The process to install Workspace ONE PIV-D Manager on devices is similar on Android and iOS. Following prompts on the device, users configure the app for the derived credential your organization uses for authentication, signing, or encryption.

End users follow these steps on their devices to install Workspace ONE PIV-D Manager.


  1. Users enroll the device using the Workspace ONE Intelligent Hub.
  2. After the device is enrolled, users tap the prompt to install the Workspace ONE PIV-D Manager. Users can also download the app through the app catalog.
  3. Users follow the instructions provided by their admins. Instructions often require users to smart card authenticate to the PIV-D provider self-service portal (SSP).

    If admins did not pre-configure a derived credentials provider with an app config value in the Workspace ONE UEM console, end users must select the provider and follow the configuration steps for the selected provider.

  4. After authentication from the PIV-D provider SSP, complete the enrollment process in Workspace ONE PIV-D Manager.


After enrollment is complete, the application shows the derived credentials and triggers the installation of any device profiles that use a derived credential.
Note: Anytime admins update a device profile or create a new one, users must launch the Workspace ONE PIV-D Manager for the new profile to get pushed down to the mobile device.

What to do next

Navigate to Settings > General > Device Management to view the profile and the certificates on the device as a managed profile.