Fixed issues in UEM 12.23 and UEM Cloud
UEM on-premises 12.23 Quick Fix 11
|
After upgrading to UEM version 12.23, the scheduled daily purge of UEM audit logs might not have occurred as expected, and might have consumed excessive disk space on the database server. (EMM-161000) |
|
In certain environmental circumstances, actions in the management console might not have completed as expected due to a communication timeout between the management console and the UEM Core service. This QF increases the timeout period to reduce occurrences of this issue. (EMM-160732) |
UEM on-premises 12.23 Quick Fix 10
|
When an Apple ADE device was moved to a new ADE account, user assignments were not retained as expected and activation with UEM might not have completed successfully. (EMM-160745) |
|
On older Android devices (for example, Pixel 3a and Pixel 6), hardware attestation validation might have failed. As a result, those devices were reported as out of compliance. (EMM-160406) |
|
This QF release includes security improvements to enhance the protection of the product and user data. (EMM-160373, EMM-160372, EMM-159943, EMM-159180) |
|
This QF release includes updates to ensure compatibility with the upcoming iOS 27 release. (EMM-160331) |
|
If you enabled the "Delay software updates" and "Automatically update device OS" iOS IT policy rules, on iOS 26 devices, the software update delay period might not have been applied as expected. As a result, devices might have downloaded OS updates immediately instead of waiting until the delay period expired. To fully resolve this issue, after you apply QF 8 or later, you must edit and save any impacted IT policies. This issue was originally fixed in QF 8 (May 2026). QF 10 includes further changes to prevent this error condition going forward. (EMM-160248) |
|
If you activated an Apple ADE device with BlackBerry UEM using the BlackBerry UEM Client, an issue might have occurred during BlackBerry Dynamics enrollment that made activation appear successful even though it did not complete. This error condition might have also caused device data to be deleted. (EMM-160058) |
UEM Cloud Quick Fix 9 (July 2026)
|
On older Android devices (for example, Pixel 3a and Pixel 6), hardware attestation validation might have failed. As a result, those devices were reported as out of compliance. (EMM-160406) |
|
If you enabled the "Delay software updates" and "Automatically update device OS" iOS IT policy rules, on iOS 26 devices, the software update delay period might not have been applied as expected. As a result, devices might have downloaded OS updates immediately instead of waiting until the delay period expired. To fully resolve this issue, after you apply QF 8 or later, you must edit and save any impacted IT policies. This issue was originally fixed in QF 8 (May 2026). QF 9 includes further changes to prevent this error condition going forward. (EMM-160248) |
|
If you activated an Apple ADE device with BlackBerry UEM using the BlackBerry UEM Client, an issue might have occurred during BlackBerry Dynamics enrollment that made activation appear successful even though it did not complete. This error condition might have also caused device data to be deleted. (EMM-160058) |
UEM on-premises 12.22.1 Quick Fix 8
|
On older Android devices (for example, Pixel 3a and Pixel 6), hardware attestation validation might have failed. As a result, those devices were reported as out of compliance. (EMM-160406) |
|
This QF release includes security improvements to enhance the protection of the product and user data. (EMM-160373, EMM-160372, EMM-159943, EMM-159180, EMM-158968) |
|
This QF release includes updates to ensure compatibility with the upcoming iOS 27 release. (EMM-160331) |
UEM on-premises 12.23 Quick Fix 8 and UEM Cloud (May 2026)
|
When you associated an ACME profile with a VPN profile and assigned the VPN profile, if the key algorithm specified in the ACME profile had an associated HardwareBound key, the VPN profile might not have been applied to devices as expected. (EMM-160233) |
|
If you enabled the "Delay software updates" and "Automatically update device OS" iOS IT policy rules, on iOS 26 devices, the software update delay period might not have been applied as expected. As a result, devices might have downloaded OS updates immediately instead of waiting until the delay period expired. To fully resolve this issue, after you apply QF 8, you must edit and save any impacted IT policies. (EMM-160248) |
|
If the "Automatically update rapid security responses" iOS IT policy rule was enabled in an assigned IT policy, devices did not receive rapid response updates as expected. This was due to a change that Apple made recently to the version string format for rapid response updates. (EMM-160157) |
|
If you associated an ACME profile with a VPN profile and assigned the VPN profile, the VPN profile might not have been applied to devices as expected. (EMM-160136) |
|
If an Apple ADE (formerly DEP) device was migrated to another UEM tenant that shared the same UEM database (for example, as a result of management activities in Apple Business), the duplication of the same device serial number across tenants caused an error. As a result, the ADE account could not be migrated. (EMM-160115) |
|
The "Control Incoming Attachments" setting has been added to BBM Enterprise profiles to allow you to control the types of file attachments that users are allowed to send and receive in BBM Enterprise. When enabled, in the "Allowed File Extensions" field, type the list of allowed file types, separating each file type with a comma or semi-colon (for example: pdf,docx,png). (EMM-159980) |
|
If iOS software update rules were enabled in an assigned IT policy, iOS updates might not have been applied to devices as expected. (EMM-159477) |
UEM on-premises 12.23 Quick Fix 7 and UEM Cloud (April 2026)
|
If you enabled hardware attestation for Android devices, when a user activated a device that uses Remote Key Provisioning, UEM might have identified the device as out of compliance with a "Hardware attestation failed" error. (EMM-159947) |
|
When you created a new BlackBerry Dynamics profile, the "Enable FIPS" setting was enabled by default. After you apply this QF, this setting is turned off by default when you create a new BlackBerry Dynamics profile. (EMM-159832) |
|
If the certificates in your UEM environment used SHA1 algorithms, after updating to JRE version 17.0.18 or later, you might not have been able to log in the UEM management console. (EMM-159763) |
UEM on-premises 12.22.1 Quick Fix 6 (April 2026)
|
If you enabled hardware attestation for Android devices, when a user activated a device that uses Remote Key Provisioning, UEM might have identified the device as out of compliance with a "Hardware attestation failed" error. (EMM-159947) |
UEM on-premises 12.23 Quick Fix 6 (March 2026)
|
This release includes improved UEM logging data for iOS updates that have a pending status. (EMM-159840) |
UEM on-premises 12.23 Quick Fix 5 and UEM Cloud (March 2026)
|
If you configured an activation profile to not allow certain versions of iOS, and you applied UEM 12.23 QF 3 or 12.23 QF 4, this setting could have been applied to already activated devices when it should have been applied only to new device activations. If you applied QF 3 or QF 4, you must apply QF 5. (EMM-159796) |
|
In certain circumstances, iOS updates initiated by UEM did not complete as expected. (EMM-159770) |
|
If you used the Apple Business to migrate iOS 26 devices from a third-party MDM solution to UEM, the devices activated as expected on UEM, but all managed iOS VPP apps were removed from the devices. This issue is resolved, with the following actions required for future migrations of DEP devices to UEM from a third-party MDM:
|
UEM on-premises 12.23 Quick Fix 4 and UEM Cloud (February 2026)
|
A small number of the new macOS IT policy rules added in QF2 were missing tool tip text. The missing tool tip text has been added in this release. (EMM-159564) |
|
If multiple UEM Cloud tenants connected to and synchronized with the same Active Directory group, and the same user was added to both tenants, that user was not onboarded and synchronized as expected. (EMM-159553) |
|
In certain circumstances, if the BlackBerry Proxy lost a proxy connection, it entered a paused state and would not reestablish connections without a restart. (EMM-159511) |
|
In a multi-tenant environment with authentication delegation configured for BlackBerry Dynamics apps, if a user's BlackBerry Dynamics apps became locked and the user tried to unlock them with an unlock key, the apps did not unlock and a "Setup Failed" error message displayed. (EMM-159457) |
UEM on-premises 12.23 Quick Fix 3 (February 2026)
|
If you upgraded the computers that host UEM to use JRE 17.0.18 or later, the BlackBerry Secure Connect Plus service did not start and remained in paused state. For more information, see KB 141054. (EMM-159587) |
|
If you tried to import the latest IT policy pack, an error displayed and the policy pack was not imported successfully. (EMM-159579) |
UEM on-premises 12.23 Quick Fix 2 and UEM Cloud (February 2026)
Upgrade fixed issues
|
After upgrading to UEM version 12.23, an attempt to log in to the management console might have failed due to an authentication issue. (EMM-159152) |
Management console fixed issues
|
The following changes have been made to ACME profiles:
For more information, see Send client certificates to devices using ACME. (EMM-159275) |
|
This QF release adds many new IT policy rules for macOS device and user restrictions. macOS password restrictions now apply to both the device and user. See the macOS tab in any new or existing IT policy to view tool tip descriptions for each rule. After you upgrade to QF2 or after the UEM Cloud update, you must edit existing IT policies and save them (you do not have to make any changes) to ensure that macOS user and device restriction rules are properly delivered to devices. (EMM-159027) |
|
If you edited a Microsoft Intune app protection profile and you used the option to add Intune apps by selecting them from a list, the available apps did not display in the app list. (EMM-159018) |
User, device, and app management fixed issues
|
When an Apple DEP user that was added to UEM from a company directory tried to activate their device with a password, the activation did not complete successfully. (EMM-159508) |
|
If you assigned a VPP app to a user as unmanaged (disposition set to optional, target set to personal, associated a user license), the VPP app was installed as managed instead. This is resolved in QF2 and the UEM Cloud February 2026 update; for any users that had this assignment prior to the upgrade or UEM Cloud update, you must remove the VPP app assignment to remove the app, then assign the VPP app to users again. (EMM-159507) |
|
If you configured Knox Mobile Enrollment, when a user tried to activate their device with UEM using their Active Directory credentials, the activation did not complete successfully. (EMM-159496) |
|
This QF release adds the "Allow video conferencing remote control" IT policy rule, supported for devices with iOS 18.4 and later. This rule controls whether a remote FaceTime session can request control of the device. By default, this rule is enabled. (EMM-159484) |
|
If you enabled the "Non-assigned app is installed" compliance rule in the assigned compliance profile, iOS 26 devices were reported as out of compliance because system apps were incorrectly identified as non-assigned apps. (EMM-159462) |
|
If you assigned both required VPP apps and more than one optional personal VPP app to an iOS device user, the required apps were not installed automatically on the user's device. (EMM-159450) |
|
When a user tried to install an iOS VPP app, the app might not have installed due to a request timeout issue. (EMM-159224) |
BlackBerry Web Services fixed issues
|
If you tried to use BlackBerry Web Services Applications routes (/api/v1/applications), Active Directory authentication failed, preventing access to the APIs. (EMM-159474) |
|
When you used the GET /{tenantGuid}/api/v1/exchangeConfigurations API, the modernAuthentication value would always return false even if modern authentication was configured. (EMM-159049) |
UEM on-premises 12.23 Quick Fix 1 and UEM Cloud (December 2025)
|
After upgrading to UEM 12.23, if you did not edit and save an IT policy after the upgrade, the policy was not delivered as expected to iOS devices. (EMM-159228) |
|
After you installed or upgraded to UEM 12.23, if you tried to create or change a directory synchronization schedule, the management console might have stopped responding when you clicked Add, and the synchronization schedule was not saved. (EMM-159169) |
UEM on-premises 12.23 and UEM Cloud (November 2025)
Installation and UEM services fixed issues
In a UEM Cloud environment, whenever the BlackBerry Secure Gateway service was stopped, the JVM might have generated hs_err and .mdmp log files that consumed disk space over time and had to be removed manually. (EMM-158998) |
|
In certain circumstances, after you installed UEM version 12.22 and you tried to log in to the management console for the first time, the authentication process might have taken longer than expected and might have stopped with a "Login failed" error message. (EMM-157944) |
Management console fixed issues
|
If you added a user to UEM and you did not enable the user for device management, you did not have to associate an email address with the user. If you later enabled that user for device management and you tried to migrate the user to a different UEM domain (Settings > Migration), the following error occurred because the user did not have an email address: “An error was encountered. The user cache could not be refreshed.” (EMM-157491) When you enable a user for device management, if the user does not have an email address, an error message now prompts you to add an email address for the user before device management can be enabled. |
|
When you enabled a Chrome OS user in the management console, the user was successfully enabled, but an error message indicated that the action could not be performed. (EMM-157206) |
|
When you viewed managed devices in the console, for Chrome OS devices, the Chrome OS icon did not display as expected in the OS column. (EMM-157196) |
User, device, and app management fixed issues
|
If you assigned a SCEP profile with a key size of 3072 (the default setting), the profile did not apply as expected to iOS devices. The default key size is now 4096. (EMM-158628) |
|
If you configured directory synchronization and enabled offboarding, when a user with more than one device activated with a user privacy activation type was supposed to be offboarded from UEM, the offboarding process did not complete successfully. (EMM-158001) |
|
If you used a .csv file to import directory user accounts into UEM, and you used the Directory UID column to specify a unique ID that UEM could use to validate each directory user (instead of each user's email address), if any of the Directory UID values were not valid, the import process did not complete and no users are imported. (EMM-157829) |