Showing posts with label Citrix XenMobile. Show all posts
Showing posts with label Citrix XenMobile. Show all posts

Monday, December 9, 2013

Mobile Device Management - Part III

I just finished reading Instant XenMobile MDM - a very simple book with only 46 pages.


The book compares container-based solutions by many other vendors with the application-based enforcement found in Citrix XenMobile MDM (mobile device management). Container-based solutions are applications that embed corporate data, e-mail, contact, and calendar data.

Unfortunately, in many cases these solutions break the user experience by limiting how they can use native applications. XenMobile does this without compromising the user experience, allowing the secure applications to exist and share the same calendar, contact, and other key integration points on the mobile device. They were the only vendors at the time of writing this book, that had a single management platform which provided MDM features with secure storage, integrated VDI, multitenant, and application load balancing features, which we believe are some of the differentiators between XenMobile and its competitors.

The concept of Citrix XenMobile MDM is very similar to that of Blackberry Enterprise Server, except it supports more devices. It has integration with Apple iOS 7 MDM APIs as well as Samsung KNOX and Amazon MDM platforms extend the 60+ application-specific policy controls of XenMobile.

A "Quick start - setting up your XenMobile Server" follows in subsequent chapter. The setting up of Citrix XenMobile MDM is fairly straight-forward. (This reminds me of BES server installation sometimes back. Very simple and fast to deploy)



It covers specific platforms like Apple iOS and Samsung SAFE (Samsung for Enterprise).


The book ends with "Top 6 features you need to know about".

  1. Reporting
  2. Application stores
  3. Secure Mobile Gateway
  4. The XenMobile service manager
  5. Dashboard management
  6. Common management tasks


There are many reports which are mostly self-explanatory. E.g. OS version, OS type, Device Type. The more interesting report will be those that list the jailbroken devices and rooted devices.



I am more interested in Secure Mobile Gateway since I'm a Mail person (used to deploy numerous Sun Messaging Servers in the South-East Asia region), besides IAMS.


Secure Mobile Gateway provides granular access control for e-mail and calendar applications on devices that support Microsoft ActiveSync. ….

The benefit of Secure Mobile Gateway is that it ensures that a user won't bypass your XenMobile policies that are being enforced on devices. A user who does not agree with your policies may decide to skip enrollment. He may have somehow decided that he does not need corporate applications that are being pushed or other device centric policies. However, typically most users will need access to their e-mail from their devices. If a user somehow figures out the necessary settings and credentials to configure his device manually, Secure Mobile Gateway can intercept that connection and make policies decisions based on an organization's needs. In other words, you could stop a user from accessing e-mails until he enrolls in the XenMobile MDM solution..

Citrix Secure Mobile Gateway works as an ISAPI plugin on the same server with Microsoft Forefront Threat Management Gateway.

Hmm… I thought Microsoft has announced discontinued support for Microsoft Forefront Threat Management Gateway? No, it still has mainstream support until April 2015 and extended support until April 2020. Good to know.



.


Saturday, December 7, 2013

Mobile Device Management - Part II

In October, I blogged about Mobile Device Management and I was thinking aloud about how a traditional IDM product can add-on a new feature to provision to a MDM product.
  



The next feature will definitely be able to bridge the gap between identities from enterprise customers (most likely, in-house Microsoft Active Directory) and MDM products. I do not think we should cross the path of building a MDM product from scratch. That would be too far-fetching. 
This would be a one-stop solution.


This morning, an email came from SailPoint announcing the release of IdentityIQ 6.2. 

Dream comes true! Yes, indeed.




Highlights of what’s included in the new release:
  • First of its kind integration with mobile device management (MDM) solutions from AirWatch, Good and MobileIron
  • Re-styled user interface with crisp, clean look-and-feel
  • Expanded scalability support for critical IAM processes
  • Enhanced administrative user experience with improvements to workflow and quick link configuration
  • Separation-of-duty (SoD) policy simulation
  • End user tablet support (iPad)
  • Integration support for STEALTHbits, Cyber-Ark and Microsoft FIM
  • Expanded healthcare integration with Epic & GE Centricity connectors


These days, any IAMS product will want to get "friendly" with mobile devices. Why not? It's a super huge market in the mobile space.


.

Thursday, October 31, 2013

Mobile Device Management

I blogged about New Paradigm for the Modern Web few months ago when I came back from ForgeRock Open Identity Summit in San Francisco. 


Few weeks after I came back from the US, I attended the 1st Compuware APM User Conference in Singapore. I then blogged about New Paradigm for the Modern Web - Part II


I concluded that Cloud, Mobile, Social is not going to go away anytime soon. They will just get bigger, and we should better prepared ourselves for them.

Mobile - yes, this is the tiny little gadget that is getting very hot these days. Every company is finding ways to have corporate applications installed on the mobile devices so as to increase the productivity and mobility of their workforce. 

But security is the top issue. 


This morning, I came across an article from Citrix and looked further into XenMobile.


XenMobile delivers enterprise grade MDM with role-based management, configuration, security and support for corporate and employee-owned devices. Users enroll their devices, enabling IT to provision policies and apps to those devices automatically, blacklist or whitelist apps, detect and protect against jailbroken devices, troubleshoot device and app issues, and wipe or selectively wipe a device that is lost, stolen or out of compliance. Users can use any device they choose, while IT can ensure compliance of corporate assets and secure corporate content on the device.


This is the Mobile Device Management (MDM) offering from Citrix. Quite typical of any MDM product out there in the market.


But XenMobile attempts to offer more features…


The XenMobile App Controller is a SAML-compliant identity provider that connects to the enterprise directory, reads the authorization policies configured and provides the appropriate secure SAML tokens for user sign-on to federation-enabled applications. To interoperate with older applications that do not support SAML, XenMobile can act as a password manager, storing user credentials and providing them securely so users don’t have to remember their app credentials. Built into XenMobile is a long list of “connectors” for applications that have all the required interaction logic leveraging APIs that the applications expose; for example, APIs to create user accounts within those applications based on authorization policies. With App Controller, authorized applications are exposed to users through Worx Home, forming an enterprise app store and providing users a single place to authenticate and get access to all their enterprise applications. 

Pretty cool.

This gets me thinking … currently, we have ForgeRock Bridge SPE (of course, there is now the famous SalesForce Identity Connect) that helps Cloud Service Providers to federate identities between enterprise customers and the services they offer.

The next feature will definitely be able to bridge the gap between identities from enterprise customers (most likely, in-house Microsoft Active Directory) and MDM products. I do not think we should cross the path of building a MDM product from scratch. That would be too far-fetching.

This would be a one-stop solution.

Just my thought. What's your view?


.