Smishing, also known as SMS-based Phishing, is a social engineering attack that uses text messages (SMS, MMS, RCS) to deceive recipients into revealing sensitive personal or financial information, downloading malware, or sending money to cybercriminals.
Workspace ONE Mobile Threat Defense can detect smishing text messages and warn users to use caution (Android, iOS). Mobile Threat Defense can also prevent users from accessing the link by moving it to a junk filter (iOS only). Smishing Protection proactively alerts end users regarding the following:
- Malicious URLs attempting to deliver malicious software or codes to devices.
- Phishing URLs attempting to phish for sensitive information or credentials.
Workspace ONE Mobile Threat Defense notifies users if any of these text message types are detected and provides choices as to what they can do to protect themselves. As the administrator, you can configure these choices. Note that if Phishing and Content Protection is also activated, users are protected if they click on the URLs.
Smishing Protections requires the Lookout for Work application to be installed on end-user devices. When deployed, Lookout for Work performs all Mobile Threat Defense (MTD) functions on the device. As a result, Workspace ONE MTD is disabled within Intelligent Hub, while Intelligent Hub remains installed and continues to provide all non-MTD features and functionality.
Enabling Smishing Protections
-
In the Workspace ONE Mobile Threat Defense console, navigate to Protections and click the Smishing tab.
-
Choose the Device Policy Group for which you want to enable Smishing or use the default group to copy settings to multiple groups.
-
Slide the Enable Smishing toggle to ON.
-
Set Phishing and Malicious content settings as needed:
- Enable the Content Type. Slide the toggle to ON. This enables the feature to scan messages and generate threat notifications in the Workspace ONE Mobile Threat Defense Console.
- Enable iOS Message filtering. Slide the toggle to ON. This filters messages to junk folders on iOS devices (Android devices only receive alerts).
- Enable Alert Device. Slide the toggle to ON. This sends alerts to end-user devices.
- Set Custom Message (Optional): Enter an appropriate alert message to send if that content type is detected.
-
For Android devices only, administrators can enable the Smishing Permissions Not Accepted policy in the Protections module to detect when users have not accepted the permissions required.
How to Enable Smishing on iOS Devices
This feature requires the Lookout for Work (iOS) application to function as the Workspace ONE Mobile Threat Defense (MTD) agent on the device. Deploy the application to the required devices along with the managed app configuration needed to activate Workspace ONE MTD.
Before deploying and activating MTD in the Lookout for Work application, ensure that Workspace ONE MTD is disabled in Intelligent Hub.
Deploying the Lookout for Work Application
- Perform the steps in Deploy Public Applications on your Devices to deploy the Lookout for Work public application with Workspace ONE UEM.
- Select Auto as the App Delivery Method in the Assignments configuration
- In the left sidebar of the Assignments configuration, click Application Configuration, enable the Managed Access and Send Configuration toggles. Enter the following configuration keys:
| Configuration Key | Value Type | Configuration Value |
|---|---|---|
| DEVICE_UDID | String | {DeviceUid} |
| MDM | String | AIRWATCH |
| String | {EmailAddress} | |
| GLOBAL_ENROLLMENT_CODE | String | Enter the alphanumeric Enrollment Code for the relevant device policy group in your WS1 MTD Console or the Global Enrollment Code in System > Accounts. |
- Save and Publish the Assignment.
Required End-User Actions
When Workspace ONE MTD is activated and Smishing Protection is enabled, end users must grant specific permissions on their iOS devices for the feature to function. Due to iOS privacy requirements, these permissions must be granted manually by the user and cannot be enforced through device management.
Users receive a one-time prompt to configure Lookout as the SMS Filtering provider.
-
Navigate to Message Settings:
a. On iOS versions prior to iOS 18, navigate to Device Settings > Apps (iOS 18+) > Messages > Unknown & Spam. b. On iOS versions 18+, navigate to Settings > Apps > Messages > Unknown & Spam. c. On iOS versions 26+, navigate to Settings > Apps > Messages > Scroll to Unknown Senders.
-
Toggle Filter Unknown Senders to ON.
a. On iOS versions 18 and under, toggle Filter Unknown Senders to ON. b. On iOS versions 26+, toggle Filter Spam to OFF so that Lookout will be your spam filter. i. Toggle on Screen Unknown Senders. ii. Tap on Text Message Filter.
-
Select Lookout Work.
Note: Scanning is applied only to messages from unknown senders. Messages from saved contacts, or from numbers the user has replied to at least three times, are considered known by iOS and are not scanned.
How to Enable Smishing on Android Devices
This feature requires the Lookout for Work (Android) application to function as the Workspace ONE Mobile Threat Defense (MTD) agent on the device. Deploy the application to the applicable devices along with the managed app configuration required to activate Workspace ONE MTD.
Before deploying and activating MTD in the Lookout for Work application, ensure that Workspace ONE MTD is disabled in Intelligent Hub. For Android devices configured with both Work and Personal profiles, enable Dual Enrollment to activate MTD in the Personal Profile, where the SMS or text messaging application resides.
Deploying the Lookout for Work Application
- Perform the steps in Deploy Public Applications on your Devices to deploy the Lookout for Work public application with Workspace ONE UEM.
- Select Auto as the App Delivery Method in the Assignments configuration
- In the left sidebar of the Assignments configuration, click Application Configuration, enable the Managed Access and Send Configuration toggles. Enter the following configuration keys:
| Configuration Key | Value Type | Configuration Value |
|---|---|---|
| MDM name | String | AIRWATCH |
| MDM Device ID | String | {DeviceUid} |
| Global Enrollment Code | String | Enter the alphanumeric Enrollment Code for the relevant device policy group in your WS1 MTD Console or the Global Enrollment Code in System > Accounts. |
| Dual Enrollment | String | False unless using Dual Enrollment . |
| HSM Key Value | Boolean | False |
- Save and Publish the Assignment.
Required End-User Actions
When Workspace ONE MTD is activated and Smishing Protection is enabled, end users must accept specific permissions for Lookout to read SMS text messages and to read contacts.
-
Tap the notification as indicated and follow the prompts to get started.
-
Perform either of the following steps:
a. Navigate to Device Settings > Apps > Lookout for Work. b. Select Contacts permission and SMS permission, and tap Allow for both. This allows Lookout to scan SMS messages from unknown senders (any contact you have not saved in the contact list).
War diese Seite hilfreich?