EPM for Mac 26.3.2
🆕 New features
Prevent child process execution (Shell Guardian) for macOS sudo rules
You can now allow a macOS sudo command while blocking any additional processes it tries to start. In the Policy Editor, open a macOS sudo application rule and use the Child Processes setting. When a child process is blocked, EPM records an audit event that includes the parent process context.
ImportantThis feature requires the
com.beyondtrust.guardsystem extension to be pre-approved through your MDM solution. The BeyondTrust provided configuration profile v2.4.0 has been updated to approve this.
For more information, see Configure a sudo rule with Shell Guardian.
Use Microsoft Entra ID computer groups in Workstyle computer filters
You can now reference an Entra ID group that contains computer objects in the computer filters of a workstyle. Previously, computer group filters supported only local operating system computer groups, and Entra ID groups could be used for user filters only.
- Supported on Windows and macOS endpoints.
Add Active Directory accounts manually to Windows workstyle computer filters
You can now add Active Directory accounts manually to the computer filters of a Windows workstyle in the Policy Editor. This means you can build the computer filters you need even when EPM cannot connect to your Active Directory instance through the connector.
This matches the existing behavior for adding Active Directory accounts manually elsewhere in the Policy Editor.
IPv6 support for Endpoint Privilege Management in BeyondInsight and the U-Series Appliance
Endpoint Privilege Management is now certified for BeyondInsight and U-Series Appliance deployments on IPv6-only networks. The following flows have been validated against an IPv6 environment:
- Account discovery
- Password rotation
- Client install, upgrade, and uninstall through Intune
- Power Rules ServiceNow integration
- OpenID Connect (OIDC) authentication
- Microsoft Entra ID connectivity
Limitations:
- IP address policy filtering does not support IPv6 addresses.
- Endpoint Privilege Management audit events do not record IPv6 addresses.
✨ Enhancements
Entra ID user group resolution for users in more than 200 groups
Endpoint Privilege Management for Mac now resolves complete Entra ID user group membership for users who belong to more than 200 groups, so Workstyle rules that target user groups evaluate correctly for those users. Previously, Entra ID omitted group memberships from the token once a user exceeded 200 groups, and affected users fell through to a less restrictive Workstyle, or to none at all, with no visible error.
- The client detects the condition and retrieves the full group list automatically. End users are never prompted to sign in again.
- The client honors the configured user group refresh period.
There is no change to workstyles.
🛠️ Issues resolved
| Description | Resolution |
|---|---|
Running pmfmdiag --output xml printed the description for each check twice whenever the check reported an error. | pmfmdiag --output xml now prints a single description for every check, including checks that report errors. |
Parent-child process matching failed during authorization evaluation when the parent process path could not be resolved, so processes such as osascript were not matched as Docker child processes. | EPM now matches child processes correctly when the parent process path cannot be resolved. |
| End-user message dialogs on macOS, including block, allow, and Just-in-Time request messages, cut off part of the message body and appeared misaligned when the policy message text was longer than approximately 250 characters. | Message dialogs now display the full message body and stay correctly aligned regardless of message length. |
| Strict local or MDM password policies prevented the EPM daemon from initializing its internal service account password, so EPM never took control of the macOS authorization database. | The EPM daemon now adheres to endpoint password policy requirements, so it takes control of the macOS authorization database and enforces policy as expected. |
| On macOS, Just-in-Time Admin requests stayed stuck in progress when the request was removed mid-session through Platform SSO. | JIT Admin requests now complete correctly on macOS when a request is removed mid-session through Platform SSO. |