Views:

Configure mobile policies for Android devices in your organization based on your security requirements.

Important
Important
  • A group, assignment group, or organizational unit can only be on the target list of one policy at a time.
  • In Google Workspace, one user can only be assigned to one organizational unit.
  • If a user is the member of multiple groups and the groups are targets of different policies, only the highest priority policy affects the user.

Procedure

  1. On the Trend Vision One console, go to Mobile SecurityMobile Policy.
  2. Click the Android tab.
  3. Click Create or click the name of an existing policy.
  4. On the General Settings screen, specify a policy name and select the protection strength that best suits your needs, or click Custom to customize your own policy.
    Important
    Important
    The protection strength selected in the General Settings screen provides predefined settings accordingly in subsequent steps. You can modify the predefined settings during later configuration.
    If you modify the predefined settings, the protection strength changes to Custom.
  5. Configure Malware Detection settings.
    1. Click Malware Detection.
    2. Choose the scan scope.
    3. Configure malware scan criteria.
      • Malware
      • Unofficially modified app content/data
      • Transmission of personal data without consent
      • System/App vulnerabilities
  6. Configure Wi-Fi Protection settings.
    1. Click Wi-Fi Protection.
    2. Configure Wi-Fi scan criteria.
      • Automatic decryption of HTTPS traffic
        The Wi-Fi network traffic is decrypted, which may result in data leakage.
      • Unsafe access point
        The device is connected to an insecure Wi-Fi network.
  7. Configure Configuration Manager settings.
    Note
    Note
    This feature is not available when you integrate with an MDM through managed configuration.
    1. Click Configuration Manager.
    2. Configure configuration scan criteria.
      Criteria
      Description
      Rooted device
      The device is rooted.
      Developer mode enabled
      The developer mode is enabled.
      USB debugging enabled
      USB debugging is enabled.
      Lock screen disabled
      • (For Android) The device is not locked with a PIN, pattern, or password.
      • (For iOS/iPadOS) The device is not locked with a passcode, Touch ID, or Face ID.
      Outdated OS
      The device operating system is out of date.
      Outdated security patch
      The device security patch is out of date.
  8. Configure Web Reputation settings.
    Trend Micro Web Reputation technology assigns websites a "reputation" based on an assessment of the trustworthiness of a URL, derived from an analysis of the domain.
    1. Click Web Reputation.
    2. Select a security level.
    3. To automatically approve or block certain websites, specify the websites in the following formats based on device platforms and add them to the allow list or to the block list.
      Item
      Format
      Website format
      • URL
      • FQDN
      Wildcard character support
      *
      Tip
      Tip
      • * : Matches any number of characters
      • ? : Matches a single character in a specific position
  9. Configure permission settings by specifying the permissions that you do not want to prompt users to grant upon installation of the Mobile Security for Business app.
    • Do not require phone number access permission
    • Do not require phone battery access permission
    Users will later be prompted to grant these permissions on their devices when they need to use the related functions.
  10. Configure policy targets.
    1. Click Targets.
    2. Specify one or more groups, assignment groups, or organizational units.
      Note
      Note
      Specifying a group, assignment group, or organizational unit that is on the target list of another policy removes it from the previous policy. The previous policy no longer affects the group, assignment group, or organizational unit.
  11. Configure advanced settings to schedule Mobile Security scanning by selecting Scheduled scan and specifying the scan frequency.
    Note
    Note
    This feature is not available when you integrate with an MDM through managed configuration.
  12. Click Save.
  13. (Optional) Click Continue if you are prompted to confirm the policy changes.
    Note
    Note
    This step is required only if you have added or deleted policy targets when editing a policy.