IP Library Granted Patent US 12,101,305
Granted Patent B2
US 12,101,305 · App. 17/015,244 · Granted Sep 24, 2024

Co-existence of management applications and multiple user device management

Inventors: Jason Roszak (Brookhaven, GA); Varun Murthy (Atlanta, GA); Shravan Shantharam (Cumming, GA); Blake Watts (St. George, UT); Kalyan Regula (Alpharetta, GA)
Assignee: Omnissa, LLC
H04L63/08G06F9/485G06F21/10G06F21/50G06F21/52G06F21/56G06F21/62H04L67/34
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,101,305
App. No.
17/015,244
Granted
Sep 24, 2024
Kind
B2
Abstract

Various examples for managing a client device having multiple enrolled user accounts thereon are described. A computing device is directed to store a mapping of a client device to a plurality of user accounts active. The computing device communicates remotely with a management application on the client device to identify an active one of the user accounts from an operating system of the client device. In response to receipt of information associated with a first one of the user accounts active on the client device, the computing device enrolls the first one of the user accounts with a management service in association with the client device. In response to receipt of information associated with a second one of the user accounts active on the client device, the computing device enrolls the second one of the user accounts with the management service in association with the client device.

Claims (47)

1. A system, comprising:

at least one server computing device; and

program instructions stored in memory and executable in the at least one server computing device that, when executed, direct the at least one server computing device to:

store, in memory, a mapping of a plurality of identifiers to a plurality of user accounts of a management service, wherein an identifier uniquely identifies both a client device identifier and an individual user identifier of the client device, wherein the client device is shared among multiple users;

communicate remotely with a management application on the client device, wherein the management application is configured to identify an active one of the user accounts of the management service based on user information obtained from an operating system of the client device using an application programming interface (API) provided by the operating system to query the operating system to identify at least one of a user login event or an active user of the operating system, wherein the user information comprises an operating system user identifier to the operating system of the client device, wherein an individual user associated with the active one of the user accounts of the management service is identified from the operating system user identifier to the operating system;

in response to receipt of an operating system identifier associated with a first one of the user accounts active on the client device, enroll the first one of the user accounts with the management service in association with the client device, wherein the management service is configured to manage operation of the client device based on the identifier associated with both the client device identifier and the individual user identifier; and

in response to receipt of an operating system identifier associated with a second one of the user accounts active on the client device, enroll the second one of the user accounts with the management service in association with the client device.

2. The system of claim 1 , wherein the mapping stored in memory comprises a user account identifier that uniquely identifies a corresponding one of the user accounts, the operating system user identifier, and a device identifier that uniquely identifies the client device.

3. The system of claim 1 , wherein the at least one server computing device is further directed to:

in an instance in which the first one of the user accounts is enrolled with the management service and the first one of the user accounts is active on the client device, manage the client device using a first configuration profile for the first one of the user accounts; and

in an instance in which the second one of the user accounts is enrolled with the management service and the second one of the user accounts is active on the client device, manage the client device using a second configuration profile for the first one of the user accounts.

4. The system of claim 1 , wherein:

the first one of the user accounts is enrolled with the management service using the identifier, wherein the identifier comprises a domain and a user handle identified from a first login of the first one of the user accounts on the client device, and a unique device identifier that uniquely identifies the client device; and

the second one of the user accounts is enrolled with the management service using a second identifier, wherein the second identifier comprises a domain and a user handle identified from a second login of the second one of the user accounts on the client device, and the unique device identifier.

5. The system of claim 4 , wherein the unique device identifier is obtained from a registry of the client device.

6. The system of claim 1 , wherein the active one of the user accounts is determined to not be a staging user account based at least in part on a current user identified from the operating system of the client device.

7. A computer-implemented method, comprising:

storing, in memory of a server computing device, a mapping of a plurality of identifiers to a plurality of user accounts of a management service, wherein an identifier uniquely identifies both a client device identifier and an individual user identifier of the client device, wherein the client device is shared among multiple users;

communicating remotely, by a server computing device, with a management application on the client device to identify an active one of the user accounts of the management service based on user information obtained from an operating system of the client device, wherein the user information comprises an operating system user identifier to the operating system of the client device using an application programming interface (API) provided by the operating system to query the operating system to identify at least one of a user login event or an active user of the operating system, wherein an individual user associated with the active one of the user accounts of the management service is identified from the operating system user identifier to the operating system;

in response to receipt of an operating system identifier associated with a first one of the user accounts active on the client device, enrolling the first one of the user accounts with the management service in association with the client device, wherein the management service is configured to manage operation of the client device based on the identifier associated with both the client device identifier and the individual user identifier; and

in response to receipt of an operating system identifier associated with a second one of the user accounts active on the client device, enrolling the second one of the user accounts with the management service in association with the client device.

8. The computer-implemented method of claim 7 , wherein the mapping stored in memory comprises a user account identifier that uniquely identifies a corresponding one of the user accounts, the operating system user identifier, and a device identifier that uniquely identifies the client device.

9. The computer-implemented method of claim 7 , further comprising:

in an instance in which the first one of the user accounts is enrolled with the management service and the first one of the user accounts is active on the client device, managing the client device using a first configuration profile for the first one of the user accounts; and

in an instance in which the second one of the user accounts is enrolled with the management service and the second one of the user accounts is active on the client device, managing the client device using a second configuration profile for the first one of the user accounts.

10. The computer-implemented method of claim 7 , wherein:

the first one of the user accounts is enrolled with the management service using the identifier, wherein the identifier comprises a domain and a user handle identified from a first login of the first one of the user accounts on the client device, and a unique device identifier that uniquely identifies the client device; and

the second one of the user accounts is enrolled with the management service using a second identifier, wherein the second identifier comprises a domain and a user handle identified from a second login of the second one of the user accounts on the client device, and the unique device identifier.

11. The computer-implemented method of claim 10 , wherein the unique device identifier is obtained from a registry of the client device.

12. The computer-implemented method of claim 7 , wherein the active one of the user accounts is determined to not be a staging user account based at least in part on a current user identified from the operating system of the client device.

13. A non-transitory computer-readable medium having program instructions stored thereon executable by at least one server computing device that, when executed, directs the at least one server computing device to:

store, in memory, a mapping of a plurality of identifiers to a plurality of user accounts of a management service, wherein an identifier uniquely identifies both a client device identifier and an individual user identifier of the client device, wherein the client device is shared among multiple users;

communicate remotely with a management application on the client device, wherein the management application is configured to identify an active one of the user accounts of the management service based on user information obtained from an operating system of the client device using an application programming interface (API) provided by the operating system to query the operating system to identify at least one of a user login event or an active user of the operating system, wherein the user information comprises an operating system user identifier to the operating system of the client device, wherein an individual user associated with the active one of the user accounts of the management service is identified from the operating system user identifier to the operating system;

in response to receipt of an operating system identifier associated with a first one of the user accounts active on the client device, enroll the first one of the user accounts with the management service in association with the client device, wherein the management service is configured to manage operation of the client device based on the identifier associated with both the client device identifier and the individual user identifier; and

in response to receipt of an operating system identifier associated with a second one of the user accounts active on the client device, enroll the second one of the user accounts with the management service in association with the client device.

14. The non-transitory computer-readable medium of claim 13 , wherein the mapping stored in memory comprises a user account identifier that uniquely identifies a corresponding one of the user accounts, the operating system user identifier, and a device identifier that uniquely identifies the client device.

15. The non-transitory computer-readable medium of claim 13 , wherein the at least one computing device is further directed to:

in an instance in which the first one of the user accounts is enrolled with the management service and the first one of the user accounts is active on the client device, manage the client device using a first configuration profile for the first one of the user accounts; and

in an instance in which the second one of the user accounts is enrolled with the management service and the second one of the user accounts is active on the client device, manage the client device using a second configuration profile for the first one of the user accounts.

16. The non-transitory computer-readable medium of claim 13 ,

wherein:

the first one of the user accounts is enrolled with the management service using the identifier, wherein the identifier comprises a domain and a user handle identified from a first login of the first one of the user accounts on the client device, and a unique device identifier that uniquely identifies the client device; and

the second one of the user accounts is enrolled with the management service using a second identifier, wherein the second identifier comprises a domain and a user handle identified from a second login of the second one of the user accounts on the client device, and the unique device identifier.

17. The non-transitory computer-readable medium of claim 16 ,

wherein:

the unique device identifier is obtained from a registry of the client device; and

the user account is determined to not be a staging user account based at least in part on a current user identified from the operating system of the client device.

Assignments (3)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0242 →