Workspace ONE UEM allows you to assign applications to devices using Assignment Groups, giving you control over which devices receive an app. You can also exclude specific Assignment Groups to ensure that devices in those groups do not install the application.
You can define single or multiple assignments, each with its own set of application deployment parameters, such as restrictions, tunnel configurations, and other settings. When devices qualify for multiple assignments, you can prioritize assignments by moving them higher or lower in the list to determine which configuration takes precedence. Additionally, for Internal applications, you can schedule deployments for a future date and time, allowing UEM to automatically carry out the deployment without requiring further administrative action.
The Phased Deployment method is another way of deploying resources to devices. This method allows you to roll out resources across your device fleet gradually. For more information about using this method, see Phased Deployment of Resources.
Follow the procedure to deploy your app using Assignment Groups.
-
Navigate to Resources > Apps > Native Apps > Internal or Public.
-
Upload an application and select Save & Assign or select the application and select Assign from the actions menu.
-
On the Assignments tab, select Add Assignment and complete the following options.
a. In the Distribution tab, enter the following information: Platform-specific configurations are listed separately.
Setting Description Name Enter the assignment name. Description Enter the assignment description. Deployment Method This setting is available only for Internal apps in modern SaaS enabled UEM environments. There are two deployment methods:
Assignment Groups - Choose this method to deploy the app on all devices of the selected Assignment Groups at once upon check-in.
Phased Deployment - Choose this method to deploy the app gradually through phases. For more information about creating Phased Deployment assignments, see Phased Deployment of Resources.
For public apps, the setting appears as Assignment Groups rather than Deployment Method, since Assignment Groups is the sole deployment method available.Deployment Begins Deployment Begins On is available only for internal applications. Set a day of the month and a time of day for the deployment to start.
For a successful deployment, consider the traffic patterns of your network before you set a beginning date with bandwidth.
Note: If the Deployment Begins date is set to a future date, newly enrolled devices do not receive the previous app version assignment until the latest version of the app is released. This behavior applies to legacy UEM environments only. In modernized UEM environments, newly enrolled devices continue to receive the older app version.App Delivery Method On-Demand – Deploys content to a catalog or other deployment agent and lets the device user decide if and when to install the content. This option is the best choice for content not critical to the organization. Allowing users to download content when they want helps conserve bandwidth and limits unnecessary traffic.
Automatic – Deploys content to a catalog or other deployment Hub on a device upon enrollment. After the device enrolls, the system prompts users to install the content on their devices. This option is the best choice for content critical to your organization and its mobile users.
Note: Devices that already have an on-demand application installed cannot receive any updates to that application unless an administrator or end user initiates the installation.Allow User Install Deferral Toggle the setting to allow users to defer app installs. Use UEM or Custom Notifications Select the notification you want to use for install deferrals.
UEM – By using a UEM notification, you can define for how long the end user can defer app installs and also set a deferral message.
- Number of days after which the application automatically installs - Enter the number of days up to which you can delay app installation in the field. The maximum number of days is 10.
- Number of times a user may defer installation - Enter the number of times a user can choose to defer app installation. The maximum value is 10.
- Deferral Message - Set a Default or a Custom deferral message.
Custom – By using a custom notification, you can deploy an application wrapped in PowerShell App Deployment Kit (PSADT) from UEM and take advantage of all the features that PSADT offers, including application deferral.
- Installer Deferral Interval – Select the deferral timeframe.
- Installer Deferral Exit Code – Enter the code to indicate that the app install has been deferred.Platform-specific Setting
Platform Setting Description macOS and Windows Display in App Catalog Select Show or Hide to display an internal or public application in the catalog.
Note: The Show or Hide option applies only to the Workspace ONE Catalog and not the legacy AirWatch Catalog.
Use this feature to hide applications in the app catalog you do not want users to access.Windows Application Transforms This option is visible when your app has transform files associated. Select the transform file that must be used on the devices selected in the Distribution section. If the transform file selection is changed after the app is installed, the update does not get applied to the devices. Only the newly added devices that do not have the app installed receive the updated transform. Windows Override Reboot Handling The Device Restart settings that you configure while uploading the Win32 applications determine the device reboot action required during app installation. You can override this setting by activating the Override Reboot Handling setting from the Distribution tab of the App Assignment page. The Override Reboot Handling, when activated, displays the Device Restart options.
The Device Restart options in conjunction with the Override Reboot setting configured at the app assignment level take precedence over the restart options activated at the app configuration level. If deactivated, the reboot action defined at the app configuration level occurs.Windows Keep Application on Device after Unassignment
Keep Application on Device after Enterprise WipeUse these settings to retain or remove the Windows apps when a device is enterprise wiped or when an app is unassigned.
With these settings, you can choose to always retain critical apps (for example, security tools, VPN, firewall) on wipe or unassignment, automatically remove business or sensitive apps when devices are lost, stolen, or unenrolled. It also minimizes disruptions for end users if apps are unintentionally unassigned, and accelerates recovery after troubleshooting wipes by keeping large apps installed.
Choose one of the following to configure the setting:
- Enable - App stays on the device after it is unassigned or the device is enterprise wiped.
- Disable - App is removed.
- Default - App is removed from Windows Desktop but retained on Windows Server.
Note: Apps are removed by default on Windows desktop and kept on Windows Server, and any explicit app‑level setting overrides the existing global 'Keep Managed Applications on Device' profile for that app.b. In the Restrictions tab, enter the following information:
Platform Setting Description Android and iOS EMM Managed Access Enable adaptive management to set Workspace ONE UEM to manage the device so that the device can access the application.
Workspace ONE controls this feature and not AirWatch Catalog.
Only the devices that are enrolled in EMM are allowed to install the app and receive app policies when you enable this setting.
The setting only impacts Workspace ONE Intelligent Hub users, not the legacy AirWatch Catalog users.iOS Remove on Unenroll Set the removal of the application from a device when the device unenrolls from Workspace ONE UEM.
If you choose to activate this option, supervised devices are restricted from the silent app installation.
If you choose to deactivate this option, provisioning profiles are not pushed with the installed application. That is, if the provisioning profile is updated, the new provisioning profile is not automatically deployed to devices. In such cases, a new version of the application with the new provisioning profile is required.iOS Prevent Application Backup Prevent backing up the application data to iCloud. iOS Prevent Removal If you enable this setting, the user is prevented from uninstalling the app. This is supported in iOS 14 and later. iOS and Windows Make App MDM Managed if User Installed Assume management of applications previously installed by users on their iOS devices (supervised and unsupervised) and Windows. MDM management occurs automatically regardless of the application delivery method and requires privacy settings to allow the collection of personal applications. For unsupervised iOS devices, the apps get converted to MDM managed only upon the user’s approval.
Enable this feature so that users do not have to delete the application version installed on the device. Workspace ONE UEM manages the application without having to install the application catalog version on the device.Windows Desired State Management This option is visible only if you:
- Activate the Make App MDM Managed if User Installed setting.
- Set the app delivery method as Auto, and if the auto app does not use script detection.
Activate this setting to automatically reinstall apps when the apps' uninstall status is detected.c. In the Tunnel tab, enter the following information:
Paltofrm Setting Description Android Android Select the Per-App VPN Profile you want to use for the application and configure a VPN at the application level. Android Android Legacy Select the Per-App VPN Profile you want to use for the application and configure a VPN at the application level. iOS Per-App VPN Profile Select the Per-App VPN Profile you want to use for the application. iOS Other Attributes App attributes provide device-specific details for apps to use. For example, when you want to set a list of domains that are associated with a distinct organization. d. In the Application Configuration tab, enter the following information:
Setting Description Android Send application configurations to devices. Supported for public and internal applications. iOS Upload XML (Apple iOS) – Select this option to upload an XML file for your iOS applications that automatically populates the key-value pairs. Get the configurations supported by an application from the developer in XML format. - You might see additional configuration tabs while configuring productivity apps.
- Starting with Workspace ONE UEM 2410, the application configuration size limit has been increased from 4,000 to 30,000 characters. This enhancement allows admins to configure and deploy applications that require significantly larger configuration data, such as certificates, without encountering errors.
-
Select Create.
-
Select Add Assignment to add new app assignments for your application.
-
Configure flexible deployment settings for your application by editing the schedules and priority for your deployments. Options that are displayed on this window are platform-specific.
Setting Description Copy From the ellipses-vertical, you can click copy if you choose to duplicate the assignment configurations. Delete From the ellipses-vertical, you can delete to remove the selected assignment from the application deployment. Priority You can modify the priority of the assignment you configured from the drop-down menu while placing the selected assignment in the list of assignments. Priority 0 is the most important assignment and takes precedence over all other deployments. Your devices receive all the restrictions distribution policies and the app configuration policies from the assignment group which has the highest priority.
If a device belongs to more than one smart group and you assign these smart groups to an application with several flexible deployments, the device receives the scheduled flexible deployment with the most immediate Priority. As you assign smart groups to flexible deployments, remember that a single device can belong to more than one smart group. In turn, one device can be assigned to more than one flexible deployment for the same application.
For example, if Device 01 belongs to Smart Group HR and Smart Group Training. You configure and assign two flexible deployments for application X, which include both Smart Groups. Device 01 now has two assignments for application X.
Priority 0 = Smart Group HR, to deploy in 10 days with On Demand.
Priority 1 = Smart Group Training, to deploy now with Auto. Device 01 receives the priority 0 assignment and gets the application in 10 days because of the assignment's priority rating. Device 01 does not receive the priority 1 assignment.Assignment Name View the assignment name. Description View the assignment description. Smart Groups View the assigned smart group. App Delivery Method View how the application pushes to devices. Auto pushes immediately through the AirWatch Catalog with no user interaction. On-demand pushes to devices when the user initiates an installation from a catalog.
Note: Devices that already have an on-demand application installed cannot receive any updates to that application unless an administrator or end-user initiates the installation.EMM Managed Access View whether the application has adaptive management enabled.
When you enable this setting, the end-user is allowed to access the applications using Omnissa Workspace ONE SDK only when it is EMM managed. To avoid any disruption to the service, ensure to take over management if the 'user installed' flag is enabled. -
Select the Exclusions tab and enter smart groups, organization groups, and user groups to exclude from receiving this application.
- The system applies exclusions from application assignments at the application level.
- A device cannot receive the application if it is excluded from any version of the application or from anywhere in the Organization Group (OG) hierarchy for the same application bundle identifier. Regardless of where in the hierarchy the exclusion was set, this exclusion is applicable.
- Exclusions apply only to direct assignments and do not apply to workflows. The devices continue to get apps deployed using Workflow even if they are part of an excluded smart group.
-
Select Save & Publish.
Was this page helpful?