You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
- The Workspace ONE UEM [OAuth 2.0 Token URL for your region](https://docs.omnissa.com/bundle/WorkspaceONE-UEM-Console-BasicsVSaaS/page/UsingUEMFunctionalityWithRESTAPI.html#datacenter_and_token_urls_for_oauth_20_support)
55
55
- The OAuth client ID and secret you saved in Step 1
@@ -68,7 +68,7 @@ Within a few minutes after adding the connection, you should see all of your Wor
68
68
1. In Workspace One UEM, visit **Resources → Scripts**
69
69
2. Choose **Add** and then **Windows**
70
70
1. In the General tab, provide a name for the script, such as “Smallstep Agent Enrollment”
71
-
2. On the Details tab, ensure the **Language** is “Poweshell” and the **Execution Context & Privileges** is “System Context”
71
+
2. On the Details tab, ensure the **Language** is “Powershell” and the **Execution Context & Privileges** is “System Context”
72
72
3. Use the following snippet as the **Code**, making sure to replace `<team-id>` with the Team ID value you copied from the Smallstep UI earlier.
73
73
74
74
```xml
@@ -125,7 +125,7 @@ In this step, we’ll tie everything together by creating Windows policy to enro
125
125
126
126
#### Gather required details
127
127
128
-
1.You’ll need the following values from when your configuration your Workspace ONE connection:
128
+
You’ll need the following values from when you configured your Workspace ONE connection:
129
129
- SCEP URL
130
130
- SCEP Challenge URL
131
131
- Challenge Basic Authentication Username
@@ -143,11 +143,11 @@ For compatibility with Workspace ONE, Smallstep emulates the Microsoft ADCS’s
143
143
2. For Authority Type, choose `Microsoft ADCS`
144
144
3. For Protocol, choose `SCEP`
145
145
4. For Version, choose `NDES 2008/2012` ([NDES for SCEP](https://docs.omnissa.com/bundle/CertificateAuthorityIntegrationsV2410/page/NDESforSCEP.html))
146
-
5. Provide the SCEP URL from Step 1
146
+
5. Provide the SCEP URL
147
147
6. For Challenge Type, choose `Dynamic`
148
-
7. Provide the Challenge Username and Password from Step 1
148
+
7. Provide the Challenge Username and Password
149
149
8. No client certificate is needed
150
-
9. Provide the SCEP Challenge URL from Step 1
150
+
9. Provide the SCEP Challenge URL
151
151
10. Choose **Show Advanced Options**
152
152
- For SCEP Challenge Length, choose `32`
153
153
11. Choose **Test Connection** and wait for a ✅ success modal
@@ -176,11 +176,11 @@ A new modal screen will be presented with the empty Request Template configurati
176
176
3. Click Windows, and then select Windows again
177
177
4. Click Device Profile
178
178
5. Under General, Provide a name (e.g. “Smallstep Device Enrollment”)
179
-
1. Select the All Devices group in the Smart Groups dropdown
179
+
1. Select the All Devices group in the Smart Groups select list
180
180
2. Other options can be left as-is
181
181
3. Optionally, click the View Device Assignment button to see the devices to which the profile will be distributed
182
-
6.Add a Credential by clicking the **Configure** button , and set the following settings:
183
-
1. Credential Store: Defined Certificate Authority
182
+
6.Select the **Credential** payload type on the left and choose **Configure**. Set the following settings:
183
+
1. Credential Source: Defined Certificate Authority
184
184
2. Certificate Authority: Choose the CA connection you created earlier
185
185
3. The certificate template should be selected automatically. If not, select an appropriate one.
186
186
4. Key Location: TPM Required
@@ -190,4 +190,6 @@ A new modal screen will be presented with the empty Request Template configurati
190
190
191
191
### Confirmation
192
192
193
-
In the Smallstep UI, go to the device's profile page. In the **Device Registration** section, you'll see an **Enrolled At** timestamp.
193
+
In the Smallstep console, find your device. In the **Device Registration** section, you'll see an **Enrolled At** timestamp.
194
+
Workspace ONE's device UI also shows both the installed apps and issued certificates on the device.
0 commit comments