BeyondTrust Discovery Agent 26.3.0 release notes
BeyondTrust Discovery Agent 26.3.0 release notes
April 7th, 2026
🆕 New features
Sudo elevation for Any type credentials over SSH
The scanner now supports sudo elevation when connecting over SSH with credentials of the Any type. You can scan Unix and Linux targets that require elevation without maintaining a separate credential type for each host.
Deployment status alerts for the Phoenix extension
A new Alert event record reports the status of the Scanner extension deployment to a target, so you can confirm that the extension reached each target and troubleshoot deployments that did not complete.
Runtime option configuration through Phoenix.Client
You can now configure selected scanner runtime options directly through Phoenix.Client, without editing configuration files on the scanner host.
Multiple encryption types for Resource Brokers installation secrets
The scanner supports multiple encryption types for Resource Brokers installation secrets, giving you more flexibility to align agent installation with your organization's encryption standards.
✨ Enhancements
Scanner security hardening
The scanner tightens access to its own resources and to directory traffic:
- The scanner updates the ACL for the Discovery folder to restrict access to Administrators and SYSTEM.
- The scanner updates the ACL for the BDA registry key to restrict access to Administrators and SYSTEM.
- LDAP queries no longer default to plaintext when the registry flag is absent.
- The scanner no longer performs silent anonymous LDAP binds when credential authentication fails.
- Executable signature verification is improved. If verification fails, the service starts but refuses to scan instead of failing the MSI installation with error 1603.
Remote Agent security and reliability
Remote Agent communication and service handling are more robust:
- Encryption between the Remote Agent client and server is improved.
- Remote Agent binary verification is restored and enabled by default.
- The Remote Agent no longer stops the RemoteRegistry service when other services depend on it.
- The Remote Agent returns and logs errors instead of discarding them.
Faster scans and queueing
Several changes reduce scan and queueing time:
- SCOM enumeration moves to the Phoenix extension.
- A DNS stall before scan start is eliminated, improving queueing speed.
- Linux service enumeration requests only the required systemctl properties, speeding up Linux target scans.
- Remote Agent deployment expands archived files in memory before copying them to the target.
- Throughput between the Remote Agent service and client is improved.
More accurate target identification
Target naming and group enumeration are more reliable:
- Domain group enumeration uses the domain the target is joined to rather than the domain of the scanning credential.
- The UseBIProvidedName option is honored across the shared name and DNS resolution layer and all 29 target-ops classes, including the Windows registry name.
Simplified deployment and packaging
The agent is easier to install and script:
- The scanner and Remote Agent are retargeted to .NET 10 and no longer require Core Hosting.
- Phoenix.Service ships as a self-contained, single-file bundle.
- Phoenix.Client ships as a self-contained, single-file bundle.
- BTDiscovery.cmd is now a pass-through command file, which simplifies scripting.
🛠️ Issues resolved
| Product area | Description | Resolution |
|---|---|---|
| Scanner | A /32 IPv4 CIDR block was rejected by the address parser and expanded to zero targets. | The parser now accepts /32 as a valid IPv4 CIDR block. |
| Scanner | Data was dropped from the local results repository when a duplicate port was stored. | Duplicate ports are now stored without dropping data from the local results repository. |
| Scanner | Valid DCOM objects were filtered out of scan results. | Valid DCOM objects are now included in scan results. |
| Remote Agent | Failed Remote Agent sessions hung the scanner in the cleanup phase, blocking scan completion until the full scan duration timeout elapsed. | Failed Remote Agent sessions now release cleanly, so scans complete without waiting for the scan duration timeout. |
| Remote Agent | Remote Agent sessions failed because of ACL access to the default Windows station. | Remote Agent sessions now access the default Windows station correctly. |
| Remote Agent | Remote Agent deployment failed during local scans when NTLM was disabled. | Remote Agent deployment for local scans now succeeds when NTLM is disabled. |
🚧 Known issues
- Windows PowerShell does not pass command line options through to btdiscovery.cmd. Run this command from a standard Windows command shell.
- Sybase authentication is not supported for IPv6.
- MySQL 9 enumeration on Linux is not supported.
📝 Requirements
- The .NET 10 Hosting package must be installed.
- OAuth authorization requires BeyondInsight 24.2.0.
- Retrieving all scheduled scans through the Central Policy message requires BeyondInsight 24.3.0 or later.
🗒️ Notes
- This release is available by download from the BeyondTrust Client Portal (https://www.beyondtrust.com/support/).
- The SHA-256 signature is: a2b825379ac2f2145ce366c879fded2c5b78296c7c32b1a7885d3c14efccd9eb
- The SHA-1 signature is: a69532552ce0ec4cd0d0eb662100caebbbfa9860
- The MD5 signature is: 66889e78018f57129deb19868f1e54fd
⏰ Deprecation notices
- Support for SSH session encryption using the SHA-1 cipher is removed. Use SHA-256 or higher.
- Support for DSA as an SSH authentication cipher is removed.
- The legacy gRPC and Go client paths are removed.
- Support for Retina to Phoenix migration is removed.
- Windows 8 and Windows Server 2012 are no longer supported as scanner hosts.
- Windows Server 2016 as a scanner host is deprecated.
⌛ End of support
The product versions below have reached, or are nearing, their end of support. Upgrade to the latest version to continue receiving updates and support. Support ends on the last day of the month listed below.
For more information about supported versions, see Product Support Life Cycle.
| Product version | End of support |
|---|---|
| Out of support | |
| Password Safe 24.2.x | September 2026 |
| Near end of support | |
| Password Safe 24.3.x | December 2026 |