Skip to main content

August 21, 2026

Android Device Management with Workspace ONE UEM

After your devices are enrolled and configured, manage the devices using the Workspace ONE UEM console Device Dashboard. The management tools and functions allow you to keep an eye on your devices and remotely perform administrative functions.

The Dashboard is a searchable, customizable view that you can use to filter and find specific devices. This feature makes it easier to perform administrative functions on a particular set of devices. The Device List View displays all the devices currently enrolled in your Workspace ONE UEM environment and their status. You can filter the list view specific to Android and see how devices are being managed in a a glance.

Using the Device Details Page

The Device Details page provides device-specific information such as profiles, apps, Workspace ONE Intelligent Hub version and which version of any applicable OEM service currently installed on the device. You can also perform remote actions on the device from the Device Details page that are platform-specific.

You can access the Device Details page by either selecting a device's Friendly Name from the Device Search page, from one of the available Dashboards or by using any of the available search tools with the Workspace ONE UEM console.

Enrollment Status in Device Details

There are some cases when the Device Details page does not update the enrollment status due to actions performed locally on the device.

Here are some scenarios:

  • When a user performs a factory reset from the Settings app on their device, the enrollment status is not updated in the UEM console.
  • If a user removes the work profile from the Settings app on their device, the enrollment status is not updated in the UEM console.
  • The enrollment status is not updated after the limit of failed work profile or device passcode is reached which triggers a work profile or device wipe depending on the enrollment mode:
    • On Work profile, the work profile is wiped.
    • On COPE and Fully Managed devices, the whole device is wiped.

If Devices are in Power Saving Mode

Android devices running Android M use power saving options for idle apps and devices. If a user unplugs a device and leaves it stationary, with its screen off, for a period of time, the device goes into Doze mode, where it attempts to keep the device in a sleep state. There will be no network activity during this time.

Additionally, App Standby mode allows the device to determine that an app is idle when the user is not actively using it. When devices are in either state, the Workspace ONE UEM console will not receive reports on device details. When the user plugs a device in to charge or opens an app, the device will resume normal operations and reporting from AirWatch apps installed on the device to the Workspace ONE UEM console resumes.

Direct Boot for Android Devices

Direct Boot mode is when the device has been powered on but the user has not unlocked the device. When in this state, apps cannot run normally. Apps, such as Workspace ONE Intelligent Hub for Android, are not able to send samples to the UEM console or perform supported functionality when the device is in this state.

Direct Boot affects devices enrolled in Work Profile Mode differently. The Work Profile is still locked in Direct Boot mode until the Work Profile is unlocked by entering the Work Profile passcode, if one exists. In this way, apps outside the Work Profile may be able to function normally if the device is unlocked, but apps within the Work Profile may still be locked in Direct Boot mode until the Work Profile is unlocked by the user.

When a device is locked during Work Profile enrollment mode, the Work Profile lock screen supports the "Forgot my Password" button for Android 11 devices that have separate device and work profile passwords.

When a user selects "Forgot my Password", they are prompted to contact their IT admin. Selecting "Forgot my Password" the button also starts the Work Profile in direct boot (locked) mode, allowing your DPC to complete the steps to perform a secure Work Profile passcode reset.

Supported Android Device Commands By Enrollment Mode

This matrix shows you the available device commands by enrollment mode.

The asterisk denotes which commands are supported while devices are in Direct Boot mode. Executing commands in Direct Boot mode is only supported when Workspace ONE UEM uses FCM (Firebase Cloud Messaging) to communicate with devices. For more information, please see Android Settings for Workspace ONE Intelligent Hub.

Device CommandWork Managed Device ModeWork ProfileCOPE (Android 8.0-Android 10)COPE Android 11+
Device Query
Send
Lock (The Lock Command for COPE Android 11 or later devices only locks the Work Profile not the entire device.)
Clear Passcode
Clear Device Passcode (The Clear Passcode command while in direct boot is only supported with FCM (Firebase Cloud Messaging). AWCM is not supported.)✓*
Clear Work Profile Passcode✓*✓*
Generate App Token
Management
Change Device Passcode
Change Work Passcode
Lock SSO
Reboot Device
Enterprise Wipe✓*
Device Wipe (Please make sure any OEM specific policies to block factory reset are removed prior to issuing this command, otherwise it may fail.)✓*✓*✓*
Enterprise Reset (Zebra devices only)
Support
Find Device
Sync Device
Admin
Change Organization Group
Manage Tags
Edit Device
Delete Device✓*✓*✓*
Request Device Log
Override Job Log Level
Advanced
Start/Stop AWCM
Sync Device

Use the Device Details menu tabs to access specific device information, including:

  • Summary – View general statistics such as enrollment status, compliance, last seen, platform/ model/OS, organization group, contact information, serial number, power status including battery health, storage capacity, physical memory and virtual memory. Zebra devices feature a panel displaying detailed battery information. You can also view the Workspace ONE Intelligent Hub and which version of any applicable OEM is currently installed on the device. Note: If Android devices report a Manufacturer and Model that is determined to be invalid according to Android standards, the Model/OS field of the summary for the devices displays in the Console as "Unknown".
  • Compliance – Display the status, policy name, date of the previous and forthcoming compliance check and the actions already taken on the device.
  • Profiles – View all MDM profiles currently installed on a device.
  • Apps – View all apps currently installed or pending installation on the device. For internal apps, we sample the install status of all Apps. For public apps, we sample only for apps that have a launchable icon on the device. Non-managed apps without a launchable icon are not sampled.
  • Content – View status, type, name, priority, deployment, last update, and date and time of views, and provide a toolbar for administrative action (install or delete content).
  • Location – View current location or location history of a device. If your device is in power saving mode, the location data might not be updated during Doze Mode. Users are prompted to turn on Google Location Accuracy on any device where: Location data collection is enabled in Intelligent Hub Settings at the device's Organization Group or Location data collection is enabled in Privacy Settings for the device (based on Organization Group and ownership type). Users will be prompted to grant Hub Location permissions in Work Profile and COPE devices on Android 12 and higher. For more information, see Android Settings for Workspace ONE Intelligent Hub.
  • User – Access details about the user of a device as well as the status of the other devices enrolled to this user. The menu tabs below are accessed by selecting More from the main Device Details tab.
  • Network – View current network (Cellular, Wi-Fi, Bluetooth, or eSIM) status of a device. Note: If Location Services is not enabled on a device, it may not be possible to collect and report the active SSID. In these cases, SSID is reported as "Unknown SSID".
  • Telecom – View all amounts of calls, data and messages sent and received involving the device.
  • Notes – View and add notes regarding the device. For example, note the shipping status or if the device is in repair and out of commission.
  • Certificates – Identify device certificates by name and issuant. This tab also provides information about certificate expiration.
  • Products –View complete history and status of all packages provisioned to the device and any provisioning errors.
  • Custom Attributes – Enable you to use advanced product provisioning functionality.
  • Files/Actions – View the files and other actions associated with the device.
  • Event Actions – Allows you to take action on a device when predetermined conditions are met
  • Shared Device Log – View history of device in terms of Shared Device, including past checkins and check-outs and current status.
  • Troubleshooting – View Event Log and Commands logging information. This page features export and search functions, enabling you to perform targets searches and analysis.
  • Event Log – View detailed debug information and server check-ins, including a Filter by Event Group Type, Date Range, Severity, Module, and Category. In the Event Log listing, the Event Data column may display hypertext links that open a separate screen with even more detail surrounding the specific event. This information enables you to perform advanced troubleshooting such as determining why a profile fails to install.
  • Commands – View detailed listing of pending, queued, and completed commands sent to the device. Includes a Filter enabling you to filter commands by Category, Status, and specific Command.
  • Compromised Detection – View details about the compromised status of the device including the specific Reason for the status and how Severe the status is.
  • Status History – View history of device in relation to enrollment status.
  • Targeted Logging - View the logs for the Console, Catalog, Device Services, Device Management, and Self Service Portal. You must enable Targeted Logging in settings and a link is provided for this purpose. You must then select the Create New Log button and select a length of time the log is collected.
  • Attachments – Use this storage space on the server for screenshots, documents, and links for troubleshooting and other purposes without taking up space on the device itself.

MAC Address Behavior for Android

On devices that run Android 10 or higher, the system transmits randomized MAC addresses by default. This is different from previous versions of Android.

The Android OS version and the enrollment type determines how we collect the Wi-Fi MAC address:

  • Fully managed devices can collect the actual hardware WiFi MAC address on all OS versions.
  • COPE devices can collect the actual hardware WiFi MAC address on all OS.
  • Work Profile devices can collect the actual hardware Wi-Fi MAC address on Android 9 and below.
  • Work Profile devices can collect the randomized WiFi MAC address for the active SSID on Android 10 or later.

eSIM Management

You can remotely manage embedded SIMs (eSIMs) on Android devices. Add, track, and remove managed eSIMs while minimizing user interaction and maintaining full visibility into managed eSIMs across your device fleet.

Requirements

  • Minimum OS version: Android 15
  • Supported Management Type: Custom DPC

Remotely Add an eSIM to a Single Device

To add an eSIM to an individual Android device, use the Install eSIM action, accessible from the device record in the console.

  1. Navigate to the target device via Device Details > More Actions and select Install eSIM.
  2. Select how to add the eSIM to the device. Your carrier may only support one of the following methods:
    • Activation Code: Use a pre-generated activation code provided by your carrier.
    • eSIM Server Hostname: Enter the hostname of the carrier's SM-DP+ server.
  3. (Corporate-owned devices only) For devices enrolled as Work Managed or COPE, you can choose to enable the eSIM as soon as it is added to the device. Workspace ONE UEM will attempt to enable the eSIM silently, but user interaction will be required in some cases.

Deploy Managed eSIMs at Scale

Use the Workspace ONE UEM REST API to deploy managed eSIMs across multiple devices. You may use either of the following APIs:

  • MDM v4 Actions: This API supports adding eSIMs to Android devices using eSIM Server Hostname or Activation Code.
  • MDM v2 Commands: This API supports adding eSIMs to iOS devices as well. However, this API only supports adding eSIMs on Android devices using an eSIM Server Hostname. Activation Code is not supported.

User Experience for eSIM Addition

The eSIM user experience varies depending on the device's management mode and whether the Enable eSIM option is selected during provisioning.

Management ModeEnable eSIMUser experience
Work Managed & Corporate Owned Personally Enabled (COPE)EnabledWorkspace ONE UEM attempts to add and enable the eSIM silently. Workspace ONE Intelligent Hub will notify the user if manual action is required.
Work Managed & Corporate Owned Personally Enabled (COPE)DisabledWorkspace ONE UEM adds the eSIM to the device and notifies the user. The user may tap on the notification or navigate to Settings to enable the eSIM.
Employee-ownedN/AWorkspace ONE UEM adds the eSIM to the device and notifies the user. The user may tap on the notification or navigate to Settings to enable the eSIM.

You can find the MAC Address listed in the Network tab of Device Details.

Device Management Commands for Android Devices

The More drop-down on the Device Details page enables you to perform remote actions over-the-air to the selected device. The actions listed below vary depending on factors such as device platform, Workspace ONE UEM console settings, and enrollment status.

Clear Passcode

  • Clear Passcode (Device) – Clear the device passcode. To be used in situations where the user has forgotten their device's passcode.
  • Generate App Token - Generate app token for users who forget their login information for Workspace ONE SDK-built applications.
  • Clear Work Passcode - Clear the work or container passcode. To be used in situations where the user has forgotten their device's passcode.

Management

  • Change Device Passcode – Replace any existing device passcode used to access the selected device with a new passcode.
  • Change Work Passcode - Select to remove the work security challenge on the device. For Android 8.0 or later.
  • Lock SSO – Lock the device user out of Workspace ONE UEM Container and all participating applications.
  • Reboot Device – Reboot a device remotely, reproducing the effect of powering it off and on again.
  • Device Wipe – Send an MDM command to wipe a device clear of all data and operating system. This action cannot be undone. Note: On Zebra devices, Workspace ONE UEM will only execute the Device Wipe command when the device battery level is at 5% or higher. The behavior of the Device Wipe feature varies based on profile settings and management mode. For more information see Android Profiles
  • Lock SSO – Lock the device user out of Workspace ONE UEM Container and all participating applications.
  • Enterprise Wipe – Removes enterprise data from the device without impacting any personal data. On COPE enrolled Android 11 + devices, Enterprise Wipe unenrolls the device, removes the work profile, and leaves the personal profile in tact.
  • Install eSIM - Remotely activate an eSIM on corporate-owned devices without physical interaction. Managed eSIMs must be enabled at least once on the device before Workspace ONE UEM can collect and display their information in Workspace ONE UEM. You must provide an eSIM URL or an activation code to install.
  • Remove eSIM - Delete the eSIM profile and cellular carrier data from a managed device. Once you select the Remove eSIM option, you will select them eSIM you wish to remove and save.

Support

  • Find Device – Send a text message to the applicable Workspace ONE UEM application together with an audible sound designed to help the user locate a misplaced device. The audible sound options include playing the sound a configurable number of times and the length of the gap, in seconds, between sounds.
  • Sync Device – Synchronize the selected device with the UEM console, aligning its Last Seen status.

Admin

  • Change Organization Group – Change the device's home organization group to another existing OG. Includes an option to select a static or dynamic OG. If you want to change the organization group for multiple devices at a time, you must select devices for the bulk action using the Block selection method (using the shift-key) instead of the Global check box (next to the Last Seen column heading in the device list view).

  • Manage Tags -

  • Edit Device – Edit device information such as Friendly Name, Asset Number, Device Ownership, Device Group Device Category.

  • Delete Device – Delete and unenroll a device from the console. Sends the enterprise wipe command to the device that gets wiped on the next check-in and marks the device as Delete In Progress on the console. If the wipe protection is turned off on the device, the issued command immediately performs an enterprise wipe and removes the device representation in the console.

  • Request Device Log – Request the debug log for the selected device, after which you can view the log by selecting the More tab and selecting Attachments > Documents. You cannot view the log within the Workspace ONE UEM console. The log is delivered as a ZIP file that can be used to troubleshoot and provide support. When you request a log, you can select to receive the logs from the System or the Hub. System provides system-level logs. Hub provides logs from the multiple agents running on the device.

    Android Only: you can retrieve detailed logs from corporate-owned Android devices and view them in the console to resolve issues on the device quickly.

  • Override Job Log Level – Override the currently specified level of job event logging on the selected device. This action sets the logging verbosity of Jobs pushed through Product Provisioning and overrides the current log level configured in Android Hub Settings. Job Log Level Override can be cleared by selecting the drop-down menu item Reset to Default on the action screen. You can also change the Job Log Level under the Product Provisioning category in Android Hub Settings.

Advanced

  • Start/Stop AWCM – Start/Stop the Cloud Messaging service for the selected device. AirWatch Cloud Messaging (AWCM) streamlines the delivery of messages and commands from the Admin Console. The AWCM eliminates the need for end users to access the public Internet or use consumer accounts such as Google IDs.
  • Sync Device – Synchronize the selected device with the UEM console, aligning its Last Seen status.

Device Wipe and Enterprise Factory Reset Protection

Enterprise Factory Reset Protection lets you specify trusted Google accounts that can unlock a device after it's been factory reset. This helps prevent unauthorized access, but it's worth understanding how it interacts with the device wipe functionality in Workspace ONE UEM.

If EFRP is not removed before or during a factory reset, the device will require manual sign-in with a trusted Google account before it can be set up or re-enrolled.

How EFRP is handled depending on how the device is unenrolled

If your device has EFRP configured through an Android profile, here's what happens in each scenario:

  • Device Wipe command: You'll be prompted to choose whether to remove the EFRP policy as part of the wipe. Note: If the device is managed in Custom DPC and is in Direct Boot mode when the wipe is initiated, EFRP may be removed regardless of your selection.
  • Admin deletes the device from the Workspace ONE UEM console: EFRP is automatically removed.
  • User unenrolls from Intelligent Hub: EFRP is automatically removed.

Details Apps Tab

The Devices Details Apps Tab in the Workspace ONE UEM console contains options to control public applications by device. You can view apps that have been assigned in the UEM console and personal apps based on the enrollment type and privacy configurations.

Admins can view information about the application including the installation status, the application type, the application version, and the application identifier.

The Install option from the actions menu lets you select the assigned apps from the list view and directly push to the device. The Remove option from the actions menu to uninstall the application silently off the device.

Work Profile enrollments only display apps assigned by the admin and will not display personal applications installed by the user. Work Managed enrollments display all applications because Workspace ONE UEM has full control of the device, and there is no concept of personal applications. For a COPE enrollment, the device details apps tab display managed applications, which include internal applications that are install on the personal side by default.

The Workspace ONE UEM console will not show apps that cannot be launched by users. The UEM console reports the status of apps that have a Launcher icon that the user can click on and open. Therefore, background apps or service applications are not shown in device details.

The Request Device Log command allows you to retrieve Workspace ONE Intelligent Hub or detailed system logs from corporate-owned devices and view them in the console to quickly resolve any issues on the device. The Request Device Log dialog box allows you to customize your logging request for Android devices. See more details below.

Request Device Log

The Request Device Log command allows you to retrieve Workspace ONE Intelligent Hub or detailed system logs from corporate-owned devices and view them in the console to quickly resolve any issues on the device. The Request Device Log dialog box allows you to customize your logging request for Android devices.

File Storage is not set up in Workspace ONE UEM, logs uploaded by Workspace ONE Intelligent Hub will be divided into multiple, smaller files. Piecing together these files is not always feasible, such as in the case of System logs, where not all log lines contain a timestamp. File Storage must be manually set up for on-premises Workspace ONE UEM environments. More information on File Storage can be found here: File Storage.

  1. Navigate to Groups & Settings > All Settings > Devices and Users > General > Privacy and enable Request Device Log in the privacy settings.

    Employee- owned devices are not allowed to be selected due to privacy concerns

  2. Navigate to Devices > List View > Select device from list > More Actions > Request Device Log.

  3. Customize the log settings:

    SettingDescription
    SourceSelect Hub to collect logs generated by Workspace ONE Intelligent Hub.
    Select System to collect logs for all applications and events on the device. Supported only in devices enrolled in Work Managed mode. For Zebra devices, Intelligent Hub collects the output of RX Logger. On non-Zebra devices, users will see a notification asking them to authorize collection of a bug report by their administrator.
    Select Network to record DNS requests and network connections from apps to a log file for the specified duration. Note: Available on Work Managed devices running Android 8 or higher. Note: Collect Public IP Address must be enabled in Privacy Settings.
    Select Security to collect security logs that detail possible security breaches such as pre and post boot activities, authentication attempts, credential storage modification, attempted adb connections, and more. Note: Requires Work Managed Android 7.0 or later devices and Workspace ONE Intelligent Hub 21.05 for Android. The Security option is greyed out if devices do not meet these requirements.
    Select AMAPI to collect logs generated by Android Management API, including what device information AMAPI currently has for a device and the latest policies that AMAPI is applying to the device.
    TypeSelect Snapshot to retrieve the latest log records available from devices. Select Timed to collect a rolling log over a specified period. Multiple log files may be sent to UEM console.The 'Level' option will not be available when Network is selected
    DurationSpecify the duration of time for the device to collect and report logs to the console.
    LevelDetermine the level of detail included in the log (Error, Warning, Info, Debug, Verbose).
  4. Select Save.

  5. To review the log files, navigate to Device Details > More > Attachments > Documents.

  6. Cancel the device log request after the logs have been received and there is no further need for log collection. Navigate to Devices > List View > Select device from list > More Actions > Cancel Device Log to cancel the device log request.

SafetyNet Attestation

SafetyNet Attestation is a Google API used to validate the integrity of the device ensuring the device is not compromised.

SafetyNet validates software and hardware information on the device and creates a profile of that device. This attestation helps determine if a particular device has been tampered or modified. When the Workspace ONE UEM console runs the SafetyNet Attestation API and reports the device has been compromised, the UEM console Device Details page reports the device as compromised. If SafetyNet Attestation detects the device as compromised, the only way to revert a device compromised state is to re-enroll the affected device.

It is important to note that SafetyNet Attestation does not re-evaluate compromised status after it is initially reported.

SafetyNet Attestation is only supported with Workspace ONE Intelligent Hub.

Enable SafetyNet Attestation Enable the SafetyNet Attestation API in the UEM console to validate the integrity of a device and determine if a device has been compromised.

  1. Navigate to Groups & Settings > All Settings > Apps > Settings & Policies > Settings > Custom Settings

  2. Paste the following custom XML into the Custom Settings field: { "SafetyNetEnabled":true }

  3. Save the Custom XML.

  4. Verify SafetyNet from the Summary tab in the Device Details page in the UEM console. If you do not see the status of the SafetyNet Attestation, you can send a remote command to restart the device.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…