Omnissa EUC Newsletter - Week 34





 

Upcoming EUC Events

Event

Link and description

Speakers

Date

Omnissa ONE

(on-site, Amsterdam)

[REGISTER HERE]

The future of digital work starts here - Join us at Omnissa ONE to gain new insights into improving the digital workspace experience for both IT teams and employees. You'll also have a front row seat to the latest innovations across the Omnissa Platform, including the products you know best, Workspace ONE and Horizon. Secure your complimentary spot and RSVP today.

Various

23./24.10.2024

Omnissa Live

[RECORDING LINK]

Join us in the next step of our journey as we launch Omnissa, formerly VMware’s End User Computing Business. We’re excited to share our plans with you and our global community of customers, partners, and industry experts. Together we are shaping the future of digital work!

Shankar Iyer, Renu Upadhyay, Bharath Rangarajan

23.07.2024

VMUG

Watch On-Demand webcasts here.

Register for upcoming live webcasts here.

Register for Regional VMUG events here.

Release Updates Week 34-24:

Workspace ONE Access

Renewed App Policy Association Interface in Workspace ONE Access

App access policy assignment now has a new UI and improved workflow. The new policy assignment is now independent of policy creation flow, allowing app assignment without editing a policy. New UI lists apps with additional fields, supports multi-selection of apps for assignment, shows policy assignment conflicts, and offers better search and filtering.

New Settings to Grant Omnissa Technical Support Access to Workspace ONE Access

New settings are now available to securely grant the Omnissa technical support team access to the Workspace ONE Access admin console to resolve or debug technical issues. You can now control when to allow Omnissa technical support team access to your Workspace ONE Access admin console and can determine the role and duration of the access. By default, Omnissa support team’s access to your console is turned off.

Enhanced Availability and Faster Launches for Horizon Apps

Horizon connection servers now use a single service provider metadata across all servers in a Horizon pod. This enhancement significantly reduces metadata refresh time, leading to faster app launches and improved overall availability.

This enhancement is available with Workspace ONE Access Cloud, Workspace ONE Access connector 24.07, and Horizon 8.13.

Workspace ONE Access Connector 24.07

Workspace ONE Access connector 24.07 is compatible with Workspace ONE Access Cloud, Workspace ONE Access On-premise 24.07, and Workspace ONE Access for FedRAMP.

Resolved Issues for Connector 24.07

This connector release includes the following resolved issues:

  • HW-200932: Resolved an issue where Active Directory over IWA directory sync was failing with safeguard violations. A configurable option for comparing only attributes for updates during directory sync is now available.
  • HW-200972: Prevent parallel sync if both People Search photo sync and directory sync are configured for the same time.
  • HW-204691: Resolved an issue with directory sync exiting due to communication channel errors. A configurable parameter is available to set the number of hours after which scheduled sync starts automatically if the directory sync service exits due to unexpected communication channel errors.

Workspace ONE Hubservices

Notification Deletion Now Available for Hub Services Admins

The Hub Services admin console now includes the ability for admins to delete previously sent notifications. Admins with super admin role can utilize this feature to remove notifications that were sent in error, contained incorrect information, or were distributed with ill intent. This deletion functionality ensures that admins can quickly and effectively retract messages that should no longer be visible to end-users, thereby maintaining the accuracy and integrity of communication within the platform.

Workspace ONE Intelligent Hub App Now Visible in the Hub Services App Catalog

The Workspace ONE Intelligent Hub app, when assigned through Workspace ONE UEM, will now be displayed in the Hub Services app catalog. Previously, the Intelligent Hub app did not appear in the catalog, limiting visibility to end-users. With this update, users can manually trigger updates to the Hub app, which is especially useful if there are issues with auto-pushed updates.

If admins prefer to revert to the previous behavior where the Hub app is hidden from end-users, they can utilize the Exclude Apps functionality to remove it from view. For more details on that, refer to the documentation topic Selectively Exclude Apps From Users in Intelligent Hub Catalog<https://docs.omnissa.com/bundle/workspace-one-hub-services/page/SelectivelyExcludeAppsFromUsersinWorkspaceONEIntelligentHubCatalog.html >.

Your are notified of these changes through the admin notification bar in the VMware Access console which is displayed when the customer admin logs in.
Workspace ONE Identity Services<https://docs.omnissa.com/bundle/identity-services-release-notes/page/identity-services-release-notes.html >
Workspace ONE Access<https://docs.omnissa.com/bundle/workspace-one-access-release-notes/page/WorkspaceOneAccess-ReleaseNotes.html >
Workspace ONE Hub Services<https://docs.omnissa.com/bundle/workspace-one-hub-services-release-notes/page/WorkspaceOneHubServices-ReleaseNotes.html >
Workspace ONE Access FedRAMP<https://docs.omnissa.com/bundle/workspace-one-access-release-notes-fedramp/page/WorkspaceOneAccess-fedramp-releasenotes.html >

Workspace ONE Access Connector 24.07

Workspace ONE Access 24.07 is a general maintenance release that includes security improvements, connector updates, and other product fixes.

Workspace ONE Content for iOS 24.08

  • Preserve bookmark enhancements in PDF.

Workspace ONE Intelligence 24.08.19

  • We moved the Potential Impact element in workflows.
    • We moved the Potential Impact to the Workflow Settings component in the workflow canvas.
    • Now that it is easier to find, you have a chance to review the Potential Impact details before proceeding to build the rest of your workflow.
    • In addition, we made the Potential Impact panel wider to fit more columns, which reduces the need to horizontally scroll.
  • We’ve changed the Potential Impact behavior in workflows.
    • Upon saving a workflow with Trigger Settings set as Automatic with a one-time manual run, Schedule, or Manual, the system evaluates the Potential Impact.
    • If it detects an excessive target count, it displays a warning message to alert you to revisit the filter because, the filter might be configured incorrectly.
    • You have the option to accept the warning and proceed if you determine the workflow is configured to operate as desired.

Experience Management 2407 for Horizon

  • New Features
    • We’ve added support for Horizon multi-session desktops and applications for App Performance, Application Crash, Application Hang, and Application Usage(Start/Exit/Foreground) telemetry.
    • Use the new GPO (Group Policy Object) Load Time breakdown data for Horizon sessions, which is applicable for both single-session VDI desktops and multi-session published desktops and applications.
    • You can identify whether users installed applications using App Volumes or not with the new App Volumes integration with Experience Management for Horizon.

VMware EUC Security Advisories: 

***No new Security Advisories this week***

Find latest advisories in the Omnissa Security Response Center

EUC UX Research Opportunities: 

  • Our goal is to gather insight into user behaviors, motivations, and goals, so we can use those insights to inform and strengthen product and design decisions.
  • Interested in giving your opinion and making your voice heard? Check out what’s available!

NEW OPPORTUNITIES COMING SOON

KB Highlights & Announcements Week 34-24:

F5 and Omnissa Partner Again on Digital Workspaces

  • F5's newest strategic partner is actually an old friend. F5 and Omnissa, the elegant new name for VMware’s end-user computing (EUC) business, are resuming a successful past relationship to bring customers more scalable and secure virtual desktop infrastructure (VDI) and digital workspace solutions.
  • Following Broadcom's acquisition of VMware, investment firm KKR recognized the potential in VMware’s esteemed EUC unit and invested in its bright future, resulting in the creation of Omnissa as a private entity. This move has paved the way for F5 and Omnissa to rekindle their collaboration, leveraging F5’s industry-leadingapplication delivery services to enhance Omnissa’s VDI and digital workspace offerings with superior network traffic optimization and security.

AGGL-17234 - Lookup values in Android Application Configuration not delivered correctly (6000155)

  • When administrators assign Android public applications through the Workspace ONE UEM Console, they may set lookup values for certain fields in the Application Configuration tab. If lookup values are used in nested fields – in other words, fields that are nested under other fields in the Application Configuration tab – Workspace ONE UEM will fail to resolve the lookup values when the app is pushed to a device. Impacted devices will get Application Configuration that contains the lookup value string instead of the resolved value for that user or device (e.g. “{SerialNumber}” is configured instead of the device’s actual Serial Number).
  • This affects Workspace ONE UEM versions 23.10.0.25 and 23.10.0.26.

PPAT-1156: Low internet speeds when connected through Omnissa Tunnel for Windows (2960281)

  • Omnissa Tunnel 2.0 for Windows
  • Upon creating a VPN profile with per-app VPN configuration and deploying the profile to Windows 10 devices, the internet speed on the configured application (using Omnissa Tunnel) might be consistently low.

Announcing End of Life for Shift-Based Access Control in Workspace ONE (6000150)

  • We are announcing end of life for the Shift-Based Access Control functionality supported by Workspace ONE Intelligent Hub, Hub Services and UEM. This will be effective 31st October 2024.
  • Following this date, the feature will be removed from the foregoing products and will no longer be supported.

Workspace ONE UEM Freestyle Orchestrator Workflow Status Mapping for Windows App Deployment Agent (6000149)

  • As we start work on enriching and enhancing the admin experience with more status and error codes, we’ve made a small improvement to address the visibility of existing statuses and error codes. We’re adding in additional context to provide admins with more clarity on exactly what state the device is in during workflow execution. Please use the following table as a reference.
  • The first column lists out what statuses and error codes exists within SFD, the component that handles app installation on a device. The second column lists out what statuses map to those SFD codes within the server with the third column showing what the admin sees on the UI within Freestyle workflows.

Integration of Hub Services from Workspace ONE UEM leveraging basic credentials will fail (6000147)

  • Administrators may encounter the error "Connection failed with given URL, Username, and Password" when integrating Hub Services with Workspace ONE UEM using basic authentication credentials.

The "Login as Current User" feature will not function as expected when a AllowCustomSSPsAPs GPO is enabled. (95168)

  • Unable to use Login as Current User feature when an AllowCustomSSPsAPs GPO is applied to the agent machine.
  • The "Login as Current User" feature will not function as expected when the AllowCustomSSPsAPs GPO is enabled.

Disclaimer: Omnissa is not responsible for the reliability of any data, opinions, advice or statements made on third-party websites LocalSecurityAuthority Policy CSP - Windows

High Priority KBs: 

Recently updated or added KBs (Links) 

Digital Workspace Techzone, Blog and YouTube Updates 

3rd Party Blog Updates & Industry News 

August Software Releases  

System

Component

Release

Announcement

Release Date

Horizon

Horizon Cloud Service Next Gen

August 1

Release Notes

02.08.24

Backend

WS1 Intelligence

24.08.05

Release Notes

05.08.24

Android

Content SDK 

24.07

06.08.24

Android

Boxer

24.07

Release Notes

06.08.24

Windoews

Hub

23.10.10

Release Notes

07.08.24

Backend

WS1 Access OnPrem

24.07

Release Notes

12.08.24

Backend

WS1 Intelligence

24.08.12

Release Notes

12.08.24

iOS

Hub

24.07

Release Notes

15.08.24

Android

Launcher

24.08

Release Notes

15.08.24

Backend

WS1 Access Connector

24.07

Release Notes

19.08.24

iOS

Content

24.08

Release Notes

20.08.24

Backend

WS1 Intelligence

24.08.19

Release Notes

19.08.24

Horizon

Experience Management

24.07

Release Notes

22.08.24

Patch & Seed Script Updates Week 34-24

OS Updates Seed Script

  • iOS 17.6.1 (21G101), tvOS 17.6.1 (21M80)
  • Last Update: CW34

Seed Script for latest Device Model Information

  • Seed Script to support new iPad Air M2 and iPad Pro M4 models
  • Last update: CW30

 

Workspace ONE UEM 22.12

  • Patch Level 22.12.0.48
  • ARES-29546 - App details view page crashes when clicked on filters.
  • UM-8986 - With Read-only admin we are able to add admin account through batch import.
  • Last Update: CW28

 

Workspace ONE UEM 23.02

  • Patch Level 23.02.0.50
  • AMST-41536 - Redirect blob download request from DS to CDN when a branch is disabled.
  • Last Update: CW32

 

Workspace ONE UEM 23.06

  • Patch Level 23.06.0.38
  • UM-9100 - Editing an Admin account deactivates the account.
  • MACOS-4806 - Smart group assignment for the macOS internal app fails to be assigned for a couple of users devices.
  • AAPP-17841 - Improve ExternallyRedeemedLicense Job.
  • Last Update: CW34

 

Workspace ONE UEM 23.10

  • Patch Level: 23.10.0.29
  • Patch .28
    • AGGL-17248 - To deploy apps through new devicepolicy API, update autoupdatepriority value for apps to 0.
  • Patch .29
    • RUGG-13181  API Search filter does not work for Product Extensive search API call
    • AAPP-17752    Update deviceApplication.VppLicenses_SyncByAdamID to support V2 flow
    • AGGL-17229   Internal apps are removed via Google EMM APIs during CICO with PlayEmmDeprecationForAppPublishFeatureFlag enabled
    • AGGL-17285   Unable to modify and save the iOS app assignments
    • ARES-28911    Unhandled exception on the DS nodes
    • CMSVC-17985 API /tags/{tagId}/devices returning 0 for deviceUUID in response code
    • CRSVC-51126 Add code block on UEM side to block Conditional access configured at any other customer OG if its already configured for once customer OG within same UEM env
    • MACOS-4812 Yaml Changes macOS Hardware Seeding
  • Last Update: CW34

Workspace ONE UEM 24.02

  • Patch Level: 24.2.0.12
    • UM-9060 - Rocket/Spaceman error when trying to cancel pending records in Batch Status page.
    • UM-9042 - Editing an Admin account deactivates it.
    • PPAT-17120 - Tunnel test Connection Failed.
    • MACOS-4362 - Multiple certificates installed on device enrollment in mod enabled environment.
    • MACOS-3910 - Smart group assignment for the macOS internal app fails to be assigned for a couple of users devices. .
    • FS-5811 - Incoherence of devices number related to a specific Smart Group.
    • CRSVC-51417 - Modstack migration status alert not working.
    • CRSVC-50027 - Add Organization Group check to CA flow which sends unenrollment and non compliant for existing lingering devices for Microsoft tenant.
    • CRSVC-50025 - Add code block on UEM side to block Conditional access configured at any other customer OG if its already configured for once customer OG within same UEM environment.
    • ARES-29831 - Clicking on Internal App Name in Resources > Native > Internal Results in Spaceman Error.
    • ARES-29786 - Evaluated device details are getting listed under the Installed but not assigned tab after doing a refresh.
    • ARES-29785 - ‘Export’ from the Installed but not assigned tab in the Profile DT page shows “Something Unexpected Happened”.
    • ARES-29230 - When adding a new version of an app, during the completion criteria when pushing Add, an alert appears saying Leave or Cancel.
    • ARES-29119 - Application_Uuid is missing while running API call.
    • ARES-28503 - Summary tab is reporting incorrect number of installed profiles for macOS platform.
    • ARES-28364 - All system installed apps are getting listed in Managed app tab.
    • ARES-28244 - When we add 2 or more Geo fencing locations to the profile, only 1 Geo location is seen in UI.
    • ARES-27051 - Rule action isn’t reflecting on the autocomplete field type (default).
    • AMST-41872 - Seed Windows Hub 24.4.6.0 x86 Patch3 to UEM console - 2402.
    • AMST-41785 - Application is Getting re-install on click of publish button click in assign popup without doing anything.
    • AGGL-17149 - Android Restrictions JSON Exceeds Memcached Limit.
    • AGGL-17093 - Delete AMAPI Profile Owner enrolled Android device.
    • AAPP-17770 - iOS: Unable to retrieve the email address in “local identifier” for VPN profile.
    • AAPP-17695 - Improve logging on Apple notification API.
    • AAPP-16916 - Refreshing AppleCare Warrantly information is throwing error “PleaseCheckGSXSettings” for all Apple Devices.
    • Last Update: CW34

 

 


Comments