Enrolling a device is required before the device can be managed by the Workspace ONE UEM. There are multiple enrollment paths, each path with options.
Before you start the enrollment process, there is something you must understand about the top level organization group (OG), commonly known as Global. There are several reasons enrolling devices directly to Global is not a good idea. These reasons are multitenancy, inheritance, and functionality.
You can make as many child organization groups as you need and you configure each one independently from the others. Settings you apply to a child OG do not impact other siblings.
Changes made to a parent level OG apply to the children. Conversely, changes made to a child level OG do not apply to the parent or siblings.
There are settings and functionality that are only configurable to Customer type organization groups. These include wipe protection, telecom, and personal content. Devices added directly to the top-level Global OG are excluded from these settings and functionality.
The Global organization group (OG) is designed to house Customer and other types of OGs. Given the way inheritance works, if you add devices to Global and configure Global with settings intended to affect those devices, you are also affecting all the Customer OGs underneath. This undermines the benefits of multitenancy and inheritance.
Enrolling a device with the Workspace ONE Intelligent Hub is the main option for Android, iOS, and Windows devices in Workspace ONE Express and Workspace ONE UEM powered by AirWatch.
Download and install the Workspace ONE Intelligent Hub from the Google Play Store (for Android devices) or from the App Store (for Apple devices).
Downloading the Workspace ONE Intelligent Hub from public application stores requires either an Apple ID or a Google Account.
Windows 10 devices must point the default browser on the device to https://getwsone.com to download the Hub.
Run the Workspace ONE Intelligent Hub upon the completion of the download or return to your browser session.
Important: To ensure a successful installation and running of the Workspace ONE Intelligent Hub on your Android device, it must have a minimum of 60 MB of space available. CPU and Run Time Memory are allocated per app on the Android platform. If an app uses more resources than allocated, Android devices optimize themselves by killing such an app.
Enter your email address when prompted. The Workspace ONE console checks if your address has been previously added to the environment. In which case, you are already configured as an end user and your organization group is already assigned.
If the Workspace ONE console cannot identify you as an end user based on your email address, you are prompted to enter your Server, Group ID, and Credentials. If your environment URL and Group ID are needed, your Workspace ONE Administrator can provide it.
Finalize the enrollment by following all remaining prompts. You can use your email address in place of user name. If two users have the same email, the enrollment fails.
The device is now enrolled with the Workspace ONE Intelligent Hub app. In the Summary tab of the Device Details View for this device, the security panel displays "Hub Registered" to reflect this enrollment method.
For more information, see Device Details.
Workspace ONE UEM makes the enrollment process simple, using an email-based autodiscovery system to enroll devices to environments and organization groups (OG). Autodiscovery can also be used to allow end users to authenticate into the Self-Service Portal (SSP).
Note: To enable an autodiscovery for on-premises environments, ensure that your environment can communicate with the Workspace ONE UEM Autodiscovery servers.
The server checks for an email domain uniqueness, only allowing a domain to be registered at one organization group in one environment. Because of this server check, register your domain at your highest-level organization group.
Autodiscovery is configured automatically for new Software as a Service (SaaS) customers.
Autodiscovery Enrollment simplifies the enrollment process enrolling devices to intended environments and organization groups (OG) using end-user email addresses.
Configure an autodiscovery enrollment from a parent OG by taking the following steps.
What to do next: Instruct end users who enroll themselves to select the email address option for authentication, instead of entering an environment URL and Group ID. When users enroll devices with an email address, they enroll into the same group listed in the Enrollment Organization Group of the associated user account.
You can configure Autodiscovery Enrollment from a child organization group below the enrollment organization group. To enable an autodiscovery enrollment in this way, you must require users to select a Group ID during enrollment.
Force users to select a Group ID during enrollments.
In some unique cases, the enrollment process into Workspace ONE UEM must be adjusted for specific organizations and deployments. For each of the additional enrollment options, end users need the credentials detailed in the Required Information section of this guide.