VMware EUC Newsletter - Week 22

   

Week 22 - 2023

 

 

 



 

 

 

Upcoming EUC Events:

 

Event

Start Date

Link

Apple WWDC 2023 Keynote

5-06-2023

https://developer.apple.com/wwdc23/

Workspace ONE - What is DEX?

20-06-2023

https://www.vmware.com/learn/2059251_REG.html

vEUC TechCon (NL)

22-06-2023

https://veuctechcon.nl

VMware Explore US

21-08-2023

https://www.vmware.com/explore/us.html

Apps on Demand: Mastering the Eight Activities of Modern App Management

20-09-2023

UPCOMING: Look out for your invitation to the next VMware EUC Tech Insight Session!

VMware Explore EU

6-11-2023

 

https://www.vmware.com/explore/eu.html

 

Weekly highlight:

 

VMware Security Advisory: 

  • VMSA-2023-0011 - CVSSv3 6.1 - VMware Workspace ONE Access and Identity Manager update addresses an Insecure Redirect Vulnerability. (CVE-2023-20884)
    • An insecure redirect vulnerability in Workspace ONE Access and Identity Manager was privately reported to VMware. Updates are available to address this vulnerability in affected VMware products.
    • VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 6.1.
    • An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.

 

 

 

Release Updates Week 22:

New Apple Builds Are Now Available:

New builds of the following software are now available:

  • iOS 16.6 Beta 2 (20G5037d)
  • iPadOS 16.6 Beta 2 (20G5037d)
  • macOS 13.5 Beta 2 (22G5038d)
  • tvOS 16.6 Beta 2 (20M5538d)
  • watchOS 9.6 Beta 2 (20U5538d)

 

Workspace ONE Boxer for Android 23.05

  • CBA (Certificate-Based Authentication) with Modern Authentication from Workspace ONE Boxer to Microsoft OneDrive
    • EnterpriseContentCBAEnabled is a new, account-based KVP, of type bool.
    • If the KVP is activated, CBA is used for end-user authentication instead of username and password when the end user is redirected to Microsoft OneDrive.
  • Delegated and Shared Accounts Sync Periods Extension
  • The sync periods for the delegated and shared mailboxes and calendars are extended to match the sync periods set for the parent mailbox and calendar accounts in the Workspace ONE UEM admin console.
    • maximum sync period for delegated mailbox/calendar = maximum sync period for parent mailbox/calendar;
      • When a user changes the default sync periods for their mail account, the sync periods for the delegated and shared accounts are also changed.
    • default sync period for delegated mailbox/calendar = default sync period for parent mailbox/calendar
  • Quality Improvements

 

Zebra MX Service 5.8 for Android

  • AAGNT-196844 Support for Android 13 on Zebra OS
  • Known Issue: Stagenow enrollment from UEM console is not currently possible with Android 13

 

Workspace ONE Boxer for iOS 23.05

  • Delegated and Shared Accounts Sync Periods Extension 
    • The sync periods for the delegated and shared mailboxes and calendars are extended to the sync periods set for their parent accounts in the admin console.
      • Maximum sync period for delegated mailbox/calendar = maximum sync period for parent mailbox/calendar;
      • Default sync period for delegated mailbox/calendar = default sync period for parent mailbox/calendar)
    •  When the user changes the default sync periods for their mail account, the delegated/shared accounts sync periods are also changed. 
  • Quality improvements and crash fixes

 

Workspace ONE Content for Android 23.05 (staged)

  • Ability to upload multiple files from the device to the Content app, with ability for admin to set a limit in terms of maximum number of files that a user can upload in one time.

 

 

EUC UX Research Updates & Opportunities 

Our goal is to gather insight into user behaviors, motivations, and goals, so we can use those insights to inform and strengthen product and design decisions.

Upcoming Opportunities - Who Wants To Join?

Interested in giving your opinion and making your voice heard? Check out what’s available!

  • Employee Experience/DEEM for Horizon Admins 
    • Talk to us about how the Experience Mgmt/DEEM feature can be more useful if you were to use it for Horizon
    • 60-minute 1x1 conversation via Zoom
    • Relevant for: Horizon IT Admins
    • Fielding: the week of June 5
    • Admins will receive VMware swag upon completing the 1x1 Zoom conversation!



 

SIGN UP HERE!

 

KB Highlights & Announcements Week 22:

AAGNT-196924: Disable Hub instance in personal side with Application Level Enablement API (92575)

  • We have identified an issue in which the hub app continues to receive updates from the Play Store, even when the policy setting is set to "postpone" for devices enrolled as PO or work profile mode. This behavior contradicts the intended functionality of the "postpone" option, which is designed to temporarily halt updates. As a result, users may receive unexpected app updates, leading to potential disruptions in their workflow or compatibility issues.
  • The root cause of this issue lies in the usage of the “setComponentEnabledSetting” API from Google. It has been observed that the postpone update feature is not functioning as intended. In response to this, Google now recommends utilizing the "Application Level Enablement API" as an alternative solution.

 

 

[ESC-38514] WPA2 Enterprise WiFi Profiles fail to install on Android 11+ devices (92679)

  • When organizations install WiFi Profiles with Security Type WPA/WPA2 Enterprise, the Profile may fail to install on Android 11+ devices if a Domain value is not specified in the Profile. This issue occurs even if a Root Certificate is specified in the WiFi Profile. The Domain field was introduced in Workspace ONE UEM 2210. When the issue occurs, the Profile install status is "Failed". The issue occurs on Android 11+ devices that have received the latest security updates.   

 

AAGNT-196924: Disable Hub instance in personal side with Application Level Enablement API (92575)

  • We have identified an issue in which the hub app continues to receive updates from the Play Store, even when the policy setting is set to "postpone" for devices enrolled as PO or work profile mode. This behavior contradicts the intended functionality of the "postpone" option, which is designed to temporarily halt updates. As a result, users may receive unexpected app updates, leading to potential disruptions in their workflow or compatibility issues.

 

VMware Horizon on Alibaba Cloud VMware Service (ACVS) Support (92140)

  • Starting with version 8 2212, Horizon can be deployed on Alibaba Cloud VMware Service (ACVS). This article discusses the support details including interoperability with Alibaba Cloud VMware Service versions as well as feature parity between Horizon on-premise and Horizon 8 on Alibaba Cloud VMware Service.

 

High Priority KBs

  • VMware Workspace ONE UEM New Control Plane SaaS Deployment Schedule (86243)
    Workspace ONE UEM has undergone a complete re-architecture to modernize the platform using microservices and containers to enable increased scalability and performance and increase the rate of innovation. Now after having conducted significant and careful testing, these architecture updates, including a new control plane, will be deployed to UEM SaaS environments over the next several weeks, with options available to on-premise customers after this roll-out (Later in 2022).
  • Support Access Policies for Customers with Expired SaaS EUC Licenses (89494)
    In alignment with VMware's Corporate Standards and those of the industry as a whole, VMware customers who have purchased SaaS (Software-as-a-Service) licenses for EUC (End-User Computing) products can expect the behavior outlined in the KB regarding Support access when their subscription has a status of Active Pending Cancellation or Expired/Cancelled.

 

Recently updated or added KBs (Links)

 

Digital Workspace Techzone, Blog and YouTube Updates

 

3rd Party Blog Updates & Industry News

 

 

 

May/June Software Releases

 

System

Component

Release

Announcement

Release Date

Android

Boxer

23.04

Release Notes

01.05.23

Backend

Photon OS

5.0

Release Notes

02.05.23

macOS

Hub

23.04

Release Notes

03.05.23

Android

SDK

23.04

Release Notes

05.05.23

Linux

Hub

23.04

Release Notes

05.05.23

Android

Hub

23.04

Release Notes

17.05.23

Android

Launcher

23.04

Release Notes

09.05.23

Android

Tunnel

23.01

Release Notes

17.05.23

iOS

Hub

23.04

Release Notes

11.05.23

Linux

Hub

23.04.1

Release Notes

12.05.23

iOS

Web

23.05

Release Notes

15.05.23

Android

Web

23.05

Release Notes

19.5.23

iOS

Tunnel

23.01.1

Release Notes

15.05.23

Windows

Hub

23.02.3

Release Notes

17.05.23

macOS

Mac OS Admin Assistant

23.03

Release Notes

17.05.23

Backend

WS1 Access SaaS

May 2023

Release Notes

18.05.23

Backend

Hub Services SaaS

May 2023

Release Notes

17.05.23

Android

Hub

23.04.1

Release Notes

19.05.23

macOS

Hub

23.04.1

Release Notes

19.05.23

iOS

Content

23.05

Release Notes

22.05.23

iOS

Hub

23.04.1

Release Notes

22.05.23

Android

XR Hub

23.04

Release Notes

23.05.23

Backend

Console Installer

23.02

Release Notes

24.05.23

Android

Web

23.05.1

Release Notes

25.05.23

Horizon

Horizon Cloud Service Next Gen

2305

Release Notes

26.05.23

Android

Boxer

23.05

Release Notes

01.06.23

Android

Zebra MX Service

5.8

Release Notes

30.05.23

iOS

Boxer

23.05

Release Notes

31.05.23

Android

Content

23.05

Release Notes

staged

 

Patch & Seed Script Updates Week 22-2023

 

 

 

 

 

 

  • Workspace ONE UEM 22.12
    • Patch Level 22.12.0.17
    • AAPP-15941: Device synchronization must not queue remove Provisioning Profile command if the provisioning profile is shared by other assigned apps.
    • PPAT-14137: After migration to AWS CloudFront, the Tunnel Configuration page does not load.
    • SINST-176111: Airwatch API Gateway file copy failed during deployment.
    • ARES-25413: Unintended consequences of enabling SAML authentication for Self Service Portal on Legacy Application Catalog.
    • ARES-25417: High latency in purge expired sample data job execution.
    • AMST-38846: Reduce traffic of empty sample for WinRT devices.
    • CRSVC-37374: When you press Enter while creating a new compliance policy under the view Device Assignment page, the compliance policy is getting saved.
    • https://docs.vmware.com/en/VMware-Workspace-ONE-UEM/2212/rn/vmware-workspace-one-uem-2212-release-notes/index.html#Resolved%20Issues-22.12.0.04%20Patch%20Resolved%20Issues
    • Last Update: CW22

 

  • Workspace ONE UEM 23.02
    • Patch Level 23.2.0.6
    • AMST-38847 Reduce traffic of empty sample for winRT devices.
    • CRSVC-37428: Certificates are not getting deployed to the devices.
    • PPAT-14138 : Tunnel Configuration Page does not load after migration to AWS CloudFront.
    • PPAT-14380: MFA Flag is not set to true in the tunnel allowlist table for Windows.
    • AAPP-15942: Device Sync should not queue Remove Provisioning Profile Command if PP is shared by other assigned apps.
    • AAPP-15907: iOS DDUI SSO extension profile (credential shown for generic type) xml does not contain additional settings fields.
    • CRSVC-37351: Interrogator service unable to save Certificate samples.
    • CRSVC-37372: While creating new Compliance policy under view Device Assignment page pressing enter is saving the compliance policy.
    • AMST-38884: MacOS DDUI Network profile not saving PayloadCertificateAnchorUUID issue.
    • CRSVC-37379: Certificate Import method taking time under load.
    • AAPP-15904: Wi-Fi DDUI payload is crashing on closing the third tab.
    • ARES-25414: Unintended consequences of enabling SAML Authentication for Self Service Portal on Legacy Application Catalog.
    • FCA-205323: Missing Management Mode tab and no activation email for adding email domain.
    • FCA-205349: Improve session timeout experience.
    • ARES-25410: App Config missing for Epic Rover after re-publishing the app.
    • AAPP-15907: iOS DDUI SSO extension profile (credential shown for generic type) XML does not contain additional settings fields.
    • https://docs.vmware.com/en/VMware-Workspace-ONE-UEM/2302/rn/vmware-workspace-one-uem-2302-release-notes/index.html#Resolved%20Issues
    • Last Update: CW22

 

 

 

 

 

Comments