Two-factor sign-in, end to end in the UI. The sign-in page asks for the authenticator code (or a recovery code) when the policy requires one, with a "remember this browser" option labelled with the real number of days; My Profile gains self-service set-up with the QR code, the confirmation code and the recovery codes to store; Settings > Two-Factor lets an administrator set the policy (Off, Optional or Required, for everyone or for administrators, grace period, remember-browser lifetime) and, per account, require, exempt or reset two-factor. Nothing appears anywhere until an administrator switches the policy on. Requires the API from release 1.0.0.12476 or later.
Azure Virtual Desktop (AVD) profiles can be created, edited, cloned and reviewed in the generic load profile wizard, with the Entra client id, tenant id and desktop name in the connection step and a per-user desktop resource. Requires the API from release 1.0.0.12476 or later. A profile whose technology this build does not know is rendered read-only instead of emptying the Load Profiles page, which one AVD profile did before.
Insight machine groups: Linux, macOS and package-inventory settings, and per-OS filter values. Administrators can edit a machine group's Linux, macOS and package-inventory sections and give Linux and macOS agents their own process, network, directory-size and CPU-load values instead of the Windows ones. Requires the API from release 1.0.0.12476 or later.
Config > Workloads downloads a workload from its row, and the Upload Workload dialog's drop zone takes a dropped .lgs file; before, only Browse Files worked.
Launcher Appliances: a "Chromium (Playwright)" tile on the Updates tab to install or update Playwright's Chromium, so web workloads that ask for USEBROWSER: Chromium can run; the ".NET runtime" tiles show the host's runtimes, the Appliance Agent's own runtime is labelled as not the host's, and a Launcher with an older agent shows a note to update the Appliance Agent first; a combined Core Agent + Appliance Agent update pushes the agent first, waits for the new build to be verified, then pushes the Core Agent, and an appliance whose agent rolled back or never answered is shown as Cancelled with the reason. Requires the API from release 1.0.0.12476 or later.
[#9663] The Enroll appliances wizard now pairs the batch on an enrollment token you can see and reuse instead of a hidden one-use token per appliance, which is what broke pairing with "1 of 1 used" and left a spent "Remote enrollment of ..." row in the token list every time. The Review step gains a token picker listing the tokens that can pair the whole batch, with Create a new enrollment token (description, expiry date, max enrollments) as the last option; the token is created on Enroll and kept for a retry. An amber note says where a reusable token travels unencrypted and advises revoking it afterwards on an untrusted network. A role that may enroll but may neither create nor reveal tokens falls back to per-appliance single-use tokens, and the Review step says so. A row that failed after the appliance registered shows the appliance as awaiting approval.
[#9664] The Enroll appliances wizard pre-fills Platform URL the appliances call back on with the address the platform resolves for itself, still editable, and a line under the field says where the value came from: the configured public URL, the platform's own domain, or, in amber, the address the frontend reaches the API on, with a reminder to check that the appliances can reach it too. Typed text is never overwritten, Enroll more re-seeds the field, and when nothing usable resolves the field stays blank and shows the API's reason. Requires the API from release 1.0.0.12476 or later; against an older API the field opens blank as before.
[#9662] Fixed a click on the dim area outside a dialog or drawer closing it and losing everything typed, anywhere in the app: the Enroll appliances wizard, the Linux user dialogs, the air-gapped upload dialogs, the dashboard, chart and report editors, the Analyse panel builder and the machine editor drawer among them. Leaving is now a deliberate act: Cancel, the X or Escape ask Discard changes (Discard / Keep editing) whenever there is something to lose, and an untouched dialog closes at once.
[#8470] Fixed Test & Inspect for a WHOIS Expiry check showing the raw WHOIS answer as "Domain expires in" and showing no expiry tile on a successful check. The tile now shows the domain's day count, a threshold failure shows the (possibly negative) count, and when the check finds no expiry date the raw registry answer appears under its own "WHOIS response" label. The wizard's "WHOIS server (optional)" field explains that a blank field reads RDAP first and then WHOIS, that a configured server skips RDAP, and that the whois.nic.uk example stops working on 9 February 2027. The SSL "Certificate expires in" tile no longer shows "-1 days" on a failed certificate check.
Fixed the monitoring profile wizard: editing a profile no longer offers a change of technology in step 2, because a profile cannot change technology; a Horizon profile's Connection Server and desktop pool and an AVD profile's tenant and client id now reach the API; and the agent step says which account runs the agent and which one signs in to the target, shows the agent's Windows Run-As per row, and lines its controls up.
Fixed Insight machine-group editing: clicking Add on a process filter card no longer hangs the page; a group whose configuration sections are stored empty opens and saves from every editor tab; and the editor shows one master-agent setting instead of two and says whether master agent mode is in effect and why not.
Sessions and sign-in. A session the API has ended is replaced by the API's own sentence and a Sign in again button on every page instead of a mix of empty states and errors; a new browser tab opens signed in as the newest sign-in of this browser, never as an older one or signed out; signing in on a slow appliance keeps the account's role and permissions and no longer waits about 90 seconds on a stalled call; Extend Session extends your own session, also while the header is connected to another API server; a refused single sign-on names only ways out that clear it, and an e-mail link refused as unverified is explained; Settings > SSO Providers keeps and shows Link on email match and Reconcile username on login and says which settings apply at sign-in.
Page access follows the session's grants. Pages open by the routes the session may reach, not by what the menu shows; configuration and administration pages stay closed while permissions are unknown and the menu says why; Home offers only the links the guard opens; Settings shows exactly the tabs the account's permissions open (the operations role has Settings again, and the two-factor tab is no longer a way into the other tabs); tabs a role can only read show the data read-only without controls the API would refuse; every licence call to action, upsell and promo card is offered only to a role that can act on it; and the Licensing page offers each action to the roles that hold it and reads a licence refusal as a licence refusal, not as missing permissions.
Licensing and lockout. The lockout pages no longer tell a role that can upload an offline licence that it cannot manage licensing; Sign in again on the lockout pages really starts a new sign-in; Revalidate and an offline licence upload lift the lockout in the open tab; a trial that lapses mid-session locks the shell to Licensing from the first refused call of any page; the setup grace period no longer starts the checks it is meant to skip; a stalled API no longer holds a new tab's start-up placeholder while the licence read waits; and Promote to Master names a permission refusal as one.
Connected to another API server. While the header is connected to a remote API, that API decides what a page offers and this Frontend's own pages keep their local rule; the live-update badge shows a fallback in amber and says why, a fallen-back connection keeps retrying the remote and moves back once it answers, and a remote that stays down no longer writes an Error line on every retry; My Profile always changes the account this tab signed in with and says so; the Licensing page acts on this appliance's own licence; and the remote API's uptime script authors can author scripts.
Security > Permissions and Security > Roles show a refused save or write in the API's whole sentence with its reason code, inside the dialog that sent it; Delete is withheld for every built-in role name and the Disabled role concept is gone; a member list that failed to load says so instead of showing everyone as role-less, and a recovery row is told apart from an account that simply has no role; Add User trims the typed id and points at actions that exist; the rename dialog says when a repository holds the name; a repository member's refused change and the changes held back until the Master is upgraded are shown on their rows; Remove User on an enrolled appliance says what the removal reaches; Delete Role opens at once and names the holders once they are read; a custom role ticked from the workload keys gets its workload controls; and a tenant-scoped member keeps its scope on save.
API Testing pages: the Flows search box searches, and Run History filters by date and by the API's run states; Diff shows the pair you clicked; Revision Restore works and brings back the revision's flow variables; every list and flow picker reads every page instead of the first 25 rows; the schedule dialog says why a save or Run now was refused, and the Schedules page names the zone a schedule runs in and marks a catch-up fire; Loop (For Each) and Assert Contract nodes can be configured again, and the If and Switch placeholders are real expressions; a paused debug run can be read and followed through Resume, Step, Cancel and Abort, and Set Breakpoint on the canvas pauses the run; Rerun replays the revision the run used and opens the new run, the run header says which revision ran, and the run page says why a run ended; the canvas colours a node that passed with a failed soft assertion amber, and the run timeline nests a Flow Call's child nodes under the call row; flow variables are visible, editable and survive every save; auth profiles save for the roles that own them, a Basic auth profile keeps its username and password, and Test says what actually happened; the AI wizard's Save Flow opens the flow it saved under the name you typed; Refresh Now imports the spec while you watch, and a source without a URL can be given one; the import wizard's Map References step lists this appliance's sources, environments and auth profiles; a node's retry policy reaches the API and is offered only on the four HTTP request types; a node Test can stand in for the values earlier nodes would set; Capture All reaches the API; the CI/CD recipe can fail a build and keeps the bearer token private, and a finished run offers its JUnit and HTML reports; the overview shows how the last 24 hours went; refusals and failures read as a sentence instead of the API's JSON; and read-only roles can see an environment's, an auth profile's, a schedule's and a source's settings again.
Sync > Collections and Sync > Repositories: a push or pull says exactly what it carried, Compare shows what differs from the Master, a pull that fails says so, and Pull from Master reaches the API and says when managed scripts were refused; the editor lists virtualization, and its Load Profiles and User Pools pickers list their rows; Edit Role Access no longer offers Save on a collection whose stored restriction already excludes you; Revoke API Key revokes the keys; Pending approvals asks for the queue only with the grant, warns before approving a repository id that brings back role assignments or member removals, and offers Approve and Deny only to roles that hold them; an approved enrollment can be applied from the Repositories page again; a refused enrollment poll no longer comes back on every visit; and repository management is offered only with the Master module licensed.
Uptime: the Alerts page lists the failures the appliance records; a dashboard keeps the access the API reports, a read-only board says so, an Uptime administrator can edit a Shared dashboard somebody else owns, and a copy is offered only to a role that can make one; the Alerting steps of the uptime check and monitoring profile wizards word a refused alert-profile read by what is linked and offer the inline creator before the first profile exists; the check wizard's Endpoint step writes only the body and language of the check's own script and never rewrites a script it only picked, and its catalog says which grant a PowerShell check needs; the Reminders Source column names the row's source and each link names the page it opens; only an account that may close an incident by hand is told to; and the expiring-credentials toast names the page that issued an expiring platform token.
Infrastructure > Appliance: the tabs show a refused domain, data path or version inside the dialog or tile that sent it and keep what was typed; on the Backups tab Restore restores and Import imports, Restore shows what it could not use, Download never claims a download the appliance refuses, and a restore waits for the signing-key check instead of failing; Configuration > Backup downloads the bundle just exported through the export's own link, says a stored bundle is corrupt in the API's words, and the backup picker says what a backup carries for Alert Triggers; Workload Files shows a refused New Folder or Delete inside its dialog; every workload upload shows a refusal in the API's words; and a session the API refuses is told it may not manage the appliance.
Fixed the alerting pages, Notification Accounts and API Testing Retention hiding their data from a read-only role; they now show the data without the controls the API would refuse, alert triggers are shown and offered as the API says the role may use them, and the alert trigger editor stores what the person typed, a whole mask included.
Fixed Home: the Test Scheduling card offers New Schedule again, the setup checklist is shown only to sessions that can open the Appliance page, and the LoadGen Cloud credential status is asked for only by roles that may read it.
Fixed the header's time chip: every role sees the appliance's configured zone, and the chip says so when it cannot load it.
Environment variable chips in the flow editor show the variable's name only.
Fixed local users in a module or infrastructure role losing screens their role allows (Configuration Backup said "Access Denied"), and administrator screens being offered on a role's name rather than on its grants.
Fixed a flow generated with AI opening as an empty canvas, and the next Save overwriting the generated draft.
Fixed error banners not looking like errors, an Alert banner losing its colour, and the refusal card ignoring the dark theme; background calls the API refuses are sent at most once per page load and no longer logged as errors, and the bell stops asking for resolved-ticket notifications once the API refuses them for the account.
Fixed saving a flow node on a Windows-hosted Frontend marking the canvas unsaved.