There are three main ways to get an application installed onto an iOS device. The most common way will be to install applications on devices directly from the iOS App Store, or if your organisation has developed their own application in-house or through a developer you can deploy this as an internal application.
Once the application is added to the Workspace ONE UEM Console it is will be available to install by end users. All pretty straight forward however there is more ways can we make this process even easier.
All things VMware Workspace ONE, Identity and everything in between.
Showing posts with label iOS. Show all posts
Showing posts with label iOS. Show all posts
Monday, October 14, 2019
Tuesday, October 1, 2019
Configuring Mobile SSO for iOS Devices in Workspace ONE

One of big differentiators we have with Workspace ONE is ability to use MobileSSO to drastically improve security and the user experience.
MobileSSO with Workspace ONE leverages certificates deployed to devices to seamlessly sign the user into the Workspace ONE Intelligent Hub and any federated SaaS services.
This solution requires both Workspace ONE UEM (to deploy and manage the lifecycle of the certificates) and Workspace ONE Access (to challenge the device for the certificate and authenticate the user). On iOS MobileSSO technically uses Kerberos by validating the certificate on the device and generating a Kerberos token the device can then present back for authentication.
In this post I'll discuss how to configure Workspace ONE Access for iOS MobileSSO and how to create a profile in Workspace ONE UEM to deploy the required certificate and approve the domains and applications that can use it.
Labels:
Access Policy,
Active Directory,
Apple,
Identity,
Identity Manager,
Identity Provider,
iOS,
Profiles,
SAML,
vIDM,
VMware,
Workspace ONE Access,
Workspace ONE Hub,
Workspace ONE Intelligent Hub,
Workspace ONE UEM
Basics of Device Profiles in Workspace ONE UEM
They're very small in size usually, and contain information that the device Operating System can understand to effect changes.
The important part to note here is that we are typically bound by what the vendor makes available via their APIs as to what we can configure. To put it more simply, the capability to make changes to settings needs to be made available by the vendor - then we can push a profile to configure it.
Seeing our environment is configured to enroll iOS devices, Android Enterprise Devices, and Windows 10 devices I'll cover some basics of profiles that are relevant to all.
Monday, September 30, 2019
Enabling Password (Cloud Deployment) Auth Method in Workspace ONE Access
The simplest way to do this is to enable Password (cloud deployment) so that our users are able to authenticate with their Active Directory credentials using the Identity Manager Connector we installed and configured. What's great about this method is that its outbound meaning that a user authentication request never comes inbound so there's no inbound firewall rules.
Let's look at how to configure this authentication method and set up our default access policy to use it.
Labels:
Access Policy,
Active Directory,
Identity,
Identity Manager,
Identity Provider,
iOS,
Microsoft,
Third Party IDP,
vIDM,
VMware,
Workspace ONE Access,
Workspace ONE Intelligent Hub,
Workspace ONE UEM,
WorkspaceONE
Monday, June 24, 2019
Secure, Automated and Passwordless Mobile Clinical Device Provisioning
If you've ever been in a hospital, I'm sure you would have seen clinical staff (literally at times) running between rooms, back to nursing stations or if they're lucky into the hall to enter notes or lookup information on a WOW (Workstation on Wheels). Apart from the time it takes to get back to any of these places, they have to leave the patient bedside and remember what they need to capture in the medical records. Typically, to try and gain some time back computers are logged in as generic accounts (shudder) and there is no user personalisation or account auditing on these devices. To me, this just sounds like a recipe for disaster.
In recent years, we've seen the uptake of VDI (year of the desktop anyone?) and that brought some improvements around session portability between devices but there is no true mobility use case like a mobile tablet or phone that the clinician or doctor can take with them and complete their tasks at the bedside.
True, a device for every employee would be expensive. And they could just use their own devices to take notes or photos, but from a regulatory and compliance perspective this is really not a good idea.
This is where GroundControl and VMware Workspace ONE come in to save the day.
Imagine being a nurse, doctor or any healthcare employee for that matter. You now walk up to a pool of iOS devices, tap your RFID Employee badge onto the proximity card reader and in seconds a device is allocated to you which is completely personalised with your authentication credentials, your relevant applications and is ready to use without having to enter and passwords or further configuration. When you're done, just dock it back where you got it and it is securely erased to factory defaults ready for the next user.
Sound too good to be true?
Nope. Read to find out how and see this is action.
In recent years, we've seen the uptake of VDI (year of the desktop anyone?) and that brought some improvements around session portability between devices but there is no true mobility use case like a mobile tablet or phone that the clinician or doctor can take with them and complete their tasks at the bedside.
True, a device for every employee would be expensive. And they could just use their own devices to take notes or photos, but from a regulatory and compliance perspective this is really not a good idea.
This is where GroundControl and VMware Workspace ONE come in to save the day.
Imagine being a nurse, doctor or any healthcare employee for that matter. You now walk up to a pool of iOS devices, tap your RFID Employee badge onto the proximity card reader and in seconds a device is allocated to you which is completely personalised with your authentication credentials, your relevant applications and is ready to use without having to enter and passwords or further configuration. When you're done, just dock it back where you got it and it is securely erased to factory defaults ready for the next user.
Sound too good to be true?
Nope. Read to find out how and see this is action.
Subscribe to:
Posts (Atom)



