PingID Mobile Device Management (MDM)
This section describes the steps to configure PingID’s MDM integration, which verifies that devices connected through the PingID mobile app are managed by the organization’s MDM infrastructure.
MDM is the administration of mobile devices, such as smartphones, tablet computers, and laptops. It can also be applied to desktop computers. Organizations can control activities of their employees by implementing MDM products or services.
MDM primarily deals with corporate data segregation, securing emails and corporate documents on mobile devices. MDM enforces corporate policies and supports the integration and management of mobile devices including laptops and hand-held devices of various categories.
|
MDM integration flow
Integrating with an MDM involves the following steps:
-
Configure the PingID mobile application to include MDM and generate a token for MDM. Learn more in (Workforce Only) Configuring the PingID mobile application settings.
-
Configure the third-party MDM system for PingID integration.
-
Generate and configure an APNS certificate for iOS in the MDM system. For example:
-
Configure Android for Work in the MDM system so that the PingID mobile app configuration can be pushed to managed mobile devices. For example:
-
In the organization’s MDM system, add PingID as a managed app and configure the token that was generated in PingOne admin portal. For example:
-
-
After configuration, the MDM system distributes the token to its managed devices. During pairing and authentication, the PingID server compares the user’s token with current active tokens, and the flow can only continue if there is a match between the user’s token and a currently active PingID token.PingID permits administrators to define more than one active token.
Ongoing maintenance
As part of periodic MDM maintenance activities, you can generate new tokens for the PingID mobile app and revoke old tokens. Learn more in the following topics:
-
PingID: You can generate a new token, rotate a token, or revoke a token. Learn more: Managing MDM tokens
-
For the supported MDM systems: