Netwrix Auditor 10.9 Update 1 (10.9.16400)

Netwrix Auditor 10.9 Update 1 strengthens your security posture with a new Entra ID Empty Groups report and smarter alert scheduling, while closing long-standing gaps in Azure Files permission visibility, SharePoint Online monitoring accuracy, and syslog timestamp handling.

Want the full details? Click the link below!

What’s Changed in Netwrix Auditor 10.9 Update 1

New Entra ID Report: Empty Groups

Netwrix Auditor now includes an Entra ID Empty Groups report that surfaces every Microsoft Entra ID group with zero members. Security and compliance teams can use this audit-ready evidence to identify and remove dormant groups before they become a backdoor for privilege escalation.

Day-of-Week Filters for Alerts

Alert configurations now support a Day-of-Week filter, letting administrators specify which days an alert should or should not trigger. Available in both the UI and the API, the filter can be combined with existing time-of-day conditions to align alerting with maintenance windows and operational schedules, reducing alert fatigue by suppressing notifications on days when activity is expected, such as weekends or planned maintenance.

Skip Inaccessible SharePoint Online Sites

The SharePoint Online collector can now be configured, via the UI, to silently skip site collections that are fully archived or return access-denied responses, rather than raising a collection error every cycle. This keeps Monitoring Plan health status meaningful in large Microsoft 365 tenants, where Microsoft’s automatic archiving of inactive OneDrive sites previously triggered a stream of false-positive health log events.

On-Premises Active Directory Integration for Azure Files Permission Reports

Azure Files state-in-time permission reports can now optionally draw on on-premises Active Directory credentials to fill identity gaps that cloud-only lookups miss. When enabled, Netwrix Auditor expands on-premises AD group membership so every user with group-based access appears as an individual row in Account Permissions and Permission Details reports, and resolves display names for accounts not yet synced to Entra ID. The integration is fully optional and purely additive, no existing reports are affected unless you turn it on.

Syslog Time Offset Normalization for Network Devices

Netwrix Auditor now correctly normalizes timestamps from network devices that send syslog in local time rather than UTC. RFC 5424 sources have their embedded time offset parsed automatically, while legacy RFC 3164 sources gain a new “Assumed Time Zone” setting at the monitoring item level, eliminating a recurring source of inaccurate “When” values on Activity Records, with no manual configuration file edits required.

Secure Protocol Enforcement for the Public API

The Public API now supports configuring a minimum TLS version directly through the UI, closing a gap where administrators previously had no in-product way to enforce stronger transport security. This aligns the API with the product’s broader move toward secure-by-default communications and gives security and compliance teams a documented control to cite during audits.

Other Enhancements

  • Netwrix Auditor now supports audit data collection from Oracle Database 26, using the same collection, processing, and reporting pipeline as existing Oracle Database integrations.
  • Azure Files state-in-time stabilization and performance improvements.
  • The Password Expiration Notification (PEN) module now supports Group Managed Service Accounts (gMSA) for running its collection tasks.
  • The “Data Access Surges” report has been optimized for better performance.
  • The “Potentially Harmful Files” report has been optimized for better performance.
  • The “RPC server is unavailable” error message shown during Windows File Server Auditing collection has been made more actionable, helping administrators diagnose connectivity issues faster.

Bug Fixes and Miscellaneous Updates

Description Escalation # Case # Bug #
Memory leak in the audit archive service that could leave the datasource manager stuck uninitialized after high load, causing the Web API to stop returning new Activity Records (as seen with SIEM integrations). 419119 463696 439978
SQL Server State-in-Time collection failing when databases contain external (Entra ID) users or groups, which previously caused snapshot upload errors and incomplete reports after cross-domain migrations or in-place upgrades. 440809 474524 443994
Azure AD/Entra ID State-in-Time snapshot uploads failing due to duplicate directory role membership records returned by the Microsoft Graph API, which previously caused role-membership reports like Global Administrators to return no data. 441316 477823 442693
Report generation failing with an “Inconsistent Report Server URL” error when the SSRS Report Server URL was configured with an explicit port 443, which previously required removing the port number as a workaround. 442161 479410 371525
File Storage Auditor collection stopping entirely after a snapshot became corrupted on Unity/EMC storage targets, which previously required manually clearing the snapshot folder to resume data collection. 441016 478630 441087
Netwrix Auditor Logs Collection Service crashing repeatedly when a Nutanix Files monitoring plan is active, caused by a syslog TCP reactor invoking a callback on an already-destroyed collector object. 447641 482867 N/A
Mailbox audit collection fails with ArgumentNullException in SerializationDataPsMailboxParser (System.Guid..ctor) 450457 483208 450861
Netwrix Auditor for Azure Files reports user actions as Entra Object ID (GUID) instead of UPN in “Who” column. 445513, 445518 475884, 482070 445664
Exchange Online throws “Unable to collect mailbox permissions due to the following error: Object reference not set to an instance of an object.” 444558 481540 444947
Insufficient space for TempDB and execution plan regression after bulk operations due to stale statistics on Conf* tables. 444008 477732 450299
Fixed SSRS report generation continuing to run on the server after a user navigated away or re-generated a report, which previously wasted server resources on abandoned report jobs. N/A N/A 114059
Fixed User Activity Monitoring incorrectly treating two different computers as the same monitored target when IP addresses were reassigned within a configured IP range, which previously caused monitoring data to merge under one identity. N/A N/A 344712
Fixed SharePoint Online State-in-Time statistics collection failing after Microsoft retired the legacy MSOnline API, which previously caused an access-denied error during snapshot collection. N/A N/A 391452
Fixed SharePoint Online permission reports failing to mark externally shared Entra ID accounts as External, which previously caused those users to appear in reports even when external sharing was disabled for the tenant or site. N/A N/A 406505

Need help with this update?

There are many different ways to get help with our products!

Situation Action
If you feel the product is broken and not working as intended… Contact Support
If you have a question you’d like to ask other experts… Create a discussion in the community: Auditor > Discussions & Questions
If you have a feature request… Let our product team know directly: Auditor > Ideas
If you have something cool to show… Show everyone what you built: Auditor > Show & Tell

What are your thoughts?

We are always happy to hear from our users on what you like, and what you hope to see in the future. Please, share your thoughts below!

2 Likes

“Fixed SSRS report generation continuing to run on the server after a user navigated away or re-generated a report, which previously wasted server resources on abandoned report jobs.”

THANK YOU !!!

2 Likes

Thanks for the update. I’m just curious why the Console Update does not get published so it is seen from the portal.

Robert,

When you say, “Console Update”, are you referring to the client that you can put on individuals PCs? If so, there is actually not a separate installer for the client version. You can use the same installer you used to update the server. If the client was previously installed, it will automatically just upgrade it. If it’s never been installed, it will prompt you if you want the full version or the client version.

Also, just a quick note, only the Auditor server needs to be upgraded when we release a new update. The only time the client needs to be upgraded is if we release a new full version. For example, 10.9 to 10.10 would require.

Let me know if you have any other questions!

Michael Purdin
Manager, Technical Support Engineering

Hi Michael,
Thanks for the response… I only saw the update availability because I actually read the post. When I check in the console for version updates, it only says, “I’m using the latest product version”.
So, if I had not read your Community post I would not have investigated, since the “Check for Updates” says I’m current.
I guess under Settings it only reflects full version changes only, like from 10.9 to 10.10 and nothing in between?

Hello Daniel,

Can you engage our Account Manager and possibly support for the current system we have and the potential upgrades we need.

Let’s set up a meeting to get this going.

Regards,

Hi Achilles,

Sure, Bianca will reach out to you shortly.

Best, Daniel

Robert,

The Check for Updates button is actually controlled by us. We update a system on our end that pushes that out. Unless we have a critical fix, we typically wait a bit before we update the system to allow people who read the post to be able to get it and then we push it out the general public via the Check for Updates. It’s normally not that long of a delay for most updates.

Michael Purdin
Manager, Technical Support Engineering