Omnissa ONE 2026: Elara, Agents and an MCP Server for Workspace ONE
My recap of the announcements from Omnissa ONE in Orlando
Disclosure: I’m an Omnissa Tech Insider. The opinions below are my own.
Omnissa ONE 2026 in Orlando (September 28-30) came with a lot to unpack. A new CEO took the keynote stage on day two of his new job, and the company put out a run of announcements built around one theme: an autonomous workspace where AI agents do real work, with IT still in control.
I already wrote about Amit Singh’s “The Agentic Endpoint” post. This is the follow-up: what was actually announced, what’s available now, and what I’m most interested in.
Omnissa Elara: governing AI on your endpoints
The headline announcement is Omnissa Elara, which Omnissa describes as an authority layer for AI. Its principle is “control before consequence.” It connects the systems you already run (identity, endpoint, security and ITSM) so that actions taken by people and AI agents can be understood, approved and recorded.
Omnissa’s announcement and the Reworked coverage describe four things Elara does:
- Finding shadow AI. It looks for AI apps, models and agents that aren’t on your approved list.
- Setting rules for AI use. Through the Omnissa AI Gateway, you decide which people, apps and agents can reach which AI models, and you can track token usage.
- Checking changes before they happen. Before a change goes through on a company system, it checks for conflicts, scheduled freezes and dependencies, then approves the change, limits it or sends it to the person with authority to sign off.
- Keeping a record. It logs what happened, who approved it and what it touched, so the sequence can be repeated later.
Brian Link, Product CTO (Americas) and Head of Platform, put the reasoning well: “The most important questions rarely live in any one system. They live between them.”
Status: Elara is in beta, with a waitlist and an interactive demo tour. Pricing and detailed specs weren’t published in what I read.
A hosted MCP server for the Omnissa platform (generally available)
This is the announcement I expect to matter to admins the most day to day. Omnissa announced a hosted Omnissa MCP server, built on the Model Context Protocol. Admins can connect an AI client of their choice, such as Claude or Copilot, directly to Workspace ONE UEM and other Omnissa services. Omnissa’s own example of where this is headed is an admin asking “What needs attention today?” instead of clicking through multiple screens.
The important part is the guardrail: every action taken through an AI client inherits the same role-based access controls and audit trail admins already rely on. Because it’s a standards-based protocol, it also avoids locking you into one AI vendor.
Status: generally available.
More autonomous endpoint management in UEM
The same set of UEM announcements includes:
- Smart Groups 2.0. Multi-step rule building with sensor values and nested AND/OR logic, so you can target devices by how they behave instead of static lists or custom scripts.
- Smarter phased deployments. Rollout progression can now use digital experience metrics such as crash rates and startup performance, along with reusable rollout templates.
- Dual admin approval. A second reviewer for defined resources before changes take effect. This is listed as coming.
- Root-of-trust resource signing. Makes sure only verified, unmodified resources install on endpoints. Also listed as coming.
New agents for IT operations
Omnissa announced three IT operations agents, each with a human in the loop:
- Digital Employee Experience (DEX) Agent. Investigates employee experience issues, finds root causes, and recommends fixes using playbooks and session history.
- Workspace ONE Vulnerability Defense Agent. Autonomously reviews and prioritizes vulnerabilities, prepares patching actions and approves deployment, with human-in-the-loop guardrails.
- Windows App Lifecycle Agent. Packages and tests applications before an administrator reviews them.
Horizon and Cloud PC
- Horizon Delegate. Lets users hand tasks to their own persistent agent inside their virtual desktop session. It acts with the user’s approved identity and permissions and can keep working when the user is disconnected. Expected as limited availability in Horizon 2609.
- App Packaging Agent. Continuously finds app updates and builds packages based on IT approvals. Expected as beta in App Volumes 2609.
- Omnissa Cloud PC. A turnkey cloud PC service that bundles compute, unified endpoint management, digital employee experience and Horizon Cloud DaaS. It launches on AWS first, with other hyperscalers planned. No general availability date was given.
What’s available now, and what isn’t
| Announcement | Status |
|---|---|
| Omnissa MCP Server | Generally available |
| Omnissa Elara | Beta (waitlist) |
| Horizon Delegate | Limited availability, Horizon 2609 |
| App Packaging Agent | Beta, App Volumes 2609 |
| Dual admin approval, root-of-trust signing | Coming |
| Omnissa Cloud PC | Announced, on AWS first, no date |
| DEX, Vulnerability Defense and Windows App Lifecycle agents | Announced, no dates published |
My take
I’m most excited about Elara, and it’s because of shadow AI. I’ve wanted a way to see what people are actually running on their devices, and this is the first announcement I’ve seen that goes straight at that problem. Discovery of unapproved AI apps and agents, plus rules for what they can reach, is exactly the visibility Singh’s Discover-Decide-Contain-Prove framework starts with. It’s still beta, so I’ll be watching how deep the discovery really goes and how well it fits with the tools we already run.
The MCP server is the practical win today. Letting admins use the AI tool they already like, with the same role-based access controls and audit trail they already rely on, is the right way to bring AI into daily operations. It’s generally available, so it’s the thing you can try first.
I’ll also be watching the agents. The Vulnerability Defense Agent is interesting because patching is where a lot of IT time goes, and the release says it runs with human-in-the-loop guardrails. I’d want to see exactly where those guardrails sit before trusting it with deployments. No dates have been published for most of these agents, so I’d treat them as direction, not a plan.
The overall message is consistent: agents are coming to managed devices, and Omnissa wants to be the layer that governs them. Some of this is shipping now, some is in beta, and some is still an announcement. That’s a fair state for a first showing. I’m looking forward to seeing which pieces land first.
Sources
- Omnissa unveils AI innovations for autonomous IT workspaces (press release)
- Introducing Omnissa Elara
- The building blocks of autonomous endpoint management
- AI-ready workspaces with Omnissa Horizon
- Reworked: Elara targets shadow AI, new agents automate IT
What are you most interested in? I’d like to hear it in the comments.



You must be logged in to post a comment.