Distribute the mobile client with Microsoft Intune
Before you begin:
Make sure that your organization has an Intune management account with administrator privileges. An administrator needs the Intune management role.
Complete these steps to distribute the ETP mobile client to iOS and Android devices with Microsoft Intune.
To distribute the mobile client with Microsoft Intune:
- Add the mobile client to Microsoft Intune from the app store.
- Create a configuration profile for each device OS:
- Configure custom app configuration values:
- Enroll devices:
- Enroll Android devices. See Microsoft Intune documentation.
- Enroll iOS and iPadOS devices. See Microsoft Intune documentation.
Add the mobile client for Android devices to Microsoft Intune
Complete this procedure to add the ETP mobile client from the Google Play store to Microsoft Intune. After you add the app to Intune and assign it to users as detailed in this procedure, it is automatically deployed to your enrolled devices.
To add the mobile client for Android devices to Microsoft Intune:
-
Log in to Microsoft Endpoint Manager admin center.
-
In the navigation menu, click Apps.
-
In the Apps overview menu, select Android as the platform.
-
Click +Add.
-
In the Select app type window that appears, do one of the following:
- To access the app through the public Google Play store, select Android store app.
- To access a Google Play store that is private and specific to your organization, select Manage Google Play app.
-
Click Select.
-
If you selected to add an Android store app:
- Navigate to the Google Play store and search for the ETP Client app. Take note of the app details.
- In the App information page, add the app details for the ETP Client app. Make sure you provide the URL for the app in the Appstore URL field.
- Click Next.
- Click Next until you reach the Assignments page. If you want to add groups, see Add groups to organize users and devices.
- Click Next. Review the details on the Review + Create page.
- Click Create.
-
If you selected to add a Managed Google Play app:
- If you haven’t done so already, connect your Managed Google Play developer account to Intune. For instructions, see Connect your Intune account to your Managed Google Play Account.
- Search for ETP Client in the Google Play Store and click the app.
- On the page that displays, click Approve.
- Click Approve to access the permissions.
- Select Keep approved when app requests new permissions in the Approval Settings tab.
- Click Done.
-
If you created a Managed Google Play app, perform these additional steps to synchronize your app with the Google Play store:
- In the navigation menu, select Tenant administration > Connectors and tokens > Managed Google Play.
- Navigate to the bottom of the page and click Save + Sync. It may take a few minutes to sync. Refresh the page and check if the Last sync time updated.
Next steps
Create a configuration profile for Android.
Add the mobile client for iOS and iPadOS devices to Microsoft Intune
Complete this procedure to add the mobile client for iOS and iPadOS devices to Microsoft Intune. After you add the app to Intune and assign it to users as detailed in this procedure, it's automatically deployed to enrolled devices.
To add the mobile client for iOS and iPadOS device to Microsoft Intune:
-
Log in to Microsoft Intune admin center.
-
In the navigation menu, click Apps.
-
In the Apps overview menu, select iOS/iPadOS as the platform.
-
Click +Add.
-
Select the app from either the iOS store or from an iOS app package (.ipa) file that you have.
-
If you want to select an app from the iOS App store:
- In the App type menu, select iOS store app, and click Select.
- Click Search the App Store and search for the ETP Client app.
- Add or change any app information and then click Next.
- In the Required section, add users and groups. Click Next.
- Review the app information and click Create to add the app to Intune.
-
If you are uploading an iOS app package (.ipa) file:
- In the App type menu, select Line-of-business app.
- Search for the .ipa file and select it.
- Add or change any of the app information and click Next.
- In the Assignments area, add users and groups, and click Next.
For more information on associating the app to users, groups, and devices, see Microsoft Intune documentation. - In the Review + create area, review the information and click Create.
Next steps
Create a configuration profile for iOS/iPadOS
Create a configuration profile for Android
Complete this procedure to create a configuration profile for the Android version of the client. For more information on configuring a profile, see the MIcrosoft Intune documentation.
Unlike the profile for iOS/iPadOS, you cannot create a custom VPN profile where you configure it to be an Always-On VPN. You can automate the installation and activation of the client. However, users will need to open the client and grant permission for it to act as a VPN. The user will only need to do this the first time they access the client.
To create a configuration profile for Android:
- In the Microsoft Intune admin center, select Devices > Configuration profiles.
- Click Create profile.
- In the Platform menu, select your Android platform. Depending on what applies for your organization, you can select:
- Android device administrators
- Android Enterprise > Fully Managed, Dedicate, and Corporate-Owned Work Profile
- Android Enterprise > Personally-owned work profile
- In the Profile Type, select VPN.
- Click Create.
- In the Basic setting, enter a name and description for the profile, and click Next.
- Depending on the platform you selected, you need to configure specific settings. For more information, see Android device administrator or Android Enterprise.
- Click Next and then click Next until you reach Assignments.
- Select the user or groups that you want to receive the profile, and click Next.
- Review the settings and click Create.
Next Steps:
Configure custom app configuration values for Android.
Create a configuration profile for iOS/iPadOS
This procedure requires that you create a custom VPN profile where you set the client as an always-on VPN.
To configure an app configuration policy:
- In the Microsoft Intune admin center, select Devices.
- In the platform area of the menu, select iOS/iPadOS.
- Click Configuration profiles.
- Click Create profile.
- In the Create a profile window, select VPN as the profile type.
- Enter a name for the profile, and click Next.
- In the Connection type menu, select Custom VPN.
- Under Base VPN, enter the following information:
- For the Connection Name, enter ETP Client Connector VPN.
- For the VPN server address, enter
mobolize.com
. - For the VPN Identifier, enter
com.akamai.etp.client.mobo
. - For the Authentication method, select Username and password.
- Enter these key and value pairs. Select string as the value type.
Configuration Key | Value Type | Value |
---|---|---|
entitlementCode | string | Enter the entitlement code or the activation URL. |
owner | string | {{userprincipalname}} |
deviceName | string | {{serialnumber}} |
The configuration keys are case sensitive.
- In the VPN section:
- In the Type of automatic VPN menu, select On-demand VPN.
- For On-demand rules, click Add.
- In the settings for the On-demand rule, do the following:
- In the I want to do the following menu, select Connect VPN.
- In the I want to restrict to menu, select All domains.
- Click Save.
- For the Block user from disabling automatic VPN setting, select Yes.
- Click Next.
- For assignments, click Add all users and Add all devices.
- Click Next and then click Create. You can see the configuration profile by navigating to Devices > Configuration Profiles.
Next Steps:
Configure custom app configuration values for iOS/iPadOS
Configure custom app configuration values for Android
Complete this procedure to configure custom app configuration values for the ETP Client app on Android.
To create a configuration profile:
-
In the navigation menu, click Apps and then click App configuration policies.
-
Click Add and in the menu, select Managed devices.
-
Configure Basic settings:
- Enter a name and description for the policy.
- In the Platform app, select Android Enterprise.
- In the Profile Type menu, select All Profile Types.
- In the Targeted app, click Select app and from the app, select the app that you created in Add the mobile client for Android devices to Microsoft Intune.
- Click Next.
-
Configure policy settings:
-
In the Configuration settings format, select Use configuration designer.
-
Enter these keys and values. Select string as the value type.
Configuration Key Value Type Value entitlementCode string Enter the entitlement code or the activation URL. owner string {{userprincipalname}} deviceName string {{serialnumber}} -
Click Next.
-
-
In the Assignments area, select the users or groups that you want to include or exclude from this policy.
-
Click Next.
-
Review the app configuration policy and click Create.The configuration now applies to the ETP mobile client. Make you refresh the configuration on the device before you manage the mobile client app.
Next Steps:
Enroll devices. After new devices are enrolled, the app is deployed on them. You may need to refresh the configuration on the device before it’s applied.
Configure custom app configuration values for iOS/iPadOS
Complete this procedure to configure custom app configuration values for the ETP Client app on iOS or iPadOS.
To configure custom app configuration values:
- In the navigation menu, select Apps and then under policy, select App configuration policies.
- Click Add and in the menu, select Managed devices.
The Manage apps option is not supported for the mobile client.
-
Configure basic settings for the policy:
- Enter a name and description for the policy.
- Select iOS/iPadOS as the platform.
- For Targeted app, click Select app and in the list that appears, select the app that you created in Add the mobile client for iOS and iPadOS devices to Microsoft Intune and click OK.
- Click Next.
-
Configure policy settings:
-
In the Configuration settings format, select Use configuration designer.
-
Enter these key and value pairs. Select string as the value type.
Configuration Key Value Type Value entitlementCode string Enter the entitlement code or the activation URL owner string {{userprincipalname}} deviceName string {{serialnumber}} -
Click Next.
-
-
In the Assignments area, select the users or groups that you want to include or exclude from this policy.
-
Click Next.
-
Review the configuration and then click Create. The configuration now applies to the ETP mobile client. Make sure you refresh the configuration on the device before you manage the mobile client app.
Next Steps:
Enroll devices. After new devices are enrolled, the app is deployed on them. You may need to refresh the configuration on the device before it’s applied.
Updated over 1 year ago