Remote Support 25.3.1 release notes
December 18, 2025
🆕 New features
Slow-roll Releases
Remember that automatic update feature from Base 8.0? It’s back, but smarter and friendlier!
What’s Changing in 25.3:
- No surprise pushes. You get to choose when you update.
- You’ll get a heads-up when a new update is available.
- Download and install when it works for you. Full control, zero stress.
- Staggered releases mean no mass rollout chaos.
Simply check the auto install checkbox and select your update cadence.
This is updates done right: transparent, flexible, and customer-first.
For more information, see:
Support for MacOS Tahoe
Get ready for the future of macOS! With the launch of Apple’s latest version, we have you covered. Enjoy instant compatibility, expert guidance, and tips to unlock the newest features without missing a beat.
Session Forensic Tool for Command Shell Traceability
We’re bringing the Privileged Remote Access Forensic Tool magic to Remote Support, because visibility is everything.
What’s in the toolbox?
- Command Shell Traceability - Track every action taken in the Command Shell tab on Windows machines with Jump Client.
- Screen Sharing Capability - Advanced traceability of what happens during screen sharing: processes launched, keystrokes, applications, and more.

- Session Forensics Report - You can even run a report to display session events across all access sessions.

For more information, see:
Automatic import of Password Safe managed credentials and endpoints
Say goodbye to manual drudgery! Vault admins can now automatically import domain accounts, endpoints, and local accounts right after scheduled discovery runs, thanks to smart, predefined filters. With Import Rules, you can assign filters to apply during a predefined scheduled discovery. This keeps your Vault fresh and secure, while still giving you the freedom to manually import anything that falls outside the filters.
This works across all scheduled discovery job types supported by Vault.

For more information, see:
Eliminate ECM Dependency for Password Safe Integrations
Goodbye ECM, Hello Simplicity!
We’re making Remote Support and Password Safe integrations faster, lighter, and cloud-ready. No more heavy lifting with Endpoint Credential Manager. This release kicks complexity to the curb!
What’s Changing?
- Native Discovery & Import: Remote Support now directly handles all the credential types you love: SSH, WebJump, MS SQL, PostgreSQL, and MySQL, all without ECM.
- Simpler Deployments: No extra agents, no headaches. Upgrades are smoother, deployments are quicker.
- Cloud & DevOps Friendly: Built for zero-trust and just-in-time access, aligning perfectly with modern workflows.
Why You’ll Love It:
- Less infrastructure overhead
- Faster time-to-value
This update requires a new plugin download. For more information, see Install the Endpoint Credential Manager.
For more information, see:
✨ Enhancements
Grey out Vault accounts already in use
Get ready for a sleek, modern UX on the /login admin interface! This isn’t just a facelift, it’s a real-time command center for your appliance.
Here’s what’s new:
-
New License Usage panel, showing total active licenses, total available licenses, and total license pools.

-
New Jump Clients panels, showing Online, Offline, and Offline (disabled) Jump Clients, and new Jumpoints panel, showing Connected, Partially Connected, and Disconnected Jumpoints.

For more information, see:
Prioritize external representative invite session policy over jump item session policies
Managing Jump Client sessions just got easier, and way more intuitive. You can now prioritize Session Policies assigned to external reps/access invites, ensuring expected policy enforcement in external session/access scenarios.
What’s New?
- The policy selected during the invitation process is the only policy applied to the invited Rep.
- Jump Item and Public Portal policies are skipped for external invitees.

For more information, see:
Additional security controls for Command Shell context
Flexibility meets control! Shells start in the context of the endpoint’s logged in user and use a button in the console to open an elevated shell tab that runs in the system/root context (only if the Jump Client is elevated).
- Match the Logged-In User for a familiar experience
- Go System/Root when Jump Client is elevated for full power

Allow Shell rules

Allow elevated access

Open elevated shell tab running on system/root context
Your shell, your rules. Simple, secure, and ready to roll!
For more information, see:
Granular /login admin permissions
We’re introducing granular RBAC magic to make remote access management a breeze.
Remote Access Management Role
- Non-admins can add members to group policies

Why it matters:
Delegate /login administrative tasks to others that don’t need global admin rights to enable zero trust.
Non-admins:
- Can see the Group Policy tab
- Cannot create a new group policy or change the order
- Can only see and edit group policies they are in and
- Only membership section
For more information, see:
Grey out Vault accounts already in use
If a Vault account doesn’t allow simultaneous checkout and you try to grab it while someone else already has, no worries! The account still displays, but is grayed out with a little lock icon. Hover over it, and you’ll see a friendly message letting you know it’s currently checked out by another user.

Desktop Console

Web Console
For more information, see:
- Pathfinder - Allow simultaneous checkout rules
- Cloud - Allow simultaneous checkout rules
- On-Prem - Allow simultaneous checkout rules
Force close windows in elevated sessions
We’re adding new functionality to force close windows in an elevated session:
- New Config Option in /login > Management > Security
- Force-close any windows opened during an elevated session
- Applies to Windows elevated sessions only
- Off by default. Enable when you need that extra lockdown!

E.g.: Pathfinder - Management > Security > Representative Console
For more information, see:
📝 Requirements
- Requires Base 8.1.0
- Supports ECM Protocol 1.6
- Supports upgrades from 25.1.1 Remote Support+.
- Validated with ECM 1.6.5
- Validated with Integration Client 25.1.1
- Includes VSC 1.2.10.2
Before upgrading, ensure any SSL certificates used are either from a trusted Certificate Authority, or, for self-signed certificates, the certificate is either trusted on all endpoints or explicitly included in their installation.