IBM®
MaaS360® features are available for customers to enable in
the form of services. Depending on the license entitlement, these services are available for
customers to turn on from the IBM
MaaS360 Portal Services section or
as settings in the IBM
MaaS360 policies. IBM
MaaS360 license management monitors the activation of
these services on devices to determine license usage. The service usage is aggregated for a device
or a user, depending on whether the license model is per device or per user.
List of IBM MaaS360 billed services
The following IBM MaaS360 services include how the
service is enabled and how the service usage is calculated.
For details on the list of services that are available with each of the different IBM MaaS360 licenses, see the service description at https://www.ibm.com/software/sla/sladb.nsf/latest/sd-6741.
The following combination of criteria is used to enable and track the usage of the various IBM
MaaS360 services.
-
- Portal service
- Services that are listed on the Services page in the IBM
MaaS360 Portal. For more
information, see Configuring services in the IBM MaaS360 Portal.
-
- Policy setting
- The service is enabled in an IBM
MaaS360 policy. For more information, see IBM MaaS360 security policies overview.
-
- Installed service on the device
- Enter criteria in the Advanced Search option to view services that are
installed on the device ().
Table 1. Mobile Device Management
| Platform |
How is the service enabled? |
How is the usage tracked? |
| iOS |
- Portal service
- Enable .
|
The managed status of the device is Enrolled. Note: The Managed Status
attribute in Advanced Search is part of the Hardware Inventory category.
|
| Android |
- Portal service
- Enable .
|
The managed status of the device is Enrolled. Note: The Managed Status
attribute in Advanced Search is part of the Hardware Inventory category.
|
>>Back to the list of
MaaS360 billed services
Table 2. Laptop Device
Management
| Platform |
How is the service enabled? |
How is the usage tracked? |
| macOS |
- Portal service
- Enable .
|
The device is managed by the MaaS360 agent or the
macOS MDM agent. |
| Windows |
- Portal service
- Enable Windows Desktop and Laptop
Management.
|
The device is managed by the MaaS360 DTM agent or
by the Microsoft MDM agent. |
>>Back to the list of
MaaS360 billed services
Table 3. Mobile Application
Management
| Platform |
How is the service enabled? |
How is the usage tracked? |
| iOS |
-
- Portal service
- Enable .
- The App Catalog is available on the device.
Notes:
- For MDM, the App Catalog is installed automatically even with no app distributions. The IBM
MaaS360 app is available by default.
- For SPS, the App Catalog is available as part of the IBM
MaaS360 app when there is at least one app that is
distributed to the device apart from IBM
MaaS360.
|
- Installed service on the device
- The Installed Services category for the device at lists the App Catalog as a
service that is installed on the device.
|
| Android |
-
- Portal service
- Enable .
- At least one platform-specific app other than the IBM
MaaS360 app is distributed to the device.
|
- Installed service on the device
- The Installed Services category for the device at lists the App Catalog as a
service that is installed on the device.
|
| Windows |
-
- Portal service
- Enable .
- At least one platform-specific app other than the IBM
MaaS360 app is distributed to the device.
|
- Installed service on the device
- The Installed Services category for the device at lists the App Catalog as a
service that is installed on the device.
OR
The Apps Distributed category for the device lists at least one app with an
Installed, Pending Install, Pending
Update, or Installing status.
|
| macOS |
-
- Portal service
- Enable .
- The device is enrolled and the App Catalog (you can change the default name with the MaaS360 branding feature) app is installed.
|
The App Catalog status for the device is enabled at
. |
>>Back to the list of
MaaS360 billed services
Table 4. Application
Security
| Platform |
How is the service enabled? |
How is the usage tracked? |
| iOS |
-
- Portal service
- Enable .
-
- Policy setting
- Add an enterprise iOS app to the App Catalog, enable the Apply WorkPlace
Policy option from the Wrapping and Signing tab, and then
distribute the app to devices. For more information, see Adding an enterprise app for iOS and Deploying apps to devices.
|
-
- Portal service
- is enabled.
-
- Policy setting
- An enterprise app was added to the App Catalog with the Apply WorkPlace
Policy setting enabled and then distributed to the device.
|
| Android |
|
-
- Portal service
- is
enabled.
-
- Policy setting
- An enterprise app was added to the App Catalog with the Apply WorkPlace
Policy setting enabled and then distributed to the device.
|
>>Back to the list of
MaaS360 billed services
Table 5. MaaS360 Enterprise Browser
| Platform |
How is the service enabled? |
How is the usage tracked? |
| iOS |
-
- Portal service
- Enable
.
-
- Policy setting
- Enable the
MaaS360 Browser service in the WorkPlace Persona policy that is
assigned to the device at
.
- The IBM
MaaS360 Browser app is installed on the device.
OR
-
- Portal service
- Enable
.
- The IBM
MaaS360 Browser app is used at least once on the
device.
|
-
- Portal service
- is enabled.
-
- Installed service on the device
- The Installed Services category for the device at
lists MaaS360 Browser as a service that is installed on
the device.
|
| Android |
-
- Portal service
- Enable
.
-
- Policy setting
- Enable the
MaaS360 Browser service in the WorkPlace Persona policy that is
assigned to the device at
.
- The IBM
MaaS360 Browser app is installed on the device.
OR
-
- Portal service
- Enable .
- The IBM
MaaS360 Browser app is used at least once on the
device.
|
-
- Portal service
- is enabled.
-
- Installed service on the device
- The Installed Services category for the device at
lists MaaS360 Browser as a service that is installed on
the device.
|
>>Back to the list of
MaaS360 billed services
Table 6. MaaS360 Enterprise Mail
| Platform |
How is the service enabled? |
How is the usage tracked? |
| iOS |
-
- Portal service
- Enable
.
-
- Policy setting
- Enable the MaaS360
Mail service in the WorkPlace Persona policy that is assigned to the device at
.
OR
- Policy setting
- Configure MaaS360
Mail in the WorkPlace settings in the iOS MDM Policy that is assigned to the device at
.
Note: WorkPlace settings in the iOS MDM policy are only available when the Use WorkPlace
Settings in MDM Policies customer property is enabled by the administrator.
|
-
- Portal service
- is enabled.
-
- Installed service on the device
- The Installed Services category for the device at
lists MaaS360
Mail as a
service that is installed on the device.
|
| Android |
-
- Portal service
- Enable
.
-
- Policy setting
- Enable the MaaS360
Mail service in the WorkPlace Persona policy that is assigned to the device at
.
Note: WorkPlace settings are not available in the Android MDM policy.
|
-
- Portal service
- is enabled.
-
- Installed service on the device
- The Installed Services category for the device at
lists MaaS360
Mail as a
service that is installed on the device.
|
>>Back to the list of
MaaS360 billed services
Table 7. Gateway for
Apps
| Platform |
How is the service enabled? |
How is the usage tracked? |
| iOS |
-
- Portal service
- Enable the following.
-
- Policy setting
- Enable the Workplace App Container service in the WorkPlace Persona policy that is assigned to
the device at
.
-
- Policy setting
- Enable the Enable MaaS360 Gateway For Workplace Apps option in the
WorkPlace Persona policy that is assigned to the device at
.
|
- Installed service on the device
- The Installed Services category for the device at
lists Workplace SDK MaaS360 Enterprise Gateway as a
service that is installed on the device.
|
| Android |
-
- Portal service
- Enable the following.
-
- Policy setting
- Enable the Workplace App Container service in the WorkPlace Persona policy that is assigned to
the device at
.
-
- Policy setting
- Enable the Enable MaaS360 Gateway For Workplace Apps option in the
WorkPlace Persona policy that is assigned to the device at
.
|
- Installed service on the device
- The Installed Services category for the device at
lists Mobile Enterprise Gateway for Enterprise Apps as a service that is installed on the
device.
|
>>Back to the list of
MaaS360 billed services
Table 8. Gateway for
Browser
| Platform |
How is the service enabled? |
How is the usage tracked? |
| iOS |
- Upload Browser MaaS360 Enterprise Gateway from the MaaS360 app.
-
- Portal service
- Enable the following.
-
- Policy setting
- Enable the
MaaS360 Browser service in the WorkPlace Persona policy that is
assigned to the device at
and
enable the Enable MaaS360 Gateway for Intranet Access option in the WorkPlace
Persona policy that is assigned to the device at
.
- The MaaS360 Browser app is installed on the
device.
- Upload MaaS360 Browser
Gateway from the
MaaS360 Browser.
-
- Portal service
- Enable .
- The MaaS360 Browser app is used at least once by the
device.
|
- Installed service on the device
- The Installed Services category for the device at
lists MaaS360 Browser
Gateway or MaaS360 Browser or
MaaS360 Enterprise Gateway as services that are installed on the device.
|
| Android |
- Upload Mobile Enterprise Gateway for Intranet Access from the MaaS360 app.
-
- Portal service
- Enable the following.
-
- Policy setting
- Enable the
MaaS360 Browser service in the WorkPlace Persona policy that is
assigned to the device at
and
enable the Enable MaaS360 Gateway for Intranet Access option in the WorkPlace
Persona policy that is assigned to the device at
.
- Upload MaaS360 Browser
Gateway from the
MaaS360 Browser.
-
- Portal service
- Enable .
- The IBM
MaaS360 Browser app is used at least once by the device.
|
- Installed service on the device
- The Installed Services category for the device at
lists MaaS360 Browser
Gateway or MaaS360 Browser or MaaS360 Enterprise Gateway as services that are installed on the device.
|
>>Back to the list of
MaaS360 billed services
Table 9. Gateway for
Documents
| Platform |
How is the service enabled? |
How is the usage tracked? |
| iOS |
-
- Portal service
- Enable the following.
- At least one of the following Content Sources that enables intranet content is available on the device.
- IBM Connections
- Microsoft SharePoint
- Windows File Share
- CMIS Sources ()
|
- Installed service on the device
- The Installed Services category for the device at
lists one of the following services as installed on the device.
- CMIS MaaS360 Enterprise Gateway
Note: At least one MEG
CMIS Share must be distributed and available on the device.
- SharePoint MaaS360 Enterprise Gateway
Note: At least
one MEG Sharepoint Share must be distributed and available on the device.
- Windows File Share MaaS360 Enterprise Gateway
Note: At least one MEG WFS Share must be distributed and available
on the device.
- IBM Connections MaaS360 Enterprise Gateway
Note: At least one MEG IBM
Connection Share must be distributed and available on the device.
|
| Android |
-
- Portal service
- Enable the following.
- At least one of the following Content Sources that enables intranet content is available on the device.
- IBM Connections
- Microsoft SharePoint
- Windows File Share
- CMIS Sources ()
|
- Installed service on the device
- The Installed Services category for the device at
lists one of the following services as installed on the device.
- CMIS MaaS360 Enterprise Gateway
Note: At least one MEG
CMIS Share must be distributed and available on the device.
- SharePoint MaaS360 Enterprise Gateway
Note: At least
one MEG ISP Share must be distributed and available on the device.
- Windows File Share MaaS360 Enterprise Gateway
Note: At least one MEG WFS Share must be distributed and available
on the device.
- IBM Connections MaaS360 Enterprise Gateway
Note: At least one MEG IBM
Connection Share must be distributed and available on the device.
|
>>Back to the list of
MaaS360 billed services
Table 10. Content Management
(Non-MEG Sources)
| Platform |
How is the service enabled? |
How is the usage tracked? |
| iOS |
-
- Portal service
- Enable .
- At least one of the following Content Library documents or folders, or one of the following
Content Sources (that is not configured from the MaaS360
Gateway) is available on the device.
- IBM Connections Files
- Microsoft SharePoint
- Microsoft OneDrive
- Box
- Google Drive
- Other Sources
|
- Installed service on the device
- The Installed Services category for the device at
lists one of the following services as installed on the device.
- Corporate Docs
Note: At least one document or folder must be distributed and available in Corp
Docs on the device.
- CMIS Resources
Note: At least one CMIS Share must be distributed and available on the
device.
- Corporate SharePoint Access
Note: At least one sharepoint site must be distributed and available
on the device.
- IBM Connections
Note: At least one IBM Connection Share is distributed and available on the device.
- Public Cloud integration for Docs
Note: At least one Box, GoogleDrive, OneDrive share must be
shared and available on the device.
Note: Content sources that use the Rover Gateway also mark the device as using the following services.
- Mobile Enterprise Gateway for IBM Connections
- Mobile Enterprise Gateway for Internal SharePoint
- Mobile Enterprise Gateway for Other Protocols
|
| Android |
-
- Portal service
- Enable .
- At least one of the following Content Library documents or folders, or one of the following
Content Sources (that is not configured from the MaaS360
Gateway) is available on the device.
- IBM Connections Files
- Microsoft SharePoint
- Microsoft OneDrive
- Box
- Google Drive
- Other Sources
|
- Installed service on the device
- The Installed Services category for the device at
lists one of the following services as installed on the device.
- Corporate Docs
Note: At least one document or folder must be distributed and available in Corp
Docs on the device.
- CMIS Resources
Note: At least one CMIS Share must be distributed and available on the
device.
- Corporate SharePoint Access
Note: At least one sharepoint site must be distributed and available
on the device.
- IBM Connections
Note: At least one IBM Connection Share must be distributed and available on the device.
- Public Cloud integration for Docs
Note: At least one Box, GoogleDrive, OneDrive share must be
shared and available on the device.
Note: Content sources that use the Rover Gateway also mark the device as using the following services.
- Mobile Enterprise Gateway for IBM Connections
- Mobile Enterprise Gateway for Internal SharePoint
- Mobile Enterprise Gateway for Other Protocols
|
>>Back to the list of
MaaS360 billed services
Table 11. Mobile Document
Editor
| Platform |
How is the service enabled? |
How is the usage tracked? |
| iOS |
-
- Portal service
- Enable .
-
- Policy setting
- Enable the Docs Editor service in the WorkPlace Persona policy that is assigned to the device at
.
- The IBM
MaaS360 Editor app
is installed on the device.
|
- Installed service on the device
- The Installed Services category for the device at
lists IBM
MaaS360 Editor as a
service that is installed on the device.
|
| Android |
-
- Portal service
- Enable .
-
- Policy setting
- Enable the Docs Editor service in the WorkPlace Persona policy that is assigned to the device at
.
- The IBM
MaaS360 Editor app
is installed on the device.
|
- Installed service on the device
- The Installed Services category for the device at
lists IBM
MaaS360 Editor as a
service that is installed on the device.
|
>>Back to the list of
MaaS360 billed services
Table 12. Mobile Document
Sync
| Platform |
How is the service enabled? |
How is the usage tracked? |
| iOS |
-
- Portal service
- Enable .
-
- Policy setting
- Enable the Docs Sync service in the WorkPlace Persona policy that is assigned to the device at
.
|
- Installed service on the device
- The Installed Services category for the device at
lists User Sync for Docs as a service that is installed on the device.
|
| Android |
-
- Portal service
- Enable .
-
- Policy setting
- Enable the Docs Sync service in the WorkPlace Persona policy that is assigned to the device at
.
|
- Installed service on the device
- The Installed Services category for the device at
lists User Sync for Docs as a service that is installed on the device.
|
>>Back to the list of
MaaS360 billed services
Table 13. Threat
Management
| Platform |
How is the service enabled? |
How is the usage tracked? |
| iOS |
- Trusteer® Malware as an installed service
-
- Portal service
- Enable
.
-
- Policy setting
- Enable the Restrict Devices with Malware option in the WorkPlace Persona
policy that is assigned to the device at
.
OR
- Policy setting
- Enable the Enable Trusteer Threat Management option in the iOS MDM
policy that is assigned to the device at
.
- Trusteer as an installed service.
-
- Portal service
- The Enable Trusteer customer property is enabled by the primary
administrator.
-
- Policy setting
- Enable Restrict Jailbroken/Rooted Devices in the WorkPlace Persona policy
that is assigned to a device at
, or,
in the WorkPlace Settings section in the iOS MDM policy that is assigned to the device at
.
Note: WorkPlace settings in the iOS MDM policy are only available when the Use WorkPlace
Settings in MDM Policies customer property is enabled by the primary
administrator.
- Endpoint Security as an installed service.
-
- Portal service
- Enable
.
-
- Policy setting
- Endpoint Security policy must be configured and pushed to the
device.
|
-
- Portal service
- is enabled or the
Enable Trusteer customer property is enabled by the primary
administrator.
-
- Installed service on the device
- The Installed Services category for the device at
lists Trusteer Malware or Endpoint Security as installed
services.
|
| Android |
- Trusteer Malware as an installed service.
-
- Portal service
- Enable
.
-
- Policy setting
- Enable the Restrict Devices with Malware option in the WorkPlace Persona
policy that is assigned to the device at
.
OR
- Policy setting
- Enable the Enable Trusteer Threat Management option in the Android MDM
policy that is assigned to the device at
.
- Trusteer as an installed service.
-
- Portal service
- The Enable Trusteer customer property is enabled by the primary
administrator.
-
- Policy setting
- Enable Restrict Jailbroken/Rooted Devices in the WorkPlace Persona policy
that is assigned to a device at
, or,
in the Security section of the Android MDM Policy that is assigned to the device at
.
Note: For Android Enterprise devices, use Android Enterprise Settings. For
other MDM devices, use Device Settings.
- Endpoint Security as an installed service.
-
- Portal service
- Enable
.
-
- Policy setting
- Endpoint Security policy must be configured and pushed to the
device.
|
-
- Portal service
- is
enabled or the Enable Trusteer customer property is enabled by the primary
administrator.
-
- Installed service on the device
- The Installed Services category for the device at
lists Trusteer Malware or Endpoint Security as installed
services.
|
>>Back to the list of
MaaS360 billed services
Table 14. Mobile Threat Defense
- Advanced service
| Platform |
How is the service enabled? |
How is the usage tracked? |
| iOS or Android |
-
- Portal service
- Enable
.
-
- Policy setting
- Enable Mobile threat defense option in the Endpoint Security policy that
is assigned to the group at
.
-
- Group setting
- Distribute the Endpoint Security policy to device group.
|
-
- Portal service
- is
enabled.
-
- Installed service on the activated device
- The Installed Services category for the device at
lists as installed
services.
-
- For enrolled device
- MaaS360 MTD app must be
installed on the device.
|
>>Back to the list of
MaaS360 billed services
Table 15. Mobile Threat Defense
- Professional service
| Platform |
How is the service enabled? |
How is the usage tracked? |
| iOS or Android |
-
- Portal service
- Enable
.
-
- App setting
- Setup the required app configuration in IBM
MaaS360 app by using the MaaS360 MTD Portal.
-
- Group setting
- Distribute the MaaS360 MTD app to device group.
|
-
- Portal service
- is
enabled.
-
- For enrolled device
- MaaS360 MTD app must be
installed on the device.
|
>>Back to the list of
MaaS360 billed services
Table 16. Risk based
application patching
| Platform |
How is the service enabled? |
How is the usage tracked? |
| macOS |
- Portal service
- Enable .
|
-
- Portal service
- is enabled.
- The device is managed by the macOS MDM agent.
- The managed status of the device is Enrolled.
|
| Windows |
- Portal service
- Enable .
|
-
- Portal service
- is enabled.
- The device is managed by the Microsoft MDM
agent.
- The managed status of the device is Enrolled.
|
>>Back to the list of MaaS360 billed services
Table 17. Identity Management
| Platform |
How is the service enabled? |
How is the usage tracked? |
| iOS |
-
- Portal service
- Enable
.
-
- Policy setting
- Enable the Enable Single Sign-On Conditional Access option in the iOS MDM
policy that is assigned to the device at
.
|
-
- Portal service
- is enabled.
-
- Policy setting
- The Enable Single Sign-On Conditional Access option is enabled in the iOS
MDM policy that is assigned to the device at
.
|
| Android |
-
- Portal service
- Enable
.
-
- Policy setting
- Enable the Enable Single Sign-On Conditional Access option in the Android
MDM policy that is assigned to the device at
.
|
-
- Portal service
- is enabled.
-
- Installed service on the device
- The Installed Services category for the device at
lists Identity and Access Management as a service that is installed on the device.
|
| Windows |
-
- Portal service
- Enable
.
-
- Policy setting
- Enable the Enable Single Sign-On Conditional Access option in the Windows MDM policy that is assigned to the device at
.
|
-
- Portal service
- is enabled.
-
- Installed service on the device
- The Installed Services category for the device at
lists Identity and Access Management as a service that is installed on the device.
|
>>Back to the list of
MaaS360 billed services
Table 18. OS VPN
| Platform |
How is the service enabled? |
How is the usage tracked? |
| iOS |
-
- Portal service
- Enable
.
-
- Policy setting
- Configure the MaaS360 VPN service in the iOS MDM
policy that is assigned to the device at
.
|
-
- Portal service
- is enabled.
-
- Policy setting
- MaaS360 VPN is configured in the iOS MDM policy that
is assigned to the device at
.
|
| Android |
-
- Portal service
- Enable
.
-
- Policy setting
- Configure the MaaS360 VPN service in the Android MDM
policy that is assigned to the device at
.
- The MaaS360 VPN app is installed on the device.
|
-
- Portal service
- is enabled.
-
- Installed service on the device
- The Installed Services category for the device at
lists MaaS360 VPN as a service that is installed on the
device.
|
>>Back to the list of
MaaS360 billed services
Table 19. Mobile Expense
Management
| Platform |
How is the service enabled? |
How is the usage tracked? |
| iOS |
|
-
- Portal service
- is enabled.
- The device is associated with a Mobile Expense Management (MEM) plan on the backend.
Note: This usage tracking applies to managed devices only, not activated devices.
|
| Android |
|
-
- Portal service
- is enabled.
- The device is associated with a Mobile Expense Management (MEM) plan on the backend.
Note: This usage tracking applies to managed devices only, not activated devices.
|
>>Back to the list of MaaS360 billed services