# Welcome

Lunar Control Center is a security-first Mobile Device Management system used for managing Android-based devices. It is designed to perform key functions helping teams control and support devices, as well as executing day-to-day operations.&#x20;

Welcome to the Lunar Control Center documentation space. This space is designed to provide comprehensive information about Lunar Control Center, including an overview of features, installation guides, and manuals.

The intended audience is:

* **System Administrators:** For teams managing the IT systems of the organization hosting the solution.
* **Support teams:** For teams providing day-to-day support for the fleet of devices managed by Lunar Control Center. &#x20;


# Lunar Control Center Console

## Overview

The Lunar Control Center Console serves as a centralized user interface for operators to efficiently manage and monitor devices remotely. The console acts as a single point of control, providing operators with a comprehensive set of tools and features to ensure seamless device management and real-time monitoring.

## Functionality

<details>

<summary>Account provisioning</summary>

Operators can create, suspend, or delete device accounts on demand.&#x20;

</details>

<details>

<summary>Management actions</summary>

Operators can remotely execute management actions on devices, including resetting device account passwords, wiping devices, and changing device visibility and permission groups.

</details>

<details>

<summary>Policy management</summary>

Operators can create, edit, or delete device policies which are then applied through the Policy Controller application. The policies can be managed on three levels: instance-wide (affecting all devices), group-wide (affecting a subset of devices), and specific devices (affecting a single device).

</details>

<details>

<summary>Software OTA updates</summary>

Operators manage OTA OS updates through the console, allowing them to initiate OTA updates to their fleet of devices.

</details>

<details>

<summary>Management of app catalogue</summary>

Operators can manage app catalogs for their fleet of devices. The app catalogs can be created on three levels: instance-wide (affecting all devices), group-wide (affecting a subset of devices), and specific device (affecting a single device).

</details>

<details>

<summary>Device logs</summary>

Operators can access device logs individually for devices or aggregated in a report. The logs include network logs, action logs, sensor logs, traffic logs, and notification logs.

</details>

<details>

<summary>Software integrity</summary>

The Lunar Control Center receives information about the local device settings through the [Policy Controller](/lunar-control-center-console/policy-management) application. The Software Integrity report feature compares the on-device settings with the policy configured on Lunar Control Center, including whether certain settings are enabled or disabled, and the software version the device is running on.&#x20;

Any discrepancies between configured policies and actual device settings trigger notification warnings, helping SOC teams identify any potential device security threats.&#x20;

</details>

[Follow our manual to get started with Lunar Control Center Console.](broken://pages/R9kGH8Rt5hjvJwnvcNaz)


# User Management

Lunar Control Center lets you seamlessly create and manage users in your organization.  Once the users are created, you can directly manage all the devices under a specific user by associating policies and actions with the user.

## User Administration

Lunar Control Center admins can create, edit, and delete user accounts through the Lunar Control Center Console.

### Creating users

You can create a user account by following the steps:

{% hint style="success" %}

1. Click on Manage\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FFByIjHnRSNRaQWxUfZvS%2Fimage.png?alt=media\&token=079f932a-87cf-48e5-9adb-b1a19509e10a)
2. Click on Accounts\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FcLD2GB67jeB1VkuyYrii%2Fimage.png?alt=media\&token=c776ead7-fc2d-46e4-bb74-f7b9ff3729a7)
3. Click on Create\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2F9NkTbGXkP9QqmKJgIcms%2Fimage.png?alt=media\&token=d4c07ec7-68c1-4237-b8fb-efbdd38348fd)
4. Fill up the fields, including:\
   \- **Username**: a unique name used for enrolling the user account on the device. The username should include the user domain (e.g. <user1@domain.com>)\
   \- **Display name**: a name showing to contacts of the user\
   \- **Group**: select the [group ](/lunar-control-center-console/policy-management#group-level)for the user. The device inherits the device policies of that group.\
   \- **Password and Re-Password**: choose and re-enter the password used for enrolling the user account on the device.\
   \- **Subscription end-date**: determines the expiration date of a user account. If left empty, the account will not expire unless edited later.\
   \- **Access level**: select the [user access level](/lunar-control-center-console/policy-management#user-access-level).\
   \- **Re-enrollment**: this policy determines whether the user will be allowed to re-enroll the device after the initial enrollment.\
   \- **Password recovery email**: allows you to add an email the user will use to reset their account password in case they forget it. The account password reset can be initiated from the user portal of LCC (if enabled). If left empty, only LCC administrators can reset the account password.\
   \- **Receive sampling logs**: determines whether the device will send sampling logs to LCC.\
   \- **Receive SIM logs**: determines whether the device will send SIM logs to LCC.\
   \- **Show widget page**: determines whether the user will have access to the LCC widget page in their LCC user portal.\
   \- **Can upload and use personal apps**: determines whether the user can. \
   \- **Notes**: optional notes that can be added on creation.\
   \- **Language**: determines the default system language for the device. \
   \- **Time zone**: determines the default time zone for the device
5. Click on Create\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FeutFYwGVWs1OmFIy1nOT%2Fimage.png?alt=media\&token=1a87b670-627d-4951-b02e-14e9d57bb66c)
   {% endhint %}

### Editing user account

You can edit already created user accounts by following the steps:

{% hint style="success" %}

1. Click on Manage\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FFByIjHnRSNRaQWxUfZvS%2Fimage.png?alt=media\&token=079f932a-87cf-48e5-9adb-b1a19509e10a)
2. Click on Accounts\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FcLD2GB67jeB1VkuyYrii%2Fimage.png?alt=media\&token=c776ead7-fc2d-46e4-bb74-f7b9ff3729a7)
3. Select the account you want to edit by clicking on their username\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2Fy1pZuRXHeKNfmqpCsx2A%2Fimage.png?alt=media\&token=51a0db97-85b6-4f98-9849-431a53e37df6)
4. Make the edits to the user account
5. Click on Save\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2Fa7rNtj90TRoALgFrnBO0%2Fimage.png?alt=media\&token=76bcefd6-765c-4ee9-873d-12ff88f97b00)
   {% endhint %}

### Deleting user account

You can delete already created user accounts by following the steps:

{% hint style="success" %}

1. Click on Manage\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FFByIjHnRSNRaQWxUfZvS%2Fimage.png?alt=media\&token=079f932a-87cf-48e5-9adb-b1a19509e10a)
2. Click on Accounts\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FcLD2GB67jeB1VkuyYrii%2Fimage.png?alt=media\&token=c776ead7-fc2d-46e4-bb74-f7b9ff3729a7)
3. Click on the "X" sign next to the user you want to delete\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FhA2X2aeme6g0KasyjKDC%2Fimage.png?alt=media\&token=1202006c-1655-41a9-b6b2-cc66a2ea4071)
4. Click on Yes to confirm
   {% endhint %}

## Management actions

LCC administrators can perform several management actions on devices, including wipe, password change, and force sync.

### Wiping device

You can initiate a device wipe by following the steps:&#x20;

{% hint style="success" %}

1. Click on Manage\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FFByIjHnRSNRaQWxUfZvS%2Fimage.png?alt=media\&token=079f932a-87cf-48e5-9adb-b1a19509e10a)
2. Click on Accounts\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FcLD2GB67jeB1VkuyYrii%2Fimage.png?alt=media\&token=c776ead7-fc2d-46e4-bb74-f7b9ff3729a7)
3. Click on the "X" round sign next to the user you want to wipe\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FA2ha6I21QPZE7pJ0tYXa%2Fimage.png?alt=media\&token=2d3ebcda-3135-486a-ac82-f6f425dde51d)
4. Click on Yes to confirm
   {% endhint %}

The device will need to be online in order to receive the wipe command and initiate a local device wipe.

### Password change

You can change the user account password by following the steps:&#x20;

{% hint style="success" %}

1. Click on Manage\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FFByIjHnRSNRaQWxUfZvS%2Fimage.png?alt=media\&token=079f932a-87cf-48e5-9adb-b1a19509e10a)
2. Click on Accounts\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FcLD2GB67jeB1VkuyYrii%2Fimage.png?alt=media\&token=c776ead7-fc2d-46e4-bb74-f7b9ff3729a7)
3. Click on the padlock sign next to the user you want to change the password of\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2F8Tsz3ljkNvwnN5nRpLNx%2Fimage.png?alt=media\&token=c332daf0-c4cb-4f7c-ae36-0dbc64de725e)
4. Enter and re-enter the new user password
5. Press Reset to confirm\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FS3QjeqE06nP5RQ8Oa273%2Fimage.png?alt=media\&token=a0152ff1-6fe9-492e-9a38-b070255951a6)
   {% endhint %}

The device will need to be online in order to receive the wipe command and initiate a local device wipe.

### Force sync

You can force a sync between LCC and the device via the force sync action by following the steps:

{% hint style="success" %}

1. Click on Manage\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FFByIjHnRSNRaQWxUfZvS%2Fimage.png?alt=media\&token=079f932a-87cf-48e5-9adb-b1a19509e10a)
2. Click on Accounts\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FcLD2GB67jeB1VkuyYrii%2Fimage.png?alt=media\&token=c776ead7-fc2d-46e4-bb74-f7b9ff3729a7)
3. Click on the two arrows sign next to the user you want to sync with\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FuHpj80Dfd9h01OCmLmGJ%2Fimage.png?alt=media\&token=3877b441-729c-4e64-a51c-cfcac9c0a7d6)
4. Press OK to confirm<br>
   {% endhint %}

LCC uses MQTT to sync with devices. MQTT syncs are instant upon policy change or upload of a new software version. The force sync action is used in troubleshooting devices that do not sync with LCC as designed.


# Policy Management

## About the feature

The Policy Management features provide a way for organizations to manage and configure devices seamlessly at scale.

It is an administrative tool for remote device configuration. Lunar Control Center interacts with devices through a collection of APIs integrated with the managed devices through a System application.&#x20;

Lunar Control Center does not rely on any third-party infrastructure of services, such as Google Play Store or Android Enterprise. It delivers its functionality through services hosted by the organization.

Lunar Control Center admins can manage the following device policies through the Console:

### Device policies

Those represent a group of policies, including hardware, device, sync, wipe lock screen, and encryption policies.&#x20;

#### Hardware policies

{% hint style="info" %}
Includes settings related to the availability of functions delivered by hardware components. When disabled, applications will not be able to provide functions that require the use of these components even if applications are granted access to these components.
{% endhint %}

<details>

<summary>Camera</summary>

Allows to enable or disable device cameras. Admins can disable only the front camera, only the rear cameras, or all device cameras.

</details>

<details>

<summary>Location access</summary>

Allows to enable or disable access to location services by the device.&#x20;

</details>

<details>

<summary>USB</summary>

Allows to enable or disable USB functions including File Transfer, MIDI, PTP for connected devices. Deices with disabled USB by policy can still be charged through their USB port.

</details>

<details>

<summary>Bluetooth</summary>

Allows to enable or disable Bluetooth connection on the device.

</details>

<details>

<summary>WiFi</summary>

Allows to enable or disable WiFi connection on the device.

</details>

<details>

<summary>Screenshots</summary>

Allows to enable or disable screenshot taking on the device. The screenshot taking permissions affects screenshot taking through any application, including system or third party applications.

</details>

<details>

<summary>Microphone</summary>

Allows to enable or disable the usage of a microphone on the device. Disabling the microphone will prevent all voice functionality including calls, push-to-talk messages, audio recording, and audio feed on recorded videos.

</details>

<details>

<summary>Fingerprint</summary>

Allows to enable or disable the usage of the fingerprint sensor as authentication on the device.

</details>

<details>

<summary>Device sensors</summary>

Allows to enable or disable the functionality of all device sensors such as accelerometer, geomagnetic field, gravity, gyroscope, light, proximity, and more sensors. Device sensors depend on the device model used.&#x20;

</details>

<details>

<summary>Kill switch</summary>

Allows to enable or disable the functionality of a custom device component used for disabling services such as connectivity, bluetooth, WiFi from the user. Kill switch functions are only available for specific device models.&#x20;

</details>

<details>

<summary>Developer options</summary>

Allows to enable or disable access to Android Developer Options on the device.

</details>

#### Service Policies

{% hint style="info" %}
Includes settings related to the availability of different device functions. When disabled the functions will not be accessible by any application.
{% endhint %}

<details>

<summary>Voice service</summary>

Allows to enable or disable voice services on the device. When disabled it restricts all incoming and outgoing telephony calls on the device. VoIP calls made through external apps are not restricted.&#x20;

</details>

<details>

<summary>SMS/MMS</summary>

Allows to enable or disable SMS and MMS services on the device. When disabled it restricts all incoming and outgoing SMS or MMS messages, including silent SMS or MMS.&#x20;

</details>

<details>

<summary>Installation of 3rd party apps</summary>

Allows to enable or disable the installation of 3rd party applications on the device. Disabling it prevents installation of any applications through 3rd party app stores or local APK installation. When disabled, users will only be able to install applications allowed in their application policy.&#x20;

</details>

<details>

<summary>Send debugging information</summary>

When disabled, prevents users from sending device software bug reports to Lunar Control Center.

</details>

<details>

<summary>Emergency center</summary>

Allows to enable or disable access of the device user to the emergency center functionality on Lunar OS. When enabled the user can activate an SOS sound alarm or initiate an SOS device Wipe, including sending an SOS message to their organization and triggering instant device wipe.

</details>

<details>

<summary>Can manage Screen timeout</summary>

Allows to enable or disable the option for users to change their screen timeout setting on the device.

</details>

<details>

<summary>SIM logs</summary>

When disabled, Lunar Control Center can not get SIM logs from the device.

</details>

<details>

<summary>Top-up</summary>

When enabled, it adds a top-up option for users in their My Account menu on their device. Top up menu function depends on the custom implementation on the OS side.

</details>

<details>

<summary>Update account password</summary>

Allows to enable or disable the function for device users to update the account password used to enroll the device. If disabled, the account password can only be changed from Lunar Control Center.

</details>

<details>

<summary>MicroG Services</summary>

When enabled, devices get MicroG service installed and configured on their device. [Read more about MicroG functionality here](https://microg.org/).

</details>

#### Sync Policies

{% hint style="info" %}
Includes settings related to the frequency of automated device syncs to the server and sync wipe rules.
{% endhint %}

<details>

<summary>Allow accounts to manage "sync" section in personal account settings</summary>

If enabled, users will be able to select the sync interval and the max failed sync to wipe settings.&#x20;

</details>

<details>

<summary>Sync interval [s]</summary>

Determines how frequently would the device attempt to sync with the Lunar Control Center.

</details>

#### Wipe Policies

{% hint style="info" %}
Includes settings related to device wipe functions.&#x20;
{% endhint %}

<details>

<summary>Max failed sync to wipe</summary>

Determines the maximum unsuccessful sync attempts a device is allowed before a local device wipe triggers. If the device fails to sync with Lunar Control Center server for the set interval, an automated factory reset will be triggered, wiping all device data and logging out of the account.&#x20;

</details>

<details>

<summary>Count missed offline syncs</summary>

If disabled, the max failed sync to wipe will not trigger a device wipe.

</details>

<details>

<summary>Allow accounts to manage "wipe password" section in personal account settings</summary>

If enabled, users will be able to set up a duress wipe PIN/Password on their device. &#x20;

</details>

<details>

<summary>Wipe password</summary>

Allows Lunar Control Center administrators to set up a wipe password for the device. The device wipe password is used to wipe the device when entered in the lock screen menu.&#x20;

</details>

#### Lock Screen Policies

{% hint style="info" %}
Includes settings related to the lock screen function for devices. &#x20;
{% endhint %}

<details>

<summary>Lock Screen Method</summary>

Determines if the user is allowed to use a PIN code or a Password when setting up their lock screen protection.

For PIN code method, administrators can set minimum PIN symbols required.&#x20;

For Password method, administrators can set a pass quality requirement. &#x20;

</details>

<details>

<summary>Pass history restriction</summary>

Determines if the user is allowed to use a PIN code or a Password when setting up their lock screen protection.

For PIN code method, administrators can set minimum PIN symbols required.&#x20;

For Password method, administrators can set:

* pass quality requirement
* password history restriction (determines the number of unique new passwords that must be associated with a user account before an old password can be reused)
* Password minimum length
* Password expiration \[days]

</details>

<details>

<summary>Timeout for screen lock [s]</summary>

Used to set value for screen timeout before automatic device lock. Available values include 15s, 30s, 1min, 2min, 5 min, 10 min, and 30 min.

</details>

<details>

<summary>Can manage Screen timeout</summary>

Allows to enable or disable the option for users to change their screen timeout setting on the device.

</details>

### Application Policies

{% hint style="info" %}
Application policies determine the access to applications for device users. By using application policies, administrators can select to install and/or uninstall applications from devices.
{% endhint %}

### OS policies

{% hint style="info" %}
Includes settings related to the OS running on the device.  Admins can set the OS version the device will be running on. Can include a specific OS or be set to the latest OS build made available through OS Updater.
{% endhint %}

### Software policies

{% hint style="info" %}
Includes settings related to the software version of applications on devices.
{% endhint %}

##

## Policy Levels and Creation of Policies

Lunar Control Center allows the management of policies on multiple levels, including Default System, Group, and Personal policies.&#x20;

### Default System level

Each LCC instance has a set of Default System Policies. Those are the default policies for all users unless a Group or Personal policy overwrites them.

Administrators can set up Default System policies for Device, Applications, OS, and Software Policies.

{% hint style="success" %}

1. Click on Manage\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FFByIjHnRSNRaQWxUfZvS%2Fimage.png?alt=media\&token=079f932a-87cf-48e5-9adb-b1a19509e10a)
2. Click on Device Policy / Application Policy / OS Policy / Software Policy (depending on what policy you want to create)\ <img src="https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2F8Dl7l5pu25FCxId6VDXr%2Fimage.png?alt=media&amp;token=4ab6e439-e580-4fef-808e-df7370a2fdd9" alt="" data-size="original">
3. Click on + Default Policies\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2F12LsOLjMCoQZHcK5yPab%2Fimage.png?alt=media\&token=d9b89858-d17e-4593-b2d9-d1643f2cc911)
4. Select OS type\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FaTcmrrdALxqfM4rslKI0%2Fimage.png?alt=media\&token=0273b759-196e-4141-aef4-dcd849714eee)
5. Select policies
6. Click on Create\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FeutFYwGVWs1OmFIy1nOT%2Fimage.png?alt=media\&token=1a87b670-627d-4951-b02e-14e9d57bb66c)
   {% endhint %}

### Group level

Groups are objects created by Lunar Control Center administrators in order to manage policies for a collection of accounts. Group policies overwrite Default System policies and are applied to all users part of the Group.

To start you will have to create a group, by following the steps below:

{% hint style="success" %}

1. Hover over the Config icon in the top right corner. \
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FJg3L1RZLBTooYb1UCvTK%2Fimage.png?alt=media\&token=c729a590-5502-4353-901f-34c5c9d3a578)
2. Click on Groups
3. Click + Create \
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FrJG52fNsg40ViHR2AFK6%2Fimage.png?alt=media\&token=ddf4ea51-ab6f-46cf-82c9-c97f4290a9d3)
4. Fill up fields, including:\
   \- **Name**: the name the group will be identified with\
   \- **Parent group**: allows you to create a group under an already existing parent group. \
   \- **Group disk quota \[MB]**: allows you to set up a quota different than the default for the maximum amount of backup each account can use.\
   \- **Group traffic quota \[MB]**: allows you to set up a traffic quota different than the default for the maximum network traffic a device can make.&#x20;
   {% endhint %}

<figure><img src="https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FAFbiDk76UqCIQ4dDbsz5%2Fimage.png?alt=media&amp;token=efba392b-d8d6-4b5d-ad3d-273320f5d2b7" alt=""><figcaption><p>Once you fill in the necessary fields, you can complete the group creation by pressing Create.</p></figcaption></figure>

Once you have a group created, you can set up Device, Applications, OS, and Software Policies for it by following the steps:

{% hint style="success" %}

1. Click on Manage\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FFByIjHnRSNRaQWxUfZvS%2Fimage.png?alt=media\&token=079f932a-87cf-48e5-9adb-b1a19509e10a)
2. Click on Device Policy / Application Policy / OS Policy / Software Policy (depending on what policy you want to create)\ <img src="https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2F8Dl7l5pu25FCxId6VDXr%2Fimage.png?alt=media&amp;token=4ab6e439-e580-4fef-808e-df7370a2fdd9" alt="" data-size="original">
3. Click on + Create\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2Fdxk2XA6wU94d9dkDm447%2Fimage.png?alt=media\&token=8cceff6c-1799-4413-ab83-7a1183dd0041)
4. Find your group in the Search for Group field\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FMgWXdS2kUEspTfpvqjz3%2Fimage.png?alt=media\&token=a2997354-8af2-4fd5-be2b-3cf0872cd7c1)
5. Select OS type\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FaTcmrrdALxqfM4rslKI0%2Fimage.png?alt=media\&token=0273b759-196e-4141-aef4-dcd849714eee)
6. Enter a policy name\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2F0cz5T0ocOVNZIbJT32Tf%2Fimage.png?alt=media\&token=bec14e12-f057-4b10-b75a-c1a2ab173f86)
7. Select policies
8. Click on Create\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FeutFYwGVWs1OmFIy1nOT%2Fimage.png?alt=media\&token=1a87b670-627d-4951-b02e-14e9d57bb66c)
   {% endhint %}

### Personal level

Personal policies are created for each user account. Personal policies overwrite Group and Default System policies.

You can do that by following the steps:

{% hint style="success" %}

1. Click on Manage\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FFByIjHnRSNRaQWxUfZvS%2Fimage.png?alt=media\&token=079f932a-87cf-48e5-9adb-b1a19509e10a)
2. Click on Device Policy / Application Policy / OS Policy / Software Policy (depending on what policy you want to create)\ <img src="https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2F8Dl7l5pu25FCxId6VDXr%2Fimage.png?alt=media&amp;token=4ab6e439-e580-4fef-808e-df7370a2fdd9" alt="" data-size="original">
3. Click on + Create\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2Fdxk2XA6wU94d9dkDm447%2Fimage.png?alt=media\&token=8cceff6c-1799-4413-ab83-7a1183dd0041)
4. Find your group in the Search for Group field\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FG3n9oG8Kvj3uKGttNN2u%2Fimage.png?alt=media\&token=8aad86f9-3842-4bb2-a9c0-caadac6b45e6)
5. Select OS type\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FaTcmrrdALxqfM4rslKI0%2Fimage.png?alt=media\&token=0273b759-196e-4141-aef4-dcd849714eee)
6. Enter a policy name\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2F0cz5T0ocOVNZIbJT32Tf%2Fimage.png?alt=media\&token=bec14e12-f057-4b10-b75a-c1a2ab173f86)
7. Select policies
8. Click on Create\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FeutFYwGVWs1OmFIy1nOT%2Fimage.png?alt=media\&token=1a87b670-627d-4951-b02e-14e9d57bb66c)
   {% endhint %}

## Assignment of Policies

Newly enrolled devices are automatically assigned with their Group Policies if a group exists, or assigned with the Default System Policies if they are not part of a group.

If the same Policies (Default System or Group) are being edited, the changes will affect devices under those policies.

As a Lunar Control Center admin, you can change the policy for each user account, by following the steps:

{% hint style="info" %}

1. Click on Manage\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2F4z6AYZbMSGmGms4aj5kr%2Fimage.png?alt=media\&token=493631f1-e798-423c-8a74-70a5e8566e22)
2. Click on Accounts\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2Ff4wM12QK4SZe3i0V9z49%2Fimage.png?alt=media\&token=3e505ff4-7a80-4215-ad19-02a76ac82aaf)
3. Click on the User's username under the "Username" section\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2Fy1pZuRXHeKNfmqpCsx2A%2Fimage.png?alt=media\&token=51a0db97-85b6-4f98-9849-431a53e37df6)
4. Select from the dropdown the Device, Application or OS policy you want to reassign.\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FDiausu608WfIbKYIrCjT%2Fimage.png?alt=media\&token=94333395-3bd1-47a0-ac66-ad9d27ab4f0b)
5. Click on Save\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FDQjR0SMQGJAUjEwrApqa%2Fimage.png?alt=media\&token=946ef20d-2dbf-4984-bd93-455489cb73b5)
   {% endhint %}

## User Access Level

The access level of the user determines how much control users can have on their device policies.

There are 3 access levels:

* **Limited user**: users are not able to change their own device policies. Policies assigned to them are forced.
* **Power-user**: power users' devices receive the policies assigned to them, but they can also change those via their Phone Manager application (installed on their device), or through the Lunar Control Center User Portal if such is enabled.&#x20;
* **Group administrator**: group administrators have all the rights of power users, plus the ability to manage policies for devices that are in their group. Management of group policies is only available in the Lunar Control Center User Portal if such is enabled.

As an administrator, you can change user access level by following the steps:

{% hint style="success" %}

1. Click on Manage\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2F4z6AYZbMSGmGms4aj5kr%2Fimage.png?alt=media\&token=493631f1-e798-423c-8a74-70a5e8566e22)
2. Click on Accounts\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2Ff4wM12QK4SZe3i0V9z49%2Fimage.png?alt=media\&token=3e505ff4-7a80-4215-ad19-02a76ac82aaf)
3. Click on the User's username under the "Username" section\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2Fy1pZuRXHeKNfmqpCsx2A%2Fimage.png?alt=media\&token=51a0db97-85b6-4f98-9849-431a53e37df6)
4. Select an option from the access level dropdown.\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2Fbwe8JpjrASNbivRambXY%2Fimage.png?alt=media\&token=d898770d-b3a0-456c-99d5-73b03b4d27f9)
5. Click on Save\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FDQjR0SMQGJAUjEwrApqa%2Fimage.png?alt=media\&token=946ef20d-2dbf-4984-bd93-455489cb73b5)
   {% endhint %}

## Permission Groups

Permission groups allow additional policy control for Lunar Control Center administrators.

Permission Groups are used to set restrictions for Power Users, limiting what policies they can manage themselves and what policies are restricted and can not be changed.

<figure><img src="https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2Fp75Ld0bwXymULAIRF2oi%2Fimage.png?alt=media&amp;token=d0fa293e-f9a5-4252-a688-c740bf548123" alt=""><figcaption><p>Policies with an open padlock icon indicate that power users can manage that policy. Policies with a closed padlock icon indicate that power users can not manage that policy </p></figcaption></figure>

To use Permission Groups, you first have to create one by following the steps below:&#x20;

{% hint style="success" %}

1. Click on Manage\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FFByIjHnRSNRaQWxUfZvS%2Fimage.png?alt=media\&token=079f932a-87cf-48e5-9adb-b1a19509e10a)
2. Click on Permission Groups\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FbgiKXInjCzY6LZL1Savu%2Fimage.png?alt=media\&token=eacf3f6e-76d2-438e-a1ad-99aec24b124c)
3. Click + Create \
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FrJG52fNsg40ViHR2AFK6%2Fimage.png?alt=media\&token=ddf4ea51-ab6f-46cf-82c9-c97f4290a9d3)
4. Fill up fields, including:\
   \- **Name**: the name of the permission group\
   \- **Group**: choose a group associated with the permission group. (users in this group will not be automatically added to the permission)\
   \- **OS version**: select OS version
5. Configure your permission group rules
6. Click Create\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FEQtuq9h5z0DgiGzK44Vh%2Fimage.png?alt=media\&token=231a99ec-639e-4e26-81c9-c0248f28b289)
   {% endhint %}

Once the permission group is created, you can add user accounts to it by following the steps:&#x20;

{% hint style="success" %}

1. Click on Manage\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FFByIjHnRSNRaQWxUfZvS%2Fimage.png?alt=media\&token=079f932a-87cf-48e5-9adb-b1a19509e10a)
2. Click on Permission Groups\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FCcSpLT2UBHBjw9amGvdj%2Fimage.png?alt=media\&token=c6258943-1bd4-45f6-af59-26b7ff113385)<br>
3. Click on Manage Users\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FQJga6N4xQt3dmpFxYB0a%2Fimage.png?alt=media\&token=88f7dd02-65d3-49ea-9c42-70f2eccb14b7)
4. Select users to be added to the permission group by clicking on the checkmark next to the username (only users that are part to the linked Group will be shown as available)
5. Press Add All Checked Users\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FGgR1EhB3VfQ3PVuT550B%2Fimage.png?alt=media\&token=fff8ea2c-4393-448c-aaeb-ea61e427f7be)
6. Press Save\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FXngwWqClSdgkWH0p8C19%2Fimage.png?alt=media\&token=3b76b2d8-a89b-471a-ba36-d8f8d3aed5d1)
   {% endhint %}

The Manage Users menu also allows you to remove Users from the Permission Group.


# Application management

Lunar Control Center lets you manage what applications can users access. Once added to your LCC instance, you can enable applications through the [Application policies](/lunar-control-center-console/policy-management#application-policies).&#x20;

## Application levels

Lunar Control Center supports 2 levels for applications:

* **Organization apps**: organization apps are installed for all users, regardless of their policies. In addition, the necessary in-phone permissions are granted automatically for organization apps
* **Custom apps**: custom apps are applications that may or may not be enabled for users through policies. Users will have to grant app permissions after app installation.

## Adding applications

You can add applications by uploading a file locally or by getting an app from the Update Server (requires [connection to the update server](/lunar-control-center-console/automated-software-updates#how-to-enable-software-updates))

### Adding app through Update Server

You can add applications by following the steps:

{% hint style="success" %}

1. Click on Apps\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FLrGxEc2nyo8bIsLE9GBG%2Fimage.png?alt=media\&token=a1d20354-9013-4ffc-9c04-1af4d02f083a)
2. Click on Organization or Custom apps (depending on what app level you want to add)\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2F335U1p0Y4PNcCZtar1M6%2Fimage.png?alt=media\&token=68979803-7875-49e5-a840-8fa945b3a017)
3. Click on Add from APK station\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FfAQPxsZLio742XvnRja9%2Fimage.png?alt=media\&token=6c6fa195-b259-459d-baf1-4bee5543c32e)
4. Type the app name or package name in the search section and press search\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FImkCEjwsCBqrJVg9MR9i%2FNew%20Project.png?alt=media\&token=d749c3e5-f829-412c-9bea-5f5cce0ea8cf)
5. When you find the app(s) you need, press the request toggle\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2Fc8c8MAkDmahdveD0nVop%2Fimage.png?alt=media\&token=c07f1e86-d796-48a4-9480-c4d2ef8bebe4)
6. Press the request button after you are done selecting apps\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FsIV6IOelMgKzAZXACW4j%2Fimage.png?alt=media\&token=b4640c76-8ba3-412b-a385-5a7ab93c4f84)
7. Open the update menu by pressing on the Android icon\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FVkzaoI5yfHCci0KUnMFF%2Fimage.png?alt=media\&token=5b0b629f-44c1-4d61-a6b6-cbedfd29cf87)
8. Download each app you have requested by pressing the download icon next to the app\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2Fn7iWtosfZTSdPXZ0E1Uy%2Fimage.png?alt=media\&token=f1b9f51b-27fa-45c6-a753-e4b0597666b8)
   {% endhint %}

### Adding app from local upload

You can add applications by following the steps:

{% hint style="success" %}

1. Click on Apps\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FLrGxEc2nyo8bIsLE9GBG%2Fimage.png?alt=media\&token=a1d20354-9013-4ffc-9c04-1af4d02f083a)
2. Click on Organization or Custom apps (depending on what app level you want to add)\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2F335U1p0Y4PNcCZtar1M6%2Fimage.png?alt=media\&token=68979803-7875-49e5-a840-8fa945b3a017)
3. Click on Create\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2Fiik3QcGXE6WKVTNCJZSD%2Fimage.png?alt=media\&token=a5e6d5a5-d291-436c-ac0b-7e9c8bbdce52)
4. Fill up the fields:\
   \- File: upload the APK file of the app\
   \- Icon: upload an icon. The icon will be visible in LCC Console and in the App store to users.\
   \- Name: Put the name of the app. The app name will be visible in LCC Console and in the App store to users.\
   \- Author: Add an author of the app. The app author will be visible in LCC Console and in the App store to users.\
   \- Category: Select a category of the app.\
   \- Available on the following OS: select if the app is for a specific Device OS version.\
   \- Prevent app from updating: if toggled on, the app version can not be updated.\
   \- Images: upload images of the app UI. The images will be visible in LCC Console and in the App store to users.\
   \- Description: add a description of the app. The description will be visible in LCC Console and in the App store to users.\
   \- Summary for description: add a summary of the description. The description summary will be visible in LCC Console and in the App store to users.\
   \- Change log: add an internal note regarding the change.
5. Click on Create\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FZFh5L3sDLPZFDLoaYX9e%2Fimage.png?alt=media\&token=4b08b1b5-2df7-46d8-bcf2-a9afd000fbd7)
   {% endhint %}

## App version management

Administrators of Lunar Control Center can easily manage the application version pushed to devices.

### Checking for new App version

The connection with Lunr's [Update Server](/lunar-control-center-console/automated-software-updates#application-updates) allows for instant checks of the latest available app version.&#x20;

Administrators can use the check update feature for both Organization and Custom apps.

#### Organization Apps

Follow the steps below to check for a new version of Organization Apps:

{% hint style="success" %}

1. Click on Apps\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FLrGxEc2nyo8bIsLE9GBG%2Fimage.png?alt=media\&token=a1d20354-9013-4ffc-9c04-1af4d02f083a)
2. Click on Organization Apps\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FQRUpdAfVS44c8ah5qvO9%2Fimage.png?alt=media\&token=989c5afa-b040-4df3-9338-4097e3a37c67)
3. Hover over the app you want to check and click on the edit icon\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2F77TXbvlM6MaeWZUbglGf%2Fimage.png?alt=media\&token=9192e8e3-2b19-48f6-8716-a1a3b9fd15ae)
4. Click on Check For Updates\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FTftYeUJCL3UtcQykVjqU%2Fimage.png?alt=media\&token=5627d1c2-3339-4380-ad21-65920b98180f)
5. Click on OK

If a new app version is available, you will receive a notification in the top right corner (see Android icon).&#x20;

6. Open the update menu by pressing on the Android icon\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FVkzaoI5yfHCci0KUnMFF%2Fimage.png?alt=media\&token=5b0b629f-44c1-4d61-a6b6-cbedfd29cf87)
7. Download the new app version by clicking on the download icon next to the app\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2Fn7iWtosfZTSdPXZ0E1Uy%2Fimage.png?alt=media\&token=f1b9f51b-27fa-45c6-a753-e4b0597666b8)
8. Once you download the latest version, navigate back to the application menu by following steps 1, 2 and 3.
9. Hover over the app information button and select the latest version\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FADrwlODKtpQpTplFfJyV%2Fimage.png?alt=media\&token=3f7fe540-ccfe-41dc-b2ac-fabbbc0b628b)
10. Click on the Mark as Default button to make the version default for all devices that have the app enabled by policy\
    ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FQpjFTMn6pTNDLvk5eTLy%2Fimage.png?alt=media\&token=c9d0b930-8743-4f55-91ca-efe94098c374)
    {% endhint %}

#### Custom Apps

Follow the steps below to check for a new version of Custom Apps:

{% hint style="success" %}

1. Click on Apps\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FLrGxEc2nyo8bIsLE9GBG%2Fimage.png?alt=media\&token=a1d20354-9013-4ffc-9c04-1af4d02f083a)
2. Click on Custom Apps\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FSltnWcsT8rAFQSK0AjUf%2Fimage.png?alt=media\&token=cc34cfa6-a712-45ce-97ed-7a89fc007534)
3. Click on the application name (or icon) you want to check\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FpRPxCU1QDhy6eIXcH8B3%2Fimage.png?alt=media\&token=68f637c1-b747-49bf-a303-d8fe7c39a74b)
4. Click on Check For Updates\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FTftYeUJCL3UtcQykVjqU%2Fimage.png?alt=media\&token=5627d1c2-3339-4380-ad21-65920b98180f)
5. Click on OK

If a new app version is available, you will receive a notification in the top right corner (see Android icon).&#x20;

6. Open the update menu by pressing on the Android icon\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FVkzaoI5yfHCci0KUnMFF%2Fimage.png?alt=media\&token=5b0b629f-44c1-4d61-a6b6-cbedfd29cf87)
7. Download the new app version you by clicking on the download icon next to the app\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2Fn7iWtosfZTSdPXZ0E1Uy%2Fimage.png?alt=media\&token=f1b9f51b-27fa-45c6-a753-e4b0597666b8)
8. Once you download the latest version, navigate back to the application menu by following steps 1, 2 and 3.
9. Hover over the app information button and select the latest version\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FADrwlODKtpQpTplFfJyV%2Fimage.png?alt=media\&token=3f7fe540-ccfe-41dc-b2ac-fabbbc0b628b)
10. Click on the Mark as Default button to make the version default for all devices that have the app enabled by policy\
    ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FQpjFTMn6pTNDLvk5eTLy%2Fimage.png?alt=media\&token=c9d0b930-8743-4f55-91ca-efe94098c374)
    {% endhint %}

### Update app version through local upload

Administrators can upload a new app version in case they have not connected to Lunr's Update Server or in case the app is not found through a search to the Update Server.&#x20;

The app version can be uploaded for both Organization and Custom apps.

#### Organization Apps

Follow the steps below to upload a new Organization app version:

{% hint style="success" %}

1. Click on Apps\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FLrGxEc2nyo8bIsLE9GBG%2Fimage.png?alt=media\&token=a1d20354-9013-4ffc-9c04-1af4d02f083a)
2. Click on Organization Apps\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FQRUpdAfVS44c8ah5qvO9%2Fimage.png?alt=media\&token=989c5afa-b040-4df3-9338-4097e3a37c67)
3. Hover over the app you want to check and click on the edit icon\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2F77TXbvlM6MaeWZUbglGf%2Fimage.png?alt=media\&token=9192e8e3-2b19-48f6-8716-a1a3b9fd15ae)
4. Click on Create New Version\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FUnxeY94smKp0PzsK66G1%2Fimage.png?alt=media\&token=d4b6ca3d-35bb-4e6f-8663-b750ee96ee6f)
5. Fill up the fields: \
   \- Set as default version: sets the version you are about to upload as default version for devices that have the app enabled by policy\
   \- File: upload the APK file\
   \- Change log: add notes about the app changes. Change log notes will be visible to LCC administrators.&#x20;
6. Click on Create\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FPO78b5cPaRMCHqfCI3Zr%2Fimage.png?alt=media\&token=41878df5-c989-4482-939a-766bb122085e)
   {% endhint %}

#### Custom Apps

Follow the steps below to upload a new Custom app version:

{% hint style="success" %}

1. Click on Apps\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FLrGxEc2nyo8bIsLE9GBG%2Fimage.png?alt=media\&token=a1d20354-9013-4ffc-9c04-1af4d02f083a)
2. Click on Custom Apps\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FSltnWcsT8rAFQSK0AjUf%2Fimage.png?alt=media\&token=cc34cfa6-a712-45ce-97ed-7a89fc007534)
3. Click on the application name (or icon) you want to check\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FpRPxCU1QDhy6eIXcH8B3%2Fimage.png?alt=media\&token=68f637c1-b747-49bf-a303-d8fe7c39a74b)
4. Click on Create New Version\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FUnxeY94smKp0PzsK66G1%2Fimage.png?alt=media\&token=d4b6ca3d-35bb-4e6f-8663-b750ee96ee6f)
5. Fill up the fields: \
   \- Set as default version: sets the version you are about to upload as default version for devices that have the app enabled by policy\
   \- File: upload the APK file\
   \- Change log: add notes about the app changes. Change log notes will be visible to LCC administrators.&#x20;
6. Click on Create\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FPO78b5cPaRMCHqfCI3Zr%2Fimage.png?alt=media\&token=41878df5-c989-4482-939a-766bb122085e)
   {% endhint %}

## Deleting applications

Deleting applications from your Lunar Control Center instance helps you improve user experience by removing unneeded apps. Once applications are deleted, they are removed from user devices.

As an Administrator, you can delete both Organization and Custom Apps.

#### Deleting Organization Apps

Follow the steps below to delete an Organization app:

{% hint style="success" %}

1. Click on Apps\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FLrGxEc2nyo8bIsLE9GBG%2Fimage.png?alt=media\&token=a1d20354-9013-4ffc-9c04-1af4d02f083a)
2. Click on Organization Apps\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FQRUpdAfVS44c8ah5qvO9%2Fimage.png?alt=media\&token=989c5afa-b040-4df3-9338-4097e3a37c67)
3. Hover over the app you want to check and click on the X icon\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FjfFfAi6stG9tf8Uvvoet%2Fimage.png?alt=media\&token=b05ed30f-1403-4abb-8ddb-5d422985eebc)
4. Click on OK
   {% endhint %}

#### Custom Apps

Follow the steps below to check for a new version for Custom Apps:

{% hint style="success" %}

1. Click on Apps\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FLrGxEc2nyo8bIsLE9GBG%2Fimage.png?alt=media\&token=a1d20354-9013-4ffc-9c04-1af4d02f083a)
2. Click on Custom Apps\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FSltnWcsT8rAFQSK0AjUf%2Fimage.png?alt=media\&token=cc34cfa6-a712-45ce-97ed-7a89fc007534)
3. Click on the bin icon next to the app you want to delete\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FpVooUoTFytSTxzN8weaU%2Fimage.png?alt=media\&token=8029c82f-2754-4385-9df2-99ca5dcfc5cc)
4. Click on OK<br>
   {% endhint %}

## Validation certificates

Ensuring that you are pushing an authentic application version is crucial for securing your device fleet.

Lunar Control Center allows you to add certificates in order to guarantee the authenticity of the apps you are uploading.

You can add validation certificates by following the steps:&#x20;

{% hint style="success" %}

1. Hover over the config button\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FRtMUc1CBNAWJhCCxkBzu%2Fimage.png?alt=media\&token=c2110ecd-535f-4e25-84a5-d86b42cbe676)
2. Click on Settings\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FzeoOReU01jfrZeMVJ8Kd%2Fimage.png?alt=media\&token=d1dd980d-fbbf-4653-b4ad-5ed89983e8b0)
3. Click on Updates\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FxQznc1e9sEgBHMDGllb8%2Fimage.png?alt=media\&token=c93b8dd5-8977-4328-a8da-709799705ad0)
4. Fill up values for: \
   \- **Secure APK validation certificate**: enter the certificate values\
   \- **Secure APK validation certificate owner**: enter the certificate owner values
5. Click on Save
   {% endhint %}

Applications that do not pass the certificate validation will show as Untrusted once uploaded to your Lunar Control Center


# Automated software updates

## About

Updating your Lunar Control Center and device software to the latest version is crucial for the security of your device fleet.

We've made the update process easy, through the integration with our update server.&#x20;

You can benefit from secure OTA updates on your Lunar Control Center, Devie Operating System, and applications, all easily managed through the LCC Console.

## How to enable software updates

To enable automated software updates, you will have to first connect your LCC instance to Lunr's update server, by following the steps:

{% hint style="success" %}

1. Hover over the Config icon in the top right corner\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FGEfWJCxriPeB0bSV4vay%2Fimage.png?alt=media\&token=2c09683e-3c5f-4320-9df6-f91204534ee2)
2. Click on Settings\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FMTqWNXQhnOvkHir3arlF%2Fimage.png?alt=media\&token=e76c7b92-d796-460b-9dc6-f86d654c804b)
3. Click on Updates\ <img src="https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FBwZcy0ZhN6bbWpSxDTtX%2Fimage.png?alt=media&amp;token=38c3591c-3910-484b-a9f9-766d1e8d7af5" alt="" data-size="original">
4. Toggle On Subscribe On Updates\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FXccrNyJBT53huDO3f1Hp%2Fimage.png?alt=media\&token=c154a232-383b-442d-89c8-9f3ecf805e19)
5. Add Lunr's update server URL: noc-noc.cc\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FGMZWIe2rn0LwP5Fe9Nf0%2Fimage.png?alt=media\&token=babdc2bd-332f-4980-bdc6-fd74b1f4ece4)
6. Add Update Server access token (it is the same as your registry subscription key you used to install your LCC instance)\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2Fsb7eYZDlkGguX2BcOOTZ%2Fimage.png?alt=media\&token=d4e83dfb-7c3d-40d3-9eb3-7c931f79d07d)
   {% endhint %}

## Application Updates

The connection between your LCC instance and Lunr's Update Server allows you to automate updates of the software version of your organization and custom applications added to your instance.

### Configuring app updates

You can configure your App Update settings by following the steps:

{% hint style="success" %}

1. Hover over the Config icon in the top right corner\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FGEfWJCxriPeB0bSV4vay%2Fimage.png?alt=media\&token=2c09683e-3c5f-4320-9df6-f91204534ee2)
2. Click on Settings\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FMTqWNXQhnOvkHir3arlF%2Fimage.png?alt=media\&token=e76c7b92-d796-460b-9dc6-f86d654c804b)
3. Click on Updates\ <img src="https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FBwZcy0ZhN6bbWpSxDTtX%2Fimage.png?alt=media&amp;token=38c3591c-3910-484b-a9f9-766d1e8d7af5" alt="" data-size="original">
4. Navigate to APK Updates section\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FdtqkXKCkNUOkfId3FEhX%2Fimage.png?alt=media\&token=a8dd20ea-28de-4ec2-90fb-1a08f02d9422)
   {% endhint %}

Once you navigate to the section, you will see the following options:

* **Automatic APK download**: toggle on to download the latest app version in your LCC instance. If disabled, you will need to download app versions when they are made available manually.
* **Automatic APK release**: toggle on to automatically update the app version to the latest downloaded app version. If toggled off, you will need to release the new app version to devices manually.
* **Expiration time for an update notifications \[minutes]**: defines for how long should an update notification be kept if you have not downloaded the app. This value is relevant if you have disabled Automatic APK download.

### Manually downloading app updates

To update manually you need to navigate to the update menu, by clicking on the icon ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FQo1yB4xKTNukDDUiyaAv%2Fimage.png?alt=media\&token=10d64822-8094-4f86-8ae9-fc4afb733e32) on the top right. Once clicked, you will be taken to the menu with requested applications that are available for downloading. In the menu, you will be able to download the new version of the app by clicking on the download icon.

## OS updates

### Configuring OS updates

You can configure your OS Update settings by following the steps:

{% hint style="success" %}

1. Hover over the Config icon in the top right corner\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FGEfWJCxriPeB0bSV4vay%2Fimage.png?alt=media\&token=2c09683e-3c5f-4320-9df6-f91204534ee2)
2. Click on Settings\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FMTqWNXQhnOvkHir3arlF%2Fimage.png?alt=media\&token=e76c7b92-d796-460b-9dc6-f86d654c804b)
3. Click on Updates\ <img src="https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FBwZcy0ZhN6bbWpSxDTtX%2Fimage.png?alt=media&amp;token=38c3591c-3910-484b-a9f9-766d1e8d7af5" alt="" data-size="original">
4. Navigate to OS Updates section\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2Fvqo7umEaYKm1kTwhU6bO%2Fimage.png?alt=media\&token=b636f5cc-43a4-413a-bd55-619153b07375)
   {% endhint %}

Once you navigate to the section, you will see the following options:

* **OS updates**: toggle on to subscribe for OS version updates.&#x20;
* **Automatic OS download**: toggle on to download automatically the new stable OS version. If toggled off, you will need to download the OS update to your LCC instance manually. Downloading the OS automatically or manually will not release it to end-users.
* **Automatic OS publish**: toggle on to automatically publish the newly downloaded version to users. If toggled off, you will need to publish the OS to devices manually.
* **Beta releases**: toggle on to subscribe for beta OS releases. The behavior in terms of auto-downloading or publishing is determined by the Automatic OS publish and Automatic OS download toggle options.&#x20;


# Managing device models

Lunar Control Center can be used to manage different compatible Android devices.&#x20;

## Adding a new device model

In order to manage Android devices, you first need to add it as a device to your Lunar Control Center.

You can add a new device by following the steps:

{% hint style="success" %}

1. Click on OS\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FeqN9SzOWKZPy5t6qRx1H%2Fimage.png?alt=media\&token=46b30a4a-58ee-4f7c-81cb-30ffcbc23706)
2. Click on Device Models\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2F1Pzank9quCdXz9DaE3E3%2Fimage.png?alt=media\&token=02eacca2-e34b-4a50-a244-ad135be11e28)
3. Click on + Create\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2Fdxk2XA6wU94d9dkDm447%2Fimage.png?alt=media\&token=8cceff6c-1799-4413-ab83-7a1183dd0041)
4. Fill up the fields, including:\
   \- **Name**: this is the name of the device. You will see it in your console\
   \- **Unique**: it is a unique identification of the device. Make sure to fill in the exact one as provided by the phone manufacturer. It is required in order to fetch OS updates from the Update Server\
   \- **Build JSON**: this is a piece of JSON that gets fed to the device. Make sure to follow the instructions provided by the phone manufacturer.
5. Click on Create\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FeutFYwGVWs1OmFIy1nOT%2Fimage.png?alt=media\&token=1a87b670-627d-4951-b02e-14e9d57bb66c)
   {% endhint %}

## Enabling MicroG

MicroG is an integration with LCC-compatible devices that enables push notifications for de-googled Android devices. If your use case requires MicroG, you will need to add the necessary MicroG libraries to the device model.

You can do that by following the steps:

{% hint style="success" %}

1. Click on OS\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FeqN9SzOWKZPy5t6qRx1H%2Fimage.png?alt=media\&token=46b30a4a-58ee-4f7c-81cb-30ffcbc23706)
2. Click on Device Models\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2F1Pzank9quCdXz9DaE3E3%2Fimage.png?alt=media\&token=02eacca2-e34b-4a50-a244-ad135be11e28)
3. Click on the edit icon next to your device model\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2FSTKOG6htDMcPlgHiogDS%2Fimage.png?alt=media\&token=11132cc9-c0a8-4a00-9b04-60313cdd43e7)
4. Upload the necessary library files as instructed by the manufacturer of the phone.
5. Click on Save\
   ![](https://3030434181-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi5iD0Y9AwBWF4RPuodeX%2Fuploads%2F94k5ZYrSxXMh2NFdTTrz%2Fimage.png?alt=media\&token=e2356451-f2f2-4256-bde9-23e816d3644f)
   {% endhint %}


# LCC CLI

## About

The LCC CLI is a tool designed to provide administrators with efficient management capabilities for the Lunar Control Center system. It provides a unified command line interface for deployment, update, and backup services.

LCC CLI runs on the machine hosting the LCC instance. Follow the [installation guide](/deployment/installation) to get started.&#x20;

Once LCC CLI is installed, you can start using it through your terminal.

In order to use LCC CLI functions, you first need to activate a custom Python environment environment:

```
source /usr/local/lib/lcc/bin/activate
```

The environment gets deactivated automatically after the LCC-CLI is no longer in use.&#x20;

## LCC-CLI: List of available commands

***

### Help command

Get a list of all available commands

```
lcc-cli --help
```

***

### Version command

Print Lunar Control Center and third-party services software version information.

```
lcc-cli version
```

***

### Service status command

Get the current state of Lunar Control Center docker service.

```
lcc-cli status --service proxy_proxy
```

***

### Service install command

This command provides the capability to install additional services integrated with Lunar Control Center.

```
lcc-cli install [OPTIONS]
```

<table><thead><tr><th width="279">Name</th><th>Description</th></tr></thead><tbody><tr><td>--service [openfire | kamailio | portainer | grafana | zabbix | wazuh | homer | ntp | dnscrypt]</td><td>Choose a service to install. [default: None] [required]</td></tr><tr><td>--help</td><td></td></tr></tbody></table>

***

### Service uninstall command

This command provides the capability to uninstall additional services integrated with Lunar Control Center.

```
lcc-cli uninstall [OPTIONS]
```

<table><thead><tr><th width="279">Name</th><th>Description</th></tr></thead><tbody><tr><td>--service [openfire | kamailio | portainer | grafana | zabbix | wazuh | homer | ntp | dnscrypt]</td><td>Choose a service to uninstall. [default: None] [required]</td></tr><tr><td>--help</td><td></td></tr></tbody></table>

### Init command

Install a clean LCC instance

```
lcc-cli init [OPTIONS]
```

Options:

<table><thead><tr><th width="279">Name</th><th>Description</th></tr></thead><tbody><tr><td>--lcc-domain-name</td><td>Selection of domain for the LCC instance. [required]</td></tr><tr><td>--lcc-admin-username</td><td>Selection of admin username. Has to be in email format. [required]</td></tr><tr><td>--lcc-admin-password</td><td>Selection of admin password. Has to be in passphrase format. [required]</td></tr><tr><td>--lcc-registry-subscription-key</td><td>LCC Registry Subscription Key [default: None] [required]</td></tr><tr><td>--help</td><td></td></tr></tbody></table>

***

### Docker cleanup command

Cleanup LCC Instance dangling images, logs, unused containers, networks, anonymous volumes

<pre><code><strong>lcc-cli cleanup [OPTIONS]
</strong></code></pre>

Options:

<table><thead><tr><th width="279">Name</th><th>Description</th></tr></thead><tbody><tr><td>--force</td><td>Forces a deep cleaning procedure [default: no-force] </td></tr><tr><td>--no-force</td><td>Initiates a deep cleaning procedure [default: no-force] </td></tr><tr><td>--help</td><td></td></tr></tbody></table>

***

### Flush command

Flush an instance from a previous LCC installation.

```
lcc-cli flush [OPTIONS]
```

<table><thead><tr><th width="279">Name</th><th>Description</th></tr></thead><tbody><tr><td>--force</td><td>Forces a flush of instance from previous LCC installation [default: no-force]</td></tr><tr><td>--no-force</td><td>Flush an instance from previous LCC installation [default: no-force]</td></tr><tr><td>--help</td><td></td></tr></tbody></table>

***

### SSL management command

This command offers functionality to generate self-signed keys, request LetsEncrypt certificates using the HTTP challenge, renew existing certificates, and check the status of the current certificates.

```
lcc-cli ssl [OPTIONS]
```

<table><thead><tr><th width="372">Name</th><th>Description</th></tr></thead><tbody><tr><td>--action [request | renew  | status | generate]</td><td>Generate,request or renew your LCC Let'sEncrypt certificates. [default: None] [required]</td></tr><tr><td>--help</td><td></td></tr></tbody></table>

***

### Password change command

The "change password" feature provides admins with the ability to update their existing passwords easily and securely.

```
lcc-cli password [username] [OPTIONS]
```

<table><thead><tr><th width="372">Name</th><th>Description</th></tr></thead><tbody><tr><td>--password</td><td>Enter your new password. [default: None] [required]. The entered password should be between apostrophes (e.g. 'password')</td></tr><tr><td>--help</td><td></td></tr></tbody></table>

***

### Backup

The command allows the local backup of the Lunar Control Center instance, including users, policies, logs, software versions, and additional services configurations.

```
lcc-cli backup [OPTIONS] /tmp/

```

<table><thead><tr><th width="163">Name</th><th>Description</th></tr></thead><tbody><tr><td>--path</td><td>Chooses a path where the backup file will be saved. Path should be writable.</td></tr><tr><td>--help</td><td></td></tr></tbody></table>

***

### Restore

The command allows the restoration of a Lunar Control Center from a backed-up file.

```
lcc-cli restore [OPTIONS] /tmp/[file name]

```

<table><thead><tr><th width="163">Name</th><th>Description</th></tr></thead><tbody><tr><td>--file</td><td>Selects a path and file for the restoration process. File should exist and the directory with the file should be writable</td></tr><tr><td>--help</td><td></td></tr></tbody></table>


# Deployment

Lunr Control Center is deployed through lunr CLI.&#x20;

Deployment requires the administrator to go through the following steps:

* Lunr CLI installation (if not already installed);
* Lunar Control Center installation;
* (optional) Installation of integrations.


# Requirements

In order to run Lunr Control Center, you need a server with the following requirements:&#x20;

### Infrastructure prerequisites <a href="#lcccli-begins.-serverrequirements" id="lcccli-begins.-serverrequirements"></a>

* Debian 12 | Ubuntu 24.04 server
* 16 GB of RAM
* 4 cores CPU
* at least 40 GB of ROM.
* network requirements:

  * resolvable domain name (A, AAAA  DNS record)

  * &#x20;server ports:
    * LCC:&#x20;
      * 80/http -  Lets Encrypt request | renew HTTP challandge
      * &#x20;443/https -  management panels
      * 8333/https - LCC device API&#x20;
      * 8243/https - LCC storage service&#x20;
      * 1883/tcp - LCC MQTT (+TLS)
      * 389/tcp -  LCC PGP Public Keyserver
    * XMPP:

      5223/tcp\
      5263/tcp\
      5262/tcp\
      7777/tcp\
      5275/tcp\
      5269/tcp\
      7443/tcp\
      7070/tcp\
      5222/tcp -  XMPP  device communication

      z9091/tcp - XMPP server admin panel
    * VoIP
      * 10000-10300/udp - media proxy traffic
      * 5061/tcp - SIP TLS traffic
    * DNS
      * 53/tcp - DNS Crypt
    * NTP
      * 123/udp - NTP server

  * Ping (may be needed depending on the environment):
    * ICMP

  * DNS rules for  managed domain name ( "domain.com" is just an example of a  server domain name) :

    * LCC:
      * A: domain.com
      * CNAME: keys.domain.com
      * SRV: \_api.\_tcp.domain.com 8333 domain.com
      * SRV: \_secureapi\_v2.\_tcp.domain.com 8333 domain.com&#x20;
    * XMPP:
      * CNAME: conference.domain.com
      * CNAME: pubsub.domain.com
      * CNAME: search.domain.com
      * SRV: \_xmpp-client.\_tcp.domain.com 5223 domain.com
      * SRV: \_xmpp-server.\_tcp.domain.com 5269 domain.com
      * SRV: \_xmpp-server.\_tcp.conference.domain.com 5269 domain.com
      * SRV: \_xmpp-server.\_tcp.pubsub.domain.com 5269 domain.com
    * VoIP:
      * SRV: \_sips.\_tcp.domain.com 5061 domain.com

  *


# Installation

Lunar Control Center is deployed via an installation script. This script is intended as a convenient way to configure LCC's package repositories and install LCC on your server.

Before starting with the deployment of Lunar Control Center, ensure that you have an installed and configured host server as per the requirements: [Requirements](/deployment/requirements).&#x20;

**The script:**&#x20;

* requires 'root' or 'sudo' privileges to run
* attempts to detect your Linux distribution and version and configure your package management system for you
* installs dependencies without needing  confirmation
* installs the latest stable release (by default) of LCC CLI and Lunar Control Center

- requires 'root' or 'sudo' privileges to run
- attempts to detect your Linux distribution and version and configure your package management system for you
- installs dependencies without needing  confirmation
- installs the latest stable release (by default) of LCC CLI and Lunar Control Center

## Installation steps

To install the latest stable versions of LCC CLI, Lunar Control Center, and their dependencies, follow the steps below:&#x20;

1. **Open your terminal**

   Log in to the server that will host Lunar Control Center and open a terminal window.<br>
2. **Download the script to start the installation process**

```
bash <(wget -qO- lcc.sh)
```

Running the command above will start the installation process of the latest stable version of LCC CLI and Lunar Control Center.

3. **Provide the required information to set up LCC**

The installation process requires the set up of the LCC instance and verification of a LCC registry subscription key. Administrators will be prompted to input the following information:

3.1. **LCC Domain**

```
LCC Domain name: [enter your domain name here]
```

Administrators are required to set up a domain for LCC. For LCC to function, DNS should be configured with the right records, as per the article [Requirements](/deployment/requirements).

3.2. **Admin credentials**

```
LCC Admin username (email): [enter your admin email here]
LCC Admin password: [enter your admin password here]
```

The script will suggest an admin user to you, based on the domain chosen (e.g. <admin@domain.com>). You will also be suggested a strong password (randomly generated). Feel free to use the suggested username and password or use different ones.&#x20;

Minimum requirements for passwords:

* Minimum 8 characters in length.
* At least one uppercase letter (English).
* At least one lowercase letter (English).
* At least one digit.
* At least one special character: #?!@$^&\*-

\
An LDAP user will be created with the credentials entered from the step above. The user will have Admin access to the Lunar Control Center console and all installed services.&#x20;

3.3. **Registry subscription key**

```
LCC Registry Subscription key: [enter your subscription key provided to you]
```

The deployment process will continue once you enter a valid registry subscription key.&#x20;

3.4. **Confirm input**

You will be prompted to confirm the input provided by you prior to initiation of the deployment. Once confirmed, the deployment will commence. No additional action is required prior to completion.

Once you go through the steps, you will have successfully installed LCC CLI and Lunar Control Center.&#x20;

Relevant pages:

* [LCC CLI manual](/lcc-cli)
* [Lunar Control Center console manual](broken://pages/R9kGH8Rt5hjvJwnvcNaz)


# Third-party services

Lunar Control Center comes with readily available deployment scripts of third-party services.&#x20;

The third-party services configuration scripts come with the installation of Lunar Control Center. The scripts can help administrators quickly deploy and configure services that will add additional functionalities or control over their Lunar Control Center instance.&#x20;

### Third-party services

<table><thead><tr><th width="155">Product</th><th width="571">Description</th></tr></thead><tbody><tr><td>Zabbix</td><td>Monitoring software that provides real-time monitoring and metrics collection for your LCC instance.</td></tr><tr><td>Wazuh</td><td>Security monitoring platform for detecting, monitoring, and responding to security threats on your infrastructure hosting LCC.</td></tr><tr><td>Openfire</td><td>A real-time collaboration (RTC) server that enables XMPP communication. </td></tr><tr><td>Kamailio</td><td>A SIP server that handles SIP signaling, registration, routing, and other tasks necessary for enabling VoIP services. </td></tr><tr><td>Portainer</td><td>A lightweight container management platform that provides a user-friendly interface for managing Docker containers, and related resources.</td></tr><tr><td>Grafana</td><td>A data visualization tool that allows users to create dashboards and graphs for analyzing and monitoring metrics from various data sources such as databases, APIs, and monitoring systems like Zabbix.</td></tr><tr><td>Homer</td><td>Packet and Event Observability framework for VoiP/RTC Monitoring Applications based on the <a href="http://github.com/sipcapture/hep">HEP/EEP</a> protocol for ingesting signaling, rtc events, logs and statistics with instant search, end-to-end correlation and drill-down capabilities. Used for monitoring and troubleshooting SIP-related issues.</td></tr><tr><td>NTP</td><td>The Network Time Protocol is a networking protocol for clock synchronization between computer systems over packet-switched, variable-latency data networks.</td></tr><tr><td>DNScrypt</td><td>A protocol that authenticates communications between a DNS client and a DNS resolver. It prevents DNS spoofing. It uses cryptographic signatures to verify that responses originate from the chosen DNS resolver and haven't been tampered with.</td></tr></tbody></table>

The scripts are available in .sh format. With every update of Lunar Control Center, the scripts are also updated. The scripts are used to deploy and/or update packages, as well as install dependencies with Lunar Control Center.&#x20;

{% hint style="danger" %}
Using our third-party services set up scripts is important for OpenFire, Kamailio, and RTPEngine technologies due to version compatibility and dependencies.
{% endhint %}


# Security

In addition to the built-in security-hardening features in applications, all of our applications follow a security standard that complete the security robustness of the system.&#x20;

* **Encrypting data in transit:** HTTPS (TLS/SSL) is always used to encrypt data transmitted between Lunar Control Center and the Applications with the API server. This helps prevent man-in-the-middle attacks and ensures the confidentiality and integrity of the data in transit.
* **Authentication:** strong authentication mechanisms is implemented to verify the identity of clients accessing the API. API keys are used to control access.&#x20;
* **Secured data storage:** API keys are accessible only for Lunar Control Center system admins. The multiple access role levels ensure that the API keys are not accessible by LCC operators lacking the right access.
* **Compliance with Android security guidelines:** our applications are developed in compliance with the standard security guidelines for Android applications ensuring securing data at rest


