Workspace ONE Tunnel for Android and ChromeOS Release Notes describe the new features and enhancements in each release. This page contains a summary of the new capabilities, issues that have been resolved, and known issues that have been reported in each release over the last 12 months.
Workspace ONE Tunnel 26.06
New Features
Behavior change to DNS resolution when the use_internal_dns_for_domains Tunnel server KVP is configured
We are standardizing the behavior of the use_internal_dns_for_domains Tunnel server KVP across all Tunnel clients. Going forward, any domain listed in this KVP will always have its DNS requests sent over Tunnel and resolved by internal DNS — regardless of how Device Traffic Rules (DTR) are configured for that domain. This ensures consistent, predictable behavior across all platforms.
Impact on Android Tunnel: This change has a direct behavioral impact on Android clients for deployments that make use of the use_internal_dns_for_domains Tunnel server KVP.
For more information, see Action Required for Android Tunnel customers: DNS resolution change starting with Android Tunnel 26.06.
New Diagnostic and Configuration History Logs
The client now generates dedicated diagnostic and configuration history logs, providing a record of configuration changes and profile updates to simplify troubleshooting.
Improvements to handle device Sleep and Wake events
Improved handling of device sleep and wake events to maintain connectivity to tunneled resources following periods of inactivity.
Starting with Workspace ONE UEM 2602, Tunnel client on Android now supports zero-downtime server certificate rotation for both Workspace ONE CA and Third Party CA-issued certificates.
Minimum Requirements
- Android 12 and later
- Workspace ONE UEM Console 2410 or later
- Unified Access Gateway 2406 or later | Workspace ONE Tunnel Container 24.12 or later
Resolved Issues
-
PPAT-21185: Client does not show the Send Log option.
-
PPAT-21951: Client keeps disconnecting in Lockdown mode.
Known Issues
We haven’t identified any notable known issues in this release. If you encounter any issues, contact Omnissa support team.
Workspace ONE Tunnel 26.03
New Features
Support zero-downtime Tunnel Server certificate rotation
Starting with Workspace ONE UEM 2602, Tunnel client on Android now supports zero-downtime server certificate rotation for both Workspace ONE CA and Third Party CA issued certificates.
New information added to Client Access Log
- Connections to the Web Proxy
- DNS Request and Response
- Tunnel Server configuration
Minimum Requirements
- Android 12 and later
- Workspace ONE UEM Console 2410 or later
- Unified Access Gateway 2406 or later | Workspace ONE Tunnel Container 24.12 or later
Resolved Issues
We are always working to improve Workspace ONE Tunnel with every release. There are no major bug fixes to report.
Known Issues
We haven’t identified any notable known issues in this release. If you encounter any issues, contact Omnissa support team.
Workspace ONE Tunnel 25.12.2
New Features
In this release, we have made a few updates containing general quality and performance improvements.
Minimum Requirements
- Android 12 and later
- Workspace ONE UEM Console 2410 or later
- Unified Access Gateway 2406 or later | Workspace ONE Tunnel Container 24.12 or later
Resolved Issues
Public IP address is not reported. This is in support of Geolocation Policies with Workspace ONE Tunnel, which is now in Limited Availability.
Known Issues
We haven’t identified any notable known issues in this release. If you encounter any issues, contact Omnissa support team.
Workspace ONE Tunnel 25.12.1
New Features
- Improvements to Tunnel server reachability check.
Minimum Requirements
- Android 12 and later
- Workspace ONE UEM Console 2402 or later
- Unified Access Gateway 2406 or later | Workspace ONE Tunnel Container 24.12 or later
Resolved Issues
- PPAT-21008: Tunnel does not automatically connect after device check-out.
Known Issues
We haven’t identified any notable known issues in this release. If you encounter any issues, contact Omnissa support team.
Workspace ONE Tunnel 25.12
New Features
-
Device Traffic Rules (DTR) now support HTTP Web Proxy, enabling direct devices to proxy connectivity.
Note: Starting with Workspace ONE UEM 2511, there is an update to DTR Actions options.- The original Proxy Action label, previously used for Mobile SSO workflows, is renamed to MobileSSO.
- The Proxy Action label now applies to the new Web Proxy workflows.
- All existing Proxy Action rules are now automatically migrated to MobileSSO rules. No admin action is required.
-
SAML Re-authentication on Device Reboot
- Administrators can now force users for SAML re-authentication after a device reboot. This enhancement provides an additional security layer by ensuring that users re-verify their identity before accessing resources post-restart.
- Enablement: Android Tunnel App Config KVP
- KVP:
ForceMFAonReboot - Value:
True|False(default)
- KVP:
-
As part of the ongoing Device Trust for Workspace ONE Technical Preview, administrators can now prompt users to install the required Android Device Policy app, if not already installed.
- Enablement: Standalone Tunnel Profile - Custom Settings
- Key:
InstallADP - Value:
True|False(default)
- Key:
- Enablement: Standalone Tunnel Profile - Custom Settings
Minimum Requirements
- Android 12 and later
- Workspace ONE UEM Console 2402 or later
- Unified Access Gateway 2406 or later | Workspace ONE Tunnel Container 24.12 or later
Resolved Issues
- PPAT-20484: Tunnel app may crash when PCP is enabled.
- PPAT-20802: DTR do not work for IP ranges using non-octet CIDR masks.
- PPAT-20806: Tunnel app does not connect if user interacts with the SAML MFA prompt after server has disconnected the client session after the idle-timeout.
Known Issues
We haven’t identified any notable known issues in this release. If you encounter any issues, contact Omnissa support team.
Workspace ONE Tunnel 25.08.1
New Features
In this release, we have made a few updates containing general quality and performance improvements.
Minimum Requirements
The following are the minimum requirements for this release.
- Android 12 and later
- Workspace ONE UEM Console 2402 or later
Resolved Issues
-
PPAT-20497: Unable to access internal websites over DTLS channel.
-
PPAT-20395: Tunnel does not reconnect in on-demand mode when the 'All Other Apps' DTR is set to Tunnel.
Known Issues
We haven’t identified any notable known issues in this release. If you encounter any issues, contact Omnissa support team.
Workspace ONE Tunnel 25.08
New Features
- Request Tunnel client log from Workspace ONE UEM.
- Log can be requested and retrieved from the UEM console by navigating to Device > Details View > Apps > Tunnel > Request Logs.
- You can retrieve current Tunnel log or set desired log level and upload after set time.
Minimum Requirements
The following are the minimum requirements for this release.
- Android 12 and later
- Workspace ONE UEM Console 2402 or later
Resolved Issues
We are always working to improve Workspace ONE Tunnel with every release. There are no major bug fixes to report.
Known Issues
We haven’t identified any notable known issues in this release. If you encounter any issues, contact Omnissa support team.
Workspace ONE Tunnel 25.02.1
New Features
- Added improvements to Access Log to include Tunnel server connection information.
Minimum Requirements
The following are the minimum requirements for this release.
- Android 12 and later
- Workspace ONE UEM Console 2310 or later
Resolved Issues
PPAT-19723: Application Configuration Custom Settings are not enforced correctly.
Known Issues
We haven’t identified any notable known issues in this release. If you encounter any issues, contact Omnissa support team.
Workspace ONE Tunnel 25.02
New Features
-
Send Tunnel client log to Workspace ONE UEM.
- User can now use the “Send logs to admin” option under the Diagnostics menu to upload the Tunnel client log to UEM.
- Log can be retrieved from the UEM console by navigating to Device > Details View > More > Attachments.
-
Added an ‘Access Logs’ file for better visibility into device network activity.
-
Improvements to PCP skip list evaluation to include support for sub-domains.
Minimum Requirements
The following are the minimum requirements for this release.
- Android 12 and later
- Workspace ONE UEM Console 2306 or later
Resolved Issues
We are always working to improve Workspace ONE Tunnel with every release. There are no major bug fixes to report.
Known Issues
We haven’t identified any notable known issues in this release. If you encounter any issues, contact Omnissa support team.
Support Contact Information
To receive support, either submit a ticket through the Customer Connect portal or call your local support line. See Omnissa Support Phone Numbers (6000004) and Omnissa Customer Connect FAQs.
Download Instructions
- Prior Version is Installed: Direct end users to update the app when prompted. The application seamlessly updates over the existing application version without disrupting the device's enterprise functionality.
- Prior Version is Not Installed: Direct end users to download it from the PlayStore.
Was this page helpful?