Repository navigation
Wireless guide: iOS and Android with Workspace ONE UEM (SCEP) - #564
Merged
Merged
Conversation
Add an MDM-managed client section for iOS and Android devices managed by Workspace ONE UEM, using the Smallstep integration's dynamic-challenge SCEP CA resource, a request template, and per-platform Wi-Fi profiles. Call out that these certificates come from the team's Agents authority, which the RADIUS server must trust. Add APNs to the Vale vocabulary.
Refer to "your RADIUS server's CA" and its certificate hostname instead of Smallstep Managed RADIUS values, and drop the Managed RADIUS API steps for adding the Agents root. Update Verify with what testing showed on iOS: the Audit log's certificate-issued event, the Workspace ONE event log sequence, and pushing a profile that stays pending.
Require Android Enterprise management (Work Profile or another Android Enterprise mode, not Android (Legacy)), note the Certificate Issued event Android logs, and add troubleshooting for devices that enroll in Hub's registered mode, adding a work profile to a device that's already set up, and paused work profiles. Bump updated_at.
State why the template uses the device UUID without claiming inventory linking that testing didn't confirm, and let readers who reuse an existing CA resource skip to either platform's profile.
|
|
The integration's SCEP provisioner lives on the Agents authority by default, but Smallstep support can place it on another authority. Say "your issuing authority" and point readers to the integration settings to find its root, instead of naming the Agents authority.
Prefer active voice, merge the Android server-validation note into one sentence, and split the Verify list so troubleshooting has its own heading.
joshdrake
marked this pull request as ready for review
October 5, 2026 20:34
dopey
approved these changes
Oct 5, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Describe your changes:
Adds an iOS and Android with Workspace ONE UEM (SCEP) section to the MDM-managed clients part of the Wireless Networks guide. Workspace ONE issues a client certificate from Smallstep through the integration's dynamic SCEP challenge, trusts the RADIUS server's CA, and configures an EAP-TLS Wi-Fi network. The Smallstep Agent isn't required.
The section covers:
Device instructions don't assume a RADIUS setup. They refer to "your RADIUS server's CA" and the hostname on its certificate, so they work with Smallstep RADIUS or your own.
Also adds
APNsto the Vale vocabulary.Tested end to end with a Workspace ONE UEM tenant and a UniFi access point:
Vale shows no new findings beyond the guide's existing colon and heading patterns. markdown-link-check reports only the existing
/graphicsand Aruba failures. The page compiles with the site's MDX toolchain.Related links/other PRs/issues: