Windows 10 Challenge Lab Tasks

Enroll the device

  1. Ensure user holuser is imported from Active Directory
  2. Connect your VMware Access Tenant to your Workspace ONE UEM tenant.
    • You will need to ensure the user enrolled holuser can access the Workspace ONE app catalog
  3. Enroll the Windows 10 Virtual Machine

Windows 10 Applications

Ensure the applications are set to "On-Demand"

Download and configure the below applications

  1. Office Pro Plus
    • Only install Outlook, Word, Excel, and PowerPoint.
    • No OneDrive, Skype or Visio.
    • Require a reboot after installation
  2. Microsoft Teams
    • Must appear in Workspace ONE catalog as a separate application to Office
    • Require a reboot after installation
  3. Zoom Plugin for Outlook
    • Must-have criteria to check for Outlook is installed first

Windows 10 Applications - Success Criteria

To PASS:

  • You must show all 3 applications in the Workspace ONE catalog. 
  • Show successfully installed applications under device details in the Workspace ONE UEM console
  • All Applications MUST be set to On-Demand
  • Office Pro Plus
    • Show on the device that only the applications instructed above are installed
    • You can find recently installed apps in the start menu
  • Microsoft Teams
    • Must appear in Workspace ONE catalog as a separate application to Office
  • Zoom Plugin for Outlook
    • Must show criteria to check for Outlook is installed in Workspace ONE UEM console

Windows 10 Policies

Ensure the policies are set to "Automatic"

Configure the below policies on the device:

  1. Add corporate wallpaper and lock screen
    • Choose any image you choose
    • Make sure to reboot here
    • Note: lock screen image may not apply due to GPOs
  2. Set Edge Browsers Home page
    • Set home page to techzone.vmware.com
  3. Add Bit-Locker encryption
    • You must add the Custom URL for Recovery Screen 
    • Enable authentication mode: Password
    • Enable a Rotation Period of 60 days
    • Enable a Grace Period of 10 days   
    • Enable BitLocker Suspend from 8pm til 6am daily
      • Note: if Bitlocker suspend will turn on during your lab, you can leave this option off.
  4. Configure Windows Anti-Virus
    • Enable Real Time Monitoring
    • Require Full Scan Weekly outside of working hours
    • Require Quick Scan Daily outside of working hours
    • Low Threat Default Action : Clean
    • Moderate Threat Default Action : Quarantine
    • High Threat Default Action : Quarantine
    • Severe Threat Default Action : Block
  5. Configure Windows Updates Policy
    • Defer Feature Updates  for 180 days 
    • Allow Users to dismiss notification is Auto Restart is Required
    • Change Schedule Imminent Restart Warning to 30 minutes.
    • Auto-Approved Updates : Critical , Definition ,Security & Update Rollups

Windows 10 Policies - Success Criteria

To PASS:

  • You MUST show the creation of policies in the Workspace ONE UEM console
  • ALL policies must be shown successfully delivered to the device in the Workspace ONE UEM console
  • Policies MUST match any configuration changes described above.
  1. Add corporate wallpaper and lock screen
    • Must show the lock screen and wallpaper changed
  2. Set Edge Browsers Home page
    • You must open the Edge Browser and show the home page techzone.vmware.com
  3. Add Bit-Locker encryption
    • Configured the Bit-Locker policy as instructed - Show the configurations
    • Must show recovery key in the Workspace ONE UEM console
  4. Configure Windows Anti-Virus
    • Configured the Windows Anti-Virus policy as instructed - Show the configurations
  5. Configure Windows Updates Policy
    • Configured the Windows Update policy as instructed.
    • Show on the Windows 10 device where the End-User will navigate to find Windows update settings

Congratulations! Lab Complete

0 Comments

Add your comment

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.