Skip to main content
August 26, 2026

Top 8 new features in Workspace ONE UEM 2607

  • Last updated 08/27/2026
  • View Author Bio
    Lisa Matragrano
    Group Product Line Marketing Manager

    Lisa Matragrano is a group product line marketing manager for Workspace ONE UEM at Omnissa.

Young business woman working on a tablet computer while seated in a wheelchair.

Innovation here at Omnissa isn’t slowing down. The third major release of Workspace ONE Unified Endpoint Management (UEM) this year is here! The 2607 release of Workspace ONE UEM brings more flexible enrollment, modern Apple update management, and the launch of Printer management. Here's what's new. 

Modern printer management paves the way for broader IoT support

2607 introduces modern printer management that uses a message queuing telemetry transport (MQTT)-based communication layer to enable real-time command delivery, status updates, and alerting across distributed fleets at scale: 

  • Manage printers alongside every other endpoint: Printers now appear directly in the Device List View—no separate console section, no context switching. If you manage it with UEM, it's in the same place. 
  • Configuration and firmware management: Deploy certificate-based network connectivity profiles and keep printer firmware current. 
  • Orchestrate workflows from printer events: Critical alerts, like low toner or offline status, flow into Omnissa Intelligence where you can trigger automated workflows and act before users feel the impact. 

Read more about modern printer management here.

Apple device updates move to declarative device management

Apple has announced the deprecation of imperative software update commands. 2607 moves Apple OS update management to declarative device management (DDM), the modern, device-driven model  that is becoming standard for UEM and mobile device management (MDM).

The experience is cleaner and more capable with:

  • One unified Apple view: The separate macOS and iOS update lists are combined into a single Apple view, with a clearer "Platform" column and filters consistent with the rest of the console.
  • True auto-update enforcement: A new auto-update control, built on DDM software update enforcement, lets admins automatically keep devices on the latest compatible major or minor OS release using Apple's Global Device Management Framework (GDMF) feed.
  • Declarative by default: New update assignments default to the declarative path. Admins who still need imperative behavior can enable it with a clear toggle, along with an in-console notification about its upcoming deprecation.

Underpinning the cutover, 2607 also expands the DDM foundation with new declarative assets and declarations—including username/password credential assets—so more configurations can be delivered using DDM. The result is more reliable update enforcement, less drift, and a head start on  Apple’s future device management model.

image_1787777042.png image_1787777043.png 

Deploy DEX on third party managed macOS devices

Contractors, bring-your-own (BYO) Macs, and Digital Employee Experience (DEX)-only use cases call for a lighter footprint. With  2607, Registered mode comes to macOS, joining the registered-mode experience already available on other platforms.

Admins enable macOS Registered mode and choose the scope: all macOS devices in an organization group or a targeted set via smart group assignment. Registered mode supports Hub-targeted resources, such as apps, sensors, scripts, and Freestyle workflows, which is enough to deploy the DEX agent, run check-in/check-out scripts, and deliver everyday automation without taking full control of the device.

Omni, our agentic assistant, steps out of the sidebar

2607 brings the Omni agentic experience into the UEM console as a full-page app. Until now, Omni appeared only as an embedded view. The richer full-page experience gives admins more room to work with the assistant directly inside the console.

Crucially, access is governed, not open by default. The full-page Omni app is wired into UEM's role-based access control and honors the Omni permissions defined in Omnissa Connect, ensuring only administrators explicitly granted the role can open it.

image_1787777044.png 

Deliver internal apps to Windows devices at the edge with relay servers

For distributed organizations, such as retail chains, branch networks, warehouses, pushing every app install over the internet to thousands of endpoints is slow, bandwidth-hungry, and fragile in low-connectivity sites. Until now, Relay Servers in Workspace ONE UEM only carried Product Provisioning content. With 2607, relay server support extends to internal applications (and Windows updates) on Windows devices, so app content can be staged locally and delivered from inside the network.

The payoff is concrete: faster installs, dramatically less internet egress, and reliable delivery to devices in low-bandwidth or intermittently connected locations. Admins stay in control with a per-app toggle on the Internal Applications screen to deliver a given app via Relay Server (off by default), a global setting to opt the environment out entirely, and a per-app view of the Relay Servers associated with each application.

This release targets Windows internal apps and Windows updates using pull relay servers, with additional resource types and platforms (including Android and macOS) planned for future phases. For the large, geographically distributed fleets that have been asking for exactly this—think hundreds of stores or sites served from local infrastructure—it removes a real barrier to rolling apps out at scale.

Next-gen Windows management supports seamless enrollment

Many large Windows estates still run on System Center Configuration Manager (SCCM), and for years, IT teams were stuck with a painful “rip and replace” migration to Workspace ONE UEM because co-management wasn’t an option. Today, co-management with next-gen Windows management in Workspace ONE UEM bridges that gap, but it  hasn't completely solved the friction of going fully to cloud-native modern management.

Moving a device entirely to Open Mobile Alliance Device Management (OMA-DM) historically required full device re-enrollment, meaning the final step toward modern management remained a disruptive hurdle for IT. With 2607, Workspace ONE UEM removes that barrier with step-up enrollment for Windows.

Admins can configure an organization group to enroll new Windows devices in Registered mode, providing immediate visibility with scripts, sensors, and reporting, or in Hub-managed mode, which delivers full management through the Intelligent Hub without committing to OMA-DM on day one. When the time is right, admins promote individual devices or a subset to full OMA-DM directly from Device Details or Device List view,  like the existing "Migrate to Multi-user" action.

The promotion happens without a device wipe or additional end-user action. OMA-DM capabilities switch on automatically, server- and client-side, and the console unlocks full management for those devices.

For organizations starting fresh in Hub-managed mode, 2607 allows for automatic step-up to OMA-DM on user sign-in. This is important because OMA-DM enrollment requires a signed-in user. Admins can configure this once at the organization group level and let the transition happen naturally as users log in.

For organizations transitioning off of SCCM or co-managing alongside other tools, this is a measured, low-risk path to modern management on Windows, empowering IT to migrate devices on their own timeline.

Enhance Windows device onboarding with Focused Enrollment

Fully setting up a Windows device after enrollment has always depended on end users  completing onboarding instead of skipping ahead before critical apps, profiles, and scripts finish running. In practice, that doesn't always happen. And until now, users had little visibility into what was actually happening during setup. Workspace ONE UEM 2607 addresses both sides of this problem with Focused Enrollment for Windows.

On the user side, the Post-Enrollment Onboarding (PEO) screen now shows real-time, step-by-step progress for every onboarding workflow running on the device, including apps, profiles, and scripts. A progress bar shows how much of the setup is complete and highlights any tasks that are still in progress or require attention.

On the admin side, Focused Enrollment lets IT lock the PEO screen until setup is complete, preventing users from bypassing the setup process:

  • The "Get Started" button remains disabled until the onboarding is complete.
  • Keyboard shortcuts are blocked to prevent users from navigating away.
  • Task Manager is disabled to prevent the onboarding process from being interrupted.

If IT needs to intervene, a device-specific PIN generated at enrollment and available in the UEM console, unlocks the screen without waiting for onboarding to complete.

Focused Enrollment is disabled by default, so existing deployments are unaffected. For shared devices, high-security environments, or any scenario where a half-configured device is a real risk, it's just a few console settings away.

image_1787777453.png 

Pause device management actions with one click in Freeze Mode

When an admin runs a pilot on a set of VIP devices or troubleshoots a device being flooded with install and remove requests, blocking resources one by one is painful. 2607 introduces Freeze Mode, letting admins pause UEM-generated device management actions at the device level.

While a device is in Freeze Mode, Workspace ONE pauses auto-assigned installs and removals, along with any workflows that haven’t started yet.  Assignments remain unchanged, the  device stays enrolled , and all paused work resumes automatically after the admit lifts Freeze Mode and the device checks in.

Admins can still force specific actions from the console when needed, and every change is captured in the event log. An MDM application programming interface (API) is available to place and remove devices from Freeze Mode programmatically.

image_1787777047.png 

 Stay current 

Full feature documentation for Workspace ONE UEM 2607 is available on Omnissa Docs. Questions or deployment help? Connect with peers on Omnissa Community, or reach out to your Omnissa account team to plan your rollout.

Back to insights

You are now being redirected to an external domain. This is a temporary redirect while we build our new infrastructure and rebrand our legacy content.

This message will disappear in 10 seconds

CONTINUE