Shared Devices - Setting Up Check-In/Check-Out (Android)

Introduction

Using Multi-User Shared Devices with AirWatch on Android devices does not work the same way as with iOS devices. Android devices leverage the Secure Launcher in order to streamline the end-user experience while using Shared Devices. This gives IT Admins greater control over the profiles, applications, and content that end-users can access when the device is checked-out to them.

Check-In/Check-Out works differently in different versions of AirWatch - older versions i.e. 7.0 and lower have a slightly more complex configuration than 7.1 and higher, which is simplified and has less prerequisites. This article describes the prerequisites and configurations for both pre- and post-7.1 consoles.

 

Check-In/Check-Out in AirWatch 7.1 and Higher

Prerequisites

  • 2 Organization Groups, Parent and Child 

  • 1 Staging User Account 

  • 1 Secure Launcher profile configured at the Child level 

  • Note: For 7.3+ it is not a required prerequisite to create a separate parent and child Organization Group. The staging user and the check in/check out users can be created at the same OG with the Secure Launcher profile assigned with Smart Groups based on 'Select Devices or Users' to the check-in/check-out users. If you want to assign the Secure Launcher profile based on Smart Groups based on Organization Groups, it might be beneficial to create a parent OG and a child OG for easier organization.

Configuration

  • Create/use two organization groups, one for the Staging User and one for the Org Group where the Check-Out Secure Launcher profile will exist.

  • At the Parent level, set the Shared Device settings under All Settings > Devices & Users > General > Shared Device. 

  • Add a Staging User at the Parent staging Org Group. This user will be used to enroll the device that will be used as a shared device. 

  • Add a Secure Launcher profile to the Child Check-Out Org Group with the device settings/apps that the user should receive when they check the device out with their user ID. 

  • Create the user ID(s) for the users that will be used by the users checking out the device as follows

Summary: v7.1+

1. Create/use two Org Groups, one parent for the Staging User and one child for the Org Group where the Check-Out Secure Launcher profile will exist
2. “Shared” Parent Org Group

  • Devices & Users > General > Shared Device > Check: Prompt For Org Group

  • User Accounts > Create User > Enable Staging

  • Settings > Devices & Users > Android > Service Applications > Set Secure Launcher app version to 1.3+

3. “Check-Out” Child Org Group

  • Devices & Users > General > Shared Device > Check: Prompt For Org Group

  • User Accounts > Create User > Do Not Enable Staging

  • Profiles > Create Secure Launcher Profile

  • Settings > Devices & Users > Android > Service Applications > Set Secure Launcher app version to 1.3+

 

Process Flow: AirWatch v7.1+

800px-CICOFlow71.png 

 

Check-In/Check-Out in AirWatch 7.0 and Below

Prerequisites

  • 2 parallel Organization Groups, Check-Out and Check-In 

  • 1 Staging User Account 

  • 1 Secure Launcher profile configured at the Check-Out Org Group 

Configuration

  • Create/use two sibling org groups at the same level as follows, one for the Staging User and one for the Org Group where the Check-Out Secure Launcher profile will exist.

  • At the Check-In group, set the Staging settings under Settings > Devices & Users > General > Enrollment > Staging and set the Shared Device settings under Settings > Devices & Users > General > Shared Device.

  • At the Check-Out group, set the Staging settings under Settings > Devices & Users > General > Enrollment > Staging and set the Shared Device settings under Settings > Devices & Users > General > Shared Device.

  • Set Secure Launcher to always use v1.3+ under Settings > Devices & Users > Android > Service Applications. 

  • Add a Secure Launcher profile to the Check-Out Org Group with the device settings/apps that the user should receive when they check the device out with their user ID. 

  • Add a Staging User at the Check-In Org Group. This user will be used to enroll the device that will be used as a shared device. 

  • Create the user ID(s) for the users in the Check-Out Org Group that will be used by the users checking out the device.

 

Summary: v7.0 & Below

1. Create/use two parallel Org Groups, one for the Staging User and one for the Org Group where the Check-Out Secure Launcher profile will exist
2. “Check-In” Org Group

  • Devices & Users > General > Enrollment > Staging > Check: Multi-User

  • Devices & Users > General > Shared Device > Check: Shared Device Mode, Check: Prompt for Organization Group

  • User Accounts > Create User > Enable Staging > Check: Default Staging Settings

  • Settings > Devices & Users > Android > Service Applications > Set Secure Launcher app version to 1.3+

3. “Check-Out” Org Group

  • Devices & Users > General > Enrollment > Staging > Un-Check: Multi-User, Un-Check: Single-User

  • Devices & Users > General > Shared Device > Check: Shared Device Mode, Check: Prompt for Organization Group

  • User Accounts > Create User > Do Not Enable Staging

  • Settings > Devices & Users > Android > Service Applications > Set Secure Launcher app version to 1.3+

  • Profiles > Create Secure Launcher Profile

Process Flow: AirWatch v7.0 & Below

800px-Cicoprocessflow70.png

 

For additional information on Shared Devices, please refer to the Mobile Device Management Guide (Chapter 9). 

Have more questions? Submit a request

0 Comments

Article is closed for comments.