Skip to content
Get Started

Release Notes

New capabilities, improvements and changes to existing behaviour across every service, newest first.

Bug fixes and routine maintenance are not listed here. Each service also keeps its own Release Notes page, showing the same entries filtered to that service.

80 entries

  1. 2026

    New

    Custom attributes at two levels #

    Custom attributes can now be defined as endpoint managed as well as group managed. A group managed attribute holds one value applied to every endpoint in the group, as before. An endpoint managed attribute holds a value on each device, entered when the device is added or edited, and is opted in per group. The level belongs to the attribute and is fixed when it is created.

    A definition now also carries an input type (text, integer, decimal, toggle, IP address, date, dropdown or key), an optional display name, a required flag, and a self-service exposure setting of none, display or editable. Dropdown options carry a description and an optional icon, so the value written to Cisco ISE can stay machine friendly while readers see something meaningful.

    Device type is no longer a fixed field. It ships as a seeded system attribute named Device Type, pre-selected on every group, whose options, requiredness and exposure an administrator can edit.

    Endpoint Manager

    New

    Identity PSK, shared or per device #

    An attribute can hold a Wi-Fi pre-shared key that the platform generates and rotates: one shared key for a whole group, or a unique key on every device. A group carries one variant or the other, never both.

    When a shared group key is activated you choose between supplying the key the group already uses and letting the platform generate a new one. Supplying the existing key is what lets you bring a fleet that is already connected under management without knocking it off the network.

    Updating or regenerating a key rewrites it on every affected endpoint and triggers a Change of Authorization, so the previous key stops working immediately. You can also supply a key you already use when adding an individual device, not only when activating a group key.

    A group now carries a Wi-Fi network name, prompted when a group key is activated. It is what the self-service connect guide and its QR code are built from.

    Self-service users can reveal, copy and, where permitted, rotate their device key, and read it as a Wi-Fi QR code. Note that a group is administered collectively: every member of a group can see the keys of the devices in it.

    Endpoint Manager

    Improved

    Attribute definitions can be reordered #

    The order you put the definitions in decides the field order everywhere the attributes appear, in both the admin console and the Self-Service portal.

    Endpoint Manager

    Improved

    Device writes are validated before anything reaches Cisco ISE #

    The MAC format, that the attribute keys are known and at the right level, and that each value fits its input type are all checked up front. Batch rows are validated the same way, with the row number in the error, so a file that would previously have half-succeeded is rejected before it starts.

    Endpoint Manager

    Changed

    A group applies only the attributes it manages #

    Previously a group wrote every attribute the service context defined and blanked the ones it had no value for. It now leaves attributes it does not manage alone.

    Endpoint Manager

    Changed

    Moving an endpoint applies the destination group's values #

    Attributes the destination group does not manage keep the value they had, and endpoint level values are carried over untouched.

    Endpoint Manager

    Changed

    Drift correction covers group managed values only #

    The periodic verification task never reads or rewrites an endpoint level value, so a per device asset ID or key is not corrected away by it.

    Endpoint Manager

  2. 2026

    New

    Cloud DNS #

    A Sign In Enterprise network can be turned from plain DNS forwarding into a managed filtering resolver that Netgraph runs for it. Every lookup is checked against the policy you set before it is answered: blocked domains do not resolve, allowlisted domains always do.

    You subscribe to blocklists by URL, which are fetched and kept refreshed for you, or build your own. Allowlists always override blocklists, and custom records map internal names to addresses.

    A ruleset combines the lists, an audience of either the whole network or selected sites, and an optional weekly schedule with its own time zone, so a policy can apply only at certain hours.

    Lists and records can be imported and exported in bulk, and the fetch status of a subscribed list shows when it was last refreshed.

    Cloud DNS Sign In

  3. 2026

    New

    Attribute Profiles on an EasyPSK group #

    An EasyPSK group can be given Attribute Profiles from its Group Settings, so the network policy returned at authentication, a VLAN through tunnel attributes or a Cisco security group tag, is set per group. The other EntryPoint variants already worked this way and EasyPSK now matches them.

    Profiles are defined once on the service context and reused across its groups.

    EasyPSK EntryPoint

  4. 2026

    Improved

    The exact request behind a failed call #

    An Integration Log entry now carries the outgoing request exactly as it was sent, together with a ready to run command that reproduces it, so a failing call can be tested from elsewhere. Very large requests are stored in shortened form and offer no command, because it would no longer reproduce the original call.

    Endpoint Manager

  5. 2026

    Improved

    Turn off HTTP keep-alive for Cisco ISE calls #

    A service context can disable HTTP keep-alive on its outbound calls to Cisco ISE, on the API tab of the context settings. Some load balancers and firewalls in front of Cisco ISE handle persistent connections poorly, and this is the switch for those deployments.

    Endpoint Manager

  6. 2026

    New

    Reconcile a whole Meraki WPN context from one CSV file #

    Batch Group Sync takes a CSV of groups, units and members and reconciles an entire context against it in one run. Groups and users are created, updated, reset or removed so the context ends up matching the file.

    Nothing is applied before you have seen it. The file is parsed and analysed first, then a review step reports the counts per action and asks you to confirm the scope of what the run will change. A file with errors blocks the analysis rather than producing a half-applied run.

    The run is monitored live, survives a page refresh, and can be exported as a CSV when it finishes. Earlier runs are kept in a run history.

    It is reached from the Groups page of a Meraki WPN context. An example file can be downloaded from the upload step, and a context can export its current groups as a CSV to start from.

    EasyPSK

    Improved

    Optional phone number on a Meraki WPN member #

    A member of a Meraki WPN group can carry a phone number. Administrators set it from the admin console, and group administrators can set or update it in the Self-Service portal.

    The number has to include a country code. It is contact information held with the member and nothing is sent to it.

    EasyPSK Self-Service

  7. 2026

    New

    Teams: grant roles once, to a group of administrators #

    A Team is a named group of administrators that holds roles. Instead of assigning roles to each person, you grant them to a Team and manage who belongs to it. Every member inherits what the Team holds.

    A Team can hold different roles in different service contexts, so one team can administer a context while holding read only access to another. Access to a further context can be added from the Team itself.

    An administrator's detail page lists the Teams they belong to and what each one grants, so it is possible to see where a person's access actually comes from.

    Available at organization level and, for partners, in the MSP Portal.

    Platform MSP Portal

    New

    Provision administrators from your identity provider with SCIM #

    Administrator accounts and groups can be provisioned automatically from an identity provider over SCIM 2.0. When someone joins the relevant group in your directory they become an administrator here, and when they are removed or deactivated their access is withdrawn.

    A provisioned group becomes a Team, so the roles granted to that Team apply to whoever your directory places in it.

    A provisioning activity log records what the identity provider sent and what came of it, searchable and paged.

    Platform MSP Portal

  8. 2026

    New

    Create DHCP scopes in bulk on a Service Gateway #

    DHCP scopes can be uploaded as a batch instead of created one at a time, and the scope selector stays usable when a gateway carries a large number of them.

    Sign In

    New

    Administrators can sign in with SAML single sign-on #

    An organization, and a partner in the MSP Portal, can federate administrator sign-in with its own identity provider. The sign-in page offers the identity providers configured for the scope being signed in to.

    A federation carries a default role, so someone who arrives without a role claim still lands with defined access, and roles can be mapped from the claim your identity provider sends.

    Administrators who arrive this way appear in the list without having been invited, with the source of the account shown alongside the date they joined.

    Platform MSP Portal

  9. 2026

    Improved

    Export whitelistings, and import them with an end date #

    A context can export its whitelistings, and the import file accepts an optional end date column, so an entry can be given an expiry when it is created rather than afterwards.

    Sign In

  10. 2026

    New

    Reveal and rotate a device key from the Self-Service portal #

    A Self-Service User can see a device key, copy it, and read it as a Wi-Fi QR code together with the network name, without going through an administrator.

    Rotating a key is tied to the user's role and can be switched off for the context, so an administrator decides whether delegated users may regenerate keys at all.

    The device view also shows accounting data for the group, so a delegated administrator can see what is actually connected.

    EasyPSK Self-Service

    New

    The Self-Service portal in thirteen languages #

    The portal is available in every language an organization can be set to. A language picker is offered, and the organization's own default takes precedence over a secondary browser language rather than losing to it.

    The page also reports its active language to the browser, so screen readers pronounce it correctly.

    Self-Service Platform

    Improved

    Better device type identification #

    Device type is derived from more of the profiling data the wireless network reports, so devices that previously showed as unknown are now classified. Apple TV, Apple Watch and HomePod are recognised as their own types rather than being lumped together.

    EntryPoint EasyPSK

    New

    EasyPSK over RADIUS #

    EasyPSK can now be delivered over RADIUS, created and managed as a context variant of EntryPoint, alongside the existing Cisco Meraki WPN path. The key a device presents identifies its group, and the group's network attributes are returned at authentication, so keys resolve at connect time instead of being pushed into the wireless platform in advance.

    This is the primary delivery for Cisco Meraki and Cisco Catalyst 9800. It carries far more keys than the Dashboard API path, which remains available and is capped per Meraki network.

    A group is created with one of three flavours. Instant shares one group key and registers a device on first connect. Approved shares one group key but admits only MAC addresses registered in advance, with optional four-eyes approval. Dedicated gives every device its own key, and both the MAC and the key have to match.

    EasyPSK EntryPoint

  11. 2026

    New

    Integration Log: see why a call to Cisco ISE failed #

    Each service context now records the outbound calls to Cisco ISE that failed, and keeps them for 30 days: the operation, who or what triggered it, the reason it failed, and the response. Entries carry an explanation written to be acted on rather than escalated.

    Failures are separated into distinct reasons, so an unreachable host is not reported as a certificate problem. The log is reachable from a tab on the service context and from the Cisco ISE API status card.

    Endpoint Manager

    Improved

    PEAP account passwords are hidden by default #

    An account password is masked in the admin console list, with a show and hide control on each row, so the list can be read over someone's shoulder without exposing credentials.

    EntryPoint

  12. 2026

    New

    Reach a Cisco ISE that is not exposed to the internet #

    A service context can now reach Cisco ISE through a Service Connector over IPSec instead of calling it over the public internet. The Cisco ISE deployment no longer has to be publicly reachable, and no inbound path from the platform to the ISE administration node is required.

    The choice is made per service context on the Cisco ISE connection settings, between calling the API directly and routing it through the connector. Everything else about the integration is unchanged: the same three API families, the same API account, and the same behaviour in the console.

    Endpoint Manager Service Connector

    New

    Private connectivity between the platform and your network #

    An organization can reach the platform over a private IPSec tunnel instead of the public internet. A firewall, or any device on your side that supports IPSec, establishes a single tunnel to a dedicated endpoint on the platform, and the services you bind to it carry their traffic through it.

    EntryPoint's RADIUS path, EasyPSK via RADIUS, the platform's access to an on-premises Cisco ISE, and webhook deliveries can each be bound to the same tunnel. Sign In is not carried this way: it uses the Service Gateway.

    A connector's page shows the settings to apply on your own device, including a worked Cisco IOS-XE example, the routes the connector publishes, and which services and ports are using it. Tunnel status is shown per connector, and the destination of a bound service can be changed without unbinding it first.

    Available to organization administrators and, for partners, in the MSP Portal.

    Service Connector Platform EntryPoint EasyPSK

  13. 2026

    Improved

    Support information on a service #

    The services list in the MSP Portal shows support information for a service in one place, laid out in sections and naming the cloud the service runs in.

    MSP Portal

  14. 2026

    Changed

    The Sign In dashboard says "Logins last 24h" #

    The card was headed "Logins Today", which read as logins since midnight. It has always counted a rolling 24 hour window, and the heading now says so. The number itself is unchanged, but a report built on the old wording was measuring something else than it claimed.

    Sign In

    Improved

    See the RADIUS payload behind an authentication #

    The admin console shows the incoming request as it arrived, so an authentication that did not behave as expected can be inspected without taking a packet capture.

    The device list searches across several fields at once, including the called station identifier, and shows a fuller description for 802.1X flows.

    EntryPoint EasyPSK

  15. 2026

    Improved

    Move an EntryPoint device to another group #

    A registered device can be moved from one group to another from the admin console, so a device that ends up in the wrong group does not have to be removed and registered again.

    EntryPoint

  16. 2026

    Improved

    The address webhooks are delivered from #

    The basic settings show the source host name that webhook deliveries come from, so it can be allowed through a firewall without guessing.

    Platform

  17. 2026

    New

    Authentication Log #

    Every RADIUS authentication attempt is recorded with its outcome, and for a denial the specific reason: an unknown RADIUS client, a shared secret that does not match, an unregistered device, a user outside the expected group, or a configuration problem.

    An attempt expands into a timeline of the decision points that led to the outcome, and the request and the response can be inspected as readable tables rather than raw text.

    The log is filtered by time range, by decision and by free text, and it is embedded on the context and group pages as well as available on its own, so it can be reached from the device or group being investigated.

    EntryPoint EasyPSK

  18. 2026

    New

    Fill the captive portal's look and feel from your website #

    The portal's colours and imagery can be drawn from a website address instead of being set by hand, and the address is prefilled from the organization's own website when one is recorded.

    Sign In

  19. 2026

    Improved

    You land back where you were after signing in again #

    When a session expires the page you were on is remembered, and you are returned to it after signing in instead of to the dashboard.

    Platform

    New

    MSP Tenant Helpdesk role #

    A partner role for staff who support customers day to day, without the rights that come with administering the partner itself.

    MSP Portal

  20. 2026

    New

    Service Gateway configuration frameworks #

    A Service Gateway is configured from a framework template rather than field by field. The template carries variables, and the console shows which ones are unresolved and which custom variables are defined but never used, so a template can be checked before it is applied.

    A template with unresolved variables cannot be downloaded, which is what previously produced a gateway configuration that looked complete and was not.

    Creating a gateway also asks for less: IP and BGP settings are no longer required and fall back to defaults, and framework and BGP settings are edited in place instead of through separate dialogs.

    Available to organization administrators and, for partners, in the MSP Portal.

    Sign In MSP Portal

  21. 2026

    New

    MAC Authentication Bypass fallback in a Dot1x context #

    A Dot1x context can admit a device by its MAC address when 802.1X does not complete, so headless equipment on the same SSID does not need a context of its own.

    EntryPoint

  22. 2026

    New

    Send a guest to a chosen address after sign-in #

    A site can define the address a guest is sent to once they are online, so the portal can hand over to a venue page or a booking system instead of the page the guest first tried to reach.

    Sign In

  23. 2026

    New

    Additional Input Fields on email self-registration #

    The email self-registration form can carry extra fields that you define, so a guest can be asked for what the venue actually needs, such as a room number, a company or a reason for the visit.

    Sign In

  24. 2026

    New

    A connection limit on Quick Access #

    Quick Access, the one-click sign-in that asks a guest for nothing, can be given a limit on how many connections it admits, so an open network can be capped without switching to a login module that asks for an identity.

    Sign In

  25. 2026

    New

    DHCP Option 114 policy per scope #

    Each DHCP scope on a Service Gateway decides for itself whether it hands out Option 114, the captive-portal address that lets a device open the portal on its own instead of waiting for a redirect. The scope list shows the policy per scope.

    Sign In

  26. 2026

    New

    Roles granted per organization and per service context #

    An administrator is given roles at the level the access belongs to: on the organization, or on a single service context inside it. The same person can therefore administer one service while only reading another.

    The partner side works the same way in the MSP Portal, with its own set of partner roles.

    Platform MSP Portal

  27. 2026

    New

    Organizations and service contexts #

    A customer is an organization, and each service it runs is a service context inside that organization. Sign In, EntryPoint, EasyPSK and Endpoint Manager are all created and administered the same way, under the same organization, instead of each living in its own structure.

    One identity can hold roles in more than one organization and move between them without signing out, which is what lets a consultant or a partner employee work across several customers.

    Platform

  28. 2026

    New

    SAML single sign-on for administrators, Self-Service and the captive portal #

    An organization can federate sign-in against its own identity provider on all three surfaces: the administration portal, the Self-Service portal, and the captive portal where a guest or employee signs in to the network.

    Each surface is configured separately, so an organization can federate its administrators without federating its guests, or the other way around.

    Platform Self-Service Sign In

  29. 2025

    New

    Restrict administration to your own IP ranges #

    An organization can list the IP ranges its administrators sign in from, so the administration portal answers only from the networks you name.

    Platform

  30. 2025

    Changed

    One audit log and one webhook model across every service #

    Administrative changes are recorded the same way whichever service they concern, and read from one place, instead of each service keeping its own record in its own shape.

    Webhooks follow the same model, so the events an integration subscribes to look alike across services.

    Platform

  31. 2025

    New

    The MSP Portal #

    Partners have their own portal, separate from the Administration and Self-Service portals that customers use. It is where a partner provisions and manages the organizations it serves, and follows their usage and support.

    MSP Portal Platform

  32. 2025

    Improved

    Search and endpoint counts on the group overview #

    The overview lists every Cisco ISE endpoint group, supports search by name, and shows how many endpoints each group holds.

    Endpoint Manager

    Improved

    Search endpoints by MAC address #

    The endpoint overview covers every Cisco ISE endpoint and can be searched by MAC address.

    Endpoint Manager

    New

    Service context dashboard metrics #

    The dashboard now reports the number of Cisco ISE endpoint groups, the number of endpoints, how many groups are connected, and how many Self-Service Users exist.

    Endpoint Manager

    New

    Create an endpoint identity group from the platform #

    Administrators can create a new Cisco ISE endpoint identity group without leaving the admin console.

    Endpoint Manager

    Improved

    Browse everything before connecting a group #

    All Cisco ISE endpoint groups and endpoints can be inspected without bringing any group under management first.

    Endpoint Manager

    Changed

    Bringing a group under management is now called connecting it #

    The flow used to be described as creating a group, which suggested the platform made something new in Cisco ISE. It does not. It connects a group that already exists.

    Endpoint Manager

    Changed

    Endpoint IP addresses follow Cisco ISE #

    The address shown for an endpoint is the one Cisco ISE reports through its own API rather than one derived from session data, so the console and Cisco ISE agree.

    Endpoint Manager

    Changed

    Groups are labelled connected or unconnected #

    The previous labels, managed and unmanaged, said less about what the state actually meant.

    Endpoint Manager

    New

    Move endpoints between groups, and export a group #

    Endpoints can be moved from one group to another, and a group can be exported as a CSV file.

    A Change of Authorization is triggered automatically when endpoints are added, removed, updated or moved, so Cisco ISE re-evaluates them without waiting for the next natural re-authentication.

    Endpoint Manager

    New

    Trigger a Change of Authorization from the console #

    Administrators can ask Cisco ISE to re-authenticate an endpoint on demand.

    Endpoint Manager

    New

    Add endpoints in bulk from a CSV file #

    Batch upload is available in both the admin console and the Self-Service portal.

    Endpoint Manager Self-Service

    Improved

    Clearer invitation emails for Self-Service Users #

    The email a Self-Service User receives explains what they have been given access to and how to reach it.

    Endpoint Manager Self-Service

  33. 2025

    New

    Define which Cisco ISE custom attributes the platform manages #

    A service context declares which Cisco ISE endpoint custom attributes are available to the groups under it, so only the attributes you intend to manage can be applied to endpoints.

    Endpoint Manager

    New

    Apply an attribute value across a whole group #

    A value set on a group is written to every endpoint in it, whether the endpoint was added by an administrator or through self-service, and a scheduled verification keeps them consistent.

    The clearest use is Identity PSK, where every endpoint in a group is meant to carry the same key.

    Endpoint Manager

  34. 2025

    New

    eduroam and RADIUS Proxy #

    EntryPoint can forward an authentication request upstream to a remote RADIUS federation instead of answering it itself. This is what an organization taking part in eduroam needs, and it is configured as a variant of an EntryPoint context like the others.

    EntryPoint

  35. 2025

    New

    Webhooks for every service #

    Webhooks are no longer tied to one service. Every service can publish its events, and which webhooks an administrator may see and change follows their roles.

    A delivery is inspectable: the console shows which endpoint was called, which event types the delivery carried, and whether it succeeded. Events raised while a webhook is switched off are held rather than lost, and the console says plainly that the webhook is disabled.

    Sign In session events are covered in full, and events can be delivered in batches instead of one request per event.

    Platform

  36. 2025

    New

    Password subscribers are told the new password by email #

    The people on a Password module subscription list are emailed when a new password takes effect, so reception staff and hosts do not have to look it up. The notification can also be sent again on request.

    Sign In

  37. 2025

    New

    Device certificates as their own EntryPoint variant #

    A context can authenticate equipment on a certificate that names the device rather than the user, which is what company-owned laptops and headless gear issued from a customer PKI need.

    EntryPoint

  38. 2025

    New

    Endpoint status and a fuller endpoint list #

    An endpoint shows whether it is currently connected, in the admin console and in the Self-Service portal, together with what it is connected to.

    The admin console gained a detail list for the endpoints in a group with an action menu per row, and a service context can be given a description of its own.

    The console also checks up front whether the API account is allowed to read session data, instead of failing later without explaining why.

    Endpoint Manager Self-Service

  39. 2025

    New

    Sites, and redirects that follow the site #

    A context can be divided into sites, and an access policy can defer its redirect to the address configured for the site the guest is actually at. One policy then sends guests to different places depending on where they connected.

    Sign In

  40. 2024

    Changed

    A RADIUS client secret per service #

    The RADIUS client secret is held separately for each service instead of being shared, so a secret can be rotated for one service without disturbing the other.

    EntryPoint EasyPSK

  41. 2024

    New

    Meraki WPN in the Self-Service portal #

    A delegated administrator can manage the devices and members of a Meraki WPN group from the Self-Service portal, without an account in the admin console.

    EasyPSK Self-Service

  42. 2024

    New

    Add iPSK devices in bulk #

    Devices can be uploaded to an iPSK group from a file instead of being added one at a time.

    EntryPoint

  43. 2024

    New

    Roles per service in the admin console #

    Each service carries its own set of administrator roles, so access can be granted for one service without granting it for the others an organization happens to run.

    Platform

  44. 2024

    Changed

    PEAP personal accounts belong to the group #

    Personal accounts are administered on the group rather than centrally, which is what makes it possible to delegate a group without handing over every account in the context.

    Self-service enrollment moved onto the group's Self-Service tab at the same time, next to the other delegation settings.

    EntryPoint

  45. 2024

    New

    Configurable data retention #

    How long login records, session history and device data are kept is set per service context, under Administration and Compliance. The shortest period that can be configured is one day.

    Terms and privacy policy are handled separately from each other at the same time, so one can be changed without touching the other.

    Sign In Platform

  46. 2024

    New

    Attribute Profiles #

    An Attribute Profile defines the network policy returned on a successful authentication, such as a VLAN through tunnel attributes or a Cisco security group tag. Profiles are defined once and reused across groups, so the same policy does not have to be typed out per group.

    EntryPoint

  47. 2024

    New

    EAP-TLS with Microsoft Entra ID #

    A context can authenticate users on a certificate issued through Microsoft Entra ID, with the certificate settings configured in the console and group membership checked against Entra at each authentication.

    EntryPoint

  48. 2024

    New

    Endpoint Manager for Cisco ISE #

    An existing Cisco ISE endpoint identity group can be brought under management from the platform, and administered without anyone signing in to Cisco ISE. A group can also be pointed at a different context later without being recreated.

    Endpoints carry attributes written onto the Cisco ISE record, including their device type, and the console keeps an audit of what was changed and validates the connection settings before saving them.

    Delegated administration came with it: the people who own the equipment manage their own endpoints from the Self-Service portal.

    A Cisco ISE API status card reports whether the platform can reach the deployment, and a service context carries a connection name of its own so several can be told apart.

    Endpoint Manager

  49. 2024

    Improved

    RADIUS settings for Meraki MAC authentication and the splash page #

    The RADIUS settings a Cisco Meraki network needs for MAC-based authentication and for the splash page are presented together, so the values to enter in the Meraki dashboard can be read off in one place.

    Sign In

  50. 2024

    Improved

    The Self-Service portal redesigned #

    A full pass over the portal: a dark mode that covers the whole interface, a search field on the device lists, a table view for devices as an alternative to cards, and icons that distinguish wired from wireless at a glance.

    Keys are masked in the connect instructions until asked for, a device list can be reloaded without leaving the page, and a Wi-Fi QR code prints properly.

    Self-Service

  51. 2024

    New

    Meraki group policy and access policy strategy #

    A Meraki integration carries a group policy and an access policy strategy, set when the integration is added and changeable afterwards. The group policy can be changed where the strategy is a shared one, and the Meraki API user can be updated without recreating the integration.

    EasyPSK

  52. 2024

    New

    DHCP audit #

    DHCP activity is recorded and can be downloaded, and the lease history for a single device is shown on that device in the console, so an address can be traced back to the equipment that held it.

    Sign In

Next