Secure mobile access

This page contains best practices for keeping Zabbix mobile app and Zabbix bridge adapter secure.

Enable app lock

To prevent other people from opening the app on your mobile device, enable app lock in the app Settings.

Remove lost or compromised devices

If a device with Zabbix mobile app on it has been lost or compromised, remove the device in the Zabbix web interface:

  • Users > Devices (as Super admin, remove your own or other user mobile devices; requires the Manage user devices permission)
  • User settings > Devices (as any user, remove your own mobile devices; requires the Manage own devices permission)

When you remove a device, its access credentials are revoked and removed from Zabbix, after which it can no longer access Zabbix.

Restrict access to devices

As Super admin, you can restrict which users can manage mobile devices. To do this, configure the Devices permissions of their user role.

Restrict Zabbix API methods

Zabbix bridge adapter passes requests from mobile devices to Zabbix API. To restrict which API methods can be called through Zabbix bridge adapter, use its AllowedAPIMethods parameter. For example, allow only the minimal set of methods that the mobile app requires, or even fewer, if you do not want some mobile app features to be used (e.g., do not allow event.acknowledge if mobile app users should not update problems).

Protect Zabbix bridge adapter data

Zabbix bridge adapter stores its data (state file and encryption keys) in the directory specified in the DataDir parameter of Zabbix bridge adapter configuration file. Make sure that the directory has 0700 permissions, and all files stored in it have 0600 permissions.