Looking for a bug fix list for all versions of Endpoint Protector Server?
All bug fixes will automatically be added here!
2608.0 Updates
Netwrix Endpoint Protector Server 2608.0.1.0
September 1, 2026
| Module | Title & Description | ADO Number | Salesforce Number |
|---|---|---|---|
| General | Backup import fails with old database schema — Fixed issue when system backup import failed with an old database schema — importing a backup taken on an earlier EPP version failed due to schema compatibility issues. | 412033 | 00466840 |
| General | Diagnostic artifacts not downloadable from server UI — Fixed issue when EPP Client artifacts and diagnostic files were not downloadable from the server UI. | 366535, 389189 | 00428733, 00446646 |
| General | SMTP notifications failing with error 421 — Fixed issue when SMTP notifications failed with error 421 (Service Unavailable). | 379463 | 00439536 |
| General | Device Control alert emails not sent — Fixed issue when Device Control alert emails were not sent. | 422756 | 00472954 |
| General | Audit Log Backup not enforcing retention threshold — Fixed issue when Audit Log Backup did not remove logs older than the configured retention threshold — logs due for removal remained on the server after the backup job completed. | 432539 | 00475601 |
| General | Scheduled Audit Log Backup enters infinite retry loop and never completes — Fixed issue when the Scheduled Audit Log Backup entered an infinite retry loop and never completed — in certain conditions the job retried indefinitely without completing (workaround at the time was to use a one-time backup). | 441482, 440702, 437803 | 00479915, 00478217 |
| General | Logging level reset to Error after restoring global settings — Fixed issue when the logging level was incorrectly reset to Error after restoring global settings with file tracing enabled — affected individual computers and groups. | 441346 | 00480317 |
| General | User not available in OTP dropdown menu — Fixed issue when a user was not available in the OTP dropdown menu — when logged in as a non-super administrator assigned to multiple departments, searching for a specific user in the OTP dropdown did not return all matching users. | 355792 | 00419825 |
| Administration and User Management | Users absent from CAP after Entra ID synchronization — Fixed issue when users were absent from CAP after Microsoft Entra ID synchronization — users and groups synced from Entra ID appeared correctly in Device Control, but users were missing from the CAP entity picker; root cause was the sync script stopping processing of all subsequent groups when it encountered a previously deleted group in Entra ID. Note: users who have not had an EPP client installed do not appear as selectable entities in CAP until the client is deployed — this is expected behavior and is unchanged. | 422196 | 00472683 |
| Administration and User Management | Cannot change admin role for SSO/Okta/Azure AD-provisioned accounts — Fixed issue when admin role could not be changed for SSO/Okta-provisioned accounts, Azure AD-imported administrators (could not be changed from Super Administrator to Regular Administrator), or administrators provisioned via SSO generally — root cause was the SSO Administrator edit page being broken on load (JS crash) and missing several settings toggles (Account is active, Failed Login Alert, Enforce login IP restrictions), plus an empty email field for Azure SSO users. | 438442, 438116, 438175, 439843, 444560 | 00478387, 00478406, 00479385, 00481547 |
| Administration and User Management | Department-restricted admin sees all computers on login — Department-restricted admin sees all computers on initial login. | 444564 | 00481562 |
| Administration and User Management | Repeated failed logins block the login page — Repeated incorrect login attempts block the login page for multiple minutes. | 432072 | 00473869 |
| Administration and User Management | Login fails after removing an IP Access Restriction — Login fails after removing an IP Access Restriction. | 445643 | 00482109 |
| Administration and User Management | Login Time Restrictions intervals do not work — Fixed issue when Login Time Restrictions intervals did not work properly under System Configuration > System Administrators — the validator rejected valid values between 5 and 60 minutes, and the Login Attempt Restrictions inputs disappeared from the UI after disabling and re-enabling the option. | 451432 | 00483928 |
| Device Control | Group membership editing shows no selected members after 2604 upgrade — Fixed issue when group membership editing displayed no selected members following an upgrade to 2604 — computers and users were correctly assigned to groups but appeared unselected in the group edit view, and searching for users or computers within groups also returned no results. | 435876, 435920, 437552, 439728, 440182 | 00477423, 00477460, 00478034, 00479323, 00479680 |
| Device Control | Replicated group content does not match source — Fixed issue when replicated group content did not match the source (Group Replication feature). | 441072 | 00480162 |
| Device Control | False “missing serial number” error on device rename — Fixed issue when editing only the Device Name of a device record and saving triggered a false “missing serial number” error. | 438509 | 00478653 |
| Device Control | Policy reorder arrows missing from Widget View — Fixed issue when policy reorder arrows were missing from Widget View. | 438339 | 00478540 |
| Device Control | Allow rules scoped to computer and user not evaluated correctly — Fixed issue when allow rules scoped to both computer and user were not evaluated correctly. | 383749 | 00442556 |
| Device Control | Bulk device import blanks description with special characters — Fixed issue when special characters in a device description caused bulk device import to leave the description blank. | 422447 | 00472814 |
| Device Control | Unable to delete more than 10 computers/host entries in bulk — Fixed issue when deleting host entries from Device Control > Computers only worked for 3–5 entries at a time — selecting 10 or more silently failed to delete. | 424106 | 00473516 |
| Device Control | EasyLock client list filter panel renders blank — Fixed issue when the EasyLock client list filter panel rendered blank. | 436844 | 00477696 |
| Device Control | Web console freezes reordering Device Control groups via drag-and-drop — Fixed issue when reordering Device Control group priority via drag-and-drop froze the web console and eventually returned a 502 error, with no changes applied. | 432229 | 00475443 |
| Device Control | Diagnostics artifacts cannot be downloaded from server UI — Fixed issue when diagnostics artifacts could not be downloaded from the server UI. | 372622 | 00428246 |
| Device Control | Audio device incorrectly allowed by Windows Sound Recorder — Audio device incorrectly allowed by Windows Sound Recorder. | 432668 | 00475101 |
| Device Control | TightVNC file transfer logging via Extended VNC Policy Exit Point misbehaves — Extended VNC Policy Exit Point / TightVNC file transfer logging does not behave as intended. | 435616 | 00480546 |
| Device Control | Bulk import missing on Custom Classes — Fixed issue when clicking Import Content while creating a Custom Class in Device Control with “Bulk List of Devices” selected as the Adding method produced no response — the file import UI did not appear. | 440703 | 00479902 |
| Content Aware Protection | Actions menu dropdown mispositioned in CAP policy list — Fixed issue when accessing the actions menu at the bottom of the CAP policy list — the dropdown appeared at an incorrect position when the list was scrolled to the bottom. | 396733, 401244 | 00451651 |
| Content Aware Protection | MIME allowlist selections revert on save — Fixed issue when MIME file types deselected in the CAP allowlist reverted to selected on save. | 440033 | 00479560 |
| Content Aware Protection | Custom threat threshold not applied with regex-based rules — Fixed issue when the custom threat threshold was not applied when using regex-based Content Detection Rules. | 434607 | 00476714 |
| Content Aware Protection | URL denylist not enforced on Brave and Chrome — Fixed issue when the URL denylist was not enforced on Brave and Chrome — blocking worked only on Edge. | 424945 | 00473863 |
| Content Aware Protection | CAP conditions not evaluated with special characters in names — Fixed issue when CAP policy conditions were not evaluated if dictionary or regex names contained special characters or spaces — double-encoding of &, <, > and incorrect whitespace handling in condition names caused conditions to never match on the client, allowing files through instead of being blocked. | 426395 | 00474838 |
| Content Aware Protection | CAP policies sent from server to agent incorrectly — Fixed issue when CAP policies were sent from the server to the agent incorrectly under specific rights configurations. | 326875 | 00409969 |
| Content Aware Protection | iPhone Messages synced to macOS logged as CAP false positives — Fixed issue when iPhone Messages synced to macOS were logged as CAP false positives — when the CAP policy for Instant Messaging > Messages is enabled, messages synced from an iPhone to macOS via iCloud were incorrectly detected as policy events. | 412457 | 00467246 |
| Content Aware Protection | Wrong Destination Type displayed in CAP logs — Fixed issue when the wrong Destination Type was displayed in CAP logs — when a file was copied from a removable device to the local machine, the Destination Type incorrectly showed “USB Storage Device” instead of the local drive. | 319732 | 00409911 |
| Content Aware Protection | Regex Denylist Test tool rejects case-insensitive patterns — Fixed issue when the Regex Denylist Test tool rejected case-insensitive patterns — the Test button failed on patterns using the (?i) modifier, incorrectly flagging valid patterns as invalid; policy enforcement itself was unaffected, only the server-side Test tool was broken. | 445749 | 00482252 |
| Content Aware Protection | Regex not detected consistently with Boolean operators — Fixed issue when regex was not detected consistently when combined with Boolean operators — regex-based Content Detection Rules combined with other rules using AND/OR did not reliably detect all specified threats, and some terms were missed depending on operator and rule order. | 444158 | 00481191 |
| Content Aware Protection | Content Aware Report not loading — Fixed issue when the Content Aware Report failed to load, causing the EPP portal to become unresponsive when opening it. | 444030 | 00481117 |
| Content Aware Protection | AWS SES configuration for Email Server Settings stopped working after upgrade — AWS SES configuration for “E-mail Server Settings” stopped working after upgrade, resulting in missing alert notifications. | 383157 | 00436586 |
| Content Aware Protection | Content Aware email notifications missing attachment with “Native” mail settings — Content Aware email notifications are sent without the expected attachment when using “Native” mail server settings. | 449233 | 00483046 |
| Content Aware Protection | Unable to change Content Aware Protection policy priority — Unable to change Content Aware Protection policy priority. | 446134 | 00482384 |
| DPI | DPI Allowlist edit form missing file upload fields — Fixed issue when the DPI Allowlist edit form was missing file upload fields for entries with existing imported content. | 437887 | 00478275 |
| eDiscovery | eDiscovery logs not visible to read-only admin users — Fixed issue when eDiscovery logs were not visible to read-only administrative users. | 397798 | 00452708 |
| Reports and Analysis | Effective Rights report returns empty with filters applied — Fixed issue when the Effective Rights report returned empty when filters were applied — filtering by computer name or username returned no results despite data being present in the unfiltered view; some customers also observed mismatched computer-user pairs in the full export. | 394400, 399153, 418207 | 00449797, 00453974, 00470496 |
| Reports and Analysis | Report export stuck as “export currently running” — Fixed issue when the Content Aware Report / Logs Report export got stuck showing “export currently running.” | 413495 | 00467724 |
| Reports and Analysis | Audit Log Backup export file contains repeated header lines — Audit Log Backup export file (ofiletrace.csv) contains the same header line repeated multiple times. | 401383 | 00455638 |
| Reports and Analysis | Artifact log files cannot be downloaded — Artifact log files cannot be downloaded. | 426325 | 00473021 |
| Reports and Analysis | DNS display issue — Fixed issue with the DNS display. | 444703 | 00480718 |
| SCIM | SCIM log entries truncated at 65,535 characters — Fixed issue when SCIM log entries were truncated at 65,535 characters — request_body and response_body were cut off for large payloads, hindering troubleshooting; the character limit has been increased. | 432826 | 00475770 |
| SCIM | Okta SCIM subset PUT overwrites full group membership — Fixed issue when a subsequent subset PUT request from Okta SCIM overwrote full group membership — when Okta sent a second PUT with a membership subset shortly after the first, EPP replaced the complete membership with the subset. | 434480 | 00476615 |
Netwrix Endpoint Protector Client Version 2608
August 24, 2026
The following table contains a comprehensive list of updates and fixes introduced in this version:
| Component | Description | Case # | Escalation # |
|---|---|---|---|
| Security | **Updated Component: OpenSSL library** — EPP uses latest version with upstream security fixes. | 437978 | — |
| Security | **Updated Component: WolfSSL library** — Enforced Encryption uses latest version with upstream security fixes. | 445103 | — |
| Security | **Files exposed under Tamper Protection** — Fixed an issue on Windows where, with Tamper Protection enabled, two internal configuration files could be read by unauthorized processes. File access permissions have been tightened to prevent this exposure. | 440887 | — |
| General | **False “Forced Uninstall” log on Linux startup** — Fixed an issue where Linux endpoints generated a “Forced Uninstall” log entry every time the machine started, even though no uninstall was attempted. | 320083 | — |
| General | **Collect Diagnostics action not returning data** — Fixed an issue where running “Collect Diagnostics” from the server did not return a diagnostic artifact, leaving the Diagnostic Data table empty. | 438317 | — |
| General | **Client sending empty log packets** — Fixed an issue where the client periodically sent empty log packages to the server, creating unnecessary log traffic. | 442256 | — |
| General | **Client configuration could be lost after an unexpected shutdown** — Improved reliability on macOS and Linux so the client’s local settings file can no longer be left empty if the client process is terminated while saving, which previously could cause the client to lose its server connection details. | 445461 | 00481291 |
| General | **Leftover files after uninstalling on macOS** — Fixed an issue where uninstalling the client on macOS left behind two application support folders instead of removing them completely. | 451175 | — |
| General | **File Shadows not delivered to FTP repository** — Fixed an issue where shadow copies of blocked files were not sent to the File Shadows Repository when it was configured to use an FTP connection. | 452018 | — |
| General | **File shadows missing for file move events on Linux** — Fixed an issue where moving a file to a removable device or network share generated a File Copy event without an accompanying shadow copy. | 390728 | — |
| General | **Linux install certificate script failed to detect domain-style home paths** — Fixed an issue where the Linux DPI certificate installer did not correctly detect a user’s home path when the path included a domain name (e.g. `/home/infra@domain`). | 447476 | 00481378 |
| DC | **Device lockdown option not enforced on macOS Sonoma** — Fixed an issue on macOS Sonoma where enabling “lockdown all endpoints” and clearing exclusions in the Device Control dashboard did not actually block the excluded device types (Wi-Fi, Bluetooth, keyboard, etc.). | 319869 | — |
| DC | **Bluetooth mouse/keyboard remained usable after being denied** — Fixed an issue on Linux where a Bluetooth mouse or keyboard set to Deny was blocked only briefly, then resumed working with erratic behavior. | 437232 | — |
| DC | **Third-party virtual drives could crash on startup** — Fixed an issue where certain virtual drive software (e.g., Box Drive) was incorrectly identified as an unknown storage device, causing it to crash on launch when unknown devices were set to Deny. | 442287 | 00480242, 00481321 |
| DC | **Specific virtual drives could be blocked by “Unknown Devices” policies** — Improved device identification so administrators can exclude specific third-party virtual drives from Device Control enforcement at the driver level, without needing to broadly allow all unknown devices. | 442754 | 00466821 |
| DC | **Advanced Printer and MTP Scanning not working correctly on Windows ARM64** — Fixed an issue where the Advanced Printer and MTP Scanning feature did not interoperate correctly with x64 and x86 processes running under WoW64 emulation on ARM64 Windows devices. | 426297 | — |
| DC | **Trusted Device content readable outside EasyLock on macOS** — Fixed an issue where files on a TD1/TD1+ device could be listed and copied via Finder or Terminal on macOS, bypassing EasyLock. macOS now matches the full-block behavior already applied on Windows. | 452102 | 00477749 |
| DC | **Built-in webcam not blocked on macOS** — Fixed an issue on macOS where denying the Webcam device right did not stop the built-in camera; on affected Macs, the built-in camera is handled by a separate system component that was not covered by the existing camera-blocking logic. | 452353 | 00482087 |
| CAP | **DLP engine could crash loading a large custom dictionary** — Fixed a crash that could occur when the DLP engine loaded a large custom dictionary file. | 437988 | — |
| CAP | **DLP engine could crash reporting threats on a network share** — Fixed a crash that could occur when threat events were reported for files detected on a network share. | 438145 | — |
| CAP | **Duplicate remediation prompts for network share transfers** — Fixed an issue on macOS where the user remediation pop-up for a Block & Remediate policy could appear twice for a single file transfer to a network share, with the event logged multiple times. | 320086 | — |
| CAP | **CAP scanning direction dependent on File Tracing settings (Linux)** — Fixed an issue on Linux where Content Aware Protection scanning of removable-device transfers was incorrectly affected by the File Tracing direction setting, letting some monitored transfers through undetected. | 341792 | — |
| CAP | **CAP scanning to removable devices required File Tracing (Linux)** — Fixed an issue on Linux where Content Aware Protection policies for removable devices were enforced only when File Tracing was also enabled, letting transfers bypass detection otherwise. | 347533 | — |
| CAP | **Sensitive DOCX files could bypass network share protection via “Save As”** — Fixed an issue where using “Save As” to copy a DOCX file with sensitive content to a network share could bypass Content Aware Protection, even though the transfer was logged as blocked. | 398611 | 00452594 |
| CAP | **SBF files not always recognized by content detection** — Fixed an edge case where certain .sbf files were not correctly identified, allowing them to bypass Content Aware Protection policies restricting this file type. | 426543 | 00473674 |
| CAP | **Outlook attachment policy also matched email body content** — Fixed an issue where a Content Aware Protection policy scoped to Outlook attachments could still block an email based on content found in the message body rather than the attachment. | 432088 | 00475228 |
| CAP | **Print jobs sometimes evaluated against the wrong document** — Fixed an issue where, in certain printing scenarios, the client could attempt to scan a temporary print file that no longer existed on disk, so the print job was not properly evaluated against content policies. | 433789 | 00475104 |
| CAP | **Sensitive image files not blocked when “report all sensitive data” enabled** — Fixed an issue where enabling “Ignore thresholds (report all sensitive data)” caused image files that should have been blocked by file location, filename, or size rules to be allowed through instead. | 437668 | — |
| CAP | **False content alerts triggered by Chrome Translate** — Fixed an issue where using Chrome’s built-in translate feature could trigger false-positive gzip file detections when Chrome monitoring and DPI were enabled. | 437698 | — |
| CAP | **Policy conditions using multiple custom dictionaries did not trigger correctly** — Fixed an issue where a file was not blocked if a matched word belonged to more than one custom dictionary and the policy used logical conditions referencing those dictionaries. | 437734 | 00474838 |
| CAP | **Google Photos uploads not blocked** — Fixed an issue where image uploads to Google Photos were not blocked by Content Aware Protection policies denying graphic file types on browser exit points. | 437861 | 00477061 |
| CAP | **Sensitive clipboard content could remain visible in remote sessions** — Fixed an issue where blocking a clipboard copy/paste in AnyDesk cleared the content locally but not on the remote machine, leaving it accessible there. | 438599 | 00477984 |
| CAP | **Shadow copies not created for large blocked files** — Fixed an issue where shadow copies were not consistently generated for blocked files, most often affecting files larger than 10 MB transferred via Teams or USB. | 439926 | 00450675 |
| CAP | **Downloaded Teams screenshots occasionally removed** — Fixed an issue on macOS where screenshots downloaded from Microsoft Teams could be intermittently and silently removed from the Downloads folder while OCR-based content scanning was active. | 442103 | 00480316 |
| CAP | **Non-JPEG image uploads to M365 Copilot not monitored** — Fixed an issue where the client only inspected JPEG image attachments uploaded to Microsoft 365 Copilot; other common image formats (PNG, BMP, GIF) were not monitored. | 444447 | — |
| CAP | **OCR-enabled policies could delete newly created image files** — Fixed an issue where, with OCR content scanning enabled, newly saved image files such as screenshots could be deleted shortly after creation, even under Report Only policies. | 444725 | 00481321 |
| CAP | **First message in Google AI Mode not inspected** — Fixed an issue where the first text message sent in a new Google AI Mode session was not inspected for monitored content. | 447532 | — |
| CAP | **Paste restrictions not enforced in ChatGPT desktop app** — Fixed an issue where clipboard paste restrictions configured in a Content Aware Protection policy were not enforced when pasting into the ChatGPT Windows app. | 450844 | — |
| CAP | **Fasoo DRM-encrypted files not detected** — Improved file type detection to recognize Fasoo DRM-encrypted documents, which were previously classified as a generic file type and could bypass policies restricting this format. | 451642 | 00483864 |
| CAP | **Printer name missing from CAP report on Mac** — Print events on macOS did not include the printer name in the CAP report; the report showed a generic “Printer” or “Network Printer” label instead. | 452007 | 00484573 |
| DPI | **Slow or failed website loading with DPI enabled on macOS** — Fixed an issue on macOS where enabling Deep Packet Inspection could cause certain websites to load very slowly or fail to load, caused by an excessive number of concurrent inspection connections. | 423981 | 00468494 |
| DPI | **DPI inspection process could crash** — Fixed a crash in the client’s SSL inspection component caused by an internal memory-handling error. | 438981 | — |
| DPI | **Large file uploads could stall when DPI scanning is enabled** — Fixed an issue where uploading files larger than the initial HTTP/2 flow-control window while DPI content scanning was enabled could cause the upload to hang and eventually fail. | 439906 | 00479286 |
| DPI | **Google Meet calls dropped when DPI enabled** — Fixed an issue where Google Meet and other WebRTC-based apps could drop calls after about a minute when Deep Packet Inspection was enabled. | 444654 | 00483630, 00480760 |
| DPI | **External sites unreachable with DPI enabled while on GlobalProtect VPN** — Fixed an issue where several external sites, including Outlook, Azure DevOps, Grok, and Copilot, became unreachable when a policy had DPI enabled while connected to GlobalProtect VPN. | 451184 | — |
| DPI | **Stale IPv6 connectivity status on macOS after network changes** — Fixed an issue where the Transparent Proxy network extension on macOS did not re-evaluate IPv6 connectivity when the network configuration changed (Wi-Fi/Ethernet connect/disconnect, VPN connect/disconnect, interface changes), which could route browser and app connections to IPv6 destinations based on stale connectivity information. | 452053 | 00479286 |
| DPI | DPI could block access to GitHub and Azure DevOps — Fixed an issue where enabling Deep Packet Inspection could prevent connections to github.com and dev.azure.com from completing in the browser. | 452165 | — |
Known Limitations
| Component | Description | Case # | Escalation # |
|---|---|---|---|
| General | In newer Linux distributions, the default snap application for file access events in xdg Desktop portals is not supported by the EPP Client. | EPP-8735 | EPPSUPPORT-3198 |
| General | Windows XP, Windows 7, Windows 8, early Windows 10 builds, and Windows Server 2016/2019 no longer supported as of EPP client version 5.9.4.1. | 438053 | — |
| DC | Despite denying Bluetooth, Webcam, and iPhone access on macOS, Continuity Camera continues functioning in Slack, Zoom, FaceTime, and Photo Booth. | EPP-8781, EPP-6826 | — |
| CAP | On Linux environments using the Wayland protocol by default, paste control is constrained due to Wayland’s inability to detect the focused window. | EPP-8510 | — |
| CAP | File Shadow downloads from AWS S3 buckets with concurrent File Tracing and CAP may result in inconsistent behavior. | 320213, EPP-9023 | — |
| CAP | AI interaction monitoring does not extend to meta.ai when accessed within Facebook, Messenger, or WhatsApp due to encryption dependencies. | 410799 | — |
| CAP | On macOS, files containing confidential content are not blocked when uploaded through the Cursor application’s “New Agent” feature, even when a CAP policy with DPI enabled is monitoring Cursor. A fix is targeted for a future release. | 453228 | — |
| General | On macOS 27 “Golden Gate”, both a fresh EPP Client install and an upgrade of an existing install trigger a Bluetooth permission pop-up that requires manual end-user approval; the previous silent pre-approval method is no longer available under macOS 27. A fix restoring silent, MDM-enforced approval is in progress for a future release. | 451042 | — |
Deprecated
| Component | Description | Case # |
|---|---|---|
| CAP | Contextual Detection under System Parameters has been discontinued and replaced by Context Detection Rules in CAP Policies. | EPP-8941 |
Upcoming Deprecations
| Component | Description | Case # | Targeted Release |
|---|---|---|---|
| General | The File Shadow Maintenance feature for listing and managing File Shadows on the EPP Server will be discontinued in a future release. | — | TBD |
2604.0 Updates
Endpoint Protector Server 2604 Released
May 5, 2026
| Module | Description | ADO Number | Salesforce Number |
|---|---|---|---|
| Alerts | Content Aware Alert Email Delivery - Fixed an issue where Content Aware alert emails were not generated in certain configurations that included both computers and users. In these cases, incorrect policy association in backend processing could prevent the alert from matching the expected policy and stop the email from being sent. Alert evaluation now works correctly, and email notifications are generated as expected. | 320002 | 00029809 |
| SIEM Integration | Administrator Username in SIEM Logs for SSO Authenticated Users - Fixed an issue where SIEM exports displayed the Azure UUID instead of the administrator username for users authenticated through Single Sign-On (SSO) with Azure AD. Endpoint Protector now sends the correct username in SIEM logs, improving event readability and audit traceability. | 377615 | 00437325 |
| CAP | Paste Restriction Enforcement for KakaoTalk on macOS - Fixed an issue where Content Aware Protection paste restrictions were not enforced for KakaoTalk on macOS when the option to apply paste restrictions to all monitored applications was enabled. This occurred because the localized KakaoTalk process name was not recognized correctly. KakaoTalk is now identified properly and paste restriction policies are enforced as expected. | 412474 | 00463597 |
| Reports and Analysis | Log Export for Administrators Assigned to Multiple Departments - Fixed an issue where log exports could fail when initiated by an administrator assigned to multiple departments. This affected export generation from reports such as Device Control, Content Aware Protection, and File Tracing. Log exports now complete successfully regardless of the number of departments associated with the administrator. | 415113 | 00468236 |
| Reports and Analysis | Historical CAP Policy Type Display After 2602 Upgrade - Fixed an issue where historical Content Aware Protection logs created before the 2602 update could be displayed incorrectly as Outside Network instead of Standard in Reports and Analysis after the patch was applied. Historical log entries now retain the correct policy type in reports. | 416392 | 00469556 |
| Single Sign-On | SSO Redirect Handling After Login - Fixed an issue introduced after the 2601 upgrade where Single Sign-On (SSO) authentication could complete successfully, but the console did not redirect users correctly and displayed a failure message instead. This issue affected environments using PingID. Users are now redirected to the Endpoint Protector dashboard as expected after successful authentication. | 417621 | 00468481 |
| System Maintenance | System Backup Import with Legacy Database Schemas - Fixed an issue where System Backup import could fail when the backup was created from an older database schema and restored on a newer Endpoint Protector server version. System Backup imports now complete successfully in legacy schema migration scenarios. | 417735 | 00466840 |
| Reports and Analysis | CAP Log Details for Delegated Administrators - Fixed an issue where administrators with access to the Reports and Analysis section, but without Super Administrator privileges, could not expand and view Content Aware Protection log details. CAP event details now load correctly for delegated administrators with the appropriate permissions. | 419361 | 00470747 |
| General | QuickLogs Recovery and Ingestion Handling - Improved handling for scenarios where oversized QuickLogs directories could interrupt log ingestion. However, this process should still go through flagged by customers and go through Netwrix Support for a quicker fix. | 423709 | 00472377 |
| Directory Services | Active Directory Sync for Organizational Units with Special Characters - Fixed an issue where Active Directory sync could fail to display Organizational Units and related objects in the Directory Browser when Organizational Unit names contained special characters, such as %, , parentheses, braces, or brackets. Associated objects, including groups, computers, and users, are now displayed and synchronized correctly. | 425953 | 00474344 |
| Reports and Analysis | Okta not able to create groups through SCIM - Fixed an issue where group provisioning from Okta through SCIM could fail because the Department attribute was required during group creation. Endpoint Protector now supports Okta SCIM group creation without requiring this attribute, improving compatibility with Okta group provisioning workflows. | 418944 | 00470914 |
2602.0 Updates
Netwrix Endpoint Protector Client version 2602 Released (Now with Hotfix 2)
February 5, 2026
No bugs were fixed in this update.
Endpoint Protector 2602.0.1.0 Server Patch Released
February 5, 2026
| Module | Title & Description | ADO Number | Salesforce Number |
|---|---|---|---|
| General | Backend Security Updates – MariaDB package conflict prevention - Fixed an issue where applying Backend Security Updates on EPP Server 2510 could fail to apply (updates would reappear as available) and, in some cases, could lead to the Web UI becoming inaccessible with a 500 Internal Error after updates. | 409945 & 411911 | 00463162 & 00466742 |
Known Limitations
| Component | Description | Case # | Escalation # |
|---|---|---|---|
| CAP | An error is returned when enabling CAP and eDiscovery modules on a new server: ”An error occurred. Please ensure the Endpoint Protector Server has a functional Internet connection or that the required domain and ports have been whitelisted for outgoing traffic." This is not a blocking limitation, as the modules can be enabled after trying to click “Save” and enable them a second time. | 370216 | |
| CAP | File Shadow downloads from AWS S3 buckets, with concurrent File Tracing and CAP activation, may result in inconsistent behavior, displaying artifacts deleted in File Tracing reports but still available in CAP reports, and vice versa. | 320213, EPP-9023 | |
| EPP Server UI | When installing a fresh Endpoint Protector (EPP) Server, the default time zone is set to a default value that may differ from your own. As a result, computers may appear as “Offline” in the status column until the time zone is adjusted and synchronized. To resolve this, navigate to Appliance → Server Maintenance, select the appropriate time zone (e.g., Istanbul), and synchronize the server time. This action ensures computers will display the correct “Online” status. A fix for this issue is planned for future updates. | 395435 | |
| EPP Server Networking | When performing a backup restoration from a 5942 server to a 2510 server, the custom logo used for User Remediation is not imported correctly. After completing the restoration process, navigate to System Parameters → User Remediation; you may notice that the custom logo is missing. A fix for this issue is being considered for an upcoming release. | 402066 | |
| EPP Client Update | Starting with the 2601.0.1.0 release, the Client Upload page in EPP Server was cleaned up, and there is currently a known limitation that does not allow EPP Clients older than the 2509 version to be uploaded. Currently only EPP Clients with version 2509 and up are permitted for upload by the interface. | 414748 |
For any issues, please contact the Support team for assistance.
Upcoming Deprecations
List of features which will be discontinued in future.
| Component | Description | Case # | Targeted release |
|---|---|---|---|
| CAP | Contextual Detection under SYSTEM PARAMETERS will be discontinued in future updates and replaced by ‘Context Detection Rules’ in the ‘Content Detection Summary’ section of CAP Policies. | EPP-8941 | TBD |
| General | The File Shadow Maintenance feature, which provides functionality for listing and managing File Shadows stored locally on the EPP Server will be discontinued in future. | TBD |
2601.0 Updates
Netwrix Endpoint Protector Server Version 2601.0.1.0 Released
January 15, 2026
| Module | Title & Description | ADO Number | Salesforce Number |
|---|---|---|---|
| CAP | NetworkShare Allowlist Application Issue - Resolved a critical issue where NetworkShare Allowlist settings were not applied correctly on versions 2509/2510, causing copy operations from allowed shares to be blocked. A query change resulted in endpoints receiving an empty allowlist. This has been fixed, ensuring allowlisted shares function as expected. | 406336 & 406650 | 00460045 & 00460337 |
| Enforced Encryption | EasyLock and Client Presence Issue on Windows 11 - Fixed an issue where “Client Presence” settings didn’t prevent access to EasyLock on non-client Windows 11 machines, allowing partition access across non-client setups. A discrepancy in settings transmission from server-side to group levels caused improper application of “Client Presence.” We’ve corrected the logic for group settings, ensuring proper enforcement across all environments. This includes ensuring that EasyLock settings are correctly applied and inherited at the group level, with additional database changes like introducing a new table for logging client settings. | 404913 | 00458700 |
| Reports and Analysis | Fix for Missing XML Files and Empty Export Archives - Addressed issues where exporting reports such as CSV or XLSX files from Logs Reports, File Tracing, and Content Aware Reports resulted in empty directory archives with missing XML files. Following an update to version 2509, customers experienced loss of historical report downloads and encountered errors in generating new logs reports. The fix ensures all exported archives contain the selected files and that logging processes are adequately handled across server environments. Additional adjustments were made to alleviate time-out issues during export processes, particularly when file tracing reports are involved. | 405845 | 00459480 |
| General | IP Saving Issue on VMware EPP 2510 Image - Addressed a persistent issue where IP configurations failed to save on VMware vSphere VM appliances (versions 7.0.2, 8.0.2) using EPP Image 2510.0.1.0. Customers had to manually adjust netplan configurations as a workaround due to DHCP not assigning IPs on first boot. A fix has been implemented to ensure network settings are correctly applied during initial configurations. Investigations highlighted a need for configuration adjustments in the virtual appliance setup process. | 408487 & 408764 & 408135 | 00461744 & 00461971 & 00461405 |
| General | Language Display Error on Web Console - Resolved a critical issue where selecting Ukrainian language in the web console incorrectly displayed Turkish. This affected entire environments post-migration to EPP server version 2510, causing disruptions for many administrators. The fix ensures correct language selection and display across server interfaces, restoring smooth workflow integration for all users. | 409305 | 00462409 |
| System configuration | PHP ELS State and License Import Issue - Resolved an issue where importing a new license with a unique ELS key on the 2510 server resulted in an erroneous message, “Something went wrong during the installation. Please retry.” The ELS state did not update in the UI, and the php_els_install_status parameter remained at 0. This was caused by DNS and internet connectivity issues, as well as scenarios with duplicate licenses. The fix addresses these scenarios by ensuring accurate error messaging and state updates, improving overall stability and clarity during license import processes. | 407585 & 408350 | 00460881 & 00461569 |
| Reports and Analysis | Audit Log Backup Download Issue - Resolved a critical issue where audit log backup files could not be downloaded from the EPP server hosted on AWS. Following the upgrade to EPP Server version 2510, attempts to retrieve backup logs for compliance audits failed, affecting multiple log entries and blocking audit preparations. The fix addresses inconsistencies in log data handling post-migration, with DevOps implementing a cron job to extract available data. This solution prioritizes restoring log accessibility through simulated audit archiving. | 408745 | 00461931 |
| Certificate Management | Certificate Display Issue on macOS - Resolved an issue where DPI certificates marked as trusted on macOS clients appeared as N/A in the EPP Server UI. This was due to a validation process in the backend that erroneously used UI-only components, causing worker processes to fail. The improvement ensures certificates are accurately reflected and updates are correctly processed by server-side validation logic, enhancing synchronization between macOS clients and the server. | 406528 | 00460223 |
| Reports and Analysis | EPP Console Not Displaying Detailed Logs for Certain Files - Fixed an issue where detailed logs for CSV files were not visible in the EPP console, despite the server receiving accurate information. The console was not correctly processing logs for CSV files while PDF logs were displayed properly. The resolution ensures comprehensive visibility of log details for all file types, reinforcing complete reporting in Content Aware Reports. | 409935 | 00463129 |
| General | Email Alert - Log csv file not properly aligned - Resolved a problem where CSV files attached to email alerts were not properly parsed, resulting in all data being added to the first column. This made it difficult to read and utilize the data effectively. The fix ensures that content in CSV files is correctly distributed across the appropriate columns, enhancing clarity and usability of alert information. | 406074 | 00459728 |
| General | EPP 2510 OS downgraded to 2509 after importing 2509 backup - Addressed an issue where importing a 2509 backup file into an EPP 2510 server incorrectly showed the server version as downgraded to 2509. This is a UI display issue rather than an actual version rollback. The fix ensures that the server version is accurately displayed post-backup import, avoiding confusion and ensuring consistency across system maintenance operations. | 409666 | 00462856 |
