Skip to main content

Workspace ONE UEM

Visualize Omnissa Workspace ONE UEM (formerly VMware AirWatch) admins, users, organization groups, profiles, and devices, map Workspace ONE UEM users to employees, and monitor changes through queries and alerts.

Installation​

Omnissa Workspace ONE UEM was formerly known as VMware AirWatch. Instances configured before the rename keep working without changes.

To install this integration, you will need to configure settings both within Workspace ONE UEM and on JupiterOne. Before enabling in JupiterOne, ensure that you have completed the setup within your Workspace ONE UEM console.

Configuration in Workspace ONE UEM​

Log into the Workspace ONE UEM console and create an Administrator user account for the integration to authenticate with the REST API:

  1. Select Accounts > Administrators > Admins (List View in console versions 2402 and earlier).

  2. Select Add > Add Admin. On the Basic tab, set User Type to Basic and fill in the required details. The integration authenticates with this username and password.

    note

    We recommend setting values that represent JupiterOne as a system user account. Ensure that you set Title on the Details tab to system so that JupiterOne understands this is a user for automation (so it does not attempt to map to a Person entity).

  3. Assign the necessary read-only permissions to the administrator account. The REST API key does not carry permissions of its own; requests use the permissions of this administrator's role. The integration requires read access to:

    • Devices (/mdm/devices/search, /mdm/devices/security)
    • Administrators (/system/admins/search)
    • Organization Groups (/system/groups/search, /system/groups/{id}/children)
    • Profiles (/mdm/profiles/search, /mdm/profiles/{uuid}/devices)

    Roles are managed under Accounts > Administrators > Roles.

  4. Navigate to Groups & Settings > All Settings > System > Advanced > API > REST API (Omnissa documentation):

    • On the General tab, select Enable API Access.
    • Select Add, enter a Service name (for example JupiterOne), set Account Type to Admin, and copy the generated API Key.
    • On the Authentication tab, make sure Basic is enabled.
    • On the Usage tab, check the Daily Quota (50,000 calls per day by default). See Skip Device Security Details below for large tenants.

Configuration in JupiterOne​

To install the Workspace ONE UEM integration in JupiterOne, navigate to the Integrations tab in JupiterOne and select Workspace ONE UEM. Click New Instance to begin configuring the integration.

Creating a Workspace ONE UEM instance requires the following:

  • The Account Name used to identify the Workspace ONE UEM account in JupiterOne. Ingested entities will have this value stored in tag.AccountName when the AccountName toggle is enabled.

  • Description to assist in identifying the integration instance, if desired.

  • Polling Interval that you feel is sufficient for your monitoring needs. You may leave this as DISABLED and manually execute the integration.

  • The Hostname (for example cn1234.awmdm.com), Admin Username, and Admin Password of your Workspace ONE UEM environment.

  • Rest API Key (or Tenant Code) used to authenticate with Workspace ONE UEM.

  • Optionally, Skip Device Security Details. By default the integration makes one Workspace ONE API call per device to collect passcode and encryption properties. On large tenants this is most of the integration's API usage, which counts against the Workspace ONE daily API quota (50,000 calls per day by default). Enabling this option skips that call, and those device properties are no longer ingested.

Click Create once all values are provided to finalize the integration.

Next steps​

Now that your integration instance has been configured, it will begin running on the polling interval you provided, populating data within JupiterOne. Continue on to our Instance management guide to learn more about working with and editing integration instances.