Introduction to Workspace ONE Express and Express+
With the release of Workspace ONE UEM 1907 AirWatch Express has been renamed to Workspace ONE Express and a few months later VMware announced Workspace ONE Express+ which is the result of a partnership with Dell.
Workspace ONE Express (WS1 Express) is a SaaS-only solution which is perfectly made for startups and the small- and mid-market in general. It is a simple mobile device management (MDM) solution designed to get your mobile devices up and running quickly without requiring extensive knowledge or an on-premises infrastructure.
The main features are the configuration of WiFi, apps, e-mail and security – basic MDM. WS1 Express requires a minimum of 10 devices and can be used for up to 500 devices, whereas the regular Workspace ONE UEM editions require at least 25 devices/users and have an unlimited licensing scale.
So, which edition is the right one for you? It depends on your types of mobile devices, use cases and requirements.
If you are a small company for example with 50 iOS and Android devices and would like to configure the native e-mail client, WiFi access, deploy some apps and set a passcode, then the Workspace ONE Express is the edition you are looking for.
If you are a company with around 250 users and would like to manage your macOS and Windows 10 clients, then we have to take a closer look what your requirements are.
IMPORTANT: WS1 Express has some policies for macOS, but Windows 10 can only be managed with Workspace ONE Express+ !
This means that you have to go for the Workspace ONE UEM Standard edition, if you need an acceptable feature set for these operating systems.
What is the big difference between Workspace ONE Express and Workspace ONE UEM Standard?
As just mentioned before, the biggest difference is the limited feature set of WS1 Express and that you cannot configure payloads, but have to use the “blueprint setup”.
Upon the initial login, a step-by-step wizard will help and guide you through the process of configuring WS1 and your devices.
During the creation of a blueprint you can select the policies for each operating system and you quickly realize that Workspace ONE Express is really offers basic MDM capabilities.
Apple DEP and Android Zero-Touch Enrollment are fully supported with the Express edition.
Can you start with Express and upgrade later to Standard or Advanced? Yes, you can! This is the great thing about Workspace ONE. If your company is small and would like to start small, then choose Express. If your company, the employee number and your requirements grow, upgrade to a regular Workspace ONE UEM Edition like Standard or Advanced. That’s the most recent Workspace ONE Edition Comparison Guide about Express, Express+ and Standard:
Workspace ONE Standard for macOS and Windows 10 Management
I doubt that a customer would start with Express if they have macOS and Windows clients. Even smaller companies have probably 80% of the same requirements when it comes to macOS and Windows 10 modern management.
But which features and configurations does VMware support with Workspace ONE Standard for Windows 10 management? Please find here an unofficial listing of the supported features:
- OOBE and Factory Provisioning (Device Onboarding)
- Co-Management with SCCM and Workspace ONE AirLift
- MDM profiles (passcode, WiFi, restrictions etc.)
- OS Updates via WSUS or Windows Updates for Business
- Enterprise Application Store with Workspace ONE Intelligent Hub
- Store Apps (Business and Public App Store) and MS Office 365 via CSP
- Device Restrictions
- Remote and Enterprise Wipe
- GPS Tracking
- DLP (Windows Information Protection, AppLocker)
- AV and Firewall (Windows Defender, 3rd party AV deployment, Windows Firewall)
- Conditional Access Management
- Enforce BitLocker Encryption
That is a lot you can do already with our Standard edition, right? What are the reasons that you would need the next higher Workspace ONE Advanced edition? Most probably if you need one or more features like:
- Application Delivery and Application Lifecycle (win32 – MSI, EXE, MST, MSP, PS1, BAT, ZIP)
- Peer-to-Peer Distribution (WS1 uses Windows BranchCache feature!)
- Advanced BitLocker Encryption Management (key rotation, maintenance windows etc.)
- Per-App VPN Tunneling with VMware Tunnel
What are the capabilities when it comes to macOS management? Well, also here, VMware’s approach is to have a modern imageless management over the air from the same management console. New devices can be enrolled with DEP and the Bootstrap Enrollment method, but existing users and devices have the choice of a web-based or staged enrollment.
Please find here an unofficial listing of the supported features and configuration for macOS payloads which are included in Workspace ONE Standard.
Via MDM interface
- Parental Controls
- Directory Binding
- Security & Privacy
- Disk Encryption
- Login Items
- Login Window
- Time Machine
- Content Filter
- Device & Enterprise Wipe
- Token Enrollment
- User Management (unlock user account, logout current user, delete user)
Via our Intelligent Hub (Agent)
- Enforce Encryption
- Firmware Password
- VMware Fusion
- Microsoft Outlook
- Custom Attributes
How can I deliver 3rd party apps like MS Office, Adobe Creative Suite etc.? VMware use the open source “Munki” framework for that.
Workspace ONE Assist (formerly known as Advanced Remote Management)
There is also an add-on called Workspace ONE Assist which enables you to remotely access and troubleshoot a device.
At the moment of writing WS1 Assist only supports iOS, Android, Windows Mobile and Windows 10 devices, but the support for macOS is coming until the end of this year (2019).
Via the WS1 Admin Console WS1 Assist let’s you to capture images and videos of the remote device and you can view and export audit logs of the sessions and even manage files and folders on the Windows 10 remote device for example.
If you would like to get a TestDrive access for Workspace ONE Express or Workspace ONE UEM, don’t hesitate to contact your partner or VMware account executive.
If you are a partner and would like to sell Workspace ONE, VMware has a MSP (Managed Service Provider) model for you! In this case contact your VCPP representative.
And I hope that you found valuable information here to better decide which Workspace ONE edition is the right one for you! 🙂