Device Registration: Ivanti Go now supports registration of non-AOSP devices in AOSP mode using QR codes generated either through the Provisioner app or from the server.
-
Enhanced Device Registration Block Messages: Ivanti Go now provides clearer and more informative device registration block messages during enrollment. When device registration is blocked due to configured compliance requirements, users receive detailed messages indicating the specific reason for the block. This enhancement applies to devices enrolled in Device Owner, Profile Owner, and Enhanced Profile Owner modes and covers the following Device Registration Settings:
-
Minimum OS Version
-
Minimum Security Patch Level
-
Manufacturer Whitelist/Blacklist
-
Minimum SafetyNet Certification
These improved messages help users and administrators quickly identify and address registration issues, resulting in a smoother enrollment experience.
-
-
Google Account Configuration Support in Shared Kiosk Mode: Ivanti Go now supports configuring Google accounts on devices running in Shared Kiosk mode. This enhancement helps streamline access to Google services in kiosk deployments. Additionally, administrators can configure Gboard (version 16.5 and later) behavior through App Configuration settings, including controls for clipboard access, suggestion strip icons, suggestion removal, and the Settings icon. To ensure the configured settings are applied correctly, administrators must enable the option to clear the Gboard cache in Kiosk Lockdown.
-
Samsung ELM License Activation Bypass Support: Ivanti Go now supports bypassing Samsung Enterprise License Management (ELM) license activation based on administrator-defined configurations.
-
LEO URL Support in Ivanti Go: Ivanti Go now supports dynamic LEO URL configuration, allowing administrators to override the default LEO URL when required. This enhancement provides greater flexibility for deployment scenarios by enabling the client to connect to a custom LEO endpoint based on configuration settings, simplifying environment-specific setup and management.
-
Android 17 Day Zero Support for Samsung Devices: Ivanti Go now provides Day Zero support for Samsung devices running Android 17, enabling organizations to enroll and manage supported Samsung devices as soon as they are upgraded to Android 17. This helps IT administrators adopt the latest Android release without delay while maintaining device management, security, and compliance capabilities.
-
Enhanced sign-up flow and device enrollment: Starting from this release, the sign-up and device enrollment experience has been enhanced using Google BTE tokens with Custom DPC on Android 12+ devices.
-
RCS and SMS and MMS Archival Support for Android enterprise: Ivanti Neurons for MDM now supports automatic archival of Rich Communication Services (RCS), SMS and MMS messages from Google Messages on managed Android enterprise devices.
-
Reporting active SIM subscriptions to Ivanti NMDM: All active subscriptions available on the device are now reported to Ivanti Neurons for MDM as part of the device details payload.
-
OU attributes support in CSR during Android device enrollment: Ivanti Go for Android has been enhanced to support populating the Organizational Unit (OU) field in the subject of the Certificate Signing Request (CSR) during device enrollment. As part of this update, both the Organization (O) and Organizational Unit (OU) attributes are now submitted as required fields in the CSR to the DoD approved Certificate Authority.
-
On Demand App cache clearing from N MDM console: Ivanti Go for Android has been enhanced to support on demand clearing of application caches initiated directly from the Ivanti Neurons for MDM console. This enhancement applies to all apps installed on the device, including both corporate or enterprise applications and third party apps.
-
Custom ticketing portal link in Support tab: Administrators can now configure a custom ticketing portal URL within the application. This URL is displayed in the Support tab, allowing end users to directly access the configured portal for submitting support tickets using Raise a Support Ticket.
-
Smishing protection enhancement: In Ivanti Go for Android, Smishing protection can now be managed through the Ivanti Portal.
Disabling Smishing protection causes the app to restart.
-
Enhanced eSIM configuration support: Devices can now install eSIM configurations across all supported provisioning modes:
-
Work Profile
-
Work Profile on Company Owned Device
-
Work Managed Device
Auto Enable eSIM
A new Auto Enable functionality is now available for eSIM configurations, allowing the eSIM profile to activate automatically after installation.
This functionality is supported only in Work Profile on Company Owned Device and Work Managed Device modes.
Automatic eSIM Profile Removal on Configuration Uninstall
When an eSIM configuration is uninstalled from the device, the associated eSIM profile is automatically deleted from the devices.
Enhanced wipe settings
The option to retain data plans during device operations is now available on Android 15 and later.
-
If the checkbox is unchecked, the system will erase all eSIM data plans from the device.
-
If the checkbox is checked, the device’s existing data plans are retained.
-
-
Enhanced Terms of Service format support: Ivanti Go for Android extended support for displaying the Terms of Service in HTML format, in addition to the existing plain text format.
-
New Support Tab for enhanced user assistance: A new Support tab has been added to the client menu, giving end users quick access to essential help resources. This tab provides step by step instructions, support contact information, useful reference links, and additional support details.
-
New Logout button for Kiosk users: A Logout button has been added to the Kiosk home screen, making it easier and more intuitive for kiosk users to securely log out their session.
-
New Lockdown Policy for AppFunctions: A new lockdown option has been introduced to enhance control over the AppFunctions policy.
The lockdown includes three configurable states:
-
Not Controlled
-
Disabled
-
Disabled for Cross Profile
AppFunctions policy is supported in Work Profile on Company Owned Device, Work Managed Device, and Work Profile.
-
-
Enhanced EID retrieval for Android devices: Support has been added in Ivanti Go for Android to fetch EID values on Android devices running Android 13 and later. The retrieval behavior varies based on the device ownership mode:
-
Work Managed Device mode: EID values are retrieved automatically without user interaction.
-
Work Profile and Work Profile on Company Owned Device modes: EID values are retrieved only when a request command is issued from the server.
-
-
Update Lookout SDK to Version 4.2.5.193: The Lookout SDK has been updated to 4.2.5.193.
-
Support for Samsung Knox SDK 3.12: Ivanti Go for Android now integrates with Samsung Knox SDK version 3.12.
-
Easy Access to End User License Agreement (EULA): Users can now view the End User License Agreement (EULA) directly in Ivanti Go for Android. The EULA can be accessed by navigating to: Settings > About.
-
Enhancement in device registration: Ivanti Go for Android has been enhanced to restrict device registration based on the supported enrollment type. This enhancement allows only with the following enrollment methods:
-
Samsung Knox Mobile Enrollment (KME)
-
Google Zero-Touch Enrollment
-