{"id":1863,"date":"2020-09-01T04:45:32","date_gmt":"2020-09-01T04:45:32","guid":{"rendered":"https:\/\/partnernews.sophos.com\/en-us\/?p=1863"},"modified":"2020-09-01T04:46:33","modified_gmt":"2020-09-01T04:46:33","slug":"remote-users-and-the-need-for-mobile-containerization","status":"publish","type":"post","link":"https:\/\/partnernews.sophos.com\/en-us\/2020\/09\/products\/remote-users-and-the-need-for-mobile-containerization\/","title":{"rendered":"Remote Users and the Need for Mobile Containerization"},"content":{"rendered":"<p>Perhaps unsurprisingly, over the last few months there\u2019s been a definite upsurge in the number of conversations I\u2019m having with customers and partners around end users wanting to use their personal devices for both home and work purposes, in a secure fashion and without risk of data loss.<\/p>\n<p>The need for this is likely further on the rise where individuals are tired of being locked up in back to back video conference meetings and may decide they want to mix up their day up a bit by answering emails on their phone during their daily walk, whilst also still having access to corporate apps and data. Obviously, the challenge for IT admins and MSPs when providing corporate access on personal devices is also providing security and integrity of company data. This is where Sophos Mobile can come into play and has some great containerisation capabilities which are worth a reminder!<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-1869 size-full\" src=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/image2-1.png\" alt=\"\" width=\"225\" height=\"225\" srcset=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/image2-1.png 225w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/image2-1.png?resize=150,150 150w\" sizes=\"auto, (max-width: 225px) 100vw, 225px\" \/> <img loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-1868 size-full\" src=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/Image-1-1.png\" alt=\"\" width=\"225\" height=\"225\" srcset=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/Image-1-1.png 225w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/Image-1-1.png?resize=150,150 150w\" sizes=\"auto, (max-width: 225px) 100vw, 225px\" \/><\/p>\n<p>The first form of containerisation we brought out in Sophos Mobile and perhaps the most well-known is our container apps \u201cSophos Secure Workspace\u201d and \u201cSophos Secure Email\u201d. These two apps are what are known as container apps and allow an organisation to only manage the data for those apps and not the rest of the phone. An overview of the features of these two apps <a href=\"https:\/\/www.sophos.com\/en-us\/medialibrary\/PDFs\/factsheets\/sophosmobilecontroldsna.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">can be found here<\/a>.<\/p>\n<p>A key benefit of these container apps is the provision of a simple and non-intrusive way of giving end users access to corporate data. The apps and sensitive data can swiftly be removed via Sophos Central by an admin or an end user that may have had the phone stolen from them for example. The other great feature is that these container apps provide is \u201cgeo-fencing\u201d and \u201cWIFI-fencing\u201d. This means the admin can define what geographical location the phone is required to access the corporate data on these apps, or what access points can be used when accessing corporate data.<\/p>\n<p>One of the main requirements around BYOD I often see, however, is for corporate email to only be accessed via a corporate app. This can also be achieved by the secure email app in conjunction with the Sophos EAS proxy and alterations made in O365 Exchange admin centre which I will explore further below.<\/p>\n<p>The Sophos container apps do have their limitations and to those of you who are new to Sophos Mobile, you may find yourselves wondering if it\u2019s possible to create a container area on the device and push corporate apps to devices rather than just the use of Sophos container apps. The answer to this is yes and this is where \u201cAndroid Enterprise Work Profiles\u201d come in to play.<\/p>\n<p>The two main methods of Android Enterprise enrolment are full device management and work profile management. The former is often the most well-known, as it\u2019s the main and current way we provide corporate management of devices. It provides full control and requires a factory reset to enrol the device in this way.<\/p>\n<p>AE Work Profile is sometimes overlooked since Sophos Container Only mode (Container Apps) is mistaken as the only way of providing containerisation and BYOD capabilities. AE Work profile sits nicely in the middle and provides a lot of the of functionality you would want in a BYOD deployment and does not require you to factory set your end user\u2019s personal device. Thank goodness!<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-1864 size-full\" src=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/Image-2-1.png\" alt=\"\" width=\"220\" height=\"391\" srcset=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/Image-2-1.png 220w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/Image-2-1.png?resize=169,300 169w\" sizes=\"auto, (max-width: 220px) 100vw, 220px\" \/> <img loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-1870 size-full\" src=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/image4.png\" alt=\"\" width=\"220\" height=\"391\" srcset=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/image4.png 220w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/image4.png?resize=169,300 169w\" sizes=\"auto, (max-width: 220px) 100vw, 220px\" \/><\/p>\n<p>The Android Enterprise Work Profile allows you to create a separate space on the Android device when running Android 5.0 and above. This enables you to use both the advantages of the Sophos Container apps, whilst also being able to control a portion of the end user\u2019s phone required for work purposes. The work profile is natively kept separate from the rest of the device. This means work data is not shared across to the personal part of the phone and corporate apps can be silently installed or just made available via the play store within the work profile.<\/p>\n<p>Play store apps can be prepopulated with company settings before being delivered to the device and there are further controls around stopping screenshots and clipboard share. There are also two device settings you have some control over. You can require that the device has an access pin and you can deploy Wi-Fi settings from Sophos Mobile.<\/p>\n<p>As with Sophos Container only mode you can also completely remote wipe this \u201cwork partition\u201d and leave the rest of the device untouched. The end user experience can vary slightly depending on firmware version, but the underlying technology functionality is the same. It is provided via the Android Enterprise API, which has incorporated the some of the KNOX capabilities into the base Android OS.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"framed-image alignnone wp-image-1865 size-full\" src=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/Image-3.png\" alt=\"\" width=\"640\" height=\"370\" srcset=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/Image-3.png 1642w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/Image-3.png?resize=300,174 300w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/Image-3.png?resize=768,444 768w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/Image-3.png?resize=1024,592 1024w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/Image-3.png?resize=1536,889 1536w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>End user Setup for any of the BYOD modes is the same and very simple. It is a case of getting the user to download the \u201cSophos Mobile Control App\u201d and scanning a QR code. This can be done via an email sent to the end user and\/or getting the them to login to the Sophos Central Self-Service Portal to enrol.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"framed-image alignnone wp-image-1866 size-full\" src=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/Image-4.png\" alt=\"\" width=\"640\" height=\"509\" srcset=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/Image-4.png 1226w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/Image-4.png?resize=300,239 300w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/Image-4.png?resize=768,611 768w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/Image-4.png?resize=1024,815 1024w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/p>\n<p>Lastly, the Sophos EAS proxy provides you with a way of telling your email server which mobile devices can receive corporate email. There is also an option to enforce that only the Sophos secure email app can receive corporate email. The EAS proxy works with a traditional on-premise mail server as a man in the middle, but there is also a powershell script that we have published. With some configuration in O365 Exchange admin centre this can also enable you to only allow emails sent to dynamically approved devices by Sophos Mobile.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"framed-image alignnone wp-image-1867 size-full\" src=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/Image-5.png\" alt=\"\" width=\"640\" height=\"526\" srcset=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/Image-5.png 1096w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/Image-5.png?resize=300,246 300w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/Image-5.png?resize=768,631 768w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/08\/Image-5.png?resize=1024,841 1024w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/p>\n<p>You will need an available server to act as the proxy; this can be hosted wherever you like.<\/p>\n<p>Setup documentation <a href=\"https:\/\/docs.sophos.com\/central\/Mobile\/help\/en-us\/esg\/Sophos-Mobile\/tasks\/InstallExtProxy.html\" target=\"_blank\" rel=\"noopener noreferrer\">can be found here<\/a>.<\/p>\n<p>If you want to get it to work with O365 there are some <a href=\"https:\/\/community.sophos.com\/kb\/en-us\/125890\" target=\"_blank\" rel=\"noopener noreferrer\">additional steps listed here<\/a>.<\/p>\n<p>In summary, Sophos Mobile can really enable your customers to be more flexible with the way they work. It can help you fulfill the BYOD and security requirements you&#8217;re getting from customers and it can be managed alongside all their other Sophos Security products.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Perhaps unsurprisingly, over the last few months there\u2019s been a definite upsurge in the number of conversations I\u2019m having with customers and partners around end users wanting to use their personal devices for both home and work purposes, in a [&hellip;]<\/p>\n","protected":false},"author":57,"featured_media":1190,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[2],"tags":[33,16],"coauthors":[65],"class_list":["post-1863","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-products","tag-sophos-mobile","tag-technical-news"],"jetpack_featured_media_url":"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/04\/featured-image-UKI-tech-update-Partner-app-icon-1600x960-1.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/posts\/1863","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/users\/57"}],"replies":[{"embeddable":true,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/comments?post=1863"}],"version-history":[{"count":12,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/posts\/1863\/revisions"}],"predecessor-version":[{"id":1906,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/posts\/1863\/revisions\/1906"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/media\/1190"}],"wp:attachment":[{"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/media?parent=1863"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/categories?post=1863"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/tags?post=1863"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/coauthors?post=1863"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}