Configuring UEM to Deploy Harmony Mobile Protect app

Prerequisites

Harmony Mobile Gateway/Server – Server name of the Harmony Mobile gateway/server, which should be us-gw01. If you don’t know your Harmony Mobile server name, follow the instructions in section Integration Information to find out.

Adding the Harmony Mobile Protect App to Your App Catalog

Now that the UEMClosed Unified Endpoint Management. An architecture and approach that controls different types of devices such as computers, smartphones and IoT devices from a centralized command point. and Harmony Mobile Dashboard are communicating, you can start deploying the Harmony Mobile Protect app from the public stores to those devices that will be protected by Harmony Mobile.

You need to add the App for both iOS and Android operating systems.

Get Dashboard’s Token

  1. Go to your Harmony Mobile dashboard > Settings > Integration > Click on the three dots on the top right > Edit:

  2. Click Deployment on the left nav, and then copy the token of your dashboard:

iOS App – Add to Catalog

The Harmony Mobile Protect App for iOS can be automatically configured and deployed. The user only needs to accept the installation, and then launch the app once it is installed to finish activation and registration.

  1. Navigate to APPS > Catalog.

  2. Click Add > iOS > iTunes App Store App.

  3. In the App field, enter Harmony Mobile Protect to start actively searching the store. Select the Harmony Mobile Protect app as indicated below.

  4. Navigate to the Policies and Distribution tab, and select Distribute to > select Group or All Devices, and select Install Automatically.

  5. Navigate to the Configuration tab, and select App Config Source of “Key/Value”.

  6. Add the following Key/Value pairs:

    Configuration Key

    Configuration Value

    Lacoon Server Address

    Security GatewayClosed Dedicated Check Point server that runs Check Point software to inspect traffic and enforce Security Policies for connected network resources. servers:

    Region

    Server

    US

    gw.locsec.net

    Ireland (EU region)

    eu-gw.locsec.net

    Australia (Asia region)

    au-gw.locsec.net

    Canada (Canada)

    ca-gw.locsec.net

    UK region (UK)

    uk-gw.locsec.net

    India

    in-gw.locsec.net

    Device Serial Number

    %csn%

    token

    Take the copied value from section Configuring UEM to Deploy Harmony Mobile Protect app

    portalAccountId

    Account ID of application in the Infinity Portal, to integrate it with the UEM.

  7. Click Add.

  1. Enter your admin password and click Confirm.

Android Enterprise App – Add to Catalog

The Android Harmony Mobile Protect App can be automatically configured and deployed. The user only needs to accept the installation, and then launch the app once it is installed to finish activation and registration.

  1. Navigate to APPS > Catalog and click Add > Android > Google Play App.

  2. In the Google Play search field, enter Harmony Mobile Protect to start actively searching the store. Select the Harmony Mobile Protect app as indicated below.

  3. Navigate to the Policies and Distribution tab, and select Distribute to > Group or All Devices, and select Install Automatically.

  4. Navigate to the App Config tab, and select Configure App Settings.

  5. Add the following Key/Value pairs:

    Item

    Configuration Value

    mdm_uuid

    %deviceid%

    gwAddress

    Security Gateway servers:

    Region

    Server

    US

    gw.locsec.net

    Ireland (EU region)

    eu-gw.locsec.net

    Australia (Asia region)

    au-gw.locsec.net

    Canada (Canada)

    ca-gw.locsec.net

    UK region (UK)

    uk-gw.locsec.net

    India

    in-gw.locsec.net

    Token

    Take the copied value from section Configuring UEM to Deploy Harmony Mobile Protect app

    portalAccountId

    Account ID of application in the Infinity Portal, to integrate it with the UEM.

  6. Click the Add button.

  7. Enter in your admin password and click the Confirm button.

Deploying Harmony Mobile Protect app

To deploy the Harmony Mobile Protect app to devices that will be registered to the Harmony Mobile solution you need to link the Harmony Mobile Protect app in our app catalog to the Device ProvisioningClosed Check Point Software Blade on a Management Server that manages large-scale deployments of Check Point Security Gateways using configuration profiles. Synonyms: SmartProvisioning, SmartLSM, Large-Scale Management, LSM. Group you created in section Creating a Device Provisioning Group.

  1. Navigating to Apps > App Catalog, select both the iOS and Android Harmony Mobile Protect apps.

  2. Click the Distribute link.

  3. On the Distribute pop-up window, set Available for equal to ''All''.

  4. Set Target equal to “Group” and choose the device provisioning group you created in Section Creating a Device Provisioning Group, in our example “MP_Devices_Group”.

  5. Select Install Automatically and Send Email check boxes.

  6. Click the Distribute button.

  7. Enter your admin password, and click the Continue button.

Setting Policy to Require Harmony Mobile Protect to be installed

To require the Harmony Mobile Protect app to be installed create a Security PolicyClosed Collection of rules that control network traffic and enforce organization guidelines for data protection and access to resources with packet inspection. for iOS and Android devices, then create a compliance ruleClosed Set of traffic parameters and other conditions in a Rule Base (Security Policy) that cause specified actions to be taken for a communication session. set to the Device Provisioning Group you created in section Creating a Device Provisioning Group, and apply the compliance policy to the Device Provisioning Group.

Creating Compliance Actions for iOS Devices (Policy)

The policy specifies the actions taken on all Harmony Mobile iOS devices.

  1. Navigate to Security > Policies, and click the Add Policy button.

  2. Enter a Name for the policy, such as “MP_App_iOS”, select a Type of “iOS UEM”, and select Start From equal to “My Existing Policies''. On My Existing Policies select ''(def) Default iOS UEM Policy”.

  3. Click the Continue button.

  4. On the menu to the left, on the Device Settings pane there are several sections for policy sets, such as “Passcode, Restrictions, Application ComplianceClosed Check Point Software Blade on a Management Server to view and apply the Security Best Practices to the managed Security Gateways. This Software Blade includes a library of Check Point-defined Security Best Practices to use as a baseline for good Security Gateway and Policy configuration., etc. We will make our modifications in the ''Application Compliance'' section.

  5. Click the Edit button.

  6. Under the Application Compliance section, select Configure Required Applications.

  7. In the Application Name field, start typing Harmony Mobile Protect and the app will pop-up, select Harmony Mobile Protect.

  8. Click the Save and Publish button.

  9. On the ''Publish'' pop up window click Continue.

  10. Enter in your admin password and click the Confirm button.

Creating Compliance Actions for Android Devices (Policy)

The policy specifies the actions taken on all Harmony Mobile Android devices.

  1. Navigate to Security > Policies, and click the Add Policy button.

  2. Enter a Name for the policy, for example “MP_App_Android”, select a Type of “Android UEM”, and select Start From equal to ''My Existing Policies''. On My Existing Policies select “Default Android UEM Policy”.

  3. Click the Continue button.

  4. On the menu to the left, on Device Settings there are several sections for policy sets, such as “Passcode'', ''Security'', ''Restrictions'', ''Application Compliance'', etc. Make the modifications in the “Application Compliance” section.

  5. Click the Edit button.

  6. Under the Application Compliance section, scroll down and select Configure Required Applications.

  7. In the Application Name field, enter Harmony Mobile Protect

  8. In the Application ID field, enter “com.lacoon.security.fox”.

  9. Click the Save And Publish button.

  10. On the Publish pop up window click on Continue.


  1. Enter in your admin password and click the Confirm button.

Applying App Required Policy to Device Provisioning Group

The policies created in the previous section are assigned to the device provisioning group created in section Creating a Device Provisioning Group, in our example “MP_Devices_Group”.

  1. Navigate to Devices > Groups, locate the device provisioning group, click the More… link, and select Change Policy.

  2. Set iOS Policy to the compliance policy we created in Section 4.4.1, in our example “MP_App_iOS”.

  3. Set Android Policy to the compliance policy we created in Section 4.4.2, in our example “MP_App_Android”.

  4. Click the Submit button.

  5. Enter in your admin password, and then click the Confirm button.

  6. The policies and the apps added to the MP_Devices_Group.

Note - Any device that belongs to the Device Provisioning Group (“MP_Devices_Group”) that hasn’t installed the Harmony Mobile Protect app will be out of compliance.