User Self-Service Configuration Overview

Similar documents
Good Share Client User Guide for ios Devices

Service Release Notes 8.2

Good Connect for ios Client User Guide

Technical Certificates Overview

Cloud Deployment Guide

Advanced Configuration Steps

Service Desk Guide. Version 8.2. Mobile Service Manager

System Requirements. Version Mobile Service Manager

Configuration and Administration

Sophos Mobile Control user help. Product version: 6.1

Mobility Manager 9.5. Users Guide

User Guide. BES12 Self-Service

BES10 Self-Service. Version: User Guide

UP L18 Enhanced MDM and Updated Protection Hands-On Lab

DameWare Server. Administrator Guide

WatchDox Administrator's Guide. Application Version 3.7.5

DocAve for Office 365 Sustainable Adoption

How To Configure A Windows 8.1 On A Windows (Windows) With A Powerpoint (Windows 8) On A Blackberry) On An Ipad Or Ipad (Windows 7) On Your Blackberry Or Black

Sophos Mobile Control Startup guide. Product version: 3.5

Administrators Help Manual

NotifyMDM Device Application User Guide Installation and Configuration for Windows Mobile 6 Devices

Welcome Guide for MP-1 Token for Microsoft Windows

Sophos Mobile Control User guide for Apple ios. Product version: 4

Enterprise Self Service Quick start Guide

MaaS360 Cloud Extender

GO!Enterprise MDM Device Application User Guide Installation and Configuration for BlackBerry

Sophos Mobile Control Startup guide. Product version: 3

NetWrix Account Lockout Examiner Version 4.0 Administrator Guide

MaaS360 On-Premises Cloud Extender

Sophos Mobile Control Super administrator guide. Product version: 3

GO!Enterprise MDM Device Application User Guide Installation and Configuration for ios Devices

Employee Active Directory Self-Service Quick Setup Guide

Pipeliner CRM Phaenomena Guide Getting Started with Pipeliner Pipelinersales Inc.

QuickStart Guide for Mobile Device Management

GO!Enterprise MDM Device Application User Guide Installation and Configuration for ios with TouchDown

Sophos Mobile Control User guide for Windows Phone 8. Product version: 3.5

Implementing and Supporting Windows Intune

Resource Online User Guide JUNE 2013

Configuration Guide for SQL Server This document explains the steps to configure LepideAuditor Suite to add and audit SQL Server.

Viewing Paycheck Information Online - LSUSH Off Campus

Sophos Mobile Control User guide for Apple ios

Building a BYOD Program Using the Casper Suite. Technical Paper Casper Suite v9.4 or Later 17 September 2014

1. What are the System Requirements for using the MaaS360 for Exchange ActiveSync solution?

StarWind iscsi SAN Software: Installing StarWind on Windows Server 2008 R2 Server Core

QuickStart Guide for Mobile Device Management. Version 8.6

GO!Enterprise MDM Device Application User Guide Installation and Configuration for Android with TouchDown

Sophos Mobile Control Administrator guide. Product version: 3

RSA Authentication Manager 8.1 Help Desk Administrator s Guide

AT&T Business Messaging Account Management

Macs are not directly compatible with Noetix.

NETWRIX IDENTITY MANAGEMENT SUITE

Android App User Guide

Active Directory Self-Service FAQ

Sophos Mobile Control Administrator guide. Product version: 3.6

SafeNet MobilePASS Version 8.2.0, Revision B

Generating an Apple Push Notification Service Certificate

BlackShield Authentication Service

Pipeliner CRM Phaenomena Guide Sales Pipeline Management Pipelinersales Inc.

Generating an Apple Push Notification Service Certificate for use with GO!Enterprise MDM. This guide provides information on...

Intel Unite Solution. Standalone User Guide

WhatsUp Gold v16.2 Installation and Configuration Guide

Telstra Mobile Device Management (T MDM) Getting Started Guide

GO!Enterprise MDM Device Application User Guide Installation and Configuration for Android

Configuration Guide. for the Lepide User Password Expiration Reminder

StarWind iscsi SAN Software: Using an existing SAN for configuring High Availability storage with Windows Server 2003 and 2008

RSA Authentication Manager 8.1 Help Desk Administrator s Guide. Revision 1

DocAve 6 Service Pack 1 Job Monitor

COMMUNITAKE TECHNOLOGIES MOBILE DEVICE MANAGEMENT FROM BELL USER GUIDE

Preparing for GO!Enterprise MDM On-Demand Service

Mobile Iron User Guide

StarWind iscsi SAN: Configuring HA File Server for SMB NAS February 2012

BlackBerry Enterprise Service 10. Universal Device Service Version: Administration Guide

Viewing Paycheck Information Online - LSU Health New Orleans - On Campus

Integrating ConnectWise Service Desk Ticketing with the Cisco OnPlus Portal

Lepide Software. LepideAuditor for File Server [CONFIGURATION GUIDE] This guide informs How to configure settings for first time usage of the software

Installation & Activation Guide. Lepide Active Directory Self Service

AvePoint Tags 1.1 for Microsoft Dynamics CRM. Installation and Configuration Guide

Intel Active Management Technology with System Defense Feature Quick Start Guide

Orientation Course - Lab Manual

Onboarding for Administrators

User Guide Novell iprint 1.1 March 2015

WatchDox for Mac User Guide

MCBDirect Corporate Logging on using a Soft Token

Installing and Configuring DB2 10, WebSphere Application Server v8 & Maximo Asset Management

SonicWALL SSL VPN 3.5: Virtual Assist

DIGIPASS KEY series and smart card series for Juniper SSL VPN Authentication

PrinterOn Mobile Applications for ios and Android

ALTIRIS Software Delivery Solution for Windows 6.1 SP3 Product Guide

Sample- for evaluation purposes only! Advanced Outlook. TeachUcomp, Inc. A Presentation of TeachUcomp Incorporated. Copyright TeachUcomp, Inc.

Omniquad Exchange Archiving

DocuSign Connect for Salesforce Guide

Optum Patient Portal. 70 Royal Little Drive. Providence, RI Copyright Optum. All rights reserved. Updated: 3/7/13

Administration Guide. BlackBerry Enterprise Service 12. Version 12.0

Sample- for evaluation purposes only! Outlook Web App. TeachUcomp, Inc. A Presentation of TeachUcomp Incorporated. Copyright TeachUcomp, Inc.

753 Broad Street Phone: Suite 200 Fax: Augusta, GA Copyrights

StarWind iscsi SAN Software: Tape Drives Using StarWind and Symantec Backup Exec

CRM to Exchange Synchronization

MaaS360 Mobile Device Management (MDM) Administrators Guide

formerly Help Desk Authority Upgrade Guide

Transcription:

User Self-Service Configuration Overview Version 8.2 Mobile Service Manager

Legal Notice This document, as well as all accompanying documents for this product, is published by Good Technology Corporation ( Good ). Good may have patents or pending patent applications, trademarks, copyrights, and other intellectual property rights covering the subject matter in these documents. The furnishing of this, or any other document, does not in any way imply any license to these or other intellectual properties, except as expressly provided in written license agreements with Good. This document is for the use of licensed or authorized users only. No part of this document may be used, sold, reproduced, stored in a database or retrieval system or transmitted in any form or by any means, electronic or physical, for any purpose, other than the purchaser s authorized use without the express written permission of Good. Any unauthorized copying, distribution or disclosure of information is a violation of copyright laws. While every effort has been made to ensure technical accuracy, information in this document is subject to change without notice and does not represent a commitment on the part of Good. The software described in this document is furnished under a license agreement or nondisclosure agreement. The software may be used or copied only in accordance with the terms of those written agreements. The documentation provided is subject to change at Good s sole discretion without notice. It is your responsibility to utilize the most current documentation available. Good assumes no duty to update you, and therefore Good recommends that you check frequently for new versions. This documentation is provided as is and Good assumes no liability for the accuracy or completeness of the content. The content of this document may contain information regarding Good s future plans, including roadmaps and feature sets not yet available. It is stressed that this information is non-binding and Good creates no contractual obligation to deliver the features and functionality described herein, and expressly disclaims all theories of contract, detrimental reliance and/or promissory estoppel or similar theories. Legal Information Copyright 2015. All rights reserved. All use is subject to license terms posted at www.good.com/ legal. GOOD, GOOD TECHNOLOGY, the GOOD logo, GOOD FOR ENTERPRISE, GOOD FOR GOVERNMENT, GOOD FOR YOU, GOOD APPCENTRAL, GOOD DYNAMICS, SECURED BY GOOD, GOOD MOBILE MANAGER, GOOD CONNECT, GOOD SHARE, GOOD TRUST, GOOD VAULT, and GOOD DYNAMICS APPKINETICS are trademarks of Good Technology Corporation and its related entities. All third-party technology products are protected by issued and pending U.S. and foreign patents. USS Configuration Guide 2

Contents Section 1 : User Self-Service Overview 4 Section 2. Corrective Actions and User Workflows 8 Add Device 9 Activate App (GFE Only) 11 Pending Good for Enterprise (GFE) activation 12 Security Management 13 Replace Device 16 Reset Password 17 Lost Device 20 Deactivate Device 20 USS Configuration Guide 3

01 User Self-Service Overview What is User Self-Service? User Self-Service (USS) is a web portal that fosters user self-sufficiency by enabling users to complete a range of corrective actions for their devices without having to escalate issues to the service desk. Instead of initiating a support ticket via email or phone, users may navigate to the USS URL and complete the action on their own through a series of guided workflows. Additionally, from the landing page users will be able to view compliance alerts listed for their devices and use the posted recommendations to resolve issues. Configuring USS Settings Before running USS, system settings must be configured on the Good MSM Admin page on the Settings menu located in the Good MSM Web Console. Good MSM settings allows administrators to modify all Good MSM configurations on a consolidated page. Use the User Self-Service sections in Good MSM Settings to modify the configurations in USS. The following items must be configured before users can access the USS online portal. Hostname for the USS portal: Configure the hostname and list a URL for the USS site. Device Deactivation Instructions: Provide instructions for safely returning a company-owned manged device after deactivation. Custom Branding: Customize the USS online portal and Enrollment application to reflect your company s corporate identity by using your logo and enterprise colors to brand these assets. Support Contacts: Provide support information in the event the customer experiences issues. User Agreement: Provide Terms and Conditions of expected use for the portal. Typically, customers will only see this page once. However, if the User Agreement changes between visits or if the user switches browers or clears cookies, users will have to consent to terms again. USS Configuration Guide 4

USS Overview Mapping USS Roles within the Admin Console As part of the configuration process, the ussdeviceowner group role must be mapped within the Admin Console prior to launching the USS web application. To access the Admin Console, press the desktop application icon. 1. Login to the Admin Console using administrator credentials 2. Press the Map Users shortcut button. 3. By default the Use Windows Authentication checkbox should be checked, if it is not, check the box. 4. Click the appropriate field in the Mapped Windows Security Group column to enter a group or to browse for a group to map. This will open the Select Group window. Complete the fields and press OK. 5. Press OK at the bottom of the Map Users window to exit after all roles and groups have been mapped. USS Configuration Guide 5

USS Overview Platforms and Licensed Modules Modules and platforms licensed by your enterprise will dictate the workflows and the combinations of options available to users at any given time. USS workflows will vary based upon the licensed Good MSM modules and platforms such as Good for Enterprise, ActiveSync, Blackberry and Security Management. What actions are available within the USS Portal? The USS portal allows users to take the following actions for their devices: Reset device or application (Good for Enterprise) password Enroll a device or activate application (Good for Enterprise) Lock or wipe device or application (Good for Enterprise) Replace a device Deactivate a device Check status of a device and troubleshoot compliance issues Welcome Page To login to the USS console, users will be required to enter their Active Directory (AD) credentials including the user name, password, and corresponding domain. Also available on the USS Welcome page are the following: Sign In button to allow the user to log into the USS portal Support link with contact information for all support resources. USS Configuration Guide 6

USS Overview The Welcome page and corresponding USS home page may be customized with your corporate brand logo, colors and contact information. To update these items, visit the Enterprise Information panel on the Good MSM Admin Settings page. USS Configuration Guide 7

USS Portal Overview The USS home page lists each enrolled device associated with the user. A set of available actions will be available beneath each device. The available actions will vary based upon the enrolled platforms. Status notifications and compliance alerts will post in the field next to each device to inform users about service issues and required actions. Additionally, the Add Device action will be available on the top left of the screen to allow the user to enroll new devices. User Information Device Summary and Support Contact Information Through this bar, you can add a new device to monitor and see a summary of your current devices and policies. Technical support contact information for your organization is also available from this bar. User name and sign out Device Issues/Status Status messages and compliance issues will appear in this panel. Device Panel Provides an image, OS version, and contact details about the device. Deactivate Device Wipe the device and remove it from security management. Wipe the Good for Enterprise app and delete the device from the Good server. Device Details Selecting the device will direct you to device details and issues. Lost Device Initiate protective measures such to lock the device and/or wipe device Replace Device Activate App Reset Password content (for Good for Enterprise). Deactivate a current device from management and enroll a new device. Initiates an activation for the Good for Enterprise app (if it is licensed). Depending on the licensed modules, you can reset an application or device password. USS Configuration Guide 8

Device Reconciliation Through device and platform-specific data, we attempt to consolidate multiple connections on the same device, also referred to as device reconciliation. For example, if the system discovers a device has a Good Dynamics connection and an ActiveSync connection, we will reconcile the connections to appear in consolidated display under one device (instead of displaying the device twice). In most cases, devices will be reconciled within a few minutes of any activation/service changes in Service Desk and User-Self Service. The platform combinations in the table below should reconcile with very few exceptions. Device Reconciliation Table Full Reconciliation Combinations GFE +GD Descriptions Good for Enterprise and Good Dynamics: Where a user is using Good for Enterprise to receive email on a device where Good Dynamics apps have also been installed, the MSM will combine the device details received from both systems to display a single device record. GD + AS MDM +AS Good Dynamics and ActiveSync: Where Good Work is used to receive email, MSM will combine the device details received from Good Dynamics with the device details received from ActiveSync that are associated with the Good Work client so that a single device record is displayed on the accordion. Mobile Device Management and ActiveSync: Where MDM has been used to provision an ActiveSync account to a device, MSM will combine device details from ActiveSync and MDM to display a single record on the accordion. MDM+GFE Mobile Device Management and Good for Enterprise: Where Good for Enterprise is used to receive mail on a device that is enrolled in MDM, MSM will combine device details from both platform to display a single device on the accordion. Known Limitations Though we make every attempt to reconcile connections for ease of use and convenience, there are some instances when connections are unable to be reconciled and may appear individually within the dashboard (resulting in a device being listed more than once). This occurs primarily because the data collected varies across platforms. These dissimilarities in collected data make it difficult to associate the connections with the same device. The platform combinations in the table below will be listed once for each connection in User Self-Service. USS Configuration Guide 9

Incomplete Reconciliations AS + AS ActiveSync and ActiveSync: Where two different ActiveSync accounts are present on a single device MSM will not reconcile them to create a single device. This allows both ActiveSync connections to be separately managed. GFE + AS Good for Enterprise and ActiveSync: Where both Good for Enterprise and ActiveSync are both used to check email on a device, typically the data MSM receives from both platforms makes it difficult to say definitively whether the data received from the two systems describe a single device, or two separate devices. In most cases two devices will be displayed in the accordion. USS Configuration Guide 10

02 01 Corrective Actions and User Workflows Add Device Users are able to enroll new devices through the workflow initiated from the Add Device button at top of the screen. When users enroll devices, they are consenting to bring their devices under Good MSM Mobile Device Management and agreeing to allow corporate resources and policies to be pushed to the device. To begin the process of enrolling a new device, press Add Device. A window will appear with the option to select a Device Type. If the desired device type does not appear in the list, select the option button next to Not Listed. USS Configuration Guide 11

Corrective Actions and Workflows! Note: The Next button will remain deactivated until you select a device type. Next, in order to capture the appropriate liability of the device, USS will prompt the user to select the ownership of the new device. If the user is enrolling a personal device, select the radio button next to I own this device. If a user has been issued a new corporate device, choose Enterprise Name owns it. Pressing next will initiate the guided workflow through the ios Activation workflow. USS Configuration Guide 12

Corrective Actions and Workflows The next steps will depend on which platforms (Security Management, Good for Enterprise) have been licensed and available in Good MSM. A user can enroll in both Security Management and Good for Enterprise or just one of the two, or simply Exchange ActiveSync. For Security Management enrollment, the user will walk through a series of steps and instructions: 1. Download the Good Device Activation app from the App Store 2. Install the app on their device Good Activation Good Device Activation app. Good Device Activation app. Good! Note: The activation application steps will only be part of your workflow if Security Management has been licensed by your company. 3. Start the Security Management enrollment process from the app. USS will make available all the necessary information to guide the user through the enrollment process: a. Provide the enrollment URL b. Provide the One-Time Password to the user if this option is enabled in Good MSM Admin. c. Provide any additional information to the user such: user name, domain to use during the enrollment. USS Configuration Guide 13

Corrective Actions and Workflows For Good for Enterprise, the user will walk through a series of steps and instructions: 1. If Good for Enterprise is not already available on the device, download the Good for Enterprise app from the App Store. USS Configuration Guide 14

Corrective Actions and Workflows 2. USS will generate the activation PIN to user to use during the activation process for Good for Enterprise (GFE). GFE device is automatically created on the appropriate Good Mobile Messaging (GMM) server. The appropriate GMM server is selected automatically based on the rules set by the administrator in Good MSM Admin for either preferred GMM server assignment whereby an Active Directory group can be mapped to a specific GMM server or to a system wide default GMM server. The default GMC policy will be applied. If no rules are configured or applied and no enterprise default server is configured, the following rules will apply: If one Good Mobile Control (GMC) server is configured, the system will add the device to that GMC server without specifying the GMM server and lets the GMC server select the default. If multiple GMC servers are configured, then Good MSM will generate a No default GMM server configured error. The GFE OTA PIN is generated and displayed in the USS for the user. The OTA PIN is also emailed to the user if they need to reference it again. 3. And finally any additional information such as how to set a password on Good for Enterprise app. USS Configuration Guide 15

Corrective Actions and Workflows Activate App (GFE Only) In an environment where Good is configured, users will be able to activate Good for Enterprise for existing enrolled devices (including Security managed, Exchange ActiveSync devices) that are compatible with Good for Enterprise. In this workflow, Activate App will create a device on the GMM server and display the activation PIN for the user during app activation. The process is similar to adding a new GFE device through Add Device action.. Pressing Activate will initiate a guided session through the activation process USS Configuration Guide 16

Corrective Actions and Workflows Pending Good for Enterprise (GFE) activation If the user progresses through the USS GFE activation workflow, but has not activated the GFE application on the device, a generic device will be displayed in the device panel on USS to indicate that a device record was created on the GMC server, but the application has not been activated. A generic device may also display during the activation process until BoxTone syncs to confirm the activation has completed successfully. The Activate App button will allow users to retrieve another activation PIN for GFE or remove the pending activation as alternative actions to pressing the Deactivate Device button. To cancel the activation, press Deactivate Device. USS Configuration Guide 17

Corrective Actions and Workflows Enabling Exchange ActiveSync For Exchange ActiveSync, the user will walk through a series of steps and instructions: Good MSM USS will provide the user with all the information necessary to activate an Exchange ActiveSync email account on their device including: User name Email address Domain name Replace Device If the user has at least one existing device enrolled, and intends to replace it with a new device; the user can navigate down to the device that requires the action and press Replace Device. The Replace device workflow can also be invoked through the Add Device action. The Replace Device workflow will guide the user through deactivating an existing device and enrolling the new USS Configuration Guide 18

Corrective Actions and Workflows device. Depending on the platforms licensed and available in BoxTone, the user will be able to enroll a new device in Security Management and Good for Enterprise or one of the two, or simply Exchange ActiveSync. A progress bar at the top of the pop up window will indicate the steps left to complete the action. If the user reaches the maximum number of devices and attempts to enroll a new devices using the Add Device button, Good MSM will automatically prompt the user to deactivate an existing device before enrolling a new one. The user is able to replace the following type of devices: BlackBerry device Exchange ActiveSync device Good for Enterprise device Security managed ios device! Note: The user can only replace one device at a time USS Configuration Guide 19

Corrective Actions and Workflows Reset Password The USS portal allows the user to reset the password for each device enrolled in Good MSM. The user may reset either the password for the device if it is under Security Management or for GFE, if GFE is activated on the device. On the USS landing page, the user navigates down to the appropriate device and Press Reset Password. A popup window will open and prompt the user select a password to reset if there are multiple selections or simply redirects the user to the appropriate workflow if there is only one available option (device vs. GFE password reset), depending on the environment and state of the device. Reset Password: ios device under Security Management The user can unlock an ios security managed device by simply clicking Unlock Device. A remote call will be made to the device to unlock it. The user will then be prompted on the device to select a new password. Reset Password: Good for Enterprise In order to unlock the Good for Enterprise application, the user is required to enter the unlock code available once they select the Forgot Password option on the application. USS Configuration Guide 20

Corrective Actions and Workflows Once the unlock code is entered, Good MSM will validate the code with the Good Mobile Control server. If the validation is successful, a new temporary unlock code will be generated and appear onscreen. The user will have to then use this temporary unlock code to unlock the GFE application. The GFE application will prompt the user to set a new password.! Note: BlackBerry Fix-it actions are limited at this time. The current options include replacing a device, deactivating a device, and your device is lost. USS Configuration Guide 21

Corrective Actions and Workflows Lost Device In the event the user s device is lost, misplaced or stolen, Good s USS enables the user to remotely lock or wipe the device or the Good for Enterprise application. For Exchange ActiveSync devices, users will only have the option to complete a full wipe of the device. On a security managed ios device, the Lock command is automatically issued as soon as the user initiates the Lost Device workflow. This command will lock the home screen of the device. Additionally, the user can then choose to selectively wipe the device. When wiping a device, the user has the option to use the Selective or Full Wipe function. If these options are selected, the device will no longer be under management. A Selective wipe will permanently remove all corporate data from the device. A Full wipe will remove both corporate and personal data. If a wipe is issued for a device that has GFE activated, it will clear the GFE container and remove the device from the GMC sever. Once a device is wiped, it is no longer under security management.! Note: Automatically locking the device does not lock the Good for Enterprise application. On a non-security managed device with GFE, clicking on Lost Device prompts the user if they would like to lock or wipe the GFE application.! Note: Wiping the GFE application removes the device from the GMC server as well. Deactivate Device The user can deactivate a device at will. Deactivate Device invokes a wipe of the device. Depending on the platforms the device is enrolled to, the user may opt to selectively wipe a security-managed device. Issuing an MDM wipe on a device that also have GFE activated, will wipe the GFE container and remove the device from the GMC sever. On a non-security managed device with GFE, clicking on Deactivate Device prompts the user to wipe the GFE application also known as the work email app. On an Exchange ActiveSync device, issuing the command to deactivate the device will result in a full device wipe. USS Configuration Guide 22

User Self-Service Configuration Overview Version 8.2.0.1.1072 Copyright 2015 by Good Technology. All rights reserved. Trademarks Good is a registered trademark of Good Technology Incorporated. Microsoft and Microsoft Windows are registered trademarks of Microsoft Corporation. All other product names used are trademarks of their respective owners. Notice The material in this document is for information only and is subject to change without notice. While reasonable efforts have been made in the preparation of this document to assure its accuracy, Good Technology Inc. assumes no liability resulting from errors or omissions in this document, or from the use of the information contained herein. Good Technology Inc. reserves the right to make changes in the product design without reservation and without notification to its users. Edition July 16, 2015 Mobile Service Manager