Datasheet Version 2.4
Deploy, Secure and manage your iPhones/iPads remotely
2
PMDP is simple to set up, start using, and
maintain
• Access the web-based console from anywhere, in complete security over Internet. Configure your on-line environment in just a few minutes No infrastructure. No complex network configuration.
• • • • •
CREATE CONFIGURATION POLICIES
to configure ActiveSync, Wifi, VPN … and secure your
smartphones
ASSIGN POLICIES TO USERS AND GROUPS.
DEPLOY YOUR DEVICES VIA INTERNET, E-MAIL OR
SMS.
MONITOR THE DEPLOYMENT STATUS, HELP YOUR
USERS, ERASE THE CONTENT ON YOUR
SMARTPHONES IF NECESSARY
Datasheet Version 2.4
Deploy, Secure and manage your iPhones/iPads remotely
3
• • • • • • • • • •
SAAS PLATFORM READY TO USE
PMDP in SaaS version enables quick deployment and rapid ROI
• SaaS architecture not requiring any modification of your infrastructure • No significant investment in technology or installation services
• Maintenance and upgrades are handled by Ibelem
Datasheet Version 2.4
Deploy, Secure and manage your iPhones/iPads remotely
4
ON PREMISE DELIVERY OPTION
PushManager Deployment Platform offers a fully intergrated MDM platform that can be deployed, managed and maintained on premise.
• Offer solution for company that require customization an integration with IT infrastucture.
• Integration with IT insfratructure (User certificates import, MS SQL database servers).
• Solution independant from Hardware • Designed to run on virtual environments • No transmission and storage of data off site.
Datasheet Version 2.4
Deploy, Secure and manage your iPhones/iPads remotely
5
SIMPLIFIED WIRELESS DEPLOYMENT
Simplified deployment process
PushManager provides a unique activation code for each device, to effortlessly deploy a large number of smartphones.
Mobile users are authenticated by an activation code on the activation portal An activation e-mail and/or SMS is sent, depending on the type of platform,
containing the activation URL.
The type of smartphone is detected automatically the first time the user logs in on the activation portal.
Deployment of iOS 3.x Apple devices
As soon as the mobile user is authenticated on the PMDP platform, the different configuration profiles are pushed onto the iOS 3.x smartphones. The profiles are generated according to the configuration policy assigned to the mobile user.
Deployment of iOS 4.x Apple devices
As soon as the mobile user is authenticated on the PMDP platform, the provisioning mechanism pushes the user's identity certificate onto the device. The device is then registered automatically on MDM and the smartphone's configuration profiles are pushed transparently onto the device.
SMS Reception
Self-provisioning portal
Datasheet Version 2.4
Deploy, Secure and manage your iPhones/iPads remotely
6
REMOTE CONFIGURATION
PushManager Deployment Platform enables you to remotely create and edit your configurations and push them onto your smartphone fleet.
The configuration update of your smartphones fleet is performed without any user interaction on iOS 4 devices.
Configuration policies editing interface
Generation of configuration policies is simplified by a user-friendly editing interface. For example you will be able to:
• Configure an ActiveSync e-mail account with authentication by certificate • Configure WIFI access points (WEP, WPA, WPA2) with authentication settings (PSK, Radius)
• Push web clips onto the device home page • Deploy company certificates
• Configure Safari browser settings
• Enforce use of a locking passcode, indicating its complexity, minimum length, maximum number of attempts, etc.
Datasheet Version 2.4
Deploy, Secure and manage your iPhones/iPads remotely
7
Over-The-Air configuration and device control
• Automatic deployment of configuration settings, transparent for the user. • Remote clear the device passcode.
Datasheet Version 2.4
Deploy, Secure and manage your iPhones/iPads remotely
8
Configuration features
Locking passcode Restrictions ActiveSync account
Enforce lock passcode
• Authorize simple passcodes
• Demand alphanumeric values
• Minimum passcode length
• Minimum number of complex characters
• Number of unsuccessful attempts before device is wiped
• Maximum passcode duration
• Automatic locking after X minutes
• Locking grace period
• Passcode history
Restrict :
• Use of YouTube
• Use of iTune Music Store
• Apps installation
• (with App Store and iTunes)
• Use of the camera
• Screenshots
• Use of FaceTime
• Auto synch when roaming
• Use of Safari
• Use of voice dialing
• Use of purchasing within an application
Configure Safari preferences:
• Disable Javascript
• Block Pop-ups
• Reject cookies
• Set fraud warnings
• Authorize automatic filling
• Block explicit content music and podcasts
ActiveSync account:
• Account name displayed
• ActiveSync server address
• SSL protection
• Domain
• Number of days of e-mail to synchronize
• Use of authentication by User Certificate
• Protection of the ActiveSync profile against user deletions
Values automatically set
• User login
• E-mail address
• Identity certificate
POP and IMAP e-mail account VPN connections WIFI
General settings:
• Account name
• Account type: POP or IMAP
• Protection of the E-mail profile against user deletions
Settings for incoming and outgoing e-mails:
• Server address and port
• Use of SSL
• Choice of authentication method
•
Values entered automatically
• User login
• E-mail address
• Several VPN per device
• Connection name
• Server hostname
• Account
• Shared secret
• Configuration of the associated proxy
Type of VPNs supported:
• Cisco IPSec
• SSID of WIFI networks
• Masked network
• Security type: WEP, WPA, WPA2
• Associated passcode
WAP enterprise support
• Configuration of accepted EAP types
• EAP-FAST configuration
• Authentication settings
• User's identity certificates
• Approved server certificates
• Selection of approved servers
• Authorize reliability exceptions
Device Control Distribution of certificates Web Clips / APN
• Device control policy
• Limit the number of devices per user
• Limit the authorized types of device
• Control the authorized iOS versions
• Identity certificates
• Root authority certificates
• PKCS12 and PKCS7 format
Distribution of web clips:
• Name
• Web site URL
• Associated icon
• Protection of the web clip
Configuration of the APN:
• Access Point Name
• User name and passcode
Datasheet Version 2.4
Deploy, Secure and manage your iPhones/iPads remotely
9
ASSET MANAGEMENT
Monitoring of your fleet's deployment status
PushManager Deployment Platform enables you to track precisely the different deployment statuses of your smartphones.
• Activation code sent
• User authenticated on the platform
• Registration of the device on the MDM server • Confirmation of correct E-mail reception
The list of smartphones is displayed as a customizable grid: • Multi-criteria search engine
• Text-based filter by field type
Datasheet Version 2.4
Deploy, Secure and manage your iPhones/iPads remotely
10
Display detailed information for each smartphone
Using iOS 4.XPushManager Deployment Platform gives you a detailed inventory of your fleet of Apple iOS 4.x devices.
This detailed data is automatically updated and available at all times for the administrator.
Characteristics Network/Security information Deployment status
• Device name
• Device model
• Device's Apple reference
• OS version
• Interface language
• Firmware version
• Total storage capacity
• Available storage capacity
• Serial number
• IMEI number
Network :
• SIM card number
• Telephone number
• Current operator
• SIM card operator
• Roaming synchronization activated
Security :
• Locking passcode activation
• Passcode compliant
• Hardware encryption capacity
• MDM status
• Last contact with device
• Date activation SMS/e-mail was sent
• Provisioning date
• E-mail test date and result
Installed applications
Datasheet Version 2.4
Deploy, Secure and manage your iPhones/iPads remotely
11
Using iOS 3.X
PushManager Deployment Platform also collects information about iOS 3.x smartphones during the provisioning step:
• Version of installed iOS • Interface language
Datasheet Version 2.4
Deploy, Secure and manage your iPhones/iPads remotely
12
SECURE YOUR SMARTPHONES
Prohibit unauthorized devices
• Define a maximum number of devices per mobile user • Control access according to type of device and iOS version
Enforce configuration policy
• Enforce locking passcode configuration • Define the device protection level
• Prohibit smartphone functionalities not compatible with your security policy • Control use of native applications (Safari, YouTube, etc.)
Remotely Control your deployed devices
• Set remote locking of smartphones
• If necessary, remotely clear the locking passcode
• Wipe the entire configuration and company data with a single click. • Once the partnership between the Apple Smartphone and PMDP is
terminated, all company data is automatically deleted from the device. • Wipe and completely reset a device
Delegate administration rights
• Create your own administration roles: administrator operators, helpdesk operators, etc.