Applies to:
Kaspersky Endpoint Security 8 for SmartphoneKaspersky Administration Kit 8.0
Before you begin deploying Kaspersky Endpoint Security 8 for Smartphone via Kaspersky Administration Kit 8, the administrator must configure management of the mobile devices on the Administration Server.
Please perform the following actions depending on the selected Kaspersky Endpoint Security 8 for Smartphone deployment mode (from a workstation or by email):
Installing the Mobile devices support component
Configuring the connection settings
Creating groups and relocation rules for mobile devices
Installing the plug-in for managing Kaspersky Endpoint Security 8 for Smartphone
Installing the Mobile devices support component
To manage the protection of mobile devices through
Kaspersky Administration Kit, it is essential that the
Mobile devices support box is checked at the
Select Features stage in the Kaspersky Administration Kit setup wizard.


If you are using the
Administration Server version higher than
8.0.2134 Critical Fix 2 (e.g. have the
Patch D installed = version
8.0.2163), you should reinstall the
Administration Server before installing the
Mobile devices support component. You should install the
Mobile devices support component on an
Administration Server version 8
.0.2134.
When installing the component Mobile devices support, the Administration Server for mobile devices certificate is created. This is used for authentication of the mobile devices when exchanging data with the Administration Server.
The mobile devices certificate files klsrvmob.cer and klsrvmob.prk are stored in the
Cert folder within the Kaspersky Administration Kit installation folder. During the first synchronization of the mobile devices and the Administration Server, a copy of the certificate is delivered to the device and stored in a special folder.

Without the mobile devices certificate, it is not possible to establish a connection between the Administration Server and the mobile devices. It is useless to copy the klsrvmob.cer and klsrvmob.prk certificate files from one Administration server to another. If the user renames the mobile devices certificate, or deletes it from the device, during the next synchronization the Administration Server automatically sends a copy of the certificate to the device.
If, during installation of the Administration Server, the
Mobile devices support box was not checked, perform an installation “on top” of the installed Administration server and check the
Mobile devices support box.
The data exchange between the mobile devices and the Administration server goes over Internet. Therefore you should configure the address used by mobile devices to connect to the Administration Server.
Back to the beginningConfiguring the connection settings
In order to configure the connection settings for mobile devices:
- Select the Administration Server in the Administration console;
- Go to the Settings tab;
- Check the Open port for mobile devices box;
- Indicate the port through which the Administration Server should expect to connect with mobile devices. Port 13292 is used by default.

If the box is not checked, or the port is indicated incorrectly, devices will not be able to connect to the server or send and receive information.
Back to the beginningCreating groups and relocation rules for mobile devices
Instances of the application installed on mobile devices are managed by applying the group policy to these devices. For this reason, before installing the application on mobile devices, you should create an individual administration group for these devices in the Managed computers node and relocation rules according to which the mobile devices will be moved to that group.
It is necessary to define a group for mobile devices. It may be a new group.
- Right-click the Administration Server to which the mobile devices are connected in the Administration console;
- Select Properties;
- Go to the Computer relocation tab and click Add;
- Go to the General tab in the New rule window;
- Select a group to which the mobile devices will be relocated;
- Enable the option Enable rule;
- Go to the Applications tab and select Windows Mobile in the drop-down menu;
- Click OK;
- Create relocation rules for Symbian and BlackBerry in the same manner.

Android devices are relocated according to Windows Mobile rules.
Back to the beginningInstalling the plug-in for managing Kaspersky Endpoint Security 8 for Smartphone
The plug-in for managing Kaspersky Endpoint Security 8 for Smartphone is a module integrated into the Administration console. This allows managing the application settings, create policies and reports.
You can create a policy for Kaspersky Endpoint Security 8 for Smartphone only after installing a plugin for managing this application into the Administration console.
There exist plugins for the applications manageable via Kaspersky Administration Kit 8.
The plugin version corresponds to the managed application version, but they do not always match.
Run the klcfginst.exe file (included into the Kaspersky Endpoint Security 8 for Smartphone distribution package) on the host running the Administration console to install the plugin.
How to find the version of the plugin installed on the Administration console:
- Open the Administration server properties;
- Go to the General tab and click Advanced;
- Click the Information about the plug-ins installed for the application link.
Back to the beginning