Lab 2: Troubleshooting in the Workspace ONE UEM console
Objective and Tasks
Resolve issue using the Workspace ONE UEM administration console:
- Troubleshoot a Smart Group Configuration
Task 1: Troubleshoot a Smart Group Configuration
Scenario: After a new Windows endpoint was enrolled, a profile did not deploy to the new endpoint, even after waiting a day.
Root cause: The profile is assigned to the NA Sales smart group. When the smart group was first created, the Craig account was excluded. As a result, the profile and application are not assigned to the Craig account.
You help the UEM administrator remove the exclusion from the NA Sales smart group and restore profile assignment.
- From the lab environment interface, make sure that uem-01a is selected from the dropdown at the top-left of the screen.
- Username: techseals\administrator
- Password: Pa$$w0rd
- If not already opened, open the Workspace ONE UEM administration console.
- On the uem-01a Windows taskbar, click the Google Chrome icon and select UEM from the bookmark toolbar
You can also enter https://wsone.techseals.co/AirWatch in the address bar. - Log into Workspace ONE UEM.
- Username: admin
- Password: Pa$$w0rd
- On the uem-01a Windows taskbar, click the Google Chrome icon and select UEM from the bookmark toolbar
- On the Workspace ONE UEM console menu bar, verify that Techseals is selected from the Organization Group drop-down menu.
Techseals is the top-level organization group. - In the navigation pane on the left, select Resources > Profiles & Baselines > Profiles.
- Review the profiles that appear in the Profile list.
- iOS Exchange Email
- iOS Passcode
- iOS Restrictions
- Windows Device Encryption
- Windows Exchange Email
- Windows User Auth
- Windows Wallpaper
| NOTE |
|---|
| The profiles have different assignment groups. The relevant profile in this scenario is the Windows Device Encryption profile. |
- In the Windows Device Encryption profile row, click View under Installed Status. The number of assigned devices is 1 and the number of installed devices is also 1. However, the correct number for each should be 2 because there is a Windows Desktop device enrolled in this environment.
- In the navigation pane on the left, select Groups & Settings > Groups > Assignment Groups.
- Click the NA Sales smart group hyperlink. The Edit Smart Group dialog box appears.
- Next to Device Preview, click Enabled. The smart group does not include the device for user Craig.
- Scroll down to the bottom of the navigation pane on the left and expand Exclusions. The user Craig is selected as an excluded user.
- Deselect the Craig user check box.
- Verify that the Windows endpoint enrolled with the Craig user account now appears under Device Preview.
- Click Next. The View Assignments dialog box appears.
- Click Publish.
- In the Workspace ONE UEM console, select Resources > Profiles & Baselines > Profiles in the navigation pane on the left.
- In the Windows Device Encryption profile row, click View under Installed Status.
- Verify that the number of assigned devices now shows 2.
- In the navigation pane on the left, select Devices > Devices list view.
- To access the Device Details page for Craig's device, click the device name hyperlink under General Info.
- Select the Profiles tab.
- Hover over the Status icon for the Windows Device Encryption profile and verify that the status of the Windows Device Encryption profile is now Installed.
| NOTE |
|---|
| Profiles take up to two minutes to install. You can try refreshing the browser to update the installation status. |
- (Optional) If the profile installation status does not change, force synchronization from the Windows endpoint.
- From the lab environment interface, click on the dropdown at the top-left of the screen, where it probably says, "uem-01a", and select w11Client-01a.
- Click anywhere on that screen.
- Log into w11Client-01a:
- Username: Techseals\Craig
- Password: Pa$$w0rd
- On the w11Client-01a, click on the Start icon, and type hub. From the Best match section, click Workspace ONE Intelligent Hub.
- Enter and confirm Pa$$w0rd in the BitLocker Encryption window. Then click on Encrypt.
- At the bottom-left side of the Intelligent Hub screen, click on Craig Stroser.
- Click Sync Device. Eventually, it will say, "Sync has completed"
- Return to the Workspace ONE UEM console on the uem-01a VM. You might have to log back in by going to the top-left of the screen where you will see an icon of a keyboard. Click on the keyboard icon, and a dropdown will appear, showing an option, “Ctrl+Alt+Delete”. Click on Ctrl+Alt+Delete and now you can type the password, which is “Pa$$w0rd”
- Refresh the web browser page.
- Verify that the status of the Windows Device Encryption profile is now Installed.
- (Optional) If the profile installation status does not change, push the profile manually.
a. On Device Details View page, click the Profiles tab.
b. Click the button next to the profile that failed to install.
c. Click Install.
d. Click OK.
e. Refresh the web browser page.
f. Verify that the status of the profile is now Installed.
0 Comments
Add your comment