DocumentationAPI ReferenceRelease Notes
Release Notes

EPM for Windows and Mac (Cloud and Pathfinder) 26.3.2

🆕 New features

Prevent child process execution for macOS sudo rules

You can now allow a macOS sudo command while blocking any additional processes it tries to start. In the Policy Editor, open a macOS sudo application rule and use the Child Processes setting. When a child process is blocked, EPM records an audit event that includes the parent process context.

❗

Important

This feature requires the com.beyondtrust.guard system extension to be pre-approved through your MDM solution.

For more information, see Configure a sudo rule with Shell Guardian.

Use Microsoft Entra ID computer groups in Workstyle computer filters

You can now reference an Entra ID group that contains computer objects in the computer filters of a workstyle. Previously, computer group filters supported only local operating system computer groups, and Entra ID groups could be used for user filters only.

  • Supported on Windows and macOS endpoints
Add Active Directory accounts manually to Windows workstyle computer filters

You can now add Active Directory accounts manually to the computer filters of a Windows workstyle in the Policy Editor. This means you can build the computer filters you need even when EPM cannot connect to your Active Directory instance through the connector.

ℹ️

This matches the existing behavior for adding Active Directory accounts manually elsewhere in the Policy Editor.

IPv6 support for Endpoint Privilege Management in BeyondInsight and the U-Series Appliance

Endpoint Privilege Management is now certified for BeyondInsight and U-Series Appliance deployments on IPv6-only networks. The following flows have been validated against an IPv6 environment:

  • Account discovery
  • Password rotation
  • Client install, upgrade, and uninstall through Intune
  • Power Rules ServiceNow integration
  • OpenID Connect (OIDC) authentication
  • Microsoft Entra ID connectivity

Limitations:

  • IP address policy filtering does not support IPv6 addresses.
  • Endpoint Privilege Management audit events do not record IPv6 addresses.

✨ Enhancements

Select multiple values from the Application Group Name filter in Analytics

The Application Group Name filter in Events and Applications now lets you select multiple group names from a fast-loading dropdown, instead of typing at least three characters to search. Group names remain available for up to 90 days after their policy is deleted.

Queries now run automatically in more Analytics flows

Opening a saved view that lands on the Events, Applications, or Users page now runs the query automatically, as does opening the Endpoint User Logins dashboard tile. You no longer need to select Run Query to see your results in these flows.

Added an inactivity warning before signing you out

The console now warns you shortly before you are signed out after a period of inactivity, so a session no longer ends without notice. Any interaction with the console resets the inactivity timer (that is, moving the mouse, selecting an item, or navigating).

ℹ️

The inactivity timeout is 20 minutes and is not configurable.

Broader translation coverage across the console

Text that was previously built directly in the console code is now routed through the translation pipeline, so more of the console appears in your selected language. This includes error, success, and warning messages, empty states, tooltips, placeholders, and screen reader labels.

Authentication performance improvements for large device fleets

Token issuance is now considerably more efficient on tenants managing very large numbers of devices, so clients authenticate quickly and consistently as your fleet grows.

Redesigned Updates tab for computer groups

The Updates tab for a computer group is redesigned to explain what auto-updates does and what each setting controls, so you can configure update behavior for a group with confidence.

  • Descriptive text and inline guidance clarify how auto-updates applies to the computers in the group.
  • Configuration options are reorganized so the effect of each choice is clear before you save.
ℹ️

For more information, see Computer Groups.

Package Manager update status for computers in a group

The Updates tab now shows the Package Manager update status for every computer in the group, so you can track rollout progress and find machines that need attention. Component status is calculated from the client, the adapter, and Package Manager, giving you a single, accurate view of where each computer stands.

  • See at a glance which computers are up to date, pending an update, or reporting an error.
  • Identify computers that are blocked partway through an update, without checking each computer individually.
ℹ️

For more information, see Computer Groups.

Four-part version numbering for PM Cloud

Privilege Management Cloud now uses a four-part version number. Versions display as 26.3.1.500 in place of the previous three-part format.

  • 26 - year
  • 3 - release number within that year
  • 1 - patch release within that release
  • 500 - build number

The third segment is new. It increments when a patch or security release ships between scheduled releases, so you can tell at a glance whether you are running the latest patch level for a given release.

ℹ️

If you have scripts, asset inventories, or CMDB entries (for example, ServiceNow) that read the PM Cloud version string, confirm they handle a four-part value.

🛠️ Issues resolved

Product areaDescriptionResolution
AnalyticsThe Event Details page intermittently took 10 to 12 seconds to load, particularly for recent events.The Event Details page now retrieves the event directly, resulting in faster and more consistent load times.
AnalyticsSelecting the 1 Hour time period on the Events page returned no results, even when events existed in that time range.The 1 Hour time period filter now calculates the correct time range and returns the expected events.
AnalyticsThe Policy Name filter on the Events page displayed duplicate entries and continued to show policies that had been renamed or deleted.The Policy Name filter now reflects current policy names and no longer lists duplicate or deleted policies.
APISorting the computer list by credential type using the Management API returned an HTTP 500 error.Sorting the computer list by credential type now returns the expected ordered results.
APISorting the users list by user type using the Management API returned an HTTP 500 error.Sorting the users list by user type now returns the expected ordered results.
APIThe Management API Events/FromStartDate endpoint rejected valid date values in the yyyy-MM-ddTHH:mm:ss.ffffffZ format.The Management API Events/FromStartDate endpoint now accepts date values in this format.
APIThe Management API Events/FromStartDate endpoint returned events out of ingestion order, which could cause SIEM integrations to skip or duplicate events when paging.Events are now returned in ascending ingestion order, so timestamp-based pagination retrieves every event exactly once.
APIAdmin access requests were not returned in the requested order when sorted by computer name.Admin access requests are now correctly sorted by computer name.
AuthenticationAfter upgrading to 26.2, users whose only role was Request Manager were returned to the sign-in screen immediately after signing in.Users with the Request Manager role now remain signed in to the console.
ComputersThe Days Disconnected column in the Computers list showed -- for archived, deactivated, and rejected computers, and exported as 0 in CSV, while the Computer Summary page showed the correct value.The Days Disconnected column now shows the correct value in the Computers list and in CSV exports for all computer states.
ConfigurationOn some settings pages, switching a toggle on and then back off before saving was treated as a change, which triggered a save and created an audit log entry even though nothing had changed.Settings pages now compare the current state against the last saved state, so no save or audit log entry occurs when there is no net change.
Directory IntegrationsEntra ID group synchronization failed on tenants where the filtered group sync setting had not been explicitly configured.Entra ID group synchronization now applies the configured default value and completes successfully.
Directory IntegrationsSearching for Okta groups in the workstyle account filter returned an error when the search term contained leading or trailing spaces.Search terms are now trimmed before validation, so leading and trailing spaces no longer cause a search error.
Directory IntegrationsPaging through Entra ID user group lookup results returned duplicate groups, omitted groups, and reported an incorrect total number of pages.Entra ID user group lookup results are now consistently ordered and paged, and the total page count is reported correctly.
Just-in-Time AccessAuthorization requests submitted to ServiceNow failed permanently with a 401 (Unauthorized) error until the service was restarted.PM Cloud now detects a rejected ServiceNow token, requests a new one, and recovers automatically without a restart.
Just-in-Time AccessThe JIT email notification job stopped for the remainder of each run when it reached a queued notification for a computer that belonged to no computer group, so some JIT emails were never sent.The JIT email notification job now handles these queue entries individually and continues to process the remaining notifications.
Just-in-Time AccessPolicies containing both Windows and macOS workstyles were missing from the Admin Access Policy Updates grid and its CSV export when a workstyle name was used on both platforms.Workstyle details are now recorded for each platform, so combined Windows and macOS policies appear in the Admin Access Policy Updates grid and CSV export.
Policy EditorSorting by the Account Name column on the macOS workstyle account filter page had no effect.The Account Name column on the macOS workstyle account filter page now sorts correctly.

©2003-2026 BeyondTrust Corporation. All Rights Reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.