Omnissa Newsletter - Week 7




 

 

 

Upcoming Omnissa Events


Release Updates: 

Workspace ONE Intelligent Hub 25.01 for Android

  • Improvements to Intelligent Hub notifications in Android notification drawer.
  • Default Samsung KNOX License Key now supports premium features.
  • Improvements to the Enrollment Terms of Use
  • HUB-11504 - Android devices are not adding web links to homescreen automatically
  • AAGNT-200603 - When a product is re-pushed, Intelligent Hub re-downloads apps that are already installed

 

Workspace ONE Intelligent Hub 24.11 for macOS

  • With this release, Intelligent Hub for macOS has a new application Bundle ID to reflect Omnissa branding. Other features in this release include,
    • Enhanced Hub logs - Workflow logs are included in Hub logs, a new log end point is implemented for increased logs limit and package URL printed by Hub logs are now masked.
    • Improved Sensor reporting - You can now report the Sensor values for scheduled event ensuring the samples are sent to UEM as and when the periodic Sensors execute.

 

Workspace ONE Intelligence SDK 25.1.0 for Android

  • Daily App Usage and Performance metrics for all apps on the device (usage, battery consumption, data consumption). Requires query all packages and usage access permissions to be granted.
  • Device Language is now sent with device events to better understand how to communicate with a user who may have a different preferred language than the region their device is located.

 

Workspace ONE Assist for MacOS 24.11.1

This release includes backward compatibility support, with no new features added.

 

Workspace ONE Assist for Android 24.11.1

This release includes backward compatibility support, with no new features added.

 

Workspace ONE UEM 2410

Admin Experience

Intuitive page navigation for Workspace ONE UEM
Explore our new page navigation for Workspace ONE UEM. Similar functions are now categorized together in sub-menus, with updated labels. For more information, see the KB article.

Revamped UEM API Explorer page includes comprehensive API metadata and search features
We’ve built a new API Explorer to provide enhanced security, improved search functionality, and reduce page load times.

Overcome random MAC address challenges with Cisco Identity Services Engine (ISE) 3.1+ integration
The Workspace ONE UEM and Cisco Identity Services Engine (ISE) 3.1+ integration is now available to everyone. This allows end users’ devices to connect securely to network resources, even when they use randomized MAC addresses. For more information and integration instructions, refer to the Tech Zone article Integrating Workspace ONE UEM and Cisco ISE v3.1 and beyond.

Troubleshoot large device log files easily
You can now collect and access large device logs more efficiently. The previous process involved uploading multiple files from Workspace ONE Hub to UEM, requiring administrators to download and merge numerous separate files, which was time-consuming for troubleshooting large log files. Device logs are now uploaded and automatically merged into a single file (up to 200MB), reducing the effort and time needed to troubleshoot devices. This feature is supported only for Android and Windows platforms, starting from 2408 release of the Android and 2410 release for Windows Hub clients.

Modern SaaS Architecture is now available for MSP Partners
We are excited to extend the rollout of the Modern SaaS Architecture to Managed Service Provider (MSP) partner environments, which will be introduced to your environments in the coming months. With this rollout, MSP partner environments can leverage the next-generation Workspace ONE features that enhance performance, scalability, and management capabilities, alongside the ongoing support for existing Partner Organization Group use cases.

Omnissa Branding Update
The Workspace ONE UEM console has been updated to align with the new Omnissa brand identity. We have made changes to all the login screens, message templates, URLs, and policy documents to conform to Omnissa standards. We have also replaced old logos, illustrations,and labels with the new Omnissa changes. For more information, see the KB article.

Android Management

Support for Corporate Owned Personally Enabled mode with Android Management API
Organizations can now manage Android devices in Corporate-Owned Personally Enabled (COPE) mode using AMAPI. This mode was previously only supported with Android using the Custom DPC management type. The QR code generation wizard for corporate-owned Android devices has been enhanced to support generation of QR codes for AMAPI. Also, Android profiles for AMAPI feature new payloads and settings to support COPE devices.

This integration will be enabled by phased rollout for Workspace ONE UEM 2410 environments deployed on UEM modern architecture.

Enhancements to Application Management for Android Management API
For devices managed using AMAPI, Workspace ONE UEM introduces multiple enhancements to application management that bring it to parity with Custom DPC Android device management. Administrators can now remotely configure applications using Application Configuration, which in turn enables organizations to deploy OEMConfig applications. A new Application Policy tab has been added to the application assignment flow for Android public apps that supports app-specific policies, such as managing runtime permissions. Finally, the Auto Update Priority setting is now supported for devices managed using AMAPI.

This integration will be enabled by phased rollout for Workspace ONE UEM 2410 environments deployed on UEM modern architecture.

Support for Full-Device VPN with Workspace ONE Tunnel and Android Management API
Workspace ONE Tunnel is now supported on devices managed using AMAPI. Administrators can now configure Workspace ONE Tunnel through the Tunnel and Always-On VPN profile payloads for AMAPI. When assigning public Android applications, administrators can also select a Full-Device VPN profile for AMAPI devices. Support for Per-App Tunnel mode will be added in a future update.

This integration will be enabled by phased rollout for Workspace ONE UEM 2410 environments deployed on UEM modern architecture.

Updates to Android Public Application Management
In recent years, Google has introduced significant updates to the Play Store APIs. Workspace ONE UEM uses to provision public applications to managed Android devices. Workspace ONE UEM now supports these updated APIs. This introduces several behavioral changes that administrators should be aware of. For more information, see the KB article Upcoming Changes to Android Public Applications.

Support for up to two Root Certificates for enterprise WiFi profiles (Custom DPC)
Workspace ONE UEM now supports setting up to two trusted Root Certificates in WiFi profiles for Custom DPC devices. This allows administrators to set two trusted certificate authorities for a WPA2 Enterprise SSID. In turn, this allows organizations to update network servers to use a certificate issued by a new certificate authority without disrupting connected devices.

Freestyle Orchestrator

Freestyle for Mobile – Android and iOS Devices (General Availability)
Our powerful workflow orchestration solution is available for Android and iOS platforms. Create intuitive, conditional workflows using Freestyle’s drag-and-drop UI to sequence the deployment of applications and profiles to your mobile device fleet.

  • Target devices based on Smart Group Membership
  • Leverage device conditions for granular targeting
  • Empower end users with on-demand workflows they can initiate through the Intelligent Hub app
  • Configurable retry behavior
  • Robust deployment tracking at both the workflow level and individual step execution level

Note: To use this feature, your environment must be Modern Stack-enabled. For information regarding the rollout schedule, view KB article.

Enhanced Reporting for Application Deployments within Freestyle Orchestrator
Gain better visibility into application deployment outcomes with improved reporting capabilities for Windows devices. When app deployments are triggered from Freestyle workflows, you’ll now receive detailed status updates, clear failure reasons, and timestamp enrichments. The minimum versions necessary to support this are UEM 2410, HUBW 2410, and SFD 2410.

Export evaluated devices within Freestyle Workflow details
Admins can now export evaluated (In Progress, Completed, Failed, Blocked) devices from within the Workflow Details page. Exporting the device table leverages the export framework within UEM Monitoring, so exported devices can be found there. Mod Stack is required for this feature.

iOS Management

Declarative Device Management

  • Status Channel
    Workspace ONE UEM now supports 9 new status items via Declarative Device Management (DDM). For eligible devices, Workspace ONE UEM will automatically receive these attributes as they change on managed iOS devices.
    • OS Version (iOS 16+)
    • Build Version (iOS 16+)
    • OS Supplemental Build Version (iOS 16.1+)
    • OS Supplemental Build Version Extra (iOS 16.1+)
    • OS Family (iOS 16+)
    • Pending Version (iOS 17+)(Available only in Omnissa Intelligence)
    • Install State (iOS 17+)(Available only in Omnissa Intelligence)
    • Install Reason (iOS 17+)(Available only in Omnissa Intelligence)
    • Failure reason (iOS 17+)(Available only in Omnissa Intelligence)
  • Declarations
    Declarative Configurations now integrate with Apple’s GitHub MDM developer documentation! This integration enables us to implement and update configurations significantly faster. With the help of this integration, Workspace ONE UEM now supports the following new configurations:
    • Math Settings (iOS 18+)
    • Safari: Extension Settings (iOS 18+)
    • Software Update: Settings (iOS 18+)

This integration will be enabled by phased rollout for Workspace ONE UEM 2410 environments deployed on UEM modern architecture. To access Declarative Configurations in the Apple GitHub MDM developer documentation, go to the GitHub Device Management repository.

Application Management
Workspace ONE UEM now collects and displays the Distributor Identifier application attribute on the Device Details > Apps tab. This attribute indicates where an application was downloaded from, whether it be Apple’s App Store or an alternative app marketplace. Alternative app marketplaces are currently only available in the European Union. For more information on alternative app marketplaces, see About alternative app distribution in the European Union.

Profiles
We’ve enhanced the existing RestrictionsVPNSkip Setup AssistantWeb Clip, and Font payloads and added new payloads for ACME Certificate, and Relay payloads.

 

 

 

Current Omnissa Security Advisories 

<<<No New OMSAs this week>>>

Find all latest advisories in the Omnissa Security Response Center

 

Omnissa UX Research Opportunities: 

  • Our goal is to gather insight into user behaviorsmotivations, and goals, so we can use those insights to inform and strengthen product and design decisions.
  • Interested in giving your opinion and making your voice heard? Check out what’s available!

 

KB Highlights & Announcements: 

  • We are shutting down my.workspaceone.com and resources.workspaceone.com on 18-Feb-2025, due to legal compliance requirements.
    All new Omnissa branded product binaries are being made available on customerconnect.omnissa.com . Some product releases are in progress and will be available soon.
    Any customer needing older product binaries can follow the request previous binaries flow, upon which they will receive a link to download older binaries.

 

Preparing for Workspace ONE Modern SaaS Rollout (Managed Hosting / Dedicated Cloud Customers)

 

 

High Priority KBs: 

Recently updated or added KBs (Links) 

Digital Workspace Techzone, Blog, Community and YouTube Updates 

3rd Party Blog Updates & Industry News 

Beta, Lab and Tech Preview Updates 

Get started with Omnissa Beta-program

 

Sign up or LogIn [HERE] to get access to the latest Beta versions.

 

Latest Patch & Seed Script Updates: 

OS Updates Seed Script

  • Most recent update :
    visionOS 2.3 (22N6896), macOS 13.7.3 (22H417) and macOS 14.7.3 (23H417)
  • Last Update: CW06

 

Seed Script for latest Device Model Information

  • Seed Script to support 
    • iPad mini 7th Generation and 2024 iMac, MacBook Pro and Mac mini
  • Last update: CW45

 

Workspace ONE UEM 23.02

  • Patch Level 23.02.0.52
  • PPAT-17448 - Tunnel client not reconnecting once the device regains compliance. 
  • MACOS-4942 - Smart group assignment for the macOS internal app fails to be assigned for a couple of users’ devices. 
  • CRSVC-51130 - Add code block on the UEM side to block Conditional access configured at any other customer OG if it is already configured for once customer OG within same UEM environment. 
  • AMST-42076 - Time zone displayed in Scripts tab is different from the Execution logs.
  • Last Update: CW38

 

Workspace ONE UEM 23.06

  • Patch Level 23.6.0.46
    • AAPP-18407 - Improve VPP license reconciliation performance.
    • AAPP-17985 - Add process to purge stale VPP v2 notification data.
    • AAPP-18356 - Fix looping issue when batch size is set to 0.
    • AAPP-18245 - During DEP enrollment, the Device OS version is not correctly read from the device.
  • Last Update: CW06

 

Workspace ONE UEM 23.10

  • Patch level 23.10.0.44
    • UM-9396 - Unable to add user groups to a customer-type organization group (OG) from a partner-type OG.
    • AAPP-17804 - Admin account stuck in “Delete In Progress” state, must be deleted from the console.
    • AMST-42780 - Seed SFD 23.10.6 to UEM 23.10.
  • Last Update: CW06

 

Workspace ONE UEM 24.02

  • Patch Level: 24.2.0.24
  • RUGG-13303 - Organization group change for Zebra Printers does not automatically update the smart group subscriptions.
  • RUGG-12961 - Diacritical marks created by changing Languages (localization) in Custom Profiles Lost During Profile Edits.
  • AAPP-17985 - Enhance purge script logic to handle stale VPPv2 notification data (30 day retention).
  • AAPP-17804 - Admin account stuck in “Delete in Progress” state, must be deleted from the console.
  • AMST-41534 - Seed Windows Hub 24.4.3.0 x86 Patch1 to UEM console 2402.
  • Last Update: CW07

 

Workspace ONE UEM 2406

  • Patch level 24.6.0.21
    • AGGL-17006 - Android devices may be delayed in processing Freestyle workflow steps from UEM.
    • AMST-42613 - ARM64 - OOBE enrolled Windows devices Stuck in Pending Hub state.
    • AGGL-17422 - Automatic Profiles May Not Install for Android Shared Devices.
    • AMST-42648 - Devices getting enrolled with Container type management.
    • AAPP-17985 - Enhance purge script logic to handle stale VPPv2 notification data (30 day retention).
    • CRSVC-57547 - Enhanced Profile State to Include UUID and Unique Key for Mac Devices.
    • AAPP-17594 - Failure to Install Unmanaged Profiles via URL.
    • AAPP-18661 - Fixed Issue Where No Notification Was Sent If a Problematic Device Was Found in Sample Job Run.
    • MACOS-5537 - Fixes for Disk Encryption Profile via Script.
    • MACOS-5419 - Logic Added for Payload UUID Generation of Uploaded Profiles Using DSM.
    • MACOS-5468 - Mac Profile Status Displays as Out of Date/Not Installed After Mod Upgrade.
    • MACOS-5233 - Maintain checkbox selection during next and back operations.
    • ARES-30838 - Resource name may not be visible in Device Troubleshooting logs for ‘Install’ or ‘Remove’ events manually triggered by admins from the UEM Console.
    • MACOS-5449 - Script to Remediate Disk Encryption Profile Delivery to Excluded Devices.
    • AMST-42615 - SharedDeviceSettings profile is showing up on Device Details page for Windows devices.
    • CRSVC-57939 - Update Device State Table Entries which were causing Invalid Device Type
    • MACOS-5482 - Update macOS selective app list sample source when sent from Intelligent Hub from MDM to MAC_OS_MUNKI.
    • ESI-398 - Update push notification logic to trigger immediately on tag modification or OG assignment change of device.
    • AAPP-17304 - Update user list during native check-in/check-out (CICO).
    • MACOS-5452 - Updated Admin Actions Logic for Installing and Removing Applications to Route Notifications to AWCM.
    • AGGL-18123 - Workspace ONE UEM may fail to configure per-app VPN with Tunnel for Android devices.
  • Last Update: CW07

 

Workspace ONE UEM 2410

  • Patch level 24.10.0.0
    • AAPP-16804: ToU displays incorrectly when ABM device is enrolled for iPadOS.
    • AAPP-16890: Non-English characters typed at “Department” in DEP profile are garbled when viewed in iOS device.
    • AAPP-17070: In an iOS desktop device profile with DDUI, aw-tag for Allow Find My Device is located incorrectly.
    • AAPP-17815: Custom Command shows Pending under Troubleshooting
    • AAPP-17946: Empty App Config is delivered to device in a specific update scenario of Internal iOS App
    • AAPP-17981: Notifications not being sent upon successful installation of iOS update.
    • AAPP-18028: ABM resources do not get installed upon enrollment.
    • AAPP-18183: Personal / User-installed apps display in console even though privacy settings are not enabled for it.
    • AAPP-18397: DEP Await Configuration ends prematurely before device is fully configured.
    • AET-18974: UEM MDM API - Assist Chat features not visible when Session Launch from RemoteManagementV1/V2 Controller MDM API.
    • AGGL-17018: CICO with Launcher Apps are not always removed when combined with App assignments.
    • AGGL-17044: Android devices intermittently not added to Smart Groups that filter by manufacturer and model.
    • AGGL-17096: “IsEncrypted” API call for Android not working.
    • AGGL-17113: VPN Profile URL Whitelist does not get applied through profile UI.
    • AGGL-17115: Application Configuration Inconsistent Behavior for Check In Check Out User on Android Devices.
    • AGGL-17301: Deleting area associated profile and the area data causes error in subsequent area profiles creation.
    • AGGL-17514: App Configuration Fails to Apply After Enrollment.
    • AGGL-17553: Changes under Enrollment Restrictions can not be saved.
    • AGGL-17575: Android Credentials profile becomes corrupted when adding version if “Allow silent app access” is enabled.
    • AGGL-17940: Android app are removed from devices when renamed by administrator.
    • AMST-41216: Wireless MAC address will not display when enrolled on LAN.
    • AMST-41420: Baselines are not getting downloaded on some window devices.
    • AMST-41583: Windows | Compliance status for firewall not showing correct at the start of device.
    • AMST-41874: Unable to delete an OG and getting error “Save Failed Delete Failed”.
    • AMST-41960: Application installation status is not reporting correctly on UEM.
    • AMST-42059: Firewall Profile failing to install on Windows 11 systems .
    • AMST-42156: Factory Provisioning Service / PPKG generation stuck.
    • AMST-42458: Addressed certificate profiles not installing with optional assignment while leveraging the Modern SaaS Architecture.
    • AMST-42554: Windows | Firewall Profile installation fails with RemotePortRanges settings in profile.
    • AMST-42613: ARM64 - OOBE enrolled Windows devices Stuck in Pending Hub state .
    • AMST-42637: Baseline and Sensors are not assigned when user signs in as AD user on Win PC and the PC moves to a different OG while leveraging the Modern SaaS Architecture. *
    • AMST-42648: Devices getting enrolled with Container type management.
    • ARES-29119: Application_UUID missing in response of GET API mdm/devices/{deviceUuid}/apps/search for Windows and Mac devices.
    • ARES-29230: Alert to ‘Leave’ or ‘Cancel’ configuration received when adding criteria under ‘When to Call Install Complete’ in Deployment Options for Windows apps.
    • ARES-29493: BIOS Password Profiles not applying on devices when deployed via Workflows.
    • ARES-29652: Child OG remains undeleted despite admin’s attempt to delete it.
    • ARES-29876: Addressed UEM Console ‘page not found’ error, when you click Query button at Resources > Apps > Internal > 3CX Desktop App > Devices > Query.
    • ARES-29939: Unable to save iOS Boxer application configuration when the ‘Enable FastSync’ App Policy is applied.
    • ARES-30062: Exporting list of evaluated devices from an Application Deployment Tracking page results in a failed export.
    • ARES-30074: Spaceman error occurs while searching for a number on Profile List View page.
    • ARES-30209: App removal commands re-triggered for applications already deleted months ago.
    • ARES-30516: Profiles existing in UEM before modern architecture enablement not installing on newly enrolled Work Profile Android Devices.
    • ARES-31019: Status of installed profiles shown as ‘Installed but not assigned’ on Device Details Profiles tab.
    • ARES-31047: Launcher Profile configured with Custom Lookup fields failing to install on devices.
    • CMCM-191121: Content locker application shows foreign folder names and intermittent issue with files missing/ or displaced.
    • CRSVC-50701: Enhanced logging functionality to obfuscate full API key entries.
    • CRSVC-52960: Status Query String Not Honored for GET api/mdm/compliancepolicies.
    • CRSVC-53629: Resource delivery blocked by Compliance Policy with Enterprise Wipe action.
    • CRSVC-56613: Hardened Email Address continuity validations within UEM Console and API.
    • ENRL-4305: Enrollment blocked by server timeout in customer OG.
    • ESI-103: Tags are not getting assigned for devices being enrolled through Dropship Provisioning.
    • ESI-320: Garbled text being shown to end users upon enrolment failure due to user group restrictions.
    • FCA-207745: Environment sends email notifications for account modifications when the home button is pressed using the new deployment method.
    • FCA-207895: UEM Console makes an incorrect request at landing page for the admin user who enables 2FA and configures landing page.
    • FCA-208029: EID Value and Phone Number are not getting populated for iPad devices.
    • FCA-208096: PhysicalMemory values missing in UEM devices/search API call.
    • FCA-208136: API call “DeviceExtensiveSearchAsync” doesn’t work properly with multiple filters.
    • FCA-208232: “POST /devices/gps/search API call does not honour date ranges.
    • FCA-208380: Custom message template for Admin Activation is not getting selected correctly.
    • FCA-208389: Workspace ONE API request continually failing with 500 Internal Server error for mdm/devices/search endpoint.
    • FCA-208390: The “Apply” button on Filters does not work when devices list is opened from Assignment Groups page.
    • FCA-208408: REST API settings inheritance is being incorrectly applied for the child OG.
    • FCA-208419: NetworkInfoSearch API is not using the steps that appear in the official documentation.
    • FCA-208431: Dual SIM iOS devices showing only one phone number in the “Device Info” section.
    • FCA-208432: Device Usage Detail report reporting incorrect values for Roaming Start Date and Roaming End Date.
    • FCA-208533: Reports with a large volume of data are getting stuck as queued on the Exports page.
    • FCA-208840: Sim card details are reported as blank in the report but it is present in the UEM Console and in the DB.
    • FS-5588: Workflows install retired app version.
    • FS-5716: Windows app install fail.
    • FS-6560: Failed’ sensor status incorrectly parsed by workflow as ‘condition not met’.
    • MACOS-5408: Disk Encryption profile is incorrectly delivered to excluded devices.
    • PPAT-17434: Tunnel client not reconnecting once device regains compliance.
    • RUGG-13040: Products being pushed to unintended devices when assignment rules have integer-based custom attributes.
    • RUGG-13180: Manual sorting of Manifests not working in Products.
    • RUGG-13232: Product search (/products/search) and Product extensive search (/products/extensivesearch/) APIs are returning a default policy UUID(0000-000) instead of the actual Device Policy UUID.
    • RUGG-13304: Relay Servers were unable to connect to the Console when default Mac address was used in the discovery text.
    • UM-9294: Attribute sync is failing post upgrade to 2402 console version.
    • UM-9396: Unable to add user groups to a customer-type organization group (OG) from a partner-type OG.
  • Last Update: CW07



Comments