Experience Center
Deploying Zscaler Client Connector with Microsoft Intune for Android
This guide is for admins only. If you are an end-user, contact your organization’s administrator for deployment-related details.
With Microsoft Intune, you can deploy Zscaler Client Connector for your Android devices. The Microsoft Intune Service release version 2006 is shown in the following steps.
- From Google Play with Android Enterprise enabled
To deploy Zscaler Client Connector to Microsoft Intune for Enterprise enabled Android devices:
Close- Configure Managed Google Play app
- Click All apps, and then click Add.
- Select Managed Google Play app from the App type drop-down menu, and then click Select.
- In the Managed Google Play app store, search for and select Zscaler Client Connector.
- Click Approve to accept Zscaler Client Connector permissions in the Managed Google Play page.
- Select Keep approved when app requests new permissions in the Approval Settings tab, and then click Done.
- Click Select, and then click Sync to add Zscaler Client Connector to your Intune Portal.
- To configure the app for Android devices:
- Navigate to Client apps > App configuration policies > Add > Managed devices.
- On the Basics tab, configure the following parameters, and then click Next.
- Name: Enter
Zscaler Client Connector
. - Description: (Optional) Enter a relevant description for Zscaler Client Connector.
- Platform: Select Android Enterprise.
- Profile Type: Select a relevant profile type based on your requirements. In this example, it's Work Profile Only.
- Targeted app: Click Select app, select Zscaler Client Connector from the Associated app window, and then click OK.
The Device enrollment type field is automatically set to Managed devices and is not editable.
- On the Settings tab, select Use configuration designer as the Configurations settings format.
- Click Add. Select the following configuration keys for the app, and then click OK.
- Ownership: If you use the device posture type Ownership Variable, add the key
Ownership
. You can enter up to 32 alphanumeric characters in the Configuration value field. To learn more, see Configuring Device Posture Profiles. - userDomain: Your organization's domain name (e.g.,
safemarch.com)
. If your instance has multiple domains associated with it, enter the primary domain for your instance. - cloudName: The name of the cloud on which your organization is provisioned. For example, if your cloud name is zscalertwo.net, you would enter
zscalertwo
. - deviceToken: The appropriate device token from the Admin Portal, if you want to use the Zscaler Client Connector as an IdP.
userName: The username for the user. For example, if the username is j.doe@zscaler.com, you would enter
j.doe.
To use the same username used for enrolling into Intune, you can use the
{{partialupn}}
token. To view a complete list of available Intune tokens, refer to the Microsoft documentation.enableFips: Enabling this option indicates that Zscaler Client Connector uses FIPS-compliant libraries for communication with Zscaler infrastructure. Enter
1
to enable or0
to disable this option.Enable this option only if you require FIPS-level security within your organization.
autoEnrollWithMDM: Use this parameter to determine auto-enrollment without user interaction when using Zscaler Client Connector as an IdP. Select from the following options:
- Enter
0
to disable auto-enrollment. - Enter
1
to have users always auto-enroll, even if they log out. - Enter
2
for one-time auto-enrollment.
This option applies to only the Internet & SaaS-enabled accounts that are using Zscaler Client Connector as an IdP. The parameters deviceToken, cloudName, and userDomain must be specified before enabling the autoEnrollWithMDM option.
- Enter
- customDNS: By default, Zscaler Client Connector uses the device's DNS server. You can change the value to another DNS server using this setting. Enter the DNS IP address.
- allowZCCOnRootedDevice: This is set to 0 by default to restrict users from running Zscaler Client Connector on a rooted device. Enter
1
to allow users to run Zscaler Client Connector on a rooted device. - externalDeviceId: Use this ID to associate devices in an MDM solution with devices in the Admin Portal. By default, the value is 0. Enter a custom value to identify the device.
- After you enter the appropriate values for the configuration keys that you selected, click Next.
- On the Assignments tab, select the group assignments for which you want to assign the app configuration policy, and then click Next.
- On the Review + create tab, review the values and settings entered, and then click Create. Zscaler Client Connector is pushed to the devices in the group that you selected.
After Zscaler Client Connector is installed on users' devices, they must launch the app and log in to enroll in the Zscaler service.
Close - Configure Managed Google Play private app
- In the Microsoft Intune Portal, click Apps from the left-side navigation.
- Click Add.
- Select Managed Google Play app from the App type drop-down menu, and then click Select.
- In the Managed Google Play app section, click the lock icon from the left-side menu.
- Click the + icon located on the bottom left corner of the screen.
- In the Private app section:
- Title: Add a title of your file.
- APK file: Upload the APK file. Contact Zscaler Support for a private APK file.
- Click Create.
The app can take up to 10 minutes to publish and appear in private apps.
- Select the app you have created from the Android apps list.
- (Optional) Click Edit next to App information and Assignments to make any changes to these sections.
- On the Review + create tab, review the values and settings entered and save your settings.
To configure Always on VPN device restrictions for private apps, see Configure Always On VPN.
Close
- Configure Managed Google Play app
- From Google Play without Android Enterprise enabled
To deploy Zscaler Client Connector to Microsoft Intune from the Google Play Store for Android devices that are not Enterprise enabled:
- In the Microsoft Intune Portal, click Apps from the menu.
- Click All apps, and then click Add.
- Select Android store app from the App type drop-down menu, and then click Select.
- To add the app from the Android store app:
- On the App information tab, provide the following Zscaler Client Connector details, and then click Next.
- Name: Enter
Zscaler Client Connector
. - Description: Enter a relevant description for Zscaler Client Connector.
- Publisher: Enter
Zscaler Inc
. - Appstore URL: Enter the following Google Play Store URL:
https://play.google.com/store/apps/details?id=zscaler.com.zscaler. Minimum operating system: Select Android 8.0.
The minimum operating system for Android on ChromeOS is Android 6.0.
- Show this as a featured app in the Company Portal: Select Yes.
- Name: Enter
- On the App information tab, provide the following Zscaler Client Connector details, and then click Next.
- On the Assignments tab, select the group assignments for which you want to deploy Zscaler Client Connector, and then click Next. For more information on adding groups, refer to Microsoft technical documentation.
- On the Review + create tab, review the values and settings entered, and then click Create. Zscaler Client Connector is pushed to the devices in the group that you selected.
After Zscaler Client Connector is installed on users' devices, they must launch the app and log in to enroll in the Zscaler service.
Close - As an APK file
To deploy Zscaler Client Connector to Microsoft Intune for Android devices as an APK file:
- Configure using an App Package File
- From the Admin Portal, download the Zscaler Client Connector APK file.
- In the Microsoft Intune Portal, click Apps from the menu.
- Click All apps, and then click Add.
- Select Line-of-business app from the App type drop-down menu, and then click Select.
- To add the app as an APK file:
- On the App information tab, click Select app package file.
- Upload the Zscaler Client Connector APK file, and then click OK.
- Provide the following Zscaler Client Connector details, and then click Next.
- Name: Enter
Zscaler Client Connector
. - Description: Enter a relevant description for Zscaler Client Connector.
- Publisher: Enter
Zscaler Inc
. - Minimum operating system: Select Android 8.0.
- Show this as a featured app in the Company Portal: Select Yes.
- Name: Enter
- On the Assignments tab, select the group assignments for which you want to deploy Zscaler Client Connector, and then click Next. For more information on adding groups, see Microsoft technical documentation.
- On the Review + create tab, review the values and settings entered, and then click Create. Zscaler Client Connector is pushed to the devices in the group that you selected.
After Zscaler Client Connector is installed on users' devices, they must launch the app and log in to enroll in the Zscaler service.
Close - Configure Always On VPN (Optional)
Zscaler Client Connector can restrict the traffic and secure the device before enrollment if Always ON VPN is enabled on your organization's MDM for Zscaler Client Connector. After the app is enrolled, it intercepts the traffic and forwards it according to the policies in the Admin Portal. To learn more, refer to Android documentation.
- In the Microsoft Intune for Android Admin Portal, go to Devices > Android.
- From the options, click Configuration Profiles.
- Click Create profile.
- In the Create a profile section:
- Platform: Enter
Android Enterprise
. - Profile type: Choose Device Restrictions from the Profile type drop-down menu Fully managed or Personally Owned Work Profiles based on your configuration.
- Click Create.
- In the Basics section:
- Name: Enter a name.
- Description: (Optional) Enter a description.
- Click Next.
- In the Configuration settings section, expand the Connectivity section:
- Always-on VPN: Enable to allow Zscaler Client Connector to restrict the traffic and secure the device without enrollment.
- VPN client: Choose Custom.
- Package ID: Type your package ID e.g., (
zscaler.com.zscaler
.)
- Click Next.
- In the Assignments section, choose the users, groups, and devices for the profile.
- Click Next.
- In the Review + create section, review the summary, and click Create.
- Configure using an App Package File
If you deploy Zscaler Client Connector from Google Play with Android Enterprise enabled, you can preconfigure Zscaler Client Connector with parameters. This allows you to simplify the Zscaler Client Connector enrollment process for your users. But, if you deploy Zscaler Client Connector from Google Play without Android Enterprise enabled or as an APK file, you cannot preconfigure Zscaler Client Connector.