mobilecho: 5-Step Deployment Plan for Mobile File Management
Overview GroupLogic s mobilecho is the industry s first and only secure Mobile File Management (MFM) solution for ipads. mobilecho enables IT organizations to provide secure and managed corporate file access for enterprise ipad users, based on existing security and access control policies. With the simplicity demanded by end-users, and the security and management required by enterprise IT, mobilecho provides organizations with the foundation for their mobile file management strategy. mobilecho consists of an ipad app which is downloaded for free from the Apple App Store i and a server component which is purchased or trialed from GroupLogic. ii The server is installed on the Windows file servers that store the files that your mobile users need to access. If outside your corporate network, the mobilecho ipad client needs to connect through your firewall to the mobilecho file server running on your Windows server. One server can optionally be designated as the mobilecho client management server. All mobilecho clients will receive their configuration over-the-air (OTA) from the server, both the first time the user configures mobilecho and also on subsequent connections, to refresh the settings on the mobile device. In planning your deployment of mobilecho, you need to understand the topology of the solution and then determine the best path for your organization. i http://itunes.apple.com/us/genre/mobile-software-applications/id36?mt=8 ii http://www.grouplogic.com/ 2
5 Easy Steps to Deploy mobilecho 1. Secure ipad with a Passcode Lock and backup with encryption Using the iphone Configuration Utility (ICU) http://www.apple.com/support/iphone/enterprise/ or your mobile device management (MDM) solution, set your devices to require a Passcode Lock. Apple Data Protection hardware encryption requires a Passcode Lock be enabled in order to provide encryption, so you must use the ICU or your MDM solution to require that devices have a PIN. This step will also secure your back up in itunes. Your ios device is backed up every time it is synched to itunes. This back up is a potential security risk that will be secured automatically once your device is configured to "require a device PIN" on your itunes backup. Please read the Group Logic Enterprise Security with mobilecho Whitepaper to fully understand the security elements of mobilecho and the ipad. Apple documentation notes that: If you protect your iphone or ipod touch with a passcode, you will be prompted to enter the passcode when you connect to itunes. Once you successfully enter the passcode, itunes will recognize that device as authorized and you will not need your passcode to back up or sync. [Reference http://support.apple.com/kb/ht1766] You can confirm that your device backup is secured with a password in the Preferences -> Devices panel of your itunes software as pictured here: 3
2. Select your method of traversing the firewall When outside your corporate network, mobilecho clients need to connect from the Internet to the mobilecho server running inside your firewall. mobilecho can communicate securely using HTTPS, with or without a VPN, so your options are: Certificate Authentication. enterprise apps through the firewall. convenience is valued. For more information on VPN on Demand with Certificate Authentication, check here: http://support.apple.com/kb/ht1288 For information on configuring an HTTPS reverse proxy, consult the Microsoft Forefront Threat Management Gateway (formerly ISA) [http://www.microsoft.com/forefront/threat-management-gateway] or documentation on other reverse proxy solutions [http://en.wikipedia.org/wiki/reverse_proxy]. 4
3. Determine which servers your mobile users need mobilecho server software must be installed on at least one server. A mobilecho server can be configured to give access to locally stored files and can also act as a gateway to SMB/CIFS volumes on other corporate file servers and NAS storage. Make arrangements for the server software to be installed, configured and managed, ideally via a central management tool such as Microsoft Systems Center. 5
4. Configure mobilecho client management profiles for your users or groups With mobilecho client management profiles, you can centrally configure the mobilecho client security settings, application settings and server settings. Management profiles allow complete control of the mobilecho app s capabilities. For each user or group, configure the appropriate Security settings. These settings can require an application lock password and specify password complexity requirements. Users can be prevented from changing and removing their mobilecho management profiles. [mobilecho Profiles - Security settings] 6
For each user or group, configure the appropriate Application settings. These settings determine which functions of the mobilecho app are enabled. Keep in mind that mobile users may or may not need the same breadth of functions available to desktop users, so it may be okay to disable privileges from your mobilecho app. [mobilecho Profiles - Application settings] 7
For each user or group, configure the appropriate Server settings. These settings determine how often the user must log into servers and automatically provision the list of servers that appear in the mobilecho app. [mobilecho Profiles - Server settings] 5. Deploy mobilecho to users via email or webpage Upon completion of these steps, you can deploy mobilecho to ipad users in your organization and deliver productivity while securing the organization s data against loss. Send your users an email or link to a webpage containing two required items: Hotlink this button to the App Store [ http://www.grouplogic.com/web/meappstore ] where they can install the free mobilecho app Hotlink this button to the invitation file generated by the mobilecho client management server. This invitation file connects the mobilecho app to your mobilecho management server. The user is prompted to authenticate with the Active Directory credentials and is then automatically configured OTA with their assigned user or group profile. 8
Summary Deploying mobilecho is easy and puts your organization on the path of establishing a secure mobile file management strategy. mobilecho enables your enterprise to provide secure access to enterprise file servers for ipad users, eliminating the need for work-arounds and third-party mobile applications that compromise the security of corporate files and assets. Configurable and deployable across the enterprise within minutes, mobilecho promotes efficient IT management while ensuring corporate security and compliance standards are met. Enterprise end-users of mobilecho can access, browse, search and interact with corporate files as well as cache files for offline access, improving overall mobile worker productivity regardless of job function. About GroupLogic GroupLogic helps enterprise and education IT organizations simply and securely integrate diverse computing platforms into enterprise environments, connecting employees and students to enterprise files, content and assets to facilitate a more productive and efficient work environment. With more than two decades of experience, GroupLogic leads the marketplace in helping IT organizations effectively and easily manage the integration of Apple products into the enterprise ecosystem. Whether IT organizations are looking to integrate existing Apple assets, purchase additional Apple hardware like Macs and ipads, or want to take advantage of the hardware costs savings that accompany the adoption of IT consumerization, GroupLogic enables IT organizations to easily and securely manage the rapid integration of diverse platforms while ensuring resources are optimized. GroupLogic enables the enterprise to focus on what is really important competitive differentiation, improved employee productivity, mitigated risk and reduced costs. GroupLogic s proven products mobilecho, ExtremeZ-IP, ArchiveConnect, and MassTransit are in use by some of the world s most innovative companies, including Christie s, International Greetings and Omnicom Group. GroupLogic, mobilecho, ExtremeZ-IP, MassTransit, Zidget, ShadowConnect and ArchiveConnect are all registered or unregistered trademarks of Group Logic, Inc. All other trademarks referenced herein are the property of their respective owners. 2011 Group Logic, Inc. All Rights Reserved. 9