Skip to main content

August 26, 2026

Windows Server Management

Workspace ONE UEM lets you manage Windows servers with the same policies, workflows, and consoles you use for Windows desktops. Managing Windows Server and Windows Desktop with Workspace ONE UEM delivers:

  • Single unified platform: Manage servers, desktops, and mobile devices from one console using a single agent-based framework and unified policy model.
  • Reuse of policies and workflows: Apply existing Workspace ONE UEM policies, workflows, and automation consistently across both Windows Server and Windows Desktop environments.
  • Cost and tool consolidation: Reduce costs and save time by replacing multiple tools (for example, separate server and desktop management products) with a single UEM platform.

Technical Requirements

To implement Windows Server Management with Workspace ONE UEM, your environment must meet the following technical requirements:

  • Workspace ONE UEM 2604 or later
  • Modstack-enabled tenant
  • Windows Server Management License assigned to the tenant (Omnissa recommends you contact your account team for assistance with this)
  • Agent-based Management Mode enabled OG
  • Workspace ONE Intelligent Hub for Windows 2604 or later, which is available from https://getwsone.com
  • Windows Server 2016 or later

Configure your Organization Group or Tenant

A Windows Server Management license is required to manage Windows Server devices with Workspace ONE UEM. Without this license, you cannot enroll servers or apply configuration profiles, security policies, and compliance monitoring to server devices.

To configure the tenant organization group (OG), complete the following steps:

  1. (Optional) Create a child OG under your tenant and a new staging account to maximize security, delegation, and streamlined administration. Navigate to Groups & Settings > Groups and click OG Details.

    Note: A group ID must also be designated. Omnissa strongly recommends you create a new OG for Windows Server however; this step is optional.

  2. In the OG Details screen, enter the following parameters:

    a. Enter a name for your OG.

    b. Enter Group ID for your OG. Note: You must assign a group ID to your tenant or OG.

    c. Type: Customer.

    d. Select your Country from the drop-down menu.

    e. Select Locale from the drop-down menu.

    f. Select Time Zone from the drop-down menu.

    g. Click Save to save the configuration.

  3. Navigate to System > Devices & Users > General > Enrollment and click Management Mode, under Windows select OMADM Management for Windows devices to be enrolled into this OG whether by overriding and configuring No OMADM Management and Intelligent Hub Managed Mode.

    Note: Omnissa recommends activating this setting at the organization group (OG) level for all devices, assuming the OG contains only Windows servers. If the OG includes mixed device types, keep the setting deactivated at the OG level and apply it selectively to Windows Server Smart Groups instead.

  4. Modify the User Mode on the OG from the default Multiuser Mode to Single User Mode after overriding the current setting. Navigate to System > Devices & Users > Microsoft > Windows, click Intelligent Hub Settings and select the Windows Enrollment User Mode* as Single User Mode.

    Within Groups & Settings > Devices & Users > Microsoft > Windows > Intelligent Hub Settings, change the default Windows Enrollment User Mode to Single User
  5. Navigate to System > Devices & Users > General > Shared Device, edit the Current Setting to Override and Group Assignment Mode to Fixed Organization Group.

    Within Groups & Settings > Devices & Users > General > Shared Device, set the Group Assignment Mode to Fixed Organization Group
  6. (Optional) Navigate to System > Devices & Users > General > Enrollment and click Grouping. Configure the Default Action For Inactive Users as override and select Restrict Additional Device Enrollment.

    Go to Groups & Settings > Devices & Users > General Enrollment > Grouping to set the Default Action for Inactive Users to Restrict Additional Device Enrollment

Windows Server Enrollment

Windows Server enrollment is the process of registering Windows Server devices with Workspace ONE UEM for management. Omnissa recommends using a Directory-based service account rather than a Basic account for enrolling Windows servers. To create the service account, navigate to Accounts > Users > Add > Add User, select Basic or Directory and designate the account to be used.

Directory-based Service Account should be used for Windows Server enrollments

Use either of the following ways to enroll your Windows server devices:

  • Command Line Installation and Enrollment in a Single Step: A method of deploying the Workspace ONE Intelligent Hub agent where both the software installation and device enrollment occur simultaneously using a single command.

    1. Full Silent Install and Enroll: msiexec.exe /i AirwatchAgent.msi /quiet ENROLL=Y SERVER=$ServerName LGNAME=$GroupID USERNAME=$UserName PASSWORD=$UserPass
  • Command Line Installation and enrollment in two steps: For imaging or Virtual Machine Golden Image scenarios, installation and enrollment can be performed in two phases:

    1. In Audit mode, run: msiexec.exe /i AirwatchAgent.msi /quiet DEFERENROLLMENT=Y
    2. SYSPREP the device so the same installation can be cloned or deployed to many computers.
    3. Capture the image or create a VM Template.
    4. Deploy the device.
    5. Use a startup script or scheduled task to run: "C:\Program Files (x86)\Airwatch\AgentUI\AWProcessCommands.exe" ENROLL --SERVER $ServerName --OG $GroupID --USERNAME $UserName --PASSWORD $UserPass

    Additional parameters: Add PROVISIONHUB=Y and DEFERENROLLMENT=Y parameters to install the Intelligent Hub but not initiate the enrollment process.

Pre-registration of Windows Servers is also possible using the Bulk Import or REST API by providing the serial number or Active Directory SID of the device. For additional information, contact Omnissa Support.

Windows Server Unenrollment

You can unenroll Windows server devices from Workspace ONE UEM. The default behavior for managed resources when unenrolling a Windows Server device is to retain such resources. This can be overridden with the updated Managed Resources Policy profile.

Note: Administrators can no longer override the default behavior for applications using the Keep Apps checkbox. This checkbox is no longer available on the confirmation dialog when initiating an enterprise wipe for a single device or multiple devices. For more information, see https://kb.omnissa.com/s/article/6000825.

Resources: Baselines, Profiles, and Apps

All Windows server managed resources function the same as Windows Desktop platforms. However, since Windows Server does not include an OMADM client as part of the operating system, all Workspace ONE profiles that use CSPs are not available.

The Windows ADMX > Administrative Templates Profiles function as the primary configuration mechanism for Windows Servers. For detailed information about Baselines and Profiles, see TechZone article: Configuring Workspace ONE Windows Baselines and Profiles.

Native Applications

The Windows platform supports comprehensive application management for all four application types: EXE, MSI, MSIX, and ZIP.

Note: MSIX is supported only on Windows Server 2019 and newer versions due to an OS limitation.

When adding or modifying an application, ensure that Server is selected as a Supported Model in the Application Details. Optionally, both Desktop and Server can be selected. The minimum OS version may also be configured in alignment with the corresponding Windows Desktop version.

Windows Server designation for App Files

Baselines

Omnissa recommends applying the Windows Security Baseline to Windows Servers to strengthen security. Baseline settings vary depending on the selected Windows Server versions 2016, 2019, 2022, or 2025 and the server role, such as Member Server or Domain Controller.

Profiles

The Windows ADMX profiles are independent of OMA-DM and represent the primary profile option for Windows Server management. Each setting applicability such as OS version and OS Type is identified with an indicated by a label on the right-hand side.

For configurations involving credentials, managed resources, or custom settings, use Windows Profiles.

Note: Since Workspace ONE Assist is included with Windows Server management licensing, Omnissa recommends disabling RDP through the Windows ADMX Profile to close TCP port 3389.

Resource Assignment

Resource assignment follows the same process as other platforms, with resources being assigned through Smart Groups. Omnissa recommends assigning resources directly to the Windows Server device rather than to the user.

Smart Groups

When the Platform and Operating System are set to Windows, you can specify the Model Type as Selected > Windows - Server. This ensures that only devices running a Windows Server Operating System are included.

Note:

  • Platform and Operating System > Windows: The text currently lists Windows 10 and Windows 11 build versions, but the build numbers accurately reflect the server OS version.

  • For:

    • Windows Server 2016: Select “Windows 10 (10.0.14393)”
    • Windows Server 2019: Select “Windows 10 (10.0.17763)”
    • Windows Server 2022: Select “Windows 10 (10.0.20348)”
    • Windows Server 2025: Select “Windows 11 (10.0.26100)”

OS Updates

The Devices > Device Updates displays a breakdown of the OS versions, a list of the devices, and relevant OS update metadata.

OS updates samples are common across the Windows Platform but related to Windows Server only.

The Windows Update Administrative Template profile provides the same policy control of Windows Updates as is provided within Group Policy. Note: Windows Updates can only be configured as a Windows ADMX profile.

Sensors and Scripts

Sensors and Scripts are standardized across the Windows platform and support the same PowerShell scripting language. They can run in either System or User Execution Contexts and support multiple execution architectures. The response data types supported include String, Boolean, Integer, and Date Time.

Sensors and Scripts must be assigned to devices through a Smart Group. When targeted to the System context, they install and run even if no user is actively logged in. If configured to run in the User context, execution will occur once a user logs on to the device.

Workflows

Workflows are standardized across the Windows platform and support the same resources and conditions. Workflows must be assigned to devices through a Smart Group and will run and report their status even if there is no active user logged in.

Note: Workflows do not currently support the new Windows Server Roles and Features attributes as conditions. This limitation can be addressed by using Sensors to evaluate those attributes instead.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…