Lab 8: Assigning Profiles for Windows Endpoints
Objective and Tasks
Add smart groups and configure profile restrictions for Windows endpoints:
- Review Payload Capabilities
- Add a Windows Restrictions Profile
- Add a Wi-Fi Profile
- Create a Windows Hello Profile
- Deploy a Windows Update Profile
- Deploy a Windows Application Control Profile
- Configure the Health Attestation Settings
- Review the Profile Management Settings
- Verify the Profiles and Settings for an Enrolled Device
Task 1: Review Payload Capabilities
You explore the core payloads available when creating device profiles for Windows endpoints.
- Log in to the ControlCenter desktop VM.
- User name: administrator
- Password: Pa$$w0rd
- Open Chrome and log in to Workspace ONE UEM.
- User name: studentadmin{labid}
- Password: Pa$$w0rd
- On the Workspace ONE UEM console menu bar, verify that Student{labid} is selected from the Organization Group drop-down menu.
- In the navigation pane on the left, select RESOURCES > under the Profiles & Baselines > Profiles.
- From the Add drop-down menu, select Add Profile.
- In the Add Profile dialog box, click Windows.
- In the Select Device Type dialog box, click Windows.
- In the Select Context dialog box, click Device Profile. The General page opens.
- In the navigation pane on the left, explore the available settings for the selected payloads.
- Click Password.
- To display the configuration options, click Configure.
- In the navigation pane on the left, select a different payload without making any changes.
- Click Cancel to close the Add a New Desktop Profile dialog box.
- Click OK to discard changes.
Task 2: Review Windows Restrictions Profile
You configure profile restrictions for your Windows devices to remove user access to device features and to ensure that your Windows devices are secure.
- On the Workspace ONE UEM console menu bar, verify that Student{labid} is selected from the Organization Group drop-down menu
- In the navigation pane on the left, select RESOURCES > under the Profiles & Baselines > Profiles.
- From the Add drop-down menu, select Add Profile.
- Select Windows > Windows > Device Profile. The General page appears.
- Configure the General settings.
- Enter Block Date Time Adjustment in the Name text box.
- Click the Smart Groups search bar and select Windows Devices (Student####). Note: The #s represent the Lab ID.
- In the navigation pane on the left, select Restrictions and click Configure.
- Under Settings, click Don’t Allow next to Date/Time.
- Click Cancel to close the Add a Windows Restriction Profile dialog box.
- Click OK to discard changes.
Task 3: Add a Wi-Fi Profile
You configure a Wi-Fi profile.
The W11Client-01a VM cannot connect to a Wi-Fi network, so this task is for demonstration purposes only.
- On the Workspace ONE UEM console menu bar, verify that Student{labid} is selected from the Organization Group drop-down menu
- In the navigation pane on the left, select RESOURCES > under the Profiles & Baselines > Profiles.
- From the Add drop-down menu, select Add Profile.
- Select Windows > Windows > Device Profile. The General page opens.
- Configure the General settings.
- Enter Test Wi-Fi in the Name text box.
- Click in the Smart Groups search box and select Windows Devices (Student####).
- In the left pane, select Wi-Fi and click Configure.
- Configure the General settings.
- The network determines many of these values.
- Enter Test Wi-Fi in the Service Set Identifier text box.
- From the Security Type drop-down menu, verify that Open is selected.
- Click Save and Publish.
- To push the configuration, click Publish.
Task 4: Create a Windows Hello Profile
You configure a Windows Hello profile.
Because the lab environment is not set up for Windows Hello, you cannot successfully apply a Windows Hello profile to your device.
- In the navigation pane on the left, select RESOURCES > under the Profiles & Baselines > Profiles.
- From the Add drop-down menu, select Add Profile.
- Select Windows > Windows > Device Profile.
- The General page opens.
- Configure the General settings.
- Enter Test Windows Hello in the Name text box.
- Click in the Smart Groups search box and select Windows Devices (Student####).
- In the navigation pane, select Windows Hello and click Configure.
- Review the available settings.
- Biometric Gesture: You enable this setting to permit users to use the device biometric readers.
- TPM: You click Require to disable passport use without a Trusted Protection Module (TPM) installed on the device.
- Minimum PIN Length: You enter the minimum number of digits that a PIN must contain.
- Maximum PIN Length: You enter the maximum number of digits that a PIN can contain.
- Digits: You set the permissions level for using digits in the PIN.
- Uppercase Letters: You set the permissions level for using uppercase letters in the PIN
- Lowercase Letters: You set the permissions level for using lowercase letters in the PIN.
- Special Characters: You set the permissions level for using special characters in the PIN.
Special characters: ! " # $ % & ' ( ) * + , - . / : ; < = > ? @ [ \ ] ^ _ ` { | } ~
- Click Cancel to close the profile creation page without saving.
- Click OK to discard changes.
Task 5: Deploy a Windows Update Profile
You review the Windows Update management capability.
- In the navigation pane on the left, select RESOURCES > under the Profiles & Baselines > Profiles.
- From the Add drop-down menu, select Add Profile.
- Select Windows > Windows > Device Profile. The General page opens.
- Configure the General settings.
- Enter Windows Update Profile in the Name text box.
- Click the Smart Groups search box and select Windows Devices (Student####).
- In the navigation pane on the left, select Windows Updates and click Configure.
- Review the Windows Updates settings.
- Device Scheduling
- Update Behavior
- Device Behavior
- Delivery Optimization
- OS Version
- Click Cancel to close the profile creation page without saving.
- Click OK to discard changes.
Task 6: Deploy a Windows Application Control Profile
You enable Application Control to allow and deny specific applications to permit or prevent the installation of applications on devices.
- On the Workspace ONE UEM console menu bar, verify that Student{labid} is selected from the Organization Group drop-down menu
- In the navigation pane on the left, select RESOURCES > under the Profiles & Baselines > Profiles.
- From the Add drop-down menu, select Add Profile.
- Select Windows > Windows > Device Profile. The General page opens.
- Configure the General settings.
- Enter Block Xbox in the Name text box.
- Click the Smart Group search box and select Windows Devices (Student####).
- In the navigation pane on the left, select Application Control and click Configure.
- Configure the Application Control settings.
- Select the Import Sample Device Configuration check box.
- Click Upload.
- Click Choose File.
- Navigate to the Desktop > Software folder > Lab Activities
| IMPORTANT |
| An XML for an application control rule was already created and pre-staged in the lab environment. The BlockXBox.xml application rule is used in this task. |
- Click the BlockXbox.xml file.
- Select Open.
- Click Save.
- Click Save and Publish.
- Click Publish.
Task 7: Configure the Health Attestation Settings
You configure the compromised status definitions for Windows Desktop devices.
- In the Workspace ONE UEM console, select GROUPS & SETTINGS > All Settings > Devices & Users > Microsoft > Windows > Windows Health Attestation in the navigation pane on the left.
- Next to Current Setting, click Override.
- Select the Early Launch Anti-Malware Disabled check box.
- You leave the default values for all other health attestation options.
- Click Save.
- Close the Settings dialog box.
Task 8: Review the Profile Management Settings
You review the profile management settings available to UEM administrators.
- On the Workspace ONE UEM console menu bar, verify that Student{labid} is selected from the Organization Group drop-down menu
- In the navigation pane on the left, select RESOURCES > under the Profiles & Baselines > Profiles.
- Review the available settings and actions.
- From the Add drop-down menu, you can upload a profile or batch-import profiles.
- In the top-right corner of the Profiles page, you can perform a profile search, change the layout, refresh the data, or export the data in CSV or XLSX format.
- You can use the Filters list to filter profiles based on Status, Platform, and Smart Group assignment.
- Profiles can be deactivated by clicking the button to the left of the profile name and then selecting Deactivate from the More Actions drop-down menu.
When a profile is deactivated, it is removed from all devices.
- Under Installed Status, click View in the row of one of the profiles.
You can see the number of devices that have a Not Installed, Installed, or Assigned status.
- Click the button next to a profile name to show the profile task menu.
- Devices: You can view the device assignment for a selected profile.
- </> XML: You can view the XML code for the selected profile.
- More Actions: You can copy, deactivate, or delete the selected profile.
- Click an existing profile name to view and edit the profile details.
- Add Version: You can modify the profile payload content.
| NOTE |
| Only click Add Version if you want to modify the profile payloads for all assigned devices. Publishing the profile after clicking Add Version will reinstall the profile to all assigned devices. You have no requirement to click Add Version if you only want to change the assignment. In this case, you can directly modify the Smart Groups and click Save and Publish. The profile is only applied to devices that are new to the assignment or only removed from devices that are no longer part of the assignment. |
- Save and Publish: You publish the updated profile content to all assigned devices.
- Cancel: You return to the Profiles page without making changes to the profile details.
- Click Cancel.
Task 9: Verify the Profiles and Settings for an Enrolled Device
You verify that the profiles are installed on the enrolled devices.
- On the Workspace ONE UEM console menu bar, verify that Student{labid} is selected from the Organization Group drop-down menu
- In the navigation pane on the left, select DEVICES > Devices.
- In the General Info column, click the friendly name hyperlink of your enrolled Windows device.
- The Details View page of the device appears.
- To review the assigned profile configurations deployed to the device, click the Profiles tab.
- The Status column shows a green checkmark if the profile successfully installed and configured itself on the device.
Your lab environment might not show a green checkmark. You can continue.
You can also attempt a manual installation of the profile by clicking the button to the left of the profile name. The Install and Remove options appear above the profile list.
0 Comments
Add your comment