Configure and deploy Lookout for Work apps
Applies to: System Center Configuration Manager (Current Branch)
This article explains how to configure and deploy the Lookout for Work app for Android and iOS devices.
Android (Google Play store app)
In the Configuration Manager console, click Software Library > Application Management > Applications.
On the General page of the Deploy Software Wizard, specify the following information:
- Type: select App package for Android on Google Play.
- Location: copy the Lookout for work app link from the Google Play store as paste it here
- Publisher: Lookout Mobile Security
- Name: Lookout for Work
- Description: Lookout offers the best protection against mobile threats to keep your device safe. When the Lookout app is installed, the app protects your device from threats. If it finds any threats, it alerts you and your IT administrator.
- Administrative category: Computer Management
Upon successful completion, you see the Lookout for Work app in your list of applications.
On the Home tab, in the Deployment group, choose Deploy to deploy the Lookout for Work app to users.
You must select the same users added in to the Enrollment Management option in the Lookout MTP console.
Choose the Required Install option. This option requires the Lookout app to install on the user’s device.
iOS (enterprise-signed version of Lookout app)
Make sure iOS management is set up on your devices. For instructions on how to set up your device for iOS management, see Set up iOS and Mac device management.
Re-sign the Lookout for Work iOS app. Lookout distributes its Lookout for Work iOS app outside of the iOS App Store. Before distributing the app, you must re-sign the app with your iOS Enterprise Developer Certificate. For detailed instructions to re-sign the Lookout for Work iOS apps, see Lookout for Work iOS app re-signing process on the Lookout site.
Enable Azure Active Directory (Azure AD) authentication for the iOS users.
Sign in to the Azure AD blade of the Azure portal, and navigate to the app registrations page.
Specify the Name as Lookout for Work iOS app, and select Native as the Application Type.
For this Redirect URI, use the following format:
<yourcompanyname>with your company name. For example:
Click Create to create the app.
Open the new app, click Settings, and add an additional Redirect URI. Use the following format:
<originalURI>is a URL-encoded version of your original Redirect URI. For example,
In the app settings, go to Required permissions and click Add. Select the following delegated permissions:
API Permission Lookout MTP Access Lookout MTP Microsoft Graph Sign in and read user profile
For more information, see Configure a native client application.
In Configuration Manager, upload the re-signed .ipa file. Set the minimum OS version to iOS 8.0 or later. For more information, see Create iOS applications.
Create the managed app configuration policy. For more information, see Configure iOS apps with mobile app configuration policies.
Deploy the Lookout for Work app to users. For more information, see Deploy applications.
Select the same users that were added to the Enrollment Management option in the Lookout console. Choose the Required Install option. This option requires the Lookout app to install on the user’s device.
What happens when the deployed app is opened on the device
When the user opens the Lookout for Work on the device, it prompts them to activate the app. They should choose to sign in with the Azure AD option. A detailed walkthrough with the end-user flow is in the following articles:
Send feedback about: