Description
The VMware Workspace ONE solution for Microsoft Sentinel enables ingestion of enrolled device inventory and installed application details from Workspace ONE UEM into Microsoft Sentinel. For more information about Workspace ONE UEM and its APIs, see the official Omnissa documentation: https://developer.omnissa.com/workspace-one-uem-apis/
Underlying Microsoft Technologies used:
- Microsoft Sentinel
- Azure Monitor Logs
- Data Collection Rules (DCR)
- Codeless Connector Framework (CCF)
Dependencies:
- A valid VMware Workspace ONE UEM tenant
- Workspace ONE API credentials
- API access to device inventory and installed application endpoints
- Version
- 3.0.1
- Declared author / publisher
- Microsoft - support@microsoft.com
- Support tier
- Microsoft
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
629d1d3↗- Source identifier
azure-sentinel-solution-vmware-workspace-one
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC