<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Workspace ONE - AirWatch Provisioning App in Legacy User Blogs</title>
    <link>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/ta-p/2766388</link>
    <description>&lt;P&gt;&lt;SPAN&gt;For updates on this blog and other blogs: &lt;/SPAN&gt;&lt;A href="https://twitter.com/SteveIDM?ref_src=twsrc%5Etfw" target="_blank" rel="nofollow noopener noreferrer"&gt;Follow @SteveIDM&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="7"&gt;This blog has been moved to&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="7"&gt;&lt;A href="https://TheIdentityGuy.ca" target="_blank" rel="noopener nofollow noreferrer"&gt;https://TheIdentityGuy.ca&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 15 Jun 2021 14:27:19 GMT</pubDate>
    <dc:creator>StevenDSa</dc:creator>
    <dc:date>2021-06-15T14:27:19Z</dc:date>
    <item>
      <title>Workspace ONE - AirWatch Provisioning App</title>
      <link>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/ta-p/2766388</link>
      <description>&lt;P&gt;&lt;SPAN&gt;For updates on this blog and other blogs: &lt;/SPAN&gt;&lt;A href="https://twitter.com/SteveIDM?ref_src=twsrc%5Etfw" target="_blank" rel="nofollow noopener noreferrer"&gt;Follow @SteveIDM&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="7"&gt;This blog has been moved to&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="7"&gt;&lt;A href="https://TheIdentityGuy.ca" target="_blank" rel="noopener nofollow noreferrer"&gt;https://TheIdentityGuy.ca&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 14:27:19 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/ta-p/2766388</guid>
      <dc:creator>StevenDSa</dc:creator>
      <dc:date>2021-06-15T14:27:19Z</dc:date>
    </item>
    <item>
      <title>Re: Workspace ONE - AirWatch Provisioning App</title>
      <link>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766389#M6498</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Steve&lt;/P&gt;&lt;P&gt;Have you ever had the case where you get the following error message?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper"&gt;&lt;img src="https://communities.vmware.com/skins/images/825FC13A7A158B39E0186DF171286099/responsive_peak/images/image_not_found.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks for more information on this.&lt;/P&gt;&lt;P&gt;Best Arian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Apr 2020 14:20:03 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766389#M6498</guid>
      <dc:creator>ArianZuta</dc:creator>
      <dc:date>2020-04-17T14:20:03Z</dc:date>
    </item>
    <item>
      <title>Re: Workspace ONE - AirWatch Provisioning App</title>
      <link>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766390#M6499</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you complete Step 2 above? SAML needs to be configured on the directory services page.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Apr 2020 14:37:17 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766390#M6499</guid>
      <dc:creator>StevenDSa</dc:creator>
      <dc:date>2020-04-17T14:37:17Z</dc:date>
    </item>
    <item>
      <title>Re: Workspace ONE - AirWatch Provisioning App</title>
      <link>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766391#M6500</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Steven,&lt;/P&gt;&lt;P&gt;Yes I did. As discribed above.&lt;/P&gt;&lt;P&gt;What I changed from above was External Id to a manual value (as ${user.ExternalId} always prompted the error number 1 in your troubleshooting guide.&lt;/P&gt;&lt;P&gt;Best Arian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Apr 2020 14:43:11 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766391#M6500</guid>
      <dc:creator>ArianZuta</dc:creator>
      <dc:date>2020-04-17T14:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: Workspace ONE - AirWatch Provisioning App</title>
      <link>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766392#M6501</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;And you are doing this on the top level OG?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Apr 2020 14:47:24 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766392#M6501</guid>
      <dc:creator>StevenDSa</dc:creator>
      <dc:date>2020-04-17T14:47:24Z</dc:date>
    </item>
    <item>
      <title>Re: Workspace ONE - AirWatch Provisioning App</title>
      <link>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766393#M6502</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have an onpremise environment and i am doing this on the top level OG (of type customer)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Apr 2020 14:49:45 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766393#M6502</guid>
      <dc:creator>ArianZuta</dc:creator>
      <dc:date>2020-04-17T14:49:45Z</dc:date>
    </item>
    <item>
      <title>Re: Workspace ONE - AirWatch Provisioning App</title>
      <link>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766394#M6503</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Strange. The only reason you should get this error is because SAML is not configured on the top level OG.&amp;nbsp; Directory Type should be set to none. SAML should be configured for at least Enrollment and SSP. Also Directory Type should be checked off in Devices &amp;amp; Users -&amp;gt; General -&amp;gt; Enrollment. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that doesn't work I suggest you contact VMware Support. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Apr 2020 14:56:48 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766394#M6503</guid>
      <dc:creator>StevenDSa</dc:creator>
      <dc:date>2020-04-17T14:56:48Z</dc:date>
    </item>
    <item>
      <title>Re: Workspace ONE - AirWatch Provisioning App</title>
      <link>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766395#M6504</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alright, thanks for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Apr 2020 15:08:27 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766395#M6504</guid>
      <dc:creator>ArianZuta</dc:creator>
      <dc:date>2020-04-17T15:08:27Z</dc:date>
    </item>
    <item>
      <title>Re: Workspace ONE - AirWatch Provisioning App</title>
      <link>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766396#M6505</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin: 2px; font-family: proxima-nova, Arial, sans-serif; color: #666666;"&gt;Hi &lt;B&gt;ArianZuta&lt;/B&gt;​&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 2px; font-family: proxima-nova, Arial, sans-serif; color: #666666;"&gt;In order to solve this, in Workspace ONE UEM Console, Navigate to GROUPS &amp;amp; SETTINGS &amp;gt; All Settings &amp;gt; Devices &amp;amp; Users &amp;gt; General &amp;gt; Enrollment,&amp;nbsp; and mark the “Directory” checkbox for the customer Organization Group.&lt;/P&gt;&lt;P style="margin: 2px; font-family: proxima-nova, Arial, sans-serif; color: #666666;"&gt;&lt;/P&gt;&lt;P style="margin: 2px; font-family: proxima-nova, Arial, sans-serif; color: #666666;"&gt;&lt;SPAN style="color: #666666; font-weight: inherit; font-size: 11pt; font-family: proxima-nova, Arial, sans-serif; font-style: inherit;"&gt;Arale&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Apr 2020 13:48:10 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766396#M6505</guid>
      <dc:creator>aralesahar</dc:creator>
      <dc:date>2020-04-24T13:48:10Z</dc:date>
    </item>
    <item>
      <title>Re: Workspace ONE - AirWatch Provisioning App</title>
      <link>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766397#M6506</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;B&gt;StevenDSa&lt;/B&gt;​&lt;/P&gt;&lt;P&gt;We have completed this, as well as the 1-4 parts of integrating Okta with WS1 Access but we are still seeing two issues:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;When we try to log into the WS1 UEM instance we get different responses depending on what we are doing:&lt;UL&gt;&lt;LI&gt;From the web using cnXXXX.awmdm.com we are not redirected to Okta and get "Invalid credentials, Try again."&lt;/LI&gt;&lt;LI&gt;When&amp;nbsp; provisioning a new macOS device with ABM/DEP we get the redirection to Okta and are able to verify the okta credentials but are then sent back to UEM and given the error "Invalid User Credentials ?? An unexpected error occured."&lt;/LI&gt;&lt;LI&gt;When manually enrolling a windows 10 device we get the same result as macOS ABM/DEP&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Both the Groups and users are being synced from the AirWatch Provisioning App in WS1 Access but the users are not being assigned to those groups in WS1 UEM&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jun 2020 19:40:09 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766397#M6506</guid>
      <dc:creator>kw1548</dc:creator>
      <dc:date>2020-06-18T19:40:09Z</dc:date>
    </item>
    <item>
      <title>Re: Workspace ONE - AirWatch Provisioning App</title>
      <link>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766398#M6507</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kw,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding the first point, have you configured Hub Services to use Workspace ONE Access? You will also have to configure Directory Services (in UEM) to use SAML with Workspace ONE Access as well? This also means you will need to configure the AirWatch app inside of WS1 Access. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding point 2. Please make sure in the A/W Provisioning Application that the OG specified is the top OG.&amp;nbsp; Also, the groups you are trying to push from WS1 -&amp;gt; UEM, are these regular groups in Okta or assignment groups in Okta. This makes a difference. Okta does not support/recommend pushing the same groups that are using for assigning the WS1 application. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jun 2020 20:13:18 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766398#M6507</guid>
      <dc:creator>StevenDSa</dc:creator>
      <dc:date>2020-06-18T20:13:18Z</dc:date>
    </item>
    <item>
      <title>Re: Workspace ONE - AirWatch Provisioning App</title>
      <link>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766399#M6508</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For reference as I forgot this in the first post - We are on UEM 2007&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For Hub Services I access that normally though the the UEM apps menu (9 dots at the top right) then I am forwarded to our DOMAIN.workspaceoneaccess.com/catalog-portal/admin-console#/uem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that is the right area that you are speaking of then it is configured as follows and does not seem to have a way to change or update the settings.&lt;/P&gt;&lt;P&gt;Under Workspace ONE Hub Services - System Settings we don't seem to have any way to change it.&amp;nbsp; &lt;BR /&gt;Currently this has only two things&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL style="list-style-type: disc;"&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Helvetica',sans-serif; color: #3d3d3d;"&gt;System Settings&lt;/SPAN&gt;&lt;UL style="list-style-type: circle;"&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Helvetica',sans-serif; color: #3d3d3d;"&gt;Mobile Flows URL: Our URL&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Helvetica',sans-serif; color: #3d3d3d;"&gt;UEM Integration&lt;/SPAN&gt;&lt;UL style="list-style-type: circle;"&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Helvetica',sans-serif; color: #3d3d3d;"&gt;API URL: Our asXXXX.awmdm.com&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Helvetica',sans-serif; color: #3d3d3d;"&gt;API Certificate: Our Cert&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Helvetica',sans-serif; color: #3d3d3d;"&gt;Certificate Password: Our Password&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Helvetica',sans-serif; color: #3d3d3d;"&gt;Admin API Key: Our API Key&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Helvetica',sans-serif; color: #3d3d3d;"&gt;Group ID: Our top OG&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Helvetica',sans-serif; color: #3d3d3d;"&gt;Device Services URL: Our dsXXXX.&lt;/SPAN&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Arial',sans-serif; color: #575757; background: #FAFAFA;"&gt;awmdm.com/DeviceServices&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #575757; font-family: Arial, sans-serif;"&gt;We also have the Airwatch app and the AirWatch Provisioning Applications both configured in ACCESS and with the same groups assigned to them.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #575757; font-family: Arial, sans-serif;"&gt;In UEM we are configured to use SAML and that is pointing to ACCESS.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #575757; font-family: Arial, sans-serif;"&gt;For our second issue is all that is needed here is to switch the Okta group type then re-sync those groups?&amp;nbsp; I will have to check with our Okta admin to be sure but I would bet we are using the assignment groups.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jun 2020 20:43:12 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766399#M6508</guid>
      <dc:creator>kw1548</dc:creator>
      <dc:date>2020-06-18T20:43:12Z</dc:date>
    </item>
    <item>
      <title>Re: Workspace ONE - AirWatch Provisioning App</title>
      <link>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766400#M6509</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't know if I'll have the right answers for you but based on your comment "&lt;SPAN style="color: #666666; font-family: proxima-nova, Arial, sans-serif;"&gt;From the web using cnXXXX.awmdm.com we are not redirected to Okta and get "Invalid credentials, Try again."&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #666666; font-family: proxima-nova, Arial, sans-serif;"&gt;If you go to in your browser:&lt;A href="https://cnXXXX.awmdm.com/mydevice/Login?gid=OG" title="https://cnXXXX.awmdm.com/mydevice/Login?gid=OG"&gt; https://cnXXXX.awmdm.com/mydevice/Login?gid=OG&lt;/A&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #666666; font-family: proxima-nova, Arial, sans-serif;"&gt;You should be redirected to WS1 Access and then Redirected to Okta.&amp;nbsp; If this is not happening then you most likely have an issue in Enterprise Integration -&amp;gt; Directory Services (Specifically Under SAML Settings)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #666666; font-family: proxima-nova, Arial, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;If you are having a problem on the return, its probably an issue with the values being passed in the response are not matching the UEM user. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jun 2020 21:55:50 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766400#M6509</guid>
      <dc:creator>StevenDSa</dc:creator>
      <dc:date>2020-06-18T21:55:50Z</dc:date>
    </item>
    <item>
      <title>Re: Workspace ONE - AirWatch Provisioning App</title>
      <link>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766401#M6510</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Using this link I am forwarded to Okta for SSO then I can see the trace to WS1 Access, and then from Access to UEM but I am still getting "Login Failed, please try again." At this point I would guess its an issue with the username values or something similar.&amp;nbsp; How would I be able to confirm this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did run a saml trace on this login event and can see UEM sending to Access, Then Access to Okta, Okta replys to Access and then Access forward back to UEM where we still get the same error "Invalid User Credentials ?? An unexpected error occurred."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I checked in the Applications for UEM and Access and can not find any mismatch on pass values..&amp;nbsp; I am overlooking something?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Here is the UEM Console SAML Settings&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper"&gt;&lt;img src="https://communities.vmware.com/skins/images/825FC13A7A158B39E0186DF171286099/responsive_peak/images/image_not_found.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Here are the 3 Applications in Access (The first two were created and provisioned by the UEM client when setting up)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Each of them is configured as below:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper"&gt;&lt;img src="https://communities.vmware.com/skins/images/825FC13A7A158B39E0186DF171286099/responsive_peak/images/image_not_found.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The provisioning is all working as expected and configured similarly&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper"&gt;&lt;img src="https://communities.vmware.com/skins/images/825FC13A7A158B39E0186DF171286099/responsive_peak/images/image_not_found.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I highlighted in red the ones I thought could be the issue but how would I go about finding out what other possible values these could have?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jun 2020 18:51:07 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766401#M6510</guid>
      <dc:creator>kw1548</dc:creator>
      <dc:date>2020-06-23T18:51:07Z</dc:date>
    </item>
    <item>
      <title>Re: Workspace ONE - AirWatch Provisioning App</title>
      <link>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766402#M6511</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you change your UEM settings from Redirect to Post?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jun 2020 20:04:43 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766402#M6511</guid>
      <dc:creator>StevenDSa</dc:creator>
      <dc:date>2020-06-23T20:04:43Z</dc:date>
    </item>
    <item>
      <title>Re: Workspace ONE - AirWatch Provisioning App</title>
      <link>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766403#M6512</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That did it!&amp;nbsp; Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jun 2020 20:17:59 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766403#M6512</guid>
      <dc:creator>kw1548</dc:creator>
      <dc:date>2020-06-23T20:17:59Z</dc:date>
    </item>
    <item>
      <title>Re: Workspace ONE - AirWatch Provisioning App</title>
      <link>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766404#M6513</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;B&gt;StevenDSa&lt;/B&gt;​,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am configuring Okta SCIM users &amp;amp; groups to WS1 Access then WS1 Access to provision the same sets of users and groups to UEM. The first part from Okta to WS1 Access has no issue. From WS1 Access to UEM, the AirWatch Provisioning app can only provision users to UEM. Group Provisioning just stuck at provisioning and never actually provision the groups to UEM. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper"&gt;&lt;img src="https://communities.vmware.com/skins/images/825FC13A7A158B39E0186DF171286099/responsive_peak/images/image_not_found.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any chance you know what it could cause the issue where group provioning just stuck there?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jun 2020 20:00:23 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766404#M6513</guid>
      <dc:creator>donion23</dc:creator>
      <dc:date>2020-06-24T20:00:23Z</dc:date>
    </item>
    <item>
      <title>Re: Workspace ONE - AirWatch Provisioning App</title>
      <link>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766405#M6514</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've not seen that one before. Here are some suggestions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Make sure there is no directory configured at the customer level OG in UEM&lt;/LI&gt;&lt;LI&gt;Make sure customer level OG is specified in WS1 Access.&lt;/LI&gt;&lt;LI&gt;Assuming the same group does not already exist in UEM?&lt;/LI&gt;&lt;LI&gt;Make sure Chrome autofill did not change the username/password for Provisioning tab&lt;/LI&gt;&lt;LI&gt;Wait for it to fail (might take some time). Hopefully the error can point us in the right direction or give us the ability to deprovision. &lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jun 2020 20:13:50 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766405#M6514</guid>
      <dc:creator>StevenDSa</dc:creator>
      <dc:date>2020-06-24T20:13:50Z</dc:date>
    </item>
    <item>
      <title>Re: Workspace ONE - AirWatch Provisioning App</title>
      <link>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766406#M6515</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks so much @StevenDSa for helping. Below is my check&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Make sure there is no directory configured at the customer level OG in UEM&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;--&amp;gt; No directory is configured in UEM&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #666666; font-family: proxima-nova, Arial, sans-serif;"&gt;Make sure customer level OG is specified in WS1 Access.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #666666; font-family: proxima-nova, Arial, sans-serif;"&gt;--&amp;gt; yes&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #666666; font-family: proxima-nova, Arial, sans-serif;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Assuming the same group does not already exist in UEM?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;--&amp;gt; yep, I ensure no WS1 Authorization exist in UEM prior. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Make sure Chrome autofill did not change the username/password for Provisioning tab&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;--&amp;gt; I disable the Chrome auto fill. Make sure the Admin Password typed in correctly. Test connection is success. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Wait for it to fail (might take some time). Hopefully the error can point us in the right direction or give us the ability to deprovision.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;---&amp;gt; Waited two days now&lt;/P&gt;&lt;P&gt;--&amp;gt; Further troubleshooting steps --&amp;gt; Check mark the WS1 Authorization group --&amp;gt; Deprovision --&amp;gt; Wait for it to be gone under Group Provisioning --&amp;gt; Re-add the same group for Provisioning --&amp;gt; It kicked into "Ready for Provision" --&amp;gt; then go into "Provisioning" --&amp;gt; stuck there and won't fail at all. No matter how long i would wait.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---&amp;gt; Proceed to create another seperate blank group (contain no users) in Workspace ONE Access --&amp;gt; Access AirWatch Provisioning app --&amp;gt; Group Provisioning --&amp;gt; Add that blank group --&amp;gt; still stuck at Provisioning and won't fail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe contact support? could be something is wrong with my VIDM tenant?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andre&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2020 08:09:53 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766406#M6515</guid>
      <dc:creator>donion23</dc:creator>
      <dc:date>2020-06-25T08:09:53Z</dc:date>
    </item>
    <item>
      <title>Re: Workspace ONE - AirWatch Provisioning App</title>
      <link>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766407#M6516</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Otherwise, users are being provisioned flawlessly. Just groups won't come over&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2020 08:10:56 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Legacy-User-Blogs/Workspace-ONE-AirWatch-Provisioning-App/tac-p/2766407#M6516</guid>
      <dc:creator>donion23</dc:creator>
      <dc:date>2020-06-25T08:10:56Z</dc:date>
    </item>
  </channel>
</rss>

