Configure Content Gateway settings in the Workspace ONE UEM console to establish a node and pre-configure the settings that get bundled into the configuration file. The pre-configured settings eliminate the need to configure the settings manually post-installation on the server.

Configuration includes selecting the configuration model, associated ports, and if necessary, uploading an SSL certificate.
Note: Content Gateway services are now supported only on the Unified Access Gateway. Legacy Linux and Windows versions of Content Gateway are no longer supported.


  1. Navigate to Groups & Settings > All Settings > System > Enterprise Integration > Content Gateway in the Organization Group of your choice.
  2. Set Enable the Content Gateway to Enabled.
    You might need to select Override to unlock Content Gateway settings.
  3. Click Add.
  4. Complete the text boxes that appear to configure a Content Gateway instance.
    1. Configure the Installation Type.
      Setting Description
      Installation Type Unified Access Gateway appears as the default available platform for Content Gateway.
    2. Configure the Content Configuration settings.
      Setting Description
      Configuration Type
      • Basic – Endpoint configuration with no relay component.
      • Relay – Endpoint configuration with a relay component.
      Name Provide a unique name used to select this Content Gateway instance when attaching it to a Content Repository, Repository Template, or RFS Node.
      Content Gateway Relay Address If implementing a relay configuration, enter the URL used to access the Content Gateway Relay from the Internet.
      Content Gateway Relay Port If implementing a relay configuration, enter the relay server port.
      Content Gateway Endpoint Address Enter the host name of the Content Gateway endpoint. The Public SSL certificate bound on the configured port must be valid for this entry.
      Content Gateway Endpoint Port Enter the endpoint server port.
    3. Configure the Content SSL Certificate settings.
      Setting Description
      Ignore SSL Errors (not recommended) If you are using a self-signed certificate, then enable this setting. If enabled, Content Gateway ignores certificate trust errors and certificate name mismatches.
    4. Configure the Certificate Authentication settings.
      Setting Description
      Enable Cross-domain KCD Authentication Enable this setting to authenticate users with the PIV-D Derived Credentials instead of user names and passwords.

      PIV-D certificate authentication is for the users who access the on-prem SharePoint repositories from their devices.

      Client Certificate Chain The certificate chain used to issue client certificates.
      Target SPN

      SPN of the target service.

      Service Account Username User name of the service account that has delegation rights.
      Service Account Password Password for the service account.
      Domain Name of the domain in the Active Directory (AD) containing the users.
      Domain Controller Hostname or IP address of the domain controller for the domain.
    5. Enter the Content Gateway edge service values under the Custom Gateway Settings.

      This step is optional. You must perform this step only if you want to override the default configuration values for Content Gateway.

      With the edge service values set on the UEM console, the configuration file changes are automated and do not require manual updates to the configuration files each time the UAG is upgraded. For more information about the custom values for Content Gateway, see #GUID-97362C4E-3CCC-43C9-91F0-B85EDB6874DF.

      ICAP Proxy configurations are not supported from Workspace ONE UEM console version 9.7. However, existing configurations can be edited. For information about configuring ICAP Proxy, see

  5. Select Add and then select Save.

What to do next

After configuring settings in the UEM Console, download the installer, configure additional nodes, or manage configured nodes.