Lab 4: Troubleshooting Endpoints
Objective and Tasks
Resolve various problems related to enrollment and endpoints:
- Restore Device Enrollment with Directory Accounts
- Verify Device Communication with the Workspace ONE UEM Console
- Enable Targeted Logging for Devices
Task 1: Restore Device Enrollment with Directory Accounts
Scenario: After importing a directory user account to enroll a new device into the Asia Pacific Japan organization group (OG), the user received an Invalid User Credentials error message.
In the Workspace ONE UEM environment, you verified that AirWatch Cloud Connector and directory services are connected, and you verified that enrollment with directory user accounts works for the North America OG.
You help the administrator troubleshoot an endpoint enrollment issue in the Asia Pacific Japan OG.
- From the lab environment interface, log into the uem-01a VM.
- Username: techseals\administrator
- Password: Pa$$w0rd
- Open the Workspace ONE UEM administration console.
- On the uem-01a VM Windows taskbar, click the Google Chrome icon.
- From the bookmarks bar, select UEM.
You can also enter https://wsone.techseals.co/AirWatch in the address bar to access the console page. - Log in to Workspace ONE UEM:
- User name: admin
- Password: Pa$$w0rd
- On the Workspace ONE UEM console menu bar, select Asia Pacific Japan from the Organization Group drop-down menu.
- In the navigation pane on the left, select Groups & Settings > All Settings > Devices & Users > General > Enrollment.
- On the Authentication tab, make sure that Override is selected for Current Setting.
- Next to Authentication Mode(s), select the Directory check box.
- Scroll down and click Save.
- Click x in the upper-right corner to close the Settings dialog box.
- Connect to the w11Client-02a VM.
- Log in with the
- User: Nancy
- Password: Pa$$w0rd
- On the w11Client-02a desktop, double click the Workspace ONE Intelligent Hub icon in the Taskbar or search for Intelligent Hub in the start menu.
The Workspace ONE Intelligent Hub application should open with an Email or Server Address prompt.
| NOTE |
|---|
| If the Intelligent Hub application does not load the enrollment screen or does not display correctly, you go to Start > Settings > Apps > Apps & features to uninstall the Workspace ONE Intelligent Hub and Workspace ONE Intelligent Hub Installer applications. |
| After the applications are uninstalled, you go to https://getwsone.com in a web browser to download and install the latest version of the Workspace ONE Intelligent Hub application installer. |
- If you receive a prompt from the User Account Control to permit the application to change the w11Client-02a VM, click Yes.
- Configure the Workspace ONE UEM settings in the Workspace ONE Intelligent Hub application.
- Enter wsone.techseals.co in the Email or Server Address text box.
- Click Next.
- Enter APAC in the Group ID text box.
- Click Next.
- Log in to Workspace ONE Intelligent Hub.
- User name: Nancy
- Password: Pa$$w0rd
You are authenticated and the Workspace ONE Intelligent Hub application begins enrolling the device.
| NOTE |
|---|
| The enrollment process can take up to 5 minutes to finish. |
- Click Not Now on the Want an even better experience? page.
- Click Done when the Congratulations message appears.
- Click Get Started on the Hello, Nancy window.
Task 2: Verify Device Communication with the Workspace ONE UEM Console
You perform a manual device synchronization on the newly enrolled Windows endpoint.
- Open the Workspace ONE UEM administration console.
- On the uem-01a Windows taskbar, click the Google Chrome icon.
- If prompted, log in to Workspace ONE UEM.
- Username: admin
- Password: Pa$$w0rd
- On the menu bar, select Asia Pacific Japan from the Organization Group drop-down menu.
- In the navigation pane on the left, select Devices > Devices.
- Locate the newly enrolled Windows endpoint. for Nancy
- Verify that the value under the Last Seen column is less than 5 minutes.
- If the Last Seen value is greater than 5 minutes, force a synchronization from the Windows endpoint.
- Switch to the w11Client-02a VM.
- On the w11Client-02a VM desktop, double-click the Workspace ONE Intelligent Hub shortcut.
- In the Workspace ONE Intelligent Hub window, click on Nancy at the bottom-left of the screen.
- Click Sync Device.
- Return to the uem-01a Windows VM, and go back to the Workspace ONE UEM Admin console.
- In the navigation pane on the left, select Devices > Devices.
- If the Last Seen value did not update, refresh the Workspace ONE UEM Admin console page.
- Verify that the Last Seen value of the enrolled Windows device is less than 5 minutes.
Task 3: Enable Targeted Logging for Devices
Scenario: Recently, latency is being reported for the enrolled device of user Craig. Profiles and applications take too much time to download and install, and the device's status is not reported to Workspace ONE UEM in a timely manner. So far, this enrolled device is the only one with this problem.
Root cause: Because only one device is having the latency problem, the issue is most likely specific to the affected device.
You enable Targeted Logging for the affected device.
- Open the Workspace ONE UEM administration console.
- On the uem-01a Windows taskbar, click the Google Chrome icon.
- If prompted, log in to Workspace ONE UEM.
- User name: admin
- Password: Pa$$w0rd
- On the Workspace ONE UEM console menu bar, select Techseals from the Organization Group drop-down menu.
- In the navigation pane on the left, select Devices > Devices.
- On the Devices List View page, click the Craig W11CLIENT-01A hyperlink.
The Details View for the device appears. - Click on More from the drop-down tab, select Targeted Logging.
The Targeted Device Logging page appears. - Enable Targeted Logging for the selected Windows device for 1 hour.
- Click the CREATE NEW LOG button.
- Select 1 Hour.
- Click Start.
Targeted Logging is started for the selected device for 1 hour. The Targeted Logging stops after 1 hour or after you click Stop.
After Targeted Logging stops, a log file is generated on the UEM Device Services server:- If your Workspace ONE UEM console is SaaS hosted, you must contact the support team to retrieve the targeted log for you.
- If your Workspace ONE UEM console is hosted on-premises, you can collect the targeted log from the Device Services server by navigating to the UEM_installation_path\Logs\Targeted Logging folder.
- Close Google Chrome.
0 Comments
Add your comment