Skip to main content

September 2, 2026

Omnissa Workspace ONE UEM Release Notes

We're excited to share the new release of Workspace ONE UEM version 2604! Read on to learn about the new features and improvements in this release.

What's New in this Release

Admin Experience

New Workspace ONE UEM Console experience
Experience a redesigned Workspace ONE UEM console featuring a modern layout and intuitive navigation. This feature is now Generally Available and is enabled as the default console experience. The Organization Group picker is now prominently accessible in the console header, making it easier to switch context across your deployment. For more details, see KB Article.

Improved user detail visibility in Device List View
Administrators can now view accurate user details directly in the Device List View, even when encryption is enabled. Encrypted user detail fields (First Name, Email Address, etc.) previously displayed the placeholder text "Encrypted" and now show the correct user information, while the underlying data remains encrypted in the database.

Enhanced troubleshooting experience using Device Operations tab
The new Device Operations tab provides administrators a unified view of all device actions. This interface combines Legacy Commands and Modern stack actions into one consolidated timeline, allowing users to track operations from initiation to completion. By minimizing context switching, administrators can diagnose issues more quickly and efficiently. For more information, see Device Operations Tab.

Android Management

Mobile Network Slicing Support (Custom DPC)
Android 13+ supports mobile network slicing, enabling Custom DPC EMMs to configure how enterprise apps utilize carrier network resources. You can now assign network slices to specific applications or globally to all work applications. You may also restrict applications to only using the assigned network slice.

Enhanced Screen and Display Controls for Custom DPC
You now have more precise control over screen timeout and brightness, including the option to lock brightness at a fixed level on corporate-owned devices. Minimum OS version varies based on the device management mode:

  • Work Managed mode on Android 9+
  • Corporate Owned Personally Enabled (COPE) mode on Android 15+

For more information, see our Android Device Management documentation.

Certificate Management

Expanded Entrust Dynamic SCEP challenge support
Workspace ONE UEM now supports flexible parameter pass-through for Entrust Dynamic SCEP challenges, removing the previous three-parameter limitation (IGUsername, IGGroup, DeviceType). Administrators can now configure any parameters required by their Entrust certificate templates.

Key benefits:

  • Prevents enrollment failures caused by missing Entrust-specific parameters
  • Supports complex template configurations without predefined parameter restrictions

Freestyle Orchestrator

Streamline onboarding entitlements in Android workflows
Onboarding entitlements within workflows allow administrators to prioritize resources essential for onboarding that take precedence over other resource assignments. For more information, see Onboarding Workflows.

Upgrading the communication pipeline from UDS to gRPC for macOS
Administrators now have more consistent workflow executions with our replacement of the communication pipeline between the workflow engine and macOS intelligent hub. This ensures that workflow step statuses are sent reliably so that execution can proceed to the next step. This change is in Limited Availability and will require Workspace ONE Intelligent Hub for macOS version 26.04. To have this enabled for your environment, contact your Account team.

iOS Management

App preservation during MDM migration
The new Preserve Applications setting in ADE profile now provides enhanced control for preserving managed applications during MDM migration scenarios. Administrators can specify which apps must be preserved and available immediately after migration during the Setup Assistant phase—choosing to await all apps or selecting specific critical applications. This ensures essential apps are ready before devices reach end users, minimizing downtime and eliminating the need for manual app reinstallation. The enhancement streamlines migrations, reduces IT intervention, and delivers fully configured devices ready for immediate productive use. For more information, see App preservation during MDM migration.

DDM app status subscriptions for iOS
On supported iOS devices, app-related Declarative Device Management (DDM) status subscriptions are enabled automatically, so application state can flow through declarative reporting without additional admin setup.

Key features:

  • Automatic enablement: App-related DDM status subscriptions activate automatically on compatible iOS devices with no manual setup required
  • Real-time app inventory: Application state flows through declarative reporting, keeping managed app data current and aligned with device-reported information
  • Enhanced visibility: Console displays more accurate, up-to-date information about installed applications as iOS surfaces it through DDM
  • Improved troubleshooting: Reduced blind spots when auditing app deployments, verifying installations, or diagnosing assignment issues across your fleet.

Platform-based default ADE profiles for automated enrollment
Administrators can now configure separate default Automated Device Enrollment (ADE) profiles for iOS, macOS, tvOS, and visionOS. This makes mixed-fleet onboarding more predictable. Each platform can land on the right baseline profile automatically as devices sync, with less manual cleanup and fewer mismatched assignments when you expand ADE across your Apple estate.

Enhanced Apple App platform management - Universal App support
With this Limited Availability feature, the Workspace ONE UEM console now dynamically recognizes and manages supported platforms for apps imported from Apple Business Manager, replacing previous hardcoded logic. An admin can automatically sync and assign the same application for iOS, iPadOS, visionOS, macOS, and tvOS from ABM into the console without having to sync an app version for each individual operating system.

Key enhancements include:

  • Dynamic platform detection: Automatically identifies supported platforms (iOS, iPadOS, visionOS, macOS, and tvOS) from Apple Business Manager metadata
  • Flexible app assignment: Enhanced VPP app assignment page enables platform-specific deployment selection
  • Universal app support: Streamlined deployment workflows for Universal Apps across all supported Apple devices

These updates ensure seamless app management, flexible deployment options, and alignment with organizational policies for Apple device ecosystems. For more information, see Universal Apps.

Automatic Apple OS version seeding
Workspace ONE UEM now automatically detects and seeds new Apple OS versions across all platforms (iOS, iPadOS, macOS, watchOS, and tvOS). When a new OS version is detected or when a device enrolls with an unseeded OS version, UEM automatically seeds it and makes it immediately available for use in Enrollment Restrictions, Smart Group Criteria, Compliance Policies, Add Device, and ADE/DEP profiles, without relying on manual seeding. Administrators receive a notification when a new Apple OS version is available.

Support for OS 26.4 MDM and DDM payload and key changes
UEM now includes Apple OS 26.4 updates for MDM payloads and DDM declarations. New 26.4 keys and declaration types appear in the Console as you roll out policies aligned with Apple’s current device management specifications.

Target policies and content by Apple device model
Smart Groups now allow you to filter by Apple device model, so you can assign configurations and apps to particular hardware types using the same model names found in Enrollment Restrictions. This update lets administrators deploy test builds to lab devices, apply camera policies only to supported models, or roll out updates by device generation, all without the need for manual device lists or error-prone naming.

Key features:

  • Familiar model selection: Define audiences using the same clear Model names you already use in Enrollment Restrictions
  • Multi-select capability: Multi-select option allows coverage of multiple models in a single group
  • Dynamic membership: Group membership automatically updates based on device-reported models, ensuring accuracy as inventory changes
  • Data quality protection: Devices without a reliable model value are excluded from model-based groups to prevent silent mis-application of criteria
  • Rule compatibility: Model-based rules work alongside your other Smart Group rules

macOS Management

Simplified macOS application deployment and management
The Enterprise App Repository (EAR) for macOS eliminates manual app packaging and enables admins to deploy enterprise applications as easily as App Store apps—streamlining deployment and ongoing maintenance.

  • Curated app catalog

    • Deploy enterprise apps directly from the repository without manual packaging
    • Add apps via Add > Enterprise App Repository > macOS to browse available applications
  • Intelligent search & discovery

    • Search applications by name or vendor to quickly find what you need
    • Filter and browse the catalog efficiently
  • Seamless upgrades

    • Apps with available updates will show the corresponding status in the Apps List View
    • Seamlessly update previously deployed apps, even if they were originally added manually

For more information, see Add macOS applications from the Enterprise App Repository.

Platform SSO with Automated Device Enrollment in macOS 26
With this feature, macOS 26 streamlines Platform Single Sign-On (PSSO) configuration by integrating it directly into Setup Assistant, enabling first-user account creation through Identity Provider authentication. This streamlined workflow delivers faster onboarding, improved security, and simplified deployment by replacing multi-step setup processes with one integrated flow.

How it works:

  • During the Setup Assistant, users authenticate using their Identity Provider (such as Omnissa Access, Okta, Microsoft Entra ID, etc.).
  • The Setup Assistant temporarily pauses while the Platform SSO application and necessary profiles are deployed to the device.
  • macOS automatically completes the registration for Platform SSO.
  • A new first-user account is created using the authenticated IdP credentials, which is then immediately registered with the Platform SSO frameworks.

Enhanced admin experience for macOS software distribution
Workspace ONE UEM now provides administrators with the ability to customize macOS application names using a new Display Name field. When adding macOS applications, admins can now assign custom display names for different versions of the same application while the parent application name remains unchanged. A future release of macOS Intelligent Hub will allow for this value to be displayed to users in the Hub Catalog. Additionally, the supported models and minimum OS fields have been removed from the macOS application workflow to streamline the app management process. This allows for applications to be deployed to macOS virtual machines. When adding new macOS applications, administrators will see an informational banner notifying them of these field removals to ensure awareness of the updated workflow.

Declarative Device Management Assets for macOS
Declarative Management for macOS now supports User Identity asset for eligible macOS devices. You can create a single User Identity asset, reuse it across declarative configurations, and manage it through the standard declarative profile workflow (add, edit, assign, and delete). That gives admins a consistent way to supply identity context for declarative scenarios without duplicating the same data across multiple declarations. For more information, see Declarative Device Management.

Enhanced Apple App platform management - Universal App support
With this Limited Availability feature, the Workspace ONE UEM console now dynamically recognizes and manages supported platforms for apps imported from Apple Business Manager, replacing previous hardcoded logic. Administrators can automatically sync and assign the same Application for iOS, iPadOS, visionOS, macOS, and tvOS from ABM into the console without having to sync an app version for each individual operating system.

Key enhancements include:

  • Dynamic platform detection: Automatically identifies supported platforms (iOS, iPadOS, visionOS, macOS, and tvOS) from Apple Business Manager metadata
  • Flexible app assignment: Enhanced VPP app assignment page enables platform-specific deployment selection
  • Universal app support: Streamlined deployment workflows for Universal Apps across all supported Apple devices

These updates ensure seamless app management, flexible deployment options, and alignment with organizational policies for Apple device ecosystems. For more information, see Universal Apps.

Platform-based default ADE profiles for Automated Enrollment
Administrators can now configure separate default Automated Device Enrollment (ADE) profiles for iOS, macOS, tvOS, and visionOS. That makes mixed-fleet onboarding more predictable. Each platform can land on the right baseline profile automatically as devices sync, with less manual cleanup and fewer mismatched assignments when you expand ADE across your Apple estate.

Support for OS 26.4 MDM and DDM payload and key changes
UEM now includes Apple OS 26.4 updates for MDM payloads and DDM declarations. New 26.4 keys and declaration types appear in the Console as you roll out policies aligned with Apple’s current device management specifications.

Resource Management

Percentage based phased rollout for internal apps
Phased Deployment is now Generally Available for Internal apps. Additionally, you can now configure phases to target a specific percentage of your device pool. In the previous release, phased deployment required setting up specific Assignment Groups for each phase. This enhancement relieves you of the overhead of creating and maintaining custom Assignment Groups for each phase. It gives you greater flexibility and control over your rollout strategy. Moreover, for progressed phases, you’ll now see additional progression details captured at the moment the deployment has advanced. For more information, see Phased Deployment of Resources.

Vulnerability Defense

Vulnerability Defense integration with CrowdStrike
Workspace ONE UEM 2604 offers Limited Availability for Workspace ONE Vulnerability Defense, bringing seamless assessment, prioritization, and remediation directly into the Omnissa platform.

Key Capabilities

  • CrowdStrike Falcon Integration: Seamlessly integrate Workspace ONE UEM with CrowdStrike Falcon Exposure Management to retrieve comprehensive vulnerability assessment data
  • Automated Device Correlation: Automatically map CrowdStrike vulnerability data to your Windows devices in Workspace ONE UEM
  • Risk-Based Prioritization: Access context-rich dashboards that enable rapid, data-driven prioritization of security risks
  • Streamlined Remediation: Deploy remediations directly through Workspace ONE UEM's native app and OS management capabilities to address vulnerabilities and reduce organizational risk

Windows Management

Windows server management: Enroll and manage Windows servers using Intelligent Hub
Windows Server management is now Generally Available. This feature was previously available under Limited Availability and is now enabled by default for licensed tenants. Administrators can enroll and manage Windows Server 2016, 2019, 2022, and 2025 devices, including Server Core, using Workspace ONE Intelligent Hub. Management is Hub-based.

Supported capabilities include:

  • Hub-managed profiles: ADMX-backed, DDUI-backed, Certificate (SCEP not supported), Custom Settings, and Managed Resources
  • Security Baselines enforcement and remediation
  • Granular Patch Management with scheduled maintenance windows, zero-day patching, deferral notifications, and per-device patch lifecycle logging
  • Internal application deployment via SFD with assignment-level retention control on enterprise wipe or unassignment
  • Sensors and Scripts for custom data collection and on-demand or scheduled actions
  • Roles and Features Sampling for automatic inventory of installed server roles and features
  • Freestyle Orchestrator workflows with sequenced execution and conditional logic
  • Workspace ONE Assist for remote view, remote control, file transfer, and remote shell

For more information, see Windows Server Management.

Granular patch management with on-demand update deployment
Administrators can now deploy specific Windows updates, such as critical security KBs to targeted Windows desktops and servers outside of their standard Windows Update for Business ring configuration. This capability enables a rapid response to urgent security patches without disrupting established update schedules. For more information, see Granular Patch Management.

Unified App Sampling: Remove application uninstallation
Administrators can now remotely trigger the uninstallation of applications collected through Unified App Sampling. This enhancement lets you control apps that are not managed, are unwanted, or not allowed on devices from the Workspace ONE UEM Console or through the supported APIs. For more information, see Assign Applications to your Windows Device.

Resolved Issues

Admin Experience

  • FCA-212233: Settings Summary XML export fails when the Organization Group (OG) name contains a comma (,).

  • FCA-212663: Images vanish from custom message templates after they are saved.

  • FCA-213345: Incorrect devices scoped for bulk actions in the Device List View when filters are applied on Tags, Smart Groups or User Groups.

Android Management

  • AGGL-20077: Managed config keys do not update when adding new version of internal app.

  • AGGL-20435: Newly enrolled Zebra devices are showing up with the wrong oeminfo.

Common Services

  • CMSVC-20840: OEM and model IDs are silently ignored during SG creation.

Core Platform

  • CRSVC-62551: Script trigger updates on console is not synced to device.

  • CRSVC-73705: Enhanced SCEP auto-renewal logic to support user-based profiles where signed user & enrollment user are not the same.

Content Management

  • CMCM-191789: Content app on iPad and Android, displays duplicate of same folders.

Enrollment and Service Integrations

  • ESI-596: Allow admin users to access multiple UEM tenants when logging in via Omnissa Connect.

Freestyle Orchestrator

  • FS-9815: macOS profile installation step in the workflow can hang indefinitely if Hub fails to report status.

  • FS-9708: Onboarding workflows may stall during device enrollment due to a database concurrency issue on macOS.

  • FS-8185: Scripts removed from device when unassigned from one workflow but still assigned to another on macOS.

  • FS-9903: Workflow execution may fail on devices in positive UTC offset timezones on macOS.

iOS Management

  • AAPP-21692: VPP apps are not receiving app settings, and users encounter an error stating, "no server has been configured for this app.""

Resource Management

  • ARES-32876: Application removal protection triggered despite device threshold not being met within time window, causing false alarms.

  • ARES-36784: Passcode not cleared from shared iOS devices when user logs out of it.

  • ARES-37278: Incorrect app config delivered to newly enrolled devices assigned to future-dated Internal app assignments.

  • ARES-19301: Profiles requiring WLAN MAC address lookup are delivered to iOS devices without the required value, resulting in authentication failures.

User Management

  • UM-10208: Directory-type admin account is unable to modify roles while logged in at Partner-type OG.

  • UM-10209: Inconsistent Full Name and Display name during OIS SCIM Provisioning.

  • UM-10484: User Search option in Add Device Registration screen permits search for empty string.

  • UM-10592: Admin Group Deletion Removes Roles from existing Admins.

  • UM-11073: Enrollment to a child OG fails for basic users in OIS-enabled tenants.

  • UM-11104: SSP authentication to a child OG fails for basic users in OIS-enabled tenants.

Windows Management

  • AMST-44384: When ProfileDeliveryAtScaleFeatureFlag is enabled, nodes are absent from the profile syncML when resuming.

  • AMST-46045: Apps installed on the Hololens are appearing as Not managed, which is preventing us from uninstalling them.

Patch Resolved Issues

Patch 1

  • PPAT-21484: Fix Tunnel Exceptions during the profile publish.

  • PPAT-21104: Set Multi Profile Support For Managed TunnelClients Phase1 FF to rollout.

  • MACOS-7327: WS1 Assist - 'Remote Assist' button goes away/missing on Hub sync.

  • FS-9894: For PO-enrolled devices, the onboarding status remains stuck at "Onboarding in Progress" when the assigned onboarding workflow includes internal apps as the last step.

  • FCA-213532: Error occurs while filtering with tags in the device list view using "space" as a character.

  • FCA-212413: Clicking "Other" in the Operating System breakdown chart from the Device Dashboard displays an error.

  • CRSVC-74796: Accessing the "User Sync Failed" events in the console results in the error: "An error has occurred".

  • ATL-28994: Seeding macOS Hub 26.04.0 to UEM 26.04 Patch1. For more information, see, Omnissa Workspace ONE Intelligent Hub for macOS Release Notes.

  • ATL-28828: Seed Workspace ONE Intelligent Hub v26.04 for Windows. For more information, see Workspace ONE Intelligent Hub for Windows Release Notes .

  • AMST-47028: Application removed from device even though "Keep App After Un-Assignment" option is enabled.

  • AMST-46364: Multi User Checkout restrictions are not getting overwritten in child OG.

  • ARES-37726: Devices not visible on Phase Deployment Tracking page of apps deleted previously from list view and added back later.

Patch 2

  • RUGG-14306: Relay server content will not be pushed to FTP when RSCC is used in some cases.

  • FCA-212480: Incorrect highlight colour appearing in drop-down menus resulting in readability issues.

  • FCA-210931: Update Event Log to display username of admins which triggered bulk actions.

  • CMEM-187318: CPU contention caused by [mobileEmailGateway].[AccountUser_Load].

  • AGGL-20378: eSIM actions missing in Device Details and installing eSIM throws an error.

Patch 3

  • UM-11153: Addressed scenario where child OG deletion can cause OIS fail to update UEM.

  • RUGG-14288: Certificate renewal fails for Android devices published through Product provisioning profiles.

  • PPAT-21400: Updated Tunnel pages Read-Only RBAC role permissions.

  • PPAT-21355: ETag is not updated when the shift status after changes.

  • FS-9924: Workflows and scripts fail to run on Brownfield macOS devices after upgrading to 2602 or 2604.

  • FCA-213604: Resized upgrade banner to prevent messages from blocking user actions.

  • FCA-212597: Enhanced RequireJS pages to prevent displaying version information.

  • FCA-212214: Updated the default Read-Only Administrator role to include all read permissions.

  • CRSVC-76143: Updated DeviceStatev3 API response to prevent duplicate Device UUID value reporting.

  • CRSVC-75006: Azure token may not be revoked if device is deleted when offline.

  • CRSVC-74767: Addressed scenario where optional profiles are not displayed in the Devices Profiles tab.

  • CRSVC-71788: Certificate count in the Device Details > Summary does not match the data under Device Details > Certificates.

  • ATL-29192: Update macOS Workflowd Package.

  • ARES-38095: App and profile list cannot be exported from Device Details.

  • AMST-47061: Aligned Windows CLI staging enrollment with AssignToLoggedOnUser to enforce allowed user group policies.

Patch 4

  • RUGG-14484: Product Set remains stuck in processing state, preventing edits.

  • PRNT-345: LA Availability for Printers & IoT Platform.

  • MACOS-7103: Resolved an issue where newer application versions, deployed to lower OGs, were incorrectly inheriting and overwriting the Bundle Identifier schema.

  • HUBW-22664: 2602 Bitlocker profiles being blocked in the onboarding workflow.

  • FS-9911: Resolved an issue where Freestyle workflows did not re-execute on devices after unenrollment and re-enrollment.

  • CRSVC-78779: Bitlocker profiles being blocked in the onboarding workflow.

  • CRSVC-77709: Resource delivery may be blocked due to stale overrides created by Compliance Policy evaluation.

  • CRSVC-74767: Addressed scenario where optional profiles aren't displayed in the devices Profiles tab.

  • CRSVC-74427: "Profile Install Blocked" and "Profile Install Initialized" event logs do not display NotNow status reason details in the Troubleshooting page.

  • ATL-29318: Updated macOS Workflowd Package.

  • ATL-29287: Updated Software Distribution Agent Package to 26.4.1.

  • ARES-38221: Resolved an issue where transitioning an application from Internal App to Product deployment within 24-hours caused unintended device uninstalls.

  • ARES-37566: Installed devices not visible on Deployment Tracking view unless filtered.

  • ARES-37354: Nested app configurations such as VPN settings fail to get saved.

  • AMST-46952: Add event log support for Windows Update sample.

  • AMST-46950: Enrollment Token Bulk Upload - Device friendly name in the uploaded sheet is not getting considered.

  • AMST-44925: Unable to edit a Baseline if saved with empty values.

  • AGGL-20567: Enhanced assignment rules response to resolve issues impacting assignment updates.

  • AGGL-20483: Android Internal App upload intermittently failing.

  • AGGL-20450: Improve Performance for Android App Catalog.

  • AGGL-20442: Enterprise wipe from UEM consistently wipes / power‑washes Chrome OS device but does not deprovision it from Google Admin.

  • AGGL-19985: Enrollment Date is Not Set on Chrome OS device.

  • AAPP-22209: Improved Apple device release diagnostics by retaining API error responses and added event logs for key release states.

  • AAPP-21843: Enhanced VPP integration synchronization to ensure proper cleanup when no licenses are returned.

  • AAPP-21301: Intermittent ADE Sync Failures Due to Apple Rate Limiting (HTTP 429).

Patch 5

  • AGGL-20730: Managed App Configs are Corrupted by Hierarchical Key.

Patch 6

  • MACOS-7484: Support for macOS Registered Mode.

  • FS-10219: A post install script issue may corrupt workflow binaries and prevent workflows from executing on macOS devices.

  • FS-10111: Expired internal device credentials may cause workflows to be stuck in progress and prevent new workflows from executing on macOS devices.

  • FS-9762: Event-based scripts execute more frequently than expected after device check-in on macOS.

  • FS-8052: Missing search functionality on workflow details page device status table.

  • FCA-214062: Fixed a display issue on the Freestyle Orchestrator page that blocked workflow naming and creation.

  • FCA-213920: Self-Service Portal (SSP) language selection was unavailable when authenticating via Workspace ONE Access.

  • FCA-213739: Authorization error message is being incorrectly shown on some console screens.

  • ATL-29599: Seed - Machost 2604.7135 to release 2604.

  • ATL-29537: Seed - Machost to canonical release PR2604-6.

  • ATL-29407: Seed - Machost to canonical release PR2604-6.

  • ATL-29400: Seed Workspace ONE Intelligent Hub v26.04.1 for Windows.

  • ARES-38128: DDM profile not displayed in Smart Groups’s profile assignment preview.

  • ARES-36322: ADMX Profile gets corrupted by character-escaping issue.

  • AMST-47802: Privilege Elevation feature is now part of Workspace ONE Advanced SKU.

  • AMST-47787: Added execute/genericcommand API Endpoint to api/help page in production environments.

  • AMST-47779: Manage inclusion of AllowOOBEUpdates node according to OS build version.

  • AMST-47071: Newer version of Enterprise Repository Apps get assigned even though assignment carry over is cancelled.

  • AMST-43186: New API version available for Application creation with multiple processor architectures.

  • AAPP-22776: MAM API returning duplicate results.

  • AAPP-22508: Device updates tab shows 'Not Available' for Apple OS Updates.

  • AAPP-22155: Improve retry logic for VPP v2 calls.

  • AAPP-21991: Unable to configure Network usage rules payload profile for iOS.

  • AAPP-21422: Improvements to VPP v2 license management.

  • ARES-32880: Multiple profile removal failure events displayed in troubleshooting logs of mobile devices for profiles deleted from UEM.

Patch 7

  • UM-11206: User group memberships are updated when enrolling iOS or macOS devices even if Sync User Groups in real time is disabled.

  • UM-11085: Child OG admin is unable to remove users from a Custom User Group.

  • FCA-214069: Editing a profile for an extended period might trigger a session error, interrupting the edit before assignment.

  • FCA-213533: OG picker placed incorrectly in the header on some pages in the console.

  • FCA-213213: Inconsistent notification count is seen on different pages of the console when notifications are dismissed.

  • CRSVC-75786: Enable feature that allows collection of all logs with one click.

  • ARES-38601: VPN profile cannot be assigned to an application's Tunnel settings.

  • ARES-38352: 'Platform' filter displayed twice on Profile List view.

  • ARES-37842: Device cannot be rebooted from Devices List view.

  • ARES-37341: Deployment metrics under 'View' on app and profile list hides upon hover.

  • AAPP-21798: Improve handling of Apple's throttling limits for VPP v2 flows.

Patch 8

  • AAPP-22654: VPP On-demand Applications intermittently getting re-installed on devices when the application is removed by an Admin in the console.

  • AMST-45142: Fixed issue where Drop Ship Provisioning (DSP) at child OG was getting disabled when changes are made to Parent OG DSP configuration.

  • AMST-46668: Filtering in Device Registration List View with Serial Number does not work.

  • AMST-46946: Fixed issue in UEM console, where after selecting apps for inclusion in a provisioning package (PPKG), the "NEXT" button becomes greyed out and the app selection on the initial page is lost when navigating back to it.

    • AAPP-20744: Actions and commands both are generated for iOS profiles.
  • AAPP-21403: Return to Service option does not display Wi-Fi profiles.

  • AAPP-22255: App sample save issues for web enrolled device which was DEP enrolled in past & never completed configuration al page is lost when navigating back to it.

  • AMST-47153: Device Reassignment fails at child OG after overriding Multi-User Checkout restrictions.

  • AMST-47763: Fixed issue with Enterprise App Repository config page crashing for the OneDrive app.

  • AMST-47775: Fixed issue where profile removal fails on the device but removed from Workspace ONE UEM.

  • AMST-47797: Fixed issue where Device List view incorrectly shows Windows devices as "Multi User" for the Windows User Mode column, though the device is enrolled as 'Single User'.

  • ARES-37420: Internal app deployment metrics incorrect when fetched through API.

  • ARES-37451: Geofencing profiles not delivered as expected in modern architecture enabled environments.

  • FCA-213810: OG Picker dropdown is missing when an admin has access to only one OG.

  • FCA-214005: Fixed a display issue where the Compliance Status tile appeared misaligned on the Baseline Dashboard.

  • FCA-214150: Fixed an issue where dropdown menus in Profile and App Configuration pages were unresponsive in Firefox.

  • FS-10101: Total Execution Count in the Freestyle Orchestrator overview has been reset.

  • MACOS-7301: Onboarding and Focused Enrollment status is displayed in device details page even if Focused Enrollment is Disabled.

Patch 9

  • VULN-1688: Re-registering a device in CrowdStrike can cause mapping issues.

  • VULN-1504: Remediation Wizard - apps search does not filter by platform.

  • VULN-1459: Incorrect Vuln Defense logo in nav menu.

  • VULN-1458: Vulnerabilities list view - Filters reset does not work.

  • VULN-1403: Filters and Search on Product Details page do not work.

  • VULN-1401: Summary counts are incorrect across multiple pages.

  • VULN-1397: Fallback logic for CVSS score resolution.

  • VULN-1301: Vulnerabilities count discrepancy between Vulnerabilities list view and Device Details.

  • UM-11243: User Management Service client is incorrectly invoked when feature flag is disabled.

  • UM-10919: Device registration record creation fails due to incorrect handling of selected message template.

  • RUGG-14521: Last Seen timestamp is incorrectly updated for devices belonging to smart groups assigned to a product upon product activation.

  • MACOS-7325: Page error occurs when UEM Console Admin tries to edit the Mobility Profile.

  • CRSVC-80819: Fixed an issue where an incorrect unauthorized error was displayed on some pages.

  • ATL-29824: Seed Workspace ONE Intelligent Hub v26.04.2 for Windows.

  • ARES-38439: Copying and editing profiles having passcode in payload causing issues.

  • ARES-38239: Devices not visible in future phase on phased deployment tracking view if assigned to another app version.

  • ARES-38099: Installed profile shown as removed in Intelligence.

  • ARES-37991: Force removal of a few iOS apps failing from Device Details Apps tab.

  • AMST-48196: Manage inclusion of AllowOOBEUpdates node only on supported OS build versions.

  • AMST-48015: Domain Join Config ignores Base DN config if multiple domains are configured.

  • AMST-47928: Intelligent Hub on Windows not updating post UEM upgrade to 2509.

  • AAPP-22642: Sync ADE Devices isn't working.

  • AAPP-21508: VPP Applications are intermittently failing to install on random Devices.

Patch 10

  • VULN-1891: Remediation wizard may show incorrect app version.

  • VULN-1489: Remediation wizard may show an error when recommendation is not available.

  • FCA-213916: DLV Smart Group filter breaks for smart groups with large manually added device/user lists.

  • FCA-213816: Unable to change Deployment Begins date when publishing an application.

  • FCA-213597: Fixed visual inconsistencies where some console pages displayed updated UI styling while others retained the older design.

  • ATL-29786: Seeding SFD 26.4.2 build to UEM 2604 release.

  • ARES-38312: Profile save fails when assigned to devices with ownership type 'undefined'.

  • ARES-37644: Incorrect installation status reported for some profiles in Device's Profile list.

  • ARES-37362: User accepted counts for Terms of Use fails to load for Application type.

  • ARES-36887: Some profile installation statuses reported to Intelligence are incorrect.

  • ARES-34956: Uploading a static certificate in a Credential slot in the Credentials profile payload copies validity dates and thumbprint from another slot.

  • AAPP-22395: Ability to turn off scheduled sample collection continuation on NotNow responses.

  • AAPP-21467: Advanced Security Controls profile does not work as expected.

  • AAPP-21462: VPP apps are not updating on many devices.

Patch 11

  • VULN-1912: VMS - sort criticality rating by enum, not lexicographixally.

  • VULN-1897: Remediation wizard for apps does not filter for recommended version.

  • VULN-1412: Vulnerabilty Details page - Setup Remediation button is misaligned.

  • SINST-176815: Revert .msi request-filter change — restore /agents access in patches 2602 #13 and 2604 #11.

  • PPAT-22197: meta.gateway empty in managed Tunnel client-config response.

  • PPAT-22044: Performance Improvement for Tunnel allowlist endpoint.

  • LAUN-211: The Launcher Profile does not allow page changes for layout.

  • FCA-214321: "Query" action button isn't enabled for Windows devices in NextGen App Device List.

  • FCA-214156: Device version sorting is inconsistent across operating systems on the device dashboard.

  • FCA-213816: Unable to change Deployment Begins date when publishing an application.

  • FCA-213196: GetTenantUuidForOrganizationGroupAsync breaking behaviour after partner enablement.

  • ARES-30925: Inconsistent color to status mapping in Deployment Tracking charts.

  • AMST-48112: Dropship Provisioning auto enrollment PPKG certificate signing failure.

  • AMST-48002: Admin_LocationGroupDelete fails on FK constraints — missing EARAppAutoUpdateConfig and DduiPayload cleanup.

  • AGGL-20648: SCEP/Credentials profiles for Android are unable to proceed despite providing all mandatory fields.

  • AAPP-23168: Reduce the VPP license pool count in VppV2Licenses_SyncByAdamID on license deletion.

  • AAPP-22293: Blank URLPrefixMatches Causes iOS SSO Profile Failures.

  • AAPP-21344: Remove admins email alerts for exceeding Application Removal Limit for VPP apps.

  • ESI-1241 - Fixed an issue where a shared device could remain in a checked-out state after an interrupted check-out, preventing users from logging in until an administrator intervened.

Patch 13

  • SINST-176756: Updated service runtime to .NET 10 for improved performance, security, and long-term support - UEM & CP Services.

  • FS-10300: After an interrupted workflow engine upgrade, Freestyle workflows on macOS devices may fail to execute because a stale database migration lock prevents the workflow engine from starting.

  • FS-9932: Repeated profile installation attempts may occur if a response is missing during re-evaluation on macOS devices.

  • FCA-213887: Read-Only administrator accounts and roles are not visible to console admins.

  • CTRLP-14512: Improved authentication and authorization controls for service-to-service messaging.

  • CMEM-187334: Optimize response payload for mem endpoint activesync/memconfigdevicepolicies.

  • ATL-30384: Seed - Machost to canonical release PR2604-13.

  • ARES-39062: 'Save Failed' error sometimes received while publishing app to thousands of devices and parallelly deleting devices from UEM.

  • AMST-42947: Device Details - WNS Connected Last Seen timestamp is not show in Admin's selected timezone.

  • AAPP-23362: Device List page crash after upgrade 26.2.0.10 → 26.4.0.6+.

  • AAPP-22485: Unable to renew or clear the VPP sToken from the UEM Console because the option is grayed out.

  • AAPP-21015: {DeviceFriendlyName} value not populated on Enrollment Message.

  • AAPP-19323: Purchased apps showing inconsistent installation status.

Patch 14

  • VULN-2214: While processing device vuln from crowdstrike ensure to check for AID by ignoring the CID prefix.

  • VULN-1733: Vulnerability management performance optimization.

  • RUGG-14610: Zebra OTA updates stop working and device update status not reflecting correctly.

  • PPAT-22293: DTR-based traffic policy cannot be configured/updated for macOS from the profile UI.

  • MACOS-7626: MacHub sends empty Application List sample during Hub Sync.

  • FCA-214004: Lock device command not working when Notes Description is a required field.

  • CMSVC-21034: Device List View shows an incorrect device count when filtering by smart group.

  • CMSVC-21003: App assignment page fails to load in organization groups with a large number of smart groups.

  • ATL-30314: Seed Workspace ONE Intelligent Hub v26.04.3 for Windows.

  • ARES-39049: Product sent repeatedly to device if app configured to be installed through Product Provisioning is sideloaded by device.

  • ARES-38920: Geofencing area change event is not delivering the right profiles in modern architecture enabled environments.

  • ARES-37109: Error occurs while deleting retired apps from the console.

  • AMST-48247: Cache CND URL for redirection while serving branch cache requests.

  • AGGL-20938: Duplicated assigned Android app package names may cause FCM messages to fail.

  • AGGL-20862: Hub 26.05 fails to install Wi-Fi profile on Android devices.

  • AAPP-23784: Fix Apple sample commands error processing.

  • AAPP-22963: ADE/DEP Settings tab is erroring out in several OGs, including the top OG.

  • AAPP-21974: Unable to edit/create iOS VPN profile.

Known Issues

  • ARES-38094: App list cannot be exported from Device Details page for Windows devices.

Release Availability

We strive to deliver high-quality products, and to ensure quality and seamless transitions, we roll out our products in phases. Each rollout may take up to four weeks to accomplish and is delivered in the following phases:

  • Phase 1: Demo, Shared SaaS UATs, and Latest Mode UATs

  • Phase 2: Shared SaaS environments

  • Phase 3: Latest Mode environments

Getting Ready for Major OS Releases

To prepare for the upcoming software updates from major device vendors, read through the Getting Ready for Major OS releases section of the Omnissa Product Documentation.

Documentation

To learn more about Workspace ONE UEM, browse Workspace ONE UEM Documentation.

Localized Content for Omnissa Docs

For details on Omnissa's localization strategy, see the KB article: Announcing Omnissa Localization Support.

Support Contact Information

To receive support, access Omnissa Customer Connect. For information about filing a Support Request in Customer Connect and using Cloud Services Portal, see the KB article here.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…