home

Mobile Endpoint Security

Lookout Product Documentation

Find answers about using and optimizing Lookout products.

The Lookout and Workspace ONE Risk Remediation Workflow

  1. A device is impacted by an active threat.
  2. Lookout for Work identifies the threat and communicates the device's status to the Lookout MES Console.
  3. The Lookout MES Console categorizes the device according to the settings in the Protections module.
    For example, by default, a device with an active issue classified as "Trojan" is considered High Risk.
  4. The Lookout MES Console communicates this device status by applying the "Lookout MES - High Risk" tag to the device in Workspace ONE.
  5. Because it is tagged as "Lookout MES - High Risk," Workspace ONE dynamically adds the device to the "Lookout High Risk" Smart Group.
    All policies that apply to the "Lookout High Risk" Smart Group are now in effect for the device.
  6. The device user remediates the threat by uninstalling the "Trojan" malware.
  7. Lookout for Work gives the all clear and communicates the device's new status to the Lookout MES Console.
  8. The Lookout MES Console no longer considers the device high risk, so it removes the "Lookout MES - High Risk" tag from the device in Workspace ONE.
  9. Because it is no longer tagged as "Lookout MES - High Risk," Workspace ONE removes the device from the "Lookout High Risk" Smart Group.
    The device user is no longer affected by the policies for that Smart Group.