IP Library Granted Patent US 11,108,831
Granted Patent B2
US 11,108,831 · App. 16/240,223 · Granted Aug 31, 2021

Machine policy configuration for managed devices

Inventors: Robert Stanley Schlotman, Jr. (Cumming, GA); Zuhaib Zakaria Abdul Zakaria Khan (Cumming, GA); Srinivasan Subramanian (Johns Creek, GA); Arnout Martijn Grootveld (Amsterdam, NL)
Assignee: VMWARE, INC.
H04L63/205H04L41/0813H04L41/0893H04L41/50H04W4/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,108,831
App. No.
16/240,223
Granted
Aug 31, 2021
Kind
B2
Abstract

Disclosed are various examples for managing and customizing policy configurations on user devices enrolled in an enterprise management service. The policy configurations can include machine policies and/or user policies. An administrator can customize a baseline including a list of policies supported by an operating system of managed user devices. A management component on the user devices can obtain the baseline specified by the administrator from a managing service and apply the policies to the user device.

Claims (30)

1. A system for machine policy enforcement, the system comprising:

a client device enrolled in a management service; and

at least one application executable in the client device, wherein the at least one application, when executed, causes the client device to:

obtain a baseline configuration file from a computing device associated with the management service, the baseline configuration file comprising a list of policies associated with an operating system of the client device, and the baseline configuration file being obtained from a command queue of the computing device; and

apply the list of policies for the client device by modifying a registry of the operating system in accordance with the list of policies.

2. The system of claim 1 , wherein a particular policy in the list of policies is a non-registry policy, and applying the particular policy further comprises generating a command-line input to apply the particular policy using a command line interface of the operating system.

3. The system of claim 1 , wherein the baseline configuration file comprises an extensible markup language (XML) document.

4. The system of claim 1 , wherein the at least one application further causes the client device to at least detect a change to the registry that differs from a policy included in the list of policies.

5. The system of claim 4 , wherein the at least one application further causes the client device to at least reapply the baseline configuration file in an instance in which the change is detected.

6. The system of claim 1 , wherein the list of policies include Group Policy settings.

7. The system of claim 1 , wherein the baseline configuration file specifies a schedule associated with a deployment of the baseline configuration file.

8. A computer-implemented method for machine policy enforcement, comprising:

obtaining, by a client device, a baseline configuration file from a computing device associated with a management service, the baseline configuration file comprising a list of policies associated with an operating system of the client device, and the baseline configuration file being obtained from a command queue of the computing device; and

applying, by the client device, the list of policies for the client device by modifying a registry of the operating system in accordance with the list of policies.

9. The computer-implemented method of claim 8 , wherein a particular policy in the list of policies is a non-registry policy, and applying particular policy further comprises generating a command-line input to apply the particular policy using a command line of the operating system.

10. The computer-implemented method of claim 8 , wherein the baseline configuration file comprises an extensible markup language (XML).

11. The computer-implemented method of claim 8 , further comprising detecting a change to the registry that differs from a policy in the list of policies.

12. The computer-implemented method of claim 11 , further comprising reapplying the baseline configuration file in an instance in which the change is detected.

13. The computer-implemented method of claim 8 , wherein the list of policies comprises a plurality of Group Policy settings.

14. The computer-implemented method of claim 8 , wherein the baseline configuration file specifies a schedule associated with a deployment of the baseline configuration file.

15. A non-transitory computer-readable medium embodying a program executable in a client device, wherein when executed, the program causes the client device to at least:

obtain a baseline configuration file from a computing device associated with a management service, the baseline configuration file comprising a list of policies associated with an operating system of the client device, and the baseline configuration file being obtained from a command queue of the computing device; and

apply the list of policies for the client device by modifying a registry of the operating system in accordance with the list of policies.

16. The non-transitory computer-readable medium of claim 15 , wherein a particular policy in the list of policies is a non-registry policy, and applying particular policy further comprises generating a command-line input to apply the particular policy using a command line of the operating system.

17. The non-transitory computer-readable medium of claim 15 , wherein the baseline configuration file comprises an extensible markup language (XML).

18. The non-transitory computer-readable medium of claim 15 , wherein, when executed, the program further causes the client device to at least:

detect a change to the registry that differs from a policy in the list of policies; and

reapply the baseline configuration file in an instance in which the change is detected.

19. The non-transitory computer-readable medium of claim 15 , wherein the list of policies comprises a plurality of Group Policy settings.

20. The non-transitory computer-readable medium of claim 15 , wherein the baseline configuration file specifies a schedule associated with a deployment of the baseline configuration file.

Assignments (4)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0314 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 4, 2019
From: SCHLOTMAN, ROBERT STANLEY, JR.; KHAN, ZUHAIB ZAKARIA ABDUL ZAKARIA; SUBRAMANIAN, SRINIVASAN; GROOTVELD, ARNOUT MARTIJN
To: VMWARE, INC.
Reel/Frame 047905/0770 →
Continuity (1)
Related Publication 20200220902A1 · Jul 9, 2020
Cited By (1)
US 12,255,894