AirWatch 8.1 is a sophisticated control plane for mobile devices that meets the needs of large enterprises. It stacks up well against other MDM apps we’ve tested, and features container demarcation plus elements of data loss prevention.
AirWatch controls end user access to applications and other resources like email, and works across a wide variety of phone, tablet, and notebook/desktop devices. For some device platforms, containerization can be managed by policy, down to the level of permitting or denying things like built-in camera activation.
A VMware unit, AirWatch has the advantage of being completely autonomous from the big sellers of phones and their carriers, and it also boasts third-party associations that add to its overall systems integrity.
We tested AirWatch in the cloud as a SaaS application, and found it very compelling, rapidly accessible, and easily joined to your existing systems infrastructure. Airwatch’s cloud-based UI is good, even on smaller displays.
For administrators, there are buttons linking to videos on what to do in various contexts. Wizards can drive most of the app, and even newbie administrators ought to be able to get things moving quickly.
What’s compelling? It’s approachable for all levels of administrator and covers many devices, often with selections tailored specifically for a brand; an example would be understanding Android, but also some of the nuances of Android Samsung phones.
We could start in a minimalistic administrative fashion, or extend control to a fleet of diverse mobile devices. We could navigate by wizard or by elemental fine control —and the controls can be extensive, with sophisticated policy relationships. In turn, customized (in some cases organizational branding) screens tell users what’s going on at installation/device enrollment time.
Third-party add-ins help AirWatch, too. An example is a relationship with AppThority, a mobile applications analyzer company that vets mobile applications by disassembling them and exposing what they do and the known implications, capability-by-capability. These add-ins are optional, but several are available from the VMware Store.
There are many often-unrealized actions a mobile application can perform—including informing servers of user location, their contacts, and even upload pictures, docs, and user files. The combination of AirWatch with such applications can be quite powerful — if administrators are willing to use set-policy controls with third party app data.
AirWatch offers control via profiles for specifics of Blackberry 10; Android; Mac OS X, Apple TV, and iOS; Windows/Windows Rugged; ChromeOS; Tizen; and Symbian.
Setup and Installation
AirWatch was tested as a SaaS application. There are numerous steps involved and much thought should be given to how to most effectively use AirWatch.
But it’s also possible to just breeze in and wing it, if you’re experienced with phones, policies, your directory service (LDAP or AD) infrastructure, and your control desires.
There are wizards aplenty, executed sequentially, so as to build a basic framework that works for AirWatch administrative beginners. Parsers check each field and page and wouldn’t let us save incomplete forms or nonsense. Links to chapter and verse inside of a help system aren’t there for manual configurations or wizards, although the contexts are usually well-explained. There are also videos to view at important stages.
The portal that AirWatch offered for our test has the keys to the kingdom, and although strong passwords are mandated, secondary authentication and ACLs involving more than just username/password authentication isn’t found. Our singular warning is that the portal is the nervous system of enterprise control over the applied security of the domain, and we recommend a secondary authentication mechanism and browsers known to force highest encryption for use of the portal. The portal must be profoundly protected.
The supplied Getting Started routine of Wizards involves:
- Setup including Apple MDM and APNS certificate management (for iOS devices), then an email domain link.
- Enroll actions for devices, a Device Dashboard, and Hub to monitor Compliance, Violations, Devices with Blacklisted or Required Apps, Devices without Profiles, Devices without Latest Apps, most installed apps.
- Secure/Security, enabling policies for encryption and passwords, also Restrictions and Compliance Policy Controls.
- Profiles for device-specific usage characteristics configuration, privacy permissions, and a customized Terms of Use for enrolled users.
- Grouping for organizational device/policy delineation, user groups for like-type characteristic group management, and “Smart Groups” that are like-type enrolled devices based on life cycle or other common characteristics.
- Enterprise Integration, which mates AirWatch with organizational directory services, Exchange Active-Sync (where present), and internal/external certificate authorities, which in turn, enable custom code, content tracking, third-party certificate-based data loss prevention/DLP apps, and the establishment of an organizational mobile app gateway.
- Advanced Enrollment that places constraints on number of devices that can be managed per/by user, adding choices for customized enrollment procedures and organizationally-specific contact/help desk/support information.
- Container app provisioning steps for enrolled devices, and defining the characteristics of the sandboxed components, which aren’t controlled directly under AirWatch active MDM control.
- Email management and integration.
- Administrative accounts and controls.
Each of the Getting Started submenu selections has a percentage-of-task completed progress bar, as well as a video link that describes the process, and a bit of how this process relates to overall management of devices. One doesn’t have to complete everything at once, we found, leaving nagging/reminders in the remaining incomplete percentage bars. Usually, but not always, the help instructions, video, and actual procedure are in sync; we found only a couple of minor discrepancies.
AirWatch allows organizational email integration, including actively permitting access to email from enrolled devices. Email controlled in this way is limited to Microsoft Exchange, 2003+ and Office365, IBM Domino, Novell GroupWise, and Google Apps for Work or those that might be able to successfully emulate one of these, but not VMware’s Zimbra platform.
+ ALSO ON NETWORK WORLD: MDM features and functions compared +
We integrated AirWatch with our Microsoft 2012R2 Certificate Authority, and our Microsoft Exchange 2013 mail platform as a proof of concept, and Microsoft Active Directory integration with these two elements—mail and CA—worked successfully and without incident.
This allowed us to import organizational units, users, and certs somewhat effortlessly. We used a gateway access node that ran an app for email gateway access on Windows hardware configured as a proxy. The setup steps are not entirely transparent, but those understanding Office365 and/or Exchange services, should have no difficulty in configuring this proxy. The proxy system is a single point of failure, and so needs to either be monitored, or multiple failover proxy servers (easy to do, no licensing problems beyond cost of additional redundant paths) are recommended.
Device controls
Mac and Windows desktops, along with their phone OS versions, are covered by AirWatch Policy Management. Devices that can be controlled include: Android, Apple iOS, Apple Mac OS X, Apple TV, Blackberry, Blackberry 10, ChromeOS, QNX, Symbian, Tizen, Windows 7/Rugged/Phone/Desktop. Of these, we tested with BlackBerry 10, iOS 8/9, Mac OS X 11, and Windows 7. As your fleet may vary, a dependency builds on the ability of AirWatch to cover newly released OS versions, and AirWatch seemed to be at most, a couple of months behind in specific OS releases through the five-month cycle in which we worked with the AirWatch SaaS app.
In AirWatch, devices are designated and treated by policy as corporate, corporate/shared, or user devices and the distinctions are important. Integrating a device, for example a phone, means choosing things like terms of service, policies, and auditing—then actual permitted use cases.
Apps receive much control, including the ability for third parties (currently Appthority, Palo Alto Networks Wildfire, Praedeo, and Veracode services) to examine/report applications on platforms they support.
There can be a wide variety of organizational apps, media, and content provided via organizational upload to the AirWatch portal. It’s even possible to add-in an Apple Volume Purchase Plan (VPP) license to facility proxy license counting via iTunes, if your organization is Apple-inclined. A catalog of resources can be filled-in administratively, then accessed by users in subdivided categories.
Security settings entail invoking policy enforcement requirements, such as requiring passwords, the use and type of certificates (files and Kerberos), or the NAPPS protocol, which is a mobile identity SSO protocol. There’s an app tunneling protocol (that we couldn’t easily find information about) and geo-fencing (we tried to spoof location, but were unable to do so in a limited test).
Data loss prevention components consist of enabling/disabling items like cut/paste, printing, composing email, cameras present, backups, limit document handling, location-based services, as well as enabling single-sign-on. These settings worked as selected.
We downloaded the AirWatch app via the usual stores/downloads pertinent to the device under control, which means going to Google Play for Android, the Apple Store for MacOS or iOS. Windows agents can be downloaded or auto-discovered via a URL or Windows resource.
There are then client app logic branches that either include containers/sandboxing, or not. Windows 7-10 (XP wasn’t mentioned) and Mac OS X clients have differing methods of client agent download, and pertinent selections for each, in terms of OS features. Additional controls for Windows 10 are available that are missing for prior versions of Windows.
Administrative control
In our small test fleet of devices, we incurred few foibles. Controlling Macs was easy, and during installation the Agent installer correctly prompted the client user to make changes necessary to comply, as an example, enabling Location services via invoking Setup, and the specific item needed to be unlocked, checked, and locked again. This allows geolocation of our test Macs.
Windows setup, tested on Windows 10, was equally simple, but the Windows 10 compliance elements are more varied, as Windows 10 offers more control contexts—although some of these contexts, like is Windows 10 secure-booted, may or may not cause a fleet of variances/exceptions to be managed.
Blackberry 10 use is bridged through Blackberry Enterprise Server (BES), which controls the functionality of the phones—there is no direct control, only reporting and controls placed through the BES; if you’re not using BES, you won’t be able to control Blackberries.
Android control was also smart enough to pickup our Samsung test phones. We could create a container, and isolate application functionality, as well as push content and a trial set of apps to our phones. Once wiped, only the container goes away. We could also suspend/enable email. Other email apps, depending on their location in a contained environment, could work—even ones we pushed to the devices. Inventory and care of email circuits need to be administratively monitored if data loss protection (DLP) is to plug all leaks.
IOS uses Apple Push Notification Services to send apps and content, just as many other providers of Apple products use APNS. There are AirWatch Mail, Secure Browser, Chat Client, a Content Locker, App Catalog, and Secure Workspace available for iPhones and iPads. Apple TV wasn’t tested.
Staging accounts can be used as a proxy method to wrap large wads of apps and content together to be pushed to enrolled devices, subject to administrative approval, and varying group memberships in such a way as to tailor the payloads.
In turn, the payloads go to the individual enrolled devices subject to the device availability. We could not test large groups of device payload disbursement to judge whether a fleet of say, iPhone packages might surge network wires or cause synchronization problems, where zero day updates might be required. Larger organizations may face distribution problems of large amounts of updates.
Like many network management systems that have software inventory control, AirWatch allowed us to query specific types of applications across our admittedly small user base. We could therefore check for versions of apps like Java, or drivers that might need updating, and flag them for deletion, replacement, etc.
We found this especially handy for searching for certificates of all kinds—which aids administrators in ensuring proper payloads of certificate objects across wide turfs of systems covered by AirWatch. Finding apps or certificates or other attributes means keeping the polling frequency-interval somewhat up to date.
Test parameters
We tried a sample of devices, and not a large fleet of them. A circuit to AirWatch’s various servers is required, and we did not hammer these sources. We also didn’t download megaloads of patches and fixes—which we don’t recommend anyway unless the transactional duty cycles have been assessed and perhaps piloted.
We did see updates for Windows 10, iOS 9, and MacOS 11 arrive soon after each of these were generally released. Unless an organization is dependent on specific versions that they release and manage empirically, BYOD installations could conceivably cause problems.
We also didn’t test Windows 10 phone, Tizen, and Symbian. The populations of these at test time are comparatively small relative to Blackberry, Android, and iPhone/iPad installations. We did test a user device limit, which worked as expected—the fifth device for a test user would not go under control. Some organizations face such near-geometric growth in user devices and 10 users might have 50 devices among them in some departments.
We didn’t extensively test containers for the strength of their walls, but could not “break” them or breach them. And we pushed only a handful of trial apps to each device under test as proof of concept, which worked as expected.
Overall
AirWatch is highly adaptable, and attempts successfully to make bridges over the myriad choices that could give an administrator configuration option shock. Each step of configuration has a checklist, and a video attached to it online. The tasks can be done in batches, sequentially, or as needed to address varying option needs. There is a depth that’s also difficult to adequately describe in a short review, and AirWatch increases its power through use of third-party apps that enable Mobile Application Management (MAM) analysis and control functionality missing in the base AirWatch portal. We also feel that AirWatch has an excellent chance of being successful in a wide-denominator of organizations.
AirWatch takes the place of a category once called Network Management Systems, and combines MDM and MAM into a single package with a lot of muscle and administrative cohesiveness. It lacks a few features found in sophisticated Cloud Access Security Broker (CASB) packages, but it’s likely a matter of time and third-party support before AirWatch learns this lesson, too.
How we tested AirWatch
We used two Macs (Macbook Air, OSX 11.1, iMac17 with OS X 10.3), a Samsung notebook (Core i7, Windows 10 SP1), an iPhone 5C (iOS9, 32GB), a Samsung G3 (32GB), and a Blackberry 10 phone, downloading clients for each, connected through a Windows 2012R2 headless server to Office365 for Business/Exchange Server 2013.
We created platform-specific app and content payloads using actual apps and fake content, and verified fleet-wide payloads by OS-platform type. We also tried violating policies (mostly copying and cut/paste functions), and then tracked administrative console returns to see how quickly these might appear as violations. Depending on the polling frequencies, they were found very quickly, often within a second of the device poll. We also tested email blocking/admission, and downloading unapproved apps, where that’s possible to do in unjailbroken phones, or through general browser use on MacOS 10/11 or Windows 10.
We downloaded an APN certificate from Apple to test iOS, and connected the Blackberry 10 through a BES12 (12.03) resident on a Windows 2012 R2 VM. We used Windows 2012R2 Certificate Services to generate certificates and host a trial Active Directory to test certificate use (which can be no fun).
We trialed our connectivity over T-Mobile, Xfinity, and circuits at our NOC at Expedient in Indianapolis, which hosted our core test servers, connected to their backbones.




