Enrolling the Work Managed Device mode using AirWatch Relay varies depending on the Android OS version.
Note: AirWatch Relay is not supported in Android 10 or later.
For Android 6.0+, the AirWatch Relay app provides a single bump option which configures region, Wi-Fi, provisioning settings, and enrollment settings in the single bump.
Procedure
From the parent device, define the following settings:
Setting | Description |
---|---|
Local Time | Enable this field for the device to automatically configure with local time. |
Time Zone | Select the time zone. |
Locale | Select the location your device will be enabled. |
Wi-Fi Network | Specify the Wi-Fi network the device will connect to. |
Security Type | Determine the encryption type for the connection. |
Wi-Fi Password | Enter the Wi-Fi Password. |
Encrypt Device | Disable to skip device encryption as part of Work Managed device provisioning. |
Disable System Apps | When enabled, Workspace ONe Intelligent Hub disables system apps during set up. |
Server | Enter the server URL or hostname. |
Group ID | Enter an identifier for the organization group for the end users to use for device to log in. |
Username | Enter the credentials for the user the child device will be enrolled. |
Password | Enter the credentials for the user the child device will be enrolled. |
Tap Ready from the parent device.
Tap Encrypt on the child device with the devices still back to back. This step only applies if Encrypt Device is not enabled. Otherwise, it is automatically accepted. The child device automatically:
Connects to the Wi-Fi network defined in the AirWatch Relay app.
Downloads and silently installs the Workspace ONE Intelligent Hub.
Sets the Workspace ONE Intelligent Hub as device administrator.
Resets the device.
After the child device has reset, the device is provisioned for Work Managed Mode. A welcome screen displays on your child device. To verify this from the child device, navigate to Device Settings > Security > Device Administrators to view Workspace ONE Intelligent Hub listed as the device administrator. End users will not be able to deactivate this setting.
You will also notice on the device homescreen the pre-downloaded apps allowed. Any other applications will need to be approved by the administrator from the Workspace ONE UEM console.
If you have several devices to enroll in your device fleet, then repeat NFC bump one on each child device to provision them in Work Managed Device mode.
Results
If enrollment was successful, the My Device page will display on the child device. All profiles and applications will start to automatically push to the device. You will repeat the enrollment steps for each device needing to be enrolled in your device fleet.
The Workspace ONE UEM console reports the status of Android on the users devices. You can check the Details View page to verify the device enrolled in Work Managed mode successfully.
For Android v5.0 and Android v6.0, the AirWatch Relay app provides a NFC bump option that automatically configures region, Wi-Fi, provisioning settings, and enrollment settings.
Procedure
From the parent device, define the following settings:
Setting | Description |
---|---|
Local Time | Enable this field for the device to automatically configure with local time. |
Time Zone | Select the time zone. |
Locale | Select the location your device will be enabled. |
Wi-Fi Network | Specify the Wi-Fi network the device will connect to. |
Security Type | Determine the encryption type for the connection. |
Wi-Fi Password | Enter the Wi-Fi Password. |
Encrypt Device | Enable this field to indicate that device encryption can be skipped as part of Work Managed device provisioning. |
Disable System Apps | If this field is enabled, Workspace ONE Intelligent Hub disables system apps during set up. |
Perform the first NFC bump by touching the parent and child device back to back. The child device should be in factory reset mode which will ensure the device is not being used for personal use.
Prior to performing a factory reset on child devices (if the device isn’t new out of the box), disable the lock screen and remove any existing Google account configured on the device. Device Protection is a feature for Android 5.1 that requires uses to enter the Google account credentials prior to performing a factory reset. If you disable lock screen and remove existing Google account, you will not be prompted for credentials and enrollment will not be hindered.
Tap Encrypt on the child device with the devices still back to back. This step only applies if Encrypt Device is not enabled, otherwise it will be automatically accepted.
The child device will automatically:
Connect to the Wi-Fi network defined in the AirWatch Relay app.
Download and silently install the Workspace ONE Intelligent Hub.
Set the Workspace ONE Intelligent Hub as device administrator.
Reset the device.
After the child device has reset, the device is provisioned for Work Managed Mode and bump one is complete. A welcome screen displays on your child device. To verify this from the child device, navigate to Device Settings > Security > Device Administrators to view Workspace ONE Intelligent Hub listed as the device administrator. End users will not be able to deactivate this setting.
You will also notice on the device homescreen the pre-downloaded apps allowed. Any other applications will need to be approved by the administrator from the Workspace ONE UEM console .
If you have several devices to enroll in your device fleet, then repeat NFC bump one on each child device to provision them in Work Managed Device mode. If not, proceed to enrollment.
Alternatively, you can choose to enroll the child devices manually and skip the second NFC bump steps outlined below. You will need to enter enrollment details manually on each device. For additional enrollment flows, please see Additional Enrollment Workflows in the Mobile Device Management (MDM) documenation.
Return to the AirWatch Relay app, from the parent device, and tap Enroll.
Define the enrollment settings. These setting will be used to automate enrollment of child devices.
Setting | Description |
---|---|
Server | Enter the server URL or hostname. |
Group ID | Enter an identifier for the organization group for the end users to use for device to log in. |
Tap Ready.
What to do next If enrollment was successful, the My Device page will display on the child device (shown above). All profiles and applications will start to automatically push to the device. You will repeat the enrollment steps for each device needing to be enrolled in your device fleet.