Capsule Workspace Settings - Profile - Mobile Security
What can I do here?
Use this page to configure integration with the Mobile Security application or with Harmony App Protect.
|
|
Getting Here - Manage & Settings > Blades > Mobile Access |
Configuring Mobile Profile Settings
-
In the Security tab, configure Access Settings:
-
Session timeout - After users authenticate with the authentication method configured in Gateways & Servers > Security Gateway object > Mobile Access > Authentication, configure how long they stay authenticated to the Security Gateway.
-
Activate Passcode lock - Select to protect the Business Secure Container area of the mobile device with a passcode.
-
Passcode profile - Select a passcode profile to use. The profile includes the passcode complexity, length, expiration, and number of failed attempts allowed.
-
Allow storing user credentials on the device for single-sign on - If username and password authentication is used, store the authentication credentials on the device. Then users are only prompted for their passcode not also for their username and password.
-
-
Report jail-broken devices - Create a log if a jail-broken device connects to the Security Gateway.
-
Block access from jail-broken devices - Block devices that are jail-broken from connecting to the Security Gateway.
-
-
Block third party keyboard - Block keyboards that are not the native keyboard for the operating system of the endpoint device.
-
Hide 'connect anyway' on SSL trust screen - If the endpoint device does not trust the certificate of the Security Gateway, users do not have the option to connect.
-
-
In the Applications tab, select which application features are available on devices:
-
Mail
-
Allow printing mail - allows users of the endpoint device to print email.
-
Max attachment size (MB) - select the maximum attachment size to allow.
-
-
Offline Content - configure what data is saved and for how long when the Check Point App cannot reach the Security Gateway.
-
Mail from the last x days - Select the length of time from which emails are saved.
-
Calendar from the last x months and the following x months - Select which parts of the calendar are saved: the length of time in the past and length of time in the future.
-
Synchronize contacts - Synchronize contacts from the organization's mail server to the endpoint device.
-
-
Push Notifications - allow push notifications on devices. See the Push Notifications section below for details. To use this, push notifications must be enabled for Capsule Workspace on the Security Gateway that users connect to.
-
Calendar - select Allow business calendar to sync to the device's native calendar if you want to sync both calendars on the device. Events from Capsule Workspace will show in the device's calendar, outside of Capsule Workspace.
-
Contacts - select which additional contacts to show in Capsule Workspace on the device:
-
Global Address List - contacts from the end user's corporate Microsoft Outlook application.
-
Mobile Device's contact list - contacts from the mobile device's contact list.
-
-
Web Applications - Save local web cache configure what data is saved and for how long when the Check Point App cannot reach the Security Gateway. By default, the endpoint device is allowed to save data in its local cache.
-
Check Point Capsule Documents - select the Capsule Docs information that is stored in Capsule Workspace.
-
Allow caching Check Point Capsule Docs credentials - The credentials are required to open Capsule Docs protected documents are cached on the device. If they are not cached, users must enter their credentials each time they open a document for the first time.
-
Allow caching Check Point Capsule Docs keys - The Capsule Docs keys are cached on the device. If they are cached users can open a previously opened document with no need to enter credentials.
-
-
-
In the Data Loss Prevention tab, configure settings for Outbound and Inbound traffic.
-
Outbound
-
Share protected files extensions to external apps - Select which types of protected files can "exit the boundaries" of Capsule Workspace. In Android, this setting restricts the "share" action. In iOS, this setting restricts all actions that take a file from Capsule Workspace.
-
Share unprotected files extensions to external apps - Select which types of unprotected files can "exit the boundaries" of Capsule Workspace. In Android, this setting restricts the "share" action. In iOS, this setting restricts all actions that take a file from Capsule Workspace.
-
Open the following extensions with external apps when they cannot be opened with Capsule viewer - This rule
Set of traffic parameters and other conditions in a Rule Base (Security Policy) that cause specified actions to be taken for a communication session. applies only in Android. This rule describes which types of files can "exit the boundaries" of Capsule Workspace when Capsule Workspace cannot display the file. Capsule Workspace prompts the user to pick an app in which to open the file. -
Block Screenshot - select to block end users from taking screenshots inside of Capsule Workspace.
-
Allow copy paste to external apps - select to allow Capsule Workspace users to copy content and paste it into external apps.
-
Block forward attachments by mail - select to prevent Capsule Workspace users from forwarding email attachments outside of the organization.
-
Allow domain for forward attachments by mail - Enter a fully qualified domain name that Capsule Workspace users are allowed to forward emails. You can enter more than one FQDN separated by commas. For the entered domains this setting overrides the previous setting.
-
-
Inbound
-
Accept protected files with these extensions from external apps - Select which types of protected files can "enter the boundaries" of Capsule Workspace.
-
Accept unprotected files with these extensions from external apps - Select which types of unprotected files can "enter the boundaries" of Capsule Workspace. This holds only for files not protected by Capsule Docs.
-
Offer Capsule as a viewer for external protected documents - Select to configure the device to offer Capsule Workspace as a document viewer for protected documents from outside of the organization. This is similar to the behavior of Capsule Docs.
-
Allow taking photos and videos - Select to allow the device's camera to take pictures and videos and bring them into Capsule Workspace.
-
Allow Importing media From Gallery - Select to allow the user to import media from the device into Capsule Workspace.
-
-
-
In the Harmony Mobile section, configure settings for Harmony Mobile integration with the Mobile Security application or with Harmony App Protect.
-
Enabled application integration - Capsule Workspace enforces installation of Mobile Security. If Mobile Security does not meet the requirements of the policy, Capsule Workspace does the enforcement action.
-
Enforcement policy - Select under which conditions Capsule Workspace does the enforcement action:
-
Not enforced - Capsule Workspace does not enforce a security policy
Collection of rules that control network traffic and enforce organization guidelines for data protection and access to resources with packet inspection.. -
Ensure application installed - If Mobile Security is not installed on the device, Capsule Workspace does the enforcement action.
-
Ensure application activated - If Mobile Security is not activated on the device, Capsule Workspace does the enforcement action.
-
Ensure application compliant - If Mobile Security finds that the device is not compliant with the security policy, Capsule Workspace does the enforcement action.
-
-
Enforcement action - Select what Capsule Workspace does when the device does not meet the Harmony enforcement policy:
-
Warn - Capsule Workspace warns the user that the device does not meet the policy.
-
Block - Capsule Workspace does not open.
-
-
Enforcement Message - Enter a free text message for Capsule Workspace to show the user when it does the enforcement action. If you do not enter an enforcement action, then Capsule Workspace users see pop-up messages with the options Continue Anyway (only if the enforcement action is Warn) and Sign Out.
-
-
Enable Harmony App Protect - enable the administrator to use the software development kit (SDK) to configure the behavior of Capsule Workspace. This feature requires an additional license. Enter the license in the Harmony App Protect license field. For each kind of security vulnerability that Harmony App Protect can detect, select how Harmony App Protect enforces policy for Capsule Workspace.
List of security vulnerabilities:
-
Device Compromised
-
Malware
-
Man in the Middle Attack
-
OS Integrity Compromised
-
Suspicious App
-
Suspicious Enterprise Certificate
List of enforcement actions:
-
Block - Capsule Workspace shows users a block page and is not usable.
-
Notify - Capsule Workspace shows users a popup window that says there is a security vulnerability.
-
Ignore - Capsule Workspace does nothing.
-
-
-
In the Client Customization tab, configure what end users see in the client
-
Appearance
-
Application light mode color: Enter a hex color.
-
Application dark mode color: Enter a hex color.
-
-
Allowed items - select which Exchange features are available on endpoint devices.
-
Mail
-
Messages
-
Calendar
-
Contact
-
Tasks
-
Notes (iOS only)
-
Saved Files
-
-
Certificates - enter a message to show to the end user when the client certificate expires.
-
-
In the Advanced tab, configure custom fields for new Capsule Workspace features that do not exist in your version of SmartConsole
Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on..-
In the Custom Fields section, click the plus (+) icon.
The New Future Compatibility Field window opens.
-
Enter the Key for the feature.
-
Enter the Value for the feature.
-
Click OK.
-