DocumentationAPI ReferenceRelease Notes
Release Notes

BeyondTrust Discovery Agent 26.3.0 release notes

BeyondTrust Discovery Agent 26.3.0 release notes

April 7th, 2026

🚧

Important

This release supersedes Discovery Agent versions 20.1.0 through 26.1.1.2200.

🆕 New features

Sudo elevation for Any type credentials over SSH

The scanner now supports sudo elevation when connecting over SSH with credentials of the Any type. You can scan Unix and Linux targets that require elevation without maintaining a separate credential type for each host.

Deployment status alerts for the Phoenix extension

A new Alert event record reports the status of the Scanner extension deployment to a target, so you can confirm that the extension reached each target and troubleshoot deployments that did not complete.

Runtime option configuration through Phoenix.Client

You can now configure selected scanner runtime options directly through Phoenix.Client, without editing configuration files on the scanner host.

Multiple encryption types for Resource Brokers installation secrets

The scanner supports multiple encryption types for Resource Brokers installation secrets, giving you more flexibility to align agent installation with your organization's encryption standards.

✨ Enhancements

Scanner security hardening

The scanner tightens access to its own resources and to directory traffic:

  • The scanner updates the ACL for the Discovery folder to restrict access to Administrators and SYSTEM.
  • The scanner updates the ACL for the BDA registry key to restrict access to Administrators and SYSTEM.
  • LDAP queries no longer default to plaintext when the registry flag is absent.
  • The scanner no longer performs silent anonymous LDAP binds when credential authentication fails.
  • Executable signature verification is improved. If verification fails, the service starts but refuses to scan instead of failing the MSI installation with error 1603.
Remote Agent security and reliability

Remote Agent communication and service handling are more robust:

  • Encryption between the Remote Agent client and server is improved.
  • Remote Agent binary verification is restored and enabled by default.
  • The Remote Agent no longer stops the RemoteRegistry service when other services depend on it.
  • The Remote Agent returns and logs errors instead of discarding them.
Faster scans and queueing

Several changes reduce scan and queueing time:

  • SCOM enumeration moves to the Phoenix extension.
  • A DNS stall before scan start is eliminated, improving queueing speed.
  • Linux service enumeration requests only the required systemctl properties, speeding up Linux target scans.
  • Remote Agent deployment expands archived files in memory before copying them to the target.
  • Throughput between the Remote Agent service and client is improved.
More accurate target identification

Target naming and group enumeration are more reliable:

  • Domain group enumeration uses the domain the target is joined to rather than the domain of the scanning credential.
  • The UseBIProvidedName option is honored across the shared name and DNS resolution layer and all 29 target-ops classes, including the Windows registry name.
Simplified deployment and packaging

The agent is easier to install and script:

  • The scanner and Remote Agent are retargeted to .NET 10 and no longer require Core Hosting.
  • Phoenix.Service ships as a self-contained, single-file bundle.
  • Phoenix.Client ships as a self-contained, single-file bundle.
  • BTDiscovery.cmd is now a pass-through command file, which simplifies scripting.

🛠️ Issues resolved

Product areaDescriptionResolution
ScannerA /32 IPv4 CIDR block was rejected by the address parser and expanded to zero targets.The parser now accepts /32 as a valid IPv4 CIDR block.
ScannerData was dropped from the local results repository when a duplicate port was stored.Duplicate ports are now stored without dropping data from the local results repository.
ScannerValid DCOM objects were filtered out of scan results.Valid DCOM objects are now included in scan results.
Remote AgentFailed Remote Agent sessions hung the scanner in the cleanup phase, blocking scan completion until the full scan duration timeout elapsed.Failed Remote Agent sessions now release cleanly, so scans complete without waiting for the scan duration timeout.
Remote AgentRemote Agent sessions failed because of ACL access to the default Windows station.Remote Agent sessions now access the default Windows station correctly.
Remote AgentRemote Agent deployment failed during local scans when NTLM was disabled.Remote Agent deployment for local scans now succeeds when NTLM is disabled.

🚧 Known issues

  • Windows PowerShell does not pass command line options through to btdiscovery.cmd. Run this command from a standard Windows command shell.
  • Sybase authentication is not supported for IPv6.
  • MySQL 9 enumeration on Linux is not supported.

📝 Requirements

  • The .NET 10 Hosting package must be installed.
  • OAuth authorization requires BeyondInsight 24.2.0.
  • Retrieving all scheduled scans through the Central Policy message requires BeyondInsight 24.3.0 or later.

🗒️ Notes

  • This release is available by download from the BeyondTrust Client Portal (https://www.beyondtrust.com/support/).
  • The SHA-256 signature is: a2b825379ac2f2145ce366c879fded2c5b78296c7c32b1a7885d3c14efccd9eb
  • The SHA-1 signature is: a69532552ce0ec4cd0d0eb662100caebbbfa9860
  • The MD5 signature is: 66889e78018f57129deb19868f1e54fd

⏰ Deprecation notices

  • Support for SSH session encryption using the SHA-1 cipher is removed. Use SHA-256 or higher.
  • Support for DSA as an SSH authentication cipher is removed.
  • The legacy gRPC and Go client paths are removed.
  • Support for Retina to Phoenix migration is removed.
  • Windows 8 and Windows Server 2012 are no longer supported as scanner hosts.
  • Windows Server 2016 as a scanner host is deprecated.

⌛ End of support

The product versions below have reached, or are nearing, their end of support. Upgrade to the latest version to continue receiving updates and support. Support ends on the last day of the month listed below.

For more information about supported versions, see Product Support Life Cycle.

Product versionEnd of support
Out of support
Password Safe 24.2.xSeptember 2026
Near end of support
Password Safe 24.3.xDecember 2026

©2003-2026 BeyondTrust Corporation. All Rights Reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.