---
title: Workspace ONE UEM Integration Kit
description: The Workspace ONE UEM Integration Kit allows PingFederate to integrate with Workspace ONE (formerly known as AirWatch).
component: workspaceone-uem
page_id: workspaceone-uem::pf_workspaceone_uem_ik
canonical_url: https://docs.pingidentity.com/integrations/workspaceone-uem/pf_workspaceone_uem_ik.html
revdate: July 9, 2025
section_ids:
  features: Features
  components: Components
  intended-audience: Intended audience
  system-requirements: System requirements
---

# Workspace ONE UEM Integration Kit

The Workspace ONE UEM Integration Kit allows PingFederate to integrate with Workspace ONE (formerly known as AirWatch).

## Features

* Make policy decisions based on the security posture of employees' devices.

* Mitigate the risks that come with allowing employees' mobile and desktop devices to access corporate resources.

## Components

* Workspace ONE IdP Adapter

  Allows PingFederate to communicate with the Workspace ONE API.

## Intended audience

This document is intended for PingFederate administrators.

If you need help during the setup process, see the following resources:

* The following sections of the PingFederate documentation:

  * [Identity provider SSO configuration](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/pf_ident_provid_sso_config.html)

  * [Managing IdP adapters](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/pf_managing_idp_adapters.html)

  * [Authentication policies](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/pf_authentication_policies.html)

  * [Policy contracts](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/pf_policy_contracts.html)

  * [SP connection management](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/pf_sp_connect_management.html)

* If you want to use Workspace ONE to manage the PingID app on devices, refer to [Configure Workspace ONE UEM for PingID](https://docs.pingidentity.com/pingid/pingid_service_management/pid_configuring_workspace_one_uem.html) in the PingID documentation.

## System requirements

* PingFederate 9.0 or later.

* The X.509 Certificate Integration Kit, deployed in PingFederate.

* An on-premise or cloud deployment of the Workspace ONE platform.

* The Workspace ONE certificate authority (CA) root certificate, installed in the PingFederate trust store.

  You can find help in [Manage trusted certificate authorities](https://docs.pingidentity.com/pingfederate/latest/administrators_reference_guide/help_certmanagementtasklet_trustedcas_certmanagementstate.html) in the PingFederate documentation.

* A device enrolled with Workspace ONE that you can use to test your configuration.

* The following mobile single sign-on requirements:

  * A web controller, to allow the application to read the certificate from the device:

    * Android

      Chrome 45 or later and Chrome Custom Tabs.

    * Apple

      iOS9 or later and Safari View Controller.

  * AppAuth, to share sessions between supported mobile apps.
