Who can use this feature?
đ€ Organization Owners, Admins, Group Admins, and custom roles with the "Configure Security Settings" permission can configure these settings directly on a group or ungrouped device, and can assign an existing Security preset. Creating or editing a Security preset is an organization-level action: Organization Owners and Admins can do this by default, and custom organization roles can be granted Create and Edit permissions for Security presets under Settings â Roles â Configuration Presets.
đ© Available on the Essential, Classroom Pro, Classroom Ultimate, and Enterprise Plans.
Overview
The Security settings of a group or ungrouped device control what device users can do locally and how ArborXR interacts with the device:
Developer Options: enables USB debugging and lets users open the Developer Options menu in system settings.
File Transfer via USB: lets users transfer files to and from the device over USB.
Allow User Factory Reset: lets users factory reset the device locally from its system settings. Remote factory reset from the ArborXR portal is still available when this is disabled.
Request User Consent for Remote Assistance: asks the device user for permission at the start of each Remote Assistance session. The prompt covers screen, audio, and camera.
Enforce Microsoft Intune Compliance: requires the device to be compliant in Microsoft Intune before it can access Entra-protected organizational resources. This requires the Intune device compliance integration to be set up first.
Developer Options, File Transfer via USB, and Allow User Factory Reset each have three options: Enabled, Disabled, and Not Managed by ArborXR. Not Managed by ArborXR is the default and means ArborXR leaves the setting alone on the device; choose Enabled or Disabled to have ArborXR enforce it. Request User Consent for Remote Assistance and Enforce Microsoft Intune Compliance are simple on/off toggles and are off by default.
There are two ways to configure them:
Option 1 (recommended): with a Security Configuration Preset. You define the settings once in the preset, then assign the preset to as many groups and ungrouped devices as you like. When you update the preset, the change applies immediately everywhere it's assigned.
Option 2: directly on an individual ungrouped device or device group.
Option 1: Configure with a Security Preset (Recommended)
đĄ Why we recommend Configuration Presets. Configuring a group or ungrouped device directly means repeating the same clicks for every group and device, and repeating them again each time the setting needs to change. With a preset you configure the setting once, assign it to up to 100 groups or ungrouped devices in a single operation, and any later change to the preset applies immediately everywhere it's assigned. Over the life of a fleet this saves a significant amount of time and removes the risk of groups drifting out of sync.
Step 1: Create the preset
Navigate to Configuration Presets in the left sidebar.
Click Create Configuration Preset in the top right corner and choose Security.
Enter a Name for the preset and click Create.
Configure the settings as desired. Leave any setting you don't want ArborXR to manage at Not Managed by ArborXR; only the settings you configure in the preset are applied to devices.
Click Save.
Step 2: Assign the preset
Assign the preset from the Configuration Presets library. You can assign it to up to 100 groups or ungrouped devices in a single operation.
Navigate to Configuration Presets in the left sidebar.
Select the checkbox next to the Security preset you want to assign.
Click Assign.
Choose either Assign to Groups or Assign to Ungrouped Devices.
Select the target groups or ungrouped devices, then click Assign.
Option 2: Configure Directly on a Group or Device
đĄ If your organization has Require Configuration Presets enabled, direct configuration is disabled and the Security section must be configured with a preset.
Navigate to the ungrouped device or configuration group in question.
Select the Settings tab.
Select Security to expand the section.
Configure the settings as desired. Leave any setting you don't want ArborXR to manage at Not Managed by ArborXR; only the settings you configure in the preset are applied to devices.
Click Save.




