Ivanti User Workspace Manager is a comprehensive workspace management solution that enables IT teams to deliver personalized, secure, and responsive desktop experiences across Windows-based physical, virtual, and cloud desktops. It simplifies desktop administration by eliminating complex logon scripts and Group Policy Objects (GPOs), providing just-in-time personalization for fast logon times, and enhancing endpoint security through application control and role-based access. The solution includes three core modules—Environment Manager, Application Control, and Performance Manager—managed via a centralized Management Center. It supports seamless Windows migrations, Office 365 optimization, and secure file synchronization, reducing IT costs and improving user productivity. Ivanti User Workspace Manager is particularly suited for organizations transitioning to cloud-based management, offering flexibility for on-premises, hybrid, or cloud deployments, making it a modern alternative to the discontinued Ivanti Workspace Control
- Architecture:
- Components:
- Management Center: Centralized framework for managing Environment Manager, Application Control, and Performance Manager across the enterprise.
- Environment Manager: Handles on-demand profile management and contextual policy control.
- Application Control: Enforces application security via Trusted Ownership, whitelisting, and privilege management.
- Performance Manager: Optimizes resource allocation to ensure responsive desktops.
- Deployment Agent: Lightweight agent on endpoints for communication with Management Center.
- Console: Desktop or web-based interface for configuration and administration.
- Deployment Options:
- On-Premises: Management Center and database hosted locally.
- Hybrid: Combines on-premises agents with cloud-based management via Ivanti Neurons.
- Cloud-Native: Fully hosted on AWS or Azure for scalability.
- Scalability: Supports tens of thousands of endpoints; scales with clustered Management Center servers.
- Operation Mode: Agent-based for full functionality; supports Evaluation (local) and Advanced (centralized) modes.
- Components:
- Supported Platforms:
- Endpoints: Windows 10/11 (Enterprise, Pro), Windows Server 2016/2019/2022 (for VDI/RDS).
- Virtual Desktops: Citrix Virtual Apps and Desktops, VMware Horizon, Microsoft Azure Virtual Desktop.
- Cloud: AWS, Azure, Google Cloud for desktop delivery and management.
- Note: Not recommended for mission-critical servers (e.g., Domain Controllers) due to agent hooks and drivers.
- Discovery and Personalization:
- Methods: Agent-based profile capture, real-time user context analysis (e.g., location, device, role).
- Capabilities: Tracks user settings, files, and application preferences; syncs across devices.
- On-Demand Profiles: Streams user profiles just-in-time, eliminating roaming profile issues (e.g., bloat, corruption).
- Authentication:
- Integration: Active Directory, Azure AD, Okta, SAML 2.0 for SSO.
- Access Control: Role-based access for users and admins; supports MFA for console access.
- Privilege Management: Elevates application rights without granting admin privileges to users.
- Policy Management:
- Environment Manager Policy: Applies contextual policies (e.g., based on IP, time, device) without GPOs.
- Multi-Threaded Logon Engine: Executes context-aware actions simultaneously at logon for faster performance.
- Triggers: Conditions-based actions (e.g., apply settings if user is remote).
- Application Control:
- Trusted Ownership: Allows only admin-installed apps to run, blocking unauthorized executables.
- Whitelisting/Blacklisting: Simplified management without extensive lists.
- License Compliance: Tracks software usage to optimize licensing.
- Performance Optimization:
- Resource Management: Controls CPU-intensive apps, reallocates resources dynamically.
- User Density: Increases VDI/RDS session capacity by optimizing performance.
- Process Control: Stops runaway processes to maintain desktop responsiveness.
- File Synchronization:
- File Director: Syncs user files to on-premises or cloud storage (OneDrive, Google Drive) in real-time, on-demand, or in the background.
- Migration: Simplifies file migration during OS upgrades or hardware refreshes.
- Data Sprawl: Centralizes user files to prevent scattered data across devices.
- Integrations:
- Ivanti Ecosystem: Ivanti Policy Secure (NAC), Endpoint Manager, Neurons for UEM, Connect Secure (VPN).
- Third-Party: Microsoft SCCM, Intune, ServiceNow, Splunk, Citrix, VMware, Palo Alto Networks.
- APIs: REST APIs for custom integrations; syslog for event logging.
- Cloud Storage: OneDrive for Business, Google Drive for file sync.
- Visibility and Reporting:
- Dashboards: Real-time views of user sessions, application usage, and performance metrics.
- Reports: Customizable for compliance, license usage, and user experience.
- Personalization Operations: Web console for managing personalization data.