Skip to content
Endpoint Manager

Release Notes

What has changed in Endpoint Manager for Cisco ISE, newest first.

Bug fixes and routine maintenance are not listed here. The platform release notes cover every service in one feed.

  1. 2026

    New

    Custom attributes at two levels #

    Custom attributes can now be defined as endpoint managed as well as group managed. A group managed attribute holds one value applied to every endpoint in the group, as before. An endpoint managed attribute holds a value on each device, entered when the device is added or edited, and is opted in per group. The level belongs to the attribute and is fixed when it is created.

    A definition now also carries an input type (text, integer, decimal, toggle, IP address, date, dropdown or key), an optional display name, a required flag, and a self-service exposure setting of none, display or editable. Dropdown options carry a description and an optional icon, so the value written to Cisco ISE can stay machine friendly while readers see something meaningful.

    Device type is no longer a fixed field. It ships as a seeded system attribute named Device Type, pre-selected on every group, whose options, requiredness and exposure an administrator can edit.

    New

    Identity PSK, shared or per device #

    An attribute can hold a Wi-Fi pre-shared key that the platform generates and rotates: one shared key for a whole group, or a unique key on every device. A group carries one variant or the other, never both.

    When a shared group key is activated you choose between supplying the key the group already uses and letting the platform generate a new one. Supplying the existing key is what lets you bring a fleet that is already connected under management without knocking it off the network.

    Updating or regenerating a key rewrites it on every affected endpoint and triggers a Change of Authorization, so the previous key stops working immediately. You can also supply a key you already use when adding an individual device, not only when activating a group key.

    A group now carries a Wi-Fi network name, prompted when a group key is activated. It is what the self-service connect guide and its QR code are built from.

    Self-service users can reveal, copy and, where permitted, rotate their device key, and read it as a Wi-Fi QR code. Note that a group is administered collectively: every member of a group can see the keys of the devices in it.

    Improved

    Attribute definitions can be reordered #

    The order you put the definitions in decides the field order everywhere the attributes appear, in both the admin console and the Self-Service portal.

    Improved

    Device writes are validated before anything reaches Cisco ISE #

    The MAC format, that the attribute keys are known and at the right level, and that each value fits its input type are all checked up front. Batch rows are validated the same way, with the row number in the error, so a file that would previously have half-succeeded is rejected before it starts.

    Changed

    A group applies only the attributes it manages #

    Previously a group wrote every attribute the service context defined and blanked the ones it had no value for. It now leaves attributes it does not manage alone.

    Changed

    Moving an endpoint applies the destination group's values #

    Attributes the destination group does not manage keep the value they had, and endpoint level values are carried over untouched.

    Changed

    Drift correction covers group managed values only #

    The periodic verification task never reads or rewrites an endpoint level value, so a per device asset ID or key is not corrected away by it.

  2. 2026

    Improved

    The exact request behind a failed call #

    An Integration Log entry now carries the outgoing request exactly as it was sent, together with a ready to run command that reproduces it, so a failing call can be tested from elsewhere. Very large requests are stored in shortened form and offer no command, because it would no longer reproduce the original call.

  3. 2026

    Improved

    Turn off HTTP keep-alive for Cisco ISE calls #

    A service context can disable HTTP keep-alive on its outbound calls to Cisco ISE, on the API tab of the context settings. Some load balancers and firewalls in front of Cisco ISE handle persistent connections poorly, and this is the switch for those deployments.

  4. 2026

    New

    Integration Log: see why a call to Cisco ISE failed #

    Each service context now records the outbound calls to Cisco ISE that failed, and keeps them for 30 days: the operation, who or what triggered it, the reason it failed, and the response. Entries carry an explanation written to be acted on rather than escalated.

    Failures are separated into distinct reasons, so an unreachable host is not reported as a certificate problem. The log is reachable from a tab on the service context and from the Cisco ISE API status card.

  5. 2026

    New

    Reach a Cisco ISE that is not exposed to the internet #

    A service context can now reach Cisco ISE through a Service Connector over IPSec instead of calling it over the public internet. The Cisco ISE deployment no longer has to be publicly reachable, and no inbound path from the platform to the ISE administration node is required.

    The choice is made per service context on the Cisco ISE connection settings, between calling the API directly and routing it through the connector. Everything else about the integration is unchanged: the same three API families, the same API account, and the same behaviour in the console.

    Service Connector

  6. 2025

    Improved

    Search and endpoint counts on the group overview #

    The overview lists every Cisco ISE endpoint group, supports search by name, and shows how many endpoints each group holds.

    Improved

    Search endpoints by MAC address #

    The endpoint overview covers every Cisco ISE endpoint and can be searched by MAC address.

    New

    Service context dashboard metrics #

    The dashboard now reports the number of Cisco ISE endpoint groups, the number of endpoints, how many groups are connected, and how many Self-Service Users exist.

    New

    Create an endpoint identity group from the platform #

    Administrators can create a new Cisco ISE endpoint identity group without leaving the admin console.

    Improved

    Browse everything before connecting a group #

    All Cisco ISE endpoint groups and endpoints can be inspected without bringing any group under management first.

    Changed

    Bringing a group under management is now called connecting it #

    The flow used to be described as creating a group, which suggested the platform made something new in Cisco ISE. It does not. It connects a group that already exists.

    Changed

    Endpoint IP addresses follow Cisco ISE #

    The address shown for an endpoint is the one Cisco ISE reports through its own API rather than one derived from session data, so the console and Cisco ISE agree.

    Changed

    Groups are labelled connected or unconnected #

    The previous labels, managed and unmanaged, said less about what the state actually meant.

    New

    Move endpoints between groups, and export a group #

    Endpoints can be moved from one group to another, and a group can be exported as a CSV file.

    A Change of Authorization is triggered automatically when endpoints are added, removed, updated or moved, so Cisco ISE re-evaluates them without waiting for the next natural re-authentication.

    New

    Trigger a Change of Authorization from the console #

    Administrators can ask Cisco ISE to re-authenticate an endpoint on demand.

    New

    Add endpoints in bulk from a CSV file #

    Batch upload is available in both the admin console and the Self-Service portal.

    Self-Service

    Improved

    Clearer invitation emails for Self-Service Users #

    The email a Self-Service User receives explains what they have been given access to and how to reach it.

    Self-Service

  7. 2025

    New

    Define which Cisco ISE custom attributes the platform manages #

    A service context declares which Cisco ISE endpoint custom attributes are available to the groups under it, so only the attributes you intend to manage can be applied to endpoints.

    New

    Apply an attribute value across a whole group #

    A value set on a group is written to every endpoint in it, whether the endpoint was added by an administrator or through self-service, and a scheduled verification keeps them consistent.

    The clearest use is Identity PSK, where every endpoint in a group is meant to carry the same key.

  8. 2025

    New

    Endpoint status and a fuller endpoint list #

    An endpoint shows whether it is currently connected, in the admin console and in the Self-Service portal, together with what it is connected to.

    The admin console gained a detail list for the endpoints in a group with an action menu per row, and a service context can be given a description of its own.

    The console also checks up front whether the API account is allowed to read session data, instead of failing later without explaining why.

    Self-Service

  9. 2024

    New

    Endpoint Manager for Cisco ISE #

    An existing Cisco ISE endpoint identity group can be brought under management from the platform, and administered without anyone signing in to Cisco ISE. A group can also be pointed at a different context later without being recreated.

    Endpoints carry attributes written onto the Cisco ISE record, including their device type, and the console keeps an audit of what was changed and validates the connection settings before saving them.

    Delegated administration came with it: the people who own the equipment manage their own endpoints from the Self-Service portal.

    A Cisco ISE API status card reports whether the platform can reach the deployment, and a service context carries a connection name of its own so several can be told apart.