Deploy Client on Android Using IBM MaaS360
Deploy Client on Android Using IBM MaaS360
This topic covers the steps to deploy Netskope Client for Android mobile devices using IBM MaaS360.
Prerequisites
-
On the Netskope UI, go to Settings > Security Cloud Platform > Netskope Client > MDM Distribution. Download the Netskope Root Certificate and Intermediate certificates. These are needed to configure IBM MaaS360 certificate profiles.
-
On the MDM Distribution page, scroll down to Create VPN Configuration section to find your Organization ID.
-
User accounts provisioned within the MDM/EMM platform must match with those provisioned with the Netskope tenant.
Add Netskope Client App
The following section describes the steps to add the application from Google Play app in the IBM MaaS360 console.
To add Netskope Client:
-
In the IBM MaaS360 console, go to Apps > Catalog.
-
In the App Catalog page, click Add > Android > Google Play App.
-
The Add Google Play App window is displayed. In the text field, search for Netskope Client.
-
Click the Netskope Client app to select.
-
Click Select and Approve the permissions to the app.
-
Click Add to add Netskope Client to the App Catalog.
Distribute and Assignment
This section describes the steps to distribute and assign the Netskope Client app to devices in a group after adding Netskope Client to the App Catalog. To learn more, view Deploy Apps to Devices.
To distribute and assign NS Client:
-
In the App Catalog page, click Netskope Client.
-
On the top-right corner of the Netskope Client app page, click Distribute.
-
In Distribute App: Netskope Client, make an assignment to the appropriate group.
-
Click Distribute.
Setting up Netskope Client
Setting up Netskope Client for Android devices with IBM MaaS360 includes the following mandatory steps:
Automatic Installation and App Configuration
You need to set up automatic app installation and enrollment settings for Netskope Client from the MaaS360 Portal. To learn more, view Configure Automatic App Installation.
To install Netskope Client automatically:
-
In the App Catalog page, click Netskope Client.
-
In the Netskope Client app page, scroll down to Install Settings and select the following options:
-
Install Automatically
-
Retry Installation
-
-
In the App Configurations section, click Add Configuration.
-
In the Configuration tab, provide the following:
-
UserEmail: %email%
-
Host: addon-<tenant-URL>
-
Token: <Organization ID> This value is retrieved from Netskope tenant.
-
-
Click Next.
-
Select the checkbox for Set as default configuration.
-
Click Publish.
Push VPN Profile Configuration
To provide a seamless Netskope Client deployment in IBM MaaS360, you need to create a VPN profile controlled through security policies. You can either create a new security policy or a VPN profile to an existing policy. To learn more, view Create Security Policy.
To add a VPN profile in a security policy:
-
In the IBM MaaS360 console, go to Security > Policy.
-
Click Add Policy.
-
Provide the following details:
-
Type: Android MDM
-
Start From: Business Templates Based Policies
-
Business Usecase – Select an appropriate one and click Continue.
-
-
The Policy Details page is displayed.
-
Select VPN and click Edit to configure the settings.
- Enable Always On VPN: Select the checkbox to enable this option
- Always on VPN Package Name: Enter com.netskope.netskopeclient
- Enable Lockdown: Select this checkbox to enable this option.
-
Click Next.
-
Assign the policy to the appropriate group.
-
Click Save and Publish.
Create a Trusted Netskope Root Certificate Profile
Adding certificates enables you to perform SSL inspection. To learn more about SSL Inspection for Android, view SSL Inspection.
To upload the Intermediate and Root certificates:
-
In the IBM MaaS360 console, go to Security > Policy.
-
Click Add Policy.
-
Provide the following details:
-
Type: Android MDM
-
Start From: Business Templates Based Policies
-
Business Use Case – Select an appropriate one and click Continue.
-
-
The Policy Details page is displayed.
-
Select Certificates and click Edit to upload the certificates.
-
Click + to upload a new certificate.
-
In the Upload New Certificate window, provide the certificate name and upload the Netskope Root Certificate.
-
Click the refresh icon on the right and select the uploaded certificate name from the dropdown.
-
Repeat the steps 6 to 8 for uploading and selecting the Intermediate certificate.
-
Click Next, Next and Publish.
You can add the Certificate and VPN profile details under one security policy and assign them to an appropriate group. If you are creating separate policies for Certificate and VPN profiles, you must add them to appropriate groups separately.