Skip to main content

September 2, 2026

Omnissa Workspace ONE UEM Release Notes

We’re excited to share the new release of Workspace ONE UEM version 2410! Read on to learn about the new features and improvements in this release.

What's New in this release

Admin Experience

Intuitive page navigation for Workspace ONE UEM
Explore our new page navigation for Workspace ONE UEM. Similar functions are now categorized together in sub-menus, with updated labels. For more information, see the KB article.

Revamped UEM API Explorer page includes comprehensive API metadata and search features
We’ve built a new API Explorer to provide enhanced security, improved search functionality, and reduce page load times.

Overcome random MAC address challenges with Cisco Identity Services Engine (ISE) 3.1+ integration
The Workspace ONE UEM and Cisco Identity Services Engine (ISE) 3.1+ integration is now available to everyone. This allows end users' devices to connect securely to network resources, even when they use randomized MAC addresses. For more information and integration instructions, refer to the Tech Zone article Integrating Workspace ONE UEM and Cisco ISE v3.1 and beyond.

Troubleshoot large device log files easily
You can now collect and access large device logs more efficiently. The previous process involved uploading multiple files from Workspace ONE Hub to UEM, requiring administrators to download and merge numerous separate files, which was time-consuming for troubleshooting large log files. Device logs are now uploaded and automatically merged into a single file (up to 200MB), reducing the effort and time needed to troubleshoot devices. This feature is supported only for Android and Windows platforms, starting from 2408 release of the Android and 2410 release for Windows Hub clients.

Modern SaaS Architecture is now available for MSP Partners
We are excited to extend the rollout of the Modern SaaS Architecture to Managed Service Provider (MSP) partner environments, which will be introduced to your environments in the coming months. With this rollout, MSP partner environments can leverage the next-generation Workspace ONE features that enhance performance, scalability, and management capabilities alongside the ongoing support for existing Partner Organization Group use cases.

Omnissa Branding Update
The Workspace ONE UEM console has been updated to align with the new Omnissa brand identity. We have made changes to all the login screens, message templates, URLs, and policy documents to conform to Omnissa standards. We have also replaced old logos, illustrations,and labels with the new Omnissa changes. For more information, see the KB article.

Workspace ONE Mobile Threat Defense Dual Enrollment Configuration by Smart Groups
We initially released support for the configuration of Workspace ONE Mobile Threat Defense (MTD) by Smart Groups in UEM 2406. Now, with Workspace ONE MTD, you can also configure Dual Enrollment support for Android devices by Smart Group. Android Dual Enrollment allows you to enable MTD in both the personal and work profiles of their users' devices. You can also introduce a custom settings profile using the MTD configuration page for specific Smart Groups, enabling support for any future MTD custom settings. This requires Workspace ONE UEM version 2410 Patch 2 and Intelligent Hub 25.01+ on Android.

Faster resource delivery for Tag and Organization Group changes
Resource delivery now happens instantly whenever a tag is added or removed from a device, or when its Organization Group changes. Based on the updated tags or Organization Group, the device will check in immediately and receive the necessary installations or removals. This enhancement ensures faster updates for applications and profiles, reducing delays in bringing devices to their desired state in modern architecture enabled UEM environments.

Android Management

Support for Corporate Owned Personally Enabled mode with Android Management API
Organizations can now manage Android devices in Corporate-Owned Personally Enabled (COPE) mode using AMAPI. This mode was previously only supported with Android using the Custom DPC management type. The QR code generation wizard for corporate-owned Android devices has been enhanced to support generation of QR codes for AMAPI. Also, Android profiles for AMAPI feature new payloads and settings to support COPE devices. For more information on Android Management modes and AMAPI, see Integrating Workspace ONE UEM with Android.

This feature requires the UEM modern architecture and is enabled in Workspace ONE UEM 2410 patch 5.

Enhancements to Application Management for Android Management API
For devices managed using AMAPI, Workspace ONE UEM introduces multiple enhancements to application management that bring it to parity with Custom DPC Android device management. Administrators can now remotely configure applications using Application Configuration, which in turn enables organizations to deploy OEMConfig applications. A new Application Policy tab has been added to the application assignment flow for Android public apps that supports app-specific policies, such as managing runtime permissions. Finally, the Auto Update Priority setting is now supported for devices managed using AMAPI.

This feature requires the UEM modern architecture and is enabled in Workspace ONE UEM 2410 patch 12.

Support for Full-Device VPN with Workspace ONE Tunnel and Android Management API
Workspace ONE Tunnel is now supported on devices managed using AMAPI. Administrators can now configure Workspace ONE Tunnel through the Tunnel and Always-On VPN profile payloads for AMAPI. When assigning public Android applications, administrators can also select a Full-Device VPN profile for AMAPI devices. Support for Per-App Tunnel mode will be added in a future update.

This feature requires the UEM modern architecture and is enabled in Workspace ONE UEM 2410 patch 12.

Updates to Android Public Application Management
In recent years, Google has revamped the Google Cloud APIs that Workspace ONE UEM leverages to provision public applications to Android devices through the managed Play Store. Workspace ONE UEM now supports the updated Google Cloud APIs. For more information, see the KB article Upcoming Changes to Android Public Applications.

Support for Root Certificates for enterprise WiFi profiles (Custom DPC)
Workspace ONE UEM now supports setting up to two trusted Root Certificates in WiFi profiles for Custom DPC devices. This allows administrators to set two trusted certificate authorities for a WPA2 Enterprise SSID. In turn, this allows organizations to update network servers to use a certificate issued by a new certificate authority without disrupting connected devices.

Freestyle Orchestrator

Freestyle for Mobile – Android and iOS Devices (General Availability)
Our powerful workflow orchestration solution is available for Android and iOS platforms. Create intuitive, conditional workflows using Freestyle’s drag-and-drop UI to sequence the deployment of applications and profiles to your mobile device fleet.

  • Target devices based on Smart Group Membership
  • Leverage device conditions for granular targeting
  • Empower end users with on-demand workflows they can initiate through the Intelligent Hub app
  • Configurable retry behavior
  • Robust deployment tracking at both the workflow level and individual step execution level

Note: To use this feature, your environment must be Modern Stack-enabled. For information regarding the rollout schedule, view KB article.

Enhanced Reporting for Application Deployments within Freestyle Orchestrator
Gain better visibility into application deployment outcomes with improved reporting capabilities for Windows devices. When app deployments are triggered from Freestyle workflows, you’ll now receive detailed status updates, clear failure reasons, and timestamp enrichments. The minimum versions necessary to support this are UEM 2410, HUBW 2410, and SFD 2410.

Export evaluated devices within Freestyle Workflow details
Admins can now export evaluated (In Progress, Completed, Failed, Blocked) devices from within the Workflow Details page. Exporting the device table leverages the export framework within UEM Monitoring, so exported devices can be found there. Modern Stack is required for this feature.

iOS Management

Declarative Device Management

  • Status Channel
    Workspace ONE UEM now supports 9 new status items via Declarative Device Management (DDM). For eligible devices, Workspace ONE UEM will automatically receive these attributes as they change on managed iOS devices.

    • OS Version (iOS 16+)
    • Build Version (iOS 16+)
    • OS Supplemental Build Version (iOS 16.1+)
    • OS Supplemental Build Version Extra (iOS 16.1+)
    • OS Family (iOS 16+)
    • Pending Version (iOS 17+)(Will be available in Omnissa Intelligence)
    • Install State (iOS 17+)(Will be available in Omnissa Intelligence)
    • Install Reason (iOS 17+)(Will be available in Omnissa Intelligence)
    • Failure reason (iOS 17+)(Will be available in Omnissa Intelligence)

    For more information on the declarative status channel, see Declarative Device Management.

  • Declarations
    Declarative Configurations now integrate with Apple’s GitHub MDM developer documentation. This integration enables us to implement and update configurations significantly faster. With the help of this integration, Workspace ONE UEM now supports the following new configurations:

* Math Settings (iOS 18+)
* Software Update: Settings (iOS 18+) 

  This integration will be enabled by phased rollout for Workspace ONE UEM 2410 environments deployed on UEM modern architecture. To access Declarative Configurations in the Apple GitHub MDM developer documentation, go to the [GitHub Device Management repository](https://github.com/apple/device-management/). 

Application Management
Workspace ONE UEM now collects and displays the Distributor Identifier application attribute on the Device Details > Apps tab. This attribute indicates where an application was downloaded from, whether it be Apple’s App Store or an alternative app marketplace. Alternative app marketplaces are currently only available in the European Union. For more information on alternative app marketplaces, see About alternative app distribution in the European Union.

Application configuration size limit increased to 30,000 characters

The application configuration size limit has now been increased from 4,000 to 30,000 characters. This enhancement allows you to configure and deploy applications that require significantly larger configuration data, such as certificates, without encountering errors. While the previous limit was sufficient for most use cases, this change addresses scenarios where more extensive configurations are essential.

Profiles
We’ve enhanced the existing Restrictions, VPN, Skip Setup Assistant, Web Clip, and Font payloads and added new payloads for ACME Certificate, and Relay payloads.

Updated Payloads

PayloadDescription
RestrictionsThe Restrictions payload now supports all new iOS 18 features. Here is the list of newly added Restrictions, along with their version and supervision requirements.
  • Allow or block Apple Intelligence features
    • Genmoji (iOS 18 + Supervised)
    • Image Playground (iOS 18 + Supervised)
    • Image Wand (iOS 18 + Supervised)
    • Personalized Handwriting Results (iOS 18 + Supervised)
    • Writing Tools (iOS 18 + Supervised)
    • Mail Summary (iOS 18.1 + Supervised)
    • External Intelligence Integrations (iOS 18.2)
    • External Intelligence Integrations Sign-in (iOS 18.2 + Supervised)
  • Allow or block Auto Dim (iOS 17.4 + Supervised)
  • Allow or block iPhone Mirroring (iOS 18 + Supervised)
  • Allow or block Video Conferencing Remote Control (iOS 18 + Supervised)
  • Allow or block Hiding Apps (iOS 18 + Supervised)
  • Allow or block Locking Apps (iOS 18 + Supervised)
  • Allow or block Call recording (iOS 18.1 + Supervised)
  • Allow or block RCS Messaging (iOS 18.1 + Supervised)
  • Allow or block Default Browser Modification (iOS 18.2 + Supervised)
VPNThe VPN payload now supports Cellular Slice(iOS 18) and Post-Quantum Pre-Shared Key(iOS 18) functionality. You can now assign a specified cellular slice to a VPN tunnel, and configure a VPN with post quantum pre-shared keys.
FontYou can now deploy font files via the Profiles page. Previously, this was only possible via Settings > Devices & Users > Apple > Font.
Web ClipsAdded new options for Target Application Bundle ID and Ignore Manifest Scope.

New Payloads

PayloadDescription
ACME Certificate (iOS 16+)The Automated Certificate Management Environment (ACME) Certificate payload allows for ACME certificate deployment.
Relay (iOS 17+)The Relay payload allows for the creation, deployment, and modification of relay settings. This feature enables administrators to configure an array of dictionaries that define one or more relay servers, which the system can chain together for enhanced routing flexibility and performance.

Enrollment

Device Enrollment Program (DEP) is now Automated Device Enrollment (ADE)
In Workspace ONE UEM, we are adopting Apple's rebranding of Device Enrollment Program (DEP) to Automated Device Enrollment (ADE). The Device Enrollment Program console settings page is now named Automated Device Enrollment. We have also renamed the existing Automated Enrollment console settings page to Apple Configurator Enrollment.

Enforce minimum OS for Automated Device Enrollment
You can now enforce a minimum OS during Automated Device Enrollment (formerly known as Device Enrollment Program). There is a new option within the Automated Device Enrollment (ADE) profile to set a minimum OS. This feature requires the device be running at least iOS 17 or above. When a device attempts to enroll via ADE and the minimum OS is not yet, the device is forced to update to the OS version defined in the ADE profile. For more information, see Automated Device Enrollment.

Linux Management

Check out the new profiles that have been added to Workspace ONE UEM
Workspace ONE UEM 2410 environments installed on UEM modern architecture will gradually roll out two additional profiles.

  • Restrictions Profile - This release introduces the capability for administrators to configure device restrictions and deploy them through a profile for enrolled devices. This profile includes various configurations, including restricting sudo access, limiting access to USB storage media, and naming specific folders as restricted on the endpoints, among other options.

  • Passcode Profile - With this release, administrators are provided with the capability to configure mandatory passcode restrictions through a profile assigned to enrolled devices. This profile enforces various passcode restrictions, including complexity, length, and expiration timeframes for the endpoints.



macOS Management

Workspace ONE UEM updates that requires user action
This release includes Omnissa rebranding changes that change the bundle identifiers for Intelligent Hub for macOS and other supporting software. This requires user action to ensure continued function of our solution.

  • Changes to Intelligent Hub for macOS bundle identifier
    In Intelligent Hub for macOS 24.11, the bundle identifier of the application has changed from com.vmware.hub.mac to com.ws1.hub.mac. When deploying Intelligent Hub for macOS 24.11, any references to the Hub bundle identifier in your custom settings profiles will need to be updated. If you are using Intelligent Hub for macOS 24.07 or lower, no updates are required to the Custom Settings or profiles.

  • Update custom settings for blocking applications and processes
    If you are using a Custom Settings profile to block applications and processes using Intelligent Hub for macOS, we recommend using the Advanced Security Controls profile that is now available in UEM console. However, as Advanced Security Control profile requires Workspace ONE Intelligent Hub for MacOS 24.11, you need to upgrade to Intelligent Hub version 24.11.

    To continue using custom settings profile to block applications and processes using Intelligent Hub for macOS version 24.11, update the custom settings to replace the existing payload type key value to com.ws1.hub.mac.restrictions. If you are using Intelligent Hub for macOS 24.07 or lower, no updates are required to Custom Settings profile.

  • Managing new internal applications
    The Bundle ID for all internal applications distributed through software distribution has changed from com.vmw.macos.<appname> to com.ws1.macos.<appname> format. From UEM 24.10 version onwards, any newly added application will have the Bundle ID with the com.ws1.macos.<appname> format.

  • Managing updates to internal applications
    Bundle ID for applications added before UEM 24.10 upgrade as well as any new versions added for existing applications will have the com.vmw.macos.<appname> format.

  • Disk Encryption profile update requires user action
    After the upgrade to UEM version 2410, macOS device users subject to a Disk Encryption profile will receive a one-time prompt to enter their FileVault password. This change occurs because the profile is re-deployed to refresh the escrow location with Omnissa branding. While the configuration visible to customers remains unchanged, the escrow location value has been updated to eliminate any legacy references.

Declarative Device Management
This release marks the introduction of the first set of features for macOS using Declarative Device Management (DDM). These enhancements leverage DDM's modern approach to device management, enabling faster updates and improved compliance.

New Declarative Configurations
You can now configure a number of Declarative Configurations for macOS including:

  • Software Update Enforcement Configuration

    • Enforce macOS updates using the latest DDM capabilities. (Force Required Operating System Updates)
    • Define policies to ensure devices are running the minimum required macOS version.
    • Administrators can streamline software update compliance without relying solely on legacy MDM commands.
  • Passcode DDM Configuration

    • Introduce passcode compliance through DDM configurations.
    • Simplified passcode policy enforcement for macOS devices, ensuring alignment with organizational security standards.
    • Policies include specifications for passcode complexity, length, and reset intervals.

    These features represent a significant step toward modernizing macOS management and enhancing your ability to secure and manage Apple devices efficiently. Future UEM releases will have full support for DDM.

Status Channel
Workspace ONE UEM now supports 9 new status items via Declarative Device Management (DDM). For eligible devices, Workspace ONE UEM will automatically receive these attributes as they change on managed macOS devices.

  • OS Version (macOS 13+)
  • Build Version (macOS 13+)
  • OS Supplemental Build Version (macOS 13+)
  • OS Supplemental Build Version Extra (macOS 13+)
  • OS Family (macOS 13+)
  • Pending Version (macOS 14+)(Available only in Omnissa Intelligence)
  • Install State (macOS 14+)(Available only in Omnissa Intelligence)
  • Install Reason (macOS 14+)(Available only in Omnissa Intelligence)
  • Failure reason (macOS 14+)(Available only in Omnissa Intelligence)

For more information on the declarative status channel, see Declarative Device Management.

Enrollment

Device Enrollment Program (DEP) Updates
The section All Settings > Apple > Device Enrollment Program has been renamed to All Settings > Apple > Automated Device Enrollment (ADE). Prior to this release, DEP skip keys could be configured either using the standard profile builder in Data Driven UI or within All Settings. These keys are now exclusively supported in the newly renamed Automated Device Enrollment (ADE) area under System Settings.
Note: We have replaced all references of Device Enrollment Program and DEP with Automated Device Enrollment and ADE.

Enforce minimum OS for Automated Device Enrollment

You can now enforce a minimum OS during Automated Device Enrollment (formerly known as Device Enrollment Program). There is a new option within the Automated Device Enrollment (ADE) profile to set a minimum OS. This feature requires the device be running at least macOS 14 or above. When a device attempts to enroll via ADE and the minimum OS is not yet, the device is forced to update to the OS version defined in the ADE profile. For more information, see Automated Device Enrollment.

Profiles

DDUI (Data-Driven User Interface) Enablement
This UEM release will enable the Data-Driven User Interface (DDUI) by default. As part of this update, numerous new payloads and keys are introduced, expanding beyond those listed here.

Updated Payloads

PayloadDescription
Skip Setup AssistantYou can now skip the new Apple Intelligence setup assistant screen in both the DEP profile and Setup Assistant payloads.
  • Skip Setup Intelligence Pane (macOS 15.0+)
  • Enable Lockdown Mode (macOS 14.0+)
RestrictionsThe Restrictions payload now supports all new macOS 15 features. Here is the list of newly added Restrictions, along with their version and supervision requirements.
  • Allow or block Apple Intelligence features
    • External Intelligence Integrations (macOS 15.2)
    • External Intelligence Integrations Sign-in (macOS 15.2+)
    • Genmoji (macOS 15.0+)
    • Image Playground (macOS 15.0+)
    • Writing Tools (macOS 15.0+)
    • Mail Summary (macOS 15.1+)

Advanced Security Controls
This feature allows for granular restrictions on applications and processes, enabling organizations to better protect their environments from unauthorized or potentially harmful software. If you are using Custom Settings profiles today to manage this settings, you can now do it all right from the Workspace ONE Console. This payload requires Intelligent Hub for macOS 24.11 or higher. If you are using an older version of Hub, continue to use Custom Settings.

The key features are:

  • Application Restrictions by Bundle IDs - Specify application bundle identifiers to restrict access to specific apps.
  • Application Name Restrictions - Define application names to apply restrictions, ensuring a straightforward way to block apps based on their names.
  • File Path Restrictions - Restrict specific executables by defining their file paths, offering precise control over application behavior.
  • CDHash Value Restrictions - Utilize cryptographic hashes (CDHash) of app code to block specific applications, ensuring that restrictions are applied to the intended software.
  • SHA-256 Hash Value Restrictions - Enhance security further by restricting binaries using their SHA-256 hash values, preventing tampering and unauthorized execution.
  • Customizable User Notifications - Customize notifications displayed to users when restricted apps or processes are blocked. This ensures clarity and consistency in communication.

This new payload empowers administrators to implement tailored security policies, ensuring environments remain compliant and protected from evolving threats.

New Payloads

PayloadDescription
Relay ProfileThe Relay profile allows for the creation, deployment, and modification of relay settings. You can configure an array of dictionaries that define one or more relay servers, which the system can chain together for enhanced routing flexibility and performance.
  • HTTP/3 Relay URL: Define relay server URLs compatible with HTTP/3 protocol.
  • HTTP/2 Relay URL: Define relay server URLs compatible with HTTP/2 protocol.
  • Additional HTTP Header Fields: Configure custom headers for HTTP requests.
  • Authentication Certificate: Specify certificates required for authenticating relay connections.
  • Raw Public Keys: Provide raw public keys for enhanced security measures.
  • Match Domains: Define specific domains for relay server matching.
  • Exclude Domains: Specify domains to exclude from relay server processing.
ACME CertificateEnhancements to the Automated Certificate Management Environment (ACME) Certificate payload simplify certificate provisioning and add flexibility.
  • Directory URL: Configure the directory endpoint for ACME operations.
  • Client Identifier: Specify a unique identifier for ACME clients.
  • Key Size and Type: Define the size and type of the certificate keys.
  • Hardware Bound: Specify whether the certificate is tied to hardware.
  • Attest: Enable certificate attestation.
  • Subject, DNS, NT Principal, RFC822, URI, and Alternative Names: Configure various subject and alternative name fields.
  • Key Usage: Define allowed uses for the certificate keys.
  • App Access Settings: Restrict which apps can access the certificate.
DNS ProxyThis update adds the ability to configure a DNS proxy network extension, giving administrators control over how DNS traffic is routed through proxies.
New keys:
  • App Bundle Identifier: Identify the application responsible for the DNS proxy.
  • Provider Bundle Identifier: Specify the bundle ID of the DNS provider.
  • Provider Configuration: Configure DNS proxy provider-specific settings.
Font PayloadWith the new Font payload, you can deploy font files directly to devices. This simplifies font management across macOS environments.
Key details:
  • Each payload may contain a single font file.
  • Supported formats: TrueType (.ttf) and OpenType (.otf).
  • Unsupported formats: Collection types (.ttc or .otc).
  • Fonts are uniquely identified by their embedded PostScript name.
  • Installing multiple fonts with the same PostScript name is not supported and may result in undefined behavior.

Download the rebranded Admin Assistant version 24.11

Admin Assistant version 24.11 includes updated Omnissa branding, also available in UEM version 24.10. You can download this renamed version from the UEM dashboard by navigating to Resources > Apps > Native Apps > Add Application for macOS application lifecycle management.

Resource Management

Installation metrics now retained upon Resource and Smart group updates
When assignment or payload updates are made to apps and profiles, or when their assigned Smart groups are modified and republished, installation metrics achieved so far will now be retained and remain visible on the Deployment Tracking page as Currently assigned. It denotes all devices having a confirmed assignment to an app or profile at any given time. This enhancement is currently being rolled out on a Limited Availability basis starting Patch 33. If you are interested in an early access, get in touch with your account team.

Rugged Device Management

Deprecation of Sideloading and Barcode Mobile Staging features
The following Mobile Staging features for Android devices will be deprecated with this release:

  • Sideloading
  • Honeywell Barcode
  • Barcode

Note: QR Code and Stage Now Barcode features will remain supported for Android Rugged Devices. For more details, refer to the KB article.

Support for Zebra LifeGuard OTA
You can keep the Zebra devices in your fleet up to date by using Lifeguard, Zebra’s over the air (OTA) security and patching system for its Android devices. Workspace ONE UEM provides native capabilities for applying LifeGuard updates. For more information, see Zebra Lifeguard OTA Updates.

Tunnel

We’ve updated Tunnel administration for enterprise management and monitoring capabilities
This is a Limited Availability feature. If you have multiple networks to manage or use cases for distinct organizations, you can now easily set up and manage multiple Tunnel environments in a single organization group. This simplifies the integration and distribution of apps and profiles and consolidates the view of their deployment. This update is part of the navigation updates to UEM and also includes new updates to Tunnel's navigation and health metrics for monitoring your Tunnel deployment. For more information, refer to the KB article.

visionOS Management

Support for visionOS
You can now enroll and manage Apple Vision Pro devices in Workspace ONE UEM. Workspace ONE UEM supports all versions of visionOS 1.1 and higher. Devices can be enrolled using Account Driven User Enrollment or Automated Device Enrollment. Workspace ONE UEM manages visionOS as a new platform alongside iOS, macOS and tvOS.

The key features are:

  • Enroll Apple Vision Pro devices.
  • View device details.
  • Configuration Profiles for Wi-Fi, Credentials, Custom Settings and Restrictions.
  • An initial set of commands and custom commands are supported.

Automated Device Enrollment (ADE)
Workspace ONE UEM now supports ADE for visionOS 2.0 and higher based devices that are registered in Apple Business Manager (ABM). Work with Apple to register any Apple Vision Pro devices in ABM. visionOS devices enrolled using ADE are supervised devices.

Once visionOS devices are synchronised between ADM and UEM, you can set up an ADE profile for enrollment. For more information on ADE, see TechZone article.

Account Driven User Enrollment
Workspace ONE UEM now supports Account Driven User Enrollment (ADUE) for visionOS 1.1 and higher devices. ADUE allows users to enroll a device into Workspace ONE UEM via the Apple visionOS Settings UI. visionOS devices enrolled using ADUE are user enrolled devices and not supervised.

ADUE has several requirements including a Managed Apple ID, Apple service discovery, and more. For more information, see User Enrollment and MDM.

Profiles
We have now added the following profiles for visionOS:

  • Wi-Fi
  • Restrictions
  • Credentials
  • Custom Settings

For profiles that are not added in the UEM console, the Custom Settings profile can be used to push down the XML for any Apple supported MDM configuration profile. More visionOS profiles will be added in future versions of UEM.

Commands
We have added the following commands for visionOS:

  • Query
  • Lock
  • Clear Passcode
  • Enterprise Wipe
  • Device Wipe
  • Custom Command

For any command that is not in the UEM console, the Custom Command feature in the Device List View can be used to apply any Apple-supported MDM command to a device. More commands will be added in future versions of visionOS.

Windows Management

Enhanced certificate template for OID-SID extension support
In order to address certificate requirements set to be enforced by February 11, 2025, we have enhanced certificate templates for ADCS within Workspace ONE UEM to include OID-SID Extension. This implementation introduces the users SID attribute as an object identifier (OID) within a non-critical extension key value pair to ensure that certificates meet these new minimum requirements. For more information, see Certificate-based authentication changes on Windows domain controllers.

Intel's Chip to Cloud capabilities
Enable this feature through the Workspace ONE UEM Integrations panel. This cloud-native integration supports device capabilities with Intel vPro® Enterprise. Workspace ONE and Intel® Active Management Technology provide complete remote manageability, allowing access to devices outside the corporate firewall or those with a non-responsive operating system. Additionally, Intel® Endpoint Cloud Services lets IT remotely and securely manage devices inside and outside the firewall, over the cloud.

  • Power Actions - Send out-of-band power commands to devices such as Power On, Power Off, Cycle, and Reset actions.
  • KVM control - Remote keyboard, video, and mouse (KVM) control.
  • The minimum versions necessary to support this are UEM 2410 and HUBW 2410.

Check out more new Windows Security Baseline Templates
We have added new baseline templates for creating Microsoft security baselines for Windows 11 24H2. For more information, see Creating Baselines with a Template.

Support for push notifications in the new WinUI-based Hub
We are launching support for Workspace ONE UEM push notifications in the new WinUI-based Hub as part of our transition from the legacy UWP framework to the new WinUI framework in Intelligent Hub for Windows.

Workspace ONE Mobile Threat Defense Dual Enrollment Configuration by Smart Groups
We initially released support for configuration of Workspace ONE Mobile Threat Defense (MTD) by Smart Groups in UEM 2406. With the 2410 patch 2 release, Workspace ONE MTD customers can also configure Dual Enrollment support for Android devices by Smart Group. Android Dual Enrollment allows customers to enable MTD in both the personal and work profiles of their users' devices. Customers will also be able to introduce a custom settings profile via the MTD configuration page for specific Smart Groups, enabling support for any future MTD custom settings. This requires Intelligent Hub 25.01+ on Android.

Resolved Issues

  • AAPP-16804: ToU displays incorrectly when ABM device is enrolled for iPadOS.

  • AAPP-16890: Non-English characters typed at "Department" in DEP profile are garbled when viewed in iOS device.

  • AAPP-17070: In an iOS desktop device profile with DDUI, aw-tag for Allow Find My Device is located incorrectly.

  • AAPP-17815: Custom Command shows Pending under Troubleshooting

  • AAPP-17946: Empty App Config is delivered to device in a specific update scenario of Internal iOS App

  • AAPP-17981: Notifications not being sent upon successful installation of iOS update.

  • AAPP-18028: ABM resources do not get installed upon enrollment.

  • AAPP-18183: Personal / User-installed apps display in console even though privacy settings are not enabled for it.

  • AAPP-18397: DEP Await Configuration ends prematurely before device is fully configured.

  • AET-18974: UEM MDM API - Assist Chat features not visible when Session Launch from RemoteManagementV1/V2 Controller MDM API.

  • AGGL-17018: CICO with Launcher Apps are not always removed when combined with App assignments.

  • AGGL-17044: Android devices intermittently not added to Smart Groups that filter by manufacturer and model.

  • AGGL-17096: "IsEncrypted" API call for Android not working.

  • AGGL-17113: VPN Profile URL Whitelist does not get applied through profile UI.

  • AGGL-17115: Application Configuration Inconsistent Behavior for Check In Check Out User on Android Devices.

  • AGGL-17301: Deleting area associated profile and the area data causes error in subsequent area profiles creation.

  • AGGL-17514: App Configuration Fails to Apply After Enrollment.

  • AGGL-17553: Changes under Enrollment Restrictions can not be saved.

  • AGGL-17575: Android Credentials profile becomes corrupted when adding version if "Allow silent app access" is enabled.

  • AGGL-17940: Android app are removed from devices when renamed by administrator.

  • AMST-41216: Wireless MAC address will not display when enrolled on LAN.

  • AMST-41420: Baselines are not getting downloaded on some windows devices.

  • AMST-41583: Windows | Compliance status for firewall not showing correct at the start of device.

  • AMST-41874: Unable to delete an OG and getting error "Save Failed Delete Failed".

  • AMST-41960: Application installation status is not reporting correctly on UEM.

  • AMST-42059: Firewall Profile failing to install on Windows 11 systems.

  • AMST-42156: Factory Provisioning Service / PPKG generation stuck.

  • AMST-42458: Addressed certificate profiles not installing with optional assignment while leveraging the Modern SaaS Architecture.

  • AMST-42554: Windows | Firewall Profile installation fails with RemotePortRanges settings in profile.

  • AMST-42613: ARM64 - OOBE enrolled Windows devices Stuck in Pending Hub state .

  • AMST-42637: Baseline and Sensors are not assigned when user signs in as AD user on Win PC and the PC moves to a different OG while leveraging the Modern SaaS Architecture.

  • AMST-42648: Devices getting enrolled with Container type management.

  • AMST-41753 - Internal Server error while retrieving profile details using GET API.

  • ARES-29119: Application_UUID missing in response of GET API mdm/devices/{deviceUuid}/apps/search for Windows and Mac devices.

  • ARES-29230: Alert to 'Leave' or 'Cancel' configuration received when adding criteria under 'When to Call Install Complete' in Deployment Options for Windows apps.

  • ARES-29493: BIOS Password Profiles not applying on devices when deployed via Workflows.

  • ARES-29652: Child OG remains undeleted despite admin's attempt to delete it.

  • ARES-29876: Addressed UEM Console 'page not found' error, when you click Query button at Resources > Apps > Internal > 3CX Desktop App > Devices > Query.

  • ARES-29939: Unable to save iOS Boxer application configuration when the 'Enable FastSync' App Policy is applied.

  • ARES-30062: Exporting list of evaluated devices from an Application Deployment Tracking page results in a failed export.

  • ARES-30074: Spaceman error occurs while searching for a number on Profile List View page.

  • ARES-30209: App removal commands re-triggered for applications already deleted months ago.

  • ARES-30516: Profiles existing in UEM before modern architecture enablement not installing on newly enrolled Work Profile Android Devices.

  • ARES-31019: Status of installed profiles shown as 'Installed but not assigned' on Device Details Profiles tab.

  • ARES-31047: Launcher Profile configured with Custom Lookup fields failing to install on devices.

  • CMCM-191121: Content locker application shows foreign folder names and intermittent issue with files missing/ or displaced.

  • CRSVC-50701: Enhanced logging functionality to obfuscate full API key entries.

  • CRSVC-52960: Status Query String Not Honored for GET api/mdm/compliancepolicies.

  • CRSVC-53629: Resource delivery blocked by Compliance Policy with Enterprise Wipe action.

  • CRSVC-56613: Hardened Email Address continuity validations within UEM Console and API.

  • ENRL-4305: Enrollment blocked by server timeout in customer OG.

  • ESI-103: Tags are not getting assigned for devices being enrolled through Dropship Provisioning.

  • ESI-320: Garbled text being shown to end users upon enrollment failure due to user group restrictions.

  • FCA-207745: Environment sends email notifications for account modifications when the home button is pressed using the new deployment method.

  • FCA-207895: UEM Console makes an incorrect request at landing page for the admin user who enables 2FA and configures landing page.

  • FCA-208029: EID Value and Phone Number are not getting populated for iPad devices.

  • FCA-208096: PhysicalMemory values missing in UEM devices/search API call.

  • FCA-208136: API call "DeviceExtensiveSearchAsync" doesn't work properly with multiple filters.

  • FCA-208232: "POST /devices/gps/search API call does not honour date ranges.

  • FCA-208380: Custom message template for Admin Activation is not getting selected correctly.

  • FCA-208389: Workspace ONE API request continually failing with 500 Internal Server error for mdm/devices/search endpoint.

  • FCA-208390: The "Apply" button on Filters does not work when devices list is opened from Assignment Groups page.

  • FCA-208408: REST API settings inheritance is being incorrectly applied for the child OG.

  • FCA-208419: NetworkInfoSearch API is not using the steps that appear in the official documentation.

  • FCA-208431: Dual SIM iOS devices showing only one phone number in the "Device Info" section.

  • FCA-208432: Device Usage Detail report reporting incorrect values for Roaming Start Date and Roaming End Date.

  • FCA-208533: Reports with a large volume of data are getting stuck as queued on the Exports page.

  • FCA-208840: Sim card details are reported as blank in the report but it is present in the UEM Console and in the DB.

  • FS-5588: Workflows install retired app version.

  • FS-5716: Windows app install fail.

  • FS-6560: Failed sensor status incorrectly parsed by workflow as 'condition not met'.

  • MACOS-5408: Disk Encryption profile is incorrectly delivered to excluded devices.

  • PPAT-17434: Tunnel client not reconnecting once device regains compliance.

  • RUGG-13040: Products being pushed to unintended devices when assignment rules have integer-based custom attributes.

  • RUGG-13180: Manual sorting of Manifests not working in Products.

  • RUGG-13232: Product search (/products/search) and Product extensive search (/products/extensivesearch/) APIs are returning a default policy UUID(0000-000) instead of the actual Device Policy UUID.

  • RUGG-13304: Relay Servers were unable to connect to the Console when default Mac address was used in the discovery text.

  • UM-9294: Attribute sync is failing post upgrade to 2402 console version.

  • UM-9396: Unable to add user groups to a customer-type organization group (OG) from a partner-type OG.

  • CMCM-191100: Admin repo content list view page fails to load.

Patch Resolved Issues

2410 Patch 1

  • FCA-209557: "Query" action is not resulting in Device Check-In for macOS devices.

  • FS-6714: Hide Reported Time in device details page workflow tab and workflow page for mobile devices.

  • FS-7038: Not pushing global tags in while reporting metrics.

  • FS-6781: Spaceman error when clicking into a newly published workflow.

  • AGGL-17575: Android credentials profile becomes corrupted when adding version if "Allow silent app access" is enabled.

  • ARES-31051: API to fetch profiles in an organization group is failing intermittently with 'Internal Server Error'.

  • AMST-42286: EAR update notifications not working.

  • CRSVC-58722: Extend syslog coverage to include all modern SaaS services.

  • FS-6808: Freestyle Getting Started page - change text to include mobile platforms.

  • AGGL-18066: Geofencing for Android profiles is not honored.

  • FCA-208850: Improved logic for offline devices within the data migration stored procedure for modern SaaS architecture.

  • AAPP-17770: iOS: Unable to retrieve the email address in "local identifier" for VPN profile.

  • PPAT-18645: Modern Stack only - Tunnel certificates are not delivered to the Windows Tunnel client on certificate renewal.

  • CRSVC-58684: Prevent incorrect Purchased app removals on the device.

  • FCA-209732: Right click issue caused by blinking popup when hover on devices when using Layout > Custom in UEM (2410).

  • AAPP-18195: SSO extension generates duplicate XML entries.

  • AMST-42945: Update Intel cloud service build to include commit and build tag info.

  • MACOS-5482: Update macOS selective app list sample source when sent from Intelligent Hub from MDM to MAC_OS_MUNKI.

  • CRSVC-58522: Windows | Failed to fetch metadata from the server for workflows, which causes delays in resources delivery.

2410 Patch 2

  • AAPP-18723 [Mod Stack]: Unable to create unmanaged profile with assignment type manual.

  • FCA-209286 [Mod Stack]: Unenrolled devices are unexpectedly shown in Device List View filtered by Smart Group

  • ARES-30148: 'Assigned' count on the Profile Deployment Tracking page displays as 0 instead of showing actual device count after publishing a workflow.

  • ARES-31178: 'Installed but not assigned' status incorrectly highlighted in red for seeded apps like Launcher on Device Details Apps summary page.

  • CRSVC-59402: [Hub Enrollment] iOS 17 Enrollment Fails Due to MDM Profile Installation Error.

  • ARES-31627: Admin unable to save iOS Boxer application configuration.

  • AMST-42987: AirWatch CA certificate not getting installed with manual push of the SCEP profile.

  • AAPP-18691: Cannot install some VPP Apps due to an Associate Failure for licenses.

  • AMST-42768 - Dell Integration - Enrollment with dropship provisioning does not work as call to device services to get generic ppkg fails.

  • AAPP-18898: DEP profile creation is failing with Multi User Device Staging mode.

  • ESI-481: Enable configuration of Dual Enrollment and Custom Settings for MTD.

  • CRSVC-55217: Enhance the Certificate API to support querying all certificates versus the latest available for macOS and Windows.

  • CRSVC-58576: Freestyle Workflow status says failed for app removal even though the app is removed successfully.

  • MACOS-5239: Improvements to command generation for macOS devices.

  • AGGL-18107: Internal apps are sometimes unexpectedly not installed after enrollment completes.

  • PPAT-18798: List of available tunnel configurations are not populating if an associated tunnel configuration is deleted.

  • CMEM-187133: Managed devices are marked as unmanaged by SEG.

  • FCA-209724: New Admin creation causing page crashes in a Container OG created outside of a Customer OG.

  • ARES-30919: Profile not being removed from device when 'Remove' action is performed from Device Details Profiles tab.

  • AMST-43019: Profiles with Unknown Context are removed from Device when modstack is enabled.

  • FCA-209694: Sorting Based on OS Version in the Device List View is not working as expected.

  • ARES-31862: Unable to remove Purchased Apps from Apps Tab of Device Details Page for iOS devices.

2410 Patch 3

Modernized Environment Issues

  • ARES-31581: 'Distribution' tab on Windows Internal app Assignment page missing several options when editing assignments from Deployment Tracking page.

  • AGGL-18264: Android Legacy profiles installing on Android Enterprise devices.

  • CRSVC-59015: App install actions creating multiple log entries.

  • ARES-31350: Deleting child OG crashes Profile List View of parent OG if a Smart Group of child OG was assigned to a profile existing at Parent OG.

  • CRSVC-59520: Device profile installation status is incorrect in device details Profiles tab.

  • AMST-42758: Friendly name is not updated when Windows staging enrolled device is checked out by designate user.

  • AAPP-18726: Handle the XML parsing for the uploaded profiles if it is signed.

  • ARES-31696: Incorrect profile name and version are displayed when editing profile from the Profile List View.

  • MACOS-5598: macOS Declarative profile is not getting installed on the device until profile query is done.

  • CRSVC-59428: Profile installation status shown as 'Not Installed' instead of 'Out of Date' when installed and assigned versions are different.

  • AAPP-18868: Single App Mode not working when using native Apple applications.

  • CRSVC-57677: Some profiles are missing a name when viewing the device details page for a macOS device.

All Environment Issues

  • MACOS-4532: Added System Migration profile payload for macOS.

  • AGGL-18188: Android Internal App upload fails in Product Provisioning if the Package Name ends with a number.

  • AAPP-18903: App installation failures when VPP licenses request is not confirmed complete.

  • AAPP-18119: Assignment Preview MDM API throws 500 error for tvOS.

  • AGGL-18313: Custom attributes are not able to be used as lookup values for App configs.

  • CRSVC-59977: Devices are unenrolled when MDM endpoint returns 4xx.

  • MACOS-5367: Issues with adding a second SSO Extension tab in macOS profile.

  • RUGG-13443: Product fails to honor applicability rule when oemBuildVersion attribute is used more than once in applicability rule.

  • RUGG-13452: Pull Service configuration file fails to download in OGs with trailing spaces in OG name.

  • AAPP-17274: The status for vpp apps shows up as "Update Pushed" in the list view even though auto update is disabled.

  • AMST-42933: UI crashes if multiple keys are saved for removable drive for Windows.

  • AAPP-18601: Unable to edit iOS profiles.

2410 Patch 4

Modernized Environments

No issues reported for this patch.

All Environments

  • FS-7388: [MSP] In Workflow details page, device list is not showing assigned device record.

2410 Patch 5

Modernized Environments

  • ARES-31973: Access denied error is intermittently displayed when deleting profile from Profile List View page and the profile cannot be uninstalled from devices.

  • ARES-31909: Admin unable to install or remove apps from Device Details Apps tab and from App Details page if they are logged into an OG outside Customer OG.

  • ARES-31818: Hub app catalog intermittently does not display the assigned apps.

  • ARES-32014: Incorrect profile status is displayed intermittently in the Device Details Profiles tab due to device sample information being dropped by UEM.

  • AAPP-18006: Support option to defer VPP license revocation.

  • FCA-209896: Device List View does not show the correct set of devices when filtered by Assignment Group.

All Environments

  • AMST-42753: API/system/users/delete fails with 500 error if action exceeds 30 sec timeframe for completion.

  • AMST-42815: Device Sampling API failing for windows devices due large ApplicationListSample.

  • MACOS-5714: Fix to run migration script in 2410 for queueing install profile command for Intelligent Hub Settings profile.

  • MACOS-5713: MacOS Intelligent Hub version selected in settings page is not being honored.

  • CRSVC-60801: MDM queries coming from ISE for endpoints via the MAC address are not returning the expected response, preventing the devices from connecting to the network.

  • AAPP-18577: Per App rules for iOS VPN profile gets enabled by default when adding a new version of the profile.

  • AAPP-18006: Support option to defer VPP license revocation.

  • AAPP-18834: VPP Application assignment change triggers Public application removal.

2410 Patch 6

Modernized Environments

  • ARES-31983: Deleted profiles visible on Profile List View.

  • FCA-210023: Event data opening up to an error screen in the Device Details > Troubleshooting tab.

  • ARES-30330: Installation status on Device Details Profiles tab do not match with the actual profile installation status on devices.

  • CRSVC-59015: Update Event Log entries to improve scenarios where multiple log entries are displayed.

  • RUGG-13537: Product status incorrectly displayed as Non-Compliant despite a successful installation.

All Environments

  • AMST-43100: Add Multi User Status to devices/deviceuuid API.

  • CRSVC-57763: Add support for issuing of non-escrowed certs for EJBCA.

  • AGGL-18137: Android Enterprise Factory Reset Protection profile not prompting option to remove FRP prior to wiping device.

  • CRSVC-60454: Break MDM Complete Event Notification No Longer Includes Detailed Event Information - Breaking Third-Party Workflows.

  • UM-9568: Certificate does not contain SID when “Include Security Identifier (SID) in certificate” is enabled. If you use ACC for PKI integration, restart ACC after UEM patch is deployed.

  • RUGG-13523: Errors enrolling Zebra Printers with Zebra Airwatch Connector.

  • MACOS-5595: macOS uploaded profiles must be linked to user or device context.

  • AGGL-17463: Single App Mode profiles are failing to migrate to EntitlementService under certain conditions in production environments.

  • MACOS-5499: User profile removal from profile deployment tracking page is not working.

2410 Patch 7

Modernized Environments

  • FCA-209869: 'Query Device' action is not working for a bulk selection of devices on the list view.

  • ARES-31425: Assignment summary counts for a profile created through the 'Copy' action are inaccurate at the time of profile creation.

  • ARES-32334: Device list cannot be exported from an app or profile's Deployment Tracking page.

  • FCA-209970: Device List View OS version filter was not working for iOS devices.

  • ARES-32008: Devices under the 'Installed but not assigned' tab cannot be selected when filtering or navigating through pages in the device grid.

  • ARES-31696: Incorrect profile name and version were displayed when editing the profile from the Profile List View.

  • ARES-32251: Profiles on the Device Details Profiles tab were listed in reverse alphabetical order.

All Environments

  • ARES-32080: 'Clear App Data' action in Device Details Apps list was failing with a Page Not Found error.

  • FS-7146: Add Resources Name to Entitlement in Workflow Authoring Flow.

  • CRSVC-61004: Add database script to set value of YATS new domain systemcode/systemcodeoverride.

  • CRSVC-51320: Address SID not being recognized using the URL SAN field.

  • CMSVC-20167: After Partner as tenant enablement some of the smart groups have missing customerUuid.

  • ESI-499: An end-user is able to enrol a device in an OG when the registration token is mapped to a different user.

  • AGGL-18379: Android checked-out/checked-in devices failed to install the required resources based on the smart group membership.

  • PPAT-19198: Bundle ID field was removed from iOS and macOS Tunnel profile on UEM upgrade to version 2410.

  • CRSVC-60706: Current OG missing in UEM admin configured application entity record in lineage list field.

  • CRSVC-57864: Decrease HTTP timeout in DSM for outbound calls.

  • MACOS-5635: Defaults for new keys in macOS SSO Extension payload were not applied correctly.

  • CRSVC-60458: Deserialize protobuf bytes before sending to Intelligence from ICS.

  • AAPP-18767: Device_entitlements cache key for Apple devices were occupying 500 MB for 85000 devices.

  • CRSVC-58755: DSM BG Service or Onetime overrides were not getting purged even after several weeks.

  • CRSVC-59843: Fix Webclient metrics to emit unsubstituted URI in metrics.

  • AMST-43082: Fixed issue with AppX app deployment not working after Hub and SFD were upgraded in UEM 24.2.0.18.

  • CRSVC-60983: Gumdrop - Incorrect index pattern causes security exception.

  • CRSVC-60644: Improve logging for version mismatch issue.

  • RUGG-13451: Install Prov profile going in loop for certain policies, resulting in high RPS and samples.

  • CRSVC-60930: Interrogator sample count value shows the collection length.

  • FS-7042: Interrogator Service Error: duplicate key with unique index 'UX_Status_DeviceUuid_WorkflowUuid_V2'.

  • MACOS-5710: Migration of macOS apps was not happening through the ES migration tool.

  • FS-7368: Move Hub Cache Events feature flag to Production state.

  • CRSVC-60811: Reconciliation tool for Read validation with ELS data needs the ELS table created in canonical.

  • RUGG-13436: RSCC fails to pull content with duplicate entries for the same relay server mapped to different RSCCs.

  • UM-9637: SAML SSO fails when Google IDP is configured for SAML authentication in UEM.

  • UM-9585: Unable to add users to custom user group.

2410 Patch 8

Modernized Environments

  • PPAT-19282: Windows Tunnel on Workspace ONE HUB Registered devices is unable to connect to the gateway after DTR update.

  • ARES-32318: App configured to be installed through Product Provisioning gets removed automatically from devices.

  • ARES-32296: Unable to apply Dependency App filter for Windows Internal apps on Internal App List View page.

  • ARES-31601:Count of profiles on the Device Details Summary page does not match the profile listed in Device Details.

  • AAPP-18837: Supervised iOS devices cannot be deleted.

  • FCA-209954: Add a label to the 'About' page in UEM for environments that have the modern architecture enabled.

All Environments

  • AAPP-18693: Added additional OS support for Restriction Keys (iOS 18.3 & macOS 15.3).

  • ARES-30941: Admin unable to enter multiple custom values for profile payloads with dropdown select fields.

  • CRSVC-59850: Enhanced attribute metadata accuracy for Android and Apple devices.

  • AGGL-18447: Installing the On-Demand public app from Device Details may fail to open for some Android applications.

  • LAUN-22: Launcher layout page is not scrollable when many apps are added.

  • MACOS-5594: Privacy preferences profile failing to install on macOS device.

  • CRSVC-60875: Resolved scenario where Device Wipe Log did not load successfully.

  • AAPP-18578: Schedule OS Update commands in the Queueing state are not removed when excluding the device at the Smart Group.

  • FCA-210103: UEM Device Location Log support for non DST timezones.

  • AGGL-18561: Unable to Override Privacy Settings.

2410 Patch 9

All Environments

  • MACOS-5594: Privacy preferences profile failing to install on macOS device.

  • LAUN-22: Launcher layout page is not scrollable when many apps are added.

  • FCA-209882: Resolves CVE-2025-25229. For more information about these vulnerabilities and their impact on Omnissa products, see OMSA-2025-0004.

  • FCA-210103: UEM Device Location Log support for non DST timezones.

  • CRSVC-62148: Administrator at a child OG is unable to re-evaluate Compliance Policies managed by a parent OG.

  • CRSVC-60875: Resolved scenario where Device Wipe Log did not load successfully.

  • CRSVC-59850: Enhanced attribute metadata flows for Android and Apple devices.

  • ARES-30941: Admin unable to enter multiple custom values for profile payloads with dropdown select fields.

  • AGGL-18561: Unable to Override Privacy Settings.

  • AGGL-18447: Installing On-Demand public app from Device Details may fail to open for some Android applications.

  • AAPP-18693: Added additional OS support for Restriction Keys (iOS 18.3 & macOS 15.3).

  • AAPP-18578: Schedule OS Update commands in Queueing state are not removed when excluding the device at Smart Group.

  • AAPP-19129: Device dashboard Not Encrypted device count is not matching with the Device list view Not Encrypted device count.

  • CRSVC-61651:Enhance the Digicert ONE CA Filtering to include additional CA profile types.

Modernized Environments

  • ARES-32051: Profiles removed from Windows devices displayed on Device Details Profiles tab.

  • ARES-32024: Error displayed while viewing App details for installed VPP apps from Device Details Apps tab.

  • ARES-31103: Spaceman Error received while viewing app details on Device Details Apps Tab for MacOS device.

  • ARES-30528: Admin not able to export XML of Declarative profiles.

2410 Patch 10

All Environments

  • UM-9658: User Group Enrollment Mapping - Unable to map User Group to a lower Organization Group.

  • UM-9396: Unable to add user groups to a customer-type organization group (OG) from a partner-type OG.

  • RUGG-13566: Failed Products are being marked as Compliant in mod stack-enabled environments.

  • MACOS-5777: macOS device not updating OS version in UEM.

  • LUEM-913: Linux Profiles - Add Date/Time and new languages supported in the custom configuration.

  • LAUN-54: Adding apps to an existing Launcher profile under Products fails.

  • FS-7589: macOS Workflows failing due to timeout errors.

  • CRSVC-62204: Administrator at a child OG is unable to perform operations for Compliance Policies managed by a parent OG.

  • CRSVC-61975: OID-SID option visible for incorrect CAs.

  • CRSVC-61277: Update UEM to support additional YATs Domain endpoints (workspaceone.com).

  • CRSVC-59946: Remove unnecessary metrics created in RPS.

  • CRSVC-59830: Data hydration service skips the 1st batch of events intermittently.

  • ARES-32140: Admins with the pre-existing 'Application Management' role unable to publish app assignments after UEM console 2410 upgrade.

  • AMST-43407: Admin account stuck in DELETE IN PROGRESS state when trying to remove admin.

  • AMST-42419: Add Device Reassignment pause status to WinRT agent setting payload.

  • AGGL-17989: Android Device Sampling handle samples from unenrolled device.

  • ATL-24672: Seed Windows Hub 24.10.9.0 x64 and ARM64 MSI to UEM 2410 Patch.

2410 Patch 11

All Environments

  • AAPP-18753: VPN profile was not installing due to missing VPN UUID.

  • CRSVC-62524: Resolves CVE-2025-25231. For more information about these vulnerabilities and their impact on Omnissa products, see OMSA-2025-0004.

  • LUEM-836: Support for ARM64 architecture in Web enrollment.

  • FCA-210276: Admin role comparison was not working.

Modernized Environments

  • RUGG-13045: Apps and Profiles installed from products shows 'Installed but not assigned' in device details page.

  • PPAT-19290: Rapid DTR does not work for Windows Tunnel.

  • FCA-210004: Bulk Action for 'Delete Device' is resulting in a "Save Failed" error.

  • FCA-209694: Sorting Based on OS Version in the Device List View is not working as expected.

  • AGGL-18457: Public App Auto Update profiles still shown as Installed after they are removed.

2410 Patch 12

All Environments

  • RUGG-13614: Unable to add application to Launcher profile.

  • RUGG-13611: Attempting to delete a printer record results in an error.

  • PPAT-19357: Windows Tunnel profiles now respect Tunnel configuration override settings and no longer display inherited Tunnel configurations.

  • MACOS-5768: macOS SSOExtension profile failing due to incorrect use of UseSharedDeviceKeys.

  • MACOS-5198: macOS preference profiles install only after a delay.

  • FS-7692: [Windows Workflow] Workflows/Scripts Created Prior to Rebranding will not Execute Upon Upgrade to HUBW 2410.

  • FS-7690: Product Provisioning .apk app versions are showing up in Freestyle public apps.

  • FS-7685: [Mac Workflow] Workflows/Scripts created prior to rebranding will not execute upon upgrade to HUBM 2411.

  • FCA-210177: Unable to reset password of a basic admin account in UEM with MFA enabled.

  • FCA-210157: Unable to save the Notification for 'Device Enrolled Successfully' with new template.

  • FCA-209243: When "Getting Started" is disabled in an environment, the menu item is still visible in primary navigation pane.

  • ESI-542: Enforcement of enrollment restrictions is not consistent when multiple overlapping policies are created.

  • CRSVC-62586: The Console events profiles filter is resetting to baseline filter.

  • ARES-32367: Admin receives notifications about high usage of device app log storage at all OGs within a customer OG instead of just the customer OG.

  • AMST-43251: Certificates are retained on devices after profile removal.

  • AMST-43118: DiskEncryptionRemovableDrive_Save handling multiple saved keys.

  • AMST-42203: Profile XML not created with SCEP payload with multiple SANs.

  • AMST-41448: Intel vPro power actions do not show up on Device List View (DLV).

  • AGGL-18065: IMEI data is not displaying on Device List View.

  • AAPP-19340: Issues with iOS VPN profiles and VPN UUID.

  • AAPP-19307: Unable to enroll the iOS 18.5 devices when enrollment restriction policy is set to iOS 18.4.1.

  • AAPP-19234: Newly created Derived Credentials Profiles not installing.

  • AAPP-19172: Cannot Update iOS Devices due to page not found error.

  • AAPP-19115: Fail to sync VPP apps in Workspace ONE UEM Console.

Modernized Environments

  • ARES-32084: Desktop application gets reinstalled when assignments are edited for the first time after publish.

  • ARES-32058: Installation status incorrect in Device Details Profiles tab for a few profiles installed through Workflows.

2410 Patch 13

All Environments

  • AAPP-19064: Add troubleshooting events for handling Not Now events on Apple devices.

  • AAPP-19150: Issues with Per App VPN in the Profile Preview screen.

  • AAPP-19167: Denied URLs is blank when editing an iOS Content Filter profile.

  • AAPP-19304: Await Configuration failures for tvOS ADE enrollments.

  • AMST-42645: (Windows Beta Profiles) WS1 - Mod Stack - Windows Profiles Not Automatically Installing.

  • ARES-31991: Command to install an SDK profile not deleted when SDK assignment is removed.

  • ARES-32467: 'View' instead of 'Assign' displayed against internal app versions on App List View even when no direct or workflow assignments exist.

  • ARES-32677: Requesting Hub logs from Device Details page throws error.

  • CMEM-187136: Email configuration does not show configurations until page is refreshed.

  • CRSVC-60724: Applications not removed from Windows devices with compliance policy action to block/remove all managed apps.

  • CRSVC-61478: Workflow-Assigned App is Being Reinstalled After Manual Uninstall when using Freestyle for Mobile.

  • CRSVC-62002: Resolved Issues Preventing the Initiation of Device-Based Targeted Logging.

  • CRSVC-62531: Address Workspace ONE DB Upgrade Maintenance Schema Conflict.

  • FCA-209867: Enrollment Terms of Use incorrectly overridden.

  • FCA-210043: Re-introduce Dutch and Italian locales.

  • FCA-210440: The /devices/extensivesearch API in MDM API V1 does not filter device records with MAC address.

  • FS-7580: Mac Workflows have decreased completion rate, stuck at "In Progress".

  • INTEL-62080: When apps are uninstalled, app record disappears from Intelligence even though the app is still assigned.

  • MACOS-5740: DEP Devices: Queue Scheduled Security Information Sample for Escrowing Personal Recovery Key.

  • MACOS-5817: Re-enrolled macOS device not installing profiles unless device record is deleted prior to re-enroll.

  • PPAT-19252: Console to AWCM connectivity is intermittently failing in tunnel test connection following UEM Console upgrade.

  • PPAT-19334: Custom Setting option not visible for the Saved STC profile.

  • RUGG-13625: File Not Found error when creating Zebra Stage Now staging profiles.

  • RUGG-13646: Profile and app assignment status incorrectly shown as Assigned for deleted or unassigned Products.

Modernized Environments

  • ARES-31938: List of impacted devices not visible in App Removal Log when admin clicks on 'Impacted Device Count' for apps in 'Paused' state.

  • ARES-32065: Incorrect total profile count sometimes displayed on the Device Profiles list.

  • ARES-32306: Internal app version does not upgrade on devices when setting 'Keep app updated automatically" is enabled.

  • ARES-32356: While publishing a VPP app, device preview page displayed 'Added' devices even when no changes are made to the assignment.

  • ARES-32372: Inactive profiles sometimes not visible on Profile List view.

  • ARES-32479: Display correct assignment and installation status for tvOS Apps and Profiles.

  • ARES-32506: False ARP alarm received by admin even though ARP threshold not breached in configured time window.

  • ARES-32773: Duplicate entry sometimes present on Device Apps list with status as Installed but not assigned for app installed via Workflow.

  • ARES-32807: Device Profile list sometimes throws error after configuring Customer Attributes payload in a MacOS profile Issue key Summary.

  • CRSVC-57423 (Former Known Issue): Fixed an issue where if an app was installed via Freestyle for Mobile, then removed by the end user, the app would be re-installed on the device during one of its subsequent check-ins. This differed from expected behavior, where apps are not re-installed if removed.

  • FS-6996 (Former Known Issue): Fixed an issue where in Freestyle for Mobile, the ‘App Exists’ and ‘App Does Not Exist’ condition was case sensitive. It is now case insensitive.

  • RUGG-13615: Count of apps on the Device Details Summary page isn't matching with the apps listed in Device Details.

2410 Patch 14

All Environments

  • UM-9742: Users V2 PUT API does not update deviceStagingType.

  • RUGG-13635: Zebra FOTA Eligible devices grid is not taking SmartGroup assignment into consideration.

  • RUGG-13613: Cannot Publish Edits to Android (Zebra) Device Updates.

  • LAUN-59: Devices do not move back to the staging user when checked in.

  • INTEL-69274: Number of iOS device on Workspace One is 4k+ but it reduced to 2K+ on Intelligence.

  • FCA-210519: Update Intelligence Domain.

  • FCA-210215: Data Encryption in the device list view is not being applied to the 'Phone Number' field.

  • ESI-554: Registered device records have incorrect user info link.

  • CRSVC-62871: Support the UserInfo object in DigiCert CA template.

  • CRSVC-62832: 'ConnectSync' webhook event not showing on UEM console under Event notifications list.

  • CRSVC-62786: Add support for FS while hydration.

  • CRSVC-62771: Windows Profiles are queued for macOS devices.

  • CRSVC-62589: Logging improvement task for ELS.

  • CRSVC-59721: Use Static Mapper for frequent API mappers.

  • CRSVC-58157: Fix OG caching, job interval, and brittle test.

  • CRSVC-57801: Compliance policy evaluation does not reflect updates to policy rules immediately.

  • CRSVC-45576: Update organization group ITs with data-drift.

  • CMSVC-20270: Smart Group Service CI Workflow Build 220 build and publish Failed.

  • CMSVC-20250: Missing tenant checks in add tags to a device endpoint.

  • ARES-32778: Devices not getting profiles and sync not updating for profiles in partner environment.

  • AMST-43596: Firewall Profile - Interface types not loading correctly during edit.

  • AMST-43177: Push Notification Messages not arriving to Win devices.

  • AMST-43157: Fixes to add Mod Stack Dependency to Intel C2C FF.

  • AMST-42645: [Windows Beta Profiles] Workspace ONE - Mod Stack - Windows Profiles Not Automatically Installing.

  • AAPP-19320: DEP Token Flap on Lifecycle Registration Page Caused by ABM API Sync Add/Delete Race.

Modernized Environments

  • ARES-32182: Error occurs when Deployment Tracking page of a Dependency app is accessed from App List view.

  • ARES-3273: Force removal of Internal app from Device Apps list gives 'Door Locked' error sometimes.

  • ARES-28824: Apps should be sortable on app name on Device Details Apps tab but is currently not sortable.

2410 Patch 15

All Environments

  • RUGG-13616: APN profile was not loading any payload settings.

  • MACOS-5747: Incorrect verbiage was seen when Lock Screen was initiated from the Device Details View page.

  • MACOS-4581: Extensible Single Sign-on Kerberos payload updates.

  • CRSVC-57942: Remove the Server EKU attribute from CSR generation for device certificates generated through ADC.

  • CRSVC-62551: Unexpected behaviour around macOS script assignments in Version: 24.6.0.21 (2406).

  • CRSVC-62548: Error while trying to access the API Event Notifications page.

  • ARES-32380: Admin at the child OG receives 'Door Locked' error while accessing the Deployment Tracking page of an app added at the parent OG.

  • ARES-28988: The UEM admin cannot export application's User Ratings list.

  • AMST-43483: Profile deletion was not working.

  • AMST-42971: ARM64 devices were unable to use Registry detection criteria.

  • AGGL-18806: PRM cache does not consider the resource target filter when returning actions - shared iPads.

  • AAPP-19376: Purchased VPP app uninstall API was not working in customer environment.

  • AAPP-19353: Select number of VPP apps get "access denied" grey banner when pushing installation from device details.

  • AAPP-19260: Sample job queuing beyond expected in a run.

Modernized Environments

  • VOS-226: The Profiles Install action was not delivered to AppleVisionPro devices.

  • ARES-33156: Error was displayed when editing profiles that have excluded Smart Groups but no assigned Smart Groups.

  • ARES-32708: A few profiles were not visible on the Device Profiles list in Partner-enabled UEM environments.

  • ARES-32372: Inactive profiles were sometimes not visible on the Profile List view page.

  • ARES-31813: Saving SDK profile shows error has occurred, but entered details are still present when the profile is opened for viewing.

  • AGGL-18785: When Freestyle Mobile workflows are assigned to a device, configuring per-app VPN may fail.

  • AGGL-18692: Profile installation and removal intermittently fail on shared iPads.

2410 Patch 16

All Environments

  • RUGG-13643: Unable to generate StageNow barcode from child OG after upgrade to 2410.

  • LAUN-59: Devices do not move back to the staging user when checked in.

  • CRSVC-63805: Unable to filter Console logs by searching the account name.

  • ATL-25151: Updated seeded Mac Workflow package.

  • ARES-33207: Profile issues with certificate data on Linux devices due to cached enrollment user data.

  • AMST-43593: User installed apps show as "Not Installed" when device sample is taken when no user is logged in on Windows devices.

  • AGGL-18821: PhoneNumber Lookup returns blank when used in App Configuration.

  • AGGL-18227: Support EMM Registration for Modern Private Cloud deployments.

  • AGGL-18224: Edit App Assignment removes the configured per-app tunnel setting and Application Policy when using AMAPI.

  • AAPP-19421: Improvements to dissociation logic for Apple VPP.

  • AAPP-18285: Increased the character limit for URL in Webclip payload on iOS.

Modernized Environments

  • ARES-32641: Door locked error displayed while trying to delete profile from Profile List view.

  • RUGG-13697: Search for apps in the Device's App list failing to return results.

  • RUGG-13687: Device Details page crashes when a device has a profile product with regular and force-reprocessed job.

  • ARES-32372: Inactive profiles sometimes not visible on Profile List view.

  • ARES-32083: Assignment status displayed as 'Assigned' under 'Excluded' tab on app's Deployment Tracking for a device excluded from an app version.

  • AGGL-18083: VPN Profile on app assignment is unable to be edited.

2410 Patch 17

All Environments

  • RUGG-13652: Apps and profiles counts in the Device Details Summary tab should consider unassigned resources, and apps should move to installed once it is reassigned.

2410 Patch 18

All Environments

  • AGGL-18935: Add index for geofencing query to reduce memory waits.

  • MACOS-5913: Adding the rebranded bundle-id of Hubd process to Intelligent Hub settings profile.

  • FCA-210730: API MDD/devices/search should not throw 404 if some of the devices are not found.

  • RUGG-13690: Exception in products cutover flow for WinMo devices when the FF is disabled.

  • FS-7926: Freestyle Orchestrator Application Version Exists Condition Fails with UI Error (24.10 Patch 15, Mod-Stack).

  • CRSVC-63160: Include offline checkin resource types for requests to IH DSM from drift evaluation service.

  • AGGL-17539: Metrics are not getting parsed properly by telegraf.

  • AAPP-19505: Profile samples fails to update when queried.

  • CMEM-187179: The SEG installer navigation link is broken in Add Email Configuration Wizard Settings.

  • CRSVC-64697: Update Digicert profile fetch version.

  • HUBW-18222: Add a Circuit Breaker for repeated DSM failures after Modstack Enablement.

Modernized Environment

  • MACOS-5913: Adding the rebranded bundle-id of Hubd process to Intelligent Hub settings profile.

  • FCA-210730: API mdm/devices/search should not throw 404 if some of the devices are not found.

  • CRSVC-63160: Include offline check-in resource types for requests to Intelligent Hub DSM from drift evaluation service.

  • CRSVC-64697: Update Digicert profile fetch.

2410 Patch 19

All Environments

  • MACOS-5335: Unable to refresh a sensor for a macOS device from the Device Details page.

  • FCA-210831: Admin account roles not readable.

  • FCA-210742: Errors while navigating to different pages in the UEM console.

  • ESI-549: Launcher CICO fails when enrolment restriction for device model is present, despite device being in allowlist.

  • AGGL-18884: Credential payload upload certificate failing for ChromeOS.

  • AAPP-19271: Custom DEP now supports min OS version enforcement.

Modernized Environments

  • ARES-33610: Assignment and installation data misreported for devices assigned to Internal app versions with exclusions.

2410 Patch 20

All Environments

  • PPAT-19169: UEM console Tunnel Config test connection shows old results for UAG versions.

  • AGGL-18988: Certificate profiles are installed twice after Android device enrollment when a compliance policy is assigned.

  • AAPP-19398: Mismatch between Total Eligible Devices and Device Status charts when reviewing iOS OS Update Details.

  • AAPP-19394: Readability updates to iOS Device Updates Details page.

  • ATL-25688: Seed Windows Hub 24.10.13.0 x86 and ARM64 MSI to UEM 2410 patch.

  • ATL-25619: Seeding - latest SFD 24.10.7 build to UEM 2410 latest patch.

Modernized Environments

  • ARES-33371: Device preview displays incorrect counts while updating assignments of Purchased apps supporting multiple platforms.

2410 Patch 22

  • MACOS-5574: Modify XML to allow base 64 encoded data for a valid font and perform E2E testing on iOS and MacOs device.

  • ESI-608: Staging User unable to enroll an Android device registered to an end user in Registered Devices Only mode.

  • ATL-25637: Seeding macOS Hub v24.11.3 to UEM 24.10 Patch.

  • ARES-33173: Spaceman error displayed when clicked on 'View' on Profile List.

  • AMST-44100: Application deployments are very slow during Enrolment.

  • AMST-44014: Add logs to capture exceptions from the resources/status endpoint.

  • AMST-43813: Validate the profile XML for custom settings before delivering the XML to the device.

  • AMST-43450: Continue Checking Intel ECS for Capabilities.

  • AGGL-18815: Fix start time switching from PM to AM in System Updates Profile.

  • AAPP-19393: iOS Device Updates Details page update-status grid filters are not functioning as expected.

  • ARES-34117: Deleting a product-provisioned app via the API unintentionally uninstalls it from devices.

2410 Patch 23

All Environments

  • RUGG-13708: Staging manifest will not be pushed, and QR enrollment fails with discovery error.

  • RUGG-13738: Incorrect installation status shown for Internal App, which failed to install through Product.

  • ATL-26002: Seed Windows Hub 24.10.14.0 x86 and ARM64 MSI to UEM 2410 patch.

  • AMST-44340: Add support to enforce key protectors.

2410 Patch 24

All Environments

  • SINST-176475: Security Enhancements to Backup Configuration File Connection Strings.

  • MACOS-5768: macOS SSOExtension profile failing due to incorrect use of UseSharedDeviceKeys.

  • AMST-44176: Intel vPro- Fixed Power Actions to now show up on all environments regardless of the SKU purchased.

Modernized Environments

  • ARES-32051: Device Profile list not updated when user checks out a Windows device.

2410 Patch 25

All Environments

  • ATL-26140: Seeded Workspace ONE Intelligent Hub for Windows v24.10.15.0.

  • ATL-26078: Seeded Software Deployment Agent (SFD) v24.10.8.

  • AAPP-19393: iOS Device Updates Details page update-status grid filters are not functioning as expected.

  • ESI-708: Resolves CVE-2025-25236. For more information about these vulnerabilities and their impact on Omnissa products, see OMSA-2025-0005.

2410 Patch 26

All Environments

  • VOS-234: Wi-Fi profile fails validation on visionOS devices.

  • UM-10014: Performance issues when trying to export User List.

  • UM-9666: Last Sync On Time Is Off By four Hours.

  • PPAT-19095: Improved performance of console UI while editing profiles containing Tunnel configuration payloads.

  • FCA-210746: License count not properly reflecting in the UEM Admin Panel.

  • CRSVC-66538: Syslog integration stopped working after upgrade to 2506.3.

  • ATL-26283: Seed Windows Hub 2410.16 x86 and ARM64 MSI to UEM 2410.

  • AMST-44046: Fixed issue with Device Root certificate reapply not working as expected.

  • AMST-43530: Device Logs from Scripts are having old tenant uuid even after partner migration.

  • AGGL-19217: Multiple certificates generated for iOS device when device is in Locked state.

  • AAPP-19722: VPP License sync error for certain applications in the console.

  • AAPP-19352: Skip Apple subscription for OnPrem customers.

  • AAPP-18714: Some Internal and Purchased iOS apps fail with error 12008 MDM Command invalid.

  • ESI-736: Multiple pages Such as Diagnostics Pages failing to load after upgrade from UEM 2212 to UEM 2410.

Modernized Environments

  • ARES-34443: Admin occasionally unable to save assignments for Android Internal Apps.

2410 Patch 27

All Environments

  • FS-8130: Time executed and reported time are displaying different time zone.

  • ESI-727: Tags are not getting applied to devices as part of Drop Ship Provisioning enrollment.

  • CRSVC-66560: Application is getting removed and workflow fails when running again.

  • ATL-26469: Seed - Machost to canonical release PR2410-Patch27.

  • ARES-31936: Profile does not get installed on devices with 'Auto' direct assignment unless the On-demand workflow is manually triggered.

  • AMST-44455: Sample Save failure at DiskEncryptionV3SampleProcessor.

  • AGGL-17570: /API/MDM/profiles call fails with 400 error for Android Application Control profiles with Personal Play Store Restrictions set.

  • AAPP-19530: Support for new Setup Assistant (Skip) Keys introduced in Apple OS 26.

  • AAPP-19528: Support for new VPN keys introduced in Apple OS 26.

  • AAPP-19526: Support for new Managed Relay & Restriction keys introduced in Apple OS 26.

  • AAPP-19524: Support for new Parental Controls->Content Filter keys introduced in Apple OS 26.

  • AAPP-19472: Incorrect XML generated for Web Clip payload.

  • AAPP-18368: FasterDSM flow fastlaneapnsoutbound throttling not working - Apple/Mac.

  • AAPP-19523: Support for new extensible SSO keys introduced in Apple OS 26.

Modernized Environments

  • ARES-33410: "Keep App Updated Automatically" setting missing when assigning Windows Internal app from Deployment Tracking page.

2410 Patch 28

All Environments

  • PPAT-20330: Implement changes to upload certificate without client or server authentication EKU.

  • FS-8432: Workflow steps getting stuck on macOS post environment upgrade.

  • CRSVC-64367: Resource delivery is not unblocked when device becomes Compliant for a policy with Block or Remove resource actions.

  • CRSVC-67208: Remove SID Check for Strong Mapping (OID/SID) certificate generation to allow custom systemcode override values on 24.10.

  • CMSVC-20517: Error occurs while creating OAuth token in Partner OG.

  • ATL-26565: Seed - Machost to canonical release PR2410-Patch28

  • ATL-26537: Seeding SFD 24.10.9 build to UEM 2410 patch release

  • ARES-33742: App Search API does not return highest app version under an OG when 'distinctApplicationsPerOg' is True.

  • AMST-44769: Windows Autopilot Enrollment stuck at OOBE “Setting up Work or School” screen post Patch 24 upgrade.

  • AGGL-19201: Patching AMAPI device policy fails when passcode profile uses L/M/H Complexity.

  • AAPP-19871: VPP Apps not uninstalled when switching from staging to end user on iOS devices.

Modernized Environments

  • ARES-33301: App scheduled for future deployment installs immediately.

2410 Patch 29

All Environments

  • ESI-775: Staging user enrolment failing for multiple platforms.

  • AGGL-17372: Throttle SCEP payload creations based on existing throttle limits.

2410 Patch 30

All Environments

  • AMST-44461: Fix MSIX uninstallation.

  • ARES-33719: Profile publish fails when 'Next' button is clicked repeatedly on payload page.

  • ATL-26576: Seed Workspace ONE Intelligent Hub v24.10.17 for Windows to UEM 2410.

  • ATL-26877: Seed - Machost to canonical release PR2410-Patch30.

  • CRSVC-66301: Internal app install for some iOS devices was showing an error of "App Install Blocked".

  • CRSVC-68107: Profiles set to be removed through Compliance Policy were not getting uninstalled from the device.

  • ESI-711: "Registration" page title changes to "Enrollment Status" after performing action.

  • FCA-210682: Custom message templates in deprecated languages cannot be edited.

  • FCA-211402: SmartGroup filter in the Device List View shows incorrect list of devices for groups with enrolment category including "Apple - Supervised".

  • FS-7867 - App Removal log missing.

  • LAUN-66: ForYouWidget functionality using UEM UI was not working as expected.

  • MACOS-4472: macOS Font profile payload has incorrect setting "FontName" in the XML sent to the device.

  • MACOS-5609: macOS devices stalling while in the AwaitingConfiguration state.

  • MACOS-6015: OGs cannot inherit Intelligent Hub settings.

  • RUGG-13784: Product Wifi Profile Domain does not accept URL and IP.

Modernized Environments

  • ARES-33466: Existing assignments displayed as 'Added' in assignment preview while republishing Web Link.

  • ARES-35212: Device Details Profile list incorrectly displays profile from an OG outside the device’s OG hierarchy.

2410 Patch 31

  • FS-7918: Apps installed prior to enrollment and assigned to a workflow won't show steps as completed.

  • FCA-211788: Upgrades to multiple JavaScript libraries to avoid potential cross-site scripting vulnerabilities.

  • ATL-26917: Seed - Machost 2410.3919 to canonical.

  • AAPP-19171: VPP invite status not correctly updated via scheduler in v2 flow.

  • AAPP-16990: Improve purchased application delete flow.

2410 Patch 32

  • FCA-211751: OG filters applied in the Device List View are not applied when exported.

2410 Patch 33

  • INTEL-73644: Data discrepancy observed while creating report in Workspace ONE Intelligence.

  • FS-8083: Workflow time executed and time reported columns in the wrong format.

  • FCA-211499: API returns a 400 Bad Request, and the content of this result will not be a BaseExceptionModel object but will instead be null.

  • FCA-210698: Incorrect Exception seen when API returns a 400 Bad Request for some scenarios.

  • FCA-209987: [UI] Getting Started is appearing as a menu item in Mod UI and Astro even when it is disabled.

  • ESI-744: Admin Provisioning fails when there is no ContactID for an existing admin in UEM.

  • CRSVC-68457: ES and SG crashing because of huge AppList.

  • CRSVC-67084: Add jitter for ES event cache.

  • CRSVC-65842: Reduce DSM docker_build logs.

  • CRSVC-65334: Unnecessary connector configuration updates in CRS.

  • CRSVC-55456: Certificate list API and UI are showing incorrect number of certificates.

  • ATL-27003: Seed Workspace ONE Intelligent Hub v24.10.18 for Windows to UEM 2410.

  • ARES-35007: Error occurs while editing existing Declarative profiles.

  • ARES-34881: Administrator is incorrectly reported in the troubleshooting log for events arising from a tag change.

  • ARES-34536: Trusted Credentials setting under Wifi payload cannot be saved in DDUI Profiles.

  • ARES-34394: Incorrect admin reported in the troubleshooting log for events arising from device tag update.

  • AAPP-20600: Device Updates page failing to load new versions (iOS/macOS).

  • AAPP-20016: (AppleTv)License count is not revoked after removing VPP app from DDV page.

  • AAPP-18838: Apple Declarative Device Management log entries in Troubleshooting Log improvements.

  • ARES-34142: Remove last evaluation dependency and apply changes to retain Deployment Tracking metrics.

2410 Patch 34

  • PPAT-20208: Unable to install VPN profile on both iOS and Android devices.

  • CRSVC-68364: Handling actions when the device is in NotNow state (iOS/MacOS)

  • AAPP-20440: Add telemetry to identify the source of message in queue.

  • AAPP-20370: DEP skip key additions.

  • AAPP-19826: VPP Sync application improvements.

2410 Patch 35

  • RUGG-13770: Custom update creation is limited to loading a maximum of 10 policies.

  • MACOS-4459: Fix macOS restriction to lock desktop wallpaper.

  • FCA-211042: Configure admin roles with Read-Only access to All Settings.

  • FS-8831: Silent failures during script execution causes it to be stuck in progress for macOS devices..

  • FS-8580: Workflow fails on macOS 26 RC 1 devices due to step timeout persisting after completion.

  • FS-8564: Scripts unable to execute due to an unexpected reboot causing a corrupted DB on macOS devices.

  • ESI-728: Launcher stuck in login loop if "Always prompt for terms of use" is enabled.

  • CRSVC-67576: Throttle event log sync failure notifications.

  • CRSVC-67375: Add Windows Pure SCEP Flow Support for OID-SAN Scenario in 24.10.

  • CRSVC-67264: Improvements in throttling event log sync failure notifications.

  • CRSVC-66851: Devices are part of compliance target despite not being in assignment group.

  • CMCM-191640: Admin repo empty after clicking on 'sign-in' in Content app.

  • ATL-27188: Seeding SFD 24.10.10 build to UEM 2410 patch release.

  • ATL-27173: Seed latest Machost to 2410.

  • ARES-35269: Error occurs intermittently while viewing Profile List View.

  • ARES-35213: Profile of another tenant sometimes displayed on Device Profile list.

  • ARES-34661: Removing Smart Group from profile assignments may show devices from other assigned Smart Groups as removed.

  • ARES-33874: Email settings of Boxer app cannot be accessed or updated sometimes.

  • ARES-33477: Few profiles installed on devices of Smart Group previously assigned through a deleted Workflow.

  • ARES-33343: Declarative profile not visible on Device Profiles list when accessed from any Parent Organization Group.

  • ARES-32810: Error occurs while accessing App Removal Log page if any app is in 'Reset' state.

  • AMST-44385: App removal failing instantly for a Windows internal application.

  • AGGL-19140: Maintenance Window is pushed even when Auto Update Policy is "Never" .

  • AGGL-17150: Internal apps stop installing automatically after configuring app control profile and Allow list app group.

  • AAPP-20215: Delay in VPP app installation across large iOS device fleet.

  • AAPP-19620: Unable to install/upgrade VPP apps on selected devices using 'Install on Selected' option.

  • CRSVC-67416: Resource delivery blocked when compliance policy with Block/Remove action for specific profiles is pending evaluation.

2410 Patch 36

  • UM-10252: Clear & Save actions are failing for 'Service Provider (AirWatch) Certificate' and 'Identity Provider Certificate'.

  • RUGG-13821: Push Relay Server stuck at In-Progress stage if large file upload to FTP fails.

  • MACOS-6589: New versions of native Mac app uploads improperly handling rebranded (com.ws1) Bundle ID.

  • CMEM-187215: Test connection button does not work if there are multiple MEM configurations.

  • CMCM-191535: Unable to access network shares on Content app post UEM upgrade to 24.10.

  • ARES-33952: Incorrect total profile count shown in device's profile list when page size is smaller than total records.

  • ARES-33604: Deployment Tracking view displays an incorrect 'Assigned' count of 0 upon adding a new profile version.

  • ARES-32643: Editing assignments of an app fails if an uninstallation script exists in the Organization Group above the app's group.

  • AGGL-19053: FRP remove profile command not received in Mod Stack enabled environments when Admin performs a Device Wipe.

  • AGGL-17740: App configuration, App policy, and per-app VPN settings unexpectedly removed from AMAPI devices.

  • AAPP-20394: ABM resources do not get installed upon enrollment when custom enrollment is enabled.

  • AAPP-20322: iOS Device Updates details page update-status grid filters are not functioning as expected.

  • RUGG-13731: Repeated Product Delivery and Device Reboots When Reboot Manifest Is Used With Other Actions.

2410 Patch 37

  • FS-8912: Time Executed and Time Reported columns not showing values in Workflow Details page.

  • FCA-211768: Improved reading of special characters through assistive technology.

  • FCA-211628: 'Logging Server Failure' notification preferences are not seen in Account Settings.

  • FCA-211493: Improved accessibility for images in the console with added alt-text.

  • FCA-211417: Introduced consistent heading structure in the console to convey information structure and relationships in an accessible manner.

  • ESI-825: MTD Activation through Smart Groups fail when deployed from Partner tenant.

  • CRSVC-70337: Improved logic for device command queue stored procedure related to application removal protection.

  • ATL-27378: Seed Workspace ONE Intelligent Hub v24.10.19 for Windows to UEM 2410.

  • ARES-35595: Apps cannot be sorted on App Group app list view.

  • ARES-31049: Legacy app catalog persists on Android and iOS devices after being turned off in UEM.

  • AMST-45190: Handle Device Reassignment failures with internal server error.

  • AAPP-20207: VPP application versions are not updating in the Console when the country code is non-English.

  • AAPP-20151: Improvements in VPP license sync logic.

2410 Patch 38

  • FCA-211617: Accessibility: Focus ring not rendering correctly on unselected tabs during keyboard navigation.

  • CRSVC-71133: Resolved scenario where profiles using SCEP certificates may not install correctly for newly enrolled MacOS devices.

  • ATL-27504: Update 24.10 with latest Windows Workspace ONE Intelligent Hub v24.10.20.

  • AGGL-19570: Per-app VPN settings not working when VPN profile includes additional payloads.

  • AGGL-19016: IMEI is not seen in the Device List View for some of the Android devices.

2410 Patch 39

  • CMCM-191772: "Allow Upload From Camera Only" flag is not present for a newly created manual user repo.

  • CMCM-191749: "allowUploadFromCameraOnly" flag in the User Repository remains false when 'Allow Upload from Camera Only' option is enabled in the console.

  • CMCM-191657: Console - Implementation of advance DLP controls on image uploads - User Repositories.

  • ATL-27668: Update 24.10 with the latest AWCM binaries (v25.11).

2410 Patch 40

  • FCA-212071: Incomplete data in the settings summary page on UEM.

  • FCA-211762: Improvement to selection and focus state of elements.

  • FCA-211755: Improvements to link readability.

  • FCA-211654: Improvements to console usability via keyboard.

  • ATL-27668: Update 24.10 with the latest AWCM binaries (v25.11).

  • AMST-42184: Race condition observed when Hub loses internet in the last step of enrollment.

2410 Patch 41

  • RUGG-13748: Force Reprocess for any product set from Device Details page fails with page not found error.

  • PPAT-21050: Unable to save Multi-Factor Authentication settings under UEM console for the Tunnel settings page.

  • PPAT-20482: Customer integrated AirWatch SDK with the "SmileToPay" application and which is using device is used as a Kiosk machine with the Single App Mode enabled.

  • FCA-212155: Accessibility: Improvements to keyboard navigation through the console.

  • FCA-211764: Accessibility: Improvements to screen reader support for buttons and links.

  • FCA-211763: Accessibility: Improvements to Settings tree structure for screen reader & keyboard access.

  • FCA-211612: Accessibility: Improvements to focus state visibility and keyboard access for interactive controls.

  • ESI-998: Omni is unable to access the Intelligence console and provides incorrect query AI responses.

  • CRSVC-71256: Compliance notifications over SMS are not delivered in some environments.

  • CRSVC-59655: YATS provisioner for CP services needs change to keep CCs in sync in both YATS database and Vault.

  • ATL-28067: Update 24.10 with latest Windows Workspace ONE Intelligent Hub v24.10.21.

  • AGGL-18782: Vendor keys not deploying to Pulse Secure on Android when a profile is used.

  • AAPP-21374: Enable Apple VPP V2 API.

  • AAPP-20775: Proper IMEI/MEID/Phone Number reporting for iOS 26+.

  • AAPP-20350: Supervised label missing from iOS restriction key "Allow mail smart replies".

2410 Patch 42

  • UM-10484: User Search option in Add Device Registration screen allows search for empty string.

  • MACOS-5970: DEP device configured command is incorrectly delivered to User Channel.

  • LAUN-49: UEM console wrongly mixes up apps and folders on Launcher's canvas if additions and deletions are repeated.

  • FCA-212155: Accessibility - Improvements to keyboard navigation through the console.

  • FCA-211759: Accessibility: Improvements to labels when screens are accessed through screen reader.

  • CRSVC-68230: Profiles installed through Workflow incorrectly show "Installed but not Assigned" status in the Device Details Profiles tab

  • ARES-35383: Side-loaded (unmanaged) iOS profile shown as removed in Device Profiles list despite being installed.

  • AGGL-19665: App Config screen for an internal app does not show all options for some dropdown settings.

  • AGGL-19335: Unable to set Application Configuration if app has duplicate keys in its schema.

  • AGGL-19105: After deactivating Android Public App on Console, App remains on the Device's Play Store.

  • AAPP-21456: Support for OS 26.4 MDM keys (Restrictions, Parental Controls).

  • AAPP-20699: Update profiles with new Skip Keys (Camera Control, Keyboard, Dictation, Age Assurance, Age-Based Safety Settings) and Restriction Key (RatingAppsExemptedBundleIDs).

  • AAPP-20461: Add support for new Skip or Setup Assistant Keys in ADE profile: Camera Control, Keyboard, Dictation, Age Assurance, Age Based Safety Settings.

  • AAPP-19962: VPP V2 - Unenrollment of the primary device of a Shared User-Based License was not working as expected.

2410 Patch 43

  • FCA-213005: Multiple console pages crash when language is set to Non-English locale.

  • FCA-212910: Clicking UEM logo redirects to error page with “Cannot convert undefined or null to object”.

  • FCA-212810: Date picker fails when editing download start, end, and install by fields in Zebra LG OTA Updates.

  • CRSVC-73705: Enhanced SCEP auto-renewal logic to support user-based profiles where signed user & enrollment user are not the same.

  • CMCM-191789: Content app on iPad and Android, is displaying duplicate of same folders.

  • ARES-37278: Incorrect app config delivered to newly enrolled devices assigned to future-dated Internal app assignments.

  • AMST-46117: Filter uem zip/exe from inventory view.

  • AMST-45941: Seeded Resources- Dashboard - App Deployment Agent Tab doesn't load devices when "resource_subtype" is "UNKNOWN".

2410 Patch 44

  • FCA-213282: Enterprise Wipe action does not validate administrator OG access when "Prevent Re-enrollment" is unchecked.

  • FCA-211761: Accessibility - Improvements to screen reader usability in the console for datagrids and other elements.

  • FCA-211733: Accessibility - Improvements to focus state of buttons and other elements for keyboard users.

  • FCA-211732: Accessibility - Improvements to console navigation through keyboard.

  • FCA-211258: Accessibility - Improved color contrast ratio in screens across the console.

  • FCA-213345: Incorrect devices scoped for bulk actions performed from the Device List View.

2410 Patch 45

  • AGGL-20112: ChromeOS Wi-Fi profile with credentials payload fails to install.

  • AAPP-21692: VPP apps not getting app config settings delivered.

2410 Patch 46

  • RUGG-14238: Searching and sorting products in device details page does not work if the device has more than 50 products.

2410 Patch 47

  • MACOS-7216: Unable to edit the iOS VPN payload for IKEv2 type.

  • MACOS-6810: If device reports NotNow for one scheduled sample, next sample is not tried.

  • CRSVC-75006: Azure token may not be revoked if device is deleted when offline.

  • CRSVC-71788: Certificate count inconsistency between Certificate list and Widget.

  • AMST-46542: Fixed issue with MST apps unavailable when you navigate directly to the Assignments tab.

  • AMST-46303: Tunnel - Client certificate may require repush before landing on the device.

  • AMST-46121: SCEP sample is queued even when the seeded SCEP profile installation has failed.

  • AAPP-20576: Failed to fetch user token for macOS device.

2410 Patch 48

  • FCA-209931: Login history is not being recorded for Omnissa Connect admins in UEM.

  • ATL-28337: Seeded AWCM with the latest binaries.

  • AGGL-20567: Enhanced assignment rules response to resolve issues impacting assignment updates.

  • AGGL-20483: Android Internal App upload intermittently failing.

2410 Patch 49

  • FCA-211725: Accessibility enhancements to allow UEM console screens to render at up to 200% Zoom.

  • AGGL-20730: Managed App Configs are Corrupted by Hierarchical Key.

  • AAPP-22508: Device updates tab shows 'Not Available' for Apple OS Updates.

  • AAPP-21422: Improvements to VPP v2 license management.

  • AAPP-20656: Handle license revocation failures for externally redeemed VPP apps.

2410 Patch 50 (SaaS only)

  • PPAT-19201: Hide "Tunnel & Other Attributes" when deploying the Workspace ONE Tunnel app.

  • LAUN-211: The Launcher Profile does not allow page changes for layout.

  • LAUN-185: Implement configurable header font size for Workspace ONE Launcher.

  • FS-8548: Address app and profile quick action workflows failures on Android.

  • FCA-214054: Update Last Seen, Compliance and Enrollment Status colour palette in Device List View for accessibility and visual distinguishability.

  • FCA-213846: Resolved a display issue where device tags were missing from the summary layout of the Device List View.

  • FCA-213818: Authorization error message is being incorrectly shown on some console screens.

  • FCA-212015: Improvements to content visibility at 200% zoom.

  • FCA-211715: Text alternatives provided to graphs on Content Dashboard.

  • FCA-211714: Text alternatives provided to graphs on Device Dashboard.

  • CRSVC-66297: Compliance status update is not sent to Conditional Access partner when compliance policy is unassigned.

  • ARES-38352: 'Platform' filter displayed twice on profile list view.

  • AAPP-22155: Improve retry logic for VPP v2 calls.

  • AAPP-21798: Improve handling of Apple's throttling limits for VPP v2 flows.

  • AAPP-21344: Admins receive email alerts that Application Removal Limit Exceeded for VPP apps.

2410 Patch 51

  • MACOS-7103: Resolved an issue where newer application versions, deployed to lower OGs, were incorrectly inheriting and overwriting the Bundle Identifier schema.

  • CMCM-189936: DS changes for Moving files in NFS repositories.

  • AAPP-21214: VPP applications not installing on AppleTV devices.

  • ARES-39102: App UUID displayed instead of app name in device troubleshooting log.

2410 Patch 52

  • SINST-176756: Updated service runtime to .NET 10 for improved performance, security, and long-term support - UEM & CP Services.

Known Issues

  • ARES-32181: MacOS Hub App shows loading state when user re-installs App within 2 hours of previous install

    When an end user triggers an app reinstall through the Mac Hub app within 2 hours of a previous install, the new installation does not proceed and the Hub displays a persistent loading icon instead of the expected "Re-install" option. This issue occurs only when the same app is installed, uninstalled, and then reinstalled within a 2-hour window by the end user through the Hub app. Admin-initiated installs through the UEM console are not impacted. This impacts all UEM environments including Modern stack enabled environments.

    Workaround: Admins can manually trigger the install from the UEM console, or the end user can retry the installation through the Hub app 2 hours after the initial install.

  • FS-4005: Freestyle for Mobile will not have the ‘Latest Version’ feature available yet. Admins will need to use specified versions of internal applications. Profiles will also need to be update by editing the workflow.

  • CRSVC-54789: Apps cannot be reinstalled within a 4 hour window. This applies to all methods of re-installation, including direct assignment, auto-deploy workflow, and on-demand workflow. If a workflow tries to re-install an app within 4 hours of the previous installation, the workflow step will get stuck in-progress then fail once retries are exhausted.

    Workaround: Set up a retry interval that is longer than 4 hours.

  • VOS-128: Regular DEP with Authentication enabled doesn't request for credentials from the User on the device During DEP enrollment of Apple Vision Pro Device, depending on the dep profile configuration, we request the user to enter the credentials or not. During regular DEP, the default is to pick the staging user for enrollment and that can be changed to request for authentication from the user. The device gets hung on the screen and does not request for the credential.

    Workaround: For Authentication to work, the customer needs to turn on Custom Enrollment in the ADE profile.

Release Availability

We strive to deliver high-quality products, and to ensure quality and seamless transitions, we roll out our products in phases. Each rollout may take up to four weeks to accomplish and is delivered in the following phases:

  • Phase 1: Demo, Shared SaaS UATs, and Latest Mode UATs

  • Phase 2: Shared SaaS environments

  • Phase 3: Latest Mode environments

This version is initially available to our SaaS customers on the latest mode. The features and improvements incorporated in this version will be available to our on-premises or managed hosted customers with the next on-premises release. For more information, see the KB article.

Note: The Modern SaaS Architecture features will not be available in on-premises releases.

Getting Ready for Major OS Releases

To prepare for the upcoming software updates from the major device vendors, read through the Getting Ready for Major OS releases section of the Omnissa Product Documentation.

Documentation

To learn more about Workspace ONE UEM, you can browse Workspace ONE UEM Documentation.

Localized Content for Omnissa Docs

For details on Omnissa's localization strategy, see the KB article Announcing Omnissa Localization Support.

Support Contact Information

To receive support, access Omnissa Customer Connect. For information about filing a Support Request in Customer Connect and using Cloud Services Portal, see the Knowledge base article here.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…