Release Updates Week 44-24:
- We’ve added report templates for the Software Asset Management (SAM) feature.
- Product Specific templates: See usage for multiple applications within a suite (like in Adobe or Microsoft). Use these templates to help view the overall strategy for managing apps within a suite of tools.
- Inactive App templates: See all apps with no activity within a time period across your app environment.
- Mapped and Unmapped templates: View Software Application Catalog apps that are mapped or not mapped to the SAM solution. You can work with your Omnissa representative and account team to update mapping as needed.
- SAM is in limited availability.
- Find these templates in the Marketplace in Intelligence at Marketplace > Templates > Reports.
- We’ve added Product Last Foreground data to the SAM feature to help with identifying if a device has used an application within a specific time period, up to 120 days, regardless of version.
- We’ve enhanced the joining of data for Product Catalog, App Activity, and Workspace ONE UEM in the App Activity report that now supports adding filters and columns from all three data sources.
Workspace ONE Intelligent Hub 24.04.12 : ARM Release and Patch 7 for Windows
- Bug Fixes Only
Resolved Issues
- HUBW-16700 - Reboot notification toast is coming up for the same app after Reboot
- HUBW-16698 - Hub UI Crash - AppCenter - COMException: The group or resource is not in the correct state to perform the requested operation.
- HUBW-16654 - Show apps in activity monitor even if Hide notification is set to true
- HUBW-16444 - Stop refreshing content manifest expired URL on AppNotAssigned error
- HUBW-16387 - Removing wrong API calls for Application metadata
- FS-6422 - Fixed an issue where if a workflow fails but the step status isn’t marked as failed, the workflow is never retried
- FS-6371 - Fixed an issue where workflows is unable to restart when needed due to changes made to an in progress workflow
- FS-5648 - Fixed an issue where workflow was creating duplicate events
- AMST-42396 Update order of execution for resource types in action orchestrator
Workspace ONE Boxer 24.10 for Android - staged
- What's New
- Contact cache control
- This feature allows users and admins to turn off contact suggestions when composing emails while maintaining access to mailbox contacts and the GAL, improving security and reducing the risk of sending emails to the wrong recipients.
- An application-level Boolean KVP DisableContactCache is available. Its default value is FALSE. If set to TRUE, contact cache is disabled, but users can still search the mailbox and GAL.
- A toggle for "Enable Contact Suggestions" is available in the user settings under the "Email" section.
- If the KVP is set via the console, the user-configurable option in the app is disabled.
- Quality improvements and crash fixes
- Bugs Fixed
- BINXA-20355[Calendar] Organizers of an event cannot be emailed when they are not present in the GAL
- BINXA-20357[Attachments] Cannot add attachment with Attachment New UI enabled on unmanaged account
- BINXA-20435[Calendar] Cancelation of an occurrence cancels the whole series of the event
Current Omnissa Security Advisories
>>> No new Security Advisories this week <<<
Find latest advisories in the Omnissa Security Response Center
Omnissa UX Research Opportunities:
- Our goal is to gather insight into user behaviors, motivations, and goals, so we can use those insights to inform and strengthen product and design decisions.
- Interested in giving your opinion and making your voice heard? Check out what’s available!
Workspace One UEM – Windows Server Management (NEW FEATURE)
- About: WS1 UEM is expanding into Windows Server Management, and wants to better understand what features could supercharge your operations - from enhanced security measures to intuitive dashboards that provide real-time insights.
- Opportunity: 5-minute survey with drag and drop activity. This won't require talking or typing, just multiple choice, AND you can do this in your own time.
- ACTIVITY HERE
Horizon Console – Refresh + Roadmap
- About: Research, Design and Product are developing improvement plans to the Horizon console, and want Admins to be a part of the roadmap and future vision.
- Opportunity: Variety of interactive group workshops and 1x1 conversations via Zoom. You’ll receive Omnissa swag upon completing the interviews.
- SIGN UP HERE.
Managed Service Provider – Enhancements + Customization
- About: Research, Design and Product want to better understand areas of improvement and needs specifically of MSPs.
- Opportunity: Variety of interactive group workshops and 1x1 conversations via Zoom. You’ll receive Omnissa swag upon completing the interviews.
- SIGN UP HERE.
Workspace One Intelligence - AI and Playbooks (NEW FEATURE)
- About: To understand expectations and concerns with using AI in the Playbooks feature, and how much you’d trust it.
- Opportunity: Variety of interactive group workshops and 1x1 conversations via Zoom. You’ll receive Omnissa swag upon completing the interview.
- SIGN UP HERE.
KB Highlights & Announcements Week 44-24:
Hub Web app behavior may change due to Default Access Policy enforcement (6000376)
- The Hub Web application now enforces the default Workspace ONE Access policy, addressing a potential security vulnerability that previously allowed unauthorized access to the Hub Services catalog. The screenshot below highlights where the Default Policy can be viewed and edited within the Access console.
- This update ensures Hub Web fully adheres to the Access policies, enhancing security. Users may notice some behavioral changes in Hub Web as a result. Here are two example scenarios illustrating these updates:
Horizon CloudPod failed to join due to Server Unreachable error (6000370)
- When you attempt to join a Horizon cluster to another or to an existing CloudPod instance, you receive the error below.
- To determine the error, open adsi edit on the connection server you are currently on and connect to the local adam database.
- Navigate to OU=Properties>OU=LMV>OU=Global>CN=Common and double-click on cn=common. Scroll down to pae-linkedmodelasterror.
This is where it should state SERVER_UNREACHABLE
VDI Windows logon message – “Please wait for the VMware DEM Service” (6000215)
- When logging into your Windows VDI you are presented with the following logon message for an extended period of time.
- The purpose of this document is to define the reason for this message and how to investigate the issue.
- This message can appear for a variety of reasons which require interrogation of the logs to determine the issue.
- DEM waits for Windows services like the Windows Profile Service and the Windows Group Policy Service to complete their functions.
- The Session Collaboration feature is disabled starting with version 24.08, and it will reach its End of Life in version 25.01 of Assist. This decision is due to the minimal usage of the feature and the significant overhead required to maintain it.
Customer Impact:
Starting in version 24.08, customers will no longer have access to this feature. Console users with roles that previously included the session collaboration option will no longer see it in the Assist console, nor will they be able to invite guests to ongoing active sessions.
We recommend planning accordingly as the feature will be fully retired by version 25.01.
Workspace One Assist - System Prompts on macOS 15 (6000378)
- This article outlines the system prompts that end users may encounter when starting an Assist session on macOS 15 devices.
Details:
- Screen Capture: Users will see a "Window Picker" system prompt, even if the necessary permissions have been pre-configured through profiles. Selecting "Allow for One Month" means users will receive another prompt requesting permission for Assist when starting a session after the one-month period expires.
Screen Sharing Issue in Assist Sessions on Firefox Version 131.xx.x and Above (6000382)
- Grey screen when initiating an Assist screen share session on Firefox version 131.xx.x or higher.
- The team is actively investigating and working on a solution. This KB article will be updated as soon as a fix is available.
- When organizations assign public applications to Android devices through the Workspace ONE UEM Console, Workspace ONE UEM:
- If the assignment type is Automatic, installs the application on the device
- Adds the application to the home page of the Play Store application on the device
- If the administrator assigns Application Configuration to the device, pushes said configuration to the application
Applications, like other resources in Workspace ONE UEM, are assigned to devices via Assignment Groups. When devices leave an Assignment Group and/or join a new Assignment Group, the resources (profiles, apps, etc.) assigned to a device may change. Organizations can normally expect Workspace ONE UEM to install and/or remove resources for the device to reflect these changes. For example, if an Assignment Group has filters to only include devices on Android 15, devices would join the group once they upgrade to Android 15. If profiles, apps, and other resources were assigned to this Assignment Group, Workspace ONE UEM would install them on this device.
Horizon Connection Server reporting Radius failed login attempts from unknown users (6000383)
- In the Application events log of the Horizon Connection server Admin Console, you see failed Radius login attempts from users that you do not recognize.
- This is also evident in the Windows event application log on the Connection Server.
Changes in Certificate Management in UEM for Microsoft KB5014754 (6000384)
- Microsoft released Windows Server updates in May 2022 to address the elevation of privilege vulnerabilities. After the update, the certificates for a user or computer object must be strongly mapped to their Active Directory object for certificate authentication to work. To ensure that Workspace ONE UEM maintains the highest security posture and that there are no interruptions once full enforcement is enabled, you should review the certificate templates used for generating the certificates used in Cert-based authentication.
- This KB intends to inform UEM customers how to manage the updates released via KB5014754.
UI issues observed in UEM Admin Console (6000385)
- Page load errors have been observed in older versions of the UEM console where in-product support is enabled.
- The in-product support feature is dependent on an API which has been deprecated. This is resulting in page load errors on the console.
- Users may experience login issues with Omnissa Access when using Apple MobileSSO on iOS 18.X. Additionally, for Certificate (Cloud Deployment) on macOS 15.X, there is a noticeable delay in displaying the certificate picker.
- A delay in certificate display is observed with Mobile SSO (for Apple) on iOS 18.X and Certificate (Cloud Deployment) on both iOS 18.X and macOS 15.X. The Apple MobileSSO extension includes a timeout setting for the SafariViewController (SVC) panel. If the SVC panel exceeds this timeout while loading the certificate picker, the extension dismisses the SVC panel prematurely, preventing certificate selection and resulting in authentication failure.
Upcoming Workspace ONE UEM AWS(Amazon Web Services) Datacenter migrations (6000144)
- Continuing Omnissa’s responsibility to provide better service to customers, the Workspace ONE Team has made the strategic decision to migrate our cloud infrastructure to the AWS(Amazon Web Services) platform. By making this change, the Workspace ONE Team will be able to leverage additional automation features and infrastructure efficiencies to provide a higher level of service and resiliency to customers, including:
- Shorter upgrade and maintenance windows
- Improved scaling and monitoring
- Increased service availability/resiliency and security
- When will customers be migrated to the AWS datacenter?
Environment migrations will commence by the end of October, 2024. The migrations are tentatively scheduled as below:
- UAT environments - 2024
- Production environments - 2025
Recent Apple OS Updates - Changes in the Enterprise
- Apple updates iOS, iPadOS, macOS, visionOS, tvOS and watchOS iOS 18.1, iPadOS 18.1, iOS 17.7.1, iPadOS 17.7.1, macOS 15.1, macOS 14.7.1, macOS 13.7.1, visionOS 2.1, tvOS 18.1, watchOS 11.1
- What's new for enterprise in iOS 18
- About iOS 18 Updates
- What’s new in iOS 18
- What's new for enterprise in iPadOS 18
- About iPadOS 18 Updates
- What’s new in iPadOS 18
- What's new for enterprise in macOS Sequoia
- What's new in the updates for macOS Sequoia
- What's new for enterprise in macOS Sonoma
- What's new in the updates for macOS Sonoma
- What’s new for enterprise in visionOS 2
- About visionOS 2 Updates
- About Apple TV 4K and Apple TV HD software updates
- About watchOS 11 Updates
- Apple Platform Certifications
- Apple security releases
- Private Cloud Compute Security Guide
High Priority KBs:
- Omnissa new world link directory
For an overview about links to customer portals and relevant information follow the above link. - Workspace ONE UEM – Modern SaaS Architecture Rollout (6000206)
Workspace ONE UEM has undergone a complete re-architecture to modernize the platform using microservices and containers to enable increased scalability and performance and increase the rate of innovation. Now after having conducted significant and careful testing, these architecture updates, including the new Modern Stack, will be deployed to UEM SaaS environments over the next several months. Also review: Introducing Workspace ONE (WS1) UEM Next-Gen SaaS. - System Migration Changes Impacting Workspace ONE and Horizon Customers (97841)
The end-user computing (EUC) division of Broadcom will transition from VMware-hosted systems to EUC-hosted systems in April and May 2024. This transition is part of our preparation to become a standalone entity following the pending acquisition of EUC by KKR. - End of Life Announcement for the Legacy App Catalog in Workspace ONE UEM for SaaS UEM Customers (95774)
We are announcing the End of Life (EOL) for the UEM Legacy Catalog for UEM SaaS customers only at this time. If you are a On-Premises UEM Customer, this notice does not impact you at this time, further communications will follow for timelines on migrating On-Premises UEM Customers to the Intelligent Hub App Catalog.
Recently updated or added KBs (Links)
- Upcoming Workspace ONE UEM AWS(Amazon Web Services) Datacenter migrations (6000144)
- Unified Access Gateway(UAG):Lifecycle support policy for Omnisaa Unified Access Gateway (2147313)
- Purging old data from the Horizon Events Database (2150309)
- Problems with Mobile SSO (for Apple) on iOS 18.X and Certificate (Cloud Deployment) on iOS 18.X and macOS 15.X (6000361)
- Changes in Certificate Management in UEM for Microsoft KB5014754 (6000384)
- UI issues observed in UEM Admin Console (6000385)
- Microsoft .NET Support for Horizon (6000360)
- Horizon Connection Server reporting Radius failed login attempts from unknown users (6000383)
- [AGGL-10959] Play Store Home and Application Configuration not updated on Smart Group membership changes (6000380)
- Screen Sharing Issue in Assist Sessions on Firefox Version 131.xx.x and Above (6000382)
- Workspace One Assist - System Prompts on macOS 15 (6000378)
- Disablement and End of Life for the Session Collaboration Feature in Omnissa Workspace ONE Assist (6000379)
- VDI Windows logon message – “Please wait for the VMware DEM Service” (6000215)
- Horizon CloudPod failed to join due to Server Unreachable error (6000370)
- Omnissa CloudPod join fails due to replication failure (6000377)
- Hub Web app behavior may change due to Default Access Policy enforcement (6000376)
- Enhanced Horizon Blast Error Codes with Horizon Client 2303 and Later (91013)
- URL Content Redirection agent-to-client not functioning after upgrading Chrome/Edge to version 130 (6000372)
- Introducing IP Limited CDN capabilities in Managed Hosting SaaS Workspace ONE Environments (76872)
- Device with UDID Not Registered for Remote Management Error in when initiating an Assist session (6000371)
- Workspace ONE UEM - Removal of support of specific versions of Windows Server and Microsoft SQL Server for installation (90455)
- How to upgrade and downgrade license keys in Omnissa customer connect portal. (2006974)
- How to invite new users to an account in Customer Connect (2070555)
Digital Workspace Techzone, Blog, Community and YouTube Updates
- What is Workspace ONE Intelligent Hub?
- Omnissa community event recap at EUC World Independence
- Successfully Implement Software Asset Management
- Continuous Access Evaluation through Security Signal Sharing
3rd Party Blog Updates & Industry News
- Dennis de Kok: Recap Omnissa One Amsterdam
- Ivan de Mes: The Unofficial Omnissa Products and Services Visio Stencil
- Apple Business Manager Updates
Beta, Lab and Tech Preview Updates
WS1 Intelligent Hub 24.10 for Android
- Workspace ONE Mobile Threat Defense file access permissions prompt. If needed to detect malicious application files, users will be prompted to grant Intelligent Hub the All Files Access permission.
- The Intelligent Hub Beta menu is no longer accessible by end users. The Beta menu has historically been available in Android Intelligent Hub as an easter egg. This has allowed users to disable and enable feature flags in Hub. To avoid unexpected behavior, access to this menu has been removed in Intelligent Hub.
- Support for Samsung Android 15 devices. This version of Intelligent Hub introduces support for management of Samsung devices on Android 15.
- Prevents non-system personal apps from accessing work notifications. On devices managed using Custom DPC, Android allows any application in the personal profile with the privileged READ_NOTIFICATIONS permission to read the notifications of apps in the Work Profile. With Intelligent Hub 24.10 and onward, an administrator can prevent access to work notifications by non-system applications in the personal profile. To do so, administrators only need to install a Restrictions profile on the device. To explicitly allow non-system personal applications to read work notifications, administrators must now push a Custom Settings profile to enable this.
- Bug Fixes
- AAGNT-200423: Restrictions profile setting that allows personal applications to access work files not working
- AAGNT-200409: Request Device Logs (System) command fails to collect RXLogger output from Zebra devices
WS1 Tunnel for Android
- In this release, we’ve made a few updates containing general quality and performance improvements.
Sign up or LogIn [HERE] to get access to the latest Beta versions.
October Software Releases
System | Component | Release | Announcement | Release Date |
iOS | Hub | 24.08.1 | 30.09.24 | |
Android | Boxer | 24.09 | 01.10.24 | |
Backend | WS1 Intelligence | 24.09.30 | 30.09.24 | |
Android | Hub | 24.09 | GA | |
Android | Content | 24.09 | 15.10.24 | |
iOS | Boxer | 24.10 | 10.10.24 | |
iOS | Content | 24.08.1 | 10.10.24 | |
Windows | Tunnel Win10 | 24.08 | 10.10.24 | |
Backend | WS1 Intelligence | 24.10.07 | 07.10.24 | |
iOS | Web | 24.08 | 04.10.24 | |
iOS | Tunnel | 24.08 | 14.10.24 | |
Android | Zebra MX Service | 6.1 | 11.10.24 | |
Android | Hub | 24.09.1 | 21.10.24 | |
iOS | Tunnel | 24.08.1 | 18.10.24 | |
Backend | WS1 Intelligence | 24.10.21 | 21.10.24 | |
Backend | WS1 Access Cloud | November 2024 | 24.10.24 | |
Backend | Hub Services Cloud | November 2024 | 24.10.24 | |
Android | Boxer | 24.10 | staged | |
Windows | Hub | 24.04.12 | 29.10.24 | |
Backend | WS1 Intelligence | 24.10.28 | 28.10.24 |
Patch & Seed Script Updates Week 44-24
- Seed macOS 13.7.1 (22H221), macOS 14.7.1 (23H222), visionOS : 2.1 (22N581) and iOS 18.0.0 (22A3351)
- Last Update: CW44
Seed Script for latest Device Model Information
- Seed Script to support
- iPhone 16
iPhone 16 Plus
iPhone 16 Pro
iPhone 16 Pro Max
- Last update: CW40
- Patch Level 23.02.0.52
- PPAT-17448 - Tunnel client not reconnecting once the device regains compliance.
- MACOS-4942 - Smart group assignment for the macOS internal app fails to be assigned for a couple of users’ devices.
- CRSVC-51130 - Add code block on the UEM side to block Conditional access configured at any other customer OG if it is already configured for once customer OG within same UEM environment.
- AMST-42076 - Time zone displayed in Scripts tab is different from the Execution logs.
- Last Update: CW38
- Patch Level 23.06.0.41
- MACOS-4815 - macOS device model seeding API implementation.
- CMSVC-18185 - Disable smart group tenancy correction support from UEM production environments.
- ARES-30025 - DDUI - Removing new smart group assignment clears existing smart groups.
- AMST-42069 - Time zone displayed in the Scripts tab is different from the Execution logs.
- AAPP-17951 - Update the VPP notification status sync job to discard the duplicate notifications.
- Last Update: CW38
•Patch level 23.10.0.36
- PPAT-17066 - Improvement to prevent crash of DDUI profile page if tunnel health is down.
- UM-9174 - Unable to switch basic users to AD users through the User Migration tool.
- Last Update: CW41
- Patch Level: 24.2.0.17+18
- 24.2.0.17
- UM-9294 - Attribute sync is failing post upgrade to 2402 console version.
- UM-9173 - Page crashes when trying to load user group list view page.
- UM-9083 - Issue with Directory Admin login after making any changes to the admin role or account.
- UM-9079 - Connections to LDAP/AD needs timeout.
- PPAT-17160 - Update UEM Tunnel Service to .NET 8.
- CRSVC-52975 - Request getting rejected in Boeing with 429 error.
- CRSVC-46583 - Migrate DSM service code to .NET 8.0.
- CMSVC-18231 - Smart group rules are being removed from evaluation flow during device event race condition.
- ARES-30227 - Add logs for adding profile assignment.
- ARES-30171 - Incorrect profile DT page counts of child OGs.
- ARES-29939 - Unable to save Boxer configuration in the UEM console (multiple customers).
- ARES-29837 - Update the version of .Net Referenced by Metadata Transform Service to 8.0.
- AMST-42162 - Seed Windows Hub 24.4.11.0 x86 and ARM64 MSI to the UEM console master.
- 24.2.0.18
- UM-9168 - Scim user API throws error while patching user data if the path is not supported and value is empty or null.
- AGGL-17044 - Highly intermittent failures in Smart Group Reconciliation for Zebra Devices where Make/Model criteria is used.
- UM-9174 - Unable to switch basic users to AD users through the User Migration tool
- PPAT-17066 - Improvement to prevent crash of DDUI profile page if tunnel health is down.
- CMCM-191091 - Duplicate entries returned for new folder resources created on the NFS repositories.
- CMCM-191121 - Content locker application shows foreign folder names and intermittent issues with files missing or displaced.
- ESI-109 - Improve logging for email notification flow.
- Last Update: CW42
- Patch Level: 24.6.0.8
- UM-9174 - Unable to switch basic users to AD users through the User Migration tool.
- UM-9173 - Page crashes when trying to load the user group list view page.
- UM-9168 - Scim user API throws error while patching user data if the path is not supported and the value is empty or null.
- SINST-176422 - Backport .NET 8 compatibility.
- RUGG-13256 - Page crashing while reprocessing the product on devices.
- PPAT-17160 - Update UEM Tunnel Service to Dotnet 8.
- PPAT-17066 - Improvement to prevent crash of DDUI profile page if tunnel health is down.
- FS-6127 - Remove ‘Latest Version’ from drop-down for Internal Apps for iOS and Android.
- FS-5588 - Workflows install retired app version.
- FCA-208533 - Reports are getting queued on the Exports page.
- ESI-274 - Enhance Windows native enrollment flow to use allowlist record during enrollment
- ESI-173 - iOS Hub does not receive silent push notifications related to smart group assignment published changes
- CRSVC-53629 - ABM resources do not get installed upon enrollment.
- CRSVC-52748 - Remove app assignment requirement from LUT token request endpoint.
- CRSVC-50186 - Prevent certificate from changing not in use status for 48 hours.
- CRSVC-48864 - Unable to save the syslog settings with the hostname.
- CRSVC-48401 - Missing logs some required logs in the targeted logging.
- CRSVC-46583 - Migrate DSM service code to .NET 8.0.
- CMCM-191121 - Content locker application shows foreign folder names and intermittent issues with files missing or displaced.
- ARES-30315 - Fails to navigate from Profile edit screen to Assignment screen, when admin locale is Japanese.
- ARES-30283 - MDM AppsV1 API is not returning results for Windows devices.
- ARES-30279 - Icons are not displayed in the App catalog.
- ARES-30276 - Profile migration to RMS failing for Windows Beta profiles.
- ARES-30274 - Icons are not displayed in the App catalog
- ARES-30171 - Incorrect profile DT Ppage counts of child OGs.
- ARES-30118 - For Declarative Asset profiles, in the Assignment Summary and Preview Device page, all platform devices are displayed.
- ARES-29837 - Update the version of .Net referenced by Metadata transform service to 8.0.
- ARES-29746 - Tool tips incorrect for evaluated and installed but not assigned for Apps & Profiles.
- ARES-29653 - MDM AppsV1 API is not returning results for Windows devices.
- ARES-29481 - Device records is removed from the profile DT page, after switching between Evaluated & Pending tab.
- AMST-42330 - Publishing app is queuing app install commands for devices where the same app is already installed and reported in AL and MAL.
- AMST-41960 - Application installation status is not reporting correctly on the UEM.
- AMST-41691 - Prevent auto-reinstallation of on-demand apps when DSM is deactivated.
- AMST-41565 - X-axis in dashboard charts should be sorted by version.
- AMST-41200 - Dashboard not refreshed after OG change.
- AMST-40513 - Dashboard charts are not rescaled when the window is readjusted.
- AMST-40461 - Padding is too large for the data grid.
- AGGL-17562 - Few of the COPE devices are showing the spaceman error for “Apps” page within the Device details view.
- AGGL-17553 - Changes under the Enrollment Restrictions cannot be saved.
- AGGL-17248 - To deploy apps through a new device policy API, update autoupdatepriority value for apps to 0.
- AGGL-17054 - Create MDM Get Device Policy API.
- AAPP-18187 - Remove commands created for profiles during CICO along with remove action from DSM.
- AAPP-18028 - ABM resources donot get installed upon enrollment.
- AAPP-17991 - Remove creation of user profile in case of declarative profiles.
- AAPP-17986 - Add iOS 18 “Passwords” app bundle ID to seed data.
- AAPP-17815 - Custom Command shows Pending under Troubleshooting.
- AAPP-17725 - Implement GET Books Detail API.
Patch level: 24.6.0.9
- CMSVC-18409 - 24.6.0.X - Installer failed to stop AirWatchSmartGroupService.
- Last Update: CW44
Comments
Post a Comment