home

Mobile Endpoint Security

Lookout Product Documentation

Find answers about using and optimizing Lookout products.

Configure On-Device Threat Protection

By default, On-Device Threat Protection is disabled and not used as a response to active threats. You must first activate the feature, and then set it as a Response action for one or more issue classifications:

  1. Enable on-device threat remediation from the Protections module by clicking the On-Device Threat Protection tab and enabling the Enable On-Device Threat Protection toggle.
  2. Optionally, set specific domains to block, such as corporate resources, by adding entries to the Block Specific Domains list and clicking Save changes.
    Note:

    NOTE: The Block Specific Domains table does not require wildcard entries. Domains are always treated as suffixes, where only an exact match causes Lookout to block the domain.

  3. Navigate to the Policies tab directly or by clicking the Configure policies link at the bottom of the On-Device Threat Remediation settings.
  4. Set either Block internet and alert or Block domains and alert as a Response to one or more issue classifications.

    If you have not added entries to the Block Specific Domains list, you cannot select Block domains and alert.

    When Lookout detects an active threat with one of the specified classifications, it blocks the device from accessing the internet or the specified domains depending on the chosen response.