harmon.ie for MobileIron

harmon.ie Knowledge Base - Mobile Enterprise

harmon.ie for MobileIron gives employees full SharePoint access while protecting and minimizing risk to corporate data. Business data is protected by encryption and applying application and data access controls within a secure container, separating it from personal information.

Protection at the application level also prevents users from inadvertently leaking corporate data. For example, IT can prevent employees from sending SharePoint document links, or copying them into consumer apps or personal email.

harmon.ie for MobileIron guaranties secured networking, data storage and data transfer between harmon.ie and third party apps via the MobileIron API.

Network Diagram

In this article:

What's new in harmon.ie for MobileIron

Version 3.8 (March, 2017)

Version 3.2.6 (November, 2016)

  • Improved single sign-on integration to allow silent bootstrap (via enterprise provisioning).
  • Added Open in Browser action to sites, which opens the site’s URL in harmon.ie's internal browser.

Version 3.2.5 (November, 2016)

  • Improved single sign-on integration.

Version 3.2.4 (October, 2016)

  • Improved the support for followed sites.

Version 3.2.3 (August, 2016)

  • Support the removal of Sandbox Solutions in SharePoint Online.

Version 3.2.2 (April, 2016)

  • Fixed an Microsoft 365 connectivity issue.

Version 3.2.1 (February, 2016)

  • Added support for MobileIron Go, in order to connect to MobileIron Cloud.
  • Bug fixes.

Version 3.2 (November, 2015)

Configuring Cloud security with MobileIron Access:

Before you can start distributing harmon.ie to your users, you need to add harmon.ie to the MobileIron App Catalog:

  1. Login to the MobileIron Cloud.
  2. Select Apps > App Catalog > Add.
  3. Search and select harmon.ie for ME, and then click Next.
  4. Optionally define Category and Description, and then click Next.
  5. Select distribution audience: Everyone / No One / Custom (which allows to set User Groups as well as single Users), and then click Next.
  6. Click the + icon next to AppConnect Custom Configuration:
    1. Supply a Name for the Configuration Setup.
    2. Optionally, add the following key:
      ​​provisioningURL - The URL of the provisioning file. This is a permanent provisioning source updated automatically to devices. (Value: full URL)
      Note: Only one provisioning source should be used. If you choose to use the MobileIron VSP as the provisioning source, do not use harmon.ie setup as a second provisioning source.
    3. Select distribution audience for the App Config: Everyone with App / No One / Custom.
  7. Click the + icon next to AppTunnel
    1. Supply a Name for the Configuration Setup.
    2. Under App Tunnel, select your company's Sentry Profile.
    3. Select distribution audience for the App Config: Everyone with App / No One / Custom.
  8. Click Next.

Configuring desktop security with MobileIron Bridge:

Before you can start distributing harmon.ie to your users, you need to create the following items on your MobileIron VSP:

  1. harmon.ie app Configuration – this allows AppConnect to auto-configure the harmon.ie client app
  2. harmon.ie app Container Policy – this policy can then restrict some of the capabilities of harmon.ie.
  3. harmon.ie app Group Policy - there can be multiple group policies that can restrict some of the user's capabilities on harmon.ie devices.

Note: In order for these policies to be applied to mobile devices, ensure that you assign the MobileIron labels for any required users to both the Configuration and the Container Policy.

harmon.ie App Configuration

  1. Log into your MobileIron VSP web console and select the POLICIES & CONFIGS tab.
  2. In the Configurations tab, click Add New. In the AppConnect menu item, select Configuration.

    The Modify AppConnect App Configuration page appears.
  3. Enter the following information:
    • Name – The name of this configuration. You may create more than one configuration and assign those configurations to different MobileIron labels.
    • Description – A description of the configuration.
    • Application – From the drop-down list, select the harmon.ie app.
    • AppTunnel – The AppTunnel settings enable you to use the AppTunnel to provide access to your SharePoint server(s).
      URL Wildcard – the DNS address of your SharePoint server(s) and the Office Online server.
      Port – the port number used to connect to your SharePoint server(s).
      Sentry – the DNS address of your MobileIron Sentry server.
    • Under Settings > Sentry > App Tunneling Configuration,​ add the services required for each of your SharePoint servers.
      • For Microsoft 365 add:
        1. Server host: "domain.sharepoint.com:443"
        2. My Site host: "domain-my.sharepoint.com:443"
        3. Office Online host: "euc-word-edit.officeapps.live.com:443"
      • For SharePoint on premise add:
        1. Server host
        2. My Site host (if it is different from the primary server host)
        3. Office Online host (add the internal server's host)
    • App-specific Configurations – Optionally, add the following key:
      ​​provisioningURL - The URL of the provisioning file. This is a permanent provisioning source updated automatically to devices. (Value: full URL)
      Note: Only one provisioning source should be used. If you choose to use the MobileIron VSP as the provisioning source, do not use harmon.ie setup as a second provisioning source.
    The following screen capture is an example of the required information described above:

harmon.ie ​App Container Policy

Note: This policy is created specifically for an application. Alternatively, you can assign a Global Policy to your harmon.ie users.

  1. Log into, or return to your MobileIron VSP web console's POLICIES & CONFIGS tab.
  2. In the Configurations tab, click Add New. In the AppConnect menu item, select Container Policy.
    The Modify AppConnect Container Policy page appears:
  3. Enter the following information:
    • Name – The name of this configuration. You may create more than one configuration and assign those configurations to different MobileIron labels.​
    • Description – A description of the configuration.
    • Application – From the drop-down list, select the harmon.ie app.​
    • Exempt from AppConnect passcode policy - Select this option if you would like users to be able to open harmon.ie without having to first authenticate with their AppConnect passcode.
    • For iOS, select from the following options:
      • Allow Copy/Paste To - Select this option if you would like harmon.ie users to be allowed to copy and paste text from documents viewed in harmon.ie into other apps on the device that are either managed or not managed by AppConnect.
      • Allow Open In - Select this option if you would like to allow harmon.ie users to open files into other applications on the device. If selected, this option will also allow you to specify a list of specific apps that are allowed.