icon-zapp.svg
Client Connector

Deploying Zscaler Client Connector with Workspace ONE UEM for Android

This guide is for admins only. If you are an end user, contact your organization’s administrator for deployment-related details.

With Workspace ONE Unified Endpoint Management (UEM), you can configure and deploy Zscaler Client Connector for Android devices by pushing the app:

  • From Google Play with Android Enterprise enabled
  • From Google Play without Android Enterprise enabled
  • As an APK file

If you deploy Zscaler Client Connector from Google Play with Android Enterprise enabled, you can preconfigure Zscaler Client Connector with parameters. This allows you to simplify the Zscaler Client Connector enrollment process for your users. But, if you deploy Zscaler Client Connector from Google Play without Android Enterprise enabled or as an APK file, you cannot preconfigure Zscaler Client Connector.

The version used for the following steps is Workspace ONE UEM 20.7.0.0 (2007).

  • To deploy Zscaler Client Connector to Workspace ONE UEM for Android devices from the Google Play Store:

    1. In the Workspace ONE UEM portal, go to Apps & Books > Applications > Native > Public and then click Add Application.

    Screenshot of Worksapce ONE UEM portal to select Apps&Books from the menu

    1. On the Add Application page, configure the following options, and then click Next.
    • Managed By: Enter Zscaler.
    • Platform: Select Android from the Platform drop-down menu.
    • Source: Click Search App Store.
    • Name: Enter Zscaler Client Connector.

    Screenshot of Worksapce ONE UEM portal with Add Application Window

    1. Select Zscaler Client Connector from the Google Play store.

    Screenshot of Worksapce ONE UEM portal selecting Zscaler Client Connector from the Google Play Store

    1. Click Approve to review and accept Zscaler Client Connector permissions.
    2. Select Keep approved when app requests new permissions to automatically approve all future updates to the app.
    3. Click Select to select Zscaler Client Connector from the Google Play store.

    Screenshot of Worksapce ONE UEM portal selecting Zscaler Client Connector to add the app to the portal

    1. On the Details tab, enter Zscaler Client Connector in the Name field, and then click Save & Assign. Zscaler Client Connector is added to your Workspace ONE UEM portal.

    Screenshot of Worksapce ONE UEM portal App Configuration Details page

    1. Select Zscaler Client Connector for the Android platform from the Workspace ONE UEM portal, and then click Assign.

    Screenshot of Worksapce ONE UEM portal selecting Assign from the portal

    1. On the Zscaler Client Connector - Assignment page, click Add Assignment and then click Save.

    Screenshot of Worksapce ONE UEM portal selecting Add Assignment for app assignments

    1. On the Distribution tab, configure the following options and then click Create.
      • Name: Enter Zscaler Client Connector.
      • Description: Enter a relevant description for the app.
      • Assignment Groups: Select a group for which you want to assign the app.
      • App Delivery Method: Select the app delivery method as Auto or On-Demand based on your requirements.
      • Pre-release Version: Select None from the drop-down menu.

    Screenshot of Worksapce ONE UEM portal Distribution tab for app Assignments

    1. (Optional) On the Application Configuration tab:

    If you have Android Enterprise enabled, you can use parameters to preconfigure Zscaler Client Connector. Preconfiguring Zscaler Client Connector allows you to remove steps from the user enrollment process (e.g., allowing users to skip the enrollment page or the cloud selection prompt on Zscaler Client Connector).

    1. Enable Send Configuration.
    2. The following parameters are available to configure:
    • userDomain: Your organization’s domain name (e.g., safemarch.com). If your instance has multiple domains associated with it, enter the primary domain for your instance.
    • cloudName: The name of the cloud on which your organization is provisioned. For example, if your cloud name is zscalertwo.net, you would enter zscalertwo. To learn more, see What is my cloud name for ZIA?
    • deviceToken: The appropriate device token from the Zscaler Client Connector Portal, if you want to use the Zscaler Client Connector Portal as an IdP.
    • userName: The username for the user. For example, if the username is j.doe@zscaler.com, enter j.doe.
    • enableFips: Enabling this option indicates that Zscaler Client Connector uses FIPS-compliant libraries for communication with Zscaler infrastructure. Enter 1 to enable or 0 to disable this option.

    Enable this option only if you require FIPS-level security within your organization.

    • Ownership: If you use the Ownership Variable device posture type, add the key Ownership. You can enter up to 32 alphanumeric characters in the Configuration value field. To learn more, see Configuring Device Posture Profiles for ZPA.
    • autoEnrollWithMDM: Use this parameter to determine auto-enrollment without user interaction, when using the Zscaler Client Connector Portal as an IdP. Select from the following options:
      • Enter 0 to disable auto-enrollment.
      • Enter 1 to have users always auto-enroll, even if they log out.
      • Enter 2 for one-time auto-enrollment.

    This option applies to only the ZIA-enabled accounts that are using Zscaler Client Connector Portal as an IdP. You must specify the parameters deviceToken, cloudName, and userDomain before enabling the autoEnrollWithMDM option.

    • customDNS: By default, Zscaler Client Connector uses the device's DNS server. You can change the value to another DNS server using this setting. Enter the DNS IP address.
    • allowRunningOnRootedDevice: This is set to 0 by default to restrict users from running Zscaler Client Connector on a rooted device. Enter 1 to allow users to run Zscaler Client Connector on a rooted device.
    • externalDeviceId: Use this ID to associate devices in an MDM solution with devices in the Zscaler Client Connector Portal. By default, the value is 0. Enter a custom value to identify the device.

    Screenshot of Worksapce ONE UEM portal Application Configuration tab for app configurations

    1. Click Create.
    2. On the Zscaler Client Connector - Assignment page, review the values and settings entered, and then click Save. Zscaler Client Connector is pushed to the devices in the group that you selected.

    Screenshot of Worksapce ONE UEM portal Assignment page to review app Assignments

    After Zscaler Client Connector is installed on users’ devices, they must launch the app and log in to enroll in the Zscaler service.

    Close
  • To deploy Zscaler Client Connector to Workspace ONE UEM for Android devices as an APK file:

    1. From the Zscaler Client Connector Portal, go to Administration > Client Connector App Store and download the Zscaler Client Connector APK file from the Registered Devices tab.

    Contact Zscaler Support to enable the APK file link.

    1. On the Workspace ONE UEM portal, go to Apps & Books > Applications > Native > Internal and then click Add. Select Application File from the drop-down menu.

    Screenshot of Worksapce ONE UEM portal to select Apps&Books from the menu

    1. On the Add Application page:
    • Organization Group ID: Enter Zscaler.
    • Application File: Click Upload.

    Screenshot of Worksapce ONE UEM portal Add Application page to upload app APK file

    1. On the Add page, select Choose File to upload Zscaler Client Connector APK file from your local file, and then click Save.

    Screenshot of Worksapce ONE UEM portal Add page to upload app APK file

    1. Click Continue on the Add Application page.

    Screenshot of Worksapce ONE UEM portal app APK file uploaded to Add Application page

    1. On the Details tab, configure the following options, and then click Save & Assign.
      • Name: Enter Zscaler Client Connector.
      • Minimum OS: Select Android 8.0.

    The minimum operating system for Android on ChromeOS is Android 6.0.

    Screenshot of Worksapce ONE UEM portal App Configuration Details page

    1. On the Zscaler Client Connector - Assignment page, click Add Assignment.

    Screenshot of Worksapce ONE UEM portal Assignment page to add app assignments

    1. On the Distribution tab, configure the following options, and then click Create.
    • Name: Enter Zscaler Client Connector.
    • Description: Enter a relevant description for the app.
    • Assignment Groups: Select a group for which you want to assign the app.
    • Deployment Begins: Set a date and a time for the deployment to start based on your requirements.
    • App Delivery Method: Select the app delivery method as Auto or On Demand based on your requirements.

    Screenshot of Worksapce ONE UEM portal Distribution tab to select app assignment

    1. On the Zscaler Client Connector - Assignment page, review the values and settings entered, and then click Save. Zscaler Client Connector is pushed to the devices in the group that you selected.

    Screenshot of Worksapce ONE UEM portal Assignment page to review app Assignments

    After Zscaler Client Connector is installed on users’ devices, they must launch the app and log in to enroll in the Zscaler service.

    Close
Related Articles
Understanding Zscaler Client Connector App DownloadsConfiguring Zscaler Client Connector for Microsoft 365 Cloud PCsCustomizing Zscaler Client Connector with Install Options for MSICustomizing Zscaler Client Connector with Install Options for EXECustomizing Zscaler Client Connector with Install Options for macOSCustomizing Zscaler Client Connector with Install Options for LinuxCustomizing Zscaler Client Connector with Install Options for AndroidCustomizing Zscaler Client Connector with Install Options for iOSDeploying Zscaler Client Connector with Active Directory for WindowsDeploying ZDX With Workspace ONE UEM for iOSDeploying ZDX with Jamf Pro for iOSDual Tunnel Feature Configuration with Jamf Pro for iOSDual Tunnel Feature Configuration with Microsoft Intune for iOSDeploying Zscaler Client Connector with MaaS360 for AndroidDeploying Zscaler Client Connector with MaaS360 for iOSDeploying Zscaler Client Connector with Microsoft Intune for AndroidDeploying Zscaler Client Connector with Microsoft Intune for macOSDeploying Zscaler Client Connector with Microsoft Intune for iOSDeploying Zscaler Client Connector with Google WorkspaceDeploying Zscaler Client Connector with MobileIron for iOSDeploying Zscaler Client Connector with MobileIron for AndroidDeploying Zscaler Client Connector with JAMF Pro for macOSDeploying Zscaler Client Connector with Jamf Pro for iOSDeploying Zscaler Client Connector with Workspace ONE UEM for AndroidDeploying Zscaler Client Connector with Workspace ONE UEM for iOSBlocking LAN AccessBest Practices for Zscaler Client Connector DeploymentBest Practices for Updating Latest Versions of Zscaler Client Connector ApplicationUninstalling Zscaler Client ConnectorReverting Zscaler Client Connector to the Previous VersionUpgrading Zscaler Client Connector