Windows Desktop Documentation
Total Page:16
File Type:pdf, Size:1020Kb
Windows Desktop Documentation VMware Workspace ONE UEM Windows Desktop Documentation You can find the most up-to-date technical documentation on the VMware website at: https://docs.vmware.com/ VMware, Inc. 3401 Hillview Ave. Palo Alto, CA 94304 www.vmware.com © Copyright 2021 VMware, Inc. All rights reserved. Copyright and trademark information. VMware, Inc. 2 Contents 1 Workspace ONE UEM Device Management, Enrollment Requirements, and Supported Windows 10 Versions 9 Workspace ONE UEM Device Management for Windows Desktop Devices 9 Enrollment Requirements for Windows Desktop Devices 10 User-Side Requirements 10 Device-Side Requirements 10 What Windows 10 Versions Are Supported? 11 Windows 10 Version Matrix 11 2 Enrolling Windows 10 Devices into Workspace ONE UEM 14 Enrollment Basics 14 Workspace ONE Intelligent Hub for Windows 10 Enrollment 16 Procedure to Enroll with the VMware Workspace ONE Intelligent Hub 16 Native MDM Enrollment for Windows Desktop 17 Enroll Through Work Access With Windows Auto Discovery 17 Enroll Through Work Access Without Windows Auto Discovery 19 Windows 10 Device Staging Enrollment 21 Bulk Import Device Serial Numbers 22 Carbon Black and Workspace ONE Intelligent Hub for Windows 22 Enroll Through Command-Line Staging 23 Enroll Through Manual Device Staging 24 Silent Enrollment Parameters and Values 24 Examples of Silent Enrollment 26 Workspace ONE UEM and Azure AD Integration 27 Configure Workspace ONE UEM to Use Azure AD as an Identity Service 27 Enroll a Device with Azure AD 29 Enroll an Azure AD Managed Device into Workspace ONE UEM 29 Enroll Through Out of Box Experience 30 Enroll Through Office 365 Apps 34 Bulk Provisioning and Enrollment for Windows 10 Devices 35 Enroll with Bulk Provisioning 35 Install Bulk Provisioning Packages 36 Enroll with Registered Mode 37 Windows 10 Enrollment Statuses 38 3 Profiles for Windows Desktop 41 What Are Profiles? 42 User or Device Level 42 VMware, Inc. 3 Windows Desktop Documentation Antivirus 42 Application Control 44 Configuring an Application Control Profile 45 BIOS 47 Credentials 50 Configuring a Credentials Profile 50 Custom Settings 51 Preventing Users from Disabling the Workspace ONE UEM Service 53 Data Protection 53 Configuring a Data Protection Profile 55 Creating an Encrypting File System Certificate 56 Defender Exploit Guard 56 Encryption 59 Exchange ActiveSync 64 Removing Profiles or Enterprise Wiping 64 Username and Password 64 Configuring an Exchange ActiveSync Profile 64 Exchange Web Services 65 Firewall 66 Firewall (Legacy) 68 Kiosk 69 OEM Updates 71 Passcode 73 Peer Distribution 74 Configuring a Peer Distribution Profile 75 Personalization 75 Proxy 76 Restrictions 77 SCEP 80 Configuring a SCEP Profile 81 Single App Mode 81 VPN 82 Per-App VPN for Windows 10 Using the VPN Profile 86 Web Clips 87 Wi-Fi 87 Windows Hello 88 Creating a Windows Hello Profile 89 Windows Licensing 90 Windows Updates 90 Device Updates for Windows Desktop 94 Approve Windows Updates 95 VMware, Inc. 4 Windows Desktop Documentation 4 Using Baselines 96 Cloud-Based Micro-Service 96 Baselines Require Constant Connectivity to Device Services 96 Types of Baselines 97 CIS Benchmark Considerations 97 What Happens After You Assign Baselines? 97 How Do I Control the Assignment of Baselines? 97 Baselines Management 98 Baselines Compliance Status 98 Creating Baselines 98 Prerequisites 99 Creating with Templates 99 Creating Your Own 100 5 Compliance Policies 101 Compliance Policies in Workspace ONE UEM 101 Dell BIOS Verification for Workspace ONE UEM 101 Benefits of Dell Trusted Device 102 Prepare Your Devices for Dell Trusted Device 102 Dell BIOS Verification Statuses 102 Compromised Device Detection with Health Attestation 103 Configure the Health Attestation for Windows Desktop Compliance Policies 103 6 Windows Desktop Applications 105 Workspace ONE Productivity Apps 105 VMware Workspace ONE App for Windows Desktop 105 Configure the Workspace ONE Intelligent Hub for Windows Desktop 106 7 Technical Preview: Collect Data with Sensors for Windows Desktop Devices 107 Technical Previews 107 Sensors Description 107 Workspace ONE UEM Options 108 Sensors Triggers 108 Added PowerShell Scripts 108 Device Details > Sensors 108 Workspace ONE Intelligence Options 108 Reports and Dashboards To Analyze Data 108 RBAC to Control Access To Data 109 Encryption 109 Use Write-Ouput and Not Write-Host in Scripts 109 Workspace ONE Intelligence Documentation 109 VMware, Inc. 5 Windows Desktop Documentation Windows Desktop Devices and Sensors Data 110 PowerShell Script Examples for Sensors 110 Check Remaining Battery 110 Get Serial Number 110 Get System Date 110 Check If TPM Is Enabled 110 Check If TPM Is Locked 111 Get TPM Locked Out Heal Time 111 Check If SMBIOS Is Present 111 Check SMBIOS BIOSVersion 111 Get BIOS Version 111 Get BIOS Status 112 Get Average CPU Usage (%) 112 Get Average Memory Usage 112 Get Average Virtual Memory Usage 112 Get Average Network Usage 112 Get Average Memory Usage For A Process 112 Check If A Process Is Running Or Not 113 Check If Secure Boot Is Enabled 113 Active Network Interface 113 Check The PowerShell Version 113 Check Battery Max Capacity 114 Check Battery Charging Status 114 Active Power Management Profile 114 Check If Wireless Is Present 114 Get Java Version 114 Create a Sensor for Windows Desktop Devices 115 8 Technical Preview: Automate Endpoint Configurations with Scripts for Windows Desktop Devices 117 Technical Previews 117 Scripts Description 117 How Do You Know Your Scripts Are Successful? 118 Create a Script for Windows Desktop Devices 118 9 Dell Command | Product Integrations 120 Dell Command | Configure Integration 120 Basics 120 Supported Devices 120 BIOS Profile 120 Add Dell Command | Configure to Workspace ONE UEM 121 Dell Command | Monitor Integration 121 VMware, Inc. 6 Windows Desktop Documentation Basics 121 Supported Devices 121 BIOS Profile 122 Battery Health Status 122 Dell Command | Update Integration 122 Basics 122 Supported Devices 122 Configure the OEM Updates Profile 122 Add Dell Command | Update to Workspace ONE UEM 122 10 Windows Desktop Device Management 124 Device Dashboard 124 Device List View 125 Customize Device List View Layout 126 Exporting List View 127 Search in Device List View 127 Device List View Action Button Cluster 127 Remote Assist 127 Windows Desktop Device Details Page 128 Windows Notification Service Details 128 More Actions 129 Manage Your Microsoft HoloLens Devices 132 Enroll Your HoloLens Devices 132 Manage Your HoloLens Devices 132 Product Provisioning 132 11 How Do You Deploy Domain Join Configurations for Windows Desktop? 133 Integration with Microsoft Autopilot (Hybrid Domain Join) 133 Use a Windows Autopilot Profile for OOBE Enrollments 133 Requirements 134 Assumptions 134 Order of Tasks 135 Step One: Configure Autopilot Devices 135 Step Two: Configure On-Premises Domain Join 135 On-Premises Domain Join 135 Requirements 136 Assumptions 136 Order of Tasks 136 Step One: Configure ADUC 136 Step Two: Configure ACC 139 Step Three: Create an On-Premises Domain Join 139 VMware, Inc. 7 Windows Desktop Documentation Step Four: Assign a Domain Join Configuration 140 Workgroup Join 141 Order of Tasks 141 Step One: Create a Domain Join for Workgroups 141 Step Two: Assign a Domain Join Configuration 142 VMware, Inc. 8 Workspace ONE UEM Device Management, Enrollment Requirements, and Supported 1 Windows 10 Versions Workspace ONE UEM powered by AirWatch provides you with a set of mobility management solutions for enrolling, securing, configuring, and managing your Windows 10 device deployment. To use Workspace ONE UEM's management solutions, meet the requirements to enroll supported Windows 10 devices. Management solution availability depends on the Windows 10 OS version of your devices. This chapter includes the following topics: n Workspace ONE UEM Device Management for Windows Desktop Devices n Enrollment Requirements for Windows Desktop Devices n What Windows 10 Versions Are Supported? n Windows 10 Version Matrix Workspace ONE UEM Device Management for Windows Desktop Devices Through the Workspace ONE UEM console, you have several tools and features for managing the entire lifecycle of corporate and employee-owned devices. You can also enable end users to perform tasks themselves, for example, through the Self-Service Portal and user self-enrollment, which saves you vital time and resources. Workspace ONE UEM allows you to enroll both corporate and employee-owned devices to configure and secure your enterprise data and content. By using of our device profiles, you can properly configure and secure your Windows devices. Detect compromised devices and remove their access to corporate resources using the compliance engine. Enrolling your devices into Workspace ONE UEM allows you to secure and configure devices to meet your needs. VMware, Inc. 9 Windows Desktop Documentation Enrollment Requirements for Windows Desktop Devices Before enrolling your Windows Desktop (Windows 10) devices with Workspace ONE UEM, your devices and users must meet the listed requirements and configurations or enrollment does not work. User-Side Requirements Your Windows 10 users must meet this list of requirements to enroll their devices with Workspace ONE UEM. n Admin Permissions – The logged in user enrolling the device must be an Administrator. n Group ID – If your Workspace ONE UEM environment prompts users for their Group ID, the logged in user needs this value. n Device Root Certificate - All users need the Device Root Certificate configured in the System Settings before enrolling their devices. To configure the certificate, navigate to Groups & Settings > All Settings > System > Advanced > Device Root Certificate. n Enrollment URL – All users can enter a unique URL that takes them directly to the enrollment screen to enroll in a Workspace ONE UEM environment. For example, mdm.example.com.Important: If your enrollment server is behind a proxy, you must configure the Windows service WINHTTP to be proxy-aware when configuring your network settings. Device-Side Requirements Your Windows 10 devices must access the listed sites, have the listed settings enabled, and have the listed services running to enroll with Workspace ONE UEM.