Skip to content

Wireless guide: iOS and Android with Workspace ONE UEM (SCEP) - #564

Merged
joshdrake merged 6 commits into
mainfrom
docs/ws1-mobile-wifi
Oct 5, 2026
Merged

joshdrake merged 6 commits into
mainfrom
docs/ws1-mobile-wifi

Conversation

@joshdrake

@joshdrake joshdrake commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Describe your changes:

Adds an iOS and Android with Workspace ONE UEM (SCEP) section to the MDM-managed clients part of the Wireless Networks guide. Workspace ONE issues a client certificate from Smallstep through the integration's dynamic SCEP challenge, trusts the RADIUS server's CA, and configures an EAP-TLS Wi-Fi network. The Smallstep Agent isn't required.

The section covers:

  • Prerequisites per platform. Android devices must be managed through Android Enterprise, not legacy device admin.
  • Trusting the integration's issuing authority on the RADIUS server, and finding that authority's root in the Smallstep console.
  • The Workspace ONE CA resource and certificate request template.
  • The iOS profile: SCEP, a Credentials payload for the RADIUS server CA, and Wi-Fi.
  • The Android profile: Credentials for the client certificate and the RADIUS server CA, and Wi-Fi with a trusted server domain.
  • Verification and troubleshooting, limited to what testing showed.

Device instructions don't assume a RADIUS setup. They refer to "your RADIUS server's CA" and the hostname on its certificate, so they work with Smallstep RADIUS or your own.

Also adds APNs to the Vale vocabulary.

Tested end to end with a Workspace ONE UEM tenant and a UniFi access point:

  • iPad mini (iOS 18.6): certificate issued, profile installed, joined the network
  • Pixel Tablet (Android 16, work profile): certificate issued, profile installed, joined the network

Vale shows no new findings beyond the guide's existing colon and heading patterns. markdown-link-check reports only the existing /graphics and Aruba failures. The page compiles with the site's MDX toolchain.

Related links/other PRs/issues:

Add an MDM-managed client section for iOS and Android devices managed by
Workspace ONE UEM, using the Smallstep integration's dynamic-challenge
SCEP CA resource, a request template, and per-platform Wi-Fi profiles.
Call out that these certificates come from the team's Agents authority,
which the RADIUS server must trust.

Add APNs to the Vale vocabulary.
Refer to "your RADIUS server's CA" and its certificate hostname instead
of Smallstep Managed RADIUS values, and drop the Managed RADIUS API steps
for adding the Agents root. Update Verify with what testing showed on
iOS: the Audit log's certificate-issued event, the Workspace ONE event
log sequence, and pushing a profile that stays pending.
Require Android Enterprise management (Work Profile or another
Android Enterprise mode, not Android (Legacy)), note the Certificate
Issued event Android logs, and add troubleshooting for devices that
enroll in Hub's registered mode, adding a work profile to a device
that's already set up, and paused work profiles. Bump updated_at.
State why the template uses the device UUID without claiming inventory
linking that testing didn't confirm, and let readers who reuse an
existing CA resource skip to either platform's profile.
@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

The integration's SCEP provisioner lives on the Agents authority by
default, but Smallstep support can place it on another authority. Say
"your issuing authority" and point readers to the integration
settings to find its root, instead of naming the Agents authority.
Prefer active voice, merge the Android server-validation note into one
sentence, and split the Verify list so troubleshooting has its own
heading.
@joshdrake
joshdrake marked this pull request as ready for review October 5, 2026 20:34
@joshdrake
joshdrake requested a review from a team as a code owner October 5, 2026 20:34
@joshdrake
joshdrake merged commit abe34b0 into main Oct 5, 2026
3 of 6 checks passed
@joshdrake
joshdrake deleted the docs/ws1-mobile-wifi branch October 5, 2026 21:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants