Workspace ONE UEM
Visualize Omnissa Workspace ONE UEM (formerly VMware AirWatch) admins, users, organization groups, profiles, and devices, map Workspace ONE UEM users to employees, and monitor changes through queries and alerts.
- Installation
- Authorization
- Data Model
- Types
- Release Notes
Installation
Omnissa Workspace ONE UEM was formerly known as VMware AirWatch. Instances configured before the rename keep working without changes.
To install this integration, you will need to configure settings both within Workspace ONE UEM and on JupiterOne. Before enabling in JupiterOne, ensure that you have completed the setup within your Workspace ONE UEM console.
Configuration in Workspace ONE UEM
Log into the Workspace ONE UEM console and create an Administrator user account for the integration to authenticate with the REST API:
-
Select Accounts > Administrators > Admins (List View in console versions 2402 and earlier).
-
Select Add > Add Admin. On the Basic tab, set User Type to Basic and fill in the required details. The integration authenticates with this username and password.
noteWe recommend setting values that represent JupiterOne as a
systemuser account. Ensure that you set Title on the Details tab tosystemso that JupiterOne understands this is a user for automation (so it does not attempt to map to a Person entity). -
Assign the necessary read-only permissions to the administrator account. The REST API key does not carry permissions of its own; requests use the permissions of this administrator's role. The integration requires read access to:
- Devices (
/mdm/devices/search,/mdm/devices/security) - Administrators (
/system/admins/search) - Organization Groups (
/system/groups/search,/system/groups/{id}/children) - Profiles (
/mdm/profiles/search,/mdm/profiles/{uuid}/devices)
Roles are managed under Accounts > Administrators > Roles.
- Devices (
-
Navigate to Groups & Settings > All Settings > System > Advanced > API > REST API (Omnissa documentation):
- On the General tab, select Enable API Access.
- Select Add, enter a Service name (for example
JupiterOne), set Account Type to Admin, and copy the generated API Key. - On the Authentication tab, make sure Basic is enabled.
- On the Usage tab, check the Daily Quota (50,000 calls per day by default). See Skip Device Security Details below for large tenants.
Configuration in JupiterOne
To install the Workspace ONE UEM integration in JupiterOne, navigate to the Integrations tab in JupiterOne and select Workspace ONE UEM. Click New Instance to begin configuring the integration.
Creating a Workspace ONE UEM instance requires the following:
-
The Account Name used to identify the Workspace ONE UEM account in JupiterOne. Ingested entities will have this value stored in
tag.AccountNamewhen theAccountNametoggle is enabled. -
Description to assist in identifying the integration instance, if desired.
-
Polling Interval that you feel is sufficient for your monitoring needs. You may leave this as
DISABLEDand manually execute the integration. -
The Hostname (for example
cn1234.awmdm.com), Admin Username, and Admin Password of your Workspace ONE UEM environment. -
Rest API Key (or Tenant Code) used to authenticate with Workspace ONE UEM.
-
Optionally, Skip Device Security Details. By default the integration makes one Workspace ONE API call per device to collect passcode and encryption properties. On large tenants this is most of the integration's API usage, which counts against the Workspace ONE daily API quota (50,000 calls per day by default). Enabling this option skips that call, and those device properties are no longer ingested.
Click Create once all values are provided to finalize the integration.
Next steps
Now that your integration instance has been configured, it will begin running on the polling interval you provided, populating data within JupiterOne. Continue on to our Instance management guide to learn more about working with and editing integration instances.
Endpoints
API endpoints that the integration makes requests to.
Show Endpoints (7)
https://<workspaceOneHost>/API/mdm/devices/searchhttps://<workspaceOneHost>/API/mdm/devices/securityhttps://<workspaceOneHost>/API/mdm/profiles/searchhttps://<workspaceOneHost>/API/mdm/profiles/{profileUuid}/deviceshttps://<workspaceOneHost>/API/system/admins/searchhttps://<workspaceOneHost>/API/system/groups/searchhttps://<workspaceOneHost>/API/system/groups/{id}/children
Documentation Links
Links to provider documentation relevant to setup and configuration.
Show Documentation Links (5)
- https://developer.omnissa.com/workspace-one-uem-apis/versions/2607/mdm-api-v1/
- https://developer.omnissa.com/workspace-one-uem-apis/versions/2607/mdm-api-v2/
- https://developer.omnissa.com/workspace-one-uem-apis/versions/2607/mdm-api-v3/
- https://developer.omnissa.com/workspace-one-uem-apis/versions/2607/system-api-v1/
- https://developer.omnissa.com/workspace-one-uem-apis/versions/2607/system-api-v2/
Per-Step Breakdown
Detailed authorization requirements for each ingestion step.
Show all steps (2)
| Step | Endpoints |
|---|---|
| Build device and profile relationships | https://<workspaceOneHost>/API/mdm/profiles/{profileUuid}/devices |
| Fetch Admins | https://<workspaceOneHost>/API/system/admins/search |
Entities
The following entities are created:
| Resources | Entity _type | Entity _class |
|---|---|---|
| Account | workspace_one_uem_account | Account |
| Admin | workspace_one_uem_admin | User |
| Device | workspace_one_uem_device | Host, Device |
| Device User | workspace_one_uem_user | User |
| Organization Group | workspace_one_uem_group | Group, UserGroup |
| Profile | workspace_one_uem_profile | Configuration |
Relationships
The following relationships are created:
Source Entity _type | Relationship _class | Target Entity _type |
|---|---|---|
workspace_one_uem_account | HAS | workspace_one_uem_group |
workspace_one_uem_account | MANAGES | workspace_one_uem_device |
workspace_one_uem_device | INSTALLED | workspace_one_uem_profile |
workspace_one_uem_group | HAS | workspace_one_uem_group |
workspace_one_uem_group | HAS | workspace_one_uem_admin |
workspace_one_uem_user | OWNS | workspace_one_uem_device |
Workspace One Uem Account
workspace_one_uem_account inherits from Account
Workspace One Uem Admin
workspace_one_uem_admin inherits from User
| Property | Type | Description | Specifications |
|---|---|---|---|
initialLandingPage | string | Console page shown to the admin after login | |
lastLoginTimeStamp | number | Last console login time | |
locale | string | Admin console locale | |
locationGroup | string | Name of the admin organization group | |
locationGroupId | string | Id of the admin organization group | |
messageTemplateId | string | Id of the admin notification message template | |
messageTemplateUuid | string | UUID of the admin notification message template | |
organizationGroupUuid | string | UUID of the organization group the admin belongs to | |
timeZone | string | Admin time zone | |
uuid | string | Workspace ONE admin UUID |
Workspace One Uem Device
workspace_one_uem_device inherits from Host, Device
| Property | Type | Description | Specifications |
|---|---|---|---|
assetNumber | string | Device asset number | |
authenticatedRootVolumeEnabled | boolean | Whether the macOS authenticated root volume is enabled | |
blockLevelEncryption | boolean | Whether block-level encryption is enabled | |
bootstrapTokenAllowedForAuthentication | string | Whether the macOS bootstrap token is allowed for authentication | |
bootstrapTokenEscrowStatus | boolean | Whether the macOS bootstrap token is escrowed | |
bootstrapTokenRequiredForKernelExtensionApproval | boolean | Whether the macOS bootstrap token is required for kernel extension approval | |
bootstrapTokenRequiredForSoftwareUpdate | boolean | Whether the macOS bootstrap token is required for software updates | |
dataProtectionEnabled | boolean | Whether data protection is enabled on the device | |
dellDdpeEncryptionStatus | boolean | Dell Data Protection | Encryption status | |
deviceFriendlyName | string | Device friendly name in Workspace ONE | |
driveEncryptionLevel | string | Disk encryption level reported by Workspace ONE | |
email | string | Lower-cased email of the device user | |
encryptionStatus | string | Disk encryption status reported by Workspace ONE | |
enrolledViaDep | boolean | Whether the device enrolled via Apple Automated Device Enrollment (DEP) | |
fileLevelEncryption | boolean | Whether file-level encryption is enabled | |
hasInstitutionalRecoveryKey | boolean | Whether an institutional disk recovery key is set | |
hasPersonalRecoveryKey | boolean | Whether a personal disk recovery key is escrowed (the key itself is never ingested) | |
imei | string | Device IMEI | |
isActivationLockManageable | boolean | Whether Activation Lock can be managed by MDM | |
isCompromised | boolean | Whether the device is reported as compromised | |
isEncrypted | boolean | Whether the device disk is encrypted | |
isPasscodeCompliant | boolean | Whether the device passcode complies with policy | |
isPasscodePresent | boolean | Whether a device passcode is set | |
isRecoveryLockEnabled | boolean | Whether macOS Recovery Lock is enabled | |
isSupervised | boolean | Whether the Apple device is supervised | |
locationGroupIdName | string | Name of the organization group referenced by LocationGroupId | |
locationGroupName | string | Name of the organization group the device belongs to | |
macAddress | string | Primary MAC address, colon-separated and lower-cased | |
operatingSystem | string | Operating system version reported by Workspace ONE | |
ownerId | string | Workspace ONE owner id of the device | |
passcodeLockGracePeriod | number | Passcode lock grace period reported by the device | |
passcodeLockGracePeriodEnforced | number | Passcode lock grace period enforced by policy | |
percentComplete | number | Disk encryption progress percentage | |
platform | string | Lower-cased Workspace ONE platform, e.g. apple, winrt, android | |
serialNumber | string | Device serial number | |
systemIntegrityProtectionEnabled | boolean | Whether macOS System Integrity Protection is enabled | |
userApprovedEnrollment | boolean | Whether the MDM enrollment was approved by the user | |
userEmailAddress | string | Email address of the enrolled user as reported by Workspace ONE | |
username | string | Enrollment username of the device user | |
uuid | string | Workspace ONE device UUID | |
wifiSsid | string | SSID of the Wi-Fi network the device last reported |
Workspace One Uem Group
workspace_one_uem_group inherits from Group, UserGroup
| Property | Type | Description | Specifications |
|---|---|---|---|
admins | number | Number of console admin users in the organization group | |
country | string | Organization group country | |
devices | number | Number of enrolled/unenrolled devices present in the organization group | |
groupId | string | Organization group identifier (activation code) | |
locale | string | Organization group locale | |
locationGroupType | string | Type of organization group Examples: Global, Customer, Partner | |
users | number | Number of enrollment users in the organization group | |
uuid | string | Organization group UUID |
Workspace One Uem Profile
workspace_one_uem_profile inherits from Configuration
| Property | Type | Description | Specifications |
|---|---|---|---|
managedBy | string | Organization group that manages the profile | |
payloads | array of strings | Names of the payloads configured in the profile | |
platform | string | Platform the profile applies to |
Workspace One Uem User
workspace_one_uem_user inherits from User
| Property | Type | Description | Specifications |
|---|---|---|---|
uuid | string | Workspace ONE enrollment user UUID |
Release Notes
- 2026-04-08 — Improved OS name accuracy for AirWatch device entities, deriving human-readable OS names from the device platform and model fields.
- 2025-04-22 — Updated AirWatch admin user entities to align with the latest data model, adding email domain and short login ID properties.
- 2025-04-17 — Added location group name and ID to AirWatch device entities.
- 2025-04-17 — Added email address to AirWatch device user entities.