Workspace ONE UEM Release Notes provide information on the new features and improvements in each release. This page includes a summary of the new features in 2310, issues resolved, and known issues.
When can I expect the latest version?
We strive to deliver high-quality products, and to ensure quality and seamless transitions, we roll out our products in phases. Each rollout may take up to four weeks to accomplish and is delivered in the following phases:
-
Phase 1: Demo, Shared SaaS UATs, and Latest Mode UATs
-
Phase 2: Shared SaaS environments
-
Phase 3: Latest Mode environments
This version is initially available to our SaaS customers on the Latest mode. The features and improvements incorporated in this version will be available to our on-premises or managed hosted customers with the next on-premises release. For more information, see the KB article. Workspace ONE UEM for 2310 release will also be an on-premises release.
Getting Ready for Major OS Releases
Interested in learning about the latest major OS updates and their resulting implications on Workspace ONE? See the Getting Ready for Major OS Releases section in Workspace ONE UEM Console Documentation for more information.
What's New
Console
Would you like to check the Device Registration Status for Conditional Access? We report that in Device Details page.
You can now refer Device Details page on the console to check if the registration was successful and plan further actions such as pushing the desired apps to the devices. Check out Azure conditional access and Google's context-aware access information in Device Details. For more information, see Other Integrations with Directory Services..
Rugged
We've now enabled Agent or Hub Upgrade File-Action upload in partner type OGs too.
Prior to this feature, you could upload Workspace ONE Intelligent Hub Packages only in Global and Customer organization group types. But now, you can upload an AirWatch MDM Agent (also known as Workspace ONE Intelligent Hub) to a partner type organization group. For more information, see Upload a Workspace ONE Intelligent Hub APF File, Upgrade File-Action.
Android
Compromised Device Detection with Play Integrity API.
Workspace ONE UEM can use Play Integrity API to obtain further information about an Android device’s integrity and determine if the device is compromised. Play Integrity API replaces Google’s SafetyNet Attestation API. It works together with the compromised device detection capabilities in Workspace ONE SDK to better protect endpoints and protected resources.
iOS
Deploying iOS profiles is now easier and faster with the new data-driven user interface.
We have completed the rollout of our new Data-Driven User Interface (DDUI) user experience for iOS profiles. This functionality will now be enabled by default starting with Workspace ONE UEM 2310.
We've a new iOS 17 Restriction profile key.
We have implemented the new “Allow iPhone Widgets on Mac” Restriction profile key that was introduced with iOS 17. This key can be used to prevent iPhone widgets on a Mac that have signed into the same Apple ID for iCloud.
macOS
We’ve enhanced macOS profiles.
We have added new configuration profile payload keys introduced in macOS 14 Sonoma to the Workspace ONE Console UI.
Note: DDUI is required for the latest payloads and keys.
Newly supported keys can be found in the payloads listed below. For more information, see macOS Device Profiles.
-
Restrictions
-
SSO Extension
-
Disk Encryption
-
Passcode
-
DNS Settings
Linux
We’ve introduced new device commands.
Workspace ONE UEM now supports Device Reboot, Device Lock, and Full Device Wipe commands for Linux endpoints. IT administrators can now have a little more control, and in the case of Device Wipe, there are additional security controls for devices.
Experience the new Data-driven UI for profiles.
Like other platforms UEM supports, Linux has migrated to the new DDUI framework for profiles. Although functionality is identical, the UI has changed and provides a mechanism to add new profile features at a more rapid pace.
Windows
Software Distribution(SFD) now downloads links on-demand.
We've enhanced the way SFD manages downloads. When the download URL link you received through an earlier install command expires, you are no longer required to resend an application install command to get a new download link. Now, on a need-basis, the Software Distribution (SFD) can send a request to the Workspace ONE UEM server for a new download link
Check out Device Updates to monitor Windows updates progress.
We have improved device updates reporting. With this limited availability feature, you can filter or search Windows devices with different versions in the organization group or child organization. You can easily go through the Device or Update Overview to see if the latest quality updates have been delivered to each device and take further action. For more information, see Resources - Device Updates.
Note: This limited availability feature requires Modern Stack to be activated in the environment.
Track Workflow Status in Provisioning Tool
You can now detect and track the status of Freestyle Workflows through Provisioning Tool. Each workflow will be tracked in the UI and the system will not complete processing (Green Screen) until all the workflows are complete.
Check out more new Windows Security Baseline templates
We have added new templates for creating CIS Windows Benchmarks. Both Windows 10 22H2, and Windows 11 22H2 were added. For more information, see Creating Baselines with a Template.
Freestyle
Quick and easy profile and app removal for Windows devices.
You can now create a workflow for one-time removal of an application and/or profile from a device. After the workflow is deployed on the device, the app or profile is uninstalled successfully.
- To ensure your devices have the minimum required version of Intelligent Hub (2310), you can download version 2310 from https://my.workspaceone.com/products/Workspace-ONE-Intelligent-Hub/
Explore the new Freestyle templates.
Workspace ONE UEM Freestyle templates are now available in Workspace ONE Cloud Marketplace. Utilize these templates to get started with the most common use cases.
Before You Begin
The Workspace ONE Unified Endpoint Management (UEM) console supports the latest stable builds of the following web browsers.
-
Chrome
-
Firefox
-
Safari
-
Microsoft Edge
Comprehensive platform testing has been performed to ensure functionality using these web browsers. If you run the UEM console with an older version browser or on a non-certified browser, you can experience minor issues.
Resolved Issues
- Resolved Issues for 2310
Resolved Issues for 2310
-
HUBW-8770: Device eligibility check fails after app installation.
-
AAPP-16299: No Query Update Status button on UEM 2302 after pushing out iOS updates.
-
AAPP-15989: VPP License is not revoking when Remove Application request is sent through Device Details page.
-
AAPP-16021: Query related to iOS restriction “Allow deprecated TLS versions”.
-
AAPP-16010: Republished profile is being removed from some devices due to stored procedure timeout.
-
AAPP-16024: iOS device freezes in Single App Mode configuration if profile installs before the Hub installs.
-
AAPP-16036: Unable to upload an iOS application with nested watchOS app on the UEM console.
-
AAPP-16037: /mam/apps/purchased/search API does not always return App Size.
-
AAPP-16122: Unable to migrate APNS Certificate from Global OG to Parent OG.
-
AAPP-16191: AirPlay Security profile (tvOS) shows ‘Unknown Payload’ on a device.
-
AAPP-16193: Query to validate Cellular APN as required field with DDUI enabled.
-
AAPP-16245: VPP applications are removed from the Workspace ONE console upon syncing the asset and reappears with no assignments.
-
AAPP-16288: Custom data (key/value) not retained in VPN profile (iOS) after re-opening the profile.
-
AAPP-16389: ABM profile doesn't return proper API response when uuid is used.
-
AAPP-16401: iOS DDUI - Lookup Values not being translated.
-
AAPP-16406: iOS Boxer Standalone enrollment is showing incorrect OS version on UEM console post Boxer level enrollment.
-
AAPP-16426: iOS Web Clip Profile cannot work without a protocol prefix such as http://, https://.
-
AAPP-16434: Unable to edit existing iOS device profiles post UEM upgraded to 23.6.0.1.
-
AAPP-16436: Device Name being set to friendly name when setting is disabled.
-
AAPP-16487: Customer’s orders are seen in other customer’s OG.
-
AAPP-16490: Unable to select credential from dropdown list in iOS DDUI VPN profile with connection type IKEv2.
-
AAPP-16505: DEP assignment taking too long to change UI.
-
AAPP-16527: VPP Auto Update failing with specific country code.
-
AAPP-16533: Content Filter profile saves successfully without the title preventing installation.
-
AAPP-16568: Post VPP V2 migration, Workspace ONE UEM - VPP "Sync Assets" stuck at "Sync in progress" and licenses are seen as “Unknown”.
-
AAPP-16594: Homescreen layout payload is allowing empty app lines.
-
AAPP-16642: Broken icon image for iOS Web Clip Profile.
-
AAPP-16748: Apple Store Bundle ID (com.apple.store.Jolly) is incorrect.
-
AGGL-14899: Android DDUI Profile Payloads not loading.
-
AGGL-14917: Android App groups filter for OS version is not working.
-
AGGL-15212: CSRF Allows Adding and Deleting Android EMM Configuration to Any Tenant while Unauthenticated.
-
AGGL-15357: Unable to create Android profile with a Time Schedule, whose UUID is NULL.
-
AGGL-15845: Android VPN profile throws "Failed to save profile" error when trying to modify it or add a version to it.
-
AGGL-15892: All internal android apps uploaded to the console are getting the default android icon.
-
AGGL-15935: Unable to install profiles on Chrome OS devices post V2 migration.
-
AGGL-15984: {DeviceModel} lookup value in Friendly Name reported as "Android" rather than actual Model Number in Console List View.
-
AMST-38722: Certificate revoked automatically for Windows devices where migration data is missing.
-
AMST-39017: Workflow Stuck in Progress when including install profile for secure mode Windows device.
-
AMST-39055: The default 'Read Only' Admin role to view the Baseline is not working.
-
AMST-39210: Arm x64 agent is not getting installed on OOBE enrolled Windows devices.
-
AMST-39300: WNS Disconnected for multiple Windows devices.
-
AMST-39323: UEM console fails to edit windows profiles the day after they were created onwards.
-
AMST-39412: UEM Workflows: Windows apps do not honor app deferral setting.
-
AMST-39441: Smart Group is not recognizing 32-bit devices from console v2212.
-
AMST-39524: API 'mdm/devices/security' endpoint fails with 500 internal server error for some devices.
-
AMST-39569: Bios Verification status sent incorrectly as a part of Windows Security Information Sample.
-
AMST-39673: Removing Windows update profile does not remove configured policies.
-
AMST-39683: Autopilot enrollment failing after UEM update to 2306.
-
AMST-40069: If the "Managed Applications" payload is configured in Windows profile, checkbox size in other payloads will become huge.
-
AMST-40235: Windows - API call to Begin Install does not work when Value type is 'Multi-String'.
-
ARES-25379: Copied iOS profiles with password present fail to save when Allow Removal is set to 'With Authorization'.
-
ARES-25390: App Publish for Android fails due to duplicate key error when publishing app during device check in.
-
ARES-25740: Device logs not uploaded to console.
-
ARES-25746: WS1 UEM DB - Profile Installation status is not loading for profiles deployed to the entire environment.
-
ARES-25806: Unable to view Application Group page due to crashing.
-
ARES-25819: Deploying internal apps is getting stuck in “Pending Release” status.
-
ARES-26031: Device Profile Status ID incorrect in API Call.
-
ARES-26217: Inactive update profiles getting removed from machines automatically causing the devices unnecessary upgrade to Windows 11.
-
ARES-26243: DDUI - Unable to add multiple apps to folders in Home Screen Layout due to duplicate records from MTS database.
-
ARES-26465: CST Time Zone settings in Workspace One UEM console is throwing Compliance Policy Violation notification and ‘Removal Date’ in Profile settings is using UTC time instead of CST.
-
ARES-26565: Custom attribute value is not displayed in Launcher.
-
ARES-26610: Multiple nodes of MetadataTransformService tried to parse the files and seed them concurrently which causes the DbUpdateConcurrencyException.
-
ARES-27147: WS1 UEM API endpoint continually failing with an error "Collection cannot be null or empty".
-
ARES-26808: Failed to update profile segment attributes.
-
ARES-26828: Unable to add multiple apps to folders in Home Screen Layout of iOS Device Profile.
-
ARES-27084: Profile is showing out of date status on installation after adding the version.
-
CMCM-190579: Large file uploads from App to repo fails.
-
CMCM-190605: "Content Detail by Device" Report incorrect.
-
CMCM-190592: Managed Content not showing up on newly enrolled devices.
-
CMCM-190630: Security tab in Device Details page is intermittently timing out for some macOS devices.
-
CMCM-190643: Adding content via API defaults to unknown "Paxar" value for customer, while the default should be N/A.
-
CMCM-190711: Status of document in content detail report was not corrected.
-
CMSVC-17101: Unable to Assign Internal Application page crashes.
-
CMSVC-17121: When Navigating to Apps tab in device summary, page errors out.
-
CMSVC-17091: Assignments based on user group do not update name when name of user group is changed, for AD user groups.
-
CRSVC-36850: iOS - Device details certificates tab not showing full certificate metadata (OU details).
-
CRSVC-37221: Azure conditional access Shared Device Mode is failing with errors.
-
CRSVC-37564: ADCS certificate chain is building incorrectly when Root and IM1 have identical subject names.
-
CRSVC-37764: Android compliance status not being refreshed.
-
CRSVC-38282: User in Device List View is Incorrect.
-
CRSVC-38313: Syslog integration for SIEM.
-
CRSVC-38570: Stop throwing exception From DSM in case 404 enrollment user not found.
-
CRSVC-38914: Unable to send custom commands.
-
CRSVC-40519: Navigating to app events gives spaceman error.
-
CRSVC-41218: The console is not getting samples from Android and iOS devices post upgrade from 2209 to 23.2.0.17.
-
CRSVC-41904: SQL fails to complete the maintenance job "AirWatch - Purge Expired Sample Data".
-
CRSVC-42926: Admins receiving email that 50% API Utilization limit being hit for a specific OG.
-
CRSVC-42227: S/MIME certificates are getting revoked on macOS devices whenever the certificate profile is removed or device is unenrolled.
-
CRSVC-43269: WS1 UEM - Syslog is no longer sending Application Published events after Patch 21 upgrade of UEM version 2302.
-
CRSVC-43376: Android Shared Device Mode app configuration with the Microsoft Authenticator app is not completing.
-
ENRL-3770: Enrollment Restrictions not blocking enrollment for logged in AD users when ASSIGNTOLOGGEDINUSER=Y in command line enrollment.
-
ENRL-3771: Under wipe log, 'Device Last Seen' information showing incorrectly for non-US locale.
-
ENRL-3809: One iOS device got enrolled with the lower OS version than the one set on enrollment restriction policy.
-
ENRL-3848: Devices within the customer OG are shown as being enrolled to the users from a different tenant in the same console.
-
ENRL-3889: Enrollment Restriction policy is not functioning as intended, allowing to enroll more devices than specified in the policy.
-
ENRL-3897: Unable to save enrollment restrictions settings due to bad data in database.
-
FCA-205518: Unable to send the Push Notifications/Email notifications using Bulk Management.
-
FCA-205533: Leaving the Asset number blank on device details page, it is taking up the last initial value.
-
FCA-205604: No new data is Syncing to Intelligence from the UEM.
-
FCA-205608: When viewing Devices > List view > Custom Layout and you start to rearrange the columns the data under it starts to mis-match with the header.
-
FCA-205650: Spaceman error when accessing OG List View page from customer OG.
-
FCA-206024: Unable to send template message to device from public app details device tab.
-
FCA-206027: Console allows creation of a customer-type OG under another customer-type OG.
-
FCA-206036: Device Events and Console Events filters cannot be managed by Admin user who is assigned build-in Read Only role.
-
FCA-206087: All device types is replaced with "Device Category List" for Device Category when editing any device from the device summary page.
-
FCA-206189: CSRF Protection Bypass Exposes Authorization Header for Certificate Authentication from any Tenant.
-
FS-3877: Workflow failing to execute script due to unauthorized error from inability to refresh the token after reassignment.
-
FS-3932: Admin Role Permissions Needed to Edit Freestyle Workflows.
-
FS-4179: Workflow stuck in progress when including install profile in UEM version 2302.13.
-
FS-4491: Fix performance and workflow status reporting issues in workflows for profile installation.
-
FS-4561: macOS Workflow status doesn't update without manual query.
-
FS-4620: macOS Workflow stuck waiting on profiles.
-
INTEL-51802: Intelligence Android Application App Version Code is not fetched correctly.
-
MACOS-3914: MAC OS profile Keeps spinning in the Japanese language.
-
MACOS-3993: Unable to setup admin account on a macOS device.
-
MACOS-4021: Device list export not working.
-
MACOS-4038: Incorrect App Bundle ID is updated on WS1 for macOS apps using Electron Framework.
-
MACOS-4074: Apple DEP devices are not being set to "Corporate Owned".
-
MACOS-4082: Device Bluetooth turns off upon saving the “Set Friendly Name as Device Name” setting in the UEM console.
-
PPAT-15360: Failed to add the new version to Android DDUI Profile.
-
PPAT-15803: Tunnel server traffic rule with Pac Reader does not work.
-
RUGG-11951: Multi-user CICO failing for Android AOSP device.
-
RUGG-12150: Products are not installed on devices that check in after remaining offline for more than 30 days.
-
RUGG-12153: Android devices staging fails as cached sideload package is downloaded instead of new config.
-
RUGG-12165: Getting the error: 'Invalid inputs, please try again.' when we click on "Test Connection" for the Push Relay servers.
-
RUGG-12201: Unable to get the launcher speed lock down feature working.
-
RUGG-12345: Getting a blank screen when navigating to Devices > Provisioning > Components > Profiles > Add profiles > Windows.
-
RUGG-12398: IDOR Allows Read/Write Access to Staging Devices.
-
RUGG-12402: Products are showing In Progress after UEM upgrade.
-
RUGG-12643: Public apps missing in Launcher app layout since WS1 upgrade to 2306.
-
RUGG-12670: App search bar does not appear in Launcher when the profile is in multi-app mode.
-
RUGG-12696: WS1 servers is not able to Connect to SFTP Relay Servers after the relay server SFTP settings have been updated to disable SHA-1 key exchange.
-
UM-7778: UserGroupActions APIs in System Management V2 return 404.
-
UM-7851: Directory Admin accounts created at OGs below SAML config cannot log in or be edited.
-
UM-8131: Admin Group Creation UI fails to search directory group when locale is non-English.
-
UM-8132: Unable to add new or modify existing administrators when the email address contains multiple consecutive special characters.
-
UM-8138: OOBE enrollment failing for the customer. Additionally duplicate users created for successful enrollments.
-
UM-8186: API /admins/{id}/update can update admin password bypassing password policy.
-
UM-8261: LDAP Sync page showing incorrect Created Date for LDAP Sync Job.
-
UM-8374: With Read only admin we are able to add admin account through batch import.
-
UM-8502: Unable to create Admin Groups if there are restricted characters in Distinguished Name.
Patch Resolved Issues
- 23.10.0.1
- 23.10.0.2
- 23.10.0.3
- 23.10.0.4
- 23.10.0.5
- 23.10.0.6
- 23.10.0.7
- 23.10.0.8
- 23.10.0.9
- 23.10.0.10
- 23.10.0.11
- 23.10.0.12
- 23.10.0.13
- 23.10.0.14
- 23.10.0.15
- 23.10.0.16
- 23.10.0.17
- 23.10.0.18
- 23.10.0.19
- 23.10.0.20
- 23.10.0.21
- 23.10.0.22
- 23.10.0.23
- 23.10.0.24
- 23.10.0.25
- 23.10.0.26
- 23.10.0.27
- 23.10.0.28
- 23.10.0.29
- 23.10.0.30
- 23.10.0.31
- 23.10.0.32
- 23.10.0.33
- 23.10.0.34
- 23.10.0.35
- 23.10.0.36
- 23.10.0.37
- 23.10.0.38
- 23.10.0.39
- 23.10.0.40
- 23.10.0.41
- 23.10.0.42
- 23.10.0.43
- 23.10.0.44
- 23.10.0.45
- 23.10.0.46
- 23.10.0.47
- 23.10.0.48
- 23.10.0.49
- 23.10.0.49
- 23.10.0.50
- 23.10.0.51
- 23.10.0.52
- 23.10.0.54
23.10.0.1
-
FCA-206489: Upgrade handlebars js to latest versions to mitigate security risk.
-
AMST-40252: Windows credentials profile shows installed when the certificate request fails.
-
CMSVC-17353: Smart Group search returns complete path of the organization group.
-
PPAT-15759: Copy Identifier button is not functional within the tunnel list view page.
-
AMST-40293: Seed 23.02.8 patch to Workspace ONE UEM console.
-
CMCM-190858: Handle server connection error to repositories.
23.10.0.2
-
UM-8525: Admin role not auto filled in DDUI when adding Admin manually.
-
MACOS-4195: macOS restriction payload automatically adds Activity Monitor to Allowed Apps in the Launch Restrictions.
-
MACOS-4186: Unable to add version to macOS profile due to login window payload.
-
MACOS-4184: macOS update management does not work when the install action is “Install Later”.
-
MACOS-4137: Auto-join gets automatically selected in the macOS network profile.
-
CMSVC-17479: Unable to push iOS update, page was crashing and getting error.
-
ARES-26580: Fix application segment data mismatch from Apple devices.
-
AMST-40324: Wifi certificates were not getting auto-renewed.
-
AMST-39891: Sensor and Script - Remove search Hub dependency.
-
AAPP-16599: Fix duplicate entry for setting value creation in the credential payload.
-
AAPP-16722: Native CICO was not updating the User List.
23.10.0.3
-
AMST-40267: Workspace ONE UEM was not processing assignments unless triggered.
-
FS-4746: Workflow deployment options were not showing in freestyle.
-
ARES-27264: Apps/APIs - Adding a newer version of an app through APIs removes the app config KVPs for the previous version.
-
UM-8450: The translated strings "Basic", "Temporary", and "Directory" are not loaded in the admin type column of the administrator page.
-
AAPP-16864: iOS Mobileconfig upload results in DDUI blank page.
-
CRSVC-45792: Secure channel failure with Android Intelligent Hub 20.X.
-
CMSVC-17435: Unable to create a smart group via API when smart group name contains double-byte symbol or number.
-
CMSVC-17509: Inconsistence device tag data upon re-enrollment.
-
AAPP-16701: Unable to clear Activation lock on iOS devices.
-
AAPP-16809: Copying iOS DDUI profile where the context is unknown causes error.
23.10.0.4
-
UM-8426: User group sync select by DN was throwing error.
-
FCA-205246: Terms of use displaying unicode value when declined.
-
CRSVC-42335: Stale DSM override records not being cleaned up due to exception.
-
AAPP-16792: VppSyncAssets API throwing error with VppV2 featureflag enabled.
-
INTEL-56281: Add device Azure registration status support in ETL V1.
-
AAPP-16829: Device attribute phone number modified on WiFi iPads with no SIM card.
-
AAPP-16892: iOS Updates - Eligible device models are blank.
-
AAPP-16682: Unable to view assignment on shared iPad for business for supported profiles.
-
AAPP-16834: VppV2 deviceId changing to null on clicking sync assets after VppV2 migration is completed.
-
AAPP-16633: Unable to delete ABM stale record from the Enrollment lifecycle page.
-
UM-8646: Implement brokerID in Workspace ONE UEM.
23.10.0.5
-
AMST-40597: Edit of Kiosk profiles was failing.
-
UM-8574: Fix error codes for authentication endpoint.
-
ARES-25268: Workspace ONE Express - Unable to add or edit icon images for Web apps.
23.10.0.6
-
AAPP-16943: Not able to configure EAS payload when credential payload is added.
-
AGGL-14885: ChromeOS Credentials Profiles do not redeploy between user logins.
-
UM-8727: Fix the parameter passed to the Microsoft Graph Client APIs when searching by devices.
-
AAPP-16463: Spacemen error when customer is trying to assign/edit/Manage Device for VPP app (proloquo2g).
-
CRSVC-44714: SAN is missing in eJBCA CSR.
23.10.0.7
-
RUGG-12350: CustomAtttibute sample update in DeviceState was failing due to duplicate custom attributes mapping.
-
ARES-27674: ARP not triggering when threshold is met.
-
UM-8719: Unable to access user groups even with the admin roles and right permissions.
-
AAPP-16991: VPP application was not updating version on the console for one application but does push the updated version to the devices.
-
AAPP-15183: The description for custom B2B apps was not shown in the Legacy and Hub catalog.
-
ENRL-4098: After WS1 UEM 2310 upgrade, iOS CICO fails when the OS version is used in the Enrollment Restriction policy.
-
AMST-40710: Seed Windows Hub 23.10.5 x86 UEM console 2310.
-
CRSVC-46455: Unable to save Intelligent Hub setting page on lower organization groups.
-
CRSVC-46731: Device summary tab, security card was not displaying Azure Active Directory Registration or Azure Device ID under device details.
-
CMCM-190923: Increase the maximum page size for managed content DS endpoint.
23.10.0.8
-
ARES-27051: Rule action is not reflecting on the autocomplete field type (default).
-
ARES-27794: Database error while hitting the Devices tab to check the devices assigned details on an app.
-
ARES-27798: Web links report is empty.
-
ARES-27955: Total assigned devices in preview of profile assignment page does not work properly.
-
ARES-28090: Unable to view the XML file of specific iOS profiles if option to sign certificate is enabled.
-
ARES-28121: Unable to add Dell command update v5.1.0 from EAR.
-
ARES-27792: macOS credential profile does not save identity preference and certificate preference correctly in DDUI.
-
CRSVC-45750: Bulk SMS fails when notifying over 500 devices.
-
CRSVC-47017: API call invoked commands associated to unknown admin account.
-
MACOS-4265: Cannot save any modified or new system extension macOS profiles.
-
AMST-40765: Seeding - latest SFD 23.10 build to WS1 UEM 2310 or 2402 or master releases.
-
CMSVC-17670: Renewal of macOS CLI enrollment triggers 'RemoveApplication' process.
-
CRSVC-47130: Object reference not set to an instance of an object error if SAN is not configured.
23.10.0.9
-
CRSVC-46849: Update EJBCA integration to accommodate breaking change in EJBC 8.0 and above.
-
AMST-40526: Drop Ship device registration allows the same serial number registration from parent and child OG.
-
CMSVC-17671: SmartGroupSearch - V2 intermittent failure due Internal server error.
-
AAPP-17074: On demand VPP assignments are installing on devices automatically.
-
AMST-40687: Unable to save profile with two certificates, error: Save Failed. Invalid Certificate.
-
AMST-39272: Windows SAL sampling improvements.
23.10.0.10
-
AMST-38952: Windows BIOS profile missing custom BIOS Attributes after saving.
-
LUEM-835 Latest Hub version from server should contain build version.
-
AMST-38933: Reduce unnecessary calls between UEM and OEM Provisioning Service.
-
ARES-28244: When we add two or more Geofencing locations to the profile, only one Geo location displays in UI.
-
AMST-40955: Unable to save iOS SDK profiles.
-
AMST-40972: Profile with multiple Credential payloads is failing while adding new version.
-
MACOS-4368: Environment unable to automatically install Intelligent Hub macOS application.
-
RUGG-12568: Create additional logging for Smart Group removal flows.
-
FS-5031: Cannot use negative integers in WorkFlow condition checks.
-
CMCM-190922 Localization blocks upload of managed content.
23.10.0.11
-
AGGL-16565: Redirect to Google in EMM registration fails.
-
AAPP-17047: VPP license cleanup job is causing errors and not clearing externally redeemed licenses.
-
CMCM-190772: Special character check for Managed content name only on the Info page.
-
UM-8807: Unable to delete or edit directory admin accounts.
-
FCA-206199: Remote Assist from UEM sends non-silent APNs.
-
AMST-40969: Seed Windows Hub 23.10.6 x86 to UEM console Master.
-
AMST-40984: Profile sample is not getting updated until query.
23.10.0.12
-
UM-8570: UI change to AdminDefination V3 model.
-
UM-8444: The “Organization Group” tab in the Administrator Account was removed on the new DDUI from v2210 onwards.
-
AGGL-16745: Android COPE enrollment fails when using the IMEI for the enrollment token.
-
FCA-207510: Available OS updates not listed on the device details summary page.
-
CRSVC-47902: SAN variable values passed as string literals.
-
AMST-40976: All UEM Console 2310 and 2402 and master branches were seeded with SFD 23.10.0.18 installer.
23.10.0.13
-
CRSVC-43986: Correlation ID header is missing from the Device State Migration tool to DST service.
-
FS-5414: Matches Found count is incorrect whenever adding/removing Application Versions/Names in Condition.
23.10.0.14
-
RUGG-12991: Custom Attribute API unable to create a Custom Attribute with double-byte alphanumeric via API.
-
MACOS-4008: Add Execution of script to re-install Intelligent Hub Settings profile for already enrolled devices.
-
ENRL-4095: Update logging for failure of enrollment restriction check.
-
CMCM-190986: Remove the command queue to delete content from device during managed content delete.
-
AMST-41181: Seed Windows Hub 23.10.7 x86 to UEM console 2310.
-
AAPP-17049: VPP failures while resolving enrollment users.
23.10.0.15
-
UM-8905 - Issues while retrieving and updating VIS user data.
-
UM-8864 - “Invalid Data Entered” when editing and saving Admin account - Phone Number value
-
CRSVC-46068 - CellTrust integration was not working.
-
AMST-41274 - Seed Windows Hub 23.10.8 x86 to UEM console 2310.
-
AMST-39774 - Kiosk profile was not working on Windows 11 while it works perfectly on Windows 10.
-
AMST-41242 - Seeding latest SFD 23.10.1 build to UEM 2310 release.
23.10.0.16
-
UM-8917 - VIS to UEM unlink is not removing the UEM user from the UEM group.
-
ARES-28503 - Summary tab is reporting incorrect number of installed profiles for macOS platform.
-
ARES-27373 - FastSync when enabled does not show enabled in UEM after saving the App assignment.
-
AMST-41202 - Baseline payload should not have installation status "PENDING_REMOVAL".
-
AMST-41101 - Arm64 hub not getting published to device.
23.10.0.17
- PPAT-16943 - Limit Device traffic rule calls for Tunnel Server syncs.
23.10.0.18
-
MACOS-4330 - macOS devices update notification repeating after install.
-
CRSVC-48979 - Enrolled macOS device was not getting assigned to the workflow and takes hours to get assigned.
-
AAPP-17310 - The VPP application publish was failing due to the SPROC timing out.
23.10.0.19
-
UM-8842 - Unable to view User Groups for certain User Accounts regardless of the admin role.
-
FCA-207737 - Physical memory values missing in Workspace ONE UEM devices or search API call.
-
AMST-40244 - Actual file version is not updating when adding new version for Windows app.
-
AGGL-16985 - Not able to publish public app with SG having devices.
-
AAPP-17051 - VPP failures for asset management due to duplicate assets in request to V2 endpoints.
23.10.0.20
-
CMCM-190997 - Content dashboard most/least viewed files section is empty.
-
AMST-40778 - Proxy settings not included in Windows profile XML file if configured in Wi-Fi payload.
-
AGGL-16898 - FCM API deprecation updates.
-
AAPP-17255 - Issue placing the iOS WebClip on the Home Screen first page.
23.10.0.21
-
FS-5716 - Windows app install fail.
-
FS-5690 - Workflows install retired app version.
-
CRSVC-45834 - Workspace ONE device-based compliance policy not automatically evaluating compliance and actions.
-
CMCM-191000 - Intelligence report seeing discrepancies with specific filters and columns for the category of device content.
-
CMCM-190959 - Optimize user repository creation during content sync.
-
AMST-41488 - Redirect blob download request from DS to CDN when branch is disabled.
-
AAPP-16964 - Refreshing sToken for a VPP v2 enabled OGs, resets migration flag.
23.10.0.22
-
PPAT-16819 - Update page size to 500 in tunnel configuration export.
-
CRSVC-48864 - Unable to save the syslog settings with the hostname.
-
AGGL-17049 - FCM not clearing passcode in direct boot mode.
23.10.0.23
-
CRSVC-48609 - Device wipe log report showing no entries.
-
AMST-41589 - Seeded latest SFD 23.10.2 build to UEM release 2310.
-
AAPP-17212 - iOS Restrictions profile Hide or Show apps list is blank.
-
AMST-41558 - Seeded Windows Hub 23.10.9 x86 to UEM console 2310.
23.10.0.24
-
PPAT-17120 - Tunnel test connection failed.
-
MACOS-4351 - MAC install fonts.
-
FS-5811 - Incoherence of devices number related to a specific SG.
-
CRSVC-48317 - Enrollment tests fail intermittently on IT builds when RLS is enabled.
-
ARES-29119 - Application_Uuid is missing while running API call.
-
AMST-40407 - Increase application installation timeout
-
AAPP-16282 - Derived credentials iOS profile's "installed" count constantly fluctuates.
-
UM-8892 - Admin Group creation UI fails to save when locale is non-English.
-
AGGL-16666 - Deprecate legacy play EMM API for Android.
23.10.0.25
-
UM-8638 - User groups list view errors out at top OGs with error has occurred.
-
ARES-27051 - Rule action was not reflecting on the autocomplete field type (default).
-
AMST-41277 - Device in WNS renewal loop causing DM profiles to fail.
-
AGGL-17018 - CICO with Launcher apps are not always removed when combined with app assignments.
-
AAPP-16799 - VppNotificationStatusJob was not updating the retry count, causing the job to process the record infinitely.
-
AAPP-17695 - Improve logging on Apple notification API.
-
AAPP-17678 - Fix looping issue while making association calls for VPP v2.
23.10.0.26
-
UM-9042 - Editing an admin account deactivates the account.
-
PPAT-17309 - Multi-factor authentication in allowlist table for Tunnel payload.
-
MACOS-3910 - Smart group assignment for the macOS internal app fails to be assigned for a couple of users' devices.
-
AMST-41808 - Seed Windows Hub 23.10.10 x86 to UEM console 2310.
-
ARES-27488 - Unable to delete certain internal apps.
-
AGGL-17115 - Application configuration inconsistent behavior for check-in check-out users on Android devices.
-
AAPP-17305 - forceAirDropUnmanaged is enabled by default on ABM shared iPad.
-
AAPP-17277 - Create a migration script to clear old duplicate credential profile setting value data.
-
AAPP-17687 - Add request uuid and correlation key headers to logs.
-
UM-9060 - Rocket/Spaceman error when trying to cancel pending records in Batch Status page.
23.10.0.27
-
UM-9061 - Admins with source equals Cloud Services can be edited in UEM admin list view.
-
MACOS-4269 - Unlock pin not escrowed on the Workspace ONE UEM Console.
-
FCA-206523 - Device location log retrieves many records for a sample time. So, it looks like duplicated records.
-
CRSVC-50027 - Add OG check to CA flow which sends unenrollment and non-compliant for existing lingering devices for Microsoft tenant.
-
CMEM-187045 - Deadlock occurred when trying to delete records from the mobileEmailGateway. MEMDeviceActivity table.
-
AGGL-17234 - Fix lookup field resolution for app configurations when using new devices.
-
AGGL-17149 - Android restrictions JSON exceeds memcached limit.
-
AAPP-17458 - Improve ExternallyRedeemedLicense job.
-
AAPP-16916 - Refreshing AppleCare warranty information is throwing the error "PleaseCheckGSXSettings" for all Apple devices.
-
AAPP-16849 - VPP Timeouts seen in deviceApplication.VppAssetManagementEventData_Save.
23.10.0.28
- AGGL-17248 - To deploy apps through new devicepolicy API, update autoupdatepriority value for apps to 0.
23.10.0.29
-
RUGG-13164 - API Search filter does not work for Product Extensive search API call.
-
AGGL-17280 - Unable to modify and save the iOS app assignments.
-
AGGL-17200 - Internal apps are removed through Google EMM APIs during CICO with PlayEmmDeprecationForAppPublishFeatureFlag enabled.
-
AAPP-17220 - Update to support V2 flow.
-
ARES-28360 Unhandled exception on the DS nodes.
23.10.0.30
-
RUGG-12947 - Screen orientation does not stay locked in "portrait mode" on Zebra TC77s.
-
FCA-206880 - Device List View is not sorted by Build Version.
-
ESI-111 - Admin is assigned Console Admin role when assigned both platform and UEM roles via RBAC Admin groups.
-
CRSVC-39303 - Changing pagination on the event crashes the page.
-
AMST-41764 - (Sensor & Script) Remove Search Hub dependency from the APIs.
-
AAPP-17816 - Sync Vpp Assets/License fails due to foreign key constraint reference for VppLicenseID.
23.10.0.31
-
FCA-206903 - Push notification does not leave the log in the EventLog when the HUB service is enabled.
-
FCA-207109 - TOU list view miscounts number users when multiple language versions are set.
-
CRSVC-50186 - Prevent certificate from changing not in use status for 48 hours.
-
AMST-42013 - Seeding - latest SFD 23.10.3 build to UEM - 2310 release.
-
AMST-41960 - Application installation status is not reporting correctly on UEM.
-
AGGL-17044 - Highly intermittent failures in smart group reconciliation for Zebra devices where Make/Model criteria is used.
-
AGGL-16399 - Fix integration tests which are using deprecated API endpoints.
-
FCA-208096 - PhysicalMemory values missing in UEM devices/search API call.
23.10.0.32
-
PPAT-17434 - Tunnel client not reconnecting once device regains compliance.
-
FCA-207834 - Pendo account ID being incorrectly captured as the same across multiple customer Organization Groups.
-
ARES-29486 - APIs for uploading the logs using Multipart and fetching LUT fails if Workspace ONE apps are not assigned to Organization Group.
-
ARES-27803 - Device Security Posture report profile "Pending Installs" count inconsistency.
23.10.0.33
-
CRSVC-51239 - Event notifications inheritance at sub child OG inheriting wrong rules.
-
AMST-41345 - Large awwnsnotification message size causing process failures.
-
ESI-201 - Devices not being moved to the correct OG by IP address.
-
AMST-42115- Seeding - latest SFD 23.10.4 build to UEM - 2310.
-
AMST-41802 - Time zone displayed in Scripts tab is different from the Execution logs.
-
CMSVC-18184 - Disable Smart Group Tenancy Correction support from UEM production environments.
-
AMST-42059 - Firewall profile failing to install on Windows 11 systems.
-
CMSVC-17744 - Newly enrolled devices were not added to the Smart Group causing issues with assignments of resources.
-
MACOS-4530 - macOS device model seeding API implementation.
23.10.0.34
-
UM-9142 - OG consolidation script fails.
-
UM-9168 - Scim user API throws an error while patching user data if the path is not supported and the value is empty or null.
-
AAPP-17986 - Add iOS 18 "Passwords" app bundle ID to seed data.
23.10.0.35
-
FCA-208096 - PhysicalMemory values missing in UEM devices/search API call.
-
CRSVC-49934 - Disable system admin password.
-
UM-8753 - Authentication response security option in SAML.
23.10.0.36
-
PPAT-17066 - Improvement to prevent crash of DDUI profile page if tunnel health is down.
-
UM-9174 - Unable to switch basic users to AD users through the User Migration tool.
23.10.0.37
-
RUGG-13020 - Unable to download certain .ps1 files which uploaded in UEM.
-
CMCM-191091 - Duplicate entries returned for new folder resources created on NFS repository.
23.10.0.38
- SINST-176422 - Backport .NET 8 to Workspace ONE UEM 23.10.
23.10.0.39
-
FCA-208928 - Rollback axios dependencies
-
FCA-207350 - Remove VMware Analytics from UEM console - Canonical.
-
ARES-29652 - Child OG remains undeleted despite the attempt to delete it
-
AMST-42465 - Seed Windows Hub 23.10.11.0 x86 to UEM 2310.
-
AMST-42453 - Seeding - latest SFD 23.10.5 build to UEM release - 2310.
-
AMST-41549 - Remove the Version Check from Seeded Apps in the mapping table.
-
AAPP-18024 - Fix data duplication in VPP asset management event data.
-
AAPP-18094 - Fix to prevent returning process related exceptions except UnAuthorized on Apple callback API.
23.10.0.40
-
UM-8878 - Input data validation SCIM API.
-
UM-9111 - Administrator user deletions must be logged.
-
CMSVC-17777 - Internal server error reported from MDM tags API when tag is not assignable to any of the devices.
-
AMST-42510 - Removed URL encoding while uploading icon from EAR.
-
AMST-41549 - Remove the Version Check from Seeded Apps in the mapping table.
23.10.0.41
-
UM-9173 - Page crashes when trying to load user group list view page.
-
RUGG-13331 - Organization group deletion fails when Relay Servers have undelivered content in the queue.
-
RUGG-13304 - Relay Servers were unable to connect to the Console when default Mac address was used in the discovery text.
-
RUGG-13040 - Products being pushed to unintended devices when assignment rules have integer-based custom attributes.
-
CRSVC-56124 - Make previous supported versions compatible to auto-update ACC.
-
ARES-29939 - Unable to save iOS Boxer application configuration when the “Enable FastSync” App Policy is applied.
-
AAPP-18323 - Cannot install user-based VPP app on device that are user enrolled.
23.10.0.42
-
RUGG-13370 - Unable to save Schedule type Condition when the schedule date is in the year 2025 or later.
-
RUGG-13232 - Product search (/products/search) and Product extensive search (/products/extensivesearch/) APIs are returning a default policy UUID(0000-000) instead of the actual Device Policy UUID.
-
RUGG-12961 - UEM-Console - Finnish special vowels are not loading in the DDUI while reloading/editing the profile.
-
PPAT-18289 - Device-initiated sync of Tunnel Device Traffic Rules pulling cached policy and not new policy.
-
ARES-31047 - Launcher Profile configured with Custom Lookup fields failing to install on devices.
-
AMST-42501 - ModStack - Firewall Profile failing to install on Windows 11 systems.
-
AGGL-17940 - Android Apps lose assignments after being renamed.
23.10.0.43
-
RUGG-13303 - Organization Group change for Zebra Printers does not automatically update the SmartGroup subscriptions.
-
MACOS-5322 - MacOS devices not completing enrollment as expected and Getting stuck on "waiting for management" server while DEP enrollment.
-
ARES-30902 - Devices failing to install Internal App within 24 hours of receiving install instructions may install latest version afterwards.
23.10.0.44
-
UM-9396 - Unable to add user groups to a customer-type organization group (OG) from a partner-type OG.
-
AAPP-17804 - Admin account stuck in "Delete In Progress" state, must be deleted from the console.
-
AMST-42780 - Seed SFD 23.10.6 to UEM 23.10.
23.10.0.45
-
PPAT-17178 - Custom Configuration support for iOS and macOS (Tunnel-VPN payload).
-
FCA-208683 - Intelligence Opt-In flow showing error screen after clicking the 'Opt-In' button.
-
CRSVC-58522 - Windows failed to fetch metadata from the server for workflows.
-
AMST-42826 - Commands getting queued on Windows devices post console upgrade to 2406.
-
AGGL-18021 - Prioritize Installation of Tunnel Profile.
-
AGGL-17170 - App config settings not configurable in the UEM console for internal apps built using android.enableResourceOptimizations=true.
-
AAPP-18245 - The Device OS version is not correctly read from the device during DEP enrollment.
-
AAPP-17985 - Enhance purge script logic to handle stale VPPv2 notification data (30 day retention).
-
AAPP-17815 - Custom command shows Pending under Troubleshooting tab in Device Details.
23.10.0.46
-
RUGG-13443 - Product fails to honor applicability rule when oemBuildVersion attribute is used more than once in the applicability rule.
-
HUBW-17234 - Fixing issue with apps stuck in SFD queue and not processing any app installs even when pushed manually.
Note: This fix is available as part of SFD version 23.10.7 that is seeded into UEM version 23.10.0.46.
23.10.0.47
-
MACOS-4328 - Provide Full Disk Access to the process "managedsoftwareupdate" to ensure application installations do not fail.
-
AAPP-18691 - Cannot install some VPP Apps due to an Associate Failure for licenses.
-
AGGL-16360 - Fix cast exception after moving Google API Calls for Android CICO Event from SmartGroup Service to Integration Service.
-
AAPP-18090 - VPP apps install delay fixes.
23.10.0.48
- FCA-207991 - Updated console notification templates.
23.10.0.49
-
ARES-31049 - Legacy app catalog is not removing from Android and iOS devices after disabling it from UEM.
-
RUGG-13436 - RSCC fails to pull content with duplicate entries for same relay server mapped to different RSCCs.
23.10.0.50
-
FCA-210456 - Update the 'Help Page' link to the new Omnissa Docs portal.
-
FCA-209879 - Resolves CVE-2025-25229. For more information about these vulnerabilities and their impact on Omnissa products, see OMSA-2025-0004.
-
CRSVC-62527 - Resolves CVE-2025-25231. For more information about these vulnerabilities and their impact on Omnissa products, see OMSA-2025-0004.
-
CRSVC-61977 - Transitioned Token Service URLs to updated Workspace ONE domains (workspaceone.com).
-
AGGL-18563 - Modify sub-domain Enterprise ID comparison logic for GSuite setup across multiple environments.
23.10.0.51
- AAPP-19167 - Denied URLs is blank when editing an iOS Content Filter profile.
23.10.0.52
- AGGL-18082 - Move Google API calls from Entity Reconcile Service to Integration Service for events like User Group Edited.
23.10.0.53
- FCA-210523 - Add fallback support for old domain.
23.10.0.55
- AAPP-19421 - Improvements to dissociation logic for Apple VPP.
Known Issues
Work profile enrollments using tokens for Registered Android 10+ devices may fail
Work profile enrollments using a token for Android 10+ devices will fail if the device is registered with any of the identifiers such as IMEI, Serial Number, or UDID.
Customers using the affected UEM version and intending to register Android 10+ devices for Work Profile enrollment should create the device registration record without using identifiers such as IMEI, Serial Number, and UDID. If a device is already registered, we recommend updating the registration record by removing these identifiers and re-generating the token for enrollment.
For customers who have not yet consumed the affected UEM version, it is strongly recommended to review the device identifiers used for registering devices before proceeding with the upgrade.
For more information, see the Knowledge Base Article
- UM-8444: Organization Group tab in the Administrator Account is removed on the new DDUI from version 2210 or later
When trying to edit the account, users get an access denied error message and the Organization Group details cannot be found.
There is no workaround for this issue.
- AAPP-16722: Native Check in Check out not updating user list.
When signed in with Apple ID on the device, the device should be assigned to the end user on the console. The device is not getting assigned to the end user on the User List tab. On the shared device logs, we could see only the check out and check in happening. The Hub does not automatically get logged in and the Web clip profiles are not deployed.
Support Contact Information
To receive support, access Omnissa Customer Connect.For information about filing a Support Request in Customer Connect and using Cloud Services Portal, see the knowledge base article at here.
Documentation
To learn more about Workspace ONE UEM, you can browse Workspace ONE UEM Console Documentation.
Was this page helpful?