Deploy agent via Microsoft Intune

This section explains how to deploy Forcepoint Mobile Endpoint Agent to Android devices using Microsoft Intune. These steps include adding the application and provisioning devices with an app configuration policy.

Note: Forcepoint has validated the steps below using Microsoft Intune. While similar configurations may be possible with other MDM solutions, Forcepoint has not verified them.

Steps

  1. Step 1: Configure Mobile Endpoint Agent application.
    1. Sign in to the Microsoft Intune admin center.
    2. Navigate to Apps > Android > +Create. The Select app type pane opens.
    3. From the Category dropdown, select Store app, then select the Managed Google Play app radio button. Click Select.
    4. On the Managed Google Play page, search for and select the Forcepoint Mobile, then click Select.
    5. Navigate to the Apps > Platforms > Android, open the Forcepoint Mobile application you created, then select Properties.
    6. In the Assignments section, click Edit.
    7. On the Assignment tab, under the Required section, choose groups that will have the solution force installed. This can be a user group, device group, all users, or all devices. Then click Next.
    8. On the Review + create tab, verify your settings, then click Create. The application uploads and becomes available to your selected groups.
  2. Step 2: Configure the App Configuration policy.
    1. Navigate to Apps > Configuration > +Create > Managed devices.
    2. On the Basics tab, enter the following properties:
      Table 1.
      Key Value
      Name Enter a name that identifies the profile. Use a descriptive name so you can easily recognize it later.
      Description Enter a description for the profile (optional).
      Platform Select Android Enterprise.
      Profile Type Select Fully Managed, Dedicated, and Corporate-Owned Work Profile Only.
      Note: The profile type selection shown here is an example based on enrollment type. Select the profile type that corresponds to your device enrollment configuration.
      Targeted app Select the Forcepoint Mobile application you created in Step 1.

    3. On the Settings tab, select Use configuration designer from the Configuration Settings dropdown. Add and configure the following settings from the Global Settings page in the Forcepoint Data Security Cloud portal.

      Before entering values, navigate to Endpoint Management > Mobile Endpoint Agent > Global Settings in the Forcepoint Data Security Cloud portal and copy these values:

      Table 2.
      Configuration key Value
      FP_BACKEND Enter the Registration URL.
      FP_INSTALLER_KEY Enter the Installer Key.
      FP_DS_TENANT_ID In the portal, select User profile icon > User profile > Profile Information. Enter the TENANT ID.
      FP_USER_NAME Enter the {{UserPrincipalName}}.
      FP_SENTRY_DSN Enter the Logging URL.
      FP_SKIP_STARTUP_SCREEN
      • Select true to enable auto-start, allowing the application to launch automatically.
        Note: For Android devices, the user needs to accept the VPN permission before the app can start the VPN service.
      • Select false to display the End-User License Agreement (EULA) screen. Users must read and accept the EULA before proceeding to use the application.

      For more details about these fields, see the Global Settings page.

    4. On the Assignments tab, under the Included groups select the same groups that received the application in Step 1.g. This can be a user group, device group, all users, or all devices. Then click Next.
      Note: The groups included here should be the same as the groups assigned to the application in Step 1.g.
    5. On the Review + create tab, verify your settings, then click Create. Your changes are saved, the profile is assigned, and it appears in the profiles list.

Result

After completing all configuration steps, Microsoft Intune initiates deployment of the Mobile Endpoint Agent to the assigned devices.