What Changed

The VMware Workspace ONE CCF data connector has been promoted from Public Preview (isPreview: true) to General Availability (isPreview: false) in v3.0.1. The connector ingests enrolled device inventory and installed application details from the Workspace ONE Unified Endpoint Management (UEM) platform into Microsoft Sentinel, covering iOS, Android, Windows, and macOS managed endpoints.

The only functional change beyond the GA flag is a fix to a sample query: the graphQueriesTableName template variable was removed, and VMwareWorkspaceOneDevices is now referenced directly as a hardcoded table name in the sample queries.

Security Impact

No detection logic or ingestion pipeline was modified. This promotion signals that the connector is considered production-ready by Microsoft. Environments that held off deploying this connector due to its Preview status can now deploy with full Microsoft support. The data source supports device compliance tracking and unauthorized application discovery, relevant to Initial Access (T1078) and Defense Evasion detection scenarios involving unmanaged or non-compliant endpoints.

Affected Files

Solutions/VMware Workspace ONE/Data Connectors/VMwareWorkspaceOneConnector_CCF/VMwareWorkspaceOne_ConnectorDefinition.json
(packaging artefacts: 3.0.1.zip, ReleaseNotes.md, Solution_VMwareWorkspaceOne.json, createUiDefinition.json, mainTemplate.json)