How to configure VMware AirWatch integration - SimplexMobility/public_wiki GitHub Wiki
Workspace ONE UEM integration
MyServe connects to Workspace ONE UEM to read your device inventory and to run device actions such as lock, wipe and send message.
This guide covers both Workspace ONE UEM SaaS (Omnissa cloud) and on premises deployments. The steps below are the same for both. The one thing that differs is the address you enter in step 3.
A note on naming. The product was called AirWatch, then VMware Workspace ONE UEM, and is now owned by Omnissa. MyServe still labels the integration VMware AirWatch. It is the same product and the same API, so choose that option regardless of which version you run.
Before you start
You need an administrator account in your Workspace ONE UEM console with permission to create administrators and to enable the REST API.
Step 1: Create an administrator account for MyServe
Open your Workspace ONE UEM Console.
Go to Accounts > Administrators > List View.
Press the Add button and then Add Admin.

Fill all required fields in the Add / Edit Admin window:

Click the Roles tab and select the Device Manager role. Then press Save.

MyServe uses this account to read device information and to run the device actions you trigger from MyServe. The Device Manager role is enough. There is no need to grant anything broader.
Important: check the Organization Group. The Organization Group assigned to this account determines which devices MyServe can see. If your devices are spread across several Organization Groups, use an account in a parent group that covers all of them. Otherwise MyServe will only see part of your fleet, and the devices in the other groups will look missing.
Step 2: Enable the REST API and copy the API key
Navigate to Groups & Settings > All Settings > System > Advanced > API > REST API.
Select Override for Current Settings.
Select Enabled for Enable API Access.
Add a new service with Admin account type if one does not exist.
Copy the value from the API Key text box. You will need it in step 4.
Then click Save.

If you use Whitelisted Domains. This screen lets you restrict which addresses are allowed to use the API key. If you enable that restriction, you have to add DMI's addresses to the list, otherwise MyServe will be blocked. Ask your DMI contact for the current list of addresses.
Step 3: Find your API server address
This is the step most often missed, and getting it wrong is the most common reason the integration fails.
On SaaS, the console address and the API address are not the same. They follow this pattern:
| Example | |
|---|---|
| Console address, the one in your browser | cn137.awmdm.com |
| API address, the one MyServe needs | as137.awmdm.com |
MyServe needs the API address. If you enter the console address instead, every request fails.
To find it, go to Groups & Settings > All Settings > System > Advanced > Site URLs, where your environment's API server address is listed.
On premises, use the hostname your administrator provides for API access. It may not match your console hostname, particularly if your organisation puts a gateway in front of Workspace ONE UEM.
Enter the hostname on its own, with no https://, no trailing slash and no path. For example as137.awmdm.com, and not as137.awmdm.com/API. MyServe adds the API path to the address itself, so anything extra on the end makes the final address wrong and every request fails.
Step 4: Enter the credentials in MyServe
Sign in to your MyServe account (https://myserve.ca or https://myserve.co).
From the menu, choose Settings > MDM Configuration.
In the MDM Integrations block choose VMware AirWatch, then press the Add button.

Fill in the four fields:
| Field | Value | From |
|---|---|---|
| Domain name | Your API server hostname, with no https:// and no path |
Step 3 |
| Username | The administrator account username | Step 1 |
| Password | The administrator account password | Step 1 |
| API Key | The REST API key | Step 2 |
Press Add, then press Synchronize inside the Manual Synchronization panel.
Step 5: Confirm it worked
The Manual Synchronization panel shows the result of the last synchronization.
If it succeeded, your devices start receiving MDM data as the synchronization progresses. You can check any device by opening its detail page and looking at the MDM tab. A small fleet fills in quickly. A large one is processed device by device and can take a few hours to complete, so it is normal to see some devices with data and others without while it runs.
After the first synchronization, MyServe refreshes the data automatically once a day.
If it failed, see the table below.
Troubleshooting
| What you see | Most likely cause |
|---|---|
| Every synchronization fails immediately, and the failure shows no reason | The Domain name is wrong. Either it is the console address rather than the API address, or it has something extra on the end such as /API. See step 3 |
| Synchronization fails with a credentials or login error | The username or password is wrong, or the account does not have the Device Manager role. See step 1 |
| Synchronization succeeds but only some devices appear | The account's Organization Group does not cover your whole fleet. See the note in step 1 |
| Synchronization succeeds but devices have no phone number | MyServe matches devices by phone number. Devices without a phone number in Workspace ONE UEM cannot be matched |
| Synchronization stopped working without any change on your side | Check whether Whitelisted Domains was enabled on the API key, or whether the API key or the account password was rotated |
Notes
Authentication. MyServe authenticates to Workspace ONE UEM with a username, a password and an API key. Omnissa also offers OAuth 2.0 for SaaS tenants and presents it as the preferred method. This integration does not currently support OAuth 2.0. If your security policy requires OAuth 2.0, or if you plan to disable Basic authentication for the REST API, please contact DMI first so we can plan for it.
Console layout. Menu names and paths have changed across Workspace ONE UEM versions, and the screenshots in this guide were captured on an earlier one, so some screens look different today. If a path in this guide does not match what you see, your own environment's API explorer at https://[your-api-server]/api/help is authoritative for your version. Tell your DMI contact if you find something out of date here and we will correct it.