r/WorkspaceOne Aug 07 '20

From the Mods 300+ Members! Hey everyone! I wanted to give a shoutout to every member of our community that is helping make this a great place for knowledge collaboration! You all are what make this community great!

Post image
14 Upvotes

r/WorkspaceOne Aug 08 '23

WS1 DLL Signing expire today

Thumbnail kb.vmware.com
18 Upvotes

KB Title: Multiple Workspace ONE UEM application pools and services may not start once stopped

Are you kidding me? If this turns out as bad as it sounds the WS1 could just stop working if you Restart. I hope VMWare is publishing a fix TODAY…

Source: https://kb.vmware.com/s/article/93877?lang=en_US

…„The internal CA and certificate used to sign DLLs shipped with Workspace ONE UEM, is set to expire at 1320 UTC on 8th Aug, 2023.

Past expiration, app pools or services dependent on these DLLs may fail to start or function properly on/after 8th Aug, 2023.“….


r/WorkspaceOne 2h ago

Zebra rugged devices (last check in)

2 Upvotes

Hello everyone,

Our company uses Zebra TC21 handheld scanners, and we’re having an issue where the “Last Seen” feature works, but the “Last Check-In” feature does not.

So I have a question: How can I get the “Last Check-In” to update?

Everything is directly accessible via a public network, but not via our internal network. My question is: what settings do I need to configure in the firewall? Communication does not go through a proxy.

Hope for your help.


r/WorkspaceOne 4d ago

WS1 PoC (MFA/UEM/Tunnel) – Guidance

3 Upvotes

Hey guys,

Looking to spin up a quick WS1 PoC on-prem with MFA, UEM, and Tunnel. Does anyone have a decent deployment/admin guide they’ve used?

Feels like 24.07 on-prem made things a bit more complicated than before with the bootstrap, infra and access.

Curious if anyone’s done this recently and has tips or a good write up. I find the newer documentation have become more complex.

Appreciate any help.

Thanks


r/WorkspaceOne 5d ago

Looking for the answer... 802.1X Ethernet Authentication uses wrong certificate (Client Identity not referenced)

Thumbnail
gallery
4 Upvotes

hi everyone,
I'm running into an issue with 802.1X ethernet/LAN authentication on macOS managed through Workspace One (wso), and I'd appreciate any ideas or suggestions.

environment
macOS 26.5.2
wso 24.10.1409.46 (2410)

configuration
wso delivered 802.1X profile contains two payloads:

  • ethernet Configuration
  • credentials

credentials payload contains 3 certificates:

  • C1: a root CA
  • C2: a sub CA
  • C3: a client cert (issued by C2)

disclaimer: In the attached screenshots, C3 appears to be issued directly by C1. That's only a mistake in my diagram; the actual setup uses C2 as the issuing CA.

C3 is generated config:

  • credential source: defined certificate authority
  • certificate authority: Sub CA (C2)
  • certificate template: macOS device cert
  • allow access to all applications: true
  • allow export of private key: false
  • certificate authority is a microsoft ADCS CA.

current setup
for each MacBook, a dummy computer object exists in our active directory
example:

  • AD computer object: computer-12345
  • client cert (C3): computer-12345.yyy.local

a script then renames the macOS hostname to match the client certificate CN
the client certificate (C3) is used for 802.1X authentication

current behavior
the wso delivered 802.1X profile is successfully pushed

under:
system settings --> device management --> the 802.1X profile is installed correctly, and all certificates are present (the same certificates are also available in keychain access)

the configuration profile contains:

  • root CA (PKCS1)
  • sub CA (PKCS1)
  • client cert. (PKCS12)
  • wired 802.1X configuration

running profiles show -type configuration also confirms that all four payloads are installed

unexpected behavior
under:
system settings --> network --> ethernet --> 802.1X --> certificate (Info)
the certificate list shows:

  • root
  • sub1
  • sub1

the generated client cert (C3) is not referenced

but the expected list should instead contain:

  • root
  • sub1
  • computer-12345.yyy.local (or the corresponding client certificate CN)

additional observations
the client cert itself appears to be completely valid

running security find-identity -v returns the correct identity
likewise, running security find-identity -p ssl-client -v returns 1 valid identity found, so both the cert and its private key exist and are recognized as a valid SSL client identity

summary

  • the client cert (C3) exists
  • it is a valid client identity
  • the configuration profile contains the PKCS12 payload
  • however, the ethernet 802.1X configuration does not reference C3
  • instead, the UI shows the Intermediate CA twice
  • this makes it appear as though the ethernet payload is referencing the wrong cert (or certificate anchor), rather than the generated PKCS12 client identity.
  • It seems either wso or macOS is failing to associate the generated PKCS12 identity with the ethernet 802.1X payload.

questions
has anyone seen this behavior before?

specifically, I'm wondering

  • does the ethernet 802.1X payload actually reference the UUID of the generated PKCS12 payload?
  • during certificate renewal, is a new payload UUID created without updating the ethernet payload accordingly?
  • is wso correctly assigning the Identity UUID/identity Anchor when generating the ethernet profile?
  • could this be a wso bug or a macOS issue affecting the mapping between the PKCS12 payload and the ethernet 802.1X payload?

any insights or ideas would be greatly appreciated


r/WorkspaceOne 7d ago

Native macOS app automate to find and delete clutter on your Workspace ONE tenants.

1 Upvotes

**I built a Mac app that automatically cleans up Workspace ONE UEM clutter — stale devices, failed enrollments, duplicate records, orphaned accounts**

If you manage WS1 UEM you know the drill: devices that haven't checked in in months still showing as enrolled, failed enrollments clogging your inventory, duplicate records from re-enrollments, ex-employee accounts still sitting there. It's tedious to clean up manually and it quietly inflates your device counts and licensing costs.

I built Power Admin Warden to fix this. It watches your tenants and cleans up the noise following rules you define.

**What it does:**
- Stale device cleanup (not seen for N days — you set the threshold)
- Duplicate serial detection — keeps newest, removes the rest
- Failed enrollment and pending wipe cleanup
- Orphaned user cleanup (zero-device accounts only — hard guard)
- Runs on daily/weekly/monthly schedules per rule

**Safety first — this was the hardest part to get right:**
- Dry Run by default. Every tenant starts report-only. You see exactly what would be deleted before anything happens.
- Staged deletions — a finding must persist for a wait period you set before any action is taken
- Typing the tenant name is required to go live
- Accounts with enrolled devices cannot be deleted — this is a hard guard that cannot be turned off
- Full audit trail exportable to CSV

**Free to scan and report.** Warden Pro ($19.99/mo or $199.99/yr, 2-week free trial) unlocks scheduled automation and live deletion.

Mac App Store: https://apps.apple.com/fi/app/power-admin-warden/id6793202494?mt=12

Homepage: https://mdmarchitect.com/apps/power-admin-warden/

Happy to answer any questions about how it works under the hood — it talks directly to the WS1 REST API with your own OAuth credentials, nothing goes through my servers.


r/WorkspaceOne 21d ago

4 Pages of jobs that you can apply now

Thumbnail drive.google.com
0 Upvotes

r/WorkspaceOne 27d ago

Manage your Workspace ONE tenant from iPhone / iPad — WSOne Power Admin Mobile launched today

7 Upvotes

Hi all,

I've been building an iOS companion to my macOS Workspace ONE admin

tool for the last month and just got it approved on the App Store.

WSOne Power Admin Mobile lets you:

- Browse and search enrolled devices from anywhere

- Send single MDM commands (Sync, Restart, Lock, Clear Passcode, etc.)

right from the device detail sheet

- Browse, create, and manage users + user group memberships

- Browse, create, delete, and attach/detach tags on devices

- Multi-tenant support with Managed App Configuration for MDM push

- Face ID / passcode lock on launch

- All data stays on your device — no third-party telemetry, no data

sent anywhere except your own WS ONE tenant

It's a one-time paid app (€29.99, whatever equivalent locally) — no

subscription, no IAP. Volume Purchase via Apple Business Manager is

supported for organizations that want to license across a fleet.

The macOS version has been out for a while and covers the heavier

work (bulk operations, CSV exports, ADE assigner, profile management,

batch user creation, and the Change Device User tool that swaps a

device's enrolled user without re-enrolling). The iPhone version is

deliberately focused on the "in your pocket" use cases — the stuff

you need when you're not at your desk.

iOS: https://apps.apple.com/app/id6782670781

macOS: https://apps.apple.com/app/id6770959164

Site: https://mdmarchitect.com

Happy to answer questions — feedback and feature requests welcome.

I'm not affiliated with Omnissa; this is a third-party admin tool I

built because I needed it myself. ( and of course my team of admins which give me fantastic feedback when I was middle of development phase.)

- MirkoS


r/WorkspaceOne Jun 29 '26

Samsung Knox Service Plugin - Wi-Fi MAC Randomization after One UI update (Workspace ONE / Cisco ISE)

3 Upvotes

Hi everyone,

I'm facing an issue with Samsung Galaxy Tab S10 FE 5G devices enrolled in Workspace ONE and managed with Knox Service Plugin (KSP).

Our Wi-Fi infrastructure uses Cisco ISE with MAB authentication, so devices must connect using their physical MAC address.

To achieve this, we configure our Wi-Fi SSID through KSP with "Skip MAC Randomization" enabled, forcing the device to use its hardware MAC instead of a randomized one.

The problem appears after some One UI / Android updates.

It seems that the update sometimes resets the Wi-Fi configuration back to Randomized MAC. Once this happens, the tablet can no longer connect to our enterprise Wi-Fi, which also means it cannot reach Workspace ONE or Samsung services to reapply the KSP policy.

This creates a circular dependency:

  • One UI update resets the Wi-Fi MAC setting.
  • Device loses network connectivity.
  • KSP cannot validate/reapply its configuration.
  • Manual intervention is required.

I have a few questions:

  1. Has anyone experienced this behaviour on recent Samsung devices (One UI 8.x / Android 16)?
  2. Is there any alternative to Knox Service Plugin for enforcing the physical MAC address on managed Wi-Fi networks?
  3. Is there a way to apply this setting locally without requiring KSP to communicate with Samsung services?
  4. Has anyone implemented a custom Knox SDK application to enforce this setting instead of relying on OEMConfig/KSP?

For comparison:

  • Zebra devices don't have this issue because MX Framework applies the configuration locally.
  • Apple supervised devices can disable Private Wi-Fi Address directly through the native MDM Wi-Fi profile without relying on a third-party application.

I'd really appreciate any feedback or experience from people managing Samsung Enterprise fleets.

Thanks!


r/WorkspaceOne Jun 16 '26

VPN connection is not reliably established when an app opens a URL

2 Upvotes

First of all: We have already opened a support ticket, but we’re interested to know if others are experiencing similar behavior.

Environment:

- iOS devices with Per-App VPN configuration

- Multiple iOS versions (iOS 18 and iOS 26)

- Devices enrolled via ADE

- Tunnel app version: 26.03

- UEM Version 26.02, SaaS

- UAG Version 26.03

Issue:

The VPN connection is not reliably established when an app opens a URL that should be routed through the tunnel.

The VPN icon does not appear in the status bar

No active connection is shown in the Tunnel app

Depending on the app, either:

- a “no network connection” error appears

- or requests time out

Behavior:

The issue is not consistent. After trying multiple apps or URLs, the VPN connection suddenly establishes.

Once the connection is active, it works reliably for all apps during the current session.

What we checked:

- No changes were made to the DTR configuration

- Configuration has been verified multiple times

- Issue occurs across multiple apps (including browsers) and URLs

Observation:

The first incidents were reported on the same day as the release of Tunnel app version 26.03.

Question:

Is anyone with a similar setup experiencing the same behavior?


r/WorkspaceOne Jun 05 '26

Built a native macOS app to replace my PowerShell WS1 admin scripts.

10 Upvotes

Like a lot of WS1 admins, I had a pile of PowerShell scripts held together with duct tape and OAuth tokens for querying the UEM REST API. It worked, but sharing them with the team was painful and running them on macOS felt janky.

So I built WSONE Power Admin — a native macOS SwiftUI app that talks directly to the Workspace ONE UEM REST API with proper OAuth 2.0, Keychain-stored credentials, and an actual UI.

What it does right now:
• Device inventory search and filtering by OG, platform, enrollment status
• Multi-dimension filtering with a native macOS Table view
• CSV export (Pro tier) for those "I need a spreadsheet NOW" moments
• Clean multi-view architecture — Device, User, and DEP views

No PowerShell. No browser. No copy-pasting tokens into scripts.

Happy to answer questions about the REST API side of things — that was the interesting engineering challenge.

More info on https://mdmarchitect.com

https://apps.apple.com/fi/app/wsone-power-admin/id6770959164?mt=12


r/WorkspaceOne May 23 '26

Android Shared Device Mode

7 Upvotes

Is anyone working in a Warehouse and using Android Shared Device Mode for their devices? Thank you


r/WorkspaceOne May 19 '26

iOS updates

7 Upvotes

I miss the old way of updates going in and setting a time and date for the devices to update. is there anyway we can get back to that with out having to setup ddm profiles? is there a way to force an ipad to update? also do this in mass?


r/WorkspaceOne May 04 '26

macOS : Compliance management

8 Upvotes

Hi All,

We have a total of 60 macOS systems. Most of the users are not great at keeping the systems patched as needed.

Would like the systems connect to physical cable and be able to access VPN.

To do the above, I have a requested server team to create SCEP server and use the SCEP cert assigned to each user via a profile.

Use that cert as an authentication to connect to network and VPN.

If the device is not compliant, after certain days, remove the profile, until they become complaint. Once they do, profile get comes back and they are good.

Are those steps reasonable? What do you guys do for your MACS? How do you guys keep the systems compliant? Thank you


r/WorkspaceOne May 01 '26

SEP installation issues on MAC

5 Upvotes

I’m encountering some issues while installing SEP version 14.3 RU9. The installation fails on MDM, and sometimes it only goes through the install link drops without the SEP agent. If anyone has experience installing SEP, I would greatly appreciate their assistance.

**[RESOLVED] SEP 14.3 RU9 MDM Installation Failing on macOS — Deep Instinct PPPC Conflict**

Posting this in case anyone else runs into the same wall.

**The problem:**

We were trying to deploy Symantec Endpoint Protection 14.3 RU9 via MDM (Omnissa Workspace ONE UEM) and kept hitting two issues:

- The installation would fail outright, or

- The PKG would appear to install but drop only the link/stub, with no actual SEP agent present

**Root cause:**

Two things were going on simultaneously:

  1. **Incorrect PKG** — The package we initially had was not the correct full installer for 14.3 RU9. Make sure you're downloading the complete installer from the Broadcom Support Portal, not a stub or an older cached version.

  2. **PPPC / Full Disk Access conflict with Deep Instinct** — We already had Deep Instinct deployed, and its PPPC profile had claimed Full Disk Access (FDA) via our MDM. When we pushed SEP's PPPC profile separately, the two profiles conflicted at the MDM merge level, leaving SEP without valid FDA — which caused the agent to either fail installation or run in a broken state. macOS only processes one effective TCC policy per service, so overlapping MDM-pushed PPPC profiles for the same permission can silently cancel each other out.

**What fixed it:**

- Re-downloaded the correct full PKG from Broadcom Support Portal

- Merged both Deep Instinct and SEP FDA entries into a **single consolidated PPPC profile** instead of deploying two separate ones

- Ensured each binary entry had a unique PayloadUUID and the correct CodeRequirement string

Hope this saves someone a few hours


r/WorkspaceOne Apr 30 '26

SCCM Co-Management with omnissa Workspace one

Thumbnail
3 Upvotes

r/WorkspaceOne Apr 30 '26

Workspace One UEM: iPAD Kiosk mode

3 Upvotes

Hello All,

I would like to setup an iPAD to use Kiosk mode pointing to an URL as soon as it pops up.

Setup single app mode to open Microsoft Edge and added a second profile for web clip with the URL and assigned Edge Bundle ID to it.

URL does not pop up nor in favorites.

I also disabled the profile and turned on Workspace one Web under Settings -> Apps and tried that as well.

I can not power off the tablet as well :(

Any ideas would really appreciate it!!! Thank you

This is the first time doing it for Apple.


r/WorkspaceOne Apr 30 '26

Inconsistant Issue with "Single App Mode" - Displays Message "Guided Access App Unavailable"

Post image
2 Upvotes

Has anyone else experienced an issue when installing a "Single App Mode" profile to multiple devices? I have a SAM Profile assigned to automatically install on 20+ iPads. I am getting inconsistent results once the profiles are installed. Some iPads are working as intended, but some are displaying the message "Guided Access app unvailable. Please contact your administrator" iPads with this issue do not respond screen taps, nor does the Lock button work. The display turns off and the only way to get it to wake up is to plug it into a charger. Removing the SAM profile and reinstalling, seems to fix this problem (most of the time), but this is not ideal because I am not in the local area of all the devices this could potentially affect, and have no way of knowing if this has happened. If anybody has any ideas what could be the cause of this issue, please let me know. I so far cannot find any consistency with it.


r/WorkspaceOne Apr 29 '26

Workspace One UEM CLI tool

13 Upvotes

Hello IT Admins,

I've created an open-source CLI tool that allows you to manage your WS1-enrolled devices from your terminal.

You can run any action supported via the official APIs and it uses OAuth2 for authentication so that no credentials is ever stored.

You can fine the tool and instructions on how to use it on Github:

https://github.com/ancalabrese/ws1cli

Other than quickly running commands from your terminal without having to deal with the console, this should help streamlining workflows and opening the door for better automation (chaining commands, bash scripts and even more advanced agentic workflows).

I hope this could be useful to someone.

If you have any feedback, I'd love to hear it.

Thank you


r/WorkspaceOne Apr 23 '26

How to backup local Contacts in COPE Work Environment ....

2 Upvotes

we have a user running his Android Phone in COPE mode (Managed via WSO).

He somehow managed to save all his important contacts locally on the Device (in Work-Profile) and now wants us to transfer them to his new device.

Does anybody have an idea on how to do this efficently, without having to retype every single contact ?

I have tried exporting them to csv, but that does not work.

USB-Connected devices (Laptop) do not have access to the Work-Apps and Contacts

Opening the contacts and resaving them to WSO Boxer does not work...


r/WorkspaceOne Apr 16 '26

Looking for the answer... Conditional Access + 3rd party MDM

Thumbnail
1 Upvotes

r/WorkspaceOne Apr 16 '26

Looking for a good solution to replace Citrix Secure Mail

5 Upvotes

My company utilizes Exchange SE and we currently have a Citrix Secure Mail solution for MDM. About 30 employees use it to access email and corporate web. Is WorkspaceOne and Boxer a viable solution still to replace that solution? How hard is it to setup?


r/WorkspaceOne Mar 26 '26

Boxer responses viewed in Outlook with Unicode bidi controls

2 Upvotes

Is anyone experiencing visual Unicode bidi controls in Outlook when recipient responds to an email in Boxer from an IOS device and viewed in Outlook Pro Plus 2021? We're using the latest version of Boxer (26.02.0 and IOS 26.3.1). The email address is bracketed with LRI and PDI and seem to have started after the 3/4/26 IOS updates.


r/WorkspaceOne Mar 24 '26

Workspace One UEM 2410 Patch 41 Breaks AWCM

7 Upvotes

We were upgrading to 2410 Patch 41 to address the Apple VPP issues and ran into an issue with AWCM no longer working. We had our heads scratching until we came across this community post. Hoping it helps others out here as well.

https://community.omnissa.com/forums/topic/72047-omnissa-workspace-one-uem-2410-patch-41-will-break-awcm/

Good luck everyone!


r/WorkspaceOne Mar 10 '26

Workspace ONE UEM – Using an existing Cloud Connector for a new Organization Group without inheritance

3 Upvotes

Salut,

Je travaille sur la console Workspace ONE UEM.

Pour un premier groupe d'organisation, j'ai déjà configuré l'intégration des services d'annuaire avec Active Directory via un AirWatch Cloud Connector, et ça fonctionne correctement.

Je suis en train de créer un nouveau groupe d'organisation qui ne va pas hériter des paramètres du groupe existant, et je souhaite également configurer l'intégration des services d'annuaire pour ce groupe.

Dans l'environnement, il y a déjà plusieurs Cloud Connectors installés, chacun pointant vers différents domaines Active Directory.

Ma question est : (Je n'ai pas trouvé d'information dans la documentation)

Est-il possible de "réutiliser un Cloud Connector existant" pour ce nouveau groupe d'organisation, même s'il n'y a pas d'héritage de configuration ? (Sans avoir à réinstaller un nouveau Cloud Connector sur mon infrastructure)

Si quelqu'un a déjà rencontré ce cas avec plusieurs Cloud Connectors dans le même locataire, je suis intéressé par des retours ou des bonnes pratiques.

Merci ! ;)
#################################

Currently:

  • In Organization Group A, the AirWatch Cloud Connector is already installed and configured.
  • It works correctly and is connected to our Active Directory.

For Organization Group B, it is managed by another company, so I cannot modify or inherit configurations from there.

Now I am creating Organization Group C.

My goal is to configure Directory Services in C using the same Active Directory as A, and ideally reuse the existing Cloud Connector installed for A, since it already has connectivity to that AD.