Cisco Secure Access Help

PDF

Cisco Secure Access Help

Workspace ONE Registration

Want to summarize with AI?

Log in

Describes Workspace ONE Registration in Cisco Secure Access and explains Prerequisites and Anonymization. It summarizes the behavior, configuration context, and operational considerations presented throughout the topic.


By downloading an XML file from Secure Access, optionally updating it, and then pasting part of its contents into your Workspace ONE system, Workspace ONE is able to push configuration information to both the Cisco Security Connector (CSC) and Secure Access so that your iOS device is registered with Secure Access. The result is that your iOS device is protected by Secure Access.

For information about configuring Workspace ONE, see Workspace ONE's documentation.

Note

Version Information

Secure Access supports Workspace ONE Mobility Management On-Prem and Cloud versions 9.2 or higher. Workspace ONE was previously known as AirWatch.

Prerequisites

  • The Cisco Security Connector requirements
  • Workspace ONE Mobility Management On-Prem and Cloud versions 9.2 or higher.
  • You must first configure your Workspace ONE MDM system. Configure Workspace ONE as required so that it is able to push configuration information to both CSC and Secure Access. For information about configuring Workspace ONE, see Workspace ONE documentation. For support, contact Workspace ONE support.

Anonymization

Secure Access provides you with the option of anonymizing mobile devices for reporting and administration purposes. When you anonymize a mobile device, its label is hidden and replaced by your device's serial number. The label name is anonymized in both the Secure Access dashboard and in the CSC app UI. For information about how to anonymize your device, see Anonymize Devices.


Procedure

Note
You must log into your Secure Access dashboard as an administrator.

Procedure

  1. In Secure Access, navigate to Connect > End User Connectivity and click Internet Security. Click the iOS tab.


    iOS tab displaying the option to download the associated iOS configuration file for MDM configuration
  2. Under the MDM Managed Devices section, click Download.

  3. In the Configure Managed iOS Clients window, click Download.


    Configure iOS Managed Clients window displaying the option to download the Workspace ONE configuration file
  4. Add the administrator's email address to which the problem report will be sent when an issue occurs and click Download.

    This email address is where diagnostic reports are sent when a user clicks the I icon from within the iOS device. Once set, this email address is automatically added when managing an MDM.


    Download Workspace ONE Config section for adding the email address to receive diagnostic reports when an issue occurs
  5. In your new profile, applied for the CSC group, choose Custom Settings, and then Configure. Paste the XML from the Dashboard download (above) here. It should start and end with <dict> and </dict>.

    If successful, your mobile device registers with Secure Access and is listed at Resources > Roaming Devices > Mobile Operating Systems. CSC on your mobile device updates to connect to Secure Access so that your iOS device is protected by Secure Access.

What to do next

We recommend also deploying the Cisco Secure Access root certificate under the Certificates payload of your Workspace One profile. This certificate will allow HTTPS blocked and proxied pages to be certificate error-free.


Mobile Operating Systems page displaying the list of mobile devices registered with Secure Access

If you have anonymized your device (see Anonymize Devices), Secure Access hides the device's true label name by replacing it with the device's serial number. Existing active devices anonymize with 24 hours. New devices anonymize immediately.


Mobile Operating Systems tab displaying the device serial number

As no changes can be made in Secure Access to the actual provisioned device, these mobile devices are simply listed in Secure Access as identities; however, you can now use Secure Access to apply policies to these mobile device identities. For more information, see Apply a DNS Policy to Your Mobile Device.


Verify Secure Access on Your iOS Device

Procedure

  1. In the CSC app, tap the Status icon and confirm that it shows Protected by Secure Access.

  2. For protection details, tap Protected by Secure Access.


    Screen displaying instructions to verify Secure Access on an iOS device.