We're excited to share the new release of Workspace ONE UEM version 2602! Read on to learn about the new features and improvements in this release.
What's New in this Release
Admin Experience
New Workspace ONE UEM Console Experience
Experience a redesigned Workspace ONE UEM console featuring a modern layout, intuitive navigation, and a refreshed Device List View to improve admin efficiency. Administrators can opt in to the new experience at their own pace and switch back to the legacy console at any time. This feature is currently available under Limited Availability. For more details, see KB article. To enable this feature, contact your Omnissa Account team.
Cancel queued Wipe commands
Administrators can now cancel accidental Device Wipe or Enterprise Wipe commands that are still queued and have not yet reached the device. A new Cancel Wipe action in the device details page helps prevent unintended data loss, and keeps devices safely enrolled in Workspace ONE UEM. For more information, see Device Actions.
Improved enrollment failure visibility and troubleshooting
Enrollment failures caused by administrator configured enrollment restrictions now surface clear, user-friendly error messages that identify the specific restriction blocking enrollment. Detailed events are logged in the console to help administrators quickly diagnose issues, and enable faster remediation. For more information, see Troubleshoot Restricted Devices.
Android Management
Support for remotely managing eSIMs (Custom DPC)
Workspace ONE UEM now allows administrators to remotely manage embedded SIMs (eSIMs) on Android devices managed using Custom DPC. Individual eSIMs can be pushed to devices through the Workspace ONE UEM Console, and administrators can scale up deployments using the Workspace ONE UEM REST API. In addition, Workspace ONE UEM now reports whether a SIM is physical or embedded and categorize eSIMs as managed or unmanaged. Requires Android Intelligent Hub 26.02. For more information, see Supported Android Device Commands by Enrollment Mode
View and monitor multiple SIMs in Device Details (Custom DPC)
Workspace ONE UEM now lets administrators see multiple SIMs on dual-SIM and eSIM-capable devices, so you’re no longer limited to just the primary SIM slot. For devices managed using Custom DPC, information for multiple SIMs can be viewed under Device Details > Network. In addition, SIMs in Device Details > Network are categorized as managed or unmanaged. The Workspace ONE UEM REST API will now also return details for multiple SIMs. Requires Android Intelligent Hub 26.02.
Optimized device communication with separated Status and Command handling
We have improved communication between Intelligent Hub and the Workspace ONE UEM Console by separating the device heartbeat from command processing. The device heartbeat is a summary status update that communicates critical information, such as the IP address and whether the device is compromised, at a higher frequency. This makes the system more efficient while keeping important details, such as device location and IP address, current. Administrators can now set different values for Heartbeat Interval and Check-in Interval in the Android Intelligent Hub settings page. Requires Android Intelligent Hub 25.08.
MAC Address Randomization Control (Custom DPC)
You can now disable MAC Randomization for Wi-Fi configurations managed through Workspace ONE UEM. A MAC Address Randomization setting has been added to the Android Custom DPC Wi-Fi profile payload. When you set this field to Hardware, Android uses the device’s hardware MAC Address when connecting to the network. Requires Android Intelligent Hub 25.10. For more information, see Android Device Management
New management features for AMAPI
We have expanded AMAPI support to provide coverage of new Android management policies. These policies are added to Android AMAPI profiles.
- Screen and Display (Android 15+): You now have more precise control over screen timeout and brightness, including the option to lock brightness at a fixed level on Corporate-Owned, Personally Enabled devices.
- Private Spaces (Android 15+): You can now prevent users from enabling Private Spaces in the personal profile on Corporate Owned Personally Enabled devices.
- Content Protection Policy (Android 15+): You can now control whether Google Play Protect can use real-time scanning to detect deceptive apps.
- Circle-to-Search (Android 15+): You can now disable the Circle-to-Search feature in the work profile.
- App Functions (Android 16+): You can now prevent apps in the Work Profile from exposing functions to other apps, such as assistant applications, for cross-app orchestration. You may also prevent only personal apps from accessing functions for Work Profile apps.
- Allow System Credentials Providers (Android 14+): You can now control whether system applications can act as credentials providers, storing passcodes and other credentials.
- Network Slicing Support: You can now set default network slices and define application-specific policies to prioritize business-critical traffic.
- Multiple trusted CAs in WOA2 Enterprise Wi-Fi profiles: You can now select multiple root certificates in the Wi-Fi profile, following the pattern used in Custom DPC. This provides greater flexibility and supports migration of network server certificates to new vendors.
- Wi-Fi Roaming (Android 15+): You can now configure device roaming between access points while connected to Wi-Fi networks. For a specific network, you can enable more aggressive roaming to prioritize signal strength over battery consumption. Supported on Corporate-Owned, Personally Enabled devices.
- More Device Connectivity Controls: You can now block outgoing Bluetooth connections, prevent users from modifying VPN settings, block mounting of physical storage media, and disable printing.
Android Management (AMAPI) Enhancements for COPE Mode
This release includes various features and UI enhancements to ensure that Android devices enrolled in COPE mode using AMAPI provide the same core functionality. These updates include:
-
Preserve Factory Reset Protection on Wipe: Administrators now have greater control during the device wipe process. If an Enterprise Factory Reset Protection profile is assigned to the device, you can now choose to preserve it when wiping the device from Workspace ONE UEM. By preserving this configuration, you can prevent unauthorized users from setting up the device after the factory reset. This helps organizations prevent loss of corporate-owned devices.
-
Management Source Filtering: We’ve updated the Devices List View with new filtering options to help you better manage diverse Android fleets:
- The new Android Management Source filter allows you to quickly distinguish between devices managed via AMAPI versus Custom DPC.
- The existing Android Management filter has been renamed to Android Management Mode.
Improved Supportability and Resilience for Android Management API (AMAPI)
This release includes the following improvements to prevent and more easily remediate issues affecting AMAPI-managed devices:
- Enhanced Query: The Query action will now retrieve the latest information that AMAPI has for the managed device. While AMAPI normally notifies Workspace ONE UEM whenever new information about the device is available, the enhanced Query action provides a level of redundancy for cases where AMAPI notifications fail.
- AMAPI Log Collection: The Request Device Log action now supports an AMAPI option. Workspace ONE UEM fetches the currently applied policies and latest device information from AMAPI. The output is stored in a log file under Device Details > More > Attachments and speeds up the investigation and resolution of issues.
- Resilience to Intelligent Hub Connectivity Issues: In cases where Intelligent Hub is unable to communicate with Workspace ONE UEM, policies and applications can still be installed and removed from the device. When Workspace ONE UEM receives new device state information from AMAPI, Workspace ONE UEM now treats this as a “check-in” and brings the device in sync with the resources assigned by the administrator.
Conditional Access
Global Sign-in/Sign-out for Workspace ONE UEM iOS-shared devices using Entra ID Shared Device Mode
This Limited Availability feature streamlines the user experience for front-line workers on shared iOS devices. It enables seamless single sign-on (SSO) to Intelligent Hub, Microsoft apps, and other enterprise applications that support Microsoft Authentication Library (MSAL) and Shared Device Mode. Additionally, it includes support for Global Sign-Out functionality, which clears cached authorization tokens on the device, enhancing security by ensuring the user’s Entra ID credentials are cleared from all these apps with a single action.
Content Management
Advanced DLP Controls for user repository image uploads
Administrators now have the option to enable image uploads only from the camera for user repositories. This feature allows end users to upload photos directly from their camera while preventing access to their photo albums.
- Users can upload photos only from the camera.
- Users cannot upload photos from the gallery.
- Users cannot import photos into their repositories.
Azure File Share integration for Workspace ONE Content
Workspace ONE Content users can now access files and folders from the Azure File Share repository hosted in the Unified Endpoint Management (UEM) system. Users can now access the Azure File Share repository, download and upload files, and create new folders.
User Notification for newly pushed content from UEM
Administrators can now alert users about new content from the Unified Endpoint Management (UEM) system. This feature improves user engagement and ensures the timely delivery of important updates.
- Users can navigate directly to the location of the new content by tapping on the notification.
- Notifications are grouped together when the user receives multiple new content items at the same time.
- Notification is received on the app for the new content that is added after the app is installed or the initial synchronization is complete.
Freestyle Orchestrator
Send near real-time workflow step status samples for Windows
We have reduced the minimum workflow step status reporting interval with Limited Availability. Administrators can now configure their selective workflow step statuses to be sent every 5 minutes. To have this feature enabled for your environment, contact your Account team.
Streamline onboarding entitlements in workflows for macOS
Onboarding entitlements within workflows are now supported on macOS. This feature allows administrators to prioritize resources essential for onboarding, which take precedence over other resource assignments.
macOS workflow logging enhancements
We have converted our structured logs to an unstructured format so that they can be read in plain text.
iOS Management
Enhanced Declarative Device Management (DDM) for iOS
-
Status Items: DDM now automatically subscribes to critical device status items, providing continuous monitoring without administrator intervention. The following status items are now subscribed to by default:
- Battery Health: Current battery condition
- Passcode Presence: Whether a device passcode is configured
- Passcode Compliance: Passcode meets organizational security requirements
- Model Marketing Name: Device model identifier for inventory management
-
New Apple DDM configuration: Safari bookmarks
Workspace ONE UEM now supports the Apple Declarative Device Managementsafari.bookmarksconfiguration for iOS. Administrators can deploy and manage curated Safari bookmark sets on iPhone and iPad using declarative profiles.
Enhanced Smart Group filter criteria for iOS devices
Enhanced Smart Group filter criteria now includes 'Non-Supervised' and 'User Enrolled' enrollment categories for Apple devices, enabling more precise targeting and streamlined device management. For more information, see Smart Groups for iOS Devices.
Streamlined ADE Setup, Restore, and App Controls for iOS
- Skip New Setup Assistant Screens: ADE profiles now include options to skip additional Setup Assistant panes such as Camera Control, Keyboard setup, language & voice selection, and age‑based safety screens. This helps administrators deliver a fully guided, zero‑touch out‑of‑box experience for users while preventing them from getting stuck on new iOS setup flows.
- More Reliable Enrollment After Backup Restore: A new ADE profile option ensures devices restored from iCloud or computer backups always apply the current enrollment profile from Omnissa UEM instead of using an older profile stored in the backup. This reduces enrollment failures and configuration drift when IT regularly re-provisions devices or recycles them between users.
- Exceptions for App Rating Restrictions: Administrators can now define exceptions for specific apps when enforcing app rating restrictions. This makes it possible to allow critical business or clinical apps that have higher age ratings, while still applying stricter content controls to the rest of the App Store.
Simplified identity-based enrollments for Apple devices
We have added support for hosting the Apple well-known service discovery file on the Workspace ONE UEM server. Administrators can enable Account‑Driven User Enrollment from the console and automatically use a UEM‑hosted URL in Apple Business Manager, eliminating the need to host the file on their own domain and removing a key barrier to adopting identity-based enrollment.
VPP v2 Support for Workspace ONE UEM Deployments
- Scalability and Performance Improvements: VPP v2 APIs are asynchronous, enabling more scalable and performant app deployments, especially for large environments (e.g., publishing apps to 100K devices). This reduces bottlenecks and improves reliability compared to the synchronous v1 APIs.
- Improved Reliability: Asynchronous event handling with notification subscriptions ensures more reliable status tracking for app installs and other actions.
- Seamless Migration: Migration from v1 to v2 is supported without license loss or disruption, and existing workflows remain functional post-migration.
macOS Management
Dynamic hardware seeding - Enroll and manage any new macOS device as soon as you get it
We’ve automated the addition and support of new macOS models in Workspace ONE UEM. When Apple releases a new macOS device with an unrecognized model ID, you can enroll it successfully. In addition, other areas of Workspace ONE UEM that rely on this information will automatically update to use the device’s model ID. Manual seed scripts for macOS model IDs are no longer required.
Enhanced Declarative Device Management (DDM) for macOS
-
Status Items: DDM now automatically subscribes to critical device status items, collects device attributes, and provides continuous monitoring without administrator intervention. The following status items are now subscribed to by default:
- Battery Health: Current battery condition
- Model Marketing Name: Device model identifier for inventory management
-
New Apple DDM configuration: Safari bookmarks
Workspace ONE UEM now supports the Apple Declarative Device Managementsafari.bookmarksconfiguration for macOS. Admins can manage Safari bookmark collections via declarative profiles.
Enhanced Smart Group filter criteria for macOS devices
Enhanced Smart Group filter criteria now includes 'Non-Supervised' and 'User Enrolled' enrollment categories for Apple devices, enabling more precise targeting and streamlined device management. For more information, see Smart Groups for macOS Devices.
VPP v2 Support for Workspace ONE UEM Deployments
- Scalability and Performance Improvements: VPP v2 APIs are asynchronous, enabling more scalable and performant app deployments, especially for large environments (e.g., publishing apps to 100K devices). This reduces bottlenecks and improves reliability compared to the synchronous v1 APIs.
- Improved Reliability: Asynchronous event handling with notification subscriptions ensures more reliable status tracking for app installs and other actions.
- Seamless Migration: Migration from v1 to v2 is supported without license loss or disruption, and existing workflows remain functional post-migration.
Resource Management
Application blob access via APIs
We are introducing enhanced API support for accessing application blobs, making it easier to build scalable and automation-driven use cases around application management. With this update, the API apps/internal/{applicationId} now exposes blob UUIDs for application icons and packages. These blob UUIDs can be used with API blobs/downloadblob/{uuid} to directly retrieve the corresponding blobs. For detailed guidance on implementing these APIs, refer to API documentation.
Phased deployment for internal Apps
You can now deploy Internal apps to devices gradually in phases, empowering you to identify and mitigate potential risks early before they impact a broader set of devices. With this feature, you can target specific Assignment groups in each phase and choose how phases progress - manually or automatically. Additionally, you can track deployment at the phase level with detailed insights ensuring safer and more predictable deployments. This feature is currently available under Limited Availability and requires the enablement of new modern Console experience. If you’d like to participate in the limited rollout, contact your Account team.
Real-time profile assignment status in Device Details
You can now view profile assignment status in real-time within the Profiles tab of a Device Details view. This enhancement provides immediate visibility into profile assignment status, reducing troubleshooting delays and helping you act faster. This capability is currently in Limited Availability. To have it enabled for your environment, contact your account team.
Installation metrics now retained upon Resource and Smart group updates
When assignment or payload updates are made to apps and profiles, or when their assigned Smart groups are modified and published, installation metrics achieved so far will now be retained and remain visible on the Deployment Tracking page as Currently assigned. It denotes all devices having a confirmed assignment to an app or profile at any given time. This enhancement ensures continuous visibility of installation metrics, even as you update assignments. For more information, see Tracking and Monitoring Deployment of Applications and Profiles (Modernized).
Faster resource delivery for larger device populations
Faster Resource Delivery now supports larger device populations. It triggers when new apps or profiles are published, assignments or payloads are updated, or Smart Group rules change—provided the number of impacted devices is below a defined threshold. Devices impacted by these updates will check in immediately and install or remove necessary resources instead of waiting for the standard check-in cycle. You can also lower the default impacted‑device threshold that triggers Faster Resource Delivery, allowing you to align it with your network or testing needs. These enhancements are Generally Available from this version. If you want to reduce the threshold in your tenant, contact the Support team. For more information, see Accelerating Resource Delivery with Fast Lane Deployment.
Impact Preview on Smart Group Edit
Administrators now receive a warning about how devices will be affected when they edit Smart Groups that have assignments. The assignment preview screen displays how many devices will be added or removed, helping prevent unintended resource deployment or removal and reducing risk from large scale configuration changes. For more information, see Edit a Smart Group.
Enhanced Smart Group Assignment Visibility
The Smart Group assignment preview and list views now correctly display additional resource types, including Device Updates, Workflows, Time Windows, and Baselines.
Enhanced Tag APIs with UUID Support
Tag management APIs have been enhanced to support UUIDs, improving reliability and interoperability across integrations. Administrators can create, update, delete, and assign tags to devices, as well as search devices using the new UUID based APIs.
User Management
Enhancements to User Authentication and Access Management
-
Password policies for Basic Administrators: You can now configure password and authentication policies that meet your organization's needs, at a Customer-type or Partner-type Organization Group to control password complexity, validity, recovery questions, maximum invalid login attempts, etc. For more information, see Password Policy.
-
Enhanced audit capabilities for changes to enrollment users: You can now view audit information such as Created and Last Modified timestamps, administrator accounts associated with user creation and modification, in the User Details page in the console. These details are also available in the GET user v2 APIs -
/users/searchand/users/{uuid}. The audit information also includes high level information of the workflow and service through which the last change was triggered for the account. Additionally, User Modified events published to Console Events now show old and new values for Email Address, First Name, Last Name, and Active/Inactive status, when these attributes are modified for a user. -
Enhanced audit capabilities for changes to administrator accounts: You can now view audit information such as Created and Last Modified timestamps, administrator account authorizing the administrator creation and modification, in the GET admins v2 APIs -
/admins/searchand/admins/{uuid}. The audit information also includes high level information about the workflow and service through which the last change was triggered for the account -
Enrollment User Password settings: Password settings for Basic Enrollment Users have been enhanced to provide additional controls such as Password Expiration Period, Password Expiration Notification Period, Maximum Invalid Login Attempts, and Lockout Period. The settings apply to Basic users only, allowing security and password controls for Directory users to be controlled directly by your Identity Provider or on-premise directory. This is currently a Technical Preview feature.
-
Improved resiliency in automated user group sync: The automated (scheduled) group synchronization process for LDAP integrations will no longer be terminated if multiple user groups are not found in your directory. If a group is missing, Auto Sync, Auto Merge, and Add Group Members Automatically will be disabled for that group, preventing it from being included in future sync cycles. Additionally, a Console Event (User group not found. Auto sync disabled) will be generated, allowing you to identify the affected groups and address the issues before re-enabling Auto Sync and the other features for them. If a group is no longer present in your directory, you can delete it from Workspace ONE UEM. Previously, the group sync process for an organization group was stopped if three or more groups could not be located in the directory.
Windows Management
Enhanced application inventory and reporting for Windows devices
Workspace ONE now provides an enhanced application inventory, ensuring consistent and accurate application reporting across platforms.
- Unified Application Sampling: A new sampling framework that collects application data consistently across Intelligent Hub, UEM, and DEX.
- Comprehensive App Coverage: All installed software, including Win32 and .appx applications, is now reported.
- Expanded Application Attributes: Inventory reporting now includes display name, version, publisher, install date, install location, estimated size, language, uninstall strings, and data source (user or device registry, 32-bit or 64-bit).
For more information, see View Device Application Inventory.
Streamline application management with Enterprise Application Repository v2 (EARv2)
This feature simplifies how administrators discover, configure, and deploy over 8500 enterprise applications for Windows devices in Workspace ONE UEM. The new Enterprise Application Repository (EAR) provides a centralized, secure source of pre-vetted applications that can be managed directly from the UEM Console, minimizing manual packaging and configuration.
- Centralized Application Catalog: Easily navigate, search, and add trusted applications from the Enterprise Application Repository directly from the UEM Console.
- Automated Configuration: The repository automatically generates commands to install, uninstall, and detect, reducing manual setup and improving consistency.
- Existing App Linking: Existing (manually uploaded) applications can now be linked to the repository for automatic version tracking and update visibility.
- Seamless Updates: Initiate updates directly from the UEM Console, facilitating continuous application maintenance with minimal effort.
For more information, see Add Windows applications from the Enterprise Application Repository.
Automate Windows App Patching with Enterprise Application Repository (EARv2)
Workspace ONE UEM now supports automated patching of over 8500 applications imported from the Enterprise Application Repository (EARv2) or existing applications where the repository ID was added. This new capability allows you to configure update schedules to ensure that applications remain current without manual intervention.
- Auto-Update During App Addition: Enable automatic updates when adding an application from EARv2.
- Auto-Update for existing applications: Add the repository ID to existing applications and enable the same auto-update functionality as for EAR added applications.
- Flexible Scheduling Options: Configure updates to run daily, weekly or monthly based on organizational requirements.
- Automatic Version Import: When a newer version is available, Workspace ONE UEM automatically imports and configures the update using repository defaults.
Hub Managed Enrollment: Next-Gen Windows management with Intelligent Hub managed mode
Workspace ONE UEM is introducing a new Windows enrollment mode called Hub Managed, that delivers full Intelligent Hub–based management for devices that cannot use native OMADM management or are transitioning from another OMADM-based management tool.
With Hub Managed mode, IT administrators can:
-
Fully manage Windows devices enrolled only via Intelligent Hub
- Deliver and manage apps (via Software Distribution Agent aka SFD)
- Assign and enforce Hub-targeted profiles and ADMX based profiles
- Use workflows to orchestrate multi-step deployments
- Leverage baselines, sensors, and scripts for configuration, monitoring, and remediation
- Continue to use Tunnel profiles across all enrollment types
-
Start with Intelligent Hub Managed for new enrollments via OG based settings
- Enable Intelligent Hub managed mode for brand new enrollments via the OG based settings located within All Settings > Devices & Users > General > Enrollment > Management mode.
- Use existing provisioning methods like Dropship or Silent enrollment.
Note: OOBE like Autopilot is not supported on Hub Managed mode due to its dependency on OMADM.
-
Step up from Registered to Hub Managed without re-enrollment
- For existing Hub Registered devices, when ready, perform a server-side step up to Hub Managed
- Devices automatically gain full Hub-based management with no end-user re-enrollment
-
Expand Hub Catalog capabilities
- End users on Hub Managed devices can install or uninstall applications and execute workflows or scripts on demand directly from the Intelligent Hub catalog, similar to Full MDM devices.
Key Values
-
More flexibility in Windows management. Choose from the following options:
- Hub Registered: Limited management that offers support for Scripts and Sensors, and can be used along with our Digital Employee Experience solution.
- Hub Managed: Full Hub-driven management without requiring OMADM enrollment.
- Full MDM: Combined native OMADM and Hub management. This is existing functionality.
-
Modern management without native MDM dependency
Ideal for environments migrating from another OMADM-based management tool to Workspace ONE, providing flexibility to transition workloads at your own pace without a disruptive full device migration. This is also ideal where devices are OMADM-managed by another MDM, OMADM management is not desired or unavailable, or when still gaining rich app, profile, workflow, and automation capabilities from Workspace ONE UEM.
-
Simplified admin experience
- Clear, mode-aware UI within UEM Device details: Tabs and actions adapt based on enrollment type (e.g., Compliance, Workflows, Apps, Baselines, Scripts, Sensors, Updates are available for Hub Managed).
- Consistent resource targeting rules so OMADM-only content continues to route only to Full MDM devices, avoiding conflicts.
-
License-aware enablement
- Hub Managed is available to customers licensed for WS1 Standard, Advanced, Enterprise, Desktop Essentials, or UEM Essentials.
For more information on Hub Managed mode, see Intelligent Hub Managed Mode Enrollment.
Enhancements to Drop Ship Provisioning for a better administrator experience
We have enhanced the Drop Ship Provisioning (DSP) administrator experience through enhanced automation and better record management.
- Bulk DSP Online Registration API: Added an API to support bulk Drop Ship Provisioning (DSP) Online registration operations.
- Improved Device Record Management: Add, edit, and remove flows are streamlined. Changes to DSP device records sync automatically, removing the need for administrators to click SYNC after each operation and reducing duplicate device records.
Note: The SYNC button remains available in the Console for troubleshooting purposes. - New Column, Last Modified On: Added a Last Modified On column to display the date and time of changes to each device record.
Note: The Last Sync field has been deprecated, as Last Modified On provides more accurate and granular information. - Enhanced DSP Enablement Flow at the Organization Group (OG) Level: Enabling DSP now checks prerequisites and notifies administrators if requirements are not met.
Additionally, two critical issues were resolved: intermittent provisioning issues due to user detection problems and duplicate device registrations caused by case-sensitive serial number handling.
Granular application retention control for Windows devices
Administrators now have the ability to manage, at both the application and assignment levels, whether Windows applications are kept or removed when a device is enterprise wiped or when an application is unassigned. This capability applies to Windows desktop and Windows Server devices, providing IT departments with much finer control compared to the previous all-or-nothing global approach.
With two new assignment-level options, Keep app on enterprise wipe and Keep app on unassignment, you can choose to:
- Always keep critical apps (e.g. security tools, VPN, firewall) on wipe or unassignment
- Automatically remove business or sensitive apps when devices are lost, stolen, or unenrolled
- Reduce end-user disruption when apps are accidentally unassigned, and speed up recovery after troubleshooting wipes by leaving large apps in place.
For more information, see Assign Applications to your Windows Device.
Support for app upload via link
Workspace ONE UEM now allows administrators to add internal applications as external links without requiring UEM to download, store, or distribute the application binaries. Administrators can add internal applications using a URL-based link instead of uploading binaries to UEM. For more information, see Add Internal Applications as a Link.
Access Application deployment logs within Apps tab in Device Details
You can now view the last deployment log for each managed Windows application directly from the device’s details page in the UEM Console. A new Log column on the Device Details > Apps > Managed Apps tab surfaces a View link for managed apps, opening the latest deployment log inline in the Console.
With App Last Deployment Logs, administrators can now:
- See exactly what happened in the last deployment of a specific app on a specific Windows device, without pulling full device logs
- Reduce time-to-resolution for deployment issues by going straight to the relevant app log lines
- Improve support efficiency by giving teams quick, targeted visibility into app installation problems
- Minimize impact on infrastructure, since logs are uploaded on error or on-demand rather than through bulk log collections.
For more information, see View Device Application Inventory.
Administrative Template (ADMX) with profiles
Workspace ONE UEM now supports Administrative Template (ADMX), providing a unified and scalable way to manage Windows policies across the device fleet. With this feature, you can manage all administrative templates for Windows 10, Windows 11, and Windows Server directly from the UEM Console. You are provided with Pre-Uploaded ADMX templates for common applications, including those for Microsoft Office, Omnissa Horizon, Google Chrome, Mozilla Firefox, and more. For more information, see Windows ADMX Profiles.
Support for Baselines in machine mode when there is no active user logged in
Previously, Baselines were applied and refreshed only when an active Windows user session was present. With this release, both device-level and user-level Baselines are now applied and re-applied regardless of whether a user is logged in. This enhancement occurs automatically—no additional configuration is required.
- When no user is logged in, only device-level Baselines take effect.
- User-level Baselines are applied but become effective once an end user signs in.
Key features include:
- Device-level Baseline Application: Baselines are now applied and refreshed even when no Windows user session is active.
- Baseline Conflict Resolution: When multiple Baselines target the same device, they are applied in order of creation date—newest wins.
- A new Install Order column indicates precedence.
Note: Avoid creating multiple, overlapping Baselines for the same device to prevent unintended configuration overrides.
For more information, see Device-Level Baseline Policy Enforcement During No-User Session.
Fastlane support for Sensors
This enhancement enables administrators to receive immediate device notifications upon sensor assignment and provides real-time access to sensor data for up to 20,000 devices.
- Sensor Integration: Device notifications are now triggered immediately upon sensor assignment, ensuring timely data availability.
- Real-Time Data Access: Administrators can retrieve sensor data as soon as it is assigned, improving responsiveness and operational efficiency.
Dashboard in UEM to track Intelligent Hub/SFD version across managed devices
The Workspace ONE Agent Updates dashboard delivers near real-time visibility into Intelligent Hub and SFD agent versions across your device fleet. Toggle between agents, view version distribution through visual charts, drill down to device lists, and apply bulk tags for targeted remediation—all from a single dashboard in the UEM Console. With the new dashboard, you can now:
- Centralize agent version tracking directly in the UEM Console
- Speed up identification of outdated Hub/SFD versions across your fleet
- Reduce rollout risk by making it easy to find devices that missed or lagged an update
- Improve remediation workflows by letting you tag out-of-date devices directly from the dashboard for follow-up actions (for example, assigning a Smart Group or triggering upgrade workflows).
For more information, see Workspace ONE Agent Dashboard in Workspace ONE UEM Console.
Real-time statuses for on-demand scripts and workflows
End users can now see real-time status updates for on-demand scripts and workflows that are launched from the Intelligent Hub App Catalog on Windows. Instead of waiting for the next sync or manually refresh, users immediately see whether a script or workflow is running, has failed, or has completed.
What’s changed for on-demand scripts and workflows started from the App Catalog on Windows:
-
Real-time status display
- Statuses such as In-progress, Failed, and Completed are now shown directly in the App Catalog tile or action area.
- Status is updated live as the Windows agent reports progress back to Hub.
For more information, see Real-Time Execution Status for On-Demand Scripts and Workflows.
Option to keep Hub installed after unenrollment
A new admin-configurable setting allows Hub to remain installed when a device is unenrolled. This capability supports Horizon workflows where UEM is used to configure VM Templates (Gold Images). IT administrators can now easily enroll their templates for staging and then enroll clones for day-two management without reinstalling the Hub. For more information, see Managed Resources Profile.
Windows Server: Support for key Workspace ONE profiles
We are extending Workspace ONE UEM profile support to Windows Server devices as part of our broader Windows Server management initiative. Administrators can now use a selected set of existing Windows profiles with supported Windows Server versions, including:
- Certificate profiles for installing certificates on servers (SCEP not supported)
- Custom Settings profiles for applying advanced agent configuration
- Managed Resources profiles to control whether Workspace ONE resources are kept or removed
Profiles are created and managed through the existing Windows legacy profile user interface, with a new option to target either Windows desktop or Windows Server. Windows desktop behavior is unchanged. This enhancement allows you to reuse familiar Windows profile workflows to configure both desktops and servers, helping standardize management of your Windows estate while we continue to expand Windows Server profile coverage in future releases. For more information, see Windows Server Profiles.
Intel C2C client observability and troubleshooting improvement
-
Dedicated C2C Logging:
- C2C events are now separated into a dedicated log file, ensuring administrators can quickly locate and analyze relevant logs without filtering through unrelated data.
- Enhanced log details provide deeper visibility into driver versions, service statuses, and client-side operations, improving diagnostic accuracy.
-
Client-Side Design Improvements: The activation and checking of the AMT interface has been revised and improved. For more information, see Intel Chip to Cloud Log Files.
BIOS profile - Support for new Signer of Dell Trusted Devices
We have updated the BIOS verification workflow in Workspace ONE Intelligent Hub for Windows devices that use Dell Trusted Devices. Dell has deprecated the previous BIOS check method in recent agent versions. To ensure continuity, Intelligent Hub now uses Dell’s latest, officially supported integration to retrieve BIOS verification results and report them into UEM compliance as before. This change restores and future-proofs BIOS integrity reporting for supported Dell Trusted Device agent versions, with no configuration changes required for administrators.
Enhanced reliability for Windows Hub auto-upgrades with Background Downloads
The Windows Hub now uses Windows Background Intelligent Transfer Service (BITS) to download new versions of the Hub when performing auto-upgrades from UEM. BITS is a Windows-native background download service designed to be resilient to network issues and device restarts.
- Fewer failed upgrades: If the network drops or the device restarts during an upgrade, the Hub download can now resume from where it left off instead of starting over.
- More efficient bandwidth use: Resume capability minimizes repeated full downloads on unstable connections.
- More reliable rollouts at scale: Large fleets and remote devices are less likely to be left on older Hub versions due to transient network problems.
When a new Hub version is available from UEM, Hub will use BITS to download the installer in the background. If BITS isn’t available on the device or repeatedly fails, Hub will automatically fall back to the standard HTTP download method to ensure the upgrade can still complete.
Notes:
- No configuration change is required for existing deployments.
- The feature is enabled by default for Hub for Windows auto upgrades initiated from UEM.
- Existing auto-upgrade policies and workflows continue to work as before; this change is purely about making the underlying download process more robust.
Windows native enrollment: Auto-Move devices to specified Organization Group (OG) via allowlist
Administrators can now assign a target Organization Group while creating allowlist records for Windows devices. Upon enrollment, devices automatically move to the specified OG, streamlining device management without requiring prior user association.
Rule-Based Privilege Elevation
Workspace ONE UEM Enterprise licenses now include Privilege Elevation profiles, delivering advanced rule-based elevation capabilities. This profile allows administrators to define Privilege Elevation rules based on path, hash, publisher, and additional criteria to provide more granular control over elevated actions.
Resolved Issues
Admin Experience
-
FCA-210698: Incorrect Exception seen when API returns a 400 Bad Request for some scenarios.
-
FCA-210837: Permission for the Diagnostics APIs doesn't appear in Admin Role View.
-
FCA-211319: Device Wipe Log report is empty when exporting from Reports section.
-
FCA-211387: Admin password reset emails are not sent.
-
FCA-211419: Android devices enrolled via SMS-based one-time links fail to auto-populate the Server URL and Group ID in Intelligent Hub.
Android Management
-
AGGL-18684: Android device is included in the smart group, but some of the apps are not assigned on staging enrolment.
-
AGGL-19052: Using UserSmimeEncryption lookup value expected to resolve to P12 certificate data within Samsung KSP app config does not work.
-
AGGL-19412: Outdated settings shown when viewing ChromeOS Credentials Profiles.
Core Platform
-
CRSVC-65637: An error occurs when viewing device certificates page on Console.
-
CRSVC-66140: Conditional Access Logs show Enrollment Status as NA instead of Unmanaged.
-
CRSVC-66297: Compliance status update is not sent to the Conditional Access partner when the compliance policy is unassigned.
-
CRSVC-66301: Internal app install for some iOS devices is showing an error of "App Install Blocked".
-
CRSVC-66480: Resource removal blocked due to Compliance upon Android device checkout.
-
CRSVC-66654: Inconsistency in the "Break MDM" event notification impacting audit and integration workflows
-
CRSVC-66851: Devices no longer get added to compliance targets when they're not part of the assigned group.
-
CRSVC-66733: Logging Server Failure notification not sent to Admins with conflicting Roles and Usernames can be cached incorrectly.
-
CRSVC-67416: Resource delivery blocked when compliance policy with Block/Remove action for specific profiles is pending evaluation.
-
CRSVC-68243: Certificate Profile option in Certificate Template does not retain setting after it is saved and reopened.
-
CRSVC-70582: Compliance evaluation is not happening after Tag change when Smart Groups based on the Tag are not assigned to any policies.
-
CRSVC-71133: Resolved scenario where profiles using SCEP certificates may not install correctly for newly enrolled MacOS devices.
-
CRSVC-71542: Compliance Install or Block profile actions are not reverted when device becomes Compliant.
iOS Management
-
AAPP-19829: Shared iPads for Business experience delays in resource delivery when switching users.
-
AAPP-19914: Workspace ONE UEM Console inherit setting blocked for Apple > SCEP.
-
AAPP-20190: Incorrect calculation of allocated and redeemed VPP counts, resulting in a negative unallocated count.
-
AAPP-21229: Critical VPP apps are getting removed from iPads.
-
AAPP-20869: DDM profile Account:Exchange config does not honor User Identifier asset on iOS device.
Freestyle Orchestrator
- FS-4749: Replaced a scheduler so that workflow step timeouts are more reliable, preventing the step from becoming stuck in progress/failed.
Resource Management
-
ARES-34004: Cannot save internal app assignments after associated workflow is deleted or Smart Group is removed.
-
ARES-34023: Can't remove the profile from the list of available profiles on the device.
-
ARES-34111: System apps treated as managed, triggering compliance policies that mark the device as non-compliant.
-
ARES-34117: Deleting Product provisioned app via API uninstalls it from devices.
-
ARES-34443: Admin occasionally unable to save assignments for Android Internal Apps.
-
ARES-34459: Modified profile has no corresponding entries in the Console Events to verify the action.
-
ARES-34502: Error 'Something unexpected happened' is received while exporting App log.
-
ARES-34661: Removing Smart Group from profile assignments may remove the profile from other assigned Smart Groups.
-
ARES-34664: 'Installed Date' column is blank in Profile Details by Device report.
-
ARES-34857:'Failed to save profile' error is received sometimes while publishing a profile whose payload has not been updated.
-
ARES-34947: Certificate data is incorrectly cross-utilised while creating a macOS Credentials profile.
-
ARES-36784: iPhones not clearing pascode on device check in for shared devices.
User Management
-
UM-10204: Device Manager user can access the user Batch details.
-
UM-10746: User batch import does not trim leading or trailing whitespaces in user attributes.
Windows Management
-
AMST-44385: App removal failing instantly for a Windows internal application.
-
AMST-44769: Windows Autopilot enrollment stuck at OOBE "Setting up Work or School" Screen after patch 24 upgrade.
-
AMST-45025: "Device Re-assignment Failed" error prompt shown when logging in using a different user on a Windows Machine.
-
AMST-45224: Changes made to “Retry Count, Retry Interval, Install Timeout” for Windows dependency Application "Deployment Options" are not retained.
-
AMST-45408: Windows Device Reassignment is failing with HybridAD setup.
-
AMST-45591: VPN profile failing to install on devices; seems isolated to devices where profile was previously installed.
Patch Resolved Issues
Patch 1
-
UM-10484: User Search option in Add Device Registration screen permits search for empty string.
-
MACOS-6719: macOS Advanced Security Control Profile - Restriction for multiple apps not applying properly.
-
MACOS-6594: Screensaver on Smart Card removal option not saving correctly.
-
FS-9293: Move database initialization to application startup.
-
FCA-212711: Overlapping checkboxes observed in the Devices table on horizontal scroll.
-
FCA-212558: Ensure user data appears in the device list view when encryption is enabled.
-
ATL-28012: Seed - Machost to canonical release PR2602-1.
-
ATL-27821: Seed Workspace ONE Intelligent Hub v26.02.1 for Windows.
-
AGGL-19335: Cannot set Application Configuration if app has duplicate keys in its schema.
Patch 2
-
PPAT-21050: Unable to save Multi-Factor Authentication settings under UEM console for the Tunnel settings page.
-
CRSVC-71550: Conditional Access Google BeyondCorp Integration - Intermittent failure in status update calls to Google due to e-tag mismatch.
-
CRSVC-71334: Apps and profiles assigned through workflow do not install after unlock on iOS and macOS devices.
-
CMSVC-20830: Smart Group update API fails when Name field is missing.
-
ATL-28161: Seeding SFD 26.2.1 build to UEM 2602 release.
-
ARES-37387: Intelligence workflow not executing on newly enrolled devices after 2602 upgrade.
-
AGGL-20047: ChromeOS certificates not installed if device is powerwashed and immediately re-enrolled.
-
AGGL-19967: UEM re-pushes ChromeOS certificates each time user logs in.
-
AGGL-19954: UEM repeatedly installs certificates on ChromeOS devices.
-
AGGL-19947: ChromeOS Credentials profiles stuck in pending status.
-
AGGL-19913: ChromeOS certificates are not installed on re-enrolled devices.
-
AAPP-21456: Support for OS 26.4 DDM configurations (Intelligence, Keyboard, Siri) and MDM keys (Restrictions, Parental Controls).
-
AAPP-21445: Enable internal visionOS app deployment for Apple Vision Pro.
Patch 3
-
FCA-212784: Ensure user data appears in the Device list view when encryption is enabled.
-
CRSVC-66502: Pin the Customer or Partner OG where BYOK is managed in SaaS.
-
CRSVC-62768: Resolved scenario where autorenewal for SCEP NDES would fail for Windows devices.
-
ATL-28366: Seed Workspace ONE Intelligent Hub v26.02.2 for Windows.
-
ATL-28345: Seeding macOS Hub 26.0.1.1 to UEM 2602.
-
ARES-37111: Door locked displayed when attempting to remove iOS or Mac app from device.
-
AMST-46322: App upload fails with error "No valid file extension found in file link".
-
AMST-46303: Tunnel - Client authentication certificate is not present.
-
AMST-46183: [FedRAMP] docker-local-ws1uem-qe-builds/intel-command-processor.
-
AGGL-20158: Export status shows "Failed" Instead of "Download" after exporting device data in UEM console.
-
AGGL-20113: Deprovisioned Chrome OS devices can still check in and get certificates.
-
AGGL-20026: Application status not updated to "Installed".
-
AGGL-19665: App config screen for an internal app does not show all options for some dropdown settings.
-
AGGL-19606: SDK profile removal fails when Modstack is enabled.
-
AAPP-21334: Support for new OS 26.4 DDM configurations (External Intelligence, Migration Assistant).
-
AAPP-21277: Show Physical memory as “Unavailable” in UEM console for iOS or iPadOS devices reporting ≥ 4GB RAM.
Patch 4
-
SRVMGT-624: UEM Console shows an error while deleting a device.
-
MACOS-6810: If Device reports NotNow for one scheduled sample, next sample is not tried.
-
FS-9064: Sqlite queries executing/evaluating outside of locks will throw exceptions.
-
FCA-212583: Summary page loading when clicked on other tabs in Device Details.
-
ESI-871: Open redirect via callback parameter.
-
CRSVC-66733: Administrator Notification Logic Updated to Allow Notifications for Larger Administrator Counts.
-
ATL-28538: Seed - Machost to canonical release PR2602-4.
-
ARES-32876: Application removal protection triggered despite device threshold not being met within time window causing false alarms
-
AMST-46256: App retention warning message should be shown only for windows device.
-
AMST-46178: Windows devices in registered only mode are not consistently reporting the correct friendly name.
-
AMST-46177: Managed App Name is not displayed correctly.
-
AMST-46121: SCEP sample is queued even when the seeded scep profile installation has failed.
-
AMST-45619: Windows Wi-Fi profile should allow to edit SSID.
-
AMST-43621: Handle the user object identifier not present for windows devices.
-
AAPP-21457: Add new File Provider sync management settings for macOS 26.4.
Patch 5
-
ARES-37118: Automatic progression of phased deployment does not occur for Windows Internal apps
-
FCA-213005: Multiple console pages crash when language is set to Non-English locale.
-
FCA-212910: Clicking on the UEM logo redirects to an undefined error page.
-
FCA-212810: Date picker fails when editing download start, end, and install by fields in Zebra LG OTA Updates.
-
FCA-213345: Incorrect devices scoped for bulk actions performed from the Device List View.
-
CRSVC-73705: Enhanced SCEP auto-renewal logic to support user-based profiles where signed user and enrollment user are not the same.
-
CMCM-191789: Content app on iPad and Android is displaying duplicate of same folders.
-
AMST-46304: Granular level app control UI needs to be migrated to modern-ui.
-
AMST-44384: When ProfileDeliveryAtScaleFeatureFlag is enabled, delete nodes are absent from syncML when resuming.
-
AGGL-20435: Newly enrolled Zebra devices are showing up with the wrong oem info.
Patch 6
-
UM-11073: Enrollment to a child OG fails for basic users in OIS-enabled tenants.
-
MACOS-7043: Deactivation of asset isn't working.
-
FS-8357: Removal of all script triggers within the console are not honored for scripts that have executed on a trigger before.
-
FCA-212924: Canceling pending enterprise wipe command on a device in airplane mode causes the device's enrollment date to update incorrectly in both the UEM console.
-
CRSVC-74796: Accessing the User Sync Failed events in the console results in the error.
-
CMSVC-20840: Improved input validation for OEM and Model ID fields during SmartGroup creation via API.
-
ARES-37278: Incorrect app config delivered to newly enrolled devices assigned to future-dated Internal app assignments.
-
AMST-46752: Dropship Provisioning online gets stuck on random devices.
-
ATL-28839: Seed - Machost to canonical release PR2602-7
-
ARES-37278: Incorrect app config delivered to newly enrolled devices assigned to future-dated Internal app assignments.
-
AMST-46752: Dropship Provisioning online gets stuck on random devices.
-
AMST-46344: Migrate to EAR v2 UI to Mod UI.
-
AMST-46325: During app upload, blob link is not getting saved.
-
AMST-46119: App Install Fail for MSIX app with error "Package depends on a framework that could not be found".
-
AGGL-20395: Certificates tied to a Wi-Fi profile are not populating in the cert fields within the Wi-Fi profile.
-
AAPP-21609: Discrepancy between the pre-enrollment device registration record and the enrolled device details.
Patch 7
-
RUGG-13772: Product status view reports fail to report devices.
-
FCA-212880: Some of the fields are misaligned in the 'Add Assignment' screen.
-
FCA-212377: Send Message action on iOS devices fails to send email from Device List View with an unexpected error.
-
FCA-210931: Update Event Log to display username of admins which triggered bulk actions.
-
CRSVC-75705: Conditional Access registration and status updates may not be sent when Partner-type OG is set as tenant.
-
CRSVC-75370: Update hyperlink to correct public documentation for upload key material.
-
CRSVC-73175: Added status reason to initialized event types in the Device Troubleshooting events.
-
ARES-37360: Android profiles incorrectly displayed as Declarative profiles.
-
AGGL-20483: Fix Android APK parsing crash and improve resource resolution robustness.
-
AGGL-20008: Profile installation status not updated in UEM Console for AMAPI COPE device after Auto assignment.
-
AGGL-19936: AMAPI devices not shown in assignment preview and incorrect app status displayed as "Installed but not Assigned" for Auto Public Apps.
-
AAPP-21692: VPP apps not getting app configuration settings delivered.
Patch 8
-
SINST-176753: Certificate installer Hardening.
-
RUGG-14288: Certificates renewal fails for Android devices published via Product provisioning profiles.
-
RUGG-14238: Searching and sorting products in device details page does not work if the device has more than 50 products.
-
PPAT-21484: Fix Tunnel Exceptions during the profile publish.
-
MACOS-7327: WS1 Assist - 'Remote Assist' button goes away/missing on Hub sync.
-
MACOS-7103: New version of app in child OG is getting created with com.ws1.* identifier incorrectly.
-
FS-9924: Workflows and scripts fail to execute on brownfield macOS devices after upgrading to 2602 or 2604.
-
FCA-213604: Modified the upgrade notification banner to prevent user actions from being blocked on screen.
-
FCA-212660: Devices "extensivesearch" API returns invalid results when using Platform as filter.
-
FCA-212597: Enhanced RequireJS pages to prevent displaying version information.
-
FCA-212214: Updated the default Read-Only Administrator role to include all read permissions.
-
CRSVC-76143: Updated DeviceStatev3 API response to prevent duplicate Device UUID value reporting.
-
ATL-29181: Update macOS Workflowd Package.
-
AMST-47061: Enrollment restrictions now honored during CLI checkout, blocking auto-creation of unapproved user accounts.
-
AMST-47028: Application removed from device even though Keep App After Un-Assignment option is enabled..
-
AMST-46117: Enhance inventoried apps to prevent duplicate display of managed and unmanaged applications in all apps view.
-
AMST-46045: App installed on Hololens is showing as "Not managed" preventing some management functionality.
-
AGGL-20567: Enhance inventoried apps to prevent duplicate display of managed and unmanaged applications in all apps view..
-
AGGL-20378: eSIM actions missing in Device Details and installing eSIM throws an error.
-
AGGL-20112: ChromeOS Wi-Fi profile with credentials payload fails to install.
Patch 9
-
AGGL-20730: Managed App Configs are Corrupted by Hierarchical Key.
-
AAPP-20831: Support app preservation during MDM Migration for iOS or iPadOS.
Patch 10
-
RUGG-14484: Product set remains stuck in processing state, preventing edits.
-
MACOS-7216: Unable to edit the iOS VPN payload for IKEv2 type.
-
FS-10219: A post install script issue may corrupt workflow binaries and prevent workflows from running on macOS devices.
-
FS-10111: Expired internal device credentials may cause workflows to be stuck in progress and prevent new workflows from executing on macOS devices.
-
FS-9762: Event-based scripts run more frequently than expected after device check-in on macOS.
-
FCA-214069: Fixed an issue where editing a profile for an extended period could trigger a session error, interrupting the edit before assignment.
-
CRSVC-73175: Added status reason to initialised event types in Device Troubleshooting events.
-
CRSVC-71788: Certificate count in the Device Details > Summary does not match the data under Device Details > Certificates.
-
ATL-29536: Seed - Machost to canonical release PR2602-10.
-
ATL-29377: Seed Workspace ONE Intelligent Hub version 26.02.3 for Windows.
-
ATL-29297: Seeding SFD 26.2.2 build to Workspace ONE UEM 2602 release.
-
ARES-38352: Mod UI user can see two platform filter options under Profiles.
-
ARES-38095: App and profile list cannot be exported from Device Details.
-
ARES-37562: Multiple apps cannot be configured against Android Restrictions profile setting ‘Allow Apps that can Utilize Widgets’.
-
AMST-47802: Privilege Elevation feature is now part of Workspace ONE Advanced SKU.
-
AMST-46036: Fixed issue with Peer Distribution details sent for apps downloaded through Branch Cache.
-
AMST-43186: New API version available for application creation with multiple processor architectures.
-
AGGL-20450: Improve performance for Android app catalog.
-
AGGL-20395: Certificates tied to a WiFi profile were not populating in the cert fields within the WiFi profile.
-
AGGL-19985: Enrollment Date was not set on Chrome OS device.
-
AAPP-22508: Device updates tab shows 'Not Available' for Apple OS Updates.
-
AAPP-22155: Improve retry logic for VPP v2 calls.
-
AAPP-21301: Intermittent ADE Sync Failures Due to Apple Rate Limiting (HTTP 429).
-
AAPP-20831: Support app preservation during MDM Migration for iOS or iPadOS.
Patch 11
-
UM-11243: Fixed Android enrollment failures with response code 500.
-
UM-11206: User group memberships are updated when enrolling iOS or macOS devices even if Sync User Groups in Real Time is disabled.
-
PPAT-21355: ETag is not updated when the shift status changes.
-
FS-8052: Missing search functionality on workflow details page device status table.
-
FCA-214062: Fixed a display issue on the Freestyle Orchestrator page that blocked workflow naming and creation.
-
FCA-213920: Self-Service Portal (SSP) language selection is unavailable when authenticating through Workspace ONE Access.
-
FCA-213739: Authorization error message is being incorrectly shown on some console screens.
-
CRSVC-74767: Addressed scenario where optional profiles were npt displayed in the devices Profiles tab.
-
ARES-36322: Escape characters added automatically to ADMX Profile payloads.
-
AMST-47779: Manage inclusion of AllowOOBEUpdates node only on supported OS build versions.
-
AMST-46946: Fixed issue in UEM console, where after selecting apps for inclusion in a provisioning package (PPKG), the "NEXT" button becomes greyed out and the app selection on the initial page is lost when navigating back to it.
-
AAPP-21422: Improvements to VPP v2 license management.
-
AAPP-20744: Both actions and commands are generated for iOS profiles.
Patch 12
-
RUGG-14521: Last Seen timestamp is incorrectly updated for devices belonging to smart groups assigned to a product upon product activation.
-
PPAT-22197: meta.gateway empty in managed Tunnel client-config response.
-
PPAT-22044: Performance Improvement for Tunnel allowlist endpoint.
-
FCA-213916: DLV Smart Group filter breaks for smart groups with large manually added device/user lists.
-
FCA-213887: Read-Only administrator accounts and roles are not visible to console admins.
-
ATL-29894: Seed Workspace ONE Intelligent Hub v26.02.4 for Windows.
-
ARES-38312: Profile save fails when assigned to devices with ownership type 'undefined'.
-
ARES-38099: Installed profile shown as removed in Intelligence.
-
ARES-36887: Incorrect installation statuses reported for some profiles in Intelligence.
-
ARES-34956: Uploading a static certificate in a Credential slot in the Credentials profile payload copies validity dates and thumbprint from another slot.
-
AMST-48015: Domain Join Config ignores Base DN config if multiple domains are configured.
-
AGGL-20938: Application ID Resolution for FCM Fails.
-
AGGL-20864: Support Multiple Readers for AWIntegrationResourceSyncQueue.
-
AGGL-20473: Add a separate queue to handle resource sync requests coming from newly enrolled devices.
-
AAPP-22395: Ability to turn off scheduled sample collection (during continued NotNow responses).
Patch 13
-
FCA-212096: Prevent concurrent administrator sessions in Workspace ONE UEM when 'Allow Multiple Sessions' setting under Session Management is disabled.
-
ATL-29672: Seeding SFD 26.2.3 build to UEM 2602 patch release.
-
ARES-39049: Product sent repeatedly to device if app configured to be installed through Product Provisioning is sideloaded by device.
-
ARES-38920: Geofencing area change event is not delivering the right profiles in modern architecture enabled environments.
-
ESI-1241: Fixed an issue where a shared device could remain in a checked-out state after an interrupted check-out, preventing users from logging in until an administrator intervened.
Patch 14
-
SINST-176756: Updated service runtime to .NET 10 for improved performance, security, and long-term support - UEM & CP Services.
-
ATL-30445: Seed - Machost to canonical release PR2602-14.
-
ARES-39224: App uninstalled via Product Provisioning keeps getting repeated uninstall attempts even after the first attempt succeeded.
-
ARES-39062: ‘Save Failed’ error sometimes received while publishing app to thousands of devices and parallelly deleting devices from UEM.
-
AMST-42947: Device Details - WNS Connected Last Seen timestamp is not show in Admin's selected timezone.
-
AAPP-21974: Unable to edit or create iOS VPN profile.
-
AAPP-21302: App assignment shows more devices in the newly added device count while adding a Smart Group.
-
AAPP-21015: {DeviceFriendlyName} value not populated on Enrollment Message.
Known Issues
- VOS-128: When using regular ADE with authentication that expects user credential prompts, Vision Pro devices may fail to complete enrollment. The device may not display the expected authentication prompt and appear to be stuck in the enrollment process.
Workaround: If you require authentication during enrollment, turn on Custom enrollment in your ADE profile. This ensures the authentication prompt displays correctly and enrollment completes successfully.
Release Availability
We strive to deliver high-quality products, and to ensure quality and seamless transitions, we roll out our products in phases. Each rollout may take up to four weeks to accomplish and is delivered in the following phases:
-
Phase 1: Demo, Shared SaaS UATs, and Latest Mode UATs
-
Phase 2: Shared SaaS environments
-
Phase 3: Latest Mode environments
Getting Ready for Major OS Releases
To prepare for the upcoming software updates from major device vendors, read through the Getting Ready for Major OS releases section of the Omnissa Product Documentation.
Documentation
To learn more about Workspace ONE UEM, browse Workspace ONE UEM Documentation.
Localized Content for Omnissa Docs
For details on Omnissa's localization strategy, see the KB article: Announcing Omnissa Localization Support.
Support Contact Information
To receive support, access Omnissa Customer Connect. For information about filing a Support Request in Customer Connect and using Cloud Services Portal, see the KB article here.
Was this page helpful?