About deploying the
SEP Mobile
app on devices with Android work profile

The Android enterprise solution (Android for Work) offers a work profile container that lets you manage all business content and apps within the container, without accessing personal content and apps.
There are 3 methods to deploy the
SEP Mobile
app on devices with Android work profile
  1. As a managed app inside the container
  2. As a regular app outside the container
  3. As an inside and outside the container app
Pros and cons of each deployment method
SEP Mobile
deployment option
Pros
Cons
Inside the container
  • A single installation of the app
  • Full protection against network connection threats that are applied to enterprise apps and content
  • Full protection against OS-level vulnerabilities and advanced indicators of compromise
    Alerting on available OS upgrade
  • Malware and unwanted apps are analyzed only for apps inside the container
  • No protection against SMS phishing
  • Enforcement of access to sensitive corporate resources is limited (based on threats inside the container, and only applies to access from the container)
Outside the container
  • A single installation of the app
  • Full protection against network threats
  • Malware and unwanted apps are analyzed for all apps that the end-user installs outside the container, thus applying protection against threats on BYO devices
  • Full protection against OS-level vulnerabilities and advanced indicators of compromise
    Alerting on available OS upgrade
  • Protection against network threats, malicious or unwanted apps cannot be applied to enterprise apps and content inside the container
  • Enforcement of access to sensitive corporate resources is limited (based on threats outside the container, and only applies to access from outside the container)
Inside and outside the container
  • Complete detection and protection of threats across the device
  • Enforcement of access to sensitive corporate resources across the device
Requires installing SEP Mobile twice on each device
Key considerations when evaluating each deployment method
  • Unmanaged apps, content, and configuration (e.g. malware, SMS phishing and device root, etc.) outside the work profile can pose a threat to the entire device.
  • Apps installed on the work profile can only monitor apps and processes running inside the container.
  • While it's possible to easily deploy and activate the
    SEP Mobile
    app inside the container as a managed app, deploying outside the container requires more interaction with the end-user. To resolve interaction friction with end-users, you can deploy the app through an SMS message.