Upcoming EUC Events
Event | Link and description | Speakers | Date |
Securing Your Digital Workspace: The Essential Role of VMware Workspace ONE Tunnel | Registration link: https://broadcom.zoom. Description: In an era where cybersecurity threats evolve daily, ensuring your digital workspace remains secure against sophisticated attacks is paramount. With recent incidents highlighting the vulnerabilities within traditional VPN solutions, it's clear that a more robust and adaptable approach to remote access security is needed. Discover the Zero Trust Model: Learn how this security model can protect your organization against both external and internal threats by enforcing "never trust, always verify" policies. | Pim van de Vis | 28th of May |
VMware Digital Workspace Virtual Customer Success Roundtable | Next VMware Digital Workspace Virtual Customer Success Roundtable Coming Soon! | ||
VMUG | Watch On-Demand webcasts here. Register for upcoming live webcasts here. Register for Regional VMUG events here. | ||
End User Computing Webinars | Sign up for upcoming webcasts and watch VMware On-Demand webcasts here. |
Release Updates Week 21-24:
Workspace ONE Access & Hub Services May update
Support for Entra ID MFA as additional authentication method
Workspace ONE Access now enables integration with Microsoft Entra ID MFA as an additional authentication method. Users can log in to Workspace ONE Access using their existing authentication methods, and then be prompted for Entra ID MFA without an additional Entra ID login prompt. This feature simplifies the user experience while adding the feature-rich Entra MFA capabilities to Workspace ONE Access authentication.
Workspace ONE Hubservices
Device Enrollment Terms of Use support in Workspace ONE Intelligent Hub
Workspace ONE Intelligent Hub app users can now view and act on updates to the Terms of Use (TOU) for any of their enrolled devices directly within the Intelligent Hub app. Previously, this functionality was only available through the Self-Service Portal (SSP), requiring users to log in separately, often delaying critical actions on TOU updates. By integrating this feature into the Intelligent Hub app, we streamline it into the regular employee workflow, allowing for more immediate responses to TOU updates.
This functionality is currently available on Hub Web and Windows.
Application Terms of Use support in Workspace ONE Intelligent Hub
Users of the Hub native applications (i.e. Hub iOS, Android and Windows) can now view and act on updates to the Terms of Use (TOU) associated with any applications installed on their devices. Previously, Intelligent Hub prompted users for TOU action (acceptance or rejection) only during the initial app installation via the Hub catalog, with no way to address subsequent TOU updates. This new feature enables users to stay updated and respond to TOU changes at any time.
This functionality is currently available on Windows on all Intelligent Hub app versions. For iOS and Android, please refer to the iOS and Android Hub release notes for the Intelligent Hub version which adds support for this feature.
NOTE: This was the last significant parity gap between the Hub Services app catalog and the legacy UEM app catalog, which is already scheduled for end-of-life See KB article 95774
Increase in limit for Employee Self-Service Helpful Links from 10 to 20
Hub Services admins can now configure up to 20 Helpful Links in the Employee Self-Service section of the Hub admin console, doubling the previous limit of 10 links. This increased capacity allows admins (UEM and Horizon) to provide more self-service content, such as knowledge bases (KBs), for end users in the Intelligent Hub Self-Support tab.
You can refer to individual services documentation
- Workspace ONE Identity Services
- Workspace ONE Access
- Workspace ONE Hub Services
Workspace ONE Intelligent Hub 24.04 for Windows x86
- [Hub] - Support for Multi User on Windows Desktops -
- Workspace ONE Intelligent Hub now supports Multi User devices on Modern Stack enabled environments. Workspace ONE will now update the enrollment user based on the logged in Windows User. The UEM console will track each user's log in history in the Shared Devices tab. Admins will also have the ability to pause user reassignment for troubleshooting via the device details page or using a user group restriction in System Settings. For more information on Multi User Support on Windows, please see our documentation on Techzone.
- [Hub] - Dark Mode support within Intelligent Hub
- Workspace ONE Intelligent Hub now supports Dark Mode. You can enable Dark Mode in Hub Services under the Branding Tab.
- [Hub] - Silent Enrollment for Non-AD Environments
- Workspace ONE environments that do not leverage Active Directory (SCIM, OKTA, Other Ldap, etc.) now support silent enrollment. With this enhancement, there is no longer a requirement (for any directory type including AD) to have line of sight to Domain Controller for silent enrollment.
- [Hub] - Notification badge/icon indicator on Intelligent Hub icon in menu bar
- [Hub] - Enhanced Upgrade Experience
- The Intelligent Hub upgrade can now be executed from anywhere on the device. Admins no longer need to run the controlled upgrade process. Admins can simply run the MSI installer and upgrade the agent.
- [Experience Analytics]
- Adds support for battery and its health information for Windows devices
- Adds support for LAN & Internet latency information for Windows devices
- Bug Fixes
Workspace ONE Launcher for Android 24.05
- Dynamic App Availability
We're thrilled to announce the introduction of Dynamic App Availability in our latest release. This configurable feature is designed to enhance user experience by automatically detecting and removing inaccessible applications from the Launcher canvas. Whether an app isn't downloaded or is unavailable in specific geographical locations, Dynamic App Availability ensures a seamless and optimized user experience. - Enhanced Speed Lock
We're excited to unveil the enhanced 'Speed Lock' feature in this update! Now, with our improved Speed Lock functionality, administrators can configure a more versatile exprience for devices on the go. Previously, the feature restricted device use while in motion; now, it intelligently displays essential applications such as maps, ensuring convenience and safety for users navigating while traveling. - Notification Handling Enhancement in Launcher
Launcher now boasts improved notification management, offering a more intuitive experience. Users will notice that multiple notifications are displayed simultaneously, rather than just the latest one. Additionally, clearing notifications will no longer occur automatically if only one notification within a group has been read. - Reporting Blocked Activities in Launcher
We've initiated the reporting of activities blocked by Launcher to UEM. This new functionality empowers administrators to gain detailed insights into all blocked activities on each device. This visibility aids in troubleshooting and facilitates informed decisions regarding the optimal implementation of new applications within Launcher. The UEM functionality is slated to released in a future version (tentatively slated to be part of UEM 24.05) - Bug Fixes
Workspace ONE Boxer 24.04 for iOS
- Screenshot Blocking Improvement
- In the previous Boxer versions the users were advised that their organization does not allow taking screenshots and the admins were alerted but the users were able to take them any way.
- In this version a huge security improvement is made and when the screenshots are restricted in the UEM console by the existing DLP policy, the users won't be able to take any screenshots of the content.
- Support for .zip files preview
- Users can now access and preview the list of content of .zip email attachments directly from their email thread, without the need for external applications.
- If the users want to see the content of a file in the .zip file options for apps supporting this functionality are presented and the user is directly redirected.
- Settings improvements
- Simplification of advanced settings.
- Quality improvements and crash fixes
Workspace ONE Boxer 24.04 for Android
- Support for .msg files preview
- Users can now access and preview .msg email attachments directly from their email thread, without the need for external applications
- Microsoft Conditional Access Authentication improvement on password change
- When the Active Directory password of a user is changed, the user is directly redirected to the Microsoft Authenticator App when he/she taps "Retry Authentication" button.
- Phishing reporting improvement
- When phishing is reported, email is moved to trash instead of being permanently deleted
- Support for Cisco Jabber meeting links
- Cisco Jabber meeting links from calendar events are now directly opened from Boxer in Cisco Jabber app.
- When Cisco Jabber app is not installed on the device the user gets prompted to have it installed from Google Play Store.
- Settings improvements
- Simplification of advanced settings.
- Quality improvements and crash fixes
Workspace ONE SDK 24.04 for iOS
- Bug fixes and Stability improvements.
- Third party library updates.
Workspace ONE Intelligent Hub 24.04 for Android (staged)
- Accessibility improvements in Intelligent Hub
- Support for enabling 3rd-party cookies when authenticating with Workspace ONE Access: In some cases, Intelligent Hub needs to support 3rd-party cookies in order for users to authenticate with Workspace ONE Access. In cases where 3rd-party cookie support is required and this is not enabled, users may see a "cookies not supported" error in Intelligent Hub. See How to Enable 3rd-party Cookies for Workspace ONE Access Authentication in the Beta Resources for more information on how to test this features.
- Intelligent Hub processes pending actions and delivers samples at a more consistent frequency: When an Android device exits Doze Mode, Intelligent Hub will now count the time the device spent in Doze Mode to determine when to next execute certain recurring tasks. Previously, the time a device spent in Doze Mode would not be considered in this calculation, which extended the time between executions of said recurring tasks on devices that frequently entered Doze Mode. These tasks include processing pending actions in Workspace ONE UEM, such as installation of profiles and apps, as well as sending device information to Workspace ONE UEM.
- Higher priority for Tunnel Profile installation: In instances where Intelligent Hub needs to apply multiple resources, it will install Tunnel Profiles before most other resources. This can accelerate setup of Workspace ONE Tunnel during checkout of shared devices, which in turn can allow users to authenticate with applications sooner using Mobile SSO.
- Improvements to Samsung KNOX integration: Intelligent Hub uses a Samsung KNOX License to leverage Samsung-specific Android device management functionality, such as Samsung-only profiles. Intelligent Hub 24.04 improves the resilience of this integration to prevent issues where the KNOX license key is not properly activated.
- Bug Fixes
Workspace ONE Send for Android 24.01.1
- General Improvement
VMware EUC Security Advisories:
VMSA-2024-0011 - VMware ESXi, Workstation, Fusion and vCenter Server updates address multiple security vulnerabilities
- VMSA-2024-0011 - VMware ESXi, Workstation, Fusion and vCenter Server updates address multiple security vulnerabilities (CVE-2024-22273, CVE-2024-22274, CVE-2024-22275)
Please see the advisory here: https://support.broadcom.com/web/ecx/support- content-notification/-/ external/content/ SecurityAdvisories/0/24308
VMSA-2024-0011.1 - VMware ESXi, Workstation, Fusion and vCenter Server updates address multiple security vulnerabilities
- VMSA-2024-0011.1 - VMware ESXi, Workstation, Fusion and vCenter Server updates address multiple security vulnerabilities (CVE-2024-22273, CVE-2024-22274, CVE-2024-22275)
Please see the advisory here: https://support.broadcom.com/web/ecx/support- content-notification/-/ external/content/ SecurityAdvisories/0/24308
EUC UX Research Opportunities:
- Our goal is to gather insight into user behaviors, motivations, and goals, so we can use those insights to inform and strengthen product and design decisions.
- Interested in giving your opinion and making your voice heard? Check out what’s available!
WS1 UEM: File As A Service
- About: FaaS is an approach to manage file and action resources, so Admins can define a set of file-relevant actions to perform on an end-user’s device and then assign to smart groups or leverage in Freestyle. Relevant for Admins managing frontline devices, push internal apps and configuration files, issue security patches, and manage specific files/folders like pushing the zip required for OS upgrade, the delivery route file for a worker delivering packages, and deleting the log files.
- What: Focus Group conversation via Zoom to provide feedback on concept.
- SIGN UP HERE
WS1 UEM: Vulnerability Mgmt. – Remediation
- About: A new feature that allows UEM Admins to view vulnerabilities relevant to their desktop device fleet. It provides recommendations for remediating those threats. Relevant for those involved in overseeing/remediating vulnerabilities like Security/Security Operations or Endpoint Managers.
- What: Focus Group conversation via Zoom to provide feedback on concept.
- SIGN UP HERE
WS1 UEM: Deployment Phases
- About: A new feature that will allow Admins to deploy applications to various user groups and types, mitigating concerns before they affect the remaining user types. Relevant for Admins responsible for deploying applications and managing various platforms, including mobile and desktop devices.
- What: Focus Group conversation via Zoom to provide feedback on concept.
- SIGN UP HERE
KB Highlights & Announcements Week 21-24:
Broadcom (VMware) named a Leader in four 2024 IDC MarketScape assessments for UEM
- As we enter an exciting new chapter, the End-User Computing (EUC) Division of BroadcomⓇ — formerly VMware EUC and soon to be Omnissa — is excited to announce that Broadcom (VMware)* was positioned as a Leader in four recent IDC MarketScape vendor assessments for the unified endpoint management (UEM) market. Click the links below to download excerpts of the reports to see why we believe the IDC MarketScape positioned us as a Leader in all four!
- IDC MarketScape: Worldwide Unified Endpoint Management Software 2024 Vendor Assessment (IDC #US51234224, April 2024) — a Leader for the sixth time!
- IDC MarketScape: Worldwide Unified Endpoint Management Software for Frontline/IoT Devices 2024 Vendor Assessment (IDC #US51779324, April 2024) — a Leader for the sixth time!
- IDC MarketScape: Worldwide Unified Endpoint Management Software for Apple Devices 2024 Vendor Assessment (IDC #US51779224, April 2024) — a Leader for the third time!
- IDC MarketScape: Worldwide Client Endpoint Management Software for Windows Devices 2024 Vendor Assessment (IDC #US51234324, April 2024) — a Leader in the inaugural report!
Setting the record straight: EUC to continue to offer Horizon with vSphere and vSAN
- With the news of the pending divestiture of the End-User Computing (EUC) Division of Broadcom, formerly VMware EUC, both customers and industry pundits are naturally wondering what comes next for our business. One point of speculation is the historical bundling of VMware vSphere and vSAN with the Horizon VDI, DaaS, and published apps offerings. EUC has offered its Term and SaaS editions for years: versions of Horizon that are combined with vSphere and vSAN (depending on the edition) and versions of Horizon that were without vSphere and vSAN.
- KB: VMware Horizon combined offerings with vSphere and vSAN will continue post divestiture (14804)
How to configure the macOS Tunnel MDM Profile for Full-Device Tunnel mode (6000006)
- Starting with the WS1 macOS Tunnel client 24.01, we are excited to introduce Full Device Tunnel mode on MDM enrolled devices.
The following documentation will guide you through the set up of macOS Tunnel MDM Profile for Full Device Tunnel mode.
How to file a Support Request in Customer Connect and via Cloud Services Portal (6000005)
- This article provides steps to file a Support Request in Customer Connect including the steps when filing a Support Request coming from the Cloud Service Portal.
- It helps you troubleshoot the Get Support process in Customer Connect and helps you understand which category to choose when filing a Support Request.
- Note: To file a Technical Support Request, you require a support contract or Pay Per Incident Support. For more information about Pay Per Incident support, see How to Purchase and file Pay Per Incident support for VMware products (2014035). If you have a support contract or Pay Per Incident Support and are facing an issue related to product usage or installation, choose from the Technical dropdown.
EUC Support Phone Numbers (6000004)
- The end-user computing (EUC) division of Broadcom has successfully transition from VMware-hosted systems to EUC-hosted systems in May 2024.
- Workspace ONE and Horizon customers can now raise support request using the new EUC Customer Connect URL. This is the fastest and effective way to get your queries and issues addressed.
EUC Customer Connect URL - https://customerconnect.omnissa.com
In Horizon sessions (Blast, PCoIP) on Windows 11 (RDSH install, Single/Multi session), explorer.exe keeps on crashing and restarting when Time zone redirection is enabled via GPO. (88086)
- When the policy “Allow time zone redirection” is enabled on the guest VM and a horizon client creates a RDSH session using Blast or PCoIP.
- The Explorer process crashes repeatedly. This can be verified with Task Manager.
- Visually, The user may notice that the Guest desktop does not show the taskbar or the Guest desktop display flickers.
System Migration Changes
- Due to Backend System Changes no new KBs published this week. Find the latest KBs now at https://kb.omnissa.com/s/.
- Migration work is still in progress for some functionalities.
- Links to documentation, product notes etc. in the EUC Newsletter will be fixed one after the other over the next weeks.
- Find all latest information, support portals, documentation etc. at:
Service | Old Link | New Link |
CustomerConnect | ||
CSP | ||
Documentation | ||
KB | ||
Techzone | ||
MyLearn | ||
MyWorkspaceONE | ||
Horizon Launcher | ||
Horizon ControlPlane | tbd | |
EUC Beta Portal | tbd | |
Aha! Feature Requests | ||
Status WorkspaceONE | ||
Omnissa PartnerConnect | https://www.vmware.com/ | https://omnissa.my.site.com/ |
High Priority KBs:
- System Migration Changes Impacting Workspace ONE and Horizon Customers (97841)
The end-user computing (EUC) division of Broadcom will transition from VMware-hosted systems to EUC-hosted systems in April and May 2024. This transition is part of our preparation to become a standalone entityfollowing the pending acquisition of EUC by KKR. - End of Life Announcement for the Legacy App Catalog in Workspace ONE UEM for SaaS UEM Customers (95774)
We are announcing the End of Life (EOL) for the UEM Legacy Catalog for UEM SaaS customers only at this time. If you are a On-Premises UEM Customer, this notice does not impact you at this time, further communications will follow for timelines on migrating On-Premises UEM Customers to the Intelligent Hub App Catalog. - Workspace ONE UEM - Updated requirements for on-premise cumulative patches (94706)
The base GA version for current Workspace ONE UEM releases is being revised through updated installers. On-premise customers will need to consume a revised installer for a given major version before any future cumulative patches can be deployed for that major version. These revised installers are required to address compatibility issues with regular cumulative patches. - Introducing Workspace ONE (WS1) UEM Next-Gen SaaS
VMware is excited to announce that the resource management & tracking improvements, the first major feature-based milestone in the Workspace ONE UEM Modernization Journey, is now available for customer testing. These improvements will be enabled in limited testing environments (CN135) starting on Thursday August 24, 2023.
Recently updated or added KBs (Links)
- VMware Horizon combined offerings with vSphere and vSAN will continue post divestiture (14804)
- Index of Customer Connect articles (6000002)
- EUC Support Phone Numbers (6000004)
- How to configure the macOS Tunnel MDM Profile for Full-Device Tunnel mode (6000006)
- How to file a Support Request in Customer Connect and via Cloud Services Portal (6000005)
- In Horizon sessions (Blast, PCoIP) on Windows 11 (RDSH install, Single/Multi session), explorer.exe keeps on crashing and restarting when
- How to configure the macOS Tunnel MDM Profile for Full-Device Tunnel mode (6000006)
Digital Workspace Techzone, Blog and YouTube Updates
- Blocking Unwanted Apps on Managed macOS Devices with Workspace ONE UEM
- Horizon Cloud Service - next-generation Network Ports Diagrams
- Guided Tour: Deliver Windows Apps from the Enterprise App Repository
- Understanding User Sentiment through Surveys
- Enhancing IT Communications with Workspace ONE Intelligence Freestyle Orchestrator Workflows
- Automating Service Desk Ticket Creation with Workspace ONE Intelligence Freestyle Orchestrator
- VMware by Broadcom Product Security: Secure Development Lifecycle and Response
- Setting the record straight: EUC to continue to offer Horizon with vSphere and vSAN
- How Workspace ONE can mitigate Cyber Insurance Premium Requirements
- Guided Tour: BitLocker Profile for Windows Desktops
- Migrating from Mobile SSO (for iOS) to the New Mobile SSO (for Apple) Extension
3rd Party Blog Updates & Industry News
- Cloud-Duo: VMware EUC – a new beginning named Omnissa!
- Android Blog: 3 new ways to use Google AI on Android at work
- Comdivision: Expand Horizon VDI on-premises to Azure with Horizon Cloud Next Gen
Beta, Lab and Tech Preview Updates
Workspace ONE Tunnel 24.05 for Android
- In this release, we’ve made a few updates containing general quality and performance improvements with the following new feature:
- New workflow to allow Tunnel to be exempt from battery optimization.
Workspace ONE Tunnel 24.06 for macOS
- This beta is an update to our modern macOS Tunnel client delivered through the Workspace ONE Resources Portal.
With this beta, we are pleased to introduce support for Per-App Tunnel mode on MDM enrolled devices.
This is in addition to existing support for Full Device Tunnel mode for MDM and Standalone enrollment.
This macOS Tunnel client delivered through the Early Access Community and once GA, through the Workspace ONE Resources Portal, will now support Per-App and Full Device Tunnel mode for MDM enrolled devices and Full Device Tunnel mode for Standalone enrolled devices. - Our legacy macOS Tunnel client delivered through the App Store continues to support Per-App Tunnel mode on MDM enrolled devices
Sign up or LogIn [HERE] to get access to the latest Beta versions.
May Software Releases
System | Component | Release | Announcement | Release Date |
macOS | Hub | 24.04 | 08.05.24 | |
Horizon | Horizon Cloud Service Next Gen | May 06 | 06.05.24 | |
Backend | WS1 Intelligence | 24.05.06 | 06.05.24 | |
Horizon | Experience Management | 24.04 | 02.05.24 | |
Windows | Hub | 23.10.8 | 16.05.24 | |
iOS | Content | 24.04.1 | 16.05.24 | |
Backend | WS1 Intelligence | 24.05.13 | 13.05.24 | |
Android | Hub | 24.04 | staged | |
Android | Boxer | 24.04 | 22.05.24 | |
iOS | SDK | 24.04 | 17.05.24 | |
iOS | Boxer | 24.04 | 20.05.24 | |
Android | Send | 24.01.1 | 22.05.24 | |
Windows | Hub | 24.04 | 22.05.24 | |
Android | Launcher | 24.05 | 23.05.24 |
Patch & Seed Script Updates Week 21-24
- OS Updates Seed Script
- Most recent update: tvOS 17.5.1 (21L580)
- Last Update: CW21
- Seed Script for latest Device Model Information
- Seed Script for latest Device Model Information Seed Script to support new MacBook Air M3 model Mac15,2 models
- https://resources.
workspaceone.com/view/ x8kn6bslt67vwvlgx4ld/en - Last update: CW11
- Workspace ONE UEM 22.12
- Patch Level 22.12.0.45
- UM-8871: Unable to create Admin Groups if "&" is in Distinguished Name
- CMSVC-17802: SmartGroup Backup queue errors from logzio
- https://docs.vmware.com/en/
VMware-Workspace-ONE-UEM/2212/ rn/vmware-workspace-one-uem- 2212-release-notes/index.html# Resolved%20Issues-22.12.0.04% 20Patch%20Resolved%20Issues - Last Update: CW20
- Workspace ONE UEM 23.02
- Patch Level 23.02.0.44
- ARES-28053: Web links report is empty.
- AMST-40945: Increase application installation timeout.
- AMST-40942: Reduce unnecessary calls between WS1 UEM and OEM Provisioning Service.
- https://docs.vmware.com/en/
VMware-Workspace-ONE-UEM/2302/ rn/vmware-workspace-one-uem- 2302-release-notes/index.html# Resolved%20Issues - Last Update: CW15
- Workspace ONE UEM 23.06
- Patch Level 23.06.0.31
- UM-8923 VIS to UEM unlink is not removing the UEM user from the UEM group
- FS-5534 Seed Mac Workflow Host in Canonical - Release 23.06
- ENRL-4265 Notification flow update: Passing HS configured OG UUID instead of tenant UUID
- CRSVC-46415 CellTrust Integration Not Working
- CMSVC-17800 SmartGroup Backup queue errors from logzio
- CMCM-190983 Optimize Sync sproc for user repo creation
- CMCM-190966 Scheduled job using Content_StatusByLocationGroup_
Save is causing DB performance issues. - ARES-28483 WS1-UEM-ARES-Apps-Sync-
Failure-Alert CN1567 - AAPP-17126 Refreshing AppleCare Warrantly information is throwing error "PleaseCheckGSXSettings" for all Apple Devices.
- Last Update: CW21
Workspace ONE UEM 23.10
- Patch Level: 23.10.0.14
- RUGG-12995 [Custom Attribute API] Unable to create a Custom Attribute with double-byte alphanumeric via API.
- MACOS-4449 Add Execution of script to re-install Intelligent Hub Settings profile for already enrolled devices.
- ENRL-4235 Update logging for failure of enrollment restriction check
- CMCM-190990 Remove the command queue to delete content from device during managed content delete
- AMST-41181 Seed Windows Hub 23.10.7 x86 to UEM console 2310
- AAPP-17183 VPP failures while resolving enrollment users
- Last Update: CW19
- Workspace ONE UEM 24.02
- Patch Level: 24.2.0.6
- AGGL-16822: Capability enrichment sample failing post the patch update in environment to update enterprise version.
- AGGL-16827: Android Device delete intermittently takes 4 hours to wipe the device.
- FCA-207587: DLV tooltip for friendly name is broken.
- FCA-207603: Device List view Export is not producing export to download.
- AMST-40616: Device state to capture new status for pause.
- AMST-40654: Pause status to be displayed in List view.
- AMST-41111: Bulk Management settings throwing error.
- FS-5414: Matches Found count is incorrect whenever adding/removing Application Versions/Names in Conditions.
- Last Update: CW18
Comments
Post a Comment