Who We Are
What We Do
Who We Serve
Resources
Connect With an ExpertExplore Our Solutions
Home/Blog & Podcasts/Workspace ONE for Frontline Workers: A Practical Rollout Guide
Blogs·Endpoint Management

Workspace ONE for Frontline Workers: A Practical Rollout Guide

How to enroll, secure and manage shared and rugged devices for retail, healthcare and logistics teams.

Frontline workers, from store associates and nurses to drivers and warehouse staff, often outnumber office staff, yet their devices are frequently the least well managed. Shared scanners, rugged handhelds and kiosk tablets have their own challenges. Omnissa Workspace ONE gives you one platform to manage them alongside laptops and phones. Here’s how to roll it out.

The frontline device challenge

  • Shared devices: one device, many users across shifts, each needing their own apps and data
  • Rugged and specialist hardware: scanners, printers and handhelds from vendors such as Zebra and Honeywell, often running Android
  • Limited connectivity: devices in warehouses, vehicles or remote sites that drop off the network
  • Minimal training time: staff need to pick up a device and start working, with no IT help
  • Physical risk: devices are lost, dropped or left in the wrong place more often

Before you start: prepare the console

Do these once in the Workspace ONE UEM console before you enroll anything.

  1. Create an organization group for each region or site under your top-level group (Groups & Settings > Groups > Organization Groups). Policies and apps inherit downward, so set shared settings at the top and site differences lower down.
  2. Register Android Enterprise (Groups & Settings > All Settings > Devices & Users > Android > Android EMM Registration) and bind it to a managed Google Play account owned by the company, not an individual.
  3. Upload an Apple Push Notification service certificate (Devices & Users > Apple > APNs for MDM), using a shared company Apple ID so renewal does not depend on one person.
  4. Connect your directory so users and groups sync, and create smart groups by site, role and device model (Groups & Settings > Groups > Assignment Groups). Every later assignment uses these.

Step 1: Choose your enrollment approach

Company-owned Android handhelds

Recommended: Android Enterprise fully managed (Work Managed), using zero-touch or QR enrollment.

  1. For zero-touch, have your reseller add the devices to your zero-touch portal, then create a configuration that names Workspace ONE Intelligent Hub as the device policy controller and includes your server URL and organization group ID.
  2. For QR enrollment, generate the code with the enrollment configuration wizard (Devices > Lifecycle > Staging) and include the Wi-Fi details so the device can connect on first boot.
  3. On a factory-reset device, tap the welcome screen six times to open the QR reader, then scan.
  4. For Zebra and Honeywell hardware, add the vendor’s OEMConfig app from managed Google Play to control scanner settings, hardware keys and other device-specific features.

Company-owned iPads and iPhones

Recommended: Apple Business Manager with Automated Device Enrollment.

  1. In Apple Business Manager, add Workspace ONE as an MDM server and download the server token.
  2. Upload the token in the console (Devices & Users > Apple > Device Enrollment Program) and create an enrollment profile with supervision on and MDM profile removal blocked.
  3. Skip the Setup Assistant screens your staff do not need, so the device reaches the home screen quickly.
  4. Assign device serial numbers to the MDM server in Apple Business Manager, or set it as the default for new purchases.

Shared devices across shifts

Recommended: shared device (multi-user) mode with check-in and check-out.

  1. Turn on shared device settings for the organization group (Devices & Users > General > Shared Device) and choose how users are placed into groups at sign-in.
  2. Enroll the devices with a multi-user staging account so no device belongs to one named person.
  3. On Android, use Workspace ONE Launcher for check-in and check-out. On iOS, users sign in and out through Intelligent Hub.
  4. Set what is cleared at check-out, such as app data and passcode, so the next user starts clean.

Kiosks and fixed-purpose tablets

Recommended: single-app or multi-app kiosk (launcher) mode.

  1. On Android, create a Launcher profile (Resources > Profiles & Baselines > Profiles) and choose single-app, multi-app or template mode.
  2. On supervised iPads, use a Single App Mode profile for one app, or a Home Screen Layout profile with restrictions for several.
  3. Hide settings, notifications and the status bar where the device allows, and set an administrator passcode for exiting kiosk mode.

Personal devices (BYOD)

Recommended: work profile or app-level management only.

  1. On Android, enroll with a work profile so company apps and data sit in a separate container.
  2. On iOS, use User Enrollment, which manages work apps and accounts without taking over the device.
  3. Publish terms of use at enrollment that state what IT can and cannot see.

Zero-touch and automated enrollment are worth the setup effort. Devices arrive configured the moment they’re switched on, which matters when you’re deploying hundreds across dozens of sites.

Step 2: Deliver the right apps, and only those

Frontline workers need a small number of apps to do their job. Use Workspace ONE to:

  • Push line-of-business apps, scanning tools and communication apps automatically
  • Use a launcher to lock the home screen to approved apps
  • Assign apps by role, so a picker and a supervisor see different tools on the same model of device
  • Schedule updates outside shift hours so nobody is interrupted mid-task

Technical steps

  1. Approve public Android apps in managed Google Play and add them under Resources > Apps > Native > Public. Upload in-house apps under Internal.
  2. For Apple apps, buy licenses in Apple Business Manager (Apps and Books), sync them to the console, and assign them to devices, not users, so nobody needs an Apple ID.
  3. Set each assignment to automatic delivery and target it at a role smart group. Use application configuration key-value pairs to pre-fill server addresses and site codes so users never type them.
  4. Add the assigned apps to the Launcher layout for each role. An app that is installed but not in the layout stays hidden.
  5. Set a maintenance window for app updates and an Android system update policy with an install window outside shift hours.
  6. For sites with poor connectivity, use product provisioning with a relay server at the site, so large files download once locally and devices pick them up when they reconnect.

Step 3: Secure without slowing people down

  • Require a device passcode, or use quick badge or PIN sign-in for shared devices
  • Apply compliance policies that restrict access if a device is out of date or tampered with
  • Enable remote lock and wipe for lost devices
  • Use conditional access so corporate apps only open on managed, compliant devices
  • Keep sessions short on shared devices, with automatic sign-out at the end of a shift

Technical steps

  1. Create a Passcode profile for single-user devices. For shared devices, set the check-in method in Launcher or the shared device settings.
  2. Build compliance policies (Devices > Compliance Policies > List View > Add) with rules for minimum OS version, compromised status and last check-in time.
  3. Give each policy escalating actions: notify the user first, then block managed apps, then enterprise wipe if the device stays non-compliant.
  4. Connect device compliance to your identity provider, through Workspace ONE Access or Microsoft Entra ID conditional access, so sign-in to corporate apps checks the device state.
  5. Test lock, lost mode and wipe on a pilot device, and write a one-page runbook so a site supervisor knows who to call when a device goes missing.
  6. Set an automatic check-out or session timeout that matches your shift length.

Step 4: Plan the rollout

A typical rollout for a multi-site organization looks like this:

  1. Weeks 1–2: Design, enrollment configuration and app packaging
  2. Weeks 3–4: Pilot at one site with a small group of devices and users
  3. Weeks 5–6: Refine policies and training based on pilot feedback
  4. Week 7 onwards: Roll out site by site, with a short on-site or remote check-in for each

Technical steps

  1. Build and test everything in a pilot organization group first, then move the settings up to the parent group when they are proven.
  2. Pilot with every device model you plan to deploy. Rugged devices from different vendors behave differently.
  3. Tag devices by site and rollout wave so you can target and report on each wave separately.
  4. Check the site Wi-Fi and firewall before each wave. Devices need to reach Workspace ONE, Google and Apple services to enroll.
  5. Print the QR code and a three-step enrollment card for each site, in case a device needs to be reset and re-enrolled locally.

Build in a simple way for staff to report device problems, and track the most common issues so you can fix them centrally.

Measure success

Track device uptime, time to deploy a new device, number of support tickets per 100 devices, and how quickly a lost device is locked. These numbers make the value of the program clear to operations leaders. Workspace ONE Intelligence can report enrollment status, compliance and app adoption by site once devices are tagged.

How XenTegra helps

XenTegra designs and deploys Workspace ONE for frontline and office environments, from enrollment design and app packaging to rollout and ongoing management. We work across retail, healthcare, logistics and field services, and we can manage the platform for you after go-live.

Rolling out devices to frontline teams? Talk to XenTegra Canada about a Workspace ONE frontline pilot.

← Back to Blog & PodcastsTalk to an Expert