Workspace ONE Mobile Threat Defense

Workspace ONE Mobile Threat Defense provides endpoint security and protection for iOS, Android, and Chrome OS, securing devices against app, device, OS, and network-based threats. Integrating Mobile Threat Defense with Workspace ONE UEM empowers your organization to adopt secure mobility without compromising productivity. It allows the integration of mobile security threat and device events into your security incident and event workflows. Additionally, Mobile Threat Defense allows you to streamline the management of devices and drive enforcement when threats are detected.


  • Workspace ONE Mobile Threat Defense.
  • A currently supported version (non EOL) of Workspace ONE UEM, shared SaaS, Managed Hosting, or on-premises.
  • Administrator access to the Workspace ONE UEM console.
  • Workspace ONE Intelligent Hub 23.05 or later installed on devices intended for protection.
  • Workspace ONE Tunnel 23.01.1 or later (for Phishing and Content Protection)

The Workspace ONE Intelligent Hub mobile application is the device-side agent, detecting threats on mobile devices and reporting the information to the end user and also to the console. Workspace ONE Intelligent Hub is available for iOS from the App Store and for Android from the Google Play Store. Enter into the browser window of any device and you can download the correct Workspace ONE Intelligent Hub installer for that device.

Network Requirements

Devices protected with Workspace ONE Mobile Threat Defense must be able to communicate with Lookout Services. Add the following IP addresses to your firewall when devices are running on a closed or restricted network.


  • Secure DNS (https 443)
  • MiTM Reference Endpoint (https 443)
  • IP Addresses for Lookout Services

MTD Console (443)

Supported Platforms

  • Android 11.0+
  • Apple iOS 15.0+
  • Apple iPadOS 15.0+
  • Chrome OS

Mobile Threat Defense Capabilities by Management Mode

Depending upon which mode of management you select for your environment, you can expect different capabilities and behaviors from Mobile Threat Defense.

This table displays MTD's capabilities based upon the mode of management you emply.

1 Apps and web content for Android devices in OS Partitioned management mode is supported with Workspace ONE Mobile Threat Defense Dual Enrollment which is currently in Beta and will be generally available (GA) soon.


For more information about how VMware handles information collected through our products, see the VMware Privacy Policy at

For more information about what data is collected from your end users’ devices, visit the VMware Workspace ONE Privacy Disclosure page:

For more information about how our Mobile Threat Defense service provider, Lookout, uses data from end user devices for its security research and to improve its ability to detect new threats, visit

check-circle-line exclamation-circle-line close-line
Scroll to top icon