Workspace ONE UEM Directory Integration Examples

Introduction Below are Omnissa Workspace ONE UEM Directory Integration examples for various directory types. Please note, always refer to VMware documentation as those are official. The below are examples for use as assistance in configuring your own environments.

WARNING: ALWAYS TEST IN NON-PRODUCTION ENVIRONMENTS - NEVER TEST IN PRODUCTION!

NOTES!

Common UEM Directory Service Configurations Server Settings

SettingAD - DirectoryAD - BasicOpenLDAPLotus DominoNovell e-DirectoryOracle (ODSEE)
Directory TypeActive DirectoryActive DirectoryOpenLDAPLotus DominoNovell e-DirectoryOther LDAP
Server[server_FQDN][server_FQDN][server_FQDN][server_IP][server_IP][server_FQDN]
Encryption Typenonenonenonenonenonenone
Port3893893893893891389
Protocol Version333333
Service Account Credentialsnononononono
Authentication TypeNTLMBasicBasicBasicBasicBasic
Username[domain][username][domain][username]cn=[container],dc=[domain],dc=[domain][username]CN=[username],OU=[org_unit],OU=[org_unit],O=[org]cn=[container]
Password[password][password][password][password][password][password]
Domain[domain][domain]nonenonenone[domain]

User Settings NOTE: Only modified sections are listed below. Blank entries do not mean delete the corresponding UEM setting. Rather it means the default settings should be left alone.

SettingAD - DirectoryAD - BasicOpenLDAPLotus DominoNovell e-DirectoryOracle (ODSEE)
Base DNDC=[domain],DC=[domain],DC=[domain]DC=[domain],DC=[domain]dc=[domain],dc=[domain]O=[Org]O=[Org]DC=[domain],DC=[domain]
User Object Class
User Search Filter(&(objectCategory=person)(sAMAccountName={EnrollmentUser}))(&(objectClass=person)(uid={EnrollmentUser}))(&(objectClass=person)(uid={EnrollmentUser}))(&(objectClass=person)(uid={EnrollmentUser}))(&(objectClass=person)(cn={EnrollmentUser}))
Object IdentifierobjectGUIDentryUUIDdominoUNIDGUIDnsuniqueid
UsernamesAMAccountNameuiduiduidcn
Member OfmemberOfgroupMembership
Full Name
Display Name
First Name
Middle Name
Last Name
Email Address
Email Username
Mobile Phone
Phone Number
Distinguished Name
User Principal Name
Department
Status
Lockout Time
Object ClassobjectClassobjectClassobjectClassobjectClass
Last Modified
Binding Attribute

Group Settings NOTE: Only modified sections are listed below. Blank entries do not mean delete the corresponding UEM setting. Rather it means the default settings should be left alone.

SettingActive Directory (both)Open LDAPLotus DominoNovell e-DirectoryOracle (ODSEE)
Base DNDC=[domain],DC=[domain],DC=[domain]dc=[domain],dc=[domain]O=[Org]O=[Org]
Group Object ClassgroupposixGroupdominogroupgroupofuniquenames
Organizational Unit Object Class
Group Search Filter(&(objectClass=posixGroup))Group Attribute("Member")
Membership AttributeRelative Distinguished Name
Search Members Using
Object IdentifierobjectGUIDentryUUIDdominoUNIDGUIDnsuniqueid
Namenamecncncncn
Membermember
Common Namecn
Member OfmemberOfmemberOfgroupmembership
Distinguished NamedistinguishedName
Group Object ClassobjectClassobjectClass
Organizational Unit
Organizational Unit Object Class

Thanks: Big thanks to VMware Engineering Austin Schoen and John Richards for providing this data.

#WS1 #UEM