home

Mobile Endpoint Security

Lookout Product Documentation

Find answers about using and optimizing Lookout products.

Enabling On-Device Threat Protection

On-Device Threat Protection blocks compromised devices in your fleet from accessing corporate or Web resources. By enabling this feature, you can use Block internet and alert or Block domains and alert as responses in your protection policy settings. The first setting blocks all internet access on a compromised device. The second setting blocks a list of domains that you can configure from this tab.

Some policy responses, such as OS Out-of-Date or Patch Level Out-of-Date only allow you to block certain domains, since the device needs internet access to resolve the threat.

Because On-Device Threat Protection runs as an always-on VPN, users must accept the VPN permission from the Lookout for Work app during setup, and the device cannot have another always-on VPN present.

To enable and configure On-Device Threat Protection from the Multi-Tenancy Admin Console:

  1. Click Protections in the left navigation bar.
  2. Click the Manage settings for: dropdown and click the device group you wish to configure:


  3. Click the On-Device Threat Protection tab and enable or disable the feature for the selected group.
  4. To only block specific domains when Lookout detects threats on a device, add entries to the Block specific domains list.

    If you leave this list blank, Lookout blocks all internet traffic on the device until threats are resolved.

  5. Click Save Changes.
  6. Click Configure policies to go to the Protections tab.

    You can now use the Block Internet and Alert or Block Domains and Alert Response settings.