IP Library Granted Patent US 11,573,806
Granted Patent B2
US 11,573,806 · App. 16/898,818 · Granted Feb 7, 2023

Managing persistent enrollment of a user device

Inventors: Rupesh Jain (Atlanta, GA); Kishore Krishnakumar (Atlanta, GA); Vijay Chari Narayan (Atlanta, GA); Ameya Jambavalikar (Cumming, GA)
Assignee: VMware, Inc.
G06F9/4451G06F9/4401
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,573,806
App. No.
16/898,818
Granted
Feb 7, 2023
Kind
B2
Abstract

Systems and methods are included for managing persistent enrollment of a user device. The persistent enrollment can be controlled by an administrator at an administrator console. The administrator can enable or disable persistent enrollment for the user device at the admin console. A deployment agent can be provided to the user device. During the boot process, the deployment agent can verify the persistent enrollment status of the user device. The deployment agent can retrieve and install a software package for a management agent. The management agent can enroll the user device with an enterprise under a staging user profile. The management agent can install a provisioning package associated with the staging user profile. The management agent can receive user input login credentials. The management agent can change the ownership of the user device with the enterprise. The management agent can configure the user device for the user profile.

Claims (70)

1. A method for persistent enterprise device enrollment, comprising:

verifying, by a deployment agent installed in a booting firmware of a user device, that persistent enrollment is enabled for the user device during a booting process of the user device;

pausing the booting process for an operating system (“OS”) loading on the user device;

receiving an address for an enrollment provisioning package;

retrieving, using the address, the enrollment provisioning package, the enrollment provisioning package including a software package for a management agent; and

installing the management agent on the user device, whereupon the management agent completes enrollment of the user device with a Unified Endpoint Management System (“UEMS”) by performing stages comprising:

configuring the user device using a staging user profile included the enrollment provisioning package;

in response to the configuring being completed, resuming the booting process to provide a user login prompt;

receiving user login credentials via the user login prompt;

retrieving, using the user login credentials, a user profile associated with the user login credentials; and

configuring the user device using policies and configuration settings included in the user profile.

2. The method of claim 1 , wherein the deployment agent verifying that persistent enrollment is enabled for the user device comprises providing, to an enrollment server, a hardware identifier associated with the user device and a user identifier associated with the staging user profile, the hardware identifier and the user identifier being previously provided to the enrollment server by an administrator console.

3. The method of claim 1 , wherein the management agent completing enrollment of the user device with the UEMS comprises

changing ownership of the user device with the UEMS to a user profile associated with the log in credentials.

4. The method of claim 1 , the stages further comprising:

verifying with the UEMS that the user device is still opted in for persistent enrollment; and

in an instance where the verification indicates that the user device is not opted in for persistent enrollment, executing a security protocol.

5. The method of claim 4 , wherein the security protocol includes at least one selected from:

uninstalling the deployment agent;

removing all applications and data files associated with the enterprise; and

restoring the user device to its factory settings.

6. The method of claim 4 , wherein the user device is not opted in for persistent enrollment as a result of an administrator console disabling persistent enrollment of the user device.

7. The method of claim 1 , wherein the booting firmware is a Basic Input/Output System (“BIOS”).

8. A non-transitory, computer-readable medium containing instructions that, when executed by a hardware-based processor, performs stages for persistent enterprise device enrollment, the stages comprising:

verifying, by a deployment agent installed in a booting firmware of a user device, that persistent enrollment is enabled for the user device during a booting process of the user device;

pausing the booting process for an operating system (“OS”) loading on the user device;

receiving an address for an enrollment provisioning package;

retrieving, using the address, the enrollment provisioning package, the enrollment provisioning package including a software package for a management agent; and

installing the management agent on the user device, whereupon the management agent completes enrollment of the user device with a Unified Endpoint Management System (“UEMS”) by performing stages comprising:

configuring the user device using a staging user profile included the enrollment provisioning package;

in response to the configuring being completed, resuming the booting process to provide a user login prompt;

receiving user login credentials via the user login prompt;

retrieving, using the user login credentials, a user profile associated with the user login credentials; and

configuring the user device using policies and configuration settings included in the user profile.

9. The non-transitory, computer-readable medium of claim 8 , wherein the deployment agent verifying that persistent enrollment is enabled for the user device comprises providing, to an enrollment server, a hardware identifier associated with the user device and a user identifier associated with the staging user profile, the hardware identifier and the user identifier being previously provided to the enrollment server by an administrator console.

10. The non-transitory, computer-readable medium of claim 8 , wherein the management agent completing enrollment of the user device with the UEMS comprises

changing ownership of the user device with the UEMS to a user profile associated with the log in credentials.

11. The non-transitory, computer-readable medium of claim 8 , the stages further comprising:

verifying with the UEMS that the user device is still opted in for persistent enrollment; and

in an instance where the verification indicates that the user device is not opted in for persistent enrollment, the user device executing a security protocol.

12. The non-transitory, computer-readable medium of claim 11 , wherein the security protocol includes at least one selected from:

uninstalling the deployment agent;

removing all applications and data files associated with the enterprise; and

restoring the user device to its factory settings.

13. The non-transitory, computer-readable medium of claim 11 , wherein the user device is not opted in for persistent enrollment as a result of an administrator console disabling persistent enrollment of the user device.

14. The method of claim 8 , wherein the booting firmware is a Basic Input/Output System (“BIOS”).

15. A system for persistent enterprise device enrollment, comprising:

a memory storage including a non-transitory, computer-readable medium comprising instructions; and

a computing device including a hardware-based processor that executes the instructions to carry out stages comprising:

verifying, by a deployment agent installed in a booting firmware of a user device, that persistent enrollment is enabled for the user device during a booting process of the user device;

pausing the booting process for an operating system (“OS”) loading on the user device;

receiving an address for an enrollment provisioning package;

retrieving, using the address, the enrollment provisioning package, the enrollment provisioning package including a software package for a management agent; and

installing the management agent on the user device, whereupon the management agent completes enrollment of the user device with a Unified Endpoint Management System (“UEMS”) by performing stages comprising:

configuring the user device using a staging user profile included the enrollment provisioning package;

in response to the configuring being completed, resuming the booting process to provide a user login prompt;

receiving user login credentials via the user login prompt;

retrieving, using the user login credentials, a user profile associated with the user login credentials; and

configuring the user device using policies and configuration settings included in the user profile.

16. The system of claim 15 , wherein the deployment agent verifying that persistent enrollment is enabled for the user device comprises providing, to an enrollment server, a hardware identifier associated with the user device and a user identifier associated with the staging user profile, the hardware identifier and the user identifier being previously provided to the enrollment server by an administrator console.

17. The system of claim 15 , wherein the management agent completing enrollment of the user device with the UEMS comprises

changing ownership of the user device with the UEMS to a user profile associated with the log in credentials.

18. The system of claim 15 , the stages further comprising:

verifying with the UEMS that the user device is still opted in for persistent enrollment; and

in an instance where the verification indicates that the user device is not opted in for persistent enrollment, the user device executing a security protocol.

19. The system of claim 18 , wherein the security protocol includes at least one selected from:

uninstalling the deployment agent;

removing all applications and data files associated with the enterprise; and

restoring the user device to its factory settings.

20. The system of claim 18 , wherein the user device is not opted in for persistent enrollment as a result of an administrator console disabling persistent enrollment of the user device.

Assignments (4)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0395 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 11, 2020
From: JAIN, RUPESH; KRISHNAKUMAR, KISHORE; NARAYAN, VIJAY; JAMBAVALIKAR, AMEYA
To: VMWARE, INC.
Reel/Frame 052908/0740 →