Administrator Actions

A Secure Access DNS admin can deploy a mobile device that is not managed by a Mobile Device Management (MDM) system. As a full administrator, you must provision authorized users by uploading the list of users from a comma-separated values (CSV) file or syncing the users from Active Directory (AD) using the AD Connector. Then, after you register a user in Secure Access DNS, share the enrollment information with the user.

Table of Contents

Prerequisites

  • Full admin access to Secure Access DNS. For more information, see Manage User Roles
  • Upload or sync authorized users to Secure Access DNS
    • Upload the list of users from a CSV file
    • Integrate Active Directory (AD) users using the AD Connector
  • Access to a Secure Access DNS subscription that supports the deployment of mobile devices

Procedure

  1. Navigate to Resources > Mobile Devices.
  2. Click Manage.
  1. Choose Unmanaged and click Next.
1180
  1. Provision Identities
    a. If your organization is not connected to Secure Access DNS, click Upload New to provision authorized users.
    b. If you already provisioned users, Secure Access DNS displays the counts of the provisioned users and groups. Click Next.
  1. If no users are provisioned, the setup wizard prompts you to upload a CSV file of user data.

Secure Access DNS only requires certain attributes to provision an unmanaged mobile device. If you plan to integrate AD users and groups beyond mobile device enrollment, we recommend that you review the full AD integration guide.

Required Attributes for Unmanaged Mobile Devices

  • Mail

Optional Attributes for Unmanaged Mobile Devices

  • DN
  • memberOf
  • sn—Add for visibility of identity information in the policy
  • givenName—Add for visibility of identity information in the policy
  • userPrincipalName—Add for visibility of identity information in the policy
  1. Share Enrollment Information
    After at least one user is deployed, you can view any provisioned users in Secure Access DNS. To enroll, an admin must share enrollment data with users directly.
    a. Click iOS or Android, and then click Done.
1246

b. Share the enrollment instructions with the provisioned users.

  • Only users in the authorized list are permitted to enroll.
  • The enrollment is time-limited and the enrollment link expires at the date indicated.
  • Once expired, a new enrollment data set must be supplied to continue enrollment.

Secure Access DNS Unmanaged Mobile Device Protection < Administrator Actions > End-User Actions