Configure the Security, Assignment, and Deployment details to ensure the content in the Managed and Corporate File Server repositories remain secure.


  1. On the Security tab, complete the text boxes to control how the end users share and move sensitive documents outside of corporate mediums.
    The Force Encryption setting has been removed since Workspace ONE UEM console version 9.5. The VMware Workspace ONE Content app encrypts all the files by default, whether the setting is available or not.
    Setting Description
    Document Sharing Disable the sharing settings for maximum security. You can enable them for configuring end-user collaboration.
    Access Control Set to Allow Offline Viewing to give end users the most viewing freedom for their document. Configure Allow Online Viewing Only to ensure that all devices accessing content are compliant, as Workspace ONE UEM cannot scan offline devices for compliance.
    Allow Open in Email Allow the content to open in emails.

    Users cannot open files that are larger than 10 MB. To allow users to open files larger than 10 MB, you must edit such files on the UEM console and enable this option. Files in user repositories cannot be edited.

    Allow Open in Third Party Apps Give the permission to open this content in other applications. You can set a list of approved apps in the SDK Profile. Disabling this option also disables the end user's permission to print the PDF documents from the iOS VMware Workspace ONE Content.
    Allow Saving to Other Repositories Select to allow your end users to save this file to their Personal Content.
    Enable Watermark Select to add a watermark overlay to the file.

    Configure the Overlay Text for the watermark as part of an SDK profile.

    Allow Printing Give the end users the permission to print PDF documents from the iOS VMware Workspace ONE Content using AirPrint server. Once printed, content falls out of the control of the Workspace ONE UEM administrator. Printing is supported only if Allow Open in Third Party Apps is enabled.
    Allow Edit This setting only applies to write-enabled repositories.
  2. Configure the Assignment settings to control which users have access to content.
    This function ensures that only authorized employees have access to confidential or sensitive material and allows you to set up a tiered hierarchy of content access.
    Setting Description
    Device Ownership Define as Any, Corporate-Dedicated, Corporate-Shared, Employee Owned or Undefined.
    Organization Groups To assign the content to a new group, start typing in the text box.
    User Groups Designate groups if you are integrating with Directory Services or custom user groups.
  3. Use the Deployment settings to control how and when your end users access content.
    Setting Description
    Transfer Method Specify Any method or Wi-Fi Only from the drop-down menu. Restricting transfers to Wi-Fi forces devices to check in with Workspace ONE UEM to ensure compliance.
    Download While Roaming Enable to allow your end users to download the content while roaming.
    Download Type

    Set to deploy content one of two ways:

    • Automatically – Installs on devices when content becomes available.
    • On Demand – Installs on devices only at the end user's request.
    Download Priority Define to let your end users know if the content download is Normal, High, or Low priority.
    Required Select to flag the content as required in the VMware Workspace ONE Content. End users must download and review the required content in order for their devices to maintain compliance with Workspace ONE UEM.
    Effective Date Specify to configure a limited range of content availability.
    Expiration Date Specify to configure a limited range of content availability.
  4. Select Save.