Digital Workspace Mobile Threat Detection & Response with Workspace ONE & Zimperium - Integrating zConsole
Mobile threat detection and response is an area of ever-growing importance, as the world finds themselves accessing sensitive resources on devices everywhere. Application, identity or device management only offers so many protections to the assortment of threats users are faced with.
Digital Workspace products like Workspace ONE and Zimperium's zIPS compliment each other, and offer an additional level of compensating controls, specifically for mobile threats. These capabilities allow your organization to detect threats you might not have had visibility of, let alone the ability to mitigate.
Zimperium focuses on being best-in-breed in MTD, and it shows. In 2019; Zimperium would be the first MTD to be FedRAMP authorized, partner with the VMware to join the Trust Network, and selected by Google to join the App Defense Alliance.
To make this integration possible, you must first, thank your CISO, and then integrate Zimperium's zConsole with Workspace ONE UEM. In this post, we'll go through all the requirements. Requirements like...
Digital Workspace products like Workspace ONE and Zimperium's zIPS compliment each other, and offer an additional level of compensating controls, specifically for mobile threats. These capabilities allow your organization to detect threats you might not have had visibility of, let alone the ability to mitigate.
Zimperium focuses on being best-in-breed in MTD, and it shows. In 2019; Zimperium would be the first MTD to be FedRAMP authorized, partner with the VMware to join the Trust Network, and selected by Google to join the App Defense Alliance.
To make this integration possible, you must first, thank your CISO, and then integrate Zimperium's zConsole with Workspace ONE UEM. In this post, we'll go through all the requirements. Requirements like...
- Mood lifting console background picture
- Obtaining an API Key for integration
- Setting up MDM Integration with zConsole and Workspace ONE UEM
- Testing Integration
Grand Hyatt Kauai, not included in Workspace ONE. But, a great place to treat your team and hold a meeting. Hint, hint... |
- Open the Workspace ONE UEM console and go to;
Groups & Settings -> All Settings - Open the Workspace ONE UEM console and go to;
System -> Advanced -> API -> REST API - In the 'General' tab, click 'Add'
Note: Ensure 'Enable API Access' is set to enabled. This is required. - Name the Service, in this example 'zConsole' is used. Ensure the 'Account Type' is set to 'Admin'. Copy the API Key to your clipboard. We will reuse this in the zConsole.
- Login to your Zimperium zConsole
- In the left navigation pane, locate 'Manage'
- Click 'Manage'
- In the page that opens, at the top, locate 'Integrations' and click it
- Click 'Add MDM'
- Select 'airwatch by VMware', depending on your console version, it may say Workspace ONE. Once selected, click 'Next'
- Add the following information;
URL: This is the URL your Workspace ONE UEM API Endpoint is accessible at.
Note: This needs a DNS A record, publicly resolvable, with 443 inbound/outbound TCP/UDP traffic allowed. This public DNS A record could be created in whatever manages your public facing DNS. Examples: AWS Route 53, Cloudflare DNS, GCP Cloud DNS, Azure DNS.
In this example, I have a DNS A Record created in Azure DNS for the URL: https://ws1.ryanpringnitz.com
The appropriate network security group, route table and associated configuration is inplace to support this.
Username: A Basic user, or LDAP user in Workspace ONE UEM.
Note: The account must have permissions to make API calls for the smart groups, users, devices, and applications for the organization group(s) being managed. This example uses a directory account of ryanpringnitz\ws1
MDM Name: Name it something appropriate, like 'Hawaii Retirement Provider', or
Molokai Bank - Workspace ONE UEM - 1903 - Prod
There is no incorrect value for this field. This is strictly to label the MDM environment in zConsole
Background Sync: Ensure this box is checked
Mask Imported User Information: Check if you prefer the data to be anonymized. There are other unique identifiers that are not anonymized, and additional ways to limit data returned for other scenarios (e.g. GDPR compliance). I leave this unchecked in my lab environment.
API Key: This is the API Key you copied in to your notepad. Paste it here. - In the lower right corner, click 'Next'
- At the next page, select smart groups from Workspace ONE UEM that you want to import in to the Zimperium Mobile Threat Detection & Response console.
Note: I suggest making and importing the following (5) smart groups in Workspace ONE UEM; Risk-Critical, Risk-Elevated, Risk-Low, App - Zimperium - Pilot, and App - Zimperium - GA
More on this in an upcoming post covering... - Click 'Finish'
- This will take you back to the 'Integrations' page. Proceed to verify your configuration by clicking the green button 'Test MDM'
- Verify all the tests passed.
Note: During these tests, network traffic between the VPC and your Workspace ONE environment is expected. A series of API calls from the VPC will be made to verify access to Workspace ONE API endpoints.
This API key is just for example |
In this example, an existing environment is seen integrated already. Currently, you can have multiple environments associated with a single Zimperium SaaS VPC tenant or on-premise environment |
Mahalo,
Ryan Pringnitz
Comments
Post a Comment