MobileIron products involved with derived credentials

The following table shows the MobileIron products necessary for an AppConnect app to use derived credentials.

Table 1. MobileIron products involved with using derived credentials

Product

Role in supporting derived credentials

MobileIron Core

You configure Core so that the appropriate AppConnect apps use derived credentials.

NOTE: MobileIron Connected Cloud does not support derived credentials.

Mobile@Work for iOS

On iOS devices:

Registers the device users with MobileIron Core
Stores the derived credential that a derived credential app obtained from a derived credential provider.
Delivers the certificates from the credential to the appropriate AppConnect apps.

Mobile@Work for Android

On Android devices:

Registers the device users with MobileIron Core
Passes information between the Secure Apps Manager and MobileIron Core.

Secure Apps Manager for Android

On Android devices:

Stores the derived credential.
Delivers the certificates from the credential to the appropriate AppConnect apps.

PIV-D Manager app for Android

On Android devices:

Obtains the Entrust derived credential from Entrust.
Delivers the credential to the Secure Apps Manager.

PIV-D Manager app for iOS

On iOS devices:

Obtains the derived credential from Entrust or DISA Purebred
Delivers the credential to Mobile@Work for iOS.

iOS: AppConnect for iOS SDK or wrapper used in third-party or in-house AppConnect apps

Android: the AppConnect wrapper

Provides AppConnect functionality to apps. Only AppConnect apps can use derived credentials.

Standalone Sentry

Provides email access control and AppTunnel support for iOS AppConnect apps using derived credentials, just as it does for any app.

NOTE: On iOS devices, for derived credential providers other than those supported by the PIV-D Manager app, a third-party derived credential app can be used. The app must be built with APIs provided by MobileIron in the AppConnect for iOS SDK. It obtains a derived credential from the derived credential provider and delivers the credential to Mobile@Work.
App use cases for derived credentials
For information about supported and compatible versions of MobileIron components, see:
- MobileIron Core and Connector Release Notes and Upgrade Guide
- Mobile@Work for iOS Release Notes
- Mobile@Work for Android Release Notes
- Android Secure Apps Release Notes and Upgrade Guide
- MobileIron PIV-D Manager App for iOS Release Notes
- MobileIron PIV-D Manager App for Android Release Notes