Views:

Requirements

To integrate other MDM solutions with Trend Micro Mobile Security, you must use the following:

  • Mobile Security for Enterprise 9.8 SP3 or later
  • Local Communication Server or Cloud Communication Server configured in Mobile Security

Architecture

The following image shows the high-level architecture of integration with BlackBerry UEM.

TMMS Architecture

  • Mobile App Reputation Services (MARS)

    Mobile App Reputation is a cloud-based technology that automatically identifies mobile threats based on app behavior, crawls and collects huge number of Android apps from various Android markets, identifies existing and brand new mobile malware, and identifies apps that may abuse privacy or device resources. It is also the world’s first automatic mobile app evaluation service.

  • Smart Protection Network (SPN)

    Trend Micro Smart Protection Network delivers proactive global threat intelligence against zero-hour threats to ensure that you are always protected. We use our up-to-the-second threat intelligence immediately.

Basic Deployment

We need to have a BlackBerry UEM account to be used for the communication between the TMMS server and BlackBerry UEM. The user has been granted administrator access to the BlackBerry UEM management console.

Add a device in BlackBerry UEM and then enroll the device to BlackBerry UEM. TMMS will use the BlackBerry UEM agent to install mobile security agent for Android and iOS.

  1. Log on to the Mobile Security Administration web console.
  2. On the menu bar, click Administration and select Communication Server Settings. Make sure the Communication Server settings are configured.

    If the settings are not configured, refer to the topic Configuring Communication Server Settings in the Installation and Deployment Guide for the configuration steps.​

    Communication Server Settings

  3. Go to Administration > Deployment Settings.
  4. Under the Server tab, select Security Scan, and then select BlackBerry UEM as the MDM Solution from the drop down list.

    Select BlackBerry UEM

  5. Under Register Service, configure the following BlackBerry UEM settings:
    • API URL
    • SRP ID
    • Account Name (The account used in the integration feature should have BlackBerry UEM administrator role privilege.)
    • Password
    • Provider (It is recommended to use LOCAL provider.)

    Security Scan Settings

  6. Click Verify Settings to make sure Mobile Security can connect to the BlackBerry UEM server.
  7. Once the connection is verified, click Synchronize Now and click Save to update the data from BlackBerry UEM and save the settings in TMMS.

    Enable Data Synchronization

TMMS has two (2) Android agent versions. BlackBerry UEM administrator needs to choose one of the following versions:

  • Google Play version. Administrator needs to send an email to end-user with QR code or Enrollment Key. End-users need to open the TMMS agent and scan the QR code or manually enter the Enrollment Key to register the device to server. Agent can be updated automatically.
  • TMMS Server version. Administrator needs to send an email to end-user asking them to launch TMMS Agent. Once the end-user launched the TMMS Agent, it will register to TMMS server. When TMMS agent has new version, end-user needs to click the upgrade button in the notification bar.

Google Play Build

  1. Tick the Use preset Enrollment Key option for the application to be enrolled with this key.

    Use preset Enrollment Key

  2. Deploy BlackBerry UEM agent and launch it, then log on to BlackBerry UEM agent console.
  3. On the BlackBerry UEM web console, add Trend Micro Mobile Security from Google Play Store.
  4. On the BlackBerry UEM agent console, install Enterprise Mobile Security agent application.
  5. Launch the Mobile Security application, and then scan the QR code to enroll device to TMMS server. While doing a security scan and security issues are found, the information will be reported to the TMMS server.

    Security Scan Results

    Suspicious Applications

Local Server Build

  1. Tick the Use preset Enrollment Key option.

    Local server build enrollment key

  2. On the TMMS for Enterprise web console, go to Administration > Deployment Settings > Android Agent.
  3. Choose Download from Trend Micro Mobile Security server and tick Auto Enrollment.

    Auto Enrollment

  4. Click the Upload button to upload the TMMS application to BlackBerry UEM server.
  5. Find the application and schedule the deployment for TMMS Mobile Security. Once the application has been deployed, TMMS Mobile Security will do a scheduled scan for the devices.
  6. Launch the Mobile Security application on the end-user to enroll the device to the server. It also has real-time scan. When you install new application, TMMS will scan and report to server too.
  1. Log in to the BlackBerry UEM admin console and add Trend Micro Mobile Security from Apple Store under the Add Application page.
  2. Follow the wizard to set the deployment.
  3. On the Apple device, install BlackBerry UEM agent and enroll the device to BlackBerry UEM server.
  4. On the web console, configure the settings to deploy the mobile security application. Wait for the BlackBerry UEM application to install the mobile security agent.
  5. Once the application is installed on the Apple device, go to Deployment Settings page and click the Data Sync button. The device should now be available on the TMMS management console.
  6. Perform a scan on the device. If there are malwares found, it will be set to dangerous on TMMS Server console, TMMS will also do scheduled scan.

For more details, refer to Trend Micro Mobile Security 9.8 SP3 Administrator's Guide (Security Scan Deployment Mode, Chapter 3).