Skip to content
Platform

Release Notes

What has changed in the shared platform every service runs on, newest first.

Changes to administration, roles and Teams, identity and provisioning. Bug fixes and routine maintenance are not listed here, and the platform release notes cover every service in one feed.

  1. 2026

    New

    Teams: grant roles once, to a group of administrators #

    A Team is a named group of administrators that holds roles. Instead of assigning roles to each person, you grant them to a Team and manage who belongs to it. Every member inherits what the Team holds.

    A Team can hold different roles in different service contexts, so one team can administer a context while holding read only access to another. Access to a further context can be added from the Team itself.

    An administrator's detail page lists the Teams they belong to and what each one grants, so it is possible to see where a person's access actually comes from.

    Available at organization level and, for partners, in the MSP Portal.

    MSP Portal

    New

    Provision administrators from your identity provider with SCIM #

    Administrator accounts and groups can be provisioned automatically from an identity provider over SCIM 2.0. When someone joins the relevant group in your directory they become an administrator here, and when they are removed or deactivated their access is withdrawn.

    A provisioned group becomes a Team, so the roles granted to that Team apply to whoever your directory places in it.

    A provisioning activity log records what the identity provider sent and what came of it, searchable and paged.

    MSP Portal

  2. 2026

    New

    Administrators can sign in with SAML single sign-on #

    An organization, and a partner in the MSP Portal, can federate administrator sign-in with its own identity provider. The sign-in page offers the identity providers configured for the scope being signed in to.

    A federation carries a default role, so someone who arrives without a role claim still lands with defined access, and roles can be mapped from the claim your identity provider sends.

    Administrators who arrive this way appear in the list without having been invited, with the source of the account shown alongside the date they joined.

    MSP Portal

  3. 2026

    New

    The Self-Service portal in thirteen languages #

    The portal is available in every language an organization can be set to. A language picker is offered, and the organization's own default takes precedence over a secondary browser language rather than losing to it.

    The page also reports its active language to the browser, so screen readers pronounce it correctly.

    Self-Service

  4. 2026

    New

    Private connectivity between the platform and your network #

    An organization can reach the platform over a private IPSec tunnel instead of the public internet. A firewall, or any device on your side that supports IPSec, establishes a single tunnel to a dedicated endpoint on the platform, and the services you bind to it carry their traffic through it.

    EntryPoint's RADIUS path, EasyPSK via RADIUS, the platform's access to an on-premises Cisco ISE, and webhook deliveries can each be bound to the same tunnel. Sign In is not carried this way: it uses the Service Gateway.

    A connector's page shows the settings to apply on your own device, including a worked Cisco IOS-XE example, the routes the connector publishes, and which services and ports are using it. Tunnel status is shown per connector, and the destination of a bound service can be changed without unbinding it first.

    Available to organization administrators and, for partners, in the MSP Portal.

    Service Connector EntryPoint EasyPSK

  5. 2026

    Improved

    The address webhooks are delivered from #

    The basic settings show the source host name that webhook deliveries come from, so it can be allowed through a firewall without guessing.

  6. 2026

    Improved

    You land back where you were after signing in again #

    When a session expires the page you were on is remembered, and you are returned to it after signing in instead of to the dashboard.

  7. 2026

    New

    Roles granted per organization and per service context #

    An administrator is given roles at the level the access belongs to: on the organization, or on a single service context inside it. The same person can therefore administer one service while only reading another.

    The partner side works the same way in the MSP Portal, with its own set of partner roles.

    MSP Portal

  8. 2026

    New

    Organizations and service contexts #

    A customer is an organization, and each service it runs is a service context inside that organization. Sign In, EntryPoint, EasyPSK and Endpoint Manager are all created and administered the same way, under the same organization, instead of each living in its own structure.

    One identity can hold roles in more than one organization and move between them without signing out, which is what lets a consultant or a partner employee work across several customers.

  9. 2026

    New

    SAML single sign-on for administrators, Self-Service and the captive portal #

    An organization can federate sign-in against its own identity provider on all three surfaces: the administration portal, the Self-Service portal, and the captive portal where a guest or employee signs in to the network.

    Each surface is configured separately, so an organization can federate its administrators without federating its guests, or the other way around.

    Self-Service Sign In

  10. 2025

    New

    Restrict administration to your own IP ranges #

    An organization can list the IP ranges its administrators sign in from, so the administration portal answers only from the networks you name.

  11. 2025

    Changed

    One audit log and one webhook model across every service #

    Administrative changes are recorded the same way whichever service they concern, and read from one place, instead of each service keeping its own record in its own shape.

    Webhooks follow the same model, so the events an integration subscribes to look alike across services.

  12. 2025

    New

    The MSP Portal #

    Partners have their own portal, separate from the Administration and Self-Service portals that customers use. It is where a partner provisions and manages the organizations it serves, and follows their usage and support.

    MSP Portal

  13. 2025

    New

    Webhooks for every service #

    Webhooks are no longer tied to one service. Every service can publish its events, and which webhooks an administrator may see and change follows their roles.

    A delivery is inspectable: the console shows which endpoint was called, which event types the delivery carried, and whether it succeeded. Events raised while a webhook is switched off are held rather than lost, and the console says plainly that the webhook is disabled.

    Sign In session events are covered in full, and events can be delivered in batches instead of one request per event.

  14. 2024

    New

    Roles per service in the admin console #

    Each service carries its own set of administrator roles, so access can be granted for one service without granting it for the others an organization happens to run.

  15. 2024

    New

    Configurable data retention #

    How long login records, session history and device data are kept is set per service context, under Administration and Compliance. The shortest period that can be configured is one day.

    Terms and privacy policy are handled separately from each other at the same time, so one can be changed without touching the other.

    Sign In

Next