Secure Your Mobile Deployment from End-to-End

Security for mobile devices, applications and content is a paramount concern in a mobility management strategy. Whether users have a corporate-owned or employee-owned device, they are accessing corporate data, email and more from their mobile devices. These user actions require you to implement a mobile strategy with strong security policies.

Security is at the core of AirWatch Enterprise Mobility Management (EMM). The AirWatch Mobile Security solution ensures your enterprise mobility deployment is secure and corporate information is protected with end-to-end security that extends to users, devices, applications, content, data, email and networks. AirWatch provides real-time device details and continuous compliance monitoring to ensure your users, devices and corporate data are secure.

User Security

User Security

With AirWatch, you can manage user access to corporate resources with basic, AD/LDAP, SAML, smart-card or token-based authentication. Administrators can require multifactor authentication and require users to be authenticated during device enrollment and before accessing corporate email, applications, content and networks.

Containerization

Ensure the security of data in applications, content and email through containerization with AirWatch. AirWatch App Wrapping enables you to containerize applications on devices and set application-level policies for access, such as user authentication. AirWatch Secure Content Locker™ provides a corporate container that enables secure distribution and access to corporate documents. Email can be containerized in AirWatch Email Container™ on Android devices. Data can be encrypted, passcode protected and wiped remotely.

Device Security

Device Security

Ensure the security of all devices, whether they are corporate-owned, corporate-shared or employee-owned. AirWatch enables administrators to prevent device enrollment based on platform, operating systems version and device type; and to require a user accept a Terms of Use agreement before granting access. Blacklist specific devices or block unknown devices by serial number or IMEI. With AirWatch, you can enforce restrictions on devices features, applications and web browsing; detect compromised devices and take automatic, escalating actions against compromised and noncompliant devices. If a device is lost or stolen, you can remotely lock the device, wipe the device, and use GPS tracking to locate the device.

Application Security

AirWatch ensures your applications and corporate data stored in applications are secure. AirWatch allows you to set both device-level policies, such as requiring a device passcode, and application-level polices, like requiring user authentication for app access. Administrators can also restrict native apps on devices, configure application whitelists and blacklists, and set application use policies. With AirWatch, you can enforce device and application compliance policies, monitor status, and disable access to corporate apps if a device is compromised, non-compliant or the user leaves the company. If you develop internal applications, the AirWatch Software Development Kit (SDK) and AirWatch App Wrapping enable you to add AirWatch security features directly to your applications.

Application Security
Content Security

Content Security

AirWatch keeps corporate content secure by containerizing documents in Secure Content Locker™. Content is encrypted with industry-standard, FIPS-140 compliant 256-bit SSL encryption, and access can be restricted based on location and time of day with geofencing and time-based profiles. AirWatch allows you to configure the ability to edit, share or open files in other applications by user or group. AirWatch can also automatically disable access and wipe content if a device is compromised, non-compliant or the user leaves the company.

Data Security

AirWatch provides companies with the ability to encrypt data at rest on device and SD card, as well as in transit according to industry standards. Administrators can disable the backup of data settings and AirWatch detects if device switches to an unapproved SIM card. If a device is lost or stolen, administrators can remotely lock and wipe a device to protect corporate data.

Data Security
Email Security

Email Security

AirWatch enables ultimate mobile email security by enabling you to require devices be enrolled in AirWatch, encrypted and compliant before granting access to corporate email. You can also allow or prevent access based on device model, operating system or email client. Administrators can configure policies to prevent copy/paste, email forwarding and disable access if a device is compromised, noncompliant or the user leaves the company. You can require attachments to be opened and stored securely in Secure Content Locker™. AirWatch Email Container™ provides a secure, sandboxed email client and a native user experience on Android devices.

Network Security

AirWatch enables administrators to prevent unknown devices from connecting to corporate networks, and configure certificate-based access to corporate VPN and Wi-Fi networks. Network Access Control (NAC) integration enables you to determine access rights based on compliance, traffic prioritization and protocol restrictions. With AirWatch VPN On Demand, your users can securely access internal websites through a VPN tunnel. AirWatch AppTunnel also enables you to secure access and communication with enterprise entworks from wrapped applications.

Network Security

Compliance Engine

The AirWatch compliance engine enables administrators to continuously monitor devices and automate actions to prevent noncompliance. Administrators set compliance policies, such as a required device passcode and encryption, and configure automated actions and define severity levels for non-compliant devices. If the compliance engine detects a noncompliant device, actions are performed automatically to bring the device back into compliance. For example, if a device removed a required passcode from their device, they can be alerted by a notification and given a specified amount of time to become compliant before the next automated action is performed. Any actions taken can be automatically reversed when the device is compliant.

Compliance Engine