How to Configure AirWatch for Multi-User Shared Devices

Shared tablets, laptops and rugged handhelds can help organisations reduce hardware costs while keeping frontline teams productive. AirWatch, now associated with VMware and commonly encountered through the Workspace ONE platform, gives IT teams a central way to enrol, configure, secure and support these endpoints.

The setup differs from a standard one-user device. A shared device needs a reliable sign-in method, clean handover between workers, limited access to corporate data and a predictable process for resetting the device. These requirements matter in warehouses, hospitals, schools, retail stores and Australian field operations where a device may change hands several times in one shift.

A careful configuration also reduces support calls. Staff in Sydney offices, Perth mining sites or regional Queensland depots should be able to pick up an approved device, authenticate quickly and access the applications required for their role. The following process covers planning, enrolment, profiles, user experience and ongoing management.

Define The Shared Device Model

Start by identifying how each device will be used. A kiosk is usually tied to one application or workflow, while a shared workstation may allow several approved business apps. A shift-based device may require each employee to sign in with an individual account, whereas a task device could use a managed service identity with no personal sign-in.

List the hardware and operating systems involved before creating profiles. Android rugged scanners, iPads, Windows laptops and dedicated point-of-sale terminals may require different management approaches. Record the device owner, physical location, business purpose, connectivity requirements and expected replacement cycle. This information will make it easier to build smart groups and assign settings accurately.

Choose whether workers authenticate with Microsoft Entra ID, another identity provider, local credentials or a dedicated Workspace ONE account. Individual authentication generally provides better audit trails because application access can be linked to a person. A shared account may be faster, but it weakens accountability and can expose data if the password is circulated.

For Australian organisations, consider connectivity outside major cities. A device used on a mine site near Kalgoorlie or in a regional health service may have intermittent coverage, so essential settings and applications should remain available offline. Plan a process for synchronisation when the device reconnects.

Prepare Enrolment And Identity Settings

Create a dedicated organisation group or smart group for shared endpoints. Avoid placing these devices in the same assignment structure as executive laptops or personally owned mobiles. Separate groups let administrators apply stricter restrictions, different application sets and location-specific configurations without affecting other users.

For Android Enterprise devices, select the appropriate mode, such as dedicated device or shared device, depending on whether users need an interactive sign-in. For Apple hardware, use Automated Device Enrolment through Apple Business Manager where possible. Windows endpoints can be enrolled through supported Windows provisioning methods and assigned to the relevant Workspace ONE policies.

Configure enrolment restrictions before devices are issued. You may restrict ownership types, block unsupported operating system versions, require approved serial numbers or limit enrolment to corporate accounts. Naming rules should make devices easy to identify, using information such as site, department and asset number rather than a worker’s name.

Identity integration deserves careful testing. Confirm that the directory sends the correct user groups, authentication claims and access permissions. If multifactor authentication is required, test whether the chosen method works on a shared terminal. A phone-based approval may be inconvenient for a warehouse worker who is wearing gloves, while a security key or passcode may be more practical.

For a practical reference on organising an endpoint rollout, this step-by-step guide can complement the platform-specific planning process. Use it as a planning aid rather than copying settings without checking your own identity, compliance and network requirements.

Build Profiles, Applications And Restrictions

Profiles define how a shared device behaves. Configure Wi-Fi, certificates, VPN, email, browser settings, passcode rules and operating system updates through separate profiles where possible. Smaller, focused profiles are easier to troubleshoot than one large policy containing every setting.

Apply a restricted launcher or kiosk configuration when workers should see only approved applications. Hide system settings, app stores, cameras, screenshots, account changes and unapproved browsers if the workflow requires it. For a general-purpose shared laptop, use application allowlists and prevent local administrator access instead of locking the user into a single app.

Install essential software automatically, including productivity tools, line-of-business applications, remote support agents and security controls. Set applications to update during a maintenance window so a device does not restart halfway through a delivery run or clinical handover. Use phased deployment for important updates and monitor failures in the console.

The most important shared-device setting is the handover experience. Configure automatic sign-out, session timeout and removal of local user data when a user finishes. Where supported, enable a guest or shared-session mode that clears cached credentials and application data. Test whether files, browser history, downloaded documents, notifications and clipboard contents remain after sign-out.

Device approach Authentication Recommended controls Suitable use
Dedicated kiosk No individual sign-in or managed account Single-app mode, locked settings, automatic restart Reception, check-in and production displays
Shift-based shared device Individual directory sign-in Session timeout, data wipe, app restrictions Warehouses, hospitals and retail teams
Shared Windows workstation Individual sign-in or smart card Standard user rights, profile cleanup, patch control Desks, service counters and classrooms
Task-specific rugged handheld Managed identity or worker sign-in Offline access, barcode apps, rugged-case support Logistics, utilities and field service

When configuring Windows endpoints, compare device-management capabilities with your wider endpoint strategy. A specialist Windows UEM platform may provide useful context for Windows-specific provisioning, policy and application requirements, while AirWatch remains the central console for the broader mobility programme.

Test The Worker Experience And Security

Build a pilot group with representative devices and users. Include a newer model and an older supported model, as performance and application compatibility can differ. Test at the actual workplace rather than relying solely on an office network. A tablet used in a Brisbane loading bay may behave differently from one tested on a fast corporate Wi-Fi connection.

Run through the full shift lifecycle. Enrol the device, sign in as Worker A, use every required application, save or submit work, sign out and then sign in as Worker B. Check that Worker B cannot see the previous user’s documents, notifications, browser history or account tokens. Repeat the test after a poor network connection, forced reboot and battery drain.

Validate emergency and recovery procedures as well. Confirm that IT can lock, wipe or locate a device when it is lost, subject to organisational policy and privacy obligations. Check that a replacement device can be enrolled quickly and that staff have a documented process for reporting damage, theft or suspicious activity.

Australian Privacy Principles should be considered when collecting location, login and usage data. Explain what is monitored, why it is collected and who can access it. Location tracking may be justified for fleet security or asset recovery, but broad monitoring of workers can create trust and compliance concerns. Involve privacy, HR and workplace representatives before enabling extensive reporting.

Also test accessibility and practical usability. Small buttons, short session timeouts or repeated multifactor prompts can slow down a busy café team in Melbourne or a public-facing service desk in Adelaide. The best security policy is one workers can follow consistently without resorting to workarounds.

Operate And Improve The Environment

After the pilot, expand by site or department rather than enrolling every shared device at once. Monitor enrolment status, compliance, application installation, battery health and last check-in time. Create dashboards or alerts for devices that have not connected within an expected period.

Use smart groups to automate changes. Devices can be assigned policies based on operating system, model, location, ownership or compliance state. For example, a rugged scanner at a Perth distribution centre may receive warehouse applications and a restricted Wi-Fi profile, while an iPad at a Sydney clinic receives clinical software and a different certificate.

Establish a regular maintenance routine. Review unused applications, expired certificates, outdated operating systems, inactive accounts and devices that have not checked in. Coordinate updates with operational managers so patching does not interrupt school terms, retail promotions or seasonal logistics peaks.

Document the reset and replacement process. A technician should know how to retire a damaged device, remove it from Apple Business Manager or another provisioning service when necessary, issue a replacement and confirm that old access tokens are revoked. Keep asset records aligned with the management console and finance system.

Use reporting to improve the service over time. High numbers of failed logins may indicate an identity problem, while frequent device wipes may point to an overly aggressive timeout. Review support tickets alongside console data, and adjust the user experience without weakening data protection. AirWatch’s pricing and package information, customer stories and advertised 30-day free trial can help an organisation assess the platform before expanding its deployment.

A well-designed shared-device environment gives each worker the access they need while keeping sessions separate and corporate information controlled. Begin with a small pilot, document the operating model, test handovers in real Australian conditions and then scale through smart groups and repeatable profiles. Explore the available AirWatch capabilities and use the 30-day trial to validate enrolment, identity, application delivery and secure session cleanup before committing to a wider rollout.