EPM for Windows 26.3.2
🆕 New features
Filter Workstyles by Entra ID computer group
You can now target Workstyles at Entra ID computer groups, combining user and device targeting so policies can be scoped to specific machines. Endpoint Privilege Management retrieves computer group membership from Entra ID by device ID.
Endpoint Privilege Management caches Entra ID computer group membership on each endpoint. You can refresh the cache on demand in two ways:
- Refresh Entra ID computer group membership from the system tray.
- Refresh the Entra ID computer groups for the current device using Endpoint Utility.
Entra ID computer group filtering is available in EPM Cloud only.
Notifications for JIT Admin request decisions
Endpoint users now receive a notification when their JIT Admin request is approved or denied, so they no longer need to check the request status manually.
IPv6 support with BeyondInsight and Password Safe
Endpoint Privilege Management for Windows with BeyondInsight and Password Safe is supported in IPv6-only and hybrid IPv6/IPv4 environments, from Endpoint Privilege Management 26.3.1 and BeyondInsight and Password Safe 26.3. The BeyondInsight adapter can also populate the Preferred IP Address field with an IPv6 address in the BeyondInsight heartbeat.
The following limitations apply:
- IP address policy filtering does not support IPv6 addresses.
- Endpoint Privilege Management audit events do not record IPv6 addresses.
✨ Enhancements
Staggered group refresh when identity authentication falls back to EPM Cloud
When identity authentication falls back to EPM Cloud to resolve an Entra ID user's group membership, the scheduled group refresh now starts after a small randomized delay on each endpoint. This spreads requests over time so large fleets no longer query EPM Cloud simultaneously.
Updated Microsoft recommended block rules and QuickStart application definitions
The BGInfo application definition is updated to reflect Microsoft's changes to its list of applications that can bypass Windows Defender Application Control.
For more information, see BgInfo.
🛠️ Issues resolved
| Product area | Description | Resolution |
|---|---|---|
| Analytics & Reporting | Filtering Analytics by account privilege returned only the user logon event for a session instead of all events in that session, under-reporting activity. | EPM now records the account privilege value (standard user or administrator) on all event types, so filtering Analytics by account privilege returns the complete set of events for a session. |
| Application Control | Selecting Run as administrator on a Microsoft Store app, such as Windows Terminal, displayed an Application Rules message instead of the Windows User Account Control prompt. | Microsoft Store apps launched with Run as administrator now display the Windows User Account Control prompt. |
| Application Control | Launching an application from an advertised shortcut displayed a Windows User Account Control prompt during the automatic MSI repair instead of applying EPM policy. | EPM policy now applies to the MSI repair that runs when an application launches from an advertised shortcut. |
| Application Control | Launching an application as administrator from the Windows Run box (Win+R, then Ctrl+Shift+Enter) was evaluated against Application rules instead of On-Demand rules. | Applications launched as administrator from the Windows Run box are now evaluated against On-Demand rules. |
| Auditing | The EPM service could crash during auditing. | The EPM service now remains stable during auditing. |
| Endpoint client | Desktop applications could crash to a black screen at logon when another endpoint security product ran alongside EPM at startup. | Desktop applications now start correctly at logon when EPM runs alongside other endpoint security products. |
| Endpoint client | Applications built with the Bun runtime, such as the Claude Code CLI, crashed intermittently at startup on EPM-protected endpoints. | Bun-based applications now start reliably on endpoints protected by EPM. |
| Endpoint Utility | Endpoint Utility hung when launched from an elevated command prompt or PowerShell session. | Endpoint Utility now runs correctly when launched from an elevated command prompt or PowerShell session. |
📝 Requirements
- Microsoft .NET Framework 4.6.2 (required to use Power Rules, PowerShell audit scripts, PowerShell API, and Agent Protection)
- Microsoft .NET Framework 4.8 (required to use Multifactor Authentication with an OIDC provider)
- Windows PowerShell 3.0 (required to use Power Rules, PowerShell audit scripts, and PowerShell API)
- Microsoft VBScript feature enabled
- Trellix (formerly McAfee) Agent (required if you are installing the Privilege Management client with switch
EPOMODE=1)
🔄 Compatibility
- Privilege Management Policy Editor 26.3 (recommended), 24.5+
- Privilege Management ePO Extension 26.1 (recommended), 24.5+
- Privilege Management Console Windows Adapter 26.2.1 (recommended), 24.5+
- BeyondInsight/Password Safe 26.2.0.1443 (recommended), 24.2.0+
- IPv6 support requires BeyondInsight/Password Safe 26.2+
- Trellix Agent 5.7+
- Trellix ePO Server 5.10 Service Pack 1 Update 6 (recommended), Update 4+
For more information, see EPM for Windows and Mac supported platforms.