Skip to content

2026

Release notes for the August, 23 2026 update

Update Version 4.1.202608181429

Extensions

  • Added a hostname verification option for the Operational Service on the Peer Node configuration screen, allowing connections when SSL certificate hostnames do not match the configured peer node.

  • Added group separators to the Peer Node configuration screen for clearer organization of Operational Service, Gateway, HTTP Proxy, Main Node, and Local Storage settings.

Security

Components Update
  • Updated application WEB container to the latest version.

  • Updated internal scripting language to the latest version.

  • Updated data handling component to the latest version.

  • Updated Code Editor component to the latest version.

  • Updated REST API Documentation component to the latest version.

  • Updated dashboard charts component to the latest version.

  • Updated client side markdown toolkit to the latest version.

Fixes

  • Fixed the issue with extending access requests to the time that includes zero hours, minutes or seconds.

  • Fixed the issue with localization of messages on the RDP proxy initialization screen.

  • Fixed the issue with canceling Save on Alias screen prevented further save actions.

  • Fixed the issue with the LDAP Import query had to include a wildcard to query data from the LDAP server.

  • Fixed the issue with removing periodic tasks scheduled for the asset when deleting the asset.

  • Fixed the issue with orphaned tasks scheduled for deleted assets.

  • Improved system log reporting about the replication errors to balance information in the message and the volume of reporting.

Release notes for the August, 16 2026 update

Update Version 4.1.202608141714

Extensions

  • Added support for TOTP challenge during authentication in WEB HTTP sessions.

  • Added support for multi-page wizard authentication in WEB HTTP sessions.

  • Added the option to create the initial tenant from a backup during deployment setup.

  • Added the option to disable job execution on the replication peer.

  • Improved the user experience on the tenant creation screen with clearer labels, helpful hints, and selection options.

Security

Components Update
  • Updated application WEB framework to the latest version.

  • Updated WEB HTTP Sessions driver to the latest version.

Fixes

  • Improved performance and stability of WEB HTTP sessions.

  • Improved the performance of back-end workflow activities.

  • Fixed the issue where notification errors could block subsequent notifications.

  • Fixed the issue with deep deletion of containers with complex hierarchies of nested containers.

  • Fixed the issue with the entity class label in request action notifications.

  • Fixed the issue with authentication when some configured directories have incomplete settings.

  • Fixed the issue with mass enabling assertion based SMTP configuration.

  • Fixed the issue with reusing password reset jobs across consecutive executions, ensuring Windows endpoints are properly released from workers after security context changes.

  • Improved stability of live node-to-node replication.

  • Fixed the issue with replicating cached or proxied objects during live node-to-node replication.

  • Fixed the issue with replicating updates involving complex object relationships.

  • Fixed the issue with preserving data modified in a peer tenant during replication synchronization.

  • Fixed the issue to ensure that replication synchronization and incremental backup restore delete only data created by the originating node.

  • Fixed the issue with copying tenant master keys during replication synchronization.

Release notes for the August, 11 2026 update

Update Version 4.1.202608111743

Security

Components Update
  • Updated application WEB framework to the latest version.

  • Updated dashboard charts component to the latest version.

  • Updated Unit test component to the latest version.

  • Updated HTTP communication component to the latest version.

Fixes

  • Fixed the issue with slow mouse performance in WEB HTTP Sessions

  • Optimized action request workflow component for deployments using limited-capacity back-end databases.

  • Optimized network management component for deployments using limited-capacity back-end databases.

  • Optimized import component to accommodate larger volumes of imported details and limited-capacity databases.

  • Optimized import component for deployments using limited-capacity back-end databases.

  • Fixed the issue with displaying asset name in the event report about deleted asset instead of asset id.

  • Fixed the issue with importing assets from large CSV files.

Release notes for the August, 9 2026 update

Update Version 4.1.202608071759

Extensions

  • Added support for credential injection in HTTP web sessions for web portals with two-step login workflows.

  • Added GUI and server-side message translations for Latin American Spanish, Simplified Chinese, and Traditional Chinese.

  • Improved GUI and server-side message translations for German, Spanish, French, Italian, Japanese, Portuguese, Russian, and Ukrainian.

  • Improved performance of the session connection screen for sessions established using native desktop or mobile clients.

  • Improved the stability of credential injection for zero-trust HTTP web sessions connecting to web portals.

Security

  • Improved full backup security by removing the encryption key from backup files, preventing backups from being restored without the break-glass key.

  • Added a break-glass key field when creating a new tenant from a backup.

Components Update
  • Updated application WEB framework to the latest version.

  • Updated dashboard charts component to the latest version.

  • Updated REST API documentation component to the latest version.

  • Updated internal scripting run time component to the latest version.

  • Updated document model sanitation component to the latest version.

  • Updated client side markdown library to the latest version.

  • Updated client side IP address management library to the latest version.

  • Updated Code Editor HTML language component to the latest version.

  • Updated Code Editor Markdown language component to the latest version.

  • Updated Code Editor View component to the latest version.

  • Updated network streaming component to the latest version.

  • Updated server side markdown toolkit to the latest version.

Application build process update
  • Updated application version generation to use the EST/EDT time zone.

Fixes

  • Fixed the issue where restoring from an incremental backup did not delete objects, such as permissions, that had been deleted from the original tenant.

  • Fixed the issue where the replication synchronization process did not delete objects that had been deleted from the synchronization source.

  • Fixed the issue with the proportions of the top icons on the application dashboard at certain screen sizes or when displaying long labels.

  • Fixed the issue with periodic execution of Import Service jobs.

  • Fixed the issue with periodic execution of Import Entra ID Users jobs.

  • Fixed the issue with un-scheduling periodic import jobs when deleting an Import Configuration.

  • Fixed the issue with availability RDP, SSH, HTTP and PowerShell Proxy configurations in the sub-sites.

  • Fixed the issue with availability of the retention configuration in the sub-sites.

  • Fixed the issue with the option to edit and to verify trust of the peer node configurations inherited from the top level site.

  • Optimized action request workflow performance in deployments using limited-capacity back-end databases.

  • Optimized import data structure for deployments using limited-capacity back-end databases.

Release notes for the August, 2 2026 update

Update Version 4.1.202607311901

New Features

Added support for approving and rejecting action requests by email

Approvers can now approve or reject action requests directly by replying to the notification email, simplifying the approval process. Rejection responses can include a comment explaining the decision.

Extensions

  • Added support for UDP transport for sessions established using native desktop and mobile RDP clients.

  • Added Establish Trust and Establish Entra ID Trust options to SMTP and IMAP configurations.

  • Added the option to display all fields of the selected asset during break-glass recovery to provide additional context for secret fields.

  • Added the option to browse the site and container hierarchy during break-glass recovery to simplify asset discovery in backups.

  • Added the option to search assets by ID

Security

Components Update
  • Updated server side run time framework to the latest version.

  • Updated application WEB framework to the latest version.

  • Updated dashboard chart component to the latest version.

  • Updated Code Editor view component to the latest version.

  • Updated Oracle RDBMS driver to the latest version.

  • Updated Informix driver to the latest version.

  • Updated MySQL driver to the latest version.

  • Updated MariaDB driver to the latest version.

  • Updated low level database replication and restore operations to the latest version to support future updates of database access component.

  • Updated HTTP communication toolkit to the latest version.

  • Updated IBM i driver to the latest version.

Application build process update
  • Update frontend build environment to the latest version.

  • Updated WEB application build framework to the latest version.

Fixes

  • Fixed the issue with displaying asset hidden fields on the safe link display screen.

  • Fixed the issue with the safe link display screen stays open after safe link is expired.

  • Fixed the issue with RDP proxy connection through remote Peer node.

  • Fixed the issue with restoring personal sites from backup.

  • Fixed the issue with the process display labels on the node monitoring screen.

  • Fixed the issue where Ask AI User Defined Prompts did not work in newly created tenants. This fix also resolves the issue for existing tenants affected by the same problem.

  • Fixed the issue with the excessive logging on the browser console for the WEB sessions started based on the access request.

  • Fixed the issue with session intelligence termination event details.

  • Fixed the issue with the asset viewer can download and upload files during the session based on the user access profile settings.

  • Fixed the issue with the last joined session set the size for all previously established WEB sessions.

  • Fixed the issue where long names in the Session Events report caused the report to extend beyond the screen boundaries.

  • Fixed the issue with starting on-demand archive process when background archival process was already scheduled.

Release notes for the July, 26 2026 update

Update Version 4.1.202607250358

New Features

Added session management permissions for asset workflow approvers.

This update allows the application to automatically grant dedicated permissions to users who are designated as approvers for asset assigned workflows. Users designated as workflow approvers can now perform the following actions without requiring additional administrative permissions including the option to establish sessions or unlock secret fields:

  • Access the web console with no permissions other than workflow approver.
  • Search for, browse, and view assets associated with assigned workflows.
  • View remote sessions associated with assigned workflows.
  • Join or terminate active sessions associated with assigned workflows.
  • Play back session recordings and review session events for completed sessions associated with assigned workflows.

The workflow approver role enables organizations to separate access governance from privileged access. Approvers can review requests, monitor active sessions, join or terminate sessions when necessary, and audit completed activities without receiving privileged access to the managed assets themselves.

This approach supports the principle of least privilege, strengthens segregation of duties, and helps organizations meet security and compliance requirements by ensuring that those responsible for approving and overseeing privileged access cannot use that access for administrative tasks.

Extensions

  • Added enforcement for exclusive action requests.

  • Added approval expiration for pending workflow requests.

  • Added customizable email templates for request submission, approval, and rejection notifications.

  • Added support for archiving Sessions and Session Events according to the configured session retention policy.

  • Added support for archiving historical backups according to the configured backup retention policy.

  • Added Verify Trust option for Entra ID configurations to load Microsoft certificates into the tenant store.

  • Added support for interactive script execution on remote assets that prompts users to enter additional script parameters through a graphical user interface.

  • Added a link to the asset on the My Requests and Approvers List.

  • Added the option to override default WEB console idle timeout for individual sessions using access profile setting.

Security

Components Update
  • Updated application WEB framework to the latest version.

  • Updated dashboard chart component to the latest version.

  • Updated client side markdown toolkit to the latest version.

  • Updated IBM i driver to the latest version.

Application build process update
  • Updated build environment including run time framework, build toolkit and repository actions to the latest version.

  • Reduced build log verbosity to simplify troubleshooting and improve the visibility of errors and warnings.

Fixes

  • Fixed the issue preventing Asset Manager users from terminating active sessions.

  • Fixed the issue with Asset Access action label displayed on the list of requests.

  • Fixed an issue with QR codes being difficult to scan during TOTP enrollment.

  • Fixed the issue with incorrect level number displayed for the approved, completed or rejected requests on the Request View and Requests List screens.

  • Fixed the issue with password reset scripts for MySQL and MariaDB.

  • Fixed the issue with initializing SSH Proxy in new tenant.

  • Fixed the issue with mass enabling Assertion based Entra ID configurations.

  • Fixed the issue with reporting low level communication errors when processing Cloud AI queries.

  • Fixed the issue with interactive password reset screen to enable the process using initial form configuration with generated password.

Release notes for the July, 19 2026 update

Update Version 4.1.202607172047

Extensions

  • Added transcript recording support for Microsoft Graph sessions using native PowerShell clients.

  • Added asset information and access request management commands to the application command-line interface.

  • Expanded support for public key cryptographic algorithms when connecting to Windows RDP hosts using native desktop and mobile RDP clients.

  • Added support for high-availability Domain Controller configurations for LDAP password reset operations to improve Active Directory password reset reliability.

  • Added support for Personal Sites in the browser extension, enabling users to search for and autofill credentials from their personal vaults.

  • Added the option for the WEB HTTP Sessions to fill fields on the login forms that rely on post input events to continue with the process.

  • Added the option to regenerate and download SSH proxy server private key from the WEB Console GUI.

  • Added the option to regenerate and download RDP proxy server certificate from the WEB Console GUI.

  • Added the option to regenerate and download PowerShell proxy server certificate from the WEB Console GUI.

  • Added pagination support to the list of backups on the backup management screen.

  • Added LDAP HA Administrator asset type to support password reset scenario for multiple LDAP servers deployed in HA architecture.

  • Added multi-valued URL field with the option to verify trust to import remote server certificate into the tenant key store.

Security

Components Update
  • Updated application WEB framework to the latest version.

  • Updated application WEB container to the latest version.

  • Updated database access component to the latest version.

  • Updated WEB HTTP Sessions driver to the latest version.

  • Updated client side document sanitation component to the latest version.

  • Updated unit test framework to the latest version.

  • Updated PDF toolkit to the latest version.

  • Updated cryptography library to the latest version.

  • Updated cryptography utilities to the latest version.

  • Updated Duo Security driver to the latest version.

  • Updated Code Editor markdown language component to the latest version.

  • Updated dashboard chart component to the latest version.

Fixes

  • Fixed the issue with the Access option is available for the HTTP proxy enabled assets on the asset view page.

Release notes for the July, 12 2026 update

Update Version 4.1.202607102103

New Features

Added support for Microsoft Graph sessions using native PowerShell clients

Added support for establishing Microsoft Graph sessions from native PowerShell clients, enabling secure, Zero Trust access to Microsoft Graph APIs for managing Microsoft Entra ID, Azure, and Microsoft 365 environments.

The integration supports credential injection, role-based access control (RBAC), access request and approval workflows, session suspension and termination, and session logging for auditing and compliance.

Added Personal Site support for application users

Added support for Personal Sites, allowing application users to securely store and access personal non-shared credentials and other sensitive information in isolated areas of the vault.

Assets stored in Personal Sites integrate with browser extensions to securely fill login forms on web portals. Sensitive information can also be shared using short-lived, secure Safe Links.

Personal Sites promote better security hygiene by providing users with a secure location to store web portal credentials and other sensitive information that falls outside the organization's centrally managed accounts and policies.

Site administrators can explicitly grant users permission to provision and use Personal Sites, enabling organizations to control their deployment and adoption across the enterprise.

Extensions

  • Added descriptive labels to tasks on the asset view screen to distinguish whether each task runs on the main or related asset, and to indicate its trigger type.

  • Added the option for Web HTTP sessions and the browser password autofill extension to use default field names in addition to the field names defined by the asset's page schema by preceding page schema entries with the plus sign (+).

  • Added the option to retrieve the decrypted history of an asset field value from backup during Break Glass access, limited to a specified number of previous values.

  • Added support for Elliptic Curve (EC) public keys when connecting to Windows RDP hosts using native desktop and mobile RDP clients.

Security

Security Improvements
Components Update
  • Updated application WEB framework to the latest version.

  • Updated application WEB container to the latest version.

  • Updated database access component to the latest version.

  • Updated data processor component to the latest version.

  • Updated SSH client, server and proxy components to the latest version.

  • Updated internal scripting component to the latest version.

  • Updated Code Editor view and state components to the latest version.

  • Updated PostgreSQL driver to the latest version.

  • Updated network streaming component to the latest version.

  • Updated Informix driver to the latest version.

  • Updated client side markdown processing component to the latest version.

Fixes

  • Fixed the issue that caused duplicate site roles to be displayed on the current user information card in the login toolbar when accessing sub-sites.

  • Fixed the issue with duplicated AI Manager role on the site roles management screen.

  • Fixed the issue with extra permissions allowed to unprivileged users for certain operations in the vault.

  • Fixed the issue with the Assets by Type dashboard chart displaying assets from the sub-sites.

  • Fixed the issue where server-side errors displayed in the Web Console could cause users to be logged out.

  • Fixed the issue where the Web Session control box remained on the screen longer than necessary after session initialization or after it was no longer in use.

  • Fixed the issue where Web HTTP sessions and the browser password autofill extension continued to use default field names in addition to the field names defined by the asset's page schema.

  • Fixed the issue with displaying the list of backups with incomplete or broken individual backups.

Release notes for the July, 5 2026 update

Update Version 4.1.202607021637

New Features

Added on-demand data synchronization between replication nodes

Added an on-demand replication synchronization process to synchronize new and updated data between replication nodes.

Unlike real-time replication, which transfers changes as they occur, replication synchronization scans for changes made during a configurable time period and synchronizes them between connected nodes. This makes it easy to recover updates that may have been missed while real-time replication was unavailable, such as during maintenance or network interruptions.

Replication synchronization is also useful for periodically synchronizing Disaster Recovery (DR) environments without maintaining continuous real-time replication, reducing unnecessary network traffic while ensuring data remains up to date when needed.

Extensions

  • Improved the performance of paginated data retrieval from the Microsoft Entra ID REST API.

  • Added the option to verify connectivity and establish trust with cloud AI providers directly from the integration list and edit screens.

  • Added the option to regenerate HTTP proxy certificate from the WEB Console GUI.

  • Improved Active Directory integration by enforcing the requirement to use service accounts in User Principal Name (UPN) format.

Security

Security Improvements
  • Updated code signatures for Windows installers.

  • Improved the security of Microsoft Entra ID token caching by preventing tokens generated for the same applications from being shared across different tenants or sites.

  • Improved communication security with Microsoft Entra ID to strengthen authentication and API interactions.

  • Added support for FIPS-compliant certificate storage for Microsoft Entra ID and OpenAI communications.

  • Added connection timeouts for Microsoft Entra ID communications to improve reliability during network connectivity issues and reduce the risk of denial-of-service (DoS) conditions.

Components Update
  • Updated application WEB framework to the latest version.

  • Updated database access component to the latest version.

  • Updated Code Editor view components to the latest version.

  • Updated test framework to the latest version.

  • Updated WEB application icons library to the latest version.

  • Updated PostgreSQL driver to the latest version.

  • Updated HTTP communication component to the latest version.

  • Updated SSH and PowerShell proxy sessions player component to the latest version.

  • Updated terminal emulator component to the latest version.

  • Updated WEB HTTP Driver to the latest version.

  • Updated application logger component to the latest version.

Fixes

  • Fixed an issue with resolving the dynamic issuer for the certificates, tokens and signatures to the site URL when the configured issuer contained leading or trailing whitespace.

  • Fixed the issue with deleting the asset that has associated failed password reset jobs.

  • Fixed the issue that allowed the deletion of local users and groups that were still in use by asset or container permissions, workflow approvers, or workflow selectors.

Release notes for the June, 28 2026 update

Update Version 4.1.202606261936

New Features

Added support for key-based authentication to Microsoft Entra ID applications

Key-based authentication improves security when integrating with Microsoft Entra ID applications:

  • Private keys never leave the client. Instead of transmitting a shared secret over the network, the client signs a time-stamped authentication assertion with its private key. Microsoft Entra ID validates the signature using the corresponding public certificate.

  • Independent credential management. Each client can use its own certificate and private key, making it easy to grant, revoke, and rotate credentials for individual clients without impacting other applications or integrations.

Key-based authentication is supported across a wide range of Microsoft Entra ID integration scenarios, including:

  • Authentication: Direct and single sign-on (SSO) user authentication
  • Authorization: User and group authorization, including permission assignment, revocation and reporting
  • Multi-Factor Authentication (MFA): Verifying user identity before granting access to remote sessions or sensitive data.
  • Import: Importing virtual machines and accounts into the application vault
  • Account Management: Password reset, reconciliation and verification for Microsoft Entra ID accounts
  • Azure AI: Integrating with Azure AI services to analyze and query application data.
  • Notifications: Sending email through Microsoft 365

Security

Components Update
  • Updated application WEB framework to the latest version.

  • Updated WEB container component to the latest version.

  • Updated REST API documentation component to the latest version.

  • Updated markdown rendering toolkit to the latest version.

  • Updated database access component to the latest version.

  • Updated SSH and PowerShell Proxy sessions player component to the latest version.

  • Updated dashboard charts component to the latest version.

  • Updated Code Editor command, view, language and state components to the latest version.

  • Updated HTTP communication component to the latest version.

Fixes

  • Fixed the issue with REST API documentation browser

  • Fixed the issue with the Quick Access option for the Remote App session enforcing default jump host member asset selection as a credentials type even if the last launch did not include it or included the wrong one.

  • Fixed the issue with listing member assets with only container viewer permissions.

  • Fixed the issue where the Quick Access option could start a member session using the member selected for a previous session when the target asset had no such member.

  • Fixed the issue with the Access report did not correctly handle permissions assigned to non-existent groups.

  • Fixed the issue with Access button is available on the Asset View screen for the assets that do not support access (no protocol defined).

  • Fixed the issue with the secure storage of large configuration data, such as private keys.

  • Fixed the concurrency issues with creating and sending notifications.

  • Fixed the issue that prevented creating a workflow selector for a group that had not previously been used in the tenant.

  • Fixed the issue with applying configuration changes to the run time environment.

  • Improved the Microsoft Entra ID token renewal process to refresh access tokens before they expire.

  • Fixed the issue with refreshing cached cryptographic keys disrupting application functionality.

  • Fixed the issue with refreshing cached Entra Id connection.