VMware Workspace ONE UEM™ Powered by AirWatch Release Notes provide information on the new features and improvements in each release. This page includes a summary of the new features introduced in 2111 and Resolved Issues and Known Issues.

When can I expect the latest version?

We strive to deliver high-quality products, and to ensure quality and seamless transitions, we roll out our products in phases. Each rollout may take up to four weeks to accomplish and is delivered in the following phases:

  • Phase 1: Demo and UATs
  • Phase 2: Shared SaaS environments
  • Phase 3: Dedicated latest environments

Once our phased rollout is complete, we will announce general availability for on-premises and managed hosted customers. For more information, see the KB article.

Getting Ready for Apple Fall 2021 Releases

Learn more about the upcoming Fall 2021 releases for Apple. See Getting Ready for Apple Fall 2021 Releases for more information.

Upcoming Features and Tech Previews

Learn about the features and capabilities of Workspace ONE UEM that are in technical preview or will be released soon. Technical preview features are not fully tested, and some functionality might not work as expected. However, these previews help Workspace ONE UEM improve current functionality and develop future enhancements.

  • Workspace ONE Drop Ship Provisioning (Online) offers self-registration of Windows devices as a technical preview.

    As an alternative to the current Drop Ship Provisioning (Online) process where you work with your OEM to register your Windows devices, you can use this process to register and provision your devices yourself. This process is also helpful to test the provisioning of a few devices before you send your provisioning orders to your OEM. For self-registration, you work on the Windows device and in the Workspace ONE UEM console. You stage Windows devices with the Drop Ship Provisioning Generic PPKG and register your devices and configure their profiles in the console. For details about this technical preview, access Technical Preview: Self-Registration for Workspace ONE Drop Ship Provisioning (Online).

New Features in this Release

Console

  • Stay informed with our brand new console banner notifications.

    With the new console banner notifications that appear across the top of the UEM console, you can stay updated on maintenance issues, upgrades, outages, and product announcements. For more information, see Console Notifications.

  • Use Launcher devices without going through the entire authentication process.

    You can now designate a second Launcher profile as a Guest Session profile and enable users to skip directory authentication and quickly access installed applications. For more information, see VMware Workspace ONE Launcher.

  • Keep your workflow going with the improved Bulk Delete command.

    Previously when you issued a Bulk Delete command that triggered Wipe Protection, the Bulk Delete command would end and you had to manually delete the devices. We’ve improved the workflow so that Bulk Delete now resumes after resolving Wipe Protection. For more information, see Device List View.

  • Avoid abandoning devices and child OGs with our new OG deletion logic.

    Now when you attempt to delete an organization group in the UEM console, the system checks for child OGs and devices in the OG you are trying to delete. If it finds a child OG or a device anywhere in the OG tree, the deletion is cancelled. For more information, see Delete an Organization Group.

  • Add your operating system language to your DropShip Provisioning (Offline) encrypted PPKG packages.

    You can now add your operating system language when you configure encrypted packages for DropShip Provisioning (Offline). Enter a Microsoft approved BCP 47 Code in the Custom OS Language field. This setting ensures that your encrypted packages run in the correct date and time format. Find this new field in Devices > Lifecycle > Staging > Windows. Make a new provisioning package or edit an existing one. Select Encrypted PPKG and go to Configurations > OOBE Configuration > Operating System Language > Other. For more information, see Working with Provisioning Packages.

  • Discontinue use of API

    The API "/devices/{id}/sendmessage" was functional till Workspace ONE UEM console version 2010. From Workspace ONE UEM version 2111, we have now fully deprecated the API. Please visit https://<API Server URL>/API/help for more about the API information.

Freestyle

  • We've made a few enhancements to the Freestyle Orchestrator.

    Freestyle has been promoted from technical preview to limited availability for SaaS customers. The following improvements to Freestyle Orchestrator have been made in this release.

    • We have added a fast lane delivery of workflows to small device fleets. That is, workflows being deployed to <2000 devices, the devices will be notified immediately upon publishing.
    • Workflows in Windows can be retrieved by devices during device check-in even when no user is logged in. This behavior requires Windows Hub 22.01.
    • Workflow statuses will now be reported more frequently by devices to increase visibility to administrators, and this requires Windows Hub 22.01.
    • We have made changes to the Hub catalog and assignment statuses behavior when an app is assigned both from workflows and directly.
    • Additionally, admins can now add a change log to workflows and force them to execute.

Android

  • We’ve made performance enhancements to improve batching of Android public application deployment.

    These improvements will benefit larger app deployments, whether automated or on-demand.

  • We’ve made check-in check-out more flexible by introducing guest sessions for Launcher

    You can now designate a second Launcher profile as a Guest Session profile and enable users to skip directory authentication and quickly access installed applications. For more information, see VMware Workspace ONE Launcher.

  • Want to block enrollment for non Android Enterprise devices?

    If "Always Use Android" is enabled and device is not certified for Android Enterprise use, enrollment is blocked and user will see a "Android Enterprise enrollment is required to continue for this device" message on their device.

    For more information, see Android Device Enrollment.

  • Want to customize Launcher Settings without using Custom XML? We have a solution for you.

    We've simplified Workspace ONE Launcher configuration by adding UI controls for 14 features that previously required Custom XML. You can see these features implemented with the new data-driven user interface for Android. The Launcher profile configuration now includes the following Advanced Launcher Settings:

    • Use Legacy Launcher APIs
    • Default to Usage Access
    • Require Write Settings Permission
    • Enable App Data/Cache Clearing
    • Enable Admin Mode on CICO Screen
    • Allowlist Activities on Check-in Check-out Screen
    • Allowlist Specific Android Activities
    • Add Custom Device Settings
    • Customize Single App Floating Button
    • Add Launcher Branding
    • Enable Speed Lockdown
    • Set Launcher as Default after Reboot
    • Remove Floating Home Button Setting
    • Allow Popup Notifications

    For more information, see VMware Workspace ONE Launcher Profile Configuration.

iOS

  • Silently install your required App Store apps

    With iOS 15.1, you can set any single App Store app as a required app during enrollment. When installing the app using Workspace One UEM or Workspace ONE Intelligent Hub, the app deploys silently, even on unsupervised devices. For more information, see Configure Organization Settings.

  • Help users enroll their personal devices more easily with Account Driven User Enrollment.

    On iOS 15 and later devices, users can sign in with their Managed Apple ID directly in the iOS Settings app instead of navigating to a URL in Safari. This allows users to focus on setting up their enterprise account rather than switching between screens and multiple prompts. For more information, see Enroll an iOS Device Using Account Driven User Enrollment.

Scripts

  • We’ve deactivated the Scripts functionality for BYO devices.

    To preserve end-user privacy, macOS and Windows devices with Employee Owned ownership are now excluded from Scripts assignments.

Chrome OS

  • We've added support for SCEP Certificate Deployment

    rom a Chrome User or Device Network (or Credentials) profile, you can now choose a SCEP certificate authority and template when adding a template-based certificate. For more information, see Supported Certificate Authorities

Resolved Issues

2111 Resolved Issues

  • AAPP-12438: Apple wallpaper setting applies with all options unchecked.

  • AAPP-12774: ScheduleOSUpdate API fails on UEM 2105.

  • AAPP-12809: APNs for applications expiring notification for AirWatch Container and AirWatch Inbox.

    N/A

  • AGGL-8201: Multiple guard failures observed during the execution of AndroidWorkGoogleDeviceIdValidationJob across environments because of the absence of googleuserid for the device in Database.

    N/A

  • AGGL-10772: Config missing in DDUI Launcher Copy profile.

    N/A

  • AGGL-10797: Some Android Launcher profiles failing to load after upgrade to 2107 and DDUI FF enablement.

    N/A

  • AGGL-10815: Slow deployment of a new Public app.

    N/A

  • AGGL-10867: Unable to save value as unselected.

    N/A

  • AGGL-10816: Device & DS out of sync.

    N/A

  • AGGL-10901: 'Lock Orientation' checkbox gets disabled upon save.

    N/A

  • AGGL-10922: Android OEM service fails to install during legacy device enrollment.

    N/A

  • AGGL-10950: Adding auto-install application under ChromeOS Kiosk payload disappears after Save & Publish.

    N/A

  • AGGL-10940: Lockscreen Overlay under Samsung Knox Passcode payload not working with new DDUI changes.

    N/A

  • AMST-33898: Unable to authenticate for Dropship Provisioning in TechDirect when using lower OG

    N/A

  • AMST-33903: Newly built and enrolled device, built with Windows 10 x64 image and enrolled with the 21.5.4 hub is not processing app install commands.

    N/A

  • AMST-33988: Devices are not syncing after DSP registration.

    N/A

  • AMST-33982: Windows update shows as unapproval failed for feature update.

    N/A

  • AMST-34074: Windows apps are not getting installed back with 2105 and above after an Enterprise reset.

    N/A

  • AMST-34286: OG delete fails if enrolled users also have ProfilePayloadIdentifierOnDevice assignment(s).

    N/A

  • AMST-34373: Clicking the Remote Assist button shows the loading icon on the console forever and does not proceed further

    N/A

  • AMST-34393: TOU not properly displayed on enrollment of device.

    N/A

  • AMST-34331: API User deactivation flow not triggering wipe protection for windows devices in certain use-case

    N/A

  • AMST-34444: RestartDeadlineInDays Not Being Set in /begininstall API Call to Create a Windows 10 Application.

    N/A

  • CRSVC-19102: Unable to activate the inactive compliance policy from the Compliance page.

    N/A

  • CRSVC-24331: API is not loading post upgrading to 21.7.0.2.

    N/A

  • CRSVC-24392: Unable to delete workflow from workflow listview.

    N/A

  • CRSVC-24515: Phone, Current Carrier, and Home Carrier information show as Private in Device List View, even if Privacy setting is set to Display.

    N/A

  • CRSVC-24566: Unable to remove smart groups from Workflows.

    N/A

  • CRSVC-24437: Wi-Fi Adapter doesn't show up the correct IP Address.

    N/A

  • CRSVC-24526: SSL cert auth fails with ephemeral key when using web service references.

    N/A

  • CRSVC-24607: awdevicecomplianceactionsqueue backs up on the api nodes.

    N/A

  • CRSVC-24709: Pulse VPN connectivity has been failing since UEM upgrade to 2105 and 2107.

    N/A

  • CRSVC-24731: System.ArgumentOutOfRangeException in DesiredStateCalculator class.

    N/A

  • CRSVC-25020: High CPU memory utilization by scheduler service.

    N/A

  • CRSVC-25044: DuplicateCertificate_Purge job is not effectively removing duplicate certificates.

    N/A

  • CRSVC-25100: Baseline Microservice connection error when loading the baseline page in UEM.

    N/A

  • ENRL-3153: Device activation template.

    N/A

  • ENRL-3171: The smart groups are not updating post device OG change based on network range.

  • ENRL-3226: Workspace ONE UEM DB Upgrade failure.

    N/A

  • FCA-195293: Timezone is not sorted on Create Organization Group screen.

    N/A

  • FCA-200135: Console crash on report download from the Exports page.

    N/A

  • FCA-199991: Application versions in Workflows are not honored when reverting from Latest available to a previous version.

    N/A

  • FCA-199468: Message templates not showing full message body content in console UI.

    N/A

  • INTEL-33360: Intelligence missing data.

    N/A

  • FCA-200222: User Account Denial of Service.

    N/A

  • MACOS-2595: iOS profile with Allow Removal With Authentication failing to install on supervised device.

    N/A

  • PPAT-9841: Device Traffic Rule set with ports goes blank in Console and Database.

    N/A

  • MACOS-2609: macOS bootstrap package not being queued up for installation on new enrollments.

    N/A

  • RUGG-9961: Unable to add Applicability Rules to Products within Productsets through API.

    N/A

  • RUGG-10236: Unexpected error when clicking from Device -> Provisioning -> Product List View in UEM console.

    N/A

  • UM-1845: REST API Endpoint Not Paging Correctly.

    N/A

  • UM-313: When Directory User is added by batch import to child OG, Default Template configured on Global is sent.

    N/A

  • RUGG-10301: Proxy settings configured as part of staging WiFi profile (WS1) is not being applied, hence enrollment stalls.

    N/A

  • CRSVC-25134: Internal iOS SDK application displays error on launch.

    N/A

  • UM-1871: On UEM versions 2105 and above user activation email for batch import using Advanced template comes in plain text instead of HTML.

    N/A

21.11.0.2 Patch Resolved Issues

  • AAPP-13256: Exception seen on multiple environment.

    N/A

  • FCA-200862: Update SKUORDER update API to allow Freestyle basic SKU to be added to older UEM versions.

    N/A

21.11.0.3 Patch Resolved Issues

  • UM-7238: User Group User List failing to load due to dbo.UserGroup_SelectUserGroupMembers sproc timing out.

    N/A

  • FCA-200968: Migration script Notification.UpdateNotificationUUID is causing failures in upgrades.

    N/A

21.11.0.4 Patch Resolved Issues

  • AGGL-11276: Params to clear accounts is not sent on check-in from device details/auto logout.

  • AMST-34890: Disabling HardwareDeviceIdentifierForWindowsFeatureFlag is still merging device records.

21.11.0.6 Patch Resolved Issues

  • AMST-34954: Dropship Provisioning: Public access override and device E2E test

  • CRSVC-26375: SQL Blocked Processes on WMT PROD DB.

  • RUGG-10563: LogZ Error : Unique key constraints error seen in ContentPullService Logs with very high count

  • CRSVC-26469: Workflow - Limit size of Reason in Workflow step status reason

21.11.0.7 Patch Resolved Issues

  • CRSVC-26589: Update the Claim "org_location_group_id" to use customer OrganizationgroupId where Opt in happens instead of Global OrganizationgroupId.

  • SINST-175953: Seed 22.01 Hub to 2111 next patch

  • AAPP-13365: Classroom not showing updated classes.

  • RUGG-10578: Multiple getnextmanifest calls are being made causing DB contention.

21.11.0.10 Patch Resolved Issues

  • PPAT-10455: Internal SDK app throws Error Code:14 with Tunnel Proxy

  • AGGL-11328: In Android DDUI, page crashes when editing Launcher profile with Miscellaneous app added to pinned row

  • CRSVC-26679: Optimization of the sp CoreAndDefaultAttributes_Update.

  • AMST-35116: Encryption Type always switch back to TKIP for Windows Desktop WiFi Profile.

  • AAPP-13368: Apple Fast Lane Message Queue Throttler leaks memory.

  • FCA-201416: Customer is experiencing slowness in device search after upgrade to UEM version 21.09.

21.11.0.12 Patch Resolved Issues

  • ARES-21698:CN888 - DeviceProfile_SearchByDeviceDashboard_V3 causing tempdb contention

21.11.0.11 Patch Resolved Issues

  • AMST-35156:Wrong device Attributes - Enrollment Type Id - on un/re-enrollment

  • AMST-35181:Newly enrolled Windows 10 devices install x86 version of AppDeploymentAgent

  • CRSVC-26834:The Trust Service log does not output even though the log level is changed to "verbose".

  • RUGG-10571: JQuery upgrade to 1.12

21.11.0.13 Patch Resolved Issues

  • AAPP-13367: Issues Removing Apple Education Profile from iPads.

  • CMCM-189603: CN1108- DB Contention issue with multiple calls to EnterpriseContent schema.

  • AMST-35270: The Kiosk profile takes a longer time to install on the devices and sometimes days even though the device is checking in.

  • AGGL-11415 [Passcode] Unable to send Clear Device/Work App Passcode in COPE.

  • CMSVC-16026: Hub services - Unable to find the smart groups in the WS one hub services during assignment against templates

  • AAPP-13482: CN22 - VPP Auto Update not working for some applications.

  • AGGL-11382: Launcher orientation is set to locked in XML when its not selected in the UI.

  • AMST-35248: Delay in processing windows install/removal commands for apps and profiles.

  • CRSVC-27368: Increase the SMTP username limit from 64 to 255 characters.

  • CRSVC-26920: Remove the index IX_DeviceExtendedProperties_RowVersion.

  • RUGG-10704:Copy and Edit of the existing provisioning profile creates the profile copy under Devices > Profiles & Resources section.

  • FS-818: RB-2111-Freestyle Orchestrator is still tagged as Tech Preview.

21.11.0.14 Patch Resolved Issues

  • FCA-201655: Console login failing for directory admin account with error "Invalid credentials" in CN135 environment.

  • FS-800: Update Workflow Re-Evaluate to 4 hrs as default in system code.

21.11.0.15 Patch Resolved Issues

  • AMST-35482: Unable to find "Allow Enhanced PIN at Startup" in Windows Encryption profile.

  • CRSVC-27664: Dataplatform service consumes messages from sensor queue on alternate instances.

  • AGGL-11472: Model of Android devices are missing on the console and displayed as "Android" instead.

  • CRSVC-27631: Delete dead records from Device State that are deleted from canonical.

  • AAPP-13556: VPP Book Syncs as Unknown Application.

21.11.0.19 Patch Resolved Issues

  • AGGL-11387: Android Q Restrictions Check - Validate Staging Record prior to restrictions check

21.11.0.16 Patch Resolved Issues

  • AMST-35653: Dropship Provisioning: Duplicate Enrollment User

  • AMST-35624: Update MSI deployment parameters of windows seeded apps.

  • INTEL-37061: Intelligence - Recovery Key Escrowed value not matching UEM.

  • AGGL-11512: Spaceman error while launching Android DDUI profiles.

21.11.0.20 Patch Resolved Issues

  • INTEL-37768: Invalid column name 'RecoveryKeyPresent' - on multiple environments.

21.11.0.22 Patch Resolved Issues

  • CRSVC-28135: "An error has occurred" while assigning Sensors.

  • AGGL-11550: Customer is unable to set Launcher Administrative passcode with more than 10 characters.

  • AGGL-11552: DDUI - Request to increase maximum character limit for Proxy Bypass Rules field in Chrome Browser Settings profile.

  • FCA-202361: Changes to Fix FK error due to Isolation level.

21.11.0.23 Patch Resolved Issues

  • CRSVC-28169: The enrollment certificate method only adds certificates to a chain if they have a private key.

  • CRSVC-27973: Fix Compliance Evaluation when ComplianceDeviceStateIntegrationFeatureFlag is enabled.

  • CMCM-189713: Performance improvements for the RepositoryTemplate SProcs.

  • AMST-35757: When enrolling VDI, the latest enrolled device overtakes existing device record.

  • AAPP-13655: iBeacon profile not getting automatically installed on device when in region.

21.11.0.26 Patch Resolved Issues

  • AMST-35814: Domain join fails when Smart Groups evaluated before enrollment.

  • AMST-35787: Unable to run Selective App list API call on the enrolled Win 10 devices.

21.11.0.27 Patch Resolved Issues

  • CMSVC-16076: Tags Update API fails when organization group id is not passed.

  • RUGG-10851: Grid for "Last Seen' shows 5 hours behind expected Admin time zone.

  • AAPP-13760: iOS Device Updates page timeout issue.

  • FCA-202433: UEM console crash while navigating to Devices > Compliance Policies > Event Log.

  • LUEM-472: ntermittent failure during web enrollment with Hub package download.

  • AMST-35816: Blobs being served by Device Services even when they are present in the CDN and Storage Type is set to 1.

  • CRSVC-28932: Unable to install S/MIME profile due to 'Certificate is used more than once' error.

  • CMCM-189750: Removing the ContentLockerSDKLibraryKey system code causes an override.

  • AMST-35880: Windows Application Deployment Commands are only cleared after a manual Query or App Sample Query from UEM console.

  • AGGL-11679: DDUI is broken by a certificate date format in Android profiles.

  • CRSVC-28308: Async email notifications cause thread pool exhaustion and suspends compliance evaluation.

  • CRSVC-28398: Missing compliance values causing failed device migration.

  • AMST-35938 Seed v2107.9 patch version of Hub to UEM.

  • AAPP-13759: VPP licenses are not getting disassociated.

21.11.0.28 Patch Resolved Issues

  • CMEM-186612: Delay in adding the device to the allowlist from email list view.

  • UM-7450: Admin Groups not updating after Automatic or Manual sync.

  • CRSVC-28589: GSX certification save failed with password invalid.

21.11.0.30 Patch Resolved Issues

  • AMST-35970: Dropship Provisioning-Device registrations never make it to through the Bulk Importer Service.

  • AGGL-11879: Android DDUI Launcher profile 'Lock Orientation' checkbox gets disabled upon save.

  • AAPP-13878: MDM profile errors 'Decryption key for the profile is not installed'.

Known Issues

  • The translated strings "Console" and "Browser" are not loaded in login history list

    In Login history page Login Type & Application column value (console & browser respectively) is not getting translated into the console locale.

    Workaround: No Workaround, as it is a localization issue and content is always getting displayed in English.

  • Freestyle details page has an truncated issue after you publish a workflow.

    If Publish workflow action fails or we “Pause” the workflow and go to the workflow details page then breadcrumb navigation menu is getting truncated from the workflow details page.

    Workaround: On page refresh, we can see the complete breadcrumb navigation menu.

  • App Config: Unable to save value as unselected

    Android app config was designed to allow for configurations to be 'unselected' so that they are excluded from the configuration sent to Google.Unselecting something is different based on the data type (text field can be left blank, boolean can be set to 'Select', etc).For Booleans, setting it to "Select" is not saving but is excluded in the payload sent to the device. So on edit, the unselected value is set to the default value of the field

    Workaround: The deployment and the policies set on the device is not impacted but when editing an app configuration that is deployed with "Unselected" boolean value, it has to be set back to "Unselected" on edit.

  • Hub - Catalog shows incorrect version when Prod and Beta tracks exist.

    When querying Google Play to determine what version of the app to display in the Catalog, the first result is chosen without considering the assignment or installation of the application version. This can cause a beta version number of the app to appear even if the beta version is not installed or assigned to the user.

    Workaround: Removing the beta version from Google Play or assigning the beta version to the device would prevent the wrong version from being displayed.

  • Adding a version to launcher profile inside a product causes launcher to stay on reload screen

    Customer is installing launcher profile via products. Recently when they are updating the launcher profile and resaving (adding a new version) they are seeing that the profile gets removed for the device in the console, before getting installed again. Prior to this issue the profile would update on the device without having to be removed and applied again. This is due to the missing option to activate/deactivate while adding a new version of launcher profile in the new data driven profiles UI deployed via products.

    Workaround: We can deploy the new version of launcher through the profiles and resources and not through updating the provisioning profile.

  • Angular app should load for all types of admins

    There are APIs which are called as part of the angular app load which are resource protected. Since, these are minimum permissions needed to start the angular app, the app fails to load for custom roles without having these permissions.

    A workaround for this issue is to add the required permissions to an admin role. You can view more information here.

check-circle-line exclamation-circle-line close-line
Scroll to top icon