Skip Navigation

Known issues in
BlackBerry UEM
12.11 MR1

Items marked with an asterisk (*) are new for this release.

Installation, upgrade, and migration known issues

* When you install the
BlackBerry Workspaces
plug-in with
BlackBerry UEM
, the next time you open the UEM management console, an error message appears even though
BlackBerry UEM
and
BlackBerry Workspaces
are behaving as expected. (SNP-561)
Workaround:
Dismiss the error message. It does not reappear.
If you have applied an IT policy pack on your organization's
BlackBerry UEM
12.10 MR1 server and you upgrade to
BlackBerry UEM
12.11, the new IT policies are not hidden even though the policy pack was installed on the
BlackBerry UEM
12.10 MR1 server. (EMM-129252)
Workaround
: The policies will be hidden during the next policy sync or you can re-apply the IT policy pack manually.
You can't upgrade from
UEM
12.9 to
UEM
12.11 if the directory path contains brackets. For example, C:\Program Files (EXAMPLE)\BlackBerry\UEM\. (EMM-126340)
When you are migrating apps from
Good Control
to
BlackBerry UEM
, if you have not configured a policy that contains an authentication delegate in
Good Control
but
BlackBerry UEM
has a policy that configures app A as an authentication delegate, when you migrate app B, the app is blocked from migrating because app A has not been migrated. If you then migrate app A, app B will still be blocked because it does not send a request to app A to see if it has been migrated. (GD-31948)
Workaround
: On the device, force the apps to stop and then restart app B.

User and device management known issues

Note that some of these issues are for the
BlackBerry UEM Client
and will be fixed in a future
BlackBerry UEM Client
release.
* You can't modify and save an enterprise connectivity profile that has
iOS
VPN on demand rules configured. (EMM-132378)
Workaround:
Do not configure VPN on demand rules for
iOS
devices in an enterprise connectivity profile.
* If you modify an existing app lock mode profile for a
Samsung Knox
devices, the updated profile is not correctly updated on the device. (EMM-131626)
Workaround:
Create a new app lock mode profile and assign it to the device.
iOS
DEP devices can't authenticate with
BlackBerry UEM
during activation if the password contains special characters such as £. (EMM-126396)
Certificates from a two-key pair
Entrust
profile can't be installed on an
iOS
device. (EMM-120349)
On an
Android
9 device, if the Prevent Screen Capture security policy setting is disabled, the user can cut/copy/share data from a
BlackBerry Dynamics
app to a non-
BlackBerry Dynamics
app, even when data leakage prevention (DLP) is enabled via
Pixel
Launcher functionality. To ensure no data leakage, it is recommended that you enable the Prevent Screen Capture policy setting. (GD-36449)
You can't use the
Purebred
app and
Entrust
smart credentials at the same time on
iOS
devices with
BlackBerry Dynamics
. If you do, the
Purebred
certificate is imported on the incorrect user credential profile. (EMA-10637)
If your organization uses PKI and
Entrust
smart credentials together, users might need to enroll the PKI certificate multiple times on the same device (maximum of once per app). (GD-35783)
The 'Do not allow Android dictation' option in the BlackBerry Dynamics profile is used to stop dictation from keyboards, however there are certain keyboards that allow dictation through other channels. (GD-35440)
If your organization is using
Entrust
smart credentials on
iOS
, if you deactivate a device, the certificates still display as being imported on the Profiles screen. (EMA-10401)
After an
iOS
user imports a certificate, the user is taken through the import process again. (G3IOS-18108)
When you use a
Work space only
activation type to activate an
Android
8.0 device and you configure a
Wi-Fi
profile in
BlackBerry UEM
, the device user might not be able to connect to a
Wi-Fi
network. (EMA-9175)
Workaround
: In your organization's IT policy, select the “Allow changing
Wi-Fi
settings" option. Note that this issue is fixed in
Android
8.1.
When you use a
Samsung Knox
activation profile to activate an
Android
device and you select the "
Google Play
app management for
Samsung Knox Workspace
devices" option, the device will not activate and a
Google Play
services error will display. For more information, visit support.blackberry.com/community to read article KB46917. (EMA-9091)
On a
Samsung Knox
device, required
BlackBerry UEM
hosted apps might not display in the "Installed" section when the user opens
Google Play
on the device, even if they are actually installed. (EMM-95231)
You can't re-activate a
macOS
device if you remove the activation profile on the device. (EMM-92167)

Management console known issues

In a
BlackBerry UEM
and
BES5
integrated environment, if you delete a
BlackBerry
OS user from the BlackBerry Administration Service without selecting the "Delete the user and remove the
BlackBerry
information from the user’s mail system" option, and then you add the same user to
BlackBerry UEM
and activate a
BlackBerry
OS device for the user, the
BlackBerry
OS device information does not display in the
BlackBerry UEM
management console.
* When you create an Enterprise Connectivity profile for Android devices, you might not be able to add many apps to the 'Apps restricted from using BlackBerry Secure Connect Plus' section because of a database field size restriction. (EMM-145722)
* Attempting to upload an APK file for an internal app fails when using
AdoptOpenJDK
. (EMM-130584)
Workaround:
Use
Oracle
JDK instead.
* In the Apps section of the
BlackBerry UEM
management console, if you select an app category and then perform a search on the filtered results, after the search the app categories no longer display. (EMM-130581)
Workaround:
Sign out and then back into
BlackBerry UEM
.
* If a
BlackBerry UEM
administrator creates and assigns a user credential profile that is configured to use a native keystore CA connection, when a user opens a
BlackBerry Dynamics
app on an
Android
10 device, the following error message displays: "You are required to select a personal certificate. You may need to install it if the required one is missing. Please try again." This is due to a change with the KeyChain.choosePrivateKeyAlias API in
Android
10: https://issuetracker.google.com/issues/135667502
To support a native keystore connection for
BlackBerry Dynamics
apps on
Android
10 devices, in the user credential profile, the administrator must do one of the following:
  • Leave the Issuers field blank. The user will be prompted to select the certificate when it is required.
  • Specify an issuer and verify that the order of the relative distinguished name complies with the required format for
    Android
    10:. For example, "CN=core2-TKCA02-CA,DC=core2,DC=sqm,DC=testnet,DC=rim,DC=net". The full distinguished name must be provided in the same order as within the target certificate. Partial names such as "DC=rim,DC=net" are not allowed.
When a DEP connection fails because a new token is generated on the
Apple
DEP portal, you don't receive an event notification email message. (EMM-126723)
You can save an
iOS
app shortcut that has a space in the URL. (EMM-126319)
When you click Managed devices or All users, select a user, resize the window, and click the back arrow, the screen that displays is empty. (EMM-125716)
Workaround
: Click Managed devices or All users again.
A warning message does not display when you create an activation profile for an
Android
device and you do not select an activation type. (EMM-123636)
Workaround
: Select an activation type.
If you schedule a directory synchronization job for offboarding
Microsoft Active Directory
users, the synchronization job might fail.(EMM-116146)
Workaround
: Manually perform the directory synchronization job.
If you change the settings of a SCEP profile or user credential profile based on a native keystore, users are not prompted to enroll the certificates again and only new certificates receive the updated settings. (GD-37857)
Workaround
: Delete the profile and create and assign a new one to apply the new settings.
In the
BlackBerry Dynamics
profile, if you upload a list that has more than 10000 banned passwords, it is truncated at 10000 passwords. (EMM-101809)
When you are using the Advanced view in the management console, the device details page displays the incorrect Total internal storage amount for devices. (EMM-98304)
When you create an IT policy for
Android
devices, the "Force the device and work space passwords to be different" rule implies that the personal and work space passwords must be different. However the passwords can be the same, although they are separate. (EMM-91416)
You can't update the version of an app in the
BlackBerry UEM
console before the newer version of the app is available in
Google Play
. (EMM-89974)
Workaround
: Add the new version of the app to
Google Play
, wait for
Google
to publish the app and then add the app to the
BlackBerry UEM
console
When you delete a user that is enable to use
BlackBerry Workspaces
, the message that displays is misleading. (EMM-78607)
Workaround
: Log in to the console as a
BlackBerry Workspaces
Organization administrator who has an email address, remove the
BlackBerry Workspaces
service from the user, and then delete the user.

UEM Self-Service
known issues

The expiration period for access keys generated in
UEM Self-Service
is 24 hours instead of 30 days. (EMM-78769)