Omnissa EUC Newsletter - Week 30





 

Upcoming EUC Events 

Event

Link and description

Speakers

Date

Omnissa Live

[RECORDING LINK]

Join us in the next step of our journey as we launch Omnissa, formerly VMware’s End User Computing Business. We’re excited to share our plans with you and our global community of customers, partners, and industry experts. Together we are shaping the future of digital work!

Shankar Iyer, Renu Upadhyay, Bharath Rangarajan

23.07.2024

VMUG

Watch On-Demand webcasts here.

Register for upcoming live webcasts here.

Register for Regional VMUG events here.

 

Release Updates Week 30-24:

 Workspace ONE ITSM Connector for ServiceNow 5.5

Username-Based Device Search

  • Removes the dependency on a CMDB. ITOM licenses are no longer needed. A customer who hasn’t implemented a CMDB can also use the ITSM Connector.
  • The Service Desk can look up the devices assigned to the caller. They can select the device to be acted upon and finally take action on the selected device.
  • Allows ITSM Connector to support devices without a serial number (registered and non-managed devices, Android in some cases). Device details can be retrieved and actions taken even for serial number-less devices.
  • The last selected device is stored in the incident.

Support for Enrolled (Non-Managed devices)

  • Enrolled devices, that are not managed by Workspace ONE UEM can now be acted upon through the ITSM Connector. The device actions available are the same as those available in Workspace ONE UEM.

Products

  • Products assigned to a device can now be processed through the ITSM Connector.
  • Assign the Product role: x_vmw_ws1uem.ws1uemprocessproducts to the user or group that will be pushing the Products to a device.

Ticket Data Ingestion

  • ServiceNow tickets can now be exported to Intelligence. Use this feature to track the usage of the ITSM Connector. Once the incidents are imported into Intelligence, dashboards can be created to track various usage metrices.
  • Enable the feature by selecting the Property Workspace ONE Intelligence Analytics.
  • Download Link on ServiceNow

Unified Access Gateway 2406

  • Added support for Horizon Connection Server’s Home Site Redirection feature (associated with Cloud Pod Architecture), which helps to reduce backhaul traffic by redirecting users from a connected site to their designated home site. This traffic to home site is validated by Unified Access Gateway before entering the corporate network. For more information, see Enable Re-authentication in Home Site in the Configure Horizon Settings.
  • Added support for Basic and NTLM authentications in outbound proxy configuration.
  • When deploying on Azure, Unified Access Gateway VM, Virtual Network, Network Security Group (NSG) and public IP address can now be deployed in different Azure resource groups.
  • Improvements to SNMP configuration functionality - allows the retention of SNMP configuration settings for Tunnel even when SNMP is reconfigured with different parameters.
  • HTTP cookies set by Unified Access Gateway will now have SameSite attribute set to Lax.
  • Added support in PowerShell script to enable/disable monitoring of unrecognized sessions using the new field unrecognizedSessionsMonitoringEnabled. See PowerShell deployment parameters.
  • Enhancements to adminreset command line utility. See Recover the Admin using the adminreset Command.

Workspace ONE Tunnel Container

  • The Workspace ONE Tunnel gateway can now be deployed as a Container outside of Unified Access Gateway. See Deploying with Tunnel Container.
  • Update log format from plaintext to JSON, which enables simplified integration with log filtering solutions like Splunk, Elasticsearch, and so on.
  • Improvements to bulk sync retry logic to account for intermittent policy sync failures.
  • Ability to control the OpenSSL signature algorithm for Workspace ONE Tunnel via KVP openssl_signature_algorithms specifies the signature algorithms allowed in handshake between devices and the gateway.
    • Default Value:auto
    • Accepted Values: RSA+SHA256:RSA+SHA384. You may use a colon (:) to separate accepted values.
  • Logging improvements and troubleshooting enhancements.
  • Updates to OS package versions and Java component versions. These updates include OpenSSH version update to remediate a vulnerability CVE-2024-6387.


New Apple Builds Are Now Available

New builds of the following software are now available:

  • iOS & iPadOS 18, Beta 4 (22A5316j) 
  • macOS 15 Sequoia, Beta 4 (24A5298h) 
  • tvOS 18, Beta 4 (22J5324f) 
  • visionOS 2, Beta 4 (22N5286g) 
  • watchOS 11, Beta 4 (22R5318h) 
  • iOS and iPadOS 17.6, RC (21G79) 
  • macOS 14.6 Sonoma, RC (23G80) 
  • tvOS 17.6, RC (21M71) 
  • visionOS 1.3, RC (21O771) 
  • watchOS 10.6, RC (21U577)

VMware Workspace ONE Boxer 24.07 for iOSe

  • Improvements in email subject line prefixes
    • Clear subject line indications of Re: for email replies and Fwd: for email forwards.
    • No repetitions in Re: or Fwd: prefixes for cleaner subject lines

Workspace ONE Hub 24.06 for iOS 

  • EOL Notice - The Legacy Catalog in UEM for SaaS UEM Customers will be EOGS on August 31, 2024, and EOL on October 31, 2024. Please see KB for details.
    If you are using the App Catalog in Intelligent Hub then you are already migrated and no action is needed.
    Note: This EOL notice applies for all platforms (iOS, Android, macOS, Windows)
  • Support for Application Terms of Use (configured by your admin)
  • Resolved Issues
    • HUBI-11310: Icons for Web Apps configured in Access are not showing in the Catalog

Workspace ONE Content for Android 24.07

  • Show file and folder path in search results 

Workspace ONE Hub Services Cloud July 2024

  • Granular Control for Self-Service Actions

Workspace ONE Hub Services admins now have greater flexibility and granular control when configuring actions available through Employee Self-Service (Support tab). Previously, actions were grouped into broad categories of critical and non-critical toggles in the Hub Services admin console, which limited admins to enabling or disabling entire groups of actions rather than specific individual actions. This lack of precision often led to less effective management and control over the available actions for end users.

With the new update, admins can now pick and choose specific actions they want to enable for end users, tailoring the self-service experience to better meet organizational needs and policies. For example, an admin can enable the Change Passcode action for a set of users or devices while keeping the Lock Device action disabled, thereby preventing unnecessary or potentially disruptive actions. This enhanced level of customization allows for more targeted and efficient management, improving both security and user experience by ensuring that only the necessary actions are accessible to end users.

  • Ability to Hide Apps from the App Catalog

The Hub Services admin console now allows admins to selectively hide apps from end users’ view. This feature is particularly useful in scenarios where apps need to be assigned to specific devices, but admins want to manage their visibility in the catalog. By hiding these apps, admins can prevent user actions such as app updates or unintentional interactions, ensuring that app management remains centralized and controlled. This added flexibility allows for better oversight and maintenance, aligning app availability with organizational policies and strategies.

  • User Self-management of FIDO2 Keys

Workspace ONE Intelligent Hub web portal users can now manage their FIDO2 keys, configured in Workspace ONE Access for authentication, directly from the Hub web portal. Previously, only admins managed users’ FIDO keys through the Workspace ONE Access admin console, which created a significant barrier to FIDO2 adoption. This limitation often resulted in end users having to submit support tickets for simple self-management tasks, such as replacing a FIDO2 key and customers had to deal with large volumes of such tickets.

With this enhancement, end users can fully manage their FIDO2 keys independently. They can view all registered keys, register new keys, and delete any previously registered keys. This newfound autonomy not only streamlines the user experience but also reduces the administrative burden, enabling smoother and more efficient authentication management.

  • Support Favorites and Horizon Launch Preferences for Horion Next Gen apps

Workspace ONE Intelligent Hub web users can now mark Horizon Next Gen apps and desktops as favorites, providing them with the convenience of accessing and launching their favorited applications or desktops directly from the Favorites tab. This functionality mirrors the familiar process available for web applications, making it easier for users to organize and quickly find the apps and desktops they use most frequently.

In addition to this, the Hub web portal now supports the existing user preference for launching Horizon apps or desktops, extending this capability to Horizon Next Gen apps as well. Users are given the flexibility to choose whether they want to launch their Horizon Next Gen apps or desktops in a browser or a native client.

  • Support Workspace ONE Content URLs/Deep Links in Hub Helpful links

Hub Services admins can now configure a Workspace ONE Content application URL or deep link as a helpful link in the Support tab, enhancing the usability of the Helpful Links section.

Workspace ONE Access Cloud July 2024

  • Renewed App Policy Association Interface
    Workspace ONE Access SaaS July 2024 release now features a full renewed app access policy assignment UI and workflow. The new policy assignment flow offers administrators with a flexible and intuitive interface for listing and assigning of conditional access policies to applications. This update significantly improves administrative experience in managing and editing app policies, especially in very large environments with several hundreds of SaaS and virtual desktops and applications.

VMware EUC Security Advisories: 

***No new Security Advisories this week***

EUC UX Research Opportunities: 

  • Our goal is to gather insight into user behaviors, motivations, and goals, so we can use those insights to inform and strengthen product and design decisions.
  • Interested in giving your opinion and making your voice heard? Check out what’s available!

Workspace ONE: AI Assistant

  • About: What kind of personality do you envision for a WS1 AI assistant - professional, casual, witty? What kind of tone should it have when communicating with you - formal language, slang, or a mixture based on context?  
  • What: Your choice of either a 45-minute, 1x1 conversation via Zoom or a 20-minute online survey. 
  • SIGN UP HERE

Workspace ONE: Filter Placement

  • About: The placement of filters and where they’re located on the page is getting refreshed.
  • What: Play with a clickable prototype on your own time in Usertesting.com, a user testing tool. It will record your audio and computer screen while you tell us what you think.
  • SIGN UP HERE

KB Highlights & Announcements Week 30-24:

Recovering BitLocker keys for Windows devices impacted by CrowdStrike update (6000067)

  • As part of a recent update to the Crowdstrike Falcon Sensor, Windows machines may experience a bugcheck\blue screen error preventing the Windows operating system from loading.

Crowdstrike official statement on Falcon Update

  • As part of Crowdstrike’s suggested workaround for this issue, devices encrypted using the Workspace ONE Bitlocker profile will require the encryption key to be entered on reboot.
  • Workspace ONE provides a simple, self service option for end users to access their recovery key without having to contact the service desk. The key can be accessed by the end user via the Intelligent Hub on iOS, Android, or via our Self Service Portal.

Files hosted in the my.workspaceone.com resource portal are not displayed on product pages or search results (6000122)

  • An issue has been identified with my.workspaceone.com where resources and installers are not appearing in search results on the page. This problem may lead to missing installers and resources on product pages. Additionally, in certain instances, the Installs and Upgrades as well as the Software tabs are completely absent from the product pages. The files are still available and can be accessed in the portal when using a direct link to the resource.

Workspace ONE SDK for Android availability changes

Omnissa Security Advisories (OMSAs) updated location

  • The location of Omnissa Security Advisories (OMSAs) has changed on July 24, 2024. Security Advisories for Omnissa products are now available at https://www.omnissa.com/omnissa-security-response.
  • With this change, we need to alert you that the list of VMSAs for Omnissa products (Workspace ONE ® & Horizon ® product families) on http://www.vmware.com/security/advisories  is no longer maintained.
  • Notes:At this time our portal is not prepared to enroll customers or send out notifications when an Omnissa Security Advisory is published or modified.

Horizon Cloud Service First-Gen and Next-Gen (Horizon 8 & Azure) URL Endpoint Update (6000056

  • URL Updates Required by August 27th, 2024
    As the end-user computing (EUC) division transitions from Broadcom to a standalone entity, new URL endpoints will be needed for Horizon Cloud Service on Microsoft Azure and Horizon 8 Cloud Connected Environments. These new URL endpoints, referred to as Omnissa URL endpoints, are crucial for the operation and delivery of the service/product and must be added to your list of trusted URLs or allowed access through your firewall from the respective Horizon components deployed within your environment by August 27th, 2024.

Increased Data Consumption when "CaptureDEXData" is enabled in Launcher versions below 24.05 (6000065)

  • Significant increase in data consumption after enabling advanced mobile telemetry (via "CaptureDEXData":true custom SDK setting) in Launcher versions release before 24.05.
  • Please do not enable advanced mobile telemetry (the CaptureDEXData custom SDK setting) in Launcher versions below 24.05

Issue with DEM FTA and Default Browser settings post applying Feb24/March24 Monthly windows patches(KB5035845) (97169)

  • The Microsoft Windows Updates for February 2024 and later break the roaming of a user's default browser and .pdf file type association in VMware Dynamic Environment Manager. The roaming of other file-type associations and protocols is not affected.
    The DEM log file shows the following error messages:
    [ERROR] Error 5 deleting sub key for default application file type associations item '.pdf'
    [ERROR] Error 5 deleting sub key for default application protocols item 'http'
    [ERROR] Error 5 deleting sub key for default application protocols item 'https'
  • The user's default web browser and .pdf file type association are reset to defaults.

Horizon 8 on Amazon WorkSpaces Core fails to delete desktop pool (6000120)

  • When an AWS pool is selected for deletion, and “Delete VMs from disk” is selected, you may receive an error message banner rather than confirmation of the deletion under the following conditions:
  • If the pool for which the pool provisioning is disabled during the Add pool flow or the pool is deleted prior to a machine creation in AWS.
  • In general, if there are no machines associated to a desktop pool and pool is opted for deletion in the disk, the pool deletion fails.

Known issue with the Last Seen and App Sample Last Seen fields in Dashboard Widget (6000121)

  • The Last Seen and App Sample Last Seen fields in Dashboard Widget are not updating properly for UEM data entities that are not Devices. For example, if you picked UEM->Apps in Dashboard Widget, the Last Seen or App Sample Last Seen field may give you the wrong data. Note: The Last Seen and App Sample Last Seen fields in Report work properly and give the right data.

List of Public Portal URLs after VMware EUC transition

Service

Old Link

New Link

CustomerConnect

customerconnect.vmware.com

customerconnect.omnissa.com

CSP

cloud.vmware.com

connect.omnissa.com

Documentation

docs.vmware.com

docs.omnissa.com

KB

kb.vmware.com

kb.omnissa.com

Techzone

techzone.vmware.com

techzone.omnissa.com

MyLearn

mylearn.vmware.com

learning.omnissa.com/learn

MyWorkspaceONE

my.workspaceone.com

my.workspaceone.com

Horizon Launcher

launch.vmware.com

launch-horizon.omnissa.com

Horizon Cloud

*.horizon.vmware.com

*.horizon.omnissa.com

*.vmwarehorizon.com

*.omnissahorizon.com

softwareupdate.vmware.com

softwareupdate.omnissa.com

EUC Beta Portal

beta-ea.vmware.com/

beta.omnissa.com

Aha! Feature Requests

wsone.ideas.aha.io

wsone.ideas.aha.io

Status WorkspaceONE

status.workspaceone.com/

status.workspaceone.com/

Omnissa PartnerConnect

vmware.com/partners/work-with-vmware/partner-connect.html

omnissa.my.site.com/partnerconnect

Product Lifecycle Matrix

lifecycle.vmware.com/

docs.omnissa.com/bundle/Product-Lifecycle-Matrix/page/lifecyclematrix.html

Omnissa Community Forum

 

community.omnissa.com/

Developer Portal

developer.vmware.com

developer.omnissa.com

ConfigMax

  • Recommended configuration limits for VMware products

 

configmax.omnissa.com

Interoperability Matrix

interopmatrix.vmware.com

interopmatrix.omnissa.com/Interoperability

Omnissa Security Advisories

vmware.com/security/advisories

omnissa.com/omnissa-security-response

High Priority KBs: 

Recently updated or added KBs (Links) 

Digital Workspace Techzone, Blog and YouTube Updates 

3rd Party Blog Updates & Industry News 

Beta, Lab and Tech Preview Updates 

Workspace ONE Intelligent Hub 24.07 for iOS

What's New:

  • New SDK to fix issues with iOS 18 compatibility.

Bugs Fixed:

  • Miscellaneous bug fixes

Workspace ONE PIV-D Manager 24.07 for iOS

  • Thales by ID Prime Virtual is now available
  • Bug Fixes and stability improvements

Workspace ONE PIV-D Manager 24.07 for Android

  • Thales by ID Prime Virtual is now available
  • Bug Fixes and stability improvements

Workspace ONE Web 24.08 for iOS

  • BRW-175272: Ability to view site cache and cookies storage
  • IBRW-175677: Allow users to clear history based on time range
  • IBRW-175819: Obfuscate screenshots taken from SDK app if screenshots are disabled in DLP

Workspace ONE Web 24.08 for Android

  • ABRW-175740: Allow users to clear history based on time range
  • ABRW-176035: Auto file deletion of downloaded files for Web in Kiosk modes via kill & relaunch

Bugs Fixed:

  • ABRW-176040: Personal Bookmarks disappear after killing and relaunching the Android Web

Workspace ONE Tunnel 24.08 for Android

  • Version specific information will be available on the project upon the launch.

Workspace ONE Intelligent Hub 24.07 for iOS (upcomig)

  • New SDK to fix issues with iOS 18 compatibility.
  • Bugs Fixed:
    • Miscellaneous bug fixes

Omnissa Horizon Clients 2406

Android:

  • The on-screen keyboard automatically displays and the desktop view automatically scrolls to show the caret position in the text field in more Windows applications
  • The suggestion bar on the on-screen keyboard is automatically hidden when typing in the password field.

Windows

  • Client UI update, adding folder feature, which provides standard folder experience to organize user’s desktops and published application, it also can remember and keep the folder settings/configuration across various platforms.

macOS:

  • Support FIDO 2 webauth

ChromeOS:

  • This release has been tested and validated on ChromeOS 125.
  • Support for forwarding multiple audio output and input devices, allowing end users to select devices within the virtual environment.

Linux:

  • Support Ubuntu 24.04

Sign up or LogIn [HERE] to get access to the latest Beta versions.

July Software Releases  

System

Component

Release

Announcement

Release Date

Backend

WS1 Intelligence

24.07.01

Release Notes

01.07.24

Windows

Hub

23.10.9

Release Notes

03.07.24

Android

XR Hub

24.06

Release Notes

04.07.24

iOS

Send

24.07

Release Notes

09.07.24

Android

Hub

24.06

Release Notes

19.07.24

Windows

Hub

24.04.4

Release Notes

12.07.24

ChromeOS

Tunnel

24.05

Release Notes

15.07.24

Android

Content

24.07

Release Notes

22.07.24

Backend

WS1 Intelligence

24.07.15

Release Notes

15.07.24

Horizon

Horizon Cloud Service Next Gen

July 11

Release Notes

12.07.24

iOS

Hub

24.06

Release Notes

22.07.24

Backend

Hub Services Cloud

July 2024

Release Notes

23.07.24

Backend

WS1 Access Cloud

July 2024

Release Notes

23.07.24

Backend

ITSM Connector for ServiceNow

5.5

Release Notes

23.07.24

iOS

Boxer

24.07

Release Notes

24.07.24

Backend

UAG

2406

Release Notes

25.07.24

Backend

Tunnel Container

23.12

Release Notes

25.07.24

Patch & Seed Script Updates Week 30-24

OS Updates Seed Script

  • Most recent update: Android 15
  • Last Update: CW24

Seed Script for latest Device Model Information

  • Seed Script for latest Device Model Information Seed Script to support new MacBook Air M3 model Mac15,2 models
  • Last update: CW11

 

Workspace ONE UEM 22.12

  • Patch Level 22.12.0.48
  • ARES-29546 - App details view page crashes when clicked on filters.
  • UM-8986 - With Read-only admin we are able to add admin account through batch import.
  • Last Update: CW28

 

Workspace ONE UEM 23.02

  • Patch Level 23.02.0.47
  • CMCM-190982: Optimize user repository creation during content sync.
  • CMCM-190965: Fixed content dashboard outdated data issue.
  • Last Update: CW26

 

Workspace ONE UEM 23.06

  • Patch Level 23.06.0.36
  • PPAT-16486 - Cascade front-end root certificate is missing the VPN configuration.
  • FCA-207967 - EULA page crashing for CD environments.
  • AMST-41357 - Device in WNS renewal loop causing DM profiles failure.
  • Last Update: CW30

 

Workspace ONE UEM 23.10

  • Patch Level: 23.10.0.23
  • CRSVC-48609 - Device wipe log report showing no entries.
  • AMST-41589 - Seeded latest SFD 23.10.2 build to UEM release 2310.
  • AAPP-17212 - iOS Restrictions profile Hide or Show apps list is blank.
  • AMST-41558 - Seeded Windows Hub 23.10.9 x86 to UEM console 2310.
  • Last Update: CW28

Workspace ONE UEM 24.02

  • Patch Level: 24.2.0.10
    • UM-8917 - VIS to UEM unlink is not removing the UEM user from the UEM group.
    • UM-8864 - “Invalid Data Entered” when editing and saving Admin account - Phone Number value.
    • PPAT-16819 - Tunnel Console - Add KVP to make page size to 500 in tunnel configuration export.
    • PPAT-16700 - Memory usage issue observed in the tunnel mappers.
    • MACOS-4008 - Add execution of script, to reinstall Intelligent Hub settings profile for already enrolled devices.
    • FS-5628 - Seed Mac workflow host in canonical - Master -> - “Seed Mac workflow host in 2402”.
    • FCA-207737 - Physical memory values were missing in UEM devices or search API call.
    • FCA-207373 - Home and Page Save icons are missing from the device list view page.
    • ENRL-4095 - Update logging for failure of enrollment restriction check.
    • CRSVC-48390 - Enhance mod stack API status endpoint details for migration and alerts
    • CRSVC-47979 - Remove DST cleanup job limit for single execution.
    • CRSVC-47365 - Event log in user details view does not show any event data though it is shown under the devices Troubleshooting tab.
    • CRSVC-45834 - Workspace ONE device-based compliance policy was not automatically evaluating compliance and actions.
    • CMEM-187032 - Improvements for MEM APIs.
    • CMCM-191000 - Intelligence report saw discrepancies with specific filters and columns for the category of Device Content.
    • CMCM-190997 - Content dashboard most or least viewed files section is empty. 
    • CMCM-190986 - Remove the command queue to delete content from the device during managed content delete.
    • CMCM-190959 - Optimize user repository creation during content synchronization. 
    • ARES-29500 - On Profiles DT page- The Device List grid was not populating data for selected tabs.
    • ARES-29262 - Units in cache or server bytes charts was not displayed in Peer distribution. 
    • ARES-29131 - ELS validation on the Device Details > Apps > App Details page.
    • ARES-29114 - Organization group name is coming as blank in DT page exports.
    • ARES-29068 - Getting two different UIs for the app assignment restrictions page.
    • ARES-28333 - Animation on Header section and scroll transition to be smooth.
    • AMST-40778 - Proxy settings not included in Windows profile XML file if configured in Wi-Fi payload.
    • AGGL-16966 - Unable to publish public app with SG having devices.
    • AGGL-13363 - Application configuration shows disabled after publishing an app.
    • AAPP-17255 - Issue placing iOS WebClip on Home Screen first page
    • AAPP-17051 - VPP failures for asset management due to duplicate assets in request to V2 endpoints. 
    • AAPP-16964 - Refreshing sToken for a VPP v2 enabled OG, resets migration flag.
    • ARES-26037 - Internal app icon was broken in the deployment tracking page.
    • Last Update: CW28

Comments