We're excited to share the new release of Workspace ONE UEM version 2509! Read on to learn about the new features and improvements in this release.
What's New in this Release
Admin Experience
Read-Only Access Control for Settings
You can now create custom administrator roles with read-only permissions for all Settings in Workspace ONE UEM. This feature enables users to view every settings page without modifying or interacting with configurations. It improves visibility and audit capabilities while maintaining configuration integrity.
Android Management
Set WiFi roaming behavior (Custom DPC) on your devices
You can now configure device roaming between access points while connected to WiFi networks. For a specific network, you can enable more aggressive roaming to prioritize signal strength over battery consumption. This feature is supported on Work-Managed and Corporate Owned Personally Enabled (COPE) devices running Android 15 and higher.
Certificate Management
Customizable SID mapping in OID/SAN certificate attributes
Omnissa has enhanced the configuration capabilities for SID mappings within the OID/SAN certificate template attributes. The latest implementation introduces support for overriding the default user-based SID configuration, allowing administrators to define a fixed SID or substitute it with a custom variable, such as the newly introduced ComputerSID. This enhanced configurability enables organizations to meet additional advanced mapping requirements by offering greater flexibility in SID assignment.
Console Settings
Bring Your Own Key (BYOK): Take control of your data security
Workspace ONE UEM Preferred SaaS now supports Bring Your Own Key (BYOK), allowing organizations to manage their own RSA-4096 wrapped Key Encryption Keys (KEKs) for data-at-rest encryption. BYOK not only provides encryption but also empowers organizations to define their own security rules and maintain control over their keys. The key capabilities include:
- Customer-Controlled KEK: Organizations using Customer-controlled KEK can manage their own Key Encryption Keys (KEK), set renewal schedules, and control encryption lifecycle operations.
- Secure Storage: Omnissa securely stores the KEK in a Hardware Security Module (HSM), ensuring limited system access to the root of trust.
- Auditability: All key access and encryption operations are fully auditable, supporting governance and compliance requirements.
- Zero Trust Alignment: The BYOK lays the foundation for Zero Trust architecture, enabling agile adaptation to evolving security models and technologies.
For more information, see Bring Your Own Key (BYOK) Support for Workspace ONE UEM Preferred SaaS.
Improved Device and Console log collections
Workspace ONE UEM brings you an upgrade with enhanced log collection. It now supports one-click-log-collection, gathering all logs, including server and device application logs (Hub, Boxer, Tunnel, etc.). You can target Console or Services logs or start at the Device context. This process enhances the support experience and simplifies troubleshooting by ensuring log captures include all necessary information on the first attempt, preventing the need for multiple log-gathering requests. Logs collected are now accessible to Omnissa Support teams through internal tools.
Freestyle Orchestrator
Quick and easy app and profile removal for Freestyle Orchestrator Mobile
You can now create a workflow that includes a step to remove an application and/or profile from iOS and Android devices. When the workflow is deployed, the specified app or profile will be removed from the device. For more information, see Remove Applications and Profiles from Mobile Devices using Workflows.
Streamline onboarding entitlements in workflows for macOS
Onboarding entitlements within workflows are now supported on macOS with Limited Availability. This feature allows administrators to prioritize resources essential for onboarding, which take precedence over other resource assignments. To have this feature enabled for your environment, contact your account team.
ARM64 support for macOS
The workflow engine is now fully ARM64 compatible, eliminating the need for Rosetta translation on Apple Silicon devices.
macOS Management
Faster FileVault recovery key escrow for macOS enrollment
The time required for a macOS device to escrow the FileVault recovery key into Workspace ONE UEM during enrollment has been reduced. This change allows for quicker access to the key, facilitating immediate viewing following enrollment. Previously, if a user forgot their password after setup, the device would lock and the recovery key would not yet be available in the console. Now, a quick escrow process ensures the FileVault recovery key is escrowed right after you activate it at the Setup Assistant. This improves the user experience.
Resource Management
Real-time app assignment status in Device Details
You can now view app assignment status in real-time within the Apps tab of a Device Details view. This enhancement provides immediate visibility into app assignment status, reducing troubleshooting delays and helping you act faster. This capability is currently in Limited Availability. To have it enabled for your environment, contact your account team.
Installation metrics now retained upon Resource and Smart group updates
When assignment or payload updates are made to apps and profiles, or when their assigned Smart groups are modified and republished, installation metrics achieved so far will now be retained and remain visible on the Deployment Tracking page as Currently assigned. It denotes all devices having a confirmed assignment to an app or profile at any given time. This enhancement is generally available starting Patch 15.
Faster resource delivery for larger device populations
Faster resource delivery is now supported for a larger device population when apps and profiles are published. This type of delivery is initiated whenever new apps or profiles are published, assignments for existing ones are updated, profile payloads are modified, or Smart Group rules change if the number of devices impacted by such updates is below a defined threshold. Devices impacted by these updates will check in immediately and install or remove the necessary resources instead of waiting for the standard check-in cycle. This enhancement is available as Limited Availability starting with 2509 Patch 3 and is Generally Available from 2509 Patch 19.
Windows Management
Enhanced version management for Hub and improved ARM integration within Workspace ONE UEM
You can now choose the Intelligent Hub version directly from the Workspace ONE UEM Console, eliminating the need to repackage and deploy the installer for each new release.
Key features include:
- Flexible version management: Select the Intelligent Hub version for deployment, including:
- GA version (General Availability)
- Beta version (for testing and validation in specific Organizational Groups)
- Win32 and ARM support: Full support for Win32 and ARM-based devices is available in all deployment scenarios.
For more information, see Intelligent Hub Application Version Control and Intelligent Hub Application topics.
Streamline application management with Enterprise Application Repository v2 (EARv2)
This Limited Availability feature simplifies how administrators discover, configure, and deploy over 8000 enterprise applications for Windows devices in Workspace ONE UEM. The new Enterprise Application Repository (EAR) provides a centralized, secure source of pre-vetted applications that can be managed directly from the UEM Console, minimizing manual packaging and configuration.
- Centralized Application Catalog: Easily navigate, search, and add trusted applications from the Enterprise Application Repository directly from the UEM Console.
- Automated Configuration: The repository automatically generates commands to install, uninstall, and detect, reducing manual setup and improving consistency.
- Brownfield App Linking: Existing (manually uploaded) applications can now be linked to the repository for automatic version tracking and update visibility.
- Seamless Updates: Initiate updates directly from the console, facilitating continuous application maintenance with minimal effort.
For more information, see Add Windows applications from the Enterprise Application Repository.
Resolved Issues
Admin Experience
-
FCA-210682: Custom message templates in deprecated languages cannot be edited.
-
FCA-210742: Errors while navigating to different pages in the UEM console.
-
FCA-210698: Incorrect Exception seen when API returns a 400 Bad Request for some scenarios.
-
FCA-210746: License count not properly reflecting in the UEM Admin Panel.
-
FCA-207442: Problem arises from the JavaScript implementation where the 'testCookie' is set without explicitly defining the attributes.
Android Management
- AGGL-18872: DB script does not handle nvarchar to datetime conversion properly for all date formats.
Common Services
- CMSVC-20517: Error occurs while creating OAuth token in Partner OG.
Content Infrastructure
- CMCM-191349: Facing issues while accessing "Content Dashboard" with "Content Management" Admin role.
Core Platform
-
CRSVC-63683: Unable to filter console logs by searching the Account name.
-
CRSVC-64367: Resource delivery is not unblocked when a device becomes Compliant for a policy with Block/Remove resource actions.
-
CRSVC-66909: API call counter was not reporting usage as expected.
Enrollment and Service Integrations
-
ESI-563: Devices are not being assigned the correct Ownership Type.
-
ESI-603: Deleting a device on Self Service portal shows error message.
-
ESI-615: Unable to add Custom User groups for enrollment restrictions.
-
ESI-710: Unable to bulk remove device registration tokens.
-
ESI-711: "Registration" page title changes to "Enrollment Status" after performing action.
-
ESI-775: Staging user enrolment failing for multiple platforms.
Freestyle Orchestrator
-
FS-7946: UEM update trigger in-scope workflow/script for macOS unexpectedly.
-
FS-8071: Fix error while consuming feedback for workflow step keeping workflow stuck in progress.
iOS Management
-
AAPP-19306: Cannot edit a profile with exchange ActiveSync/Subscribed Calendar iOS payload.
-
AAPP-19829: Shared iPads for Business experience delays in resource delivery when switching users.
-
AAPP-20057: Device enrollment failures for iOS 18.6.2 when OS restriction policy is enforced.
Resource Management
-
ARES-31936: Profile does not get installed on devices with 'Auto' direct assignment unless the On-demand workflow is manually triggered.
-
ARES-33173: Spaceman error is displayed when clicking 'View' on the Profile List.
-
ARES-33301: App scheduled for future deployment installs immediately.
-
ARES-33361: Device Details view displays incorrect profile summary counts.
-
ARES-33426: Deleted and deactivated profiles visible on Device Profiles list.
-
ARES-33466: Existing assignments displayed as 'Added' in assignment preview while republishing Web Link.
-
ARES-33477: A few profiles unintentionally installed on Smart Groups if it were previously assigned to it through a now-deleted Workflow.
-
ARES-33610: Assignment and installation data misreported for devices assigned to Internal app versions with exclusions.
-
ARES-34443: Admin occasionally unable to save assignments for Android Internal Apps.
-
ARES-34450: Installation Status Last Scan on Device App list sometimes displays future time.
-
ARES-34502: Received 'Something unexpected happened' error while exporting App log from UEM Console.
-
ARES-34536: Trusted Credentials setting under Wifi payload cannot be saved in DDUI Profiles.
-
ARES-34857: 'Failed to save profile' error may occur when publishing a profile whose payload has not been updated.
User Management
-
UM-10250: User Groups List View does not load results beyond selected page size.
-
UM-10252: Clear and Save is failing for both 'Service Provider (AirWatch) Certificate' and 'Identity Provider Certificate'.
Windows Management
-
AMST-44769: Windows Autopilot enrollment stuck at OOBE "Setting up Work or School" screen after patch 24 upgrade.
-
AMST-44385: App removal failing instantly for a Windows internal application.
-
AMST-45025: Device reassignment is failing intermittently for a specific set of users.
Patch Resolved Issues
Patch 1
-
FS-8831: Enhanced error handling for socket exceptions to prevent silent failures during script execution.
-
FS-8564: Scripts unable to execute due to an unexpected reboot causing a corrupted DB on macOS devices.
-
FCA-211680: Add link to collect logs in the user details dropdown.
-
ATL-27185: Seed Machost v2509.4802 to 2509 patch 1.
-
ATL-27071: Seed Workspace ONE Intelligent Hub v25.06.5 for Windows to UEM 2509.
-
ARES-35268: Apps delivered through Product Provisioning removed from devices when they lose assignment.
-
ARES-34933: "An error has occurred" sometimes appears while performing actions related to apps and profiles.
-
AGGL-19412: Outdated settings shown when viewing ChromeOS Credentials profiles.
-
AAPP-20600: Device Updates page failing to load new versions (iOS/macOS).
-
AAPP-20593: Fix SKU mapping for Device Attestation and Release Device from ABM.
-
AAPP-20016: Apple TV - VPP License is not revoked after removing app from Device Details page.
Patch 2
-
MACOS-6589: New versions of native Mac app uploads improperly handling rebranded (com.ws1) Bundle ID.
-
FS-8580: Workflow fails on macOS 26 RC 1 devices due to step timeout persisting after completion.
-
ESI-825: MTD Activation through Smart Groups fail when deployed from Partner tenant.
-
CRSVC-70627: Tunnel App showing Access Denied until reinstalled.
-
CMCM-191640: Admin repo empty after clicking on 'sign-in' in Content app.
-
ATL-27265: Seed - Machost 2509.4939 to Workspace ONE UEM 2509.
-
ARES-35269: Error occurs intermittently while viewing Profile List View.
-
AGGL-19570: Per-app VPN settings not working when VPN profile includes additional payloads.
-
AGGL-19522: After running the seed script, the API level for Android 16 is displayed as null.
-
AAPP-20322: iOS Device Updates details page update-status grid filters are not functioning as expected.
-
AAPP-20207: VPP application versions are not updating in the Console when the country code is non-English.
-
AAPP-19914: Workspace ONE UEM Console inherit setting blocked for Apple -> SCEP.
-
RUGG-13731: Repeated product delivery and device reboots when Reboot Manifest is used with other actions.
Patch 3
-
RUGG-13764: Device level update status for Custom Update is not syncing after update is marked completed.
-
LUEM-963: Software Update Profile for Linux devices.
-
FCA-211628: 'Logging Server Failure' notification preferences are not seen in Account Settings.
-
FCA-211339: Update mdm/device/search v2 API to add field for reporting physical memory with the memory unit.
-
ESI-834: Azure AD token not revoked when device is unenrolled or wiped.
-
ESI-644: Android devices enroll without a registration record.
-
CRSVC-71133: Resolved scenario where profiles using SCEP certificates may not install correctly for newly enrolled macOS devices.
-
CRSVC-70627: Tunnel app showing Access Denied on rapid check-in/checkout of shared Android device.
-
CRSVC-70337: Improved logic for device command queue stored procedure related to application removal protection.
-
CRSVC-55456: Resolved inconsistency between the Certificate list API and UI.
-
CMCM-191535: Unable to access network shares on Content app post UEM upgrade to 24.10.
-
ATL-27303: Seeding macOS Hub 25.11 to UEM 25.09 patch 3.
-
ATL-27297: Seed Workspace ONE Intelligent Hub v25.06.6 for Windows to 2509.
-
ARES-34394: Incorrect admin reported for some device troubleshooting log events.
-
AMST-45190: Handle Device Reassignment failures with internal server error.
-
AAPP-20421: 500 Error on Purchased App API Endpoint (/mam/apps/purchased/search).
-
AAPP-20216: Editing iOS VPN profile requires selecting duplicate DTR fields.
-
AAPP-19962: VPP V2 - Unenrollment of the primary device of a Shared User Based License is not working as expected.
Patch 4
-
FS-8392: Kafka exploratory work with FIPS.
-
ATL-27493: Seed - Machost to canonical release PR2509-3.
-
ATL-27460: Seed Workspace ONE Intelligent Hub version 25.06.7 for Windows to 2509.
-
ARES-36022: Save Failed error received when trying to publish an app assignment with the App Config included.
-
ARES-35570: Google payload Declarative profile fails to save.
-
ARES-34664: 'Installed Date' column is blank in Profile Details by Device report.
-
AMST-45464: Main - DropshipProvisioning- Backport Dropship items.
-
AMST-45408: Windows Device Reassignment is failing with HybridAD setup.
-
AMST-44772: Higher level OG assigned domain join configuration not found at lower OG.
-
AAPP-20636: Add timeouts and additional diagnostics for APNS processing.
-
AAPP-20276: Support for new Web Content Filter keys introduced in Apple OS 26.
-
AAPP-20190: Incorrect calculation of allocated and redeemed VPP counts resulting in a negative unallocated count.
Patch 5
-
PPAT-20873: Tunnel Admin role restrictions are not enforced.
-
CRSVC-68243: Certificate Profile option in Certificate Template does not retain setting after it is saved and reopened.
-
ARES-36022: Save Failed error when trying to publish an app assignment with the App Config included.
-
ARES-34664: 'Installed Date' column is blank in Profile Details by Device report.
Patch 6
-
SINST-176707: Corrected a condition in which the updated ACC Installation Directory was not honored.
-
LUEM-1060: Intel WF that installs profiles on devices does not work.
-
ESI-892: Possible gaps in Enrollment Status writes to DST.
-
CRSVC-71542: Compliance actions are not reverted after concurrency exception.
-
CRSVC-70502: Fix read readiness flag caching and no tenant enablements.
Patch 7
-
MACOS-5970: DEP Device Configured command is incorrectly delivered to User Channel.
-
ESI-1000: Some Android devices are getting unenrolled when checking in with UEM while 'Require Registration Token' is enabled.
-
ATL-27650: Updating 25.09 macOS Hub seeded version (v26.01).
-
ARES-34736: Application cannot be added under the App and Profile Monitor.
-
ARES-34004: Cannot save internal app assignments after associated workflow is deleted or Smart Group is removed.
-
AAPP-20775: Proper IMEI/MEID/Phone Number reporting for iOS 26+.
Patch 8
-
UM-10598: Multiple checks in DirectoryUserMigration_PreCheck sproc result in false failures.
-
CRSVC-73010: {ComputerSID} is not injected into certificate for new devices post UEM upgrade to 2509.
-
CRSVC-72895: Profile not removed from Device Details after deactivation or removal of Assignment Group.
-
CRSVC-71256: Compliance notifications over SMS are not delivered in some environments.
-
CRSVC-70831: Old GoogleDeviceID is not set to Unmanaged when a new GoogleDeviceID is reported by the device.
-
ATL-27820: Seeding SFD 25.6.3 build to UEM 2509 patch release.
-
AMST-45176: Windows 11 25H2 missing in Update Dashboard.
-
AGGL-19892: [AMAPI] Device Details crash for devices with pre-release builds.
-
AGGL-19769: [AMAPI] Enrollment ID is displayed as Serial Number for Work Profile devices.
Patch 9
-
SINST-176738: Certificate installer crashes during application deployment when windows authentication is used.
-
FCA-212558: Ensure user data appears in the device list view when encryption is enabled.
-
ESI-1000: Some Android devices are getting unenrolled when checking in with UEM while 'Require Registration Token' is enabled.
-
ESI-888: Asset number not preserved after Windows enrollment via custom provisioning package.
-
CRSVC-68517: Duplicate Profile Install Commands Sent to macOS Device for Native MDM Targeted Resources.
-
ATL-27942: Seed - Mac workflow host files into 2509 Patch 9.
-
AMST-45591: VPN profile failing to install on devices.
-
AMST-45113: (ADMX Profiles) List elements are not applied on the device.
-
AMST-44776: Removed approved updates Sampling Logic to avoid delays in DM Resource Processing.
-
AAPP-21374: Enable Apple VPP V2 API.
-
AAPP-20461: Add support for new Skip/Setup Assistant Keys in ADE profile: Camera Control, Keyboard, Dictation, Age Assurance, Age Based Safety Settings.
Patch 10
-
RUGG-13841: Device list view from product status shows old OS version even after new OS version received in device sample.
-
RUGG-13748: Force Reprocess for any product set from Device Details page fails with page not found error.
-
FCA-212380: Send Message button in the Location Service is unresponsive when all devices are selected in multiple device context.
-
ESI-998: Omni is unable to access the Intelligence console and provides incorrect query AI responses.
-
ATL-27957: Seed Workspace ONE Intelligent Hub v25.06.8 for Windows to UEM 2509.
-
AAPP-21214: VPP Application(s) Not Installing on AppleTV Devices.
Patch 11
- CRSVC-72697: Bypass List not honored in console Proxy settings.
Patch 12
-
PPAT-21050: Unable to save Multi-Factor Authentication settings under UEM console for the Tunnel settings page.
-
FCA-212784: Ensure user data appears in the Device list view when encryption is enabled.
-
FCA-212071: Settings export displays NULL for some settings that have valid values configured in the UEM console.
-
CRSVC-65481: Installed app version missing under 'Apps Status' column on Device Details Apps tab for Public apps.
-
CMSVC-20830: Smart Group update API fails when Name field is missing.
-
AGGL-20047: ChromeOS certificates not installed if device is power washed and immediately re-enrolled.
-
AGGL-20008: Profile installation status not updated in UEM Console for AMAPI COPE device after Auto assignment.
-
AGGL-19967: UEM re-pushes ChromeOS certificates each time user logs in.
-
AGGL-19954: UEM repeatedly installs certificates on ChromeOS devices.
-
AGGL-19947: ChromeOS credentials profiles stuck in pending status.
-
AGGL-19936: AMAPI devices not shown in assignment preview and incorrect app status displayed as Installed but not Assigned for Auto Public Apps.
-
AGGL-19913: ChromeOS certificates are not installed on re-enrolled devices.
Patch 13
-
CRSVC-71334: Apps and profiles assigned via workflow do not install after unlock on iOS and macOS devices.
-
ARES-37111: Door locked displayed when attempting to remove iOS/Mac app from device.
-
AGGL-20113: Deprovisioned ChromeOS devices can still check in and get certificates.
-
AAPP-21456: Support for OS 26.4 DDM configurations (Intelligence, Keyboard, Siri) and MDM keys (Restrictions, Parental Controls).
Patch 14
-
UM-11090: Conflicts on UPDATE in UMS.
-
UM-10484: User Search option in Add Device Registration screen permits search for empty string.
-
CRSVC-73705: Update SCEP Certificate Auto Renewal Flow - User Based Profile Mismatch between Signed User and Enrollment User.
-
ARES-37360: Android profiles incorrectly displayed as declarative profiles.
-
ARES-32876: Application removal protection triggered despite device threshold not being met within time window, causing false alarms.
-
AMST-46322: [EAR] app upload fails with error No valid file extension found in file link.
-
AMST-46183: [FedRAMP] docker-local-ws1uem-qe-builds/intel-command-processor.
-
AGGL-20241: We see Msmq backing up for CN1498 and Server unavailable error from Google.
-
AGGL-20026: [AMAPI] Application status not updated to "Installed".
-
AGGL-19606: SDK profile removal fails when modstack is enabled.
-
AGGL-19262: Fix application_uuid in MAL samples.
-
AGGL-17740: App configuration, App policy, and per-app VPN settings unexpectedly removed from AMAPI devices.
-
AAPP-21334: Support for new OS 26.4 DDM configurations (External Intelligence, Migration Assistant).
-
AAPP-20729: Devices not reflecting correct installation status data.
-
AAPP-20699: Update profiles with new Skip Keys (Camera Control, Keyboard, Dictation, Age Assurance, Age Based Safety Settings) & Restriction Key (RatingAppsExemptedBundleIDs).
Patch 15
-
UM-10484: User Search option in Add Device Registration screen permits search for empty string.
-
CRSVC-73705: Enhanced SCEP auto-renewal logic to support user-based profiles where signed user and enrollment user are not the same.
-
ARES-37360: Android profiles incorrectly displayed as declarative profiles.
-
ARES-32876: Application removal protection triggered despite device threshold not being met within the time window, causing false alarms.
-
AMST-46322: EAR app upload fails with error No valid file extension found in file link.
-
AGGL-20026: AMAPI Application status not updated to "Installed".
-
AGGL-19606: Android SDK Profile removal fails.
-
AGGL-19262: Fix application_uuid in MAL samples.
-
AGGL-17740: App configuration, App policy, and per-app VPN settings unexpectedly removed from AMAPI devices.
-
AAPP-21334: Support for new OS 26.4 DDM configurations (External Intelligence, Migration Assistant).
-
AAPP-20729: Devices not reflecting correct installation status data.
-
AAPP-20699: Update device profile with new Skip Keys (Camera Control, Keyboard, Dictation, Age Assurance, Age-Based Safety Settings) and Restriction Key (RatingAppsExemptedBundleIDs).
-
FCA-213345: Incorrect devices scoped for bulk actions performed from the Device List View.
-
ARES-34608: View counts on App list do not match with Deployment Tracking after updating assignments.
-
AMST-43621: Handle the user object identifier not present for windows devices.
Patch 16
- FS-9925: macOS Devices Reinstalling Native Profiles.
Patch 17
-
PPAT-20482: Customer Integrated AirWatch SDK with the "SmileToPay" application and which is using device is used as a Kiosk machine with the Single App Mode enabled.
-
CRSVC-74767: Addressed scenario where optional profiles aren't displayed in the devices Profiles tab.
-
FCA-212362: Workspace ONE UEM console logo renders in incorrect colors on some pages.
-
ARES-37278: Incorrect app configuration delivered to newly enrolled devices assigned to future-dated Internal app assignments.
-
AAPP-21692: VPP apps were not getting app configuration settings delivered.
Patch 18
-
RUGG-14288: Certificate renewal fails for Android devices published through Product provisioning profiles.
-
RUGG-14238: Searching and sorting products in Device details page does not work if the device has more than 50 products.
Patch 19
-
PPAT-21484: Fix Tunnel Exceptions during profile publish.
-
FS-9293: Database corruption may occur during device reboot due to initialization timing on macOS devices.
-
FCA-212597: Suppression of require.js version information in the application interface.
-
FCA-212168: Help page displayed instead of assignment list on Sensors and Scripts workflow assignment tab.
-
CRSVC-75705: Conditional Access registration and status updates may not be sent when Partner-type OG is set as tenant.
-
CRSVC-70440: Data connector update does not includes all the connector config if there is an existing connector.
-
CMSVC-20840: Improved input validation for OEM and Model ID fields during SmartGroup creation through API.
-
AMST-44074: Device Updates and Update Details pages now support partner OGs.
-
AAPP-20403: EID value missing from network information.
Patch 20
-
UM-11073: Enrollment to a child OG fails for basic users in OIS-enabled tenants.
-
SINST-176753: Certificate installer Hardening.
-
MACOS-7216: Unable to edit the iOS VPN payload for IKEv2 type.
-
FCA-213604: Modified the upgrade notification banner to prevent user actions from being blocked on screen.
-
FCA-212660: Devices "extensivesearch" API returns invalid results when using Platform as filter.
-
FCA-212413: Clicking "Other" in the Operating System breakdown chart from the Device Dashboard displays an error.
-
FCA-210931: Update Event Log to display username of admins which triggered bulk actions.
-
ESI-835: Enrollment status changes to Enterprise Wipe Pending for unenrolled devices after adding a denied device record.
-
CRSVC-76143: Updated DeviceStatev3 API response to prevent duplicate Device UUID value reporting.
-
CRSVC-75006: Azure Token may not be revoked if device is deleted when offline.
-
CRSVC-62768: Resolved Scenario Where Autorenewal for SCEP NDES Would Fail for Windows Devices.
-
CMCM-191789: Content app on iPad and Android, is displaying duplicate of same folders.
-
AMST-47061: Enrollment restrictions now honored during CLI checkout, blocking auto-creation of unapproved user accounts.
-
AMST-46752: Dropship Provisioning Online may intermittently fail to register devices.
-
AMST-46303: Tunnel - Client Certificate may require repush before landing on the device.
-
AMST-46045: App installed on Hololens are showing as "Not managed" preventing some management functionality.
-
AMST-46039: Invalid version displayed on Add Policy when CIS latest template selected.
-
AGGL-20483: Resolved Android APK parsing crash and InvalidOperationExceptions.
-
AGGL-20005: Resolved scenario where Android Work Managed devices may not correctly report phone number to UEM console.
-
AAPP-21457: Add new File Provider sync management settings for macOS 26.4.
-
AAPP-20681: Missing expected event data upon initiating iOS OS update and querying update progress.
-
AAPP-20263: Additional enhancement to prevent resource delivery delays when switching users on Shared iPads for Business.
Patch 21
-
VOS-254: Disable MAC address randomization on visionOS devices.
-
RUGG-14484: Product Set remains stuck in processing state, preventing edits.
-
PPAT-21400: Updated Tunnel pages Read-Only RBAC role permissions.
-
MACOS-7103: Resolved an issue where newer application versions, deployed to lower OGs, were incorrectly inheriting and overwriting the Bundle Identifier schema.
-
MACOS-5921: All Profile installation fails if the device actions have duplicates.
-
MACOS-5832: User token isn’t getting properly updated if device is reenrolled without deleting.
-
HUBW-22664: 2602 Bitlocker profiles being blocked in the onboarding workflow.
-
ESI-1024: An error message appears when deleting a device from the Self-Service Portal.
-
CRSVC-78779: Fixed issue with Bitlocker profiles being blocked in the onboarding workflow.
-
CRSVC-71788: Certificate count in the Device Details > Summary does not match the data under Device Details > Certificates.
-
CRSVC-71550: Conditional Access - Redundant status update calls may cause compliance status updates to fail.
-
CRSVC-66297: Compliance status update is not sent to Conditional Access partner when compliance policy is unassigned.
-
ARES-37562: Multiple apps cannot be configured against Android Restrictions profile setting ‘Allow Apps that can Utilize Widgets’.
-
ARES-34470: App visible under Pending Actions even after it is installed on device.
-
AMST-46364: Multi User Checkout restrictions are not getting overwritten in child OG.
-
AMST-45142: Unintended disable of Drop Ship Provisioning at child OG.
-
AGGL-20112: ChromeOS Wi‑Fi profile with credentials payload fails to install.
-
AAPP-22508: Device updates tab shows 'Not Available' for Apple OS Updates.
-
AAPP-22155: Improve retry logic for VPP v2 calls.
-
AAPP-22136: Implement Apple's recommendation for VPP V2- backoff based calls.
-
AAPP-21422: Improvements to VPP v2 license management.
Patch 22
-
AAPP-21798: Improve handling of Apple’s throttling limits for VPP v2 flows.
-
AGGL-20112: Chrome OS Wi-Fi profile with credentials payload fails to install.
-
AMST-46542: Fixed issue with MST apps unavailable when you navigate directly to Assignments tab.
-
AMST-47928: Intelligent Hub on Windows not updating post UEM upgrade to 2509.
-
CRSVC-66297: Compliance status update is not sent to Conditional Access partner when compliance policy is unassigned.
-
CRSVC-78779: Fixed issue with Bitlocker profiles being blocked in the onboarding workflow.
-
FCA-213739: Authorization error message was incorrectly shown on some console screens.
-
FCA-213920: Self-Service Portal (SSP) language selection is unavailable when authenticating through Workspace ONE Access.
-
FCA-214069: Editing a profile for an extended period might trigger a session error, interrupting the edit before assignment.
-
PPAT-19201: Hide "Tunnel & Other Attributes" when deploying the Workspace ONE Tunnel app.
-
UM-11206: User group memberships are updated when enrolling iOS or macOS devices even if Sync User Groups in Real Time is disabled.
Patch 23
- RUGG-14521: Last seen timestamp is incorrectly updated for devices belonging to smart groups assigned to a product upon product activation.
Patch 24
-
UM-11243: User Management Service client is incorrectly invoked when feature flag is disabled.
-
CMCM-191541: Error screen while accessing Content List View with a Custom Content Management Role.
-
ATL-29615: Seed Workspace ONE Intelligent Hub v25.06.10 for Windows to 2509.
-
ARES-38439: Device profiles containing password fields may fail to authenticate, deploy, or open after copy or update.
-
ARES-37644: Incorrect installation status reported for some profiles in Device's Profile list.
-
ARES-36887: Incorrect installation statuses reported for some profiles in Intelligence.
-
AMST-46946: Fixed issue in UEM console, where after selecting apps for inclusion in a provisioning package (PPKG), the "NEXT" button becomes greyed out and the app selection on the initial page is lost when navigating back to it.
-
AMST-46668: Filtering in Device Registration List View with Serial Number does not work.
-
AAPP-21344: Remove admins email alerts for exceeding Application Removal Limit for VPP apps.
-
AAPP-20744: Both actions and commands are incorrectly generated for iOS profiles.
Known Issues
-
FS Mobile: Outdated Assignment Status on Legacy Screens
Some legacy screens may not accurately show the status of app/profile assignments when resources are removed through a mobile workflow. For example, the legacy App Catalog and Intelligence dashboards prior to ETLv2 may display outdated assignment information.Workaround: Upgrade to use the latest modstack-compatible features, such as the Hub Services App Catalog and ETLv2 as it becomes available, to ensure assignment statuses are displayed correctly.
-
Vison Pro device authentication issue When using regular ADE with authentication that expects user credential prompts, Vision Pro devices may fail to complete enrollment. The device may not display the expected authentication prompt and appear to be stuck in the enrollment process.
Workaround: If you require authentication during enrollment, turn on Custom enrollment in your ADE profile. This ensures the authentication prompt displays correctly and enrollment completes successfully.
Release Availability
We strive to deliver high-quality products, and to ensure quality and seamless transitions, we roll out our products in phases. Each rollout may take up to four weeks to accomplish and is delivered in the following phases:
-
Phase 1: Demo, Shared SaaS UATs, and Latest Mode UATs
-
Phase 2: Shared SaaS environments
-
Phase 3: Latest Mode environments
Getting Ready for Major OS Releases
To prepare for the upcoming software updates from major device vendors, read through the Getting Ready for Major OS releases section of the Omnissa Product Documentation.
Documentation
To learn more about Workspace ONE UEM, browse Workspace ONE UEM Documentation.
Localized Content for Omnissa Docs
For details on Omnissa's localization strategy, see the KB article: Announcing Omnissa Localization Support.
Support Contact Information
To receive support, access Omnissa Customer Connect. For information about filing a Support Request in Customer Connect and using Cloud Services Portal, see the KB article here.
Was this page helpful?