Skip Navigation

Known issues in 
BlackBerry UEM
 12.11 MR1

Items marked with an asterisk (*) are new for this release. 

Installation, upgrade, and migration known issues

* When you install the 
BlackBerry Workspaces
 plug-in with 
BlackBerry UEM
, the next time you open the UEM management console, an error message appears even though 
BlackBerry UEM
 and 
BlackBerry Workspaces
 are behaving as expected. (SNP-561)
Workaround:
 Dismiss the error message. It does not reappear.
If you have applied an IT policy pack on your organization's 
BlackBerry UEM
 12.10 MR1 server and you upgrade to 
BlackBerry UEM
 12.11, the new IT policies are not hidden even though the policy pack was installed on the 
BlackBerry UEM
 12.10 MR1 server. (EMM-129252) 
Workaround
: The policies will be hidden during the next policy sync or you can re-apply the IT policy pack manually.
You can't upgrade from 
UEM
 12.9 to 
UEM
 12.11 if the directory path contains brackets. For example, C:\Program Files (EXAMPLE)\BlackBerry\UEM\. (EMM-126340)
When you are migrating apps from 
Good Control
 to 
BlackBerry UEM
, if you have not configured a policy that contains an authentication delegate in 
Good Control
 but 
BlackBerry UEM
 has a policy that configures app A as an authentication delegate, when you migrate app B, the app is blocked from migrating because app A has not been migrated. If you then migrate app A, app B will still be blocked because it does not send a request to app A to see if it has been migrated. (GD-31948)
Workaround
: On the device, force the apps to stop and then restart app B.

User and device management known issues

Note that some of these issues are for the 
BlackBerry UEM Client
 and will be fixed in a future 
BlackBerry UEM Client
 release.
* You can't modify and save an enterprise connectivity profile that has 
iOS
 VPN on demand rules configured. (EMM-132378)
Workaround:
 Do not configure VPN on demand rules for 
iOS
 devices in an enterprise connectivity profile.
* If you modify an existing app lock mode profile for a 
Samsung Knox
 devices, the updated profile is not correctly updated on the device. (EMM-131626)
Workaround:
 Create a new app lock mode profile and assign it to the device.
iOS
 DEP devices can't authenticate with 
BlackBerry UEM
 during activation if the password contains special characters such as £. (EMM-126396)
Certificates from a two-key pair 
Entrust
 profile can't be installed on an 
iOS
 device. (EMM-120349)
On an 
Android
 9 device, if the Prevent Screen Capture security policy setting is disabled, the user can cut/copy/share data from a 
BlackBerry Dynamics
 app to a non-
BlackBerry Dynamics
 app, even when data leakage prevention (DLP) is enabled via 
Pixel
 Launcher functionality. To ensure no data leakage, it is recommended that you enable the Prevent Screen Capture policy setting. (GD-36449)
You can't use the 
Purebred
 app and 
Entrust
 smart credentials at the same time on 
iOS
 devices with 
BlackBerry Dynamics
. If you do, the 
Purebred
 certificate is imported on the incorrect user credential profile. (EMA-10637)
If your organization uses PKI and 
Entrust
 smart credentials together, users might need to enroll the PKI certificate multiple times on the same device (maximum of once per app). (GD-35783)
The 'Do not allow Android dictation' option in the BlackBerry Dynamics profile is used to stop dictation from keyboards, however there are certain keyboards that allow dictation through other channels. (GD-35440)
If your organization is using 
Entrust
 smart credentials on 
iOS
, if you deactivate a device, the certificates still display as being imported on the Profiles screen. (EMA-10401)
After an 
iOS
 user imports a certificate, the user is taken through the import process again. (G3IOS-18108)
When you use a 
Work space only
 activation type to activate an 
Android
 8.0 device and you configure a 
Wi-Fi
 profile in 
BlackBerry UEM
, the device user might not be able to connect to a 
Wi-Fi
 network. (EMA-9175)
Workaround
: In your organization's IT policy, select the “Allow changing 
Wi-Fi
 settings" option. Note that this issue is fixed in 
Android
 8.1.
When you use a 
Samsung Knox
 activation profile to activate an 
Android
 device and you select the "
Google Play
 app management for 
Samsung Knox Workspace
 devices" option, the device will not activate and a 
Google Play
 services error will display. For more information, visit support.blackberry.com/community to read article KB46917. (EMA-9091)
On a 
Samsung Knox
 device, required 
BlackBerry UEM
 hosted apps might not display in the "Installed" section when the user opens 
Google Play
 on the device, even if they are actually installed. (EMM-95231)
You can't re-activate a 
macOS
 device if you remove the activation profile on the device. (EMM-92167)

Management console known issues

In a 
BlackBerry UEM
 and 
BES5
 integrated environment, if you delete a 
BlackBerry
 OS user from the BlackBerry Administration Service without selecting the "Delete the user and remove the 
BlackBerry
 information from the user’s mail system" option, and then you add the same user to 
BlackBerry UEM
 and activate a 
BlackBerry
 OS device for the user, the 
BlackBerry
 OS device information does not display in the 
BlackBerry UEM
 management console.
* Attempting to upload an APK file for an internal app fails when using 
AdoptOpenJDK
. (EMM-130584)
Workaround:
 Use 
Oracle
JDK instead.
* In the Apps section of the 
BlackBerry UEM
 management console, if you select an app category and then perform a search on the filtered results, after the search the app categories no longer display. (EMM-130581)
Workaround: 
Sign out and then back into 
BlackBerry UEM
.
* If a 
BlackBerry UEM
 administrator creates and assigns a user credential profile that is configured to use a native keystore CA connection, when a user opens a 
BlackBerry Dynamics
 app on an 
Android
 10 device, the following error message displays: "You are required to select a personal certificate. You may need to install it if the required one is missing. Please try again." This is due to a change with the KeyChain.choosePrivateKeyAlias API in 
Android
 10: https://issuetracker.google.com/issues/135667502
To support a native keystore connection for 
BlackBerry Dynamics
 apps on 
Android
 10 devices, in the user credential profile, the administrator must do one of the following:
  • Leave the Issuers field blank. The user will be prompted to select the certificate when it is required.
  • Specify an issuer and verify that the order of the relative distinguished name complies with the required format for 
    Android
     10:. For example, "CN=core2-TKCA02-CA,DC=core2,DC=sqm,DC=testnet,DC=rim,DC=net". The full distinguished name must be provided in the same order as within the target certificate. Partial names such as "DC=rim,DC=net" are not allowed.
When a DEP connection fails because a new token is generated on the 
Apple
 DEP portal, you don't receive an event notification email message. (EMM-126723)
You can save an 
iOS
 app shortcut that has a space in the URL. (EMM-126319)
When you click Managed devices or All users, select a user, resize the window, and click the back arrow, the screen that displays is empty. (EMM-125716)
Workaround
: Click Managed devices or All users again.
A warning message does not display when you create an activation profile for an 
Android
 device and you do not select an activation type. (EMM-123636)
Workaround
: Select an activation type.
If you schedule a directory synchronization job for offboarding 
Microsoft Active Directory
 users, the synchronization job might fail.(EMM-116146)
Workaround
: Manually perform the directory synchronization job.
If you change the settings of a SCEP profile or user credential profile based on a native keystore, users are not prompted to enroll the certificates again and only new certificates receive the updated settings. (GD-37857)
Workaround
: Delete the profile and create and assign a new one to apply the new settings.
In the 
BlackBerry Dynamics
 profile, if you upload a list that has more than 10000 banned passwords, it is truncated at 10000 passwords. (EMM-101809) 
When you are using the Advanced view in the management console, the device details page displays the incorrect Total internal storage amount for devices. (EMM-98304)
When you create an IT policy for 
Android
 devices, the "Force the device and work space passwords to be different" rule implies that the personal and work space passwords must be different. However the passwords can be the same, although they are separate. (EMM-91416)
You can't update the version of an app in the 
BlackBerry UEM
 console before the newer version of the app is available in 
Google Play
. (EMM-89974)
Workaround
: Add the new version of the app to 
Google Play
, wait for 
Google
 to publish the app and then add the app to the 
BlackBerry UEM
 console
When you delete a user that is enable to use 
BlackBerry Workspaces
, the message that displays is misleading. (EMM-78607)
Workaround
: Log in to the console as a 
BlackBerry Workspaces
 Organization administrator who has an email address, remove the 
BlackBerry Workspaces
 service from the user, and then delete the user.

UEM Self-Service
 known issues

The expiration period for access keys generated in 
UEM Self-Service
 is 24 hours instead of 30 days. (EMM-78769)