Zum Inhalt springen
EBF Logo

EBF product documentation

Find help using and administering EBF applications

EBF Onboarder

  • Changelog
  • 01. Introduction
  • 02. Registration
  • 03. Preparation of the migration
  • 04. Migration project setup
  • 05. Email Content Tool
  • 06. Transformation Tool
  • 07. Enrollment Wizard
  • 08. Migration launch
  • 09. Migration monitoring
  • 10. Migration project management
  • 11. Contact

Source System Workspace ONE / Airwatch

Table of Contents
  • 01. Introduction
  • 02. Prerequisites for the source system Workspace ONE/AirWatch
    • 02.1. API Key
    • 02.2. Accounts
      • 02.2.1. Service Account
      • 02.2.2. Admin Account
    • 02.3. Privacy settings
    • 02.4. Device wipe settings
  • 03. Retiring process monitoring
    • 03.1. Notifications settings
    • 03.2. Wipe Logs
    • 03.3. Device status

01. Introduction

There is a general documentation available for the EBF Onboarder, where you can find information about its prerequisites and the whole migration project. It describes how you can setup a migration project, how you can setup invitation emails and reminders which guide your users through the migration. It also tells you how to initiate the migration process and how to track the migration status.

This documentation complements the general EBF Onboarder documentation and provides more detailed information about the prerequisites for the source system Workspace ONE.

ATTENTION: This documentation does not replace any VMware documentation. It is only describing prerequisites for the EBF Onboarder. Please consult the VMware documentation and support if necessary.

02. Prerequisites for the source system Workspace ONE/AirWatch

If your source system is Workspace ONE/AirWatch, it is recommended that you login into your Workspace ONE/AirWatch console and make the changes which are described in the following chapters. In this way you can ensure that the EBF Onboarder will be able to retire the devices from your Workspace ONE/AirWatch system.

02.1. API Key

The EBF Onboarder will require an API Key to access the Workspace ONE/AirWatch system.

NOTE: Do not use an existing API Key. Create a new API Key as there is a daily limit of 50,000 connections for each API Key that would be reached especially on shared tenants if you use an old API Key.

Follow these steps to enable API access:

  1. Login in your Workspace ONE/AirWatch console.
  2. Go to ‘Groups & Settings’ >> ‘All Settings’ >> ‘System’ >> ‘Advanced’ >> ‘API’ > ‘REST API’.
  3. Select the tab ‘General’ and select ‘Enabled’ for Enable API Access. In this way, an API key for the top organization group is created automatically.
  4. Click on ‘Add’.
  5. Scroll down the table and enter a name for your API Key and select ‘Admin’ in the drop-down list.
  6. Save the new API Key.

NOTE: Please also read the VMware documentation about generating an API Key and enabling API Access:

  • https://docs.vmware.com/en/VMware-Workspace-ONE/services/WS1-IDM-deploymentguide/GUID-1CBF64C9-5C17-4F98-8A76-C7A88F8E5E96.html
  • https://docs.vmware.com/en/VMware-Workspace-ONE-UEM/2001/System_Settings_On_Prem/GUID-AWT-SYSTEM-ADVANCED-API-REST.html
  • https://docs.vmware.com/en/VMware-Workspace-ONE-UEM/9.7/vmware-airwatch-guides-97/GUID-AW97-Pradeo_Enable_REST_NOTFE.html?hWord=N4IghgNiBcIKIDswCMIFMAEAlOBlAKhgIIAKAkiAL5A

It is recommended to create the API Key for the top organizational group with the type ‘Customer’ (not a subgroup) where you will also create a dedicated admin for the EBF Onboarder. To do this follow these steps:

  1. Login in your Workspace ONE/AirWatch console.
  2. Go to ‘Groups & Settings’ >> ‘Groups’ >> ‘Organization Groups’ >> ‘Details’.
  3. Ensure that you are in the desired organization group with the type ‘Customer’.

NOTE: If you change the structure of your top organization group, please re-create an API Key for the EBF Onboarder right after doing the changes.

02.2. Accounts

The EBF Onboarder needs an Admin Account to have access to the Workspace ONE/AirWatch system. Before you create the Admin Account (see chapter 02.2.2), you first have to create roles for a Service Account which you can then associate to the Admin Account (see chapter 02.2.1).

NOTE: Please consult the Workspace ONE documentation if necessary.

02.2.1. Service Account

  1. Login in your Workspace ONE/AirWatch console.
  2. Go to ‘Accounts’ >> ‘Administrators’ >> ‘Roles’.
  3. Click on ‘Add Role’.
  4. Enter a name and description which indicates that this role belongs to the EBF Onboarder.
  5. Select ‘API’ and provide all API REST entries with the ‘edit’ right – except the last SOAP entry (General):
  6. Add the role ‘Device Management’ and provide it with ‘read’ and ‘edit’ rights:
  7. Add the role ‘Groups’ and provide it with ‘reading’ right only:
  8. Save the settings.

02.2.2. Admin Account

Create an Admin Account which the EBF Onboarder can use to access the Workspace ONE/AirWatch system. Assign the EBF Onboarder specific role and the Device Management role which you have created (see chapter 02.2.1) to the Admin Account.

  1. Login in your Workspace ONE/AirWatch console.
  2. Go to ‘Accounts’ >> ‘Administrators’ >> ‘List View’.
  3. Click on ‘Add’ and choose ‘Add Admin’.
  4. Go to the tab ‘Basic’ and enter the parameters for the new admin account:

    NOTE: Two-Factor Authentication must be disabled as the EBF Onboarder does not support it.

  5. Go to the tab ‘Roles’ and click on ‘Add role’ to add a role for the organization group ‘Group’ and select the EBF Onboarder specific role (see chapter 02.2.1).
  6. Click once more on ‘Add role’ to add another role for the organization group ‘Group’ and select the role ‘Device Manager’ (see chapter 02.2.1).
  7. Go to the tab ‘API’ to validate that the user credentials will be used by the API to access the console. Select ‘User Credentials’ as authentication method.
  8. Save the new admin.

02.3. Privacy settings

Edit your Workspace ONE/AirWatch privacy settings so that Workspace ONE/AirWatch has full access to ‘Unassigned Devices’ as some devices may be seen as ‘Unassigned’ by EBF Onboarder when a previous enrollment was done manually.

  1. Login in your Workspace ONE/AirWatch console.
  2. Go to ‘Groups & Settings’ >> ‘All Settings’ >> ‘Devices & Users’ >> ‘General’ >> ‘Privacy’.
  3. Select ‘Override’.
  4. Scroll down to the ‘Commands’ section and select ‘Unassigned’ for ‘Device Wipe’, ‘Clear Device Passcode/Lock Device/Shutdown/Reboot’ and ‘File Manger Access’.

02.4. Device wipe settings

You need to increase the number of devices your source system will accept to retire during a certain period as there will be a large amount of retiring/wiping requests during the migration to your source system.

  1. Login in your Workspace ONE/AirWatch console.
  2. Go to ‘Groups & Settings’ >> ‘All Settings’ >> ‘Devices & Users’ >> ‘Advanced’.
  3. Click on ‘Managed Device Protection’.
  4. Select ‘Override’ and change the settings:
    • Increase the number of ‘Wiped Devices’ and enter a number between 2000 and 3000.
    • Increase the number of ‘Within (minutes)’ to 20.
  5. Save with ‘Inherit’ or ‘Override’.

03. Retiring process monitoring

03.1. Notifications settings

To follow the retiring process of the devices from your source system, enable your source system to send notifications to your Admin Account. In this way you will be informed if there is any issue during the wiping process which is required by the EBF Onboarder.

  1. Login in your Workspace ONE/AirWatch console.
  2. Go to ‘Groups & Settings’ >> ‘All Settings’ >> ‘Devices & Users’ >> ‘General’ >> ‘Notifications’.
  3. Select ‘Override’.
  4. Select ‘Administrator’, enter the email address and select a message template.

03.2. Wipe Logs

Make sure that there is no problem with the wiping of your devices by checking the Wipe Logs:

  1. Login in your Workspace ONE/AirWatch console.
  2. Go to ‘Devices’ >> ‘Lifecycle’ >> ‘Wipe Logs’ and check if the status is ‘Processed’. If not, please contact your VMware support to check why the ‘Enterprise Wipe’ is not performed.

03.3. Device status

Check the status of your devices to make sure that the device wipe command can be executed successfully.

  1. Login in your Workspace ONE/AirWatch console.
  2. Go to ‘Devices’ >> ‘List View’ and check the status:
    • In the column ‘Last seen’, a number with a green background indicates that the device was recently seen in the system. A red number indicates that the device has not been seen for several days.
    • The column ‘General info’ shows whether a device is compliant.

If the device was not seen on your source system since a few days and/or if the device is not compliant with your source system’s policies, the device wipe command may not be possible to execute.

NOTE: It is recommended to contact the users of devices which have not been seen for a while or which are uncompliant before starting any migration. In this way, you can ensure that the status will change to green for ‘Last seen’ and ‘Compliant’.

Was this article useful?
Still stuck? How can we help?

How can we help?

Updated on 8. April 2021
Source System MobileIron
Table of Contents
  • 01. Introduction
  • 02. Prerequisites for the source system Workspace ONE/AirWatch
    • 02.1. API Key
    • 02.2. Accounts
      • 02.2.1. Service Account
      • 02.2.2. Admin Account
    • 02.3. Privacy settings
    • 02.4. Device wipe settings
  • 03. Retiring process monitoring
    • 03.1. Notifications settings
    • 03.2. Wipe Logs
    • 03.3. Device status
Subscribe for EBF Newsletter
©2020 EBF-EDV Beratung Föllmer GmbH, All Rights Reserved
Imprint Terms and Conditions Privacy Statement Contact
Facebook-square
Twitter-square
Linkedin
Xing-square
Instagram
EBF Status Check