惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
G
Google Developers Blog
Blog — PlanetScale
Blog — PlanetScale
U
Unit 42
A
About on SuperTechFans
Vercel News
Vercel News
B
Blog
Martin Fowler
Martin Fowler
MyScale Blog
MyScale Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
腾讯CDC
D
Docker
V
Visual Studio Blog
博客园 - 叶小钗
The Cloudflare Blog
Jina AI
Jina AI
B
Blog RSS Feed
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
WordPress大学
WordPress大学
T
Tailwind CSS Blog
MongoDB | Blog
MongoDB | Blog
D
DataBreaches.Net
月光博客
月光博客
大猫的无限游戏
大猫的无限游戏

Omnissa

Discover which solution is best for you: VDI, DaaS, or RDSH From on-prem to cloud: how Horizon licensing adapts to you Inside the Forrester TEI findings: Workspace ONE UEM delivered 170% ROI As security continues to evolve, has your mobile strategy? Introducing automated enrollment for Horizon Cloud desktops with Workspace ONE UEM Omnissa and GEMA partner to empower organizations with a modern digital sovereignty solution Attention Omnissa Intelligence users: Show off your dashboard! How P&O Cruises and Cunard manage devices & IT support at sea Omnissa Solution Exchange: Discover additional ways to maximize your Omnissa investments Horizon Cloud on vSphere: Hybrid DaaS made easy 10 challenges that hold back Horizon success Omnissa named a Leader in the 2025 Gartner® Magic Quadrant™ for Desktop as a Service Omnissa scores highest in 4 out of 4 Use Cases in 2026 Gartner® Critical Capabilities for Endpoint Management Tools Enabling the Modern Workforce with Omnissa Workspace ONE and Samsung Knox Suite Point of view: The autonomous workspace will reshape the role of enterprise IT Introducing Workspace ONE UEM 2602: A feature packed release with updates across the board Why security fundamentals matter more than ever Android XR Management with Workspace ONE What's new with DEX for Horizon: expanding partner ecosystems and integrations Customer adoption grows for Omnissa Horizon deployments on Nutanix AHV Optimize secure, seamless workspaces with IGEL and Omnissa Omnissa Secure Access Suite delivers secure browser functionality with the Omnissa platform ICYMI: Highlights from our “App Management Reimagined” event Omnissa Pass: Native MFA for stronger, simpler security Modern education—any device, everywhere learning with smarter IT DEX is a value strategy: How Omnissa helps turn IT from cost center to value engine From fragmentation to fruition: Why a platform approach wins Mod Stack architecture: Rebuilding for flexibility, scalability, and resilience New Omnissa 2026 study finds shadow AI, security gaps, and device instability expose need for end-to-end IT observability Omnissa accelerates global market momentum with strategic board expansion and executive leadership appointment
Block risky and unwanted mobile apps with Omnissa
Wendy Leung · 2025-08-14 · via Omnissa

Apps that are considered security risks on mobile devices continue to be big problems. According to Lookout’s Q3 2024 mobile threat report, ‘more than 106,000 malicious apps were detected on enterprise mobile devices, which can vary widely from trojan malware to sophisticated spyware’. State and federal governments have garnered the most headlines for their stance on unwanted apps, but malicious apps can pose a threat to many organizations who’s employees use mobile devices for their work. 

Because these applications are a growing concern for business, IT teams are increasingly tasked with addressing these potential vulnerabilities. To bolster security, organizations need an effective strategy for blocking or removing risky mobile apps from devices that access an organization’s data. Although this may seem challenging to some, Omnissa Workspace ONE UEM administrators can easily manage and protect devices by blocking these apps.

Ways to block unwanted apps on managed devices

If you are an Omnissa Workspace ONE customer, you have two primary options to restrict unwanted apps on enrolled devices:

  1. If you have Omnissa Workspace ONE Mobile Threat Defense powered by Lookout, all apps installed across enrolled devices are scanned for malicious code to protect sensitive company information. End users will get a notification explaining why the app is dangerous and how to fix the problem. Admins, using the Apps Explorer in the console can view all apps present across enrolled devices. The list is sorted by OS, app name, risk exposure, percentage of total enrolled devices running the app and more. You can configure policies and automated response actions to detect and act when an unwanted application is installed on a device in your fleet. Learn more about creating threat response actions here.
  2. If you are not yet using Workspace ONE Mobile Threat Defense for advanced security protection, Workspace ONE UEM can assist you in approving or denying apps on your enrolled mobile devices with application groups, compliance policies, and device management.  

Use Workspace ONE UEM to manage apps

With Workspace ONE UEM, you can manage application groups and compliance by creating collections of allowed, denied, or required applications for the various personas of users within your organization. Then, you can create compliance policies to identify any drift from baselines and to take action automatically. Documentation on this can be found here

Next, blocking or restricting the app store for your device platform can prevent users from downloading unwanted apps.

For iOS devices

For iOS, you can block end user access to the Apple App Store with a restrictions profile as well as restrict a device to only install assigned public apps from the Apple App Store. You can also use restricted mode to allow installing free, public apps from the Workspace ONE Intelligent Hub but not from the Apple App Store. Documentation on how to apply these restrictions in Workspace ONE UEM are available here.

For unsupervised iOS devices, it is recommended that you use the Workspace ONE UEM compliance engine to enforce and configure security policies and automatically detect/respond to non-compliant devices. Learn more about enabling unmanaged enrollment for iOS devices here.

For Android devices

When managing Android devices, it is essential to understand the different device management modes for bring-your-own-device (BYOD) and corporate-owned personally enabled (COPE) use cases. A work profile is designed for bring-your-own-device (BYOD) use cases, allowing the organization to separate work apps and data from personal apps and data and assigning apps within the work profile on the device. In this mode, Workspace ONE UEM only has control over the work profile and cannot manage access to the Google Play Store in the device’s personal profile.

For COPE devices, work managed, or fully managed, devices are enrolled from an unprovisioned state (factory reset). In this mode, Workspace ONE UEM has full control over the apps shown in the Google Play Store on the device. Documentation on how to restrict installation of public apps in Workspace ONE UEM are available here.

Along with controlling allowed apps through the management mode of the Android device, configuration profiles in Workspace ONE UEM can help you manage applications on your devices. 

The application control profile allows you to control approved applications and prevent uninstalling important apps. To learn more about or to configure an application control profile, please read the Omnissa documentation here

Like iOS, an Android restrictions profile locks down the native functionality of Android devices. This includes removing access to the native app store for the platform. To create a restrictions profile that removes access to the Google Play Store, please refer to the Omnissa documentation here.

Secure your connected mobile fleet

Organizations may want to block specific applications on their end users’ devices for many reasons. Although the reasons may vary by industry, Workspace ONE UEM and Mobile Threat Defense have the tools to help you manage access to apps for your business.

In addition to protecting your mobile devices from unwanted apps, learn how prevalent mobile phishing is and how Workspace ONE Mobile Threat Defense can help secure your mobile fleet in this video.