Skip to main content

19 mai 2026 Archivé

Workspace ONE UEM Services, Queues, Certificates, and Tasks

Workspace ONE UEM offers an extensive assortment of services, queues, certificates, and scheduler tasks as part of our software. Learn more about the services, queues, certificates, and admin scheduler tasks including descriptions that enhance your understanding of the full Workspace ONE UEM offering.

List of Services

Learn more about the Workspace ONE UEM offered services and their purpose within your environment.

Service Description
AirWatch API WorkflowThis service processes device commands from REST API.
AirWatch Background Processor ServiceThis service is used for asynchronous execution of long running jobs.
AirWatch Batch Processing ServiceThis service processes batch requests from the AirWatch system.
AirWatch Cloud Messaging ServiceThis service runs a message queueing server which transfers messages to and from devices and AirWatch servers.
AirWatch Compliance ServiceThis service handles compliance rule level evaluations and takes action on the scheduler level.
AirWatch Content Delivery ServiceThis service pushes staging and provisions content to relay servers.
AirWatch DataPlatform ServiceThis service pushes data to the Intelligence platform.
AirWatch Device SchedulerThis service orchestrates scheduled jobs across the console and devices.
AirWatch Directory Sync ServiceThis service synchronizes uses and user groups from external user stores.
AirWatch Entity Change Queue MonitorThis service monitors the event log queue and send outbound event logs.
AirWatch Entity Reconcile ServiceThis service reconciles and syncs for entities linked to smart groups.
AirWatch Eventlog Processor ServiceThis service monitors the event log queue, enriches them, and posts to the Intelligence platform.
AirWatch GEM Inventory ServiceThis service communicates instance specific information to the GEM.
AirWatch Integration ServiceThis service integrates AirWatch with third-party applications.
AirWatch Interrogator ServiceThis service reads device sample information from the queues and writes the information to the database.
AirWatch MEG Queue ServiceThis service reads and processes mobile email gateway requests from the message queues.
AirWatch Messaging ServiceThis service sends messages to the respective device cloud services (Exmaple: APNS, FCM, and others).
AirWatch Outbound Queue Monitor ServiceThis service subscribes for outbound event notifications.
AirWatch Policy EngineThis service determines the product and the product set applicability and compliance for devices. If needed, project jobs are sent to the device to install/uninstall profiles, files, actions, and applications.
AirWatch Provisioning Package ServiceThis service generates PPKG packages for the factory provisioning flow.
AirWatch Smart Group ServiceThis service is responsible for smart group device map updates.
AirWatch SMS ServiceThis service is used by AirWatch to send SMS messages to devices.
AirWatch Tunnel ServiceThis service manages tunnel configuration for devices and servers such as traffic rules and outbound configurations.
MetadataTransformServiceThis service stores the DDUI metadata information that is used to render the UI. Also, the service creates the final device profile before sending it to the device.

List of Message Queues

The following is a list of Workspace ONE UEM message queues and descriptions.

Queue NameDescription
APNSOutboundiOS Outbound APNS Messages
AWAdminBatchQueueAdministration Group Batch Processing
AwAdminPasswordNotificationQueuePassword Expiration Management for Local Basic Admins
AWAppleCareGsxIntegrationAppleCare Model Information Request
AWApplicationEventSampleApplication Analytics for iOS Content Locker
AWApplicationFeedbackUsed for Managed Application feedback samples
AWApplicationListSampleiOS Application List Samples (From Device)
AWApplicationReportHandles report messages sent by the device SDK
AWAppScanTpiQueueApp Scan requests to Third-Party Apps
AWAppWithUpdatesQueueVPP Applications Auto Update
AWAsyncExportQueueAsync exports of Telecom data from console
AWAutoDiscoveryUsed for auto discovery messages
AWAvailableOsUpdatesListSample Process the available OS Updates Samples for Devices
AWBaselineSampleBaseline sample information from devices (in 1909, but not used)
AwBackgroundJobsReportsBatch processing for legacy SSRS reports.
AWBiosSampleDell BIOS Samples
AWBluetoothInformationSampleAndroid/WinMo Bluetooth Samples (From Device)
AWCallLogSampleAndroid/WinMo Call Log Samples (From Device)
AWCellInformationSampleAndroid/WinMo Cellular Information Samples (From Device)
AWCellSignalQualitySampleAndroid/WinMo Cell Signal Quality Samples (From Device)
AWCellTowerInformationSampleAndroid/WinMo Cell Tower Information Samples (From Device)
AWCertificateListSampleiOS Certificate List Samples (From Device)
AWCMOutboundAWCM Outbound Messages [For Rugged]
AWComplianceReconciliationQueue 
AWComplianceDeviceQueueReal Time Device Compliance for enrollment and reenrollment flows
AWComplianceServiceQueueQueue for standalone Compliance service
AwConditionalAccessConfiguredQueuedecouples one-time upload (sync) large operation when configuring conditional access for Microsoft
AWContentBatchQueueMulti-file delete support for content
AWDepBatchQueueProcess DEP sync and assign profile requests
AWDeviceCapabilitySampleAndroid Device Capability Samples (From Device)
AwdevicecomplianceactionsqueueInstaller changes to add a new queue for device compliance actions.
AWDeviceComplianceAttributeQueueTrustPoint Integration
AWDeviceCustomAttributeListSampleList of device custom attributes, used primarily by rugged devices (Android, QNX, WinMo, Mac, PCs)
AWdeviceDomainJoinResourceQueueWindows 10 Offline Domain Join
AWCdnv3OriginMigrationqueueUsed to migrate Blobs to CDN v3
AWDevicePolicyRuleComplianceEvaluationQueueHandles evaluation of sample for existing rules in the app list policy.
AWDevicePolicyRuleComplianceQueueHandles evaluation of rules on policy edit and app groups edit.
AWDeviceSampleDataUsed for initializing devices for compliance
AwDeviceSensorQueueStores Windows 10 Custom Samples before sending to AWS
AwDeviceStateChangeQueueContains Device State change events like Enrollment/Unenrollments and Compliant/Noncompliant.
AWDeviceSyncQueueGeneric MDM Queue
AWDiskEncryptionSampleDisk Encryption Samples (From Device)
AWEasSampleGeneric MDM Queue
AWEfotaSampleSamsung Efota Samples
AWEscrowedGatewayProcessingQueueDecouple cert validation and presence in Escrow Gateway service through a scheduler
AWEventActionSampleEvent Actions Samples (From Device)
AWEventLogKeeps various events related to device/system activities
AwEventLogProcessorStores event logs messages before being sent to Elastic Search (Inactive)
AWExternalDirectoryBatchQueueQueue for User Authentication and Directory Sync for Workspace One Access
AWFetchAppUpdatesQueueVPP Applications Auto Update
AWGPSCoordinateSampleAndroid/WinMo GPS Coordinate Samples (From Device)
AWGPSExtendedCoordinateSampleAndroid/WinMo Extended GPS Coordinate Samples (From Device)
AWHealthAttestationSampleQueue Health Attestation Sample
AWInstalledApplicationListSampleInstalled Application List Sample (Inactive)
AWIntegrationServiceThis queue is for handling Web Sense certificate requests asynchronously.
AWIntegrationServiceGenericQueueQueue Compliance State for Windows 10 Devices
AWInventoryCheckinCommandQueueGEM Inventory Service
AWLocalBasicUserSyncQueueUsed for triggering a local basic user sync at regular intervals (inactive)
AWLogManagerXmlWinMo LogManager XML Samples (From Device)
AWManagedLicenseListSampleWindows [Phone] 10 Application and License Status
AWManagedMediaListSampleManaged Media List Sample (Managed Books)
AWMegPayloadsMEG Payload Samples (from API)
AWMemorySampleAndroid/WinMo Memory Samples (From Device)
AWMetricsSampleNew Product Provisioning
AWMobileDataUsageSampleAndroid/iOS [Non-]Mobile Data Usage Samples
AWNetworkAdapterSampleAndroid/WinMo Network Adapter Samples (From Device)
AWNetworkWLANSampleAndroid/WinMo Network WLAN Samples (From Device)
AWOemUpdateSampleProcess the status of the OEMUpdate(s) for Devices
AwOEMProvisioningQueueDevice information for Windows OEM reprovisioning (in 1909, but not used)
AwOemUpdateSampleSummaryQueueDELL OEMUpdate Samples Summary
AWOpsDeviceRegistrationQueue 
AWOsUpdateStatustListSampleProcess the status of the OS Updates for Devices
AWOutboundEventLogOutbound queues for the "Outbound Event Notification" feature
AWPatchApplicationListSampleApplication List for Unmanaged Devices
AWPolicyListSampleNew Product Provisioning
AWPolicyProductListSampleNew Product provisioning
AWPowerSampleAndroid/WinMo Power Samples (From Device)
AWPrinterNotificationCommon MSMQ to send notifications to Zebra and Toshiba Print Servers
AWProfileListSampleiOS Configuration Profile List Samples (From Device)
AwProvisioningPackageServiceQueueCleans up the PPKG from the storage location (CDN)
AWProvisioningProfileSampleiOS Provisioning Profile Samples (From Device)
AWPublishQueueiOS Bulk Profile Publish (From Console)
AWRestrictionsListSampleiOS Restrictions List Samples (From Device)
AWRosterSyncQueueQueues an event for making a roster sync call to Apple API when an admin makes an on-demand request from the console.
AWScheduleOsUpdateResultListSampleProcess the results of the ‘Install OS Updates’ Command
AWSecurityInformationSampleiOS Security Information Samples (From Device)
AWSeedSystemAppsQueue 
AWSEGComplianceCompliance Information for SEG
AWSegFastComplianceMEM High Priority Compliance Commands
AWSelectiveApplicationListSampleApplication Sample Query for iOS 7+ Devices
AWSmartGroupDeviceMapCleanup 
AWSmartGroupEventData for Monitoring User Group Change Events
AWSmartGroupPublishSmart Group Publish Events
AWSMSLogSampleAndroid/WinMo SMS Log Samples (From Device)
AWTimeWindowSampleQueue 
AWWindowsDeviceStatusSampleWindows Device Status Sample
AWSWindowsInformationSampleWindows Information Sample (Windows 8 Devices only)
AWSystemSampleAndroid/iOS/WinMo Device/System Information Samples (From Device)
AWToMagOutboundQueueQueues message to be sent to MAG through AWCM
AWUemEnrollmentEventQueue 
AWUpdateManagedAppleId 
AWUpdateListSampleMicrosoft EMM: Handles messages related to Windows Updates Revisions
AWUploadToCdnQueueSeed Agents to CDN
AWUserBatchQueueUser Batch Processing Information
AWUserDataSampleOneDrive Integration for User Data Recovery and Migration (Inactive)
AWUserGroupsBatchQueueProcess User Group actions (sync user attributes, add missing users)
AWUserListSampleUsed for saving user list sample changes.
AWVppBulkDeploymentProcess Users for VPP bulk registration of users and licenses
AWVppLicensePreAssignmentQueueQueues an event for making a license preassignment call to Apple API when an admin makes this on-demand request from the console.
AWVppLicenseSyncQueueQueue to process the VPP apps for license sync
AwWindows10KioskQueueKiosk profile publishing
AwWindowsPpkgPackagingQueueExport applications from WS1 into the PPKG format
AwWindowsSecurityInformationSampleWindows 10 DeviceGuard / Security Information Sample (Inactive)
awwindowsupdatequeueWindows 10 (Microsoft EMM)
AWWindowsWmiSampleWindows device queue for WMI samples
AWWnsNotificationWindows Notification Service (WNS) Notifications
AWWorkflowEventProcess all workflow events
AWWorkflowStatusSampleQueueWorkflow status must go through MSMQ for changes of Rate-Limit WF Status Processing
awvpplicensesmanagementTo store the message about the device ID and list of application IDs to revoke licenses for.
C2DMOutboundAndroid Outbound C2DM Messages
FastLaneAPNSOutboundiOS Outbound APNS Messages
FastLaneWnsOutboundCritical WNS Outbound Messages
GCMOutboundAndroid Google Cloud Messaging Outbound
SyncDirectoryAdminAttributesQueueQueues for the Directory Sync Service
SyncDirectoryGroupsQueueQueues for the Directory Sync Service
SyncDirectoryUserAttributesQueueQueues for the Directory Sync Service
WorkFlow-DeviceCommandsAPI Workflow

List of Certificates

The following is a list of Workspace ONE UEM certificates bundled in the installer and the certificate generated by the installer.

File NameInstalled LocationPurpose
AppleAPNs_Entrust2048.cer Trusted Root Certification Authorities Apple Push Notification Service
AppleComputerRootCertificate.cerTrusted Root Certification AuthoritiesApple Root CA
AppleWWDRIntCA.cerIntermediate Certification AuthoritiesIssuer for certificates used to sign software for apple devices
AW_Admin_User_Root.cerTrusted Root Certification AuthoritiesRoot certificate for client certificates used for authentication to admin APIs
AW_API_Client_Root.cerIntermediate Certification AuthoritiesUsed for authenticating SOAP APIs
AW_API_Root.cerTrusted Root Certification AuthoritiesRoot for AW_API_CLIENT_Root.cer
AW_API_Server.pfxPersonal, Trusted PeopleBinding to the SOAP APIs
AW_Device_Root.cerTrusted Root Certification AuthoritiesRoot certificate for device secure channel certificates
AWDSRoot.cerTrusted Root Certification AuthoritiesRoot certificate for device services/secure channel server certificates.
ca_cert.cerTrusted Root Certification AuthoritiesCode Signing CA for third-party libraries
Symantec Class 3 Registration Authority TEST CA.cerIntermediate Certification AuthoritiesTest integration with Symantec
VeriSign Class 3 TEST Public Primary Certification Authority.cerTrusted Root Certification AuthoritiesTest integration with VeriSign
*Generated by Installer* Device Services Child CertificatePersonal, Trusted Root Certification AuthoritiesSecure channel server certificate. Used for application-level encryption of data sent from the device to the server.

List of Admin Scheduler Tasks

You can configure scheduler tasks by editing the frequency of individual tasks or by deactivating tasks. The following list explains each task.

Scheduler TaskDescription
Hub Package Process RepositoryWatches the package repository directory for WinMo Hub packages and pulls them in to the database.
Android Work Google Device Id Validation JobUpon enrollment into Android, the server waits for a Google generated deviceID, so that it can initiate the application assignment and push. There are a few minutes delay in getting this ID and this scheduler checks whether any new enrolled device has the ID updated and if yes, start the application sync process.
App EULA Update NotificationAccounts for all devices for which App EULA acceptance is pending and sends notifications. After sending the final notification, the app is removed from the device.
Auto Renew Expiring ProfileChecks for certificates that expired within a renewal grace period configured on certificate authority and renews them.
Auto-rotate Google PasswordHandles password provisioning and purging for integration with Google Sync.
BitLocker Recovery Key Rotation JobRotates the BitLocker admin recovery key based on the values configured in the profile.
Command Publish Batch JobRotates commands from held status to pending installation for application and certificate deployment.
Console NotificationsChecks to see if any new notifications must be added to an admin's notification list (Example: APNs expiration notification). These notifications appear in the admin console and are emailed to the admins.
Device Based VPP Apps to Track UpdateChecks which VPP applications at an organization group have the device-based licensing and the auto update enabled. Apps are added or removed from the list used by the VPP auto update scheduler job.
Device Enrollment Program UpdateInitiates sync command from Apple to send the added and removed devices for a DEP token at a given OG to update our records.
Email Password RemovalRemoves Google password generated for email from Workspace ONE UEM database.
File Encryption MigrationEncrypts or decrypts the content stored in the file storage based on the settings in All Settings > Admin > Storage.
Install Application On DemandTriggers install of Apple VPP applications upon VPP invite acceptance and triggers install of failed-eligible Apple VPP applications.
List View ExportChecks when an admin requests an export for the device or the user list view. If it has, it schedules a background job to run asynchronously. Once that background job completes, the list view export is available for download.
MDM Application List SampleCollects the status of applications that are marked as 'MDM apps' from all the devices. Applicable only for iOS apps and devices. Scheduler is turned off by default and enabled only for customers who request the functionality.
MDM License Count UpdateChecks device enrollment counts and updates the customer's license counts. Used to track product usage.
P2P license true-up with vendorIdentifies all the peer distribution server licenses that are about to expire, renews the licenses by communicating with the Adaptiva cloud licensing service, and distributes the renewed license key to the peer distribution server.
Peer Distribution Software Notification JobIdentifies all the Peer Distribution servers that do not have the latest version installed and notifies the administrator to update.
Profile Publish Batch JobProfile publishes for the CA and the Tunnel profile queues the install profile command in held status is by Profile Publish Batch Job in batches. Selects a batch and batch size, based on the settings configured in the Workspace ONE UEM Console (under Settings > Installation > Performance Tuning for on-premise environments).
Purge Marked For DeleteThis job deletes repos/folders/files under a repository that is marked for deletion.
Query Feedback ServiceChecks Apple's Feedback Service for statuses and causes of failed APNs commands.
Re-queue Device CommandsApplicable only for Windows devices. Identifies devices with failed application installs and re-tries installation. The number of re-try attempts and the interval for the next attempt are identified from the performance tuning settings 'Max re-try attempts for failed app install' and 'Failed Application Install Retry Interval' respectively.
Run Compliance EngineThe scheduler job evaluates compliance in scenarios where:
  • Compliance policy is created post-enrollment
  • Any subsequent changes are made to the compliance policy
  • Any changes made to smart group
  • Device moves organization groups
  • Changes made to app groups
  • Certain Telecom based compliance policies are enabled
  • Apple Templates are used
S/MIME Certificate CleanupChecks for all S/MIME certificates that have completed their retention period and purges them.
Scheduled Application Batch ReleaseUsed to release internal application install commands created and held by 'Scheduled Application Publish' job. Selects queued application batch (roundrobin). Calculates device list using configured 'Batch Size' text box of performance tuning section. Releases install commands for batch.
Scheduled Application PublishUsed to trigger the installation and removal of internal applications based on newly effective assignments. Creates held batch of install commands. Creates remove commands for the immediate release.
Send Apps to App Scan VendorSend a unique list of applications installed across entire device fleet to the configured app scan vendor.
Send VPP Invites and AppsChecks for users assigned user-based VPP apps and either sends email or device notifications inviting users or devices to participate in user-based licenses of the Volume Purchase Program.
Server Action TaskHandles Time Schedule profiles. The job runs at configured intervals and takes action of install or remove profile as per the time span configured for Time schedule profiles.
Staged Command Data Processing JobUsed to schedule the processing of bulk commands from the Device List View page.
Sync Chrome OS DevicesRetrieves new Chrome OS enrollments from Google and creates a corresponding device record in Workspace ONE UEM.
Sync Directory GroupsQueries the directory to grab all members of synchronized directory groups. Stores users who are part of the group in the UserGroupEnrollmentUserMapSync table. Compares those users by Distinguished Name (DN) or other unique attribute in the UserGroupEnrollmentUserMapSync table to the Mobilemanagement.EnrollmentUser table. If the group is configured with add missing users enabled and User does not exist with that DN, then user details are pulled from the AD using user ExternalID and stored in the Mobilemanagement.EnrollmentUser table.
Sync Directory User and Admin AttributesQueries the directory to sync user attributes based on eternalID.
Sync External ContentSyncs admin repo metadata for all the repositories where admin user credentials are set in the MCM console.
Sync MEM Device Resource ID JobSyncs Google device records with Workspace ONE UEM for approving new enrollments / mobile mail configurations
Telecom Assign Plans/Roll-up UsageCalculate usage limits for devices whose admin has enabled telecom tracking. Necessary to run reports, populate dashboard, and have the accurate list view for Telecom.
Temporary Session Key Clean UpClears temporary encryption keys used to encrypt the admin provided passphrase in a downloaded configuration file. The key is removed from the database so that it is impossible to retrieve the passphrase from the configuration file after the 48-hour key rotation window has passed.
VPP Auto UpdateChecks iTunes for latest version of VPP applications from the list created by Device Based VPP Apps to Track Update job. Each app is checked once every 24 hours. If an update is available, the job kicks off the update command to assigned devices.
VPP Revoke LicensesChecks for users with associated licenses but no corresponding assigned application. It then issues a revoke command of the license from the user to disassociate it from the license so it can be reused.
Workflow ServiceUsed with the App store restriction, if the restriction is enabled then only one app workflow is active at a time. If there is any issue with the application installation, it deletes in 15 minutes and next one starts.
Purge JobRemoves orphan application blobs from the file storage, and CDN origin server if CDN is configured. Removes expired SDK application log files from the database. By default, the application log files expire every 14 days. Moves any application binary blobs to the file storage from the database if the file storage is configured. Moves non-expired SDK application log files from the database to file storage, if the file storage is configured. Global OG data does not get impacted with respect to the changes made to the blob purge. By default, the scheduler triggers every 24 hours and can either handle 2 GB of data from the database or actively perform tasks for two hours.

Cette page vous a-t-elle été utile ?

Envoyer un commentaire sur cette rubrique

Cette rubrique vous a-t-elle été utile ?

N'indiquez aucune information personnelle ou confidentielle.

Génération du lien…