Data security for Android Enterprise

Data at Rest Security

When devices are configured for Android Enterprise, device encryption is required. Before a work profile can be created, encryption must be enabled. All data at rest and managed by applications is encrypted.

Remote App and Data Wipe

In an Android Enterprise environment, there can be situations when a device needs the enterprise data that is associated with the HCL Connections app wiped. This might happen because the device was lost, the device is no longer compliant with your security policies, or perhaps the user has left the company and can no longer have access to this data. If any of these situations occur, the Android Enterprise administrator can choose to wipe just the Android Enterprise apps and data from the device. This removes the Android Enterprise work profile and all data that is associated with the Android Enterprise apps. Any Android Enterprise apps are also removed. Apps that are installed in the personal profile remain. The wipe of the work profile is performed from the EMM administration console you are using to manage your Android Enterprise environment.

Secure Tunneling

To grant the HCL Connections mobile server application access to an HCL Connections server deployed within a company intranet topology, the HCL Connections application must be configured to point to the server URL of an edge proxy, such as HCL Mobile Connect or a per-app VPN must be used. When using a per-app VPN, the VPN application must be an approved Android Enterprise application and deployed within the work profile.

Preventing Data Leaks

With Android Enterprise, data can be copied and pasted between applications within the Work profile since they are approved by the company Android Enterprise administrator. Similarly, the screen capture capability is controlled through the EMM administration console for all applications that are managed within the work profile. Attachments and files can be shared with other applications with the work profile since those applications are also approved and managed.

App Passcodes

Starting with Android 7, app passcodes can be configured for the work profile so when an Android Enterprise application is launched, the passcode must be entered. This capability depends on your specific EMM provider support.