Mobility Manager 9.5. Users Guide

Similar documents
VMware AirWatch Integration with Apple School Manager Integrate with Apple's School Manager to automatically enroll devices and manage classes

VMware AirWatch Integration with Apple School Manager Integrate with Apple's School Manager to automatically enroll devices and manage classes

Wavelink's TE Client for Android User Guide. Version 1.3

VMware Workspace ONE UEM Integration with Apple School Manager

Integration with Apple Configurator 2. VMware Workspace ONE UEM 1902

ios Supervised Devices

VMware AirWatch Google Sync Integration Guide Securing Your Infrastructure

NotifyMDM Device Application User Guide Installation and Configuration for ios with TouchDown

QuickStart Guide for Mobile Device Management. Version 8.7

NotifyMDM Device Application User Guide Installation and Configuration for Android

VMware AirWatch Self-Service Portal End User Guide

VMware AirWatch Integration with Apple Configurator 2 Guide Using Apple Configurator 2 and AirWatch to simplify mass deployments

VMware AirWatch Android Platform Guide

Application / Document Management. MaaS360 e-learning Portal Course 3

VMware AirWatch: Directory and Certificate Authority

Table of Contents. VMware AirWatch: Technology Partner Integration

AirWatch Container. VMware Workspace ONE UEM

Table of Contents HOL-1757-MBL-6

Building a BYOD Program Using Jamf Pro. Technical Paper Jamf Pro or Later 2 February 2018

VMware AirWatch Symbian Platform Guide Deploying and managing Symbian devices

ZENworks 2017 Update 4 Troubleshooting Mobile Device Management

ipad in Business Mobile Device Management

Administrator IT Guide. Samsung Knox Configure Shared Device

Sophos Mobile Control SaaS startup guide. Product version: 6.1

Sophos Central Self Service Portal help

VMware AirWatch Google Sync Integration Guide Securing Your Infrastructure

Compliance Manager ZENworks Mobile Management 2.7.x August 2013

AT&T Business Messaging Account Management

Sophos Mobile Control Administrator guide. Product version: 5.1

VMware AirWatch tvos Platform Guide Deploying and managing tvos devices

Dell EMC OpenManage Mobile. Version User s Guide (Android)

Sophos Mobile Control startup guide. Product version: 7

Endpoint Manager for Mobile Devices Setup Guide

ForeScout Extended Module for MaaS360

Symantec Mobile Management for Configuration Manager 7.2 MR1 Release Notes

Amazon WorkMail. User Guide Version 1.0

The purpose of this document is to help you to get started with your ipad to access Lilly resources such as , calendar, Lilly apps and more.

Google Sync Integration Guide. VMware Workspace ONE UEM 1902

Lookout Mobile Endpoint Security. Deploying Lookout with BlackBerry Unified Endpoint Management

Duo Security Enrollment Guide

Table of Contents HOL-1757-MBL-5

Sophos Mobile user help. Product version: 7.1

AirWatch for Android Devices for AirWatch InBox

Print Management On-Premises

ZENworks Configuration Management 2017

Managing Windows 8.1 Devices with XenMobile

Dell OpenManage Mobile Version 1.0 User s Guide

Sophos Mobile SaaS startup guide. Product version: 7.1

VMware AirWatch - Workspace ONE, Single Sign-on and VMware Identity Manager

Table of Contents HOL-1757-MBL-4

McAfee Enterprise Mobility Management 12.0 Software

Support Device Access

Codebook. Codebook for OS X Introduction and Usage

Pulse Workspace Appliance. Administration Guide

Install and upgrade Qlik Sense. Qlik Sense 3.0 Copyright QlikTech International AB. All rights reserved.

VIRTUSA BYOD PROGRAM

Sophos Mobile. user help. product version: 8.6

Sophos Mobile. startup guide. Product Version: 8.1

Product Guide. McAfee Enterprise Mobility Management (McAfee EMM ) 9.6

Sophos Mobile as a Service

VMware Workspace ONE UEM Apple tvos Device Management. VMware Workspace ONE UEM 1811 VMware AirWatch

Dell EMC OpenManage Mobile. Version 3.0 User s Guide (Android)

TPS ISS ipad Setup Process. Setup your mobile Device

Abila Nonprofit Online. Connection Guide

Compliance Manager ZENworks Mobile Management 3.0.x January 2015

Using the Secure MyApps Environment

DSS User Guide. End User Guide. - i -

Forescout. eyeextend for IBM MaaS360. Configuration Guide. Version 1.9

Dell EMC OpenManage Mobile. Version User s Guide (ios)

Guide to Deploying VMware Workspace ONE. DEC 2017 VMware AirWatch 9.2 VMware Identity Manager 3.1

Dell EM+S Intune. Android Enrollment Guide. Version 1.5

Salesforce Classic Guide for iphone

Using the Secure MyApps Environment

Windows 8/RT Features Matrix

IPHONE DEP REGISTRATION... 4 IPHONE DEP REGISTRATION... 3

RapidIdentity Mobile Guide

Note: Support: Never use your TruMobi application for personal use.

ALTIRIS SECURITY SOLUTION 6.1 FOR HANDHELDS ADMINISTRATOR GUIDE

AirWatch for ios Devices

User Self-Administrative Web Guide

Deploying Lookout with IBM MaaS360

Table of Contents... ii. Go Ahead Bring Your Own Device to Work... 1 Requirements... 1

Colligo Briefcase 3.0

Symantec Mobile Management 7.2 MR1 Implementation Guide

Dell OpenManage Mobile Version 1.0 User s Guide

Symantec Mobile Management 7.2 MR1 Release Notes

McAfee MVISION Mobile AirWatch Integration Guide

StorageCraft Cloud Backup

Colligo Briefcase. for Good Technology. Administrator Guide

VMware PIV-D Manager Deployment Guide

Enterprise Vault.cloud CloudLink Google Account Synchronization Guide. CloudLink to 4.0.3

Vodafone Secure Device Manager Administration User Guide

Deploying VMware Workspace ONE Intelligent Hub. October 2018 VMware Workspace ONE

3CX Mobile Device Manager

Texas Division How to Login and Register for My IT Support and ServiceNow

Guide to Deploying VMware Workspace ONE. VMware Identity Manager VMware AirWatch 9.1

Support Device Access

GETTING STARTED GUIDE. Mobile Admin. Version 8.2

VMware Boxer Comparison Matrix for IBM Notes Traveler Compare the features supported by VMware Boxer and AirWatch Inbox

Amazon WorkMail. User Guide Version 1.0

Transcription:

Mobility Manager 9.5 Users Guide

LANDESK MOBILITY MANAGER Copyright 2002-2013, LANDesk Software, Inc. and its affiliates. All rights reserved. LANDesk and its logos are registered trademarks or trademarks of LANDesk Software, Inc. and its affiliates in the United States and/or other countries. Other brands and names may be claimed as the property of others. LANDesk does not warrant that this document is error free and retains the right to make changes to this document or related product specifications and descriptions at any time without notice. LANDesk does not assume any obligation to update the information contained herein. This document is provided AS IS and without any guaranty, warranty, or license, express or implied, including but not limited to: fitness for a particular purpose, merchantability, non infringement of intellectual property, or other rights of any third party. Any LANDesk products referenced in this document are not intended for use in medical, life saving, or life sustaining applications. Third parties may have intellectual property rights relevant to this document and the technologies discussed herein. Last updated: 20/09/2013 2

USERS GUIDE Contents Contents 3 Welcome to LANDesk Mobility Manager 4 Getting started with Mobility Manager 5 Working with managed mobile devices 6 Enrolling mobile devices 6 Un-enrolling mobile devices 7 Viewing mobile devices 7 Scan a mobile device 9 Remove a mobile device's passcode 9 Update a mobile device 9 Lock a mobile device 9 Wipe a mobile device 10 LANDesk Portal 13 Adding apps, docs, and links to the Portal app 13 Installing and using the LANDesk LD Portal app on mobile devices 14 Configuring LANDesk Mobility Manager 15 Configuring the mobility mail server connections 15 Discovering mobile devices 16 Connection rules 17 3

LANDESK MOBILITY MANAGER Welcome to LANDesk Mobility Manager LANDesk Mobility Manager helps you take control of the mobile devices used in your company. It simplifies device provisioning, helps enforce corporate policies, and allows an administrator to lock or wipe lost or stolen devices. LANDesk Mobility Manager adds these tools to the Management Suite console: Mobile inventory: An addition to your inventory that lists mobile devices that are under management or, if you set up device discovery, devices that have connected to your Exchange/BlackBerry server. Mobility tool: The Mobility tool (also known as Avalanche) allows you to create mobile device payload configurations that you can add to mobile profiles. These profiles then get deployed to the mobile devices you select. LANDesk Portal: Use this app to manage content (such as documents or links) and make it available to the device user. The Mobility tool manages content that appears in the Portal app. In addition to these tools, there are certain tasks added to the LDMS console that can be performed using your Microsoft Exchange Server (EAS 2007 or 2010) or BlackBerry Enterprise Server (BES): Discover devices. Configure your server to report a list of devices that have connected. Use the list of discovered devices to determine devices that need to be under management. Wipe devices. Use a command sent through the EAS/BES to wipe a device that connects to your server. This wipe is a factory reset. Create connection rules (Exchange 2010 only). Connection rules determine which device types can access mailboxes. For information on installation and the initial configuration of LANDesk Mobility Manager, see the LANDesk Mobility Manager Installation Guide. 4

USERS GUIDE Getting started with Mobility Manager When you enroll devices in Mobility Manager, you can perform actions to manage them, and also send profiles to the devices. Mobile device profiles allow you to provision devices with software, links, certificates, or Exchange, VPN, and Wi-Fi credentials. You can also require a passcode on the device or restrict what can be used on the device. To manage devices using Mobility Manager, perform the following tasks: 1. Create enrollment rules. Enrollment rules allow devices to connect to the server and display devices in the right folders. An enrollment rule contains an ID, password, and the Smart device folder that devices using the rule are placed in. For information about creating enrollment rules, see Creating Enrollment Rules for Smart Devices in the Avalanche help. 2. Enroll devices. For information on enrolling devices, see "Enrolling mobile devices" on page 6. After devices are enrolled, you can apply profiles to them and perform actions such as wipe or locate. 3. Manage devices by users. If you want to manage devices based on the user, the User Tree organizes devices based on people and organization units according to your LDAP server. For information on managing the User Tree, see Editing the User Tree in the Avalanche help. 4. Apply profiles to the device. To send configurations, applications, and other items to the device, configure a payload. Associate one or several payloads with a profile, and then apply the profile to the desired devices. 5

LANDESK MOBILITY MANAGER Working with managed mobile devices When you send a command to a mobile device, such as scan now, it can take several seconds or more for the device to receive it. How quickly a device will respond to a remote command depends on your core and network configuration, the level of network congestion, and the phone's data capabilities, among other things. Enrolling mobile devices Enrolling a device allows you to manage settings, apps, and other content on the device. IMPORTANT: You must use the Mobility tool to create an enrollment rule before devices can enroll. For information on creating an enrollment rule, see Creating Enrollment Rules for Smart Devices in the Avalanche help. The method for enrolling a device depends on the operating system running on the device: If the device is using Android, you must install the LANDesk Agent on the device and configure it with the enrollment information. If the device is using ios, you must use the browser on the device to navigate to the enrollment page and enroll the device using the enrollment information. NOTE: For devices that are unenrolled but they connect to the Exchange Server or BlackBerry Server, you can only perform device discovery and wipe. An administrator must create at least one enrollment rule before users can connect mobile devices to Mobility Manager. The device must be configured with the enrollment ID and password in order to connect to the server. For information about creating enrollment rules, see Creating Enrollment Rules for Smart Devices in the Avalanche help. Before devices are enrolled, administrators can create mobile device payloads and profiles and deploy them to Active Directory users. When a device enrolls, it automatically downloads the profiles assigned to the device user. Once a user enrolls their mobile device, that device appears in the Network View under Devices > Mobile and you can view the device's inventory information. To enroll an Android device 1. Download the LANDesk agent from the Google Play store by navigating to the URL below: https://play.google.com/store/apps/details?id=com.wavelink.android 2. From the device Notifications, tap the application to install it. 3. The Terms and Conditions appear. Tap Accept to agree to the terms. 6

USERS GUIDE 4. The app asks if you want to allow the application to be a device administrator. Tap Activate. 5. The Settings page appears. Type the Enrollment ID and Password in the text boxes and tap Register. The device is placed in the Smart device folder associated with the enrollment rule and receives the Smart mobile device profile applied to the folder. To initiate an update from an Android device that has already enrolled, launch the LANDesk Agent, navigate to the Maps tab and tap Sync. To enroll an ios device 1. From the device, use a browser to navigate to the Enrollment page: https://sds.aod.wavelink.com/mdm/wam/enroll.faces 2. Provide the enrollment ID and password. If desired, provide the Microsoft Exchange username and email address. 3. Click Enroll. 4. The device is placed in the Smart device folder associated with the enrollment rule and receives the Smart mobile device profile applied to the folder. This process can also be used to initiate an update from an ios device as long as the device is not moved to a different folder after it is enrolled. To use the LANDesk Portal app 1. Download and install the LANDesk Portal app from the App Store or Play Store. 2. Open the Portal app. 3. Enter your company network login credentials and tap Sign In. 4. Once logged in, use the app to access the content made available for your account by an administrator. Un-enrolling mobile devices If a user wants to remove his mobile device from management, he can uninstall the Agent (Android only) and Portal apps just as he would any app. Users who have ios devices that are being managed need to go into Settings > General > Profiles and remove the Wavelink MDM profile. If the profile is password protected, the user is prompted for the password in order to remove the profile. When a user uninstalls the apps, it does not remove the device from the Network view or the Mobility tool. Viewing mobile devices To view the list of devices in the Network view, click Devices > Mobile. 7

LANDESK MOBILITY MANAGER To make it easier to find devices in the devices list, use the Find box, located directly above the device list. You can use this tool to locate and display devices by typing one or more keywords and specifying the columns to search in. Mobile device discovery The Mobile device discovery tree lists devices that are associated with EAS wipe or discovery commands. You can also use it to refer to the discovery and/or wipe history of one or more devices. EAS Wipe pending: Displays a list of any devices that have been set to be wiped via Exchange ActiveSync, but which have not yet sync'd with the Microsoft Exchange server. Devices in this list can have their wipe command canceled as described in "Wipe a mobile device" on page 10. EAS Wiped: Displays a list of all devices that have been wiped via Exchange ActiveSync. Commands history > Device discovery: Keeps a record of all discovery commands that have been scheduled, when they were issued, the server type, how many devices were discovered, the user that executed the discovery, and whether or not the command was executed successfully. The data remains in the system until it is deleted. Commands history > Wiped device history: Keeps track of all devices that have been wiped using EAS/BES, when the command was issued, the device owner, ID, and operating system, the user that executed the wipe, and the status of each wipe command. The data remains in the system until it is deleted. 8

USERS GUIDE Scan a mobile device Managed devices are configured to connect to the server every 24 hours. If you want to scan a device immediately to update the displayed information, use the Scan Now command from the LANDesk console.the command requests the device to connect and pull any updates available, and it updates the device information shown in the LANDesk console. To run an on-demand inventory scan 1. Find the device in the Network view. 2. Right-click it and click Scan now. The device is requested to connect. The command is only sent once, so if the device is unreachable at the time the command is sent, the device waits until its scheduled update time. Remove a mobile device's passcode If a user forgets the passcode for his managed mobile device, you can remotely remove it. If a restriction payload applied to the device requires a passcode, users will be prompted to create a new passcode. To remove a device's passcode 1. Find the device in the Network view. 2. Right-click it and click Unlock/Reset passcode. The device's passcode is removed and the user can unlock the device. The command is only sent once, so if the device is unreachable at the time the command is sent, the device passcode is not removed. Update a mobile device You can force a managed mobile device to check in and update its mobile payloads. This is useful if you make a profile or payload configuration change and you want it applied immediately to a particular mobile device. Managed mobile devices automatically check for updates once a day, so you don't have to do manual updates unless you want a change applied immediately. To update a mobile device's policies 1. Find the device in the Network view. 2. Right-click it and click Update policies. The device is requested to connect. The command is only sent once, so if the device is unreachable at the time the command is sent, the device waits until its scheduled update time. Lock a mobile device You can remotely lock managed mobile devices if they are stolen or lost. The mobile user will need to enter their passcode to unlock the device. If the device doesn't have a passcode, users can unlock the device without entering a passcode. If the device is turned off or out of range when the command is sent, it does not receive the command. 9

LANDESK MOBILITY MANAGER To lock a mobile device 1. Find the device in the Network view. 2. Right-click it and click Lock. Wipe a mobile device When a device is lost, stolen, or assigned to a new user, you may want to wipe the device to remove any personal or sensitive information. There are two methods for wiping a device, depending on whether the device is enrolled or only discovered. Enrolled devices are wiped through the Mobility tool. Discovered devices are wiped through the EAS/BES. Wiping a managed device using the Mobility tool There are three wipe options for managed devices: Selective wipe/unmanage.removes all the data associated with the Mobility payloads on the device. For example, a selective wipe would remove app restrictions or WiFi passwords. Selective wipe/delete. Remove the data associated with the Mobility payloads and also deletes the device from the inventory. Wipe. Removes all personal files and applications from the device and restores the device to its factory settings. This option removes the LANDesk Agent from the device, but it does not remove the device from the inventory. When you send a wipe command, it is sent through either GCM or APNS (depending on whether it is an Android or an ios device). The command is only sent once, so if the device is unreachable at the time the command is sent, the device does not get wiped. To execute the wipe command 1. Find the device in the Network view. 2. Right-click it and click Wipe... Then select the type of wipe you want to perform. You are prompted to proceed with the command. Wiping a discovered device using the EAS/BES The wipe command is executed differently depending on the type of server performing the wipe. Blackberry Enterprise server (BES) On BES, a wipe is associated with the device, not with the user. Once the wipe command is issued, the wipe is executed immediately on any targeted phones that are currently turned on, and they will no longer be able to connect and synchronize with their mailbox. If the phone happens to be turned off when the wipe was initiated, the wipe will occur the next time it syncs with the server. This means that if the device is transferred to a different user and the device has been turned off, it will be wiped the first time the new user initiates a sync with the BlackBerry server. 10

USERS GUIDE Microsoft Exchange server (EAS) On a Microsoft Exchange server, the wipe is associated with both the user and the device. Once the wipe command is sent to the server, the device's status in the Mobility management tool is set to "Wipe pending". The next time the device attempts to log in, the wipe command will execute and the device will be wiped immediately. Because the wipe does not actually occur until the next time the device logs in, the wipe command can be canceled at any time (see below). To execute the wipe command 1. Find the device in the Network view. 2. Right-click it and click Wipe. You are prompted to proceed with the command. IMPORTANT: Before wiping devices, it is important to understand how the wipe command is executed on a BlackBerry-Enterprise server (BES) versus how it is executed on a Microsoft Exchange server. Because of these differences, when you send a wipe command, you are asked to confirm your intent before proceeding. 11

LANDESK MOBILITY MANAGER Canceling a wipe To cancel a Wipe command (only available on devices being wiped through EAS), open the Wipe pending folder, right-click the device and select Cancel wipe on the shortcut menu. 12

USERS GUIDE LANDesk Portal See the following topics for more information on configuring mobile LANDesk Portal content. Adding apps, docs, and links to the Portal app If you want to password-protect access to certain managed content, you can specify in a payload that the content should be delivered to the Portal app. When an app, doc, or link payload is associated with the Portal app, the device user must log in to the Portal app using his network credentials in order to access the content. Depending on the type of content, use a Document/Media payload, Link payload, or Software payload. For more information on creating payloads and profiles, see Managing Smart Mobile Device Profiles in the Avalanche help. Document / Media payloads in the Portal app When you distribute media using a Document / Media payload, make sure the device has an app that can open the filetype. The default supported file types for ios are: iwork documents Microsoft Office documents (Office 97 and newer) Rich Text Format (RTF) documents PDF files Images Text files whose uniform type identifier (UTI) conforms to the public.text type Comma-separated value (csv) files H.264 Baseline Profile Level 3.0 video, up to 640 x 480 at 30 fps. (The Baseline profile does not support B frames.) MPEG-4 Part 2 video (Simple Profile.mov,.mp4, mpv,.3gp) Link payloads in the Portal app Links sent to the device are opened with the device's default browser. When linking to a Web-based application, make sure that the application is supported by the browser. Software payloads in the Portal app You can make two types of apps available to mobile devices: Apps available from an app store such as Google Play or itunes. Enterprise apps developed internally, such as a company-specific sales or inventory app. Updating mobile device content Updates to LANDesk Portal content happen when the device connects to the server. Portal users can check the last time content was updated by dragging the Categories list down. Pulling the list down and releasing it triggers a refresh. 13

LANDESK MOBILITY MANAGER Installing and using the LANDesk LD Portal app on mobile devices The LANDesk Portal app is available from the Apple App Store and Google Play store. For users to access information through the Portal, they must enroll their devices and then download and install the Portal app. Once the app is installed, they can log in using their Active Directory credentials. Once you've installed and logged in to the app, you can do the following: Select a content category to view Download an app View a document or media View a link Check for portal content updates Update applications you've installed through the portal To use the LANDesk Portal app 1. Open the LD Portal app. 2. Enter your credentials and click Sign In. Your username should include the domain: domain\username 3. Once logged in, you can navigate the app and access content made available for your account through the LANDesk Mobility tool. 14

USERS GUIDE Configuring LANDesk Mobility Manager See the following topics for information on configuring LANDesk Mobility Manager from the LDMS console. For information on managing the user tree in the Mobility tool, see Editing the User Tree in the Avalanche help. For information about configuring payloads for devices, see Managing Smart Mobile Device Profiles in the Avalanche help. Configuring the mobility mail server connections To use your Exchange or BlackBerry servers for mobile device discovery, you first need to configure Mobility Manager so it can authenticate to the Exchange or BlackBerry server in your environment. This allows you to t to discover mobile devices and manage their access to the servers. To provide the server authentication information 1. Click Tools > Mobility > Mobile inventory. 2. Click Configure on the toolbar. 3. In the left panel, select the type of server (BlackBerry, Exchange 2007, or Exchange 2010). For BlackBerry servers 1. Click New. 2. In the BES Credentials dialog box, specify the server address, login method, and credentials. 3. Click Test connection to verify the credentials work. 4. Click Save. For Exchange 2007 servers 1. Make sure the Microsoft Exchange Server 2007 Management Tools are installed on your core server. 2. Specify the login credentials. 3. Click Test connection to verify the credentials work. 4. Click OK. For Exchange 2010 servers 1. Specify the server domain\server name and login credentials. 2. Click Test connection to verify the credentials work. 3. Click OK. NOTE: You can configure more than one BlackBerry server; Microsoft Exchange is currently limited to one server per version (2007 and 2010). With the authentication information configured, you can now discover mobile devices and display their information in the mobile device inventory. 15

LANDESK MOBILITY MANAGER Discovering mobile devices To discover devices connecting to your servers that are not currently being managed, Mobility Manager uses mobile device connection information from the Exchange and BlackBerry mail servers. Agentless discovery doesn't require any communication with the actual mobile device, but only mobile devices that have connected to a corporate mail box can be discovered. To discover mobile devices 1. Click Tools > Mobility > Mobile disdcovery. 2. Click Configure on the toolbar. 3. In the left pane, click Discovery options. 4. Change the "Recently discovered" limit if you want to. 5. Click Schedule discovery. 6. In the Schedule task dialog box, click Schedule task. 7. Click Start now. Or, click Start later and specify the date and time when you want the discovery to take place. You can also specify a repeat interval and number of retries (optional). 8. Click Save to initiate the discovery scan. Once the device discovery has completed, the devices appear in the device inventory. 16

USERS GUIDE NOTE: Device discovery history is available from the Commands history folder in the Mobile Discovery tree. Connection rules See the following topics for more information on configuring mobility connection rules for mobile devices. Mobile device connection rules If your company uses Microsoft Exchange 2010, you can use Mobility Manager connection rules that allow you to configure what devices can connect to a Microsoft Exchange 2010 mailbox. Microsoft Exchange 2007 and BlackBerry Enterprise Server environments don't support mobility connection rules. Connection rules are used to allow or deny connections for specific device types. Since the Apple mobile device model list is fairly small, it's easy to identify the devices you're interested in managing: ios ipad iphone Android is more complicated because there are so many manufacturers providing Android devices. With Android devices, you'll need to pay more attention to the much larger variety of device types that exist in the Android ecosystem. Fortunately, it's fairly easy to find out a device's type. When a user tries accessing their Exchange mailbox from a mobile device that is blocked by a connection rule, that user receives an email with information about why the mobile device was denied access. Included in that email is the mobile device's device type. Administrators can use the information from this email to add the blocked device type to an exception list if they want to allow that device model access. Apply mobile device connection rules Once you've configured a Mobility Manager connection to a Microsoft Exchange 2010 server, you can then configure ActiveSync connection rules. There are three connection rules you can apply: Do not allow mobile devices to connect: Mobile devices can't access an Exchange mailbox. Allow all mobile devices to connect (default): Any user can access an Exchange mailbox from a mobile device. You can refine this rule by creating exceptions for certain mobile device types (ios devices, for example). Allow only managed devices to connect: Mobile devices that are enrolled in Mobility Manager can access an Exchange mailbox. You can refine this rule by creating exceptions for certain mobile device types (ios devices, for example). The default device list already includes some common device types. If you don't see the device type you want to manage in the list, you can add new device types. Connection rules take effect when you click OK or Apply in the configuration dialog. There is no additional deployment required. 17

LANDESK MOBILITY MANAGER To apply connection rules 1. Click Tools > Mobility > Mobile discovery. 2. In the toolbar, click Configure. 3. In the navigation tree, click Exchange 2010 Server. 4. Select the connection rule you want. 5. Enter Notification custom text that you want. This text appears in the quarantine email that users get when they try to connect. Sample text might be instructions on how to submit a request to enable email access. HTML is allowed, so you could include a hyperlink to a web page with more information. If you're pasting text or HTML into the text box, make sure it's all on a single line. If you paste a block of text or HTML code with line breaks, only the first line will be pasted. 6. If necessary, add or select the devices you want the connection rule applied to. 7. Click OK. Grandfathering mobile devices You can grandfather all mobile devices that connected to your Exchange 2010 server in the past. Grandfathering allows these devices access regardless of any future connection rules you consider. This can be useful when you're deploying Mobility Manager and you want to be sure existing mobile devices aren't affected. 18

USERS GUIDE Use this option carefully. It modifies the Exchange 2010 Server whitelist and is not reversible using the LDMS console. In other words, once you've enabled grandfathering, the only way to remove a whitelisted device is to use the Exchange 2010 console to manage the Exchange 2010 whitelist manually. 19