How to configure MDM attributes as HIP objects for GlobalProtect using Workspace ONE with iOS devices

How to configure MDM attributes as HIP objects for GlobalProtect using Workspace ONE with iOS devices

5266
Created On 03/31/23 01:05 AM - Last Modified 07/26/23 17:12 PM


Objective


  • This document will explain how to configure MDM attributes as HIP objects for GlobalProtect using Workspace ONE with iOS devices


Environment


  • Existing GlobalProtect infrastructure
  • IOS devices managed by Workspace One MDM
  • MDM attributes used for HIP-Based Policy Enforcement


Procedure


Workspace One configuration:
  1. Navigate to Resources → Profiles & Baselines → Profiles. Select the appropriate VPN Profile or add a new VPN Profile
  screenshot showing MDM profile
2. Enter the tags under “VPN” → “Custom Data”.

screenshots for attributes

When you integrate your GlobalProtect deployment with the Workspace One MDM system, the GlobalProtect app for iOS devices can obtain the following data attributes: tagcompliance, and ownership are the keys. The keys are case-sensitive (must be lower-case), and the value can be set as anything

  • tag—Tags to enable you to match against other attributes

  • compliance —Compliance status to indicate whether the iOS device is compliant

  • ownership—Ownership category of the iOS device (for example, Employee Owned)


3. Save & Publish the Profile to the appropriate devices

screenshot for save and publish​​​
Firewall configuration:
  1. Create the HIP object under “Mobile Device” → “Tag” and set HIP objects checking for the values you assigned in Workspace Onehip object configuration
  2.  Configure a HIP profile using the HIP object configured in step # 1
Hip profile configuration
 
   3.  HIP reports for the devices with the MDM VPN profile will include the tags
         Hip report on the firewall
 
 


Additional Information



 


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000kHZpCAM&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail