The Community

Stay up to date…

VMware End-User Computing Blog Bringing you the latest VMware EUC news, trends and product innovations.

Adam Matthews Technology // IAM // EUC // Random Rubbish

  • I asked ChatGPT to write me a bash script, and it worked (mostly), why do I need to know how to...
    by adam on December 18, 2022 at 11:12 pm

    By now, ChatGPT has become pretty well known ( as of 18th Dec 2022). I’ve messed around with basic questions, but today I wanted to start to write a script that I could use with “OverSight” on Mac (https://objective-see.org/products/oversight.html). When you turn on your camera/mic, it can fire off a script with arguments. In this … Continue reading "I asked ChatGPT to write me a bash script, and it worked (mostly), why do I need to know how to code?"

  • VMware ESXi – How to Remove an NFS Share that’s ‘In Use’
    by adam on December 14, 2022 at 11:35 am

    I recently moved house, and as part of that a few things on my network changed. My NAS (A Synolofy DS8J) changed it’s IP Address. This caused an issue when ESXi was trying to get hold of the datastore. So, now this needs to be removed and replaced – I came across this error: After … Continue reading "VMware ESXi – How to Remove an NFS Share that’s ‘In Use’"

  • Easily Automate your Lab with the vCenter API
    by adam on February 14, 2022 at 6:00 pm

    Learn how to use Python to call the VMware vCenter API to Start and Suspend Virtual Machines easily, and use Crontab to define the times it runs.

  • Quickly Compress Video Files on macOS
    by adam on January 26, 2022 at 11:29 am

    When you record your videos with Quicktime and you end up with 1.7 GB of a file, how do you shrink that?! I’ve been using this process for a couple of years now to optimise the output size of my demo videos, to make it easier to share them in presentations, and to keep my … Continue reading "Quickly Compress Video Files on macOS"

  • WordPress – How to fix Jetpack connection errors, Fonts and Icons showing as squares with NGINX
    by adam on March 5, 2021 at 5:24 pm

    I recently migrated https://blog.eucse.com/blog from running on Apache to Nginx. I found it helped a lot with utilization and speed (combined with a few more tweaks), but one thing I noticed after was Jetpack wouldn’t load correctly, and some fonts and icons were showing as squares. See examples of what I was seeing below: Resolution … Continue reading "WordPress – How to fix Jetpack connection errors, Fonts and Icons showing as squares with NGINX"

Arsen Bandurian: Technical Blog Digital Workspace, End User Computing, Enterprise Mobility, AutoID, WLANs, OSes and other technical stuff I happen to work with

  • Check if a Microsoft Form comes from a trusted source
    by apcsb on November 6, 2023 at 10:14 am

    When you open a Microsoft Form asking you for some sensitive data, do you know where will your data land? Could it be phishing? Read on to find out… Recently, I have received an email at work asking me to fill out a form with some of sensitive personal details (voluntary disclosure).  I don’t mind... Continue Reading →

  • Enhancing Windows Update Catalog metadata Accessibility
    by apcsb on September 11, 2023 at 7:30 am

    Microsoft has recently released a major update to the Windows Update catalog back-end, adding crucial information such as CVEs (Common Vulnerabilities and Exposures) addressed by the update and the CVE Score directly info API. This information is essential for Threat and Vulnerability Management decisions as well as Patch management and many organizations pay $$ for... Continue Reading →

  • Quickly validate and enable manual application uninstall via Intune Company Portal using Graph API
    by apcsb on August 3, 2023 at 7:04 am

    I am back and the titles are getting longer! If you are an Intune admin, you will probably be happy to know that one of the most required features has landed: Uninstall Win32 and Microsoft store apps using the Windows Company Portal. One thing you need to be aware of, is that this feature is... Continue Reading →

  • Building a custom Windows Update Report p1: Parsing HTML via PowerShell on modern systems (no IE)
    by apcsb on July 28, 2022 at 7:30 am

    Wow, it’s been a while! A customer of mine recently wanted a detailed report that should include info such as how many weeks is the Windows on the machine behind the latest available Security Update. We’ve found to a way to combine Intune Data Warehouse and PowerBI to pull data that allows to identify the... Continue Reading →

  • A case of OneDrive Personal Vault not coming up (0x8031000a, MDM, GPO and BitLocker)
    by apcsb on March 18, 2022 at 6:23 pm

    Today I wanted to enable the Personal Vault feature on my Home PC. While following the wizard I got an error 0x8031000a “Your organization requires your device to join the domain before you can use the Personal Vault”. What does this have to do with MDM. GPO and BitLocker troubleshooting? Here’s some quick Friday entertainment!... Continue Reading →

  • How Goto's acquisition of Miradore is eroding a once-promising MDM solution
    by Jason Bayton on September 24, 2024 at 12:00 am

    Back in 2014, I discovered Miradore, an ITSM solution with a then-emerging Mobile Device Management (MDM) product that promised a robust set of features for managing Android devices. My initial review, Miradore Online: Free MDM, highlighted the platform's potential and its generous free tier, which made it stand out in a market otherwise dominated by costly alternatives. Miradore isn't defined by their free tier, of course, there's a rather large and feature-rich product behind it. It's what drew me in to their product in the first place however, and has been a consistent, defining feature of their platform for more than a decade. Over the years, I revisited Miradore multiple times, documenting its growth and the expansion of its feature set in articles like Miradore Online MDM Review: A Second Look and Miradore Online MDM: Expanding Management with Subscriptions. In 2022, when Miradore announced its acquisition by Goto, I met the news with cautious optimism. Goto, a company known for its suite of remote work tools, seemed like a reasonably safe choice to nurture Miradore's growth. Official announcements from both parties, such as Goto Acquires Miradore and Miradore Acquired by Goto: What Happens Next?, painted a rosy picture of enhanced resources and expanded capabilities. However, the honeymoon period is certainly over now. Since the acquisition, Goto has more and more shown its disdain for Miradore's core MDM USP, systematically stripping away key features from the free tier and fundamentally altering the product's value proposition and accessibility. The erosion of the free tier # Last December, a significant change came when Goto removed essential functionalities from the free plan. Email configuration, VPN setup, Wi-Fi settings, contacts management, and mail were no longer accessible without a paid subscription. Details of these changes weren't outlined in Miradore's release notes, instead opting to send direct emails to certain customers only. I personally heard about it second-hand. Nevertheless, the impact was felt by long-time users who had integrated these features into their device management workflows. The situation worsened then in April; Goto further restricted the free tier by limiting mass actions — a cornerstone feature for any MDM solution. According to the official announcement: We have modified our Free plan and limited the mass actions. From now on, Free plan customers can: Deploy configuration profiles one device at a time Synchronize a single device at a time These changes effectively crippled the efficiency that Miradore once offered. Administrators now have to perform repetitive tasks individually for each device, a tedious process that is impractical for organisations managing more than a handful of devices. But Goto isn't finished. Later this year, they have announced plans to cap the number of devices on the free plan to 50, down from unlimited. The forthcoming changes were communicated through another release note recently. Yes, effectively unlimited devices down to 50. They aren't adjusting the tier functionality either, so it remains quite limited in capability after this change also. The impact on organisations # Obviously paying customers on higher tiers are wholly unaffected by these changes, and the remaining Miradore team within Goto continue to do a wonderful job with their customer base. That said, many of the paying customers they have will have come in through their free tier, often selected because organisations could get started and grow their estates without a licence commitment. These cumulative changes have made Miradore's free tier not just limited but virtually unusable for organisations of any moderate size and/or complexity, and pit Miradore far more directly with competing platforms, such as Manage Engine's 25 free licences. Fewer, yes, but not feature-limited. If you're going to enforce limits, you'd be wise typically to pick a path - limited licences, or limited functionality. The removal of both critical features and the imposition of device limits is a double-whammy that offers the worst of both worlds. I'd ask how they expect groups on the free tier to remain loyal to a platform driven by decisions that scream "we don't want you here", but it seems apparent they haven't considered the question. As someone who has championed Miradore for nearly a decade, I find this trajectory disheartening. The platform's Unique Selling Proposition (USP) was its robust free tier, which allowed organisations — especially smaller groups and communities with tight budgets — to manage their Android devices effectively without incurring additional costs, and I have directed hobbyists, charities, and indeed potential customers their way for years to benefit from this in order to take a first step into the enterprise management ecosystem. Goto's strategy appears to be undermining this USP entirely. By going down the path they've chosen, they're alienating the very user base that helped Miradore grow. It's a puzzling move, especially when considering that the MDM market is more competitive than ever, and my sympathies go out to the remaining Miradore team suffering the consequences of these mandates. Conclusion # Miradore's journey from a promising entry point into device management to its current state of limited functionality on a finite number of devices is a cautionary tale of how acquisitions can sometimes erode the very qualities that gave a product its place in a market. Goto's incremental worsening of their product will fundamentally change what Miradore offers, making it less appealing to organisations that may have used it as a jumping point into a higher tier at a later date, and more likely to be bundled with competing platforms in the decision-making process, unfortunately some with more compelling trial / free tiers than Miradore will soon offer. My hope going forward is these changes derive very real, measurable impacts on user acquisition and retention, and force Goto to revert. Better still if they also then choose to step back and let the folks who built and know the product define how it should be positioned and operated in the market going forward.

  • How Goto's acquisition of Miradore is eroding a once-promising MDM solution
    by Jason Bayton on September 24, 2024 at 12:00 am

    Back in 2014, I discovered Miradore, an ITSM solution with a then-emerging Mobile Device Management (MDM) product that promised a robust set of features for managing Android devices. My initial review, Miradore Online: Free MDM, highlighted the platform's potential and its generous free tier, which made it stand out in a market otherwise dominated by costly alternatives. Miradore isn't defined by their free tier, of course, there's a rather large and feature-rich product behind it. It's what drew me in to their product in the first place however, and has been a consistent, defining feature of their platform for more than a decade. Over the years, I revisited Miradore multiple times, documenting its growth and the expansion of its feature set in articles like Miradore Online MDM Review: A Second Look and Miradore Online MDM: Expanding Management with Subscriptions. In 2022, when Miradore announced its acquisition by Goto, I met the news with cautious optimism. Goto, a company known for its suite of remote work tools, seemed like a reasonably safe choice to nurture Miradore's growth. Official announcements from both parties, such as Goto Acquires Miradore and Miradore Acquired by Goto: What Happens Next?, painted a rosy picture of enhanced resources and expanded capabilities. However, the honeymoon period is certainly over now. Since the acquisition, Goto has more and more shown its disdain for Miradore's core MDM USP, systematically stripping away key features from the free tier and fundamentally altering the product's value proposition and accessibility. The erosion of the free tier # Last December, a significant change came when Goto removed essential functionalities from the free plan. Email configuration, VPN setup, Wi-Fi settings, contacts management, and mail were no longer accessible without a paid subscription. Details of these changes weren't outlined in Miradore's release notes, instead opting to send direct emails to certain customers only. I personally heard about it second-hand. Nevertheless, the impact was felt by long-time users who had integrated these features into their device management workflows. The situation worsened then in April; Goto further restricted the free tier by limiting mass actions — a cornerstone feature for any MDM solution. According to the official announcement: We have modified our Free plan and limited the mass actions. From now on, Free plan customers can: Deploy configuration profiles one device at a time Synchronize a single device at a time These changes effectively crippled the efficiency that Miradore once offered. Administrators now have to perform repetitive tasks individually for each device, a tedious process that is impractical for organisations managing more than a handful of devices. But Goto isn't finished. Later this year, they have announced plans to cap the number of devices on the free plan to 50, down from unlimited. The forthcoming changes were communicated through another release note recently. Yes, effectively unlimited devices down to 50. They aren't adjusting the tier functionality either, so it remains quite limited in capability after this change also. The impact on organisations # Obviously paying customers on higher tiers are wholly unaffected by these changes, and the remaining Miradore team within Goto continue to do a wonderful job with their customer base. That said, many of the paying customers they have will have come in through their free tier, often selected because organisations could get started and grow their estates without a licence commitment. These cumulative changes have made Miradore's free tier not just limited but virtually unusable for organisations of any moderate size and/or complexity, and pit Miradore far more directly with competing platforms, such as Manage Engine's 25 free licences. Fewer, yes, but not feature-limited. If you're going to enforce limits, you'd be wise typically to pick a path - limited licences, or limited functionality. The removal of both critical features and the imposition of device limits is a double-whammy that offers the worst of both worlds. I'd ask how they expect groups on the free tier to remain loyal to a platform driven by decisions that scream "we don't want you here", but it seems apparent they haven't considered the question. As someone who has championed Miradore for nearly a decade, I find this trajectory disheartening. The platform's Unique Selling Proposition (USP) was its robust free tier, which allowed organisations — especially smaller groups and communities with tight budgets — to manage their Android devices effectively without incurring additional costs, and I have directed hobbyists, charities, and indeed potential customers their way for years to benefit from this in order to take a first step into the enterprise management ecosystem. Goto's strategy appears to be undermining this USP entirely. By going down the path they've chosen, they're alienating the very user base that helped Miradore grow. It's a puzzling move, especially when considering that the MDM market is more competitive than ever, and my sympathies go out to the remaining Miradore team suffering the consequences of these mandates. Conclusion # Miradore's journey from a promising entry point into device management to its current state of limited functionality on a finite number of devices is a cautionary tale of how acquisitions can sometimes erode the very qualities that gave a product its place in a market. Goto's incremental worsening of their product will fundamentally change what Miradore offers, making it less appealing to organisations that may have used it as a jumping point into a higher tier at a later date, and more likely to be bundled with competing platforms in the decision-making process, unfortunately some with more compelling trial / free tiers than Miradore will soon offer. My hope going forward is these changes derive very real, measurable impacts on user acquisition and retention, and force Goto to revert. Better still if they also then choose to step back and let the folks who built and know the product define how it should be positioned and operated in the market going forward.

  • Google Play Protect no longer sends sideloaded applications for scanning on enterprise-managed...
    by Jason Bayton on September 23, 2024 at 12:00 am

    In a surprise announcement last week, Google have confirmed sideloaded applications - such as those deployed via EMM solutions - will no longer be sent to Google servers for Google Play Protect scanning on enterprise-managed devices. Why apps are sent to Google # When an application is installed from a source other than Google Play, it is not considered safe by default. Google Play Protect, as part of the round-the-clock security it provides, tries to verify it. If the application doesn't match any known applications in the GPP database, it will ask the end user of the device to allow GPP to send the application up to Google's dedicated infrastructure to run the necessary security verifications. This off-device service then undertakes the necessary tasks to ensure it's safe, devoid of anything harmful, and any future devices that install the application benefit from GPP knowing of its existence ahead of time. This doesn't happen with applications that come down from Google Play because they've already undergone this security validation during the Play Store approval process. GPP knows the application, knows where it's from, and in most cases now sees an association with Google Play in the application metadata itself. Why organisations dislike it # While the service itself really can't be knocked (free security), the approach of requesting from end-users whether an application can be sent to Google is troublesome. If an organisation relies on in-house, or line of business, applications typically installed via the EMM agent directly (rather than using the Google Play iFrame or console uploaded as a private application), they may be familiar with this on-device prompt: Source: Google A disruptive, and oft-confusing interruption for end-users, this has caused questions around the quality, security, and trustworthiness of non-Google Play installed applications for years now. It is an entirely-consumer approach forced upon enterprise devices with no administrative control; had an API been present to define the answer to the above prompt (akin to how organisations can set permissions, for example) this likely wouldn't have been an issue. What's changing # As of the 6th of September (2024), applications sideloaded onto enterprise-managed devices, via any means, will no longer be sent for scanning, and thus the prompt will no longer present itself. It is, in effect, a permanent "Don't send" preset for applications installed either into the parent profile for device owner deployments (fully managed, dedicated), or the work profile of a profile owner deployment, so yes, it applies to personally owned work profile devices also. What it means for organisations # While sending applications for scanning will no longer be done, Google Play Protect remains active on devices. This is not a full disablement of on-device security, as on-device detection and prevention continues to function; known malicious apps, however they're installed, will still be flagged and may be removed. Beyond this, nothing really changes in terms of recommendations for the overall management of applications from unknown sources. Where possible it should be blocked by default. How this came to be # This announcement stems from a lengthy & passionate post on the Android Enterprise Customer Community, further highlighting the importance of the CC for direct feedback into Google and respective product teams. It's a considerable win for the community and those who use it 😁 If you're on the fence about joining up to share your own feedback, I would hope this example of Google and the customer ecosystem working together to improve the experience for everyone offers the nudge you need. Find a link to join in the share box below 👇

  • Google Play Protect no longer sends sideloaded applications for scanning on enterprise-managed...
    by Jason Bayton on September 23, 2024 at 12:00 am

    In a surprise announcement last week, Google have confirmed sideloaded applications - such as those deployed via EMM solutions - will no longer be sent to Google servers for Google Play Protect scanning on enterprise-managed devices. Why apps are sent to Google # When an application is installed from a source other than Google Play, it is not considered safe by default. Google Play Protect, as part of the round-the-clock security it provides, tries to verify it. If the application doesn't match any known applications in the GPP database, it will ask the end user of the device to allow GPP to send the application up to Google's dedicated infrastructure to run the necessary security verifications. This off-device service then undertakes the necessary tasks to ensure it's safe, devoid of anything harmful, and any future devices that install the application benefit from GPP knowing of its existence ahead of time. This doesn't happen with applications that come down from Google Play because they've already undergone this security validation during the Play Store approval process. GPP knows the application, knows where it's from, and in most cases now sees an association with Google Play in the application metadata itself. Why organisations dislike it # While the service itself really can't be knocked (free security), the approach of requesting from end-users whether an application can be sent to Google is troublesome. If an organisation relies on in-house, or line of business, applications typically installed via the EMM agent directly (rather than using the Google Play iFrame or console uploaded as a private application), they may be familiar with this on-device prompt: Source: Google A disruptive, and oft-confusing interruption for end-users, this has caused questions around the quality, security, and trustworthiness of non-Google Play installed applications for years now. It is an entirely-consumer approach forced upon enterprise devices with no administrative control; had an API been present to define the answer to the above prompt (akin to how organisations can set permissions, for example) this likely wouldn't have been an issue. What's changing # As of the 6th of September (2024), applications sideloaded onto enterprise-managed devices, via any means, will no longer be sent for scanning, and thus the prompt will no longer present itself. It is, in effect, a permanent "Don't send" preset for applications installed either into the parent profile for device owner deployments (fully managed, dedicated), or the work profile of a profile owner deployment, so yes, it applies to personally owned work profile devices also. What it means for organisations # While sending applications for scanning will no longer be done, Google Play Protect remains active on devices. This is not a full disablement of on-device security, as on-device detection and prevention continues to function; known malicious apps, however they're installed, will still be flagged and may be removed. Beyond this, nothing really changes in terms of recommendations for the overall management of applications from unknown sources. Where possible it should be blocked by default. How this came to be # This announcement stems from a lengthy & passionate post on the Android Enterprise Customer Community, further highlighting the importance of the CC for direct feedback into Google and respective product teams. It's a considerable win for the community and those who use it 😁 If you're on the fence about joining up to share your own feedback, I would hope this example of Google and the customer ecosystem working together to improve the experience for everyone offers the nudge you need. Find a link to join in the share box below 👇

  • Mobile Pros is moving to Discord
    by Jason Bayton on July 22, 2024 at 12:00 am

    Mobile Pros has been a slack group since inception, way back in the late 2010s. One of the biggest bug-bears for that platform is Slack's hostile approach to non-paying communities, withholding message history and denying access to attachments; it's meant a lot of valuable information over the years has vanished into the ether and put the community on the back-foot compared to other platforms in the ecosystem, which retain a wealth of available wisdom from their collective members. While it's arguable the ecosystem moves quickly and information soon becomes dated, I say yes and no. Specific questions about Intune or a version of iOS more than a couple of years old? Sure, it has an expiry due to the pace of development and change (perhaps Intune wasn't a great example for pace... heh), but a lot of information - the basics of management, approaches to security, best practices, etc. - change far less over time (just look at the docs here to see things from 2019 still relevant today), and means rewriting the same answers over and over with the Slack we have. Well, as of August, Slack will start deleting old history entirely. I've always wanted to find a way to make access to past messages, solutions, and discussions viable on Slack, even to the point of asking around for sponsorship opportunities, but it's simply not feasible, and so after months of thought and discussion between our core members, the Mobile Pros community is moving from Slack to Discord. Why Discord? Predominantly the popularity of the platform, but equally the reasonable parity of function between that and Slack to avoid it being too-jarring an experience to migrate. It goes without saying Discord has some great community features we can leverage as well, and I'm looking forward to putting these into use. On polling the existing community, Discord won out, with Rocket.Chat, Mattermost, Discourse, and others also considered, though with any community it's immeasurably important to ensure ease of access and simplicity of engagement; my concern with rolling a hosted instance of an (arguably easier to manage) FOSS community platform would be yet another account on yet another platform which I know can put people off. The Mobile Pros community has been going strong over the years and has nearly 1,900 members. While I expect to lose a few of you during the migration, I'm hopeful that most of you will join us on Discord. I know moving platforms can be a farce, but Discord is a very popular platform (far more so than when we looked at it back in 2021!) and I'm hopeful the move won't be too off-putting. The Slack Mobile Pros group will be officially shutting down come August, but engagement there is actively discouraged already as content will not be migrated over to Discord automatically (and I spent a week doing it all manually!). If you want to continue engaging with Mobile Pros or if you’ve been thinking about joining, now’s the perfect time to get involved. You can start joining our new Discord community today. Just follow this link to get started. I look forward to seeing you all there! (Oh, and for good measure, I've also pushed a static copy of Mobile Pros' Slack history to archive.mobilepros.org through the exceptionally simple tool from hfran. I was doing the work to migrate, I figured I might as well!) ^ Not any more 🙂

    Feed has no items.

Brooks Peppin's Blog Managing Windows in the Modern Workplace

Many Miles Away Helping you succeed with end user computing technologies

    Feed has no items.

    Feed has no items.

Sam Akroyd. Thoughts on Tech

  • Workspace ONE UEM Sensors and custom Registry values
    by techhub981158167 on June 10, 2024 at 12:58 pm

    I had a customer enquiry recently where they were looking to pull some custom fields from a device to identify a device location, well at least where it was deployed, as well as come custom tags and other information they associate with a device at the time of deployment. If you have used Workspace ONE … Continue reading Workspace ONE UEM Sensors and custom Registry values →

  • VMware App Volumes Apps on Demand
    by techhub981158167 on January 8, 2024 at 3:26 pm

    There are plenty of articles explaining what VMware App Volumes Apps on Demand are and the benefits, for example https://www.vmware.com/uk/topics/glossary/content/apps-on-demand.html. This video demonstrates how quick and east it is to associate an App Volumes Server with an RDS Host in VMware Horizon and subsequently deliver a package using Apps on Demand.

  • End of Year
    by techhub981158167 on December 20, 2023 at 10:14 am

    When I started this blog and YouTube channel a few years back I never really had a target other than to share any tips, tricks, information and how to for various EUC products. It’s always nice to see the end of year stats and know that people are looking at your content. Diving into the … Continue reading End of Year →

  • The next phase of Workspace ONE UEM Sensors
    by techhub981158167 on December 8, 2023 at 11:14 am

    Earlier this year I wrote a blog article about using ChatGPT to write PowerShell scripts that could be used in Workspace ONE UEM to create Sensors. This works fine, but bear in mind that ChatGPT created PowerShell scripts for me based on best endeavours, there is no guarantee they would work or would not contain … Continue reading The next phase of Workspace ONE UEM Sensors →

  • Workspace ONE UEM and Windows Multi User
    by techhub981158167 on August 23, 2023 at 3:48 pm

    Multi User or Shared Device, if you want to look at it that way, is something that has been supported with VMware Workspace ONE UEM but more so for Mobile Operating Systems rather than Windows. VMware has received feedback from several customers on wanting to be able to support a Windows Multi User use case. … Continue reading Workspace ONE UEM and Windows Multi User →

Thomas Cheng Welcome to my digital home!

VirtuallyUnboxed Lifting the lid on everything virtual

  • End of support for vSphere 6.5.x and 6.7.x
    by virtuallyunboxed on October 20, 2022 at 4:31 pm

    In case you missed it, last week marked the end of general support for vSphere 6.5 and 6.7. This is the same regardless of whether you were using it for data centre services or EUC services like Horizon.

  • Desktop Repurposing v4
    by virtuallyunboxed on October 20, 2022 at 4:23 pm

    This year, myself and Matt Evans joined forced again, along with newcomer, Jonathan D'arcy to review some of the best desktop repurposing tools on the market. As with previous years we reviewed imaging and performance. However, this year we also took a look at the accompanying management solutions.

  • VMware SASE and Cloud Web Security
    by virtuallyunboxed on January 22, 2022 at 3:11 pm

    Let's start with the basics! SASE is a Gartner term and is an abreviation of Secure Access Service Edge. Still not much help right? Well lets start explaining this by looking at how people typically work, espeically remotely, and how their traffic is secured. Most of you that ever work remotely will most likely use a device level VPN. This uses software on your device to create a tunnel into your company data centre and allows you to remotely access internal resources. This is how most companies have done it for many years, and it really dates back to the days when all a companies resources were in their own data centre. Tunnelling all the traffic back into the data centre was the perfect way to reach everything a remote user would need.

  • Workspace ONE UEM and Workspace ONE Access Integration for Hub Services
    by virtuallyunboxed on March 2, 2021 at 4:06 pm

    I know there are a lot of SaaS customers out there who have only been using basic MDM functionality within Workspace ONE. The platform has moved on a lot in the last few years and if you haven't already seen it i strongly suggest you check out hub services. This takes the Workspace ONE agent that is used for device management and adds additional functionality to the application such as a unified app catalogue, people search and a notifications platform to name but a few!

  • Workspace ONE Access FIDO2 integration
    by virtuallyunboxed on February 19, 2021 at 2:33 pm

    As of this month (Feb 2021) All Workspace ONE Access SaaS tenants, now supports FIDO2 as an authentication method. So, I thought i'd put together a short video showing how easy it is to configure it and some different device types using the solution.

Mobile Jon's Blog My WordPress Blog

  • Deep Dive into Windows Sudo
    by [email protected] on October 14, 2024 at 4:00 am

    This week, the focus shifts to Windows Sudo, which allows local admins to elevate commands without full admin access. The content discusses how Windows Console functions, the workings of Windows Sudo, and its code structure. Future discussions will delve deeper into its operation and monitoring through Process Monitor.

  • Windows 11 24H2 Overview
    by mobilejon on October 7, 2024 at 4:00 am

    This past week, we saw a new version of Windows 11 (highly anticipated as well) with 24H2. It’s a very

  • Introducing RDP Shortpath: Optimizing Windows 365 Connectivity
    by [email protected] on October 1, 2024 at 6:25 pm

    Windows 365 has introduced RDP Shortpath, optimizing connections between client devices and Cloud PCs. RDP Shortpath utilizes a direct UDP connection for reducing latency and increasing reliability. It leverages STUN and TURN technologies for network navigation. Proper configuration and troubleshooting of UDP settings ensure the effective use of RDP Shortpath, enhancing user experience.

  • Automating Corporate Device Identifier Imports with Power Automate and the Graph API
    by [email protected] on September 23, 2024 at 4:00 am

    The article discusses the author's positive experience with Windows Autopilot v2, focusing on the integration of corporate identifiers into Intune through a Power Automate solution. It details the process of extracting data from CDW emails, filtering valid device purchases, and constructing API requests for device identity import, ultimately enhancing device management efficiency.

  • The Magnificent 8 Conditional Access Policies of Microsoft Entra
    by [email protected] on September 9, 2024 at 4:00 am

    The blog discusses crucial conditional access policies for standard customers, emphasizing conditional access decision signals, strategies, and specific policies like MFA for all users, blocking legacy authentication, enforcing device compliance, and more. It emphasizes the need for thorough testing, monitoring, and simplicity to build a robust security strategy in Microsoft Entra.

Omnissa | Tech Zone Go from zero to hero with the latest technical resources on the VMware Digital Workspace Tech Zone.

VMware Workspace ONE The un-official subreddit for VMware Workspace ONE. I recently started learning/managing Workspace One for the company I work for, I came to reddit to find others and saw that there wasn’t a community, so I started one. Our discord is here https://discord.gg/Zhr3TqMMf6

  • migrate ws1 saas environment to another existing ws1 saas environment
    by /u/evilteddibare on October 17, 2024 at 4:09 pm

    We just bought another company which already has ws1 and we want to look at migrating the confiigs/profiles and everything over to our ws1 environment. We are wanting to create a new OG for that company and just put everything under there. Does anyone have experience doing a migration like this or is there a guide/tutorial/existing migration plans? submitted by /u/evilteddibare [link] [comments]

  • Omnissa Contact
    by /u/teedubyeah on October 17, 2024 at 1:01 pm

    Does anyone have contact information for Omnissa other than the fillable form on the website? I'm trying to figure out who our account rep is for renewals and I'm not getting anyone to call me back. submitted by /u/teedubyeah [link] [comments]

  • LDAP-Sync --> Fail
    by /u/Prof_Hase on October 14, 2024 at 2:01 pm

    https://preview.redd.it/ekoklfgiaqud1.png?width=1841&format=png&auto=webp&s=e3fab20793c28ae9489f215675809f6aa12dc292 Why? My User ist Consolen Admin Cloud and Version: 24.6.0.4 (2406) submitted by /u/Prof_Hase [link] [comments]

  • removing the default launcher
    by /u/daj_dasa1986 on October 14, 2024 at 10:01 am

    Hello everyone, i have been experiencing some issues while staging/enrolling decices to Workspace one. The problem is that the default launcher keeps installing and launching on all devices. and making devices almost unusable. Please help. submitted by /u/daj_dasa1986 [link] [comments]

  • Issue renewing vpp stoken
    by /u/parfect12 on October 10, 2024 at 8:11 pm

    i am trying to update my vpp stoken. i am at the step where i have uploaded the file and hit "save" it stays on that screen and a spinning wheel shows and it just sits there. i have tried multiple times with the same results. i was able to update my DEP token in between attempts with no issues. Any ideas? support ticket has been placed. https://preview.redd.it/7c8kz8xmkztd1.png?width=753&format=png&auto=webp&s=f2dff1c1ef226e89d00f0be1a7ff3c04eac3b718 submitted by /u/parfect12 [link] [comments]

  • profiles stuck on "pending install" - Win11-24H2
    by /u/omer-meister-smwb on October 9, 2024 at 1:38 pm

    hi there all, i have a really annoying problem lately, i think it maybe related to the 24H2 version. i have just formatted the computer, enrolled it, and only some of the profiles came in. they other are stuck on "pending install", i let it stay for a while and nothing changed. on other computers it works as usual. i didn't mess with any special windows settings. thanks in advance submitted by /u/omer-meister-smwb [link] [comments]

  • Need help register iphones in WS1.
    by /u/EDV_Sepp on October 9, 2024 at 5:18 am

    Good morning, we have a problem with our new iphones SE and Workspace One. We are unable to register the devices. We can sync the devices from Apple Business Manager to WS1 no problem. I can see the Phones under Devices -> Lifecycle -> Enrollment Status. But when we try to set up the phone, we receive an error that the credentials are wrong. We created a profile under Device Enrollment Program, the profile is assigned to the device. We assign the profile to one OU Group an used a User from that group. We don't sync users from M365 or other sources, just WS1 internal Users. But no dice. Maybe someone has a idea. Kind regards EDV_Sepp submitted by /u/EDV_Sepp [link] [comments]

  • Boxer and G-Suite enterprise
    by /u/nate_cyber on October 8, 2024 at 10:37 pm

    Anyone got Boxer working on iOS and also using G-Suite enterprise? I'm struggling getting a working configuration pushed out and documentation seems to be considerably lacking. If I deliberately do a config with broken user name, I can get the manual config to at least authenticate with Google, but sync seems broken (still investigating that issue)l It also seems to rely on google sync, which they plan to EOL starting this year, so will this continue to work? Curious if others got this working smoothly. submitted by /u/nate_cyber [link] [comments]

  • Adding Devices - Not Sending Enrollment Message
    by /u/CR00KII84 on October 8, 2024 at 8:52 pm

    Tried enrolling two personal devices today (one apple & one android) and nothing gets sent to the device to register with hub. I've tried both SMS and email. They are also in the Enrollment Status page when I look and say registration is active. What am I missing? submitted by /u/CR00KII84 [link] [comments]

  • How to Unenroll a Computer from Workspace One Without Disrupting Azure AD Joined Account
    by /u/the_elite_fish on October 8, 2024 at 7:06 pm

    Does anyone know how I can unenroll Windows 11 from Workspace One without breaking the Azure AD joined connection? Currently, when I unenroll computers that are enrolled through Autopilot, the Entra user account gets deleted on the computer. I want to avoid that. The computer is chaning MDM system. Thanks! submitted by /u/the_elite_fish [link] [comments]

  • IOS update deployment delaying?
    by /u/BarberTypical147 on October 8, 2024 at 6:41 pm

    Wondering if anyone else has noticed this in the last few IOS updates that hit. It seems that the last 2 or 3 IOS updates we'll put in a scheduled update, but ultimately only pushes out to 5 or 6 devices out of 150. We have to go in and query all of the devices after the scheduled time (set to download and install) for the other devices to start downloading the update. The devices are seen in WSO well after the scheduled time and most are left on the night before an update. Before 17.7, no problems with pushing out the update. Has anyone else noticed this, or is it just us? We've made a few changes here but nothing that should affect WSO or the Apple devices in our environment. submitted by /u/BarberTypical147 [link] [comments]

  • Apple devices / compliance issues
    by /u/DreVahn on October 4, 2024 at 4:16 pm

    Trying to figure out an inconsistent issue my Team is having with Apple devices in our MDM. Not all, but quite a few devices are showing non-compliance with encryption and password on Apple Cells and Tablets right after entering a password on the device after signing into Hub. I just signed into a test phone and have it. Syncing the device does not clear it. My team will be deploying over 2,000 phones after the new year and need to get this worked out. Any leads on a solution ? Thanks in advance. P.S. No issues with Androids. submitted by /u/DreVahn [link] [comments]

  • Add Permanent Watermark
    by /u/mbrownwrites on October 4, 2024 at 2:22 pm

    Okay, am I blind? I want to add watermarks to all documents that are emailed out of WS1 Content Manager. All I’ve found so far is the ability to add a watermark when VIEWING images saved to local storage on the device (iOS devices). We need the watermark to follow it when it’s sent via email, but it’s not. Seems like a poor implementation of DLM. I’m assuming I’m missing something? submitted by /u/mbrownwrites [link] [comments]

  • Trying to understand what claims are available to me when using OpenIDConnect/OAuth from WSOne
    by /u/usa_commie on October 3, 2024 at 1:52 pm

    When using SAML I used to just have an extension and could see all the passed claims, but I'm having trouble doing so currently. I was using sub in a subsequent client as the username claim, but it kept on appending myuser@[mydomain.com@mywsoneserver](mailto:mydomain.com@mywsoneserver). Eventually I got it to work with just "email". I'm now looking for what claim contains the groups and to troubleshoot what they are set to. I'm attempting to develop a curl to get the JWT myself, but unable to do so. Any hints? Edit: I managed to get the OpenID JWT and it looks like this and I'm confused. ``` { "jti": "cb7f18a3-ff80-4af0-bbdb-8d063ddc6188", "prn": "[email protected]@VMWARE-IDM1", "domain": "mydomain.com", "user_id": "15", "auth_time": 1727964339, "iss": "https://wsone.mydomain.com/SAAS/auth", "aud": "https://wsone.mydomain.com/SAAS/auth/oauthtoken", "ctx": "[{\"mtd\":\"http://schemas.microsoft.com/claims/multipleauthn\\",\\"iat\\":1727964338,\\"id\\":61,\\"typ\\":\\"8b6a0144-39c4-4162-9e1d-baa5e887323a\\",\\"idm\\":false}\]", "scp": "openid profile email", "idp": "0", "eml": "[email protected]", "cid": "pinniped", "did": "", "wid": "", "pid": "cb7f18a3-ff80-4af0-bbdb-8d087cce9188", "exp": 1727976533, "iat": 1727965733, "sub": "e119f91c-1ddc-4b0c-97d0-c5da88ce2569", "prn_type": "USER" } ``` Which begs two questions: "email" claim works, but I don't see it in this JWT what soever! There is also no groups in here whatsoever. I see no other way to force WS One to attach these claims? submitted by /u/usa_commie [link] [comments]

  • iOS user enrollment and VPP apps not getting pushed to all users
    by /u/nate_cyber on October 2, 2024 at 7:13 pm

    Got a frustrating issue and not getting much help from Omnissa currently. I'm building out our WS1 UEM environment and for iOS we're doing user account driven enrollment. For a couple of test users, they got the hub app pushed out to their iOS device. For another two test users, I cannot get the hub app, or any apps to deploy. APNS - all good, all users get all profiles Managed Apple IDs - identical for working and non working users VPP apps are sync'd so not a token issue (and some users get the app) If I look at the hub app under resources and manage devices, I see the VPP invite status for users that have the app as accepted. For the users that do not get the app, it says VPP invite status as not accepted. I'm wondering if this is the issue, but when I re-invite the non working users from that same section, nothing happens or changes. I cannot find a way of getting them to receive or accept an invite. Cannot see any errors, it just doesn't prompt on the device. Anyone got any ideas of things to try? It's a very frustrating issue! submitted by /u/nate_cyber [link] [comments]

  • the picture doesn't shown in boxer app
    by /u/Impressive-Gas-4630 on September 28, 2024 at 9:01 pm

    when an email with inserted photos in the body of the email, it does not shown completely.any one have this issue before and how to solve it? https://preview.redd.it/au6gu36t6mrd1.jpg?width=709&format=pjpg&auto=webp&s=5eb1f1abb3e5e7076af781e29fc893f0c88fe7eb submitted by /u/Impressive-Gas-4630 [link] [comments]

  • Outlook iOS App Configuration Policy
    by /u/LupoNupo on September 27, 2024 at 4:20 pm

    Hey i want to deploy Outlook iOS App with App Configuration. We are currently using a couple of M365 like Teams, MS Auth, ... When i deploy Outlook App my Email is picked up (I still have a little doubt that my email is found by AppConfig instead of because I am registered in Teams) But these two setting for example are not applied. I see my Test Contact in the Outlook App but i cant see it in Native iOS Contact App. Same goes for the User Button to enable contact sync. I get the message that it blocked by IT Admin. com.microsoft.outlook.Contacts.LocalSyncEnabled com.microsoft.outlook.Contacts.LocalSyncEnabled.UserChangeAllowed Is there anything special in applying app config to Outlook App with Workspace One I used this documentation for keys and values > Deploying Outlook for iOS and Android app configuration settings in Exchange Online | Microsoft Learn This is what i send out using the GUI Settings (not xml upload) |com.microsoft.outlook.EmailProfile.EmailAccountName|String|{UserPrincipalName}| |com.microsoft.outlook.EmailProfile.EmailAddress|String|{UserPrincipalName}| |com.microsoft.outlook.EmailProfile.EmailUPN|String|{UserPrincipalName}| |IntuneMAMUPN|String|{UserPrincipalName}| |IntuneMAMAllowedAccountsOnly|String|Enabled| |com.microsoft.outlook.Contacts.LocalSyncEnabled|Boolean|true| |com.microsoft.outlook.Contacts.LocalSyncEnabled.UserChangeAllowed |Boolean|true| submitted by /u/LupoNupo [link] [comments]

  • Workspace ONE Send
    by /u/Express_Manager5455 on September 27, 2024 at 3:48 pm

    Has anyone set up or used Workspace ONE Send. I am figuring out if my department needs to set this up. Do you have the o365 apps already installed will this affect or help? Workspace ONE UEM offers Workspace ONE Send, an application that connects Microsoft Azure-managed Office 365 apps to Omnissa Workspace ONE Boxer and Omnissa Workspace ONE Content. With Workspace ONE Send, you can access Intune-protected Microsoft Office files in the Boxer or Content app. If you have Intune protection and want to open a word document, PowerPoint presentation, Excel spreadsheet, or other office file, you can do so first in the Workspace ONE Send app and after that in the Boxer or Content app. Because of Intune protection, you cannot open the Microsoft Office files directly in Content or Boxer. So, the Send app enables interoperability between Office 365 apps managed by Microsoft Azure and Omnissa apps. submitted by /u/Express_Manager5455 [link] [comments]

  • Question about new Restriction Profile "Preserve eSIM on Erase"
    by /u/jmnugent on September 27, 2024 at 3:44 pm

    Hey All, I see in WS1 Console upgrade 2406,.. of the new iOS Restriction profiles we now finally have "Preserve eSIM on Erase",. however if you hover over the "!" button it says: "Select to force eSIM preservation when when a device is erased due to too many failed password attempt or the "Erase All Content and Settings" option in Settings > General > Reset. eSIM will not be preserved if the device is erased by Find My." So I'm trying to understand what that means in practical day to day use. 1.) I should know the answer to this,. but does eSIM get preserved on DFU Mode wipe ? (I'm leaning towards suspecting YES) 2.) If we have this Restriction in place "Preserve eSIM on Erase".. and we go into WS1 Console and send a Factory Wipe,. do we still need to check the box that says "Preserve Data Plan" ... ? (I'm assuming YES) 3.) On a Supervised Device,. if a User has a personal AppleID, .. and is able to login to Find My on another device (say, personal MacBook). .and send a wipe to the Supervised Phone,. the wording here makes me think "Find My" will over-ride this Restriction. So I guess I'm trying to wrap my head around how or IF this Restriction Profile even helps us ? What we'd like to prevent is "accidental eSIM wipe" .. (for example.. if a Technician sends a Device Wipe command and FORGETS to check the box "Preserve Data Plan".. we'd like the eSIM to still be protected against wipe. Does this achieve that ?. .I can't quite tell for sure. submitted by /u/jmnugent [link] [comments]

  • Email encryption iOS 18.1 beta
    by /u/Ok-WS1-1994 on September 27, 2024 at 11:48 am

    While we are trying to install certificate getting this 'An error occurred, please try again. Airwatch: No iOS devices were found for the user" Device is enrolled and certificate showing install. And only one user facing this issue with all his device but previously that user can encrypte email from his old device. Any update much appreciated submitted by /u/Ok-WS1-1994 [link] [comments]

The Support Insider VMware Support News, Alerts, and Announcements

  • Simpler Licensing with VMware vSphere Foundation and VMware Cloud Foundation 5.1.1
    by Kelcey Lemon on March 21, 2024 at 5:28 pm

    Tweet VMware has been on a journey to simplify its portfolio and transition from a perpetual to a subscription model to better serve customers with continuous innovation, faster time to value, and predictable investments. To that end, VMware recently introduced a simplified product portfolio that consists of two primary offerings: VMware Cloud Foundation, our flagship … Continued The post Simpler Licensing with VMware vSphere Foundation and VMware Cloud Foundation 5.1.1 appeared first on VMware Support Insider.

  • VMware Skyline Advisor Pro Proactive Findings – January 2024 Edition
    by James Walker on January 24, 2024 at 11:16 am

    Tweet VMware Skyline Advisor Pro releases new proactive Findings every month. Findings are prioritized by trending issues in VMware Technical Support, issues raised through post escalation review, security vulnerabilities, issues raised from VMware engineering, and nominated by customers. For the month of January, we released 60 new Findings. Of these, there are 37 Findings based … Continued The post VMware Skyline Advisor Pro Proactive Findings – January 2024 Edition appeared first on VMware Support Insider.

  • Skyline Advisor Pro: Introducing Inventory Export Reports
    by Kelcey Lemon on January 16, 2024 at 12:00 pm

    Tweet You’ve asked for the ability to export inventory information, including licensing, and we’ve listened. The Skyline Team is proud to introduce this highly requested feature, Inventory Export Reports. Inventory Export Reports allow you to generate reports on your inventory, licensing, and configuration data. These reports can help you to identify potential problems, track changes … Continued The post Skyline Advisor Pro: Introducing Inventory Export Reports appeared first on VMware Support Insider.

  • VMware Skyline Advisor Pro Proactive Findings – December 2023 Edition
    by James Walker on December 15, 2023 at 6:56 pm

    Tweet VMware Skyline Advisor Pro releases new proactive Findings every month. Findings are prioritized by trending issues in VMware Technical Support, issues raised through post escalation review, security vulnerabilities, issues raised from VMware engineering, and nominated by customers. For the month of December, we released 56 new Findings. Of these, there are 35 Findings based … Continued The post VMware Skyline Advisor Pro Proactive Findings – December 2023 Edition appeared first on VMware Support Insider.

  • VMware Skyline Advisor Pro: Proactive and Diagnostic Findings Demystified
    by Kelcey Lemon on December 13, 2023 at 3:07 pm

    Tweet While supporting VMware Explore 2023 in Barcelona, a customer asked me, “What’s the difference between Proactive Findings and Diagnostic Findings in Skyline Advisor Pro and how are each one produced?” So, I’d like to take this moment to elaborate more on my original blog that introduced Diagnostic Findings. Proactive Findings Proactive Findings are potential … Continued The post VMware Skyline Advisor Pro: Proactive and Diagnostic Findings Demystified appeared first on VMware Support Insider.

  • VMware Skyline Advisor Pro Proactive Findings – October 2023 Edition
    by James Walker on October 27, 2023 at 4:33 pm

    Tweet VMware Skyline Advisor Pro releases new proactive Findings every month. Findings are prioritized by trending issues in VMware Technical Support, issues raised through post escalation review, security vulnerabilities, issues raised from VMware engineering, and nominated by customers. For the month of October, we released 39 new Findings. Of these, there are 30 Findings based … Continued The post VMware Skyline Advisor Pro Proactive Findings – October 2023 Edition appeared first on VMware Support Insider.

  • From upgrading vSphere to troubleshooting issues with Tanzu Kubernetes Grid: Top 10 VMware Tanzu Knowledge Base Articles in September 2023.
    by Marcela Gleixner on October 11, 2023 at 12:18 pm

    From upgrading vSphere to troubleshooting issues with Tanzu Kubernetes Grid: Top 10 VMware Tanzu Knowledge Base Articles in September 2023. The post From upgrading vSphere to troubleshooting issues with Tanzu Kubernetes Grid: Top 10 VMware Tanzu Knowledge Base Articles in September 2023. appeared first on VMware Support Insider.

  • 10 most popular KB articles in September 2023, for VMware Tanzu Application Service, BOSH and more.
    by Marcela Gleixner on October 9, 2023 at 9:54 pm

    10 most popular KB articles in September 2023, for VMware Tanzu Application Service, BOSH and more. The post 10 most popular KB articles in September 2023, for VMware Tanzu Application Service, BOSH and more. appeared first on VMware Support Insider.

  • Top 10 Most Popular Knowledge Articles for Horizon, WorkspaceONE, End User Computing (EUC), Personal Desktop for September, 2023   
    by Jamie Gravatte on October 6, 2023 at 4:31 pm

    Tweet Get answers and solutions instantly by using VMware’s Knowledge Base (KB) articles to solve known issues. Whether you’re looking to improve your productivity, troubleshoot common issues, or simply learn something new, these most used and most viewed knowledge articles are a great place to start.   Here are the top 5 most viewed KB articles … Continued The post Top 10 Most Popular Knowledge Articles for Horizon, WorkspaceONE, End User Computing (EUC), Personal Desktop for September, 2023    appeared first on VMware Support Insider.

  • Top 10 Most Popular Knowledge Articles for HCX, SaaS, EPG Emerging Products Group for September, 2023   
    by Jamie Gravatte on October 5, 2023 at 2:26 pm

    Tweet Get answers and solutions instantly by using VMware’s Knowledge Base (KB) articles to solve known issues. Whether you’re looking to improve your productivity, troubleshoot common issues, or simply learn something new, these most used and most viewed knowledge articles are a great place to start.   Here are the top 5 most viewed KB articles … Continued The post Top 10 Most Popular Knowledge Articles for HCX, SaaS, EPG Emerging Products Group for September, 2023    appeared first on VMware Support Insider.