38
Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management Sinnathamby Shanmugarajah (Shan) WSO2Mobile Director, Architecture

WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

  • Upload
    wso2

  • View
    526

  • Download
    3

Embed Size (px)

Citation preview

Page 1: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Sinnathamby Shanmugarajah (Shan)WSO2Mobile

Director, Architecture

Page 2: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Achieving Safe BYOD using WSO2Mobile MDM

“Work is no longer seen as a place rather seen as an activity independent of location and specific technology”

Page 3: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Achieving Safe BYOD using WSO2Mobile MDM

Employees have started bringing their own device to work • working even after work hours from home • working even on the move

Page 4: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Achieving Safe BYOD using WSO2Mobile MDM

Some organizations openly give access to their corporate network for email and content sharing without any restrictions.

Page 5: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Achieving Safe BYOD using WSO2Mobile MDM

NOW ?

Page 6: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Achieving Safe BYOD using WSO2Mobile MDM

Biggest Challenge

1. Security Risk2. Remote Device Management

Page 7: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Achieving Safe BYOD using WSO2Mobile MDM

How to achieve safety using WSO2Mobile MDM ?

Page 8: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Achieving Safe BYOD using WSO2Mobile MDM

1.Device restrictions (OS Version)2.Authentication 3.Block compromised device 4.BYOD Policy 5.Compliance Monitoring

WSO2Mobile MDM

Page 9: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Achieving Safe BYOD using WSO2Mobile MDM

1. Device restrictions (OS and Version) > Android 4.0.4 > iOS 5.0

Page 10: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Achieving Safe BYOD using WSO2Mobile MDM

2. Authentication

Authentication against enterprise user store.

Page 11: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Achieving Safe BYOD using WSO2Mobile MDM

3. Block compromised Devices

• Before Enrolling - Blocking • After Enrolling - Block and Enterprise WIPE

Page 12: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Achieving Safe BYOD using WSO2Mobile MDM

Why ?

Jailbreaking iOS device or Rooting Android is the process of getting privileged access.

If allowed, all sensitive corporate information can be exposed.

Page 13: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Achieving Safe BYOD using WSO2Mobile MDM

4. Policy Enforcing

WSO2Mobile MDM allows you to define BYOD policy and make necessary action.

Based on• Roles • Specific User • Platform

Page 14: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Achieving Safe BYOD using WSO2Mobile MDM

Page 15: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Achieving Safe BYOD using WSO2Mobile MDM

Password Policy

Page 16: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Achieving Safe BYOD using WSO2Mobile MDM

4a. BYOD Policy - Password Policy

Password Policy enforced device

Page 17: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

4b. BYOD Policy - Encrypt phone (in iOS this is automatic when passcode policy is applied)Encrypts all your data (Both personal and Corporate)

Achieving Safe BYOD using WSO2Mobile MDM

Page 18: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

5c. Data leaks

iCloud data backup WSO2Mobile MDM disables this feature when an enterprise application is pushed or installed from the

Achieving Safe BYOD using WSO2Mobile MDM

Page 19: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

5. Compliance Monitoring

• Monitors the status based on policy• Take necessary action if violated Warn Block Access Enterprise WIPE

Achieving Safe BYOD using WSO2Mobile MDM

Page 20: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Achieving Safe BYOD using WSO2Mobile MDM

Page 21: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Achieving Safe BYOD using WSO2Mobile MDM

Page 22: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Productive Apps with Mobile Application Management

Page 23: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Productive Apps with WSO2Mobile MAM

Current situation

• Develop apps and host it in the respective platform Public Market Place (Apple Store , Android Google Play)

• App is exposed to public (Restrictions through authentication)

• Discovering the application is not easy

Page 24: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Productive Apps with WSO2Mobile MAM

Achieve productive apps • Own enterprise store• Unified store• Easy app discovery and provisioning• App policy

Page 25: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Productive Apps with WSO2 Mobile Application Management

WSO2Mobile MAM

• Store • Publisher• Application Management Console

Page 26: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Productive Apps with WSO2 Mobile Application Management

WSO2Mobile Store

• User subscription• Advanced search options• Mobile App sorting• Support for existing user stores• Single-Sign on

Page 27: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Productive Apps with WSO2 Mobile Application Management

Page 28: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Productive Apps with WSO2Mobile MAM

WSO2Mobile Publisher

• Allows publishing application

Created In-Review Published

Unpublished

Rejected

Page 29: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Productive Apps with WSO2Mobile MAM

WSO2Mobile Publisher

Page 30: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Productive Apps with WSO2Mobile MAM

Applications Supported Android Native, Hybrid Application (apk) Web Application Market Place Application (Google Play) (Free) iOS (iPhone, iPad) Native, Hybrid Application (ipa) (Need to have enterprise developer account) Web Application Apple Store Applications (Free) VPP Application

Page 31: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Productive Apps with WSO2Mobile MAM

VPP Application• Apple supports VPP program to buy applications in

bulk• Enterprise enrolls • Buys app in bulk• Receives the redemption code• Uploads to MAM• Employees download applications, MAM provisions

the redemption code through MDM

Page 32: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Productive Apps with WSO2Mobile MAM

How application is installed ?

• Employee logs to the store • Discovers the application • Installs the app to the device

Page 33: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Productive Apps with WSO2Mobile MAM

• Role Based Application Installation & Uninstallation• User Based Application Installation & Uninstallation

• Policy Install Application Policy (Role, User , Platform) Black-List Application

Application Management Console

Page 34: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Productive Apps with WSO2Mobile MAM

Page 35: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Productive Apps with WSO2Mobile MAM

Page 36: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Productive Apps with WSO2Mobile MAM

MDMDB

Adapter

iOS APNS Android GCM

MDM Console

Notification

iOS Android

App Mgmt Device Mgmt

MAMMAM Console

PublisherG-Reg

Store

User Store

MAM is tightly integrated with MDM

Page 37: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Productive Apps with WSO2Mobile MAM

Page 38: WSO2Con US 2013 - Achieving Safe BYOD and Productive Apps with WSO2 Mobile Device Management and Mobile Application Management

Thank You