Setting up your Workspace ONE Connector in the Lookout Mobile Endpoint Security Console
Once you have created an API user, an enrollment Smart Group, and tags for syncing device state between Lookout and Workspace ONE, you can create your Workspace ONE Connector in the Lookout Mobile Endpoint Security (MES) Console. If you have multiple tenants, you must repeat the following steps to connect to each of them:
- Log in to the Lookout MES Console at https://app.lookout.com.
- In the left sidebar, click Integrations.
- Under Choose a product to set up, click the Workspace ONE tile.The Workspace ONE Connector page opens.
- Under Connector Settings, enter the following:
Field Value Label for this MDM connection (Optional) A user-friendly name for the connector.
If you have multiple connectors configured, this label displays in the MDM column of the Lookout MES Console Devices list so that you can determine which connector and MDM instance a device belongs to.
Workspace ONE URL Your Workspace ONE server URL, https://<server name>.awmdm.com
API Token Copy the API key from Creating an API Key. Authentication Certificate Authentication (Recommended): Click Choose file... and then enter your Passphrase. Basic Authentication: Enter the username and password for the API user you created in Creating an API Role and User. If you use basic authentication, you must update the connector configuration whenever the API user's password expires and has to be changed. - (Optional) To route Lookout traffic through a proxy, enter the proxy address and credentials in the Proxy Settings fields.
- Click Create Integration in the top right corner.If creation is successful, a banner notification appears and additional sections become enabled.
If you get a certificate error, click Certificate Details. Otherwise continue with Step 7.
- Look for errors on the certificate details screen.Typical errors include expired or broken certificates as shown here:
Error How to Fix the Error Expired certificate The certificate expiration date is in the past. Replace the MDM certificate with a new certificate. Broken certificate. One or more intermediate certificates do not validate correctly. Replace the MDM certificate with a valid certificate. - Retry entering all required information into the Integration connector.
- Look for errors on the certificate details screen.
- Scroll down to Enrollment Management and enter the following:
Field Value Automatically drive Lookout for Work enrollment on Workspace ONE managed devices ON Use the following Workspace ONE smart groups to identify devices that should be enrolled in Lookout for Work: Select your enrollment Smart Group from Creating Smart Groups & Tags. This should be Lookout for Work. How often should Lookout check for new devices? Lookout recommends using the default 5 minute interval. Automatically send activation emails to Workspace ONE managed devices OFF
For an MDM integration, you should drive enrollment through your MDM, not via Lookout MES Console invitation emails.
Delete device on unenrollment ON - Scroll down to State Sync and enable Synchronize device status to Workspace ONE.
- Select the tags you created in Creating Smart Groups & Tags.If you choose not to synchronize a specific state to Workspace ONE, leave the corresponding toggle off.
- Device Status:
Field Value Devices that have not activated Lookout yet Lookout MES - Pending Devices with Lookout activated Lookout MES - Activated Devices with Lookout deactivated Lookout MES - Deactivated - Connection Status:
Field Value Devices that are unreachable by Lookout Lookout MES - Unreachable Devices that have lost connectivity with Lookout Lookout MES - Disconnected - Risk Status:
Field Value Devices with any issues present Lookout MES - Threats Present Devices with low risk issues present Lookout MES - Low Risk Devices with medium risk issues present Lookout MES - Moderate Risk Devices with high risk issues present Lookout MES - High Risk Devices with no issues present Lookout MES - Secured
- Device Status:
- If you have purchased the feature to add specific Risk Classifications to synchronize with Workspace ONE, you can add them using this procedure.Otherwise continue on to step 11.
If you purchased the feature to add Risk Classifications to synchronize with Workspace ONE, a Risk Classification section is visible in the Lookout Workspace ONE connector.
- In Workspace ONE, follow the steps in Creating Smart Groups & Tags to define an additional unique smart group tag for each risk classification you want to synchronize with Workspace ONE.Here are some examples:
Example Risk Classification Example Smart Group Tag Example Tag Description Phishing and Content Protection Disabled Lookout MES - PCP Disabled Devices with PCP disabled VPN Permission Not Accepted Lookout MES - VPN Prohibited Devices with VPN Permission not accepted - In the Lookout Workspace ONE connector Risk Classification section (visible only if you purchased this feature), follow these substeps:
- Click Add Risk Classification.
- Set to Enable.
- Choose the desired risk classification from the dropdown to synchronize with Workspace ONE.
Risk classification synchronization occurs only if a state sync event occurs.
- Choose the tag for the selected risk classification from the dropdown to synchronize with Workspace ONE.
If you choose not to synchronize a specific state to Workspace ONE, leave the corresponding toggle off.
- Repeat steps i - iv for each additional risk classification you want to synchronize with Workspace ONE.
Each risk classification you add here must have a corresponding unique tag defined in Workspace ONE.
- In Workspace ONE, follow the steps in Creating Smart Groups & Tags to define an additional unique smart group tag for each risk classification you want to synchronize with Workspace ONE.
- Scroll down to Error Management and enter an email address for error reporting.
- (Optional) Scroll down to Group Management and enter a Lookout MES Console Device Group for new devices from this connector.
By default, new devices are added to the Default Group in the Lookout MES Console. For more information about Device Groups, see the Lookout MES Console Administrator's Guide.
- Scroll up and click Save Changes in the top right corner.You can review connector settings from the Integrations module at any time.
- If you are running multiple Workspace ONE tenants, repeat these steps to create one connector per tenant.