home

Mobile Endpoint Security

Lookout Product Documentation

Find answers about using and optimizing Lookout products.

The Manage Admins Module

Unless you are running a Microsoft Intune integration, the Manage admins module displays a list of all MES Console Administrators. You can add new Administrators from here by clicking ADD ADMIN, or search the list by name or email.

If your tenant is integrated with a Single Sign-On Identity Provider, this list omits any administrators who sign on via SSO. It only lists Administrators who use Lookout credentials to access the console. Any Administrators included via SSO must be managed from the corresponding Identity Provider.

For Microsoft Intune, the Manage Admins module displays a notification indicating that MES Console Administrators are set based on Azure Active Directory (AAD) Groups. These are the groups that were configured for Full Access / Restricted Access / Read-Only Access when first creating your tenant. If you need to change the AAD groups associated with each access level, please contact Lookout Enterprise Support .

Available access levels are:

  • Full Access: No restrictions.
  • Restricted access: The Admin can manage devices and issues, export content, or edit personal preferences. They can't edit security policies, enroll devices, or edit system preferences.
  • Read-Only access: The Admin can only export content or edit personal preferences.