Transcription

G E T S TAR T EDWorkspace ONE UnifiedEndpoint ManagementA Single Comprehensive Solutionto Manage and Secure All DevicesAcross All Platforms

IntroductionOut-of-the-Box OnboardingModern ManagementAcross All EndpointsApp Managementand Employee ExperienceIntelligence and AutomationZero Trust SecuritySave Time and Money with aWorld-Class Replacement forMultiple Limited IT ToolsIn today’s modern decentralized workforces, employees expect their companiesto offer technologies that enable them to work from anywhere, at any time, on anydevice. They expect the ability to choose the platform they’re most comfortablewith, whether that’s Windows 10, macOS, iOS, Android, ChromeOS, or a combinationof platforms on multiple devices. And when accessing work apps and data acrossall their devices, they expect to have a consistent and user-friendly experience.Companies that can meet these expectations have an advantage over thecompetition in recruiting and retaining top talent.1 But device and applicationdeployments continue to grow and become more complex, making it difficult forIT teams to provide a consistently great employee experience. The difficulty iscompounded when admins are forced to use a handful of expensive siloed toolsthat focus on managing discrete things rather than fully empowering employees.1. Randstad North America, Inc. “Hiring and Developing Digital Leaders.” 2018.WORKSPACE ONE UNIFIED ENDPOINT MANAGEMENT2

IntroductionOut-of-the-Box OnboardingModern ManagementAcross All EndpointsApp Managementand Employee ExperienceIntelligence and AutomationZero Trust SecurityVMware: A Global LeaderVMware Workspace ONE is an industry-leading cloud platform for modern management andunified endpoint management (UEM) that gives IT teams control over the highly diversified devicedeployments found in so many organizations today, while ensuring enterprise security outsidethe hardened perimeter. Workspace ONE UEM provides device lifecycle management acrossall platforms in a single comprehensive solution that empowers IT to Automate the onboarding process over the air Intelligently manage every device on every platform Flexibly support all use cases – BYOD, corporate-owned, frontline, or purpose-built Easily manage apps and provide a consistently positive self-service employee experience Make data-driven decisions and automate important repetitive processes Secure devices, apps, and data at rest and in transitVMware Workspace ONE UEM is a single solutionto manage all device types on all platforms in all usecases. It incorporates modern device management,application management, and security that’seffective outside the corporate perimeter.WORKSPACE ONE UNIFIED ENDPOINT MANAGEMENT3

IntroductionOut-of-the-Box OnboardingModern ManagementAcross All EndpointsApp Managementand Employee ExperienceIntelligence and AutomationZero Trust SecurityAutomated Out-of-the-Box DeviceOnboardingWorkspace ONE UEM enables device lifecycle management from onboarding to retirement.New devices register over the air (with zero touch from IT) during initial power-up with customizableconfiguration tools like Windows 10 Out-of-Box Enrollment, automated device enrollment withApple Business Manager, zero-touch enrollment of rugged devices, and more. Admins can easilyset up and customize the imageless configuration of work profiles such as email, VPN, Wi-Fi, apps,content, intranet sites, and other back-end resources. This gives employees access to email, apps,and data within minutes of device startup, all of which ensures immediate user productivity anda positive employee experience right from the start.VMwareWorkspace ONEWORKSPACE ONE UNIFIED ENDPOINT MANAGEMENT4

IntroductionOut-of-the-Box OnboardingModern ManagementAcross All EndpointsApp Managementand Employee ExperienceIntelligence and AutomationZero Trust SecurityModern Management AcrossAll EndpointsWorkspace ONE UEM manages and secures devices and apps, taking advantage of nativeMDM capabilities (iOS and Android) and mobile-cloud management efficiencies (Windows,Mac, and Chrome) to simplify management of all devices at scale with a single powerful solution.Supported Device TypesDesktops and laptopsSmart glassesTabletsVR headsetsSmartphonesRugged devicesSmart watchesMobile printersInteractive kiosksWORKSPACE ONE UNIFIED ENDPOINT MANAGEMENT5

IntroductionOut-of-the-Box OnboardingModern ManagementAcross All EndpointsApp Managementand Employee ExperienceIntelligence and AutomationZero Trust SecurityComprehensive Management ReachThis comprehensive reach ensures IT can manage all endpoints and keep them always up to dateon policies, patches, and the newest versions without wasting time and money supporting multiplesiloed management tools with limited capabilities.Supported Platforms**Relationships with OEMs ensure same-day support for new releases.With so many variables, complexity can become an issue for companies with global deploymentsacross regions, divisions, and departments. To ensure efficiency and ease of use even in the mostcomplicated scenarios, Workspace ONE UEM is built on a multitenant architecture that enablesflexible groupings and assignments so admins can customize the user experience for everystakeholder in the organization. And for the IT team, role-based contextual dashboards andaccess controls allow admins to focus only on the data specific to their job function.WORKSPACE ONE UNIFIED ENDPOINT MANAGEMENT6

IntroductionOut-of-the-Box OnboardingModern ManagementAcross All EndpointsApp Managementand Employee ExperienceIntelligence and AutomationZero Trust SecurityOne Solution for All Use CasesWorkspace ONE UEM uniquely supports any use case your organization may require. In BYO situations, you can easily deliver the level of privacy employees demand withtotal separation between work and personal resources. With corporate-owned assets, admins can use a stronger supervision mode withadvanced capabilities to exert greater control. Where multiple employees share a single device—such as shift schedules in a warehouseor retail store—multiuser mode has check-out and check-in functionality so you candeploy settings and apps specific to each user. For mobile and line-of-business ruggedized devices in the field, IT can easily provisionapps and files and remotely support users.Recognizing that privacy plays a critical role in modern management, we createdWorkspace ONE Privacy Guard, designed to manage privacy policies and communicatethem proactively to employees to ensure the best possible employee experienceregardless of the use case. Workspace ONE Privacy Guard also creates a new rolein the Workspace ONE console called “Privacy Officer,” which provides access to viewsystem settings that affect users and has full editing rights around privacy.WORKSPACE ONE UNIFIED ENDPOINT MANAGEMENT7

IntroductionOut-of-the-Box OnboardingModern ManagementAcross All EndpointsApp Managementand Employee ExperienceIntelligence and AutomationZero Trust SecurityApp Management and ConsistentEmployee ExperienceWorkspace ONE UEM helps employees work effectively on the go by providing a self-serviceunified app catalog that is consistent in look, feel, and function across all devices andplatforms. The app catalog optimizes productivity with unified one-touch access to all typesof apps—native, SaaS, virtual, and web. Integrated single sign-on (SSO) eliminates multiplelogins for better security, speed, and ease of use. Built-in per-app tunneling secures sessionseven with apps behind your firewall. This consistent, quick, and secure self-service accessto the apps employees need can improve their experience and reduce trouble ticketsand other routine IT support requests.And in cases where employees do need IT support—for any reason—there’sVMware Workspace ONE Assist. This support solution allows IT to connect remotelyto problem devices from the Workspace ONE console and either view or control themto troubleshoot and resolve issues in real time, minimizing downtime. To ease privacyconcerns, Workspace ONE Assist notifies employees when their screens are visible,and they can pause remote sessions.WORKSPACE ONE UNIFIED ENDPOINT MANAGEMENT8

IntroductionOut-of-the-Box OnboardingModern ManagementAcross All EndpointsApp Managementand Employee ExperienceIntelligence and AutomationZero Trust SecurityIntelligence to Enlighten and AutomateWith VMware Workspace ONE Intelligence, IT teams get real-time visibility into the entiretechnology environment in one place so they can quickly make informed, data-driven decisions.Dashboards can be customized in infinite ways to give admins the data that matters most, andanalytics help IT resolve issues that can negatively impact the overall user experience.But Workspace ONE Intelligence is not just an analytics engine. Using dynamic policy engines,admins can automate routine processes to minimize manual tasks for the IT team. Similarly, theycan empower employees with self-service capabilities to reduce support requests. For example,Workspace ONE Intelligence may predictively recommend support services based on datasuggesting a battery is about to fail. Or it may proactively take action, such as updating driversbased on data retrieved during a vulnerability scan or optimizing firmware settings to improveperformance and stability.WORKSPACE ONE UNIFIED ENDPOINT MANAGEMENT9

IntroductionOut-of-the-Box OnboardingModern ManagementAcross All EndpointsApp Managementand Employee ExperienceIntelligence and AutomationZero Trust SecuritySecurity from Conventional to Zero TrustWorkspace ONE UEM reinvents device hygiene by addressing security on multiple fronts andproviding rich management controls that allow admins to customize an array of security policiesand device posture checks. Built-in features for system settings, data protection, apps, device controls, and more can restrictactions like sharing sensitive data between apps and syncing with unknown devices to prevent dataleakage. Corporate-owned devices can be supervised for higher levels of control. Certificate lifecycle management is a service that can renew certificates automatically or manually. VMware Workspace ONE Tunnel encrypts traffic from individual applications to the back-endsystems they talk to with “least privilege access” through the VMware Unified Access Gateway ,which proxies and protects the application.Workspace ONE is certified by a numberof security standards organizations so thattightly regulated, security-sensitive companiesand institutions can use Workspace ONEUEM to manage their device deployments.Certifications for both on-premises andcloud architectures are kept up to date andprominently displayed on the VMware websites.WORKSPACE ONE UNIFIED ENDPOINT MANAGEMENT10

IntroductionOut-of-the-Box OnboardingModern ManagementAcross All EndpointsApp Managementand Employee ExperienceIntelligence and AutomationZero Trust SecurityZero Trust Conditional AccessVMware introduced the zero trust security model to accommodate the distinctive needs of themodern decentralized workforce. The VMware Workspace ONE Access identity layer queriesUEM to determine device compliance and can also pick up on user behavioral anomalies andother attributes to assess the security risk at the moment of login. For example, built-in intelligencewill find out if a device has been jailbroken or rooted, if the passcode is insufficient, or if therehas been an unusual spike in download activity, among many other things. And throughVMware Workspace ONE Trust Network integrations with the most popular endpoint protectionproviders like Carbon Black, Netskope, Lookout, and many others, Workspace ONE can enhanceits contextual risk assessment with real-time threat data.WORKSPACE ONE UNIFIED ENDPOINT MANAGEMENT11

IntroductionOut-of-the-Box OnboardingModern ManagementAcross All EndpointsApp Managementand Employee ExperienceZero Trust Conditional Access Takes ActionOnce the security risk is fully understood, Workspace ONE can take any of several actions.If everything checks out, the user can immediately be granted full access to corporate resources.Alternatively, multi-factor authentication can be enforced, or a device that’s out of compliancemay be automatically remediated. Or, if the risk is unacceptable, access may be denied completely.Lost or completely compromised devices can also be remotely wiped.Any EndpointAny AppEncryptionPasscodeCompromisedAES iExpirationRemote wipeBlacklistTLSDevice and alaccessSettingsTunnelCopy / pasteDevice-levelencryptionHardware ence and AutomationZero Trust SecurityBefore grantingaccess to resources,zero trust securitychecks devices andcontext in a multitudeof ways and can takeactions to remediatedeficiencies or evenwipe a device.Data and AppsOffice 365supportGeofencingWatermarkData backupsWORKSPACE ONE UNIFIED ENDPOINT MANAGEMENT12

As the industry’s most comprehensive modernmanagement solution that enables incomparable levelsof automation, self-service, trustworthy user privacy andintelligent security, VMware Workspace ONE UEM canmake any IT deployment easier and less expensive tomanage. And by focusing on the employee experience,IT departments can help their companies compete for—and retain—the best talent.Join us online:VMware, Inc. 3401 Hillview Avenue Palo Alto CA 94304 USA Tel 877-486-9273 Fax 650-427-5001 www.vmware.com Copyright 2020 VMware, Inc. All rights reserved.This product is protected by U.S. and international copyright and intellectual property laws. VMware products are covered by one or more patents listed at http://www.vmware.com/go/patents.VMware is a registered trademark or trademark of VMware, Inc. and its subsidiaries in the United States and other jurisdictions. All other marks and names mentioned herein may be trademarksof their respective companies. Item No: FY20-5777-WKSPONE-FOR-UEM-EBOOK-WEB-USLET-20200309 3/20

VMware Workspace ONE UEM is a single solution to manage all device types on all platforms in all use cases. It incorporates modern device management, application management, and security that’s effective outside the corporate perimeter. VMware: A Global Leader VMware Workspace ONE is an