Real-time remediation at the edge in Workspace ONE UEM
- Last updated 10/01/2026
-
Picture three moments. A flight gate agent's ticket scanner stops working three minutes before boarding. A contact-center agent loses an hour of work when an app crashes from memory exhaustion. A remote worker files a third connectivity ticket this month because the VPN tunnel dropped and never reconnected.
Three different industries. Three different failures. One shared result: an issue on the device causes lost productivity, delayed deliverables, and frustrated employees. Here's how it usually plays out. When something breaks, the event gets logged on a remote server in the cloud. There, the system either decides on a fix or alerts IT. If it settles on a fix, it sends that fix back to the device to be applied. That means every error on the device has to make a round-trip to the cloud before it's resolved.
What if the fix happened right where the problem lives? At the recent Omnissa ONE event, we announced that a beta of real-time remediation at the edge in Workspace ONE UEM is now available, and we're inviting customers to join the beta and help us get it right.
What is real-time remediation at the edge
Real-time remediation at the edge watches for problems at the device's OS layer and remediates them immediately, directly on the device. No cloud round trip. No sync cycle. No ticket.
Three things set it apart from the remediation you know today:
- It runs where the problem is. Detection happens on the endpoint, with no server in the loop deciding what to do. There's nothing to wait for, and it keeps working even when the device is offline.
- It fixes in seconds. A crashed service is back up in the time it takes to run a command. When the print spooler stops, for example, it restarts in under two seconds end to end, including notifying the user.
- It's configured, not scripted. Admins pick prebuilt, tested commands for common cases. Scripting and other workflow actions cover the cases the framework doesn't handle yet.
How it works
Every remediation workflow follows the same four steps, and a single purpose-built component on the device owns each one:
- Event. The Event Sensor service subscribes to OS-level signals and reports every change in one consistent taxonomy: a service stops, a process crashes, a network adapter drops.
- Trigger evaluation. The Client Trigger Service (CTS) checks each event against the rule the admin configured. Only real matches proceed. This is what keeps a graceful app exit from firing the same workflow as a crash.
- Fix. The Workflow Engine, running inside Workspace ONE Intelligent Hub, runs a remediation command immediately.
- Report. Every step returns structured success or failure, rolled up to the console for audit and ROI reporting.
Here’s an example. In the workflow canvas, the admin picks the platform and Service State Change as the trigger event. Next, they set two filter conditions: the service name, and the state changed to Stopped. Then they add step one, the built-in Start Service command, and step two, a Hub notification titled "Print service restored." The workflow is ready to publish.
Proof it worked
Silent fixes only help if you can see them. In beta, the console captures every workflow execution as its own distinct run. Click into any run, and you get the on-device timeline: the exact event that fired, the trigger evaluation, and each step's start and result, down to the second.
That gives admins an audit trail per run, a way to track how effective a workflow really is, and the detail they need to triage the occasional failure.
What's in the beta
The beta runs on shared SaaS UAT environments. You can author and track event-based workflows on Windows across five event categories:
- Service: state change, created, deleted
- Process: started, exited, health state
- App user interface (UI) state: foregrounded, backgrounded
- Registry: entry change
- Network: created, deleted, state change
We expect limited and general availability by the end of 2026.
Join the beta
Beta participants get early access on shared UAT, direct access to the product team, and real influence on what lands in general availability and what comes next. Ready to shape the self-healing endpoint? Contact your Omnissa account team.