Lab 5: Device enrollment
Objective and Tasks
- Enable Directory Authentication Enrollment
- Define grouping
- Define a Terms of Use policy
- Define privacy settings
- Enroll a Windows Desktop device using Hub Enrollment
- Enroll a Windows Server device using scripted enrollment
- Enroll a Linux Device
- Verify the Assignment Group
- Navigate the Workspace ONE Intelligent Hub Application
- Configure Windows Multi-User on a Windows Desktop device
Task 1: Enable Directory Authentication
You enable directory authentication to support device enrollment with directory accounts.
Open the Workspace ONE UEM administration console.
On the ControlCenter Windows taskbar, click the Google Chrome icon.
From the bookmarks bar, select Workspace ONE UEM. You can also enter
https://omnissatraining.awmdm.com/Airwatchin the address bar to access the console page.
Log in to Workspace ONE UEM.
User name:
studentadmin{labid}Password:
Pa$$w0rd
In the upper-right corner of the console, click the drop-down menu with your administrator name and verify that Student{labid} organization group is selected from the Organization Group drop-down menu.
In the navigation pane on the left, select Groups & Settings. Then, select All Settings > Devices & Users > General > Enrollment.
On the Authentication tab, click Override next to Current Setting.
Next to Authentication Modes(s), make sure Basic and Directory are checked.
Next to Source of Authentication for Intelligent Hub, click Workspace ONE UEM.
Note: This should be selected by default. In a later lab we will also showcase authentication with Access.
Click Save.
On the Restrictions tab, click Override next to Current Setting.
Next to User Access Control, de-select Restrict Enrollment To Known Users.
a. Note: This will allow users, who have not been synced into UEM, to be synced when they enroll a device.
Click Save.
Task 2: Define grouping
You define the organization group (OG) assignment mode for enrolling devices.
Grouping permits Workspace ONE UEM to place the devices into the correct OGs based on your configuration.
In the upper-right corner of the console, click the drop-down menu with your administrator name and verify that Student{labid} organization group is selected from the Organization Group drop-down menu.
In the Settings dialog box, select Groups & Settings. Then, select All Settings > Devices & Users > General > Enrollment in the navigation pane on the left.
Click the Grouping tab.
Next to Current Setting, click Override.
Next to Group ID Assignment Mode, verify that Default is selected.
Click Save.
Task 3: Define a Terms of Use policy
You define the terms of use policy for the devices to be enrolled.
In the upper-right corner of the console, click the drop-down menu with your administrator name and verify that Student{labid} organization group is selected from the Organization Group drop-down menu.
In the Groups & Settings dialog box, select All Settings > Devices & Users > General > Enrollment in the navigation pane on the left.
Click the Terms of Use tab.
Next to Current Setting, click Override.
Next to Require Enrollment Terms of Use Acceptance, click Enabled and then click Save.
When an Enrollment Terms of Use policy is required, all device users must accept the Terms of Use during enrollment. If a Terms of Use policy is not set, the Terms of Use from a parent OG is enforced, if it has one.
Click Add New Enrollment Terms of Use.
Enter
Custom Terms of Usein the Name text box.Review all settings, such as enforcing the policy for specific platforms, device ownership types, and enrollment types.
If you exclude the device that you plan to enroll, the Terms of Use are not shown during your enrollment in later lab activities.
(Optional) Click the Select Language drop-down menu to change the language. The default language is English.
In the text editor, enter
This is a test terms of use for the Workspace ONE training courseand click Save.Click Save.
Task 4: Define privacy settings
When you enroll your device, the Workspace ONE UEM console default is to enroll it as an employee-owned device.
In the upper-right corner of the console, click the drop-down menu with your administrator name and verify that Student{labid} organization group is selected from the Organization Group drop-down menu.
In the Settings dialog box, select Groups & Settings. Then, select All Settings > Devices & Users > General > Privacy in the navigation pane on the left.
Next to Current Setting, click Override.
Scroll down to the Applications section.
In the Personal Application row, change the setting for Employee Owned to Collect Do Not Display.
By changing this setting to Collect and Display, you can gather user data and make the data visible in the Workspace ONE UEM console
By changing this setting to Collect Do Not Display, you can collect user data for use in reports and compliance, but data is not displayed within the Workspace ONE UEM console.
By changing this setting to Do Not Collect, you can prevent user data from being shown in both the Workspace ONE UEM console and in generated reports.
When you enroll your device, the Workspace ONE UEM console default is to enroll it as a Corporate - Dedicated device. Enrollment results in personal applications being shown in the device details under the Application section. To prevent your personal applications from appearing in the Workspace ONE UEM console, you change the setting to Do Not Collect and click Save.
Click Save.
Enter
1234if you are asked to enter a security PIN.Review all remaining privacy settings, including whether the Workspace ONE UEM administrator can remotely erase a device (factory wipe), remote control a device based on ownership, display user information, and so on.
Close the Settings dialog box.
Task 5: Enroll two Windows Desktop devices using Hub Enrollment
You use the Workspace ONE Intelligent Hub application to enroll two Windows VMs to your Workspace ONE UEM environment.
- From the VM Switcher, select Win11Client-01.
- If you receive a prompt to log in to, enter the password for the local account.
- User name:
administrator - Password:
Pa$$w0rd
- User name:
- If a "Get even more out of Windows" dialog box appears, click Skip for now.
- From the Win11Client-01 VM desktop, open Google Chrome.
- Go to
https://getwsone.comand click Download Hub for Windows x86/x64. - After 2 minutes, you should find the AirwatchAgent in the Downloads folder of File Explorer in the Win11Client-01 VM.
- Double-click AirwatchAgent to start the installation.
- Click Next.
- Click I accept the terms in the license agreement and click Next.
- Click Install.
- Click Finish.
- Click the Windows Start menu and select Administrator in the lower left corner.
- Click Sign Out.
- On the Logon screen, log in as craig.
- User name:
omnissatraining\craig - Password:
Pa$$w0rd
- User name:
- The Workspace ONE Intelligent Hub application will automatically open once you have logged in..
- If it does not open, you can click the W11Client-01 Start menu to open Workspace ONE Intelligent Hub manually.
- Enter your Workspace ONE UEM enrollment information in the Workspace ONE Intelligent Hub application.
- Enter
omnissatraining.awmdm.comin the Email or Server Address text box. - Click Next.
- Enter
student{labid}in the Group ID text box. - Click Next.
- Enter
craigin the username text box. - Enter
Pa$$w0rdin the password text box. - Click Sign In.
- If a "Want an even better experience?" message appears, click Not Now.
- When the Congratulations dialog box appears, click Done.
- To complete enrollment, click Get Started.
- On the ControlCenter Windows taskbar, click the Google Chrome icon to return to the Workspace ONE UEM console.
- In the navigation pane at the top, select Devices. Then, select Devices from the menu on the left. The Craig Desktop Windows VM should appear in the list.
- From the VM Switcher, select Win11Client-02.
- If you receive a prompt to log in to, enter the password for the local account.
- User name:
administrator - Password:
Pa$$w0rd
- User name:
- If a "Get even more out of Windows" dialog box appears, click Skip for now.
- From the Win11Client-01 VM desktop, open Google Chrome.
- Go to
https://getwsone.comand click Download Hub for Windows x86/x64. - After 2 minutes, you should find the AirwatchAgent in the Downloads folder of File Explorer in the Win11Client-02 VM.
- Double-click AirwatchAgent to start the installation.
- Click Next.
- Click I accept the terms in the license agreement and click Next.
- Click Install.
- Click Finish.
- Click the Windows Start menu and select Administrator in the lower left corner.
- Click Sign Out.
- On the Logon screen, log in as nancy.
- User name:
omnissatraining\nancy - Password:
Pa$$w0rd
- User name:
- The Workspace ONE Intelligent Hub application will automatically open once you have logged in.omnissatraining
- If it does not open, you can click the W11Client-01 Start menu to open Workspace ONE Intelligent Hub manually.
- Enter your Workspace ONE UEM enrollment information in the Workspace ONE Intelligent Hub application.
- Enter
omnissatraining.awmdm.comin the Email or Server Address text box. - Click Next.
- Enter
student{labid}in the Group ID text box. - Click Next.
- Enter
nancyin the username text box. - Enter
Pa$$w0rdin the password text box. - Click Sign In.
- If a "Want an even better experience?" message appears, click Not Now.
- When the Congratulations dialog box appears, click Done.
- To complete enrollment, click Get Started.
- On the ControlCenter Windows taskbar, click the Google Chrome icon to return to the Workspace ONE UEM console.
- In the navigation pane at the top, select Devices. Then, select Devices from the menu on the left. The Nancy Desktop Windows VM should appear in the list.
Task 6: Enroll a Windows Server device using scripted enrollment
You enroll a Windows Server device using scritped enrollment.
Open the Workspace ONE UEM administration console.
On the ControlCenter Windows taskbar, click the Google Chrome icon.
From the bookmarks bar, select Workspace ONE UEM. You can also enter
https://omnissatraining.awmdm.com/Airwatchin the address bar to access the console page.
Log in to Workspace ONE UEM.
User name:
studentadmin{labid}Password:
Pa$$w0rd
In the upper-right corner of the console, click the drop-down menu with your administrator name and verify that Servers organization group is selected from the Organization Group drop-down menu.
In the navigation pane on the left, select Groups & Settings. Then, select All Settings > Devices & Users > General > Enrollment.
On the Management Mode tab, click Override next to Current Setting.
Next to Windows, make sure No OMADM Management is selected.
Next to Management Mode, select the button for Intelligent Hub Managed Mode.
Select Enabled next to All Windows devices in this Organization Group.
Click Save.
On the Grouping tab, click Override next to Current Setting.
From the dropdown menu for Default Action For Inactive Users, select Restrict Additional Device Enrollment.
Click Save.
In the navigation on the left, select Devices and Users. Then select General > Shared Device.
Click Override.
Navigate to the Grouping tab.
Enable Fixed Organization Group for the Group Assignment Mode.
Click Save.
In the navigation on the left, select Devices & Users. Then, select Microsoft > Windows > Intelligent Hub Settings.
Click Override next to Current Setting.
Scroll down to Default User Mode for Enrollment. From the dropdown menu for Windows Enrollment User Mode, select Single User Mode.
Click Save.
Close the All Settings windows by cllicking the X in the upper right corner.
From the VM Switcher, select WS2025-Server.
If you receive a prompt to log in to, enter the password for the local account.
Username:
administratorPassword:
Pa$$w0rd
Navigate to C:\Resources.
Double-Click the Update Group ID file.
Type your assigned Group ID. For example:
Student########(Note: Make sure to preface the Group ID with "Student")
Make sure to preface the Group ID with "Student".
Click OK.
Then click OK to the Replacement complete... message.
Right-click on the newly created file, Right-Click Me and choose Run As Administrator batch file, And choose Run As Administrator.
Enter:
Username:
AdministratorPassword:
Pa$$w0rd
Click Yes.
A command window will appear briefly for about a minute and then go away on its own. This starts the enrollment process.
You will have to wait about 2 minutes while the device enrolls. There will be no visible progress while the enrollment is happening.
- While silent enrollment is in progress, take a look at the script. Go to C:\Resources\Right-click me and choose Run As Administrator. Right-click and select Edit in Notepad. Do not click Open. Note the parameters that have been embedded within the script. Close Notepad after viewing.
Task 7: Enroll a Linux Device
You use the Workspace ONE Intelligent Hub application to enroll a Linux VM to your Workspace ONE UEM environment.
- Select the Linux-01 VM from the drop-down at the top-left area of your window.
- Log in to the Linux-01 VM.
- User name:
Administrator - Password:
Pa$$w0rd
- User name:
- This will bring you to the desktop of the Ubuntu Linux machine.
- On the left-side bar, click on the Terminal icon (The icon looks like a Command Prompt)
- This will bring up the command-line interface window.
- The Intelligent Hub Debian has been pre-downloaded into the downloads folder.
- Now let's run the installation command. Type the following:
sudo apt install "./Downloads/workspaceone-intelligent-hub-amd64-25.06.0.23.deb"
- Click enter after the you input the command.
- Now enter the password (Note: The password will not be visible when you type)
- Type
Pa$$w0rd - Click enter.
- Type
- When prompted to approve installation of packages type Y and hit enter.
- The Workspace ONE Intelligent Hub application will be installed to the Linux VM.
- Run the following cd command to navigate to the Hub binary directory under the installation directory.
cd "/opt/omnissa/ws1-hub/bin"
- Hit enter on your keyboard
- Run the following sudo command to use the ws1HubUtil utility.
sudo ./ws1HubUtil enroll --server https://ds1605.awmdm.com
- Hit enter on your keyboard.
- You will then be prompted for the OrganizationGroup:
- Type
Student{labid} - Hit enter on your keyboard.
- Type
- You will now be prompted for the UserName:
- Type
studentuser{labid} - Hit enter on your keyboard.
- Type
- Then the Password
- Type
Pa$$w0rd - Hit enter on your keyboard
- Note: Wait about 15 seconds for the device to enroll.
- Type
- You should see a message, confirming the "Workspace ONE Intelligent Hub enrollment completed successfully."
- Return to the Workspace ONE UEM console in the ControlCenter VM.
- In the navigation pane at the top, select Devices. Then, select Devices in the menu on the left.
- The Linux VM should appear in the list. If not, you might need to refresh the page.
Task 8: Verify the Assignment Group
You verify that the enrolled devices are automatically included in the correct assignment groups.
In the upper-right corner of the console, click the drop-down menu with your administrator name and verify that Student{labid} organization group is selected from the Organization Group drop-down menu.
- In the navigation plane on the left, select Groups & Settings. Then, under Groups, select Assignment Groups.
- Verify that a number appears in the Devices column for the respective Smart Groups.
Task 9: Navigate the Workspace ONE Intelligent Hub Application
You navigate the Workspace ONE Intelligent Hub application and become familiar with the Hub Catalog user interface.
- From the VM Switcher, select Win11Client-01.
- If you receive a prompt to log in to, enter the password for the local account.
- User name:
omnissatraining\craig - Password:
Pa$$w0rd
- User name:
- Click the Start menu and open Workspace ONE Intelligent Hub.
- If you are prompted to sign in again into the Intelligent Hub
- Ensure that omnissatraining.com is selected from the Select your domain drop-down menu.
- Click Next.
- Enter
craigin the username text box. - Enter
Pa$$w0rdin the password text box.
Either the Apps or the Favorites page appears when the application opens.
No assigned applications appear yet because you have not deployed resources to any devices. This is covered in a later lab.
- If the Always Accessible window appears, click Got It.
- In the Workspace ONE Intelligent Hub application, review the available menu options.
- Favorites
- Apps
- For You
- Support
- User icon
- To open the device information page, click Craig Stroser in the bottom-left corner.
- Here you can view information about Enrollment, Compliance, Network, Profile, and Support.
- To synchronize with the Workspace ONE UEM console, click Sync Device.
The Workspace ONE Intelligent Hub application performs periodic automatic background syncs with the Workspace ONE UEM console.
The Sync Device control serves as a manual approach to trigger an immediate one-time sync with the Workspace ONE UEM console.
- Minimize the Remote Desktop Connection window.
Task 10: Configure Windows Mulit-User on a Windows Desktop device
You enable Windows Mutli-User on a Windows Desktop device.
From the ControlCenter VM, in the Workspace ONE UEM console, navigate to Groups & Settings > All Settings > Devices & Users > Microsoft > Windows > Intelligent Hub settings.
Click Override.
Expand the section for Attributes for Unique Identifier.
Set UEM Attributes to User Principal Name.
Set Client Attributes to User Principal Name.
Click Save.
Close Intelligent Hub Settings window.
The Shared Device Grouping setting controls how to map a device to the right Organization Group. To avoid prompting for OG and enabling silent reassignment, “Fixed Organization Group” should be configured.
Within the Workspace ONE UEM console, open Groups & Settings.
Navigate to All Settings > Devices and Users > General > Shared Device.
Click Override.
Navigate to the Group Assignment Mode section.
Enable Fixed Organization Group.
Click Save.
Close the Shared Device window.
In Workspace ONE UEM console, go to Devices > Devices.
Click Layout. Select Custom from the options provided.
Scroll through the available columns until you find Windows User Mode.
Confirm that your enrolled Windows Desktop devices shows Multi User.
Multi User is the default regsitration mode in Workspace ONE UEM version 2406 and 2410.
Click on the Friendly Name of the Craig... Windows computer
In the upper right corner, select More Actions.
Scroll down to the Admin section and click Single User Mode.
You will receive a message that says, "Request to pause the device reassignment was success."
Click OK to the message. The device is queued for Single user assignment.
In the Workspace ONE UEM console, go to Devices > Devices.
Select the double right arrows next to Filters.
Select Advanced > Windows User Mode.
Check Single User (Legacy) and Multi User Capable.
Click Apply. Note that no records were found.
Uncheck Single User (Legacy) and Multi User Capable.
Check Single User and Multi User.
Click Apply. Note that the Windows mode setting for one VM is shown as Single User and the other VM is shown as Multi User.
Using the VM Switcher, log into the w11Client-02 device, and then restart it.
After the device reboots, select Other user in the lower left corner of the login screen.
Designate the user as
omnissatraining\CraigandPa$$w0rd.Because this device is enabled for multi User, you will have to wait about 1 minute for the device to automatically enroll for Craig.
When it is done, you will be presented with the Want an even better experience screen.
Click Not Now. From the Hello, Craig window, click Get Started.
The Hello, Craig screen validates that enrollment has now flipped to Craig.
Logout of the Win11Client-02 desktop and log back in as Nancy.
0 Comments
Add your comment