We’re excited to share the new release of Workspace ONE UEM version 2506! Read on to learn about the new features and improvements in this release.
What's New in this Release
Android Management
Experience seamless single sign-in and sign-out with Microsoft Entra for shared Android devices
You now have the advantage of a smooth single sign-in and sign-out process for applications that support the Microsoft Authentication Library (MSAL) on shared Android devices using the Workspace ONE Launcher. This feature supports first-party Microsoft applications such as Teams and any third-party applications that integrate MSAL and support Microsoft’s Shared Device Mode.
To use this feature, organizations must configure devices to use Check-in/Check-out (CICO) with Workspace ONE Launcher. Users authenticate with Microsoft Entra to check out the shared device. Users only need to launch supported MSAL-enabled apps to start using them. When users log out of Workspace ONE Launcher, they are automatically signed out of these applications. Additionally, this feature provides an alternative to the Workspace ONE Mobile SSO for organizations that cannot federate Microsoft Entra with Workspace ONE Access or cannot use Workspace ONE Tunnel as their VPN client.
Remotely deliver certificates to your device using SCEP payload
A new SCEP payload is now available in Android Custom DPC profiles. Push this profile to enable the remote delivery of certificates to your device from your certificate authority using the SCEP protocol. The Intelligent Hub obtains an SCEP challenge from Workspace ONE UEM, securely generates a private key on the device, and acquires the certificate from your certificate authority. The Hub then adds the certificate to the Android Keystore, where other applications on the device can access it. Silently granting applications access to these certificates is supported. Workspace ONE UEM currently does not support the use of the SCEP payload for configuring Wi-Fi with certificate-based authentication.
Configure Access Point Names (APNs) for work managed Android devices
A new Access Point Name (APN) payload is now available in Android Custom DPC profiles. Push this profile to remotely add APNs for mobile networks to Android devices. Additionally, you have the option to mandate that your Work Managed devices utilize only managed APN settings. This allows organizations to easily deploy private APNs to better secure access to corporate resources over mobile networks. This is supported on Android 9.0 and higher that are enrolled in Work Managed mode.
Android Management Mode Filter for Smart Groups
You can now create Smart Groups that capture Android devices with a specific Android Management Type (Custom DPC vs AMAPI) and Android Management Mode (Work Profile, Work Managed, or COPE).
Note: This feature is available on demand in Workspace ONE UEM 2506. Please contact your Omnissa representative or submit a support request to enable this functionality. This feature will be generally available in Workspace ONE UEM 2509.
Certificate Management
Integrate OID-SID and SAN into certificate templates
To meet the updated certificate requirements, we have enhanced certificate templates within Workspace ONE UEM to include OID-SID Extension and support for SID values in the SAN field.
- When assigning a certificate to a user in Active Directory (AD), it is essential to format the certificate entry using one of the strong formats.
- Ensure that the Security Identifier (SID) is selected in the Active Directory Certificate Services (ADCS) certificate template. The Certificate Signing Request (CSR) must contain the OID-SID key-value pair and this extension is present in the generated certificates.
- Alternatively, the same value can be submitted in the SAN field and is the primary implementation for SCEP-based certificates.
For more information, see Certificate-based authentication changes on Windows domain controllers.
Integrate DigiCert ONE with Workspace ONE UEM for enhanced security
Workspace ONE administrators can now set DigiCert ONE as a trusted certificate authority within UEM. Following this, they can create a certificate template and utilize the profile’s credential payload to issue and deploy certificates. This integration significantly enhances stability, security, and authentication, facilitating the effective use of certificates across various domains, including Public Key Infrastructure (PKI) and S/MIME.
Freestyle Orchestrator
Streamline onboarding entitlements in workflows
Onboarding entitlements within workflows allow administrators to prioritize resources essential for onboarding, which take precedence over other resource assignments. This is available only for Windows. For more information, see Onboarding Workflows.
Enhance device onboarding through offline domain join within workflows
You can now incorporate the domain joining process into workflow systems, enhancing the onboarding process for devices and allowing devices to join a domain before other resources are deployed. This is available only for Windows. For more information, see Offline Domain Join in Workflows
In-line Sensor evaluation: A better way to use Sensors within workflows
Sensors are now assessed at their step within the workflow rather than at the beginning of workflow execution. This approach enables administrators to monitor sensor values within the workflow as needed instead of re-using the value stored from evaluations done prior to the start of execution.
Enhanced reporting for application deployments within Freestyle Orchestrator
Gain better visibility into application deployment outcomes with improved reporting capabilities for Windows devices. When app deployments are triggered from Freestyle workflows, you’ll now receive detailed status updates, clear failure reasons, and timestamp enrichments.
Workflow Engine Enhancements
The workflow engine has undergone a significant backend enhancement with an upgrade to .NET 8.
iOS Management
Enhance device security with Managed Device Attestation
Managed Device Attestation is available for devices running iOS 16, iPadOS 16.1 or later with Apple Silicon or A11 Bionic chip or newer. This feature offers robust verification of the device’s properties, which are essential for trust evaluation. This cryptographic declaration of device properties is based on the security of the Secure Enclave and the Apple’s attestation servers. By leveraging attributes such as Serial Number, UDID, and OS version, Managed Device Attestation enhances trust evaluations for devices enrolled through Automated Device Enrollment or profile-based device enrollment. For more information, see Managed Device Attestation.
This feature is Generally Available from 2506 Patch 1.
After device wipe, return to service easily with automated reprovisioning process
With this exciting new feature, organizations can easily wipe all user data from a managed iOS device and get the device back into service without needing administrators to physically handle it. Workspace ONE UEM supports Return to Service functionality for iOS 17 devices, allowing MDM to add an enrollment and Wi-Fi profile to the device wipe command. This automated process eliminates the need for manual Wi-Fi configuration by administrators post-Device Wipe. For more information, see Return to Service.
Easily release a device from Apple Business Manager and Workspace ONE UEM
You can release corporate iPhones and MacBooks from Apple Business Manager or Apple School Manager if they’ve been sold, lost, are beyond repair, or when an employee moves on from your organization. With Workspace ONE UEM, you can now release devices using the Enterprise Wipe, Device Wipe, and Delete Device actions. By default, this capability is only available to administrators with the System Administrator role, with plans to extend access to Console Administrator and AirWatch Administrator roles in the near future. For more information, see Release a Device.
Enhance Apple Books delivery with Modern SaaS Architecture
The delivery of Apple Books (internal and public, not VPP books) now leverages our Modern SaaS Architecture to significantly improve delivery performance. Read more about our new architecture here.
Apple GitHub integration for DDM configurations is now available
Declarative Configurations was in limited rollout in 2410 release and is now Generally Available from 2506 Patch 3. Declarative Configurations now integrate directly with Apple’s GitHub-hosted MDM developer documentation. This integration streamlines how we implement and update DDM configurations, enabling significantly faster development cycles and improved alignment with Apple’s latest specifications.
To explore Declarative Configurations in Apple’s GitHub MDM documentation, visit the GitHub Device Management repository.
The following new DDM configurations have been added with 2506 patch 3:
- Software Update: Settings
- Math Settings
Launcher
Custom XML Settings Integrated into the Console
Some settings introduced to Workspace ONE Launcher can only be configured through XML pushed through the Custom Settings profile. We have configured these settings as native features or settings in the Launcher profile payload.
The following features have been integrated into the Launcher profile:
- Speed Lock
- Dynamic App Availability
- Show Logout Button from Guest Mode
- Require Tunnel before Launcher
For more information, see Workspace ONE Launcher product documentation.
Linux Management
Easily implement firewall rules on Linux devices
In addition to the recent profile releases, including Date/Time, Proxies, Passcode, and Restrictions, we are excited to introduce support for a Linux Firewall Profile. This new profile allows users to configure firewall rules that will be enforced on the device once assigned and deployed. For more information on profiles, see Linux Profiles.
Enhancements to Workspace ONE Sensors
To provide greater flexibility and choice, administrators now have the option to write Workspace ONE Sensors using Python 3, in addition to the existing option of using Bash. For more information, see Sensors for Linux Based Devices.
macOS Management
Enhance device security with Managed Device Attestation
Managed Device Attestation is available for devices running macOS 14 or later with Apple Silicon or A11 Bionic chip or newer. This feature offers robust verification of the device’s properties, which are essential for trust evaluation. This cryptographic declaration of device properties is based on the security of the Secure Enclave and Apple’s attestation servers. By leveraging attributes such as Serial Number, UDID, and OS version, Managed Device Attestation enhances trust evaluations for devices enrolled through Automated Device Enrollment or profile-based device enrollment. For more information, see Managed Device Attestation.
This feature is Generally Available from 2506 Patch 1.
Easily release a device from Apple Business Manager and Workspace ONE UEM
You can release corporate iPhones and MacBooks from Apple Business Manager or Apple School Manager if they’ve been sold, lost, are beyond repair, or when an employee moves on from your organization. With Workspace ONE UEM, you can now release devices using the Enterprise Wipe, Device Wipe, and Delete Device actions. By default, this capability is only available to administrators with the System Administrator role, with plans to extend access to Console Administrator and AirWatch Administrator roles in the near future. For more information, see Release a Device.
Apple GitHub integration for DDM configurations is now available
Declarative Configurations was in limited rollout in 2410 release and is now Generally Available from 2506 Patch 3. Declarative Configurations now integrate directly with Apple’s GitHub-hosted MDM developer documentation. This integration streamlines how we implement and update DDM configurations, enabling significantly faster development cycles and improved alignment with Apple’s latest specifications.
To explore Declarative Configurations in Apple’s GitHub MDM documentation, visit the GitHub Device Management repository.
The following new DDM configurations have been added with 2506 patch 3:
- Account: CalDav
- Account: CardDav
- Account: LDAP
- Account: Mail
- Account: Subscribed Calendar
- Math Settings
- Screensharing: Connection
- Screensharing: Host Settings
- Disk Management: Settings
- Software Update: Settings
Resource Management
Pending Actions visible for troubleshooting
When troubleshooting device issues, you now have the advantage of accessing Pending Actions. This feature provides a comprehensive list of planned resource installation and uninstallation commands for Apps, Profiles and Workflows on a device the next time it checks in. To view a device’s Pending Actions, go to Device Details, navigate to More > Troubleshooting, and then select the newly added Pending Actions tab.
Installation metrics now retained upon Resource and Smart group updates
When assignment or payload updates are made to apps and profiles, or when their assigned Smart groups are modified and republished, installation metrics achieved so far will now be retained and remain visible on the Deployment Tracking page as Currently assigned. It denotes all devices having a confirmed assignment to an app or profile at any given time. This enhancement is generally available starting Patch 25.
Faster resource delivery for larger device populations
Faster resource delivery is now supported for a larger device population when apps and profiles are published. This type of delivery is initiated whenever new apps or profiles are published, assignments for existing ones are updated, profile payloads are modified, or Smart Group rules change if the number of devices impacted by such updates is below a defined threshold. Devices impacted by these updates will check in immediately and install or remove the necessary resources instead of waiting for the standard check-in cycle. This enhancement is being rolled out on Limited Availability starting 2506 Patch 12 and generally available starting Patch 27. Contact your Account Team if you would like to participate in the Limited Rollout or have any questions regarding this enhancement
Rugged Device Management
Relay Server Management enhanced with V2 APIs
As part of our continuous efforts to streamline and expand product provisioning, we are launching Relay Server V2 APIs. These are UUID-based endpoints supporting basic CRUD operations, advanced search(by name, type, status etc.), and a test connection API to verify relay server connectivity. The V2 APIs enable secure, fully automated, end-to-end management of relay servers. For more information, refer to the ‘RelayServersV2’ section of API help page.
tvOS Management
After device wipe, return to service easily with automated reprovisioning process
Workspace ONE UEM supports Return to Service functionality for tvOS 18 devices, allowing MDM to add an enrollment and Wi-Fi profile to the device wipe command. This automated process eliminates the need for manual Wi-Fi configuration by administrators post-Device Wipe. For more information, see Return to Service.
User Management
Streamline user group management using the latest REST APIs
A new set of REST APIs is now available to simplify group management. These APIs provide functionalities including creating user groups, updating their properties, and performing actions such as synchronization and merging, and deleting unwanted groups.
Directory Services migration to Omnissa Identity Service
With this Limited Availability feature, you can now integrate with the Omnissa Identity Service to migrate Directory Services from on-premises Active Directory (LDAP) to Entra ID (SCIM 2.0). The Omnissa Identity Service provides a seamless transition to Entra ID for user provisioning and authentication through a guided migration wizard. This is designed for users who are synced to UEM through LDAP-based integration with Active Directory.
visionOS Management
Overview of recently added profiles for visionOS
The following visionOS profiles have been introduced to the Workspace ONE Console UI. For more information, see visionOS Profiles.
- AirPrint
- CardDAV
- Certificate Transparency
- DNS Proxy
- Domains
- Global HTTP Proxy
- Passcode
- Subscribed Calendars
- VPN
Windows Management
Launch native and App Volumes MSI apps directly from Intelligent Hub for Windows
With this enhanced app catalog functionality, you can now launch native applications and App Volumes MSI apps directly from the Intelligent Hub app catalog in addition to the existing ability to launch Web and Horizon apps.
The key new features are as follows:
- App Launch Support: Native apps and App Volumes MSI apps can now be launched from within the Hub catalog.
- Admin Control: IT administrators can define custom launch commands for all applications in the app configuration within Workspace ONE UEM.
- Improved User Experience: You no longer need to manually locate and open native apps post-installation; you can now launch them directly from the Hub interface.
Previously, users could install native applications through the Intelligent Hub, but launching them directly was not possible. Now, with launch commands configured in UEM, the Hub executes the command defined by the user, providing a seamless experience to both install and launch apps from a single interface. This enhancement simplifies app access and enhances productivity by reducing the number of steps required to open frequently used apps. For more information, see Installing Native Apps.
Default User Mode configuration during Windows device enrollment
Workspace ONE UEM now supports configuring the default user mode (Single User Mode or Multi User Mode) at the Organization Group (OG) level. This setting is automatically applied to Windows devices during enrollment through the Intelligent Hub client.
- Configuration in UEM console (Requires UEM version 2506 or later): Administrators can define the default user mode in the UEM console under the OG settings. The available options include:
- Single User Mode
- Multi User Mode
- Hub behavior during enrollment (Requires Hub version 24.10.10+ or 25.06.x):
- During the enrollment process, the Windows Intelligent Hub queries the UEM console for the default user mode setting.
- The retrieved mode is validated and stored locally by the Hub.
- Based on the setting, the Hub configures the Windows device accordingly.
Manage Intelligent Hub application versions on Windows devices
The Technical Preview feature, Intelligent Hub Application Version Control allows administrators to manage precise control over version of the Intelligent Hub is installed on Windows devices, supporting both Win32 and ARM platforms. You can now deploy Intelligent Hub updates independently of Workspace ONE UEM console upgrades and gain direct access to Beta builds without manual download or upload steps. Unified version control is available for both Intel/AMD (Win32) and ARM-based Windows devices.
Once enabled, the setting Intelligent Hub Automatic Updates will be renamed to Use Intelligent Hub Version Control, and a new section for Intelligent Hub Target Seeding will allow version assignment at the Organizational Group level. The key capabilities include:
- You can now assign specific versions to production OG to ensure consistency, while using the latest GA or Beta version in a test OG for validation.
- Instant application of changes to newly enrolled devices (including OOBE and Autopilot) with existing devices auto-updating within 48 hours.
- Downgrades are not supported for devices already running newer versions.
If Intelligent Hub Automatic Updates were previously enabled, the new setting defaults to Latest available. In contrast, if automatic updates were deactivated, the new version control setting will also remain in a disabled state.
Note: This feature requires Workspace ONE UEM version 2506 or later.
Faster SFD delivery and installation through the Intelligent Hub
Workspace ONE now supports a faster and more efficient installation of the Software Distribution Framework (SFD) by shifting the process from the traditional OMA-DM channel to a Hub-based installation. With this enhancement, SFD is bundled with Hub and is installed immediately after enrollment, enabling earlier application deployment and improving overall device readiness. We've made the following improvements:
- SFD is now installed through the Intelligent Hub, independent of the OMA-DM workflow.
- Installation occurs immediately after enrollment as the SFD package is part of the Intelligent Hub, reducing delays in the provisioning process.
- Applications can start installing sooner, accelerating time-to-productivity.
- Devices reach a usable state faster, enhancing the end-user experience.
Note: This feature requires Workspace ONE UEM version 2506 or later and Hub version 25.06.x.
Enhanced Offline Domain Join (ODJ) configuration
The Offline Domain Join (ODJ) configuration process has been significantly enhanced to improve reliability and flexibility, particularly in Autopilot Hybrid Join scenarios. Configuring Offline Domain Join is no longer tied to the device enrollment process. It can now be applied at any time, significantly reducing the risk of failures caused by race conditions or timeouts during Autopilot enrollments. With this update, ODJ can also be configured as a step within the Freestyle workflows, especially the new Onboarding workflows introduced recently, enabling IT teams to properly sequence and stage devices before they reach end users. This ensures a smoother onboarding experience and more consistent device readiness. For more information, see Offline Domain Join in Workflows.
Administrators can now deploy ODJ even after a device has been moved to a different Organizational Group (OG), including child OGs. Additionally, to maintain naming consistency, a device’s computer name will only change if it is not already joined to a domain.
Note: This feature requires Workspace ONE UEM version 2506 or later and Hub version 25.06.x.
Improvements in logging and troubleshooting
This release introduces several powerful enhancements to improve visibility, streamline troubleshooting, and reduce time-to-resolution for both end users and administrators.
-
Log submission from Intelligent Hub: Users can now send logs directly to Workspace ONE UEM from the Hub Support tab, with two new options added alongside the existing Collect Logs feature:
- Send Hub Logs to UEM: Automatically uploads all Intelligent Hub-related logs to the UEM console. Logs are accessible under Device Details > Attachments > Documents.
- Send Other Logs to UEM: Sends logs from DEEM, Workspace ONE Assist, and Workspace ONE Tunnel to the same location in the UEM console. Users receive a confirmation once the log upload is complete, improving transparency and support efficiency.
-
Application deployment event logging: To enhance visibility into application deployment, Intelligent Hub now sends detailed application deployment event summaries to the UEM console under Device Details > Troubleshooting > Event Logs.These event logs include data on detection statuses, Pre-condition checks, Exit codes and more helping administrators quickly identify the causes of application installation and uninstallation failures.
-
Filter logs by duration and component : Administrators can now filter collected logs based on timeframe and log source, making it easier to isolate relevant data during troubleshooting.
- Timeframe Filters: All logs, or logs from the last 1, 3, 7, or 14 days.
- Component Filters: Hub (Logs from Intelligent Hub, App Deployment Agent, Provisioning Agent, Factory Provisioning, and MDM), System (Windows and PCRefresh logs), Other (Logs from Assist, DEEM Telemetry Agent, and Workspace ONE Tunnel)
Note: This feature requires Workspace ONE UEM version 2506 or later and Hub version 25.06.x.
Enhanced processor architecture selection for app deployment
This new feature provides administrators with granular control over app distribution based on processor architecture. Previously, administrators could only select one option among 32-bit, 64-bit, and ARM64 as the 'Supported Processor Architecture' during app deployment. UEM will then determine the distribution to device architectures in the backend, limiting flexibility. Key capabilities include:
- Multi-Selection Option: Administrators can now select multiple processor architectures during app deployment. The available options include 32-bit, 64-bit, ARM32, and ARM64.
- Granular Control: This enhancement allows for more precise control over app distribution. For example,
- Distribute a 32-bit app 'X' to devices with 32-bit and 64-bit architectures only, excluding ARM64.
- Distribute a 64-bit app 'Y' to devices with 64-bit and ARM64 architectures, utilizing x64 emulation for compatibility.
Note: This feature requires Workspace ONE UEM version 2506 or later and Hub version 25.06.x.
Support for Administrative Template (ADMX) with profiles
With this Technical Preview feature, Workspace ONE UEM now supports Administrative Template (ADMX), providing a unified and scalable way to manage Windows policies across the device fleet. With this feature, you can manage all administrative templates for Windows 10, Windows 11, and Windows Server directly from the UEM console. You are provided with Pre-Uploaded ADMX templates for common applications, including those for Microsoft Office, Omnissa Horizon, Google Chrome, Mozilla Firefox, and more.
Note: Reapplying baselines will reset policies applied though the ADMX profiles. The capability for Baselines and ADMX profiles to coexist seamlessly will be introduced when this feature becomes Generally Available. If you currently have baselines configured, refrain from using this feature.
Windows Native Enrollment: Auto-Move Devices to Specified OG via Allowlist
Administrators can now assign a target Organisation Group (OG) while creating allowlist records for Windows devices. Upon enrollment, devices automatically move to the specified OG, streamlining device management without requiring prior user association. This feature is in Limited Availability for Windows Native enrollment (Out of Box Enrollment / OOBE and Autopilot). To enable this feature, reach out to your account team.
Resolved Issues
Admin Experience
-
FCA-205420: EnrollmentUserCredentials lookup value in message template generates message preview in bad formatting.
-
FCA-206116: Console events do not log some Admin Role Events.
-
FCA-207442: SSP testCookie is set while JavaScript implementation without explicitly defining the attributes.
-
FCA-207572: Device List View filter for internal storage does not display actions in the UI.
-
FCA-207745: UEM console sends email notifications for account modifications when the home button is pressed using the new deployment method.
-
FCA-207895: UEM console makes an incorrect request at landing page for the admin user who enables 2FA and configures landing page.
-
FCA-208029: EID Value and Phone Number are not getting populated for iPad devices.
-
FCA-208136: The API call "DeviceExtensiveSearchAsync" does not work properly with multiple filters.
-
FCA-208232: "POST /devices/gps/search" API call does not honour date ranges.
-
FCA-208380: Custom message template for Admin Activation is not getting selected correctly.
-
FCA-208389: Workspace ONE API request continuously fails with a 500 internal server error for mdm/devices/search endpoint.
-
FCA-208390: The "Apply" button on filters does not work when devices list is opened from Assignment Groups page.
-
FCA-208419: NetworkInfoSearch API is not using the steps that appear in the official documentation.
-
FCA-208708: Administrator Password Reset Email is not appearing as a customizable message template.
-
FCA-208958: A DOM-based cross-site scripting (XSS) in onmodalexit query parameter leads to full ATO/environment compromise.
-
FCA-209732: When hovering over devices from Device List View (Layout → Custom), a blinking popup makes it harder to use right-click options (UEM 2410).
-
FCA-209861: Admin Account Settings > Notifications does not show the "Maintenance and Upgrade" option when "AdminSaaSNotificationsDLManagementFeatureFlag" is enabled.
-
FCA-209869: 'Query Device' action is not working for a bulk selection of devices on the list view.
-
FCA-209873: Images vanish from custom message templates after they are saved.
-
FCA-209897: Filtering for 'Container' as a management mode is also returning 'Hub Registered' devices on the Device List View.
-
FCA-209901: Event log incorrectly displaying "sysadmin" as the admin when 'Find Device' action is performed on an Android device.
-
FCA-209920: Intelligent Hub is redirecting to the login screen when an admin updates the IP address, when user name by IP range is enabled.
-
FCA-209970: The Device List View OS version filter does not work for iOS devices.
-
FCA-210004: Bulk Action for 'Delete Device' results in a "Save Failed" error.
-
FCA-210023: Event data opens an error screen in the Device Details > Troubleshooting tab.
-
FCA-210177: Unable to reset the password of a basic admin account in UEM with MFA enabled.
-
FCA-210276: Admin role comparison does not work.
-
FCA-210331: UAT environments migrated to the new Access URLs without Access being ready for new Access endpoint URL usage.
-
FCA-210440: The /devices/extensivesearch API in MDM API V1 does not filter device records with MAC address.
Android Management
-
AGGL-17018: CICO with Launcher Apps are not always removed when combined with App assignments.
-
AGGL-17044: Android devices are intermittently not added to Smart Groups that filter by manufacturer and model.
-
AGGL-17096: "IsEncrypted" API call for Android is not working.
-
AGGL-17113: VPN profile URL whitelist does not get applied through profile UI.
-
AGGL-17115: Application configuration shows inconsistent behavior for Check-in and Check Out users on Android devices.
-
AGGL-17575: Android Credentials profile becomes corrupted when adding a version if "Allow silent app access" is enabled.
-
AGGL-17940: Android apps are removed from devices when renamed by administrator.
-
AGGL-18098: When rebooting devices from UEM Console, an incorrect warning message appears.
-
AGGL-18123: Workspace ONE UEM may fail to configure per-app VPN with Tunnel for Android devices.
-
AGGL-18137: Android Enterprise Factory Reset Protection profile is not prompting option to remove FRP prior to wiping device.
-
AGGL-18264: Android Legacy profiles are incorrectly installing on Android Enterprise devices.
-
AGGL-18400: Last Reboot is not reported or is reported inaccurately in UEM console.
-
AGGL-18561: Unable to Override Privacy Settings.
Assist
- AET-18974: Assist Chat features are not visible when the Session is launched from RemoteManagementV1/V2 Controller MDM API.
Core Platform
-
CRSVC-50701: Enhanced logging functionality now obfuscates full API key entries.
-
CRSVC-51190: The targeted logging test fails with an error even after it is re-enabled with the right password and later disabled it.
-
CRSVC-53629: Resource delivery is blocked by Compliance Policy with Enterprise Wipe action.
-
CRSVC-57801: Compliance policy evaluation has been enhanced to immediately reflect updates to policy rules.
-
CRSVC-58522: Failed to fetch metadata from the server for workflows, causing delays in resources delivery.
-
CRSVC-60875: Device Wipe Log does not load successfully.
-
CRSVC-62002: Attempts to enable device-based targeted logging are failing.
-
CRSVC-62148: Administrator at a child OG is unable to re-evaluate Compliance Policies managed by a parent OG.
-
CRSVC-62531: Workspace ONE DB upgrade maintenance schema conflict resulting in job failure.
-
CRSVC-62714: Cross-tenant IDOR allows uploading the MIME Sign-in certificate not belonging to the tenant for an iOS exchange resource.
-
CRSVC-62832: 'ConnectSync' webhook event is not showing on UEM console under Event notifications list.
Enrollment
- ENRL-4305: enrollment blocked by server timeout in customer's OGs in UEM console.
Enrollment and Service Integrations
-
ESI-103: Tags are not getting assigned for devices being enrolled through Dropship Provisioning.
-
ESI-554: Registered device records have incorrect user info link.
Freestyle Orchestrator
-
FS-5588: Workflows install retired app version.
-
FS-5716: Windows application installation fails with an error.
-
FS-6560: 'Failed' sensor status incorrectly parsed by workflow as 'condition not met'.
-
FS-7790: Workflow completion rate drastically dropped upon update.
iOS Management
-
AAPP-17070: In an iOS desktop device profile with DDUI, aw-tag for Allow Find My Device is incorrectly located.
-
AAPP-17815: Custom Command shows 'Pending' under the Troubleshooting tab in Device Details.
-
AAPP-17981: Notifications are not sent upon successful installation of iOS update.
-
AAPP-18028: ABM resources don't get installed upon enrollment.
-
AAPP-18183: Personal or User-installed apps display in console even though privacy settings aren't enabled for it.
-
AAPP-18397: DEP Await Configuration ends prematurely before the device is fully configured.
-
AAPP-18577: Per App rules for iOS VPN profile are enabled by default when adding a new version of the profile.
-
AAPP-18578: Schedule OS Update commands in queueing state are not removed when the device is excluded from the Smart Group.
-
AAPP-18601: Unable to edit iOS profiles.
-
AAPP-18837: Supervised iOS devices cannot be deleted.
-
AAPP-18840: The count of 'Not encrypted devices' is not matching in the Device Dashboard and Device list view pages.
-
AAPP-18864: Repeated UserList sample processing leads to DB CPU spike.
-
AAPP-18868: Enhanced Single App Mode to Address Support for native Apple Applications.
-
AAPP-18903: App installation fails when VPP licenses request is not confirmed as complete.
-
AAPP-19172: Cannot update iOS Devices due to page not found error.
-
AAPP-19307: Unable to enroll the iOS 18.5 devices when enrollment restriction policy is set to iOS 18.4.1.
-
AAPP-19353: When trying to manually trigger an installation as a UEM admin for select vpp applications, you get a "access denied" gray banner.
Launcher
-
LAUN-21: Customize Single App Floating Button should not be displayed when profile type is multi-app or template.
-
LAUN-22: Launcher layout page is not scrollable when many apps are added.
-
LAUN-54: Adding apps to an existing Launcher profile under Products fails.
-
LAUN-58: Globalization Failure on Latest Canonical.
-
LAUN-61: Editing attributes of an app on the Launcher profile canvas allows changing the application ID to an already existing different app bundle ID.
-
LAUN-63: Web Links with the same name prevent Android Enterprise Launcher canvas from changing and saving the proper link.
macOS Management
-
MACOS-5322: macOS devices are not completing enrollment as expected and get stuck on "waiting for management" server while DEP enrollment.
-
MACOS-5408: Disk encryption profiles are incorrectly delivered to excluded devices.
-
MACOS-5594: Privacy preferences profile fails to install on macOS devices.
-
MACOS-5817: Re-enrolled macOS device is not installing profiles unless device record is deleted prior to re-enroll.
Resource Management
-
ARES-28988: Application's User Ratings list cannot be exported by a UEM admin.
-
ARES-29119: Application_UUID is missing in response of GET API mdm/devices/{deviceUuid}/apps/search for Windows and Mac devices.
-
ARES-29230: Alert to 'Leave' or 'Cancel' configuration is received when adding criteria under 'When to Call Install Complete' in Deployment Options for Windows apps.
-
ARES-29493: BIOS Password Profiles are not applied to devices when deployed via workflows.
-
ARES-29876: Getting "page not found" error, when you click Query button at Resources > Apps > Internal > 3CX Desktop App > Devices.
-
ARES-29939: Unable to save the iOS Boxer application configuration when the 'Enable FastSync' App Policy is applied.
-
ARES-30062: Exporting the list of evaluated devices from an Application's Deployment Tracking page results in a failed export.
-
ARES-30074: A Spaceman error occurs while searching for a number on Profile List View page.
-
ARES-30565: 'Setting Group' sub-filter within 'Platform' filter on Profile List View page does not filter the profiles.
-
ARES-30844: Filtering devices by installation status details or last action fails on the Internal App Deployment Tracking page.
-
ARES-30919: Profile not being removed from device when 'Remove' action is performed from Device Details Profiles tab.
-
ARES-30935: Admin is unable to view iOS profiles if any of their payload values have white spaces.
-
ARES-30970: For some profiles, unassigned smart groups are still visible under 'Assignment Groups' column on Profile List View.
-
ARES-31047: Launcher Profile configured with Custom Lookup fields fails to install on devices.
-
ARES-31178: 'Installed but not assigned' status is incorrectly highlighted in red for seeded apps like Launcher on Device Details Apps summary page.
-
ARES-31350: Deleting a child OG crashes Profile List View of parent OG if a Smart Group of child OG was assigned to a profile existing at Parent OG.
-
ARES-31581: 'Distribution' tab on Windows Internal app Assignment page is missing several options when editing assignments from Deployment Tracking page.
-
ARES-31813: Saving SDK profile shows error has occurred but entered details are still present when the profile is opened for viewing.
-
ARES-32056: Opening or editing Android Enterprise profiles displays error if DDUI is enabled in the UEM environment.
-
ARES-32065: Incorrect total profile count is sometimes displayed on the Device Profiles list.
-
ARES-32251: Profiles on Device Details Profiles tab are listed in reverse alphabetical order.
-
ARES-32296: Unable to apply Dependency App filter for Windows Internal apps on Internal App List View page.
-
ARES-32356: While publishing a VPP app, device preview page displayed 'Added' devices even when no changes are made to the assignment.
-
ARES-32372: Inactive profiles are sometimes not visible on Profile List view.
-
ARES-32380: Admin at child OG receives a 'Door Locked' error while accessing Deployment Tracking page of an app added at parent OG.
-
ARES-32467: 'View' instead of 'Assign' displayed against internal app versions on App List View even when no direct or workflow assignments exist.
-
ARES-32641: When trying to delete the profiles, it gives a 'Door Locked' error.
-
ARES-32708: A few profiles are not visible on Device Profiles list in Partner enabled UEM environments.
-
ARES-32733: Force removal of Internal app from Device Apps list sometimes gives 'Door Locked' error.
-
ARES-32773: A duplicate entry is sometimes present on Device Apps list with status as Installed but not assigned for app installed via Workflow.
-
ARES-32924: Sometimes, assigned apps are not visible in Intelligent Hub app catalog.
-
ARES-33156: An error is displayed when editing profiles that have excluded Smart Groups but no assigned Smart Groups.
Rugged Device Management
-
RUGG-13452: Pull service configuration file fails to download in OGs with trailing spaces in the OG name.
-
RUGG-13523: Zebra printer enrollment does not honor SiteURL overridden on child organization groups and uses values at Global.
Tunnel
- PPAT-17434: Tunnel client not reconnecting once device regains compliance.
User Management
-
UM-9541: Cross-tenant IDOR allows viewing email message templates that do not belong to us.
-
UM-9640: Unable to add devices on Productivity Organization Group.
Windows Management
-
AMST-41583: Compliance status for firewall does not show correctly at the start of device.
-
AMST-41874: Unable to delete an OG, getting an error "Save Failed Delete Failed".
-
AMST-41960: Application installation status is not reported correctly on UEM.
-
AMST-42059: Firewall Profile fails to install on Windows 11 systems.
-
AMST-42286: EAR update notifications are not working.
-
AMST-42316: Device unassigned from SG still shows Sensor data for the excluded devices.
-
AMST-42458: Certificate profiles are not installing with optional assignment while leveraging the Modern SaaS Architecture.
-
AMST-42513: Shared Device Log page does not show correct count and page numbers.
-
AMST-42613: ARM64 OOBE enrolled Windows devices stuck in Pending Hub state.
-
AMST-42648: Devices getting enrolled with Container type management.
-
AMST-42717: PPKG disappear in UEM but shows in DB.
-
AMST-42753: API/system/users/delete fails with 500 error if action exceeds 30 sec timeframe for completion.
-
AMST-42758: Friendly name is not updated when Windows staging enrolled device is checked out by a designate user.
-
AMST-42785: The Compromised Status shows as unknown after Modstack.
-
AMST-42826: Windows device does not check in after receiving WNS notification.
-
AMST-42846: Smart Group device count is not updated until the Smart Group is re-saved manually.
-
AMST-42971: ARM64 devices are unable to use Registry detection criteria.
-
AMST-42987: AirWatch CA certificate is not getting installed with manual push of the SCEP profile.
-
AMST-43082: AppX app deployment is not working after Hub and SFD were upgraded in UEM 24.2.0.18.
-
AMST-43251: Certificates are retained on devices after profile removal.
-
AMST-43407: Admin account stuck in DELETE IN PROGRESS state when trying to remove the admin.
-
AMST-42629: Windows scripts are not visible in the lookup value to run in Intelligence.
Patch Resolved Issues
Patch 1
-
UM-9814: Checkout for a basic user fails on an Android shared device.
-
UM-9813: Basic user authentication fails at a child OG with Omnissa Identity Services integration.
-
MACOS-5941: Editing a Declarative Profile from the profile list view fails.
-
FS-7926: Freestyle Orchestrator Application Version Exist Condition Fails with UI Error.
-
CRSVC-62849: Not all installed applications are visible in the preview report when filters are applied.
-
CRSVC-59993: Delete Certificate API does not consider reference of certificate in profile.
-
AMST-44005: Introduced API to enable updating LaunchCommand for existing apps.
-
AAPP-19505: Profile samples fails to update when queried on macOS devices.
-
RUGG-13687: Device Details page crashes when a device has a profile product with regular and force-reprocessed job.
-
ARES-33610: Assignment and installation data misreported for devices assigned to Internal app versions with exclusions.
-
ARES-32051: Device Profile list not updated when user checks out a Windows device.
Patch 2
-
UM-9806: Permissions cannot be deleted for user groups with app, profile assignments or policy mapping for enrollment grouping, restrictions, and user roles.
-
RUGG-13652: Apps and Profiles counts in Device Details Summary tab should consider unassigned resources and apps should move to Installed once it is reassigned.
-
MACOS-5913: Adding the rebranded bundle-id of Hubd process to Intelligent Hub settings profile.
-
MACOS-5768: macOS SSOExtension profile failing due to incorrect use of UseSharedDeviceKeys.
-
MACOS-5574: Modify XML to allow base 64 encoded data for a valid font and perform E2E testing on iOS and macOS device.
-
MACOS-4581: Extensible Single Sign-on Kerberos payload updates.
-
FCA-210742: Errors while navigating to different pages in the UEM console.
-
ESI-608: Staging User unable to enroll an Android device registered to an end user in Registered Devices Only mode.
-
ESI-549: Launcher CICO fails when enrollment restriction for device model is present, despite device being in allowlist.
-
ATL-25652: Seeding - latest SFD 24.10.7 build to UEM 2506.
-
AMST-43813: Validate the profile XML for custom settings before delivering the XML to the device.
-
AGGL-19047: Denied application names and IDs in app control are not resolved to actual values when viewed in XML.
-
AGGL-18988: Certificate profiles are installed twice after Android device enrollment when a compliance policy is assigned.
-
AGGL-18954: Profile installation and removal intermittently fails on shared iPads.
-
AGGL-18884: Credential payload upload certificate failing for ChromeOS.
-
AGGL-18821: PhoneNumber Lookup returns blank when used in App Configuration.
-
AGGL-17263: Denied application names and IDs in app control are not resolved to actual values when viewed in XML.
-
AAPP-19722: VPP License sync error for some applications in the console.
-
AAPP-19394: Readability updates to iOS Device Updates Details page .
-
AAPP-19271: Custom DEP now supports min OS version enforcement.
-
ARES-33458: Multiple version-level entries displayed for an Internal app on Windows Device App list.
-
AGGL-18692: Profile installation and removal intermittently fails on shared iPads.
Patch 3
-
UM-10016: Enrollment authentication failure when using OIS with Source of Authentication set to Workspace ONE Access.
-
FS-8210: Purchased apps option showing in list when creating Install App action.
-
FCA-210730: API mdm/devices/search should not throw 404 if some of the devices are not found.
-
ATL-25833: Seeded Windows Intelligent Hub v25.06 in this patch.
-
ATL-25812: Seeded Software Distribution agent 25.06 in this patch.
-
AMST-44237: Due to overlapping conflict resolution group key with MTD resource, ODJ ES rule migration is failing in some cases.
-
AAPP-19398: Mismatch between Total Eligible Devices and Device Status charts when reviewing iOS OS Update Details.
-
AAPP-12092: iOS - AirPrint missing keys.
-
AAPP-12090: iOS - Google Account missing keys.
-
AAPP-19836: Apple DDM GitHub integration GA.
Patch 4
-
RUGG-13736: Staging manifest is not pushed and Stagenow Barcode enrollment fails with discovery error.
-
RUGG-13708: Staging manifest is not pushed and QR enrollment fails with discovery error.
-
ATL-26006: Seed Windows Hub 25.06.1 x86 and ARM64 MSI to UEM 2506.
-
AGGL-19016: IMEI is not seen in the Device List View for some of the Android devices.
-
AAPP-19738: Extend 'Release Device' permission to Console Admin and Airwatch Admin UEM roles.
-
AAPP-19393: iOS Device Updates Details page update-status grid filters are not functioning as expected.
Patch 5
-
UM-10014: Performance issues when trying to export User List.
-
FCA-210686: Unable to search devices by IP Address in list view for Modstack-enabled environments.
-
ESI-614: Device enrollment fails via SAML when user's enrollment OG is changed from parent to sub-OG.
-
CRSVC-63879: Improve Certificate Templates OID/SAN SID Mapping to support Lookup and Static entries.
-
ATL-26181: Seeded Workspace ONE Intelligent Hub v25.06.2 for Windows.
-
ARES-33952: Incorrect total profile count shown in device's profile list when page size is smaller than total records.
-
ARES-33410: Keep App Updated Automatically setting missing when assigning Windows Internal app from Deployment Tracking page in Modstack-enabled environments.
-
ARES-33301: App scheduled for future deployment installs immediately in Modstack-enabled environments.
-
AMST-44408: Added look up support for {ComputerSID} in lookup value service.
-
AMST-44340: (BitLocker profiles) Added support to enforce key protectors only for configured keys.
-
AMST-44046: Fixed issue with Device Root certificate reapply not working as expected.
-
AAPP-19306: Cannot edit a profile with Exchange ActiveSync payload.
Patch 6
-
ARES-34443: Admin occasionally unable to save assignments for Android Internal Apps.
-
ARES-33371: Device preview displays incorrect counts while updating assignments of Purchased apps supporting multiple platforms.
-
UM-10083: Duplicate user groups shown in UI and usergroup/search API when the group has multiple enrollment organization group mappings.
-
MACOS-6415: Failures when attempting to save Declarative LDAP profiles.
-
MACOS-6249: Support for Audio Accessory & Safari Settings Declarative configurations introduced in Apple OS 26.
-
MACOS-6132: Support for Custom Regex in Declarative Passcode configuration.
-
MACOS-6092: UI bug fixes in rendering Declarative configuration keys.
-
ESI-603: Deleting Device on Self Service portal shows error message.
-
CRSVC-64211: Reset the reprocess interval with a "re-sync" for CICO scenario so that device is brought to the desired state.
-
AGGL-18822: Intermittent delay in syncing profiles and apps for shared devices on CICO.
-
AAPP-19829: Shared iPads for Business experience delays in resource delivery when switching users.
-
AAPP-19530: Support for new Setup Assistant (Skip) Keys introduced in Apple OS 26.
-
AAPP-19528: Support for new VPN keys introduced in Apple OS 26.
-
AAPP-19526: Support for new Managed Relay & Restrictions keys introduced in Apple OS 26.
-
AAPP-19523: Support for new Extensible SSO keys introduced in Apple OS 26.
-
AAPP-19472: Incorrect XML generated for Web Clip payload.
Patch 7
-
INTEL-67893: Mismatch in iOS device count between UEM and Intelligence.
-
ESI-563: Devices were not being assigned the correct Ownership Type.
-
CRSVC-63331: Device List for staging users not showing the correct number of devices associated to that user
-
ARES-33742: Highest app version per OG was not returned when 'distinctApplicationsPerOg' is True in App Search API /apps/search.
-
AMST-44530: Workgroup configuration update was causing ES rule creation failure.
-
AGGL-19217: Multiple certificates were generated for iOS devices when the device was in Locked state.
Patch 8
-
CRSVC-66560: Application is getting removed and workflow fails when running again.
-
CRSVC-66340: Changes observed on the Account Name in UI for the event records when reading from ELS.
-
CRSVC-66290: Discrepancies in Change Event Sequence table.
-
CRSVC-65652: Fanout Issues: Tenant deletion in UEM resulted in emitting events with incorrect data.
-
CRSVC-64298: Ensure Name is present for all network adapters.
-
CRSVC-62771: Optimize the certificate renewal workflow to avoid unintended queuing of Windows profiles on macOS devices.
-
CRSVC-62638: Search based on Device Model is not working for Windows devices.
-
ATL-26293: Seeding SFD 25.06.1 build to UEM 2506 patch release.
-
ARES-34857: 'Failed to save profile' error sometimes received while publishing a profile whose payload have not been updated.
-
AMST-44608: Clearing existing commands during enrollment is throwing exception.
-
AMST-44461: Fix MSIX uninstallation.
-
AMST-44455: Sample Save failure at DiskEncryptionV3SampleProcessor.
-
AMST-44176: Intel vPro- Fixed Power Actions to now show up on all environments regardless of the SKU purchased.
-
AMST-43994: Unable to edit SSID for when a WIFI profile is copied for Windows Device.
-
AMST-43968: Internal application can be saved without selecting the (supported architecture) required field.
-
AGGL-19053: FRP remove profile command not received in case Mod Stack enabled environments when Admin does Device Wipe.
-
AGGL-17150: Internal apps stop installing automatically after configuring app control profile and Allow list app group.
-
AAPP-19524: Support for new Parental Controls->Content Filter keys introduced in Apple OS 26.
-
AAPP-19168: Profile Home Screen Layout payloads are not saving.
-
AAPP-18853: Support for new iOS 18.4 and macOS 15.4 Setup Assistant (Skip) Keys.
-
MACOS-6449: Resolve DDM profile read issue with declarations having multiple versions.
-
MACOS-6421: Support for Safari Extensions Declarative configuration.
-
MACOS-6015: OGs cannot inherit Intelligent Hub settings.
Patch 9
-
PRNT-71: Files and profiles no longer reporting accurately on Zebra printers following 24.10 upgrade.
-
PPAT-20208: Unable to install VPN profile on both iOS and Android devices.
-
MACOS-4996: Removing assignment from credential profile is not moving certificate to revoked state.
-
MACOS-4472: macOS Install Fonts profile has incorrect setting "FontName" in the xml sent to the device.
-
FCA-211051 - Configure admin roles with Read-Only access to All Settings.
-
FS-8296: Scripts wrongly displayed under Devices -> Workflow tab.
-
ESI-727: Tags are not getting applied to devices as part of Drop Ship Provisioning enrollment.
-
CRSVC-64367: Customer has a compliance policy wherein if the device is not encrypted then a push notification is sent, vpn profile is blocked, and a compliance profile for encryption is pushed. original compliance policy.png is attached.
-
CRSVC-64700: Updated DigiCert profile fetch API to version 3.
-
ATL-26539: Seed: Machost to canonical release PR2506-Patch9.
-
ARES-33719: Profile publish fails when 'Next' button is clicked repeatedly on payload page.
-
AMST-44769: Windows Autopilot Enrollment stuck at OOBE "Setting up Work or School" screen in CN70 environment post Patch 24 upgrade.
-
AMST-44665: SFD not getting automatically upgraded when WindowsAgentAutoUpgrade is not enabled.
-
AGGL-19201: Patching AMAPI device policy fails when passcode profile uses L/M/H Complexity.
-
AAPP-20057: UK users are unable to enroll their devices and are receiving the error 403.
-
AAPP-18714: Some Internal and Purchased iOS apps fail with error 12008 MDM Command invalid.
Patch 10
-
UM-10250: User Groups List View does not load results beyond selected page size.
-
RUGG-13784: Product Wi-Fi Profile Domain doesn't accept URL and IP.
-
RUGG-13738: App incorrectly shown as Installed in Apps tab even when installation via Product fails.
-
FS-8432: Workflow steps getting stuck on macOS after an upgrade.
-
FCA-211627: Some screens under All Settings cannot be accessed.
-
FCA-211402: SmartGroup filter in the Device List View shows incorrect list of devices for groups with enrollment category including "Apple - Supervised".
-
ESI-775: Staging user enrollment failing for multiple platforms.
-
ESI-711: "Registration" page title changes to "Enrollment Status" after performing action.
-
CRSVC-66301: Internal app install for some iOS devices is showing an error of "App Install Blocked".
-
CMSVC-20517: Error occurs while creating OAuth token in Partner OG.
-
ATL-26606: Seed Machost v2506.3430 to 2506 patch release.
-
ATL-26548: Seeding SFD 25.6.2 build to UEM 2506 patch release.
-
AGGL-19351: Android PRM Check-in flow to reset Force Sync immediately after the first attempt.
-
AGGL-19177: SAN Values are Duplicated when sending a SCEP profile to Android devices.
-
AAPP-19035: iOS 18.4 and macOS 15.4 Restriction - SSO Extension, VPN and Relay, XSAN.
-
AAPP-16990: Improve purchased application delete flow.
Patch 11
-
AAPP-18402: Support for missing keys in Cellular profile payload for iOS.
-
AAPP-20263: Additional enhancement to prevent resource delivery delays when switching users on Shared iPads for Business.
-
AAPP-20371: Support for iOS 18.4 and macOS 15.4 Restriction and Setup Assistant (Skip) keys in profiles.
-
AGGL-17372: Throttle SCEP payload creations based on existing throttle limits.
-
AMST-45025: "Device Re-assignment Failed" error prompt shown when logon using different user on Windows Machine.
-
AMST-44217: Deleted OGs still exist within the UI.
-
ARES-31936: Profile does not get installed on devices with 'Auto' direct assignment unless the On-demand workflow is manually triggered.
-
ARES-33173: Spaceman error displayed upon clicking 'View' on Profile List.
-
ARES-33466: Existing assignments displayed as 'Added' in assignment preview while republishing Web Link.
-
ARES-34536: Trusted Credentials setting under Wifi payload cannot be saved in DDUI Profiles.
-
ATL-26794: Seed Workspace ONE Intelligent Hub v25.06.4 for Windows.
-
CRSVC-66526: Empty application names resulting in application event data being dropped.
-
FCA-210682: Custom message templates in deprecated languages cannot be edited.
-
FCA-210698: Incorrect exception seen when API returns a 400 Bad Request for some scenarios.
-
FS-7867 : App Removal log missing.
-
LAUN-66: ForYouWidget functionality using UEM UI was not working as expected.
Patch 12
- FCA-211779: Bulk Actions are incorrectly applied when 'Last Seen' filter is used in the Device List View in environments where CP version and UEM version are different.
Patch 13
-
RUGG-13807: Device level update status for Custom Update is not syncing after update is marked Completed.
-
FS-8083: Time executed and time reported columns in the wrong format.
-
FS-7918: Apps installed prior to enrollment and assigned to a workflow won't show steps as completed.
-
FCA-211788: Upgrades to multiple JavaScript libraries to avoid potential cross-site scripting vulnerabilities.
-
ATL-26930: Seed - Machost to canonical release PR2506-13.
-
ARES-35315: Apps delivered through Product Provisioning removed from devices when they lose assignment.
-
ARES-35213: Profile of another tenant sometimes displayed on Device Profile list.
-
ARES-33477: A few profiles unintentionally installed on Smart Groups if it was previously assigned to it via a now-deleted Workflow.
-
AAPP-20600: Device Updates page failing to load new versions (iOS/macOS).
-
AAPP-20019: 500 Error on Purchased App API Endpoint (/mam/apps/purchased/search).
-
AAPP-19871: VPP Apps Not Uninstalled When Switching from Staging to End User on iOS Devices.
-
AAPP-19508: DEP devices could be enrolled by users other than the assigned user.
-
INTEL-73644: Data discrepancy observed while creating report in Workspace ONE Intelligence.
Patch 14
- ESI-834: Azure AD token not revoked when device is unenrolled or wiped.
Patch 15
-
CRSVC-68364: Handling actions when device is in NotNow state (iOS/Mac).
-
ARES-34933: "An error has occurred" sometimes appears while performing actions related to apps and profiles.
-
AAPP-20440: Add telemetry to identify the source of message in queue.
Patch 16
-
FS-8831: Enhanced error handling for socket exceptions to prevent silent failures during script execution.
-
FS-8564: Scripts unable to execute due to an unexpected reboot causing a corrupted DB on macOS devices.
-
FCA-211751: OG filters applied in the Device List View are not applied when Exported.
-
FCA-211387: Admin password reset emails are not sent.
-
FCA-211339: Update mdm/device/search v2 API to report PhysicalMemory in Bytes.
-
ESI-728: Launcher stuck in login loop if "Always prompt for terms of use" is enabled.
-
CRSVC-70627: Tunnel App Showing Access Denied Until Reinstalled.
-
CRSVC-55456: Certificate list api and UI are showing incorrect number of certificates.
-
ATL-27195: Seed latest Machost to 2506.
-
ATL-27069: Seed Workspace ONE Intelligent Hub v25.06.5 for Windows.
-
ARES-35269: Error occurs intermittently while viewing Profile List View.
-
ARES-34142: Remove last evaluation dependency and apply changes to retain Deployment Tracking metrics.
-
AGGL-19412: Outdated settings shown when viewing ChromeOS Credentials Profiles.
-
AGGL-17740: App configuration, App policy, and per-app VPN settings unexpectedly removed from AMAPI devices.
-
AAPP-20593: Fix SKU mapping for Device Attestation & Release Device from ABM.
-
AAPP-20215: Delay in VPP app installation across large iOS device fleet.
-
AAPP-20207: VPP application versions are not updating in the Console when the country code is non English.
-
AAPP-20016: Apple TV - VPP License is not revoked after removing app from device details page.
-
AAPP-20207: VPP application versions are not updating in the Console when the country code is non English.
-
AAPP-19826: VPP Sync application improvements.
-
AAPP-19620: Unable to install/upgrade VPP apps on selected devices using 'Install on Selected' option.
Patch 17
-
UM-10252: Clear & Save actions are failing for 'Service Provider (AirWatch) Certificate' and 'Identity Provider Certificate'.
-
RUGG-13821: Large file uploads to push relay servers intermittently fail when the FTP servers are operating on slow network connections.
-
MACOS-6589: New versions of native Mac app uploads improperly handling rebranded (com.ws1) Bundle ID.
-
FS-8580: Workflow fails on macOS 26 RC 1 devices due to step timeout persisting after completion.
-
FCA-211628: EventLogSyncFailure settings are not seen in Manage Account Settings.
-
ESI-825: MTD Activation through Smart Groups fail when deployed from Partner tenant.
-
CMCM-191640: Admin repo empty after clicking on 'sign-in' in Content app.
-
CMCM-191535: Unable to access network shares on Content app post UEM upgrade to 24.10.
-
ATL-27264: Seed - Machost v2506.4931 to Workspace ONE UEM 2506.
-
ARES-35595: Apps cannot be sorted on App Group app list view.
-
ARES-34661: Removing Smart Group from profile assignments may remove profile from other assigned Smart Groups.
-
AMST-44776: Removed approved updates Sampling Logic to avoid delays in DM Resource Processing.
-
AMST-44611: Fixed issue with Workspace ONE Intelligence not pulling through Sensor data for Customer OGs created under a Partner OG.
-
AGGL-19570: Per-app VPN settings not working when VPN profile includes additional payloads.
-
AAPP-20322: iOS Device Updates details page update status grid filters are not functioning as expected.
-
AAPP-20171: The tag of the new iOS 18.4 restriction keys do not show that the device needs to be supervised.
-
AAPP-20151: Improvements in VPP license sync logic.
-
AAPP-19914: Workspace ONE UEM Console inherit setting blocked for Apple > SCEP.
-
RUGG-13731: Repeated Product Delivery and Device Reboots When Reboot Manifest Is Used With Other Actions.
Patch 18
-
RUGG-13770: Custom update creation is limited to loading a maximum of 10 policies.
-
FCA-209987: [UI] Getting Started is appearing as a menu item even when it is disabled.
-
ESI-644: Android devices enroll without a registration record.
-
CRSVC-71133: Resolved scenario where profiles using SCEP certificates may not install correctly for newly enrolled macOS devices.
-
CRSVC-66851: Resolved scenario where devices intermittently are added to compliance target despite not being in assignment group.
-
ATL-27295: Seed Workspace ONE Intelligent Hub v25.06.6 for Windows.
-
ARES-34956: Validity settings unintentionally copied across different credential sets while configuring Credentials profile.
-
ARES-34842: Error occurs while editing iOS Lock Screen Message profile.
-
ARES-34502: Error 'Something unexpected happened' received while exporting App log.
-
ARES-34450: Installation Status Last Scan on Device App list sometimes displays future time.
-
ARES-34394: Administrator is incorrectly reported in the troubleshooting log for events arising from a tag change.
-
ARES-34947: Certificate data is incorrectly cross utilized while creating a macOS Credentials profile.
-
ARES-34117: Deleting Product provisioned app via API uninstalls it from devices.
-
AMST-45464: Main - DropshipProvisioning- Backport Dropship items.
-
AMST-45408: Windows Device Reassignment is failing with HybridAD setup.
-
AMST-45190: Handle Device Reassignment failures with internal server error.
-
AMST-44447: Unable to delete the ODJ cache server.
-
AMST-44385: App removal failing instantly for a Windows internal application.
-
AMST-43680: Message body is not displaying in notification when push notification is sent through UEM console.
-
AGGL-19219: UEM does not have enterprise version listed in Android Device Summary.
-
AGGL-19140: Maintenance Window is pushed when Public App Auto Update Policy is "Never".
-
AGGL-19057: Removing Launcher app from device is not allowed.
-
AGGL-18782: Vendor keys not deploying to Pulse Secure on Android when a profile is used.
-
AAPP-20421: 500 Error on Purchased App API Endpoint (/mam/apps/purchased/search).
-
AAPP-19962: VPP V2 - Unenrollment of the primary device of a Shared User Based License is not working as expected.
-
AAPP-18838: Improvements in Apple Declarative Device Management troubleshooting log entries.
-
ARES-34956: Static Certificate upload in Credential Slot 3 causes mirroring of Certificate Data from Slot 1.
Patch 19
-
SINST-176707: Corrected a condition in which the updated ACC Installation Directory was not honored.
-
FCA-211185: Cookie Usage page throws a locked door error on first load.
-
ATL-27459: Seed Workspace ONE Intelligent Hub v25.06.7 for Windows.
-
ARES-36022: Save Failed error when trying to publish an app assignment with the App Config included.
-
ARES-33310: Loading indicator remains visible in the Payloads view when attempting to edit and publish profiles.
-
AMST-44772: Higher level OG assigned domain join config not found at lower OG.
-
AMST-44018: Network tab for Windows devices shows a random IP address for LAN.
-
AET-20109: Expanded Unattended Access Support with Assist Configurations for Windows.
Patch 20
-
PPAT-20873: Tunnel Admin role restrictions are not enforced.
-
LUEM-1060: Intel WF that installs profiles on devices does not work.
-
FS-8071: Fixed an issue where macOS workflows remain stuck in progress if there are deleted workflows on the device.
-
ESI-892: Possible gaps in Enrollment Status writes to DST.
-
CRSVC-71542: Compliance actions are not reverted after concurrency exception.
-
CRSVC-70502: Fix read readiness flag caching and no tenant enablements.
-
CRSVC-70337: Improved logic for device command queue stored procedure related to application removal protection.
-
CRSVC-68243: Certificate Profile option in Certificate Template does not retain setting after it is saved and reopened.
-
AAPP-20276: Support for new Web Content Filter keys introduced in Apple OS 26.
-
AAPP-20190: Incorrect calculation of allocated and redeemed VPP counts, resulting in a negative unallocated count.
Patch 21
-
RUGG-13935: Eligibility status of some devices are not getting updated after Zebra enrollment.
-
RUGG-13748: Force Reprocess for any product set from device details page fails with page not found error.
-
ESI-888: Asset number not preserved after enrollment.
-
CRSVC-70831: Old GoogleDeviceID is not set to Unmanaged when a new GoogleDeviceID is reported by the device.
-
ATL-27819: Seeding SFD 25.6.3 build to UEM 2506 patch release.
-
AMST-45176: Add Windows 11 version 25H2 to the Windows Update Dashboard.
-
AMST-45113: ADMX Profiles - List elements are not applied on the device.
-
AMST-44011: Unable to access Enrollment Restrictions at a particular OG due to duplicate restrictions.
-
AAPP-20775: Proper IMEI/MEID/Phone Number reporting for iOS 26+.
Patch 22
-
SINST-176738: Certificate installer crashes during application deployment when windows authentication is used.
-
ATL-28104: Seed - Machost to canonical release 2506.
-
ATL-27956: Seed Workspace ONE Intelligent Hub v25.06.8 for Windows to UEM 2506.
-
AMST-46253: Verify whether conflicting systemcodeIDs in 24.10 can cause issues during upgrade.
-
AGGL-20108: Chrome OS - Certificate Removal Issues (Canonical Side).
-
AGGL-20047: ChromeOS certificates not installed if device is powerwashed and immediately re-enrolled.
-
AGGL-19967: UEM re-pushes ChromeOS certificates each time user logs in.
-
AGGL-19954: UEM repeatedly installs certificates on ChromeOS devices.
-
AGGL-19947: ChromeOS Credentials profiles stuck in pending status.
-
AGGL-19913: ChromeOS certificates are not installed on re-enrolled devices.
-
AAPP-21374: Enable Apple VPP V2 API.
Patch 23
-
FCA-212168: Help page displayed instead of assignment list on Sensors and Scripts workflow assignment tab.
-
FCA-212071: Settings export displays NULL for some settings that have valid values configured in the UEM console.
-
ESI-998: Omni is unable to access the Intelligence console and provides incorrect query AI responses.
-
CTRLP-13184: Secret rotation for CP services (Hashi components + CP Core services).
-
CRSVC-72697: Bypass list not honored in Console proxy settings.
-
CRSVC-71256: Compliance notifications over SMS are not delivered in some environments.
-
CRSVC-68230: Profiles installed via Workflow incorrectly show "Installed but not Assigned" status in the Device Details Profiles tab.
-
CRSVC-65481: Installed app version missing under 'Apps Status' column on Device Details Apps tab for public apps.
-
AGGL-20113: Deprovisioned ChromeOS devices can still check in and get certificates.
-
AAPP-20699: Update DDUI Profiles with new Skip & Restriction Keys.
-
AAPP-20461: Add support for new Skip/Setup Assistant Keys in ADE profile: Camera Control, Keyboard, Dictation, Age Assurance, Age Based Safety Settings.
Patch 24
- FCA-212970: Bulk actions are incorrectly processed on all devices when using “Select All” or multi‑page device selections with OG filters.
Patch 25
-
CRSVC-75705: Conditional Access registration and status updates may not be sent when Partner-type OG is set as tenant.
-
CRSVC-72895: Profile not removed from Device Details after deactivation or removal of Assignment Group.
-
ARES-32876: Application removal protection triggered despite device threshold not being met within time window, causing false alarms.
-
AAPP-21457: Add new File Provider sync management settings for macOS 26.4.
-
AAPP-21456: Support for OS 26.4 DDM configurations (Intelligence, Keyboard, Siri) and MDM keys (Restrictions, Parental Controls).
-
AAPP-21334: Support for new OS 26.4 DDM configurations (External Intelligence, Migration Assistant).
-
AAPP-20461: Add support for new Skip/Setup Assistant Keys in ADE profile: Camera Control, Keyboard, Dictation, Age Assurance, Age-Based Safety Settings.
-
FCA-213345: Incorrect devices scoped for bulk actions performed from the Device List View.
Patch 26
-
MACOS-5970: DEP Device Configured command is incorrectly delivered to User Channel.
-
CMSVC-20840: Improved input validation for OEM and Model ID fields during SmartGroup creation via API.
-
ARES-37278: Incorrect app config delivered to newly enrolled devices assigned to future-dated Internal app assignments.
-
AMST-46752: Dropship Provisioning online gets stuck on random devices.
-
AMST-46303: Tunnel - Client authentication certificate is not present.
-
AAPP-21825: In VPP v2 flows, Apple Jingle IDs are not being logged.
-
AAPP-21692: VPP apps not getting app config settings delivered.
-
AAPP-21214: VPP Application(s) not installing on AppleTV devices.
-
AAPP-21075: Backport hash creation in DDM flow.
-
AAPP-20729: Devices not reflecting correct installation status data.
-
AAPP-20699: Update device profile with new Skip Keys (Camera Control, Keyboard, Dictation, Age Assurance, Age Based Safety Settings) and Restriction Key (RatingAppsExemptedBundleIDs).
-
AAPP-20681: Missing expected event data upon initiating iOS OS update and querying update progress.
-
AAPP-20656: Update ExternallyRedeemedVPPLicensesCleanupJob to pass correct VppLicenseId.
-
AAPP-20576: Failed to fetch user token for macOS device.
-
AAPP-19193: App publish flow still calls custombatch and does not notify devices for check-in.
Patch 27
-
SINST-176753*: Certificate installer Hardening.
-
RUGG-14238: Improved search and sort functionality for devices with large number of product assignments (50+).
-
MACOS-7216: Unable to edit the iOS VPN payload for IKEv2 type.
-
HUBW-22664: 2602 Bitlocker profiles being blocked in the onboarding workflow.
-
FCA-213604: Modified the upgrade notification banner to prevent user actions from being blocked on screen.
-
CRSVC-78779: Fixed issue with Bitlocker profiles being blocked in the onboarding workflow.
-
CRSVC-76143: Updated DeviceStatev3 API response to prevent duplicate Device UUID value reporting.
-
CRSVC-75006: Azure token may not be revoked if device is deleted when offline.
-
CRSVC-72697: Addressed scenario where bypass list was not properly honored when set in Console Proxy Settings.
-
CRSVC-68517: Duplicate profile install commands sent to macOS device for native MDM targeted resources.
-
ATL-29339: Seed Workspace ONE Intelligent Hub v25.06.9 for Windows.
-
ATL-29296: Seed SFD 25.6.4 build.
-
ARES-36827: Increase Fastlane delivery maximum up to 20,000 devices for apps and profiles - GA.
-
AMST-46381: Corrected scenarios where Shiplify is not downloading the highest available version.
-
AMST-44384: Improved syncML reporting to contain
nodes when ProfileDeliveryAtScaleFeatureFlag is enabled. -
AMST-44074: Device Updates and Update Details pages now support partner OGs.
-
AGGL-20005: Resolved scenario where Android Work-Managed devices may not correctly report phone number to UEM console.
-
AAPP-22155: Improve retry logic for VPP v2 calls.
-
AAPP-21798: Improve handling of Apple's throttling limits for VPP v2 flows.
-
AAPP-21422: Improve VPP v2 license management flow.
Patch 28
-
MACOS-7103: Newer application versions deployed to lower OGs are incorrectly inheriting and overwriting the Bundle Identifier schema.
-
FS-8548: Address app and profile quick action workflows failures on Android.
-
ATL-29614: Seed Workspace ONE Intelligent Hub v25.06.10 for Windows.
-
AGGL-20112: ChromeOS Wi‑Fi profile with credentials payload fails to install.
-
AAPP-22508: Device updates tab shows 'Not Available' for Apple OS Updates.
Patch 29
-
PPAT-19201: Hide "Tunnel & Other Attributes" when deploying the Workspace ONE Tunnel app.
-
FCA-213739: Authorization error message is being incorrectly shown on some console screens.
-
AMST-46946: Fixed issue in UEM console, where after selecting apps for inclusion in a provisioning package (PPKG), the NEXT button becomes greyed out and the app selection on the initial page is lost when navigating back to it.
-
AMST-46668: Filtering in Device Registration List View with Serial Number does not work.
-
AAPP-20744: Both actions and commands are generated for iOS profiles.
Patch 30
-
FS-9932: Repeated profile installation attempts may occur if a response is missing during re-evaluation on macOS devices (Short term solution).
-
ATL-30209: Seed - Machost to canonical release PR2506-30.
-
AMST-46542: Fixed issue with MST apps unavailable when you navigate directly to Assignments tab.
Known Issues
Vison Pro device authentication issue When using regular ADE with authentication that expects user credential prompts, Vision Pro devices may fail to complete enrollment. The device may not display the expected authentication prompt and appear to be stuck in the enrollment process.
Workaround: If you require authentication during enrollment, turn on Custom enrollment in your ADE profile. This ensures the authentication prompt displays correctly and enrollment completes successfully.
Release Availability
Release Availability
We strive to deliver high-quality products, and to ensure quality and seamless transitions, we roll out our products in phases. Each rollout may take up to four weeks to accomplish and is delivered in the following phases:
-
Phase 1: Demo, Shared SaaS UATs, and Latest Mode UATs
-
Phase 2: Shared SaaS environments
-
Phase 3: Latest Mode environments
Getting Ready for Major OS Releases
To prepare for the upcoming software updates from major device vendors, read through the Getting Ready for Major OS releases section of the Omnissa Product Documentation.
Documentation
To learn more about Workspace ONE UEM, browse Workspace ONE UEM Documentation.
Localized Content for Omnissa Docs
For details on Omnissa's localization strategy, see the KB article: Announcing Omnissa Localization Support.
Support Contact Information
To receive support, access Omnissa Customer Connect. For information about filing a Support Request in Customer Connect and using Cloud Services Portal, see the Knowledge base article here.
Was this page helpful?