How to configure VMware AirWatch integration - SimplexMobility/public_wiki GitHub Wiki

Workspace ONE UEM integration

MyServe connects to Workspace ONE UEM to read your device inventory and to run device actions such as lock, wipe and send message.

This guide covers both Workspace ONE UEM SaaS (Omnissa cloud) and on premises deployments. The steps below are the same for both. The one thing that differs is the address you enter in step 3.

A note on naming. The product was called AirWatch, then VMware Workspace ONE UEM, and is now owned by Omnissa. MyServe still labels the integration VMware AirWatch. It is the same product and the same API, so choose that option regardless of which version you run.

Before you start

You need an administrator account in your Workspace ONE UEM console with permission to create administrators and to enable the REST API.

Step 1: Create an administrator account for MyServe

Open your Workspace ONE UEM Console.

Go to Accounts > Administrators > List View.

Press the Add button and then Add Admin.

Fill all required fields in the Add / Edit Admin window:

Click the Roles tab and select the Device Manager role. Then press Save.

MyServe uses this account to read device information and to run the device actions you trigger from MyServe. The Device Manager role is enough. There is no need to grant anything broader.

Important: check the Organization Group. The Organization Group assigned to this account determines which devices MyServe can see. If your devices are spread across several Organization Groups, use an account in a parent group that covers all of them. Otherwise MyServe will only see part of your fleet, and the devices in the other groups will look missing.

Step 2: Enable the REST API and copy the API key

Navigate to Groups & Settings > All Settings > System > Advanced > API > REST API.

Select Override for Current Settings.

Select Enabled for Enable API Access.

Add a new service with Admin account type if one does not exist.

Copy the value from the API Key text box. You will need it in step 4.

Then click Save.

If you use Whitelisted Domains. This screen lets you restrict which addresses are allowed to use the API key. If you enable that restriction, you have to add DMI's addresses to the list, otherwise MyServe will be blocked. Ask your DMI contact for the current list of addresses.

Step 3: Find your API server address

This is the step most often missed, and getting it wrong is the most common reason the integration fails.

On SaaS, the console address and the API address are not the same. They follow this pattern:

Example
Console address, the one in your browser cn137.awmdm.com
API address, the one MyServe needs as137.awmdm.com

MyServe needs the API address. If you enter the console address instead, every request fails.

To find it, go to Groups & Settings > All Settings > System > Advanced > Site URLs, where your environment's API server address is listed.

On premises, use the hostname your administrator provides for API access. It may not match your console hostname, particularly if your organisation puts a gateway in front of Workspace ONE UEM.

Enter the hostname on its own, with no https://, no trailing slash and no path. For example as137.awmdm.com, and not as137.awmdm.com/API. MyServe adds the API path to the address itself, so anything extra on the end makes the final address wrong and every request fails.

Step 4: Enter the credentials in MyServe

Sign in to your MyServe account (https://myserve.ca or https://myserve.co).

From the menu, choose Settings > MDM Configuration.

In the MDM Integrations block choose VMware AirWatch, then press the Add button.

Fill in the four fields:

Field Value From
Domain name Your API server hostname, with no https:// and no path Step 3
Username The administrator account username Step 1
Password The administrator account password Step 1
API Key The REST API key Step 2

Press Add, then press Synchronize inside the Manual Synchronization panel.

Step 5: Confirm it worked

The Manual Synchronization panel shows the result of the last synchronization.

If it succeeded, your devices start receiving MDM data as the synchronization progresses. You can check any device by opening its detail page and looking at the MDM tab. A small fleet fills in quickly. A large one is processed device by device and can take a few hours to complete, so it is normal to see some devices with data and others without while it runs.

After the first synchronization, MyServe refreshes the data automatically once a day.

If it failed, see the table below.

Troubleshooting

What you see Most likely cause
Every synchronization fails immediately, and the failure shows no reason The Domain name is wrong. Either it is the console address rather than the API address, or it has something extra on the end such as /API. See step 3
Synchronization fails with a credentials or login error The username or password is wrong, or the account does not have the Device Manager role. See step 1
Synchronization succeeds but only some devices appear The account's Organization Group does not cover your whole fleet. See the note in step 1
Synchronization succeeds but devices have no phone number MyServe matches devices by phone number. Devices without a phone number in Workspace ONE UEM cannot be matched
Synchronization stopped working without any change on your side Check whether Whitelisted Domains was enabled on the API key, or whether the API key or the account password was rotated

Notes

Authentication. MyServe authenticates to Workspace ONE UEM with a username, a password and an API key. Omnissa also offers OAuth 2.0 for SaaS tenants and presents it as the preferred method. This integration does not currently support OAuth 2.0. If your security policy requires OAuth 2.0, or if you plan to disable Basic authentication for the REST API, please contact DMI first so we can plan for it.

Console layout. Menu names and paths have changed across Workspace ONE UEM versions, and the screenshots in this guide were captured on an earlier one, so some screens look different today. If a path in this guide does not match what you see, your own environment's API explorer at https://[your-api-server]/api/help is authoritative for your version. Tell your DMI contact if you find something out of date here and we will correct it.