Changelog - Idemeum Docs
Documentation Index
Fetch the complete documentation index at: /llms.txt
Use this file to discover all available pages before exploring further.
6/8/2026 New
- AI analysis agent to analyze and explain every elevation or execution event - docs, demo video
- Request approval flows for application allowlisting
- Sudo application control on macOS - docs
- New admin portal UI
6/8/2026 Improvements
- Registry flag for application control mode - docs
- SMB/IPC protocol replaced with LDAP during JIT login to avoid multiple connection conflicts
- Fix potential memory leak in IDM notification process
- Not applying elevation for admin users - docs
- Desktop name fix: No longer dependent on network to derive the hostname
4/16/2026 New
- Integration with Sophos Intellix for malware reputation. Every application hash is verified against malware database - learn more
- Confidence score for each application - learn more
- Publishers view to discover all publishers and auto create rules - learn more
- Agent diagnostics to troubleshoot installation failures - learn more
4/16/2026 Improvements
- When requesting Entra JIT account we check if the account is locked. If it is, then idemeum automatically unlocks it.
3/13/2026 New
- Elevation and allowlisting rules when computers are offline
- Per device rules for EPM and AL
- Automatic domain JIT account deletion if the account is not used for 30 days
2/4/2026 Improvements
- Events - Disable inputs when attributes values are empty
- IT Tenant - Show Auto update section in General settings
12/15/2025 New
- Admin email elevation notifications
- User email elevation notifications
- Reason for elevation
- Snooze allowlisting user pop ups
- Allowlist all verified publishers (Windows and macOS)
12/15/2025 Improvements
- Improved fragile apps handling in the audit mode
- Frequent MSA account update skipped to avoid replication conflicts
- Fixed the issue with application fencing not triggering post elevation flow
- Fixed the issue with multiple badge ids associated with a user record on enrollment
11/11/2025 New
- Application allowlisting for macOS (catalog, fencing, rule engine, and more)
10/14/2025 New
- macOS 2.0.0
- Unified macOS installation
- Menu bar dropdown on macOS (notifications and settings update)
10/14/2025 Improvements
- Migrated from daemon to macOS security extension
- Migrated to APNS notifications
- Reduced file size from 100MB to 35MB
9/14/2025 New
- macOS 1.16
- Support for macOS Tahoe
9/14/2025 Improvements
- macOS UI refresh with updated screen
- Windows agent migration to .NET 8.0
- Improved the TOTP login flow to account for the time drift
- Added support for German, Dutch, and French languages for Windows
- Improved performance for Windows allowlisting when collecting file information - responds 2x faster
8/18/2025 New
- Allowlisting for Windows ARM
- API - on-demand delegation for JIT access
8/18/2025 Improvements
- Ensure the user fast switch is enabled during agent installation and update
- Fix the issue of special characters in tenant display name - no longer allowing to save the display name with special characters
8/12/2025 New
- HaloPSA integration to approve tickets with buttons
- APIs to manage rules
- Auto user elevation for Windows apps
- Bulk rule deletion
- Process tree generation in the UI
7/30/2025 New
- Windows allowlisting - public release
7/23/2025 Improvements
- Updated terminology from customer to tenant everywhere in admin and user portals
- Improved tenant switcher to pull all tenants on customer tenant creation, no need to refresh the page for tenant switcher to display all tenants when new child tenant is created
- Provide search options for all drop down lists
- Close notification drawer on outside click
- Added additional test cases
- Fixed audit chart scrolling
- Fixed menu and close icons
- Fixed clipboard copy for DID
6/27/2025 New
- Real-time settings
6/27/2025 Improvements
- Updated our APIs to return parametrized installation command in addition to returning the whole command as a string.
- Enhanced Windows JIT login by avoiding automatic user switch on lock. No longer messing up with VPNs or user desktop settings.
- Enhanced how we tag devices in the admin portal. Now when agent is installed with properly show servers, domain controllers, or workstations. We also properly reflect domain, local, or Entra-joined status.
- Made an enhancement to ensure the JIT account always belongs to Administrator group. Even if membership is removed, idemeum will reassign it during next login.
- Enhanced RFID tap-out flow to ensure card data is cleared, i.e., card hold data time elapses before disconnecting or signing out of the session.
- Enhanced JIT flow to avoid WMI query which at times takes longer to complete.
- Enhanced UAC capture flow to handle unverified events properly.
- Improved log clean up.
- Google has discontinued support for the authorization flow in Internet Explorer, so changed to a Chromium-based browser instead of the default Internet Explorer for RFID SSO.
- Managing version.txt for RMM tools that cannot read from the registry.
- Optimized token fetch calls by leveraging the cached token in the Update Settings flow.
- Ensuring metadata is synced to the cloud once a day, if not updated
- Domain JIT account login: do not fail if one or more DC is not reachable during account verification.
- Fixed the issue of bulk elevation mode change in the UI.
- Fixed offline transition when DNS does not resolve the idemeum domain.
4/24/2025 New
- Device agent status
4/24/2025 Improvements
- Updated Immy.bot integration
- Add an option to set up tap out mode per device for RFID SSO devices
- Enhanced Entra JIT flows to prevent circular login issue by adding prompt=login query param to OIDC launch URL
- Show Invited status for newly added users when local directory is used
- Uninstall notification is now sent to device agent when the record is deleted from the cloud portal
- We now reload credential provider settings every time you switch between default and idemeum credential providers
- Fixed the bug in the MSP tenant switcher when multiple tenants were selected at once
4/3/2025 New
- Windows ARM support
- New APIs (
devicesandgroups)
4/3/2025 Improvements
- Enhanced
customerendpoints to return installation commands for customer tenants - Added option to change the display name for a customer tenant.
- Now when the desktop agent is installed on Windows, there is a unique agentId that is created in the registry.
- Updated the text and instructions in the welcome email that is received when you add / invite a new user to idemeum MSP tenant.
- When in RFID mode and Google directory is used as a user source, we now support logins with domain shared account, in case machine is domain-joined.
- we now support the option to delete the user from idemeum MSP tenant when the user source is Entra
- Fixed the issue for Entra ID admin accounts not being downgraded when Auto downgrade feature is enabled.
- Enhanced processing of the UAC events when the last logged in user is preselected.
- Fixed the credential submission loop when auto filling credentials for Entra ID in incognito mode.
- Fixed the issue of auto filling credentials in RFID mode when native credential provider was used.
- Fixed macOS issue when pkg files were not properly processed in Technician mode for automatic elevation.