Configuring a Device Profile for Windows 10

Profiles allow you to modify how the enrolled devices behave. This exercise helps you to configure and deploy a restrictions profile that we can verify has applied to the device later in the section.

1. Add a Profile

Add a Restriction Profile

In the upper-right corner of Workspace ONE UEM Console:

  1. Select Add.
  2. Select Profile.

1.1. Add a Windows Profile

Add a Windows Profile

Select the Windows icon.

Note: Make sure that you select Windows and not Windows Rugged.

1.2. Add a Windows Desktop Profile

Add a Windows Desktop Profile

Select Windows Desktop.

1.3. Select Context - Device Profile

Select Context - Device Profile

Select Device Profile.

1.4. Define the General Settings

Define the General Settings
  1. Select General if it is not already selected.
  2. Enter a profile name such as Windows Restrictions in the Name text box.
  3. Copy the profile name into the Description field.
  4. Click in the Smart Groups field. This will pop-up the list of created Smart Groups. Select the All Devices Smart Group.
    Note: You may need to scroll down to view the Assigned Groups field.

Note: You DO NOT need to click Save & Publish at this point. This interface allows you to move around to different payload configuration screens before saving.

1.5. Select the Restrictions Payload

Select the Restrictions Payload

Note: When initially setting a payload, a Configure button will show to reduce the risk of accidentally setting a payload configuration.

  1. Select the Restrictions payload in the Payload section on the left.
  2. Click the Configure button to continue setting the Restrictions payload.

1.6. Adding a Restriction - Disable End User Unenrollment

Adding a Restriction - Disable Cortana
  1. Select Block for Allow MDM Unenrollment.
  2. Click Save & Publish.

NOTE: Some restrictions require a certain version of Windows or higher to apply to a device.  A few references are available for you to determine which version of Windows is required, including:

  • VMware Policy Builder: https://www.vmwarepolicybuilder.com
  • Configuration Service Provider (CSP) Reference: http://aka.ms/CSPList
  • Whats New in MDM Enrollment and Management: https://docs.microsoft.com/en-us/windows/client-management/mdm/new-in-windows-mdm-enrollment-management

1.7. Publish the Restrictions Profile

Publish the Restrictions Profile

A preview of devices that will receive this profile based on the assigned smart groups is shown. Click Publish.

Navigate to Profiles List View
  1. Select Devices.
  2. Select Profiles & Resources.
  3. Select Profiles.

3. Verify the Restrictions Profile Now Exists

Verify the Restriction Profile Now Exists

You should now see your Restrictions Profile within the List View of the Devices Profiles window.

Note: If you need to edit the Restrictions Profile, this is where you would do so. To edit the profile, click the profile name, then select Add Version. Update the profile and click Save & Publish to push the new settings to the assigned devices.

0 Comments

Add your comment

E-Mail me when someone replies to this comment

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.