DocumentationAPI ReferenceRelease Notes
Release Notes

EPM for Windows 26.3.2

🆕 New features


Filter Workstyles by Entra ID computer group

You can now target Workstyles at Entra ID computer groups, combining user and device targeting so policies can be scoped to specific machines. Endpoint Privilege Management retrieves computer group membership from Entra ID by device ID.

Endpoint Privilege Management caches Entra ID computer group membership on each endpoint. You can refresh the cache on demand in two ways:

  • Refresh Entra ID computer group membership from the system tray.
  • Refresh the Entra ID computer groups for the current device using Endpoint Utility.
ℹ️

Entra ID computer group filtering is available in EPM Cloud only.

Notifications for JIT Admin request decisions

Endpoint users now receive a notification when their JIT Admin request is approved or denied, so they no longer need to check the request status manually.

IPv6 support with BeyondInsight and Password Safe

Endpoint Privilege Management for Windows with BeyondInsight and Password Safe is supported in IPv6-only and hybrid IPv6/IPv4 environments, from Endpoint Privilege Management 26.3.1 and BeyondInsight and Password Safe 26.3. The BeyondInsight adapter can also populate the Preferred IP Address field with an IPv6 address in the BeyondInsight heartbeat.

The following limitations apply:

  • IP address policy filtering does not support IPv6 addresses.
  • Endpoint Privilege Management audit events do not record IPv6 addresses.

✨ Enhancements

Staggered group refresh when identity authentication falls back to EPM Cloud

When identity authentication falls back to EPM Cloud to resolve an Entra ID user's group membership, the scheduled group refresh now starts after a small randomized delay on each endpoint. This spreads requests over time so large fleets no longer query EPM Cloud simultaneously.

Updated Microsoft recommended block rules and QuickStart application definitions

The BGInfo application definition is updated to reflect Microsoft's changes to its list of applications that can bypass Windows Defender Application Control.

ℹ️

For more information, see BgInfo.

🛠️ Issues resolved

Product areaDescriptionResolution
Analytics & ReportingFiltering Analytics by account privilege returned only the user logon event for a session instead of all events in that session, under-reporting activity.EPM now records the account privilege value (standard user or administrator) on all event types, so filtering Analytics by account privilege returns the complete set of events for a session.
Application ControlSelecting Run as administrator on a Microsoft Store app, such as Windows Terminal, displayed an Application Rules message instead of the Windows User Account Control prompt.Microsoft Store apps launched with Run as administrator now display the Windows User Account Control prompt.
Application ControlLaunching an application from an advertised shortcut displayed a Windows User Account Control prompt during the automatic MSI repair instead of applying EPM policy.EPM policy now applies to the MSI repair that runs when an application launches from an advertised shortcut.
Application ControlLaunching an application as administrator from the Windows Run box (Win+R, then Ctrl+Shift+Enter) was evaluated against Application rules instead of On-Demand rules.Applications launched as administrator from the Windows Run box are now evaluated against On-Demand rules.
AuditingThe EPM service could crash during auditing.The EPM service now remains stable during auditing.
Endpoint clientDesktop applications could crash to a black screen at logon when another endpoint security product ran alongside EPM at startup.Desktop applications now start correctly at logon when EPM runs alongside other endpoint security products.
Endpoint clientApplications built with the Bun runtime, such as the Claude Code CLI, crashed intermittently at startup on EPM-protected endpoints.Bun-based applications now start reliably on endpoints protected by EPM.
Endpoint UtilityEndpoint Utility hung when launched from an elevated command prompt or PowerShell session.Endpoint Utility now runs correctly when launched from an elevated command prompt or PowerShell session.

📝 Requirements

  • Microsoft .NET Framework 4.6.2 (required to use Power Rules, PowerShell audit scripts, PowerShell API, and Agent Protection)
  • Microsoft .NET Framework 4.8 (required to use Multifactor Authentication with an OIDC provider)
  • Windows PowerShell 3.0 (required to use Power Rules, PowerShell audit scripts, and PowerShell API)
  • Microsoft VBScript feature enabled
  • Trellix (formerly McAfee) Agent (required if you are installing the Privilege Management client with switch EPOMODE=1)

    ❗

    Important

    The executable version of the client package includes all necessary prerequisites (excluding .NET Framework) and automatically installs them as necessary. If you use the MSI or ZIP package, you must manually install any necessary prerequisites.

🔄 Compatibility

  • Privilege Management Policy Editor 26.3 (recommended), 24.5+
  • Privilege Management ePO Extension 26.1 (recommended), 24.5+
  • Privilege Management Console Windows Adapter 26.2.1 (recommended), 24.5+
  • BeyondInsight/Password Safe 26.2.0.1443 (recommended), 24.2.0+
    • IPv6 support requires BeyondInsight/Password Safe 26.2+
  • Trellix Agent 5.7+
  • Trellix ePO Server 5.10 Service Pack 1 Update 6 (recommended), Update 4+
ℹ️

For more information, see EPM for Windows and Mac supported platforms.

©2003-2026 BeyondTrust Corporation. All Rights Reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.