Rolling out enterprise mobile devices at scale can be risky. We are often asked by customers how to lock down mobile devices deployed in the field, such as phones, tablets or hand-help Android devices, to prevent other apps being loaded or to enforce certain usage policies such as blocking social media traffic.
Most customers approach this as a device problem, and solve it with device management software (MDM). That is one level of control. In our experience the most effective method is to also apply control one level lower, on the mobile data connection itself.
Control the connection with a Managed Private APN
SIMcontrol SIMs can be placed on a Managed Private APN, where all traffic passes through our firewall before it reaches the internet. You decide which specific destinations your devices may reach, and everything else is blocked.
Because the control sits in the network rather than on the handset, it applies to every device on your account, requires no software to be installed, and cannot be removed or bypassed by the person using the device. If SIMs are placed in different devices, the rules still apply.
Firewall policies – allow only the destinations your business applications need. Traffic that falls outside your policy is blocked, and is reported separately as blocked traffic versus allowed traffic.
Usage visibility – see which apps and destinations are consuming mobile data, so unexpected usage is easy to identify and act on.
IMEI Lock – tie a SIM to a specific device, so that it stops working if it is moved into another handset. See IMEI Lock on Managed Private APN.
Lock and unlock SIMs – suspend connectivity immediately on a lost or stolen device, and restore it just as quickly. See Lock & unlock managed APN SIMs.
Data quota notifications – set a limit per SIM and be alerted before it is reached. See SIM Data Quota Notifications on Managed APN.
Technical details on the private APN service is available on request.
Locking down the device itself
A private APN controls what a device may reach, but not what is installed on it. Where you also need to restrict the device, this is best handled with an Enterprise Mobility Management or Mobile Device Management platform, such as Android Enterprise and its list of Android-approved EMM's.
The two approaches work well together, and we would be glad to advise on the combination that best suits your deployment.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article