Deploy agent via Microsoft Intune
This section explains how to deploy Forcepoint Mobile Endpoint Agent to Android devices using Microsoft Intune. These steps include adding the application, provisioning devices with app configuration policy, and deploying the Forcepoint CA certificate.
Steps
-
Step 1: Configure Mobile Endpoint Agent application.
- Sign in to the Microsoft Intune admin center.
- Navigate to Apps > Android > +Create. The Select app type pane opens.
-
From the Category dropdown, select Store app, then select the Managed Google Play app radio button.
Click Select.

-
On the Managed Google Play page, search for and select the Forcepoint Mobile, then click
Select.

-
Click Sync to synchronize the managed Google Play apps with Microsoft Intune, then refresh the Android Apps
page. The Forcepoint Mobile application now appears in the apps list.
Note: After you click Select in the previous step, the application does not appear in the list immediately. You must click Sync and refresh the page for it to appear. This may take about 2–3 minutes.
- Navigate to the Apps > Platform > Android page, open the Forcepoint Mobile application you created, then select Properties.
-
In the Assignments section, click Edit.

-
On the Assignment tab, choose the groups for each assignment type, then click Next.
- Under the Required section, choose groups that will have the solution force-installed.
- Under the Available for enrolled devices section, choose groups for which the solution will be available in the managed Google Play store.
Each section can include a user group, device group, all users, or all devices.
- On the Review + create tab, verify your settings, then click Create. The application uploads and becomes available to your selected groups.
-
Step 2: Configure the App Configuration policy.
- Navigate to Apps > Configuration > +Create > Managed devices.
-
On the Basics tab, enter the following properties:
Table 1. Key Value Name Enter a name that identifies the profile. Use a descriptive name so you can easily recognize it later. Description Enter a description for the profile (optional). Platform Select Android Enterprise. Profile Type Select Fully Managed, Dedicated, and Corporate-Owned Work Profile Only. Note: The profile type selection shown here is an example based on enrollment type. Select the profile type that corresponds to your device enrollment configuration.Targeted app Select the Forcepoint Mobile application you created in Step 1. 
-
On the Settings tab, select Use configuration designer from the Configuration Settings dropdown. Add
and configure the following settings from the Global Settings page in the Forcepoint Data Security Cloud portal.
Before entering values, navigate to Endpoint Management > Mobile Endpoint Agent > Global Settings in the Forcepoint Data Security Cloud portal and copy these values:

Table 2. Configuration key Value FP_BACKEND Enter the Registration URL. FP_INSTALLER_KEY Enter the Installer Key. FP_DS_TENANT_ID In the portal, select User profile icon > User profile > Profile Information. Enter the TENANT ID. FP_USER_NAME Enter the {{UserPrincipalName}}. FP_SENTRY_DSN Enter the Logging URL. FP_SKIP_STARTUP_SCREEN - Select true to enable auto-start, allowing the application to launch automatically.Note: For Android devices, the user needs to accept the VPN permission before the app can start the VPN service.
- Select false to display the End-User License Agreement (EULA) screen. Users must read and accept the EULA before proceeding to use the application.

For more details about these fields, see the Global Settings page.
- Select true to enable auto-start, allowing the application to launch automatically.
-
On the Assignments tab, under the Included groups select the same groups that received the application in Step 1.h. This can
be a user group, device group, all users, or all devices. Then click Next.
Note: The groups included here should be the same as the groups assigned to the application in Step 1.h.
- On the Review + create tab, verify your settings, then click Create. Your changes are saved, the profile is assigned, and it appears in the profiles list.
-
Step 3: Configure the Forcepoint CA certificate.
- Navigate to Devices > Android > Configuration > +Create > New Policy.
-
Select the following options, then click Create:
- Platform: Select Android Enterprise.
- Profile type: Select Templates.
- Template name: Select Trusted certificate.
-
On the Basics tab, enter the following properties, then click Next:
- Name: Enter a descriptive name for the profile so you can easily identify it later.
- Description: Enter a description for the profile (optional).
-
On the Configuration settings tab, click the folder icon, browse to the Forcepoint CA certificate (.cer) file, then click
Upload.
To obtain the certificate, go to Endpoint Management > Mobile Endpoint Agent > Global Settings > Download Forcepoint CA Certificate in the Forcepoint Data Security Cloud portal.

For more details, see the Global Settings page.
- On the Assignments tab, under Included groups, choose the groups that will have the certificate force-installed. This can be a user group, device group, all users, or all devices. Then click Next.
- On the Review + create tab, verify your settings, then click Create. Your changes are saved, the profile is assigned, and the policy appears in the profiles list.