Showing posts with label Workspace ONE Hub. Show all posts
Showing posts with label Workspace ONE Hub. Show all posts

Tuesday, October 8, 2019

The nuances of enrolling Android Devices in Workspace ONE

So Android is Android right? Well not exactly. There are technically four modes where you can utilise Android on a managed device, but one doesn't really count anymore because its been deprecated by Google.

Android has come along way in the last few years and has some very interesting and unique features. Some of these features are only available in the different modes, where those modes can only enabled on a device during enrollment.

This may be a little confusing to start with but I'll explain a bit more in the rest of this article.

Tuesday, October 1, 2019

Configuring Mobile SSO for iOS Devices in Workspace ONE



One of big differentiators we have with Workspace ONE is ability to use MobileSSO to drastically improve security and the user experience.

MobileSSO with Workspace ONE leverages certificates deployed to devices to seamlessly sign the user into the Workspace ONE Intelligent Hub and any federated SaaS services.

This solution requires both Workspace ONE UEM (to deploy and manage the lifecycle of the certificates) and Workspace ONE Access (to challenge the device for the certificate and authenticate the user). On iOS MobileSSO technically uses Kerberos by validating the certificate on the device and generating a Kerberos token the device can then present back for authentication.

In this post I'll discuss how to configure Workspace ONE Access for iOS MobileSSO and how to create a profile in Workspace ONE UEM to deploy the required certificate and approve the domains and applications that can use it.


How to configure Workspace ONE UEM to enable Android Enterprise device management

Setting up Android Enterprise device enrollment got a lot easier about a year ago. Previously you needed to create a full blown GSuite deployment, do a heap of DNS stuff and certificates.

Now its as simple as creating a Gmail account, entering it into the Workspace ONE Console and approving some applications.

 That's not to say that the Gsuite method shouldn't be used - there are definite scenarios where this is preferred - but for testing and POC purposes (any many others) using the Gmail method is perfectly fine.

Generating an Apple Push Notifications Certificate to enroll and manage Apple Devices

Most of the time it seems like magic that Apple devices 'just work'. However, there is one fundamental service that makes this happen - the Apple Push Notification Service. This is a set of services that Apple use (and that Apple devices leverage) to communicate with MDM, App Store, Email infrastructure etc.

The part that Mobility Administrators need to do to utilise this in Workspace ONE is generate their own Apple Push Notification Services certificate to secure traffic and communicate with Apple.

It essentially allows the entire mobility infrastructure to communicate freely in a "push" fashion rather than on-demand or schedule.

Now the important part here is that this certificate needs to be renewed every 12 months. I say important because if you don't renew it and let it expire, you have to reenroll every Apple device (manually) for them to function properly again.

Enough chit-chat, lets generate an APNs certificate and upload it to the Workspace ONE UEM Console.


Monday, September 30, 2019

Integrating Workspace ONE UEM and Workspace ONE Access

So you've got your Airwatch Cloud Connector installed and configured and you have your Identity Manager Connector installed and configured, but right now Workspace ONE UEM and Workspace ONE Access are not talking to each other.

We need to configure this integration so that we can start enrolling devices, using Workspace ONE Intelligent Hub, Unified App Catalog and Mobile SSO.

Luckily, this process is pretty straight foward. The wizard that does this integration works well and does all the heavy lifting.

Lets check out the process.

Wednesday, June 26, 2019

Replacing CRTs with iPads for Patient Entertainment Systems in Healthcare

Back in my day our TVs were big square boxes. The one my family owned had a wood look vinyl covering and I think a "remote" control that had a cable. I didn't even know how to program the VCR.

I'm not that old yet my (grey) beard suggests otherwise - but I still see oldschool TVs in hospitals. You know why? Its because Patient Entertainment Systems cost a FORTUNE when they are first implemented. And if you still do it the same way, it will cost a fortune again. They are hard to repair or replace, and the content is old and static.

This post is an extension to my post from yesterday around using GroundControl with Workspace ONE. Using iPads for a Patient Entertainment System (hereby referred to as PES) was actually the first use case that introduced me to GroundControl. There is a great case study out of the US for Pheonix Children's Hospital where they are doing exactly this.

I won't get into as much detail as my last post around how GroundControl works, but read on and you'll find out exactly why Hospitals are moving toward iPads with Workspace ONE and GroundControl.

Monday, June 24, 2019

Secure, Automated and Passwordless Mobile Clinical Device Provisioning

If you've ever been in a hospital, I'm sure you would have seen clinical staff (literally at times) running between rooms, back to nursing stations or if they're lucky into the hall to enter notes or lookup information on a WOW (Workstation on Wheels). Apart from the time it takes to get back to any of these places, they have to leave the patient bedside and remember what they need to capture in the medical records. Typically, to try and gain some time back computers are logged in as generic accounts (shudder) and there is no user personalisation or account auditing on these devices. To me, this just sounds like a recipe for disaster.

In recent years, we've seen the uptake of VDI (year of the desktop anyone?) and that brought some improvements around session portability between devices but there is no true mobility use case like a mobile tablet or phone that the clinician or doctor can take with them and complete their tasks at the bedside.

True, a device for every employee would be expensive. And they could just use their own devices to take notes or photos, but from a regulatory and compliance perspective this is really not a good idea.

This is where GroundControl and VMware Workspace ONE come in to save the day.

Imagine being a nurse, doctor or any healthcare employee for that matter. You now walk up to a pool of iOS devices, tap your RFID Employee badge onto the proximity card reader and in seconds a device is allocated to you which is completely personalised with your authentication credentials, your relevant applications and is ready to use without having to enter and passwords or further configuration. When you're done, just dock it back where you got it and it is securely erased to factory defaults ready for the next user.

Sound too good to be true?

Nope. Read to find out how and see this is action.


Tuesday, December 11, 2018

Enhancing your Zero Trust Architecture with Okta Identity Cloud and Workspace ONE

I feel like it shows the quality and strength of a vendor's solution when we can confidently stand behind what we do and are also aware enough to partner with others to provide better experiences for our joint customers. One of the best examples of this is Okta and VMware coming together to jointly work on and promote a unique partnership where we can leverage the best of both vendor's portfolio to provide the best user experience while ensuring security for your Organisation.

Outside of being how it all works and integrates (which I'll deep dive into shortly), I am often asked what the value is for customers. Okta Identity Cloud (as the name suggests) is a cloud-based Identity and Access Management solution that enables Single Sign-On the User Lifecycle to Modern Applications and Services. According to their website, they have over 5500 out-of-the-box integrations and have been consistently called out as a leader in their field.

I have been developing with and using Okta for nearly a year now as part of the VMware and Okta partnership. I've found it very powerful and easy to manage, and it seems more and more customers in my region are finding this too. With this, they are now looking to leverage the integrations between Workspace ONE and Okta Identity Cloud to take their Digital Workspace to the next level.

At the risk of taking the wind out of this post's sails, VMware has a page dedicated to this partnership but I still seem to get asked Why is there a Partnership, What is the Value, and How does it Work? So with this post I am going to answer this.

So channelling my inner Simon Sinek, lets Start With Why?

Friday, November 23, 2018

Transitioning to Workspace ONE Intelligent Hub in Workspace ONE UEM



If you missed all of our announcements around this in the last few weeks, VMware Workspace ONE Intelligent Hub is the replacement of the VMware AirWatch Agent. The first phase of the rollout is to be an in-place upgrade for iOS and Android devices that are already enrolled into Workspace ONE UEM. By default, the changeover to Intelligent Hub on iOS and Android brought a new icon and branding change and didn't require any re-enrollment of devices and functioned with the same capabilities as the Agent. We also flowed the look and feel changes through to macOS and Windows 10 device Agents too.


However, for the last 18 months or so we've had the Workspace ONE App. This App includes a heap of capabilities that the Agent didn't have. It was the entry point and enrolment method for Adaptive Management and Unified Catalog and was a a key part of our Conditional Access strategy allowing different levels access to resources based on Ownership Type, Network Location, Management Status etc.

In the Release Announcements VMware also mentioned about unifying the capabilities of the AirWatch Agent and the Workspace ONE App into a single unified Intelligent Hub. If you go back to the first paragraph you would notice I said by default it only replaced the capabilities of the Agent. At VMworld Las Vegas we showed off the full  Intelligent Hub capabilities and with Workspace ONE UEM Console 1810 Release the full Workspace ONE Intelligent Hub capabilities are now GA on iOS and Android to all, with Windows 10 and macOS to be released at a later date.

I hadn't set this up in my lab yet as I was on leave during the whole release period, and being a tinkerer I wanted to make sure I had the latest capabilities for some upcoming customer demos. The configuration wasn't exactly straight forward (in all honesty I hadn't read any documentation and hadn't completed the training on what the current capabilities were, but shhh...) so I thought I'd just quickly write up the steps to bring all the Workspace ONE App capabilities into the Workspace ONE Intelligent Hub to unify the capabilities of all agents.