Hardware reference guide

86 GlobalProtect Administrator’s Guide
Define Deployment Policies Set Up the GlobalProtect Mobile Security Manager
Define HIP Objects and HIP Profiles
Using HIP profiles in Mobile Security Manager policy enables granular deployment of configurations and
ensures that the mobile devices are in compliance with corporate security requirements in order to receive the
configuration profile(s) that enable access to your corporate resources. For example, before pushing
configurations that enable access to your corporate systems, you might want to ensure that the device data is
encrypted and that the devices are not jailbroken/rooted. To do this, you would create a HIP profile that
matches devices that meet this criteria and attach it to your deployment policy rules.
Step 2 Add the LDAP server profile to the directory integration configuration.
1. Select
Setup > User Database > Directory
Integration
and click Add.
2. Select the
Server Profile you just created.
3. Make sure the
Enabled check box is selected.
4. (Optional) If you want to limit which groups
are displayed within deployment policy, select
the
Group Include List tab and then browse
through the LDAP tree to locate the groups
you want to be able to use in policy. For each
group you want to include, select it in the
Available Groups list and click the add icon
to move it to the
Included Groups list. Repeat
this step for every group you want to be able
to use in your policies.
5. Click
OK to save the settings.
Step 3 Click
Commit to save the configuration.
Integrate with the Directory Server (Continued)