Windows Desktop Device Management
Total Page:16
File Type:pdf, Size:1020Kb
Windows Desktop Device Management VMware Workspace ONE UEM 2011 Windows Desktop Device Management You can find the most up-to-date technical documentation on the VMware website at: https://docs.vmware.com/ VMware, Inc. 3401 Hillview Ave. Palo Alto, CA 94304 www.vmware.com © Copyright 2020 VMware, Inc. All rights reserved. Copyright and trademark information. VMware, Inc. 2 Contents 1 Workspace ONE UEM Device Management for Windows Desktop Devices 6 Enrollment Requirements for Windows Desktop Devices 6 What Windows 10 Versions are Supported? 7 Windows 10 Version Matrix 7 2 Enrolling Windows 10 Devices into Workspace ONE UEM 10 Workspace ONE Intelligent Hub for Windows 10 Enrollment 12 Enroll with the VMware Workspace ONE Intelligent Hub 13 Native MDM Enrollment for Windows Desktop 13 Enroll Through Work Access With Windows Auto Discovery 14 Enroll Through Work Access Without Windows Auto Discovery 15 Windows 10 Device Staging Enrollment 17 Bulk Import Device Serial Numbers 18 Enroll through Command Line Staging 19 Enroll through Manual Device Staging 19 Silent Enrollment Parameters and Values 20 Windows 10 Provisioning Service by VMware AirWatch 23 Configure Windows 10 Provisioning 24 Workspace ONE UEM and Azure AD Integration 25 Configure Workspace ONE UEM to Use Azure AD as an Identity Service 25 Enroll a Device With Azure AD 27 Enroll an Azure AD Managed Device into Workspace ONE UEM 27 Enroll Through Out of Box Experience 29 Enroll Through Office 365 Apps 31 Bulk Provisioning and Enrollment 32 Enroll With Bulk Provisioning 32 Install Bulk Provisioning Packages 34 Enroll with Registered Mode 34 Windows 10 Enrollment Statuses 35 3 Workspace ONE UEM Profiles for Windows 39 Configure a Passcode Profile for Windows 10 Devices 40 Configure a Wi-Fi Profile for Windows 10 Devices 41 Configure a VPN Profile for Windows 10 Devices 43 Per-App VPN for Windows 10 Devices Using the VPN Profile 46 Workspace ONE UEM Credentials Profile for Windows 10 Devices 47 Configure a Credentials Profile for Windows 10 Devices 48 Configure a Restrictions Payload for Windows 10 Devices 50 VMware, Inc. 3 Windows Desktop Device Management Windows Defender Exploit Guard Profile for Windows 10 Devices 54 Create a Defender Exploit Guard Profile for Windows 10 Devices 56 Workspace ONE UEM Data Protection Profile for Windows 10 Devices 57 Configure a Data Protection Profile (Windows Desktop) 58 Create an Encrypting File System Certificate (Windows Desktop) 60 Windows Hello Profile (Windows Desktop) 60 Create a Windows Hello Profile (Windows Desktop) 61 Configure a Firewall (Legacy) Profile (Windows Desktop) 61 Configure a Firewall Profile (Windows Desktop) 62 Configure a Single App Mode Profile (Windows Desktop) 64 Configure an Antivirus Profile (Windows Desktop) 65 Encryption Profile (Windows Desktop) 68 Configure an Encryption Profile (Windows Desktop) 70 Configure a Windows Updates Profile (Windows Desktop) 72 Device Updates for Windows Desktop 76 Approve Windows Updates 77 Create a Proxy Profile (Windows Desktop) 78 Configure a Web Clips Profile (Windows Desktop) 79 Exchange ActiveSync Profile (Windows Desktop) 79 Configure an Exchange ActiveSync Profile (Windows Desktop) 80 SCEP Profile (Windows Desktop) 81 Configure a SCEP Profile (Windows Desktop) 81 Application Control Profile (Windows Desktop) 82 Configure an Application Control Profile (Windows Desktop) 83 Configure an Exchange Web Services Profile (Windows Desktop) 85 Create a Windows Licensing Profile (Windows Desktop) 86 Configure a BIOS Profile (Windows Desktop) 86 Configure the OEM Updates Profile (Windows Desktop) 89 Configure a Kiosk Profile (Windows Desktop) 91 Configure a Personalization Profile (Windows Desktop) 93 Peer Distribution with Workspace ONE 94 Configure a Peer Distribution Profile (Windows Desktop) 94 Use Custom Settings (Windows Desktop) 96 Prevent Users from Disabling the AirWatch Service 97 4 Using Baselines 99 Create a Baseline 101 5 Compliance Policies 103 Dell BIOS Verification for Workspace ONE UEM 103 Compromised Device Detection with Health Attestation 105 VMware, Inc. 4 Windows Desktop Device Management Configure the Health Attestation for Windows Desktop Compliance Policies 105 6 Windows Desktop Application Overview 108 VMware Workspace ONE for Windows Desktop 108 Configure the Workspace ONE Intelligent Hub for Windows Devices 109 7 Collect Data with Sensors for Windows Desktop Devices 110 PowerShell Script Examples for Sensors 111 Create a Sensor for Windows Desktop Devices 116 8 Automate Endpoint Configurations with Scripts for Windows Desktop Devices 118 Create a Script for Windows Desktop Devices 118 9 Dell Command | Configure Integration 121 Add Dell Command | Configure to Workspace ONE UEM 122 10 Dell Command | Monitor Integration 123 11 Dell Command | Update Overview 124 Add Dell Command | Update to Workspace ONE UEM 125 12 Windows Desktop Device Management 126 Device Dashboard 126 Device List View 127 Windows Desktop Device Details Page 130 Workspace ONE Assist 133 Manage Your Microsoft HoloLens Devices 133 Product Provisioning Overview 134 VMware, Inc. 5 Workspace ONE UEM Device Management for Windows Desktop Devices 1 Workspace ONE UEM powered by AirWatch provides you with a robust set of mobility management solutions for enrolling, securing, configuring, and managing your Windows 10 device deployment. Learn more about how Workspace ONE UEM enables your Windows 10 device management. Through the Workspace ONE UEM console, you have several tools and features for managing the entire lifecycle of corporate and employee-owned devices. You can also enable end users to perform tasks themselves, for example, through the Self-Service Portal and user self-enrollment, which saves you vital time and resources. Workspace ONE UEM allows you to enroll both corporate and employee-owned devices to configure and secure your enterprise data and content. By using of our device profiles, you can properly configure and secure your Windows devices. Detect compromised devices and remove their access to corporate resources using the compliance engine. Enrolling your devices into Workspace ONE UEM allows you to secure and configure devices to meet your needs. This chapter includes the following topics: n Enrollment Requirements for Windows Desktop Devices n What Windows 10 Versions are Supported? Enrollment Requirements for Windows Desktop Devices Before enrolling your Windows Desktop (Windows 10) devices with Workspace ONE UEM, your end users must meet the listed requirements and configurations or enrollment does not work. n Active Environment – Your active Workspace ONE UEM environment and your access to the Workspace ONE UEM console. n Appropriate Admin Permissions – A type of permission that allows you to create profiles, determine policies, and manage devices within the Workspace ONE UEM console. n PowerShell Execution - Workspace ONE UEM management of Windows Desktops devices leverages PowerShell for installation and operational changes through the Workspace ONE Intelligent Hub. VMware, Inc. 6 Windows Desktop Device Management n Enrollment URL – This URL is unique to your enrollment environment and takes you directly to the enrollment screen. For example, mdm.example.com. n Group ID – This Group ID associates your device with your corporate role and is defined in the Workspace ONE UEM console. n Device Root Certificate - You must configure the Device Root Certificate in the System settings before enrolling devices. To configure the certificate, navigate to Groups & Settings > All Settings > System > Advanced > Device Root Certificate. Important If your enrollment server is behind a proxy, you must configure the Windows service WINHTTP to be proxy-aware when configuring your network settings. What Windows 10 Versions are Supported? Workspace ONE UEM powered by AirWatch supports enrolling and managing Windows 10 devices. The level of support depends on the OS version and device architecture. Platforms and Devices Supported Workspace ONE UEM supports devices running the following operating systems: n Windows 10 Pro n Windows 10 Enterprise n Windows 10 Education n Windows 10 Home n Windows 10 S Workspace ONE Intelligent Hub does not support Windows ARM Snapdragon or Hololens devices. These devices must use native MDM functionality. Important: To see the OS version each update branch supports, see Microsoft's documentation on Windows 10 release information: https://technet.microsoft.com/en-us/windows/release- info.aspx. Windows 10 Version Matrix Compare the MDM functionality available in each version of the Windows 10 OS. Workspace ONE UEM supports all versions of Windows 10 OS and the functions they support. The different editions of Windows 10 (Home, Professional, Enterprise, and Education) have different functionality. Windows 10 Home edition does not support the advanced functionality available to the Windows 10 OS. Consider using Enterprise or Education editions for the most functionality. VMware, Inc. 7 Windows Desktop Device Management Windows 10 OS Windows 10 OS Windows 10 OS Windows 10 OS Feature Home Professional Enterprise Education Native Client Enrollment ✓ ✓ ✓ ✓ Agent Based Enrollment ✓ ✓ ✓ ✓ Requires a Windows Account ID Force EULA/Terms of Use ✓ ✓ ✓ ✓ Acceptance Support for Option Prompts ✓ ✓ ✓ ✓ during Enrollment Active Directory/ LDAP ✓ ✓ ✓ ✓ Cloud Domain Join Enrollment ✓ ✓ ✓ Out of Box Experience ✓ ✓ ✓ Enrollment Bulk Provisioning Enrollment ✓ ✓ ✓ Device Staging ✓ ✓ ✓ ✓ SMS Email Messages ✓ ✓ ✓ Password Policy ✓ ✓ ✓ ✓ Enterprise Wipe ✓ ✓ ✓ ✓ Full Device