ForeScout MDM

Overview

IT organizations today need visibility into and control over the mobile devices that are entering your enterprise, whether they are employee-owned or provided by your organization. ForeScout MDM, powered by MaaS360, provides a comprehensive set of capabilities to get devices configured for enterprise access and makes sure corporate data stored on these devices is secure.


ForeScout MDM supports the entire mobile device lifecycle: provisioning, integration, management, security, monitoring and support.

Provision – ForeScout MDM streamlines the configuration and device enrollment process to make life simple for IT and mobile employees. With automatic default policies for Exchange ActiveSync- and Lotus Notes Traveler-connected devices as well as iPhone, iPad, BlackBerry and Android devices (including the Kindle Fire), IT can simply modify an existing policy rather than creating one from scratch. Device enrollment takes just minutes instead of hours. ForeScout MDM discovers new users and devices, and allows IT to launch a simple end user self-service OTA enrollment process. For instance, ForeScout MDM doesn’t require the installation of an app on Apple iOS devices for enrollment. That’s one less step for the end user. And if IT is provisioning a large scale deployment of Apple devices before the user has associated the device, IT can do that much easier compared to other MDM solutions that require an iTunes app to enroll the device in the management platform.

topTop

Integrate –Through our unique approach, ForeScout MDM makes enterprise system integration easy and straightforward. With ForeScout MDM Cloud Extender, you can securely integrate with all major email, calendar and contacts platforms including Exchange, Lotus Notes, and Microsoft’s upcoming Office 365, plus Active Directory and any required certificate authorities. Robust APIs ease the integration process for both the enterprise and channel partners.

topTop

Manage – ForeScout MDM provides a unified management console for all smartphones, tablets, and laptops with centralized policy and control across multiple platforms. Through automated workflows, IT can discover, enroll, manage and report on enterprise-wide mobile devices as part of your mobile device operations. In addition, role-based ForeScout MDM portal rights allow you to expand or restrict access to authorized users.

OTA configuration management provides simple delivery and maintenance of corporate device profiles, including Wi-Fi and VPN settings. Through device quarantine and approval, IT is automatically notified of any new devices on the network and can block or approve them, ensuring compliance with corporate policies.

ForeScout MDM also delivers robust cross-platform, application management capabilities. ForeScout MDM allows enterprises to have their own app catalog on their device that presents users with approved or recommended public applications, in-house developed applications, and the ability to push updates of those applications as they are made available.

Additionally, enterprises can use ForeScout MDM SDKs for developing in-house apps for key functions such as authentication, updates, and usage reporting. These are invaluable tools for businesses building and managing their own in-house applications. By leveraging the ForeScout MDM mobile device management platform, you can speed in-house development, reduce security risks to enterprise infrastructure, and save costs by helping an enterprise avoid buying separate mobile enterprise application development platforms or gateways.

topTop

Secure – ForeScout MDM provides dynamic, end-to-end security and compliance management capabilities for your devices. Enforcement of passcode policies and strong encryption keys protects sensitive business and personal data on mobile devices. With ForeScout MDM you can configure device passcode policies to meet your highest enterprise security standards, and actively monitor devices to ensure total compliance.

Through real-time compliance management, ForeScout MDM can detect when users opt out of your MDM program, install prohibited applications, or initiate SIM changes. Based on this information, you can take automated policy actions, such as messaging the user, blocking email, or even wiping the corporate data from the device. Through passcode and device restriction policies, IT can control approved devices to protect data from theft, and restrict unapproved features and applications. Remote wipe actions ensure lost or stolen devices are not a data leak risk, and with selective wipe, you can delete corporate data while leaving personal data intact.

ForeScout MDM’s optional secure document distribution system allows organizations to distribute sensitive documents and protect them within the ForeScout MDM app sandbox, utilizing native device encryption and policy-based restrictions on who can share what documents. Features include a web-based management console, automated alerts when new or updated content appears in each user’s document catalog, and an optional Doc Cloud distribution network which reduces load on your network and increases performance for end users.

topTop

Monitor – Dashboards deliver an interactive, graphical summary of your mobile device operations and compliance. ForeScout MDM provides integrated MI reporting and analytics to provide a high level view into your mobile device landscape across your enterprise with detailed hardware and software inventory reports, plus configuration and vulnerability details.Your organization will gain insight into the distribution of mobile devices across the different operating system platforms, approval statuses, device capabilities, ownership and various other useful summaries and detail. Administrators can customize their Watch List to track and receive alerts about key events.

topTop

Support – Supporting mobile workers requires a 24×7 operation that’s always on. You need the ability to diagnose and resolve device, user or application issues in real time from a centralized portal to keep mobile workers happy and productive. ForeScout MDM provides robust help desk capabilities for support procedures such as locating a device with GPS, resetting a user’s passcode, and sending a direct message to a device. ForeScout MDM also provides an end-user support portal that allows users to do basic self-management of their device, such as wiping or resetting the password on a lost device.

ForeScout MDM is powered by MaaS360, a powerful cloud-based technology used by over 1200 companies around the world, and named the “Clear Choice Test” winner by Network World.

topTop

Integration with ForeScout CounterACT – ForeScout MDM integrates with ForeScout CounterACT using the ForeScout Mobile Integration Module. Through this integration, you gain the following features:

  • Automated real-time detection. ForeScout CounterACT detects unknown mobile devices the moment they try to connect to your network.
  • Improved security by blocking unauthorized users and devices from the network, as well as imposing whatever limits you want on mobile devices.
  • Unified policy management and compliance reporting for all endpoint devices—PCs, smartphones, and tablets.
  • Automated installation of MDM agents by automatically users with unmanaged devices through a simple self-enrollment process.
  • Guest registration. If you wish to setup a guest network for personal mobile devices, you can use ForeScout CounterACT’s built-in guest registration system. Once a guest has been approved, CounterACT can dynamically enforce your security policies, such as restricting the user’s access to just the Internet.
  • Continuous protection. If malware exists on the mobile device and tries to propagate or interrogate your network, ForeScout CounterACT will detect the malicious behavior, block the threat, and can automatically quarantine or remove the mobile device from your network. ForeScout CounterACT includes ForeScout’s patented ActiveResponse™ technology which can detect and block zero-day threats.
topTop

Product Tours

Product Screenshots

Click image to enlarge.

 

 

 

 

MDM Watch List

View a summary of the status of all devices.

Secure Document Sharing

Centrally manage documents, users, access controls, distribution, and policies.

Android MDM Policies

Manage the configuration for Android devices.

iOS MDM Policies

Manage the configuration for iOS devices.

MDM Actions

From within the ForeScout MDM management console, take actions to protect data and the device over-the-air.

Send Enrollment Request

ForeScout MDM discovers new users and devices, and allows IT to launch a simple end user self-service OTA enrollment process.

Cloud Extender

Integrate mobile devices with email, calendar, and contacts platforms such as BlackBerry Enterprise Server, Microsoft Exchange 2007 and 2010 Server, Lotus Notes, Active Directory or Microsoft’s upcoming Office 356.

Compare

= Best = Good = Fair = Poor*
ForeScout CounterACT ForeScout CounterACT + ForeScout Mobile (iOS, Android) ForeScout CounterACT + ForeScout Mobile + ForeScout MDM ForeScout MDM
Operational Management
Provisioning
Cost management
Inventory
App management, app store
Network Security
Access control
Block threats
Detect on access
Profile device
Device and Data Security
Password
Remote wipe, selective wipe
Configuration enforcement
Detect rooted / jailbroken
Containerization / encryption
Unified security management
User impact
Transparent Lightweight Lightweight Lightweight
Price
$ $$ $$$* $$$$

*Assumes a portion of lower risk user/devices are managed by ForeScout Mobile and higher risk users/devices/applications will require complete mobile device management (MDM) solution i.e. ForeScout MDM or integrated with 3rd party MDM.

Specs

ForeScout MDM, powered by MaaS360, is entirely cloud-based. It requires no on-premises installation and integrates with your existing identity, email and document management infrastructure. It supports the following mobile operating systems:

  • iOS version 4.0 and higher
  • Android version 2.2 and higher
  • BlackBerry Enterprise Server (BES) version 5.0 and higher
  • Windows Phone—all operating systems when integrated with Exchange ActiveSync and Lotus Traveler
  • Symbian—all operating systems when integrated with Exchange ActiveSync and Lotus Traveler
  • webOS–all operating systems when integrated with Exchange ActiveSync and Lotus Traveler

ForeScout MDM provides enterprises with many important security features, including:

  • Enforcement of passcode policies and strong encryption keys to protect sensitive business and personal data on mobile devices.
  • Mobile application blacklisting, minimum OS level verification and device feature restrictions.
  • The ability to remotely locate, lock and fully or selectively wipe lost or stolen devices.
  • Powerful compliance rules engine with automated responses for defined events and contextual changes. If a violation occurs, ForeScout MDM immediately and automatically takes action by warning the user with onscreen messaging, blocking corporate email access or even wiping the device’s memory to factory default settings.
  • Protection of Personal Identifiable Information (PII) through optional secure document management which utilizes native device encryption and.

ForeScout MDM integrates with ForeScout CounterACT using the ForeScout Mobile Integration Module. Through this integration, you gain the following features:

  • Real-time detection of mobile devices accessing the network, including assessment of ownership (personal vs. corporate) and management status.
  • Unified visibility, control and compliance reporting for all mobile endpoint devices including PCs, smartphones, tablets, and laptops through the CounterACT platform.
  • Security automation to dynamically detect unmanaged devices, such as iPads, iPhones and Androids on the network in real-time and apply controls which range from block, register as guest, segregate, and direction of user to an MDM enrollment process.
  • Automated installation of MaaS360’s MDM agent by directing users with unmanaged devices through a simple self-enrollment process.
  • Continuous protection of the network from threats coming from compromised mobile devices.

Get Started. Start your evaluation now.