VMware Workspace ONE UEM Release Notes provide information on the new features and improvements in each release. This page includes a summary of the new features in 2210, issues resolved, and known issues.

When can I expect the latest version?

We strive to deliver high-quality products, and to ensure quality and seamless transitions, we roll out our products in phases. Each rollout may take up to four weeks to accomplish and is delivered in the following phases:

  • Phase 1: Demo, Shared SaaS UATs, and Latest Mode UATs

  • Phase 2: Shared SaaS environments

  • Phase 3: Latest Mode environments

This version is only available to our SaaS customers on the Latest mode. The features and improvements incorporated in this version will be available to our on-premises or managed hosted customers with the next on-premises release. For more information, see the KB article.

Getting Ready for Apple Fall 2022 Releases

Interested to learn about the recent Fall 2022 releases for Apple? See Getting Ready for Apple Fall 2022 Releases for more information.

New Features in this Release


  • We’ve added a user migration tool for LDAP Enabled Organization Groups

    A user migration tool addresses errors in the user group sync process and corrects unhandled workflow and database migration errors. You can only use this tool on organization groups that have Lightweight Directory Access Protocol setup (LDAP). For more information, see User and Admin Accounts.

  • Duplicate Authentications Eliminated on Access and Reg Token Configs

    When you enable registration tokens and choose Workspace ONE Access as the authentication source, users are no longer subject to duplicate authentications. There is no system setting to configure as this change is enabled by default.

  • The Admin Groups and Admin List View pages now have enhanced user interfaces

    We’ve refreshed the look and feel of the Admin Groups and Admin List View pages without changing their features or functionality.

  • We've simplified the process of uploading internal applications

    The Workspace ONE UEM console now uploads internal app to the Content Delivery Network (CDN) in the background, in addition to displaying CDN upload progress. This enhancement reduces the time spent on the app upload loading screen and frees you to perform other tasks in the Workspace ONE UEM console while the console prepares the app for distribution.


  • Let your apps share data by default with cross-profile communication

    In Work Profile and Corporate Owned Personally Enabled modes, applications now have a limited ability to share data with each other by default. In Android 11 or higher, Workspace ONE UEM supports allowing specific applications to request user consent for cross-profile communication. For more information, see Restrictions profile.

  • We now support configuring domain suffixes in WPA/WPA2 Enterprise Wi-Fi Profiles

    Workspace ONE UEM now supports setting a domain suffix for server certificate validation in WPA/WPA2 Enterprise Wi-Fi networks. For more information, see Wi-Fi profile configuration.


  • Support for Device Metrics in Product Assignment Rules

    You can now use device metrics such as IP address, serial number, battery level, and more for assignment rules when you make a new product to be provisioned. For more information, see Create a Product.

  • Support for deleting multiple files using wild card character

    In product provisioning, one can delete multiple files using the wildcard characters (*,?) in the delete file action. For more information, see File Actions Manifest Options for Android.


  • We've strengthened Bitlocker support

    We have added a new security feature that enables you to make the Bitlocker recovery key unique. A single use recovery key rotates the key when it is used to unlock the PC, ensuring that once a key is used to unlock the drive, it cannot be re-used in the future.

  • Keep apps on a device even if it is unenrolled

    When you enable the device based profile in the Workspace ONE UEM console, you can retain apps managed on a device even if it is unenrolled.

  • We've seeded Intelligent Hub version 22.10.1 and Application Deployment Agent (SFD) version 22.6.14 in this release of the Workspace ONE UEM console.

Resolved Issues

Resolved Issues for 2210

  • AAPP-14311: Implemented GSX v4 APIs to resolve integration issues.

  • CRSVC-32116: Notifications for VPP App Auto Update will no longer be sent to Admin Console post UEM upgrade to 2206 due to error in GetCoreUsersByLocationGroupIdAsync call.

  • FS-1973: Unable to delete Internal applications.

  • FCA-204257: For internal iOS apps, unable to renew provisioning profile.

  • INTEL-41377: Android Hub version mismatch between Workspace ONE UEM and Workspace ONE Intelligence.

  • AGGL-12944: Unable to enroll Android 12 devices as DO when Devices Enrollment Mode is set to Registered devices.

  • RUGG-11496: Problem in displaying data in the Add Custom Device settings feild.

  • ENRL-3595: Unable to update the enrollment restrictions policy if the admin username has more than 50 characters.

  • CMCM-190172: Unable to delete content from the List view or through API.

  • UM-7677: Unable to load the List View page.

  • AMST-37343: Unable to load the Staging and Provisioning settings page.

  • UM-7676: Batch status page was ignoring errors in the Workspace ONE UEM console.

  • CRSVC-32804: Event log page under troubleshooting failed to load after upgrade to Workspace ONE UEM release 2209.

  • CMSVC-16571: Unable to access Assignment groups menu and assigned resources.

  • AAPP-14746: Cannot enable Device Assignment for certain VPP applications.

  • CMCM-190045: Whitelist was not working for voice memo m4a.

  • AGGL-13140: The setAvailableProductSet EMM API call failed due to SQL truncation error.

  • AAPP-14593: Unable to add more than five credential payloads.

  • AGGL-13102: Some Pixel models were inconsistently mapped to a different model causing incorrect Smart Group reconciliation.

  • FS-1862: Unable to edit freestyle orchestrator workflow with the Time Window condition.

  • ARES-23059: When the install application command was sent in bulk, the application install on the requested device event was missing.

  • AMST-37302: Compromised status change for macOS devices were flooding the Event Logs table.

  • ARES-23282: Unable to load the App Removal Log page.

  • CMSVC-16438: Unable to delete devices from the device list view.

  • AMST-37224: Custom profiles were not installing for newly enrolled Windows devices.

  • AGGL-12856: When filtering by model, incorrect model was being updated for Zebra devices. Zebra devices were being reported as model type unknown in the Smartgroup filter.

  • MACOS-3380: macOS DDUI network device profile was not displaying the username option under the EAP-TLS protocol.

  • FCA-204047: Device roaming data issue was reported in the Devices with user details report.

  • CRSVC-31809: Desired State Management related throttling settings were residing on the App Server instead of the database.

  • CRSVC-32510: Compliance status was pending and the next compliance check date was displaying a past date.

  • AGGL-13009: On Android devices, the compliance policy was not uninstalling or blocking apps intermittently.

  • AGGL-13116: Chrome OS test connection failed with 401 error, and the new enrollments were not receiving the certificates.

  • ARES-23128: Application install was not requested on the devices when all devices were selected in the Resources> Apps> Details View> Devices tab to install a Windows internal app.

  • ARES-23119: macOS POST/apps/internal/{applicationid}/uninstall creates MDM client targeted removal application command.

  • ARES-22991: App configuration added through Safari browser shows blank.

Patch Resolved Issues

  • UM-7699: AirWatch Purge expired Sample Data SQL job is failing.

  • AGGL-13368: UI is crashing when app is force installed causing applications failing to install on iOS.

  • FCA-204296: Notes API results in 404 not found when the NotesAPI FeatureFlag is turned off.

  • ARES-23398: Wi-Fi payload does not save data for Domain field after environment upgrade.

  • UM-7709: Ldap Attribute Table is not getting populated by configure API which causes Enrollment failure.

  • AMST-37374: Revert removal of assignment following migration of v1 profile.

  • AMST-37590: Recovery Key Accessed event not raised when key is accessed from Console.

  • AMST-37371: Errors in WebConsole logs for some profile labels.

  • MACOS-3405: macOS DDUI - Network profile lookup values are not resolved.

  • FS-2037: Add API guardrail to restrict workflows to a max of 20 resources.

  • AGGL-13277: Android Hub Auth token gets revoked when Hub assignment is removed.

  • FS-2139: Seed Mac Workflow Host in canonical - 2210 (Version 2210.7).

  • AMST-37554: Security sample improvements.

  • AMST-37636: Adding new version for Win app will fail in certain scenario (EAR or change icon).

  • INTEL-44407: Display last checked out username in UEM Devices data in Intelligence.

  • CMCM-190232: Unable to Configure CG in Re-Ep mode with non-public EP URLS.

  • CMCM-190229: ContentMap Purge - duplicate key error when content map data has >1 status.

  • MACOS-3448: macOS DDUI - certificate is not referenced correctly in Network payload.

  • AGGL-13390: Device Summary page broken for multi-user Windows devices.

  • CRSVC-33490: Update OSL for Mac Host 2210 release.

  • FS-2125: Multiple freestyle issues observed for macOS devices.

  • AAPP-15022: Increased DS memory usage after upgrade to 2209.

  • AAPP-15043: Certain VPP Apps are stuck Pending Check.

  • AMST-37455: [Patch Managememt] Nodes from legacy profile should be explicitly deleted or replaced with default values following migration.

  • ARES-23742: Issue with shift based Access SDK. 

  • CRSVC-33398: Syslog connection failing when configured with ACC.

  • MACOS-3453: macOS DDUI SCEP Payload - AirWatch CA Template does not populate.

  • FCA-204359: Event Data modal is not getting loaded for device and console events

  • CRSVC-33548: Making DSM Sync schedule configurable.

  • AMST-37718: Device compliance status for baselines keeps on switching from "Compliant" to "Non-compliant".

  • AMST-37652: Seed v22.06.15 SFD patch to UEM.

  • ARES-23887: Review Assigned Device Page showing duplicate entry.

  • AMST-37732: Seed 2210.02 patch of Windows hub to UEM console 2210.

  • AMST-37722: (Factory Provisioning) Active Directory select is not working as expected.

  • AMST-37750: (P2P Branch-Cache) Peer to Peer download is not working.

  • ARES-24028: Remove time taking DB script to update Event Log.

  • CRSVC-33821: Compliance Summary performance issues.

  • CMCM-190253: Remove unwanted usage of Feature Flag.

  • AMST-37752: User profile does not install and receives error when pushing manually.

  • CRSVC-33805: Event data is not populated until refreshed if filter is changed post upgrade to UEM 2210.

  • CRSVC-33853: Unable to save Syslog settings with hostname with error "Save failed Invalid Host name".

  • UM-7789: LDAP Definition delete fails due to FK constraint.

  • UM-7796: Admin user status is not set to disabled on VIDM after deactivating it from UI.

  • AMST-37876: Old hub calling with duplicate baselines causing baseline sample save failure.

  • UM-7793: Domain migration does not update the Domain attribute of the users.

  • FCA-204489: Directory Services - Unable to add Directory accounts with SAML only integration.

  • MACOS-3502: macOS DDUI login window profile is failing to install on device with error.

  • AGGL-13534: DDUI - Request to increase maximum character limit for fields in Chrome Browser settings profile.

  • MACOS-3490: macOS DDUI - Editing Network profiles causes some keys to not populate.

  • AAPP-15236: Device details information should be fetched and displayed.

  • AGGL-13262: Apps not installing Apps on Share devices (Pixel 6).

  • FS-2529: Unable to add more than 20 resources for Windows devices.

  • AGGL-13623: Cannot view XML or install Android profile containing both VPN and Credentials payloads.

  • AMST-37921: Antivirus and Firewall status are failing periodically.

  • AGGL-13663: FCM message received on DirectBoot mode for clear passcode is empty.

  • CRSVC-34595: Handle and fix Unity dependency resolution exceptions.

  • AMST-38044: Dropship online self service not working on multiple Shared SaaS environments.

  • AMST-38008: Unable to modify and save the install command for Windows app.

  • INTEL-45765: Customer reporting device hostname is incorrect and inconsistent in Intelligence platform.

  • MACOS-3571: macOS - Add support for new hardware released.

  • FCA-204695: Unable to search and add directory accounts in UEM version 2210.

  • AMST-38169: Location option missing in Bulk management for Windows devices.

  • MACOS-3560: Rocket space man error when tried accessing Security tab for macOS devices.

  • ARES-24396: SP called too many times adding to DB contention.

  • CMEM-186762: PowerShell integration with Modern Authentication failing for O365 Tenants.

  • AMST-38159: Hub not showing device as enrolled and not receiving apps/profiles.

  • AMST-38182: Migration message appears after 22.10 update - without FF.

  • ARES-24507: InstallEnterpriseApplication Failures for macOS.

  • CMSVC-16728: Unable to load Assignment groups list view and unable to load assignment groups in app assignments.

  • CRSVC-34949: Enhance OAuth log for pin pointing error source.

  • ENRL-3676: Notifications are not sent for enrollment lifecycle.

  • FCA-204726: Incorrect alignment of app assignment columns.

  • PPAT-12922: DTR updates are not consistently consumed by Windows devices.

  • PPAT-13438: iOS VPN Profiles have the incorrect DTR ruleset getting applied for devices.

  • AMST-38173: Evaluate and update Enterprise Reset and DeviceGaurd check in the enterprise reset flow.

  • AMST-38161: Seed 22.10.4 HUB to UEM console.

  • AMST-38267: Improve products delivery for newly enrolled devices.

  • CRSVC-34952: DeviceStateMigrationService leading to 100% CPU usage on the node.

  • AAPP-15424: Post Console Upgrade from 22.06 to 22.09 VPP Assignment is not working as expected.

  • AAPP-15427: Beacon sample should trigger Device Info Sample but should not save OS data.

  • AMST-38336: Baseline compliance report generation on fully compliant devices refreshes the baseline policies and switches the status to Pending Install.

  • ARES-24501: Enterprise Application Repository is no longer able to add iTunes application.

  • FCA-204247: Console app pool is terminating with unhandled exception.

  • FCA-204891: Show success for change Organization Group of device even when it is prevented by tenancy restriction.

  • AMST-38367: Seed 22.06.20 SFD to UEM console.

  • AMST-38396: Gateway throttling for managed apps sample.

  • INTEL-46733: DB Patch failing with PK constraint error on upgrade.

  • FS-2883: Seed Mac Workflow Host in 22.10.

  • ARES-24782: Data corruption while loading data from table.

  • FS-2746: Conditions are not evaluated with macOS Freestyle.

  • CRSVC-35976: Refactor EventLogService to use concurrent bag.

  • INTEL-47500: Windows devices unenrolled.

  • ARES-24646: Public app uninstall API is not working for systems apps.

  • INTEL-47266: (ETL) Update Device checksum sproc to remove concatenation instead send columns.

  • MACOS-3660: Decouple code changes to seed new MAC models.

  • AMST-38348: Seed 22.10.5 HUB to UEM console.

  • CMSVC-16859: Smart Group deletion fails when workflow deleted assignment present for the device and application.

  • CRSVC-36192: Failed to retrieve bearer token to revoke the refresh token for Office365 apps.

  • CRSVC-36224: DB Upgrade Failure due to missing seed value in device manufacturer and device model detail.

  • FCA-204444: UEM Console unexpectedly exports all admin accounts irrespective of current admin role in UEM 2210.

  • FS-3058: Revert back the chunk change in workflow Mac host.

  • FS-3078: Seed Mac Workflow Host in canonical 2210.

  • UM-7682: Unable to see users at parent OG level using /API/system/users/search after changing user group permissions.

  • AGGL-13276: Unable to upload Calculator application from internal apps section.

  • ARES-25138: [SDK Settings] Unable to save SDK Settings after editing 'Allowed Sites' under Integrated Authentication.

  • ARES-25143: AirWatch Database Purge expired Sample Data SQL job is failing.

  • CRSVC-36793: Fix operating_system_name data mismatch in default_attribute segment of device state.

  • FCA-205073: Directory Services - Unable to add Admin AD accounts from secondary domain.

  • RUGG-11943: Loading screen takes more than one hour when you click Send button on the Device List page selecting all iOS devices.

  • ENRL-3739: Enrollment restrictions not being honored for iPad devices.

  • AAPP-15769: APNs Outbound messages throttled and failure code.

  • ARES-25323: Unable to renew provisioning profile for internal iOS apps.

  • AMST-38808: Deprecate legacy Windows Updates SOAP API call.

  • ENRL-3748: Unable to edit/view DEP profiles.

  • AMST-38805: Sample Save SPROC causing deadlocks.

  • ENRL-3676: Notifications are not sent for enrollment lifecycle.

  • ARES-25172: Improve and Optimize Entity Reconcile Service to reconcile devices in batches.

  • AMST-38675: Windows DM Session table not being updated.

  • ARES-25302: Profiles not getting assigned to iOS device.

  • AAPP-15902: Internal iOS app details display incorrect Bundle Identifier.

  • AMST-38845: Reduce traffic of empty sample for winRT devices.

  • FCA-205278: Device Search API is not returning Wi-Fi SSID in the response.

  • CRSVC-37275: Changes for correcting AppSequence workflow type in 2210.

  • AGGL-14559: Remove unwanted calls that are made to play.google.com when user saves a new application or edits the application assignment.

  • FS-3226: iOS and Android Workflows getting struck in 'InProgress' status.

  • CRSVC-37376: While creating new Compliance policy under view Device Assignment page pressing enter is saving the compliance policy.

  • PPAT-14136: Post Migration to AWS CloudFront - Tunnel Configuration Page does not load.

  • SINST-176112: Airwatch API Gateway file copy failed during deployment.

  • AAPP-15940: Device snc should not queue Remove Provisioning Profile Command if PP is shared by other assigned apps.

  • ARES-25310: Global search results screen shows garbled characters for double-byte names in UEM console 2209 or later.

  • AMST-38948: WNS Notifications - Command are not consumed immediately.

  • ENRL-3708: Beacon flow is wrongly updating OS info.

  • CRSVC-37818: Migrate invalidate refresh token flow from AAD to Microsoft Graph API.

  • AMST-39007: Seed latest SFD 22.06 build to UEM 2212, 2210, and 2209 servers.

  • AAPP-16003: Hub Registered Mode Sample Collection enhancements and fixes.

  • CRSVC-37519: Update Token Refresh Azure AD Graph API call.

  • AAPP-15978: Invalid characters causing XML validation failure.

  • ENRL-3764: Fix Attribute mismatch between canonical and device state.

  • RUGG-12118: Product assignments were delayed.

  • UM-8085: Error prompted while trying to add LDAP Admin group in Workspace ONE UEM console and save.

  • ARES-25415: Internal app publish fails due to duplicate key inserted error.

  • CRSVC-38213: Un-authenticated Deviceservices endpoint to unenroll any device.

  • ARES-25679: User-context Certificate profile installed through Workflow not saving UserId in CDD.

  • AAPP-16146: APNs outbound queue was backed up on CN230.

  • INTEL-50182: Intelligence enrollment users not syncing as expected.

  • FCA-205566: Upload the Selenoid 1.10.12 to harbor and use the docker-compose.yaml.

  • AMST-39021: Windows PC important updates - API was not working for Windows 10 or Windows 11 devices.

  • CRSVC-38143: Compliance - Prioritize sample-based compliance evaluations.

  • CRSVC-38144: Add compliance evaluation related events for troubleshooting.

  • FCA-205594: Unable to send the Push Notifications/Email notifications using Bulk Management.

  • PPAT-14530: .NET Core version Upgrade to 6 for Tunnel Microservice.

  • CRSVC-38642: Incorrect 404 exception error message during DSM.

  • SINST-176153: Updated Code signing certificate.

  • SINST-176169: DDUI Profile Screen Fix.

  • SINST-176203: Update Installer to fix issues with DDUI profile screen.

  • AAPP-16311: False APNS Notifications during Purchased App Sync.

  • AGGL-15328 : Remove EFOTA sample from microservices.

  • AGGL-15445: Unable to create Android profile with a Time Schedule whose UUID is NULL.

  • AMST-39476: The default 'Read Only' Admin role to view the Baseline is not working.

  • AMST-39539: Workaround for MSFT issue breaking SFD installation.

  • CMCM-190662:Workspace ONE UEM console shows spaceman error when viewing security tab for most macOS devices.

  • CMEM-186890: Powershell script and UEM side changes for EXO V3 Module.

  • CRSVC-39278: Certificate password is null.

  • FCA-205773: AirWatchSSP is terminated with Unhandled Profile Installation Exception.

  • FS-2212: Not able to get the App in Edit workflow screen for the existing workflow.

  • INTEL-51754: Update current device enrollment user delta export to include delete operation.

  • MACOS-3991: MacOS profile repeatedly encounters Device Profile Corrupted error.

  • ARES-26450: Clone- Inactive update profiles getting removed from machines automatically causing the devices unnecessary upgrade to Win 11.

  • AAPP-16441: Update Device Information query Cellular keys.

  • MACOS-4061: macOS 14 automatic device enrollment fails if Custom Enrollment is off.

  • AAPP-16456: Unable to upload an application with multiple info.plist on the UEM console.

  • ARES-26474: Modify sync logic to queue command when previous status is pending release with no pending commands.

  • AGGL-15531: Google seems to have increased oAuthToken length (AndroidWorkSetting AccessToken got truncated).

  • CRSVC-41709: Tunnel gateway unreachable from newly enrolled iOS devices.

  • CMCM-190727: Status of document in content detail report was not corrected.

  • ARES-26620: Device logs were not uploaded to Workspace ONE UEM console.

  • INTEL-52989: Database patch failing on PK constraint, error on upgrade.

  • PPAT-15439: Review and reduce the Tunnel service logs generation.

  • UM-8409: Unblock the auto or manual syncs during advanced LDAP sync cycle failure.

  • CMEM-186925: Objects not clearing from the memory and causing high memory usage.

  • RUGG-12627: Add support for pull relay server discovery with IP as discovery text.

  • CRSVC-42822: Secure Channel - Cannot find the original signer issue.

Known Issues


  • ARES-23585: Wi-Fi payload does not save data for Domain field after environment upgrade.

    The settings are not saved in the DB and the payload XML to be sent to the device does not have the new setting added.

    IIS reset invalidates the cache and new settings are included.

  • FCA-204274: Custom device activation template is not being sent to the devices that are enrolled through SSP.

    Custom message template should take precedence over default when its present( or added). However Resend message option picks up Default message template when a policy is present with allowed enrollment type as Container.

    There is no workaround for this issue.


  • AMST-37480: The system is not honoring the "Supported Processor Architecture" field.

    When the user uploads a windows application, the application pushed to all devices in the smart group ignoring the Supported Processor Architecture setting.

    You can create smart groups targeting to the specific architecture and use the smart group in the app assignment screen.

check-circle-line exclamation-circle-line close-line
Scroll to top icon