The Apple Settings page lets you configure various options for Workspace ONE Intelligent Hub for Apple devices.

APNs for MDM

The APNs for MDM settings page lets you generate or upload your Apple Push Notification service (APNs) certificate, which is required to manage Apple devices. If you do not already have an APNs certificate, you can generate a new one on this page. If you do have such a certificate, you can upload it here.

For more information, please see the APNs for Applications Renewal Script Notification KB article: https://support.workspaceone.com/articles/360010936073.

APNs for Applications

The APNs for Applications page displays the APNs certificates that correspond to Workspace ONE UEM apps on the app store. These are required for sending push notifications to apps, and in most cases these are settings you should not alter unless instructed.

For more information, please see the APNs for Applications Renewal Script Notification KB article: https://support.workspaceone.com/articles/360010936073.

Apple iOS / Hub Settings

The iOS Hub Settings page lets you configure various options that affect the iOS Hub mobile app.

  • Current Setting – Select whether to Inherit or Override the displayed settings. Inherit means use the settings of the current organization group's parent OG, while Override enables the settings for editing so you can modify the current OG's settings directly.

General Tab

Table 1. General
Setting Description
Disable Un-Enroll in Hub This setting deactivates the user's ability to unenroll from Workspace ONE UEM MDM using the Workspace ONE Intelligent Hub. This setting is only available in the Workspace ONE Intelligent Hub v4.9.2 and higher.
Background App Refresh

This setting tells the Workspace ONE Intelligent Hub the maximum allowed time interval to refresh app content. Some applications run for a brief period before reaching a suspended state. Background App Refresh is a feature in iOS where the application itself wakes from this suspended state. During this refresh, the Workspace ONE Intelligent Hub reports information, such as compromised detection, hardware details, GPS, iBeacon, and telecom, to the UEM console. The frequency at which the Workspace ONE Intelligent Hub refreshes is controlled by the OS and only completed during efficient times, such as when the device is plugged into a power source, frequency of use, or connected to Wi-Fi.

To take advantage of the Background App Refresh feature, this setting must be enabled in the UEM console, the Workspace ONE Intelligent Hub cannot be stopped on the device, and Background App Refresh must be enabled on the device for the Workspace ONE Intelligent Hub under Settings > General > Background App Refresh.

Minimum Refresh Interval Select the minimum amount of time that must pass before the device attempts to refresh app content.
Transmit on Wi-Fi only Enable background refresh to occur over Wi-Fi connections only.

Notification Tab

These notification settings ensure the Workspace ONE Intelligent Hub can send push notifications.

Notification (iOS Only)

Use this tab to configure notifications that are sent to devices from the UEM console.

Setting Description
Application Type Choose to configure the Workspace ONE Intelligent Hub either as a system app or an internal Workspace ONE UEM app to set system preferences. By default, the application type is set as System.
Application Name Select an internal application from the drop-down menu. Ensure the Application Name appears the same way as it is does on the Internal List View page on the Apps & Books tab in the UEM console. Only internal applications with APNs certificates that were uploaded at the time the application was uploaded to the Console are seen here.
Bundle ID This field is populated based on the selections above. This Bundle ID matches the application bundle ID that has been uploaded internally or selected from the drop-down menu.
  • Child Permission – Select the available behavior of child organization groups that exist below the currently selected organization group. Inherit only means child OGs are only allowed to inherit these settings. Override only means they override the settings, and Inherit or Override means you can choose to inherit or override settings in child OGs that exist below the currently selected OG.

Apple iOS / Managed Settings

The iOS Managed Settings page lets you configure a few additional settings related to the Workspace ONE Intelligent Hub and managing iOS devices.

  • Current Setting – Select whether to Inherit or Override the displayed settings. Inherit means use the settings of the current organization group's parent OG, while Override enables the settings for editing so you can modify the current OG's settings directly.

Default Managed Settings

Setting Description
Apply Default Settings To Select which ownership types you want each of the default managed settings below to apply to.
Voice Roaming Select the checkbox to allow voice roaming.
Data Roaming

Select the checkbox to allow data roaming.

Personal Hotspot Select the checkbox to allow personal hotspot functionality.
Activation Lock Select the checkbox to allow activation lock functionality.

Default Wallpaper

Setting Description
Apply Default Settings To Select the ownership type(s) to which the following default managed settings are applied.
Lock Screen Image Upload a lock screen image that displays when an end user locks their device.
Home Screen Image Upload the home screen image that displays on the device.

Organization Information

Send notifications or other MDM prompts with customized organization information.

Setting Description
Organization Name Enter the name of the organization.
Organization Phone Number Enter the organization phone number.
Organization Email Enter the organization email address.
  • Child Permission – Select the available behavior of child organization groups that exist below the currently selected organization group. Inherit only means child OGs are only allowed to inherit these settings. Override only means they override the settings, and Inherit or Override means you can choose to inherit or override settings in child OGs that exist below the currently selected OG.

Apple macOS / Hub Application

The macOS Hub Application settings page lets you configure various options that affect the macOS Hub application.

  • Current Setting – Select whether to Inherit or Override the displayed settings. Inherit means use the settings of the current organization group's parent OG, while Override enables the settings for editing so you can modify the current OG's settings directly.
Setting Description
Fully Qualified Path on local server to the Workspace ONE Intelligent Hub files for MAC devices

This is the default location where the Workspace ONE Intelligent Hub is stored on the local server. Only change this if needed.

If the file path is incorrectly defined, end users cannot download the Workspace ONE Intelligent Hub post-enrollment.

Download Mac Hub Post Enrollment Select this checkbox to allow the Workspace ONE Intelligent Hub to be downloaded post-enrollment by side-loading or from a web browser.
Download Hub Use this button to download the latest version of the Workspace ONE Intelligent Hub from the server.
  • Child Permission – Select the available behavior of child organization groups that exist below the currently selected organization group. Inherit only means child OGs are only allowed to inherit these settings. Override only means they override the settings, and Inherit or Override means you can choose to inherit or override settings in child OGs that exist below the currently selected OG.

Apple macOS / Hub Settings

The macOS Hub Settings page lets you configure various options that affect the macOS Hub application. Use these settings to determine how often to collect data from devices, to allow passcode enforcement through Hub message prompts, to allow AirWatch Cloud Messaging so that devices receive push notifications and information about updates when available, and to choose how and when to allow updates.

  • Current Setting – Select whether to Inherit or Override the displayed settings. Inherit means use the settings of the current organization group's parent OG, while Override enables the settings for editing so you can modify the current OG's settings directly.
Table 2. General
Setting Description
Download Latest Version Download the latest version of the VMware Workspace ONE Intelligent Hub.
Install Hub after Enrollment Activate or deactivate the option to automatically install the Hub on devices after enrollment through Apple Business Manager's DEP or Web enrollment.
Check-in Interval Enter the frequency for the Hub to check in with the server to receive new commands.
Data Sample Interval Enter the frequency for the Hub to scan devices to collect data such as product provisioning status, disk encryption status, custom attributes, GPS location, and other basic system information.
Data Transmit Interval Enter the frequency for the Hub to send data samples to the Hub UEM server.
Uninstall Privileges Activate or deactivate the option to provide end users the ability to uninstall the Hub application from their devices.
  • Child Permission – Select the available behavior of child organization groups that exist below the currently selected organization group. Inherit only means child OGs are only allowed to inherit these settings. Override only means they override the settings, and Inherit or Override means you can choose to inherit or override settings in child OGs that exist below the currently selected OG.

Apple macOS / Software Management

Use the macOS Software Distribution method to initiate the software management lifecycle for macOS applications.

  • Current Setting – Select whether to Inherit or Override the displayed settings. Inherit means use the settings of the current organization group's parent OG, while Override enables the settings for editing so you can modify the current OG's settings directly.

Enable Software Management. At this point, make sure that you verify if the File Storage is enabled. If there is no file storage enabled, you are requested to enable it.

  • Child Permission – Select the available behavior of child organization groups that exist below the currently selected organization group. Inherit only means child OGs are only allowed to inherit these settings. Override only means they override the settings, and Inherit or Override means you can choose to inherit or override settings in child OGs that exist below the currently selected OG.

AppleCare

Use the Apple Care settings page to manage options related to Workspace ONE UEM integration with AppleCare.

  • Current Setting – Select whether to Inherit or Override the displayed settings. Inherit means use the settings of the current organization group's parent OG, while Override enables the settings for editing so you can modify the current OG's settings directly.
Setting Action
GSX User ID Enter the account user ID.
GSX Password Enter the account password.
Sold-to Account Number Enter the 10-digit service account number. This account number can be found in the GSX portal at the bottom of the web page.
Time Zone Use the drop-down menu to select the appropriate time zone.
Language Use the drop-down menu to choose a language.
  • Child Permission – Select the available behavior of child organization groups that exist below the currently selected organization group. Inherit only means child OGs are only allowed to inherit these settings. Override only means they override the settings, and Inherit or Override means you can choose to inherit or override settings in child OGs that exist below the currently selected OG.

Automated Enrollment

The Automated Enrollment settings page lets you create and export an MDM profile that you can then import into Apple Configurator when staging devices.

  • Current Setting – Select whether to Inherit or Override the displayed settings. Inherit means use the settings of the current organization group's parent OG, while Override enables the settings for editing so you can modify the current OG's settings directly.
Setting Description
Enable Automated Enrollment Select this check box to display the staging settings you can configure.
Platform Select which Apple platform this profile will be used for.
Staging Mode

Select the appropriate Staging Mode depending on how the device is going to be used and how the device must enroll. You can choose to pre-register devices and enroll using Apple Configurator. By pre-registering devices and selecting the None or Single User mode, you can pre-assign the end user for each device. However, you cannot pre-register Multi User devices.

  • None – Does not stage device for other users. For non-registered devices, all devices will be enrolled under the Default Enrollment User. In this case, only non-staging users are available as default staging user options.
    Important: If you do not pre-register your devices and select None and specify a default enrollment user, then all devices that receive the .mobileconfig file will be enrolled to that user. To ensure devices are enrolled to distinct users, pre-register them to specific users or create a staging user account and select Single User as your Staging Mode.
  • Single User – Stages device for a single, known or unknown user. Only staging users are available as Default Enrollment User options. When end users open the Workspace ONE Intelligent Hub, they must enter credentials to fully enroll the staged device. At that time, the device details will update in the UEM console and the device is associated with that end user.
  • Multi User – Places device into Shared Device Mode. This stages the device for multiple, known or unknown users. Only staging users are available as Default Enrollment User options. When end users open the Workspace ONE Intelligent Hub, they must enter credentials to check out the device for use.
Default Staging User Set a Default Staging user if you are using either the None or Single User staging modes.
  • Child Permission – Select the available behavior of child organization groups that exist below the currently selected organization group. Inherit only means child OGs are only allowed to inherit these settings. Override only means they override the settings, and Inherit or Override means you can choose to inherit or override settings in child OGs that exist below the currently selected OG.

MDM Sample Schedule

The Apple MDM Sample Schedule settings page lets you configure the time intervals at which certain data samples from Apple devices are sent to the UEM console server.

  • Current Setting – Select whether to Inherit or Override the displayed settings. Inherit means use the settings of the current organization group's parent OG, while Override enables the settings for editing so you can modify the current OG's settings directly.
Setting Description
Device Information Sample Enter the frequency by which device information is refreshed on the Workspace ONE UEM server.
Application List Sample Enter the frequency by which the application list is refreshed on the Workspace ONE UEM server.
Certificate List Sample Enter the frequency by which the certificate list is refreshed on the Workspace ONE UEM server.
Profile List Sample Enter the frequency by which the profile list is refreshed on the server.
Provisioning Profile List Sample Enter the frequency by which the provisioning profile list is refreshed on the server. (iOS only)
Restriction List Sample Enter the frequency by which the restrictions list is refreshed on the server. (iOS only)
Security Information Sample Enter the frequency by which the security information is refreshed on the server.
Managed App List Sample the frequency by which the managed app list is refreshed on the server. (iOS only)
Sample Enter the frequency by which the scheduler determines how often a silent APNs is sent to the device to poll for compromised detection, data usage, and GPS, if these Hub settings are enabled for the device. This requires the Workspace ONE Intelligent Hub 4.9 or higher and is only for iOS 7 or higher devices. (Reference macOS Hub Settings for information on macOS scheduling.)
Non-Compliant Device Sample Enter the frequency by which Workspace ONE UEM queries non-compliant devices, to decrease the delay between when an end user takes actions to make their device compliant and when Workspace ONE UEM detects that action.
  • Child Permission – Select the available behavior of child organization groups that exist below the currently selected organization group. Inherit only means child OGs are only allowed to inherit these settings. Override only means they override the settings, and Inherit or Override means you can choose to inherit or override settings in child OGs that exist below the currently selected OG.

Device Enrollment Program

The Device Enrollment Program settings page lets you configure DEP-based enrollment within Workspace ONE UEM. DEP settings can be configured at any Organization Group. A wizard displays when you initially configure the DEP Profile, which walks you through the setup process.

For more information, see Create or Edit the DEP Enrollment Profile in Introduction to Apple Business Manager.

Profiles

The Apple profile page allows you to define security profile properties for your MDM profiles. You can optionally select to sign and encrypt profiles here. You can configure these settings during your initial set-up.

  • Current Setting – Select whether to Inherit or Override the displayed settings. Inherit means use the settings of the current organization group's parent OG, while Override enables the settings for editing so you can modify the current OG's settings directly.
Setting Description
Encrypt Profiles Select this checkbox to encrypt all MDM and device profiles that are installed on the devices.
Sign Profiles (Requires Server SSL Certificate) Select this checkbox to sign MDM and device profiles with a SSL certificate that is used to establish trust with the device services server.
Prompt devices to update MDM profile for iOS 5 Permissions This is a legacy setting used to provide compatibility with iOS 5. This checkbox does not need to be selected unless you are working with an iOS 5 device.
Signing Certificate Use the Upload button to upload a third-party SSL certificate to sign the profile. The SSL certificate should be the same one used on the device services end point.
  • Child Permission – Select the available behavior of child organization groups that exist below the currently selected organization group. Inherit only means child OGs are only allowed to inherit these settings. Override only means they override the settings, and Inherit or Override means you can choose to inherit or override settings in child OGs that exist below the currently selected OG.

SCEP

Use this page to configure settings for SCEP certificate enrollment on iOS devices. Select SCEP settings to retrieve a SCEP certificate instead of a self-signed enrollment certificate.

  • Current Setting – Select whether to Inherit or Override the displayed settings. Inherit means use the settings of the current organization group's parent OG, while Override enables the settings for editing so you can modify the current OG's settings directly.
Setting Description
Use in Enrollment Select this checkbox to retrieve a SCEP certificate during enrollment instead of a regular enrollment certificate.
SCEP Certificate Authority Select the certificate. If one is not available, go to Groups and Settings > All settings > System > Enterprise Integration > Certificate Authorities and follow the prompts to add a certificate.
SCEP Certificate Template Select the certificate template. If one is not available, go to Groups and Settings > All settings > System > Enterprise Integration > Certificate Authorities > Request Templates and follow the prompts to add a certificate template.
  • Child Permission – Select the available behavior of child organization groups that exist below the currently selected organization group. Inherit only means child OGs are only allowed to inherit these settings. Override only means they override the settings, and Inherit or Override means you can choose to inherit or override settings in child OGs that exist below the currently selected OG.

Install Fonts

With the iOS Install Fonts settings, you can add fonts that you want to install on device. Available to macOS Yosemite and devices running iOS 7 and higher, the UEM console provides a means to upload fonts and install them onto devices. Installing specific fonts allows users to view and read text that is not supported by standard means.

Compatible font file types include .ttf or .otf. There is no limit to the number of fonts you are can install on devices and you can remove a font at any time.

Drag a supported font file type (.ttf or .otf) onto the screen and select Save.

Education

The Apple Education page can be used to enable Apple Education functionality, which then allows for integration with Apple School Manager.

Note: This is functionality is only available to those with Workspace ONE UEM administrator roles and above.
  • Current Setting – Select whether to Inherit or Override the displayed settings. Inherit means use the settings of the current organization group's parent OG, while Override enables the settings for editing so you can modify the current OG's settings directly.
Setting General

Enable Education

Features

Select Enable to turn education functionality on.
Class Source

Select your Apple or Workspace ONE UEM as your Education functionality provider.

Note that changing sources and saving the configuration will delete all existing classes.

Set Maximum Resident Users Specify the maximum number of users each device's memory can support. This value divides the local storage on the iPad evenly for that number of users. If the number of users exceeds this setting, additional users' information is stored on iCloud instead of on the device.
  • Child Permission – Select the available behavior of child organization groups that exist below the currently selected organization group. Inherit only means child OGs are only allowed to inherit these settings. Override only means they override the settings, and Inherit or Override means you can choose to inherit or override settings in child OGs that exist below the currently selected OG.