About Workspace ONE UEM Release Notes

VMware Workspace ONE UEM Release Notes provide information on the new features and improvements in each release. This page includes a summary of the new features in 2209, issues resolved, and known issues.

When can I expect the latest version?

We strive to deliver high-quality products, and to ensure quality and seamless transitions, we roll out our products in phases. Each rollout may take up to four weeks to accomplish and is delivered in the following phases:

  • Phase 1: Demo and UATs

  • Phase 2: Shared SaaS environments

  • Phase 3: Dedicated latest environments

Once our phased rollout is complete, we will announce general availability for on-premises and managed hosted customers. For more information, see the KB article.

Getting Ready for Apple Fall 2022 Releases

Learn more about the upcoming Fall 2022 releases for Apple. See Getting Ready for Apple Fall 2022 Releases for more information.

New Features in this Release

Console

  • We've enhanced Global Search to boost your search results.

    Global search results for devices now include the device’s organization group. This provides context for locating the device in large environments. No setting is required for this default feature. For more information, see Global Search.

  • The Device Wipe page now loads much faster!

    We've enhanced the performance of the Device Wipe page by implementing a filter that retrieves only device wipe data from the complete device command table. This accelerates the rendering of the Device Wipe page.

  • Experience quicker and more seamless SaaS environment upgrades.

    Upgrading to SaaS took more time than expected because of some logic in the migration code, specifically the addition of UUIDs (Universally Unique Identifiers) to the notification table of high-volume environments. We've now decided not to move that specific set of data and to instead add UUID to every new record. The UUID is only required for newer SaaS notification APIs and not for all APIs related to UEM console notifications.

  • Tenancy enforcement on the Assignment Groups page.

    You can no longer create new Smart Groups at OGs above customer type. New Smart Groups can only be created at the Customer OG type or other OGs under Customer. For more information, see Workspace ONE UEM Modernization - Tenant ID and Customer Organization Group requirements for Smart Groups (87464).

  • Ensure shift-based workers have access to the right apps and services during on and off hours using Shift Based Access Control (Tech Preview)

    You can now configure restrictions for Hub Services, Notifications, App entitlements, and Single Sign-On when the user is not deemed to be working - based on WorkJam Time and Attendance System definitions. This feature requires Workspace ONE Experience Workflows, Workspace ONE Hub Services 2209, Workspace ONE Access 2209, and Workspace ONE Intelligent Hub iOS 22.08 and Workspace ONE Intelligent Hub Android 22.11.

Android

  • Want more control over auto updates for Android apps? We’ve got a solution for you.

    You can now set an Auto Update Priority for Android Public Apps for devices managed by Workspace ONE UEM. You can choose to enable high-priority updates or delay updates by 90 days for each app. For more information, see Deploy Application on your Android Devices through Managed Google Play Store.

  • Introducing a new enterprise wipe to relinquish ownership of an Android 11+ COPE device.

    You can now wipe only the Work Profile on Android 11+ COPE devices, allowing organizations to relinquish ownership of the device to the user. Previously, the Enterprise Wipe action would initiate a factory reset on the device, which has now been renamed Device Wipe. The new Enterprise Wipe action keeps personal apps and data intact and does not initiate a factory reset.

Content

  • Restrict users to upload images to the Content app using only the device's camera.

    You can restrict users to only uploading images to the Content app from the device's camera. To do so, activate the Allow Upload From Camera Only option when configuring an Admin repository in the Workspace ONE UEM console. For more information see, Configure an Admin Repository.

  • Specify the number of files that users can upload to the Content app.

    Set the maximum number of files that users can upload when configuring the Workspace ONE Content app using the Workspace ONE console. You can now allow users to upload up to 40 files at once in the Content app. For more information see, Configure VMware Workspace ONE Content.

macOS

  • macOS now supports the uploading of MobileConfig files.

    You can now directly upload mobileconfig profiles for macOS into the Workspace ONE UEM console. For more information, see Upload a Profile.

  • Specify the Intelligent Hub version to be distributed to the devices.

    You can now select the version of the Intelligent Hub to be deployed on the Settings page. During Automated Enrollment with Apple Business Manager or School Manager, or through web-based enrollment, you can specify which version of the Intelligent Hub must be installed on all new devices. You can seed the newest version of the Intelligent Hub into the UEM console or specify a specific version if it is supported and compatible with your console version. We will gradually add the feature to SaaS environments during the rollout. For more information, see macOS Intelligent Hub Settings.

Freestyle

  • Support for App & File conditions.

    You can now add Application and File conditions to macOS workflows. Windows workflows currently support these conditions. To add an application or a file condition for macOS devices, the Freestyle Orchestrator feature requires a minimum version of VMware Workspace ONE Intelligent Hub 22.08 installed on the target device. For more information see, Condition with Applications.

  • We've adjusted the error handling defaults.

    Previously, the default error handling settings had extremely long wait times between retry attempts. We reduced the time spent on retries so that the workflow can proceed or fail at a more reasonable rate.

    • Timeout: 120 minutes

    • Retry after 15 min

    • Maximum retries: 1

    • Bockoff rate: 2

    Existing workflows will not be affected — only newly created workflows will have these new default values. You can always adjust them according to your needs by clicking Additional Settings > Edit Error Handling. More information can be found under Resource Error Handling .

Windows

  • Query Baselines in Workspace ONE UEM for Windows desktop devices.

    You can now query Baselines on devices to update Baseline samples and refresh the Baseline Compliance Status. Use the query function from the Device Details view. To refresh the device's baseline sample, go to More Actions > Query > Baselines in the device record. The Baseline Compliance Status can be found in Resources > Profiles & Baselines > Baselines, where you can select the Baseline and view the Compliance Status card. For more information see, Using Baselines.

Resolved Issues

2209 Resolved Issues

  • AAPP-13986: Unable to assign devices to public books after the book is created.

  • AAPP-13982: Internal books are marked as Not Installed in the Books tab of the Device Details page.

  • AAPP-14521: Unable to upload internal apps with multiple info.plists.

  • AAPP-14265: When checking out a device to a child OG, the managed settings of the child OG are not reflected in the CICO scenario.

  • AAPP-14054: The EAP-TLS option was not saved in the tvOS WiFi profile (DDUI).

  • AGGL-11852: There was a language issue with the app description in the Workspace ONE Intelligent Hub app for Android devices in the Work manage mode.

  • AGGL-11868: Public Android apps that were published to over 600,000+ assigned devices did not land on the devices.

  • AGGL-12014: Time mentioned in System Updates profile changes to AM from PM after save and publish, when UI Locale languages is Japanese, Chinese, or Korean.

  • AGGL-12346: Unable to migrate Zebra devices to Work Manage mode, due to error "Hub is already device owner".

  • AGGL-12349: Device sync initiates the RemoveApp command for an iOS app.

  • AGGL-12439: Assign Outlook to a device AFTER enrolment will get the app configuration.

  • AGGL-12787: Due to data loss, the URL blocks and exceptions in the Chrome browser profile disappeared.

  • AMST-36527: A default user with a weak password was created.

  • AMST-36528: Unable to activate Show in HUB (Optional) option when a New Assignment is accessed through the Assignment column.

  • AMST-36694: Deployment options not retained on Save & Publish.

  • AMST-36710: Windows Firewall Rule was not functioning properly on Windows 10 device.

  • AMST-36758: Device context-based applications require valid user session to process uninstall.

  • AMST-36905: Unable to edit app assignments.

  • ARES-22684: Devices with Application and User Details report fails when the application filter contains different names for apps with the same bundle ID.

  • ARES-7519: Images for Tablets and Mobiles are not filtered for internal apps.

  • ARES-22753: Mac Studio Assignment Update was missing or unselected.

  • ARES-22983: High Latency was observed in Purge Expired Sample Data job execution.

  • CMCM-190017: Undefined error occured while when viewing assigned Content devices.

  • CMCM-190011: The database server CPU was spiking to 100% multiple times a day.

  • CMEM-186691: PowerShell failed with the error "user credential of the remote PowerShell server contains the special characters."

  • CRSVC-29391: Triggering the 5K API calls per minute limit despite the fact that it has been more than a minute.

  • CRSVC-29428: Unable to delete devices from th Workspace ONE UEM console.

  • CRSVC-29464: S/MIME certificates were corrupted on the database.

  • CMSVC-16348: When creating a compliance profile for the first time in a Container OG, the "All Devices" smart group that is created automatically does not display the enrolled devices.

  • CRSVC-31194: The console event date filter was not working properly.

  • CRSVC-31110: When the database credentials were changed, the entitlement service migration tool failed to connect to the database.

  • CRSVC-31387: GSX connection failed with SSL error.

  • CRSVC-31524: Unable to delete a device due to error.

  • CRSVC-31836: Unable to publish scripts.

  • ENRL-3495: API does not return tags value.

  • FCA-203090: Incorrect reason for device unenrollment notification.

  • ENRL-3521: Windows Rugged devices were no longer picking up the Registry Entry for Friendly Name.

  • FCA-203777: Unable to edit the device asset number.

  • MACOS-3211: Workspace ONE Intelligent Hub was not installing after enrollment on the production environment.

  • FCA-203685: Local time was incorrectly reported on Astro Air pages.

  • FCA-203881: When downloading legacy reports, the report name is randomized.

  • MACOS-3258: Unable to edit an existing macOS profile after macOS DDUI has been enabled in the environment.

  • MACOS-3252: macOS DDUI tunnel profile missing arrays.

  • MACOS-3300: On new enrollments, DEP or manual, Native Apps were not installing in the Post Enrollment screen as they were showing up as "waiting".

  • MACOS-3301: macOS DDUI network access profile was not showing the "Use as login window configuration" option.

  • PPAT-12022: Change the Tunnel devices API from public to internal.

  • RUGG-11361: Folder names are missing in multiple Launcher profiles for Android Enterprise.

  • RUGG-11335: Launcher Payload settings missing in 2209.

  • UM-7606: Deactivating 100 users in bulk failed on the Workspace ONE UEM console.

  • UM-7538: The attribute sync was failing primarily.

  • CRSVC-32267: iOS compliance policy for application version was not working as expected.

  • CMSVC-16504: Assignment page was crashing intermittently for internal apps.

  • FCA-203951: Unable to assign devices to the Telecom plan list.

  • AGGL-12354: Allow User to Modify Location Settings for Work Profile was not working.

  • MACOS-3339: macOS DDUI Content Filter profile had a 255 character limit for socket requirement and packet requirement.

  • AAPP-13550: Delay in OS seed script deployment is causing data inconsistency.

  • AGGL-12944: Unable to enroll Android 12 devices as DO when Devices Enrollment Mode is set to Registered devices.

  • FS-2122: Multiple freestyle issues observed for macOS devices.

22.9.0.1 Patch Resolved Issues

  • AMST-37236: Allow upper case characters for Baseline Name.

  • AGGL-12914: Zebra devices are being reported as model type "unknown" in Smartgroup filter.

  • CRSVC-32619: Optimize Publish of public and purchased apps flow.

22.9.0.3 Patch Resolved Issues

  • MACOS-3403: MacOS DDUI Network device profile not showing "username" option under EAP-TLS protocol.

  • LOC-12523: Incorrect translation for "Class Name" in Launcher payload.

  • FCA-204032: A single call to "/api/mdm/devices/search" makes around 3000 calls to DB and stressing the same.

  • CRSVC-32900: Event log page under troubleshooting fails to load after upgrade to 2209.

  • CRSVC-32880: Improve compliance flow at "/api/mdm/devices/search" to reduce DB calls.

  • CRSVC-32785: Notifications for VPP App Auto Update will no longer be sent to Admin Console post UEM upgrade to 2206 due to error in GetCoreUsersByLocationGroupIdAsync call.

  • CMCM-190198: ZDT database upgrade failed.

  • ARES-23135: Application install is not requested on the devices when all devices are selected on the Resources> Apps> Details View> Devices tab to install a Windows internal app.

  • ARES-23122:: MacOS POST /apps/internal/{applicationid}/uninstall creates mdmclient targeted removalapplication command.

  • AMST-37330: Compromised status change for Mac Devices are flooding Event Logs table.

  • AMST-37308: Device identifier and UDID mismatch for any reason should not unenroll device.

  • AMST-37303: Since upgrading 22.4.0.12 (2204) Custom profiles are not installing for newly enrolled Windows devices.

22.9.0.4 Patch Resolved Issues

  • AMST-37256: Seed v2206 SFD patch to UEM.

  • MACOS-3318: MacOS DDUI Network access profile not saving Protocols option.

  • AAPP-14824: Long running query leading to heavy DB Contention.

  • AMST-37434: Sensors tab on Device Detaisl view should be visible for Registered Mode devices.

  • UM-7681: Migration script related fixes for batch processing.

  • CMSVC-16585:Unable to access Assignements groups menu and assigned ressources.

  • CMCM-190180: Unable to delete content from List view or via API (500 error).

  • ARES-23300: A single API call makes around 600 calls to DB and stressing the same.

22.9.0.5 Patch Resolved Issues

  • INTEL-42470: Managed Application List Initial Export creation.

  • AAPP-14773: Cannot enable Device Assignment for certain VPP applications.

  • UM-7696: Unable to load Account > Users > List View page.

  • MACOS-3433: macOS DDUI - certificate is not referenced correctly in Network payload.

  • FS-2042: VMwareWorkspaceONEWorkflowEngine fails to install on new M2 Macs.

22.9.0.6 Patch Resolved Issues

  • RUGG-11580: DDUI-Launcher profile having a problem displaying data in the Add Custom Device Settings field.

  • FCA-204327: Internal iOS apps unable to renew provisioning profile.

  • CRSVC-32264: Syslog connection failing when configured with ACC.

  • ARES-23737: Performance improvement for Profiles.

  • AMST-37582 : WnsClient errors indicate incompatible app.

22.9.0.7 Patch Resolved Issues

  • INTEL-44134: Android Hub version mismatch between UEM and Intelligence.

  • FS-2124: Multiple freestyle issues observed for macOS devices.

  • CRSVC-33268: Add debug logging to the HMAC Canonical code.

  • CMCM-190233: Unable to configure CG in Re-Ep mode with non-public EP URLS.

  • CMCM-190230: ContentMap Purge - duplicate key error when content map data has >1 status.

  • FS-2132: Seed Mac Workflow Host (version 2209.8) in canonical - 2209.

  • AMST-37637: Adding new version for Win app will fail in certain scenario (EAR or change icon).

Known Issues

Console

  • CRSVC-32184: Incorrect pagination total in Message Templates list

    Inconsistent pagination total listed on the total count.

    Blackberry devices are no longer supported, but customers may have Blackberry devices still listed in their system.

    There is no current workaround as the issue is in the database data. Data will need to be cleaned up through a script before this will be resolved.

  • UM-7632: User search REST API does not return users at parent Organization Group level even if admin at child Organization Group has access to user groups at parent Organization Group.

    User groups at parent Organization Group are configured to be accessed by child Organization Group administrators. This enables child Organization Group admins to see all the users from user groups at parent Organization Group in UEM console. When the child Organization Group admin tries to fetch the same users via REST API, the API does not return those users. 

    The only workaround is to use parent Organization Group admin credentials while fetching users using REST API.

  • FCA-204004: Event Data modal is not getting loaded for device and console events.

     Index on EventLogUuid Column is missing in eventlog.eventlog due to which Stored procedure execution is taking long time and getting timing out.

    There is no current workaround for this issue.

  • FCA-204007: Unable to pull storage information with GET /devices/{uuid} V3 API.

    User is trying to use the v3 API to get the details regarding device while the data we get is different from v2 API. Since the data is different from both versions of the API, the user may not be sure which data is correct.

    V2 API can be used to get the data.

  • LUEM-529:  Certificates status in device details for Linux devices is not updating.

    After successfully installing Certificates for Linux devices using profiles, Certificate status in UEM Console remain shows as Pending Install or Unknown. However the certificates are getting deployed successfully to the devices.

    Updating the certificate status based on sampling is affected but existence of the certificate entry in the device details can be considered as the successful deployment of the certificates on device.

check-circle-line exclamation-circle-line close-line
Scroll to top icon