Skip to content

System Requirements

INFO

Swisscom beem supports all major web browsers and end-user devices. However, not all features and use cases are available or fully supported across every platform, browser, or device. Detailed compatibility information for specific use cases is listed in the relevant sections below.

My Swisscom Business

My Swisscom Business is the online self-service portal designed for business customers to manage their Swisscom Business Account. It provides:

  • 24/7 access to service and account information
  • Tools for user and permission management
  • Options to view and modify products, subscriptions, and invoices
  • Real-time notifications about service updates or maintenance
  • Access to support resources, including FAQs and documentation

This portal acts as the central interface for administrators and authorized users to configure and monitor their Swisscom services, including beem services.


TIP

When accessing My Swisscom Business, make sure to use the My Swisscom Business account (e.g. prename.surname@company.beem.swiss) that was created with your purchase of beem. Any other Swisscom account that you may have used in the past or are using for other Swisscom services will not grant you the permission to manage anything beem related.

Swisscom Business Accounts

A Swisscom Business Account represents your company’s official contractual relationship with Swisscom. It includes:

  • The company’s customer profile
  • All active subscriptions and services (e.g., internet, mobile, IT solutions)
  • Billing and invoicing information
  • Eligibility to access Swisscom’s business platforms and tools

This account forms the foundation for managing your organization’s services with Swisscom.

INFO

Swisscom Business Accounts are primarily intended for registered businesses, including start-ups, SMEs, and large enterprises. However, private individuals (e.g., freelancers or self-employed persons) can register for business services if they meet the criteria or use the services in a business-like context.

Add a Swisscom Business Account User

INFO

Only administrators can add new Swisscom Business Account users.

To add a new user:

  • Open beem Hub and, in the top-right corner, select your company.
  • Go to Company profile.
  • In the left-hand navigation, open the Users tab.
  • Select Add userSwisscom Business Account.
  • Enter the user’s information and confirm with Add user.

The user receives an email containing their username and a login link.

WARNING

The user must activate their account within 24 hours; otherwise, it expires.

beem App – Supported Client Operating Systems

The beem app is a native VPN client built for seamless compatibility with Android, iOS, macOS, and Windows operating systems.

To ensure reliable performance across devices, the app supports the following operating system versions:

Client Operating SystemVersion
Windows 11All versions ¹
macOSmacOS 15 and later
iOS/iPadOSiOS/iPad OS 15.5 and later
AndroidAndroid 13 and later²

WARNING

¹ Windows 10 is not supported, as Microsoft will discontinue official support for it in October 2025.
² Please note that the beem app has currently been tested exclusively on Samsung smartphones and tablets with One UI. Compatibility with devices from other manufacturers or Android variants is not yet confirmed, but support may be extended in the future. Even on Samsung devices, as well as on other Android models, the user experience may be limited depending on the specific configuration.

Server Operating System

The platform is fully operating system-independent and compatible with all major operating systems. beem functions reliably across environments without relying on any specific OS architecture.

Supported Browsers per Operating System

The following table provides an overview of the operating systems and browsers supported by beem:

Client Operating SystemBrowserVersionSupported
Windows 11Chrome136.0.7103.92
Windows 11Edge135.0.3179.98
macOS 15+Chrome136.0.7103.93
macOS 15+Edge135.0.3179.54
macOS 15+Safari18.4
iOS/iPadOS 15.5+Chrome131.0.6778.73
iOS/iPadOS 15.5+Edge135.3179.98
iOS/iPadOS 15.5+Safari18.4
Android 13+Chrome136.0.7103.87
Android 13+Edge135.0.3179.85

WARNING

Although older versions may still function, they are not officially supported. We strongly recommend keeping your browser up to date to ensure optimal performance and security.

Passkeys

Passkeys offer a modern alternative to conventional passwords. By using biometrics, asymmetric encryption and strong cryptographic techniques, they provide exceptional security while delivering an intuitive and streamlined user experience. Passkeys work according to the principle of asymmetric encryption. When registering for beem passkey access, two mathematically linked keys are generated:

  • A private key, which is securely stored on your device.
  • A service key, which is registered with beem.

When you want to sign in with your passkey, beem sends a challenge to your device. Your device signs it with the private key (after confirmation via Face ID, Touch ID, Windows Hello, or PIN) and beem verifies the signature using the service key. Neither the private key nor any biometric data leave your device during authentication–these are locked on your device's Trusted Platform Module.

The principle of asymmetric encryption eliminates the common risks associated with passwords since there are none to transmit. This prevents credential theft through phishing, replay attacks, database breaches and other threats. By combining passkeys with device-based authentication, beem establishes a multi-layered security model.

Passkey Authentication Methods

There are different ways in which passkeys can be used to sign in, depending on your setup, infrastructure and organisational policy:

Using a Passkey Stored on a DeviceUsing a Passkey Stored on a Security KeyUsing a Passkey via a QR Code (Bluetooth)Using a Passkey Stored in a Cloud

System Requirements Example

The above mentioned methods for storing and using passkeys.

Passkey registration

Passkeys are issued by your company's beemNet administrator and are linked to user's respective Swisscom Business Accounts. When an administrator creates a Swisscom Business Account for a user, this user will receive a confirmation e-mail containing a username and a setup link, which starts the passkey creation assistant.

After the initial setup, additional passkeys can be created on other devices. It's recommended to register at least two passkeys to prevent a lockout.

Create a Passkey on an Apple deviceCreate a Passkey on a Samsung device

Passkey recovery

After every successful passkey setup, a set of device specific recovery codes is generated and can be downloaded as a PDF. User should hold on to these codes, as they might need them to recover access to their account.

Alternatively, administrators can revoke and issue new passkeys for users in the My Swisscom Business portal:

  • Open the company tab in the top right corner (company name) and click on Company Profile .
  • Click on Users and select the respective user.
  • In the user overview, click on Login & Security and Remove passkeys and resend activation .

Passkey Compatibility Chart

This table shows the passkey compatibility between client operating systems and web browsers:

BrowseriOS/iPadOS 16+ (2022)macOS 15+ (2024)Android 13+Windows 11¹
Chrome
Safari
Edge

¹ Authentication and passkey management features were added in Windows 11 23H2.

beemNet Access

beemNet supports all major operating systems and enables secure access to the Swisscom network from both internal and external environments.

Access Requirements:
To use beemNet, customers must have:

  • A valid beem user licence, and
  • The appropriate Swisscom network access service, depending on their connectivity setup.

Supported Swisscom Access Types:

  • Enterprise Connect
  • IP-Plus
  • Smart Business Connect
  • Wireline Access

When connecting from outside the Swisscom network (e.g., home office, public Wi-Fi), users must use the beem app to establish a secure connection to the beemNet environment.

User Licence TypeMax. Number of DevicesMobile Voice & DataNo RestrictionConcurrent vs. Named
Protect & Connect6👤
Protect3👤
Collaborate1 (5)👥👥

Wireline

To convert a standard internet connection into a beemNet connection, one of the following Swisscom access products is required:

  • inOne KMU office or beem Office
  • Smart Business Connect
  • Enterprise Connect
  • IP-Plus®

If none of these access types are available, users can still connect to beemNet via the beem app, which enables secure access over third-party internet connections.

Once connected, the local area network (LAN) behind the internet connection is automatically integrated into the beemNet environment, allowing all devices within the LAN to securely communicate over the Swisscom network.

WARNING

beemNet currently does not support IPv6. Enabling IPv6 may cause connectivity issues and impact service stability.
Recommended actions to ensure optimal performance:

  • If you want to protect your Wireline Location with beem, do not enable IPv6.
  • If IPv6 is already enabled and required in your setup, please disable the "Protect" option to minimize the risk of disruptions.

We are actively working to resolve this limitation. Until official IPv6 support is available, please follow this guidance to ensure stable service.

User licence and client devices

ServiceDescription
ProtectStandard protection layer for secure access.
Collaborate(Coming soon)
NATEL® go with beemNet optionMobile subscription with optional beemNet integration for secure mobile access.

Access via Internet browser

Access to beem-protected resources via a standard internet browser does not necessarily require a user licence. If beem is used to secure services such as web servers or E-Connect servers, it is possible to allow access for unauthenticated or anonymous internet users. In such cases, users can interact with the protected service through the beem network without needing to be explicitly licensed.

Access for IoT devices

Customers with a contract for IoT devices with Swisscom can integrate them into the beem network.

Fail-Close

“Always On” with “Fail-close” is supported on Windows, macOS, and Android. iOS and iPadOS do not support “fail-close” unless device management is implemented by adopting supervised mode.

Single Sign-On

This section provides an overview of public and private Single Sign-On (SSO) support within the beem ecosystem. Currently, four SSO integration variants are available or planned:

SSO VariantDescription
Swisscom ServicesIncludes My Swisscom Business, beem, and other internal Swisscom services
Swisscom Workspace ServicesInternal Workspace, Enterprise Workspace and IT KMU Solution (Coming soon)
Customer’s Private ApplicationsSSO integration for customer-hosted apps (Coming soon)
Customer’s SaaS ApplicationsSupports third-party platforms such as salesforce and workday

Single Sign-On Use Cases

Figure: The image illustrates the SSO integration landscape across these variants.

Federation

beem supports identity federation for seamless integration with enterprise identity providers. Currently, the following federation standards are supported:

  • Microsoft Entra ID (formerly Azure Active Directory)
  • Active Directory Federation Services (ADFS)

This allows organizations to leverage their existing identity infrastructure for secure and centralized authentication across beem-enabled services.

INFO

For detailed configuration guidance or support for additional identity providers, please contact us directly.

Device Management System Requirements

This section outlines the prerequisites and supported configurations for managing devices with beem.

WARNING

Not all versions of client operating systems are supported.

Supported Operating Systems for Device Management

PlatformSupported VersionsRequirements
iOS / iPadOSiOS 16.x – iOS 18.3.1Apple Business Manager account required for enrollment and management
macOSmacOS 15 and aboveApple Business Manager account required for enrollment and management
AndroidAndroid 15 and aboveRequires enrollment via Google Enterprise account for policy enforcement
WindowsWindows 11 Pro
Windows 11 Enterprise (21H2, 22H2, 23H2, 24H2)
No account required for device management

WARNING

To ensure security and compatibility, only selected Android hardware is supported. Generic or uncertified devices are not considered secure.

Non-Compatible Configurations

The following configurations are not supported with beem:

  • Consumer and corporate VPN solutions
  • Cascading firewalls
  • Third-party solutions that interfere with secure device posture or network routing (category-based exclusions)
  • IPv6 connectivity*
  • iCloud Private Relay
  • QUIC

WARNING

*IPv6 connectivity must be disabled before activating beem net. If IPv6 cannot be disabled via device or service configuration, Swisscom Support must be contacted.

iCloud Private Relay

iCloud Private Relay (also known as Apple Private Relay) is a privacy feature included in iCloud+. Private Relay works mainly with the Safari browser and selected apps on iPhone, iPad, and Mac. Unlike a VPN or a security solution that is directly integrated into the network (such as beem), Private Relay does not cover all device traffic.

How it works: When Private Relay is enabled, your requests are routed through two secure internet relays.

  • The first relay (operated by Apple) sees your IP address but not the destination website. DNS queries are encrypted
  • The second relay (operated by a third party) assigns a temporary IP address, decrypts the domain name, and connects you to the site.

This process protects user identity without significantly impacting browsing speed.

Drawbacks of Private Relay with beem

beem is a security solution for corporate networks. It provides advanced features such as Application Control, Intrusion Prevention, Deep Packet Inspection, and Geo-IP blocking to detect threats and control traffic.

Private Relay interferes with these functions in several ways:

  • Bypassing firewall rules: Since traffic is routed through Apple relays, beem cannot fully inspect it. The firewall often classifies the traffic as Proxy Avoidance and blocks it, leading to issues with websites or apps (e.g., Apple News).
  • DNS and traffic classification issues: Private Relay traffic is frequently flagged as a potential proxy or threat, which can result in dropped DNS queries or blocked connections.
  • Performance impact: The extra relays and encryption add latency. Combined with beem, this can cause noticeably slower browsing.
  • Security blind spots: In corporate environments, visibility is critical. Private Relay obscures traffic, complicating logging and auditing. This creates blind spots where malware or unauthorized access may go undetected.

Why beem & iCloud Private Relay are not compatible

In corporate environments, however, this conflicts with the visibility and control required by beem. To ensure full functionality and compliance with enterprise policies, beem actively blocks requests to Apple’s domains used by iCloud Private Relay. As a result, your Apple device may display a message indicating that iCloud Private Relay is unavailable. This behavior is intentional and technically necessary for beem to deliver its full range of capabilities. You can safely ignore this notification.

Best Practices for Apple Devices in beem-Protected Networks

To ensure smooth operation and full compatibility with beem, please follow these best practices when using Apple devices:

  • Private Relay is not available within beemNet: Connections to iCloud Private Relay cannot be established inside beem-protected networks.
  • Disable Private Relay in device settings: Users with active Private Relay must manually disable it to avoid connectivity issues.
  • Disable per connection: Private Relay can be turned off either globally or per connection (e.g., per SIM or Wi-Fi SSID). We recommend disabling it per connection to maintain flexibility.
  • Avoid connection problems: If Private Relay remains active, it may cause temporary deactivation or blocked access to certain apps and services.
  • Guest Wi-Fi limitations: Private Relay is also unavailable in guest Wi-Fi networks protected by beem. Apple devices may display a message indicating that Private Relay is not available for the current connection and must be disabled.
How to Disable iCloud Private Relay for a Specific SIM Connection

To ensure compatibility with beem, you can disable Private Relay for individual mobile connections (e.g., SIM cards) by following these steps:

  • Open Settings on your device.
  • Tap on Mobile Service.
  • Select the SIM card or mobile plan you want to configure.
  • Deactivate the option Limit IP Address Tracking.

This disables iCloud Private Relay for that specific connection, helping avoid compatibility issues with beem while maintaining flexibility for other networks.

QUIC

QUIC is a transport protocol that combines the functionality of TCP, TLS, and HTTP/2. It is encrypted, connection-oriented, operates on top of UDP and serves as the foundation for HTTP/3. While QUIC brings improvements in speed and privacy, it poses a challenge for existing security solutions. Many security features rely on reading connection details that are visible with TCP. QUIC encrypts this information, including the connection metadata, making it inaccessible to security systems. As a result, deep packet inspection (DPI), malware scanning, and data loss prevention (DLP) rules cannot be applied to QUIC traffic. This is an industry-wide challenge, and blocking QUIC traffic is the recommended approach.

beem follows this best practice. QUIC traffic is blocked in the beemNet and connections automatically fall back to TCP-based protocols, which beem can fully inspect and protect. This ensures that all security features (including malware scanning and DLP) remain fully effective. Since QUIC is enabled by default in most browsers, a QUIC connection may still be attempted before falling back to TCP, which can cause slight delays or affect the functionality of certain online services. To avoid this, it is recommended to deactivate QUIC directly in your web browser. This ensures that connections are established via TCP from the start, providing both full security and the best possible user experience.

Use the guides below to deactivate the QUIC protocol in your web browser:


INFO

Currently, you cannot disable QUIC in Safari (macOS, iPhone, iPad).

Supported IaaS Solutions

Applicable only for API Data Protection CASB

The following Infrastructure as a Service (IaaS) platforms are supported:

  • Microsoft Azure
  • Google Cloud Platform (GCP)
  • Amazon Web Services (AWS)
  • Oracle Cloud Infrastructure (OCI)

Supported SaaS Solutions

beem supports a wide range of SaaS (Software as a Service) applications through multiple integration methods to ensure visibility, control, and data protection. The platform can detect and manage over 8'000 SaaS applications via Shadow IT discovery.

Single Sign-On (SSO) support is also planned and will be available soon.

The table below lists currently supported SaaS applications and indicates their compatibility with the following enforcement methods: inline CASB via forward proxy, inline CASB via reverse proxy, and API-based data protection CASB.

Inline CASB via Forward ProxyInline CASB via Reversed ProxyAPI-based Data Protection CASB
4shared
Amazon AWS
AOL
Bitbucket
Blogger
Box
Cisco Webex Teams
Citrix ShareFile
Confluence
Craigslist
Dailymotion
Daum Mail
DocuSign
Dropbox
eBay
Egnyte
Evernote
Excel Online
Facebook
Facebook Messenger
Facebook Workplace
Flickr
GitHub
GitLab
Google
Google Accounts
Google Docs
Google Drive
Google Gmail
Google Photos
Google Talk
imo
Instagram
Jira
Join.Me
LastPass
Line
LinkedIn
Mail.ru
Microsoft OneDrive
Microsoft OneNote
Microsoft Outlook
Microsoft SharePoint
Microsoft Teams
Microsoft Yammer
Naver Mail
Netflix
Notion
Office 365
Okta
OneDrive
OneLogin
PayPal
Pinterest
PowerPoint Online
ProtonMail
Reddit
Salesforce
ServiceNow
ShareFile.com
SharePoint Online
Shopify
Skype
Slack
SlideShare
SoundCloud
SourceForge
Spotify
Stack Overflow
Tango
Telegram
Trello
Twitch
Twitter
Viber
Vimeo
VMware
Webex
WeChat
WeTransfer
WhatsApp
Word Online
WordPress
Workplace from Meta
Xero
Yammer
Yandex
Yandex Mail
YouTube
Zalo
Zendesk
Zoom