EPM for Windows and Mac (Cloud and Pathfinder) 26.3.2
🆕 New features
Prevent child process execution for macOS sudo rules
You can now allow a macOS sudo command while blocking any additional processes it tries to start. In the Policy Editor, open a macOS sudo application rule and use the Child Processes setting. When a child process is blocked, EPM records an audit event that includes the parent process context.
ImportantThis feature requires the
com.beyondtrust.guardsystem extension to be pre-approved through your MDM solution.For more information, see Configure a sudo rule with Shell Guardian.
Use Microsoft Entra ID computer groups in Workstyle computer filters
You can now reference an Entra ID group that contains computer objects in the computer filters of a workstyle. Previously, computer group filters supported only local operating system computer groups, and Entra ID groups could be used for user filters only.
- Supported on Windows and macOS endpoints
Add Active Directory accounts manually to Windows workstyle computer filters
You can now add Active Directory accounts manually to the computer filters of a Windows workstyle in the Policy Editor. This means you can build the computer filters you need even when EPM cannot connect to your Active Directory instance through the connector.
This matches the existing behavior for adding Active Directory accounts manually elsewhere in the Policy Editor.
IPv6 support for Endpoint Privilege Management in BeyondInsight and the U-Series Appliance
Endpoint Privilege Management is now certified for BeyondInsight and U-Series Appliance deployments on IPv6-only networks. The following flows have been validated against an IPv6 environment:
- Account discovery
- Password rotation
- Client install, upgrade, and uninstall through Intune
- Power Rules ServiceNow integration
- OpenID Connect (OIDC) authentication
- Microsoft Entra ID connectivity
Limitations:
- IP address policy filtering does not support IPv6 addresses.
- Endpoint Privilege Management audit events do not record IPv6 addresses.
✨ Enhancements
Select multiple values from the Application Group Name filter in Analytics
The Application Group Name filter in Events and Applications now lets you select multiple group names from a fast-loading dropdown, instead of typing at least three characters to search. Group names remain available for up to 90 days after their policy is deleted.
Queries now run automatically in more Analytics flows
Opening a saved view that lands on the Events, Applications, or Users page now runs the query automatically, as does opening the Endpoint User Logins dashboard tile. You no longer need to select Run Query to see your results in these flows.
Added an inactivity warning before signing you out
The console now warns you shortly before you are signed out after a period of inactivity, so a session no longer ends without notice. Any interaction with the console resets the inactivity timer (that is, moving the mouse, selecting an item, or navigating).
The inactivity timeout is 20 minutes and is not configurable.
Broader translation coverage across the console
Text that was previously built directly in the console code is now routed through the translation pipeline, so more of the console appears in your selected language. This includes error, success, and warning messages, empty states, tooltips, placeholders, and screen reader labels.
Authentication performance improvements for large device fleets
Token issuance is now considerably more efficient on tenants managing very large numbers of devices, so clients authenticate quickly and consistently as your fleet grows.
Redesigned Updates tab for computer groups
The Updates tab for a computer group is redesigned to explain what auto-updates does and what each setting controls, so you can configure update behavior for a group with confidence.
- Descriptive text and inline guidance clarify how auto-updates applies to the computers in the group.
- Configuration options are reorganized so the effect of each choice is clear before you save.
For more information, see Computer Groups.
Package Manager update status for computers in a group
The Updates tab now shows the Package Manager update status for every computer in the group, so you can track rollout progress and find machines that need attention. Component status is calculated from the client, the adapter, and Package Manager, giving you a single, accurate view of where each computer stands.
- See at a glance which computers are up to date, pending an update, or reporting an error.
- Identify computers that are blocked partway through an update, without checking each computer individually.
For more information, see Computer Groups.
Four-part version numbering for PM Cloud
Privilege Management Cloud now uses a four-part version number. Versions display as 26.3.1.500 in place of the previous three-part format.
- 26 - year
- 3 - release number within that year
- 1 - patch release within that release
- 500 - build number
The third segment is new. It increments when a patch or security release ships between scheduled releases, so you can tell at a glance whether you are running the latest patch level for a given release.
If you have scripts, asset inventories, or CMDB entries (for example, ServiceNow) that read the PM Cloud version string, confirm they handle a four-part value.
🛠️ Issues resolved
| Product area | Description | Resolution |
|---|---|---|
| Analytics | The Event Details page intermittently took 10 to 12 seconds to load, particularly for recent events. | The Event Details page now retrieves the event directly, resulting in faster and more consistent load times. |
| Analytics | Selecting the 1 Hour time period on the Events page returned no results, even when events existed in that time range. | The 1 Hour time period filter now calculates the correct time range and returns the expected events. |
| Analytics | The Policy Name filter on the Events page displayed duplicate entries and continued to show policies that had been renamed or deleted. | The Policy Name filter now reflects current policy names and no longer lists duplicate or deleted policies. |
| API | Sorting the computer list by credential type using the Management API returned an HTTP 500 error. | Sorting the computer list by credential type now returns the expected ordered results. |
| API | Sorting the users list by user type using the Management API returned an HTTP 500 error. | Sorting the users list by user type now returns the expected ordered results. |
| API | The Management API Events/FromStartDate endpoint rejected valid date values in the yyyy-MM-ddTHH:mm:ss.ffffffZ format. | The Management API Events/FromStartDate endpoint now accepts date values in this format. |
| API | The Management API Events/FromStartDate endpoint returned events out of ingestion order, which could cause SIEM integrations to skip or duplicate events when paging. | Events are now returned in ascending ingestion order, so timestamp-based pagination retrieves every event exactly once. |
| API | Admin access requests were not returned in the requested order when sorted by computer name. | Admin access requests are now correctly sorted by computer name. |
| Authentication | After upgrading to 26.2, users whose only role was Request Manager were returned to the sign-in screen immediately after signing in. | Users with the Request Manager role now remain signed in to the console. |
| Computers | The Days Disconnected column in the Computers list showed -- for archived, deactivated, and rejected computers, and exported as 0 in CSV, while the Computer Summary page showed the correct value. | The Days Disconnected column now shows the correct value in the Computers list and in CSV exports for all computer states. |
| Configuration | On some settings pages, switching a toggle on and then back off before saving was treated as a change, which triggered a save and created an audit log entry even though nothing had changed. | Settings pages now compare the current state against the last saved state, so no save or audit log entry occurs when there is no net change. |
| Directory Integrations | Entra ID group synchronization failed on tenants where the filtered group sync setting had not been explicitly configured. | Entra ID group synchronization now applies the configured default value and completes successfully. |
| Directory Integrations | Searching for Okta groups in the workstyle account filter returned an error when the search term contained leading or trailing spaces. | Search terms are now trimmed before validation, so leading and trailing spaces no longer cause a search error. |
| Directory Integrations | Paging through Entra ID user group lookup results returned duplicate groups, omitted groups, and reported an incorrect total number of pages. | Entra ID user group lookup results are now consistently ordered and paged, and the total page count is reported correctly. |
| Just-in-Time Access | Authorization requests submitted to ServiceNow failed permanently with a 401 (Unauthorized) error until the service was restarted. | PM Cloud now detects a rejected ServiceNow token, requests a new one, and recovers automatically without a restart. |
| Just-in-Time Access | The JIT email notification job stopped for the remainder of each run when it reached a queued notification for a computer that belonged to no computer group, so some JIT emails were never sent. | The JIT email notification job now handles these queue entries individually and continues to process the remaining notifications. |
| Just-in-Time Access | Policies containing both Windows and macOS workstyles were missing from the Admin Access Policy Updates grid and its CSV export when a workstyle name was used on both platforms. | Workstyle details are now recorded for each platform, so combined Windows and macOS policies appear in the Admin Access Policy Updates grid and CSV export. |
| Policy Editor | Sorting by the Account Name column on the macOS workstyle account filter page had no effect. | The Account Name column on the macOS workstyle account filter page now sorts correctly. |