Showing posts with label Google. Show all posts
Showing posts with label Google. Show all posts

Tuesday, October 8, 2019

The nuances of enrolling Android Devices in Workspace ONE

So Android is Android right? Well not exactly. There are technically four modes where you can utilise Android on a managed device, but one doesn't really count anymore because its been deprecated by Google.

Android has come along way in the last few years and has some very interesting and unique features. Some of these features are only available in the different modes, where those modes can only enabled on a device during enrollment.

This may be a little confusing to start with but I'll explain a bit more in the rest of this article.

Tuesday, October 1, 2019

How to build your Workspace ONE Sandbox

Workspace ONE is incredibly powerful. But with so many features and functions, its no wonder people can get lost when working out where to start on configuring it to test with your scenarios in your environment.

As part of VMware Testdrive, other than getting access to a pre-configured testing environment and walkthroughs you also get a full fledged trial environment we refer to as a Sandbox.


This has all the capabilities of Workspace ONE where you can integrate it with all services to test it in your environment with real users and real devices.

So, this is where this guide comes in. Even I struggle to explain or give a place for my customers to go for all they need to get started. I'll add to the below information over time but this will be enough to get you started with Workspace ONE as part of a pilot or proof of concept.

How to configure Workspace ONE UEM to enable Android Enterprise device management

Setting up Android Enterprise device enrollment got a lot easier about a year ago. Previously you needed to create a full blown GSuite deployment, do a heap of DNS stuff and certificates.

Now its as simple as creating a Gmail account, entering it into the Workspace ONE Console and approving some applications.

 That's not to say that the Gsuite method shouldn't be used - there are definite scenarios where this is preferred - but for testing and POC purposes (any many others) using the Gmail method is perfectly fine.

Monday, September 30, 2019

Using Google Cloud Identity Secure LDAP with Workspace ONE

Most of my posts on my blog here have been about how to integrate other Identity Solutions with Workspace ONE.  However, the thing that all of these typically had in common was that they were synchronised with an On-Premises Active Directory.

This works well, but what happens when a customer has no On-Premises AD or is trying to get away from using one?

About a year ago, Google Announced their Cloud Identity Premium product which included a preview of LDAP connectivity. I played around with it then and it was good but for our purposes I could never get it to work - it requires the client service to use certificates to authenticate which is something that Workspace ONE doesn't support.

Recently a few customers have been asking whether there was ways to use Google Directories within Workspace ONE other than Just-In-Time provisioning and seeing that Secure LDAP from Google was now Generally Available globally it thought I'd give it another look.

Turns out I was able to get it to work! Read on to work out how, with some help from my colleagues, I was able to get it all integrated.

Wednesday, November 14, 2018

Using JIT to Provision User Accounts into Workspace ONE UEM


A few days ago I mentioned in an article with the shocking news that not everyone had Active
Directory for their user accounts. I talked about Just-In-Time Provisioning into Identity Manager
using Google Cloud Identity as the IDP. Now, this is great for getting user accounts into VMware Identity Manager but without an AD/LDAP directory to sync to our Enterprise Systems Connector with Workspace ONE UEM doesn't have a way to get user accounts automatically.



Well that's not technically true.

A while ago myself and a colleague had this exact scenario - a customer only used Google Cloud Directory and needed to get accounts into  Identity Manager and Workspace ONE UEM. What we discovered was that we were able to also JIT user accounts into Workspace ONE UEM during enrollment. This meant we didn't have to manually create accounts in Identity Manager or Workspace ONE UEM because we couldn't use the Enterprise Systems Connector due to not having an LDAP source.

Here's how we did it.

Tuesday, November 13, 2018

Google Cloud Directory as a 3rd Party IDP in VMware Identity Manager

Believe it or not, not everyone uses Microsoft Active Directory for their User Directory. Even more shocking is that many customers are using GSuite - not Office365 - for their Productivity Apps, Google Pixelbooks as their devices, and if they're smart Google Pixel devices for their mobile devices. Obviously all managed by VMware Workspace ONE UEM.

All jokes and shameless plugs aside, I am starting to see a few customers now who live only in the Google ecosystem and don't need or want to keep other services. They only use GSuite and as a result they don't have Active Directory to sync to Identity Manager and I'm being asked by colleagues around the region on how to use all the benefits of Workspace ONE UEM while still being able to leverage their Google investment.

Below, I am going to start off by showing you how to configure Google as a 3rd Party IDP in Identity Manager. There will a follow up article to this in the coming days which will talk about how to also use this configuration with the Workspace ONE UEM (Airwatch) components to round out the full set of capabilities.

This article will show you all the steps to add Google as a 3rd Party IDP in vIDM, add users via Just-In-Time Provisioning and sign into Identity Manager.

Lets dig in.