...
You may encounter the following error when saving Microsoft Conditional Access configuration in Workspace ONE UEM for the first time after 12th December 2021.“Save failed: An error has occurred. This error has automatically been saved for further analysis. Please contact technical support” OR“Save failed: Azure AD integration failed” Verbosed Web Console logs will show the following log statements associated with this issue 2021/12/23 16:12:33.516 HS00MS00 000a0a00-0000-0000-0000-000000000000 [0000000-0000000] (28) Debug AW.ServiceProxies.ConditionalAccess.ConditionalAccessClient+<>c__DisplayClass8_0+<<GetAccessTokenAsync>b__0>d.MoveNext Sending Access token request completed for URI: https://api.sandbox.data.vmwservices.com/auth/console/token 2021/12/23 16:12:33.516 HS00MS00 000a0a00-0000-0000-0000-000000000000 [0000000-0000000] (28) Debug AW.ServiceProxies.ConditionalAccess.ConditionalAccessClient+<>c__DisplayClass8_0+<<GetAccessTokenAsync>b__0>d.MoveNext Http response status: Unauthorized. Version Identified Workspace ONE UEM 2007
When setting up the integration in Workspace ONE UEM, the system performs authentication against Workspace ONE Intelligence. Due to an invalid authorization token, the integration fails. VMware engineering identified an issue where an incorrect parameter was being used to issue this token.
If the integration has been set up before 12th December 2021, your environment is not impacted. If you are setting up the integration after 12th December 2021, you may see the above error, and will not be able to complete the integration.
Our Product team has been notified and is working to address this issue in an upcoming release of Workspace ONE UEM. Additionally, the issue is addressed in patches for existing versions of Workspace ONE UEM as noted below Impacted VersionPatch containing fix2111Workspace ONE UEM 21.11.0.7 patch and above2109Workspace ONE UEM 21.9.0.21 patch and above2105Workspace ONE UEM 21.5.0.44 patch and above2102Workspace ONE UEM 21.2.0.31 patch and above 2101 Workspace ONE UEM 21.1.0.31 patch and above2011Workspace ONE UEM 20.11.0.43 patch and above 2010Workspace ONE UEM 20.10.0.26 patch and above (SaaS Only patch) Please refer to the WS1 UEM Console Releases KB for a list of all supported versions and their availability for SaaS and On-premises customers. Action Required Shared SaaS: None. VMware Cloud Operations will proactively apply patches to all Shared SaaS environments on impacted versions. The patch process will have no downtime and will be performed during business off-hours as determined by the environment region. Dedicated SaaS: If you are running into this issue, please request the patching of your environment on a specific date and time by contacting Workspace ONE Support. On-premise: Deploy the patch associated with the supported version of Workspace ONE UEM that your environment is on.