About Workspace ONE UEM Release Notes

VMware Workspace ONE UEM Release Notes provide information on the new features and improvements in each release. This page includes a summary of the New Features introduced in 2206, Resolved Issues, and Known Issues.

When can I expect the latest version?

We strive to deliver high-quality products, and to ensure quality and seamless transitions, we roll out our products in phases. Each rollout may take up to four weeks to accomplish and is delivered in the following phases:

  • Phase 1: Demo, Shared SaaS UATs, and Latest Mode UATs

  • Phase 2: Shared SaaS environments

  • Phase 3: Latest Mode environments

Once our phased rollout is complete, we will announce general availability for on-premises and managed hosted customers. For more information, see the KB article.

Getting Ready for Apple Fall 2022 Releases

Learn more about the upcoming Fall 2022 releases for Apple. See Getting Ready for Apple Fall 2022 Releases for more information.

New Features in this Release


  • Getting started with Zero-touch Enrollment for Android devices has never been this easy.

    Workspace ONE UEM now integrates directly with the Zero-touch Enrollment Portal. By linking your Zero-touch Enrollment account to the UEM Console, you can set a default enrollment configuration and support contact information for registered devices. The default configuration will apply to devices that do not already have an associated enrollment configuration in the Zero-touch Portal. To set up this integration, browse to the new Zero Touch tab under the Android EMM Registration settings page. For more information see, Android EMM Registration


  • Restore a macOS 12 device with ease.

    You can now use a simple workflow to make a used Mac ready for another user without having to erase the entire drive and OS. Just like with iOS, you can use the Erase All Contents and Settings (EACS) actions to erase all user data and user-installed apps from the device and easily restore a device with macOS Monterey. All without having to reinstall the OS. For more information, see Erase All Content and Settings (EACS).


  • We’ve improved the Workflow step messages.

    For troubleshooting purposes, we enhanced the workflow messages presented per step on the Device Details page and the Workflow Details page. The error messages offer information regarding the cause and components of the error. Click the link in the error screen to see a detailed message modal for error messages that exceed the word limit.


  • We've made improvements to Device Wipe.

    Earlier, certain BitLocker profile settings, such as Force Encryption, could interfere with reliable device wipes. Enterprise Wipe and Enterprise Reset now ensure that device wipes occur as expected.

  • Get app samples and certificate samples with no user session.

    Devices that run without a user logged in will now return app samples and certificate samples (managed certificates), to properly reflect all the software / certificates installed on a PC. Previously, app samples  and certificate samples were only sent when a user was logged in. 

Resolved Issues

2206 Resolved Issues

  • CRSVC-30417: API Call in Response Header is of past date.

  • AGGL-11892: setAvailableProductSet EMM API calls and App Syncs failing due to SQL exception - violation of PRIMARY KEY constraint

  • AAPP-14265: Managed Settings of child og not reflected in CICO scenario when checking out the device to Child OG.

  • UM-7512: On-Prem DomainJoin: Assignment screen is not auto populating "Organization Units" based on the text entered.

  • UM-7511: The page transitions in User's event log do not work properly.

  • RUGG-11019: Product Provisioning Restriction Profile does not have “Allow Data roaming” checkbox.

  • RUGG-11017: Delay in Products getting assigned to android devices.

  • RUGG-11012: Product keeps installing on Android in an endless loop even though it is successfully installed on the device.

  • PPAT-11687: Windows tunnel client "Not Configured" and certificate getting revoked with Reason Code.

  • INTEL-38152: Recovery Key Escrowed value not matching UEM.

  • FS-1408: Work flows are getting stuck at blocked and do not proceed.

  • FS-1329: macOS on-demand script does not run.

  • FCA-203536: Not able to remove roles for admins through UI

  • FCA-203516: Unable to access Event Details under Monitor >Reports and Analytics.

  • FCA-203345: Incorrect API device count for customerattribute search for device serial number.

  • FCA-203236: Console events -> User management category is not available.

  • ENRL-3454: Duplicate accounts existing and managed by OG with no Directory Services configured but linked to Higher OG when it should not be possible.

  • CRSVC-30464: Unable to delete Certificate Authority.

  • CRSVC-30455: Error of DB collation.

  • CRSVC-30051: Integrated Authentication certificate doesn't rotate to new CA when we modify the settings for the Web under SDK settings.

  • CRSVC-29998: Exported Console Events missing AccountInformation.

  • CRSVC-29893: Device Compliance check failing on WS1 Access with UEM 2204.

  • CRSVC-29523: Multiple certificates from Entrust CA show installed on Dell Federal devices.

  • CMCM-189862: Contents App cannot show contents in the specific folder in Repository.

  • ARES-22327: Unable to fetch App Removal Logs in UEM console.

  • AMST-36472: ACC and AWCM timeout while publishing content to Adaptiva

  • AMST-36528: Unable to activate "Show in HUB (Optional)".

  • AMST-36293: UEM Azure AD Integration Button Link is Broken.

  • AMST-36254: Antivirus Profile Payload not working as intended || Queries regarding Antivirus Payload.

  • AMST-36226: Unable to delete a smart group that is associated with domain joins.

  • AGGL-12272: Delay in device checking post console upgrade causing product to be in queued state unless device is queried/synced.

  • AMST-36054: EnrollmentToken Purge encounters FK error.

  • AGGL-12253: Apps added to the Play store don’t appear in the Play store.

  • AGGL-10916: Model of Android devices are missing on the console and displayed as "Android" instead - validate auto seeded model and manufacturer names.

  • AGGL-12006: Chrome OS devices not receiving certificates SCEP.

  • AAPP-13372: Need to Confirm Behavior of 'Encrypt User Information' Setting.

  • RUGG-10937: Peripheral API no longer returns PrinterSample After Enabling PrinterDeviceStateIntegrationFF.

  • RUGG-10936: Smartgroups with OS version criteria not updating when a device updates OS version.

  • MACOS-3112: macOS Privacy Preferences profile character limit.

  • MACOS-3109: VPP app installation status not getting updated on the console for MacOS devices.

  • FS-1193: Workflows and TimeWindow Tabs are not available under Devices Details Page.

  • FS-1131: macOS Workflow engine not downloading during enrollment.

  • FCA-203090: Incorrect Reason for device unenrollment notification.

  • FCA-202984: Sending query to device results in multiple device query requested events in troubleshooting event logs for device.

  • FCA-202861: Device wipe initiated for devices even if admin cancels the request mid-way.

  • FCA-202706: Unable to delete devices from console.

  • FCA-202743: Query on Devices Search API calls to retrieve HostName and LocalHostName.

  • FCA-202654: Custom role with higher privilege is unable to view the lower privileged roles like Helpdesk roles.

  • ENRL-3438: Un-enrollment date is Null in Intelligence.

  • ENRL-3427: Devices unable to move to different OG's based on UserGroup Mappings.

  • ENRL-3416: Device registration API fails when 'None' is sent as ownership type and enrollment restrictions are in place.

  • CRSVC-29464: S/MIME certificates corrupted on DB.

  • CRSVC-29391: Triggering the 5K API calls per minute limit even though it's been longer than a minute.

  • CRSVC-29325: Failed to view device summary.

  • CRSVC-29010: UEM Unenrollment Does Not Send Re-Authentication to User's Other Devices.

  • CRSVC-28803: Unable to install smime profile due to certificate is used more than once error.

  • CMSVC-16132: Smart Groups POST to /API/mdm/smartgroups throws error for duplicate Device IDs.

  • CMEM-186608: Delay in whitelisting the device from email list view.

  • ARES-22202: Query / Scenarios regarding VPP apps.

  • ARES-22078:Starting security provider failed.

  • ARES-22055: Profile V2 Search API working only for the device profiles.

  • AMST-36222: Bitlocker Suspend/Resume Option Not Showing Up Under Device Details in the UEM Console.

  • AMST-36157: Edit Intenal application page taking long time to load for apps with large number of assigned devices.

  • AMST-36126: Native Enrollment failing with error MultiUserFFSetup.

  • AMST-36040: Customer cannot upload missing dependencies for some .appx files while editing them.

  • AMST-36003: Push notification does not work as Compliance Action.

  • AMST-35942: When to Call Install Complete does not use ProductVersion.

  • AMST-35958: Update notifications filter for internal app list doesn't filter the records.

  • AMST-35941: Unable to update internal app assignments for some Windows applications.

  • AMST-35933: Dropship Provisioning: Device Registrations Never Make it to through the Bulk Importer Service.

  • AMST-34405: SSL Pinning Showing Not Synchronized.

  • AGGL-12001: Android Enterprise Public App removed from AE devices when Legacy app has exclusion added.

  • AGGL-12014: Time mentioned in System Updates profile changes to AM from PM after save and publish, when UI Locale languages is Japanese, Chinese, or Korean.

  • AGGL-11972: Model of Android devices are missing on the console and displayed as "Unknown" instead.

  • AGGL-11930: Android Chrome Browser Profile Fails to Save URL Blocks & Exceptions.

  • AGGL-11924: The GET profiles/[profileID] API works for random profiles.

  • AGGL-11868: Public Android Apps published w/ 600k+ devices assigned does not land on the devices.

  • AGGL-11902: Enrollment restrictions not working for Orbic devices.

  • AGGL-11283: Enrollment users not available when searching during QR code creation.

  • AAPP-13843: MDM profile errors out with 'decryption key for the profile is not installed'.

  • AGGL-11231: Able to enroll without registering as an allowed device for Android OS version 12 in Work Profile mode even if the console's enrollment mode is "registered devices only"

  • AAPP-13986: Unable to assign devices to public books after book is created.

  • AAPP-13752: No way to specify Device Traffic Rules for WS1 Tunnel.

  • AAPP-13982: Internal Books are displayed as Not Installed in Books tab of Device Details page.

Patch Resolved Issues

  • AMST-36612: Trigger compliance on enrollment complete for Windows devices.

  • CRSVC-30899: Unable to delete devices from console.

  • CRSVC-31183: Entitlement service migration tool fails to connect to database on DB credential change.

  • MACOS-2941: Queue a command to update Intelligent hub settings seeded profile for already enrolled macOS devices in order to include RemovableSystemExtension as part of System Extension payload.

  • MACOS-3253: macOS DDUI tunnel profile missing arrays.

  • CMCM-190021: Undefined Error when viewing assigned devices for Content.

  • CMCM-190022: DB Server CPU spiking to 100% multiple times a day.

  • CRSVC-31446: The console event date filter is not working as expected.

  • MACOS-3262: Unable to edit existing macOS profile after macOS DDUI is enabled in environment.

  • AGGL-12800: Device Sync triggers RemoveApp command for iOS app.

  • AMST-36835: Device context based applications require valid user session to process uninstall.

  • AMST-36850: Samples are being repeatedly queried till samples response comes.

  • AMST-36865: Seed v2206 SFD patch to UEM.

  • AMST-36875: App sampling to query SFD when SFD is known to be installed on device.

  • CMEM-186698: PowerShell failing: "User credential of the remote PowerShell server contains the special characters".

  • MACOS-3312: MacOS DDUI Network access profile not showing option "Use as login window configuration".

  • MACOS-3330: Identify the cause for DB Upgrade failure due to Invalid column name 'DevicePlatformId'.

  • CRSVC-31786: GSX test connection fails with SSL error.

  • AMST-36972: Unable to edit app assignments.

  • FCA-203853: Unable to load Angular Exports page.

  • MACOS-3313: macOS DDUI SCEP Payload - AirWatch CA Template does not populate.

  • INTEL-42182: ETL-Design the ability to enable CDC based exports in AWS RDS.

  • AGGL-12898: Time mentioned in System Updates profile changes to AM from PM after save and publish when UI locale languages is Japanese, Chinese, or Korean.

  • CRSVC-32057: “Renew Certificate" not working as expected in Certificate list view.

  • AMST-36832: Windows Firewall Rule not working as intended on Win 10 device.

  • MACOS-3364: Populate tunnel configuration in VPN processor properly.

  • AMST-36856: Seed v2206.2 Patch Hub to UEM.

  • ARES-22978: Invalid samples from Apple and Apple OSX devices with empty unique identifiers.

  • RUGG-11434: Policy Engine stuck on environments without processing items in queue.

  • AAPP-14586: EAP-TLS option not saved on tvOS Wi-Fi profile (DDUI).

  • CRSVC-31978: Unable to publish scripts due to errors with console.

  • CRSVC-32316: Add telemetry for counting usages of the unsigned Secure Channel payloads.

  • ARES-23168: Unable to save and publish profile due to SQL timeout.

  • ARES-23175: High SQL waits causing the console slowness.

  • AGGL-13122: Fix the incorrect Model being updated for a device from system samples - Zebra devices are being reported as model type "unknown" in Smartgroup filter

  • AMST-37237: Allow upper case characters for Baseline Name.

  • CRSVC-32618: Optimize Publish of public and purchased apps flow.

  • ENRL-3580: Add Token Preview Behind a FF.

  • AAPP-14774: Cannot enable device assignment for certain VPP applications.

  • AGGL-13160: Observed 500-Internal server error response for app details API across multiple UEM servers.

  • AGGL-13170: setAvailableProductSet EMM API call fails due to SQL truncation Error.

  • AMST-37304: Since upgrading (2204) Custom profiles are not installing for newly enrolled Windows devices.

  • AMST-37309: Device identifier and UDID mismatch for any reason should not unenroll device.

  • AMST-37331: Compromised status change for Mac Devices are flooding Event Logs table.

  • CMSVC-16561: Replace TagsDeviceStateIntegrationFeatureFlag with DeviceStateInterfaceEnabledFeatureFlag.

  • CRSVC-32685: Unable to delete some devices from UEM through UI or API.

  • CRSVC-32786: Notifications for VPP App Auto Update will no longer be sent to Admin Console post UEM upgrade to 2206 due to error in GetCoreUsersByLocationGroupIdAsync call.

  • CRSVC-32845: Improve compliance flow at "/api/mdm/devices/search" to reduce DB calls

  • FCA-204170: A single call to "/api/mdm/devices/search" makes around 3000 calls to DB and stressing the same.

  • MACOS-3383: macOS DDUI - Certificate is not referenced correctly in Network payload.

  • MACOS-3400: MacOS DDUI Network device profile not showing "username" option under EAP-TLS protocol.

  • AAPP-14823: tvOS DDUI - Unable to add more than five Credential payloads.

  • AGGL-13119: DDUI profiles fail to save settings.

  • AMST-37255: Seed v2206 SFD patch to UEM.

  • AMST-37435: Sensors tab on Device Detail view should be visible for Registered Mode devices.

  • AGGL-13311: URL Blocks & Exceptions in Chrome Browser Profile disappeared with data loss.

  • MACOS-3432: macOS DDUI - Network profile lookup values are not resolved.

  • CMCM-190214: Intermediate SQL timeout exception seen on test environment.

  • CMCM-190181: Unable to delete content from List view or through API (500 error).

  • ARES-23299: A single API call makes around 600 calls to DB and stressing the same.

  • AGGL-13352: DDUI - Request to increase maximum character limit for fields in Chrome Browser settings profile.

  • CRSVC-33269: Add debug logging to the HMAC Canonical code.

  • MACOS-3372: macOS DDUI - Character limits in payloads.

  • INTEL-44409: Display last checked out username in UEM devices data in Intelligence.

  • INTEL-44133: Android Hub version mismatch between UEM and Intelligence.

  • INTEL-44017: Add Managed Application List join in app Initial Export.

  • AAPP-14825: Environments experiencing long running query during heavy DB Contention.

  • AAPP-15041: Certain VPP applications are stuck Pending Check.

  • AMST-37556: Security sample improvements.

  • CRSVC-33615: [Compliance] Fix Toggle Compliance Policy Status not working properly when setting a active policy to inactive.

  • FCA-204360: Event data modal is not loading for devices and console events.

  • RUGG-11621: After upgrade to 2206, files downloaded from the Files or Actions are empty.

  • UM-7779: AirWatch Purge expired Sample Data SQL job is failing.

  • AMST-37720: (Factory Provisioning) Active Directory select is not working as expected.

  • FCA-204392: Custom device activation template is not being sent to the devices that are enrolled through SSP.

  • FCA-204431: Incorrect success message shows when changing the Organization Group of a device even when it is prevented by tenancy restriction.

  • AMST-37746: (P2P Branch-Cache) Peer to Peer download is not working.

  • CRSVC-34057: DB Installer script for 2209.9 fails on SQL Server Standard Edition.

  • AGGL-13506: Android Restriction - Allow user to modify Location settings for Work Profile is not working.

  • CRSVC-34055: Certificate revocation not working for OpenTrust.

  • FCA-204551: Unable to edit Device Asset Number.

  • FCA-204433: Report name is randomized while downloading legacy reports.

  • CRSVC-34606: DB Upgrade Failure due to missing seed value in device manufacturer and device model detail.

  • AAPP-14534: Delay in OS seed script deployment is causing data inconsistency.

  • CRSVC-34057: Workspace ONE UEM - DB Installer script for 2209.9 fails on SQL Server Standard Edition.

  • RUGG-11729: Product Provisioning issues after UEM and UAG upgrade.

  • AMST-38167: Location option missing in Bulk management for Windows devices.

  • MACOS-3569: macOS - add support for new hardware released.

  • AMST-38006: Unable to modify and save the install command for Windows app.

  • AMST-38157: Hub not showing device as enrolled and not receiving apps/profiles.

  • PPAT-12920: DTR updates are not consistently consumed by Windows devices.

  • PPAT-13436: iOS VPN Profiles have the incorrect DTR ruleset getting applied for devices.

  • AGGL-13791: Some Pixel models are inconsistently mapped to a different model causing incorrect Smart Group reconciliation.

  • AMST-38171: Evaluate and update Enterprise Reset and DeviceGaurd check in the enterprise reset flow.

  • CRSVC-34854: The certificate along with the private key is not stored on the Windows CE 7 rugged device.

  • AMST-38265: Improve products delivery for newly enrolled devices.

  • AMST-38334: Baseline compliance report generation on fully compliant devices refreshes the baseline policies and switches the status to Pending Install.

  • RUGG-11802: Jobs in devicePolicyJob table are not getting purged as expected.

  • AAPP-15484: Beacon sample should trigger Device Info sample but should not save OS data.

  • FS-2502: Unable to delete Internal applications.

  • FCA-204873:Wipe protection emails are not sent to the listed Admin email address.

  • AMST-38340: Antivirus and Firewall status are periodically failing.

  • CRSVC-35974: Refactor EventLogService to use concurrent bag.

  • AAPP-15585: ABM device does not update with the second enrolled user status after re-enrollment from the first user to the second user.

  • AAPP-15610: APNs samples notifications consumption rate is aligned with scheduler frequency causing queue pile up.

  • ARES-24644: Public app uninstall API is not working for systems apps, but UI is working.

  • FCA-205025: Device preview on DLV grid shows incorrect device records.

  • MACOS-3662: Decouple code changes to seed new MAC models.

  • ARES-25140: Unable to save SDK Settings after editing 'Allowed Sites' under Integrated Authentication.

  • ENRL-3706: Beacon flow is wrongly updating OS info.

  • CRSVC-36205: Add additional logging for grid export using dates.

  • ARES-24959: Internal app publish fails due to duplicate key inserted error.

  • AAPP-15820: Save information from device in the database.

  • ARES-25324: Android app publish failed with duplicate key violation error.

  • ENRL-3741: Enrollment restrictions not being honored for iPad devices.

  • AAPP-15870: Phase 1 of Rapid Security Response support.

  • CRSVC-37273: Changes for correcting AppSequence workflow type in Workspace ONE UEM 2206 release.

  • ARES-25336: App publish not being retried due to a catch block and sync SP deadlock issue.

  • FS-3211: Freestyle Orchestrator issue with workflows. Error with script, profiles, and apps deployment when done in cascade mode.

  • CRSVC-37517: Update Token Refresh Azure AD Graph API Call.

  • AMST-38843: Reduce traffic of empty sample for winRT devices.

  • SINST-176114: Airwatch API Gateway file copy failed during deployment.

  • PPAT-14134: Post Migration to AWS CloudFront - Tunnel Configuration Page does not load.

  • CRSVC-37820: Move InvalidateAllRefreshTokensMigrationFeatureFlag to production.

  • AAPP-16001: Hub Registered Mode Sample Collection enhancements and fixes.

  • RUGG-12206: Unable to bulk delete devices for more than ten printers from the Workspace ONE UEM console.

  • AAPP-16148: APNs outbound queue was backed up on CN230.

  • UM-8065: Backport "AzureAD Integration: Replace deprecated AzureAD Graph with Microsoft Graph API endpoints" Workspace ONE UEM related changes 22.06.

  • INTEL-50180: Intelligence enrollment users were not syncing as expected.

  • FCA-205564: Upload the Selenoid 1.10.12 to harbor and use the docker-compose.yaml.

  • RUGG-12116: Product assignments were delayed in getting assigned.

  • ARES-25868: Deploying internal apps is getting stuck in “Pending Release” status.

  • CRSVC-38592: Move Invalidate All Refresh Tokens Migration feature flag back to production.

  • SINST-176153: Updated Code signing certificate.

  • SINST-176171: DDUI Profile Screen Fix.

  • SINST-176201: Update Installer to fix issues with DDUI profile screen.

  • AMST-39537: Workaround for Microsoft issue, breaking SFD installation.

  • CMEM-186888: Powershell script and Workspace ONE UEM side changes for EXO V3 Module.

  • SINST-176130: Install .NET Core 6 with UEM Installer.

  • PPAT-14516: .NET Core version upgrade to 6 for Tunnel Microservice.

  • CRSVC-40044: Only save public key component of certificate to database.

  • CRSVC-39363: Memcached uses only one server.

  • CRSVC-38315: Create non-clustered index on certificate table based on observations on Kroger.

  • RUGG-12322: Add Show Search bar toggle in the Layout widget.

  • CRSVC-40108: [Certificate Installer] Private key was not exportable in manual flow.

  • AGGL-15443: Unable to create Android profile with a time schedule, whose UUID is NULL.

  • AAPP-16309: False APNS notifications during Purchased App Sync.

  • AGGL-15326: Remove EFOTA sample from microservices.

  • AGGL-13376: Event data is empty for the Remove Application Requested event.

  • SINST-176171: Fixed issues with DDUI profile screen.

  • SINST-176220: Backwards compatibility for on-premises installer.

  • MACOS-4059: macOS 14 ADE enrollment fails if Custom Enrollment is off.

  • CMCM-190725: Status of document in content detail report was not corrected.

  • CRSVC-41707: Tunnel Gateway unreachable from newly enrolled iOSdevices.

  • AAPP-16439: Update Device Information query Cellular keys.

  • AGGL-15529: Google seems to have increased oAuthToken length (AndroidWorkSetting AccessToken got truncated).

  • CMEM-186923: Objects not clearing from the memory and causing high memory usage.

  • PPAT-15437: Review and reduce the Tunnel service logs generation.

  • ARES-26831: Application rule PUT API improvements.

  • AMST-40091: UEM console fails to edit windows profiles the day after they were created onwards.

  • CRSVC-42820: Secure Channel - Cannot find the original signer issue.

  • CRSVC-43551: Increased CPU usage by CiscoISE App pool.

  • SINST-176235: UEM Patch installer fails at Cert Installer execution.

  • UM-8411: Unblock the Auto/Manual syncs during Advanced Ldap Sync cycle failure.

Known Issues


  • ENRL-3501: "Get device enrolment token details" API does not return tags value.

    When this API is used to get the enrollment token details, the details do not contain the tags which have been created for the enrollment token.

     The tags are visible in Devices > Lifecycle > Enrollment Status > Tags.

  • UM-7577: Customer is using Oracle Directory. While we are able to sync users and groups, the attribute sync is failing primarily the Distinguished Name Attribute.

    If a customer is using Oracle Directory and they do not have auto-merge enabled, its possible for user attributes to fail on sync and update correctly within the console.

    In order to remediate this please enable Auto-Merge configuration under Groups & Settings > All Settings > Enterprise Integration > Directory Services > Users Tab > Advanced.

  • FS-1297: Freestyle Orchestrator workflow identifier version is showing up in string format it should be friendly version identifier.

    Workflow identifier version on Intelligent Hub is displayed as a string format instead of an end user friendly format. This might lead to bad UI experience for end users but does not impact the functionality of workflows.

    There is no workaround for this issue.


  • LUEM-534:  Certificates status in device details for Linux devices is not updating

     After successfully installing Certificates for Linux devices using profiles, the Certificate status in the UEM console remains as Pending Install or Unknown. However, the certificates are getting deployed successfully to the devices.

    Updating the certificate status based on sampling is affected but existence of the certificate entry in the device details can be considered as the successful deployment of the certificates on device.

check-circle-line exclamation-circle-line close-line
Scroll to top icon