Skip to main content

June 11, 2026

Troubleshooting Omnissa Workspace ONE Assist

If you are having issues with your Workspace ONE Assist performance or service, consider troubleshooting your issue before calling support.

These troubleshooting steps address the most common issues with the Workspace ONE Assist service. The problems below are grouped by category. Some problems may have more than one possible cause and solution.

Dependent Features with Omnissa Workspace ONE UEM

Workspace ONE Assist, together with Workspace ONE UEM, helps you to remotely access and troubleshoot devices in real time. Listed are some of the newly added features that depend on Workspace ONE UEM.

FeaturesUEM versionAssist versionResults (FF value = true)FeatureFlag (FF)
T10 v2>= 2204>= 22.04Connection worksName: LaunchAssistApiV2FeatureFlag Scope: global
Value: true/false
< 22.04Connection does not work (To make the connection, set FF value = False)
< 2204>= 22.04Connection works
Syslog

(*supported from)
>= 2302*>= 23.02*Audit logs/events are generatedName: AssistOAuthProvisioningFeatureFlag Scope: Tenant
Value: true/false
< 23.02No audit logs/events are generated
<2302>=23.02*No audit logs/events are generated

Pre and Post-Install General Check List

Pre InstallPost Install
Check SSL certificate expiry and install a renewed certificate.Verify the Assist URL [FQDN] access from end-user devices and other systems once the Assist application is installed.
Verify all firewall rules are correctly set, allowing the required ports and allowlisting the relevant IPs and URLs.Telnet to Connection Proctor FQDN with port from the external network to check if the port and CP Service are good
Verify TLS 1.2 is activated in the environment.Check whether the RemoteManagement command is queued or processed on the UEM console for the device in troubleshooting logs.
Ensure that the control plane domain is accessible across all Assist environments if DNS is used for service discovery.Check and collect IIS logs to check whether the endpoints are invoked from the UEM console.
Ensure the required ports are open and allowed by using the Telnet command.Check and collect Assist console logs [cmd: ALT+L].
Check NETWORK SERVICE account has read permission to the Enrollment and SSL certificate private key.Check and collect browser HAR logs to verify the request and response information to confirm the assist console establishes the connection to the AetherPal Tool Controller service.
Verify DB access from the Core server with a UDL file or Ping command.Verify all core services logs.
Make sure all the assist system time syncs with NTP server time.Verify and collect the Assist DB configurations, including server table records, services table records, tenant table records, tenant configurations table records, default service configurations table records, version table records, and service configurations table records.
Check and verify the proxy configurations if the proxy is used in the environment.Verify reserved URL ACL for AetherPalToolController service is configured or not using the NETSH command. For details, see Assist Upgrade issues.
Verify if the required ports are configured properly on the LoadBalancer/Firewall if using LoadBalancer/Firewall.Verify only one server is Active and configured in the LoadBalancer pool if Active-Passive server configuration.
Verify that SSL passthrough and session persistence are configured on the LoadBalancer. This ensures that the traffic is terminated on Server 1, and the entire session remains on the same server for subsequent connections from a device.Check and verify the SSL/Enrollment certificate thumbprint is updated correctly on the assist Apadmin database default service configurations table records and service configurations table records.
Verify the traffic is correctly pointed to the Assist server if LoadBalancer is configured.Verify Web Console Log from UEM to check the status of Assist server if any issue is faced during initial UEM pre-check steps.
Flush Memcache on UEM if configured when any issue is faced during initial UEM pre-check steps. For information, see Memcached Integration.Check the CP server SSL certificate thumbprint and make sure it is correctly updated in the Assist databases. For more information, see Update the Renewed Site Thumbprint Using AdminWebPortal.
Verify ClientAuthTrustMode=2 DWORD is configured correctly on the registry for SCHANNEL to ensure the UEM pre-check connection works fine. Verify the Assist database records [Server, Services] for duplicate entries and remove and restart the services if a Session Handle NULL error is observed.
Ensure Remote Control privacy is enabled on the UEM console to remote control a device (applicable for iOS devices only).Check and archive Anchor logs if IIS crashes.
Check and verify necessary configurations are allowed in their Firewall/LoadBalancer for FCM - Android device connections. 

Generate Certificates

Problem

While running the "Certificate Seed Script.sql" file in Step 10 of the Generate Workspace ONE Assist Certificates task, you might see an error. This error reads "The conversion of a varchar data type to a datetime data type resulted in an out-of-range value."

Possible cause

Such an error is likely the result of a difference in locale between the machine upon which the SQL script was generated and the database server on which it is being run.

Solutions

There are two possible solutions.

  • Ensure that the same date format is set in the SQL script by running the cert provisioning tool on a machine with the same locale settings as the database server.

OR (if the first solution is not possible).

  • Manually edit the date format in the SQL script. For more information about date formats, see http://www.sql-server-helper.com/tips/date-formats.aspx. References in this documentation to any specific service provider, manufacturer, company, product, service, setting, or software do not constitute an endorsement or recommendation by Omnissa. Omnissa cannot be held liable for any damages, including without limitation any direct, indirect, incidental, special, or consequential damages, expenses, costs, profits, lost savings or earnings, lost or corrupted data, or other liability arising out of or related in any way to information, guidance, or suggestions provided in this documentation.

Remote Management Not Available - Device Registration Issues

Problem - Workspace ONE Assist Link Does Not Display in Workspace ONE UEM

The "Remote Management" link does not display in the More Actions drop-down menu as seen in the Device Details View OR the device is not shown in the Device List View.

Possible cause

Registration failed or Intelligent Hub might not have been deployed properly. Intelligent Hub might have not been installed on the device properly or registration to Workspace ONE Assist Server has failed.

Solution

Attempt to re-register the device. Update the Resource portal to ensure that Intelligent Hub can be properly downloaded and installed on the device. A Workspace ONE UEM administrator must re-register the device.

Problem - Registration Check Returns Failed

The device does not register with Workspace ONE UEM or the Workspace ONE Assist portal.

Possible cause

P7b file missing root/intermediate certificates in the certificate chain. In the MMC (Microsoft Management Console) certificate console when opening the certificate, the certificate path is missing, and the certificate status displays: the issue of this certificate can not be found.

Solution

Reinstall the certificate including the intermediate and root certificates. Reinstall all the certificates for this client and ensure that the root certificate is placed into the root certificate folder and the intermediate certificate is placed in the intermediate certificate folders in the MMC certificate console.

For more information about the device registration failed error, see the knowledge base article, 'Device registration check failed' error is displayed in Workspace ONE UEM Console when initiating a remote session on enrolled devices.

Problem - Error Message, 'Registration Failed: Server Not Found'

The device does not register with Workspace ONE UEM or the Workspace ONE Assist portal.

Possible cause 1

Workspace ONE Assist Site URL capital and lower-case letters. In Workspace ONE Assist tool versions 4.4.2.6291 and prior, the URL for the remote management server is CAPS sensitive. In the example shown below, the URL uses upper-case and lower-case letters ‘https://rmSTAGE01.awmdm.com’.

Solution 1

Remove upper case characters from the Workspace ONE Assist site URL. Review the Workspace ONE Assist site configuration. You must ensure that the URL has all lower-case letters. In the example above, the URL must be ‘https://rmstage01.awmdm.com’.

Possible cause 2

The firewall is ON but misconfigured. If the firewall is incorrectly configured on the Workspace ONE Assist Server, it might be preventing device registrations from being received.

Solution 2

Turn off the firewall or set up exceptions. When the firewall is on and it is not correctly configured, it might be preventing device registrations. Devices register with the Anchor web service, hosted on port 443 on the Workspace ONE Assist server. If this port is blocked on the firewall, registrations are jeopardized. Turn off the firewall and see if registrations succeed. If they do, review the exceptions to ensure that the Anchor web service on port 443 or another port defined for this service is in the list of exceptions.

Problem - Error Message, "RM failed to register. Certificate invalid server."

Possible Cause:

The device fails to register because the Assist agent does not trust the enrollment certificate. This certificate was bundled in the Workspace ONE Assist installer up to version 20.07 and had to be updated periodically.

Note: This error does not apply to iOS.

Solution:

To resolve this error, upgrade the Workspace ONE Assist agent to v20.11 or later. If the issue persists, please contact Workspace ONE Support.

Workspace ONE Assist Agent v20.11 has removed the dependency on the deployment certificate on all platforms (Android, Windows, macOS, and iOS). Instead, the Assist Agent builds the certificate chain with the embedded root and intermediaries; and receives the deployment and leaf certificates from the Assist server. This implementation ensures that the Assist application only makes enrollment requests to a trusted Workspace ONE Assist server, and all connections are secure.

Issues Connecting to Devices

If you are having connectivity issues with your Workspace ONE Assist performance or service, consider troubleshooting your issue before calling support. These troubleshooting steps address the most common connectivity issues with the Workspace ONE Assist service.

Problem - Browser Window Does Not Open Remote Management Portal

The Workspace ONE Assist portal is not opening on the Workspace ONE UEM users’ browser window.

Possible cause 1

Incompatible web browser. The browser being used by the Support staff is not compatible with Workspace ONE Assist.

Solution 1

Use a different web browser. Install or switch to a compatible browser. The following is a list of browsers currently supported by the Workspace ONE Assist Tool.

  • Google Chrome
  • Safari

Possible cause 2

Browser pop-ups are blocked. The browser being used is blocking pop-up windows from the Workspace ONE Assist portal.

Solution 2

Enable pop-ups in browser settings. UEM console users must update their browser settings to allow pop-ups from the Workspace ONE Assist portal.

Problem - Remote Support Validation Fails

During Workspace ONE Assist validation steps, one or all three validation steps and the ‘Launch Session’ button does not appear.

Possible cause(s): Certificate mismatch, Workspace ONE Assist server issues. Client-server certificates might be incorrectly deployed or there might be issues with availability of the Workspace ONE Assist server and console.

Solution: Review certificates and ensure that Workspace ONE Assist servers are operational. Ensure that the T10 interface certificate has been properly deployed on the Workspace ONE Assist servers and that Workspace ONE Assist servers are online and operational.

Modify Database Record for Multi-Node Configuration

For the Workspace ONE Assist server to operate correctly in a multi-node configuration, you might need to modify DB records in [ApAdmin].[dbo].[Server].[FQDN]. Some installations result in these tables pointing to the external Virtual IP (VIP) address by default. This default arrangement must be changed.

Note: Active-passive configurations with standard, all-in-one installations do not need this FQDN change inside the database table. Applying this change in such an environment might break the configuration. Consult with support if you are unsure which configuration you have.

Ensure that each [FQDN] record is in the [ApAdmin].[dbo].[Server] table in the database points to the internal IP address of the VIP (also known as Virtual IP) for the load-balanced pool.

The number of [FQDN] records is equal to the number of application/connection proctor servers in your deployment. Therefore, you must update each one in the table. For example, if your deployment has four connection proctor servers, then you must locate and modify 4 [FQDN] records in the [ApAdmin].[dbo].[Server] table.

After you finish the record modification, restart all Workspace ONE Assist Servers.

Assist System or Operations Management and Troubleshooting

  • Ability to reset passwords

    To reset the password for self-managed user credentials, follow the procedure:

    1. On the Core server (multi-node deployment), navigate to the Installer file.

    2. Right-click the installer file, svrcfg.exe and select Run as administrator.

      Note:

      • Executing the ServiceConfig file does not trigger the re-installation of Assist. After you complete step 7, you may close the installer UI.
      • Ignore any unhandled exceptions shown.
    3. Select Standard Installation and then click Next. Selecting this installation type does not impact the existing installation.

    4. If the HTTPS port in use prompts, enter a different port. This does not impact the existing installation.

    5. Enter the SQL Server details.

    6. In the Portal Advanced Settings, click Show Optional settings.

    7. Navigate to the Password Managementsection.

      1. Reset password for Assist System Management (AdminWebPortal) - Enter the existing username and a new password and then click Reset.
      2. Reset password for Assist Management Portal (MgmtWebPortal) Tenant Url (Assist URL)- Enter the existing username and a new password and then click Reset.
  • Enable Admin Web Portal Access

    If the deployment has more than one portal server, you must follow the procedure on all the Portal servers.

    1. On the Core server (multi-node deployment), navigate to the Installer file.

    2. Right-click the installer file, svrcfg.exe and select Run as administrator.

      Note:

      • Executing the ServiceConfig file does not trigger the re-installation of Assist. After you complete step 7, you may close the installer UI.
      • Ignore any unhandled exceptions shown.
    3. Select Standard Installation and then click Next. Selecting this installation type does not impact the existing installation.

    4. If the HTTPS port in use prompts, enter a different port. This does not impact the existing installation.

    5. Enter the SQL Server details.

    6. In the Portal Advanced Settings, click Show Optional settings.

    7. Select the Enable Portal Access check box and choose a time frame (in hours) until when the portal must be accessible for troubleshooting or management purposes.

Assist Upgrade issues

Problem

'Undefined' error shown during Core service components installation and unable to upgrade the Workspace ONE Assist system.

Possible cause

The generated self-signed assist installer root certificate may not have been updated in the database or the SQL scripts were not deployed properly.

Solution

  1. Remove the listed records from the database.

    • Apadmin > Version table > Delete the version number 3 record

      DELETE from ApAdmin.dbo.[Version] where [Version] = '3'

    • Apadmin > DefaultServiceConfiguration table > Delete the param name ":ctl.svc.ipc.cert/deployment/root/v2" record

      DELETE from ApAdmin.dbo.[DefaultServiceConfiguration] where [ParamName] = ':ctl.svc.ipc.cert/deployment/root/v2'

  2. Re-run the Workspace ONE Assist installer.

Problem

The error message 'Connection closed abnormally' appears while initiating a remote session when the connection is still in the 'sending message' step on the console.

Possible solution

The Reserved URL for the ToolController service might not have been configured properly during installation.

Solution

First, check the reserved URL for ToolController by the running following command to make sure the tool controller URL is added.

netsh http show urlacl

If the url is not configured for ToolController then add the reserved URL by running the following command on the system.

netsh http add urlacl url=https://+:<PORT>/toolcontroller user="NETWORK SERVICE"

Check the remote connection.

Problem

The error 'Invalid Admin Credentials' is observed during Portal service installation.

Possible cause

Some unsupported special characters are used within the password for Users under User Management Settings.

Solution

Reinstall the installer by creating the new user by replacing 'Rootadmin' and 'Opsadmin' with other names such as 'Rootadmin1' and 'Opsadmin1'. You must ensure their passwords do not have characters like plus (+), double quotes ("), or hash (#) symbols.

For more information, see Install Workspace ONE Assist to an On-Premises Environment.

Problem

  • IIS App Pool - 'PortalWebSite' crashed on the Portal server and in the event log "A process serving application pool 'PortalWebSite' suffered a fatal communication error with the Windows Process Activation Service." error is reported for w3wp.exe process.
  • Sometimes device is not registered and the "RM failed to register. Server not found server:<FQDN>" error is reported in the UEM troubleshooting logs.
  • 503 services unavailable error when starting remote session from UEM console.

Possible cause

More log files are available in the Assist Anchor logs folder or ensure any antivirus software configuration is not causing new IIS AppPool creation.

Solution

Empty the Anchor logs folder and restart IIS AppPool - PortalWebSite and IIS website - Portal Web Site.

or

Set the value to True for Enable 32-bit applications option in the App Pool advanced settings for PortalWebSite.

Restart IIS website - Portal Web Site and IIS AppPool - PortalWebSite.

Problem

The error 'Invalid Operations Credentials' is observed during Portal service installation.

Possible cause

Token Service [moduleid: 16399] is in Fault state [status: 9]

  • Check the following service record status on the database. It must be in the active state [4].
    • ApAdmin → dbo.Services → Token Service status
  • Ensure the Token Service parameters are available in the Default Service configuration.
    • Apadmin → DefaultServiceConfiguration table → Verify the 16399 module parameters.

Solution

  1. Remove the following record from the database.

    Apadmin -> Version table -> Delete the version number 3 record.

    DELETE from ApAdmin.dbo.[Version] where [Version] = '3'

  2. Re-run the Workspace ONE Assist installer.

Problem

The error 'CertNotAvailable' is observed during the upgrade of the Assist service installation.

Possible cause

Windows display language is set to a language other than English or Windows OS is installed with the native language.

Solution

  1. Update the English language as the Windows display language.
  2. Sign out and sign in again on the system.
  3. Re-run the Workspace ONE Assist installer.
  4. Change the Windows display language again to the old [native] language once the installation is successful.
  5. Verify the remote connections.

Remote Session Issues - Active Directory Accounts

Problems

  1. 'Unable to connect to server' error is shown when access assist console and IIS Application pool is stopped. The following error is reported in the Event logs.

    'The identity of application pool MgmtWebSite is invalid. The user name or password that is specified for the identity may be incorrect, or the user may not have batch logon rights. If the identity is not corrected, the application pool will be disabled when the application pool receives its first request. If batch logon rights are causing the problem, the identity in the IIS configuration store must be changed after rights have been granted before Windows Process Activation Service (WAS) can retry the logon. If the identity remains invalid after the first request for the application pool is processed, the application pool will be disabled. The data field contains the error number.'

  2. 'Windows could not start the service on a local computer. Error 1069: The service did not start due to a logon failure' error shown when restarting the assist services.

Possible Cause

Passwords for the assist service user are expired if Windows or Domain authenticated users are used to configure the assist services.

Solution

Reset the configured assist service user's passwords with the Assist Service User Configurations Utility tool. For information about resetting the passwords, see <a href = https://docs.omnissa.com/bundle/Workspace-ONE-AssistV24.03/page/InstallWorkspaceONEAssisttoanOn-PremisesEnvironment.html#update_service_users_password_with_assist_service_user_configurations_utility>Update Service Users Password with Assist Service User Configurations Utility.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…