AirWatch features that make endpoint management easier
AirWatch, now part of VMware and commonly encountered through the Workspace ONE UEM portfolio, gives IT teams a central way to manage laptops, mobiles, tablets, rugged devices and other business endpoints. Its value comes from bringing configuration, security, application delivery and support into one administrative console.
For Australian organisations, that central view is especially useful when staff are spread across Sydney, Melbourne, Brisbane and Perth, or when field teams work far beyond the capital cities. A single policy can cover office workers, hybrid employees, contractors and remote crews without relying on every device being physically brought to the IT desk.
The platform has many capabilities, but administrators will gain the most from using the features that reduce repetitive work and improve visibility. The following capabilities form a practical set of priorities for businesses running a managed mobility, endpoint or bring-your-own-device programme.
Simplify enrolment and device ownership
The first useful capability is automated device enrolment. AirWatch can register corporate-owned hardware through organised enrolment programmes, while employees can receive guided steps for bringing a personal phone or tablet under management. Rules based on ownership, user group and operating system help administrators apply the right controls from the start.
Zero-touch or near-zero-touch provisioning is particularly valuable for a distributed Australian workforce. A new employee in Adelaide can receive a laptop at home, connect it to the internet and have business settings, certificates and approved applications applied without waiting for a technician. That saves travel time and makes onboarding more consistent.
Self-service enrolment also reduces pressure on a small IT team. Administrators should create clear ownership categories, enrolment restrictions and authentication requirements before opening access widely. This prevents unmanaged or outdated devices from entering the environment and provides a cleaner record for audits and asset tracking.
Apply profiles and security baselines
AirWatch profiles let administrators configure Wi-Fi, VPN, email, certificates, passcodes, restrictions and other operating-system settings from a central console. Rather than asking users to follow a long setup guide, IT can publish a tested configuration and update it when network or security requirements change.
The feature is most effective when profiles are assigned through smart groups. A finance team may need a stricter configuration than a marketing team, while warehouse scanners and executive phones may require completely different settings. Smart groups allow policies to follow business roles, locations, ownership types or device characteristics.
Australian businesses should map these settings to internal security policies and obligations under the Privacy Act and Australian Privacy Principles. Organisations influenced by the Essential Eight should also use endpoint management as part of a broader control set, rather than treating a configuration profile as a complete security strategy.
Control application delivery and updates
Application lifecycle management is another core capability. AirWatch can distribute public apps, internal line-of-business software and selected desktop applications, while administrators control which users receive each package. Required apps can be installed automatically; optional apps can be offered through an enterprise catalogue.
This approach keeps devices productive without giving every employee unrestricted access to software. Version controls, deployment rings and scheduled updates are useful for testing changes with a smaller group before releasing them across the organisation. Administrators should also monitor failed installations, storage limits and operating-system compatibility.
For teams operating on patchy connections in regional Queensland or Western Australia, staged delivery matters. Large packages can be scheduled outside peak work periods, and critical tools can be prioritised over less urgent software. A clear application catalogue also gives employees a more familiar, self-service experience.
Enforce compliance and conditional access
The compliance engine can check whether a device meets defined conditions, such as having encryption enabled, a current passcode, an approved operating-system version or no signs of compromise. When a device fails a rule, AirWatch can notify the user, quarantine the endpoint or trigger a remediation workflow.
Compliance works best when rules are proportionate. A short grace period may be appropriate for an operating-system update, while a compromised device should lose access immediately. Administrators should document who owns each rule and what happens when it is triggered, so the help desk can explain decisions consistently.
Conditional access extends this protection to business services. Access to email, files or applications can depend on user identity, device status and risk signals. This is valuable for hybrid work, where staff may connect from a home office in Newcastle, a co-working space in Melbourne or a client site in Darwin.
| Capability | Best administrative use | Practical point to monitor |
|---|---|---|
| Automated enrolment | Onboard corporate devices quickly | Ownership and authentication records |
| Profiles and policies | Apply consistent security settings | Conflicting assignments |
| Application management | Deliver and update approved software | Failed installs and licence use |
| Compliance rules | Identify risky or outdated endpoints | Remediation timing |
| Conditional access | Protect cloud services | User experience and exceptions |
| BYOD privacy controls | Separate business data from personal use | Clear employee communication |
| Content management | Provide controlled access to files | Offline copies and sharing rights |
| Remote support | Resolve issues without desk visits | Consent and support logs |
| Reporting and analytics | Track fleet health and trends | Data quality and useful metrics |
| Automation and integrations | Reduce manual administration | API permissions and workflow testing |
Separate business data on personal devices
BYOD programmes need a careful balance between security and employee privacy. AirWatch can use application-level controls, managed accounts and containerisation to separate corporate information from personal content. Administrators can then remove business data without wiping a user’s photos, messages or personal applications.
The choice between a managed container and broader native device management depends on the organisation’s risk profile, operating systems and user expectations. A useful comparison of containerisation and native management can help teams assess which model fits their programme before setting policy.
Communications are as important as technology here. Employees should know what IT can see, what it cannot see, and what happens when they leave the company. A plain-language privacy notice is more effective than dense legal wording, particularly when staff use their own phones for work.
Manage content and secure access
Mobile content management gives users a controlled way to reach business documents from approved applications and devices. IT can apply sharing restrictions, require authentication, limit copy-and-paste behaviour and remove local business files when access is withdrawn.
This capability supports teams that work away from headquarters, including health services, construction crews and professional consultants. A worker may need a current form or procedure while offline, but the organisation still needs to control how that document is stored and shared once connectivity returns.
Administrators should define retention, offline access and file-sharing rules in cooperation with records, legal and business teams. Content controls should support the way people actually work, rather than forcing users towards unapproved consumer services that are harder to monitor.
Support users remotely and automate routine work
Remote support tools can help service desk staff diagnose device problems, guide users through settings and collect relevant information without taking possession of the endpoint. This is useful when a branch is several hours from the nearest IT team or a field technician is working in an area with limited transport options.
Support access should be permission-based and logged. Users need to understand when a session starts, what the technician can view and whether control is being shared. Clear boundaries protect employee trust and create evidence for internal reviews.
Automation and integrations then remove repetitive administration. AirWatch can connect with identity services, directory platforms, certificate authorities, email systems, security tools and ticketing platforms. Workflows can create accounts, assign applications, flag non-compliant devices or close routine requests without manual copying between systems.
Use analytics to improve the endpoint estate
Dashboards and reports give administrators a view of enrolment numbers, operating-system versions, application status, compliance trends and device ownership. These metrics turn endpoint management from a reactive help-desk function into a measurable operational process.
The most useful reports answer a business question. For example, an IT manager may track how many devices can support a new security baseline, which applications generate the most failures, or how long it takes to remediate a non-compliant endpoint. Raw device counts are less valuable than trends that support a decision.
Reports should be scheduled for security, finance and leadership audiences, with access restricted to appropriate roles. Australian organisations should also consider where management data is stored, who can export it and how reporting practices align with contractual requirements and privacy expectations.
Make the platform part of daily operations
These ten capabilities work best as a connected operating model rather than isolated menu items. Enrolment establishes identity and ownership, profiles set the baseline, applications and content provide productivity, compliance protects access, and analytics show whether the controls are working. Remote support and automation keep the model manageable as the fleet grows.
Start with a defined device inventory and a small pilot group representing office staff, remote workers and any specialised field devices. Use the pilot to test enrolment, application delivery, conditional access, privacy messaging and support procedures. Once the process is stable, expand through smart groups and documented change control.
AirWatch’s fully functional 30-day free trial provides a practical way to test these workflows with representative devices and applications. Build a focused evaluation around onboarding, policy enforcement, BYOD privacy, reporting and service desk effort, then compare the results with your operational requirements before wider deployment.