Workspace ONE UEM Release Notes provide information on the new features and improvements in each release. This page includes a summary of the new features in 2402, issues resolved, and known issues.
When can I expect the latest version?
We strive to deliver high-quality products, and to ensure quality and seamless transitions, we roll out our products in phases. Each rollout may take up to four weeks to accomplish and is delivered in the following phases:
-
Phase 1: Demo, Shared SaaS UATs, and Latest Mode UATs
-
Phase 2: Shared SaaS environments
-
Phase 3: Latest Mode environments
This version is initially available to our SaaS customers on the latest mode. The features and improvements incorporated in this version will be available to our on-premises or managed hosted customers with the next on-premises release. For more information, see the KB article.
Getting Ready for Major OS Releases
Interested in learning about the latest major OS updates and their resulting implications on Workspace ONE? See the Getting Ready for Major OS Releases section in Workspace ONE UEM Console Documentation for more information.
What's New
Legacy APIs
We are removing legacy Workspace ONE UEM APIs
Important:
To enhance performance and security, we have improved our Workspace ONE UEM APIs. We are removing legacy APIs that were previously marked for deprecation. To learn more about the End of Life of deprecated Workspace ONE UEM APIs, refer to the KB article here.
Android
Updates to Firebase Cloud Messaging integration for Android device management
Workspace ONE UEM uses Firebase Cloud Messaging to support sending commands and resources to the Workspace ONE Intelligent Hub in real time. In June 2023, Google announced deprecation of several FCM APIs that are used by Workspace ONE UEM to communicate with Intelligent Hub. Deprecated APIs will be shut down on June 21, 2024. Workspace ONE UEM 2402 updates its FCM integration to avoid disruption as a result of this deprecation. For more information on compatibility of older Workspace ONE UEM versions with FCM after September 20th, 2024, see Upcoming Changes to Firebase Cloud Messaging for Android (2024).
Workspace ONE UEM End of Availability for Samsung E-FOTA
With the introduction of Samsung Knox E-FOTA One, Samsung firmware updates has moved into a separate console, which is managed by Samsung. If you are using Samsung E-FOTA for MDM in the Workspace ONE UEM console, refer to the Migration Guide or reach out to Samsung about migrating to Knox E-FOTA One.
Launcher
Show Activities Blocked by Launcher
The console now provides detailed reports on activities blocked by the Launcher, offering enhanced visibility into restricted actions for administrators to monitor and manage more effectively.
Configure Launcher DDUI Widgets
Administrators can now configure widgets directly through the Launcher profile, allowing for greater customization and user interface flexibility within deployed devices.
Control Device Brightness
The device brightness settings are now fully configurable via the Launcher profile, enabling more precise control over screen brightness, improving both battery life and user comfort.
Delete and Unpair Options Available on Check-in
Administrators can now configure the option to delete or unpair devices during the check-in process through the Launcher profile, streamlining device lifecycle management and improving security.
Console
Overcome random MAC address challenges with Cisco Identity Services Engine (ISE) 3.1+ and Workspace ONE UEM integration
End user devices can now securely connect to network resources, even with randomized MAC addresses, by integrating Workspace ONE UEM with Cisco Identity Services Engine (ISE) 3.1+, which we are providing as a limited availability feature. Reach out to your account manager to enable this feature. For more information and integration instructions, see the Tech Zone article Integrating Workspace ONE UEM and Cisco ISE v3.1 and beyond.
View and act on the Enrolment Terms of Use (TOU) for enrolled devices within Intelligent Hub app
Workspace ONE Intelligent Hub app users can now view and act on updates to the Enrolment Terms of Use (TOU) created in the Workspace ONE UEM console for any of their enrolled devices directly within the Intelligent Hub app. For more details, see the KB article.
Improved device location tracking with enhanced data reliability
We have improved how device location data is stored to prevent service interruptions caused by data overflow. This update ensures smoother access to location history without changing how the feature works.
iOS
We've added a new Restrictions key for third-party app stores
We have added a new Restrictions key to allow or block app installation from alternative marketplaces. This new key is titled "Allow app installation from alternative marketplaces" and is available for supervised devices running iOS 17.4 and above. For more information, see Restriction Profiles for iOS.
Control Lost Mode via REST API
We have added a new REST API to enable or disable Lost Mode for iOS devices. This API allows third-party workflows to integrate with Workspace ONE UEM to programmatically enable or disable Lost Mode. For more information on REST APIs, see the Tech Zone article Getting Started with the Workspace ONE UEM REST APIs.
macOS
Enhance your device safety by turning on Activation Lock protection
Workspace ONE UEM provides the option to turn on Activation Lock on devices while you configure your Device Enrollment Program profile. You can store the MDM and device bypass codes that are visible in the console. By using bypass codes, you can turn off the Activation Lock on your device. Workspace ONE UEM now supports the MDM setting to turn on the user activation lock via Find My Mac.
Before You Begin
The Workspace ONE Unified Endpoint Management (UEM) console supports the latest stable builds of the following web browsers.
-
Chrome
-
Firefox
-
Safari
-
Microsoft Edge
Comprehensive platform testing has been performed to ensure functionality using these web browsers. If you run the UEM console with an older version browser or on a non-certified browser, you can experience minor issues.
Resolved Issues
- Resolved Issues for 2402
Resolved Issues for 2402
-
AAPP-17074: On Demand VPP Assignments are installing on devices automatically.
-
AMST-40687: Unable to save profile with two Certificates errors: Save Failed and Invalid Certificate
-
CMSVC-17671: (SmartGroupSearch) V2 Intermittent failure due to Internal server error.
-
MACOS-4269: Unlock pin not escrowed on the Workspace ONE UEM console.
-
MACOS-4330: macOS devices update notification repeating after install.
-
MACOS-4368: FedRAMP environment unable to automatically install Intelligent Hub macOS application.
-
AAPP-16024: iOS device freezes in Single App Mode configuration if profile installs before the Hub installs.
-
AAPP-16282: The installed count of Derived Credentials profile constantly fluctuates.
-
AAPP-16428: After the UEM upgrade, there is no option to add or edit the approved SIM for some devices.
-
AAPP-16463: Spacemen error is displayed when you assign,edit,or manage device for VPP app.
-
AAPP-16576: VPP app license is not displaying on the UEM console, stating no records.
-
AAPP-16554: App icons for some internal iOS apps won't be displayed in UEM Console and Hub Catalog.
-
AAPP-16566: During iOS Native CICO, the devices do not get assigned to end user after logging in with AppleID.
-
AAPP-16644: Some of the iOS profiles created before UEM 2212 is not getting converted to iOS DDUI profiles after the UEM console upgrade.
-
AAPP-16633: Unable to delete ABM stale record from Enrollment lifecycle page.
-
AAPP-16682: Unable to view assignment for Shared iPad for Business for supported profiles.
-
AAPP-16638: Unable to install VPN profile on iOS devices.
-
AAPP-16722: The device does not get assigned to the end user on the User List tab.
-
AAPP-16725: In Hub services, Make Noise feature shows an error message.
-
AAPP-16791: API does not return a success result when deleting iOS devices.
-
AAPP-16809: Copying iOS profile with Context = 0 causes spaceman error.
-
AAPP-16864: iOS Mobileconfig upload results in a blank DDUI page.
-
AAPP-16892: iOS Updates have no eligible device models on the console and they are blank.
-
AAPP-16985: iOS certificate profile created via API is unable to open in DDUI.
-
AAPP-16899: Unable to add the application in Deny List of the app group.
-
AAPP-16967: Error when calling the the API GET /apps/purchased/search
-
AMST-36814: Summary page crashes for windows dependency Apps.
-
AAPP-16991: VPP application not updating version on the console for one application but does push the updated version to devices.
-
AMST-36722: Update Workspace ONE UEM console Azure AD help information.
-
AMST-38952: Windows BIOS profile missing custom BIOS Attributes after saving.
-
AMST-40267: UEM not processing assignments unless triggered.
-
AMST-40244: Actual File Version is not updating when adding new version for Windows app.
-
AMST-40252: Windows Credentials profile shows installed when the cert request fails.
-
AMST-40324: Wifi certificates are not getting auto renewed.
-
AMST-40547: Disable the caching server usage.
-
ARES-25268: (Workspace ONE Express) Unable to add or edit icon images for Web Apps.
-
ARES-26301: Admin continuously receiving Device App Logs storage alert for different OG’s.
-
ARES-26721: Smartgroup Publish not triggering assigned resources assignment reconciliation.
-
ARES-26864: Unable to save icons for Windows Webclip.
-
ARES-27127: Sampling is not saving SampleHash in interrogator hashtable.
-
ARES-27288: New Script window unexpectedly shows all the categories including ones created at sibling OGs.
-
ARES-27264: Adding a newer version of an app via APIs removes app config KVPs for the previous version.
-
ARES-27690: MTD solution no longer showing user info for unmanaged apps after UEM upgrade.
-
ARES-27373: FastSync when enabled does not show as enabled in UEM after saving the App assignment.
-
ARES-27488: Unable to delete certain internal Apps.
-
ARES-27955: Total Assigned Devices in preview of profile assignment page does not work properly.
-
ARES-27988: Unable to view the XML file of specific iOS profiles if sign certificate option is enabled.
-
ARES-27798: Web links report is empty.
-
ARES-27794: Database error while fetching the details of the devices assigned to every single app for Android or Public.
-
ARES-27803: Device Security Posture report does not display the correct count of devices in the column Pending Installs .
-
ARES-27674: App Removal Protection (ARP) email is not triggered when the threshold is met.
-
ARES-28121: Unable to add Dell Command Update v5.1.0 from EAR.
-
ARES-28222: Not able to edit or add new version for an internal Windows application "Zoom", Getting a spaceman error.
-
CMCM-190818: Downloaded files gets disappeared on the random devices.
-
CMEM-187004: Unable to run sync mailbox command on all users but can run by selecting individual users.
-
CMSVC-17435: Unable to create smart group via API when smart group name contains double-byte symbol or number.
-
CRSVC-43260: An error occurs when exporting a certificate list if the file is larger than 4 GB.
-
CRSVC-42809: Some identity certificates are acknowledged as "Cert" type in error.
-
CRSVC-43578: Compliance Policy Summary tab not showing the correct device count for Compliant or Non-Compliant status when using Device Tags rule.
-
CRSVC-44553: ACC cannot export when CA cert exists in stores with private key.
-
CRSVC-44714: Subject Alternative Name (SAN) fields is missing in eJBCA Certificate Signing Requests (CSRs).
-
CRSVC-45750: Bulk SMS fails when notifying over 500 devices.
-
CRSVC-46731: Azure Active Directory Registration and Azure Device ID fields for macOS are not visible under Device Summary Page.
-
CRSVC-46455: Unable to save Intelligent Hub settings page on lower OGs.
-
CRSVC-45792: In recent patches or versions of Workspace ONE UEM, secure Channel communication with older versions of Android Intelligent Hub (20.X and older) is broken.
-
CRSVC-47017: API Call Invoked Commands Associated to Unknown Admin Account.
-
CRSVC-47130: Object reference not set to an instance of an object error if SAN is not configured.
-
CMSVC-17526: API call for Smart Group search not working.
-
CMSVC-17608: When creating a Compliance profile in a Container OG, All Devices SG that is automatically created, does not show the enrolled devices.
-
ENRL-3913: Adding enrollment restriction policies in other tenants.
-
ENRL-4013: The Save and Cancel button is not seen while adding device(s) for a user from the device list view.
-
ENRL-4098: After UEM 2310 Upgrade, CICO fails when above a specific iOS version is used in enrollment restriction policy.
-
FCA-205246: Terms of Use displaying unicode value when declined.
-
FCA-205910: Console should not trigger notifications for already expired APNs and Provisioning Profile every 75 days.
-
FCA-206523: Device Location Log retrieves many records for a sample time. So, it looks like duplicated records..
-
FCA-206076: Network ranges list does not honor page size.
-
FCA-206695: Unable to change the company logo.
-
FCA-206903: Push notification does not leave the log in EventLog when HUB service enabled.
-
FCA-206840: Console slowness is seen when adding the roles to existing admins.
-
FCA-206880: Device List View is not sorted by Build Version.
-
FCA-207109: Terms of Use (TOU) counts the users twice who set the other language setting besides English (United States).
-
FCA-207346: Device Send message permission controls visibility to Location Option in Device List View.
-
FS-4844: Scheduled retries are not cleaned up on step completion.
-
FS-5009: Workflow UI page crashes when we edit an existing workflow and check the script within the workflow.
-
INTEL-51122: Intelligence checkout status does not reliably reflect the actual checkout status.
-
MACOS-4086: All workflows show In Progress status.
-
MACOS-4137: Auto-join gets automatically selected in macOS network profile.
-
MACOS-4217: TLS Profile settings for macOS Network profile are shown incorrectly on different console versions.
-
MACOS-4184: macOS update management does not work when Install Action is "Install Later".
-
MACOS-4195: macOS Restriction payload automatically adds Activity Monitor to Allowed Apps in Launch Restrictions.
-
MACOS-4265: Cannot save any modified or new System extension macOS profiles.
-
RUGG-11602: Time condition is converted to UTC regardless of the console time.
-
RUGG-11984: Show activities blocked by Launcher offering enhanced visibility into restricted actions.
-
RUGG-11739: (Launcher DDUI) Configure widgets directly through the Launcher profile.
-
RUGG-12536: Control Device Brightness.
-
RUGG-12608: Configure the option to delete or unpair devices during the check-in process.
-
SINST-176321: Login errors are seen after upgrade to 23.06 and resetting the DB password.
-
UM-8701: Unable to delete admin account from the UEM console.
-
UM-8719: Unable to access user groups even with admin roles and right permissions.
-
UM-8444: The Organization Group tab in administrator account is removed in new DDUI from v2210 onwards.
-
UM-8525: Admin role not auto filled in DDUI when adding Admin manually.
-
UM-8638: User Groups List View errors out at Top OGs.
Patch Resolved Issues
24.2.0.1
-
ARES-28448: On the App DT page, the alignment of the first device record is not proper, and some of the device details are getting overlapped.
-
CRSVC-47469: Reset offline checkin job hydration status to support retrigger.
-
RUGG-12963: Incorrect installation status for apps under Device details > Application page.
-
AMST-40776: Incorrect target set for profiles when DSM overrides are created.
-
CRSVC-47441: Change modern-stack orchestrator job to one min.
-
CRSVC-47729: Compliance overrides to DSM migration not working.
-
AMST-39074: WNS Details are not showing on the Network or Summary page.
-
CRSVC-47761: Workflow migration to ES does not migrate the workflow choice set boolean correctly.
-
AAPP-17047: VPP License Cleanup job is erroring out and not clearing externally redeemed licenses.
24.2.0.2
-
AAPP-17107: DST Cutover for is_roaming and SubscriberCarrierNetwork in ServiceSubscription.
-
AAPP-17214: iOS Hub repeatedly prompts to update.
-
AMST-40984: Profile sample is not getting updated until query.
-
ARES-27829: "EVALUATED_DEVICES_LIST" and "PROFILE_EVALUATED_DEVICE_LIST" API call throwing error in response.
-
ARES-26772: Status tool tip logic not updated with Gumdrop response.
-
ARES-28471 Hide the export button in DLV screens of Apps / Profile until the functionality is complete.
-
ARES-28613: Fix localization issue in P2P chart.
-
ARES-28550: Excluded tab And device list counts issue.
-
ARES-28511: Installed count Exceeds Assigned count in Apps and Profiles.
-
ARES-28430: Implement Force Check-in action for Apps and Profiles deployment tracking.
-
ARES-28611: App details page is crashing for apps that are workflow assigned.
-
ARES-28558 : Profile/Apps tab does not show all profiles/apps.
-
ARES-28583: Remove assigned configuration column for public apps.
-
ARES-28574: Identifier missing from sample causing the entire sample to be dropped for mobile platforms.
-
ARES-27948: Assignment Source filter redirection is not working.
-
ARES-28470: DT view rendering issue for child Organization Groups admins with apps deployed from parent Organization Group.
-
ARES-28763 Profiles tab crashes while making call to RMS.
-
ARES-28775: On adding exclusion profile DT assigned count shown is incorrect.
-
CRSVC-47567: Deleted stale devices not getting handled from migration status table.
-
CRSVC-47525: Resources API throws exception when multiple actions present for same resource.
-
CRSVC-47813: Compliance-DSM does not honor current occurrence field for compliance action evaluation.
-
CRSVC-47774: Sample failure updates to DeviceMigration table failing with exception.
-
CRSVC-47845: Troubleshooting tab errors out on specific device.
-
CRSVC-46772: Only remove Noop overrides if all policies with resource based actions have been evaluated.
-
CRSVC-47881: DeviceStateCleaup Job trigger state is paused.
-
CRSVC-47935: Trigger offline check-in flow in DSM on CP while dual read mode is activated.
-
ENRL-4193: Terms of Use acceptance failure on device check-out.
-
FCA-207458: Deactivate device List View and Global Search in Mod Stack.
-
FCA-207510: Available OS updates not listed on the Device Details summary page.
-
FCA-207537: Summary page broken for macOS device.
-
FS-5410: Device State Sample processing failure during workflows.
-
MACOS-4353: Scheduled samples should only be processed on Native check-in not for Hub.
-
MACOS-4016: Fix security segment disk_encryption data mismatch.
-
PPAT-16512: Deactivate multiple Tunnel Gateway in Tunnel configuration.
-
RUGG-12972: Remove application action returned from PRM for provisioning apps after mod enablement.
24.2.0.3
-
UM-8865: Prevent unnecessary updates in AD sync.
-
PPAT-16386: Reduce the number of calls for endpoint /v2/device-traffic-rule-sets.
-
FCA-207435: Canonical: Handle the device-index, de-serialization issue gracefully for the DLV page.
-
CRSVC-47906: Reassess telemetry events for offline device check in and emit telemetry and add logging.
-
CRSVC-48006: Compliance DSM overrides were not removed for non-compliant devices after policy edit.
-
CRSVC-48007: Compliance Reconciliation operation fails with exception.
-
CMSVC-17756: Device state patch calls fail because tags patch calls are made with 500 devices.
-
ARES-28893: iOS public application is showing not installed on device summary as well as DT page.
-
ARES-28585: Device tab of macOS Bootstrap package is broken.
-
ARES-28592: Rendering old DT experience from Custom Apps list view for public apps.
-
ARES-28759: Fix globalization issue in Force Check Action.
-
ARES-28458: Purchased applications during enrichment send version as empty.
-
ARES-28568: Implement limits for bulk device actions in Deployment Tracking View.
-
ARES-28579: Application_uuid is not populated for one of the application in MAL sample.
-
ARES-28399: Page threw an error when attempted to remove app from device details page.
-
ARES-28062: View in Profile list view screen was not rendering accurate data.
-
AMST-40998: Observed exception in messaging service for WNS.
-
AMST-41090: Office 365 fails to install on Windows devices.
-
AMST-40976: Seeding latest SFD 23.10.0.22 build to UEM master release.
-
AMST-40969: Seed Windows Hub 23.10.6 x86 to UEM console Master.
-
AMST-40972: Profile with multiple credential payload is failing while adding new version.
-
AMST-40417: Don't make PRM call when PRM-Win FF is disabled.
-
AGGL-16791: Some of the compliance policies were not getting evaluated.
-
AGGL-16682: Application Identifier is not populated for one of the applications in sample.
-
AGGL-16775: Incorrect manufacturer name is present in DST data for Android device
-
AGGL-16755: When device has compromised compliance policy present, after device reenroll Apps/Profile resources are not installing on the device.
-
AGGL-16658: Android device details apps tab errors out.
24.2.0.4
-
AMST-41093: App deferral does not work with cn8001.
-
ENRL-4217: Reject TOU creation or update requests whose encoded TOU content cannot be URI decoded.
-
ARES-28932: MAL enrichment:error processing interrogator queue message.
-
AGGL-16784: ModStack: API calling attended Assist instead of unattanded Assist.
24.2.0.5
- CRSVC-48217: Metadata in samples causing sample size to blow up.
24.2.0.6
-
AGGL-16822: Capability enrichment sample failing post the patch update in environment to update enterprise version.
-
AGGL-16827: Android Device delete intermittently takes 4 hours to wipe the device.
-
FCA-207587: DLV tooltip for friendly name is broken.
-
FCA-207603: Device List view Export is not producing export to download.
-
AMST-40616: Device state to capture new status for pause.
-
AMST-40654: Pause status to be displayed in List view.
-
AMST-41111: Bulk Management settings throwing error.
-
FS-5414: Matches Found count is incorrect whenever adding/removing Application Versions/Names in Conditions.
24.2.0.7
-
CRSVC-43833: Handle resource delivery during CICO based on compliance configuration.
-
ARES-28834:Remove Export button from the Assignment preview page.
-
ARES-28510:Display inconsistencies in P2P chart data.
-
ARES-25176:Export devices on DT screens for profiles.
-
ARES-25175:Export devices on DT screens for apps.
-
ARES-28908: Issue resolved for Send and Query bulk action limits.
-
AMST-41179: Reassignment Admin actions were not displaying in DLV and Details page.
-
AMST-40997: Improved Event logs for admin actions.
24.2.0.8
-
UM-8905: Issues while retrieving and updating VIS user data.
-
UM-8807: Unable to delete or edit directory admin accounts with long user names.
-
RUGG-12979: Incorrect details for profiles installed through products on Device Details>Profiles page.
-
LUEM-838: Workspace ONE UEM console Device Model filter for "Arch" for Linux devices is incorrect.
-
ENRL-4149: UEM fix entitlements API for EULA/TOU with multiple apps.
-
CRSVC-48137: Overrides were not getting deleted after evaluation if policy name was changed.
-
CRSVC-46885: Auto-renewal of certificates for MU Windows with DSM.
-
CMSVC-17777: Tags API internal server error reported from MDM tags API, when tag is not assigned to any of the devices.
-
ARES-28938: Increase grid height for apps and maintain consistency with profiles.
-
ARES-28582: Wrong count display on device summary for applications deployment modes.
-
ARES-28837: Empty state chart for P2P.
-
ARES-28582: Wrong count display on device summary for applications deployment modes.
-
ARES-28466: App deployment tracking page is broken for iOS apps added using URL.
-
ARES-28061: Filtering on last checkin graph in pending tab is breaking the profile DT view.
-
AMST-41277: Device in WNS renewal loop causing DM Profiles to fail.
-
AMST-41236: Reassignment is successful to the user even if the user was added to the restriction group.
-
AMST-41188: UI filter for reassignment user modes was not working.
-
AMST-41161: DM sync fails and returns 404 error when the device is deleted from the console.
-
AAPP-17131: VPP application is not auto-updating on devices when the minor version is not present.
-
AAPP-17049: VPP failed while resolving enrollment users.
24.2.0.9
-
MACOS-4565: Evaluated device is showing up in the Pending tab.
-
CRSVC-49317: Add logging to help troubleshoot QueryBuilder issue with schema CurrentTimeStamp not found.
-
CRSVC-48291: When compliance policy is deactivated install action is not created.
-
CRSVC-46068: CellTrust integration was not working.
-
CRSVC-48188: Change the state of HighPrecisionAPIUsageTrackingFeatureFlag to Production.
-
ARES-28829: [DTUI-APPS/Profiles] Sorting needs to be enabled or disabled in grid columns as per requirement document.
-
ARES-29163: Exporting from DT screens for apps and profiles missing pop-up indicating the export has completed successfully.
-
ARES-28338: System application App status showing as installed but unassigned on Windows.
-
AMST-41410: Update labels to single user mode.
-
AMST-41374: Return whether device OG is changed after checkout as part of Checkout API response.
-
AMST-41349: Device reassignment failed with error "User Authentication Failed".
-
UM-8753: Authentication response security option in SAML.
-
AMST-41160: Pre-load device state with required segments in the vIDM settings endpoint handler to avoid multiple calls.
-
AMST-41153: Optimize the non-credential user SP to load all the information required.
-
AMST-41225: Reduce the number of samples that are scheduled post-checkout.
-
AMST-41158: Remove seeded SCEP command queueing in MU checkout flow.
-
AMST-41249: App installations with a "RAM Required" field set on the UEM side was causing multiple installation failures.
-
AMST-41101: Arm64 hub was not getting published to the device when version mismatch was present.
-
LUEM-853: All the Linux devices get the same lookup value for sensors.
24.2.0.10
-
UM-8917: VIS to UEM unlink is not removing the UEM user from the UEM group.
-
UM-8864: "Invalid Data Entered” when editing and saving Admin account: Phone Number value.
-
PPAT-16819: (Tunnel Console) Add KVP to make page size to 500 in tunnel configuration export.
-
PPAT-16700: Memory usage issue observed in the tunnel mappers.
-
MACOS-4008: Add execution of script, to reinstall Intelligent Hub settings profile for already enrolled devices.
-
FS-5628: Seed Mac workflow host in canonical: Master > “Seed Mac workflow host in 2402”.
-
FCA-207737: Physical memory values were missing in UEM devices or search API call.
-
FCA-207373: Home and Page Save icons are missing from the device list view page.
-
ENRL-4095: Update logging for failure of enrollment restriction check.
-
CRSVC-48390: Enhance mod stack API status endpoint details for migration and alerts
-
CRSVC-47979: Remove DST cleanup job limit for single execution.
-
CRSVC-47365: Event log in user details view does not show any event data though it is shown under the devices Troubleshooting tab.
-
CRSVC-45834: Workspace ONE device-based compliance policy was not automatically evaluating compliance and actions.
-
CMEM-187032: Improvements for MEM APIs.
-
CMCM-191000: Intelligence report saw discrepancies with specific filters and columns for the category of Device Content.
-
CMCM-190997: Content dashboard most or least viewed files section is empty.
-
CMCM-190986: Remove the command queue to delete content from the device during managed content delete.
-
CMCM-190959: Optimize user repository creation during content synchronization.
-
ARES-29500: On Profiles DT page- The Device List grid was not populating data for selected tabs.
-
ARES-29262: Units in cache or server bytes charts was not displayed in Peer distribution.
-
ARES-29131: ELS validation on the Device Details > Apps > App Details page.
-
ARES-29114: Organization group name is coming as blank in DT page exports.
-
ARES-29068: Getting two different UIs for the app assignment restrictions page.
-
ARES-28333: Animation on Header section and scroll transition to be smooth.
-
AMST-40778: Proxy settings not included in Windows profile XML file if configured in Wi-Fi payload.
-
AGGL-16966: Unable to publish public app with SG having devices.
-
AGGL-13363: Application configuration shows disabled after publishing an app.
-
AAPP-17255: Issue placing iOS WebClip on Home Screen first page
-
AAPP-17051: VPP failures for asset management due to duplicate assets in request to V2 endpoints.
-
AAPP-16964: Refreshing sToken for a VPP v2 enabled OG, resets migration flag.
-
ARES-26037: Internal app icon was broken in the deployment tracking page.
24.2.0.11
-
PPAT-17123: VPN applayer payload type is not part of the XML when EnablePerAppVPN is set.
-
MACOS-4351: MAC install fonts.
-
FCA-207853: SmartGroup filter in the DLV must show devices as per eligibility criteria regardless of the device check-in.
-
CRSVC-50243: Fix write enablement issues at shared SaaS.
-
CRSVC-50073: Mod stack Orchestrator is proceeding when the snapshot stage fails
-
CRSVC-48506: Tweak DST PUT API to not emit events based on a flag.
-
CRSVC-46606: Improve canonical auth troubleshooting: add middleware to catch and log details for OAuth errors.
-
ARES-29406: Peer distribution chart is disappearing on-device search.
-
ARES-29262: Units in cache or server bytes charts were not displayed in Peer distribution.
-
ARES-29238: Seeing an error when moving the cursor over the Peer Distribution column of the device table on a Windows app’s Deployment Tracker screen.
-
ARES-29140: (Backend) Move offline evaluated devices out of Pending stats in Deployment Tracking.
-
ARES-29110: Add a new section for "Installed but not assigned" devices and move them out from the Evaluated tab.
-
ARES-29100: Default assignments are disappearing from the database when we edit the assignment.
-
ARES-28586: Move offline evaluated devices out of Pending stats in deployment tracking.
-
AMST-41653: Seed Windows Hub 24.4.4.0 x86 Patch2.
-
AMST-41560: Seeding latest SFD 23.10.2 build.
-
AAPP-17678: Fix the looping issue while making association calls for VPP v2.
-
AAPP-17088: Get devices assigned to DEP profile API, which is failing.
-
AAPP-17014: Apple education profile not queuing a removal.
-
AGGL-17049: FCM not clearing passcode in direct boot mode.
24.2.0.12
-
UM-9060: Rocket/Spaceman error when trying to cancel pending records in Batch Status page.
-
UM-9042: Editing an Admin account deactivates it.
-
PPAT-17120: Tunnel test Connection Failed.
-
MACOS-4362: Multiple certificates installed on device enrollment in mod enabled environment.
-
MACOS-3910: Smart group assignment for the macOS internal app fails to be assigned for a couple of users devices. .
-
FS-5811: Incoherence of devices number related to a specific Smart Group.
-
CRSVC-51417: Modstack migration status alert not working.
-
CRSVC-50027: Add Organization Group check to CA flow which sends unenrollment and non compliant for existing lingering devices for Microsoft tenant.
-
CRSVC-50025: Add code block on UEM side to block Conditional access configured at any other customer OG if its already configured for once customer OG within same UEM environment.
-
ARES-29831: Clicking on Internal App Name in Resources > Native > Internal Results in Spaceman Error.
-
ARES-29786: Evaluated device details are getting listed under the Installed but not assigned tab after doing a refresh.
-
ARES-29785: 'Export' from the Installed but not assigned tab in the Profile DT page shows "Something Unexpected Happened".
-
ARES-29230: When adding a new version of an app, during the completion criteria when pushing Add, an alert appears saying Leave or Cancel.
-
ARES-29119: Application_Uuid is missing while running API call.
-
ARES-28503: Summary tab is reporting incorrect number of installed profiles for macOS platform.
-
ARES-28364: All system installed apps are getting listed in Managed app tab.
-
ARES-28244: When we add 2 or more Geo fencing locations to the profile, only 1 Geo location is seen in UI.
-
ARES-27051: Rule action isn't reflecting on the autocomplete field type (default).
-
AMST-41872: Seed Windows Hub 24.4.6.0 x86 Patch3 to UEM console 2402.
-
AMST-41785: Application is Getting re-install on click of publish button click in assign popup without doing anything.
-
AGGL-17149: Android Restrictions JSON Exceeds Memcached Limit.
-
AGGL-17093: Delete AMAPI Profile Owner enrolled Android device.
-
AAPP-17770: iOS: Unable to retrieve the email address in "local identifier" for VPN profile.
-
AAPP-17695: Improve logging on Apple notification API.
-
AAPP-16916: Refreshing AppleCare Warrantly information is throwing error "PleaseCheckGSXSettings" for all Apple Devices.
24.2.0.13
-
FCA-207518: Alignment is improper for workflow "name" field.
-
CRSVC-52157: Profile events are not emitting while triggering snapshot.
-
CRSVC-51337: Status is null in sample (Profile and Selective Profile List Sample).
-
CRSVC-50493: CRS update full state API request contract.
-
ARES-29711: Devices receive app assignments while in exclusion groups.
-
ARES-29538: Add a new section for "Installed but not assigned" devices and move them out from the Evaluated tab.
-
AAPP-17458: Improve ExternallyRedeemedLicense job to process the license in batches.
-
AAPP-17220: Update stored procedure to support V2 flow.
24.2.0.14
-
RUGG-13180: Unable to sort manifests in products.
-
RUGG-12991: Unable to create a custom attribute with double-byte alphanumeric through API.
-
PPAT-17434: Tunnel client not reconnecting once device regains compliance.
-
PPAT-17309: Multi-Factor authentication in allowlist table for tunnel payload.
-
MACOS-4394: Getting incorrect XML request from Hub in checkin.
-
FCA-208400: CSP violation in bing endpoint.
-
FCA-207895: The UEM console requests an incorrect request at the landing page for the admin user who enables two-factor authentication and configures the landing page.
-
ESI-111: Admin is assigned Console Admin role when assigned both platform and UEM roles through RBAC admin groups.
-
CRSVC-50186: Prevent certificate from changing not in use status for 48 hours.
-
ARES-30008: Boxer account details are not populated automatically on fresh installs.
-
ARES-29876: On the console, receiving "page not found" error, ss attached, while clicking on Query button at the following path: Resources> Apps> Internal> 3CX Desktop App (or any other app for that matter)> Devices > Query.
-
ARES-29304: Remove customization API call made for Apps and Profiles DT devices grids.
-
AMST-42040: Seed Windows Hub 24.4.8.0 x86 Patch 4 to UEM console 2406.
-
AMST-42025: Update p2p branch cache log level.
-
AMST-42016: Seeding latest SFD 23.10.3 build to UEM 2406 release.
-
AMST-41999: The string "Multi-User" is hardcode on the device details page.
-
AMST-41997: Application installation status is not reporting correctly on UEM.
-
AMST-41992: Update p2p branch cache log level
-
AMST-41960: Application installation status is not reporting correctly on UEM.
-
AMST-41868: Seed Windows Hub 24.4.6.0 x86 Patch3 to UEM console master.
-
AMST-41786: Seeding latest SFD 23.10.3 build to UEM master release.
-
AMST-41764: Sensor & Script: Remove Search Hub dependency from the APIs.
-
AMST-41671: The string "Multi-User" is hardcoded on the device details page.
-
AMST-41446: After removing the Windows update profile, some registry for updates remains on the device.
-
AMST-41285: Seed Windows Hub 24.4.2.0 x86 to UEM console master.
-
AMST-40348: Sensor and Script: Remove search Hub dependency.
-
AGGL-17307: Fix integration tests that are using deprecated API endpoints.
-
AGGL-17248: To deploy apps through the new devicepolicy API, update autoupdatepriority value for apps to 0.
-
AGGL-17234: Fix Lookup field resolution for app configs when using new devices.
-
AGGL-17200: Internal apps are removed through Google EMM APIs during CICO with PlayEmmDeprecationForAppPublishFeatureFlag enabled.
-
AGGL-17115: Application configuration inconsistent behavior for check in check out user on Android devices.
-
AGGL-16757: Unable to click continue on Enrollment Configuration Wizard
-
AGGL-16399: Fix Integration tests that are using deprecated API endpoints.
24.2.0.15
-
FCA-208390: The "Apply" button on Filters does not work when the devices list is opened from the Assignment Groups page.
-
FCA-207834: Pendo account ID being incorrectly captured as the same across multiple customer OGs.
-
ESI-102: Hub app does not load mydevices in the Support tab for users with large amount of devices.
-
ESI-186: DST read after write issue of device records.
-
CMSVC-18184: Disable Smart Group Tenancy Correction support from UEM production environments.
-
ARES-29486: APIs for uploading the logs using Multipart and fetching LUT fails if WS1 apps are not assigned to OG.
-
AMST-42084: Seed Windows Hub 24.4.10.0 x86 to UEM console 2402.
-
AMST-41802: Time zone displayed in the Scripts tab is different from the Execution logs.
-
AMST-41953: Reassignment admin actions were not being displayed.
-
AAPP-17923: Update the VPP Notification Status Sync Job to discard the duplicate notifications.
24.2.0.16
-
CRSVC-51239: Event notifications inheritance corrected for sub-child OG rules.
-
AGGL-16861: Correct OS update processing.
-
ESI-201: Devices not being moved to the correct OG by IP address.
-
CMSVC-17744: Newly enrolled devices were not added to the Smart Group causing issues with assignments of resources.
-
AMST-42116: Seeding latest SFD 23.10.4 build to UEM 2402.
-
FS-5716: Windows app install failure.
24.2.0.17
-
UM-9294: Attribute sync is failing post upgrade to 2402 console version.
-
UM-9173: Page crashes when trying to load user group list view page.
-
UM-9083: Issue with Directory Admin login after making any changes to the admin role or account.
-
UM-9079: Connections to LDAP/AD needs timeout.
-
PPAT-17160: Update UEM Tunnel Service to .NET 8.
-
CRSVC-52975: Request getting rejected in Boeing with 429 error.
-
CRSVC-46583: Migrate DSM service code to .NET 8.0.
-
CMSVC-18231: Smart group rules are being removed from evaluation flow during device event race condition.
-
ARES-30227: Add logs for adding profile assignment.
-
ARES-30171: Incorrect profile DT page counts of child OGs.
-
ARES-29939: Unable to save Boxer configuration in the UEM console (multiple customers).
-
ARES-29837: Update the version of .Net Referenced by Metadata Transform Service to 8.0.
-
AMST-42162: Seed Windows Hub 24.4.11.0 x86 and ARM64 MSI to the UEM console master.
24.2.0.18
-
UM-9168: Scim user API throws error while patching user data if the path is not supported and value is empty or null.
-
AGGL-17044: Highly intermittent failures in Smart Group Reconciliation for Zebra Devices where Make/Model criteria is used.
-
UM-9174: Unable to switch basic users to AD users through the User Migration tool
-
PPAT-17066: Improvement to prevent crash of DDUI profile page if tunnel health is down.
-
CMCM-191091: Duplicate entries returned for new folder resources created on the NFS repositories.
-
CMCM-191121: Content locker application shows foreign folder names and intermittent issues with files missing or displaced.
-
ESI-109: Improve logging for email notification flow.
24.2.0.19
-
UM-9315: Unable to replace S/MIME user certificate.
-
UM-9310: Unable to update custom attributes for users using the batch import csv.
-
RUGG-13020: Unable to download certain .ps1 files which are uploaded in UEM.
-
FS-6358: Increase device state response timeout to 20 seconds.
-
CRSVC-52748: Remove app assignment requirement from LUT token request endpoint.
-
AMST-42418: Seed Windows Hub 24.4.12.0 x86 and ARM64 MSI to UEM console master.
-
AMST-42327: Seeding latest SFD 23.10.5 build to UEM master release.
-
AMST-42059: Firewall profile failing to install on Windows 11 systems.
-
AMST-41691: Prevent auto-reinstallation of on-demand apps when DSM is deactivated.
-
AAPP-17946: Empty app configuration is delivered to devices in a specific update scenario of internal iOS app.
24.2.0.20
-
MACOS-4530: macOs Device Model Seeding API implementation.
-
ESI-332: Revert the single advance staging user email flow changes.
-
ARES-26220: Add an iOS optional profile and verify that the chart can be added on AppAndProfile monitor.
-
AAPP-18024: Fix data duplication in vppAssetManagementEventData.
24.2.0.21
-
PPAT-17178: Add custom settings support for iOS and macOS (Tunnel payload).
-
FCA-207350: Remove VMware Analytics from UEM console Canonical.
-
CRSVC-55257: Unable to delete one AD user from UEM console or using API.
-
ARES-29653: MDM AppsV1 API is not returning results for Windows devices.
-
AGGL-16468: Fix the inconsistent values for lost mode enabled column for Android devices.
-
AAPP-18094: Fix to prevent returning process-related exceptions except UnAuthorized on Apple callback API.
24.2.0.22
-
UM-8878: Input data validation SCIM API.
-
UM-9111: Administrator user deletions must be logged.
-
CMCM-191155: Invalid link issue for automatic user repositories created with link containing same consecutive folder names.
-
ARES-29652: Child OG remains undeleted despite the attempt to delete it.
-
AMST-42510: Removed URL encoding while uploading icon from EAR.
-
AMST-41549: Remove the Version Check from Seeded Apps in the mapping table.
-
AGGL-17170: Workspace ONE unable to automatically retrieve app configuration from custom apk file.
-
AAPP-17986: Add iOS 18 Passwords app bundle ID to seed data.
-
AAPP-17816: Sync VPP Assets or License fails due to foreign key constraint reference for VppLicenseID.
24.2.0.23
-
UM-8892: Admin group creation UI fails to save when locale is non-English.
-
RUGG-13304: Relay servers were unable to connect to the Console when the default Mac address was used in the discovery text.
-
RUGG-13280: Manual Sort is not working for the manifests in Files or Actions component.
-
RUGG-13278: Export functionality for the assigned device list in a Product is not working.
-
RUGG-13256: Page crashing while re-processing the product on devices.
-
RUGG-13040: Products being pushed to unintended devices when assignment rules have integer-based custom attributes.
-
FCA-208683: Intelligence opt-in flow showing error screen after the first step
-
FCA-208159: Remove setting for enabling in-product support from the console.
-
ESI-399: Console enrolls device with token registered to another user.
-
CRSVC-56124: Make previous supported versions compatible to auto-update ACC.
-
CRSVC-55376: ITrafficThrottling does not appear to be registered correctly for Device Management.
-
CRSVC-52195: Fix Windows certificate sample sorting to avoid duplicate key error.
-
ARES-28716: iOS Public App Search shows Page Not Found error when switching country.
-
AMST-42501: Firewall Profile failing to install on Windows 11 systems.
-
AMST-42060: Queue is backing up frequently.
-
AAPP-18323: Cannot install user-based VPP app on Device that are user enrolled.
-
AAPP-18090: VPP apps install delay.
24.2.0.24
-
RUGG-13303: Organization group change for Zebra Printers does not automatically update the smart group subscriptions.
-
RUGG-12961: Diacritical marks created by changing Languages (localization) in Custom Profiles Lost During Profile Edits.
-
AAPP-17985: Enhance purge script logic to handle stale VPPv2 notification data (30 day retention).
-
AAPP-17804: Admin account stuck in "Delete in Progress" state, must be deleted from the console.
-
AMST-41534: Seed Windows Hub 24.4.3.0 x86 Patch1 to UEM console 2402.
24.2.0.25
-
RUGG-13443: Product fails to honor applicability rule when oemBuildVersion attribute is used more than once in applicability rule.
-
RUGG-13370: Unable to save Schedule type Condition when the schedule date is in the year 2025 or later.
-
CRSVC-58522: Windows | Failed to fetch metadata from the server for workflows which causes delays in resources delivery.
-
ARES-31047: Launcher Profile configured with Custom Lookup fields failing to install on devices.
-
AMST-42826: Commands getting queued on Windows devices post console upgrade to 2406
-
AGGL-17940: Android app are removed from devices when renamed by administrator.
-
AGGL-17575: Android Credentials profile becomes corrupted when adding version if "Allow silent app access" is enabled.
-
AGGL-10395: Migration should be created with valid smart groups.
-
AAPP-18691: Cannot install some VPP Apps as we get an Associate Failure for the licenses.
-
AAPP-18245: During DEP enrollment, the Device OS version is not correctly read from the device.
-
AAPP-17815: Custom Command shows Pending under Troubleshooting tab in Device Details.
24.2.0.26
-
RUGG-13452: Pull Service configuration file won't download in OGs which have space at the end of their names.
-
FS-6223 - Imported workflows do not show step statuses.
-
ARES-31627: Boxer App Configurations cannot be saved when 'Display Key Escrow' setting is enabled.
-
ARES-30902: Devices failing to install Internal App within 24 hours of receiving install instructions may install latest version afterwards.
-
ARES-28785: [DDUI] Parser error if we have square bracket.
-
AMST-42846: Smart Group device count is not updated until the smart group is re-saved manually.
-
AAPP-18578: Schedule OS Update commands in Queueing state are not removed when excluding the device at Smart Group.
-
CRSVC-46695: Integration service does not consume updated ETL certificate until it is restarted.
24.2.0.27
-
FCA-207991: Update console notification templates to reflect Omnissa branding.
-
ESI-499: An end-user is able to enrol a device in an OG even when the registration token is mapped to a different user.
24.2.0.28
-
AGGL-18379: Android checked-out or checked-in devices fail to install the required resources based on the smart group membership.
-
AMST-43082: Fixed issue with AppX app deployment not working after Hub and SFD were upgraded in UEM 24.2.0.18.
-
AAPP-18578: Schedule OS Update commands in Queueing state are not removed when excluding the device at smart group.
24.2.0.29
-
RUGG-13436: RSCC fails to pull content with duplicate entries for same relay server mapped to different RSCCs.
-
FCA-209880: Resolves CVE-2025-25229. For more information about these vulnerabilities and their impact on Omnissa products, see OMSA-2025-0004.
-
FCA-210103: UEM Device Location Log support for non DST time zones.
-
CRSVC-60875: Resolved scenario where Device Wipe Log did not load successfully.
-
ARES-31049: Legacy app catalog is not removing from Android and iOS devices after disabling it from UEM.
24.2.0.30
-
CRSVC-62526: Resolves CVE-2025-25231. For more information about these vulnerabilities and their impact on Omnissa products, see OMSA-2025-0004.
-
UM-9396: Unable to add user groups to a customer-type organization group (OG) from a partner-type OG.
-
CRSVC-61977: Update hardcoded YATS URLs in Canonical code base.
24.2.0.31
- ARES-30941: Admin unable to enter multiple custom values for profile payloads with drop-down select fields.
24.2.0.32
-
RUGG-13494: Toggle Product Status from Product Set does not work.
-
FCA-210541: Some pages are showing old Workspace ONE UEM logo when the header font color is set to dark.
-
AAPP-18299: Admin without Application View permission cannot view iOS Update Details page.
24.2.0.33
-
AAPP-19421: Enhancements to dissociation logic for Apple VPP.
-
AAPP-19167: Denied URLs is blank when editing an iOS Content Filter profile.
24.2.0.34
- AAPP-18714: Unable to install a few internal and purchased apps due to error 12008 – MDM Command invalid.
24.2.0.35
-
PPAT-19095: Improved performance of console UI while editing profiles containing Tunnel configuration payloads.
-
ARES-28988: User ratings cannot be exported from app Deployment Tracking view.
24.2.0.36
-
AGGL-17263: Denied application names and IDs in app control are not resolved to actual values when viewed in XML.
-
PPAT-17627: Unable edit iOS device profile with VPN payload when IosTunnelSupportFullDeviceVPNFeatureFlag is enabled.
-
ESI-720: Resolves CVE-2025-25236. For more information about these vulnerabilities and their impact on Omnissa products, see OMSA-2025-0005.
24.2.0.37
-
RUGG-13857: Products install repeatedly if device reports Event Actions that are deleted from UEM.
-
FCA-211788: Upgrades to multiple JavaScript libraries to avoid potential cross-site scripting vulnerabilities.
-
AGGL-19105: App remains on device Play Store after deactivating Android Public App on Console.
-
AAPP-20600: Device Updates page failing to load new versions (iOS/macOS).
-
AAPP-20057: Allow for Apple device enrollment if OS version has not been seeded yet.
Known Issues
- MACOS-4362 Multiple certificates installed on device enrollment in mod enabled env
Due to the change events triggered (on Device's attribute level) in few scenarios in the Enrollment flow and with the timing of the Commands consumed, there could be a scenario where a Profile install command is queued twice.
There is no impact to the end user device, and it might not even be observed by end user or admin.
- ARES-28277: Getting spaceman error when navigating back from assignment screen if removable item has been removed from payload
While adding AirPlay Mirroring for iOS platform in DDUI screen, if the Allow List is cleared and user moves ahead by clicking the next screen and attempts to go back to previous screen by clicking back button, the page crashes. If the user decides to move ahead without back button, the saving and delivery of the profile is not impacted.
Do not click the back button from the assignment screen if there is no entry in the Allow List of AirPlay Mirroring for iOS platform.
- ARES-27817: On iOS App Assignment page, Tunnel and other attributes is falsely shown with red exclamation icon
Prevent Removal is set under Other Attributes section in JSON, so when we add /remove the Other Attributes , it removes the Prevent Removal as well from the JSON. When we try editing the app assignment again, the validation for the Prevent Removal is failing resulting in red icon.
When setting the Prevent Removal option , do not remove the Other Attributes.
- AAPP-17014: Apple Education Profile not queuing a removal
Apple Education Profile is not removed from the device during removing of EnrollmentUser > AppleEducationMember Mapping. While removing the mapping, the profiles related to the Apple Education are not selected based on the Device Type and hence incorrect profile (profiles related to MacOS) are selected for removal. Since the device does not have the profile, no Remove Profile Command is queued.
There is no workaround for this issue.
- LUEM-838: Workspace ONE UEM console Device Model filter for "Arch" for Linux devices is incorrect
On the Device List View, when the Device Model filter is applied to search for "Arch Linux" devices, no devices are shown. If "Arch Linux" is used along with other platforms, e.g. Ubuntu, only Ubuntu devices will be shown. Arch Linux devices are shown on the grid if no Device Model filter is used. This is because the platform is actually sent to UEM as "Arch", not "Arch Linux". This does not impact search of other platforms or models.
Users can use the search bar on the Device List View and search using "Arch" keyword to get such devices.
- UM-8400: Cisco ISE API account password expiration
Workspace ONE UEM enforces mandatory password rotation on basic UEM administrator accounts (with a specific API admin role) used for integrating Cisco Identity Services Engine (ISE) with Workspace ONE UEM.
Here is the workaround that you should implement before upgrading to Workspace ONE UEM 2402. See KB article.
Documentation
- To learn more about Workspace ONE UEM, you can browse Workspace ONE UEM Console Documentation.
Localized Content for Omnissa Docs
For details on Omnissa's localization strategy, see the KB article: Announcing Omnissa Localization Support.
Support Contact Information
To receive support, access Omnissa Customer Connect.For information about filing a Support Request in Customer Connect and using Cloud Services Portal, see the knowledge base article at here.
Was this page helpful?