The Qoria Filter (also known as the Filter for Android outside the US) provides real-time filtering and seamlessly integrates with Linewize Filter to consistently apply your policies.
Before you begin
You must have managed devices.
Your devices must meet the Qoria Filter minimum system requirements.
Step 1. Create a certificate
You must create a certificate to allow secure communication between devices and the Linewize Filter Appliance.
Sign in to Linewize Filter.
Go to Configuration > Self Service Certificates.
-
Complete the required fields:
Country (C): Select a country from the list.
State/Province (ST): Enter your state.
Locality (L): Enter your city.
Organisation (O): Enter your school’s name.
Common Name (CN): Enter your school’s domain name.
Key size (bits): Select a key size, or use the default. Larger keys provide stronger security.
Validity for (days): Enter the number of days the certificate remains valid. We recommend rotating certificates every two years.
Select Generate.
Copy the Signing Certificate and Signing Certificate Key for use in the next step.
The root certificate downloads automatically.
Step 2. Add the Qoria Filter app
In Google Workspace Admin Console, go to Apps > Web and Mobile Apps.
Select the Add app dropdown, then select Search for apps.
-
Search for Qoria Filter, then choose Select.
Tip
If you can’t see the app, search for com.qoria.fc.android.edu instead.
For User access, select All users in your organisation, then select Continue.
-
For Access method, select Force install and select these checkboxes:
Prevent users from uninstalling the app.
Use for Always on VPN.
Select Finish and wait until the webpage takes you to the App settings page.
In the Managed configurations section, select Add managed configuration. The Add managed configuration window will appear.
Enter "Qoria Filter app for Android" as the Configuration name.
-
Select Enable for each of these Enrolment Keys and enter the following:
Linewize App mode: Turn on the Chromebook App Filter for Linewize Filter.
Linewize Device Identifier: The primary device ID for the Linewize Filter Appliance.
Linewize Device Name: The device name for the Linewize Filter Appliance.
-
Linewize Region: The deployment region for your school:
United Kingdom (UK)
Sydney 1 (USA and New Zealand)
Sydney 2 (AU)
-
Linewize User Name: The username you want to authenticate to the device.
Important
Google Workspace doesn't support username variables for Android tablets and phones. Devices will have to share a username if they exist in the same OU. If devices are 1-to-1, you must set up a separate OU for each one in Google Workspace and assign the managed configuration to them.
Linewize Auth Secret: The secret key from your Linewize Filter Appliance. This value can be copied from the Linewize Filter under Configuration > Agent Downloads > Copy Preshared Key.
Signing Certificate: The SigningCertificate value from the certificate you generated in Step 1.
Signing Certificate Private Key: The SigningCertificateKey value from the certificate you generated in Step 1.
-
Configure optional keys:
Linewize Bypass Domains: Comma-separated list of domains excluded from filtering and reporting.
Linewize Device Mac: The MAC Address of your Linewize Filter Appliance.
Hardware Id: The serial number of your Android device
Select Save.
Step 3: Upload Trusted Certificate
In Google Workspace Admin Console, go to Devices > Networks.
Select which Organisational Unit you want to upload the certificate for. By default, the top-level OU (all users) is selected.
In Certificates, select Upload Certificate.
Enter a name for the Certificate, then select Upload.
Select the certificate file that was generated in step 1.
-
Under Certificate Authority, select Enabled for Android.
Note
If this setting is greyed out:
Go to Devices > Mobile and endpoints > Settings > Universal.
Select General.
Select the edit icon next to Mobile Management.
Select Custom, then select Advanced from the Android dropdown menu next to Android.
Select Save.
Select Add.
Step 4: Verify the app deployment
On your device:
Open the app and check that you see an authenticated user and your school name with a green tick.
Check that your Filtering policies apply correctly.
Check that other non-browser apps still work correctly.