Showing posts with label WorkspaceONE. Show all posts
Showing posts with label WorkspaceONE. Show all posts

Friday, March 20, 2020

Tech For Good: Use your idle desktop compute to help fight COVID-19

We're in a such a strange period of time globally at the moment. On the one hand, the entire world is going through the same thing bringing us together but on the other we're all "social distancing" or being isolated from each other.

Personally, I've been working from home all week.  While this isn't something new - I usually try to block out one or two days a fortnight - I've had a lot more time on my hands without the travel and disuptions. After being prodded by APJ Field CTO here at VMware, suggesting I put some thing social media about VMware and our Tech For Good program, I thought what could I actually do could help others join forces for the greater good as well.

VMware itself has advised all of our global employees to work from home too so there's a lot more chatter on Slack, and one of the things we've been talking about is everyone installing Folding At Home on our homelabs to contribute our spare compute capacity to finding a way to fight COVID-19.

This got me thinking - now that everyone is working from home, think of all the compute that is just sitting on the desks of all offices around the world. Sure we can put it into our datacentres (stay tuned for more on this), but I think I could come up with a way to get this onto all PCs managed by Workspace ONE at scale and fold the night away!

Tuesday, December 31, 2019

Add Android Applications to Workspace ONE UEM

Pop quiz: Which came first? Android or iOS?

Don't worry I had to look this up too. Technically it was iOS, because the first device with an OS called Android came a year or so after.

Not relevant to this post, but I had to check this myself before writing this because I needed a good intro.

Android itself has taken many changes over the years. But one of the biggest changes has to be the change from Device Administrator mode to Android Enterprise (formerly Android for Work). This fundamentally changed the way a device is managed using an EMM and as a result, changed the way that we can deploy, install and manage applications as well.

Given that Android Device Administrator has been deprecated as of version 10, this guide will only talk about deploying Android Applications using Android Enterprise.

Obviously for this to make sense to your deployment, you'll need to have set up Android Enterprise.

Monday, October 14, 2019

Adding iOS Applications to Workspace ONE UEM

There are three main ways to get an application installed onto an iOS device. The most common way will be to install applications on devices directly from the iOS App Store, or if your organisation has developed their own application in-house or through a developer you can deploy this as an internal application.

Once the application is added to the Workspace ONE UEM Console it is will be available to install by end users. All pretty straight forward however there is more ways can we make this process even easier.


Tuesday, October 8, 2019

The nuances of enrolling Android Devices in Workspace ONE

So Android is Android right? Well not exactly. There are technically four modes where you can utilise Android on a managed device, but one doesn't really count anymore because its been deprecated by Google.

Android has come along way in the last few years and has some very interesting and unique features. Some of these features are only available in the different modes, where those modes can only enabled on a device during enrollment.

This may be a little confusing to start with but I'll explain a bit more in the rest of this article.

Tuesday, October 1, 2019

How to configure Workspace ONE UEM to enable Android Enterprise device management

Setting up Android Enterprise device enrollment got a lot easier about a year ago. Previously you needed to create a full blown GSuite deployment, do a heap of DNS stuff and certificates.

Now its as simple as creating a Gmail account, entering it into the Workspace ONE Console and approving some applications.

 That's not to say that the Gsuite method shouldn't be used - there are definite scenarios where this is preferred - but for testing and POC purposes (any many others) using the Gmail method is perfectly fine.

Generating an Apple Push Notifications Certificate to enroll and manage Apple Devices

Most of the time it seems like magic that Apple devices 'just work'. However, there is one fundamental service that makes this happen - the Apple Push Notification Service. This is a set of services that Apple use (and that Apple devices leverage) to communicate with MDM, App Store, Email infrastructure etc.

The part that Mobility Administrators need to do to utilise this in Workspace ONE is generate their own Apple Push Notification Services certificate to secure traffic and communicate with Apple.

It essentially allows the entire mobility infrastructure to communicate freely in a "push" fashion rather than on-demand or schedule.

Now the important part here is that this certificate needs to be renewed every 12 months. I say important because if you don't renew it and let it expire, you have to reenroll every Apple device (manually) for them to function properly again.

Enough chit-chat, lets generate an APNs certificate and upload it to the Workspace ONE UEM Console.


Monday, September 30, 2019

Enabling Password (Cloud Deployment) Auth Method in Workspace ONE Access

In our current configuration, when we try to authenticate as a user in Workspace ONE Access it will probably fail. This is because we don't have an authentication method available to users that is able to authentication successfully.

The simplest way to do this is to enable Password (cloud deployment) so that our users are able to authenticate with their Active Directory credentials using the Identity Manager Connector we installed and configured. What's great about this method is that its outbound meaning that a user authentication request never comes inbound so there's no inbound firewall rules.

Let's look at how to configure this authentication method and set up our default access policy to use it.

Integrating Workspace ONE UEM and Workspace ONE Access

So you've got your Airwatch Cloud Connector installed and configured and you have your Identity Manager Connector installed and configured, but right now Workspace ONE UEM and Workspace ONE Access are not talking to each other.

We need to configure this integration so that we can start enrolling devices, using Workspace ONE Intelligent Hub, Unified App Catalog and Mobile SSO.

Luckily, this process is pretty straight foward. The wizard that does this integration works well and does all the heavy lifting.

Lets check out the process.

Installing Airwatch Cloud Connector and Configuring Directory Services in Workspace ONE UEM

Welcome to the first installment to my end-to-end lab and Testdrive Sandbox configuration series.

In this post we'll look at installing the Airwatch Cloud Connector (ACC) and integrating with your On-Premises Active Directory.

I do get asked this a bit as to why you would use the ACC and Active Directory if you're using SAML authentication with either Identity Manager/AzureAD/Okta etc. Although in this article I won't cover SAML integration I'll point out why we still recommend full directory integration.

Firstly, it allows users to authenticate securely with their directory credentials. It also pre-populates all the required user metadata in the console (email address, UPN, immutableID, phone number etc.). Using SAML without directory integration would mean the user gets created in Workspace ONE UEM using SAML JIT therefore it won't bring in the rest of those attributes. The other main reason we recommend using this is so that Administrators can use Active Directory groups for Assignment Groups in Workspace ONE UEM. As an example, you could assign a policy or application to your HR Department if that group exists in AD. If you don't have these groups, you would need to manually go into the Workspace ONE Console and assign the configurations to those users one by one.

The ACC also facilitates integration with On-Premises Certificate Authorities, Syslog servers and SMTP services (amongst other things)

So, back to the actual configuration.

Using Google Cloud Identity Secure LDAP with Workspace ONE

Most of my posts on my blog here have been about how to integrate other Identity Solutions with Workspace ONE.  However, the thing that all of these typically had in common was that they were synchronised with an On-Premises Active Directory.

This works well, but what happens when a customer has no On-Premises AD or is trying to get away from using one?

About a year ago, Google Announced their Cloud Identity Premium product which included a preview of LDAP connectivity. I played around with it then and it was good but for our purposes I could never get it to work - it requires the client service to use certificates to authenticate which is something that Workspace ONE doesn't support.

Recently a few customers have been asking whether there was ways to use Google Directories within Workspace ONE other than Just-In-Time provisioning and seeing that Secure LDAP from Google was now Generally Available globally it thought I'd give it another look.

Turns out I was able to get it to work! Read on to work out how, with some help from my colleagues, I was able to get it all integrated.

Thursday, September 26, 2019

Installing Identity Manager Connector and Configuring Directory Services in Workspace ONE Access


In this article we're going to talk about installing the VMware Identity Manager Connector in your environment to allow you connect to your On-Premises Active Directory. This connector also has a few other purposes like additional inbound authentication methods and the ability to synchronise Horizon Applications and Desktops.

We're just going to talk go through installation and configuring synchronisation with Active Directory in this article. I'll cover the rest in a later post.


Wednesday, June 26, 2019

Replacing CRTs with iPads for Patient Entertainment Systems in Healthcare

Back in my day our TVs were big square boxes. The one my family owned had a wood look vinyl covering and I think a "remote" control that had a cable. I didn't even know how to program the VCR.

I'm not that old yet my (grey) beard suggests otherwise - but I still see oldschool TVs in hospitals. You know why? Its because Patient Entertainment Systems cost a FORTUNE when they are first implemented. And if you still do it the same way, it will cost a fortune again. They are hard to repair or replace, and the content is old and static.

This post is an extension to my post from yesterday around using GroundControl with Workspace ONE. Using iPads for a Patient Entertainment System (hereby referred to as PES) was actually the first use case that introduced me to GroundControl. There is a great case study out of the US for Pheonix Children's Hospital where they are doing exactly this.

I won't get into as much detail as my last post around how GroundControl works, but read on and you'll find out exactly why Hospitals are moving toward iPads with Workspace ONE and GroundControl.

Monday, June 24, 2019

Secure, Automated and Passwordless Mobile Clinical Device Provisioning

If you've ever been in a hospital, I'm sure you would have seen clinical staff (literally at times) running between rooms, back to nursing stations or if they're lucky into the hall to enter notes or lookup information on a WOW (Workstation on Wheels). Apart from the time it takes to get back to any of these places, they have to leave the patient bedside and remember what they need to capture in the medical records. Typically, to try and gain some time back computers are logged in as generic accounts (shudder) and there is no user personalisation or account auditing on these devices. To me, this just sounds like a recipe for disaster.

In recent years, we've seen the uptake of VDI (year of the desktop anyone?) and that brought some improvements around session portability between devices but there is no true mobility use case like a mobile tablet or phone that the clinician or doctor can take with them and complete their tasks at the bedside.

True, a device for every employee would be expensive. And they could just use their own devices to take notes or photos, but from a regulatory and compliance perspective this is really not a good idea.

This is where GroundControl and VMware Workspace ONE come in to save the day.

Imagine being a nurse, doctor or any healthcare employee for that matter. You now walk up to a pool of iOS devices, tap your RFID Employee badge onto the proximity card reader and in seconds a device is allocated to you which is completely personalised with your authentication credentials, your relevant applications and is ready to use without having to enter and passwords or further configuration. When you're done, just dock it back where you got it and it is securely erased to factory defaults ready for the next user.

Sound too good to be true?

Nope. Read to find out how and see this is action.


Friday, June 21, 2019

Velocloud Dynamic Multi-Pathing and Identity Manager

I was lucky enough a few weeks ago to get a Velocloud SD-WAN by VMware router for my homelab. This post won't be about all the features and capabilities of Velocloud, but there is one particular capability that, although useful, causes a few challenges with Horizon and Identity Manager.

I'm talking about Dynamic Multi Path Optimisation. Being an End User Computing specialist, I'm not going to pretend I am a networking expert but I will try to explain it as best as I can. On my Veloloud Edge Router in my lab, traffic is dynamically routed through the Velocloud Edge Gateway hosted by VMware on the megaclouds like AWS. Read the document linked above, but what it allows is Velocloud to optimise and improve internet and network traffic when routed through one of these Gateways.

However, after setting one of these bad boys in my homelab I noticed that things weren't quite working quite as expected for Horizon and Identity Manager.

Monday, May 13, 2019

Managing Augmented Reality with VMware

Image result for deal with it glassesSeriously, it took me more time to think of a title for this post than it actually took to enrol and manage the Hololens. And this is what I came up with. Anyway, I digress.

A couple of weeks ago I was lucky to get my hands on a Microsoft Hololens Developer Kit device from our campus in Palo Alto. In case you weren't aware, VMware has an amazing and incredibly talented team in our Research and Development area working on many emerging technologies with Augmented Reality being one of them. Using my contacts within the CTO Ambassador Program I had the opportunity to meet many of them in person and see what they're working on, and as a result I was able to present our capabilities locally here in Australia at a Technology in Healthcare roadshow.

At this event I presented on how Blockchain, Machine Learning and Artificial Intelligence, Internet of Things, Virtual and Augmented Reality and Digital Twins will shape the future of Healthcare. After the presentation the VMware stand was inundated with clinicians and nurses right through to training coordinators trying out the Hololens and discussing how we can enable these kinds of devices now into organisations.

It doesn't seem to be that well known or understood how VMware can do this, so I thought I'd do a write up and give a bit of an example of what we're able to do.


Friday, April 12, 2019

Federating Multiple Identity Managers for VMware Services

For those who may have wondered, yes I am still alive.

Image result for twoIt's been a massive few months with overseas travel, new certifications and being admitted as a VMware CTO Ambassador. I'll make sure I write about all of this another time.

For background there has been a decision made by VMware recently where a lot of our Non-EUC solutions include a VMware Identity Manager licensing entitlement. What this is meant to allow is something like VMware Log Insight to be able to authenticate with Identity Manager allowing simplified SSO for administrators. This entitlement to Identity Manager is for the On-Premises version only.

So now, let's go into this scenario posed to me recently. What if that customer already has an entitlement to a SaaS Identity Manager tenant? Do they need both? Without opening a can of worms and entering the realms of licensing, the answer is "probably" and it's actually not a bad thing. Their situation was that they had some users who needed access to Log Insight that had an entitlement to a Workspace ONE SaaS license but not all of them. This meant we had to leave Log Insight federated with the On-Premises Identity Manager. If there is where we stopped everything would have worked, but the user experience would be pretty ordinary as they'd need to authenticate to both Identity Managers.

That's not how we roll at VMware! Lets make it simple!

Monday, January 7, 2019

Delivering complex Windows 10 app install routines in Workspace ONE UEM

With Windows being around for 30 years, it is no surprise that the software and configuration baggage its brings along with it to enterprise is extensive.

Unlike the truly modern mobile world, Apps for Windows 10 are typically not just a single file that lands on the device and runs with configuration being sent over APIs along with the install. Microsoft in some way have tried to transition to this with its Universal Windows Platform (UWP) Apps from the Microsoft Store and Microsoft Store for Business, but in my experience I have yet to see any organisation deliver (or develop) and truly enterprise level application using this platform.

This is why we are still nearly completely reliant on traditional Win32 Apps and needing to find a way to manage those "legacy" formats and processes in a modern management framework. VMware Workspace ONE UEM has made massive investment in development and enhancement in these capabilities and our customers are continuing to see our leadership in this space. We've talked a lot about how we can simply and robustly deliver .MSI and .EXE files and at scale, however its most often used when deploying a single installer with maybe a transform file and some checks to see if there's enough disk space.

But what if your install routine is more complex?

Tuesday, December 11, 2018

Enhancing your Zero Trust Architecture with Okta Identity Cloud and Workspace ONE

I feel like it shows the quality and strength of a vendor's solution when we can confidently stand behind what we do and are also aware enough to partner with others to provide better experiences for our joint customers. One of the best examples of this is Okta and VMware coming together to jointly work on and promote a unique partnership where we can leverage the best of both vendor's portfolio to provide the best user experience while ensuring security for your Organisation.

Outside of being how it all works and integrates (which I'll deep dive into shortly), I am often asked what the value is for customers. Okta Identity Cloud (as the name suggests) is a cloud-based Identity and Access Management solution that enables Single Sign-On the User Lifecycle to Modern Applications and Services. According to their website, they have over 5500 out-of-the-box integrations and have been consistently called out as a leader in their field.

I have been developing with and using Okta for nearly a year now as part of the VMware and Okta partnership. I've found it very powerful and easy to manage, and it seems more and more customers in my region are finding this too. With this, they are now looking to leverage the integrations between Workspace ONE and Okta Identity Cloud to take their Digital Workspace to the next level.

At the risk of taking the wind out of this post's sails, VMware has a page dedicated to this partnership but I still seem to get asked Why is there a Partnership, What is the Value, and How does it Work? So with this post I am going to answer this.

So channelling my inner Simon Sinek, lets Start With Why?

Friday, November 23, 2018

Transitioning to Workspace ONE Intelligent Hub in Workspace ONE UEM



If you missed all of our announcements around this in the last few weeks, VMware Workspace ONE Intelligent Hub is the replacement of the VMware AirWatch Agent. The first phase of the rollout is to be an in-place upgrade for iOS and Android devices that are already enrolled into Workspace ONE UEM. By default, the changeover to Intelligent Hub on iOS and Android brought a new icon and branding change and didn't require any re-enrollment of devices and functioned with the same capabilities as the Agent. We also flowed the look and feel changes through to macOS and Windows 10 device Agents too.


However, for the last 18 months or so we've had the Workspace ONE App. This App includes a heap of capabilities that the Agent didn't have. It was the entry point and enrolment method for Adaptive Management and Unified Catalog and was a a key part of our Conditional Access strategy allowing different levels access to resources based on Ownership Type, Network Location, Management Status etc.

In the Release Announcements VMware also mentioned about unifying the capabilities of the AirWatch Agent and the Workspace ONE App into a single unified Intelligent Hub. If you go back to the first paragraph you would notice I said by default it only replaced the capabilities of the Agent. At VMworld Las Vegas we showed off the full  Intelligent Hub capabilities and with Workspace ONE UEM Console 1810 Release the full Workspace ONE Intelligent Hub capabilities are now GA on iOS and Android to all, with Windows 10 and macOS to be released at a later date.

I hadn't set this up in my lab yet as I was on leave during the whole release period, and being a tinkerer I wanted to make sure I had the latest capabilities for some upcoming customer demos. The configuration wasn't exactly straight forward (in all honesty I hadn't read any documentation and hadn't completed the training on what the current capabilities were, but shhh...) so I thought I'd just quickly write up the steps to bring all the Workspace ONE App capabilities into the Workspace ONE Intelligent Hub to unify the capabilities of all agents.

Wednesday, November 21, 2018

Using Azure AD B2B Guest Accounts in VMware Identity Manager


Creating and managing the lifecycle of user accounts for users outside your organisation painful. Whether they are for contractors or external vendors, the time in creating these resetting passwords and then deprovisioning them is very time consuming - let alone the security implications if the accounts aren't removed.




A little while ago I was introduced to Azure AD Guest Accounts by a colleague. Guest Accounts are part of the Azure Active Directory Business to Business (B2B) capability where you can invite users from another Organisation's Azure Active Directory to have access to resources in yours. This means that if you have a Cloud Application federated with your Azure Tenant, you can simply invite their account and once they accept they can log in with their existing credentials and gain access.

This sounded great. But what I realised was that we were able to leverage this for using Guest Accounts in VMware Identity Manager. When using Azure Active Directory as a 3rd Party IDP in Identity Manager, you can invite a user to your Directory and they can log into Identity Manager and access the portal and any SaaS Applications you assign. You don't need to manage their account - if they forget their password its done at their Company's end, and you can even enforce additional Multifactor Authentication.

The requirements for Guest Accounts in Identity Manager are:

  • Your ‘Organisation’ must be using Azure Active Directory (doesn’t require Premium).
  • The ‘Guest’ account you are inviting must be an Azure AD account from another directory or be a Microsoft Account.
  • The ‘Service’ you’re entitling the Guest User to must have an account with a valid SAML attribute/NameID format. You can also use JIT to provision accounts into this service as well.
  • You need to have configured Azure Active Directory as a 3rd Party IDP in Identity Manager.
Let's go through how this all fits together.