Skip to main content

20 augustus 2026

Integrate Mobile Threat Defense with Workspace ONE UEM Using Smart Groups

Workspace ONE UEM SaaS and dedicated SaaS environments can use the smart group approach to supply the targeted devices with Mobile Threat Defense protections. It does not matter which organization group (OG) the device is managed from, so long as they are included in the MTD smart group, then the configuration for MTD activation is applied to the smart group and Mobile Threat Defense becomes activated on all devices in that smart group.

If you are in an on-premises environment, the best practice is to integrate MTD with UEM using organization groups.

In the past, if you have already integrated Workspace ONE UEM with Mobile Threat Defense per the organization group method and are moving to this smart group method, you can skip directly to step 4.

Prerequisites

  • Requires Workspace ONE UEM version 2406 or later with “modern architecture” services enabled.
  • Dual Enrollment requires Workspace ONE UEM version 2410 or later.
  • Requires Omnissa Workspace ONE Intelligent Hub version 24.09 or later from the Apple and Google Play Stores for iOS and Android devices respectively.

STEP 1 Create an API Role for Your Admin Service Account

  1. Log in to the Workspace ONE UEM console using your administrator account.

  2. Navigate to Accounts > Administrators > Roles.

  3. Select the Add Role button. The Create Role page displays.

  4. Enter the role name MTD_API_Admin and a description.

  5. Under the Categories column to the left, expand API and select Rest. Enable the Read check boxes for each of the following permissions.

    • Admins
    • Apps
    • Devices
    • Groups
    • Users

    this screenshot shows the Create Role screen with all the REST API permissions selected for the Mobile Threat Defense admin role.

  6. Under the Categories column to the left, expand Device Management and select Bulk Management. Enable the Edit check box for the Bulk Management permission.

    this screenshot shows the Create Role screen with the bulk management permission selected for the Mobile Threat Defense admin role.

  7. Under the Categories column to the left, scroll down and expand Settings, then select Tags and enable the Edit check box for the Tags permission.

    this screenshot shows the Create Role screen with the tags permission selected for the Mobile Threat Defense admin role.

  8. Select the Save button to save the role.

  9. Navigate to Accounts > Administrators > List View.\

  10. Select the Add button and select Add Admin. The Add/Edit Admin page displays.

  11. On the Basic tab, enter the Username and values for all other required (*) fields for this Mobile Threat Defense admin.

  12. Switch to the Roles tab and select the Select Role text box. In the drop down menu that displays, scroll down to the role you created earlier, MTD_API_Admin

  13. In the Select Organization Group field, select the name of the organization group you created in the previous step.

  14. Select Save to assign the role to the admin.

STEP 2 Create an API Key

  1. Log in to the Workspace ONE UEM console using your administrator account.
  2. Navigate to Groups & Settings > All Settings > System > Advanced > API > REST API. The REST API configuration page displays.
  3. For the Enable API Access option, select Enabled.
  4. Select the Add button. A blank key entry displays at the bottom of the listing. Add the Service Name WS1-MTD with an Account Type of Admin. This generates an API key which is used to configure the Workspace ONE Mobile Threat Defense console.
  5. Select the generated key from the API Key text box for WS1-MTD.
  6. Copy the key to clipboard with Ctrl-C (on Windows) or Command-C (on macOS). This key will be pasted later in this workflow.
  7. Select Save.

STEP 3 Create the Device Tags

The Workspace ONE UEM feature, Device Tags, is used extensively in Mobile Threat Defense. Take the following steps to create your device tags.

  1. Navigate to Groups & Settings > All Settings > Devices & Users > Advanced > Tags.

  2. Select Create Tag. The Create Tag dialog displays.

  3. In the Name text box, enter the Tag Name from the table.

    Tag NameDescription
    MTD - ActivatedActivated devices
    MTD - DeactivatedDeactivated devices
    MTD - DisconnectedDevices that have lost connectivity with Mobile Threat Defense
    MTD - PendingDevices that have not activated Mobile Threat Defense yet
    MTD - UnreachableDevices that are unreachable by Mobile Threat Defense
    MTD - Threats PresentCompromised devices
    MTD - SecuredSecured devices
    MTD - Low RiskLow risk devices
    MTD - Medium RiskMedium risk devices
    MTD - High RiskHigh risk devices
  4. Select Save.

  5. Repeat Steps 2-4 to create each tag from the table.

You can also make customized tags based on specific threats such as "Denylisted App", "PCP Disabled", and any other customized tag you want. When you reach STEP 5 Set Up Workspace ONE Mobile Threat Defense Console, you can assign these customized tags to their own Risk Classification in the State Sync section of the MTD Console.

STEP 4 Create Smart Group Used for Device Sync

The smart group you make here must include all the devices you want to protect with mobile threat defense.

  1. Navigate to Groups & Settings > Groups > Assignment Groups.
  2. Select the Add Smart Group button. The Create New Smart Group screen displays.
  3. In the Name text box, enter a name for the smart group, such as Devices in Customer OG.
  4. Select which devices belong in the smart group by taking one or both of the following steps.
    1. In the Organization Group section, the name of the OG you are currently in displays. Enable this check box to include all devices in this OG for the smart group. All devices in this OG will be protected with MTD provided you apply the MTD Custom Settings referenced in substep 18 of the next step, STEP 5 Set Up Workspace ONE Mobile Threat Defense Console
    2. Optionally, in addition to the OG you selected, select the User Group section and Add user groups. This action includes all the devices in these user groups in the Mobile Threat Defense smart group.
  5. You can include or exclude devices by filling out the Additions and Exclusions sections. For more information, see Create a Smart Group
  6. Select Save.

STEP 5 Set Up Workspace ONE Mobile Threat Defense Console

  1. Log in to the Mobile Threat Defense console.

    Navigate to https://omnissa.lookout.com (SSO enabled) or https://omnissa.lookout.com/a/ (bypassing SSO). An MTD tenant is provisioned at the time of MTD purchase and your designated contact person is created as an admin. You can select Forgot Password on the login page to reset your password. Once you are logged into the MTD console, you can create additional administrators by navigating to System > Manage Admins > Add Admin.

  2. In the left panel, select Integrations.

  3. Under Choose a product to set up, select the Workspace ONE button.

  4. Under Connector Settings, complete the following options.

    SettingDescription
    Label for this MDM connectionThis optional entry identifies and differentiates between all your integrations.
    Workspace ONE URLEnter your Workspace ONE server URL, for example, https://asXXXX.awmdm.com
    API TokenPaste the API Key you copied in the Create an API Key step. Ctrl-V (for Windows) and Command-V (for macOS).
    AuthenticationCertificate Authentication (Recommended): Upload a Workspace ONE UEM certificate and select a passphrase.

    Basic Authentication: Enter the same username and password as the admin to which you assigned the MTD_API_Admin in step 1. If you select Basic Authentication, you must update the connector configuration each time the API admin's password expires.
    The alternative to this limitation is to set the API Admin password to never expire.
    Configure this setting in Workspace ONE UEM by navigating to Accounts > Administrators > List View, find the admin in the listing, select the Edit (this edit icon is in the shape of a pencil) icon, in the Basic tab of the Add/Edit Admin screen, set the Require password change at next login option to Disabled.
  5. Select Create Integration in the top-right corner. A banner notification displays indicating a successful integration and additional sections display.

  6. Scroll down to the Enrollment Management section and complete the following options.

    SettingDescription
    Automatically drive Lookout for Work enrollment on Workspace ONE managed devicesSet to ON.
    Use the following Workspace ONE smart groups to identify devices that should be enrolled in Lookout for Work:Select the smart group you created in step 4.
    How often should Lookout check for new devices?Set to 5 to sync newly enrolled devices and unenrolled devices from UEM every 5 minutes.
    Automatically send activation emails to Workspace ONE managed devicesSet to OFF. For an MDM integration, you should drive enrollment through your MDM, not via Mobile Threat Defense Console invitation emails.
    Delete device on unenrollmentSet to ON to delete devices in Mobile Threat Defense when they are unenrolled from Workspace ONE UEM.
  7. Scroll down to the State Sync section and enable the option Synchronize device status to Workspace ONE.

    This screenshot shows the State Sync section of the MTD Console where you can configure all the risks and their corresponding UEM tags.

  8. Select and assign the tags you created in STEP 3 Create the Device Tags, per the following table. If you opt not to synchronize a specific device state to Workspace ONE, then leave the corresponding toggle off/null.

    OptionValue
    Device Status:
    Devices that have not activated Mobile Threat Defense yetMTD - Pending
    Devices with Mobile Threat Defense activatedMTD - Activated
    Devices with Mobile Threat Defense deactivatedMTD - Deactivated
    Connection Status:
    Devices that are unreachable by MTDMTD - Unreachable
    Devices that have lost connectivity with MTDMTD - Disconnected
    Risk Status:
    Devices with any issues presentMTD - Threats Present
    Devices with low risk issues presentMTD - Low Risk
    Devices with medium risk issues presentMTD - Moderate Risk
    Devices with high risk issues presentMTD - High Risk
    Devices with no issues presentMTD - Secured
    Risk Classification:(optional) add your customized Risk Classifications and assign them to specific custom tags you created in STEP 3, enable or disable them per your preferences.

    Please note that the following are EXAMPLE Risk Classifications and are not required. They are meant to demonstrate that you can make any device tag with any label you want.
    ClassificationTag
    Denylisted AppMTD - Denylisted App
    Phishing and Content Protection DisabledMTD - PCP Disabled
  9. Scroll down to the Error Management section and enter an email address to which errors are reported.

  10. Scroll up and select Save Changes in the top-right corner. You can review connector settings from the Integrations at any time.

  11. You can configure different Workspace ONE Mobile Threat Defense protection policies for different sets of devices by having different Workspace ONE MTD policy groups for each MTD assignment. You must create at least one device policy group in the Workspace ONE Mobile Threat Defense console and enter the Enrollment Code for the device policy group in the applicable MTD assignment. Creating multiple policy groups is optional. Follow the below substeps to create a policy group in the MTD Console.

    a. In the Mobile Threat Defense Console, navigate to Devices > Device Policy Groups. You can see the Default Group in the listing. This is the policy group that each device is assigned to by default.

    b. To create a new policy group, select the Create Group button to the right. The Create a new group screen displays.

    c. Enter the Name and Description of the new group.

    d. Select the Create Group button. The Device Policy Groups list view displays featuring your new group in the listing.

    e. Hover your pointer over the new group and select the View Protections link, which takes you to the Protections panel. When you create a new group, all enabled protections are inherited from the Default Group.

    f. You can customize Policies; change the risk levels, change the response, disable selected policies, enable others, and so forth.

    g. You can even customize the Alert device messages received by device end users when their device is placed in harm’s way.

    h. You can customize Phishing and Content Protection; change deployment types, change mandate levels, add domains, change allowlists, and denylists.

    i. (OPTIONAL) If you want to create multiple policy groups, then for each policy group you want to create, repeat steps b. through h. as needed.

    j. While still logged into the Mobile Threat Defense console, navigate to Devices > Device Policy Groups, then select and copy the enrollment code (Ctrl-C in Windows, Command-C in macOS). Each policy group in the listing has its own unique enrollment code. Enter the enrollment code for the device policy group in the MTD assignment configuration for the smart groups where you want these threat policies assigned to.

  12. Configure custom messages per policy group or accept the default custom message. You can configure a custom notification message that appears to your device end users if their device comes under attack. You can configure this custom message for selected policies or you can accept the default custom message.

    a. Navigate to the Protections main menu item and then the Policies tab.

    b. Select the Default custom message link to review the existing default message and to make changes per your preferences. This verbatim message displays to users for each policy violation that is set to inherit the default parent message.

    c. If you do not want to use the same message, you can create a customized message tailored for each policy. Do this by selecting the message button next to the Alert device response for the policy you want to target, clearing the check from the Inherit parent custom message checkbox, then drafting your own policy-specific message.

    This partial screenshot shows the policy listing of the MTD Console showing how you can customize the alert message users recieve when their device is attacked.

    d. If you prefer, you can also use the default parent custom message. Opt for this by enabling the Inherit parent custom message checkbox.

    This screenshot shows the customize messaging panel, where you can either customize your own policy-specific message or inherit the parent custom message.

    e. Select Save when you are finished with your messaging customizations. Note that custom message settings might take up to 24 hours after saving before they start displaying on the device. f. This custom message is presented to the user in the threat's details page in the Intelligent Hub app whenever the specified policy is violated.

    This screenshot shows the custom Alert device message that the end user sees when their device is protected from an attack.

STEP 6 Deploy the Workspace ONE Intelligent Hub App

Follow this step only if you have devices that lack the Workspace ONE Intelligent Hub app.

  1. For all devices you intend to protect with Workspace ONE Mobile Threat Defense, whether you want the Phishing and Content Protection option or not, direct your end users to the following website using their device.

    https://getwsone.com/

  2. Direct end users to download and install this app. When the end user selects the above link from their device, the resulting website checks to see what kind of device it is. The website then supplies the correct installer for that device. For a mobile device like iOS or Android, the app installation process is no different than any other app installation process.

STEP 7 Deploy Workspace ONE Mobile Threat Defense by Smart Group

  1. In Workspace ONE UEM, navigate to Groups & Settings > Configurations

  2. From the listing that displays, locate and select Workspace ONE Mobile Threat Defense.

  3. Select the Edit Assignments button. If you created an MTD assignment in the past, then you can edit those assignments here and change their priority.

    This partial screenshot shows the new MTD assignment screen

  4. Select the Add Assignment button. A new screen titled New MTD Assignment displays.

    This partial screenshot shows the new MTD assignment screen with a filled out Assignment details tab

  5. Under the Assignment details tab, enter Assignment Name, Description, then select the Assignment Groups or smart groups, that you want the MTD configuration assigned to. Select Next.

    This partial screenshot shows the new MTD assignment screen with a filled out MTD Configuration tab

  6. Under the MTD Configuration tab, expand the MTD configuration payload.

    • Toggle the Enable Mobile Threat Defense slider to the on position if it is currently OFF.

    • (Optional) If you want to implement dual enrollment, then activate the Enable Dual Enrollment slider. Dual Enrollment is supported within smart group integrations ONLY with Workspace ONE UEM version 2410 or later.

    Note: To activate MTD on your devices, ensure you enter the complete enrollment code in the MTD configuration within Workspace ONE UEM. The complete code includes the hyphen and any suffixes, such as EU or US.

  7. Select the device to view the device details and observe the risk-threat status for both the work profile and personal profile.

  8. As the administrator, you can create tags in Workspace ONE UEM to be applied to the device based on the MTD activation and/or risk status in the work and personal profiles. Accomplish this by taking the following steps.

    1. Create the relevant tags in Workspace ONE UEM (for example, MTD-Pending-Personal Profile, MTD-High-Risk-Personal-Profile).
    2. Navigate to the relevant UEM MDM connector in the Integrations page in the Workspace ONE MTD console and enable the option to synchronize advanced details from users’ work and personal profile under State Sync.
    3. This action enables the tabs for Work Profile and Personal Profile. Enable the required status and use the dropdown to select the relevant tags created in Workspace ONE UEM.
  9. Select the Create Assignment button. The MTD Assignment listing displays.

    This partial screenshot shows the MTD assignment overview screen with all the saved assignments

  10. Select the Publish button.

  11. Navigate to your top-level customer OG or the OG from which all your mobile devices are located that you want MTD to be activated. At this OG level, navigate to Groups & Settings > All Settings > Apps > Settings and Policies > Settings.

  12. Enable Override if settings are unavailable.

  13. In the Custom Settings text box, insert the below JSON code.

{
   "mtdSettings":{    
         "isEntitled":true
   }
}

STEP 8 (Optional) End User Enablement for Dual Enrollment

This last step is for the device end user to execute.

  1. An Intelligent Hub notification displays on the end uer's device to activate Workspace ONE MTD in their personal profile. They also see an info icon alerting them of the same in the device details page in Intelligent Hub.
  2. The end user must select the Dual Enrollment information icon or select the Enroll for Personal Profile tab to display the steps to activate MTD in the personal profile. The end user should read and follow these steps.
  3. The end user must copy to clipboard the activation code that displays. This activation code is required to complete Dual Enrollment. If copy and paste restrictions are enabled on their device, then direct them to write it down and enter the code manually when prompted.
  4. In the personal profile, they must launch the Google Play Store and download Lookout for Work (https://play.google.com/store/apps/details?id=com.lookout.enterprise).
  5. Direct them to launch the application and paste the activation code copied from Intelligent Hub (or input the code manually). This activates Lookout for Work.
  6. Ask the end user to accept the terms & conditions and required permissions for Mobile Threat Defense.
  7. Follow the prompts and steps provided to enable phishing and content protection in the personal profile.
    • Devices configured for Dual Enrollment reflect an overall pending status in the Workspace ONE Mobile Threat Defense console until MTD is activated in both the work and personal profile.
    • In the device details page, the work profile displays as Activated, and the personal profile displays as Pending until the activation is complete in the personal profile.
    • The MTD console displays a higher risk level between the work profile and personal profile in the Devices overview page.

.

Next Steps

If you want to implement the optional phishing and content protections, then proceed to Configure Phishing and Content Protections in the MTD Console.

Otherwise, the integration is complete. You may also want to review these topics.

Was deze pagina nuttig?

Feedback geven over dit onderwerp

Was dit onderwerp nuttig?

Vermeld geen persoonlijke of vertrouwelijke informatie.

Link genereren…