Skip to main content
August 31, 2026

Workspace ONE UEM 2607: Apple management upgrades

  • Last updated 08/31/2026
  • View Author Bio
    Pratul Mathur
    Product Manager

    Pratul is a Product Line Manager on the Apple UEM team at Omnissa, bringing over 14 years of experience in building and leading large-scale enterprise products.



     

Man in business-casual clothing working on a laptop in a bright modern transit or office space

Workspace ONE UEM 2607 marks another step forward in simplifying how organizations manage and deliver Apple experiences at scale.

This release helps IT teams simplify Apple management, accelerate deployments, and gain visibility across more devices and scenarios as Apple continues its shift toward automated, user-centric, and declarative management. New features streamline device lifecycle management, provide more control over onboarding, and expand modern app delivery, resulting in stronger overall Apple management in Workspace ONE.

Let's take a close look at what's new.

OS update management: DDM by default

Apple is moving away from the imperative mobile device management (MDM) commands traditionally used to manage operating system (OS) updates. As a result, Workspace ONE UEM now makes declarative device management (DDM) the default approach.

macOS and iOS updates are unified into a single Apple view, and new assignments automatically use the declarative model. Additionally, a new Auto Update option keeps devices on the latest major or minor release without requiring per-update assignments.

Updated OS Update dashboards under Device Updates provide visibility into install status and failure trends for each update, drawn from DDM status. Imperative methods remain available for teams during the transition period until deprecation is complete.

image_1788192150.png 

Want a closer look? Read our in-depth blog for the full walkthrough of the unified view, Auto Update, declarative assignments, and the new dashboards.

DDM assets: The missing pieces for silent account and service setup

DDM's power comes from composability. Configurations reference assets, and assets carry the content. Workspace ONE UEM did not support the Credential and Data Asset asset types that several DDM configurations require, preventing those configurations from working correctly. Both gaps are now filled.

Credentials - Username & Password

Account configurations like Exchange, lightweight directory access protocol (LDAP), Calendar Distributed Authoring and Versioning (CalDAV), Mail, and Screen Sharing all support DDM. However, without a way to deliver credentials alongside them, devices still prompted users for passwords that were supposed to be silent. 

The new Credentials - Username & Password asset closes that gap. Admins define a credential once and assign it, and Workspace ONE handles secure delivery to the device. If the password is left blank, the device prompts only for the password, with the username pre-filled. This is supported on iOS/iPadOS and macOS.

image_1788192340.png 

Data Asset

Some DDM configurations need a supporting file to do their job.  For example, a Services Configuration Files declaration delivers a configuration file to a managed background service on a Mac. There was no way to deliver that file declaratively.

The new Data Asset asset type lets admins upload it straight from the UEM console/ Workspace ONE UEM automatically hosts and delivers these assets to devices, allowing dependent configurations to function as intended.

image_1788192358.png 

macOS Registered Mode: DEX on co-managed Macs

Many organizations manage their Mac fleets with another MDM but aren’t ready to migrate yet. Until now, that meant waiting to add Workspace ONE's digital employee experience (DEX) monitoring.

Additionally, unmanaged devices—such as BYO MacOS devices used by contractors—have traditionally remained outside visibility. With Registered mode, these devices can now be included in Workspace ONE Experience Management, eliminating the need for an all-or-nothing approach and extending insights across more of the endpoint landscape.

Now admins can enable Registered mode for macOS from the Workspace ONE console, scoped to a full Organization Group or a Smart Group. Registered devices get everything DEX needs to measure and improve the Mac experience without a full enrollment, including Hub-delivered apps, scripts, sensors, and Freestyle workflows.

Organizations can now extend DEX to third-party-managed and unmanaged Macs as they standardize the experience across platforms.

image_1788192471.png 

 Enabling registered mode in the Workspace ONE console 

 App management: Freestyle Orchestrator and Vision Pro

App deployment now reaches two places it couldn't before: a flexible deployment engine and a new Apple device type. Both capabilities below are in Limited Availability.

Purchased apps in Freestyle workflows

Freestyle Orchestra lets admins build conditional workflows that sequence app installations, scripts, and profiles. Until now, those workflows couldn't include purchased apps, a gap for admins who wanted to deploy licensed paid apps as part of an automated sequence.

The Install App action in Freestyle now supports purchased apps for iOS. Admins pick from their purchased apps, the workflow requests a license at time of installation, and step-level status shows success or the exact failure reason, including when licenses run short.

Enabling registered mode in the Workspace ONE console 

image_1788192651.png 

Purchased apps on Apple Vision Pro

Apple Vision Pro is showing up in enterprise pilot use cases like design and field training and financial services walkthroughs.  But admins had no way to push managed apps to these devices. Users were left to pull apps from the public App Store on their own.

Now, admins can sync purchased visionOS apps from Apple Business and assign them to Vision Pro devices by Smart Group, the same way they do for iPhone and iPad. Custom in-house visionOS apps can be uploaded and distributed, too, and admins can install or remove apps per device for troubleshooting.

image_1788192667.png 

Platform SSO with Omnissa Access

Platform Single Sign-On (SSO) lets MacOS users:

  • Sign in with their organization's identity provider (IdP) credentials.
  • Keep their local account password synchronized with the IdP.
  • Unlocking single sign-on across apps and services.

Organizations can now use Omnissa Access as their identity provider for Platform SSO. With general availability, they can deliver a fully Omnissa-native SSO experience on macOS without a third-party IdP. Learn more on our blog.

Ready to explore 2607?

The latest Workspace ONE release delivers several major improvements for Apple management, including:

  • A cleaner, declarative-first approach to OS updates and account setup.
  • DEX support for co-managed Macs.
  • Freestyle support for purchased apps and Vision Pro.

These updates move device management, employee experience, and app deployment forward, all in the same release. Read the complete 2607 release notes.

Questions or help planning your upgrade? Your Omnissa account team is ready.

 

Back to insights

You are now being redirected to an external domain. This is a temporary redirect while we build our new infrastructure and rebrand our legacy content.

This message will disappear in 10 seconds

CONTINUE