Mobile Security 5.6.x Platform Guide

Prev Next

Release 5.6.x February 2025

Preface

This guide explains the deployment and configuration of the Trellix Mobile Security app on an iOS or Android device. With this release of 5.0 and later, most of the iOS and Android screens match; however, they differ in some cases. The screenshots in this document may reflect either OS.

Note: This document also describes how to run the Trellix Mobile Security application on a Chromebook device. Trellix Mobile Security for Android for Chromebook requires that Chromebook supports Android apps and the Google Play Store. For more information on this topic, see Appendix B – Android Support for Chromebooks section.

For related documentation, please contact Trellix support.

Audience

The intended audience for this guide is a Trellix Mobile Security administrator, security administrator, or a device end-user. The Trellix Mobile Security application provides threat protection to mobile devices. The system administrator for Trellix Mobile Console sets policies for threats, and also monitors and manages threats detected.

Supported Languages

Trellix Mobile Security provides support for the following languages on the device:

  • Arabic

  • Bengali

  • Chinese Simplified

  • Chinese Traditional

  • Dutch

  • English

  • French

  • German

  • Haitian Creole

  • Hebrew

  • Japanese

  • Korean

  • Polish

  • Russian

  • Spanish

  • Urdu

  • Vietnamese

System Requirements

For information about Trellix Mobile Security system requirements, refer to the Trellix Mobile Security Release Notes (iOS or Android).

Introduction

The Trellix Mobile Security app provides continuous detection and mitigation of malicious events affecting devices running the iOS or Android platforms. This is accomplished through real-time forensic data analysis by a detection engine that has been enhanced by machine learning. A central console is used to configure policies and manage threat events.

Note: Refer to the Related Documentation section in this guide to reference other documents.

While a user can interact with Trellix Mobile Security to see current device security status, health, and previous events, there is no requirement for any interaction.

Mitigation is performed by the Trellix Mobile Security application and through Mobile Device Management (MDM) integration via a supported MDM vendor. The type of mitigation performed is determined by the MDM integration and can range from a simple notification to the user to a wipe of all company data from the device.

This guide includes information about:

  • How the application is deployed and installed.

  • Setting runtime permissions.

  • Navigating the application.

  • Viewing events, risks, and threats.

  • The functionality provided by Trellix Mobile Security.

  • Configuration options that exist from Trellix Mobile Console.

Customer documentation that details the configuration and use of Trellix Mobile Console and the specific MDM integrations can be downloaded from the customer portal.

Detection Engine

The security experts at Trellix developed a revolutionary cyberattack detection engine that uses statistical models to dynamically detect advanced host- and network-based attacks as well as malicious applications on mobile devices. Unlike other threat detection systems, the detection engine monitors the whole device for malicious behavior without reliance on signatures. This approach allows Trellix to find and protect against both known and unknown threats in real-time, regardless of the threat source and with or without being connected to the Internet.

In addition, for Android and iOS with MDM integration, the malware engine scans for suspicious applications installed on the device and scans applications prior to being installed on the device to offer continuous protection. If malware is detected during scanning, action can be taken to remove a suspicious application, even if the device has no network connectivity. If an internet connection is available, Trellix Mobile Security performs additional malware scanning analysis against Trellix's proprietary database. This database is built using data from Trellix's research team as well as other sources.

The behavioral detection engine sits on the device, within the Trellix Mobile Security application, to detect threats without the need for Internet connectivity or special privileges, preventing a compromised device from gaining access to the corporate network. This unique approach protects the user's privacy and prevents excessive battery drain that occurs when data is sent to the cloud to determine if a certain behavior is malicious. All decisions are made on the device.

iOS Trellix Mobile Security Apps Scanning and MDM Integration

In addition, when using Trellix Mobile Security through an MDM integration, the applications on the device are scanned to see if any are malicious, with iOS Trellix Mobile Security alerting the user as needed. Trellix maintains a database of malicious iOS applications, which is built using data from Trellix's security research team and other sources. Unknown apps are evaluated in real-time, and a decision is made as to whether they are legitimate or malicious.

Android Trellix Mobile Security App Scanning Modes

Android Trellix Mobile Security checks for suspicious applications in these modes:

  • Automatic Mode before Install: When the user downloads an application from the browser, email, or any other client (which saves the file on the SDCARD), Trellix Mobile Security scans it. Trellix Mobile Security then alerts the user if the application is suspicious before the application is installed and provides a button to delete the suspicious application from the device.

  • Automatic Mode after Install: When a new application is installed, Trellix Mobile Security scans it. If it is suspicious, an event is sent to Trellix Mobile Console, and an alert is displayed with an option to uninstall the application.

Trellix Mobile Security Communicating with Trellix Mobile Console

Trellix Mobile Security communicates to Trellix Mobile Console every eight hours or when an event occurs to upload certain device information to determine if there are any policy updates that need to be incorporated. When Trellix Mobile Security is initially started, it requests the latest detection engine from Trellix Mobile Console. The latest threat policy is also downloaded along with the privacy settings. The information passed up to Trellix Mobile Console is configured with the privacy template on Trellix Mobile Console.

Threat Policy and Updates

The Trellix Mobile Security Console threat policy contains rules for the actions to take when certain threats are identified. The threat policy is updated in these ways:

  • Trellix Mobile Console sends a notification that a new threat policy is available. Then, Trellix Mobile Security pulls the updated policy information. For notifications to display in Trellix Mobile Security, the Alert User setting must be toggled on for any threat in the Threat policy.

  • Trellix Mobile Security polls Trellix Mobile Console to see if there is an updated threat policy available to download. The time interval for this polling is currently configured by Trellix.

Note: For more information about the threat policy, refer to the Trellix Mobile Security Console documentation.

Threat Policy and Severity

Behavior on the device is different based on the severity level set on each threat. These threat severity levels are set by the administrator and the policy configuration is useful for different use cases. The severity options are:

  • Normal

  • Low

  • Elevated

  • Critical

Threat information is displayed in a variety of ways on the device:

  • Dashboard: This is the initial screen on the Trellix Mobile Security app and shows tiles for the different topic categories, such as Web, Device (if configured). The dashboard shows elevated severity threats as risks detected and critical severity threats as threats detected, and the total number of both as active issues. The dashboard also shows the number as the number of active issues. See Navigating Trellix Mobile Security in this guide for more information.

  • Full Event Log: This shows a list of all the threats encountered, other than threats with the severity of normal. For threats classified as low severity, the user does not receive notification other than an entry in the event log. See the Viewing the Full Event Log section in this guide for more information.

  • User Alerts: Alerts display a message or warning to the device user. User alerts are enabled or disabled by the administrator for each threat in the Trellix Mobile Security Console Threat policy.

Trellix Mobile Security Deployment and Installation

Overview

The Trellix Mobile Security application is deployed using one of the following modes:

  • With With MDM integration: This installation is referred to as Enterprise Trellix Mobile Security. If a customer has an MDM solution, Trellix strongly suggests that the MDM be used to distribute the application. These steps are described in separate MDM integration guides specific to the supported MDM.

Note: For MDM deployment and installation information, follow the instructions to complete the MDM integration in the specific vendor-related MDM guide. You can find these documents at this website: https://docs.trellix.com/.

  • Without MDM integration: Without an MDM implementation, the user is instructed to download the Trellix Mobile Security application from the App Store or Google Play Store.

Initializing Trellix Mobile Security

When Trellix Mobile Security is installed on the device, it has to either be launched by the user or configured to protect the device on the MDM. If it is launched by the user, an initial set of installation screens is displayed. The user launches this by tapping on the Trellix Mobile Security icon that shows up on the device. An MDM configuration can push the Trellix Mobile Security installation and include some tailoring of activation, depending on the MDM.

Activation

Several Trellix Mobile Security activation features, along with the zero-touch activation option, are described in this section. The user can activate Trellix Mobile Security in one of the following ways:

  • Pressing the activation link (URL).

  • Logging in with Microsoft.

  • Scanning a QR code with the device's camera.

  • Activation with MDM integration is recommended, if possible, and involves several configuration options for activation.        

    • Regarding an activation through an email to the device user, the administrator can request an email notification for each iOS and Android device. This is done when the administrator adds the MDM in Trellix Mobile Console. The email contains a Trellix Mobile Security activation link for each new device that is synchronized from the MDM. See the Trellix Mobile Console documentation described in the Related Documentation section for more information.

    • Regarding automatic activation for iOS devices, see the MDM integration guides for more information.

    • Regarding automatic activation for the Android’s personal profile when using Android Enterprise, see the MDM integration guides and Appendix A – Google’s Android Enterprise Implementation with Trellix Mobile Security section for more information.

  • Automatic activation without MDM integration is possible in certain cases, such as when the app does not come from the App Store, Play Store, or is a branded app. However, if you are using a standard Trellix Mobile Security app from the App Store or Play Store, MDM integration is required.

With MDM Integration

An enterprise device is defined as a device managed by an enterprise’s MDM. If MDM integration is enabled and Trellix Mobile Security has been pushed to an iOS or Android enterprise device from the MDM, then the device can sometimes be transparently activated without the user having to activate it manually.

If these conditions exist, the device activation can be transparent to the user:

  • MDM integration is enabled in Trellix Mobile Console.

  • The vendor-specific MDM supports zero-touch activation with Trellix Mobile Security.

  • The MDM is configured to auto-activate the device.

If these conditions are not all met for automatic activation, often the user presses an MDM activation link. With Trellix Mobile Console, the administrator creates activation URLs from the Manage page with the Integrations tab. Also, non-enterprise devices can be activated by the user with an activation link.

In either type of activation, a device identifier is used to match up with the synchronized device identifier from the MDM. Once a match is found, then that device is associated with Trellix Mobile Security in the correct Trellix Mobile Console environment.

Note: Administrators need to ensure that variables in activation links are substituted with the actual device identifiers, either manually or through message templates where the variable can be substituted by an MDM or in the Trellix Mobile Console.

11

information about the activation topic, see the Trellix Mobile Console documentation described in the Related Documentation section.

Within most MDMs, the administrator modifies email templates that are sent to the end-user to help in device enrollment, and these are used to reference the activation URL. Refer to the specific MDM guides for more information on activation options with each MDM.

Without MDM Integration

If there is no MDM integration, the user is typically invited through an email either generated from Trellix Mobile Console or sent by the administrator for a device group.

After the agreement is accepted, the activation request page displays. The administrator must provide the end-user with the information for activation or request that Trellix Mobile Console send a welcome email.

Once activated, the device is then matched up with the correct environment for the activation link. For more information on activation links, see the Trellix Mobile Console documentation described in the Related Documentation section.

This figure shows the activation prompt that the user will see.

Activation prompt on a mobile device showing a QR code at the top, options including QR code, Log-in with Activation Link, Log-in with Microsoft, and other activation choices in a list-style interface.

Tip: If you are having trouble scanning a QR code, try switching to a light background.

For devices where you want to use a different activation link on an already activated device, the user must confirm the new activation link. This occurs, for example, on devices that are on loan and rotated to different individuals.

Upon successful installation and activation, the dashboard displays. See Application Overview for more information.

Trellix Mobile Security Zero-Touch Activation

This feature allows administrators to activate Trellix Mobile Security on managed devices with the end-user minimally required to click on the installed Trellix Mobile Security application. This provides the best user experience, allowing the user to start up Trellix Mobile Security without having to enter any credentials.

This figure provides an overview of the interactions.

Diagram showing MDM server on the left, a smartphone in the center with a threat notification, and Trellix/Zero Touch Provisioning branding and console on the right illustrating zero-touch activation workflow

This list describes at a high level the items set up for zero-touch activation and threat reporting:

  • The MDM has a group and a VPN profile for the devices.        

    • The device is registered with the MDM.

    • The Trellix Mobile Security app is pushed to the device.

    • The VPN profile is initially pushed to the device.

  • Trellix Mobile Console has the MDM defined as an integration.

  • Trellix Mobile Console has the MDM action and mitigation action set for the “App Pending Activation” threat.

For more information, refer to the MDM integration guides that support zero-touch activation.

Dynamic Branding

A Trellix Mobile Console administrator can use branding to customize the Trellix Mobile Security mobile app to specify a logo, button text and color, and custom links to your privacy policy and license agreement. For details, refer to the documentation for Trellix Mobile Console Release 5.x.

Note: This feature only applies to Trellix Mobile Console Release 5.19 or higher. It is not available in Trellix Mobile Console Release 4.x.

Trellix Mobile Security for iOS Supervised Devices

Trellix Mobile Security provides the ability to configure iOS-supervised devices so that protection is always active and cannot be disabled by the user. This feature is completely zero-touch and has no conflicts with an existing corporate VPN.

Refer to the MTD Activation for iOS-Supervised Devices Guide for more information on configuring supervised devices.

Getting Started

Users do not need to interact with Trellix Mobile Security for proper detection and prevention of suspicious activities. However, users open Trellix Mobile Security to:

  • Determine if it is set up correctly.

  • Determine if it found any alerts.

  • View recommendations on how to decrease the risk of device attacks.

Application Overview

Trellix Mobile Security provides an application overview consisting of a set of screens the user can scroll through to become familiar with the benefits of the platform. When you open Trellix Mobile Security, an introductory screen displays. You can swipe left to scroll through various introductory screens to learn about Trellix Mobile Security benefits.

Mobile phone mockup showing the Trellix Mobile Security onboarding screen with Trellix logo and a prominent Get Started button at the bottom.

Press Get Started when you are ready to begin using Trellix Mobile Security.

Activation

When you press Get Started, the activation window displays, where you can select QR Code, Log in with Activation Link, or Log in with Microsoft.

Login options box titled How do you want to get started? showing options: QR code, Log in with Activation Link, and Log in with Microsoft

Tip: If you are having trouble scanning a QR code, try switching to a light background.

Privacy Information

A Trellix Mobile Console administrator can enable a privacy summary display for all devices. When enabled, a privacy summary screen tells the user what information their organization can and cannot access from the user's device based on Trellix Mobile Console's privacy policy settings.

The following examples show which information your organization can and cannot see on your device. The information displayed depends on policy settings for the tenant and which permissions are granted based on what is configured in the Privacy Policy in Trellix Mobile Console. Press the information icon at the bottom of the screen to view the complete Trellix End User License Agreement and Privacy Policy.

Mobile privacy summary screenshot showing We value your privacy with permission list and Don't Collect / May Collect options and a Continue button

Mobile privacy summary screenshot (alternate view) showing permission categories such as Device model, Operating system, Location of your device, Wi‑Fi network and a Continue button

Press Continue to go to the Permissions screen. For more information, see About Runtime Permissions.

About Runtime Permissions

When you initially log into Trellix Mobile Security, you are prompted to select the permissions you want to allow. The specific permissions requested depend on the policy configuration in

Trellix Mobile Console and the type of activation chosen. The Permissions screen differs between iOS and Android.

Android:

Android permissions screen titled Let's Keep Your Device Protected With The Following Permissions showing items for Notifications, Battery Optimization, Device Storage and a green Continue button

iOS:

iOS permissions screen titled Let's Keep Your Device Protected With The Following Permissions showing items for Local Wi‑Fi Network, VPN, Location and a green Continue button

Note: To modify permissions at any time while using Trellix Mobile Security, tap the options menu icon options menu icon, grid of small squares and press Settings. Scroll down to the Permissions section and make your changes.

Types of Permissions

Users receive one or more runtime permission requests for these topics. You can press Allow all, Maybe later, or toggle individual permissions on.

Note: For a number of dialog messages, Trellix Mobile Security cannot localize the prompt into another language. The dialog messages are owned by the operating system, and in some instances, these dialogs are always displayed in English.

The following sections cover the different types of permissions that are requested. For more information on data privacy, refer to the Related Documentation section.

Camera Access Permission

If during activation, you select to activate the app with a QR code, the app requests camera access.
Press OK to scan your QR code to begin activation.

Notification Permission

Administrators can set notifications in Trellix Mobile Console to automatically alert users in response to certain threats or other activities. In iOS, users toggle the Notifications permission setting on, then press Allow when prompted to let Trellix Mobile Security send these notifications.

Note: To understand how notifications work in iOS, you can visit the links below:

17

Mobile screenshot of Trellix Mobile Security permissions screen with a notifications permission dialog in the center showing text “MTD Would Like to Send You Notifications” and buttons “Allow”, “Allow in Scheduled Summary”, and “Don’t Allow”. The underlying app screen shows toggles for Location, Notifications, and Local Wi‑Fi Network and a green “Allow all” button with “Maybe Later” below it.

Note: For notifications to display in Trellix Mobile Security, the Alert User toggle must be turned on for at least one of the threats in the Trellix Mobile Security Console threat policy. For more information, see the Threat Policy and Updates section in this guide or refer to the Trellix Mobile Console documentation described in the Related Documentation section.

Local Wi‑Fi Network Permission (iOS only)

To protect the device against sophisticated Wi‑Fi‑based network attacks, Trellix Mobile Security must have permission to access the local network. This helps protect your device against sophisticated Wi‑Fi network attacks and access to private data.

Location Permission

To access Wi‑Fi details, Trellix Mobile Security needs location permissions. Trellix Mobile Security requires these Wi‑Fi details to protect the device and data from sophisticated network attacks.

Important: Location permission must be set to Change to Always Allow for the Trellix Mobile Security features to work.

When a security event occurs, Trellix Mobile Security gathers forensic information. Part of this information includes the location of the device when the event occurred. This is a standard warning for any application that has location service functionality built in. Trellix Mobile Security does not keep a history of your location information.

There are different flows for setting these permissions in iOS and Android. Each one is described next.

iOS Location Permissions

Follow these steps to set location permissions for iOS:

1. When you initially launch Trellix Mobile Security and see the Permissions screen, select Allow all or toggle the Location permission to On. This location permissions screen pops up. For complete protection, select Allow While Using App.

Mobile app permissions popup over a map showing a dialog titled “Allow ‘MTD’ to use your location?” with options “Allow Once”, “Allow While Using App”, and “Don’t Allow”; background shows a map and app permissions toggles and a green “Allow all” button at the bottom.

2. If you select Allow While Using App, the following popup displays. Select Change to Always Allow.

Mobile app permissions screen with a popup offering “Keep Only While Using” and “Change to Always Allow”; background shows permission toggles (Location, Wi‑Fi, etc.) and a green “Allow all” button at the bottom.

Note: Location permission is required to get the SSID and BSSID of the current Wi‑Fi connection. The location is not stored in the Trellix Mobile Security app.

Android Location Permissions

Follow these steps to set location permissions for Android:

  1. When you initially launch Trellix Mobile Security and see the Permissions screen, slide right to toggle the location permission on. This permissions screen pops up. Select While using the App.

    Android permissions dialog showing a prompt Allow MTD to access this device's location? with two circular illustrations labeled Precise and Approximate and options including While using the app, Only this time, and Don't allow.

  2. In the screen that displays, select Allow all the time.

    Location permission settings screen for MTD showing radio button options with Allow all the time selected at the top of the list.

The location permission is required to get the SSID and BSSID of the current Wi‑Fi connection. The location is not stored in the Trellix Mobile Security app.

Note: With Android 10 and above, location permission is required to detect an unsecured Wi‑Fi threat.

VPN Permission

An administrator has the option to configure Trellix Mobile Security to set up a VPN in response to threats. If this is requested, then during the installation of Trellix Mobile Security, a VPN profile is installed and can be seen in the Settings app of the iOS device. Trellix Mobile Security requests permissions from the user or, in other configurations, the permissions are automatically granted with the activation. If permission is granted for Trellix Mobile Security to add VPN configurations, all network activity on the device may be filtered or monitored while using VPN. If applicable, Trellix Mobile Security guides the user when installing the application or when policies change for the device.

This permission is requested when an administrator:

  • Enables a phishing policy for a local VPN.

  • Enables the enhanced phishing protection plus web content filtering option.

Note: These VPN Link Verification permission screens do not display if the administrator did not configure a local VPN on Trellix Mobile Console with phishing or network sinkhole settings.

Note: When the Trellix Mobile Security VPN profile is installed but the VPN is disabled, and the Trellix Mobile Security Safari extension was previously enabled, the extension will automatically be disabled within the Safari extensions settings. To restore functionality, users must manually re-enable the extension. For instructions on re-enabling the extension, refer to the Trellix Mobile Security Safari tutorials in the Trellix Mobile Security app. When both the Trellix Mobile Security VPN and Safari extension are enabled, the VPN may take precedence in blocking webpages, which could impact the functionality of the Safari extension.

Auto-Reconnect Options

The VPN auto-reconnect feature provides users with flexible reconnection intervals for improved control over VPN connectivity. The available options are:

  • 1 Hour (default): Automatically reconnects every hour.

  • 4 Hours: Reconnects every four hours.

  • 12 Hours: Reconnects every twelve hours.

  • 24 Hours: Reconnects every twenty-four hours.

  • Disable Auto-Reconnect: Requires manual reconnection.

These options are designed to enhance user experience by offering customizable reconnection intervals to meet individual preferences.

Note: This feature requires the Trellix Mobile Security app Release 5.5.x or later.

Note: To ensure the VPN auto-reconnect period from the MDM app config is applied, users must manually refresh the app by swiping it away to close it completely and then reopening it. This step forces the app to update and display the new reconnect period. For example, if the auto-reconnect period is changed from 1 hour to 4 hours, the app will continue to show the old value until it is closed and reopened, thereby ensuring that the new setting is accurately reflected.

Battery Optimization Permission (Android only)

To allow adding the Trellix Mobile Security app to the Android battery optimization exemption list, press Allow to ensure devices are protected while the app is running in the background. This permission prompt is controlled by the administrator’s settings on Trellix Mobile Console. See the Trellix Mobile Console documentation described in the Related Documentation section for more information.

Device Storage Permission (Android only)

To allow the Trellix Mobile Security app to access your device storage areas to detect and prevent malware from harming your device and data, press Allow to ensure devices can read these storage areas.

Samsung Knox Permission (Android only)

To allow the Trellix Mobile Security app to use Samsung Knox functionality to protect your device from mobile threats, press Activate to ensure Trellix Mobile Security has the ability to behave as a device admin app.

Note: If you want to uninstall the Trellix Mobile Security app, go to Settings on the device and grant this permission.

SMS Permission (Android only)

To allow the Trellix Mobile Security app to protect you against phishing links contained in your SMS messages, press Allow to enable access to those messages.

Bluetooth Permission (Android only)

To allow the Trellix Mobile Security app to detect unknown tag trackers that may be tracking your location without your knowledge, press Allow to enable access to Bluetooth.

This section explains where to find various types of information and perform tasks within the Trellix Mobile Security app.

Using the Dashboard

The first screen that is displayed after the activation is the dashboard. The area at the top of the dashboard provides a summary of the status. Each tile is color-coded based on the status of that particular category. The status colors are explained below:

Color

Description

Green

Verifications have been made and there are no issues found.

Yellow

Threats have been detected during this timeframe, but none are critical.

Red

Critical threats have been detected during this timeframe.

Here are some examples of dashboards for iOS devices based on the status.

[IMAGE PLACEHOLDER: Three mobile app screenshots side-by-side showing status tiles — left screenshot with green "No Threat Detected / Device is secured" design, center screenshot with yellow "Risk Detected / Device is at risk" design, right screenshot with red "Threat Detected / Device is not secured" design; each screenshot shows category tiles for Apps, Web, Device, and Network]

Each tile represents a specific category for threat detection:

  • Apps scans for potentially harmful applications.

  • Web checks for phishing links and enables and disables VPN depending on the administrator's settings in Trellix Mobile Console.

  • Device scans for potential threats or risks to the device, such as outdated OS version or update required.

  • Network identifies and protects from threats to the networks.

  • Threat Zones provide information to the user if nearby available networks should be avoided (high-risk networks).

  • Files detects malicious PDFs or APKs (Android only) that are saved to the Downloads folder on your device, thereby countering novel phishing techniques that elude traditional email gateways.

  • Shortcuts (iOS only) allow a user or app to automate a set of actions. Apps can install shortcuts on the device as part of their normal operation, or shortcuts can be added directly from Apple or from external websites. Since iOS shortcuts allow executing actions on the device, they can pose a security or privacy risk. This feature detects risky iOS shortcuts and allows the user to remove them from the device.

  • Forensic Analysis (iOS only) performs a deep scan to detect malicious PDFs that are saved to your device, thereby countering novel phishing techniques that elude traditional email gateways.

  • Tutorials contain links to helpful information on various topics.

  • Tag Tracker (Android only) scans for tag trackers that may be tracking your location without your knowledge.

Note: Threats are defined in the Trellix Mobile Console Threat policy.

You can press any tile to display a list of the active issues detected and view the risks or threats for that category. If, as shown in the prior screenshot, there is an issue to fix, you can press Fix to display the Full Event Log.

Viewing the Activity Report

When the tiles in the dashboard are all green, the Report button displays at the top of the screen. Press this button to display the Activity Report shown here. This report displays statistics for the Device, Network, App, and Web categories, including the number of security scans, threats, and issues resolved or websites blocked during the specified time range shown at the bottom of the screen. You can tap on a row in the Activity Report to display the corresponding log page for that threat category and view the events in more detail, as shown in this example.

Note: The Report button only appears when the device is considered safe, meaning there are no currently active threats.

Mobile Activity Report screenshot showing Device, Network, App, and Web summary with scans and resolved counts, and a date range at the top

The Options Menu

Tap the Options menu icon — a 2x2 grid icon icon in the upper-right corner of the dashboard to display these options.

  • Full Event Log: A comprehensive list of the threat log items.

  • Settings: These are settings for the user's device display, such as the number of days for statistics and dark or light appearance.

  • Troubleshoot: Allows you to send log and debugging information to the Customer Support team. You can also access the Advanced Details screen from the Advanced Troubleshooting screen by long-pressing the Troubleshoot option.

  • About: Displays the Trellix Mobile Security version and build number installed on the device and contains links to the privacy policy and license agreement.

Note: The options that are available depend on the policies and Trellix Mobile Console settings.

The About Menu

To view information about the current version of Trellix Mobile Security, such as the privacy policy and the license agreement, tap About in the options menu [icon] to display this screen.

Screenshot of the About screen showing entries Privacy Policy and License Agreement, and version and build details in a mobile app layout

Selecting Your Viewing Preferences

If you select Settings from the options menu [icon], this screen displays. You can select your preferences for these settings:

  • Dashboard view (detailed or simplified, which only displays the icons for each tile).

  • Your preferred time range for viewing statistics.

  • The appearance mode (system appearance, light, or dark).

  • Permissions to enable continuous protection of your device.

Tall smartphone settings screenshot showing dashboard view, dashboard stats, appearance options, and permissions list with radio buttons and toggle switches inside a device frame

Viewing the Full Event Log

The Full Event Log is available from the options menu Options menu icon or the Fix button at the top of any risk or threat screen. This log shows outstanding issues that need to be fixed, along with any resolved issues at the bottom. It displays the name of the threat, the severity level, and the date/time that it was detected. Once a threat is mitigated, it moves to the bottom of the list under Resolved Issues. You can press the trash can icon beside this heading to remove all the resolved issues from the list.

Here is an example of the Full Event Log when critical threats exist.

Mobile app Full Event Log screenshot showing stacked issue cards — examples include Link Verification Disabled with a Fix button, Danger Zone Connected with a Review button, and Suspicious Android App with a Fix button; cards use colored backgrounds for severity

You can tap Fix for any active issue to view details, resolution steps, and other information depending on the type of issue, such as device or web.

Here is an example of this detailed screen based on a threat found for iOS shortcuts.

Tall mobile detailed threat screen for iOS Shortcuts titled Get Baseband Firmware with prominent THREAT DETECTED label, sections labeled DETAILS, RESOLUTION, and BREAKDOWN, bullet resolution steps, and a green action button Open Shortcuts App at the bottom

This example shows the details of a website issue. In this case, you can toggle on the option to Mark this site as “Trusted” (shown in the next image) if you want to skip the alerts. Press OK when you are finished.

Mobile app screen showing a Site Not Approved notice card with details sections (Details, Resolution, Site, Category) and an OK button at the bottom.

If no critical threats exist, here is an example of the Full Event Log with updates on the device.

Mobile screen showing the Full Event Log with update entries such as Danger Zone Connected, Developer Mode enabled, Resolved Issues: 8, and a Site Not Approved entry.

Setting Up Notifications

Notifications are part of the Trellix Mobile Security Console Threat policy that is pushed to the Trellix Mobile Security app. Each classification in the Threat policy has the option to notify the user, and the Trellix Mobile Console administrator configures this as enabled or disabled. When an event is detected, Trellix Mobile Security communicates with iOS or Android and the notification appears on the device.

There are two types of notifications: banners and popups. Tapping the notification launches the Trellix Mobile Security app and provides the user with additional information. It also includes recommended actions for the event.

Troubleshooting

When you select Troubleshoot from the options menu Options menu icon (four dots in a square), you can send the log files to a specified location for debugging. You can also perform advanced troubleshooting. These options are described next.

Send Logs for Debugging

Troubleshooting allows the user to view and share the Trellix Mobile Security application log information. Perform these steps to set this up:

  1. From the Troubleshoot screen, press Send logs for debugging.

  2. Specify where you want these log files sent, for instance, email or text. A confirmation message indicates that your logs have been submitted, along with the date and time this occurred.

Advanced Troubleshooting

From the Advanced Troubleshooting screen, you can access advanced details, all logs, and local VPN settings. You can also reset Trellix Mobile Security or clear all logs.

To display this screen, long-press Troubleshoot in the options menu Options menu icon (four dots in a square).

Screenshot of the Advanced Troubleshooting menu on a mobile device showing options such as Advanced Details, All Logs, Local VPN Settings, Reset MTD, Send logs for debugging, and Clear all logs

Note: The details of the Advanced Troubleshooting section are subject to change between releases or patch releases. The features in this section will not be translated.

Advanced Details

From the Advanced Troubleshooting screen, press Advanced Details to display information that can include, but is not limited to:

  • Bundle ID

  • App

  • Build number

  • App version

  • SDK build

  • SDK version

  • Release version

  • Embedded license

  • Device ID

  • MDM ID

  • Acceptor URL

  • License key

  • Auth token

Viewing All Logs

From the Advanced Troubleshooting screen, press All Logs to display the options shown in this example.

Note: No personal information is collected or shared through these logs.

Mobile app All Logs screen showing a list of options such as Extended Logging toggle, View Logs, Phishing Logs, VPN Logs, Rule State, Rule Download Logs, Rule Run Logs in a vertical list

Local VPN Settings

From the Advanced Troubleshooting screen, press Local VPN Settings to display the various settings. An example is shown in this figure.

Mobile app screenshot titled Local VPN Settings showing two pale cards with fields VPN TYPE Cellular, KEY DEFAULT, DNS1 1.1.1.1 / 3.3.3.3, DNS2 2.2.2.2 / 4.4.4.4 and Last updated timestamps

Reset Trellix Mobile Security

Press this option on the Advanced Troubleshooting screen and you are prompted to reset Trellix Mobile Security, which clears any login token information and restarts the Trellix Mobile Security app. This restores the app to its default settings and takes you back to the initial screen, where you press Get Started to activate the app.

Clear All Logs

Press this option on the Advanced Troubleshooting screen to clear all logs. This action may impact your app statistics. When you are prompted, press Clear all logs to continue.

Threat Protection Categories

Trellix Mobile Security scans specific categories for threats to your security. These categories are displayed in tiles on the dashboard. Each tile represents a specific category for threat detection. These categories are explained in this section, along with ways to access and interpret the information reported by Trellix Mobile Security.

Apps

In the dashboard, the Apps tile displays the status in green, yellow, or red. Tapping on this tile takes you to the Apps screen. Here is an example with no existing issues.

Mobile screenshot titled Apps showing a green 3x3 grid icon on a light green background with the message NO THREAT DETECTED ALL APPS ARE SECURED and a bottom card labeled App Look Up.

If a risky app is found, the screen provides the user with information on the application and a recommendation on how to proceed. Categories for risky apps include:

  • Suspicious apps are installed and are high risk. They have the potential to compromise the device.

  • Sideloaded apps were installed outside of the Google Play Store or App Store. They have not been officially validated and are considered risky.

  • Out of Compliance (OOC) apps, which have characteristics that do not comply with the organization’s privacy and security policies.

Note: iOS will only provide access to the apps if Trellix Mobile Security is used with an MDM.

This figure shows an Android example with a sideloaded threat.

Smartphone screenshot showing the Apps screen with the Mini Lite app and a red THREAT DETECTED banner; details text, identified malware Trojan Spyware, breakdown of Cryptographic Keys, Storage, Network, and a green Uninstall button visible

Note: The critical threats are defined by the Threat Policy.

Application Scanning

Trellix Mobile Security automatically scans the device for risky apps when it is initially installed. Apps are also scanned when they are downloaded and installed.

  1. If the Apps tile appears red or yellow, tap it to display this screen, which shows that a risk or threat has been detected for the app. In this example, a risk is detected.

Tall smartphone screenshot showing an Apps tile with RISK DETECTED / REVIEW REQUIRED, a count of 1 APP, and a green Fix button; below is an App Look Up discovery card

  1. Tap Fix to display a list of the apps with issues.

    Mobile app screenshot showing an Apps With Issues list with a card titled Sideloaded App, details including severity Risk and a detected date/time, and a green Fix button.

  2. To display the details and recommendations, tap Fix.

Searching Apps to Determine Risk

When users want to install an app on their device, but want assurance that the app is safe, they can search for the app from a comprehensive database. This displays the summarized privacy and security rating of the app, which helps users determine if it poses a threat to the device. For Android devices, you can also view the app risk report for your currently installed apps. Searches can be performed for non-English languages as well.

Note: This feature is not dependent on a z3A license.

From the Apps tile, press the App Look Up link (available if the App Risk Lookup feature is enabled in Trellix Mobile Security Console).

Follow these steps to search for an app risk report:

  1. Press App Look Up on the Apps tile.

Mobile phone screenshot titled Apps with pale green gradient background, a green grid icon in center and text NO THREAT DETECTED / ALL APPS ARE SECURED; a Discover card is visible at the bottom of the screen

The App Store Search screen displays, with a list of top trending apps and an indicator of whether a risk is detected for each.

Tall mobile screen screenshot of the App Store Search list showing multiple apps (Temu, CapCut, Chat with Ask AI, Google, TikTok, Instagram, WhatsApp Messenger, etc.) with risk indicators such as Risk detected or No risk detected to the right of each entry

  1. Enter an app name in the Search App Store field to display the matching results. The results are narrowed to match characters as you type.

  2. Tap an app name in the list to view the privacy and security risk report for the app.

  3. Tap Download to download the app to your device.

Follow these steps to view the app risk report for your installed apps (Android only):

  1. Press Installed Apps on the Apps tile.

    Smartphone screenshot showing the Apps screen. A card labeled Installed Apps is outlined in green; above it a red grid icon and the text THREAT DETECTED ACTION REQUIRED with a green Fix button are visible.

    This displays a list of apps installed on the device.

  2. Search for and select an app.

Mobile screenshot showing the Apps list with search field and multiple installed apps such as Grasshopper, WhatsApp, Instagram, and Tips; titled Apps at the top.

3. Tap the app name to view the privacy and security risk report for the app.

Allow-Listed Apps on Trellix Mobile Console

Here is information on how the apps that are allow-listed in Trellix Mobile Console show up in the App Store Search view.

Android:

  • For apps installed on the device, the app is flagged as “Trusted App” and the message “<App name> has been reviewed by your company and is approved for you to use” is displayed.

  • For apps from the Play Store, Trellix Mobile Security does not look for apps that are allowed and displays the app risk along with privacy and security risk levels.

iOS:

  • Apps installed on the device cannot be listed/scanned on iOS.

  • For apps from the App Store, Trellix Mobile Security does not look for apps that are allowed; it displays the app risk along with privacy and security risk levels.

Web

Trellix Mobile Security checks for phishing links and enables and disables VPN connections based on the Trellix Mobile Security Console Threat policy settings. In the Threat policy, administrators can select or unselect the Link Verification threat to turn this feature on and off.

Link verification uses web content filtering to warn and protect users from accessing possibly harmful websites and links, such as malware, phishing, botnets, and suspected domains. Trellix Mobile Security also provides alternatives for users to be protected from risky phishing links in SMS/MMS protection and the Safari browser on iOS without setting up the VPN.

When the user accesses a communications channel that is not secure, Trellix Mobile Security can open a secure VPN for transmitting data. The administrator can also allow the device user to enable or disable the Trellix Mobile Security local VPN on their own device.

You can specify a new content filtering category action to block and optionally create an alert. This feature expands the device's detections in filtering and alerting for websites that have specific content. It allows you to block content with or without generating an alert to the user or a threat to review in the threat log. For example, you may choose not to create an alert that blocks spam sites in order to avoid interrupting the user’s browsing experience.

In the dashboard, the Web tile displays the status of threat detection (red, yellow, or green). Tapping on this tile takes you to the Web screen.

Mobile app Web screen showing a green shield icon with text WEB IS PROTECTED / SECURE BROWSING ENABLED, a green Report button, and a list of settings including an MTD VPN toggle and phishing link check input — tall portrait screenshot with light green header and white settings cards.

If you press the Report button, the Site Scan Report displays. This report shows the number of sites that are blocked and their URLs, along with the number of safe sites and sites scanned. An example is shown here.

Mobile screen showing Site Scan Report with date range, metrics (SITES BLOCKED 0, SAFE SITES 43, SITES SCANNED 43), a green checkmark icon and the message No risky or malicious site detected during this date range.

This screen displays when a risky site is detected.

Mobile screen showing a Risk Detected warning card with an orange globe/lock icon, the text RISK DETECTED SECURE BROWSING DISABLED, a green Fix button, and settings panels below (Secure Browsing toggle, MTD VPN status, phishing link check input).

When you tap Fix, the following screen displays. If the administrator sets a site to alert the user instead of blocking that site, you will see options to Continue Anyway and Mark this site as “Trusted”, allowing you to specify whether to bypass the warnings in the future.

A mobile warning dialog titled Malicious Website showing details, resolution advice, the site URL (malware.wicar.org/data/eicar.com), a Mark this site as 'Trusted' toggle, a green Go Back button and a red Continue Anyway button

Phishing and Web Content Filtering

The Trellix Mobile Security Console Phishing policy allows an administrator to define ways to protect users from accessing any harmful websites and links (such as malware, phishing, botnets, and suspected domains) that contain content that might be risky. You can specify a new content filtering category action to block and optionally create an alert.

Actions that can be set include:

  • Alert the user by giving a warning.

  • Alert the user by giving a warning and create a threat.

  • Block the site.

  • Block the site and create a threat.

  • Block the site and do not create a threat.

When a user is alerted about a website or queries a website to see if it is safe, Trellix Mobile Security provides the category of that site, such as gambling or illegal drugs, if the administrator enables content filtering. This guidance helps the user determine what action to take next.

Note: In addition to a standard set of categories, a Trellix Mobile Console administrator can create custom categorization lists by entering a list of website URLs. In this way, it is possible to create alternative actions for a defined set of websites. Custom lists can be related to device groups to tailor the actions per group. For more information on the categories, see the Related Documentation section.

An administrator can set up these features on Trellix Mobile Console for devices running Trellix Mobile Security. These options appear when either the Phishing Protection or Enhanced phishing protection plus web content filtering option is selected in the Trellix Mobile Security Console Phishing policy.

A settings box labeled SETTINGS FOR THIS POLICY showing Phishing Protection and Web Content Filtering with radio options: Disabled; Phishing Protection (selected); Enhanced phishing protection plus web content filtering.

The phishing features are described below, and their availability depends on the option selected in Phishing Protection and Web Content Filtering.

Feature

Description

Enable inspection on a remote server

If you select Phishing Protection, the Allow URL inspection on remote servers option allows the administrator to enable a remote server check of the URL in addition to the on-device check.

Enable user-initiated URL sharing

Provides the user with the option to use the device sharing feature when a web link (URL) is encountered. The user can perform a long press on a link to share it with Trellix Mobile Security, which then analyzes the URL for a phishing risk and informs the user that the link is safe or risky.

Allow end user VPN control

Allows Trellix Mobile Security to check the safety of web links. The administrator can select between the following options when phishing links are detected if a local VPN is enabled:

  • Allow the user to control if there is a local VPN or not.

  • Block the detected phishing URL or web links or not.

  • If Phishing Protection is selected, you can select Block detected phishing URLs.

  • If Enhanced phishing protection plus web content filtering is selected, you can choose whether to block or allow using the Category Handling options.

Enable SMS/MMS message filter

Allows the administrator to enable an alternative protection method from risky links in SMS text messages. This feature filters a risky link for SMS messages in the Messages app before a user can click it, and all blocked messages are viewable in a single tab in the Messages app. Trellix Mobile Security also provides a tutorial to explain the details of its setup.

Note: This feature works only with SMS and MMS messages from unknown senders. It does not work with messages from senders in a user's Contacts list or with iMessage messages from any source.

Feature

Description

Enable the iOS Safari browser extension

Allows the administrator to enable a Safari extension as an alternative method for users to be continuously protected from malicious and risky links that are displayed by the Safari browser. Trellix Mobile Security installs a Safari extension that a user can manually enable to give the necessary permissions that allow it to run on browser pages. Trellix Mobile Security also provides a tutorial to explain the details of its setup.

Actions for Specific Categories

When you select Enhanced phishing protection plus web content filtering, the Category Handling table displays on the right. This allows the administrator to determine specific actions for website content categories such as security risks, drugs, or criminal activity.

Custom Access Control List

This expandable list lets the administrator specify URLs and their category to either override or extend the actions for specific harmful websites.

Note: When the Custom Access Control List changes, it can take up to an hour for the update to push to the device. If a faster update is needed, toggle the Enable Link Verification field under the Web tile.

See VPN Link Verification Permissions for information about enabling phishing and content filtering.

Note: Due to encryption protocols for HTTPS URLs/domains, the phishing VPN feature may not display the full HTML content, but the alert warning message still appears.

When a specific website category or URL is determined to be harmful, it is blocked. An alert displays when a site is accessed from the browser, which includes the site and category.

Trellix Mobile Security has a tutorial on how to use the URL-sharing feature.

Note: A device cannot have two VPNs running simultaneously. As a result, when you start a corporate VPN, it disables the Trellix Mobile Security VPN that is used for phishing protection. Trellix Mobile Security prompts you to re-enable phishing protection after the corporate VPN is turned off.

Local Proxy for Anti-Phishing

The local proxy feature in the Trellix Mobile Security app enhances anti-phishing protection on Android devices with corporate VPNs by using the Trellix proxy engine. This upgrade improves monitoring of HTTP/HTTPS traffic, assesses link risks, and reports security issues.

Note: See your specific MDM Integration Guide for instructions on setting up this configuration.

If link verification is enabled by the administrator in the Trellix Mobile Security Console, the user is able to toggle Enable Link Verification on and off as shown in this figure.

Mobile app screenshot showing the Link Verification screen with a RISK DETECTED banner, text Link Verification is disabled, an ENABLE LINK VERIFICATION toggle (off), and sections for Phishing Link Check and Approved Site List

If you toggle Enable Link Verification on, this popup displays.

Popup screenshot showing Enable Link Verification dialog with explanatory text and the toggle switched on (green), displayed over the mobile app screen

Once you enable link verification here, the following message displays.

Mobile app screenshot showing a “Risk Detected” message and a lower panel stating “External VPN Enabled. Only a single VPN can be enabled.” with a shield icon

VPN Protection

When the administrator enables link verification, Trellix Mobile Security must be allowed to add the local VPN to detect and block risky links on the device. The local VPN can also be used to tunnel unsecured Wi‑Fi traffic. To activate this feature, the administrator must enable at least one of the options under Use Local VPN in the Trellix Mobile Security Console Phishing policy and select Tunnel unsecured traffic in Device Actions for any of the active threats in the Threat policy.

Once the VPN configuration is set up on the device, an alert displays when the device encounters an attempt to access an unsecured Wi‑Fi network. Trellix Mobile Security automatically connects the device to a secured VPN to tunnel the insecure (HTTP) traffic over the unsecured Wi‑Fi connection.

Checking for Phishing Risk

If this feature is enabled, when you press the Web dashboard tile, the screen shows the protection available for insecure (HTTP) connections. To check a link for phishing risk, you can:

  • Type or paste a copied link.

  • Press QR code icon and scan a QR code. You will be prompted to allow Trellix Mobile Security to use the camera.

This figure shows the Phishing Link Check field, where you can copy and paste a link or scan a QR code.

Mobile app screenshot of Web is protected screen showing a green protection banner with a padlock globe icon, text WEB IS PROTECTED, a VPN enabled toggle, Sites Scanned: 49 Sites Blocked: 0, a Report button, and a phishing link check input area

If the site you entered is a threat, a screen like the one below displays, providing details about the threat along with the recommendations to resolve it.

Mobile app screenshot of Risky site blocked screen showing a red alert banner, sections labeled DETAILS and RESOLUTION, the site URL http://malware.wicar.org/data/eicar.com, CATEGORY Phishing, and an OK button

If a link is risky, Trellix Mobile Security displays a screen indicating the status, along with details, resolution, site, and category. You can enable the Mark this site as “Trusted” option to bypass this warning and proceed to the site without being alerted again.

Mobile dialog showing a yellow SITE NOT APPROVED banner with details, site URL, category, a toggle to mark site as Trusted, and an OK button

If you want to report the phishing link detection to Trellix, press Report feedback for this detection at the bottom of the Web screen that displays the threat. A popup displays, where you can press Submit to report the detection.

Mobile dialog showing a red RISKY SITE BLOCKED banner with details, resolution text, site URL, privacy note, and a green Submit button

When you press Submit, a new popup confirms that you reported the link detection.

A green badge with a white checkmark and the caption Link Detection Reported Aug 2, 2023 inside a bordered rectangle.

Additional Phishing Protection

Trellix Mobile Security offers alternative methods for continuously protecting you from malicious and risky links that are either displayed by the Safari browser (iOS only) or contained in SMS/MMS messages (iOS and Android).

Protection When Running the iOS Safari Browser

Trellix Mobile Security provides the ability to extend the anti-phishing and web content filtering capabilities to the Safari browser on mobile iOS devices. To do this, Trellix Mobile Security installs a Safari extension (if the administrator enables this feature). You can then manually enable this extension to give the necessary permissions that allow it to run on browser pages. Refer to the Trellix Mobile Security tutorial for instructions on enabling this extension.

This feature requires the Phishing Protection policy or the Enhanced Phishing Protection plus Web Content Filtering policy to be enabled in Trellix Mobile Console. The VPN Link Verification permission is not required for this feature.

Trellix Mobile Security allows you to extend the anti-phishing capabilities to the Messages app on mobile iOS devices. This feature provides an alternative method to continuously protect Trellix Mobile Security users from malicious and risky links in SMS and MMS text messages.

The Tutorials dashboard tile contains a tutorial on enabling this iOS SMS Messages feature.

This feature blocks a risky link for SMS messages in the Messages app before a user can click it, and all blocked messages are viewable in a single tab in the Messages app.

Note: This feature does not report threats to Trellix Mobile Console. It only works with SMS and MMS text messages from unknown senders; it does not work with messages from senders in a user’s Contacts list or with iMessages from any source. The SMS message detection is done only on the device itself, and no content from SMS messages leaves the device. No personal information is collected from the user’s SMS or MMS text messages, and only the links within the text messages are evaluated for risky sites.

This figure shows the setting when this extension is enabled.

iPhone Unknown & Spam settings screen showing Filter Unknown Senders toggle enabled and SMS filtering option with an app named MTD selected

After you enable filtering of the SMS messages, the Messages app places the risky SMS messages in a separate folder. This feature allows you to be more protected from risky and malicious links.

iPhone Messages app list view showing folders: All Messages, Known Senders, Unknown Senders, Unread Messages, and a Filtered by MTD section with Junk and Recently Deleted

This figure shows the filtered text messages in the separate "Junk" folder.

iPhone Junk folder view showing a list of filtered SMS messages with sender phone numbers and message previews

Trellix Mobile Security allows you to extend the anti-phishing capabilities to the Messages app on mobile Android devices. This feature provides a way to continuously protect Trellix Mobile Security users from clicking malicious links in SMS and MMS text messages on their devices.

This feature must be enabled in the Phishing or Web Content Filtering policy in Trellix Mobile Console and the user must accept the Messages permission in Android to allow the Trellix Mobile Security app to detect risky links in messages.

This feature detects and alerts a user about a risky link in SMS/MMS messages in the Messages app before a user can click it. The threat details include the phone number of the message that contained the risky link.

Mobile screenshot showing a Trellix alert for a malicious website with details including site URL, phishing source SMS phone number, a toggle to mark the site as trusted, and an OK button

Device

In the dashboard, the Device tile displays the current state of the device itself. Examples of threats that show up in this category include:

  • App Tampering

  • Device Jailbroken / Rooted

  • Actively Exploited iOS Version

  • Vulnerable iOS Version

  • OS Not Compliant

  • File System Changed

Note: For more information about threats, refer to the Trellix Mobile Console Threat Reference Guide.

Tapping on this tile takes you to the Device screen. If there are any critical events or risks detected, the details show the items that are issues.

These figures show the Device screen with no risk (green), risk detected (yellow) and threat detected (red).

Left screenshot — Device screen with green header showing a phone icon, label localhost, and NO THREAT DETECTED. Below, a card showing Developer Mode enabled and a Review button; device information section at the bottom.

Middle screenshot — Device screen with yellow/orange header showing a phone icon, label jennifers-iPhone and RISK DETECTED. Below, list cards showing active issues such as Actively Exploited iOS Version and Vulnerable iOS Version with Fix buttons.

Right screenshot — Device screen with red/pink header showing a phone icon, label QAs-iPhone-2 and THREAT DETECTED. Below, list cards showing critical issues like Device Jailbroken/Rooted with Fix buttons.

If you press Fix for an issue or threat, a screen with details and resolution displays. Examples are shown here.

Tall screenshot — Detailed issue screen titled Device with phone icon and RISK DETECTED. Sections shown: DETAILS explaining location permission is required when reporting mobile threats; RESOLUTION recommending allowing MTD to access device location; ISSUE labeled Location Access. At the bottom a green rounded Open Settings button is visible.

Mobile device screenshot showing a THREAT DETECTED screen for QA-s-iPhone-2 with a red title bar, device icon, details and a green resolution/recommendations box

Network

In the dashboard, the Network tile displays the current state of the network or Wi‑Fi connection. Examples of threats that show up in this category include:

  • Compromised Network

  • Danger Zone Connected

  • MITM (Man in the Middle)

  • Rogue Access Point

  • SSL/TLS Downgrade

If a critical threat is detected as defined by the Threat policy, the title bar changes to red. A yellow title bar indicates that a risk has been detected.

Tapping on this tile takes you to the Network screen, which displays an overview of the device network configuration, including the device’s IP address along with the currently connected SSID and its BSSID. Recommendations for the user to stay safe are displayed as appropriate for the critical event detected.

Note: If a device is connected to an unsecured Wi‑Fi and Trellix Mobile Security is installed and activated afterward, sometimes no threat occurs for that existing Wi‑Fi connection. If the Wi‑Fi connection is dropped and a reconnection is performed, you will be notified of the threat.

Here are some examples of the Network screens: one with threats (yellow) and the other without them (green).

[IMAGE PLACEHOLDER: Two smartphone screenshots side-by-side — left screenshot shows a Wi‑Fi screen with an orange theme reading "Bams‑WiFi" and "RISK DETECTED" with a Rogue Access Point / Suspicious Wi‑Fi alert; right screenshot shows a Wi‑Fi screen with a green theme reading "Bams‑WiFi" and "NO THREAT DETECTED" with a Danger Zone / update notification]

Network Anomaly Behavior

The Network Anomaly Behavior feature identifies unusual network patterns on your device, helping to detect potential security risks like unauthorized data exfiltration, malware, or misuse of app permissions. It monitors traffic patterns and location‑based behaviors to identify deviations from typical usage. These are the key functionalities:

  • Traffic Analysis: Monitors network traffic and adapts to new applications after a learning period, notifying you once the analysis is complete.

  • Geographic Analysis: Tracks location‑based activity to detect anomalies in new countries, with notification following the learning period for accurate detection.

Note: (Android Only) Mark apps as trusted to exclude them from anomaly reports, and the uninstall option will be provided only for the applications that can be uninstalled.

Threat Zones

While traveling, it is common to connect to available Wi‑Fi networks to use the internet for business or pleasure. Many open Wi‑Fi networks are traps where malicious adversaries attempt to connect to any available access point to gain access to the victim’s information. This feature is used to identify and provide details about nearby high‑risk networks so users can stay informed and avoid accessing them.

Configuring Threat Zone Detection

The administrator can configure the Threat Zones tile to display in Trellix Mobile Security by enabling the Threat Zone / Danger Zone feature in the console. They can also enable alerts using the Trellix Mobile Security Console Threat policy settings. For details about these settings, refer to the Trellix Mobile Console Configuration Guide for release v4.x or the Trellix Mobile Security Console Guide for Release 5.x.

An optional configuration alerts the user if they are not connected to a Wi-Fi network and are near a known high-risk network. Nearby networks are only evaluated while Wi-Fi is enabled and not connected. Trellix Mobile Security scans nearby networks and provides alerts for any that are known to be high-risk.

Threat zone alerts display:

  • The name of the high-risk network.

  • A recommendation to disconnect from that network.

In addition, users can indicate that a particular network should be trusted so that they are not prompted again.

For more information on these settings, see the Trellix Mobile Console documentation described in the Related Documentation section.

Using the Threat Zones Map

Before deciding which network to connect to, open the Trellix Mobile Security app and tap Threat Zones. A map displays any nearby high-risk access points using red markers, as shown in the example below. You can zoom in and out using two-finger actions on the device screen.

Mobile map screenshot showing nearby high-risk access points with red numbered markers on a map of the area; a smartphone viewport with map controls visible.

The red circles with numbers represent the number of threats detected on high-risk access points. You can tap a circle to drill down to a specific location and tap any marker to display the details for that access point, as shown in this example.

Mobile app screenshot showing a phone mockup with a map at top and a Network Information details panel below, titled Threat Zones.

Shortcuts (iOS only)

Since iOS shortcuts allow actions to be executed on the device, they can pose a security or privacy risk. This feature alerts users when risky and malicious iOS shortcuts are installed on their device so they can remove them. It also alerts users if the Trellix Mobile Security shortcut, which is required for iOS shortcut threat detection, is not installed on their device.

Note: This feature requires iOS version 16 or later.

Installing the Trellix Mobile Security Shortcut

In order to detect malicious shortcuts, the Trellix Mobile Security shortcut must be installed on the device. If this shortcut is not installed, Trellix Mobile Security identifies it as a risk and the Shortcuts tile appears yellow.

Important: It is recommended that you set up Trellix Mobile Security shortcut automation to detect risky shortcuts whenever you install them. Otherwise, you can tap the Run Shortcut button in the Shortcuts screen each time you install a new shortcut to detect whether it is risky.

To install the Trellix Mobile Security shortcut and resolve the issue:

  1. Tap the Shortcuts tile on the dashboard to display this screen.

Mobile screen showing an installation guide titled RISK DETECTED INSTALL MTD SHORTCUT with descriptive bullets and a green Install MTD Shortcut button at the bottom

2. Press Install Trellix Mobile Security Shortcut to open the screen shown here. (This button can also be accessed from the Full Event Log.)

MTD Shortcut install dialog with a green shortcut tile in the center and a blue Add Shortcut button near the bottom

3. Press Add Shortcut. This opens the Shortcuts app on your device, with the Trellix Mobile Security Shortcut tile displayed.

All Shortcuts screen showing a green MTD Shortcut tile and a search bar.

4. Tap the Trellix Mobile Security Shortcut tile to install it and choose Always Allow to provide consent. The tile displays a checkmark once the Trellix Mobile Security shortcut is installed.

Privacy dialog asking Allow 'MTD Shortcut' to share 27 shortcuts with 'MTD'? showing several shortcut tiles and the buttons Don't Allow, Show All 27, Allow Once, and Always Allow.

5. When you return to the Trellix Mobile Security dashboard, the Install Trellix Mobile Security Shortcut issue is now resolved.

Running the Trellix Mobile Security Shortcut to Detect Threats

Unless automation is set up, you need to tap Run Shortcut in the Shortcuts detail screen each time you install a new shortcut to determine if it is risky. This button is shown in the example below.

Note: Due to shortcut issues in iOS, you may receive error messages when running shortcuts after they are installed. If this happens, try rebooting your device.

[IMAGE PLACEHOLDER: Mobile Shortcuts app screen showing a red threat icon and the text "THREAT DETECTED ACTION REQUIRED", a green "Fix" button, and a "Run Shortcut" area at the bottom]

Note: To learn how to set up automation, refer to the Trellix Mobile Security Shortcut Automation tutorial.

If Trellix Mobile Security detects a risky or malicious shortcut, the Shortcuts tile displays in yellow or red, respectively and you can tap the tile for details about the issue and how to resolve it.

To continue running the Trellix Mobile Security shortcut even when the device is locked:

  1. Tap the ellipsis button on the Trellix Mobile Security Shortcut icon in the iOS Shortcuts app.

[IMAGE PLACEHOLDER: "All Shortcuts" iOS Shortcuts screen showing the MTD Shortcut tile with the ellipsis button highlighted]

  1. Tap the “i” icon at the bottom of the screen that displays. This icon is highlighted in the example below.

[IMAGE PLACEHOLDER: Example screen showing the highlighted "i" information icon at the bottom of the Shortcuts details screen]

iPhone Shortcuts workflow screenshot showing the MTD Shortcut actions list and the info/tab icon highlighted

  1. Toggle on Allow Running When Locked to ensure the Trellix Mobile Security shortcut continues to run.

iPhone shortcut privacy settings screen showing Allow Running When Locked toggle turned on

Setting Up Trellix Mobile Security Shortcut Automation

You can set up automation for the Trellix Mobile Security shortcut to check for issues when a new shortcut is added, and to ensure the iOS shortcut list in Trellix Mobile Security is up-to-date after adding or removing shortcuts on your device.

Note: The shortcut will run at the time interval you specify when setting up automation, so it may not be immediate.

  1. Tap Trellix Mobile Security Shortcut Automation from the Shortcut Look Up screen or the Tutorials tile in the Trellix Mobile Security dashboard.

  2. From the tutorial, you can open the Shortcuts app on your iOS device and follow the steps provided to set up automation.

Small screenshot of a Shortcuts Look Up screen showing LAST UPDATED 2021/12/14 | 16:15 and a card labeled MTD Shortcut Automation

Tall mobile screenshot titled Automation Tutorial showing step-by-step instructions for setting up MTD Shortcut Automation with green bullet points and a green Open Shortcuts App button at the bottom

3. Once automation is set up, this screen displays.

Screenshot of the Shortcuts app Automation tab showing a Personal automation card at 2:43 PM, displayed inside a phone-shaped mockup

Shortcut Look Up

The Shortcut Look Up screen allows you to view a breakdown of the shortcuts that are installed on the device. Each shortcut that is found is color-coded to indicate the risk level:

  • Risk detected

  • Threat detected

  • No threat detected

To access this screen, tap the Shortcut Look Up link in the screen that displays after tapping the Shortcuts tile. Here is an example of the Shortcut Look Up screen.

Mobile screenshot of the Shortcut Look Up screen showing a list of installed shortcuts with colored risk indicators and labels such as Threat Detected and No Threat Detected

You can tap on a specific shortcut to view details. Here is an example showing a threat that was detected.

Mobile screenshot titled Extract Archive WebClip Test showing a red THREAT DETECTED banner, DETAILS and RESOLUTION instructions with steps to open the Shortcuts app and delete the shortcut, and a green Open Shortcuts App button

Tip: If the shortcut was last updated a while ago (as shown in the Last Updated field at the top of the Shortcut Look Up screen), you may want to run the Trellix Mobile Security shortcut to verify there are no issues.

Deep Linking into iOS Settings via Shortcuts

The Trellix Mobile Security app provides the ability to directly link to specific iOS settings using zShortcut functionality. This feature allows you to quickly access and manage important settings without having to navigate through multiple menus. By providing direct access to settings like diagnostics, SMS filters, and password management settings, this feature makes device management more efficient and speeds up configuration tasks.

The key features available for deep linking via zShortcuts include:

  • Deep link to diagnostic and problem-reporting settings.

  • Deep link to SMS filter settings.

  • Deep link to Safari extensions related to Trellix Mobile Security.

  • Deep link to trigger a device reboot.

  • Deep link to iOS software update settings.

  • Deep link to passcode management settings.

  • Deep link to configuration profiles.

Note: This feature requires the Trellix Mobile Security app Release 5.5.x or later.

Deep Scan Forensic Analysis (iOS only)

Forensic analysis allows the user to execute a deep scan on the device. It displays a summary of actionable results, identifying whether risks or threats exist and providing recommendations to resolve any issues. This enhances on-device detection, strengthening the identification of system tampering and rogue access points for improved security measures.

Note: This feature requires the user to share iOS log files (system diagnostic logs) with the Trellix Mobile Security app for analysis.

Activating This Feature in Trellix Mobile Security Console

To activate this feature, the administrator must select the Enable Forensic Analysis feature setting in the App Settings policy for Trellix Mobile Security Console 5.24 or later.

Screenshot of the App Settings panel in Trellix Mobile Security Console showing various feature checkboxes; the Enable the Forensic Analysis feature checkbox is highlighted with a red outline.

Running Forensic Analysis

When you open Trellix Mobile Security, the Forensic Analysis tile displays in the dashboard, if enabled (for iOS devices). To perform a deep scan:

  1. Tap the Forensic Analysis tile to open the details and tap the Tutorial link shown here.

Mobile app screen titled Forensic Analysis showing a green magnifying-glass icon, the text NO THREAT DETECTED and FORENSIC ANALYSIS; below it a rounded card titled Why perform a deep scan? with three bullet points describing device diagnostic checks, malware protection, and privacy-first analysis; and a bottom tutorial button labeled TUTORIAL Perform a manual deep scan

2. The tutorial (shown here) displays an arrow to the left of the step that needs to be performed. Once that step is completed, the arrow is replaced by a checkmark and moves to the subsequent step.

Note: For details about steps 1 and 2, tap the expand icon expand icon — square with outward arrows to the right of the step.

Mobile screen titled Deep Scan Tutorial showing a list of steps for performing a manual deep scan and an estimated time of 15 mins.

Each step in the tutorial is described in detail below.

Step 1: Generate System Diagnostics

  1. To run system diagnostics, press and hold the three buttons (volume up, volume down, and power) on the side of your device for 0.5 seconds, then release. On an iPad, a screenshot is taken at the same time. On an iPhone, you will feel a short vibration when the diagnostic process starts.

Note: If your phone displays the emergency call screen after you hold the buttons, it means you pressed them too long. However, the file generation is still in progress and there is no negative impact. Press Cancel. After you receive a notification that the file was generated, proceed to the next step in the tutorial.

This process may take some time. When it is complete, a popup notifies you that the system diagnostic process has been initiated. Click OK. When the file is generated, this popup displays.

Popup titled System Diagnostic File Generated showing file name and an Ok button.

  1. Click OK to close the popup and return to the tutorial screen. Step 1 is now checked and an arrow displays beside step 2.

Note: If you want to restart the tutorial at step 1, tap Reset Steps at the bottom of the screen.

Step 2: Find and Share the System Diagnostic File with Trellix Mobile Security

This step involves going to iOS security and analytics and sharing the system diagnostic file with Trellix Mobile Security.

  1. Tap the expand icon small expand icon showing four outward-pointing arrows in the tutorial to display the instructions for step 2, which are shown here.

    Tall screenshot of the Find and share system diagnostic file with MTD instructions on iOS — purple-tinted panel showing bullet steps, example file name, share icon and a share sheet preview

  2. Open the Settings screen on your device and select Privacy & Security.

    iOS Settings screen screenshot showing the list of settings with Privacy & Security highlighted

3. In Privacy & Security, select Analytics & Improvements.

iPhone Settings Privacy & Security screen listing Research Sensor & Usage Data, HomeKit, Media & Apple Music, Files and Folders, Motion & Fitness, Focus, Safety Check, and Analytics & Improvements highlighted with a red outline

4. Select Analytics Data.

Analytics & Improvements screen showing Share iPhone Analytics toggle at top and the Analytics Data row highlighted with a red outline

5. Search and select or paste the name of the latest sysdiagnose file.

Search view showing sysdiagnose in the search box and a list of timestamped sysdiagnose files (e.g., sysdiagnose_2023.11.14_15-04-02-..., sysdiagnose_2023.11.15_12-50-28-..., sysdiagnose_2023.11.15_13-02-46-...)

6. Tap the share icon in the top right and select the Trellix Mobile Security app icon. If there are multiple versions of that file, the most recent one will be furthest down in the list.

File preview toolbar showing filename sysdiagnose_2023.11.14_15-04-02-... with the share icon in the top right highlighted

If you have selected the correct sysdiagnose file, this popup displays:

Popup window with a green checkmark badge and caption text Sysdiagnose file received and its now being analyzed by the MTD app.

Step 3: Trellix Mobile Security Performs the Scan

Trellix Mobile Security scans the device and indicates when the data generation process ends and a confirmation popup displays.

Mobile app screenshot showing a popup titled Deep Scan Completed with subtitle DEVICE HEALTH No new issues found and a green Details button

Step 4: View Results on the Device

With Findings

If issues are found, the Forensic Analysis tile appears yellow on the dashboard.

  1. Tap this tile to display a list of the active issues. An example is shown here.

Mobile screenshot of the Forensic Analysis results showing a Deep Scan Result card, a list of active issues with severity labels, and Fix buttons beside each issue

2. For any of these active issues, you can tap Fix to display the details about the threat or risk and how to resolve it.

No Findings

If no issues are found, the Forensic Analysis tile and screen show No Threat Detected.

Forensic Analysis tile showing a green gradient card with a magnifying-glass/graph icon, text NO THREAT DETECTED FORENSIC ANALYSIS, scan timestamp and a green Details button

Tap Details to view a report of the results for the areas that were checked. An example of this report is shown here.

Forensic Analysis detailed report screenshot showing Deep Scan Result card, list of checks with green check icons (Healthy Device Check, Permissions Check, Network & Wi‑Fi Check), issues found = 0, and a green Done button at the bottom

File Scanning

PDF and APK documents may contain URLs and scripts that can be used for phishing or nefarious purposes. This feature allows Trellix Mobile Security to scan files on your device, thereby countering novel phishing techniques that elude traditional email gateways. The status of the scan is shown in a progress bar during the process. Once the scan is complete, you can view the results and address any issues that were found.

Sharing the File with Trellix Mobile Security for Scanning

Before Trellix Mobile Security can scan the PDF files to detect threats for iOS, you first need to share the file with Trellix Mobile Security. This option is available in Android, but is not required unless you want to verify the scan.

To learn how to do this, refer to the tutorial link at the bottom of the Files tab and follow the instructions, which are shown here.

Android:

iOS:

Android screenshot showing a Verify Malicious File with MTD tutorial with steps (long press the file, press Share Link, select the MTD app) and icons

iOS screenshot showing a Verify Malicious File with MTD tutorial with steps (long press the PDF, press Share, enable MTD as a share action) and icons

Trellix Mobile Security notifies you if a risk was detected during the share process.

Scanning Process

This section explains what happens for different detection scenarios.

No Issues Detected

The Files tile appears green on the dashboard when no issues are detected. If you tap this tile, it shows the screen below along with a link to a report where you can view previously detected files.

Mobile app screen titled Files showing a green tile with a document icon and text NO RISK DETECTED Supported files scan complete, and two list items labeled TUTORIAL Verify malicious files by sharing them with MTD and REPORT View previously detected files

Malicious or Phishing File Detected

If a malicious or phishing file is detected, the Files tile will appear yellow. An example is shown here.

Tall smartphone screenshot of the Trellix Mobile Security app showing a beige header with a circular target icon and text RISK DETECTED DEVICE IS AT RISK, a green Fix button, and a grid of tiles for Apps, Web, Device, Network, Files, Tag Tracker, Threat Zones, and Tutorials with green icons.

To resolve this issue, tap Fix to display the details screen. The Android version, shown in the figure below, contains a Delete APK or Delete PDF button (depending on the file type), whereas the iOS version has an OK button.

[IMAGE PLACEHOLDER: Two mobile app screenshots side-by-side showing PDF threat detection screens — a light-theme "Phishing PDF Document / RISK DETECTED" screen on the left and a dark-theme "File is Malicious / RISK DETECTED" screen on the right.]

  • For iOS, press OK to exit the screen. The threat is resolved, and you can delete the PDF manually.

  • For Android, press Delete APK or Delete PDF to remove the malicious file from the device. The threat is then resolved.

You can view the Full Event Log to confirm that the threat has been mitigated.

Resuming a Scan When Threshold Is Reached

When the scan begins, a status bar indicates how many files have been scanned and when the scan is complete. Trellix Mobile Security will pause the scan when it determines that the number of files may affect performance or battery consumption during installation. In this case, a Resume Scan button displays.

Mobile app Files screen showing a document icon, text RISK DETECTED 1 FILE, progress SCAN IN PROGRESS | 5 OF 10 SCANNED, a Resume Scan outlined button and a green Fix button; also contains tutorial and report tiles at the bottom

Note: This notification also displays when resuming the scan is an option:

Small notification banner reading Resume PDF Scan - Plug in your phone to charge and open MTD app to resume scan to protect your device.

To resume scanning:

  1. Press Resume Scan to continue scanning whenever you choose. It is recommended that you plug in your device while doing this.

  2. If you return to the dashboard and tap the Files tile, it shows that the scan is complete.

  3. If a risk is detected during the scan, you can tap the Fix button to find out how to resolve the issue. See the image below for an example.

This feature notifies you if any tracking devices, such as Apple AirTags, are tracking your location. If such a device is found, a popup displays the AirTag ID, MAC address, and the date it was first identified. You can select the option to play a sound on the tracker to help you locate it. You can then choose to mark the AirTag as "trusted" if you decide it is not a risk.

Note: This type of detection requires Bluetooth permission. The Tag Tracker tile is only displayed if the “Tag Tracker Detected” threat is enabled in the console.

Here are some examples of Tag Tracker alerts.

Mobile app screenshot showing Tag Tracker main screen with orange target icon, RISK DETECTED and TAG TRACKERS DETECTED text and a green Fix button at bottom

Mobile app screenshot showing Tag Tracker details screen with target icon, an AirTag ID (MAC-like string), RISK DETECTED and resolution details with a Play a Sound button

Mobile app screenshot showing a dimmed Tag Tracker screen with modal Playing A Sound and a circular sound animation and Tag Tracker Found button

Additional Device Data from Google Logs (Android only)

The Trellix Mobile Security app can read additional information from the device, given specific EMM/MDM permissions and the data in the Google logs. This feature provides:

  • Enhancements in our on-device detection capabilities for new detections and additional forensics for existing threats.

  • Enhancements in our forensics events generated for analysis.

Detections are improved for these existing threats:

  • System Tampering

  • Site Blocked

  • Risky Site - Link Tapped

  • Risky Site - Link Visited

  • Risky Site Blocked

Additionally, for this feature to work properly, the device must be in device owner mode. Follow these instructions in order to provision the device properly.

There are several EMM/MDMs currently providing these settings. You can refer to the Trellix Mobile Console EMM/MDM documentation under the “Delegated Scope Enablement” topic for information on how to enable this feature for specific MDMs.

Using the Trellix Mobile Security Tutorials

Trellix Mobile Security provides tutorials to walk you through certain features. These are available from the Tutorials tile on the dashboard and are shown below.

Note: The tutorials that display depend on how the administrator has configured them in Trellix Mobile Console and the operating system type (iOS or Android).

The tutorials that are currently available within the app are listed below for each OS type:

iOS:

  • Add Phishing Check to Your Share Shortcut

  • Enable SMS Filtering

  • Enable Safari Protect Extension

  • Verify Malicious Files by Sharing with Trellix Mobile Security

  • Trellix Mobile Security Shortcut Automation (This tutorial only appears in the tile when the Trellix Mobile Security shortcut is installed on the device.)

Android:

  • Add Phishing Check to Your Share Shortcut

  • Verify Malicious PDF by Sharing With Trellix Mobile Security

Trellix Mobile Security Integration with Samsung Knox

With Android Release 13, Trellix Mobile Security integration with Samsung Knox MTD combines the Knox Platform for Enterprise (KPE) hardware-based capabilities with Trellix Mobile Security machine learning detection to provide users with the most advanced protection available. This provides advanced detection, more detailed forensics, and on-device detection and mitigation.

Advanced Detection and Mitigation

With the advanced integration and communication between Trellix Mobile Security and the Samsung KNOX MTD, there is faster identification and detection of potential threats, more efficient policy definition, and better data loss prevention. The three main areas that this integration leverages more efficiently include:

  • Advanced Detections: Trellix Mobile Security leverages the KPE for the Trellix Mobile Security API framework to facilitate lower-level detections than what is accomplished on other platforms. For example, Trellix Mobile Security for Samsung Knox can identify additional system anomalies, the elevation of privilege attempts, and suspicious network connections made by apps or processes.

  • Enhanced Group-based Mitigations: Trellix Mobile Security for Samsung Knox combines Trellix Mobile Security’s granular, group-based policy advantages with KPE for Trellix Mobile Security’s enhanced mitigations. For example, Trellix Mobile Security for Samsung Knox applies customized data leakage prevention (DLP) actions to prevent unauthorized data exfiltration (for example, restricting Bluetooth sharing, preventing SD card transfers, limiting access to the clipboard, and disabling screen capture).

  • Unparalleled Forensic Detail: For all threats detected, including the advanced threats, Samsung Knox MTD leverages the KPE for Trellix Mobile Security API to provide the highest granular and detailed threat forensics available today.

Note: Samsung Knox for Trellix Mobile Security capabilities requires the purchase of Samsung Knox MTD licenses from Trellix. In addition, Samsung Knox MTD support requires Knox version 3.3 and later, and KNOX API level 29 and greater, on the device.

Accessibility Features for Visual Impairment

Trellix Mobile Security includes these features for users with visual impairment:

  • iOS: VoiceOver Feature and Select Font Size

  • Android: TalkBack Feature and Change Font Size

iOS Accessibility for Visually Impaired

VoiceOver

The VoiceOver feature provides an audible description of what is shown on the device’s screen. The descriptions range from who is calling, to the name of the person that the user is trying to call, and even the battery level on the device. Some of the functions of VoiceOver include:

  • App Name: When the user touches the screen or drags their finger over the screen, the VoiceOver feature identifies the name of the app the user’s finger is on

  • Icons and Text: VoiceOver also audibly describes which icon the user is touching, and even text that is displayed on the screen.

  • Screen Changes: As the user goes from one screen to the next, VoiceOver plays a sound to alert the user to the different screen and speaks the name of the first item on the screen (generally in the top-left corner of the screen).

  • Display Orientation Change: VoiceOver tells the user if the device is in portrait or landscape orientation.

  • Dimmed or Locked Screen: The VoiceOver feature also alerts the user if the screen on the device is dimmed or locked, as well as what is active on the locked screen when the iPhone is awakened.

The speaking rate and pitch can be changed to suit the user’s preferences, and VoiceOver can be turned on or off easily by summoning Siri to do so. There are several ways to turn VoiceOver on or off, and these are all found in the iPhone Guide, along with descriptions of the gestures and different techniques to make the VoiceOver feature convenient and easy to use.

Select Font Size

The Select Font Size feature gives visually impaired users the ability to increase the size of the font so that the text is easier to read for visually impaired users. It provides for easier navigation through the app and features.

You can change the fonts in the Settings and the Accessibility area. The iPhone Guide provides additional instructions including gestures and different techniques of changing the Font Size to make the device easier to use for the visually impaired user.

Android Accessibility for Visually Impaired

TalkBack

The TalkBack feature provides an audible description of what is shown on the device’s screen, which allows visually impaired users to use their device more efficiently and with greater ease. The TalkBack features utilize audible feedback, vibration, and other techniques to let the user know what they are touching on the screen, what else is on the screen, and what actions they can take.

The TalkBack feature is automatically installed on the device as part of the Google Android application suite. It is frequently updated to add new functionality and improvements through Google Play.

Visually impaired users can slide their fingers across the screen of the device and any element - including text - is audibly read back. For text, the screen reader service actually reads the text in an audible voice, and it identifies characters that are emoticons included in the text.

There are several gestures that are used with the TalkBack feature, and various gestures are used to turn TalkBack on. To find out about the other helpful tools and how to efficiently use this feature, refer to the Android support website at www.androidcentral.com.

Change Font Size

The Change Font Size feature allows the visually impaired user to increase the size of the font or the display size so that the text is easier to read and the user can easily navigate through the apps and functionality of the device. The areas in which the font size can be changed include:

  • Email

  • Calendar

  • Device

  • Apps such as Trellix Mobile Security that support larger font and zoom settings

The fonts are easily changed in the Settings and the Accessibility area. The slider can be dragged across the screen to select a larger font size while in the Accessibility menu for either the Font size or the Display size. If the font size makes the text too large, where it becomes difficult for the user to work with the functions, it can be adjusted to a smaller font, allowing users to tap the buttons or use the apps more conveniently.

The Android Accessibility guide provides additional instructions, including gestures and different techniques for changing the font size to make the device easier to use for the visually impaired user and is found on the Google support website at support.google.com.

Local Device Actions

The Trellix Mobile Console administrator has options that are performed locally on the device when there is a threat detected. Currently, these actions can be selected as part of the Trellix Mobile Security Console Threat policy.

Android and iOS Device Actions

  • Disconnect WiFi (Android Only): When this item is selected in the Threat Policy, Trellix Mobile Security disables the Wi‑Fi network interface in response to the selected threats. The user can enable the Wi‑Fi network interface when they are in a safe location.

  • Note: Because of an Android update, the device action Disconnect Wi‑Fi requires Android 9 or earlier.

  • Network sinkhole: If a threat is detected with the ‘Network Sinkhole’ action, Trellix Mobile Security either allows or blocks network CIDRs as defined by the Trellix Mobile Console administrator. During this time, the VPN indicator is shown in the status line of the iOS device.

  • Tunnel unsecured traffic: Trellix Mobile Security connects the device to a secured VPN to tunnel the non‑secured (HTTP) traffic over the unsecured Wi‑Fi connection.

Samsung Knox Device Actions

The Standard Samsung Knox Device Actions include the following:

  • Isolate device from the network

  • Disable App

  • Uninstall App

  • Block App

  • Also use Android actions

Note: Built-in apps on the device, such as Chrome, cannot be uninstalled.

The Advanced Samsung Knox MTD device actions include Data Loss Prevention. The settings for the Data Loss Prevention device action are configured on the Samsung Knox MTD Policy tab on the Policy page.

Note: The Samsung Knox for Trellix Mobile Security Data Loss Prevention actions require the purchase of Samsung Knox MTD licenses from Trellix. In addition, Samsung Knox MTD support requires Knox version 3.3 and later, and KNOX API level 29 and greater, on the device.

Chrome Extensions Device Actions

The device actions supported for Chrome extensions are:

  • Disabled by Time Preset

  • Uninstall extension

Appendix A – Google’s Android Enterprise Implementation with Trellix Mobile Security

Overview

Google’s Android Enterprise provides an environment to separate the business app data from the user’s personal app data. Applications in the work profile of Android Enterprise run in a separate protected workspace vs the personal side of the device. For example, the Android Enterprise ‘Contacts’ app has different contacts than the personal ‘Contacts’ app. Applications running in the work profile can only see other applications and processes in the work profile.

Supported Configurations

When implementing Trellix Mobile Security on a device with Android Enterprise, there are the following supported configurations:

  • Running Trellix Mobile Security only in the work profile of the device.        

    • Monitors apps installed in the work profile.

    • Monitors network behavior on the device.

    • Monitors abnormal behavior on the device.

  • Running Trellix Mobile Security only in the Personal profile of the device.        

    • Monitors apps installed in the personal profile.

    • Monitors network behavior on the device.

    • Monitors abnormal behavior on the device.

  • Running Trellix Mobile Security in both the work and personal profiles. This configuration provides the best protection.        

    • Monitors apps installed in both the personal and work profile.

    • Monitors network behavior on the device.

    • Monitors abnormal behavior on the device.

    • For information on how to have the personal profile auto-activate, select an MDM Guide and review the configuration keys for this setup.

Regardless of which deployment option is used, Trellix Mobile Security detects device and network threats. The detection and evaluation of applications is done by Trellix Mobile Security on apps that are installed in the same container as Trellix Mobile Security (work, personal, or both depending on the deployment model).

This figure shows how Trellix Mobile Security runs within the different Android profiles.

[IMAGE PLACEHOLDER: Diagram showing Trellix Mobile Security running within the different Android profiles — work profile container and personal profile container, illustrating which apps and processes are visible to Trellix in each profile.]

Illustration of a smartphone mockup showing two columns labeled PERSONAL and WORK and three blue numbered tiles (1, 2, 3) aligned along the left edge of the device

Trellix Mobile Security Running in Work and Personal Profiles

When Trellix Mobile Security is running within both the work and personal profiles, Trellix Mobile Console shows it as one device. This configuration uses one license. Trellix Mobile Console displays the two profiles within the device as two applications.

The two Trellix Mobile Security applications coordinate so threat notifications are not duplicated. Because it is one device, the same threat policies apply to both instances of the Trellix Mobile Security application. This figure shows what displays on the Trellix Mobile Console when the device is selected.

Tall vertical screenshot of Trellix Mobile Console device details (google Nexus 5) showing device summary, app list, warnings icons, and detailed device properties

The work profile Trellix Mobile Security application can be configured to install on the device.

The personal profile application must be manually installed by the user. In the configuration with

Trellix Mobile Security in both profiles, the auto-activation functionality works the same as when a single Trellix Mobile Security application is installed.

Note: Knox security is supported the same way Trellix Mobile Security supports Android Enterprise.

Appendix B – Android Support for Chromebook

Trellix Mobile Security for Android support for Chromebook requires the Chromebook to support Android apps and the Google Play Store. A list of Chromebook devices that support Android apps is found at this link..

Trellix Mobile Security running on Chromebook supports detections across apps, devices, networks, and phishing areas. See the Trellix Mobile Console Threat Reference Guide for the list of specific threats that are supported on Chrome OS.

Trellix Mobile Security running on Chromebook supports the following local device actions for Chrome extensions:

  • Disabled by Time Preset

  • Uninstall extensions

Trellix Mobile Security running on Chromebook supports the following for local VPN phishing protection:

  • The machine-learning classifier.

  • Local or remote lookups.

  • The ability to block or allow phishing links.

Note: URL Sharing phishing and URL Handler phishing are not supported in Chromebook.

Appendix C – Handling a Server Verification Incomplete Message

If you receive a “Server verification incomplete” message as shown in the figure below, contact your administrator. For devices with phishing protection enabled, the corresponding threats must be enabled in the threat policy.

Pop-up dialog titled Server verification incomplete showing a shield icon at the top, explanatory text that references a URL, and a large green RETRY button; small close (×) icon at the top-right