Skip to main content

May 27, 2025 Archived

Omnissa Workspace ONE UEM Release Notes

Workspace ONE UEM Release Notes provide information on the new features and improvements in each release. This page includes a summary of the new features in 2306, issues resolved, and known issues.

When can I expect the latest version?

We strive to deliver high-quality products, and to ensure quality and seamless transitions, we roll out our products in phases. Each rollout may take up to four weeks to accomplish and is delivered in the following phases:

  • Phase 1: Demo, Shared SaaS UATs, and Latest Mode UATs

  • Phase 2: Shared SaaS environments

  • Phase 3: Latest Mode environments

This version is initialy available to our SaaS customers on the Latest mode. The features and improvements incorporated in this version will be available to our on-premises or managed hosted customers with the next on-premises release. For more information, see the KB article. Workspace ONE UEM for 2306 release will also be an on-premises release.

Getting Ready for Major OS Releases

Interested in learning about the latest major OS updates and their resulting implications on Workspace ONE? See the Getting Ready for Major OS Releases section in Omnissa Documentation for more information.

What's New

Console

  • Let’s keep our request templates for SCEP certificates simple.

We’ve changed the behavior for our SCEP certificates. Auto-renewed certificates no longer append sceprenew to the Subject. In prior releases, "sceprenew" was appended to the certificate Subject as a Common Name. With this modification, a sceprenew token is included in the certificate as a Subject Alternative Name (SAN).

  • Basic admin accounts now have better security hygiene.

When you reset your account password, your Workspace ONE UEM console session used to reset the password continues, but we automatically log you out of any other active sessions. This feature applies only to basic administrator accounts. The third party authentication is not currently supported. This feature is enabled by default, there is no system setting. For more information, see Logging In to the Console.

  • We've added the Subject Alt Text (SAN) field to the EBJCA CA template.

You can now add one or more SANs to the EBJCA CA template for unique certificate identification.

  • New Compliance Policy Rule: Device Tags

You can now detect whether a device tag is present (or missing) on a device and mark the device as not compliant if it is present (or missing). All platforms are supported. For more information, see Compliance Policy Rules and Actions.

iOS

  • Add Web clips to your Home Screen Layout profiles.

Manage the location of Web Clips when defining the layout of the device's home screens using the Home Screen Layout profile. You can place Web Clips on any home screen, on the Dock, or within Folders.

  • We've updated Volume Purchase Programm (VPP) to support Apple's latest API.

To improve VPP app deployments, we have now implemented Apple's latest API suite. While this update is taking place behind the scenes, you will notice improved performance and scalability when deploying managed applications through VPP.

  • Are you missing various iOS profile keys? We’ve a solution for you!

We have updated the profiles for Restrictions, Wi-Fi, VPN, and Skip Setup Assistant. As of iOS 16, these profiles now support all available configuration keys.

Here are the specific updates per payload:

New Restrictions keys: Allow Cellular Plan Modification, Allow NFC, Allow Personalized Advertising, Allow Recovery Mode with Unpaired Device, Force On-Device Dictation, Allow Automatic Lock, Force On-Device Translation, Require Managed Pasteboard, Allow iCloud Private Relay, Allow Mail Privacy Protection, Allow Rapid Security Response Installation, Allow Rapid Security Response Removal.

New Wi-Fi keys: Enable IPv6, HESSID, TLS Certificate Required.

New VPN keys: Enforce Routes, Maximum Transmission Unit, SMB Domains, Prevent On Demand Override.

New Skip Setup Assistant keys: Terms of Address, Emergency SOS, App Store.

For more information, see iOS Device Profiles.

macOS

  • Use the new macOS Device Updates dashboard to manage macOS updates.

The new macOS Device Updates dashboard enables you to assign and deploy minor and major macOS updates to devices. This dashboard leverages Apple’s MDM protocol, supporting options such as the ability to download and stage the update to a device, notify the user that an update is available, or even force an update to take place without user interaction. The target macOS version and behaviour can be scoped to specific smart groups and assigned to devices, and Workspace ONE will automatically retry the commands periodically until the device confirms the update is successful. For more information, see macOS Update Management.

  • Introducing the new macOS Ventura keys.

We’ve added several new configuration options for macOS profiles:

Login and Background Item Management: Prevent users on macOS Ventura from disabling background processing for specified apps.

SSO Extension: Support for third-party platform SSO Extension configuration.

Restrictions:

  • Allow the Deployment or Removal of Rapid Security Updates.

  • Allow Universal Control, USB Restricted Mode, and manual configuration profile installation.

Security & Privacy: More granularity around delaying major, minor, and non-OS updates.

Content Caching: Configure the native caching settings on macOS devices.

Firewall (Native): Updates to configuration options for the native system firewall.

Notifications: Configure the default notification settings for apps installed on macOS devices. For more information on the profile updates, see macOS Device Profiles.

  • Introducing a global Cloud Notification Service for delivering APNs notifications.

APNs for applications communication uses Cloud Notification Service by default. For more information, see Cloud Notification Service.

Windows

  • Updating on-demand Windows apps to newer versions just got easier!

You can now keep those on-demand apps up to date whenever you add a new version. When configuring the assignments for your app deployments, make sure to enable the Keep app updated automatically setting. For more information, see Assign Applications to your Windows Desktop.

  • Check out the fresh new Windows Security Baseline templates!

We’ve added two new templates: Windows 11 versions 21H2 and 22H2. We have also included Windows 11 version 21H2 for creating a new CIS Windows Benchmarks template. For more information, see Using Baselines.

  • Customize your Online Drop Ship Provisioning Cache Serves.

We now support custom cache servers. For more information, see Use a Custom Cache Server.

  • We enhanced the UEM console for user and device profiles.

Enhancements for Windows Profiles:

Profile data will now be provided to the console through the Windows DDUI Profiles (Beta).

Around 150 native Microsoft CSP payloads are now available to be configured without using custom settings.

Omnissa Templates are behind a feature flag - Template payloads will provide three highly customized profiles (Windows Updates, Deliver Optimization, and Proxy) to simplify Windows configurations.

Enhancements with Windows Update:

Windows Update information has been moved to the Intelligent HUB

New Device Update view shows the accurate installation status together with the Update installation source for easier troubleshooting.

For more information on both of these, see Workspace ONE UEM Profiles for Windows.

  • Troubleshooting Windows update is now much simpler!

We’ve introduced three buttons to help you troubleshoot Windows updates such as Pause, Rollback, and Resume. For more information on how these work please refer to: Workspace ONE UEM Profiles for Windows.

  • We no longer support the Tunnel Proxy Component.

The Tunnel Proxy Component support period ended on January 30, 2023. See Migrating from Tunnel Proxy to Per-App Tunnel for information on how to switch to Omnissa Tunnel. The full end-of-support announcement can be found here: KB article.

Android

  • Use Conditional Access for your shared android devices

We’re excited to announce that Omnissa has integrated with Microsoft to extend our UEM conditional access capabilities for Microsoft Azure Active Directory (AD), with support for Android shared device mode. With this new integration, you will be able to provide shared devices with secure, conditional access to Microsoft 365 apps. For more information, see Configure Shared Android Devices for your Shift Workers.

  • Simplify certificate-based authentication for your Android applications.

You can now silently grant applications access to client certificates provisioned by Workspace ONE UEM. VPN clients, browsers, and other applications will no longer have to prompt the device user to select a certificate for authentication. Supported on devices running Android 11 and higher.

Directory Services

Omnissa Identity Services lets you implement federated identity for user accounts and authentication, support service accounts and customer applications, and utilize common tenancy models and authorization patterns across Workspace ONE UEM and Workspace ONE Access. Certain limitations apply. See the Omnissa Identity Services Release Notes for more information.

Before You Begin

The Workspace ONE Unified Endpoint Management (UEM) console supports the latest stable builds of the following web browsers.

  • Chrome

  • Firefox

  • Safari

  • Microsoft Edge

Comprehensive platform testing has been performed to ensure functionality using these web browsers. If you run the UEM console with an older version browser or on a non-certified browser, you can experience minor issues.

Resolved Issues

  • Resolved Issues for 2306

Resolved Issues for 2306

  • CRSVC-37061: Filters on "Console Events" completely broken on console version 22.10.0.1.

  • AMST-39210: ARM x64 Agent is not getting installed on OOBE enrolled Windows devices.

  • AGGL-14515: Selecting "Add version" on the Assignment page of an Application Control profile reverts the Application Control profile to default settings.

  • AGGL-14916: Android Enterprise WiFi Profile (WPA/WPA2 Enterprise) - Unable to save Domain field.

  • AGGL-14746: Custom Admin Role Permissions for Android Permissions Payload.

  • INTEL-48971: Intelligence Enrollment Users Not Syncing as Expected.

  • AAPP-16060: APNs OutBound queue being backed up.

  • AMST-38993: Wi-Fi IP Address of the windows device is displayed as 0.0.0.0 in the Network tab.

  • PPAT-14564: Tunnel config/Cannot edit DTR application under certain circumstances.

  • CRSVC-37205: Admin details are missing while performing DELETE device API call on enrolled device.

  • AGGL-14628: Android Tunnel shows 'No Managed Applications' eventhough present.

  • UM-8007: Error prompted while trying to add LDAP Admin group in UEM console and save.

  • CMSVC-17033: Smart Group Migration banner is displayed even when there are no Smart Groups that need to be migrated in the OG.

  • MACOS-3836: FileVault rotate recovery key command is not working as expected.

  • AAPP-14625: SIM Card change compliance policy is being falsely marked as non-compliant for some devices.

  • AMST-38973: Migration of Windows Update (Legacy) payload fails if Locale set is other than English in Account Settings.

  • AAPP-15971: iOS compromised status compliance policy does not complete evaluation.

  • ARES-25505: Database upgrade failure due to the CREATE UNIQUE INDEX.

  • CMEM-186861: Sync Mailbox issue with Unmanaged/Blocked Records.

  • AAPP-13841: iOS Update filtering issues.

  • AAPP-15498: During iOs Native CICO, the devices do not get assigned to end user after logging in with AppleID on the device.

  • AAPP-15074: ABM device does not update with the second enrolled user status after re-enrollment from first user to second user.

  • AAPP-15653: APNsOutbound messages throttled and failure code "Unknown".

  • AAPP-15815: Mismatch app install status from device summary page with apps&books view.

  • AAPP-15878: Missing validation for Message Template in VPP Managed Distribution.

  • AAPP-15929: Renewed VPP stoken(ASM) does not sync the app details on the console.

  • AGGL-11827: Unbinding G-Suite Android EMM Registration fails.

  • AGGL-12919: Android 'Build Version' field is blank when exporting CSV/XLSX with custom layout.

  • AGGL-14222: Google seems to have increased oAuthToken length (AndroidWorkSetting AccessToken got truncated).

  • AGGL-13726: Apps not installing Apps on Share devices (Pixel 6).

  • AGGL-14249: Android apps not displaying in Hub catalog due to missing Google EMM registration.

  • AGGL-14366: VpnUUID is removed from a Workspace ONE Tunnel VPN profile XML when version is added.

  • AGGL-14488: Annual System Update Freeze Periods always goes back to default in Firefox and Safari.

  • AGGL-14532: Unable to add assignment to Android public applications, Spaceman error received on console.

  • AMST-38422: Intel vpro fails to sync devices.

  • AMST-38498: MacOS DDUI Network profile not saving PayloadCertificateAnchorUUID issue.

  • AMST-38770: Windows marked as compromised after UEM upgrade to 2302.

  • AMST-38822: Enrollment User deletion encounters FK error.

  • ARES-25392: Uploading a duplicate windows app displays an error message - "App already exists with this OG".

  • ARES-24494: Global search results screen shows garbled characters for double-byte names in UEM console 2209 or later.

  • ARES-24729: Unable to add a SG to a workflow for internal app.

  • ARES-24884: Send Configuration is set to disabled when a new app assignment is created by copying a published assignment that has Application Configuration enabled.

  • ARES-24942: AirWatch Database Purge expired Sample Data SQL job is failing.

  • ARES-24961: Using API to Exclude Smart Group from Option Profile is not Removing Profile from Devices

  • ARES-25070: Unable to view device list from app assignment or export device list.

  • ARES-25303: App Config missing for Epic Rover after re-publishing the app .

  • ARES-25083: Profiles not getting assigned to iOS device.

  • ARES-24974: Application Crash Logs - Not purging.

  • ARES-25229: Invalid ApplicationEventSample from Android devices.

  • ARES-25309: Unable to delete applications.

  • ARES-25377: High Latency in Purge Expired Sample Data job execution.

  • CMSVC-16822: Lookout Tags fail to work as expected afterconsole upgrade.

  • CMSVC-16867: Intelligence Automation is not working as expected.

  • CMSVC-16935: Unable to load Assignment and Organization groups list view and unable to load assignment groups in app assignments.

  • CMSVC-16973: Unable to load Assignment groups list view page and unable to load assignment groups in app assignments.

  • CRSVC-34061: Overview page shows incorrect data for Devices with Denied Apps.

  • CRSVC-35200: Re-provisioned Android device not installing profiles and apps.

  • CRSVC-34180: While creating new Compliance policy under view Device Assignment page pressing enter is saving the compliance policy.

  • CRSVC-35209: Unable to edit, delete or deactivate specific compliance policy.

  • CRSVC-35739: Android Hub UI - Privacy Details > Device Management information does not display.

  • CRSVC-36298: Interrogator service unable to save Certificate samples.

  • CRSVC-36361: Workspace ONE does not remove the token while deleting or enterprise wiping the devices.

  • CRSVC-36770: High CPU utilization post upgrade to 23.02.

  • CRSVC-37396: Certificates are not getting deployed to the devices.

  • ENRL-3527: UEM Unenrollment does not send re-authentication to User's other devices.

  • CRSVC-37402: Spaceman error while accessing Device summary page of windows Rugged devices.

  • ENRL-3718: Enrollment restrictions not being honored for ipads.

  • ENRL-3716: Authentication required twice during Intelligent Hub enrollment.

  • ENRL-3719: Unable to edit/view DEP profiles.

  • ENRL-3736: DS servers CPU usage spiking to almost 100%.

  • FCA-205144: Issues with Console TimeZone Guadalajara, Mexico City , Monterrey.

  • FCA-205160: Custom Admin Roles unable to load AA pages after upgrade to 2212.

  • FCA-204971: Restrict edit access for Enrollment Settings page.

  • FCA-205179: The error, “User name should not contain the following characters...” occurs at Username in "Trouble logging in" page for admin account if its username includes some special characters.

  • FCA-205220: Insecure storage of sensitive information in advanced settings page exposes all Org Groups.

  • FCA-205268: Post API/mdm/devices/id API call returning internal server error or duplicate results.

  • FCA-205221: Device List Export for Compromised Unknown not honored on Export.

  • FCA-205274: Missing Management Mode tab and no activation email for adding email domain.

  • FCA-205277: API V3 GET /devices/search doesn't return any device network information.

  • FCA-205416: A blue banner with the notification.

  • MACOS-3325: API to create MacOS DDUI Profile.

  • MACOS-3445: Unable to select SCEP certificate in Network Payload.

  • MACOS-3532: Global HTTP Proxy always shows Not Configured for captive portal bypass option.

  • MACOS-3540: macOS Login Window payload issue preventing Screen Saver customization.

  • MACOS-3691: macOS Compliance Policy false positive on Encryption status (round 2).

  • MACOS-3697: Missing Mac devices in seed script.

  • MACOS-3740: Hub 23.03 not seeded.

  • MACOS-3701: macOS devices not showing AirPlay option in More Actions menu.

  • RUGG-11913: Custom assignment rules do not apply correctly during device enrollment as the custom attribute data does not get pulled into the console as fast as product jobs gets queued up.

  • PPAT-14114: Post Migration to AWS CloudFront - Tunnel Configuration page does not load.

  • RUGG-11963: Adding Files/Actions eventually fails when clicking “SAVE” button again while a large file is being uploaded.

  • RUGG-12004: Files get corrupted when multiple files are added under Files/Actions.

  • UM-7887: Manual LDAP attribute sync fails with an error.

  • RUGG-12081: Product assignments are delayed.

  • UM-7948: Unable to modify existing Admin groups in UEM.

  • UM-7902: Administrator with two roles is unable to view user role that was created by himself.

Patch Resolved Issues

  • 23.6.0.1
  • 23.6.0.2
  • 23.6.0.3
  • 23.6.0.4
  • 23.6.0.5
  • 23.6.0.6
  • 23.6.0.7
  • 23.6.0.8
  • 23.6.0.9
  • 23.6.0.10
  • 23.6.0.11
  • 23.6.0.12
  • 23.6.0.13
  • 23.6.0.14
  • 23.6.0.15
  • 23.6.0.16
  • 23.6.0.17
  • 23.6.0.18
  • 23.6.0.19
  • 23.6.0.20
  • 23.6.0.21
  • 23.6.0.22
  • 23.6.0.23
  • 23.6.0.24
  • 23.6.0.25
  • 23.6.0.26
  • 23.6.0.27
  • 23.6.0.28
  • 23.6.0.29
  • 23.6.0.30
  • 23.6.0.31
  • 23.6.0.32
  • 23.6.0.33
  • 23.6.0.34
  • 23.6.0.35
  • 23.6.0.36
  • 23.6.0.37
  • 23.6.0.38
  • 23.6.0.39
  • 23.6.0.40
  • 23.6.0.41
  • 23.6.0.42
  • 23.6.0.43
  • 23.6.0.44
  • 23.6.0.45
  • 23.6.0.46
  • 23.6.0.47

23.6.0.1

  • CMCM-190676: Adding content via API defaults to unknown "Paxar" value for customer, while the default should be N/A.

  • AMST-39542: Workaround for MSFT issue breaking SFD installation.

  • UM-8276: Inconsistency in the response of enrolled user details for Staging Mode and DeviceStagingEnabled fields.

  • MACOS-4007: Unable to setup admin account on a macOS device.

  • CMCM-190659: "Content Detail by Device" Report incorrect.

  • AAPP-16342: Resolve errors from OS update retry job.

  • CRSVC-39404: Globalize the new error message from Blind pirate(INTEL) service.

  • ARES-25957: Application-rule PUT API improvements.

  • FCA-205819: Improve Device Dashboard performance for large device count.

  • ARES-26207: Deploying internal apps is getting stuck in “Pending Release” status.

  • AAPP-16365: Query to validate Cellular APN as required field with DDUI activated.

  • AMST-39505: WNS disconnected for multiple Windows devices.

  • AMST-39308: Arm x64 agent is not getting installed on OOBE enrolled Windows devices.

  • CMCM-190660: Renaming Folder and trying to sync is giving 404 or and empty XML.

  • AAPP-16314: False APNS Notifications during Purchased App Sync.

  • FCA-205669: Horizontal scroll missing for Organization Group selector.

  • AGGL-14594: Clicking "Add version" at the Assignment page of an Application Control profile reverts the profile to default settings.

  • AMST-39479: The default 'Read Only' Admin role to view the Baseline is not working.

  • CRSVC-39367: Memcached uses only one server.

  • CRSVC-37865: Private key does not match public key for certificates from ADCS.

23.6.0.2

  • CRSVC-40112: Certificate Installer- Private Key not exportable in Manual Flow.

  • AGGL-15331: Remove EFOTA sample from microservices.

  • INTEL-51757: Update current device enrollment user delta export to include delete operation.

  • FCA-205645: Reset password for locked admin account is not working.

  • ARES-26030: Profile Installation status is not loading for profiles deployed to the entire environment.

  • CMCM-190665: Workspace ONE UEM console shows spaceman error when viewing security tab for most macOS devices.

  • PPAT-14872: Switch from AirWatch to Third party under Client Auth is broken.

  • AAPP-16388: iOS Device Updates Notification messages are automatically truncated.

  • CRSVC-39344: Unable to send custom commands.

  • CMCM-190685: Errors during blob sync/check status to CDN.

23.6.0.3

  • AMST-39652: Newly created baselines in 2302 has NULL values in databse for BaselineTemplatePlatformUUID.

  • CMSVC-17310: SG compilation failure on device event to SG service.

  • AMST-39697: Autopilot enrollment failing after Workspace ONE UEM update to 2306.

  • AMST-39589: Seed 23.02.7 patch to Workspace ONE UEM console master.

  • CMCM-190717: ZDT database upgrade failure for content map procedure.

  • AAPP-16051: "East iOS GP and MobileConnect" profile is going to not installed state on many devices.

  • AMST-39614: Smart group was not recognizing 32 bit devices from Workspace ONE UEM console version 2212.

  • AGGL-15448: Unable to create Android profile with a TimeSchedule, whose ScheduleListUUID is Null.

  • AMST-39633: API 'mdm/devices/security' endpoint fails with 500 internal server error for some devices.

  • MACOS-4064: macOS 14 ADE enrollment fails if the Custom Enrollment is off.

  • ARES-26352: Incorrect version while creating a copy of Workspace ONE UEM profile.

  • INTEL-51913: Intelligence Android Application app version code was not fetched correctly.

  • MACOS-4033: Workspace ONE UEM downloads the binaries from ESR every time the SeedSystemAppsJob runs.

  • RUGG-12328: Update the Linux pull service installer link within Settings > System > Enterprise Integration > Pull Service Installers.

23.6.0.4

  • AAPP-16444: Update device information query cellular keys.

  • CRSVC-38843: Create non-clustered index on certificate table based on observations on Kroger.

  • CMCM-190640: Large file uploads from App to repository fails.

  • CMCM-190744: Workspace ONE UEM CMCM available updates timeout alert across Saas.

  • CRSVC-41362: Conditional access audit event timings were not localized per admin time zone.

  • AAPP-16459: Unable to upload an application with multiple info.plist on the Workspace ONE UEM console.

  • CRSVC-38844: Cisco ISE API Account password expiration.

  • ARES-26477: Modify sync logic to queue command, when previous status is pending release with No pending commands.

  • AAPP-16489: Customer’s orders were seen in other customer’s OG.

  • ARES-26477: Modify sync logic to queue command when previous status is pending release with no pending commands.

  • AAPP-16478: Unable to edit existing iOS device profiles after Workspace ONE UEM upgrade to 23.6.0.1.

23.6.0.5

  • FS-4302: Step to purge orphan Workflow Status records fails in "Purge Expired Sample Data" job.

  • AMST-39764: WNS disconnected for multiple Windows devices.

  • ARES-26473: Windows Intelligent Hub and OMADM Client reporting different versions for the same application.

  • FCA-206095: Spaceman error when accessing Organization Group List View page from customer Organization Group.

  • FCA-206048: Banner is not seeded into BannerFeature table.

  • AAPP-16513: High CPU and Memory usage by RestrictionsSampleLatest_Load.

  • FCA-206084: Unable to send the Push Notifications/Email notifications using Bulk Management.

23.6.0.6

  • FS-4329: Seed Mac Workflow Host in Canonical- Release 23.06.

  • ARES-26485: Device Profile Status ID incorrect in API Call.

  • ARES-26577: Auto purge for device application logs and move threshold on percentage basis.

  • ARES-26588: Unable to add multiple apps to folders in Home Screen Layout due to duplicate records from database.

  • ARES-26503: Multiple entries in DB table for a given profile ID and version.

  • CRSVC-41779: Cannot add more than one SAN field in template.

  • AAPP-16494: Build API to retrieve iOS device friendly name.

  • MACOS-4071: Incorrect App Bundle ID is updated on Workspace ONE for macOS apps using Electron Framework

23.6.0.7

  • CRSVC-42633: Enable Microsoft conditional access device registration for shared device mode.

  • AAPP-16575: VPP V2 compatibility updates.

  • AAPP-16588: During iOS Native Check-Check-out, the devices do not get assigned to end user after logging in with Apple ID on the device. The console shows the device is still tied to the staging account.

  • ARES-26763: Smart group publish not triggering internal application assignment reconciliation.

  • AAPP-16596: Unable to edit existing iOS Wi-Fi device profile.

  • RUGG-12553: [File Action] Upload fails for large files with exception.

  • ARES-26453: Inactive update profiles getting removed from machines automatically causing the devices unnecessary upgrade to Win 11.

  • AMST-39803: Windows updates are not getting updated in device details page under updates for Windows 11 devices.

  • AAPP-16534: VPP Auto Update failing with specific country code.

  • FCA-206101: Unable to send template message to device from public app details device tab.

  • MACOS-4090 : All workflows show "In Progress" status.

  • PPAT-15393: [Unmanaged Flow] SDK flow is not authenticated when using Third Party CA for Client authentication.

  • RUGG-12565: Products are showing "In progress" after UEM upgrade.

  • PPAT-15164: MFA option is visible for other VPN types as well.

  • AMST-39705: Bios Verification status sent incorrectly as a part of Windows Security information sample.

  • AAPP-16569: Sync is stuck in progress and apps do not get added.

  • AGGL-15900: All internal Android apps uploaded to the console are getting the default Android icon.

  • AGGL-15894: Android VPN profile throws "Failed to save profile" error when trying to modify it or add a version to it.

  • FS-4502: Fix performance and workflow status reporting issues in workflow for profile installation.

  • CRSVC-42635: Migration tool application migration custom batch.

  • AAPP-16540: VPN profile values are changing after publishing profile.

  • FS-4540: Seed Mac Workflow Host in Canonical - Release 23.06.

23.6.0.8

  • AAPP-16587: Custom data (key/value) not retained in VPN profile (iOS) after re-opening the profile.

  • AMST-39762: Workaround for OEM update profile fails to install on device.

  • ARES-26758: "App already exists with this Organization Group" error message when uploading a duplicate Windows app.

  • ARES-26865: Incorrect records are getting fetched due to ordering of duplicate payload templates.

  • CMEM-186928: Objects not clearing from the memory and causing high memory usage.

  • CRSVC-43006: Some identity certificates are reported as "Cert" type in error.

  • FCA-206261: UEM support for Workspace ONE Role Based Access Control.

  • PPAT-15442: Review and reduce the Tunnel Service Logs generation.

  • UM-8390: Unblock the Auto/Manual syncs during advanced Ldap Sync cycle failure.

23.6.0.9

  • AAPP-16648: Unable to install VPN profile on iOS devices.

  • AAPP-16654: Show or hide a field which is dependent on different fields out of which one is set.

  • AAPP-16651: Action parameter section sequencing was not correct.

  • AAPP-16640: VPN IKEv2 payload dropdown values were changing to default value after adding a version.

  • ARES-26826: Multiple nodes of MetadataTransformService tried to parse the files and seed them concurrently which causes the DbUpdateConcurrencyException.

  • AGGL-15990: Unable to install profiles on Chrome OS devices post V2 migration.

23.6.0.10

  • RUGG-12357: Unable to get the launcher speed lock down feature working.

  • AAPP-16558: DEP assignment was taking too long to change the UI.

23.6.0.11

  • AAPP-16712: Correcting the existing profile context data.

  • CRSVC-43754: Android shared device mode app configuration was not completing.

  • RUGG-12629: Add support for pull relay server discovery with IP as discovery text.

  • CMCM-190730: Status of document in content detail report was not corrected.

  • CRSVC-43331: Increased CPU usage by CiscoISE app pool.

  • AMST-40139: If the "Managed Applications" payload is configured in Windows profile, checkbox size in other payloads will become huge.

  • ARES-26622: Device logs not uploaded to console.

  • CRSVC-42825: Secure Channel - Cannot find the original signer issue.

  • CRSVC-42774: Navigating to app events gives spaceman error.

  • ARES-26909: Sync should queue install commands when there are already pending commands for other devices and previous status is pending release.

  • FS-4728: Seed Mac workflow host in canonical release 23.06.

  • AAPP-16685: Workspace ONE UEM unable to edit approved SIM for some devices.

23.6.0.12

  • PPAT-15756: Improvements around Tunnel allowlist sync endpoints.

  • CRSVC-43698: Admins receiving email that 50% API Utilization limit being hit for a specific Organization Group.

  • AMST-39888: Removing Windows update profile does not remove configured policies.

  • AAPP-16721: Stop command delivery to Non-DM clients if requestor info is missing.

  • FCA-206435: Incorrect Add Cloud Services Admin redirection.

  • CMCM-190819: Downloaded files gets disappeared on the random devices.

  • AAPP-16709: VPP App license is not displaying on the UEM console stating no records.

23.6.0.13

  • AAPP-16422: When CNS is configured for APNs, non-silent APNs is sent by manual Hub Query from UEM instead of silent APNs.

  • PPAT-15729: Sending State Attribute as part of AWCM message to the Tunnel server.

  • CRSVC-43969: Errors in WF proxy logs for metrics having too many tags and getting blocked.

  • UM-8506: Add "With Recompile" option to API User Search SP.

  • CRSVC-43972: Edit of Compliance Policy is not reverting the previously configured action.

  • AGGL-16079: ChromeOS Credentials Profiles do not redeploy between user logins.

  • AAPP-16730: Broken icon image for iOS Web Clip profile.

  • RUGG-12690: App search bar missing in Launcher when the profile is in multi-app mode.

23.6.0.14

  • ARES-27142: Profile is showing out of date status on installation after adding the version.

  • ARES-27151: Workspace ONE UEM API endpoint continually failing with error "Collection cannot be null or empty."

  • ARES-27168: Remove Wi-Fi credentials data from view XML for profile type WPA/WPA2 Enterprise Wi-Fi configuration.

  • PPAT-15811: Tunnel server traffic rule with Pac Reader does not work.

23.6.0.15

  • AGGL-15919: Global lock when stored procedure to mark snapshots as obsolete is in flight.

  • AMST-40135: Mac address is not visible for Wi-Fi adaptor in the Network tab.

  • AAPP-16742: Update Seed script to add BundleId for Journal app.

  • RUGG-12725: Workspace ONE servers unable to connect to SFTP Relay Server due to mandate to disable SHA-1.

  • CRSVC-44392: Spaceman error appears at Summary tab in the Compliance wizard for device tags.

  • AAPP-16789: The description for Custom B2B apps is not shown in legacy and Hub catalog.

23.6.0.16

  • ARES-27165: For autocomplete field, save the data which is entered manually and not selected from dropdown.

  • CMEM-186982: Optimize Stored Procedure to avoid intermittent timeout.

  • ARES-27251: Profile removal is not triggered based on the actual admin time zone after saving the expiration date in UTC.

  • AAPP-16806: Unable to delete ABM stale record from Enrollment lifecycle page.

  • AMST-40301: Seed 23.02.8 patch to Workspace ONE UEM console master.

  • ARES-27280: Certain macOS devices have Windows internal apps assigned.

  • ARES-27256: Sampling is not saving SampleHash in the interrogator hashtable.

  • ENRL-3974: Unable to save enrollment restrictions settings due to inaccurate data in the database.

23.6.0.17

  • ARES-27253: Fix application segment data mismatch from Apple devices.

  • CMSVC-17482: SmartGroup search in astro-air pages returns complete path of the organization group.

  • CMSVC-17485: Unable to push iOS update page crashing and getting error.

  • AMST-40277: Update installation did not resume after pausing the installation.

  • AMST-40278: Update Rollback does not work as the update installation was not paused.

  • CRSVC-44715: Compliance Policy Summary tab not showing correct device count for Compliant or Non-Compliant status when using Device Tags rule.

23.6.0.18

  • CRSVC-45319: Syslog is no longer sending Application Published events after WS1 UEM version 2302.

  • AMST-40279: Windows credentials profile shows as installed in WS1 UEM even when certificates are not delivered to end devices.

  • AAPP-16848: Copying iOS DDUI profile where the context is unknown causes error.

  • AMST-40370: Wifi certificates were not getting auto renewed.

  • AGGL-16310: Fix data mismatch for user data in users and accounts segment of device state.

  • UM-8577: Admin role not auto filled in DDUI when adding an admin manually.

  • AAPP-16827: Fix duplicate entry for setting value creation in credential payload.

  • AAPP-16869: VppV2 deviceId changing to null on clicking sync assets after VppV2 migration is completed.

  • AAPP-16841: Native CICO not updating user list.

  • UM-8633: Unable to create admin groups if "&" is in the distinguished name.

  • AMST-40347: Sensor and Script - Remove SH dependency.

23.6.0.19

  • MACOS-4247: macOS profile keeps spinning for XML, Rollback, More actions action buttons.

  • MACOS-4227: Auto-join gets automatically selected in macOS network profile.

  • MACOS-4224: Unable to add version to macOS profile due to Login Window payload.

  • MACOS-4221: macOS update management does not work when Install Action is “Install Later”.

  • CMSVC-17522: Unable to create smart group through API when the smart group name contains double-byte symbol or number.

  • ARES-27485: Adding a newer version of an app through APIs removes app config KVPs for the previous version.

  • AGGL-16344: Unable to send application configuration for internal app.

  • AAPP-16867: Unable to delete ABM stale record from Enrollment lifecycle page.

  • AAPP-16866: SSO extension payload has multiple issues.

23.6.0.20

  • AAPP-16873: Unable to Clear Activation Lock on iOS devices.

  • AAPP-16875: General Query - Unable to view assignment for Shared iPad for Business for supported profiles.

  • AMST-40315: UEM not processing assignments unless triggered.

  • CMSVC-17511: Inconsistency with the device tag data upon re-enrollment.

  • CRSVC-45826: Secure Channel Failure with Workspace ONE Intelligent Hub for Android.

  • FCA-206865: Console UI HTML Title changes when opening new tab using mouse middle click.

23.6.0.21

  • AAPP-16910: Device attribute phone number modified on Wi-Fi iPads with no sim card.

  • AAPP-16937 iOS Mobileconfig upload results in DDUI blank page.

  • FCA-207099: Terms of Use displaying Unicode value when declined.

23.6.0.22

  • AMST-40597: Edit of Kiosk profiles was failing.

  • UM-8663: OOBE enrollment failing for the customer. Additionally duplicate users created for successful enrollments.

  • UM-8697: Fix error codes for authentication endpoint.

  • FCA-207130: All device types is replaced with "Device Category List" for Device Category when editing any device from the device summary page.

  • AAPP-16920: VppSyncAssets API was throwing error when VppV2 featureflag is enabled.

  • ARES-27604: Admin continuously receiving Device App Logs storage alert for different OGs.

  • CMCM-190930: Increase the maximum page size for managed content DS endpoint.

  • ARES-27602: Workspace ONE Express - Unable to add or edit icon images for web apps.

  • UM-8700: Admin group creation UI fails to search directory group when locale is non-English.

23.6.0.23

  • AAPP-16986: Spacemen error when customer is trying to assign, edit, or manage device for VPP app.

  • CRSVC-46608: Unable to save Intelligent Hub setting page on lower OGs.

  • AMST-40651: WNS notification flow improvement.

  • CRSVC-46476: SAN is missing in eJBCA CSR.

  • UM-8727: Fix the parameter passed to the Microsoft Graph Client APIs when searching by devices.

23.6.0.24

  • AMST-40589: Seeding latest SFD 23.02 build to Workspace ONE UEM 2306 console.

  • ARES-27759: MTD solution no longer showing user info for unmanaged apps after UEM upgrade.

  • ARES-27857: App Removal Protection not triggering when threshold is met.

  • AAPP-17022: The description for Custom B2B apps is not shown in Legacy and Hub catalog.

  • ARES-28059: Database error while hitting the Devices Tab to check the devices assigned details on an app.

23.6.0.25

  • CRSVC-47214: API call invoked commands associated to an unknown admin account.

  • CRSVC-47167: Object reference not set to an instance of an object error if SAN is not configured.

  • ARES-28274: Prevent deletion of blob if it is connected to a resource.

  • ARES-28152: Unable to add Dell command update v5.1.0 from EAR.

  • ARES-28091: Unable to view the XML file of specific iOS profiles if option to sign certificate is enabled.

  • ARES-28054: Web links report is empty.

23.6.0.26

  • CRSVC-47170: Update EJBCA integration to accommodate breaking change in EJBC 8.0 and above.

  • AMST-40836: Drop ship device registration allows the same serial number registration from parent and child OG.

  • CMSVC-17684: Renewal of macOS CLI enrollment triggers 'RemoveApplication' process.

  • UM-8791: The “Organization Group” tab in the Administrator account was removed on the new DDUI from version 2210 onwards.

  • AMST-40886: Windows SAL sampling improvements.

23.6.0.27

  • AMST-40785: Windows BIOS profile missing custom BIOS Attributes after saving.

  • PPAT-16520: Performance improvement in Tunnel sync endpoint.

  • LUEM-843: Latest Hub version from server should contain build version.

  • AMST-40943: Reduce unnecessary calls between UEM and OEM Provisioning Service.

  • MACOS-4372: Environment unable to automatically install Intelligent Hub macOS application.

  • AAPP-17132: Fix phone number data mismatch in default attribute segment of device state.

23.6.0.28

  • AAPP-17154: VPP license cleanup job is causing error and not clearing externally redeemed licenses.

  • UM-8846: Unable to delete or edit directory admin accounts.

  • FCA-207233: Remote Assist from UEM sends non-silent APNs.

  • FCA-207456: Device Events and Console Events filters cannot be managed by Admin user who is assigned build-in Read Only role.

  • AMST-41010: Profile sample is not getting updated until query.

  • MACOS-4370: Unlock pin not escrowed on the Workspace ONE Console.

23.6.0.29

  • UM-8796: UI change to AdminDefination V3 model.

  • ARES-28270: macOS Credential Profile does not save Identity Preference and Certificate Preference correctly in DDUI.

23.6.0.30

  • FS-5465: Creating or editing conditions within a workflow, specifically Application Exists, Matches Found count is incorrect whenever adding or removing Application Versions or Names in Condition.

  • CRSVC-44198: Correlation-Id header is missing from the Device State Migration tool to DST service.

  • CMCM-190986: Remove the command queue to delete content from device during managed content delete.

  • AAPP-17251: VPP application not updating version on the console for one application but does push the updated version to devices.

  • AAPP-17246: Get devices assigned to DEP profile API is failing.

23.6.0.31

  • UM-8923 - VIS to UEM unlink is not removing the UEM user from the UEM group.

  • FS-5534 - Seed Mac workflow host in canonical release 23.06.

  • CRSVC-46415 - CellTrust integration was not working.

  • AMST-41259 - Arm64 hub was not getting published to the device

  • AAPP-17126 - Refreshing AppleCare Warranty information is displaying error "PleaseCheckGSXSettings" for all Apple Devices.

23.6.0.32

  • AMST-41360 Baseline Payload should not have installation status "PENDING_REMOVAL".

23.6.0.33

  • LUEM-858 - All the Linux devices get the same lookup value for sensors.

  • AGGL-16970 - Redirect to Google in EMM registration fails.

  • AAPP-17407 - Refreshing sToken for a VPP v2 enabled OGs, resets migration flag.

  • AAPP-17404 - Fix duplicate asset identifiers in an asset management V2 API call.

  • ARES-27837 - Add FedRamp system code for identifying FedRamp customers

23.6.0.34

  • UM-8872 - “Invalid Data Entered” when editing and saving Admin account - Phone Number value.

  • FCA-207768 - PhysicalMemory values missing in UEM devices or search API call.

  • AMST-41469 - Actual file version is not updating when adding new version for Windows app.

  • PPAT-17067 - Tunnel config XML is blank due to incorrect FE certificate mapping.

  • UM-8988 - With read-only admin we are able to add admin account through batch import.

  • AMST-41128 - Proxy settings not included in Windows profile XML file if configured in WiFi payload.

  • AGGL-16897 - FCM API deprecation updates.

23.6.0.35

  • PPAT-17180 - Limit device traffic rule calls for tunnel server syncs.

  • PPAT-17131 - Tunnel test connection failure.

  • AMST-41537 - Redirect blob download request from DS to CDN when branch is disabled.

  • AAPP-17698 - Improve logging on Apple notification API.

  • AAPP-17679 - Fix looping issue while making association calls for VPP v2.

  • AAPP-17663 - VppNotificationStatusJob is not updating retry count causing the job to process record infinitely.

  • AAPP-17670 - Optimize VPP asset management event data save SP to avoid timeouts.

  • AAPP-17686 - Add request UUID and correlation key headers to logs.

  • AGGL-17049 - FCM not clearing passcode in direct boot mode.

23.6.0.36

  • PPAT-16486 - Cascade front-end root certificate is missing the VPN configuration.

  • FCA-207967 - EULA page crashing for CD environments.

  • AMST-41357 - Device in WNS renewal loop causing DM profiles failure.

23.6.0.37

  • AGGL-17104 - CICO with Launcher apps are not always removed when combined with app assignments.

  • AGGL-16846 - Application configuration shows disabled after publishing an app.

  • AAPP-17717 - Create a migration script to clear old duplicate credential profile setting value data.

  • UM-9107 Rocket or spaceman error when trying to cancel pending records in Batch Status page.

23.6.0.38

  • UM-9100 - Editing an Admin account deactivates the account.

  • MACOS-4806 - Smart group assignment for the macOS internal app fails to be assigned for a couple of users devices.

  • AAPP-17841 - Improve ExternallyRedeemedLicense Job.

23.6.0.39

  • UM-9148 - Implement brokerID in WS1 UEM.

  • PPAT-17449 - Tunnel client was not reconnecting when device regains compliance.

  • MACOS-4811 - Yaml changes macOS hardware seeding.

  • ESI-178 - Admin is assigned Console Admin role, when assigned both platform and UEM roles through RBAC Admin groups.

  • CRSVC-51128 - Add code block on the UEM side to block Conditional access configured at any other customer OG if it is already configured for one customer OG within the same UEM environment.

  • CRSVC-51127 - Add OG check to CA flow which sends unenrollment and non-compliant for existing lingering devices.

  • CMEM-187065 - Deadlock occurred when trying to delete records from the mobile email gateway MEM device activity table.

  • AMST-41861 - Sensor and Script: Remove Search Hub dependency from the APIs.

  • AAPP-17842- Sync Vpp Assets/License fails due to foreign key constraint reference for VppLicenseID.

23.6.0.40

  • MACOS-4881 Cannot Save any modified or new System extension macOS profiles

  • AMST-41994 Application installation status is not reporting correctly on UEM

23.6.0.41

  • MACOS-4815 - macOS device model seeding API implementation.

  • CMSVC-18185 - Disable smart group tenancy correction support from UEM production environments.

  • ARES-30025 - DDUI - Removing new smart group assignment clears existing smart groups.

  • AMST-42069 - Time zone displayed in the Scripts tab is different from the Execution logs.

  • AAPP-17951 - Update the VPP notification status sync job to discard the duplicate notifications.

23.6.0.42

  • AAPP-17986 - Add iOS 18 Passwords app bundle ID to seed data.

  • AGGL-17170 - Workspace ONE not able to automatically retrieve app configuration from custom apk file.

  • CMSVC-17744 - Newly enrolled devices are not being added to the Smart Group causing issues with assignments of resources.

23.6.0.43

  • SINST-176422 - Backport .NET 8 to UEM 2306.

  • AAPP-18024 - Fix data duplication in vppAssetManagementEventData.

23.6.0.44

  • UM-9142 - OG Consolidation script execution failure due to incomplete LDAP sync job.

  • UM-9111 - Console event is not generated when an administrator account is deleted.

  • UM-9083 - Managed By Organization Group for administrator account changes when role assignments are modified.

  • UM-8878 - User provisioning through SCIM APIs may fail due to character length limitations.

  • UM-8753 - SAML authentication response validation is disabled for Omnissa Identity Services integration.

  • RUGG-13304 - Relay servers were unable to connect to the Console when default Mac address was used in the discovery text.

  • CRSVC-56124 - Make previous supported versions compatible to auto-update ACC.

  • ARES-29981 - Few apps cannot be assigned to newly enrolled devices after migrating from On-prem to SaaS environment.

  • ARES-25476 - Profile installation status inconsistent between Device Details Profiles tab and 'View Devices' screen for profiles installed through Workflows.

  • AMST-42510 - Removed URL encoding while uploading icon from EAR.

  • AMST-41549 - Remove the version check from the seeded apps in the mapping table.

  • AAPP-18323 - Unable to install User-Based VPP app on devices that are User enrolled.

  • AAPP-18094 - Fix to prevent returning process-related exceptions except UnAuthorized on Apple callback API.

23.6.0.45

  • PPAT-17066 - Tunnel Standalone Profile page fails to load if Tunnel Health is down.

  • AAPP-18090 - VPP apps install delay fixed.

  • AAPP-17804 - Admin account was stuck in "Delete In Progress" state and must be deleted from the console.

23.6.0.46

  • AAPP-18407 - Improve VPP license reconciliation performance.

  • AAPP-17985 - Add process to purge stale VPP v2 notification data.

  • AAPP-18356 - Fix looping issue when batch size is set to 0.

  • AAPP-18245 - During DEP enrollment, the Device OS version is not correctly read from the device.

23.6.0.47

  • RUGG-13443 - Product fails to honour applicability rule when oemBuildVersion attribute is used more than once in applicability rule.

  • FCA-208683 - Intelligence Opt-In flow showing error screen after clicking on 'Opt-In' button.

  • AAPP-18903 - VPP app Epic Rover app fails to install.

Known Issues

  • ARES-28988 - Admin is not able to export an app’s user ratings. This is impacting all apps - internal, public and purchased apps.

Support Contact Information

To receive support, access Omnissa Customer Connect.For information about filing a Support Request in Customer Connect and using Cloud Services Portal, see the knowledge base article at here.

Documentation

To learn more about Workspace ONE UEM, you can browse Workspace ONE UEM Console Documentation.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…