Skip to main content

August 13, 2026

Windows Desktop Applications

You can use Workspace ONE UEM applications in addition to Workspace ONE UEM MDM features to further secure devices and configure them with added functionality. Use the Workspace ONE Intelligent Hub for Windows to catalog and manage your applications and to facilitate communication between the device and the Workspace ONE UEM console.

Workspace ONE Productivity Apps

Use Workspace ONE Content to safeguard corporate content on mobile devices. Deploy the Workspace ONE Web to enable secure Web browsing for your end users. Download the Workspace ONE Intelligent Hub for Windows to monitor your devices on a more granular level.

Deploying Win32 apps to Windows Desktop devices requires the Workspace ONE Intelligent Hub to be present on the device.

Important: All public applications deployed to Windows Desktop devices are unmanaged applications. Unmanaged apps cannot be pushed to devices (end users must download the app themselves) nor can unmanaged apps be removed from devices through Enterprise Wipe.

Workspace ONE App for Windows Desktop

When the Workspace ONE application is installed on devices, users can sign in to Workspace ONE to access a catalog of applications that your organization enabled for them. When the application is configured with single sign-on, users do not need to reenter their sign-in credentials when they start the app.

The Workspace ONE user interface works similarly on phones, tablets, and desktops. Workspace ONE opens to a Launcher page that displays resources that have been pushed to Workspace ONE. Users can tap or click to search, add, and update apps; right-click on an app to remove it from the page, and go to the Catalog page to add entitled resources. If an app requires device enrollment, Workspace ONE uses adaptive management to start the enrollment process for the end user.

Configure the Workspace ONE Intelligent Hub for Windows Desktop

You can update the Workspace ONE Intelligent Hub settings to meet certain business needs.

  1. Navigate to Groups & Settings > All Settings > Devices & Users > Windows > Windows Desktop > Intelligent Hub Settings. Shows the Intelligent Hub Setting options in the UEM console.
  2. Configure the Data Sample Interval (min) menu item to define the intervals at which the Workspace ONE Intelligent Hub takes samples of data.
  3. Configure the MDM Channel Security menu item to set the app-layer security between the device and the Workspace ONE UEM console.
  4. Configure the Privacy settings if you use analytics tools for data collection.
    • Show Privacy Screen - Display a screen to tell your users that you collect data.
    • Collect Analytics - Collect various data points, like app crashes and endpoint numbers and send that data to your app analytics vendor.

What to do next

You can prevent end users from disabling the Workspace ONE UEM Service on their device using a Custom Settings profile.

Note: UI Lockdown - Enable to lock down completely the UI so end users cannot change settings.

Adding Win32 Applications and Management

When installing any new Win32 application, you will start in the Workspace ONE UEM console, under Resources > Apps > Native > Add > Application File. You can choose the file from either a Local File or Link and then click Save. Once the app is chosen, you will see an Add Application window open that will allow you to set and customize the settings.

Note: Optimized SFD Download Behavior: Beginning 2410, applications using scripts for detection or uninstallation no longer require a full application download when the cache is cleared. This optimization significantly reduces bandwidth consumption and speeds up application deployment.

Defer the Application Installation in the UEM

As an administrator, you can enable the option to allow users to manage and defer the app installs. In the Application Assignment menu, under Distribution, toggle on the Allow User Install Deferral option. Then, under Use UEM or Custom Notifications choose UEM. Now you can define how long the end user can defer the app installs.

The Application Assignment box is displayed, showing the options to defer app installation and create your own deferral toast notification.

You can choose to set:

  1. The Deferral Deadline- The number of days after which the application automatically installs.
  2. The Deferral Count- The number of times a user may defer installation.
  3. Both the Deferral Deadline and the Deferral Count.

If you choose to set both options, the first deferral option timeline that is reached will be when this would take effect. At that point, the user will be given the ability to defer one last time, but only for 30 minutes. After that the app will start the install process. Example: The admin sets both the Deferral Deadline to 10 Days and sets the Deferral Count to 3. The event that happens first will be the one that applies. So if the user reaches that 3rd deferral count option in 4 days, that is when the user will see the option to defer for only 30 minutes and then the app will start the installation.

The UEM does offer a default deferral toast notification message. However, if you would like to create your own, under Deferral Message choose Custom and provide your own deferral Headline and Message.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…