Lab 2: Troubleshooting in the Workspace ONE UEM console
Objective and Tasks
Resolve issue using the Workspace ONE UEM administration console:
- Troubleshoot a Smart Group Configuration
Task 1: Troubleshoot a Smart Group Configuration
Scenario: After a new Windows endpoint was enrolled, a profile did not deploy to the new endpoint, even after waiting a day.
Root cause: The profile is assigned to the NA Sales smart group. When the smart group was first created, the Craig account was excluded. As a result, the profile and application are not assigned to the Craig account.
You help the UEM administrator remove the exclusion from the NA Sales smart group and restore profile assignment.
- From the lab environment interface, make sure that uem-01a is selected from the dropdown at the top-left of the screen.
- Username: techseals\administrator
- Password: Pa$$w0rd
- If not already opened, open the Workspace ONE UEM administration console.
- On the uem-01a Windows taskbar, click the Google Chrome icon and click UEM from the bookmark toolbar
You can also enter https://wsone.techseals.co/AirWatch in the address bar. - Log into Workspace ONE UEM.
- Username: admin
- Password: Omnissa123!
- On the uem-01a Windows taskbar, click the Google Chrome icon and click UEM from the bookmark toolbar
- On the Workspace ONE UEM console menu bar, verify that Techseals is selected from the Organization Group drop-down menu.
Techseals is the top-level organization group. - In the navigation pane on the left, select Resources > Profiles & Baselines > Profiles.
- Review the profiles that appear in the Profile list.
- iOS Exchange Email
- iOS Passcode
- iOS Restrictions
- Windows Device Encryption
- Windows Exchange Email
- Windows User Auth
- Windows Wallpaper
| NOTE |
|---|
| The profiles have different assignment groups. The relevant profile in this scenario is the Windows Device Encryption profile. |
- In the Windows Device Encryption profile row, click View under Installed Status. The number of assigned devices is 1 and the number of installed devices is also 1. However, the correct number for each should be 2 because there is a Windows Desktop device enrolled in this environment.
- In the navigation pane on the left, select Groups & Settings > Groups > Assignment Groups.
- Click the NA Sales smart group hyperlink. The Edit Smart Group dialog box appears.
- Next to Device Preview, click Enabled. The smart group does not include the device for user Craig.
- Scroll down to the bottom of the navigation pane on the left and expand Exclusions. The user Craig is selected as an excluded user.
- Deselect the Craig user check box.
- Verify that the Windows endpoint enrolled with the Craig user account now appears under Device Preview.
- Click Next. The View Assignments window appears.
- Click Publish.
- In the Workspace ONE UEM console, select Resources > Profiles & Baselines > Profiles in the navigation pane on the left.
- In the Windows Device Encryption profile row, click View under Installed Status.
- Verify that the number of assigned devices now shows 2.
- In the navigation pane on the left, select Devices > Devices. This brings you to Devices List View page.
- To access the Device Details page for Craig's device, click the device name hyperlink under General Info.
- Select the Profiles tab.
- Hover over the Status icon (greyed out checkmark) for the Windows Device Encryption profile and verify that the status of the Windows Device Encryption profile is now Pending Install.
| NOTE |
|---|
| Profiles take up to two minutes to install. You can try refreshing the browser to update the installation status. |
- The encryption profile requires a password to be set if no TPM is available in the device. Connect to the device and provide the input.
- From the lab environment interface, click on the dropdown at the top-left of the screen, where it probably says, "uem-01a", and select w11Client-01a.
- A screen, showing the time, appears. Click anywhere on that screen.
- Log into w11Client-01a:
- Username: Techseals\Craig
- Password: Pa$$w0rd
- Open the Intelligent Hub app. It may also open on its own.
- When the BitLocker Encryption screen appears, enter Pa$$w0rd in the Password box and the Confirm Password box.
- Click Encrypt
- At the bottom-left side of the Intelligent Hub screen, click on Craig Stroser.
- Click Sync Device. In about 15 seconds, it will say, "Sync has completed".
- Return to the Workspace ONE UEM console on the uem-01a VM. (Note: You may have to go through the login steps again.)
- Verify that the status of the Windows Device Encryption profile is now Installed (Green checkmark). (Note: You may have to refresh the browser.)
0 Comments
Add your comment