Lab 4: Enterprise integrations

Objective and Tasks

  1. Install and Configure AirWatch Cloud Connector
  2. Configure Directory Services in Workspace ONE UEM
  3. Import a User Group
  4. Configure a service account for Windows Server enrollment
  5. Adding a Certificate Authority Integration Configuration

Task 1: Install and Configure AirWatch Cloud Connector

You will install AirWatch Cloud Connector on the WS1-Connector VM and connect it to your Workspace ONE deployment.

  1. Using the VM Switcher, switch to the WS-Connector VM.
  2. Log in to the WS1-Connector VM.
    • User name: administrator
    • Password: Pa$$w0rd
  3. On the WS1-Connector Windows taskbar, click the Google Chrome icon.
  4. If you get an “Enhanced ad privacy in Chrome” screen, click More and then click Got it.
  5. From the bookmarks bar, select Workspace ONE UEM. You can also enter https://omnissatraining.awmdm.com/Airwatch in the address bar to access the console page.
  6. Log in to Workspace ONE UEM.
    • User name: studentadmin{labid}
    • Password: Pa$$w0rd
    • Note: If you get a pop-up to save the password just select Never.
  7. In the upper-right corner of the console, click the drop-down menu with your administrator name and verify that Student{labid} organization group is selected from the Organization Group drop-down menu.

  8. In the navigation pane at the top, select Groups & Settings. Then, select All Settings > System > Enterprise Integration > Cloud Connector.
  9. Next to Current Setting, click Override.
  10. Next to Enable AirWatch Cloud Connector, click Enabled. This should be selected by default.
  11. Click the Advanced tab.
  12. Scroll down and verify that Use External AWCM URL is selected.
  13. Scroll down to the bottom of the page, and click Save. The process concludes with a "Saved Successfully" message.
  14. Click the General tab and at the bottom of the window, click Download AirWatch Cloud Connector Installer.
  15. In the dialog box, enter Pa$$w0rd as the password.
  16. Enter Pa$$w0rd again to confirm the password.
  17. Click Download.  The download could take a minute.
  18. After the download finishes, click the File Explorer icon on the WS1-Connector Windows taskbar.
  19. Navigate to the Downloads folder.  Inside, you will see the AirWatch Cloud Connector...Installer.
  20. Right-click the AirWatch Cloud Connector...Installer file and select Run as administrator.

The AirWatch Cloud Connector installation wizard opens.

If you are prompted with a Windows security warning, click More Info and then click Run Anyway.

  1. Click Next.

The AirWatch Cloud Connector installer might require the installation of Microsoft .NET Framework 4.8 or later. You might be required to restart the DC VM. When you log back in to the VM, the AirWatch Cloud Connector installer automatically opens. If it did not open, you must rerun the AirWatch Cloud Connector installer as an administrator.

  1. Click I accept the terms in the license agreement and then click Next.
  2. Click Next. You do not need to change the installation path.
  3. Enter Pa$$w0rd in the Certificate Password text box.
  4. Click Next.
  5. Verify that the Outbound proxy? check box is deselected and click Next.
  6. Click Install.
  7. When the prompt says that TLS 1.2 registry keys were added, click OK.
  8. When the installation finishes, click Finish.
  9. If you receive a prompt to restart the server, click Yes. Wait about 1 minute for it to restart.
  10. Reconnect to the WS1-Connector VM.  If prompted, enter the following credentials
    • User name: administrator
    • Password: Pa$$w0rd
  11. On the WS1-Connector Windows taskbar, click the Server Manager icon.
  12. From the menu bar, select Tools > Services.
  13. Verify that the AirWatch Cloud Connector service is running. The service might take up to 10 seconds to start.
  14. If necessary, right-click AirWatch Cloud Connector and select Start to manually start the service.
  15. If the service does not start, open File Explorer, navigate to C:\AirWatch\Logs\CloudConnector, and check the log file for errors.

You must set Startup Type to Automatic and not Automatic Delayed. Otherwise, the service does not start automatically.

  1. Close the Services window.
  2. Close the Server Manager window.
  3. Return to the Workspace ONE UEM console in Google Chrome.  If you see Enhanced Data Privacy, Click More, then click Got it.
  4. If the Settings dialog box is closed, select Groups & Settings from the navigation pane at the top. Then, select All Settings > System > Enterprise Integration > Cloud Connector from the navigation pane on the left.
  5. Scroll down to the bottom of the Cloud Connector page and click Test Connection to verify connectivity.
  6. A successful connection returns a "Reached Cloud Connector running version 24.x..." message.
  7. Close the Settings dialog box.

Task 2: Configure Directory Services in Workspace ONE UEM

You configure the Directory Services integration in the Workspace ONE UEM console to bind with the Domain Controller (DC).

  1. On the ControlCenter VM, log in to the Workspace ONE UEM console.
    • User name: studentadmin{labid}
    • Password: Pa$$w0rd
  2. In the upper-right corner of the console, click the drop-down menu with your administrator name and verify that Student{labid} organization group is selected from the Organization Group drop-down menu.
  3. In the navigation pane at the top, select Groups & Settings. Then, select All Settings > System > Enterprise Integration > Directory Services.
  4. Verify that Current Setting is set to Override.
  5. Click Skip wizard and configure manually.
  6. On the Server tab, configure your server information with the following, and leave the default value for any setting not specified here.
OptionAction
Directory TypeSelect LDAP - Active Directory from the drop-down menu.
DNS SRVClick Disabled.
ServerEnter controlcenter.omnissatraining.com in the text box.
Encryption TypeClick None.
PortEnter in the 389 text box.
Protocol VersionEnter in the 3 text box.
Use Service Account CredentialsClick Disabled.
Bind Authentication TypeClick GSS-NEGOTIATE.
Bind UsernameEnter administrator in the text box.
Bind PasswordEnter Pa$$w0rd in the text box, after clicking the CHANGE button.
DomainDelete defaultDomain and enter omnissatraining.com in the text box.
ServerThe text box autofills controlcenter.omnissatraining.com after you click inside it.
  1. Click Test Connection to verify connectivity. A Connection successful message appears.
  2. Click x in the upper-right corner to close the Text Connection dialog box.
  3. Click Save.
  4. Click the User tab and configure the settings.
  5. Under Base DN, click the plus (+) sign icon next to the text box. The Available Base DNs drop-down menu appears.
  6. From the Available Base DN drop-down menu, select DC=omnissatraining,DC=com.
  7. Click Save.
  8. Click the Group tab and configure the settings.
  9. Under Base DN, click the plus (+) sign icon next to the text box. The Available Base DNs drop-down menu appears.
  10. From the Available Base DNs drop-down menu, select DC=omnissatraining,DC=com.
  11. Click in the Settings dialog box to close the Available Base DNs drop-down menu.
  12. Delete organizationalUnit and enter Container in the Organizational Unit Object Class text box.
  13. Click Advanced to expand and display additional controls.
  14. Make sure the Auto Sync Default and Auto Merge Default check boxes are checked.

Enabling these settings automatically adds or removes users in Workspace ONE UEM configured user groups based on their membership in your directory service and automatically applies synchronization changes without requiring an administrator's approval.

  1. Scroll down to the Attribute and Mapping Value columns.

These columns show the mapping between the Workspace ONE UEM user attributes on the left and your directory service attributes on the right. By default, these attributes are those values most commonly used in the Active Directory. You update these mapping values to reflect the values used for your own integration.

  1. Click the Edit (pencil) icon next to the Organizational Unit text box.
  2. Delete ou and enter cn in the Organizational Unit text box.
  3. Click Save.
  4. Scroll down and click Test Connection to verify the configuration.

You might have to refresh the page and attempt the test connection after the page has refreshed.

  1. Close the Test Connection dialog box.
  2. Close the Settings dialog box.

Task 3: Import a User Group

You use the Workspace ONE UEM console to import a user group.

  1. In the upper-right corner of the console, click the drop-down menu with your administrator name and verify that Student{labid} organization group is selected from the Organization Group drop-down menu.

  2. In the navigation pane at the top, select Accounts. Then, under Users, select Users Groups.
  3. From the Add drop-down menu, select Add User Group.
  4. Next to External type, click Organizational Unit.
  5. Verify that DC=omnissatraining,DC=com is entered in the Group Base DN text box. The attribute must not contain any spaces.
  6. In the Search Text text box, enter users and click Search. The page refreshes and displays additional items.
  7. Select Users from the Group Name search result list.
  8. Leave the default values for the other settings and click Save.

The page refreshes and you are back to the User Groups list view page. You now see the new user group called Users.

When you import a user group, you add your existing directory service groups into the Workspace ONE UEM console. The addition does not immediately create the Workspace ONE UEM user accounts for each of your directory service accounts. However, it does ensure that the Workspace ONE UEM recognizes them as belonging to a configured group, which you can use as a means of restricting who can enroll.

  1. Select the Users check box.
  2. From the More Actions drop-down menu, select Add Missing Users. A dialog box appears asking if you wish to continue.
  3. To process the request, click OK.
  4. Click the Refresh button (or refresh the web page), and verify that the number in the Users column is greater than 0.
  5. Click the Edit (pencil) icon next to the Users group name. The Edit User Group page dialog box appears.
  6. Next to Add Group Members Automatically, click Enabled.
  7. Click Save.

You have successfully imported the Active Directory users into the Workspace ONE UEM console.

Task 4: Configure a service account for Windows Server enrollment

Configure a service account in the Servers OG for device enrollment.

  1. In the upper-right corner of the console, click the drop-down menu with your administrator name and verify that Student{labid} organization group is selected from the Organization Group drop-down menu.

  2. In the navigation pane at the top, select Accounts. Then, select Users.
  3. Click the Edit (pencil) icon next to the user named ws-account.
  4. Expand Enrollment.
  5. Click on the field next to Enrollment Organization Group.
  6. From the dropdown, select Student{labid} / Servers.
  7. Click Save.

Task 5: Adding a Certificate Authority Integration Configuration

You review the certificate authority (CA) integration configured for the lab environment.

  1. In the upper-right corner of the console, click the drop-down menu with your administrator name and verify that Student{labid} organization group is selected from the Organization Group drop-down menu.

  2. In the navigation pane at the top, select Groups & Settings. Then, select All Settings > System > Enterprise Integration > Certificate Authorities.
  3. Click on Add.
  4. In the Certificate Authority - Add/Edit fill in the following
    • Name: omnissatraining
    • Authority Type: Microsoft ADCS
    • Protocol: ADCS
    • Server Hostname: controlcenter
    • Authority Name: omnissatraining-CONTROLCENTER-CA
    • Authentication: Service Account
    • Username: Administrator
    • Password: Pa$$w0rd
  5. Click Test Connection.

The "Test connection" may be unsuccessful because this task only demonstrates the procedures to follow when you plan to connect to a Certificate Authority.

  1. Click SAVE.
  2. You should now see your omnissatraining certificate authority listed in the Certificate Authorities.

0 Comments

Add your comment

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.