Skip to main content

August 21, 2026

Android OS Compatibility & Behavior Tracker for Workspace ONE UEM

As Android continues to evolve, each new OS version introduces changes that can affect device behavior, management capabilities, and overall compatibility with Workspace ONE UEM. From updated enterprise APIs to modified permission models, these platform updates often impact how IT administrators configure, deploy, and support Android devices in their environment.

To help you stay ahead of these changes, the Android OS Compatibility & Behavior Tracker provides a centralized, version-by-version overview of how Workspace ONE UEM integrates with Android. This includes:

  • A breakdown of Workspace ONE UEM compatibility by Android version
  • Notes on any quirks or limitations we’ve observed
  • Highlights Android platform behaviors that might affect your device management
  • Workspace ONE version requirements to support new OS features

This page is updated regularly so you always have the latest info as Android continues to evolve.

Major OS Releases

Android 16

Android 15

Android 14

Android 12

Android 16 (2025)

Starting in June 2025, Android 16 is available on Pixel Android devices with subsequent rollouts happening in the coming months. This document provides information on the updates in Android 16 and preparations to make for your organization’s Workspace ONE UEM environment. More information on the Android 16 can be found here: Android Developer website.

Resources for Application Developers

  • Changes that affect all apps can be reviewed here.
  • Changes affecting apps that target Android 16 can be reviewed here.
  • Updates to non-SDK interface restrictions can be reviewed here.

Workspace ONE UEM Console Support for Android 16

Omnissa updates the device seed data in our Workspace ONE UEM console on SaaS to support Android 16 enrollments, enrollment restrictions, and any filters targeting Android 16. In case the seed data is needed for an on-Premises environment, the cumulative seed data update script can be used to support Android 16.

OS Updates Seed Script

Application Support for Android 16

Omnissa validates applications with the latest OS releases to ensure your devices are successful upon upgrade. To ensure a successful upgrade, users are encouraged to update to the specified version of each Android app listed to fully support Android 16.

ApplicationAndroid 16 Supported Version
Assist25.02
Boxer25.04
Content25.02.1
Workspace ONE Intelligent Hub25.05
Workspace ONE Launcher25.05
Mobile Threat Defense SDK25.04
Workspace ONE SDK25.02
Tunnel25.02
Web25.02.1
Send25.02.1
PIV-D24.11.02

Android 15 (2024)

Android 15 is generally available as of September 2024. This document is your guide for updates in Android 15 and preparations to make for your organization’s Workspace ONE UEM environment. More information on the Android 15 can be found here: Android Developer website.

Resources for Application Developers

  • Changes that affect all apps can be reviewed here.

  • Changes affecting apps that target Android 15 can be reviewed here.

  • Updates to non-SDK interface restrictions can be reviewed here.

  • Some changes affecting enterprises can be found here.

New Features

Google introduces a host of new features and enhancements for the enterprise in Android 15. Below is a comprehensive list of these features.

Note: This article does not indicate support for any of the below features with Workspace ONE UEM. To learn more about new, supported features, follow our Workspace ONE UEM Release Notes.

Embedded SIM (eSIM) Remote Provisioning and Management

Android 15 allows organizations to remotely provision embedded SIMs (eSIMs) to managed devices. Organizations can obtain eSIM activation codes from their carriers and push them to devices via UEM solutions. This cuts down on the effort required to onboard or change eSIM providers across a fleet of managed devices. Android joins other platforms, including iOS and Windows, that support remote eSIM provisioning.

On corporate-owned devices, this provisioning process is silent, and organizations can optionally activate the managed eSIM. On employee-owned devices, end users are required to consent to activating the managed eSIM.

Because eSIMs provisioned by organizations are considered managed, organizations can remove them from the device at any time.

Private Spaces

With Android 15, devices enrolled in Work Profile or Corporate Owned Personally Enabled mode, users can now create a Private Space. This is a separate app container in the personal profile that allows users to lock certain applications behind a separate pin or password. For Corporate Owned Personally Enabled (COPE) devices, Android 15 also introduces the ability for organizations to disable Private Spaces.

Private spaces are not available on devices in Work Managed mode.

Changes to Screen Recording

With Android 15, Google introduces two enhancements to screen recording/sharing that can help secure sensitive organization resources:

  • Applications can now detect if the device’s screen is being recorded while said applications are in the foreground.
  • Applications can share or record just an app window rather than the entire device screen. This feature was first enabled in Android 14 QPR2 for certain devices, such as Pixel. When starting a screen sharing session, users are prompted to select whether they wish to share a single application or the entire screen.

More Device Management Policies

Google has also introduced new device management features with Android 15 that allow organizations to:

  • Disable Thread Networking, a networking protocol that allows Android to interact with smart home and other IoT systems. This is similar to the introduction of a policy in Android 14 to disable ultra-wideband. This policy is only available on corporate-owned devices.
  • Prevent users from adding embedded SIMs to a managed device. This policy is only available on corporate-owned devices.
  • Disable Assist Content: Prevents contextual information about an application from being visible to Assistant applications. Contextual information includes what is displayed on the application’s view currently in the foreground.
  • Manage screen brightness and timeout on COPE devices: Android 15 now extends the ability to set a screen brightness level, enable/disable automatic screen brightness, and set the screen timeout for Corporate Owned Personally Enabled (COPE) devices. This was previously only possible on Work Managed devices.
  • Prevent users from modifying default applications in the personal profile on Corporate Owned Personally Enabled devices.

Known Issues

We have identified an issue preventing enrollment of Android 15 devices into Workspace ONE UEM in Custom DPC mode. Devices on Android 15 whose Google Play Services (com.google.android.gms) version is lower than 24.29.00 will fail to enroll into Workspace ONE UEM. Although no failures are seen in Intelligent Hub, devices are stuck in an Enrollment In Progress status in the Workspace ONE UEM Console, and applications, profiles, and other resources are not pushed to the device.

This issue will not affect most employee-owned devices since Google Play Services is a system that Android updates automatically. If needed, follow these steps to manually update Google Play Services - Keep your device & apps working with Google Play Services. For corporate-owned devices, if the Google Play Services version in the device image is lower than 24.29.00, this issue will be seen when enrolling with Intelligent Hub 24.07. We are actively working to resolve this issue in an upcoming release of Intelligent Hub. More information will be posted in this document.

Workspace ONE UEM Console Support for Android 15

Omnissa automatically updates the device seed data in our Workspace ONE UEM console on SaaS to support Android 15 enrollments, enrollment restrictions, and any filters targeting Android 15.

In case the seed data is needed for an On-Premise environment, the cumulative seed data update script below can be used to support Android 15.

OS Updates Seed Script

Application Support for Android 15

Omnissa validates applications with the latest OS releases to ensure your devices are successful upon upgrade. To ensure a successful upgrade, users are encouraged to update to the specified version of each Android app listed below to fully support Android 15.

ApplicationAndroid 15 Supported Version
Assist24.03
Boxer24.09
Content24.07
Intelligent Hub24.07
Launcher24.08
SDK24.07
Tunnel24.08
Web24.08
Send24.01
PIV-D24.07

Android 14 (2023)

Android has launched the Android 14 as of October 2023. This document is your guide for all of the updates and any preparations to make for your organization's Workspace ONE UEM environment.

More information on the Android 14 can be found here.

The Android Preview program runs yearly in anticipation for each major OS release. It consists of iterative releases of Android, from early Developer Previews up to more stable Beta builds. Once Android 14 reaches a milestone called Platform Stability, further releases will contain minimal changes. This is the earliest point where Workspace ONE UEM can declare support for Android 14. test

New Features

To review new Android Enterprise features on Android 14, see the Google Developer page.

  • For Android app developers, please review behavior changes that may affect your apps: Changes affecting all apps can be reviewed on the here.
  • Changes affecting apps that target Android 14 can be reviewed here.
  • Updates to non-SDK interface restrictions can be reviewed here.

Behavior Changes in Workspace ONE UEM on Android 14

The following behavior changes in Workspace ONE UEM have been identified with Android 14:

  • Deprecation of Restrictions on Cross-profile Contact/Caller ID Access

Earlier Android versions introduced support for blocking the personal applications from accessing managed contacts stored in the Work Profile. In Workspace ONE UEM, these controls are available as part of the Android Restrictions Profile:

  • Allow Work Contact Caller ID
  • Allow Work Contacts in Personal Contacts App

Android 14 deprecates these global controls. Installing a Restrictions Profile with these settings disabled will no longer block access to managed contacts.

  • Deprecation of Samsung APIs used for Samsung APN Profile Payload

In KNOX 3.8, Samsung deprecated their OEM-specific APIs used by Workspace ONE UEM to configure Access Point Names on Samsung devices. With Android 14, these APIs will cease to work. This means that the Samsung-specific APN Profile Payload will no longer work on Samsung devices running Android 14.

Intelligent Hub 23.02 introduced a new way to add Access Point Name configurations to any Work Managed Android device. This leverages OEM-agnostic APIs and therefore can be used to manage APNs on any Android device on OS 9.0 and higher that is enrolled in Work Managed mode. As of June 21st, 2023, this OEM-Agnostic capability is only supported through the Custom Settings Profile Payload. In the future, Workspace ONE UEM will support this as a new, separate Profile Payload in the Workspace ONE UEM Console.

  • Domain requirement in Enterprise Wi-Fi Profiles

As part of Android mainline updates rolled out starting in April 2023, devices running Android 11 and higher will now require a Domain value in any Enterprise Wi-Fi configurations. Administrators should specify a Domain value in any Android Wi-Fi Profiles with Security Type set to WPA/WPA2 Enterprise. If they do not, devices with the latest mainline update will fail to connect to the network. This impacts:

  1. Devices on Android 11 through 13 that receive Android mainline updates from April 2023 and later
  2. All devices on Android 14 and higher

The Domain field was introduced in Workspace ONE UEM 2210. For more information on the Domain field, please see the Wi-Fi section in How to Configure Android Profiles.

For Workspace ONE UEM versions lower than 2210, please see the Workaround section in WPA2 Enterprise Wi-Fi Profiles fail to install on Android 11+ devices (92679).

Known Issues

The following are Known Issues with Android 14 at time of its release:

  • Changing the Work or Device Passcodes

Sending a Change Device Passcode or Change Work Passcode command to an Android 14 device may fail if the new passcode has a length of 4 or 5 (e.g. a 4- or 5-digit pin). In these cases, the Device or Work Profile cannot be unlocked. To regain access to the device, send a new command to set a new passcode with length 6 or higher.

This issue will be resolved in the Android 14 QPR1 release.

Workspace ONE UEM Console Support for Android 14

Omnissa automatically updates the device seed data in our Workspace ONE UEM console on SaaS to support Android 14 enrollments, enrollment restrictions, and any filters targeting Android 14.

In case the seed data is needed for an On-Premise environment, the cumulative seed data update script below can be used to support Android 14.

OS Updates Seed Script

Omnissa Application Support for Android 14

Omnissa validates applications with the latest OS releases to ensure your devices are successful upon upgrade. To ensure a successful upgrade, users are encouraged to update to the specified version of each Android app listed below to fully support Android 14.

ApplicationAndroid 14 Supported Version
Assist23.07
Boxer23.07
Content23.08
Intelligent Hub23.07
Launcher23.07
Notebook
SDK23.06
Tunnel23.06
Web23.08
Send23.01

Android 12

As of September 29th, 2022, Android 12 is generally available from Google, please check with your device manufacturer to see when Android 12 will be available to you.

Intelligent Hub 22.09 will target API Level 31.

New Features To review new Android Enterprise features on Android 12, click here. For Android app developers, please review behavior changes that may affect your apps:

  • Changes affecting all apps can be reviewed here.
  • Changes affecting apps that target Android 12 can be reviewed here.
  • Updates to non-SDK interface restrictions can be reviewed here.

Behavior Changes in Workspace ONE UEM on Android 12

  • Work Profile devices running Android 12 will not be able to sample non-resettable device identifiers such as Serial Number, IMEI, and MEID.
    • Existing devices upgrading to Android 12 will not be impacted as these identifiers will already be sampled
    • Newly enrolling devices will no longer be able to capture these device details.

Any functionality depending on IMEI or Serial Number, including any configured enrollment restrictions to look for those values, would not work and Android 12. Work Profile devices would be blocked from enrolling. Suggested Alternative: If these identifiers are to be used to identify an enrolled device across different systems, Device UDID is recommended.

  • Work Profile devices running Android 12 will also not be able to sample SIM Card Serial Numbers. For existing devices upgrading to Android 12, SIM Card values may no longer be shown in the Workspace ONE UEM Console.

  • Android 12 Work Profile & COPE enrollments can no longer pre-grant certain permissions. If needed, users can grant the following permissions to work profile apps unless denied by their IT administrator, and they can no longer be pre-granted.

    • Location
    • Currently needed to collect Wi-Fi SSID, IP address, and MAC address
    • Camera
    • Microphone
    • Body sensor
    • Physical activity

Behavior Changes in Workspace ONE Intelligent Hub when targeting Android 12 Applications delivered through the Google Play store are required to be within one year of the available target API level each November. Behavior of applications on Android 12 and newer devices may change when Intelligent Hub begins targeting the Android 12 API level this November. Omnissa is continuing to do testing on the full impact of updating the target API level and will make information available in the knowledge base.

The full list of changes affecting apps that target Android 12 can be reviewed here. Known behavior changes when updating to the version of Intelligent Hub which will target Android 12 (release version TBD) are documented below.

  • Several APIs related to password quality requirements were formally deprecated in favor of a new API introduced in Android 12 to enforce password complexity. See Passcode Profile Changes for Android 12 for more details:
    • Workspace ONE UEM Console 2212 introduces support for configuring these new complexity values directly.
    • On Workspace ONE UEM Console releases older than 2212, for Work Profile Android 12+ devices on Intelligent Hub 22.09+, the passcode requirements enforced may differ from the requirements set in the Passcode Profile. This is because the new API is not a direct replacement of the existing API. See Versions of Workspace ONE UEM that only support Passcode Content and Minimum Length for more detail.
    • Fully managed devices and COPE devices as well as all Android 11 and lower devices are exempt from this API deprecation.

More behavior changes will be documented as testing continues.

Overview of Passcode API Updates for Android 12

Previously, organizations have been able to set minimum complexity requirements for device and Work Profile passcodes in a granular manner. In the Workspace ONE UEM Console, admins can do so by setting a minimum Passcode Content (Numeric, Complex Numeric, Alphanumeric, etc.) and a Minimum Passcode Length.

Once Intelligent Hub targets Android 12, the APIs used to set a minimum Passcode Content and Minimum Passcode Length are deprecated in favor of new APIs used to require broader complexity levels. Fully Managed and COPE devices are exempt from this deprecation. The new APIs allow organizations to enforce a Passcode Complexity of Low, Medium, and High.

More specifically, the effect for different passcode types and modes in Android 12 is as follows:

Device Passcode

  • For Work Profile devices, organizations can no longer set Passcode Content and Minimum Passcode Length requirements. Only the new Passcode Complexity (Low, Medium, High) can be required.
  • For Fully Managed and COPE devices, organizations can use Passcode Complexity (Low, Medium, High). They can still opt into setting granular complexity requirements through Passcode Content and Minimum Passcode Length instead.

Work Passcode

  • For all devices, organizations can use Passcode Complexity (Low, Medium, High). They can still opt into setting granular complexity requirements through Passcode Content and Minimum Passcode Length instead.
  • Setting broader complexity requirements makes it easier for end users to remember their passcodes. Per Google, Android uses hardware-backed throttling to thwart online and offline brute-forcing of the device's screen lock, so setting granular passcode complexity requirements may not offer the same security benefits it once did.

Passcode Profile Changes in Intelligent Hub 22.09

Intelligent Hub 22.09 will target API Level 31 and will support the new Passcode Complexity settings. As of writing, support for setting the new Passcode Complexity was introduced in Workspace ONE UEM Console 2212.

Until organizations upgrade to Workspace ONE UEM Console 2212 or higher, end users with Work Profile devices on Android 12 or higher may see device passcode requirements that are more restrictive than those set by the admin in the Passcode Profile.

For Work Profile devices on Android 12 or higher, Intelligent Hub will translate the Device Passcode settings from Passcode Content (Any, Numeric, Numeric Complex, etc.) and Minimum Length to Passcode Complexity:

Profile Specific Information

Managing Wi-Fi on Android 10 & 11 requires Location Services enabled

Issue

On Android 10 and 11 devices where Location Services is disabled, Workspace ONE UEM is unable to remove or update Wi-Fi configurations. As such, if:

  1. A Wi-Fi profile is uninstalled from the device, Workspace ONE UEM will be unable to remove the Wi-Fi configuration from the device.
  2. A new version is added to an existing, installed Wi-Fi profile, Workspace ONE UEM will be unable to update the Wi-Fi configuration on the device with any settings changes in the new profile version.

When updating or removing a network fails, the following is seen in Android device logs (some values in the snippet below replaced dummy characters):

E/Wi-FiService: Permission violation - getConfiguredNetworks not allowed for uid=####, packageName=com.xxx.xxx, reason=java.lang.SecurityException: Location mode is disabled for the device

Cause

If an Android device management client attempts to view managed networks on the device, Android will block this operation if Location Services is disabled on the device.

Resolution

While this seems to be expected behavior in Android 10 and 11, we are actively working with Google to obtain confirmation.

Workaround

On Android 10 and 11 devices enrolled in Work Managed mode, enable Location Services by pushing a Restrictions profile with Allow Location Service Configuration set to any value other than None.

Note: Setting Allow Location Service Config in Android 11 or later to any value will only enable Location Services - not set the location accuracy.

WPA2 Enterprise Wi-Fi Profiles fail to install on Android 11+ devices

Symptoms When organizations install Wi-Fi Profiles with Security Type WPA/WPA2 Enterprise, the Profile may fail to install on Android 11+ devices if a Domain value is not specified in the Profile. This issue occurs even if a Root Certificate is specified in the Wi-Fi Profile. The Domain field was introduced in Omnissa Workspace ONE UEM 2210. When the issue occurs, the Profile install status is "Failed". The issue occurs on Android 11+ devices that have received the latest security updates.

Android device logs show the following:

E Wi-FiConfigManager: Enterprise network configuration is missing either a Root CA or a domain name

Resolution

As part of Android mainline updates rolled out starting in 2023, Android 11 and higher will now require a Domain value in any Enterprise Wi-Fi configurations. Administrators should specify a Domain value in any Android Wi-Fi Profiles with Security Type set to WPA/WPA2 Enterprise. If they do not, devices with the latest mainline update will fail to connect to the network. This impacts:

  • Devices on Android 11 through 13 that receive Android mainline updates from April 2023 and later
  • All devices on Android 14 and higher

The Domain field was introduced in Omnissa Workspace ONE UEM 2210. For more information on the Domain field, please see the Wi-Fi section in How to Configure Android Profiles:

  • Domain is currently only a supported field in Profiles created under [Resources > Profiles & Baselines > Profiles]. It is not a supported field for Profiles for Products created under [Devices > Products > Components > Profiles]. For Profiles used for Product Provisioning, Custom Settings profiles will have to be used instead. See Workaround section below.
  • For Workspace ONE UEM versions lower than 2210, please see the Workaround section for steps to configure a Wi-Fi Profile using a Custom Settings Profile Payload.

Workaround

If you are using a version of Workspace ONE UEM lower than 2210, you may use Custom Settings payloads to add the Domain parameter to the Wi-Fi configuration.

Before you begin:

Identity and Password: When administrators view or edit Profiles, the Workspace ONE UEM Console obfuscates sensitive fields like Identity and Password. When using Custom Settings Profiles, these values will be displayed in plain text in the Workspace ONE UEM Console. If access to these values is restricted to specific administrators in your organization, consider using Administrator Roles to restrict access to viewing Profiles in the Workspace ONE UEM Console.

Certificates: If your Profile uses certificates, it is important to create a copy (Step 1) and replacing the Wi-Fi payload with a Custom Settings payload in the copy Profile. This is to preserve the Credentials payload and its mapping to the Identity and Root Certificates in the Wi-Fi payload.

Configure Custom Settings Profile with Domain Field

  1. Create copy of the existing Wi-Fi profile by navigating to Resources > Profiles & Baselines > Profiles.
  2. Click the radio button next to the affected Wi-Fi profile.
  3. Select More Actions > Copy
  4. Rename the profile and continue through the prompts until profile is completed.
  5. Export an XML version of the Profile copy (generated in Step #1)
    • Click the radio button next to the profile and select XML
    • Copy the Profile XML data and paste it into a text editor.
  6. Separate Wi-Fi payload from profile XML and add Domain field.
    • Search for the beginning of the “com.airwatch.android.androidwork.Wi-Fi” characteristic and separate it from the rest of the data.
    • Delete the data that above this as this is the only data that is needed.
    • Remove the “” from the end of the data.
    • Add the Domain parameter as a new line in the profile XML - .
  7. Create Custom Settings Payload
    • Edit the COPIED Wi-Fi Profile
    • Delete the Wi-Fi Payload by clicking the Trash icon to the right of the Wi-Fi payload.
    • Add a “Custom Settings” payload. Paste the XML created in Step 3.
    • Save and publish profile.

Verify New Profile

  1. Install the new profile to Android 11+ devices with the latest security updates
  2. Verify proper install and domain configuration.

If you are seeing errors:

  • Verify all opening tags are closed properly in your custom settings XML.
  • Verify “PayloadCertificateUUID” and “CAPayloadCertificateUUID” match with the corresponding Characteristic UUID removed.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…