Skip to main content

September 3, 2026

Omnissa Workspace ONE UEM Release Notes

We are excited to share the new release of Workspace ONE UEM version 2607! Read on to learn about the new features and improvements in this release.

What's New in this Release

Admin Experience

Full-Page Omni App experience now available in Workspace ONE UEM Console
Workspace ONE UEM now supports a full-page view of the Omni app within the Workspace ONE UEM Console, enabling a richer and more complete user experience beyond the previously available embedded view. Navigation to the full-page Omni app is role-based, ensuring only administrators with the appropriate Omni permissions granted in Omnissa Connect can access the page. For more information, see Accessing Omni from the UEM Console.

Android Management

SCEP-Based Certificate Distribution for Wi-Fi Authentication (Custom DPC)
The Custom DPC SCEP profile payload introduced in Workspace ONE UEM 2506 allows organizations to distribute user certificates more securely to Android devices by through on-device key generation. These certificates can now be used for certificate-based authentication into WPA2 Enterprise WiFi networks. You can now select SCEP profile payloads in the Identity Certificate field in Custom DPC WiFi profile payloads. Requires Workspace ONE Intelligent Hub 26.02.

New security policies (Custom DPC Restriction Profile)
You can now set the following policies on Android devices enrolled in Custom DPC mode. Requires Workspace ONE Intelligent Hub 26.04.

  • Allow Private Spaces (Android 15+): You can now prevent users from enabling Private Spaces in the personal profile on Corporate Owned Personally Enabled devices.

  • Allow Wi-Fi Sharing (Android 13+): You can now prevent users from sharing credentials of WiFi networks configured by your organization. This only restricts sharing for WiFi networks configured through WiFi profile payloads

  • Allow USB Data Signaling (Android 12+): You can now completely disable data transmission via USB, allowing only charging. Supported on corporate-owned devices only (Work Managed and Corporate Owned Personally Enabled).



Freestyle Orchestrator

macOS communication pipeline upgraded from UDS to gRPC
Admins now have more consistent workflow executions with our replacement of the communication pipeline between the workflow engine and macOS Intelligent Hub. This ensures that workflow step statuses are sent reliably so that execution can proceed to the next step. This change is in now in General Availability and will require Workspace ONE Intelligent Hub for macOS version 26.08.

iOS Management

New Credentials Asset in Declarative Device Management
Administrators can now create and deploy Credentials assets such as Username and Password to iOS and macOS devices directly from Profiles > List View > Profile > Declaration > Assets. This asset enables IT to securely provision username and password credentials to managed devices so that DDM configurations can silently perform authentication without requiring manual user input.

Unified Apple OS Update Management: iOS and macOS now managed from a single view
Workspace ONE UEM makes it easier to manage Apple devices' OS updates. It brings together the macOS and iOS update workflows into a single, DDM-based interface. The following enhancements have been made:

  • The OS update management page now presents macOS and iOS updates in a single Apple view, eliminating the need for administrators to navigate between separate platform pages. The Update column has been renamed to Platform for clarity, and filters have been improved for consistency with the rest of the Workspace ONE product. When an OS update is assigned to an Organization Group, it now properly inherits down to child OGs.
  • Administrators can create new assignments directly from this unified view. On the Deployment page, both Imperative and Declarative deployment options are presented, with Declarative set as the default.
  • A new Auto Update button is available at the top of the Device Updates list view. Administrators can configure Auto Update to apply the latest Major or Minor OS version using the using the Software Update Enforcement Declarative Configuration, with the system automatically selecting the latest compatible version. For more information, see OS Management.

VPP Apps in Freestyle Workflows
With this Limited Availability feature, the Install App action in Freestyle Workflows now supports VPP apps for iOS. Administrators can select from their purchased app catalogue when building a workflow step. Licenses must be allocated to the target smart group with an On Demand Assignment before deployment via workflow.To have this feature enabled for your environment, contact your account team.

macOS Management

macOS Registered Mode management in Workspace ONE UEM
Workspace ONE now introduces Registered Mode support for macOS, enabling organisations to extend Workspace ONE capabilities — including Digital Experience Management (DEX) — to Mac devices managed by third-party MDM solutions. Workspace ONE services on macOS are now available without requiring full MDM enrolment, providing a flexible, low-friction path to adoption.

Administrators can enable Registered Mode for macOS from Groups & Settings > All Settings > Devices & Users > General > Enrollment > Management Mode. The configuration supports scoping by Organisation Groups and Smart Groups, allowing targeted deployments across mixed-management fleets. In Registered Mode, macOS devices receive Hub-delivered resources, including applications, sensors, and scripts. Custom profiles are not supported in this release, as Registered Mode is designed for app-level and lightweight management rather than full device configuration. For more information, see Registered Mode.

Data Assets support in Declarative Device Management
Workspace ONE UEM now supports DDM Data Assets for macOS. Administrators can create and deploy Data Assets directly from Profiles > List View > Profile > Declaration > Assets. Data Assets let you upload arbitrary data files to the UEM Console and deploy them to devices automatically. These files can then be referenced by applicable DDM Configurations, such as Services Configuration Files and Services Background Tasks declarations.

New Credentials Asset in Declarative Device Management
Administrators can now create and deploy Credentials assets such as Username and Password to iOS and macOS devices directly from Profiles > List View > Profile > Declaration > Assets. This asset enables IT to securely provision username and password credentials to managed devices so that DDM configurations can silently perform authentication without requiring manual user input.

Unified Apple OS Update Management: macOS and iOS now managed from a single view
Workspace ONE UEM makes it easier to manage Apple devices' OS updates. It brings together the macOS and iOS update workflows into a single, DDM-based interface. The following enhancements have been made:

  • The OS update management page now presents macOS and iOS updates in a single Apple view, eliminating the need for administrators to navigate between separate platform pages. The Update column has been renamed to Platform for clarity, and filters have been improved for consistency with the rest of the Workspace ONE product. When an OS update is assigned to an Organization Group, it now properly inherits down to child OGs.
  • Administrators can create new assignments directly from this unified view. On the Deployment page, both Imperative and Declarative deployment options are presented, with Declarative set as the default.
  • A new Auto Update button is available at the top of the Device Updates list view. Administrators can configure Auto Update to apply the latest Major or Minor OS version using the Software Update Enforcement Declarative Configuration, with the system automatically selecting the latest compatible version. For more information, see macOS Update Management.

Printer Management

Next-Generation Printer Management: A Brand New MQTT-Based Platform
Printer management just got a major upgrade. Workspace ONE UEM now includes a brand new, native platform for managing mobile printers, starting with Zebra devices, built on MQTT (Message Queuing Telemetry Transport), the modern, lightweight protocol that has become the industry standard for industrial IoT communication.

This is a complete break from the legacy connector model. Printers now enroll, configure, and report health data directly through the Workspace ONE UEM Console alongside all your other managed endpoints. Everything is handled in one place, without relying on OEM-specific tools or creating yet another separate management workflow. IT teams can push configurations and firmware updates, monitor printer health and availability in real time, set automated alerts, and access full fleet-wide analytics all in the UEM Console.

And this is just the beginning. By building on MQTT, Workspace ONE is establishing a powerful, scalable foundation for managing a much broader ecosystem of connected frontline and IoT devices. For more details, see MQTT Printer and IoT Device Management.

Resource Management

Pause resource delivery with Freeze Mode to simplify device troubleshooting
Administrators can now activate Freeze Mode directly from the Device Details page to temporarily pause resource delivery on a device. When enabled, Freeze Mode blocks the installation and removal of directly assigned apps, profiles, and workflows delivered through the Modern SaaS architecture, allowing administrators to investigate resource delivery issues without interference from ongoing actions. Admin-initiated actions from the console remain unaffected during this period. Once Freeze Mode is deactivated, all blocked actions resume automatically. This feature is supported on iOS and Android devices. For more information, see Freeze Mode.

Relay Server support extended to internal applications for Windows
Relay Server support is now extended to internal applications on Windows devices. Previously limited to Product Provisioning, Relay Servers can now be used to deliver internal applications, enabling organizations to improve delivery speed and reduce internet bandwidth consumption in low-bandwidth or offline environments. Administrators can enable relay server delivery per app directly from the Internal Apps configuration screen under Deployment Options using a new toggle. Apps are only seeded to relay servers when explicitly marked for relay-based delivery.

User Management

UUID-Based APIs for custom user group membership management
Workspace ONE UEM has two new REST APIs for adding and removing users from user groups. The new APIs accept EnrollmentUserUUIDs as input, which removes the need for integer EnrollmentUserIDs and matches the UUID already returned by the existing group membership. Both APIs support batch operations with a documented upper limit on the number of users per request, skip invalid or non-member UUIDs without failing the entire batch, and trigger a console event for each membership change. The previous integer ID-based APIs for custom group membership management are now deprecated.

visonOS Management

Deploy and manage apps on Apple Vision Pro devices
Workspace ONE UEM now supports deploying and managing applications on enrolled Apple Vision Pro devices running visionOS. Administrators can sync visionOS applications from Apple Business Manager directly into UEM via Resources > Native Apps > Purchased > Sync Assets and assign them to device- or user-based smart groups for automated distribution. Custom in-house visionOS applications can also be uploaded as internal apps (.ipa format) via Resources > Native Apps > Add Application and assigned to smart groups for deployment to Apple Vision Pro devices. This enhancement is available on a Limited Availability basis. To have this feature enabled for your environment, contact your account team.

Windows Management

Step-Up Enrollment from Registered Mode to Hub Managed and Full MDM (OMA-DM)
Workspace ONE UEM now supports step-up enrollment support for Windows devices currently enrolled in Registered mode. Administrators can now upgrade these devices to either Intelligent Hub Managed or Full MDM (OMA-DM) management without requiring a device wipe or end-user re-enrollment. Devices seamlessly transition to the selected management mode and immediately gain access to the full set of corresponding management capabilities, including app deployment, profiles, baselines, sensors, scripts, and workflows.

To perform a step-up enrollment, navigate to Device Details > More Actions, and select one of the following options:

  • Step-Up to Hub Managed
  • Step-Up to OMA-DM Managed

For more information, see Enrolling Windows Devices into Workspace ONE UEM.

Step-Up Enrollment from Hub Managed to Full MDM (OMA-DM)
Devices already enrolled in Intelligent Hub Managed mode can now be stepped up to Full MDM management. When a step-up enrollment is triggered, the Intelligent Hub automatically initiates native OMA-DM enrollment on the device. This unlocks additional capabilities that require the native Windows MDM channel — including Microsoft CSP-based profiles and Autopilot support — while preserving the existing device record and all Hub-based management. No device wipe or end-user action is required.

To perform a step-up enrollment, navigate to Device Details > More Actions > Step-Up to OMA-DM Managed. For more information, see Enrolling Windows Devices into Workspace ONE UEM.



Bulk Step-Up enrollment using Device List View and APIs
Administrators can now perform step-up enrollment at scale. From the Device List View in the UEM console, select multiple Hub Registered or Hub Managed devices and trigger a bulk step-up to Full MDM management in a single action. Step-up is also available via UEM APIs, enabling automation and integration with existing IT workflows for large-scale fleet migrations. For more information, see Enrolling Windows Devices into Workspace ONE UEM.

Automatic Step-Up to OMADM on Enrollment User Sign-In
A new Auto Step-Up setting allows administrators to automatically transition eligible Hub Managed devices to Full MDM management without issuing individual step-up commands. When enabled at the organization group level, the Intelligent Hub automatically initiates OMA-DM enrollment upon user sign-in post-enrollment or after device reassignment, ensuring devices reach full management with zero admin intervention per device.

To enable automatic step-up to OMA-DM on user sign-in, navigate to All Settings > Devices & Users > General > Enrollment > Management Mode. Under the Windows section, select No OMA-DM Management> Intelligent Hub Managed and enable Auto Step-Up to OMA-DM on User Login. For more information, see Enrolling Windows Devices into Workspace ONE UEM.

Real-Time Onboarding Workflow Progress on the Post-Enrollment Onboarding Screen
The Post-Enrollment Onboarding (PEO) screen in Workspace ONE Intelligent Hub for Windows now displays real-time progress of Onboarding Workflows during device enrollment.

  • Workflow step-by-step tracking: Tracks each resource (apps, profiles, scripts) with real-time in-progress, completed, or failed status updates.
  • Progress bar indicator: A dynamic progress bar shows the overall completion percentage of the Onboarding Workflow.
  • Failure visibility: Clearly indicates if a workflow step fails.
  • Seamless transition: Automatically transitions to application installation progress once the workflow completes.

Previously, the PEO screen only showed application install and uninstall progress. This enhancement gives users full visibility into the device setup process, improving transparency and reducing help desk calls during enrollment. For more information, see Enrolling Windows Devices into Workspace ONE UEM.

Focused Enrollment: Lock Windows devices during post-enrollment onboarding
Focused Enrollment for Windows devices allows IT administrators to lock the device during the Post-Enrollment Onboarding (PEO) experience. When enabled, users are prevented from navigating away from the onboarding screen, ensuring that all critical setup steps such as profile configurations, security app installations, scripts, and workflow executions complete before the user accesses the device.

Key behaviors when Focused Enrollment is enabled:

  • Get Started button control: The Get Started button on the PEO screen remains disabled until all onboarding steps are complete, preventing users from skipping mandatory setup.
  • Keyboard input blocking: All keyboard shortcuts are blocked during onboarding, except the PEO Screen Exit Keystroke and CTRL+ALT+DEL, delivering a kiosk-like experience. Mouse and touch inputs are also blocked.
    Note: This feature is intended to guide end users through onboarding completion and prevent inadvertent bypassing of setup steps. It is not intended as a security enforcement mechanism.
  • Task Manager disabled: Task Manager is automatically disabled during focused enrollment to prevent users from terminating the onboarding process. For more information, see Enrolling Windows Devices into Workspace ONE UEM.

Resolved Issues

Admin Experience

  • FCA-212091: Report subscription not working as expected.

  • FCA-212096: Prevent concurrent administrator sessions in UEM when 'Allow Multiple Sessions' setting under Session Management is disabled.

  • FCA-212413: Clicking "Other" in the Operating System breakdown chart from the Device Dashboard displays an error.

  • FCA-212660: Devices "extensivesearch" API returns invalid results when using Platform as filter.

  • FCA-212663: Images vanish from custom message templates after they are saved.

  • FCA-212745: For Freestyle Orchestrator, marketplace link is not working.

  • FCA-213030: Unable to export Device list view with encryption.

  • FCA-213104: Put System/Groups/{OGuuid} - Does not have proper validation when setting Location Group Type.

  • FCA-213131: Error message "An error has occurred. Something unexpected happened" is seen on Terms of Use for some of the apps.

  • FCA-213152: Device List View search returns records that do not match the search keyword.

  • FCA-213345: Incorrect devices scoped for bulk actions performed from the Device List View.

  • FCA-213531: Notes added while performing restricted actions are not displayed in the Events.

  • FCA-213532: Error occurs while filtering with tags in the device list view using "space" as a character.

  • FCA-213597: UI inconsistency observed across Workspace ONE UEM Console pages(Fonts, Icons) after 2602 upgrade.

  • FCA-213693: MCC Change Events Logged Without Country Code Details.

  • FCA-213739: Workspace ONE UEM environments in FedRAMP displays "User is not authorized to perform this action error" in a red banner.

  • FCA-213813: Searching Device By Location with DLV receives an Error Has Occurred.

  • FCA-213887: Read-Only admin role becomes invisible from Console Admin after upgrading to 2602 patch 6 from patch 5.

  • FCA-213920: Users are not able to choose German for SSP with access.

  • FCA-214004: The Lock Device command does not complete when Notes description is required in DDV.

  • FCA-214156: Console UI Issue where dashboard is showing device versions for MAC OS in a decreasing order and Windows in an increasing order.

  • FCA-214665: Unable to access the monitor > export page with a custom role.

  • FCA-214716: From certain pages in console if we go to device or dashboard, the page crashes with error message "Page Not Found".

  • FCA-214815: API Memory reporting different units of measure for Windows or macOS devices in Service Now.

Android Management

  • AGGL-19005: App installs successfully despite being blocked in compliance policy.

  • AGGL-20088: Production users are incorrectly shown the Alpha track on their devices despite not having the required entitlements.

  • AGGL-20247: Intermittent Android enrollment failures caused by null EnrollmentUserId during CreateMdmInstallUrl step.

  • AGGL-20346: Repeated profile removal errors in troubleshooting events.

  • AGGL-20378: eSIM actions missing in Device Details and installing eSIM throws an error.

  • AGGL-20395: Certificates tied to a WiFi profile are not populating in the cert fields within the WiFi profile.

  • AGGL-20435: Newly enrolled Zebra devices are showing up with the wrong oeminfo.

  • AGGL-20442: Enterprise wipe from UEM consistently wipes / power‑washes Chrome OS device but does not deprovision it from Google Admin.

  • AGGL-20443: Remove actions are incorrectly generated for internal apps on Hub Registered devices due to stale MAL samples.

  • AGGL-20447: EMM test connection failure (AMAPI pubsub subscription).

  • AGGL-20479: App config JSON deserialization fails due to conflicting ID attributes.

  • AGGL-20483: Android Internal App upload intermittently failing.

  • AGGL-20567: Enhanced assignment rules response to resolve issues impacting assignment updates.

  • AGGL-20575: Discrepancy between API and console encryption data.

  • AGGL-20649: "Allow silent access to apps” option not actionable for first SCEP payload when Credential and multiple SCEP payloads are configured together.

  • AGGL-20730: Managed App Configs are Corrupted by Hierarchical Key.

  • AGGL-20911: Viewing Android Work Device Summary inadvertently creates Intelligence admin accounts for unprivileged admins.

Common Services

  • CMSVC-21034: Device count is incorrect when using smart group filter under Device List View on the UEM console.

Core Platform

  • CRSVC-71788: Certificate count in the Device Details > Summary does not match the data under Device Details > Certificates.

  • CRSVC-75006: Azure Token may not be revoked if device is deleted when offline.

  • CRSVC-75705: Conditional Access registration and status updates may not be sent when Partner-type OG is set as tenant.

  • CRSVC-77600: OAuth Client creation fails when the "description" contains a full-width space (U+3000).

  • CRSVC-77709: Resource delivery may be blocked due to stale overrides created by Compliance Policy evaluation.

  • CRSVC-79803: More Actions menu options are not visible when Freeze Mode is active.

  • CRSVC-80442: The "Renew Certificate" button on the Certificates list page does not work in UEM 2602.

Enrollment and Service Integrations

  • ESI-935: The API api/mdm/devices//enrollmentuser/ checks enrollment restrictions even when returning device to staging user.

Freestyle Orchestrator

  • FS-8052: Missing search functionality on workflow details page device status table.

  • FS-9298: Workflows could become stuck after a step completed, preventing cleanup and subsequent steps from running on macOS.

  • FS-9762: Event-based scripts execute more frequently than expected after device check-in on macOS.

  • FS-9815: macOS profile installation step in the workflow can hang indefinitely if Hub fails to report status.

  • FS-9816: WS1 Intelligent Hub could repeatedly reinitialize the scheduler’s timeouts, causing workflow steps(such as app installations) to remain stuck “In Progress” instead of properly timing out and failing on macOS.

  • FS-9911: Freestyle workflows do not re-execute on devices following unenrollment and re-enrollment.

  • FS-9932: Repeated profile installation attempts may occur if a response is missing during re-evaluation on macOS devices.

  • FS-9997: Workflow details page missing pagination on device status table.

  • FS-10101: Total Execution Count in the Freestyle Orchestrator overview has been reset.

  • FS-10111: Expired internal device credentials may cause workflows to be stuck in progress and prevent new workflows from executing on macOS devices.

  • FS-10219: A postinstall script issue may corrupt workflow binaries and prevent workflows from executing on macOS devices.

  • FS-10300: Workflow engine could crash after an upgrade, preventing workflows from executing on macOS.

iOS Management

  • AAPP-17906: Certain profiles do not auto deploy on iOS devices after a wipe.

  • AAPP-20076: Unable to view/modify/duplicate a ios HomeScreen Layout profile and getting an error.

  • AAPP-20124: Able to clear supervised iOS device's passcode with only Edit Device Remote Reboot permission.

  • AAPP-20452: Application Installation Commands showing sysadmin as createdby when manually initiated by admins in console.

  • AAPP-21015: {DeviceFriendlyName} value not populated on Enrollment Message.

  • AAPP-21301: Intermittent ADE Sync Failures Due to Apple Rate Limiting (HTTP 429).

  • AAPP-21302: App assignment shows more devices in the Newly added device count while adding a Smart Group.

  • AAPP-21344: Receiving email alerts for Application Removal Limit Exceeded for VPP apps.

  • AAPP-21403: Return to Service option not displaying any wi-fi profiles.

  • AAPP-21462: VPP apps are not updating on many devices.

  • AAPP-21467: Advanced Security Controls profile does not work as expected.

  • AAPP-21485: Unable to edit / add version to iOS VPN (L2TP type) profile.

  • AAPP-21508: VPP Applications are intermittently failing to install on "random" Devices.

  • AAPP-21626: VPP Assets not Syncing in UEM.

  • AAPP-21692: VPP apps not getting app config settings delivered.

  • AAPP-21843: Enhanced VPP integration synchronization to ensure proper cleanup when no licenses are returned.

  • AAPP-21885: Device Wipe command does not honor Preserve Data Plan setting resulting eSIM getting deleted on device under specific conditions.

  • AAPP-21936: API Call for ADE/DEP profile is returning incorrect values for "CustomPromptRequired" and "MessageTemplateId".

  • AAPP-21974: Unable to edit or create iOS VPN profile.

  • AAPP-21991: Unable to configure network usage rules payload profile for iOS platform DDUI.

  • AAPP-22202: Link not working as expected in the UEM console.

  • AAPP-22065: Profiles Framework- DDUI : Asset update is showing list of configurations for Apple iOS assets.

  • AAPP-22273: Inconsistency in availability of display name field in entitlements API and App details API.

  • AAPP-22293: Blank URLPrefixMatches causes iOS SSO profile failures.

  • AAPP-22485: VPP sToken Renew and Clear options are grayed out in the UEM Console.

  • AAPP-22508: OS updates in device updates tab showing 'Not Available'.

  • AAPP-22642: When attempting a manual sync for devices from Apple Business manager, sync ADE Devices isn't working.

  • AAPP-22963: ADE or DEP Settings tab is erroring out in several OGs, including the top OG.

  • AAPP-23098: Custom Attributes profile not installing after ModStack upgrade.

Launcher

  • LAUN-167: Launcher orientation not being honoured in Template Mode.

macOS Management

  • MACOS-5933: In MacOS Network profile, the trusted certificate selections are not persisted in the second tab onwards

  • MACOS-6598: Unable to enter text in "Desktop picture path" of macOS Restrictions payload.

  • MACOS-7103: Newer application versions, deployed to lower OGs were incorrectly inheriting and overwriting the Bundle Identifier schema.

  • MACOS-7327: WS1 Assist - 'Remote Assist' button goes away or missing on Hub sync.

  • MACOS-7488: NonPlatformSSOAccounts Key not working for macOS.

  • MACOS-7585: MacOS SSO Extension section in the VPN profile has changed after patch update.

Resource Management

  • ARES-32125: Intelligent Hub app catalog displays 'Install' action even though Internal Windows app is installed.

  • ARES-33619: App version should support special characters.

  • ARES-34405: Device Troubleshooting tab reports 'Pending install' for an already installed application on macOS devices.

  • ARES-34956: Static Certificate Upload in Credential Slot 3 Causes Mirroring of Certificate Data from Slot 1.

  • ARES-35041: Intelligence Workflow installs profile to devices not having valid assignment.

  • ARES-35262: Profile cannot be assigned to existing devices of an assigned Smart Group if profile also has Workflow assignment.

  • ARES-35498: Admin receives notifications about high usage of device app log storage.

  • ARES-36875: The API results for profile out of date is not accurate.

  • ARES-36887: Profile installation status not properly reflecting on the intelligence report.

  • ARES-36926: Unable to deactivate DDM profiles.

  • ARES-37109: Unable to delete Retired Apps.

  • ARES-37341: Profiles and Apps List view - Install Status view popup shows blank or empty content for all entries when mouse hover.

  • ARES-37354: Nested app configurations such as VPN settings fail to get saved.

  • ARES-37362: Seeing error occurred screen on clicking the count of Application Terms of use.

  • ARES-37420: Unable to fetch internal app install counts using API.

  • ARES-37443: When you do a bulk SEND option, page not found error is seen.

  • ARES-37447: We’re migrating deployments from Apps & Books to Product apps/Products using RSCC + caching/FTP, but two apps are stuck in an install–uninstall loop—l.

  • ARES-37451: Geofencing settings are not working in Mod stack.

  • ARES-37562: Multiple apps cannot be configured against setting ‘Allow Apps that can Utilize Widgets’ in Android Restrictions profile.

  • ARES-37644: Incorrect installation status reported for some profiles in Device's Profile list.

  • ARES-37672: Install Application and/or Install File actions are failing since upgrade from 2206 to 2410.

  • ARES-37706: Unable to uninstall VPP apps from the Device Details Apps list.

  • ARES-37759: UEM REST Endpoint /mam/apps/appgroups is not working as expected.

  • ARES-37842: Unable to reboot devices from Devices List View in Workspace ONE.

  • ARES-37879: Currently Assigned Profile List View export lacking the OS version.

  • ARES-37914: App version should support special characters.

  • ARES-37991: Admin initiated removal of iOS Applications failing when triggered from UEM Console.

  • ARES-38044: App update issue - On the apps which are not installed on the device, “Install” button is seen.

  • ARES-38439: Device profiles containing password fields may fail to authenticate, deploy, or open after copy or update.

  • ARES-38467: slow loading while navigating to App assignments.

  • ARES-38598: Saved tunnel configurations are not getting shown on UI.

  • ARES-38602: Verify all the models w.r.t assignments for deserialization issue.

Rugged Device Management

  • RUGG-14238: Searching and sorting products in device details page does not work if the device has more than 50 products.

  • RUGG-14240: URL Blocklist isnt functioning for Chrome Browser Restriction profile when published as Product profile.

  • RUGG-14288: Certificates renewal fails for Android devices published via Product provisioning profiles.

  • RUGG-14306: Relay server items won't be pushed to FTP when RSCC is used in some cases.

  • RUGG-14484: Product Set remains stuck in processing state, preventing edits.

  • RUGG-14521: Last Seen timestamp is incorrectly updated for devices belonging to smart groups assigned to a product upon product activation.

Tunnel

  • PPAT-21400: Default read-only role displays "door locked" error when viewing DTRs also default role incorrectly permits administrators to create Tunnel profiles.

User Management

  • UM-9753: LDAP sync page briefly shows an error message while loading - Directory sync service not configured.

  • UM-10919: Unable to create registration tokens more than 4 OGs below customer OG.

  • UM-11073: Enrollment to a child OG fails for basic users in OIS-enabled tenants.

  • UM-11104: SSP authentication to a child OG fails for basic users in OIS-enabled tenants.

  • UM-11138: Add missing users for directory user groups fails to add users with 16-byte sized User Principal Name.

  • UM-11206: User group memberships are updated when enrolling iOS or macOS devices even if Sync User Groups in Real Time is disabled.

  • UM-11153: OIS is failing to sync updates to the UEM Console.

Windows Management

  • AMST-44590: v1 application gets removed once v2 is assigned but not installed.

  • AMST-44925: Unable to edit a Baseline if saved with empty values.

  • AMST-45142: Unintended disable of DSP at child OG.

  • AMST-46045: App installed on Hololens are showing as "Not managed" preventing some management functionality.

  • AMST-46668: Filtering in Device Registration List View with Serial Number does not work.

  • AMST-46752: Dropship Provisioning Online may intermittently fail to register devices.

  • AMST-46929: Windows enrollment through OOBE moves the device to the organization group that contains the device s allow list record when DeviceMovementViaAllowListRecordFeatureFlag is enabled.

  • AMST-46946: Next button greyed out, app selection not persisting while editing ppkg.

  • AMST-47061: Enrollment restrictions now honored during CLI checkout, blocking auto-creation of unapproved user accounts.

  • AMST-47062: ARM64 apps are displaying in x64 device app catalog.

  • AMST-47071: Newer version of Enterprise Repository Apps get assigned even though assignment carry over is cancelled.

  • AMST-47167: Uncertainties with PPKG downloading.

  • AMST-47775: Profile Removal Failure from the device but removed from Workspace ONE UEM.

  • AMST-47779: Manage inclusion of AllowOOBEUpdates node according to OS build version.

  • AMST-47797: Device List view incorrectly shows Windows devices as "Multi User" for the Windows User Mode column though the device is enrolled as 'Single User'.

  • AMST-47878: Dell Command - Update is seen in the Enterprise App Repository but it is not seen in the Repository section for the actual application.

  • AMST-47928: Intelligent Hub on Windows is not updating after UEM upgrade to 2509.

  • AMST-48010: ADMX profile troubleshooting and diagnostic failed to install and lead to "DDUI profile payload is empty" Error.

  • AMST-48067: EAR App: "Update Now" opens new assignment page instead of showing existing assignments.

Patch Resolved Issues

Patch 1

  • VULN-2214: While processing device vuln from crowdstrike ensure to check for AID by ignoring the CID prefix.

  • SINST-176834: Add checksum check from NET binaries while downloading.

  • CRSVC-87649: Update device state patch regex.

  • ATL-30514: Seed Workspace ONE Intelligent Hub v26.07 for Windows.

  • ATL-30049: Seed - Machost to canonical release PR2607-1.

  • ARES-39264: DDUI FileStandAlone: files larger than 10 MB are silently corrupted on upload (intermittent).

  • AMST-48067: EAR App: "Update Now" opens new assignment page instead of showing existing assignments.

  • AGGL-20007: DLV Filters – No devices returned when Device Model is set to Android for AMAPI COPE devices.

Known Issues

We haven’t identified any notable known issues in this release. If you are facing any problems, feel free to reach out to our support team.

Release Availability

We strive to deliver high-quality products, and to ensure quality and seamless transitions, we roll out our products in phases. Each rollout may take up to four weeks to accomplish and is delivered in the following phases:

  • Phase 1: Demo, Shared SaaS UATs, and Latest Mode UATs

  • Phase 2: Shared SaaS environments

  • Phase 3: Latest Mode environments

Getting Ready for Major OS Releases

To prepare for the upcoming software updates from major device vendors, read through the Getting Ready for Major OS releases section of the Omnissa Product Documentation.

Documentation

To learn more about Workspace ONE UEM, browse Workspace ONE UEM Documentation.

Localized Content for Omnissa Docs

For details on Omnissa's localization strategy, see the KB article: Announcing Omnissa Localization Support.

Support Contact Information

To receive support, access Omnissa Customer Connect. For information about filing a Support Request in Customer Connect and using Cloud Services Portal, see the KB article here.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…