IP Library Granted Patent US 10,911,299
Granted Patent B2
US 10,911,299 · App. 16/419,354 · Granted Feb 2, 2021

Multiuser device staging

Inventor: Adam Hardy (Alpharetta, GA)
Assignee: AirWatch LLC
H04L41/0806H04L47/20H04L47/808H04L67/22H04L67/34H04L41/0893H04L67/306
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,911,299
App. No.
16/419,354
Granted
Feb 2, 2021
Kind
B2
Abstract

Disclosed are various embodiments for staging client devices that allow for multiple user access. A computing device retrieves a current version of the list of user profiles associated with the client device. The computing device determines that the current list of user profiles differs from a previous version of the list of user profiles associated with the client device. The computing device identifies a list of policies to be sent to a management component executing on the client device based at least in part on a determination that the current list of user profiles differs from the previous version, wherein the list of policies comprises at least one policy that is associated with at least one user profile included in the current list of user profiles that is absent from the previous version of the list of user profiles. The computing device then sends the list of policies to the management component executing on the client device.

Claims (54)

1. A non-transitory computer-readable medium embodying a program executable in a computing device, wherein the program is configured to cause the computing device to at least:

initiate a profile synchronization for a client device by transmitting a request for a current version of a list of user profiles associated with the client device;

receive the current version of the list of user profiles associated with the client device in an instance in which the request has been transmitted;

remove at least one of a staging user profile or an unmanaged user profile identified in the current version of the list of user profiles;

update a list of policies to be sent to a management component executing on the client device in an instance in which the staging user profile or the unmanaged user profile has been removed from the current version of the list of user profiles, the list of policies comprising at least one policy that is associated with at least one user profile included in the current version of the list of user profiles that is absent from a previous version of the list of user profiles, the at least one policy specifying a limitation imposed on an operation of the client device; and

transmit the list of policies to the management component executing on the client device, wherein transmitting the list of policies causes the management component to enforce the limitation on the operation of the client device.

2. The non-transitory computer-readable medium of claim 1 , wherein the program is further configured to cause the computing device to at least:

identify the at least one of the staging user profile or the unmanaged user profile in the current version of the list of user profiles based on a profile type associated with at least one profile in the list of user profiles.

3. The non-transitory computer-readable medium of claim 1 , wherein transmitting the list of policies to the management component executing on the client device further causes the client device to modify at least one application according to the limitation specified by the at least one policy.

4. The non-transitory computer-readable medium of claim 1 , wherein the program is further configured to cause the computing device to at least:

receive an authentication message from the client device that comprises a first user identifier; and

identify a valid login for a user profile based on the first user identifier matching a second user identifier defined in authentication data of the user profile.

5. The non-transitory computer-readable medium of claim 4 , wherein the program is further configured to cause the computing device to at least:

add the user profile to the list of user profiles associated with the client device; and

configure the user profile as a managed user profile.

6. The non-transitory computer-readable medium of claim 1 , wherein receiving the current version of the list of user profiles associated with the client device further comprises retrieving a device record associated with the client device from a database for a management system.

7. The non-transitory computer-readable medium of claim 1 , wherein the program is further configured to cause the computing device to at least:

update a status of the client device in a user interface generated by a management console.

8. A computer-implemented method, comprising:

initiating, by a computing device, a profile synchronization for a client device by transmitting a request for a current version of a list of user profiles associated with the client device;

receiving, by the computing device, the current version of the list of user profiles associated with the client device;

removing, by the computing device, at least one of a staging user profile or an unmanaged user profile identified in the current version of the list of user profiles;

updating, by the computing device, a list of policies to be sent to a management component executing on the client device in an instance in which the staging user profile or the unmanaged user profile has been removed from the current version of the list of user profiles, the list of policies comprising at least one policy that is associated with at least one user profile included in the current version of the list of user profiles that is absent from a previous version of the list of user profiles, the at least one policy specifying a limitation imposed on an operation of the client device; and

transmitting, by the computing device, the list of policies to the management component executing on the client device, wherein transmitting the list of policies causes the management component to enforce the limitation on the operation of the client device.

9. The computer-implemented method of claim 8 , further comprising:

identifying, by the computing device, the at least one of the staging user profile or the unmanaged user profile in the current version of the list of user profiles based on a profile type associated with at least one profile in the list of user profiles.

10. The computer-implemented method of claim 8 , wherein transmitting the list of policies to the management component executing on the client device further causes the client device to modify at least one application according to the limitation specified by the at least one policy.

11. The computer-implemented method of claim 8 , further comprising:

receiving, by the computing device, an authentication message from the client device that comprises a first user identifier; and

identifying, by the computing device, a valid login for a user profile based on the first user identifier matching a second user identifier defined in authentication data of the user profile.

12. The computer-implemented method of claim 11 , further comprising:

adding, by the computing device, the user profile to the list of user profiles associated with the client device; and

configuring, by the computing device, the user profile as a managed user profile.

13. The computer-implemented method of claim 8 , wherein receiving the current version of the list of user profiles associated with the client device further comprises retrieving a device record associated with the client device from a database for a management system.

14. The computer-implemented method of claim 8 , further comprising:

updating, by the computing device, a status of the client device in a user interface generated by a management console.

15. A system, comprising:

a computing device comprising a processor and a memory; and

machine readable instructions stored in the memory that, when executed by the processor, cause the computing device to at least:

initiate a profile synchronization for a client device by transmitting a request for a current version of a list of user profiles associated with the client device;

receive the current version of the list of user profiles associated with the client device in an instance in which the request has been transmitted;

remove at least one of a staging user profile or an unmanaged user profile identified in the current version of the list of user profiles;

update a list of policies to be sent to a management component executing on the client device in an instance in which the staging user profile or the unmanaged user profile has been removed from the current version of the list of user profiles, the list of policies comprising at least one policy that is associated with at least one user profile included in the current version of the list of user profiles that is absent from a previous version of the list of user profiles, the at least one policy specifying a limitation imposed on an operation of the client device; and

transmit the list of policies to the management component executing on the client device, wherein transmitting the list of policies causes the management component to enforce the limitation on the operation of the client device.

16. The system of claim 15 , wherein the machine readable instructions, when executed by the processor, further cause the computing device to at least:

identify the at least one of the staging user profile or the unmanaged user profile in the current version of the list of user profiles based on a profile type associated with at least one profile in the list of user profiles.

17. The system of claim 15 , wherein transmitting the list of policies to the management component executing on the client device further causes the client device to modify at least one application according to the limitation specified by the at least one policy.

18. The system of claim 15 , wherein the machine readable instructions, when executed by the processor, further cause the computing device to at least:

receive an authentication message from the client device that comprises a first user identifier; and

identify a valid login for a user profile based on the first user identifier matching a second user identifier defined in authentication data of the user profile.

19. The system of claim 18 , wherein the machine readable instructions, when executed by the processor, further cause the computing device to at least:

add the user profile to the list of user profiles associated with the client device; and

configure the user profile as a managed user profile.

20. The system of claim 15 , wherein receiving the current version of the list of user profiles associated with the client device further comprises retrieving a device record associated with the client device from a database for a management system.

Assignments (2)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: AIRWATCH LLC
To: OMNISSA, LLC
Reel/Frame 068327/0670 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
Continuity (2)
Continuation 14668409 · Mar 25, 2015
Related Publication 20190273657A1 · Sep 5, 2019