Exporting Apps and Creating Configuration Files
As of Workspace ONE UEM 1811, the IT administrator can leverage the provisioning wizard in the console to create the configuration file and export the apps. The IT administrator can configure OOBE, domain join and MDM enrollment from the wizard. Additionally, with a Windows 10 Enterprise license, the IT administrator can also choose to set the provisioning configuration for removal of consumer applications bundled with Windows 10. The active directory types that are supported for provisioning configuration are: on-premises domain join, Azure Active Directory Premium, Azure Active Directory - No Premium and local user/workgroup.
The provisioning configuration is exported in Windows unattend XML file format. This file follows the standard unattend XML schema, with some additional configuration for MDM enrollment into Workspace ONE UEM. The configuration is applied when the end user logs into the device.
Now that the enterprise applications are uploaded or imported using Workspace ONE AirLift (from SCCM) into Workspace ONE, the administrator is ready to export the applications into a provisioning package to share with Dell. The container used for this provisioning package is a Windows Provisioning Package (.ppkg) recognized natively by Windows 10. A custom mechanism is used in the PPKGs generated by Workspace ONE to install the applications, so it is not recommended for a customer to treat these PPKGs as generic PPKGs.
To export the enterprise applications, the IT administrator opens the Workspace ONE UEM console, and navigates to the Native Applications under the Apps & Books section. In the export dropdown, there is a new option to export PPKG. Selecting that option brings up a new dialog box with a list of applications to pick from. Currently, Windows classic desktop applications and Universal Windows Platform (UWP) apps which install in device or user context are supported.
Once the IT administrator initiates the PPKG export process, a confirmation is shown. On completion of PPKG export, a notification is sent to the Workspace ONE UEM console with a link to download the PPKG. A console administrator can have one PPKG export in progress at a time. To start a new PPKG export, the administrator needs to wait for the existing PPKG export to complete. A new PPKG export request overwrites any previously exported PPKG for that administrator. Multiple console administrators can concurrently request PPKGs to be exported though.
Lets take a look at how to export apps to provisioning packages and create the configuration file in the Workspace ONE UEM Console.
The above diagram shows the process of uploading, exporting and leveraging factory provisioning to load the apps and deliver the device to the end user.
- Workspace ONE UEM admin uploads apps to Workspace ONE UEM manually or using Workspace ONE AirLift.
- Workspace ONE UEM admin exports selected apps as a provisioning package (.ppkg).
- Admin provides the provisioning package, along with a configuration file to Dell.
- Dell performs factory provisioning using the exported apps and configuration file.
- Devices are shipped directly to end users or IT.
- End users boot device and device onboard into Workspace ONE UEM and receive app updates and other policies over-the-air.
1. Retrieve the Workspace ONE Enrollment Details
Before configuring the Windows Provisioning Package, you will need to retrieve the Workspace ONE Enrollment settings that you will need to provide during the Windows Provisioning Package configuration. Follow the next steps to retrieve this information.
1.1. Open Notepad
You will need to record values from different sections of the Workspace ONE UEM Console for the upcoming exercise. You will utilize Notepad to record these values to copy and paste them later.
- Click the Search button next to the Start button.
- Enter
notepad
. - Click the Notepad Desktop app result.
1.2. Find Your Group ID
In the Workspace ONE UEM Console,
- Click the Organization Group tab at the top of the console.
- Click and drag the Group ID value to highlight your group id.
- Right-Click and select Copy.
1.2.1. Record your Group ID in Notepad
- Click the Notepad icon.
- Enter
Group ID:
in Notepad. - Click Edit.
- Click Paste to insert your copied Group ID.
1.3. Find your Workspace ONE Enrollment Details
- Click Groups & Settings.
- Click All Settings.
1.3.1. Navigate to the Staging & Provisioning Settings
- Click Devices & Users
- Click Windows
- Click Windows Desktop
- Click Staging & Provisioning
1.3.2. Find Your Enrollment User UPN
- You may need to scroll down to find the Enrollment Details
- Click and drag to highlight the UPN value.
- Right-click and click Copy.
1.3.3. Record the UPN in Notepad
- Click the Notepad icon.
- Enter
UPN:
in Notepad. - Click Edit.
- Click Paste to insert your copied UPN.
1.3.4. Find the Enrollment Secret
Back in the Workspace ONE UEM Console,
- Click and drag to highlight the Secret value.
- Right-click and click Copy.
1.3.5. Record the Enrollment Secret
- Click the Notepad icon.
- Enter
Secret:
in Notepad. - Click Edit.
- Click Paste to insert your copied Secret.
1.4. Close the Staging & Provisioning Settings
Click Close.
2. New Provisioning Package
Navigate to the Windows Provisioning Package screen to build a new provisioning package.
- Click Devices.
- Click Lifecycle.
- Click Staging.
- Click Windows.
2.1. Create a New Windows Provisioning Package
Click New.
2.2. Enter the General Provisioning Package Details
- Enter
corp.local package
for the Provisioning Package Name. - Click Next.
2.3. Configure Provisioning Package for On-Premises Active Directory
You will configure the Provisioning Package to join the lab corp.local domain when the package is applied.
- Select On-premises Active Directory Join from the Active Directory Type dropdown.
- Enter
corp.local
for the Domain Name. - Enter
CORP\administrator
for the Domain User Name. - Enter
VMware1!
for the Domain Password. - Scroll down to continue configuring the Provisioning Package.
The following screens will be leveraging the On-premises Active Directory Join Type, reference the table with all options for more information and explanations of all required fields.
2.4. Configurations Details
The following table details all of the options for the configuration file. Leverage the below table for a detail explanation of each field.
|
2.5. Setup the built-in Administrator Account
You must enable the built-in administrator account to facilitate Workspace ONE enrollment. You can later disable this account after enrollment is complete.
- Select Yes for Enable Administrator Account.
- Enter
VMware1!
for the Administrator Password. - Scroll down to continue setting up the Provisioning Package.
2.6. Enter the Workspace ONE Enrollment Details
- Enter
hol.awmdm.com
for the Enrollment Server. - Copy the Group ID value you saved in Notepad and paste it in Enrollment OG.
- Copy the UPN value you saved in Notepad and paste it in Staging Account.
- Copy the Secret value you saved in Notepad and paste it in Staging Password.
- Click Next.
2.7. Selecting Applications
- Click the checkbox at the top to select all apps.
- Click Next.
NOTE: Apps with MSTs or MSPs will fail to deploy as those additional configurations are smart group specific, as a workaround re-package or ZIP the app with the MST/MSP already included then deploy and export.
2.8. Summary
Click Save and Export.
2.9. Success Message
Notice the Success message.
Depending on how many apps you have chosen to export will determine how long the export takes. The Unattend XML configuration file will be ready to download right away. In this lab, it may take a few minutes to process the request, then you can refresh the page.
Continue to the next step once you see the Status change from Queued to Download.
2.10. Confirm Unattend and Provisioning Package Download
- Click the PPKG link to download the file.
- Click the Unattend XML link to download the file.
- If prompted about keeping the unattend.xml file, click Keep.
Wait for both files to finish downloading. You will use this exported provisioning package and unattend.xml in a future step.
NOTE: These are the files which need to be sent to the Dell Factory for Provisioning, however you will first want to test and validate that these apps and configuration work on a test device. The next steps will walk you through how to validate on a virtual machine (VM). You will want to log back into the Workspace ONE UEM Console from the test VM to download these files.
0 Comments
Add your comment