Create a CylancePROTECT Mobile policy
CylancePROTECT Mobile
policyYou create and assign a
CylancePROTECT Mobile
policy to users and groups to enable the service and control which features you want to use.
You can configure risk assessment settings in the policy to maps the alerts that are detected by the
CylancePROTECT Mobile
app to risk levels (for example, you can specify that compromised devices should be treated as high risk). The risk levels of the alerts are used to determine a mobile device's overall risk level. You can view the device risk level in the management console (Assets > Mobile Devices and in the device details). Note that there is no default configuration of the risk assessment settings.If you integrate Cylance Endpoint Security with Microsoft Intune,
Cylance Endpoint Security
will periodically send the overall risk level of a mobile device to Intune
. You can use Intune
to configure mitigation actions for device risk levels.- In the management console, on the menu bar, clickPolicies > User Policy.
- On theProtect Mobiletab, clickAdd Policy.
- Type a name and description for the policy.
- In theNotificationssection, you can specify the count and interval of the notifications that theCylancePROTECT Mobileapp provides to the user when it detects a threat. You specify the type of notification (device, email, or no notification) in theDevice Settingssection (step 6).
- In theData privacysection, if you want to obfuscate certain pieces of information when theCylancePROTECT Mobileapp reports a threat so that the information cannot be stored and displayed in the management console in plain text, turn onData privacy, then select the fields that you want to obfuscate.
- In theDevice Settingssection, clickAndroidoriOSand turn on the features that you want to use. For more information about theCylancePROTECT Mobilefeatures, see Key features of CylancePROTECT Mobile. Note that sideload detection is not supported foriOS17.5 and later.
- For each feature that you enable, select the appropriate check box to enable or disable device notifications and email notifications. If you turn off device and email notifications, the user must open theCylancePROTECT Mobileapp to view alerts.
- If you enable any of the following features, complete these additional steps:
FeaturePlatformAdditional stepsMalicious appsAndroid- To exempt apps on the safe list from malware scanning, turn onAlways allow apps in the safe app list.
- To automatically block apps on the unsafe list, turn onAlways block apps in the restricted app list.
- If you want to scan system apps that are preinstalled in the system partition on the device, turn onScan system apps.
- If you want to enable the upload of apps to theCylancePROTECT Mobileservices over aWi-Ficonnection, turn onUpload app packages for safety check over a Wi-Fi connection. Specify, in MB, the maximum size of an app that can be uploaded overWi-Fi, and the maximum size of all apps that can be uploaded in a month (30 days). If either maximum is exceeded, the upload does not occur and an error is added to the device log.
- If you want to enable the upload of apps to theCylancePROTECT Mobileservices over a mobile network, turn onUpload app packages for safety check over a mobile network connection. Specify, in MB, the maximum size of an app that can be uploaded over a mobile network, and the maximum size of all apps that can be uploaded in a month (30 days). If either maximum is exceeded, the upload does not occur and an error is added to the device log.
Unsupported device modelAndroidiOSClickEditand select the device models that you want to restrict.Unsupported OSAndroidiOSAdd the available OS versions to the supported and unsupported lists based on your organization's security standards.SafetyNetorPlay Integrityattestation failureAndroidIf you want to enable Compatibility Test Suite matching for theCylancePROTECT Mobileapp, turn onEnable CTS profile matching.Hardware attestation failureAndroid- In theMinimum security level requireddrop-down list, click the appropriate level. For more information, see SecurityLevel on the Android Developers site.
- If you want to enforce a minimum security patch level on devices, turn onSecurity patch level. Add the appropriate device models and specify the security patch date.
InsecureWi-FiAndroidAdd the availableWi-Fiaccess algorithms to the safe and unsafe lists based on your organization's security standards.Unsafe messageAndroidiOS- In theScanning optiondrop-down list, select one of the following:
- If you want to send messages to theCylancePROTECT Mobileservices to determine if they are safe, clickCloud scanning.
- If you want to use only the local machine learning models of theCylancePROTECT Mobileapp to identify unsafe URLs, clickOn-device scanning.
- If you want to disable URL scanning, clickNo scanning.
- ForAndroiddevices, in theStart scanning offsetfield, specify, in hours, the age of text messages that are eligible for scanning. If you specify 0, only new messages are eligible for scanning.
- If you want to configure risk assessment settings forCylancePROTECT Mobilealerts, do the following:
- In theRisk Assessmentsection, clickAdd Detections.
- Drag and drop the detections to the risk level that you want to apply to them. For information about the detections, see Key features of CylancePROTECT Mobile.
- ClickSave.
- If necessary, rank policies.
- Create and assign an enrollment policy to users. After users are assigned an enrollment policy, they receive an email with instructions to download and activate theCylancePROTECT Mobileapp. For more information, see the Cylance Endpoint Security User Guide.
- Instruct users to enable JavaScript in their default mobile browser (theCylancePROTECT Mobileapp supportsGoogle Chrome,SamsungInternet, andSafari). This is required to activate theCylancePROTECT Mobileapp.
- InstructAndroidusers to allow background activity for theCylancePROTECT Mobileapp after it is installed.