Weekly highlight:
VMware Workspace ONE Mobile Threat Defense has been released!
Workspace ONE Mobile Threat Defense is an advanced security solution for Android, iOS, and Chrome OS that helps protect against threats, vulnerabilities, behaviors, and configurations originating on mobile devices. Through integrations with the Workspace ONE platform, advanced mobile security is easy to deploy and manage, and offers enhanced protection designed to secure the workspace and enhance Zero Trust initiatives. Workspace ONE Mobile Threat Defense is powered by Lookout, an industry leader in advanced mobile security:
Getting Ready for Android 13 (88379)
- As of April 26th, 2022, the Android 13 public beta 1 is available for users on Pixel devices.
- What’s new in Android 13
To review new Android Enterprise features on Android 13, click here.
For Android app developers, please review behavior changes that may affect your apps: - Behavior Changes in Workspace ONE UEM on Android 13
- Android 13 introduces a new runtime permission to send notifications.
- In order to ensure that users maintain the same experience after upgrading to Android 13, it is recommended to use the Android Permissions profile to grant this permission to any apps that need to send notifications.
- More details will be added as testing continues for Workspace ONE applications.
- Android 13 introduces a new runtime permission to send notifications.
- Known Issues for Android 13
- No issues yet identified
- VMware application support for Android 13
- Please review in the KB directly.
- Please follow: https://kb.vmware.com/s/article/88379?lang=en_US
Digital Workspace Office Hours - Virtual Customer Event
Our mission is to ensure you get the most out of your Workspace ONE and Horizon investments. These office hours provide you direct access to VMware experts and enable you to leverage all of the capabilities of VMware's Digital Workspace solutions.
During 60-minute, interactive sessions, you’ll engage with VMware experts and explore:
- Common pitfalls
- Frequently asked questions
- Best available resources
- Register for future sessions or view previous ones on-demand to get onboarding and optimizing tips from VMware Workspace ONE and Horizon experts.
- Next Session: May 12th, 17:00 CET → Automate the deployment of Applications and Configurations with Workspace ONE UEM Freestyle Orchestrator
- Hosted by Patrick Zöller and Grischa Ernst
Join this webinar session to learn the latest from our Expert Customer Success Architects on the following:
- Learn how you can use Freestyle to take your Deployment of Applications, Profiles and Scripts to the next Level
- See how you can effectively leverage Sensors and Device Attributes and Time Window in Workflows.
- Best Practices for using Freestyle Orchestrator for Windows and macOS. Introduction of Freestyle for mobile.
- Register here: https://www.vmware.com/learn/1332050_REG.html?src=so_6273f866a37bd&cid=7012H000001Kbbp
Workspace ONE UEM - Device Friendly Name and Enrollment User hyperlinks are disabled on the Device Events page (88380)
- Hyperlinks in the Device Friendly Name and Enrollment User columns are disabled on the Device Events page in the Workspace ONE UEM console. Administrators will not be able to redirect to the Device Details or User Details pages directly from the Device Events page.
- Admins will not be able to redirect to the Device Details or User Details pages directly from the Device Events page.
- Our product team has been engaged and will be working to resolve this issue as soon as possible.
- Workaround: Admins can view and copy the Device Friendly Name and/or Enrollment User from the Device Events page then manually navigate to the Device List View or Users List View pages and perform a search to view the details.
- KB-Reference: https://kb.vmware.com/s/article/88380?lang=en_US
HUBW-6320 - Workspace One UEM - Windows Baselines show as failed in the console for devices with Windows Hub 21.07.x (88377)
- New or updated baselines may fail to apply when pushed to windows devices that have Windows Hub version 21.07.x installed.
- From the Workspace ONE UEM Console, Windows baselines may show a status of failed.
- Task Scheduler and Baselines logs from the device hub logs will show an error similar to the one below.
"@mt":"Failed to reapply the baseline {Exception}","@l":"Error","Exception":"Newtonsoft.Json.JsonSerializationException: Error convertin
- Workspace ONE UEM Windows Hub 21.07.x
- This issue has been addressed in Workspace ONE UEM 2203. The fix has also been backported to Workspace ONE UEM Windows Hub 21.07.9
- KB-Reference: https://kb.vmware.com/s/article/88377?lang=en_US
Teams optimization becomes unavailable after network interruption on HTML Access and Chrome client (85761)
- When use Teams in VDI/RDSH by HTML Access and Chrome Client with Teams optimization ON, client has short network interruption, teams optimization becomes unavailable even horizon session has recovered. User cannot make video/audio call or join meeting at that time.
When there is short-time network break(similarly as refresh), the VDI session(based on blast) will use the old token to reconnect and both side will consider this VDI session continuous.
But at the same time, the VVC channel through which the Html5MMRServer and the Html5MMRClient communicate with each other will be broken down and to reconnect as brand new one. So the old WebRTC instance will destroy and pending for the new one to be created.
The WebRTC instance(consider as the initialization of all WebRTC Redirection) will only be created by the command from MS Teams client. Since MS Teams client only listen to the event of VDI session, it will treat this situation as session continuously connected and won't trigger a new command to create new WebRTC instance.
Since the root cause is that MS Teams client and Html5MMRServer are out-of-sync of the WebRTC Redirection status at this case.
We need to work with MS to figure out some way to let Html5MMRServer tell MS Teams client that "WebRTC Redirection session was broken, and there is a new session just connected. You could send a new command to create new WebRTC Instance."
- Workaround:
Option1: Quit and relaunch MS teams app.
Option2: Disconnect/logoff current session then reconnect it.
- KB-Reference: https://kb.vmware.com/s/article/85761?lang=en_US
Boxer Phishing Report (86184)
- Customer would like to change the way Boxer reports Phishing Emails, so the configured email address will receive the reported email as a forward email.
- Product working as desinged, a feature request should be open.
Currently Boxer sends an email to the configured email address for phishing reporting, the email has an attachment file with extension .EML (email extension).
- Is not possible to change the way Boxer sends the report, so a Feature Request (AHA request) should be suggested.
- https://docs.vmware.com/en/VMware-Workspace-ONE-UEM/services/BoxerAdminGuide/GUID-SupportedCapabilities.html?hWord=N4IghgNiBcIEYHsAeBTATgAgA4AsCWAzvgHYDmIAvkA
- KB-Reference: https://kb.vmware.com/s/article/86184?lang=en_US
Error “Session Handle null, Hence we are initiating to disconnect” occurs when attempting to remotely access device (84128)
- When attempting to remotely access a device, the following error message appears: “Session Handle null, Hence we are initiating to disconnect.”
- The Assist Agent prints this error when it checks in with the ARM server to verify if there is an active session, and the ARM servers say "no". Even in successful attempts to start a remote management session, this error may be viewed several times before the ARM servers say "yes" and return a handle for the session.
- To resolve, please restart the AetherPal services in the following order and check that they are functioning as expected:
- Service coordinator
- DataTierProxy
- Management entity
- MessagingEntity
- AetherPalToolController
- ConnectionProctor
- Additional information: https://kb.vmware.com/s/article/84128?lang=en_US
Highlighting High Priority KBs
Announcing end of support for device administrator (Android Legacy) in Workspace ONE UEM (80971)
To align with Google’s strategy and ensure VMware’s investment in the right long-term solution for Android, as of March 31st, 2022, VMware will no longer support device administrator-based management on Android (referred to as Android (Legacy) in the Workspace ONE UEM console).- VMware Tunnel Proxy End of Support Life Announcement (87345)
VMware is announcing End of Support Life for the Tunnel Proxy component of the VMware Tunnel solution. This will be effective January 30, 2023. - VMware Workspace ONE UEM New Control Plane SaaS Deployment Schedule (86243)
Workspace ONE UEM has undergone a complete re-architecture to modernize the platform using microservices and containers to enable increased scalability and performance and increase the rate of innovation. Now after having conducted significant and careful testing, these architecture updates, including a new control plane, will be deployed to UEM SaaS environments over the next several weeks, with options available to on-premise customers after this roll-out (Later in 2022). - [Resolved] CRSVC-25521 - Workspace ONE UEM - Guidance for addressing CVE-2021-22054 (87167)
The Workspace ONE team has investigated CVE-2021-22054 and has determined that the possibility of exploitation can be removed by performing the steps detailed in the Workaround section of this article. This workaround is meant to be a temporary solution until updates documented in VMSA-2021-0029 can be deployed.
Recently updated or added KBs
- How to Increase vIDM appliance disk space (85425)
- Custom profile fails to apply branding settings to device (83925)
- Troubleshooting Intermittent Blast Connection Issues in Unified Access Gateway (UAG) (83088)
- Invalid signature Exception on invoking any Horizon Connection Server REST APIs. (86511)
- Information on Horizon 8 Extended Service Branch (ESB) (86477)
- CRSVC-28928: How to replace the Workspace ONE UEM static master key (88323)
- "cbcs" connection issue in case of Node failover (85838)
- VMware Horizon 8 sizing limits and recommendations (88383)
- VMware Horizon 7 sizing limits and recommendations (2150348)
- Updating a System Extension profile version on macOS 11+ cause some extensions to unload (84403)
- The automated DEP enrollment of Mac Studio into Workspace ONE MDM fails (88315)
- Factors that affect resolution time with Appvolume Appcapture Issues (82582)
- VMware Workspace ONE UEM New Control Plane SaaS Deployment Schedule (86243)
- WS1 UEM Console Release and End of General Support Matrix (2960922)
- Updating a System Extension profile version on macOS 11+ cause some extensions to unload (84403)
- VMware Horizon on Oracle Cloud VMware Solution (OCVS) Support (88202)
Digital Workspace Techzone, Blog and YouTube Updates
- A new species: Remote Worker
- What Is Digital Employee Experience (DEX)?
- VMware Workspace ONE Intelligence: Top 5 Things You Should Know
- New Study Shows that Digital Employee Experience is Critical for Hybrid Work
3rd Party Blogs and Industry News
- Patrick Zöller: KB: Solving iOS MDM Profile Error “Decryption key for this profile is not installed”
- Mobile-Jon: Toxic Superiority in IT: How it Hurts Us All
Beta, Lab and Tech Preview Updates
- WS1 Web 22.05 for Android
- ABRW-173842: Allow upload of files from Workspace ONE Content repositoriesUser will now be able to upload files/documents present in WS1 Content repositories or local storage to web applications opened in the Workspace ONE Web browser.
- Bug Fixes & Stability improvements
- WS1 Web 22.05 for iOS
- IBRW-174293: Support download with HTTP POST request
• Bug Fixes & Stability improvement
- IBRW-174293: Support download with HTTP POST request
Patch & Seed Script Updates Week18-2022
- OS Updates Seed Script
- Most recent update: iOS 15.5.0 (19F5047e),tvOS 15.5.0 (19L5547e),macOS Monterey 12.4.0 (21F5048e)
- https://resources.workspaceone.com/view/rywydmj6ghb9nmch4ywq/en
- Last Update: CW14
- Seed Script for latest Device Model Information
- Update Device Model details seed for iiPad Air (Gen 5), iPhone SE (Gen 3) models
- https://resources.workspaceone.com/view/x8kn6bslt67vwvlgx4ld/en
- Last update: CW14
- Custom Script to Allow Android 12 enrollments into Workspace ONE UEM Console
- Agnostic script to update seed data to allow Android 12 enrollments into the Console.
- https://resources.workspaceone.com/view/rvfdv9s6mhsh4xgdxf7f/en
- Last Update: CW44
- Workspace ONE UEM 20.11
- Patch Level: 20.11.0.44
- CRSVC-28747: Migrate UEM database table BlobMaster that were encrypted using kv0
- CRSVC-28486: Update PasswordMigrationMetadata.json file to include Patch-2 tables and column details for migration
- CMSVC-16084: UEM discloses smart group details from other tenants
- https://docs.vmware.com/en/VMware-Workspace-ONE-UEM/2011/rn/VMware-Workspace-ONE-UEM-Release-Notes-2011.html#20-11-0-42-patch-resolved-issues-resolved
https://resources.workspaceone.com/view/pdwkjgfsb8b57cxvfnpd/en
- Last Update: CW17
- Workspace ONE UEM 21.02
- Patch Level: 21.2.0.35
- CRSVC-28747: Migrate UEM database table BlobMaster that were encrypted using kv0
- CRSVC-28486: Update PasswordMigrationMetadata.json file to include Patch-2 tables and column details for migration
- CMSVC-16084: UEM discloses smart group details from other tenants
- https://docs.vmware.com/en/VMware-Workspace-ONE-UEM/2102/rn/Workspace-ONE-UEM-2102-Release-Notes.html#21-2-0-31-patch-resolved-issues-resolved
- https://resources.workspaceone.com/view/48ktw9p6spmq8dflll49/en
- Last Update: CW17
- Workspace ONE UEM 21.05
- Patch Level: 21.5.0.55
UM-7437 Automatic LDAP group sync skipped for customer intermittently
CMSVC-16057 Evaluate and Improve Scheduler Job resiliency in the event of DB connectivity issue
ARES-21981 Device preview page should show exclusions from the current edit only
AGGL-11714 Android 11: Work Profile devices are getting Android Legacy Profiles
AGGL-11710 CN1919 - DB Systel - Post OP2S migration, Android Devices are consuming commands slowly
AGGL-11668 Chrome URLWhitelist/URLBlacklist does not work on the latest Chrome Versions.
- https://docs.vmware.com/en/VMware-Workspace-ONE-UEM/2105/rn/Workspace-ONE-UEM-2105-Release-Notes.html#21-5-0-55-patch-resolved-issues-resolved
Last Update: CW18
- Workspace ONE UEM 21.09
- Patch Level: 21.9.0.32
CMEM-186609: Email profile is republished after upgrading iOS devices to iOS 14.8 and iOS 15 (with compliance policy).
CMCM-189751: Removing the Content Locker SDK Library Key system code causes an override.
AMST-35881: Unable to modify Version field when using File Exists criteria for Windows Desktop applications.
AMST-35815: Blobs being served by Directory Services even when they are present in the CDN and Storage Type set to 1.
- https://docs.vmware.com/en/VMware-Workspace-ONE-UEM/2109/rn/Workspace-ONE-UEM-2109-Release-Note.html#21-9-0-30-patch-resolved-issues-resolved
Last Update: CW18
- Workspace ONE UEM 21.11
- Patch Level: 21.11.0.27
RUGG-10851 Provisioning/PoliciesViewDevices grid ‘Last Seen’ shows time 5 hours behind expected Admin time zone
LUEM-472 Web Enrollment - intermittent failure with hub package download
FCA-202433 UEM console crash while navigating to Devices > Compliance Policies > Event Log
CRSVC-28932 Unable to install smime profile due to certificate is used more than once error
CRSVC-28398 [Device State] Migration of few devices failing due to missing compliance_status value
CRSVC-28308 Async email notifications cause thread pool exhaustion and suspends compliance evaluation
CMSVC-16076 Tags Update API fails when organization group id is not passed.
CMCM-189750 Remove ContentLockerSDKLibraryKey system code and its overrides
ATL-15995 version updates for 21.11.0.27 package
AMST-35938 Seed v2107.9 patch version of Hub to UEM
AMST-35880 Windows Application Deployment Commands are only cleared after a manual Query or App Sample Query from UEM Console
AMST-35816 Blobs being served by DS even when they are present in the CDN and StorageType set to 1
AGGL-11679 DDUI is broken by a certificate date format in Android profiles
AAPP-13760 iOS Device Updates page timeout issue
AAPP-13759 VPP licenses are not getting disassociated
- Docs-Reference: https://docs.vmware.com/en/VMware-Workspace-ONE-UEM/2111/rn/vmware-workspace-one-uem-2111-release-notes/index.html#resolved-issues-2111026-patch-resolved-issues
- Last Update: CW18
- Patch Level: 21.11.0.27
- Workspace ONE UEM 22.03
- Patch Level 22.3.04
- MACOS-2701: Add patch.sql to execute DeviceQueue_MigrateSeededMacOsProfileMacOs2629
- CRSVC-28931: Unable to install smime profile due to certificate is used more than once error
CRSVC-28397: Migration of few devices failing due to missing compliance_status value
- CRSVC-28385: Page fail for ADCS CA in aa
- CMCM-189749: Remove ContentLockerSDKLibraryKey system code and its overrides
- AMST-35882: Unable to run Selective App list API call on the certain enrolled Win 10 devices
- AMST-35837: Purge hardcoded keys from config files
- AMST-35753: Windows OS build version shows different in Device list view and Device summary page
- AGGL-11680: DDUI is broken by a certificate date format in Android profiles
- AAPP-13787: Privacy Preferences Bugs Audit
- https://docs.vmware.com/en/VMware-Workspace-ONE-UEM/2203/rn/vmware-workspace-one-uem-powered-by-airwatch-2203-release-notes/index.html#resolved-issues-22303-patch-resolved-issues
- Last Update: CW18
Comments
Post a Comment