Lab 1: Configure UEM for Horizon Clone Enrollment

UEM Admin Account: [email protected]

UEM Admin Password: Pa$$w0rd

UEM Org Group: [email protected]

Objective and Tasks

In this lab, your Workspace ONE UEM customer organization group is created but is otherwise empty.

You will prepare Workspace ONE UEM to manage Horizon workloads.

  1. Log in to the Workspace ONE UEM console and create an organization group for Horizon workloads.
  2. Create a tag and a smart group for the Horizon desktops.
  3. Configure the staging user and streamline the enrollment experience.

For more information and guidance on integrating the two platforms, see the Omnissa Tech Zone guide, Omnissa Workspace ONE Unified Endpoint Management Integration with Horizon.

 

Expand or collapse content Task 1: Log in to the Workspace ONE UEM console and create an organization group for Horizon workloads
  1. Open the Workspace ONE UEM console.
    • Yse the keyboard icon in the lab toolbar and select CTRL-ALT-Delete
    • Log in to the ControlCenter with the default OMNISSATRAINING\Administrator user name and enter Pa$$w0rd
    • On your ControlCenter desktop, open Google Chrome.
    • From the bookmarks bar, click UEM Console. If you don't see the bookmark bar you may need to open a new tab.
    • Alternatively, enter https://cn1605.awmdm.com/AirWatch in the address bar.
  2. Log in with your assigned administrator account.
    • Enter Username: [email protected], where @lab.LabInstance.Id is the lab ID shown on the Instructions tab.
    • Click Next.
    • Enter Password: Pa$$w0rd
    • Click Log In.
  3. Complete the first-login prompts.
    • If Chrome offers to save the password, click Never.
    • Select I agree to the Omnissa General Terms
    • Click Accept
    • Set a recovery question and answer, and set 1234 as your four-digit PIN.
    • Click Save.
  4. Confirm which organization group you are working in.
    • Select the Organization Group drop-down menu in the top-left corner of the console.
    • Confirm that the organization group shown is [email protected].

Check the organization group in the drop-down menu before you change any setting, in this and in every following task. A setting applied at the wrong OG level affects every device below it.

  1. Open the organization group details.
    • Navigate to Groups & Settings > Groups > OG Details
  2. Create a child organization group for Horizon workloads.
    • Click Add Child Organization Group.
    • In the Name text box, enter Horizon-VDI.
    • In the Group ID text box, enter [email protected].
    • From the Type drop-down menu, select Container.
    • Click Save.
  3. After you click Save, the UEM Console should switch to the newly created OG automatically.
    • Confirm that Horizon-VDI now appears in the organization group drop-down menu.

Your customer OG already isolates you from the other students in this shared tenant. The child OG you just created models what you would do in a real deployment, where Horizon workloads sit alongside physical endpoints in the same tenant and need their own policy scope.

In production, give non-persistent pools their own child OG as well. Non-persistent VMs enroll with a unique device record each time they are created, and those records are orphaned when the VM is deleted.

A dedicated OG lets you point a scheduled Omnissa Intelligence workflow at exactly those records and prune them on whatever cadence suits you.

Expand or collapse content Task 2: Create a tag and a smart group for the Horizon desktops

Smart groups are the assignment mechanism in Workspace ONE UEM; you cannot assign a profile, baseline, or application without one. Tags are a lightweight way to tell Horizon workloads apart from physical endpoints in reports and dashboards. You create both now so that everything you assign later has a target.

  1. Create a tag for Horizon workloads.
    • Navigate to Groups & Settings > All Settings > Devices & Users > Advanced > Tags.
    • Click Create Tag.
    • In the Name text box, enter Horizon-VDI.
    • Click Save.
    • Close the Settings page.
  2. Open the assignment groups list.
    • Navigate to Groups & Settings > Groups > Assignment Groups.
  3. Create the smart group.
    • Click Add Smart Group.
    • In the Name text box, enter Horizon-Win11-Desktops.
    • Select Criteria rather than Devices or Users.
  4. Define the smart group criteria and save it.
    • Verify that the smart group is "Managed by Horizon-VDI."
    • Expand Platform and Operating System set Windows / equals / Windows 11 (10.0.26200).
    • Expand Model Type, change from Any to Selected, then clear Windows - Hololens and Windows Server so only Windows - Desktop is selected.
    • Click Save.

Resist the urge to build one smart group covering every Horizon desktop. Separating by operating system version, feature update, and model gives you the granularity you need when you assign baseline templates, which are version-specific.

Expand or collapse content Task 3: Configure the staging user and streamline the enrollment experience

A staging account allows a Horizon clone to enroll itself with no credentials stored on the endpoint. The lab has already created a basic user in your top level organization group. You enable device staging on it. You then disable two first-run prompts because otherwise, on a non-persistent desktop, those prompts reappear at every logon.

The [email protected] account was created at the higher level OG so it is not visible to you in the Horizon-VDI OG.

  1. From the Organization Group picker menu at the top left select the [email protected] OG to go up a level to the top OG.
  2. Open the users list.
    • Navigate to Accounts > Users.
  3. Open the pre-created basic user account.
  4. In the Add/Edit User window, select the Horizon-VDI OG.
    • Scroll down to find and open the Enrollment section.  
    • Select [email protected] / Horizon-VDI as the enrollment group.
  5. In the Add/Edit User window, enable device staging for the account.
    • Select the Advanced tab.
    • Open the Staging section.
    • Set Enable Device Staging to Enabled.
    • Set Single User Devices to Enabled.'
    • Leave the Single User Devices as Standard
    • Leave Multi User Devices set to Disabled.
    • Click Save.

Enable Device Staging is disabled by default, and enrollment fails later with an unhelpful error if you skip it.

The Multi User Devices setting does not apply to Windows devices, despite what the name suggests. Leave this setting as is.

  1. Disable the post-enrollment onboarding experience.
    • Navigate to Groups & Settings > All Settings > Devices & Users > General > Enrollment.
    • Select the Optional Prompt tab.
    • On the Current setting, select Override.
    • Scroll down to the Windows section.
    • Set Enable Post-Enrollment Onboarding (PEO) Experience to Disabled.
    • Click Save.
    • Close the Settings page.
  2. Disable analytics collection.
    • Navigate to Groups & Settings > All Settings > Devices & Users > Microsoft > Windows > Intelligent Hub Settings.
    • On Current setting, select Override.
    • Open the Privacy section.
    • Set Collect Analytics to Disabled.
    • Click Save.
    • Close the Settings page.

At this point Workspace One is configured to allow clones to enroll when a user logs in to a virtual desktop with the staging account. However, in a production deployment of Workspace One, you need to set up an Active Directory source in All Settings > Enterprise Integration > Directory Services.

This lab has already configured the directory source at a higher level OG, and your Student OGs are inheriting the Active Directory configuration from the higher level OG.

0 Comments

Add your comment

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.