Distribute the mobile client with Microsoft Intune
Make sure that your organization has an Intune management account with administrator privileges. An administrator needs the Intune management role.
Complete these steps to distribute the mobile client to iOS and Android devices with Microsoft Intune.
Set up and distribute SIA Proxy MITM certificate
If you want to use Threat Protection with SIA Proxy, distribute the SIA Proxy MITM certificate.
- See Create a SIA Proxy MITM Certificate to learn how to create a certificate.
- Download your binary (
.der) certificate and change the file extension from.derto.cer. - See Microsoft Intune documentation to learn how to create a trusted certificate profile and assign it to your devices.
Distribute Zero Trust Client with Microsoft Intune
To distribute the mobile client with Microsoft Intune, refer to Intune documentation. Note that users need to allow the VPN profile installation manually. To deploy the VPN profile automatically, see Create a VPN configuration profile for iOS and iPadOS:
-
Add the mobile client for Android devices to Microsoft Intune or Add the mobile client for iOS and iPadOS devices to Microsoft Intune.
- To configure Zero Trust Client in Intune, you may use the following app store links: Google Play Store or Apple App Store.
-
Configure custom app configuration values for Android or Configure custom app configuration values for iOS/iPadOS.
- Use the configuration designer to add this custom app configuration for Zero Trust Client. Enter your organization’s IDP URL or SIA entitlement code as the configuration value.
Configuration key Value type Configuration value idp-urlString your_IDP_URL entitlementCodeString your_SIA_entitlement_code -
Enroll Android devices or Enroll iOS and iPadOS devices in Microsoft Intune.
Create a VPN configuration profile for iOS and iPadOS
To automatically deploy and allow the VPN profile on user devices, refer to Microsoft Intune documentation for adding VPN settings.
Use the following settings to create a VPN profile for Zero Trust Client in Intune:
- In Profile type, select Templates and VPN.
- In Profile name, enter
Zero Trust Client VPN Profile. - In Connection type, select Custom VPN.
- Under Base VPN, enter the following information:
- In Connection Name, enter
ZERO TRUST VPN. - In VPN server address, enter
akamai.com. - In VPN Identifier, enter
com.akamai.ios.ztclient. - In Authentication method, select Username and password.
- In Connection Name, enter
Enter the below key and value pair. Select string as the value type.
| Configuration key | Value type | Configuration value |
|---|---|---|
entitlementCode | String | <enter your SIA entitlement code here> |
- In Automatic VPN:
- Select On-demand VPN as the type of automatic VPN.
- In On-demand rules click Add.
- In I want to do the following, select Connect VPN.
- In I want to restrict to, select All domains.
- Click Save.
- In Block user from disabling automatic VPN, select Yes.
- Assign users and devices to the policy.
- Click Create to save your policy.
Updated 14 days ago
