icon-zapp.svg
Client Connector

Deploying Zscaler Client Connector with MobileIron for Android

This guide is for admins only. If you are an end user, contact your organization’s administrator for deployment-related details.

With MobileIron Unified Endpoint Management (UEM), you can configure and deploy Zscaler Client Connector for Android devices. Before deploying Zscaler Client Connector, you must first enable the Android Enterprise feature for MobileIron UEM. For more information, refer to the MobileIron documentation.

The following deployment procedure is based on MobileIron Core 10.1.

To configure and deploy Zscaler Client Connector to MobileIron for Android devices:

  1. In the MobileIron Admin Portal, click Apps from the top menu.

Navigating to the apps page to import the Zscaler Client Connector

  1. Click Add to import Zscaler Client Connector to the App Catalog.

  1. Click Google Play, and then search for Zscaler Client Connector.

Searching for the Zscaler Client Connector

  1. Select Zscaler Client Connector from the list, and then click Next.

Selecting the Zscaler Client Connector

  1. (Optional) Modify the Description and select a Category. Click Next.

Details for the Zscaler Client Connector

  1. In the Android Enterprise (All Modes) section, enable the Install this app for Android enterprise option.

Enabling Zscaler Client Connector for Android Enterprise

The Configuration Choices section appears.

This section appears only if you have already enabled Android Enterprise for MobileIron Core.

Configuration choices for the Zscaler Client Connector

  1. Under Default Configuration for Zscaler Client Connector, the following parameters are available to configure:

    • userDomain: Your organization’s domain name, e.g., safemarch.com. If your instance has multiple domains associated with it, enter the primary domain for your instance.
    • cloudName: The name of the cloud on which your organization is provisioned. For example, if your cloud name is zscalertwo.net, you would enter zscalertwo. To learn more, see What is my cloud name for ZIA?
    • deviceToken: The appropriate device token from the Zscaler Client Connector Portal, if you want to use the Zscaler Client Connector Portal as an IdP.
    • userName: The username for the user. For example, if the username is j.doe@safemarch.com, enter j.doe.
    • enableFips: Enabling this option indicates that Zscaler Client Connector uses FIPS-compliant libraries for communication with Zscaler infrastructure. Enter 1 to enable or 0 to disable this option.

    Enable this option only if you require FIPS-level security within your organization.

    • Ownership: If you use the Ownership Variable device posture type, add the key Ownership. You can enter up to 32 alphanumeric characters in the Configuration value field. To learn more, see Configuring Device Posture Profiles for ZPA.
    • autoEnrollWithMDM: Use this parameter to determine auto-enrollment without user interaction, when using the Zscaler Client Connector Portal as an IdP. Select from the following options:
      • Enter 0 to disable auto-enrollment.
      • Enter 1 to have users always auto-enroll, even if they log out.
      • Enter 2 for one-time auto-enrollment.

    This option applies to only the ZIA-enabled accounts that are using Zscaler Client Connector Portal as an IdP. You must specify the parameters deviceToken, cloudName, and userDomain before enabling the autoEnrollWithMDM option.

    • customDNS: By default, Zscaler Client Connector uses the device's DNS server. You can change the value to another DNS server using this setting. Enter the DNS IP address.
    • allowRunningOnRootedDevice: This is set to 0 by default to restrict users from running Zscaler Client Connector on a rooted device. Enter 1 to allow users to run Zscaler Client Connector on a rooted device.
  2. Click Finish.

The Default Configuration for Zscaler Client Connector options

You can now register the device (that has a work profile or is in Device Owner mode) and apply the Android Enterprise configuration. Zscaler Client Connector is automatically installed and configured.

Users must open Zscaler Client Connector once for the configurations to be applied for the first time.

Related Articles
Understanding Zscaler Client Connector App DownloadsConfiguring Zscaler Client Connector for Microsoft 365 Cloud PCsCustomizing Zscaler Client Connector with Install Options for MSICustomizing Zscaler Client Connector with Install Options for EXECustomizing Zscaler Client Connector with Install Options for macOSCustomizing Zscaler Client Connector with Install Options for LinuxCustomizing Zscaler Client Connector with Install Options for AndroidCustomizing Zscaler Client Connector with Install Options for iOSDeploying Zscaler Client Connector with Active Directory for WindowsDeploying ZDX With Workspace ONE UEM for iOSDeploying ZDX with Jamf Pro for iOSDual Tunnel Feature Configuration with Jamf Pro for iOSDual Tunnel Feature Configuration with Microsoft Intune for iOSDeploying Zscaler Client Connector with MaaS360 for AndroidDeploying Zscaler Client Connector with MaaS360 for iOSDeploying Zscaler Client Connector with Microsoft Intune for AndroidDeploying Zscaler Client Connector with Microsoft Intune for macOSDeploying Zscaler Client Connector with Microsoft Intune for iOSDeploying Zscaler Client Connector with Google WorkspaceDeploying Zscaler Client Connector with MobileIron for iOSDeploying Zscaler Client Connector with MobileIron for AndroidDeploying Zscaler Client Connector with JAMF Pro for macOSDeploying Zscaler Client Connector with Jamf Pro for iOSDeploying Zscaler Client Connector with Workspace ONE UEM for AndroidDeploying Zscaler Client Connector with Workspace ONE UEM for iOSBlocking LAN AccessBest Practices for Zscaler Client Connector DeploymentBest Practices for Updating Latest Versions of Zscaler Client Connector ApplicationUninstalling Zscaler Client ConnectorReverting Zscaler Client Connector to the Previous VersionUpgrading Zscaler Client Connector