Changelog

Follow up on the latest improvements and updates.

RSS

The new Windows Agent v2.4.100 introduces the following improvements:
Secure Access Tunnel Compatibility
Improved Secure Access Tunnel workflows for better compatibility across different network environments.
Full Computer Hostnames
Added support for retrieving full computer hostnames, rather than only NetBIOS names.
Client Identification Behind Shared IPs
Improved client identification when multiple clients share the same egress IP address, enabling more accurate rate-limiting.
DoH GET Request Support
Added support for GET requests in the DoH (DNS over HTTPS) module, which may be used by newer versions of Firefox.
Catch-All NRPT Policy Handling
Fixed an issue where a catch-all DNS NRPT policy received from a network interface could interfere with DNS queries sent from browsers to the DefensX DoH module.
VMware NAT Mode Support
Added support for VMware virtual machines running in NAT mode in environments where the provided DNS proxy is not fully RFC-compliant.
Windows HVCI Compliance
Improved Windows driver HVCI compliance, ensuring better compatibility with Windows Memory Integrity and other virtualization-based security features.
Driver Coexistence with Other ZTNA Solutions
Improved driver-level compatibility when DefensX and other ZTNA solutions are running simultaneously on the same computer.
DefensX now supports refreshing the Autotask field lists on demand. The Sync button on the Tickets tab of the Autotask integration updates the field lists used in the ticket configuration, so issue types and other values newly created in Autotask become available for selection immediately.
A Ticket Source can also be selected when configuring the Autotask ticket integration. Tickets opened by DefensX are then created with the selected source, so they can be identified and filtered by source in Autotask. Tickets created before this release have no source set.
Screenshot 2026-07-31 at 12
Values that have been disabled in Autotask are no longer listed, and dropdown lists across the Autotask ticket configuration are sorted alphabetically. This keeps the selection limited to values that are currently in use and makes them easier to find in longer lists.
Screenshot 2026-07-31 at 12
DefensX now helps organizations control which email domains can be used when signing in to websites. Login Guard can require users to sign in with approved company email domains or prevent company email addresses from being used on selected websites.
Screenshot 2026-07-08 at 14
Company email domains are defined under Email Domains, while Login Guard is enabled and applied through the Credential Policy. This allows organizations to enforce the appropriate sign-in rule for selected website categories or Custom URL Groups.
Screenshot 2026-07-10 at 15
For configuration details and example scenarios, see the Login Guard knowledge base article.
DefensX PSA ticket integrations (ConnectWise, HaloPSA, and Autotask) now support two-way closure sync, keeping request status in DefensX and ticket status in your PSA aligned without closing the same work in both places. Each direction can be turned on independently, so you decide exactly how the two systems track each other.
Screenshot 2026-06-22 at 18
When a request is resolved in DefensX, the corresponding ticket can be automatically closed in your PSA. And in the other direction, when a ticket is closed in your PSA, the corresponding request can be automatically resolved in DefensX.
ConnectWise:
Screenshot 2026-06-24 at 12
HaloPSA:
Screenshot 2026-06-24 at 12
Autotask:
Screenshot 2026-06-24 at 12
Both behaviors are managed per integration under the Ticket settings tabs, allowing each PSA connection to follow its own closure rules.
Starting from
v2.4.x
, DefensX can enforce DNS policies on macOS through a DNS Proxy network extension, without modifying the system's interface DNS settings.
On MDM-managed devices, the DNS Proxy extension permission can be pushed via a configuration profile, and the required permissions are granted silently.
Screenshot 2026-06-19 at 14
On non-MDM devices, the extension can be enabled manually by the end user. If it is not enabled, the agent continues to operate in the previous mode where interface DNS settings are modified directly. Once permissions are granted, the agent status displays
Network Extension: Enabled
, indicating that the DNS Proxy network extension is active.
The DNS Proxy Network Extension can be disabled at the deployment level or per individual agent, similar to the Kernel Driver setting on Windows. If needed, it can be disabled regardless of whether permissions were granted via MDM or by the end user.
Screenshot 2026-06-19 at 14
Step-by-step instructions are available for both Manual Deployment and MDM Deployments.
Additionally, the macOS installer is no longer marked as requiring Rosetta, the DefensX Agent now installs natively without the Rosetta compatibility layer.
DefensX now helps protect users from sponsored search ads that may lead to malvertising, impersonation, or malware delivery campaigns. Since paid search results often appear at the top of search pages, attackers may abuse sponsored placements to mimic trusted brands and redirect users to malicious or deceptive websites.
When a user clicks a sponsored result on Google Search or Bing Search, DefensX detects the ad-based navigation and blocks access before the page loads. A clear warning informs the user about the potential risk and encourages them to continue with organic search results instead.
Screenshot 2026-06-03 181426
This protection can be managed at the policy level under Adware Blocker / Malvertising Protection, with dedicated controls for Google Search and Bing Search. This allows organizations to apply sponsored search ad protection according to their security requirements and reduce user exposure to threats commonly delivered through paid search advertising.
Screenshot 2026-06-03 at 18
Support access is now guided by the DefensX Customer Success Agent, powered by Nexi AI, our new in-product assistant built to help users reach the right information faster.
Screenshot 2026-06-01 at 17
With this update, the previous Create Ticket button in the lower-right corner has been replaced by the Support button in the upper-right corner of the console. When users open the agent and enter a question, it provides AI-assisted guidance based on DefensX Knowledge Base articles and frequently asked questions.
Screenshot 2026-06-01 at 17
If additional help is needed, users can continue from the same conversation by selecting Submit as a ticket. This keeps the support flow simple and efficient by combining quick self-service answers with a clear path to the DefensX Support team.
Audit logs now capture the remote IP address associated with each action, enriched with location data to provide greater visibility into where activity is originating.
When reviewing audit log entries, each record will display the resolved City and State alongside the remote IP, powered by GeoIP Database. This makes it easier to spot unusual or unexpected activity at a glance during security reviews and investigations.
Screenshot 2026-05-25 at 18
Customers can now be created in a trial state via the API, automatically transitioning to a billable account once the trial period ends.
When using the POST /customers endpoint, setting "trial": true in the request body will create the customer in trial mode, enabling automated onboarding flows to be fully managed through the API from trial creation to active billing.
Screenshot 2026-04-30 at 13
For environments using both SAML integration and the Teams feature, it is now possible to automatically assign admin users to DefensX Teams by mapping a SAML attribute.
This functionality is currently documented for Okta and Duo SAML integrations in the knowledge base: https://kb.defensx.com/docs/categories/62-Identity-Providers/topics/3ab53de4-fceb-4052-b273-7f02ac9d6794#_enabling_the_teams_mapping
When Teams Mapping is enabled, admin users’ team assignments are automatically updated on each login based on the teams defined in the configured SAML Identity Provider.
Load More