IP Library Granted Patent US 11,108,886
Granted Patent B2
US 11,108,886 · App. 16/911,966 · Granted Aug 31, 2021

Remote provisioning and enrollment of enterprise devices with on-premises domain controllers

Inventors: Chase Bradley (Atlanta, GA); Kevin Jones (Atlanta, GA)
Assignee: AIRWATCH, LLC
H04L67/34H04L12/4633H04L12/4641H04L41/046H04L41/0806H04L41/0816H04L61/1511H04L63/0272H04L63/0823H04L67/306H04L67/42H04W12/06H04W12/35
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,108,886
App. No.
16/911,966
Granted
Aug 31, 2021
Kind
B2
Abstract

An agent application executing on a client device retrieves an execute command from a command queue managed by a server and retrieves certificates and configuration settings for establishing a virtual private network (VPN) connection. An enrollment application resident on the client device executes in response to the execute command to modify a network setting of a network interface card (NIC) of the client device and establish a VPN connection with a domain controller located within the corporate domain using the certificate and configuration settings. The enrollment application further transmits a request over the VPN connection to the domain controller to join the corporate domain, wherein a corporate account in a directory service is established for the client device; reverts back to the prior network setting of the NIC and terminates the VPN connection and reboots the client device.

Claims (52)

1. A method, comprising:

determining that a client device located outside a corporate domain lacks an application native to an operating system of the client device with a programming interface that supports direct communication with the client device for remotely initiating execution of an application that remotely adds the client device to the corporate domain;

in response to determining that the client device lacks the application, placing an enrollment application and virtual private network (VPN) settings in a command queue associated with the client device, wherein the enrollment application is configured to:

establish a VPN connection with a domain controller located within the corporate domain using the VPN settings, the domain controller being configured to process login requests to the corporate domain;

transmit a request over the VPN connection to the domain controller to join the corporate domain, wherein a corporate account in a directory service is established for the client device;

configure the corporate account;

perform an interactive login with the domain controller using credentials of the corporate account;

in response to a successful interactive login with the domain controller, cache a user profile associated with the corporate account; and

terminate the VPN connection; and

transmitting an instruction to the client device to retrieve the enrollment application and the VPN settings from the command queue associated with the client device.

2. The method of claim 1 , further comprising:

receiving a notification from a domain controller within the corporate domain relating to addition of a new directory service account for the client device; and

in response to the notification, associating the client device with an organizational group for a management service.

3. The method of claim 1 , further comprising determining that the client device complies with at least one compliance policy, wherein placing the enrollment application and the VPN settings in the command queue occurs in response to determining that the client devices complies with the at least one compliance policy.

4. The method of claim 1 , wherein the enrollment application further comprises authentication certificates for the client device.

5. The method of claim 1 , wherein the enrollment application further comprises one or more client device credentials.

6. A system, comprising:

a computing device comprising a processor and a memory; and

machine-readable instructions stored in the memory that, when executed by the processor, cause the computing device to at least:

determine that a client device located outside a corporate domain lacks an application native to an operating system of the client device with a programming interface that supports direct communication with the computing device for remotely initiating execution of an application that remotely adds the client device to the corporate domain;

in response to a determination that the client device lacks the application, placing an enrollment application and virtual private network (VPN) settings in a command queue associated with the client device, wherein the enrollment application is configured to:

establish a VPN connection with a domain controller located within the corporate domain using the VPN settings, the domain controller being configured to process login requests to the corporate domain;

transmit a request over the VPN connection to the domain controller to join the corporate domain, wherein a corporate account in a directory service is established for the client device;

configure the corporate account;

perform an interactive login with the domain controller using credentials of the corporate account;

in response to a successful interactive login with the domain controller, cache a user profile associated with the corporate account; and

terminate the VPN connection; and

transmit an instruction to the client device to retrieve the enrollment application and the VPN settings from the command queue associated with the client device.

7. The system of claim 6 , wherein the machine-readable instructions, when executed by the processor, further cause the computing device to at least:

receive a notification from a domain controller within the corporate domain relating to addition of a new directory service account for the client device; and

in response to the notification, associate the client device with an organizational group for a management service executing on the computing device.

8. The system of claim 6 , wherein the machine-readable instructions, when executed by the processor, further cause the computing device to determine that the client device complies with at least one compliance policy, wherein placement of the enrollment application and the VPN settings in the command queue occurs in response to a determination that the client devices complies with the at least one compliance policy.

9. The system of claim 6 , wherein the enrollment application further comprises authentication certificates for the client device.

10. The system of claim 6 , wherein the enrollment application further comprises one or more client device credentials.

11. A non-transitory, computer-readable medium comprising machine-readable instructions that, when executed by a processor of a computing device, cause the computing device to at least:

determine that a client device located outside a corporate domain lacks an application native to an operating system of the client device with a programming interface that supports direct communication with the computing device for remotely initiating execution of an application that remotely adds the client device to the corporate domain;

in response to a determination that the client device lacks the application, placing an enrollment application and virtual private network (VPN) settings in a command queue associated with the client device, wherein the enrollment application is configured to:

establish a VPN connection with a domain controller located within the corporate domain using the VPN settings, the domain controller being configured to process login requests to the corporate domain;

transmit a request over the VPN connection to the domain controller to join the corporate domain, wherein a corporate account in a directory service is established for the client device;

configure the corporate account;

perform an interactive login with the domain controller using credentials of the corporate account;

in response to a successful interactive login with the domain controller, cache a user profile associated with the corporate account; and

terminate the VPN connection; and

transmit an instruction to the client device to retrieve the enrollment application and the VPN settings from the command queue associated with the client device.

12. The non-transitory, computer-readable medium of claim 11 , wherein the machine-readable instructions, when executed by the processor, further cause the computing device to at least:

receive a notification from a domain controller within the corporate domain relating to addition of a new directory service account for the client device; and

in response to the notification, associate the client device with an organizational group for a management service executing on the computing device.

13. The non-transitory, computer-readable medium of claim 11 , wherein the machine-readable instructions, when executed by the processor, further cause the computing device to determine that the client device complies with at least one compliance policy, wherein placement of the enrollment application and the VPN settings in the command queue occurs in response to a determination that the client devices complies with the at least one compliance policy.

14. The non-transitory, computer-readable medium of claim 11 , wherein the machine-readable instructions, when executed by the processor, further cause the computing device to establish a VPN connection between the client device and a domain controller, wherein the VPN connection is based at least in part on the VPN settings placed in the command queue.

15. The non-transitory, computer-readable medium of claim 11 , wherein the enrollment application further comprises authentication certificates for the client device.

16. The method of claim 1 , further comprising establishing a VPN connection between the client device and the domain controller, wherein the VPN connection is based at least in part on the VPN settings placed in the command queue.

17. The system of claim 6 , wherein the machine-readable instructions, when executed by the computing device, further cause the computing device to at least establish a VPN connection between the client device and a domain controller, wherein the VPN connection is based at least in part on the VPN settings placed in the command queue.

Assignments (2)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: AIRWATCH LLC
To: OMNISSA, LLC
Reel/Frame 068327/0670 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
Cited By (1)
US 12,443,729