home

Mobile Endpoint Security

Lookout Product Documentation

Find answers about using and optimizing Lookout products.

Detect if End Users have Configured Secure DNS on their Devices (iOS only)

Advanced customers that mandate PCP (Phishing and Content Protection) with Secure DNS can detect whether users have accepted the permission to install the Secure DNS profile on their iOS device.

iOS users who have not accepted the secure DNS permission receive a notification to configure Secure DNS on their devices and Lookout logs the issue.

Android devices do not require any user interaction and automatically configure Secure DNS.

To detect whether iOS end users have allowed secure DNS configuration, follow these steps using the Protections module:

  1. Configure Phishing and Content Protection, making Secure DNS mandatory following the procedure in Configuring Phishing and Content Protection.
    Be sure to click Save Changes.
  2. Click the Policies tab near the top of the page.
    The Policies tab opens.
  3. Find policy classification Secure DNS Not Configured.
  4. Set the policy Severity Options: None (default), Advisory, Low, Medium, or High as appropriate for your group or organization.
  5. Set the Response Options as appropriate for your group or organization.

    Once you have set up Secure DNS on the MES console, the tenant starts pushing the Secure DNS profile out to existing end user devices. iOS users must accept the permission to install the Secure DNS profile on their device:

    • New iOS users installing Lookout for Work accept the configuration during installation. No further action is needed.
    • Existing iOS users receive a notification that Secure DNS (Safe Browsing) is not enabled and to go to settings to enable it.

      These users tap the Lookout for Work hamburger menu (top left corner of the app dashboard), choose Settings and enable Safe Browsing.