home

Mobile Endpoint Security

Lookout Product Documentation

Find answers about using and optimizing Lookout products.

Configuring Zero Touch Activation for Lookout for Work on Android Enterprise

Lookout for Work 6.4 and higher on Android supports a zero-click activation workflow for Android Enterprise (Android for Work) devices in Intune. To enable it, configure the Lookout for Work app to pre-grant permissions, then deploy a VPN profile from Intune. The always-on VPN opens Lookout for Work, and when the app detects the provided values for enrollment, it switches to the zero-click activation flow.

When you enable always-on VPN functionality for zero-click activation using Intune, the Android OS will not permit any other VPN to connect.

Requirements:
  • Lookout for Work 6.4+
  • Microsoft Intune configured for Android Enterprise.
  • Android Enterprise Fully Managed or Dedicated devices.

    For additional information, see Android Enterprise device settings list to allow or restrict features on corporate-owned devices using Intune on the Microsoft Docs website.

    1. Log in to the Microsoft Intune admin center.
    2. In the left sidebar, click Devices.
    3. In the Devices blade, under Policy, click Configuration profiles.
    4. Click + Create profile.
    5. Set Platform to Android Enterprise and Profile type to Device restrictions, then click Create.
    6. Enter a name for the profile, such as Lookout Zero Touch Activation.
    7. Click Next.
    8. Click Connectivity.
    9. Set the following:



      FieldValue
      Always-on VPNEnable
      VPN clientCustom
      Package ID
      com.lookout.enterprise
      Lockdown modeNot configured
      Recommended global proxyNot configured
    10. Click Next.
    11. Click + Select groups to include.
    12. Search for and click all groups that should use the always-on VPN for zero touch activation.
    13. Click Select.
    14. Click Next, then click Save.