Customize the behavior of Workspace ONE Web by applying different key policies to meet the specifications of your organization.
To configure Workspace ONE Web with the configuration keys, you must follow these steps:
- Log in to the Workspace ONE UEM console.
- Go to Groups & Settings > All Settings > Apps > Settings and Policies > Settings.
- Add the configuration keys to the Custom Settings field.

General Policies
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
| Boolean | true or false (default) |
(Available for Android only) If the value is true, the user Hub string is deactivated. However, this also disables the ability to switch between desktop mode and mobile mode. If the value is false, the user Hub string is enabled and also enables the ability to switch between desktop mode and mobile mode. |
| Boolean | true or false (default) |
(Available for iOS only) If the value is true, Workspace ONE Web does not auto-close the tab that runs an external application. If the value is false, Workspace ONE Web auto-closes the tab that runs an external application. |
| Boolean | true or false (default) |
By default, the Webclips are shown in the Workspace ONE Web Bookmarks. If the value is set to true, the Webclips do not appear in the Workspace ONE Web Bookmarks.
You can push webclips with awbf:// and awbfs:// protocols to open in full screen mode. |
| Boolean | true or false (default) |
(Available for Android only) When set to true, Workspace ONE Web deactivates the open in the new tab and add to bookmarks dialog (or prompt) box for links that are long pressed. |
Admin Policies for Privacy and Data Collection
Use the configuration keys in the UEM console to perform additional privacy disclosure and data collection practices. End users who are upgrading or beginning to use the latest version (from v6.14 onwards on iOS and Android platform) are presented with new privacy prompt screen upon the start of the application.
The privacy prompt screen lets the user know the following device information is fetched by the application:
-
Data collected by the app – Provides a summary of data that is collected and processed by the application. Some of this data are visible to administrators of the Workspace ONE UEM administration console.
-
Device Permissions – Provides a summary of device permissions requested for the app to enable product features and functionality, such as push notifications to the device.
-
Company's privacy policy – By default, a message is shown to the user to contact their employer for more information. Users are recommended to configure their privacy policy URL in the UEM console. After configured, the users can open the employer’s privacy policy within the application.
To enable privacy and data collection policies, enter the configuration key and the corresponding value in Custom Settings under Groups & Settings > All Settings > Apps > Settings and Policies > Settings.
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
| Integer | 0 or 1 (default) |
Feature analytics data collection admin policy that controls whether the end users see the Data Sharing opt-in during configuration of the Workspace ONE Web.
When set to 0, the data sharing screen is forced off to the user. When set to 1, the data sharing screen is displayed to the user.
Note: Feature analytics data is collected to improve existing product features and invent new ones to make users even more productive. |
| Boolean | true or false (default) | Crash reporting data collection admin policy that controls the application reporting diagnostic data, which can be used to troubleshoot crash issues and provide support. If true, crash reports are reported back to Web. If false, crash reports are not reported back to Web. It Impacts the efficiency in investigating and resolving any issues with the application. |
| String |
"https://www.url.com" |
Provide the company or customer privacy policy URL that the users can view a specific privacy disclosure web page directly with the Workspace ONE Web.
Note: This policy overrides the default company privacy policy URL. |
Normal Browsing Mode
Disable QR Code on the Browser
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
| Boolean | true or false (default) |
The QR Code is enabled by default. When set to true, the QR Code is disabled on the browser.
|
Configure Web Clips in Full Screen Mode
By default, web clips are displayed in normal mode in the Workspace ONE Web Bookmarks. If you want your user to view the web clips in full screen mode, set the URL prefix as awbf:// and awbfs://. For more information on the web clip configuration process, refer to the Platform Guide.
If you want to enforce full screen mode, you can configure Workspace ONE Web using the following configuration key. This key provides a more secure and restricted experience for your end users when using web clips in full screen mode. If configured, this key:
- Opens webclips in full screen mode without allowing users to exit.
- Hides the URL address bar, navigation controls, and other Web features to minimize user distractions.
- Prevents sensitive URLs from being exposed to end users for malicious or accidental misuse.
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
| Boolean | true or false (default) |
If the value is set to true, webclips that use awbfs are opened in full screen mode, which the user cannot exit. Such URLs are not added to bookmarks or history.
When the value is set to false, webclips that use awbfs are opened in full screen mode and can be exited by the user. These URLs are added to bookmarks and history. |
Kiosk Browsing Mode
Single tab Kiosk Browsing Mode
Customize the Display of the URL Address Bar
Hide the URL address bar in single-tab Kiosk mode to reduce user distraction. To do so, you must use the following key-value pair.
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
| Boolean | true or false (default) | When the key value is set to true, the URL bar is hidden in the Single tab Kiosk mode. When the value is set to false, the URL address bar is visible. |
Hide Navigation Controls
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
| Boolean | true or false (default) | The navigation control bar is hidden by default. |
Multi tab Kiosk Browsing Mode
Editing URL in Multi tab Kiosk Mode
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
| Boolean | true or false (default) |
When set to true, the URL bar is editable. |
Single and Multi tab Kiosk Browsing Mode
-
Disable Long Press
Configuration Key Value Type Configuration Value Description DisableLongPressInKioskBoolean trueorfalse(default)When set to true, Workspace ONE Web disables the long-press option to prevent unintended actions on websites. Applies only in kiosk mode. -
Enabling Print Option in Kiosk Mode
Configuration Key Value Type Configuration Value Description BrowserAllowPrintInKioskBoolean trueorfalse(default)Set to trueto enable printing in kiosk mode.
Note: Printing must also be allowed in the SDK DLP settings. -
Scan URL QR Codes in Kiosk Mode
Configuration Key Value Type Configuration Value Description EnableQRInKioskModeBoolean trueorfalse(default)Displays a QR scanner in the URL address bar when set to true.
Note: Applies only whenEditURLBarInKioskModeis set totrue. -
Clear Cache, Cookies, and History when device is in Kiosk Mode(iOS only)
Configuration Key Value Type Configuration Value Description ClearDataInKioskModeBoolean trueorfalse(default)When this custom setting is set to true, user can select the clear cache, cookies and history action from Settings in single and multi tab kiosk mode.
Display Privacy Dialog Box
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
|
Integer | 0 or 1 (default) | When the key is set to 1, Web app displays a privacy notice to the users about the data that is collected and the permissions that are being used by the app. |
Enabling SDK logging on iOS Web
To enable the SDK logging on Web, use the following configuration key. This key provides a fallback if you want to log browser logs in the SDK logging framework.
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
| Boolean | true or false (default) | Set this value to true to log browser logs in the SDK logging framework. |
Redirect mailto: Links to your Favorite Email Clients
By default, Workspace ONE Web opens mailto: links in Workspace ONE Boxer or in the iOS native email application when the Data Loss Prevention (DLP) option is disabled. As an admin, you can change this behavior by configuring Web to open mailto: links in any configured third-party email client.
To apply the mailto: setting in Workspace ONE Web, you must add the following configuration in the Custom Settings. Before you configure, make sure that you have deactivated the Enable Composing Email option under the SDK DLP setting.
| Configuration Key | Description |
|---|---|
|
Add this configuration key to open mailto: links in any configured email client.
You must specify the target apps scheme as a value for the source scheme, and the application's name as a value for the appName.
Note: Make sure that the email application configured by you must be installed on the iOS device. |
Enable Web Fullscreen mode
With Workspace ONE Web, users can browse content in the Fullscreen viewing mode. Fullscreen mode hides the URL and the navigation bar and displays only the content. Users can exit the fullscreen mode either by a long press on the screen or stop and relaunch the Web application.
By default, the fullscreen mode is enabled, and admin can deactivate this mode using the following KVP:
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
| Boolean | true or false (default) | Set the value to true to deactivate the full screen mode view. |
SCEP Integrated Authentication
Use the integrated authentication with an authentication type set to SCEP certificates in the UEM console by configuring the following key value pairs.
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
| Integer | Min and max values | Provide the time duration after which the SCEP pending retry will time out. |
| Integer | Min and max values | Provide the maximum retry count for the SCEP certificate to update on the device. |
View Downloaded Files in Workspace ONE Content for Android Devices
To view the downloaded files in the Workspace ONE Content app, use this configuration key in the UEM console. Users must install and configure the Content application on their device to view the supported files. For more information about files supported by the Content application, see the Matrix of Supported File Type by Platform topic in the Mobile Content Management documentation.
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
| Boolean | true or false (default) | Set the key value to true, to automatically view the downloaded files in the Workspace ONE Content application. |
Add a Custom String to the Browser User Agent
As an admin, you can pass an identifier to Workspace ONE Web that appends to the user agent string. This identifier is an optional parameter and applies to both mobile and desktop user agent. It does not support double byte characters and rich text.
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
| String |
"This is the appended string"
Example: | Set the string to append at the end of the user agent. |
Configure Workspace ONE Web to Use a PAC File
You can configure Workspace ONE Web to use the Proxy Auto-Configuration (PAC) file to allow your web traffic to pass through the proxy server. A PAC file is a text file that directs a browser to a proxy server before it reaches the destination server.
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
| String | URL of the PAC file. | Set the PAC URL. |
| Integer | 1 or 2 |
Set the value to 1 to use a PAC file for URLs that are not tunneled through Workspace ONE Tunnel. For example:
Set the value to 2 to use a PAC file for URLs that are also tunneled through the Workspace ONE Tunnel. For example: |
WebRTC Support in Workspace ONE Web (Android only)
With WebRTC, websites can easily access the camera and microphone in Workspace ONE Web for Web Real-Time Communication. To enable this feature, you must configure the Web application with the following KVP.
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
| Boolean | true (default) or false |
When the value is set to true, WebRTC is enabled on Workspace ONE Web.
This feature is supported only in Android 7 and higher versions. |
Workspace ONE Web lets the end users remember their choice to allow or block camera or microphone settings for individual websites by selecting Remember my choice setting. By selecting Remember my choice setting, they can conveniently load the websites next time without the pop-up dialog box asking for the same permissions again.
Configure iOS Web to Support Shortened URLs
Use the shortened or non-FQDN (Fully qualified domain name) URLs to access the websites of your organization by adding the following Key-value pair. This Key eliminates the need to add HTTP or HTTPs to the URLs.
| Configuration Key | Description |
|---|---|
| This KVP acts as a URL prefix. Any URL whose prefix matches this value is a non-FQDN URL. For example, wmlink treats wmlink, wmlink-clarity, wmlink-byod, wmlink-internal as non-FQDN URLs. |
Set Up a Retention Period for Downloaded Files
Use the following key to configure a retention period for the downloaded files in Workspace ONE Web.
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
| String | Always (default) Day Week Month Always |
This key removes the downloaded files from Web after the configured retention period expires.
Note: When configured, this key deletes all existing downloaded files if the time since the files where downloaded exceeds the retention period. |
Automatically Open Downloaded Files (Android only)
Use the following key to configure Workspace ONE Web for Android to open the downloaded files automatically in a default application.
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
| Boolean | true (default) or false | Set the value to true to open the downloaded files automatically in a default application. |
Support for Android App Links
Configure Workspace ONE Web for Android to launch an intended application from an app link. You can use the following configuration key to enable this behavior on Web.
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
| Boolean | true or false (default) | Set the value to true to allow an app link to open in the intended app. |
Block Popup Windows in Web
Configure Workspace ONE Web to prevent JavaScripts from opening popup windows without any user interaction.
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
| Boolean | true or false (default) |
Set the value to true to prevent JavaScripts to open popups without any user interaction.
Note: In iOS Web, this key is applicable only in non-proxy scenario (WKWebView). |
Enable WebSDK (iOS only)
Use the following key value pair to enable WebSDK in Workpsace ONE Web for iOS.
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
| Boolean | true or false (default) |
If the key value is set to true, Web continues to use its own webviews for rendering purposes. And If the value is set to false, Web uses the webviews provided by WebSDK to render websites. |
Enable Secure Browsing
Configure Workspace ONE Web to provide secure browsing experience to the the end users. Use the following key value pair to use HTTPS protocol to load all URLs in Workpsace ONE Web for iOS and android.
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
| Boolean | true or false (default) |
If the key value is set to true, Web uses HTTPS protocol to load all URLs. And If the value is set to false, the Web honours the protocol provided by the user while entering the URL. |
Activate Watermark Support
You can configure Workspace ONE Web to show a custom watermark text on the websites accessed through the app. This feature protects any sensitive information from being exposed through websites browsed using Web. The bookmark is preserved even if the user tries to print a webage using the print option available in the app. To configure, you must:
- Navigate to Groups and Settings > Settings > Apps > Settings and Policies > Security Policies.
- Enable Data Loss Prevention.
- Select Yes.
- Enter the text you want to show up as a watermark in the Overlay Text field.
- Click Save.
Restrict file download/upload based on file type
You can restrict users from downloading or uploading specific files in Workspace ONE Web based on the type of file being downloaded or uploaded. To configure these restrictions, you must add the following SDK custom setting to the Workspace ONE UEM console:
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
| String |
| The download restrictions imposed by the configuration apply to all websites open in Web. When the download restriction is configured and user tries to download a restricted file, the following message appears in an alert dialogue window: "Download of this file type is disabled as part of your security policies. Please contact your IT administrator." |
| String |
| (Android only) The upload restrictions imposed by the configuration apply to all websites open in Web. When the upload restriction is configured and user tries to upload a restricted file, the following message appears in an alert dialogue window: "Upload of this file type is disabled as part of your security policies. Please contact your IT administrator." |
Deactivate SDK Blocker Screen (iOS Only)
You can use this following KVP to deactivate the SDK blocker screen security.
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
| Boolean | true or false (default) |
When set to true, the SDK security screen is not displayed when the Web app is inactive. If set to false, the SDK security screen is displayed when the Web app is inactive. |
Add a Search Engine
Use the following KVP to offer users additional options for search engines in addition to the default ones.
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
| String | name search_url | Add the name and url of the search engine. It enables you to configure additional search engines in the Web. Users can choose to use the configured search engines from the existing list of search engines. |
Resign Keyboard On Splash Screen
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
| Boolean | true or false (default) | Resign Keyboard On Splash Screen For UIWebview. |
Support WKWebView for In-App Tunnel
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
| Boolean | true or false (default) |
Starting with iOS 17+, this feature leverages Apple's new Network Relay capabilities. For iOS 15 and 16, the Web app will continue to use the legacy UIWebView for tunneling. Note: This configuration is only applicable for Omnissa Tunnel and not applicable for Per-App Tunnel. |
Manage Keyboard with Auto Focus Attribute
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
| Boolean | true or false (default) | Display keyboard when auto focus for text field is enabled. If the key is set to false, keyboard will not pop-up when the focus is on any text box during page load. |
Viewing site cache and cookies storage (iOS only)
You can restrict users from viewing and managing cache and cookies by using the following key.
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
| Boolean | true or false (default) |
When the key is set to true, does not allow users to clear cache and cookies from the browsing history.
By default, you can clear cache and cookies. |
Sync the Web page using Pull to Refresh
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
| Boolean | true (default) or false |
When the key is set to false, pull to refresh action is disabled on webpage.
|
Allow Widgets Popup
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
|
Boolean | true (default) or false | When the key is set to false, the Widget popup does not appear on the new tab. |
Show Notification Prompt Once (Android Only)
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
|
Boolean | true or false (default) | When the key is set to true, the notifications prompt is displayed only once. |
Support Per-Site Management of Camera, Microphone, and Location Permissions (iOS Only)
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
|
Boolean | true or false (default) | When the key is set to true, website specific permissions (camera, microphone and location permissions) are given. |
Custom tab support for Third Party apps using NO_HISTORY intent flag (Android Only)
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
|
Boolean | true or false (default) | When the key is set to true, the Web App will forward intent extras to the splash activity if a third-party app uses custom tabs with the NO_HISTORY intent flag. |
Send GPS data from Workspace ONE Web to Workspace ONE UEM (iOS Only)
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
|
Boolean | true or false (default) | When the key is set to true, GPS data is sent from Web to Workspace ONE UEM. |
Suppress alert from websites containing untrusted resource
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
|
Boolean | true or false (default) | When the key is set to true, the Untrusted Site Warning is not displayed during SSL trust‑validation failures. |
Allow writing tools on apps (iOS Only)
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
|
Boolean | true(default) or false | When the key is set to false, AI tools cannot be used on the Hub and Productivity Apps. |
Microsoft Conditional Access authentication (Android Only)
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
|
NA | NA | If you have configured Microsoft Conditional Access authentication, add this key to identify Microsoft Conditional Access on Web app. Note: When using Microsoft Conditional Access with Entra, browser access must be enabled for Workspace ONE Web. For more information, see the Microsoft article Browser access guidance for third-party mobile device management providers - Microsoft Entra ID. |
Web page summarization for Apple Intelligence devices (iOS Only)
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
|
Boolean | true or false(default) | If the device is configured with Apple Intelligence, add this key to allow web page summarization. By default, this key is set to false. |
Enable Email logging
| Configuration Key | Value Type | Configuration Value | Description |
|---|---|---|---|
disableEmailLogging | Boolean | true or false (default) | When set to true, Email logs option will not be available on the Support screen. |
Was deze pagina nuttig?