This release restores SSO access for provider-bound accounts to ensure seamless portal authentication.
Highlights
Restored SSO access for provider-bound accounts.
Fixes
SSO portal access: You can now log in to the portal using your provider-bound SSO credentials again, resolving an issue that prevented access for specific account types.
This release introduces a streamlined policy creation wizard, a new fleet-wide activity dashboard, and significant performance optimizations for policy delivery.
Highlights
Simplified policy creation wizard reduces steps from four to three.
New fleet-wide Activity tab provides a unified view of endpoint check-ins and command queues.
Policy delivery performance is significantly improved through automated artifact caching.
Health-check reporting now provides more accurate endpoint and event data.
Features
Simplified policy creation wizard: You can now create policies in three steps instead of four, allowing for a faster and more intuitive setup process.
Fleet-wide Activity tab: You can now monitor command queues and recent check-in heartbeats across your entire fleet in a single, unified view on the Devices page.
Security
DefenderKiller KSLDriver intel: You are now protected against the DefenderKiller KSLDriver with the addition of its specific Authentihash to our threat intelligence database.
Fixes
Accurate health-check reporting: Health-check reports now provide more reliable data by using canonical endpoint identification and improved pagination, ensuring large organizations receive complete and accurate insights.
Improvements
Landing page animations: Problem stat animations now trigger immediately upon entering the viewport, providing a smoother and more responsive experience when first visiting the site.
Updated email branding: Email notifications now feature a consistent, modern dark-mode design that matches the rest of the MagicSword platform.
Performance
Cached policy delivery artifacts: Faster policy delivery is now available as the system caches verified artifacts, reducing the need for repeated, resource-intensive policy generation during endpoint check-ins.
This release improves command-line observation processing reliability and ensures WDAC intel metadata remains accurate during policy updates.
Highlights
Improved stability for command-line observation processing.
Enhanced data integrity for WDAC intel metadata.
Fixes
Command-line observation processing: You will experience fewer processing errors during high-volume periods as the system now dynamically adjusts batch sizes to prevent statement timeouts.
This release improves agent update reliability, enhances audit and reporting privacy, and refines user entity privilege labeling.
Highlights
Improved agent update status accuracy and retry reliability.
More accurate privilege labeling for standard user entities.
Improved performance for large policy rule fetches and command-line observation processing.
Fixes
Microsoft intel blocklist retirement: Microsoft-backed vulnerable driver and recommended blocklist sources have been removed to streamline your intelligence configuration.
Stale agent update state: The portal now correctly clears update status when an agent reaches its target version, preventing endpoints from appearing stuck in an 'Installing' state.
Endpoint policy assignment: Policy assignment now correctly handles endpoint metadata, preventing errors when assigning policies to agentless devices.
User privilege posture labeling: Standard users are no longer incorrectly labeled as 'Privileged' due to the presence of non-privileged posture evidence.
Pilot intel update cloning: Pilot users will no longer encounter errors when updating policies that previously contained premium intelligence sources.
SSO signup provisioning: SSO-authenticated users now correctly map to their organization roles without being incorrectly provisioned with trial pilot access.
Stale agent update heartbeat reports: The portal now ignores stale heartbeat reports that incorrectly claim an update failed after the agent has already successfully reached the target version.
Features
Paginated changelog: You can now browse the changelog more efficiently with server-side pagination, which improves page load performance as the release history grows.
Improved audit and compliance reporting: You can now export full audit and compliance reports without UI-imposed row caps, and audit logs now include readable details instead of truncated text.
User entity privilege tooltips: You can now hover over privilege badges and posture labels to see clear explanations of what specific privilege states mean for your user entities.
Performance
Optimized command-line and check-in processing: Faster and more reliable agent check-ins and command-line processing are achieved through non-blocking locks and increased timeout thresholds for large policies.
Data retention worker optimization: The data retention worker now processes organizations with shorter retention periods first, ensuring aged heartbeat logs are cleaned up more efficiently.
This release improves system stability for high-volume telemetry ingestion, introduces automated agent authentication rotation, and refines the landing page navigation.
Highlights
Improved reliability for high-volume filesystem inventory and process telemetry ingestion.
Added support for automated agent authentication token rotation to prevent stale endpoint connections.
Refined landing page navigation for better visual alignment and accessibility.
Fixes
Filesystem inventory ingestion stability: You can now process large filesystem inventory payloads without encountering database argument limits, ensuring complete visibility into endpoint file metadata.
Features
Agent authentication token rotation: Agents can now automatically rotate authentication tokens during heartbeat and check-in, ensuring continuous connectivity without manual re-enrollment.
Improvements
Landing page navigation alignment: Enjoy a more polished experience with improved visual alignment and spacing for navigation links, dropdowns, and call-to-action buttons on the landing page.
This release introduces legacy Windows 8+ and Server 2016+ support, bulk deployment tools for fleets, improved agent collection controls, and more reliable telemetry processing.
Highlights
Added full support for legacy Windows 8+ and Windows 2016+ environments, including AppLocker and WDAC policy management.
Introduced a new bulk deployment UI for assigning and deploying policies across your fleet.
Added agent collection controls for optional telemetry and inventory settings.
Improved user and process visibility across Windows, macOS, and Linux endpoints.
Enhanced telemetry reliability with staging queues for process observations, analytics events, and high-volume endpoint activity.
Features
Legacy Windows support: You can now manage AppLocker and WDAC policies on legacy Windows systems, helping maintain consistent security coverage across older and newer endpoints.
Fleet bulk deployment UI: You can now assign and deploy policies to multiple endpoints at once, simplifying policy rollout for larger environments.
Agent collection controls: You can now tune optional telemetry and inventory collection by category, giving teams more control over what endpoint data is collected.
Improved endpoint visibility: User context and process attribution are now richer across Windows, macOS, and Linux, making it easier to understand endpoint activity.
Fixes
AppLocker compatibility: MagicSword-managed policies now coexist more safely with customer-managed AppLocker rules.
Telemetry reliability: Process observations, analytics events, and endpoint activity are processed more reliably in high-volume environments.
Performance improvements: Heartbeat payloads are smaller, improving check-in performance and reducing bandwidth usage.
Diagnostics improvements: Windows event logging and support bundle diagnostics are cleaner and easier to use.
Database migration reliability: The system now applies updates more reliably by deferring heavy historical data processing, ensuring new features are deployed without interruption.