Skip to main content

August 11, 2026

Configure Apple iOS Profile in Workspace ONE UEM Using Workspace ONE UEM Certificate Authority

Create and deploy the Apple iOS device profile in Workspace ONE UEM to push the Identity Provider settings to the device. This profile contains the information necessary for the device to connect to the Omnissa Access Identity Provider and the certificate that the device uses to authenticate.

Prerequisites

  • Built-in Kerberos configured in Omnissa Access.
  • Omnissa Access KDC server root certificate file saved to a computer that can be accessed from the Workspace ONE UEM console.
  • Certificate enabled and downloaded from the Workspace ONE UEM console System > Enterprise Integration > Omnissa Access page.
  • List of URLs and application bundle IDs that use Built-in Kerberos authentication on iOS devices.

Procedure

  1. In the Workspace ONE UEM console, navigate to Devices > Profiles & Resources > Profile > Add Profile and select Apple IOS.

  2. Configure the profile’s General settings and enter the name of the device as iOSKerberos.

  3. In the left navigation pane, select SCEP > Configure to configure the credential.

    OptionDescription
    Credential SourceSelect AirWatch Certificate Authority from the drop-down menu.
    Certificate AuthoritySelect the AirWatch Certificate Authority from the drop-down menu.
    Certificate TemplateSelect Single Sign On to set the type of certificate that is issued by the AirWatch Certificate Authority.
  4. Click Credentials > Configure and create a second credential.

  5. In the Credential Source drop-down menu, select Upload.

  6. Enter the iOS Kerberos credential name.

  7. Click Upload to upload the Identity Manager KDC server root certificate that is downloaded from the Identity & Access Management > Manage > Identity Providers > Built-in Identity provider page.

  8. In the left navigation pane, select Single Sign-On.

  9. Enter the connection information.

    OptionDescription
    Account NameEnter Kerberos.
    Kerberos Principal NameClick + and select {EnrollmentUser}.
    Realm For tenant deployments in the cloud, enter the Omnissa Access realm name for your tenant. The text in this parameter must be capitalized. For example, WORKSPACEONEACCESS.COM.
    For on premises deployments, enter the realm name you used when you initialized KDC in the identity manager machine. For example, EXAMPLE.COM.
    Renewal Certificate On iOS 8 and later devices, select the certificate used to reauthenticate the user automatically without any need for user interaction when the user's single sign-on session expires.
    URL PrefixesEnter the URL prefixes that must match to use this account for Kerberos authentication over HTTP.
    For tenant deployments in the cloud, enter the Omnissa Access URL, for example, https://example.workspaceoneaccess.com.
    For on premises deployments, enter the Omnissa Access server URL as https://myco.example.com.
    ApplicationsEnter the list of application identities that are allowed to use this sign-in. To perform single sign-on using iOS built-in Safari browser, enter the first application bundle ID as com.apple.mobilesafari. To add additional applications, continue to enter bundle IDs or select bundle IDs from the drop-down menu. A bundle ID appears in the drop-down menu after an application is uploaded to the UEM console. For example, com.air-watch.secure.browser. The applications listed must support SAML authentication.
  10. Click Save & Publish.

Results

When the iOS profile is successfully pushed to users' devices, users can sign in to Omnissa Access using the Built-in Kerberos authentication method without entering their credentials.

What to do next

Assign the device profile to a smart group. Smart groups are customizable groups that determine which platforms, devices, and users receive an assigned application, book, compliance policy, device profile, or provision. See Assign a Workspace ONE UEM Device Profile to Smart Groups.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…