Reference Architecture – Known Limitations
Mobile Access Management works alongside your MDM to deliver enhanced functionality across platforms like iOS, macOS, and Android.
Each of these ecosystems has unique restrictions and design choices that can affect the availability or behavior of certain features. As a result, some capabilities may vary by platform. Imprivata is committed to providing the best possible experience while accommodating each platform's built-in design.
Launchpads
Symptom
After upgrading to 7.5, customers who see Launchpads remain disconnected or fail to reconnect.
Explanation
Launchpad 7.5 includes updates to the cURL/TLS networking stack. In environments that perform HTTPS/SSL inspection, firewalls or security appliances may replace the MAM server certificate with an internally issued certificate.
After upgrading to 7.5, customers who see Launchpads remain disconnected or fail to reconnect should check for SSL inspection/MITM certificates with missing, unavailable, or invalid certificate-revocation information.
Remediation
When reviewing firewall or SSL-inspection rules, verify the MAM server hostname shown in the Launchpad installer download dialog for your environment, for example us.groundctl.com or uk.groundctl.com.
If SSL inspection is being applied to that hostname, review the inspection policy and certificate chain with the network/security team, or exclude the required MAM endpoint from SSL inspection.
A successful connection from a web browser does not necessarily rule out this condition, because the browser and Launchpad may validate the replacement certificate differently.
iOS
Symptom
iOS 27 devices fail during checkin when the workflow contains the Launch a Blank Page at Check In action.
Explanation
The Launch a Blank Page at Check In action is not compatible with iOS 27.
Resolution
For iOS 27 devices, remove the Launch a Blank Page at Check In action from their Workflow.
Symptom
Devices running iOS 27 that are newly provisioned into MAM may not display Battery Health and Cycle Count. Devices that are already provisioned into MAM and upgraded to iOS 27 will continue to report Battery Health and Cycle Count.
Resolution
Imprivata is investigating mitigation options within the Imprivata Locker app.
Symptom
After checking out a device successfully, if a user manually force quits the Imprivata Locker app by swiping the app off the screen, other attempts to use the Locker SSO (OIDC) login flow will result in failure. The user will land in the Imprivata Locker app without returning to the Epic Rover app. If a user manually navigates back to the Rover app, it will be stuck on a white screen.
Resolution
Imprivata is investigating mitigation options within the Imprivata Locker app.
Symptom
On iOS 27 and if configured, when prompted to Authenticate to Microsoft Apps (MSAL), the Passwords button may not appear above the keyboard, preventing users from autofilling their credentials. In this case, users must enter their credentials manually.
Resolution
Imprivata has not identified a solution or workaround for this issue at this time. We have submitted a high priority case with Apple and are working closely with them toward a resolution in a future release. If you are experiencing this issue in your environment, Imprivata encouragse you to submit feedback to Apple as well. Future updates will be posted here.
Symptom
When upgrading devices from iOS 26 to iOS 27 using a MAM workflow, the device may pause at the Liquid Glass pane in Setup Assistant, resulting in manual intervention.
Resolution
To suppress the Liquid Glass pane, configure an Update iOS with SkipKeys Standard Workflow.
Symptom
Pressing the side button of an iOS 27 device immediately after Check Out may result in 3-4 seconds of unresponsiveness after waking the display.
Mitigation
Avoid pressing the side button (the sleep/wake button) immediately after checking out the device. If you accidentally press the side button and the display turns off, press the side button again or tap the screen to wake the device. Allow 3–4 seconds for the screen to respond to touch.
Symptom
After checking out an iOS 27 device, icons on the Home Screen may not retain their position.
Resolution
Apply a Home Screen Layout using the Set Icon Arrangement action in a workflow or apply a Home Screen Layout using a configuration profile delivered by your MDM.
iOS 27 removes support of restriction profiles for iOS update delay.
This is a removal of support, not an ordinary deprecation.
Resolution
The recommendation from Apple is to use the declarative Software Update:Settings configuration in Omnissa Workspace ONE to set software update delays.
Update
Apple released iOS 26.6 on July 27th, 2026 which no longer exhibits these symptoms.
Imprivata has validated this release works as expected for check in and check out with all of the changes previously released in MAM to mitigate. There are no actions required to update your MAM configuration.
Symptom
Under certain conditions, devices running iOS 26 can kernel panic and spontaneously enter recovery mode during Check In. This issue is intermittent and is not reproducing consistently. A ticket is open with Apple and the investigation of the root cause is in progress.
Resolution
To mitigate the issue, ensure that:
-
MAM Server has been upgraded to 7.3.1 or later.
-
MAM Launchpads have been upgraded to 7.3.1 or later.
-
Imprivata Locker for iOS has been upgraded to 4.2.1 or later on all devices.
-
The Check In Workflow contains the Perform MDM Command action to Clear Passcode.
-
The Check In Workflow contains the On Failure action to Retry this workflow.
For more information on Workflows, see Standard Workflows for iOS.
Symptom
In certain conditions, you may see a new pane appear in Setup Assistant after a device has been upgraded to iOS 26 from iOS 18 or earlier. The new pane welcomes the user to iOS 26 and describes new features such as Liquid Glass and other user interface updates.
Resolution
Apple has introduced a new SkipKey to bypass this pane. The resolution is pending your MDM partners' update to Automated Device Enrollment (ADE) SkipKeys.
Symptom
During Check In, Locker iOS may display a black screen with an error message "Push notifications are disabled for this app", even though push notifications are enabled.
This issue occurs rarely and can occur regardless of how push notifications for the Imprivata Locker app are enabled (manually or by configuration profile).
Mitigation
To clear this error, restart the device and check it back in.
Symptom
Using the Set Wallpaper action to apply a Home Screen wallpaper to an iOS 26 device incorrectly applies it to both the Home and Lock Screens.
Using Set Wallpaper for the Lock Screen alone functions correctly, however applying a Home Screen always overrides the Lock Screen.
This issue is reproducible using both MAM and Apple Configurator for iOS devices running iOS 26 or later.
Resolution
There is currently no mitigation for this issue. Feedback has been filed with Apple.
Symptom
Device wallpaper may appear incorrectly sized in several scenarios:
-
After an upgrade.
-
When Workflows apply a wallpaper to a newly provisioned device.
Resolution
To resolve this issue, apply a new wallpaper size based on the device type.
If your environment is using Custom Options to assist with provisioning, note that the Launchpad Custom Options guidance has been updated.
In some cases this can also prevent Locker from launching, with an error in the Activity log like 'APNS Lock process cancel: Device token is unavailable.'
macOS
There are no known issues that affect macOS at this time.