About Workspace ONE UEM Release Notes

VMware Workspace ONE UEM Release Notes provide information on the new features and improvements in each release. This page includes a summary of the New Features introduced in 2206, Resolved Issues, and Known Issues.

When can I expect the latest version?

We strive to deliver high-quality products, and to ensure quality and seamless transitions, we roll out our products in phases. Each rollout may take up to four weeks to accomplish and is delivered in the following phases:

  • Phase 1: Demo and UATs

  • Phase 2: Shared SaaS environments

  • Phase 3: Dedicated latest environments

Once our phased rollout is complete, we will announce general availability for on-premises and managed hosted customers. For more information, see the KB article.

Getting Ready for Apple Fall 2022 Releases

Learn more about the upcoming Fall 2022 releases for Apple. See Getting Ready for Apple Fall 2022 Releases for more information.

New Features in this Release


  • Getting started with Zero-touch Enrollment for Android devices has never been this easy!

    Workspace ONE UEM now integrates directly with the Zero-touch Enrollment Portal. By linking your Zero-touch Enrollment account to the UEM Console, you can set a default enrollment configuration and support contact information for registered devices. The default configuration will apply to devices that do not already have an associated enrollment configuration in the Zero-touch Portal. To set up this integration, browse to the new Zero Touch tab under the Android EMM Registration settings page. For more information see, Android EMM Registration


  • Restore a macOS 12 device with ease.

    You can now use a simple workflow to make a used Mac ready for another user without having to erase the entire drive and OS. Just like with iOS, you can use the Erase All Contents and Settings (EACS) actions to erase all user data and user-installed apps from the device and easily restore a device with macOS Monterey. All without having to reinstall the OS. For more information, see Erase All Content and Settings (EACS).


  • We’ve improved the Workflow step messages.

    For troubleshooting purposes, we enhanced the workflow messages presented per step on the Device Details page and the Workflow Details page. The error messages offer information regarding the cause and components of the error. Click the link in the error screen to see a detailed message modal for error messages that exceed the word limit.


  • We've made improvements to Device Wipe!

    Earlier, certain BitLocker profile settings, such as Force Encryption, could interfere with reliable device wipes. Enterprise Wipe and Enterprise Reset now ensure that device wipes occur as expected.

  • Get app samples and certificate samples with no user session.

    Devices that run without a user logged in will now return app samples and certificate samples (managed certificates), to properly reflect all the software / certificates installed on a PC. Previously, app samples  and certificate samples were only sent when a user was logged in. 

Resolved Issues

2206 Resolved Issues

  • AAPP-13982: Internal Books are displayed as Not Installed in Books tab of Device Details page.

  • AAPP-13752: No way to specify Device Traffic Rules for WS1 Tunnel.

  • AAPP-13986: Unable to assign devices to public books after book is created.

  • AGGL-11231: Able to enroll without registering as an allowed device for Android OS version 12 in Work Profile mode even if the console's enrollment mode is "registered devices only"

  • AAPP-13843: MDM profile errors out with 'decryption key for the profile is not installed'.

  • AGGL-11283: Enrollment users not available when searching during QR code creation.

  • AGGL-11902: Enrollment restrictions not working for Orbic devices.

  • AGGL-11868: Public Android Apps published w/ 600k+ devices assigned does not land on the devices.

  • AGGL-11924: The GET profiles/[profileID] API works for random profiles.

  • AGGL-11930: Android Chrome Browser Profile Fails to Save URL Blocks & Exceptions.

  • AGGL-11972: Model of Android devices are missing on the console and displayed as "Unknown" instead.

  • AGGL-12014: Time mentioned in System Updates profile changes to AM from PM after save and publish, when UI Locale languages is Japanese, Chinese, or Korean.

  • AGGL-12001: Android Enterprise Public App removed from AE devices when Legacy app has exclusion added.

  • AMST-34405: SSL Pinning Showing Not Synchronized.

  • AMST-35933: Dropship Provisioning: Device Registrations Never Make it to through the Bulk Importer Service.

  • AMST-35941: Unable to update internal app assignments for some Windows applications.

  • AMST-35958: Update notifications filter for internal app list doesn't filter the records.

  • AMST-35942: When to Call Install Complete does not use ProductVersion.

  • AMST-36003: Push notification does not work as Compliance Action.

  • AMST-36040: Customer cannot upload missing dependencies for some .appx files while editing them.

  • AMST-36126: Native Enrollment failing with error MultiUserFFSetup.

  • AMST-36157: Edit Intenal application page taking long time to load for apps with large number of assigned devices.

  • AMST-36222: Bitlocker Suspend/Resume Option Not Showing Up Under Device Details in the UEM Console.

  • ARES-22055: Profile V2 Search API working only for the device profiles.

  • ARES-22078:Starting security provider failed.

  • CMEM-186608: Delay in whitelisting the device from email list view.

  • ARES-22202: Query / Scenarios regarding VPP apps.

  • CMSVC-16132: Smart Groups POST to /API/mdm/smartgroups throws error for duplicate Device IDs.

  • CRSVC-28803: Unable to install smime profile due to certificate is used more than once error.

  • CRSVC-29010: UEM Unenrollment Does Not Send Re-Authentication to User's Other Devices.

  • CRSVC-29325: Failed to view device summary.

  • CRSVC-29391: Triggering the 5K API calls per minute limit even though it's been longer than a minute.

  • CRSVC-29464: S/MIME certificates corrupted on DB.

  • ENRL-3416: Device registration API fails when 'None' is sent as ownership type and enrollment restrictions are in place.

  • ENRL-3427: Devices unable to move to different OG's based on UserGroup Mappings.

  • ENRL-3438: Un-enrollment date is Null in Intelligence.

  • FCA-202654: Custom role with higher privilege is unable to view the lower privileged roles like Helpdesk roles.

  • FCA-202743: Query on Devices Search API calls to retrieve HostName and LocalHostName.

  • FCA-202706: Unable to delete devices from console.

  • FCA-203090: Incorrect Reason for device unenrollment notification.

  • FCA-202984: Sending query to device results in multiple device query requested events in troubleshooting event logs for device.

  • FCA-202861: Device wipe initiated for devices even if admin cancels the request mid-way.

  • FS-1193: Workflows and TimeWindow Tabs are not available under Devices Details Page.

  • FS-1131: macOS Workflow engine not downloading during enrollment.

  • MACOS-3112: macOS Privacy Preferences profile character limit.

  • MACOS-3109: VPP app installation status not getting updated on the console for MacOS devices.

  • RUGG-10936: Smartgroups with OS version criteria not updating when a device updates OS version.

  • RUGG-10937: Peripheral API no longer returns PrinterSample After Enabling PrinterDeviceStateIntegrationFF.

  • AAPP-13372: Need to Confirm Behavior of 'Encrypt User Information' Setting.

  • AGGL-12006: Chrome OS devices not receiving certificates SCEP.

  • AGGL-10916: Model of Android devices are missing on the console and displayed as "Android" instead - validate auto seeded model and manufacturer names.

  • AGGL-12253: Apps added to the Play store don’t appear in the Play store.

  • AMST-36054: EnrollmentToken Purge encounters FK error.

  • AGGL-12272: Delay in device checking post console upgrade causing product to be in queued state unless device is queried/synced.

  • AMST-36226: Unable to delete a smart group that is associated with domain joins.

  • AMST-36254: Antivirus Profile Payload not working as intended || Queries regarding Antivirus Payload.

  • AAPP-14265: Managed Settings of child og not reflected in CICO scenario when checking out the device to Child OG.

  • AMST-36293: UEM Azure AD Integration Button Link is Broken.

  • AMST-36528: Unable to activate "Show in HUB (Optional)".

  • AMST-36472: ACC and AWCM timeout while publishing content to Adaptiva

  • ARES-22327: Unable to fetch App Removal Logs in UEM console.

  • CRSVC-30051: Integrated Authentication certificate doesn't rotate to new CA when we modify the settings for the Web under SDK settings.

  • CRSVC-29893: Device Compliance check failing on WS1 Access with UEM 2204.

  • CRSVC-30455: Error of DB collation.

  • CRSVC-30464: Unable to delete Certificate Authority.

  • FCA-203236: Console events -> User management category is not available.

  • RUGG-11017: Delay in Products getting assigned to android devices.

  • ENRL-3454: Duplicate accounts existing and managed by OG with no Directory Services configured but linked to Higher OG when it should not be possible.

  • RUGG-11012: Product keeps installing on Android in an endless loop even though it is successfully installed on the device.

  • PPAT-11687: Windows tunnel client "Not Configured" and certificate getting revoked with Reason Code.

  • INTEL-38152: Recovery Key Escrowed value not matching UEM.

  • FS-1408: Work flows are getting stuck at blocked and do not proceed.

  • FS-1329: macOS on-demand script does not run.

  • FCA-203345: Incorrect API device count for customerattribute search for device serial number.

  • FCA-203516: Unable to access Event Details under Monitor >Reports and Analytics.

  • RUGG-11019: Product Provisioning Restriction Profile does not have “Allow Data roaming” checkbox.

  • UM-7511: The page transitions in User's event log do not work properly.

  • CRSVC-29998: Exported Console Events missing AccountInformation.

  • UM-7512: On-Prem DomainJoin: Assignment screen is not auto populating "Organization Units" based on the text entered.

  • CMCM-189862: Contents App cannot show contents in the specific folder in Repository.

  • CRSVC-29523: Multiple certificates from Entrust CA show installed on Dell Federal devices.

  • FCA-203536: Not able to remove roles for admins through UI

  • AGGL-11892: setAvailableProductSet EMM API calls and App Syncs failing due to SQL exception - violation of PRIMARY KEY constraint

  • CRSVC-30417: API Call in Response Header is of past date. Patch Resolved Issues

  • MACOS-3253: macOS DDUI tunnel profile missing arrays.

  • MACOS-2941: Queue a command to update Intelligent hub settings seeded profile for already enrolled macOS devices in order to include RemovableSystemExtension as part of System Extension payload.

  • CRSVC-31183: Entitlement service migration tool fails to connect to database on DB credential change.

  • CRSVC-30899: Unable to delete devices from console.

  • AMST-36612: Trigger compliance on enrollment complete for Windows devices. Patch Release Notes

  • MACOS-3262: Unable to edit existing macOS profile after macOS DDUI is enabled in environment.

  • CRSVC-31446: The console event date filter is not working as expected.

  • CMCM-190022: DB Server CPU spiking to 100% multiple times a day.

  • CMCM-190021: Undefined Error when viewing assigned devices for Content. Patch Resolved Issues

  • MACOS-3330: Identify the cause for DB Upgrade failure due to Invalid column name 'DevicePlatformId'.

  • MACOS-3312: MacOS DDUI Network access profile not showing option "Use as login window configuration".

  • CMEM-186698: PowerShell failing: "User credential of the remote PowerShell server contains the special characters".

  • AMST-36835: Device context based applications require valid user session to process uninstall.

  • AGGL-12800: Device Sync triggers RemoveApp command for iOS app.

  • AMST-36875: App sampling to query SFD when SFD is known to be installed on device.

  • AMST-36865: Seed v2206 SFD patch to UEM.

  • AMST-36850: Samples are being repeatedly queried till samples response comes. Patch Resolved Issues

  • MACOS-3313: macOS DDUI SCEP Payload - AirWatch CA Template does not populate.

  • FCA-203853: Unable to load Angular Exports page.

  • AMST-36972: Unable to edit app assignments.

  • CRSVC-31786: GSX test connection fails with SSL error. Patch Resolved Issues

  • AGGL-12898: Time mentioned in System Updates profile changes to AM from PM after save and publish when UI locale languages is Japanese, Chinese, or Korean.

  • INTEL-42182: ETL-Design the ability to enable CDC based exports in AWS RDS. Patch Resolved Issues

  • AMST-36832: Windows Firewall Rule not working as intended on Win 10 device.

  • CRSVC-32057: “Renew Certificate" not working as expected in Certificate list view. Patch Resolved Issues

  • MACOS-3364: Populate tunnel configuration in VPN processor properly. Patch Resolved Issues

  • CRSVC-32316: Add telemetry for counting usages of the unsigned Secure Channel payloads.

  • CRSVC-31978: Unable to publish scripts due to errors with console.

  • AAPP-14586: EAP-TLS option not saved on tvOS Wi-Fi profile (DDUI).

  • RUGG-11434: Policy Engine stuck on environments without processing items in queue.

  • ARES-22978: Invalid samples from Apple and Apple OSX devices with empty unique identifiers.

  • AMST-36856: Seed v2206.2 Patch Hub to UEM. Patch Resolved Issues

  • ARES-23175: High SQL waits causing the console slowness.

  • ARES-23168: Unable to save and publish profile due to SQL timeout. Patch Resolved Issues

  • ENRL-3580: Add Token Preview Behind a FF.

  • CRSVC-32618: Optimize Publish of public and purchased apps flow.

  • AMST-37237: Allow upper case characters for Baseline Name.

  • AGGL-13122: Fix the incorrect Model being updated for a device from system samples - Zebra devices are being reported as model type "unknown" in Smartgroup filter Patch Resolved Issues

  • MACOS-3400: MacOS DDUI Network device profile not showing "username" option under EAP-TLS protocol.

  • MACOS-3383: macOS DDUI - Certificate is not referenced correctly in Network payload.

  • FCA-204170: A single call to "/api/mdm/devices/search" makes around 3000 calls to DB and stressing the same.

  • CRSVC-32845: Improve compliance flow at "/api/mdm/devices/search" to reduce DB calls

  • CRSVC-32786: Notifications for VPP App Auto Update will no longer be sent to Admin Console post UEM upgrade to 2206 due to error in GetCoreUsersByLocationGroupIdAsync call.

  • CMSVC-16561: Replace TagsDeviceStateIntegrationFeatureFlag with DeviceStateInterfaceEnabledFeatureFlag.

  • AMST-37331: Compromised status change for Mac Devices are flooding Event Logs table.

  • CRSVC-32685: Unable to delete some devices from UEM through UI or API.

  • AMST-37309: Device identifier and UDID mismatch for any reason should not unenroll device.

  • AMST-37304: Since upgrading (2204) Custom profiles are not installing for newly enrolled Windows devices.

  • AGGL-13170: setAvailableProductSet EMM API call fails due to SQL truncation Error.

  • AAPP-14774: Cannot enable device assignment for certain VPP applications.

  • AGGL-13160: Observed 500-Internal server error response for app details API across multiple UEM servers. Patch Resolved Issues

  • AMST-37435: Sensors tab on Device Detail view should be visible for Registered Mode devices.

  • AMST-37255: Seed v2206 SFD patch to UEM.

  • AAPP-14823: tvOS DDUI - Unable to add more than five Credential payloads.

  • AGGL-13119: DDUI profiles fail to save settings. Patch Resolved Issues

  • ARES-23299: A single API call makes around 600 calls to DB and stressing the same.

  • CMCM-190181: Unable to delete content from List view or through API (500 error).

  • CMCM-190214: Intermediate SQL timeout exception seen on test environment.

  • MACOS-3432: macOS DDUI - Network profile lookup values are not resolved.

  • AGGL-13311: URL Blocks & Exceptions in Chrome Browser Profile disappeared with data loss. Patch Resolved Issues

  • MACOS-3372: macOS DDUI - Character limits in payloads.

  • CRSVC-33269: Add debug logging to the HMAC Canonical code.

  • AGGL-13352: DDUI - Request to increase maximum character limit for fields in Chrome Browser settings profile. Patch Resolved Issues

  • AAPP-14825: Environments experiencing long running query during heavy DB Contention.

  • INTEL-44017: Add Managed Application List join in app Initial Export.

  • INTEL-44133: Android Hub version mismatch between UEM and Intelligence.

  • INTEL-44409: Display last checked out username in UEM devices data in Intelligence. Patch Resolved Issues

  • AAPP-15041: Certain VPP applications are stuck Pending Check.

Known Issues


  • FS-1297: Freestyle Orchestrator workflow identifier version is showing up in string format it should be friendly version identifier.

    Workflow identifier version on Intelligent Hub is displayed as a string format instead of an end user friendly format. This might lead to bad UI experience for end users but does not impact the functionality of workflows.

    There is no workaround for this issue.

  • UM-7577: Customer is using Oracle Directory. While we are able to sync users and groups, the attribute sync is failing primarily the Distinguished Name Attribute.

    If a customer is using Oracle Directory and they do not have auto-merge enabled, its possible for user attributes to fail on sync and update correctly within the console.

    In order to remediate this please enable Auto-Merge configuration under Groups & Settings > All Settings > Enterprise Integration > Directory Services > Users Tab > Advanced.

  • ENRL-3501: "Get device enrolment token details" API does not return tags value.

    When this API is used to get the enrollment token details, the details do not contain the tags which have been created for the enrollment token.

     The tags are visible in Devices > Lifecycle > Enrollment Status > Tags.

check-circle-line exclamation-circle-line close-line
Scroll to top icon