Known issues in UEM 12.24 and UEM Cloud

Note: The 3.20 version of each BlackBerry Dynamics app uses the BlackBerry Dynamics SDK version 15.x. This version of the SDK upgrades the Federal Information Processing Standards (FIPS) provider to version 140-3, replacing the previous standard of FIPS 140-2. If FIPS is enabled in the BlackBerry Dynamics profiles that are assigned in your UEM environment, you must ensure that any certificates that are used by BlackBerry Dynamics apps are compliant with FIPS 140-3. For more information, including details about the algorithms in 140-2 that are no longer supported, see the details for the FIPS upgrade in the BlackBerry Dynamics SDK version 15.x Release Notes (iOS or Android). For more information about possible impacts on your UEM environment and how to resolve them, see KB 141162.

Installation and upgrade known issues

If you upgrade UEM version 12.22 to UEM version 12.24, when a user that is assigned the default IT policy activates a macOS device, user and device channels are not created on the device and the work apps catalog is not available on the device. (EMM-161053)

Workaround: In this specific upgrade scenario, the issue will not occur if you assign a custom IT policy and a macOS app to users prior to activation. For users already impacted by the issue, you can resolve by assigning a custom IT policy and a macOS app to the users and instructing them to activate their devices with UEM again.

After you upgrade to UEM version 12.24 or receive the August 2026 UEM Cloud update, when you view the details for an iOS device, the IT policy and profiles section may indicate that the default device SR requirements profile is present on the device even though the profile is not enabled by default for iOS devices (you must explicitly enable iOS functionality in the profile). This is a UI defect only, as the default SR requirements profile is not delivered to the iOS device. (EMM-160914)

If the "Delay software updates" and "Automatically update device OS" iOS IT policy rules are enabled, and you upgrade UEM version 12.22 to version 12.24, the software update delay period on iOS 26 and iOS 18 devices might not be applied as expected. As a result, devices might download OS updates immediately instead of waiting until the delay period is expired. (EMM-160869)

Workaround: After you upgrade UEM, edit and save any impacted IT policies.

After the August 2026 UEM Cloud update, or after upgrading to UEM version 12.24, Apple ADE devices might return blank compliance reports. (EMM-160591)

Workaround: Make changes to the assigned compliance profile and save the profile to send an updated version to ADE devices.

After the August 2026 UEM Cloud update, or after upgrading to UEM version 12.24, any custom administrator roles that were granted all "View users and activated devices" permissions will not have the new permissions "View compliance violations" and "View device vulnerabilities". You must grant these permissions to any custom roles that you created before the upgrade. (EMM-160325)

In certain circumstances, in a UEM Cloud environment, when you open the BlackBerry Connectivity Node console for the first time after an upgrade, an HTTP Status 500 error displays and the console does not load as expected. (EMM-157113)

Workaround: Refresh the page after the error displays.

Management console known issues

If you edit a Wi-Fi profile and the Android check box is not selected under "Show device types to configure the profile for", when you try to save the profile, the UI displays the blank contents of the Android tab and the profile is not saved. (EMM-161495)

Workaround: After this issue occurs, under "Show device types to configure the profile for", select the Android check box, then clear the Android check box and save again.

If you create an app group and add Apple VPP apps with user licenses, after you assign the app group to a user group and view the app assignments in a user's details, the user license is not displayed as expected for each VPP app. (EMM-160950)

If you create or edit a BlackBerry Dynamics Notification Profile and enable both the "Use BlackBerry Connectivity Node route" and "Enable password expiry" settings, when you try to save the profile, the validation fails and the profile is not saved. (EMM-160923)

Workaround: Enable the "Use BlackBerry Connectivity Node route" setting, save the profile, then edit the profile again to add the password expiry settings.

The used licenses count for macOS VPP apps might not update as expected in the management console after users install or remove VPP apps from their macOS devices. (EMM-160915)

When you view the details for a macOS VPP app in the management console (Apps > iOS app licenses), on devices where the app is installed, the status column may incorrectly indicate that the app is not installed. (EMM-160907)

When you view a user's device details, if the user is assigned one or more Apple VPP apps, the license and app names may overlap in the assigned apps list if the browser zoom is set to 80% or higher. (EMM-160861)

If you remove the app source file from an internal BlackBerry Dynamics app entitlement, then you try to remove the app from the App installation ranking page, it appears to be removed, but appears again when you return to the App installation ranking page. (EMM-160824)

When you add an internal iOS app, if you select a category for the app, an error displays when you try to save the app. The error prevents you from adding the app to UEM. (EMM-160704)

Workaround: When you add an internal iOS app, do not select a category for the app. You can edit the app later to add a category.

When you create a Software update enforcement profile, if you include a space before or after the version number in the Target build version or Target OS version fields, you can save and assign the profile, but the profile is not delivered to devices successfully. (EMM-160635)

When you try to create a new app shortcut for Android devices, if you select the "Use app package ID" option, the app package ID field does not display as expected. (EMM-160488)

If you add an app to the app list and you try to add an app configuration, when you click an option to add an additional configuration section to the app configuration (for example, a VPN profile, an email configuration, and so on), an error displays that prevents you from adding that item. (EMM-160444)

Workaround: Add the app to the app list without an app configuration, then edit the app and add an app configuration.

If you try to delete an ADE configuration from the management console, nothing happens when you click the remove (X) icon. (EMM-160355)

When you add a new Android Management connection in UEM (Settings > External Integration > Android and Chrome Management), the UI does not update to display the new connection until you leave the Android and Chrome Management screen and return to it again. (EMM-160266)

When you remove an Apple VPP account from UEM and click Delete on the "Delete VPP account" dialog box, the dialog box remains and a delete confirmation message does not display. The VPP account is removed from UEM. (EMM-160109)

If you assign a new email profile to a user or group with an existing email profile, the prompt to replace the profile is titled "Assign Email profile" instead of "Replace email profile", and an "Assign" button is displayed instead of a "Replace" button. Clicking the "Assign" button replaces the existing email profile. (EMM-159112)

In unknown and intermittent circumstances, when a user activates a macOS device, the device details in the management console may list "Command failed" for the action of sending the IT policy and profiles to the device even though the policy and profiles were delivered successfully. (EMM-159166)

User, device, and app management known issues

If you assign a macOS app to a user or group with a required disposition and the update mode set to default or postpone, the update mode setting is not delivered to devices as expected. As a result, when a new version of the app is available in the app store, the app is not updated automatically on macOS devices. (EMM-160949, EMM-160930)

Workaround: Users can choose to update the app from the work apps catalog on the device.

If you create and assign a device SR requirements profile that includes an invalid beta token, the profile configuration is removed from the device. (EMM-160865)

Workaround: Correct the invalid beta token or remove the beta settings from the profile, then save the profile. UEM sends the updated profile to devices.

If you try to assign an iOS VPP app as an unmanaged app (disposition set to optional, target set to personal, and license assigned to user), the license is not assigned to the user as expected. (EMM-160481)

Workaround: Try to assign the VPP app with the same settings again. The assignment should work as expected on a subsequent attempt.

When you add an Apple ADE configuration to UEM, you can specify a support email address. On macOS devices, the support email address does not display as expected when a user clicks the info icon during the activation process. (EMM-160359)

As of macOS 26.2, Apple has made changes to how restriction payloads are handled. As a result, using a combination of device functionality rules and user functionality rules can result in unpredictable behavior (see developer.apple.com: Device Management Restrictions).

For devices with a version of macOS earlier than 26.2, it is a best practice to use either device functionality rules or user functionality rules. If you use a combination of both and create a rule conflict, the configuration of the device functionality rule takes precedence.

For devices with macOS version 26.2 or later, use device functionality rules only.

(EMM-159594)

After the upgrade to UEM 12.23 Quick Fix 2 or later or after the UEM Cloud January 2026 update, when you edit and save an IT policy with macOS user policy settings, macOS users who activated before the update may see a duplicate of the IT policy on their device. (EMM-159518)

If a VPP app is assigned as unmanaged (Disposition set to Optional, Target set to Personal, VPP license assigned to User), in unknown circumstances, when a user activates their device, the user might not be able to install the assigned VPP app. (EMM-159159)

Workaround: Instruct users to install another app from the Required tab in Work Apps, then try to install the unmanaged VPP app again.

If you configure a SCEP profile with an Entrust configuration, if the configuration does not include an igusername token, the certificate enrollment process does not complete as expected on devices. (EMM-159103)

If you create a group and assign multiple VPP apps with different VPP license configurations to the group as part of the initial group creation process, some of the apps might not be assigned VPP licenses as expected. (EMM-159063)

Workaround: Create the group first without assigning VPP apps, then assign the appropriate VPP apps to the group.

If you used UEM to assign the Vrbo Owner app to users or groups with the Disposition set to Optional and the Target set to Personal, but a user did not install the app yet, after the upgrade to UEM 12.23 or later or the November 2025 UEM Cloud update, when the user tries to install the app, an error message indicates that the app cannot be downloaded. UEM indicates that the app used a VPP license. (EMM-159034)

If you associate an enterprise connectivity profile configured for per-app VPN with an IMAP/POP3 profile, after the IMAP/POP3 profile is applied, iOS devices are not able to connect to the IMAP/POP3 server. (EMM-158971)

Workaround: Configure the enterprise connectivity profile for device-wide VPN.

If you create an email profile and you both specify a password and enable certificate authentication for iOS devices, the device does not authenticate as expected with the Microsoft Exchange Server. (EMM-158824)

Workaround: Configure the email profile to use either a password or certificate authentication, not both.

If a VPP app is installed on a device as unmanaged (Disposition set to Optional, Target set to Personal, VPP license assigned to User), then you change the Target setting for the app to Work, the app is still considered unmanaged by UEM and cannot be removed or otherwise managed from the management console. (EMM-158465)

If a VPP app is installed on a device as unmanaged (Disposition set to Optional, Target set to Personal, VPP license assigned to User), when you view the user’s device details, the app status is displayed as Not installed. (EMM-158447)

If you enable automatic OS updates for iOS devices in the assigned IT policy, and set an update schedule of one day, the device OS is not updated on the one day schedule as expected. The update is automatically moved to the next day (and does occur as expected on that day). This issue occurs intermittently. (EMM-157987)

If you use a .csv file to import directory user accounts into UEM, and you use the Group membership column to specify the group that you want to add each user to, during the import process you receive a prompt asking you to select the groups that you want to add the users to, even though this information is already specified in the .csv file. If you make a selection in the prompt and click Import, the selection from the prompt overrides whatever group memberships are specified in the .csv file. (EMM-157964)

Workaround: Don't select any groups in the prompt and click Import. The imported users will be added to the groups that you specified in the .csv file.

In unknown circumstances, if an assigned compliance profile is set to not allow BlackBerry Dynamics apps to run while there is a pending OS update, an impacted device might still be considered out of compliance even after a user applies an OS update. (EMM-157939)

If you configure compliance prompts for BlackBerry Dynamics apps for the "OS update not applied" (iOS and Android) or "Managed device attestation failure" (iOS) rules and you set the action for BlackBerry Dynamics apps to block or to delete BlackBerry Dynamics app data, then you remove and reassign the compliance profile, the UEM Client and other BlackBerry Dynamics apps may be blocked or deactivated and removed (depending on the selected action) without prompting the user first. (EMM-156895)

When you assign VPP apps with a user license to Apple ADE devices, if you assign the apps right after associating the VPP license to users, the apps might not install as expected because the app license cannot be retrieved. (EMM-156886)

Workaround: See Microsoft Intune - iOS and iPadOS app installation errors: Could not retrieve license for the app with iTunes Store ID.

If you assign a compliance profile with the iOS "OS update not applied" rule set to provide compliance prompts for BlackBerry Dynamics apps, then you change the compliance action for BlackBerry Dynamics apps from block to delete app data, or from delete data to block, prompts are not provided to the user before the enforcement action is applied. (EMM-156884)

When you configure a device profile with different wallpapers for the home screen and the lock screen and you assign the profile to an iOS device, the wallpaper configuration may not be applied to the device as expected. This issue occurs intermittently. (EMM-155689)

Samsung devices that are activated with Android Enterprise Work space only and are assigned an enterprise connectivity profile cannot send or receive SMS or MMS messages. (EMM-154287)

Workaround: In the enterprise connectivity profile settings, on the Android tab, select Container-wide VPN and add the com.android.mms.service and com.google.android.apps.messaging apps to the list of apps restricted from using BlackBerry Secure Connect Plus.

When you schedule an OS update for one or more supervised iOS devices, the update is delivered to devices but is not installed. This occurs intermittently and is due to an iOS known issue. (EMM-152977)

Chrome OS devices do not synchronize with UEM if they are in an org unit that has no child org units. (EMM-150375)

If an authentication delegate app is configured in an assigned BlackBerry Dynamics profile, when a device user removes the authentication delegate app from their device and then restarts a different BlackBerry Dynamics app and uses the forgot password option, the forgot password option does not work and the user does not receive an error message. (GD-66829)

Workaround: Instruct the user to install the authentication delegate app again.