Kaspersky Secure Mobility Management
Configuring a corporate container

Expand all | Collapse all

To configure the settings of a corporate container:

  1. In the main window of Kaspersky Security Center Web Console, select Assets (Devices)Policies & profiles. In the list of group policies that opens, click the name of the policy that you want to configure.
  2. In the policy properties window, select Application settings.
  3. Select Android and go to the Corporate container section.
  4. On the Corporate container on devices card, click Settings.

    The Corporate container on devices window opens.

  5. Enable the settings using the Corporate container on devices toggle switch.
  6. Specify the corporate container settings:
    • On the General tab, you can specify the settings for data sharing, contacts, and more.
      • Settings in the Data access and sharing section:
        • Prohibit personal apps from sharing data with corporate container apps
        • Prohibit corporate container apps from sharing data with personal apps
        • Prohibit corporate container apps from accessing personal files
        • Prohibit personal apps from accessing files in corporate container
        • Prohibit use of clipboard between personal apps and corporate container
        • Prohibit activation of USB debugging
        • Prohibit users from adding and removing accounts in corporate container
        • Prohibit screen sharing, recording, and screenshots in corporate container apps
      • Settings in the Contacts section:
    • On the Apps tab, specify the following settings:
      • Settings in the General section:
        • Enable App Control in corporate container only
        • Enable Web Protection and Web Control in corporate container only
        • Prohibit installation of apps from unknown sources in corporate container
        • Prohibit removing apps from corporate container
        • Prohibit displaying notifications from corporate container apps when screen is locked
        • Prohibit use of camera for corporate container apps
      • In the Granting runtime permissions for corporate container apps section you can select an action to be performed when corporate container apps are running and request additional permissions. This does not apply to permissions granted in the device settings (for example, Access All Files).
        • Allow users to configure permissions
        • Grant permissions automatically
        • Deny permissions automatically
      • In the Adding widgets of corporate container apps to device home screen section you can choose whether the device user is allowed to add widgets of corporate container apps to the device home screen.
        • Prohibit for all apps
        • Allow for all apps
        • Allow only for the listed apps
    • On the Certificates tab, you can configure the following settings:
      • Duplicate installation of VPN certificates in user's personal space
      • Duplicate installation of root certificates in user's personal space
    • On the Password tab, specify the corporate container password settings:
      • Require setting a password for corporate container
      • Minimum password length
      • Minimum password complexity requirements
      • Maximum number of failed password attempts before corporate container is deleted
      • Maximum password lifetime (days)
      • Number of days to send a notification before a required password change
      • Number of recent passwords that cannot be set as a new password
      • Period of inactivity before corporate container is locked (sec)
      • Period after biometric unlock before password must be entered (min)
      • Allow biometric unlock methods
      • Allow fingerprint unlock
      • Allow face unlock
      • Allow iris scanning
    • On the Passcode tab, specify the one-time passcode settings. The user will be prompted to enter the one-time passcode to unlock their corporate container if it is locked.
      • Passcode length
  7. Click OK.
  8. Click Save to save the changes you have made.

Mobile device settings are changed after the next device synchronization with Kaspersky Security Center. The user's mobile device is divided into a corporate container and a personal space.