Jump to:navigation, search
Wiki







































Function of the iOS app Cloud Shield

Last adaptation to the version: 1.4(10.2025)

New:
notempty
This article refers to a Beta version

Access:

Prerequisite

  • At least iOS version 17

Introduction

With the Securepoint Cloud Shield app for iOS / iPad devices, all DNS requests from the iOS / iPad device are routed through secure servers that block suspicious or malicious domains based on regularly updated filter lists

  • Requests are encrypted (DNS-over-TLS/HTTPS) to prevent tampering and eavesdropping attempts
  • Central distribution via Securepoint Mobile Device Management ensures that all smartphones are uniformly protected and that company guidelines for secure Internet use are adhered to
  • At the same time, tracking and data theft are reduced while connection speed remains optimized

Preparations

Devices in MDM

2=* A profile of type  Managed devices is available in the Securepoint Portal under Cloud Shield Profile . Further information on this can be found in the following wiki article

  • Select the desired iOS / iPad profile under  Mobile Security iOS/iPadOS  Profiles . Further information on this can be found in following wiki article
  • In the profile tab Cloud Shield select the option Enable Cloud Shield and under Profile select the Cloud Shield profile * The Cloud Shield app is then ‘’'automatically'‘’ installed on the iOS / iPad devices with the corresponding iOS / iPad profile
  • The Cloud Shield profile is applied to the iOS / iPad devices
  • When starting the Cloud Shield app for the first time, the DNS setting of the iOS / iPad device must be adjusted; this is done under ‘’'General → ‘’'VPN and device management → ‘’'DNS'‘’' switch to Cloud Shield
  • This is displayed accordingly on the home screen of the app
  • The app cannot be used until this setting has been made
  • Devices without MDM / External devices

    A profile of type  External devices is available in the Securepoint Portal under Cloud Shield Profile . Further information on this can be found in the following wiki article

    • Download the Cloud Shield app at Apple App-Store
    • When starting the Cloud Shield app for the first time, the DNS setting of the iOS / iPad device must be adjusted under GeneralVPN and device managementDNS' switch to Cloud Shield
  • This is displayed accordingly on the home screen of the app
  • Until this setting has been made, the app cannot be used

  • Cloud Shield Startscreen

    • The start screen of the Cloud Shield app for managed iOS / iPad devices shows whether the app is active    or inactive   
    • Cloud Shield can be activated or deactivated via the button
    • Error messages and notes are also displayed
    • With the button Settings button to display the settings
    Hovern: MDM ⇄ external Devices
    Start screen of the app for MDM devices
    Start screen of the app for external devices on first start without configuration ID
    • The start screen of the Cloud Shield app for ‘'external iOS / iPad devices’' will display an error message when first started: ‘’'No configuration ID'‘’'
      • As long as this message is displayed, the app cannot be activated
      • To add a configuration ID, click Settings, see below for more information
    • Cloud Shield can be activated    or deactivated    via the button
    • Error messages and notes are also displayed
    • With the button Settings button to display the settings

    Settings

     Tenant Domain: 123456.sms Displays the associated tenant
    App settings for managed devices
     Profile name: TTT-Point DNS Displays the profile name of the Cloud Shield profile used
    exclude SSIDs
    • This can be used to exclude certain SSIDs from the Cloud Shield settings
    • This is only possible with the currently connected SSID
    • Excluded SSIDs are listed
    • If an excluded SSID is to be deleted again, it is swiped to the left
    Securepoint Wiki A direct redirect in the device browser to this Wiki article
    Imprint   Displays the imprint with the contact details
    Data protection   Displays the privacy policy
    EULA   Displays the end user agreement
    Licenses   Displays the licenses of the open source programs used
     Managed devices: The Close button is closing the settings window
     External devices: The Save button is used to apply and save changes made

    Activation for external devices

    A configuration ID is required so that the Cloud Shield app can be used on external iOS / iPad devices
    • Select the desired profile of type  External devices in the Securepoint portal under Cloud Shield Profile
    • Click on the  Configuration: button  display on its profile tile and switch to the  Cloud Shield App tab in the dialog window
    • Open the Cloud Shield app and click Settings

    Either
    • the QR code from the dialog window is scanned with the app's QR scanner
      • QR scanner of the app can be called up via the button at Configuration ID
    Or
    • The configuration ID displayed in the abc123 dialog box is entered in configuration ID

    • ‘’‘Optional’‘’ a name can be entered in device name (optional)
    • The configuration ID is saved via the Save button
    App settings for external devices with configuration ID

    Activation for external MDMs

    If an iOS/iPad device is integrated in another MDM, i.e. not in Securepoint MDM, it is still possible to use the Cloud Shield app for this device.

    Prerequisite: The external MDM has a configuration ID External-Config-ID

    • Cloud Shield app in the Apple App Store is downloaded
    • In the app, click Settings
    • In Configuration ID the ‘'External-Config-ID’'
      The configuration ID of the external MDM
      is entered
    • The button Save is used to save the External-Config-ID

    After successful saving, the app can be activated    and is ready for use

    App settings for devices in external MDM
    notempty
    Under Settings the following is no longer possible after a successful save:
    • The Configuration ID field can no longer be edited
    • The QR code scanner in the configuration ID field is deactivated
    • The device name (optional) field is hidden