Skip to main content
The BlueApp for MobileIron Threat Defense provides a set of orchestration actions that you can use to identify and manage assets in your USM Anywhere environment. The following table lists the available actions from the BlueApp. Actions for the BlueApp for MobileIron Threat Defense
ActionDescription
Wipe DeviceRun this action to remotely wipe the contents of a user’s device.

You can enter a message that will be displayed on the device before it is wiped.

Once the device is wiped, it returns to factory default settings.
Change PasswordRun this action to remotely issue a new password for a user’s device.

The password must have at least 12 characters, including at least 1 special character, 1 uppercase character, 1 lowercase character, and 1 number.
Send MessageRun this action to send a message directly to a user.

You can choose to send a message either though the email registered to the phone, by push notification, or both.
Delete UserRun this action to delete a user.
Retrieve EventsRun this action to retrieve events from zConsole.
Retrieve Matched AssetsRun this action to retrieve matched assets from MobileIron Cloud.
Scan MobileIron UsersRun this action to scan the users from MobileIron.
Send MessageRun this action to send a message to the selected device from a user.
Send MessageRun this action to send a message to the selected device from an alarm.
Send MessageRun this action to send a message to the selected device from EV.
Change Password from AlarmRun this action to change the password for a user from an alarm.
Change Password from EventRun this action to change the password for a user from an event.
Change PasswordRun this action to change the password for a user.
Wipe Device from AlarmRun this action to wipe a device from an alarm.
Configure to Device/Device Group from AlarmRun this action to configure the device or device group from an alarm.
Configure Device/Device Group from EventRun this action to configure the device or device group from an event.
Configure Device/Device Group from UserRun this action to configure the device or device group from the user.
Create or assign a Device to a Device GroupRun this action to create or add an existing device to the MobileIron Device Group.

Click Associated User Details, Device Application List, or Device Compliance Status to see more details on the device.
Create or Assign a User to a User GroupRun this action to create or add an existing user to a User Group.

Click Associated User Groups to see details on the device’s current group associations.
Assign a Policy to a Device GroupRun this action to assign a policy to the selected device group.

Click Device Details, Associated Device Groups, Associated Configurations, or Associated Policies to see more details related to the device.

Click Available Configurations or **Available Policies **to see a list of all configurations and policies available.

Click Associated Policies in the action window, and select a dynamically generated list of policies from the All Policies drop-down list.
Assign a Configuration to a Device or Device GroupRun this action to assign a user configuration to the selected device group.

Click Associated Configurations to see a list of the current configurations for the device.
Lock DeviceRun this action to remotely lock a user’s device.

Click Device Details, Device Application List, or **Device Compliance Status **to see more details on the device.
Unlock DeviceRemotely unlock a user’s device.

Click Device Details, Device Application List, or **Device Compliance Status **to see more details on the device.
Restart DeviceRun this action to remotely restart a user’s device.

Click Device Details, Device Application List, or Device Compliance Status to see more details on the device.

Click Device Details, Device Application List, or Device Compliance Status to see more details on the device.
Retire DeviceRun this action to remotely retire a user’s device.

Click Device Details, Device Application List, or Device Compliance Status to see more details on the device.

When you retire a device, all management features are removed. This also deletes documents, configurations, and profiles.

If the device is registered as a corporate-owned device, it reverts to factory default settings.
To view information about these actions in USM Anywhere
  1. In USM Anywhere, go to Data Sources > BlueApps.
  2. Click the Available Apps tab.
  3. Search for the BlueApp, and then click the tile.
  4. Click the Actions tab to display information for the supported actions.
  5. Click the History tab to display information about the executed orchestration actions.

Launch Actions from USM Anywhere

You can launch an action directly from alarms or events. If you want to apply an action to similar events that occur in the future, you can also create orchestration rules directly from the action applied to an alarm or event.
  1. Go to Activity > Alarms or Activity > Events.
  2. Click the alarm or event to open the details.
  3. Click Select Action.
  4. In the Select Action dialog box, select the MobileIron tile.
  5. For the App Action, select the action you want to launch.
  6. Enter the name of the category you want the IP address added to, if applicable.
  7. Click Run. After USM Anywhere initiates the action for an alarm or event, it displays a confirmation dialog box. If you want to create a rule to apply the action to similar items that occur in the future, click Create rule for similar alarms or Create rule for similar events and define the new rule. If not, click OK.
I