check-circle-line exclamation-circle-line close-line

Workspace ONE UEM v9.5 Release Notes

Workspace ONE UEM | 11 June 2018

Check for additions and updates to these release notes.

What's in the Release Notes

The release notes cover the following topics:

New Features in this Release

Mobile Application Management

  • Wokspace ONE UEM console displays location name of the VPP location token:  Starting this release, location name of VPP location token is reported in the UEM console.

Android

  • Pre-release version deployment for Android: Admins can now decide whether to push Alpha or Beta versions of apps before pushing a production version of an app to all users. Alpha and Beta versions published through Google Play can now be assigned and made available through the managed Play Store on Android devices. When assigning applications, there is a new field, Pre-Release Version for you to select which app version. If you do not select Alpha or Beta, the production version of the app is automatically pushed to all devices.
  • Updated minimum check-in interval for AirWatch Agent for Android: The AirWatch Agent for Android has been updated with check-in interval minimum values. The minimum sample values start at 30 minutes. The Profile Refresh option for AirWatch Agent for Android now includes intervals for 6 hours. For minimum values see Agent Settings page for Android. 

iOS

  • Updated minimum check-in interval for AirWatch Agent for iOS: The AirWatch Agent for iOS has been updated with check-in interval minimum values. The minimum sample values start at one hour. For minimum values see Agent Settings page for macOS. 

Windows

  • Workspace ONE UEM OMA-DM support: Workspace ONE UEM now supports an OMA-DM secure channel to ensure communication between Windows Desktop devices and Workspace ONE UEM is secured. This secure channel uses the enrollment certificate to sign and encrypt messages between the device and Workspace ONE UEM.

Secure Email Gateway

  • Secure Email Gateway support for Email Notification Service (ENS): SEG now provides authorization and compliance for Exchange Web Services (EWS) traffic used by VMware Boxer’s Email Notification Service (ENS). ENS for Cloud and On-premises deployment, and CBA using Kerberos Constrained Delegation (KCD) is supported.

Resolved Issues

  • AAPP-2637: macOS Agent Enrollment fails if there is a DEP-enrolled device record and DEP registration record

  •  AAPP-4508: iOS device does not receive Push notification message sent through REST API

  • AAPP-5098: Smart Group Profile updates does not respect time scheduling during Profile Reconcile and incorrectly re-pushes removed profiles to other devices    

  • AAPP-5165: iOS restrictions payload does not display Allow All Movies and TV Shows option

  • AAPP-5217: Orders Assignment view restricts you from adding or editing an assignment 

  • AAPP-5236: macOS Device profiles are re-queued for installation for all the network user login accounts

  •  AAPP-5244: iOS device does not remove existing single app profile before a new profile is pushed that results in new profile installation failure

  •  AAPP-5375: iOS devices that are upgraded to 9.4 UEM results in incorrect assignment for the user based license apps and the apps are incorrectly removed on device sync.

  • AAPP-5405: Notify Devices option for Apple's Volume Purchase Program (VPP) applications does not work as expected

  • AAPP-5407: Enrollment status under Devices > Lifecycle > Enrollment Status displays an error on assigning or removing a profile

  • AGGL-3391: Device Details page for Knox Play for Work does not display excepted set of commands in the console

  • AGGL-3398: iOS or Android device enrollment in 9.3 UEM console fails to complete enterprise wipe while using the REST API 

  • AGGL-3431: Android Enterprise devices does not display all the available apps in Play Store

  • AGGL-3432: Container Enrolled Android Device that is factory wiped and re-enrolled through container results in Enrollment Blocked error

  • AGGL-3537: System apps inconsistently displays as System or Public (Managed) in device owner mode

  • AGGL-3590: Workspace ONE UEM console fails to retrieve Google Cloud Messaging Push notification

  • AMST-6769: User Group Mapping does not work as expected for the Windows 10 bulk provisioning or enrollment when using a staging account

  • AMST-6850: Device Network Details API fails to return IP address for Windows 10 devices. The information is displayed on the UEM console, but the IP address is returned as blank in the API response

  • AMST-7055: Windows 10 devices does not display Automatic Windows Update Status

  • AMST-7091: Windows device fail to execute the install commands

  • AMST-7160: Windows 10 devices API does not support multiple LANs in the device network 

  • AMST-7485: Online BSP apps does not successfully install on Windows 10 x64 machines from UEM console

  • AMST-7543: BSP license synchronization for the online version of the Citrix receiver fails and throws an error

  • ARES-3689: App Catalog landing page does not match the settings saved in the custom filter

  • ARES-4732: Assignment tab for public apps does not accurately display the number of records present per page on changing the page size filter

  • ARES-5203: Blacklist App Group does not honor device ownership during enrollment

  • ARES-5682: Application deactivation followed by reactivation and dismissing App Removal Protection shows install command ready for device

  • CMCM-185814: Workspace ONE UEM Managed Repository displays Category names multiple times when you upload content

  • CMCM-187828: Device Details Summary view fails to load in the UEM Console and Self Service Portal

  • CMEM-184597: Export SEG settings fails if the Organization Group name has a comma

  • CMEM-184605: The Mobile Email Management settings page in the UEM console fails to load when the Test mode is enabled with Basic Authentication

  • CMSVC-5517: The search user option while adding a device does not honor permission restrictions and allows the administrators with permission restrictions to add a user

  • CMSVC-5917: Registered devices fails on re-enrolling the device from the AirWatch Agent

  • CMSVC-6159: Non standard email domains restricts creating an admin user through API

  • CMSVC-6290: Devices display blank Compliance Action Taken field even though compliance actions have been taken against them

  • CMSVC-6291: User tab within the device registration token does not display the most recently enrolled device if multiple devices are enrolled under the same user.

  • CMSVC-6387: Cell data usage compliance appears to be pending even though samples are being received

  • CMSVC-6388: Multiple smart groups can be created with the same name in the same child Organization using the copy profile from the top organization and create assignment

  • CMSVC-6509: Enrolled devices does not display correct Device Asset Number

  • CMSVC-6539: UEM console restricts VMware Identity Manager configuration

  • CMSVC-6930: iOS devices display inconsistent  enrollment restrictions based on the order of the rules 

  • CRSVC-3140: Certificate Authority name on the Certificate Authority template does not display correctly

  • CRSVC-3144: Windows 10 devices displays revoke error with internal AirWatch Certificate Authority

  •  CRSVC-3166: UEM console remains in verbose logging even after disabling the logging settings

  • CRSVC-3263: Blue Coat VPN Profile configuration for iOS does not work as expected

  • CRSVC-3317: CISCO ISE Integration API call for the LAN MAC address does not work on enabling the Wi-fi settings

  • FBI-177819: Application Details by Device in the Report List view does not seamlessly load the apps that matches the search keywords in the drop-down menu 

  • FBI-177823: Application Details By Device Report does not retrieve data when the application status is selected as not installed

  • FBI-177865: Devices with Application and User Details Report does not show all the devices or users on the file for the Genius Scan and PDF scanner

  • FBI-177966: Devices with Application and User Details Report for a specific AirWatch application results in timeout issue on selecting the version

  • FBI-177973: Device Inventory Report displays incorrect IP address and roaming information for the devices that has the Roaming value set to No

  • FBI-177998: Reports violate privacy rule settings in the console

  • FCA-185496: Devices that are enrolled to a child organization, fails to receive the Terms of Use prompt in the Self-Service Portal

  • FCA-185844: Self Service Portal does not display company logo

  • FCA-185961: Admin Panel under Email settings does not display SEG status 

  • FCA-186145: Opening UEM console in multiple browser tabs results in submitting the changes to the wrong OG

  • FCA-186227: Exported CSV file for the enrolled devices contains blobs of unprintable characters at the beginning of the file

  • FCA-186289: Device Detail view takes a long time to load the summary page

  • FCA-186363: Windows 10 desktop fails to send push notification from the Self Service Portal

  • FCA-186431: Self-Service Portal login fails if the password contains "<" that is followed by any character

  • FCA-186547: Self-Service Portal landing page calls sp interrogator.ComplianceSummary_Select

  • FDB-1236: Devices Without Required App in the Hub returns incorrect device counts

  • FDB-1769: Admin_locationgroupdelete fails and results in WindowsAppDependency error

  • FDB-1819: Self Service Portal shows duplicate device entries

  • FDB-1824: When an organization that contains video content is deleted, the Admin_LocationGroupDelete sproc results in a FK error.

  • INTEL-3807: OS Update category does not display Last seen status and Enrollment status

  • RUGG-2455: Products total device count does not account for devices which have a product job status set as unknown

  • RUGG-4176: Friendly Name in the View Devices modal does not appear as a hyperlink

  • RUGG-4509: Console fails to complete the Legacy Product assignment on newly enrolled devices

  • RUGG-4693: Files/Actions component in the UEM console displays an error on uploading a cabinet file

  • RUGG-4697: Rapid Deployment Barcode enrollment in the console enrolls the device to a wrong Organization

  • SAWCM-247: Streaming API endpoints are removed from AWCM

  • SAWCM-248: AWCM does not restrict query messages that contain restricted payload

  • SINST-174801: Email Notification Service (ENS) does not start on upgrading ENS from 9.0 to 9.2.1

Known Issues

  • AAPP-5208: No notification is provided after initiating a wipe for a DEP device that is offline

    No notification is provided after initiating a wipe for a DEP device that is offline. Even though the wipe command is queued up successfully, administrators are not notified in the console. After the device comes back online, the command is logged, and the device is successfully wiped.               

    There is no known workaround to prevent this at this point, however the command goes through successfully when the device is turned on and checks into MDM.

  • AAPP-5283: DEP devices that is assigned with an authentication profile and pre-registered with an asset number are not associated with the asset number after enrollment

    If a device enrolls via the DEP with a profile that has authentication enabled and if that particular device has been associated with an asset number via batch ​import, the asset number is not assigned to the device during enrollment.  

    There is no known workaround at this point.

  • AAPP-5305: macOS Software Distribution fails if certain special characters (including < or >) are included in an install script               

    Certain escape characters, such as <<EOF>, causes saving or installation issues when they are included in the install scripts for macOS software due to improper character interpretation.

    There is no known workaround at this point.

  • AAPP-5349: iOS Content Filter profiles installation fails if the title field is blank

    The 'Title' field is required when creating an iOS profile with a content filter payload but is not enforced. iOS Content Filter profiles fails to install if the title field is blank.

    To overcome the issue, provide a title when creating the content filter profile.

  • AAPP-5395: DEP devices enrolls to the users' enrollment OG instead of the DEP profile OG for 'None' staging profiles

    For DEP profiles with authentication disabled and the staging mode set to 'none', the device enrolls to the user's enrollment organization group instead of the organization group selected on the DEP profile even when the profile's selected organization group is set to a lower organization group.

    The user's enrollment organization group can be edited to match the DEP profile or devices.

  • AAPP-5429: iOS VPN payload does not display the 'Add' button for VPN on demand option in profiles

    When creating or editing a VPN profile for iOS devices, the add/+ button is not displayed to add additional VPN on demand configurations to the profile.

    There is no known workaround at this point.

  • AAPP-5434: Device name is updated to friendly name for supervised iOS devices despite friendly name settings

    Even if the 'Set Device Name to Friendly Name' setting is disabled, the friendly name configuration in the settings is pushed to iOS devices on enrollment.

    There is no known workaround at this point.

  • AGGL-3542: Android enterprise fails to remove applications from the Console for all the devices that are enrolled post-migration

    Applications that are added before the migration cannot be removed from the Console. Applications are not removed from the device, but the status indicates removed on the Console.

    There is no known workaround at this point.

  • AGGL-3577: Unable to add Android (Legacy) public application from the play store in the UEM console using the search functionality

    UEM console administrators are unable to add Android (Legacy) public application from the play store in the UEM console using the search functionality. However, Android Enterprise devices are not affected by this issue.

    To overcome the issue, use the Application URL to add the Android (Legacy) public application.

  • AMST-7041: User initiated unenrollment is not reported to the console when the Mobile Device Management secure channel is turned on

    When the Mobile Device Management secure channel is turned on, user initiated unenrollment is not reported to the console. Settings are removed from the device but the enrollment status on the console does not change to "Unenrolled" and the Status remains "Enrolled".

    There is no known workaround at this point.

  • AMST-7132: First sync on RS4 device fails when the Mobile Device Management security feature is enabled

    When the Mobile Device Management security feature is enabled, the first synchronization on the RS4 device after the enrollment fails. After the first synchronization failure, it takes approximately five minutes to complete the next synchronization. 

    Second synchronization works based on the schedule or manual synchronization.

  • AMST-7190: Unnenrollment of a device after an application upgrade failure, fails to remove the previous version of the application

    If a device is unenrolled after an application upgrade failure, the previous version of the application remains installed after the unenrollment is complete and all the artifacts are removed from the device.

    There is no known workaround at this point.

  • AMST-7235: Incorrect Status for some of the software distribution applications

    App statuses reports incorrectly for some of the apps in the console that uses software distribution.         

    There is no known workaround at this point.

  • ARES-5719: Redundant sproc calls made by the API that is used for publishing an internal Windows app

    The API used for publishing an internal Windows app executes redundant sproc calls.

    There is no known workaround at this point.

  • ARES-5806: Uploaded mobile config profiles reported as Out of Date 

    Profile status shows "Installed Profile is Out of Date" if the same profile is being uploaded in two different OG.

    There is no known workaround at this point.

  • CMCM-187635: Purge MarkedForDeleteRepository Scheduler Job fixing orphan data issue

    Purge Marked for delete scheduler does not delete the blobs for which the content version is null. Scheduler should pick all the orphan blobs and delete it from the file storage and from the blob master table.        

    There is no known workaround at this point.

  • CMCM-187710: Content Gateway nodes disappears on saving the page

    Adding a content gateway node in console version 9.5 and the saving configuration causes disappearance of other Content Gateway nodes in that OG.          

    There is no known workaround at this point.

  • CMCM-187798: Content Gateway windows configuration displays download option of UAG build

    Content Gateway windows configuration displays download option of UAG build.

    There is no known workaround at this point.

  • CMCM-187816: Downloading the old version file from Repositories is not working

    Downloading the old version file from Content -> Repositories -> Admin Repositories does not work as expected.

    There is no known workaround at this point.

  • CMCM-187827: Invalid characters displayed on the Content Gateway configuration page at Global OG

    Invalid characters are displayed on the CG configuration page at the Global OG, if the CG is disabled at Global level.

    There is no known workaround at this point. 

  • CMEM-184638: Rules Refresh Interval is 500 instead of 60

     Rules Refresh Interval in the Advanced MEM Configuration Settings is 500 instead of 60.

    There is no known workaround at this point.

  • CMSVC-6677​: Toggle buttons does not work as expected after the settings are overridden in Devices & Users> Advance Settings

    Toggle buttons does not work as expected after the settings are overridden in Devices & Users> Advance Settings. After overriding the settings, administrators must be allowed to change the settings at the child OG as needed.

    There is no known workaround at this point.

  • CMSVC-6772: Unable to open the device registration page on removing the groupid.

    On removing the groupid, user is unable to open the device registration page and the following error is displayed "Something unexpected happened. If the issue persists, please contact your system administrator".      

    There is no known workaround at this point.

  • CMSCV-6956: Directory Services Configuration wizard allows wizard navigation without selecting any option on the wizard.

    In the Directory Services Configuration wizard, if the override option is enabled, user can navigate through the wizard by clicking Next and not selecting any option on the screen.

    There is no known workaround at this point.

  • CRSVC-3390: VMware Enterprise Systems Connector takes more than expected time to process when it is disabled and saved from the Settings page.

    When you disable the VMware Enterprise Systems Connector from the System Settings> Enterprise Integration page, and save the settings, the processing time indicating spinner does not stop unless the page is refreshed.

    Refresh the page to resolve the issue and disable VMware Enterprise Systems Connector.

  • CRSVC-3589: Device Friendly Name display as NA in the Syslog server

    Syslog configuration in the UEM Console supports the configuration of the message content which should be delivered to the Syslog server. In the Message content configuration one can also specify the device friendly name as the look up value so that this value gets replaced when the syslog message is constructed by the event framework to be send to Syslog server. 
    For all the console events, since the device-friendly name does not apply, it is shown as “N/A” in the Syslog server. 

    As a workaround, do not use device friendly name for identifying the device. The device friendly name is a dynamic value that can change over time and may lead to inconsistent logging.

  • FBI-1​77866: Application Details by Device Report fails to return correct number of devices

    Application Details by Device Report is not returning correct number of devices.

    There is no known workaround at this point.

  • FCA-179326: Password field gets auto completed while creating a blueprint in AW Express and selecting the security type as WEP 

    The field has password characters already in it, and hence administrators can save the changes without setting the password for WEP.

    There is no known workaround at this point.

  • FCA-185973: More Options link does not work as expected when you add a new Industry Template in the Internet Explorer browser

    This issue is only found in Internet Explorer 11, and this may be due to the auto complete firing and hanging browser.

    To overcome the issue, use a different browser or turn off auto complete.

  • FCA-186370: Some of the modals scrolls down while loading  

    Modals such as Add Admin scrolls down when loading which makes the user scroll back to the top of the screen. 

    There is no known workaround at this point.

  • FCA-186372: Getting Started flow clears ESC/ACC/VMESC settings

    Settings that are disabled in the ESC/ACC/VMESC pages are being reset to enabled after going through the Getting Started flow.          

    Set ESC/ACC/VMESC settings through the Getting Started Enterprise Connect and Directory flow or complete the Getting Started first and then change other settings manually.

  • FCA-186422: Cloud Services settings page has buttons that appear enabled even when the page is inheriting

    The buttons on the Cloud Services page are active when the page is inheriting. The changes are saved, but the buttons appear enabled.

    There is no known workaround at this point.

  • FCA-186567: The Device List View search does not work as expected when the management type filters are applied

    Number of results that are displayed while searching the Device List View is not accurate when the Management Type filter is applied. However, when the search is performed with the filter set to 'All', retrieves correct search result.

    To overcome the issue, use different filters to narrow down search results.

  • FCA-186610: Add productivity apps from Getting Started Page is broken          

    Unable to add the Productivity apps for Android from the Getting Started page.

    There is no known workaround at this point.

  • PPAT-3389: Proxy configuration shows SSL error when configured without per-app tunnel.

    When the Proxy configuration is configured without per-app tunnel, "SSL Certificate does not match the hostname specified" error is displayed.

    To overcome the issue, configure tunnel with dummy values.

  • CRSVC-3589: Device Friendly Name display as NA in the Syslog server

    Syslog configuration in the UEM Console supports the configuration of the message content which should be delivered to the Syslog server. In the Message content configuration one can also specify the device friendly name as the look up value so that this value gets replaced when the syslog message is constructed by the event framework to be send to Syslog server.

    For all the console events, since the device-friendly name does not apply, it is shown as “N/A” in the Syslog server.

    As a workaround, do not use device friendly name for identifying the device. The device friendly name is a dynamic value that can change over time and may lead to inconsistent logging.

  • ARES-6867: Font color of the navigation bar deviates from the configured branding theme on the legacy App Catalog

    On console version 9.4 or above, font color of the navigation bar deviates from the admin configured branding theme on the legacy App Catalog

  • ARES-7033: Legacy App Catalog CSS does not render intermittently

    On all supported console versions (9.2 and above), intermittently CSS does not render. As a result, end-users see a distorted page that is difficult to navigate.