Mobile devices have become an important enterprise productivity tool. With mobile technology, the distribution of important information is fast; hence, ensuring immediate action is taken to prevent the escalation of an issue. However, the use of mobile devices at pharmaceutical companies requires careful planning and a clear understanding of the rules since most pharmaceutical divisions are required to adhere to multiple standards and regulations, such as the US Department of Food and Drug Administration (FDA), ISO Standards, Medicines and Healthcare Products Regulatory Agency (MHRA), and European Medicines Agency (EMA).
Therefore, pharmaceutical manufacturers need to focus on mobile security to prevent the theft or malicious use of sensitive patient data, drug development R&D, high-value IP, operations, and legal information. Mobile devices have become one of the main threat surfaces for cybercriminals and industrial espionage.
The mobile device features available in the Microsoft Dynamics 365 Finance & Supply Chain Management Warehouse Management System are extended by STAEDEAN Life Sciences to enhance security and compliance with company policies and industry regulations.
Advanced mobile device security
Life Sciences Warehouse Management prevents users from accessing the Warehouse Management App if the corresponding Active Directory account is blocked or disabled; authorized users can enable advanced mobile device security. Such control can be enabled in the Mobile device security tab of the Warehouse management parameters form (Warehouse management > Setup > Warehouse management parameters):
Enable advanced security: if enabled, ensures the following:
The Worker selected in the Work users form is linked to an Active Directory user. This setup is available in the User relations form (System administration > Common > Users > Users > Relations).
Only one User ID can be associated with each Worker in the Work users form.
Enable advanced security V2: if enabled, the systems ensures that the user has an active Azure Entra ID. In this case, please also define the following parameters:
Client ID – enter the client ID of the mobile application in Azure (refer to the Installation guide for additional information)
Client secret – enter the client secret of the mobile application in Azure
Tenant Id – follow the below article: https://learn.microsoft.com/en-us/partner-center/find-ids-and-domain-names#find-the-microsoft-entra-tenant-id-and-primary-domain-name
Resource value – set it to “https://graph.microsoft.com”
Note
If the Enable advanced security V2 parameter is enabled, the Enable advanced security parameter must be enabled as well.
If the Enable advanced security parameter is enabled, it is currently not possible to use the Microsoft default user function in the Workers form.
Controls on the mobile device user ID and password
The following parameters related to the mobile device user ID and password configuration are available in the Warehouse management parameters form (Warehouse management > Setup > Warehouse management parameters > Mobile device security tab > Mobile device user ID and Warehouse management > Setup > Warehouse management parameters > Mobile device security tab > Mobile device user password):
Minimum length: Minimum length of the mobile device user ID, i.e., the User ID field in the Work users form (Warehouse management > Setup > Worker).
Password expiry days: Number of days of the mobile device password validity.
Password expiry warning: The number of days before the mobile device password expires for the user to receive a notification.
Minimum password length: Minimum length of the mobile device password.
Maximum password length: Maximum length of the mobile device password.
Change password via mobile device
Life Sciences Warehouse Management allows resetting the mobile device password via mobile device by creating a menu item with the Change password activity code in the Mobile device menu items form (Warehouse management > Setup > Mobile device > Mobile device menu items).
Additionally, users are forced to change the password in the following scenarios:
Upon the first login on the mobile device;
Whenever the system administrator resets the password;
Whenever the password has expired.
User lock-out
Lock-out parameters for mobile device users, in case of too many failed login attempts, can be defined in the Warehouse management parameters form (Warehouse management > Setup > Warehouse management parameters > Mobile device security tab > Lock-out parameters):
Reset lock-out counter after: The number of minutes elapsed after a failed login attempt before the failed logon attempt counter is reset. If this parameter is set to “0”, the system will never automatically reset the counter.
Lock-out threshold: The number of failed login attempts that causes a mobile device user to be locked out. If this parameter is set to “0”, mobile device users are never locked out.
Lock-out duration: The number of minutes a locked-out mobile device user remains locked out before automatically being unlocked. If set to “0”, the lock-out duration is considered unlimited.
When a mobile device user is locked out, the corresponding Locked out checkbox in the Work users form (Warehouse management > Setup > Worker) is automatically ticked for the user.
Only authorized users can unlock a locked-out user by clicking the Unlock button in the Work users form.