If you missed all of our announcements around this in the last few weeks, VMware Workspace ONE Intelligent Hub is the replacement of the VMware AirWatch Agent. The first phase of the rollout is to be an in-place upgrade for iOS and Android devices that are already enrolled into Workspace ONE UEM. By default, the changeover to Intelligent Hub on iOS and Android brought a new icon and branding change and didn’t require any re-enrollment of devices and functioned with the same capabilities as the Agent. We also flowed the look and feel changes through to macOS and Windows 10 device Agents too.

However, for the last 18 months or so we’ve had the Workspace ONE App. This App includes a heap of capabilities that the Agent didn’t have. It was the entry point and enrolment method for Adaptive Management and Unified Catalog and was a a key part of our Conditional Access strategy allowing different levels access to resources based on Ownership Type, Network Location, Management Status etc.

In the Release Announcements VMware also mentioned about unifying the capabilities of the AirWatch Agent and the Workspace ONE App into a single unified Intelligent Hub. If you go back to the first paragraph you would notice I said by default it only replaced the capabilities of the Agent. At VMworld Las Vegas we showed off the full  Intelligent Hub capabilities and with Workspace ONE UEM Console 1810 Release the full Workspace ONE Intelligent Hub capabilities are now GA on iOS and Android to all, with Windows 10 and macOS to be released at a later date.

I hadn’t set this up in my lab yet as I was on leave during the whole release period, and being a tinkerer I wanted to make sure I had the latest capabilities for some upcoming customer demos. The configuration wasn’t exactly straight forward (in all honesty I hadn’t read any documentation and hadn’t completed the training on what the current capabilities were, but shhh…) so I thought I’d just quickly write up the steps to bring all the Workspace ONE App capabilities into the Workspace ONE Intelligent Hub to unify the capabilities of all agents.

There are some fundamental pre-requisites to be able to use full Intelligent Hub Services which are:

  • A VMware Workspace ONE UEM ver. 1810+ environment
  • A VMware Identity Manager SaaS tenant

The assumption for what I’ll talk about below is that they are configured appropriately to allow sign-in with Active Directory credentials and integration between the two so that we can see a Unified App Catalog (SasS, Web, Native and Virtual Apps/Desktops). If you just wanted to enable Intelligent Hub and use the Native App Catalog inside the Intelligent Hub App, you don’t need to actually have Identity Manager configured at all. You just need to have a tenant and have admin credentials, then our API integrations from the UEM Console will push the required configuration to it.

It’s also important to note that in order to use the full Intelligent Hub capabilities you need a SaaS Identity Manager tenant. There are micro-services that are only available in SaaS environments and the capabilities will not function if you point your Workspace ONE UEM Console at an On-Premises environment.

Let’s get it configured.

Go to your Workspace ONE UEM Console and navigate to the Organisation Group that you want to configure Intelligent Hub at. Then, go to Groups & Settings and you’ll see a ‘Hub Configuration’ option.

When you open the the Hub Configuration Settings, you’ll be asked for a Tenant URL. This is your SaaS Identity Manager environment. 
Once you’ve entered your URL, click Launch and this will Save your URL and take you to the Configuration page.
If you haven’t integrated your Identity Manager tenant with Workspace ONE UEM for whatever reason, you’ll see the below notification. If you’ve already done this, it will skip past it. 
Clicking configure here will take you to the Enterprise Integration area to establish VMware Identity Manager trust. Click configure again here.
On the Connect to VMware Identity Manager Wizard, click Continue and on the Credentials page enter your tenant details again, along with your Identity Manager Admin Account and Password.
Click Save on this bad boy and we can continue.
Go back (if you aren’t already redirected) to Hub Configuration (see above) and if you go to the UEM integration button you’ll be able to see its now integrated. The customisation area is where we want to be, so click on customisation.
In here, you can see the options want to enable inside Hub.

These options will all appear as tabs in the Intelligent Hub App if enabled. 
This was the obvious stuff. Now let’s work through the options that we need to set to actually make it function as a replacement for Agent and the Workspace ONE App.
Click the bug ‘Back to Hub Configuration’ button, and then we need to go to:
Settings -> Apps -> Workspace ONE -> AirWatch Catalog -> General

In here we need to go to ‘Publishing’ and make sure ‘Hub Catalog’ is enabled. Do this for iOS and Android.

This will enable the App Catalog component in the Intelligent Hub App. If you don’t do this, you won’t see any Apps!
Now, let’s configure the Authentication settings for Hub. Go to
Settings -> Devices & Users -> General -> Enrollment
In the Authentication Tab, make sure ‘Source of Authentication for Intelligent Hub’ is set to Identity Manager.
We need to configure this so that when we authenticate in the Intelligent Hub App, we follow the Identity Manager authentication process. Without doing this, we will not see SaaS Apps!
The last thing we want to do is enable Adaptive Management. This functionality allows a user to login and use certain VMware Apps and allowed SaaS Apps without needing full device management. Then, when a user attempts to install an App that requires additional control or configuration it will step them through Workspace Services management.
Click on the Management Mode tab and set iOS to Enabled. Then, just select a Smart Group you want this enabled for. In my example, I enabled this for all users. You could use any of the criteria in the Smart Group settings to be as granular as you need.
Thats all the configuration done! We’ve now migrated all the capability from AirWatch Agent and Workspace ONE App into the Workspace ONE Intelligent Hub.