As you might know, Microsoft Intune has quickly become one of the most popular management tools for a managing a companies fleet of devices. Dell recognizes this and has continued to work to integrate and add new tools that integrate directly within Intune so management is done through that single pane of glass.
This allows you the ability to manage & deploy Dell client BIOS settings directly within your Intune portal. You basically deploy the Endpoint Configure application to the client, create a BIOS configuration package and upload that to Intune. Once configuration is in Intune, you can then create the device configuration policy to deploy out to the devices as needed.
Here is a quick overview of what the process looks like;
Here are couple screen shots of what the configurations look like;
The latest Wyse Management Suite (WMS) 4.1 has been released and I wanted to share some great updates! This has already been rolled out via our WMS Cloud and if you run on-prem, you can download WMS 4.1 here.
If you’re new to Wyse Management Suite and just want a quick peek at it, check out our new interactive demo! You can also check out a quick 1 min video here!
Here’s a quick rundown of the key features and enhancements:
➡️ Management for ThinOS 2306 features & platform expansion
➡️ Management for Dell Hybrid Client 2.5 features & platform expansion
➡️ Management for Windows 10 IoT Enterprise LTSC 2021 (QR 2306) & platform expansion
➡️ New configuration user interface (ConfigUI) for Windows 10 IoT. Now Win10 IoT, ThinOS, and DHC share a common WMS ConfigUI proving a more modern, consistent and intuitive experience for Dell thin clients
➡️ Migrated the WMS on-premises database to the MongoDB Enterprise version, replacing the MongoDB Community version which has EOL’d (applies to both WMS Standard and Pro versions). The MongoDB Enterprise version provides better security, compliance and Enterprise-grade support.
➡️ Customer-specific requests
➡️ Bug fixes
Cloud Client Workspace: your virtual workspace reimagined!
One of the options with Wyse Management Suite (WMS) cloud or on-prem is the ability to install a remote repository to host OS images or packages. This isn’t often required, especially with ThinOS, as the images and packages can be hosted centrally in WMS cloud or the main repository as part of your on-prem install. We also can host packages in WMS cloud for Windows 10 IoT & Dell Hybrid client.
In this case, the customer wanted to convert their existing home users who are using Windows 10 IoT based thin clients to Dell ThinOS thin clients using WMS cloud. In order to do this we needed a cloud hosted repository to host this ThinOS conversation image for all the Windows 10 IoT thin clients to download the ThinOS image from. We installed the WMS repository on a Windows Server 2019 VM in Azure and synced it with our WMS cloud portal.
I wanted to outlined the WMS repository installation and Azure virtual machine configuration below.
Review the WMS repository installation prerequisites here in the WMS admin guide in order to configure your Azure, or on-prem VM installation.
2. Download the latest WMS repository installation from the WMS downloads site here
3. Install the WMS repository following the below prompts;
4. NOTE: Once the installation finishes and you click ‘Launch’ it make take 1-2 minutes for the installation to finish, close and then launch the browser, so be patient while it finishes. The WMS repository service is starting and the web page will be unavailable until it starts. You can confirm the services started by looking here:
5. Once the web pages launches, you will be brought to the registration page. Once you are here you have a few options to configure:
The URL of your WMS server
Here we have the option to “Register to Public WMS Management Portal” or specify the FQDN of your on-prem WMS server. In my case, we are going to register to WMS cloud so we will select “Register to Public WMS Management Portal” & select “us1.wysemanagementsuite.com” (or eu1. if you’re using that tenant).
The second important item is the ‘WMS Repository URL“. This will be the URL the client that is downloading the image from will connect to. In my case, since we are using WMS cloud and doing this for remote home based users, we need to make sure that WMS Repository URL resolves externally to my server and is accessible over the Internet. By default, it lists the hostname of the server.
Here I selected “us1.wysemanagementsuite.com” & changed my WMS repository URL to an FQDN that maps to my Azure WMS repository VM: hostname.vditoolbox.com
6. Once you click ‘Register’, it will connect to your WMS management server and register successfully.
7. You can confirm it registered succussfully by looking on your WMS console under Portal Administration\File Repository:
8. At this point, your WMS repository is installed and successfully connected to your WMS portal!
9. From here, in my example I downloaded the Windows 10 IoT to ThinOS conversation image to my Azure repository and synced with my WMS portal. By default, ‘Automatic Replication’ is selected but you can also click ‘Sync Files’ or ‘Check-In’ to ensure the repository is synching & checking in successfully. If you’re doing a conversion as well, you can read more here.
10. The final step is to make sure your Azure VM is accessible externally. In my example, I used hostname.vditoolbox.com that has DNS record that resolves to the public IP address of my Azure VM. I’ve included an example of the lab setup I had during testing and yours will likely be different based on network, security groups, etc.. but wanted to give you an idea.
Troubleshooting:
We initially were receiving an error when pushing the conversion image but not a smaller package. The issue turned out to be an issue with the header and we think the the very long file name compared to that of other package files and it was getting blocked. When the thin client connected to download the image, the Azure Web Application firewall was blocking the connecting and the thin client displaying the following error:
WMS Repository Server is not available or required imaging files are missing. Trying again….Number of Retry = 1
We also saw the following error right before imaging started, followed by the one above:
When we looked at the WMS WDA logs we saw the following:
18/01/2023 13:26:37.376 E 5764 6 Unable to perform http request… 18/01/2023 13:26:37.392 E 5764 6 CCMConnectionData: BaseConnectionString: https://us1.wysemanagementsuite.com:443/Mac: “b0:4f:13:bf:08:f4″OwnerId: “50359860”WyseId: “wyse3826922988332208998″AuthCode: “****”UserAgentHeader: “Stratus /4.7.5.0 (WES 10.0.17763; en-US; Wyse 5470; Revision:14.6.2.13; cls:A)” 18/01/2023 13:26:37.392 I 5764 6 WebException returned ProtocolError – The remote server returned an error: (400) Bad Request.
The Azure administrator then looked at the Azure Web Application firewall logs and saw the following:
REQUEST-920-PROTOCOL-ENFORCEMENT.conf 920450 Restricted HTTP headers: The use of certain headers is restricted. HTTP header is restricted by policy (%{MATCHED_VAR}) Pattern match ^.*$; Within Tx:restricted_headers at REQUEST_HEADERS_NAMES. /wms-repo/image/os?filePath=ThinOS_2211_9.3.3099_WES_Conversion%5CThinOS_2211_9.3.3099_WES_Conversion%5CThinOS_2211_9.3.3099_WES_Conversion\u0026fileName=commandsXml.xml
Once the Azure admin relaxed this rule, the device was able to download the image immediately.
A new Dell Wyse ThinOS enhancement to be aware of is the introduction of a ThinOS Activation License that was introduced as part of ThinOS version 2205 (version 9.3.1129) & Wyse Management Suite 3.7.
This new license is required in certain scenarios as outlined here.
In some cases, you may encounter the following message below:
“Login is denied (ThinOS activation license is not available)”
You will get this for a few reasons as outlined in the release notes here and outlined below.
ThinOS enhancements
Added ThinOS Activation devices licenses in Wyse Management Suite—The licenses must be used in the following two scenarios:
Devices that are converted from other operating systems must use the ThinOS activation licenses to enable VDI function. Without the ThinOS activation license, you cannot log in to any Broker agent on the devices. The ThinOS activation licenses are used automatically when registering to Wyse Management Suite.
For example, you bought Windows 10 IoT/Windows Embedded devices in the past and converted them to ThinOS at one point
If you bought a newer platform, i.e. Dell 3420 thin client laptop and ThinOS was NOT installed at the factory but instead onsite, then you will need the ThinOS Activation license
Non-PCoIP ThinOS clients that are upgraded from ThinOS 8.6 can use ThinOS Activation license to enable the PCoIP function. Go to Services > WDA Settings > Enable PCoIP Activation License to enable this option in ThinOS 9.x policy. Restart your device for the function to take effect
For example, you upgraded ThinOS 8.x without PCoIP and have upgraded to ThinOS 9.x and you use PCoIP with VMware Horizon
Support for Dell Wyse Latitude 3420 Thin Client
You must have ThinOS Activation devices license for Latitude 3420 to enable VDI function
This license takes effect starting with ThinOS 2205/9.3.1129 & Wyse Management Suite 3.7 as noted in the release notes here.
If you are running into this issue after upgrading to ThinOS 2205, you may need to reach out to your Dell account team to likely purchase the appropriate ThinOS Activation License if you fall into one of the categories.
Alternatively, you can roll back to prior versions of ThinOS until you identify the reason you are getting this license message & purchase the proper ThinOS activation license(s).
The new ThinOS Activation License is discussed in greater detail here, Dell ThinOS – Installation & Activation License User Guide. This document also covers installing ThinOS on newer hardware manually such as the Wyse 3420 thin client laptop IF it is not pre-loaded at the factory.
If you use WMS on prem you will need to export your ThinOS Activation License from WMS Cloud to WMS on prem server as noted here.
The latest release of Wyse Management Suite, 3.6, is out! I put together a brief summary of the installation process if installing locally on a Windows 2019/2016/2012 server. Alternatively, WMS can also be run as a hybrid cloud solution as noted here. Enjoy!
You can download Wyse Management Suite v3.6 from here along with documentation and release notes here.
Launch the installer, WMS_3.6-xxx.exe and click ‘Next’ to begin
2. Accept EULA and click ‘Next’
3. Choose Typical or Custom and be sure to check off ‘Turn off IE Enhanced Security Configuration’ then click ‘Next’. I selected Typical for this standard install.
4. Provide credentials for both database access and administrator credentials. Note: The administrator credentials will be the login credentials you’ll use to log into the WMS console.
5. I clicked ‘Next’ past this section as it’s specific to using Teradici zero clients which I’m not using. If you are, see more info at page 15 here
6. Select an option to create the WMS service account from the below options.
7. Provide credentials for the Software Vault as noted below.
8. Click ‘Next’ to accept the default security configuration
9. Select the installation and repository location as noted below
10. Once you click ‘Next’, the installation will start!!
11. Once install finishes, click ‘Launch’ at the end and a wizard will finalize the install. You can see more of these final steps here starting at Step 14.
One of the great features of Wyse Management Suite (WMS) Pro is the ability to integrate it with Active Directory so you can log into WMS using your existing Active Directory accounts.
The process is pretty straightforward as outlined in admin guides but recently working on this with a customer I wanted to document the process with some additional details that helped.
Go to ‘Portal Administration’, ‘Active Directory (AD)’
Enter your Active Directory information as outlined below:
Name: FQDN of domain controller
Domain: domain name
Server URL: ldap://ip_fqdn of domain controller
Port: 389
Once you click ‘Save’ and it’s successful, you will see the following screen:
Click on the ‘icon’ to add by either Groups, Users, and also search by OU to enumerate from AD.
You will then see your existing Groups appear below:
You could also search just for a specific Group, i.e. WMS Administrators:
You could also search just for a specific User, i.e. wyseuser: (NOTE: User account must have email associated with account in order to show up, otherwise you will get an error message while trying to import users.
You could also search by Organizational Unit (OU), i.e. Management
Once you have imported what you choose, the users will show up under the Users tab in WMS under, ‘Unassigned Admins’. Note: This may take a few minutes to show up after importing from AD.
Select the account and select ‘Edit User’:
Select ‘Roles’ and assign the appropriate role for the user:
Once complete, the user will show up under the ‘Administrator(s)’ tab:
On the WMS Portal logon screen, choose ‘Sign in with your domain credentials’ to log in with your newly imported and assigned AD user.
In some recent lab testing I ran into the following error: “CCM on-prem Server authentication token is not available in configuration file.”
I got this error when attempting to pull a Windows 10 IoT Image off a Wyse 5060 client.
The fix was to push the updated Merlin package, aka boot agent, to the device prior to capturing image.
This package is already pre-loaded in the Wyse Management Suite software and listed under “Apps & Data\App Inventory\Thin Client” – MerlinPackage_Common.exe.
You will need to create and App Policy containing this package and push to the client.
To create App Policy go to, Apps & Data\App Policies\Thin Client\Add Policy
Complete the policy using the details below:
Once policy is created, go to, “Jobs\Schedule App Policy” and create your policy similar to below:
Once the policy is pushed successfully you should now be able to pull the image!
Error details:
(Status: Failed – [ERROR: CCM on-prem Server authentication token is not available in configuration file. (error code : 107).]
[ERROR STAGE: Repository validation.]
[REASON: Configuration file is missing authentication token of on prem Server.]
[SOLUTION: Make sure config file is updated with proper CCM on prem Server authentication token.]
| (107))
Hope this helps someone else down the road!
@chris_messer ~~> Subscribe to blog to get latest updates <~~
Additional support resources as noted below:
Dell TechCenter Wyse Product Support Forums – these are a great resource for getting up and running with the solutions as well as tips and tricks for troubleshooting common issues. Once you join the Dell TechCenter community you will have a variety of resources to get started!
Wyse general forum: for discussions that, for example, span multiple categories, involve end-to-end methods, heterogeneous environments, new use cases or topics not found under the support documentation or existing discussions.
Wyse thin clients: includes Cloud Connect, Linux, Windows Embedded Standard, ThinOS and zero clients for Citrix, MultiPoint Server and VMware.
Wyse software: includes Wyse Management Suite, Wyse Device Manager, Wyse WSM and Wyse Virtualization Software
Ensure the PC you wish to convert meets the minimum requirements and pre-requisites noted here
You will also want to get access to the Wyse Management Suite software to have a centralized way to configure and manage your converted PC’s. You can get access to Wyse Management Suite by going here. Alternatively, you can manually configure the device using local GUI during testing.
Run ‘WyseConverterforPCs.exe’ on your Windows 7 or Windows 10 PC you wish to convert. Note: By default, you will get a 45 day trial license as part of the installation.
Follow the steps below for a typical installation:
After installation completes and PC reboots you will be brought to the following screen:
8. By default, Converter for PC will auto-logon as the locked down Standard User, ‘WyseUser’ as noted in step 4. In order to login as ‘WyseAdmin’ hold down ‘shift’ key and log off and you will be brought to Windows logon screen where you can select the user account you want to log in as.
default credentials
username: wyseadmin | password: DellCCCvdi
username: wyseuser | password: DellCCCvdi
9. At this point, you can begin your configuration of the Citrix client, VMware client, etc… using one of 2 methods:
10. You can access documentation Wyse Converter for PC documentation here and Wyse Management Suite documentation here.
Additional support resources as noted below:
Dell TechCenter Wyse Product Support Forums – these are a great resource for getting up and running with the solutions as well as tips and tricks for troubleshooting common issues. Once you join the Dell TechCenter community you will have a variety of resources to get started!
Wyse general forum: for discussions that, for example, span multiple categories, involve end-to-end methods, heterogeneous environments, new use cases or topics not found under the support documentation or existing discussions.
Wyse thin clients: includes Cloud Connect, Linux, Windows Embedded Standard, ThinOS and zero clients for Citrix, MultiPoint Server and VMware.
Wyse software: includes Wyse Management Suite, Wyse Device Manager, Wyse WSM and Wyse Virtualization Software
@chris_messier ~~> Subscribe to blog to get latest updates <~~