Enrolling devices in bulk normally happens for new customers seeking to bring end user devices in their environment under the Workspace ONE UEM umbrella. These detailed use cases show every step to bulk enrolling your devices in three of the most popular paths, bring your own device (BYOD), corporate owned personally enabled (COPE), and shared devices.
Privacy Concerns
You can take preemptive steps to address privacy concerns your device end users might have. For detailed instructions on configuring privacy settings in Workspace ONE UEM, see Privacy for BYOD Deployments.
The Workspace ONE UEM console provides a simplified wizard that streamlines the directory services setup process. The wizard includes steps that integrate either Security Assertion Markup Language (SAML), Lightweight Directory Access Protocol (LDAP) or both. The wizard also automates the provisioning of Workspace ONE UEM applications to VMware Identity Manager, greatly simplifying the process.
For more information about integrating Workspace ONE UEM with Workspace ONE Access and deploying Workspace ONE with single sign-on to devices, see Workspace ONE UEM Integration with Workspace ONE Access.
Note: If you already configured SAML or LDAP settings on your directory services server, the UEM console detects it automatically.
Access the directory services setup wizard from two places.
The main UEM console Getting Started Wizard.
Navigate to Groups & Settings > All Settings > System > Enterprise Integration > Directory Services and select Start Setup Wizard.
Upon launching the wizard, select Configure to follow the steps.
Alternatively, you can Skip the wizard and configure directory services manually to configure settings on your own.
Change to the customer type OG from which you want to manage all your BYOD devices. Configuring enrollment options is easier when you are in the correct OG. For more information see Changing Organization Groups.
Navigate to Groups & Settings > All Settings > Devices & Users > Enrollment. If the options under the first tab, Authentication are dimmed and not selectable, select the Override option in Current Setting to enable all these options.
acme.com
, and a confirmation email address, for example [email protected]
. If you operate multiple domains, repeat steps 1 and 2 for each domain your employees use. The email address you enter here receives enrollment confirmations.While still in Groups & Settings > All Settings > Devices & Users > Enrollment, select the Management Mode tab. If the options are dimmed and not selectable, select the Override option in Current Setting to enable all these options.
Devices enrolled with Intelligent Hub are MDM managed by default. The Management Mode tab lets you opt out of MDM management, on a per platform basis, for devices you want to enroll in Workspace ONE UEM in favor of an alternate management mechanism such as app-based, registered mode, or unmanaged. Enable the platform and select the appropriate Smart Group to allow those devices to enroll without MDM management. Enrollment can be enabled based on the following criteria when utilizing smart groups: OS Version, Ownership Type, and User Group. Use Adaptive Management app policies to control device management levels for iOS devices enrolled without management. If you want to keep MDM Management, then skip this enrollment tab and proceed to step 4 (Hub Integration).
For each platform you want to opt out of MDM management in favor of an alternate management mechanism, select the Enabled button for that platform.
Under All [platform] devices in this Organization Group, select Enabled if you want all devices that enroll in this OG to opt out of MDM management. Those devices can be managed in registered mode or they can be managed at the application level. They can also remain unmanaged. Select Disabled and click the text box to activate the drop down menu. Select the name of the smart group to assign content to those devices. Any like-platform devices that enroll in this OG but are not included in the smart group are enrolled as MDM managed.
If you have not created this smart group yet, select the Create Smart Group button at the bottom of the drop down menu. Then follow the instructions in Create a Smart Group, making sure to take the Criteria path and also to make sure your platforms match: make an iOS smart group for the iOS Management Mode, make an Android smart group for the Android Management Mode, and so on.
Select Save.
While still in Groups & Settings > All Settings > Devices & Users > Enrollment, select the Hub Integration tab. If the options are dimmed and not selectable, select the Override option in Current Setting to enable all these options.
While still in Groups & Settings > All Settings > Devices & Users > Enrollment, select the Terms of Use tab. If the options are dimmed and not selectable, select the Override option in Current Setting to enable all these options.
While still in Groups & Settings > All Settings > Devices & Users > Enrollment, select the Grouping tab. If the options are dimmed and not selectable, select the Override option in Current Setting to enable all these options.
While still in Groups & Settings > All Settings > Devices & Users > Enrollment, select the Restrictions tab. If the options are dimmed and not selectable, select the Override option in Current Setting to enable all these options.
3. Under the Policy Settings section, you can select the Add Policy button to manually limit enrollment based on factors you decide. These factors include ownership type, enrollment type, device platform, device model, and operating system.
You can define multiple policies, for example one policy per platform, specifying a minimum model or OS version, and allow only those devices to enroll. This can be a powerful tool as you can see later in step 5.
4. Under the Management Requirements for Workspace ONE section, when Require MDM for Workspace ONE is enabled, devices that fit the assigned criteria are prompted to enroll immediately upon log in to Workspace ONE. Those devices that do not fit the assigned criteria are allowed to log in with an unmanaged state. They may come under management later using Adaptive Management. This option requires Workspace ONE application 3.2 or later.
5. Under the Group Assignment Settings section, you can apply policies you define in step 3 and send qualifying devices to the user group of your choosing.
For example, if you made a restriction policy that allowed only Employee Owned (BYOD) Android devices version 10 or later and a second restriction policy that allowed only Employee Owned (BYOD) iPhones version 15 or later, you can configure it such that Android users are added to one user group and iPhone users are added to another user group. Such organization can be useful in the future for content management.
The remaining tabs, Optional Prompt and Customization, are device end user friendly options that are less critical to BYOD functionality. For detailed instructions about each available option, see Optional Prompt and Customization.
Enrolling a device with the Workspace ONE Intelligent Hub is the main option for Android, iOS, and Windows devices in Workspace ONE Express and Workspace ONE UEM.
Download and install the Workspace ONE Intelligent Hub from the Google Play Store (for Android devices) or from the App Store (for Apple devices).
Downloading the Workspace ONE Intelligent Hub from public application stores requires either an Apple ID or a Google Account.
Windows 10 devices must point the default browser on the device to https://getwsone.com to download the Hub.
Run the Workspace ONE Intelligent Hub upon the completion of the download or return to your browser session.
Important: To ensure a successful installation and running of the Workspace ONE Intelligent Hub on your Android device, it must have a minimum of 60 MB of space available. You can allocate CPU and Run Time Memory on a per app basis on the Android platform. If an app uses more resources than allocated, Android devices optimize themselves by stopping such an app.
Enter your email address when prompted. The Workspace ONE console checks if your address was added to the environment. In which case, you are already configured as an end user and your organization group is already assigned.
If the Workspace ONE console cannot identify you as an end user based on your email address, you are prompted to enter your Server, Group ID, and Credentials. Your Administrator can provide the environment URL and group ID.
Finalize the enrollment by following all remaining prompts. You can use your email address in place of user name. If two users have the same email, the enrollment fails.
The device is now enrolled with the Workspace ONE Intelligent Hub app. In the Summary tab of the Device Details View for this device, the security panel displays "Hub Registered" to reflect this enrollment method.
Direct Enrollment represents the smoothest way to enroll devices that are corporate-owned and personally enabled (COPE). The COPE model offers businesses a way to strike a balance between the consumerization of devices and the security and control required by IT.
As an administrator, you can configure Direct Enrollment with the options you want. These options include an optional prompt, restrict by device type, limit by user group, and defer the installation of apps to the user.
Direct Enrollment is deactivated by default. To enable Workspace ONE Direct Enrollment, take the following steps.
Switch to the organization group for which you want to enable Direct Enrollment for Workspace ONE. The OG you want to move to is the one in which you plan to contain all the COPE devices that enroll. This same OG is the one you select in the near future to manage smart groups which you use to deliver device profiles for COPE, compliance policies for COPE, apps for COPE, and other content for COPE.
Navigate to Groups & Settings > All Settings > Devices & Users > General > Enrollment and select the Restrictions tab.
Scroll down to the Management Requirements for Workspace ONE and select your configuration options. If necessary, select to Override the parent OG's settings.
Setting | Description |
---|---|
Require MDM for Workspace ONE | Prompt qualified devices and users to be enrolled immediately upon logging in to Workspace ONE. Devices outside the defined criteria are allowed to enroll in an unmanaged state and can come under management later (Adaptive Management). |
Assigned User Group | This setting specifies the user group you want to include in the direct enrollment process. You can also select All Users which is the default selection when you enable Require MDM for Workspace ONE. |
iOS | Enable this setting to include iOS devices. Deactivated makes iOS devices not eligible for direct enrollment, though they can still enroll into Workspace ONE UEM in an unmanaged state. |
Android Legacy | Enable this option to include legacy Android devices. Deactivated makes legacy Android devices not eligible for direct enrollment, though they can still enroll into Workspace ONE UEM in an unmanaged state. |
Android Enterprise | Enable this setting to include Android Enterprise devices. Deactivated makes Android Enterprise devices not eligible for direct enrollment, though they can still enroll into Workspace ONE UEM in an unmanaged state. |
The remaining steps are meant for the end user to take. Sending an email with detailed enrollment steps to your end users is generally the way to accomplish this.
Navigate to Groups & Settings > All Settings > Devices & Users > General > Enrollment, select each applicable tab, and make your selections based on compatibility with Workspace ONE Direct Enrollment.
The following authentication options are compatible with Workspace ONE Direct Enrollment.
All terms of use options are compatible with Workspace ONE Direct Enrollment.
All grouping options are compatible with Workspace ONE Direct Enrollment.
The following restrictions options are compatible with Workspace ONE Direct Enrollment.
The following optional prompts options are compatible with Workspace ONE Direct Enrollment.
The following customization options are compatible with Workspace ONE Direct Enrollment.
Device staging in this COPE model using the Direct Enrollment process is not supported. If you must stage a device, whether for single or multiple users, you must enroll the device using Workspace ONE Intelligent Hub given the following platform specific configurations: