Connecting mobile devices to Kaspersky Security Center Web Console
To manage mobile devices and the mobile management apps installed on them, you must connect these devices to Kaspersky Security Center.
Before connecting, make sure the license that supports the Mobile Management solution is configured in the License keys section of the Administration Server properties.
To connect a mobile device to Kaspersky Security Center:
- In the main window of Kaspersky Security Center Web Console, select Assets (Devices) → Mobile → Devices.
- In the list of mobile devices that opens, click Add.
The Mobile device connection wizard starts. Click Start, and then proceed through the wizard using the Back and Next buttons.
Welcome
On the welcome screen, you can read a summary of the Mobile device connection wizard steps.
Step 1. Policy
At this step, choose a policy for devices that will connect. Devices operate according to the security settings specified in the policy.
- Use an existing policy
For this option, specify the administration group of the policy you want to choose. The policy name, operating systems and operating modes of the devices managed by this policy will be displayed.
If necessary, click Go to policy to view the properties of the policy you have selected.
- Create a new policy
For this option, click the Create policy button that appears. You will be redirected to the Mobile policy wizard. After a policy with the required properties is created, you can return to the Mobile device connection wizard.
Step 2. Operating systems
At this step, choose the operating systems of the devices that will connect. The policy settings determine the available operating systems: Android, iOS, or Aurora.
- Android
After you select this operating system, the Kaspersky Endpoint Security for Android Installation settings will be displayed. To modify them, click Edit settings.
- Choose the Installation source for Kaspersky Endpoint Security for Android:
This installation source works for all operating modes.
This installation source works for all operating modes.
- To choose an installation package, click Select installation package, and then select the installation package from the list that opens.
- If there are no available installation packages, you will be offered to create one. Click Create installation package, and then follow the steps of the New package wizard as described in the Kaspersky Security Center Help to create an installation package from a file or create a stand-alone installation package. After the installation package is created, you can return to the Mobile device connection wizard.
Automatic app updates through the store are not available with this installation method. You can update the app manually in the App update section of the policy settings.
The latest installation package uploaded to Kaspersky Security Center is used to install the app on devices.For corporate devices, make sure the Allow using HTTP to download the app on corporate devices check box is selected to ensure Kaspersky Endpoint Security for Android is downloaded. Otherwise, the app will be downloaded via HTTPS only if the Kaspersky Security Center Web Server certificate was issued by a trusted certificate authority.
For more information on the installation methods, refer to the Installing Kaspersky Endpoint Security for Android section.
- Choose Installation network for Kaspersky Endpoint Security for Android (corporate devices only):
- Prompt the user to select a Wi-Fi network on device
If you choose this option, the user will be prompted to connect to any available Wi-Fi network for downloading the app.
- Only use the specified Wi-Fi network (Android 9 or later)
To choose an installation network, click Select network.
In the window that opens, specify the following settings:
Do not use a password for a confidential Wi-Fi network that must not be publicly accessible. The unencrypted password is sent to the user in a QR code along with other device configuration data.
- Try to use mobile network (Android 8 or later)
If you choose this option, the device will try to use mobile data to download the app. If the device does not have a SIM card or the mobile network is not available, the user will be prompted to select any available Wi-Fi network.
- Prompt the user to select a Wi-Fi network on device
- Click the Enable all system apps check box (corporate devices only) if you want system apps to remain active on the device. If necessary, they can be disabled later in the App Control section.
- Choose the Installation source for Kaspersky Endpoint Security for Android:
- iOS
To connect and manage iOS devices in basic control and supervised operating modes, you must have an iOS MDM Server installed in the selected administration group. For detailed information on installing iOS MDM Server, refer to the Deploying iOS MDM Server section.
The Kaspersky Security for iOS app will be installed on personal iOS devices in the basic protection operating mode.
A device management profile will be installed on the devices operating in basic control and supervised operating modes.
On devices running iOS 12.1 or later, you must manually confirm the installation of a device management profile on a mobile device. You must also grant the permission for remote management of the device.
- Aurora
To connect Aurora devices, you need to have Kaspersky Endpoint Security for Aurora pre-installed on the devices that will connect.
Step 3. Accept agreements
At this step, choose who must accept the End User License Agreement (EULA) and Privacy Policy.
- Administrator
The agreements are accepted by the administrator in the next step of the wizard. In this case, the app skips the acceptance step during the app installation.
- Users
The agreements are accepted on mobile devices by users.
This step only applies to Android and iOS operating systems. If you are connecting Aurora devices, the agreements are only accepted by users on their mobile devices.
Please note that the administrator will be offered to accept the EULA only after the same version of the EULA is accepted by users on devices for the first time. After the connection and first synchronization of devices with Kaspersky Security Center, the administrator will be able to accept this version of EULA upon subsequent connection of devices.
The list of accepted agreements is available in the End User License Agreements section of the Administration Server properties.
Step 4. End User License Agreement and Privacy Policy
At this step, if Administrator is selected as the recipient of the agreements in the previous step of the wizard, you will be offered to read the Privacy Policy, EULA, and all the documents associated with it. You must accept the terms and conditions of the EULA and Privacy Policy before installation of the mobile device management apps.
Step 5. Users
At this step, choose one or more users of the devices that will connect. These users will receive the details for installing the app to connect their devices to Kaspersky Security Center. If a user is not in the list, you can add a new user account without exiting the wizard.
Due to technical limitations, you cannot select and send the connection details to more than 75 users within a single session of Mobile device connection wizard. We recommend that you divide the devices that will connect into groups of less than 75 devices and connect these groups sequentially within separate wizard sessions.
- To choose an existing user, select check boxes next to the corresponding user names.
- To add a new user, click Add user.
- Specify user credentials in the Credentials block of settings.
- User name
- Password
The password must meet the following complexity requirements:
- It must contain between 8 and 16 characters.
- It must contain the characters from at least three of these groups: uppercase letters (A-Z), lowercase letters (a-z), digits (0-9), special characters (@ # $ % ^ & * - _ ! + = [ ] { } | : ' , . ? / \ ` ~ " ( ) ;).
- If necessary, specify the optional details in the Optional information group of settings.
- Full user name
- Description
- Email address
- Phone number
- Click OK to save the changes.
The new user will be added and displayed in the list of users.
- Specify user credentials in the Credentials block of settings.
- To modify user details, click Edit user.
The fields you can modify depend on the user subtype - internal or domain.
Step 6. Send connection details
At this step, choose how to send the QR codes and links for installing the mobile management apps or device management profiles. You can choose one of the following options:
- Send a message to users' email addresses
Choose this option to send the connection details by email to the selected users. To install the app or a device management profile, the user needs to scan the QR code using the camera of the mobile device or open the link to the installation package.
These email addresses must be specified in the user account settings in Kaspersky Security Center.
If you want to send the connection details to an email address that is not specified in the user account settings in Kaspersky Security Center, select the Send a copy of the message to an alternate email address check box, and then specify the required email address. - Show QR codes and links after completing the wizard
Choose this option to scan the QR code with the camera of the mobile device or follow the link in the wizard.
Step 7. Confirm
At this step, check the mobile device connection details specified in the earlier steps, and then click Finish to confirm the operation.
Finish
On the Finish screen:
- If you chose the Send a message to users' email addresses option, the specified users will receive the emails with QR codes and links for connecting mobile devices to the Administration Server.
- If you chose the Show QR codes and links after completing the wizard option, the connection details will be available on the Finish screen. You can view the displayed details or click Download list to receive a file with summarized information.
Click Close to exit the wizard.
As soon as users install the mobile management apps, their devices are connected to the Administration Server and displayed on the Devices tab of Kaspersky Security Center Web Console.
You can now configure the settings for devices and mobile management apps using policies. You will also be able to send commands to mobile devices for data protection in case devices are lost or stolen.