Windows Server Enrollment

Lab overview

In this lab, you will prepare Workspace ONE UEM to accept Windows Server enrollments and then enroll a Windows Server device using scripted (silent) enrollment. You will start by creating the Servers Organization Group structure — a dedicated child OG, a scoped enrollment account, and Lab/Prod Smart Groups — before configuring the console-side settings that govern how Windows devices are managed, grouped, and assigned within that child OG. You will then run a pre-staged enrollment script on the Windows Server VM and confirm the enrollment process begins. 

Objectives

By completing this lab, you will be able to: 

  • Create a child Organization Group dedicated to Windows Server devices. 
  • Create a scoped account for use with Windows Server enrollments. 
  • Create Lab and Prod Smart Groups to separate Windows Server devices by purpose. 
  • Log in to the Workspace ONE UEM administration console and confirm the correct Organization Group is selected. 
  • Configure Intelligent Hub Managed Mode for Windows devices in the Servers Organization Group. 
  • Set the default action for inactive users to restrict additional device enrollment. 
  • Enable Fixed Organizational Group as the Group Assignment Mode for shared devices. 
  • Set the default Windows enrollment user mode to Single User Mode. 
  • Update a server's Group ID and run a scripted enrollment on a Windows Server VM. 
  • Review the enrollment script and understand the parameters embedded within it. 

Tasks in this lab

Task 1 — Windows Server pre-enrollment steps (child OG, enrollment account, Smart Groups) 

Task 2 — Configure console settings for Windows Server enrollment 

Task 3 — Enroll the Windows Server device using scripted enrollment 

Task 1 — Windows Server pre-enrollment steps

Before configuring enrollment settings or enrolling a device, the Servers Organization Group structure must exist. In this task, you will create a child OG dedicated to Windows Server devices, a scoped account for enrolling those servers, and two Smart Groups — Lab and Prod — to separate server devices by purpose. 

Step 1 - Create the child OG

  1. In the Workspace ONE UEM console, click your organization name in the top-left corner (or navigate to Groups & Settings > Groups > Organization Groups>OG Details
  2. Click Add Child Organization Group
  3. Enter a Name for the new OG as ServerOG######## (matching the convention used within your StudentAdmin name) 
  4. Set the Group ID to ServerOG######## (matching the convention used within your StudentAdmin name). 
  5. Set the Organization Group Type to Container
  6. Click Save

Step 2 - Create a new account for Windows Servers enrollments

In this lab, the account used for Windows Server enrollment is based on a Basic account.  In production, you should designate an Active Directory Service Account for this purpose for greater security and to reduce risk of deletion. 

  1. While in the new child ServerOG, Navigate to Accounts > Users > Users > Add > Add User 
  2. Change Security Type to Basic
  3. Designate the Username as ServerEnrollment.  Note that there is no space in between. 
  4. Designate the password as Pa$$w0rd and repeat in the Confirm Password box. 
  5. In the Full Name fields, enter Server as the First Name and Enrollment as the last name. 
  6. In the Display Name field, enter ServerEnrollment
  7. In the Email address field, enter [email protected]
  8. Click Save

Step 3 - Create Smart Groups for Windows Server devices

When creating Smart Groups for Windows Server devices, please note the following equivalents: 

  • Windows Server 2016 = Windows 10.0.14393 
  • Windows Server 2019 = Windows 10 0.17763 
  • Windows Server 2022 = Windows 10.0.20348 
  • Windows Server 2025 = Windows 10.0.26100 
  1. In the upper-left corner of the console, click the drop-down menu and verify that Student########/ServerOG######## is selected from the drop-down menu.  
  2. In the navigation pane at the top, select Groups & Settings > Groups > Assignment Groups (Smart Groups). 
  3. Click Add Smart Group
  4. Enter SG WinSvr 2025 Prod in the Name text box. 
  5. Leave Criteria selected and expand Platform and Operating System in the left pane. 
  6. In the top-left drop-down menu, select Windows, Equals, and Windows 11 (10.0.26100).   
  7. Expand Model Type in the navigation pane. 
  8. Click Selected and deselect Windows – Desktop and Windows – HoloLens such that Windows Server is the only option selected. 
  9. Click Save
  10. Repeat steps 3-9 to create a second Smart Group named SG WinSvr 2022 Test, but instead select Windows, Equals, and Windows 10 (10.0.20348). 

Checkpoint: Two Smart Groups — WinSvr 2025 Prod and WinSvr 2022 Test — exist and are scoped to the ServerOG######## child OG. 

Task 2 - Configure Console settings for Windows Server Enrollment

In this task, you will first confirm you are working in the Servers Organization Group, and configure the enrollment, grouping, and Hub settings that will govern how the Windows Server device behaves once enrolled. 

Step 1 — Log in to the Workspace ONE UEM administration console

  1. Continue within the Student########/ServerOG######## organization group.  Ensure that it is selected from the Organization Group dropdown menu in the upper left corner. 

Checkpoint: You are logged in to the Workspace ONE UEM console with the Servers organization group selected. 

Step 2 — Configure Management Mode

  1. In the navigation pane on the left, select Groups & Settings
  2. Select All Settings > Devices & Users > General > Enrollment
  3. Click the Management Mode tab, click Override next to Current Setting. 
  4. Next to Windows, make sure No OMADM Management is selected. 
  5. Next to Management Mode, select the button for Intelligent Hub Managed Mode
  6. For the “All Windows devices in this Organization Group” option, select Enabled
  7. Click Save

Checkpoint: Intelligent Hub Managed Mode is enabled for all Windows devices in the Servers organization group. 

Step 3 — Configure the default action for inactive users

  1. On the Grouping tab, click Override next to Current Setting. 
  2. From the dropdown menu for Default Action for Inactive Users, select Restrict Additional Device Enrollment
  3. Click Save. 

Checkpoint: This ensures that seemingly inactive user devices will not be subjected to device wipe.   

Step 4 — Configure Group Assignment Mode

  1. In the navigation pane on the left, select Devices and Users > General > Shared Device. 
  2. Click Override
  3. Navigate to the Grouping tab. 
  4. For the Group Assignment Mode option, enable Fixed Organization Group
  5. Click Save. 

Checkpoint: Fixed Organization Group is enabled as the Group Assignment Mode for shared devices. 

Note: This step is critical and enrollment will fail if not properly configured. 

Step 5 — Configure the default Windows enrollment user mode

  1. In the navigation pane on the left, select Devices & Users. Then, select Microsoft > Windows > Intelligent Hub Settings. 
  2. Click Override next to Current Setting. 
  3. Scroll down to Default User Mode for Enrollment. From the dropdown menu for Windows Enrollment User Mode, select Single User Mode
  4. Click Save. 
  5. Close the All Settings window by clicking the X in the upper-right corner. 

Checkpoint: Single User Mode is set as the default Windows enrollment user mode, and all console configuration for this task is complet

Task 3 - Prepare Windows Server apps

Deploying apps to Windows Servers is similar to Windows Desktop.  First, you will view the Onboarding Freestyle Orchestrator workflow that installs the CrowdStrike Falcon agent, which has been pre-configured for you.  Onboarding enables apps to be installed immediately following enrollment and prior to all other resources.  Then, you will modify two App Files to append Windows Server deployment and then deploy those apps and configure enrollment.

Step 1 - View Freestyle Orchestrator Onboarding workflow

  1. In the top left corner of the Workspace ONE UEM console, click the Organization Group selector in the console header. and validate that you are in the Parent OG. 
  2. Go to Orchestration > Freestyle > Freestyle Orchestrator
  3. Select the Install Falcon Sensor workflow to view and focus on the Overview pane.  Because this has been configured in a higher OG, you cannot see the full workflow or duplicate it, but you can note that the Deployment type is designated as Onboarding.   

Step 2 – Prepare App Files for deployment

  1. While still in the Parent OG, go to Resources > Apps > Native Apps
  2. In the Notepad++ entry, click the pencil icon to Edit the App File. 
  3. In the Details pane, scroll down to Supported Models.  Hover over the Server entry and press shift and click at the same time such that both Desktop and Server are selected.   
  4. Click Save & Assign. 
  5. On the Assignment screen, keep the default Assignment Groups option 
  6. Select the To whom do you want to assign this app field, and within the drop-down, select both the SG WinSvr 2025 Prod and SG WinSvr2022 2022 Test Smart Groups. 
  7. In the Deployment Begins, enter yesterday’s date. 
  8. For the App Delivery Method, change to Auto. 
  9. Set Deployment Begins to yesterday. 
  10. Enable Override Reboot Handling and ensure that both Device Restart and Uninstall Device Restart are set to Do not restart. 
  11. Set both Keep Application on Device options to Disable, which causes the app to be removed from Windows Server upon unassignment or enterprise wipe. 
  12. Click Create. 
  13. Click Save 
  14. Click Publish. 
  15. Back in the App list view, find the  PuTTY entry and click the pencil icon to open the App File. 
  16. In the Details pane, scroll down to Supported Models.  Hover over the Server entry and press shift and click at the same time such that both Desktop and Server are selected.   
  17. Click Save & Assign. 
  18. On the Assignment screen, click Add Assignment. 
  19. Designate the name as Notepad++ WinSvr Dist Sept 2026. 
  20. Select Phased Deployment. 
  21. In the Target Assignment Groups dropdown, select, SG WinSvr 2025 Prod and SG WinSvr 2022 Test and click Next. 
  22. In the Phase Name box, enter Phase 1, and in the Phase Target box, select SG WinSvr2022 Test from the dropdown. 
  23. Click Manual Progression. 
  24. Select Automatic Progression. 
  25. In the Install Rate box, type 100%. 
  26. On the Wait Time line, deselect the blue check mark.  This causes only the Install Rate to be used as the criteria. 
  27. Click Save in the upper right corner. 
  28. Set Deployment Begins to yesterday. 
  29. Enable Override Reboot Handling and ensure that both Device Restart and Uninstall Device Restart are set to Do not restart. 
  30. Set both Keep Application on Device options to Disable, which causes the app to be removed from Windows Server upon unassignment or enterprise wipe. 
  31. Click Create. 
  32. Click Save 
  33. Click Publish. 
  34. Back in the App list view, find the  7-Zip entry and click the pencil icon to open the App File. 
  35. Repeat steps 16-33 except designate the name as 7-Zip WinSvr Dist Sept 2026. 

Task 4 - Enroll the Windows Server device using scripted enrollment

In this task, you will switch to the Windows Server VM, update Group ID, and run a pre-staged script to silently enroll the device into Workspace ONE UEM.

Step 1 — Switch to the Windows Server VM

  1. From the VM Switcher, select WS2025-Server. 
  2. If prompted to log in, enter the password for the local account: 

Step 2 - Update the Group ID

  1. Navigate to C:\Resources. 
  2. Double-click the “Update Group ID” file. 
  3. Type the Group ID for the server OG you created earlier based on your student lab ID.   For example: ServerOG######## 

! Make sure to preface the Group ID with “ServerOG”. 

  1. Click OK. 
  2. Click OK again to the “Replacement complete…” message. 

Checkpoint: The Group ID file has been updated with the correct server Group ID. 

Step 3 - Run the enrollment script

  1. Right-click the newly created file, “Right-Click Me and choose Run as Administrator” batch file and choose Run as Administrator
  2. A command window will appear briefly for about a minute and then close on its own. This starts the enrollment process. 

Note: You will have to wait about 2 minutes while the device enrolls. There will be no visible progress while enrollment is happening. 

Step 4 — Review the enrollment script (optional, while enrollment is in progress)

  1. Go to C:\Resources\Right click me and choose Run as Administrator.  DO NOT RUN again as Administrator! 
  2. Right-click the file and select Show More Options.  Click Edit.  Do not click Open
  3. Note the parameters that have been embedded within the script. 
  4. Close Notepad after viewing, without saving any changes. 

Checkpoint: The enrollment script has been run, and the Windows Server device is enrolling into Workspace ONE UEM using the correct Group ID. 

0 Comments

Add your comment

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.