Learn about the Web app's payloads and how to configure them.
You can use Mobile Device Management (MDM) to enhance the performance of Workspace ONE Web by configuring profile payloads.
-
Navigate to Devices > Profiles > List View > Add and select Add Profile.
-
Select a platform for the profile that you want to deploy.
-
Configure General Settings to determine how the profile deploys, who receives it, and other settings.
-
Select and configure a Payload.
Platform based payloads
Payload Description iOS Android Windows 8 Restrictions Block the native browsers on devices using a restrictions payload to keep end users from using the native web instead of the Workspace ONE Web. ✓ ✓ ✓ Exchange ActiveSync Access corporate push-based email infrastructures and allows them to set the sync frequency for calendar and email systems. ✓ ✓ ✓ Credentials Configure this payload with digital certificates to protect your corporate email, Wi-Fi, VPN, and other corporate assets. ✓ ✓ ✓ SCEP With Credentials payload, you can also configure SCEP to handle digital certificates pushed to large-scale devices. ✓ Note: For step-by-step instructions on configuring a specific Payload for a particular platform, see the applicable Platform Guide at Omnissa Product Documentation.
-
Select Save & Publish.
Configure Workspace ONE Web Settings
To define any unique app behaviour, perform the following steps.
-
Navigate to Groups and Settings > All Settings > Apps > Workspace ONE Web.
-
Select whether to Inherit or Override the displayed settings.
- Inherit– Uses the settings of the current organization group's parent OG.
- Override– Modifes the current settings of OG directly.
-
Configure the relevant settings on the Web Settings tab.
Settings Description Application Profile Select an application profile to apply SDK functionality to your app. - Default – Allow applications to use the default security policies and settings defined under Apps and Group & Settings > All Settings > Apps > Settings and Policies.
- Custom – Override default settings and apply custom profiles. : Custom profiles also use the same secutity policies and settings as defines under Group & Settings > All Settings > Apps > Settings and Policies.
iOS SDK Profile Select the appropriate profile from the drop-down menu that appears when you enable a Custom Application Profile to override default SDK settings. Android SDK Profile Select the appropriate profile from the drop-down menu that appears when you enable a Custom Application Profile to override default SDK settings. General Accept Cookies Enable to accept cookies from websites viewed in the Workspace ONE Web. Clear Cookies Upon Exit Enable to clear cookies when the app fully closes. Clear Cookies and History if Idle Enable to clear cookies and history if the web is idle for x minutes. Clear Cookies and History if Idle for (mins) Set the idle time in minutes to a value between 0. 5 and 60 to ensure cookies and history are cleared. Remember History Enable to keep track of the sites visited by the user. Remember History From Select the length of time from which the history needs to be remembered. Caching Enable to enhance web performance and reduce perceived lag time. Deactivate to protect browsing data on compromised devices. Allow Connection to Untrusted Sites Deactivate if navigating to untrusted sites is a security concern for your organization. Enable to give end users maximum navigation flexibility and ease of use. Sync User Bookmarks Enable this to sync bookmarks across various devices of the same user. Default View Mode Set the default view mode for Workspace ONE Web. Select Desktop to set desktop as the default view mode. When selected, the Workspace ONE Web renders the web pages in desktop mode if the websites supports the mode. Mode Kiosk Mode Enable for Workspace ONE Web to function in Kiosk Mode. Kiosk Mode removes the navigation bar and limits browsing to the homepage and its available links. Return Home After Inactivity Direct the Workspace ONE Web back to the home page after a period of Inactivity (min). The values can be greater than or equal to 0. 5 minutes. Clear Cookies and History with Home Prevent users from accessing the previous user's secure information after they finish using the Workspace ONE Web. Enable Multiple Tabs Support You can have multiple tabs opened within kiosk mode. Home Page URL Define the URL displayed when the Web starts. Leave this field blank to display a default view with bookmarks and recently visited websites. Selection Mode Allow to limit browsing to domains that are listed in the Allowed Site URLs field. Deny to allow browsing to all sites except those denied in the Denied Site URLs field. Allowed/Denied Site URLs Utilize the following recommendations for allowed and denied domains allowed domains and denied domains. - Define domain names without including full URLs. The Workspace ONE Web filters by domain only, not by folder or page level.
- Separate domains with a space, comma, or a new line.
- Define wildcards as part of the domains; listing items from most general to specific. Example: *google. com is more general than http://yahoo.com.
Entering *. google. com allowlists <text>. google. com, but it does not allow access to http://google. com. - Leave out the scheme (http:// or https://) to test the domain for both schemes. Include the scheme to limit testing to the specified scheme.
- You can enter Port value separately. Restricted URL can contain the complete path, for example, http:// google. com:9191.
Allow IP Browsing Select to Allow IP addresses for browsing. A user can navigate to a allowed IP address even if the actual domain for the IP address was included in the Denied Site URL listing. Allowed IP Addresses Allowed IP addresses using the following recommendations: - Enter values in IPv4 formatting with four octets each separated by a period.
- Enter wildcards to allowed octets. Adding an entry that includes a * in each octet allows browsing to any IP address.
Terms of Use Required Terms of Use Select the appropriate agreement from the drop-down menu. For all internal Workspace ONE UEM apps, including the Workspace ONE Web, you can implement a single Terms of Use Agreement for end users to accept. This agreement applies to all Workspace ONE UEM internal applications, and eliminates the need for end users to accept the same agreement multiple times, across apps. You can configure and manage your Terms of Use Agreements by navigating to Groups and Settings > All Settings > System > Terms of Use. For more information, please see the Workspace ONE Mobile Device Management Guide. Note: Clear Cookies and History if idle is not supported in Kiosk mode. You must enable Return Home After Inactivity and Clear Cookies and History with Home under kiosk settings to achieve this functionality.
-
Select the Bookmarks tab and provide the following information to define and push a list of bookmarks to Workspace ONE Web.
Settings Description Name Provide text in this field to display as the friendly name. Leave this field blank to display the URL as the bookmark name. URL Provide the bookmark URL. Add Bookmark Select to add additional bookmarks. Note: Do not configure any settings on the Notifications tab unless a Workspace ONE UEM representative provided you with configuration instructions.
-
Select Save.
Configure App Suite SDK
Learn about the custom and the default SDK configurations.
When you configure your application, you select a custom or a default application profile. This action applies an SDK profile to the application, giving deployed Workspace ONE UEM applications additional features.
To ensure that your application configuration runs smoothly, it is helpful to:
- Know the difference between a Custom and Default SDK profile.
- Determine if a Custom or a Default SDK profile is more appropriate for your application.
- Ensure you have configured the SDK profile type that you want to apply.
You can define SDK profiles using two different profile types - Default or a Custom SDK application profile. Use the following chart to determine if you want to apply a default or custom SDK profile to your application, and to direct you to the configuration instructions for the profile you use.
Differentiate Default and Custom SDK Profiles
| Items | Default | Custom |
|---|---|---|
| Implementation | Share SDK profile settings across all applications set up at a particular organization group (OG) or below. | Apply SDK profile settings to a specific application, and override the Default Settings SDK profiles. |
| Advantage | Provides a single point of configuration for all your apps in a particular OG and its child groups. | Offers granular control for specific applications and overrides the Default Settings SDK profiles. |
| Configure | Groups & Settings > All Settings > Apps > Settings and Policies > Security Policies | Resources > Profiles & Baselines > SDK Profiles |
You can learn more about custom SDK profile settings in the Workspace ONE UEM Mobile Application Management Guide at Omnissa Product Documentation.
Note: Configuring client certificates to authenticate users is a part of the SDK security settings. For more information about how to configure the client certificate for the Web application, see the SDK and Managing Applications admin guide at Omnissa Product Documentation.
Custom SDK Profile Settings
Workspace ONE UEM recommends using default settings for ease of maintenance and a consistent end user experience between Workspace ONE UEM and wrapped apps. However, Custom SDK Settings are available to address cases where a single app needs to exhibit unique behaviors that differ from the rest of the app suite.
Enable Custom Applications Settings to override default SDK settings, and configure unique behaviors that only apply to a single app.
Custom SDK Configurations
| Settings | Description |
|---|---|
| Authentication Method | Defaults to Single Sign-On. Ensure you require MDM enrollment so that Single Sign-On can function properly. |
| iOS Profile | Select a custom-created SDK profile from the drop-down list the settings profile for iOS devices. |
| Android Profile | Select a custom-created SDK profile from the drop-down list the settings profile for Android devices. |
| Use Legacy Settings and Policies | Only enable legacy settings if directed to do so by a Workspace ONE UEM representative. Legacy settings do not leverage Shared SDK profile settings and should only be implemented in certain edge cases. |
| Default Authentication Method | Select the authentication method for the applications. |
| Keep me signed in | Enable to allow end users to remain signed in between uses. |
| Maximum Number of Failed Attempt | Set the number of passcode entry attempts allowed before all data in the Omnissa Workspace ONE Content is wiped from a device and the device is enterprise wiped. |
| Authentication Grace Period (min) | Enter the time (in minutes) after closing the Workspace ONE Content before reopening the Workspace ONE Content will require users to enter credentials again. |
| Prevent Compromised Devices | Enable to prevent compromised devices from accessing Workspace ONE Content. |
| Enable Offline Login Compliance | Enable to allow offline login compliance. |
| Maximum Number of Offline Logins | Enter the number of offline logins allowed before you have to go online. |
SDK Authentication
Enabling or deactivating SSO determines the number of app sessions established, impacting the number of authentication prompts end users receive.
Expected Behaviors for SDK Authentication
| Authentication Type | SSO | Sessions | Credentials | Expected Behavior |
|---|---|---|---|---|
| Deactivated | Enabled | Single | Enrollment Credentials | Open apps without prompting end users to enter credentials. |
| Passcode | Enabled | Single | Passcode | Prompts at first launch of first app, establishing a single app session. The next authentication prompt occurs after the session times out. |
| Username and Password | Enabled | Single | Enrollment Credentials | Prompts at first launch of first app, establishing a single app session. The next authentication prompt occurs after the session times out. |
| Passcode | Deactivate | Per App | Passcode | Prompts on a per app basis, establishing individual app sessions. Note that each app may have a unique passcode. The next authentication prompt occurs when launching a new app, or an individual app session times out. |
| Username and Password | Deactivate | Per App | Enrollment Credentials | Prompts on a per app basis, establishing individual app sessions. The next authentication prompt occurs when launching a new app, or an individual app session times out. |
Add Web Links on Workspace ONE Web
Web link applications in Workspace ONE Web provide a powerful way to deliver URL shortcuts to end users on their device's home screen for easy access. By leveraging custom schemas (awb://, awbs://, awbf://, awbfs://), administrators can control exactly how web links open, ensuring security and best user experience.
When configuring the URL field on Web Links window, you can use custom schemas to control how the link opens. These schemas enable specific behaviors for opening web content through Workspace ONE Web browser.
For instructions to add Web Links, see Add Web Links Applications from the Workspace ONE UEM console.
Available Custom Schema Prefixes
| Schema Prefix | Protocol | Description |
|---|---|---|
| awb:// | HTTP | Opens the URL using HTTP protocol in a standard browser window |
| awbs:// | HTTPS | Opens the URL using HTTPS protocol in a standard browser window |
| awbf:// | HTTP | Opens the URL using HTTP protocol in fullscreen mode |
| awbfs:// | HTTPS | Opens the URL using HTTPS protocol in fullscreen mode |
URL Configuration - Example
Standard HTTPS Connection - awbs://example.company.com/portal opens https://example.company.com/portal on Web app.
이 페이지가 도움이 되었나요?