KB – Working commands if no user is logged on

The scenario is not quite “modern” but from time to time we have devices where no user is logged on and you still want to manage it.

The list is based on HUB 21.02 and also tested on 21.05 – later versions might change the behaviour.

First of all: only commands that are assigned to the device and not to the user are covered. User commands are only process when the enrollment user is logged on.

Profiles

NameInstalled when no user is logged onComment
PasswordYesOnly if “Use Protection Agent” is disabled
Wi-FiYes
VPNYes
CredentialsYesAlso Certificate reporting works
RestrictionYes
Defender Exploit GuardYes
Data ProtectionYes
Windows HelloYes
FirewallYes
EncryptionNo
Anti-VirusYes
Windows UpdatesYes
ProxyYes
OEM UpdatesNo
SCEPYesAlso Certificate reporting works
Application ControlYes
Windows LicensingYes
BIOSNo
KioskYes
PersonalizationYes
Peer DistributionNo
Unified Write FilterYes
Profile installation overview

Custom Profiles

Custom Profiles are working as long as the target is set to OMA DM Client and not to Workspace ONE Intelligent HUB.
All profiles that are targeted to the HUB, are not working if no user is logged on.

Baselines

Baselines are only applied if a user is logged on.
Also Baseline compliance will only be reported if a user is logged on.

Applications

Application installation and also the installation status reporting works if no user is logged on.

Console Actions

Console Queries

Query typeWorks when no user is logged on
Device SecurityNo
Windows InformationYes
Health AttestationYes
Available OS UpdatesYes
Hub Check InNo
Certificate List SampleNo
Security InformationYes
InformationYes
App List Sample – HUBNo
App List Sample – OMA-DMNo
SensorNo
WorkflowNo
Time WindowNo
Device Queries overview

Console actions

Action nameWorks when no user is logged on
RebootYes
Enterprise WipeYes
Device WipeYes
Enterprise ResetYes
Request Device LogYes
additional console actions

Product Provisioning

Product Provisioning only works when a user is logged on.

Scripts

Scripts only work when a user is logged on.

Certificates

Since certificate deployment works, also the revocation and renewal works if no user is logged on.

Remote Assist

Currently Remote Assist does not work if no user is logged on.

Summary

Right now everything that is targeted to the Intelligent HUB is not working when no user is logged on – while everything that is targeted to the native OMA-DM client is working regardless of the user status.

Written by
+ posts

Empowering customers in client management since 2012.
Empowering customers in modern management since 2018.

Leave a Reply

Your email address will not be published. Required fields are marked *.

*
*

This site uses Akismet to reduce spam. Learn how your comment data is processed.

BCF Shop Theme By aThemeArt.
BACK TO TOP