GlobalProtect Host Information Profile (HIP) - Identify UW-Owned/Managed Devices - Internal Version
macOS & Windows
Three checks are performed to identify potential UW-owned devices. If any check returns true, the device is assumed to be UW-owned.
- Domain is 'ad.wisc.edu'
- Device has BigFix installed and the plist/registry entry is configured to use both of the following:
- ServerName: tem.services.wisc.edu
- GatherURL: http://tem.services.wisc.edu:52311/cgi-bin/bfgather.exe/actionsite
- Device has Workspace ONE (WS1) installed and the plist/registry entry is configured to use one of the following:
- awcm1733.awmdm.com
- mdm.wisc.edu
A device certificate provided by Active Directory, MDM, or other certificate management options, could also be used. At this time no campus service is providing a consistent certificate that is automatically installed on devices.
We also explored trying to identify Cisco Secure Endpoint and Qualys as potential identifiers but were unable to identify accessible configuration settings that clearly labeled those installations as University of Wisconsin-Madison configurations.
iOS & iPadOS
There is a way to identify iOS and iPadOS devices. We have only attempted this on a test device, deployment would require coordination with the IT groups administering the devices.
The steps to accomplish this via Workspace ONE are below:
- Create a VPN Profile
- Connection Name: Name of your choosing, visible to users on their devices
- Connection Type: Custom
- Identifier: com.paloaltonetworks.globalprotect.vpn
- Server: [VPN Portal Address (Example: hiptest.vpn.wisc.edu)]
- Custom Data
- Key: tag Value: managed
- Key: ownership Value: UW-Madison
- Authentication - Keep as User Authentication: Password
Android & Linux
We have not identified a viable way to determine ownership of Android or Linux devices yet.