Showing posts with label Workspace ONE UEM. Show all posts
Showing posts with label Workspace ONE UEM. Show all posts

Tuesday, April 28, 2020

The Elusive Cloud Based Windows Deployment

It's a bit like Bigfoot. Some have said they've seen it, and can suggest how it might work. Some think it will never eventuate the way we want. And Apple has had this capability for years!

There are some technical challenges from a Windows/x86/x64 perspective, but I would have thought it would be easier. My last couple of posts have been talking about building a Windows Deployment Server in your network, and while I was building this out it really made me look at the possibility of making this available over the Internet. I spent days trawling through Windows docs and lots of other pages trying to find a way to embed a VPN client into my WinPE Boot Image, but the answer was surprisingly MUCH simpler than that.

I've been sitting on this for a while and its been pretty exciting to get this working. 

If you want to know how to deploy a customised Windows 10 image to your staff, over the Internet, and have it automatically enroll into Workspace ONE read on.

Monday, April 27, 2020

Imaging Windows 10 Devices for Workspace ONE - Part 2: Creating, Capturing and Deploying a Reference Image

Now that you have a WDS environment that can complete some basic task sequences and deploy images, to make this much more useful we need to create a reference image that has (some or all of) our Workspace ONE UEM Windows 10 apps in it. We also want it to automatially enrol into Workspace ONE UEM for the end users.


I know that we normally talk about "not having an SOE" but seeing you're here you must have a use case for it, however lets make it as simple and lean as possible!

Some of the steps below are a bit out of the ordinary for a default WDS environment task sequence so please read carefully.




Saturday, April 25, 2020

Imaging Windows 10 Devices for Workspace ONE - Part 1: Installing Windows Deployment Services

Full disclose straight up - this is a long one.

I often get asked that once we remove SCCM from a customer's environment and provide full Modern Management with Workspace ONE, how do we image machines? Well, you can obviously just use what comes on the PC and enroll it then remove whatever you don't want. There's also Dell Factory Provisioning which allows you to provide the configuration and have the Dell Factory apply the image and have to directly sent ready to be used (GREAT by the way). What about if you're not using Dell? What about if the hard disk fails and needs to be replaced?

That's what I'm going to answer.





Wednesday, April 15, 2020

So I wrote my first App


And it was exhausting! I've never really been interested in coding, but with being in front a computer a lot more I've been able to spend a bit of time learning some new skills. It started off by wanting to learn some more about interacting with the Workspace ONE APIs, but I ended up wanting to add 'just that little bit more' until I ended up with something I'm somewhat happy with.

I am sure the code is very inefficient and I had to learn a lot of new concepts but what I've created is - Workpace ONE COVID-19 Notifier

What it allows you to do is obtain the latest COVID-19 Statistics for your Country and send a message to Workspace ONE users and devices.

Read on to see how I can see this being used!


Friday, March 20, 2020

Tech For Good: Use your idle desktop compute to help fight COVID-19

We're in a such a strange period of time globally at the moment. On the one hand, the entire world is going through the same thing bringing us together but on the other we're all "social distancing" or being isolated from each other.

Personally, I've been working from home all week.  While this isn't something new - I usually try to block out one or two days a fortnight - I've had a lot more time on my hands without the travel and disuptions. After being prodded by APJ Field CTO here at VMware, suggesting I put some thing social media about VMware and our Tech For Good program, I thought what could I actually do could help others join forces for the greater good as well.

VMware itself has advised all of our global employees to work from home too so there's a lot more chatter on Slack, and one of the things we've been talking about is everyone installing Folding At Home on our homelabs to contribute our spare compute capacity to finding a way to fight COVID-19.

This got me thinking - now that everyone is working from home, think of all the compute that is just sitting on the desks of all offices around the world. Sure we can put it into our datacentres (stay tuned for more on this), but I think I could come up with a way to get this onto all PCs managed by Workspace ONE at scale and fold the night away!

Wednesday, January 8, 2020

Managing Windows 10 Applications with Workspace ONE UEM

VMware has done a lot of work in the past few years with Application Deployment as part of our Windows 10 Management capabilities.

That is why it's taken me so long to get to this article - I didn't know where to start without being overwhelmed!

For Application Deployment on Windows 10 with Workspace ONE UEM, we (predominantly) support .MSI .EXE and .ZIP files as installers. We also have a lot of parameters and capabilities around deploying these to cover many scenarios. Below you'll find a good overview of what we can do and why you may want to choose one over the other.


Tuesday, December 31, 2019

Add Android Applications to Workspace ONE UEM

Pop quiz: Which came first? Android or iOS?

Don't worry I had to look this up too. Technically it was iOS, because the first device with an OS called Android came a year or so after.

Not relevant to this post, but I had to check this myself before writing this because I needed a good intro.

Android itself has taken many changes over the years. But one of the biggest changes has to be the change from Device Administrator mode to Android Enterprise (formerly Android for Work). This fundamentally changed the way a device is managed using an EMM and as a result, changed the way that we can deploy, install and manage applications as well.

Given that Android Device Administrator has been deprecated as of version 10, this guide will only talk about deploying Android Applications using Android Enterprise.

Obviously for this to make sense to your deployment, you'll need to have set up Android Enterprise.

Monday, October 14, 2019

Adding iOS Applications to Workspace ONE UEM

There are three main ways to get an application installed onto an iOS device. The most common way will be to install applications on devices directly from the iOS App Store, or if your organisation has developed their own application in-house or through a developer you can deploy this as an internal application.

Once the application is added to the Workspace ONE UEM Console it is will be available to install by end users. All pretty straight forward however there is more ways can we make this process even easier.


Tuesday, October 8, 2019

The nuances of enrolling Android Devices in Workspace ONE

So Android is Android right? Well not exactly. There are technically four modes where you can utilise Android on a managed device, but one doesn't really count anymore because its been deprecated by Google.

Android has come along way in the last few years and has some very interesting and unique features. Some of these features are only available in the different modes, where those modes can only enabled on a device during enrollment.

This may be a little confusing to start with but I'll explain a bit more in the rest of this article.

Wednesday, October 2, 2019

Introduction to Organisation Groups and Smart Groups



Workspace ONE UEM right back to the early days when it was Airwatch is inherently multi-tenanted. We achieve this through Organisation Groups.

Our Shared SaaS tenants are the same codebase as what you'd get to deploy On-Premises so even we rely on Org Groups to achieve the required separation.

With this in mind, there are many reasons why you as a customer may need to rely on this capability. Read on to find out more.


Tuesday, October 1, 2019

How to build your Workspace ONE Sandbox

Workspace ONE is incredibly powerful. But with so many features and functions, its no wonder people can get lost when working out where to start on configuring it to test with your scenarios in your environment.

As part of VMware Testdrive, other than getting access to a pre-configured testing environment and walkthroughs you also get a full fledged trial environment we refer to as a Sandbox.


This has all the capabilities of Workspace ONE where you can integrate it with all services to test it in your environment with real users and real devices.

So, this is where this guide comes in. Even I struggle to explain or give a place for my customers to go for all they need to get started. I'll add to the below information over time but this will be enough to get you started with Workspace ONE as part of a pilot or proof of concept.

Configuring Mobile SSO for iOS Devices in Workspace ONE



One of big differentiators we have with Workspace ONE is ability to use MobileSSO to drastically improve security and the user experience.

MobileSSO with Workspace ONE leverages certificates deployed to devices to seamlessly sign the user into the Workspace ONE Intelligent Hub and any federated SaaS services.

This solution requires both Workspace ONE UEM (to deploy and manage the lifecycle of the certificates) and Workspace ONE Access (to challenge the device for the certificate and authenticate the user). On iOS MobileSSO technically uses Kerberos by validating the certificate on the device and generating a Kerberos token the device can then present back for authentication.

In this post I'll discuss how to configure Workspace ONE Access for iOS MobileSSO and how to create a profile in Workspace ONE UEM to deploy the required certificate and approve the domains and applications that can use it.


Basics of Device Profiles in Workspace ONE UEM



Profiles are configurations that are sent to our devices in Workspace ONE UEM to configure our devices.

They're very small in size usually, and contain information that the device Operating System can understand to effect changes.

The important part to note here is that we are typically bound by what the vendor makes available via their APIs as to what we can configure. To put it more simply, the capability to make changes to settings needs to be made available by the vendor - then we can push a profile to configure it.

Seeing our environment is configured to enroll iOS devices, Android Enterprise Devices, and Windows 10 devices I'll cover some basics of profiles that are relevant to all.


Configuring Workspace ONE UEM for Windows 10 enrollment



There are a few configuration and settings changes that we need to do to make our environment able to support Windows 10 device management.

Given we've already set up our email domain for email based enrollment on iOS and Android, we now need to configure Windows Auto-Discovery Services (WADS) which allows us to use email addresses for Windows Enrollment.

Typically you will want to use the Cloud-Hosted version of WADS and this is what we'll cover in this post.


Setting up email based autodiscovery enrollment in Workspace ONE UEM

What is something that all users know? OK, what's something they should know.

Yes, it's their email address.

When we configure email based enrollment, it allows users to enter their email address during enrollment and it will autodiscover their correct environment.

It's pretty straightforward, but I wanted to make sure it was documented because its actually required for Windows enrollment.


How to configure Workspace ONE UEM to enable Android Enterprise device management

Setting up Android Enterprise device enrollment got a lot easier about a year ago. Previously you needed to create a full blown GSuite deployment, do a heap of DNS stuff and certificates.

Now its as simple as creating a Gmail account, entering it into the Workspace ONE Console and approving some applications.

 That's not to say that the Gsuite method shouldn't be used - there are definite scenarios where this is preferred - but for testing and POC purposes (any many others) using the Gmail method is perfectly fine.

Generating an Apple Push Notifications Certificate to enroll and manage Apple Devices

Most of the time it seems like magic that Apple devices 'just work'. However, there is one fundamental service that makes this happen - the Apple Push Notification Service. This is a set of services that Apple use (and that Apple devices leverage) to communicate with MDM, App Store, Email infrastructure etc.

The part that Mobility Administrators need to do to utilise this in Workspace ONE is generate their own Apple Push Notification Services certificate to secure traffic and communicate with Apple.

It essentially allows the entire mobility infrastructure to communicate freely in a "push" fashion rather than on-demand or schedule.

Now the important part here is that this certificate needs to be renewed every 12 months. I say important because if you don't renew it and let it expire, you have to reenroll every Apple device (manually) for them to function properly again.

Enough chit-chat, lets generate an APNs certificate and upload it to the Workspace ONE UEM Console.


Monday, September 30, 2019

Enabling Password (Cloud Deployment) Auth Method in Workspace ONE Access

In our current configuration, when we try to authenticate as a user in Workspace ONE Access it will probably fail. This is because we don't have an authentication method available to users that is able to authentication successfully.

The simplest way to do this is to enable Password (cloud deployment) so that our users are able to authenticate with their Active Directory credentials using the Identity Manager Connector we installed and configured. What's great about this method is that its outbound meaning that a user authentication request never comes inbound so there's no inbound firewall rules.

Let's look at how to configure this authentication method and set up our default access policy to use it.

Integrating Workspace ONE UEM and Workspace ONE Access

So you've got your Airwatch Cloud Connector installed and configured and you have your Identity Manager Connector installed and configured, but right now Workspace ONE UEM and Workspace ONE Access are not talking to each other.

We need to configure this integration so that we can start enrolling devices, using Workspace ONE Intelligent Hub, Unified App Catalog and Mobile SSO.

Luckily, this process is pretty straight foward. The wizard that does this integration works well and does all the heavy lifting.

Lets check out the process.

Installing Airwatch Cloud Connector and Configuring Directory Services in Workspace ONE UEM

Welcome to the first installment to my end-to-end lab and Testdrive Sandbox configuration series.

In this post we'll look at installing the Airwatch Cloud Connector (ACC) and integrating with your On-Premises Active Directory.

I do get asked this a bit as to why you would use the ACC and Active Directory if you're using SAML authentication with either Identity Manager/AzureAD/Okta etc. Although in this article I won't cover SAML integration I'll point out why we still recommend full directory integration.

Firstly, it allows users to authenticate securely with their directory credentials. It also pre-populates all the required user metadata in the console (email address, UPN, immutableID, phone number etc.). Using SAML without directory integration would mean the user gets created in Workspace ONE UEM using SAML JIT therefore it won't bring in the rest of those attributes. The other main reason we recommend using this is so that Administrators can use Active Directory groups for Assignment Groups in Workspace ONE UEM. As an example, you could assign a policy or application to your HR Department if that group exists in AD. If you don't have these groups, you would need to manually go into the Workspace ONE Console and assign the configurations to those users one by one.

The ACC also facilitates integration with On-Premises Certificate Authorities, Syslog servers and SMTP services (amongst other things)

So, back to the actual configuration.