Tagarchief: appsense

Ivanti Workspace Control vs User Workspace Manager Matrix

Now that the acquisition off RES Software is more and more adopted and spotted a place on the calendar off most IT departments it’s time to share some experience from the field.

Things that keep IT Manager awake are how to migrate their Workspace(s) to a new Workspace Management tool like UWM. Best option could be to wait until a refresh off the current workspace environment or infrastructure is needed or already planned on the IT calendar.

The other thing they struggle with is the adoption off other Workspace Management tools (Like UWM) in their environment, RES Workspace Manager (Ivanti Workspace Control) is very intuitive and easily adopted by (new) admins. If you want your admins to do the same tasks using UWM they will need training!

Don’t worry. I can advise you about the best choice(s) for your situation or help your team to migrate your workspace(s). See my contact page about how to contact me.

Another important thing that’s on their list is to find out if UWM can do the same thing for their Workspaces? Don’t worry, that’s why I created this Workspace Control (RES) vs User Workspace Manager (Appsense) table for you.

Workspace Control (RES) vs UWM (Appsense)

Item Description Workspace Control (RES) UWM (AppSense)
Desktop Composition
Logon Script Replacement UI removes the need to use VBS or PowerShell YesYes
Manage and Deploy Group Policy settings Yes Yes
Desktop Icons Manage items on the desktopYes Yes
Session and Environment Variables Manage session and environment variablesYes Yes
Printers Map printers, drivers, set default printer, save printer preferencesYesYes
Configure Start Menu Manage the Start MenuYes Yes (Except Tiles)
Pinned items Pin items on Taskbar or StartmenuYesNo
Manage Tiles in Startmenu Manage tiles in startmenuYesNo
Trigger on logon, logoff, process start/stop, connect/disconnect Yes Yes
Pre-session trigger Actions can be run early in logon process for settings like DPI and session timeouts No Yes
Desktop Created trigger Logon actions can be delayed until after the Windows desktop is visible to the user Yes – “after logon” Yes
Computer Start and Stop Non-session triggers YesYes
Additional configuration Triggers Configure settings during User Workspace SessionConnectivity Change, Session Reconnect, Session Refresh by admin or user.Lock, Unlock, Network Ready, Connectivity Change
Contextual Configuration rules Set configuration based on Workspace ContextYes Yes
Parallel Processing Fast logons as agent runs actions in parallel Most Composition actions can be set to start in a new thread All actions can run in parallel using a configurable thread pool
Real-time configuration changes on desktops Applied config can be applied immediately to clients workspace?Yes (Refresh Workspace)Partial, Best practice is to delay config changes to next logon
Desktop Refresh Update desktop with new settings without a logoff/logonYesNo
Target configurations at user groups or devices Configurations Settings for groups or devicesYesYes
Configuration Rollback Version control and approval workflowYes (buildingblocks per changed item)Yes (Config files with all last changes)
Configuration distribution methodScale-out vs scale-up Relay Servers for > 3k endpoints, or low bandwidth sitesAdd more IIS servers
Profile Management
Profile Storage to (SMB) File Share Persist user settings using SMB file shares as storage Yes Yes
Saves profiles in native Windows format YesYes
Profile rollback/reset Allow Servicedesk, Admin or user(s) to rollback Profile Settings.Yes Yes
End user Self Service Allow user(s) to use Self Service Yes Yes
Central reporting Yes Yes
Personalization Analysis Explore and edit user data in central store NoYes
Bulk changes Profile data edit/delete NoYes
API and PowerShell for managing profile data No Yes
Profile operations console for Help Desk YesYes
UWP App support Manage Windows Store appsNo Yes
Application Control
Application Whitelisting Yes Yes
App digital certificate Yes Yes
Monitor/Audit mode Used in pilot, brownfield or initial rollout Yes Yes
Metadata Support Allow/deny using app metadata such as vendor, version, etc… Yes Yes
Trusted Ownership Checking No Yes
Trusted Process Allow or deny based on parent process YesYes
Admin rights elevation and de-elevation for applications Granular control over processes that should run with admin privilege YesYes
Control elevation of child processes and common dialogs No Yes
Admin rights elevation and de-elevation for Windows components Elevate select control panels and other components No Yes
Local administrator restrictions Prevent local admins from killing services, executables, uninstall … No Yes
Self-elevation and selfauthorization Allow certain users to authorize and elevate apps and installers, with audit trail Partial - (User installed Applications)Yes
Offline change request Help desk workflow to allow installs, elevation and execution for offline users over the phone No Yes
URL Control Yes Yes
Per Device Application licencing Audit and limited access to device-based licencing apps like VisioYes Yes
Control over non-exe filesAllow/deny DLLs, batch Partial – executable files and DLLs Yes
macOS and Linux whitelisting Files, Folders and User Data Application control only Yes No
Robocopy functionality, with scheduled sync Yes Yes
Folder Redirection Yes Yes
Drive Mappings Yes Yes
Audit of file access YesYes
Controlled use of O365 OneDrive Storage Policy-controlled access, usage and audit No Yes
Application Performance
Thread throttling Temporarily clamp CPU usage by rogue threads No Yes
Memory trimming Reclaim unused allocated memory Yes Yes
CPU base priority change Moves problem threads to lower priority Yes Yes
CPU smart scheduling Replaces Windows CPU scheduler No Yes
Contextual control over performance features Condition Engine targets performance controls Yes Yes
Deployment or “push” of agents Without 3 rd party solution YesYes
Integration with SCCMAgents and configurationsYesYes
Scriptable interface Script a workspace configuration without console or UI YesYes
Configuration snippets Yes Yes
Integration with Ivanti Automation Yes No
Integration with Ivanti (RES) Identity Director Yes No
App-V deployment to desktops Initiate package streaming Yes No
App-V application configuration and personalisation Ability to customise and personalise SCCM delivered applications Yes Yes
SCCM application deployment to desktop Initiate package installs Yes No
SCCM application configuration and personalisation Ability to customise and personalise applications delivered by SCCM Yes Yes
Application UI lockdown Remove edit boxes, restrict access to WinForms and buttons within applications No Yes
USB control YesYes
File Save control Prevent and restrict users from saving files or file types to local drives YesNo
Auditing Database Event log, CSV file, SCOM pack, Database
Logon Analysis Workspace Analysis web console EmMon and LogParser tools
VDX integrationVDX (Reverse seamless) application management from Workspace console YesNo
Manage Workspace with multiple admins at the same timeBuild new environment with multiple Workspace Admins at the same timeYesNo (Config file is locked when admin configures settings)
Intuïtieve ConsoleWorkspace management config is easy adopted by new adminsYes (Application Centric Approach)No (Multiple consoles needed for configuring single application)