Netwrix Endpoint Protector 2608.0.1.0 is a major release that expands data discovery and protection capabilities while delivering significant performance, scalability, and security enhancements.
At the center of the release is a redesigned eDiscovery experience for discovering and protecting sensitive data at rest. The new eDiscovery introduces granular contextual detection at the policy level, flexible automated scan scheduling, bulk remediation, user-initiated scans, and updated reporting backed by Relational Database Management System.
The release also helps organizations address emerging data security needs with:
- New AI/LLMs application category in Content Aware Protection (CAP) policies to provide more control over sensitive data shared with AI applications.
- Expanded URL category limits for greater flexibility when defining web-based data protection policies.
- Full AWS region support for S3 file shadow repositories.
- Post-Quantum Cryptography ciphers for client-server TLS to strengthen protection against emerging cryptographic threats.
Endpoint Protector 2608.0.1.0 also completes a major scalability initiative. Updates include latest PHP, MySQL LTS for Endpoint Protector configurations, a redesigned client communication stack , and Relational Database Management System as the high-performance log storage backend for Device Control, CAP, and eDiscovery. A new Log Alerts system with priority-based scheduling and modernized infrastructure further improve the platform’s ability to support demanding enterprise environments.
Together, these enhancements give customers stronger data discovery and protection, greater control over AI-related data movement, and a more scalable foundation for protecting sensitive data across their endpoints.
Want the full details? Click the link below!
What’s New in Endpoint Protector Server 2608.0.1.0
Platform Improvements
Endpoint Protector Server 2608 is built on a fully refreshed platform foundation. The appliance now runs on Ubuntu 26.04 LTS with lates PHP, MySQL and OpenSSL, bringing the server onto a current, long-term-supported base with up-to-date security and cryptographic libraries.
This release also introduces Relational Database Management System as a dedicated log storage engine. MySQL remains in place for what it does best, storing Endpoint Protector client and user settings, policies, and overall product configuration, while RDBMS database takes over responsibility for storing Device Control, Content Aware Protection, and eDiscovery logs. Alongside this, the process that writes logs into the database has been redesigned to run far more fluently, so log data flows into the system continuously instead of in bursts.
Together, these changes raise what a single appliance can comfortably handle, with no change to its specification. In internal testing, the 2608 appliance delivers 3–4x the performance and capacity of previous versions, meaning it can support a significantly larger number of endpoints and users, ingest a higher volume of logs, and make them available for reporting in far less time. For administrators, this translates directly into a more reliable and more responsive server, and for large deployments, into fewer appliances needed to cover the same environment. Reports and Analysis has been rebuilt on top of the new log engine, with refreshed Device Control and Content Aware Protection log views, faster exports, updated dashboards, and a new Log Alerts system that notifies you on device and content activity as it happens.
Because 2608 ships as a replatformed appliance image, moving from an earlier version requires a migration procedure rather than a standard in-place upgrade. For SaaS customers this is planned and carried out by Netwrix, with no action required. On-premises and self-hosted customers should follow the migration guide before upgrading: EPP Server Migration & Upgrade Guide | Netwrix Product Documentation
S3 File Shadow Repository: Full AWS Region Support
A reworked S3 File Shadow Repository implementation reflects the latest AWS S3 SDK updates. All AWS regions, including eu-central-1 and others previously unavailable, can now be selected when configuring S3 Object Storage.
As a result:
-
The Artifact Retrieval Method setting (Direct / Indirect) has been removed. Both options existed only to work around region gaps in the earlier implementation; with every region now natively supported, neither workaround is needed.
-
Existing S3 configurations and stored shadows are preserved after the upgrade.
eDiscovery Redesign
Version 2608 delivers a comprehensive redesign of the eDiscovery module — Endpoint Protector’s data-at-rest scanning capability. The new eDiscovery introduces per-policy contextual detection, flexible automated scan scheduling, expanded scan targets, bulk remediation, and a fully updated reporting experience backed by RDBMS storage. The redesign gives organizations more control over how they discover, analyze, and remediate sensitive data residing on endpoints.
Policy Management
eDiscovery now significantly expands policy capabilities, bringing the eDiscovery module in line with the functionality available in Content Aware Protection:
Up to 40 scan policies are now supported (previously limited to a smaller set). A performance advisory is shown when more than 5 policies are active simultaneously, as each additional policy increases agent scanning workload.
Predefined Policies: administrators can apply ready-made policy templates for common compliance frameworks including HIPAA, PCI DSS, GDPR, FINRA, SOX, FERPA, ITAR, PHI-US, and NY Shield Act. This mirrors the predefined policy experience already available in Content Aware Protection.
Content Detection Summary: Boolean logic operators for content detection rules are now available per eDiscovery policy. This matches the Content Detection Summary capability in CAP but is configured independently, changes in eDiscovery don’t affect CAP, and vice versa.
Last Modified filter: policies can target files based on their Last Modified date, allowing administrators to focus scans on recently changed files or to discover historical data within a specific date range.
Policy grid and widget views: policies can be viewed and managed in both a list layout and a widget/card layout, consistent with the CAP module experience.
Contextual Detection per Policy
Contextual Detection rules are now configured per eDiscovery policy, replacing the previous global System Parameters setting. Each policy can have up to 15 contextual detection rules, with support for:
-
Included and excluded context: rules can require or exclude specific context around detected content.
-
AND / OR operators: both included and excluded contexts support AND/OR logic.
-
Independent configuration: changes to contextual detection in an eDiscovery policy do not affect Content Aware Protection policies, and vice versa.
This per-policy approach enables more targeted and accurate scanning. For example, one policy can search for SSNs only when found near addresses and names, while another policy can search for credit card numbers regardless of surrounding context.
Scan Scheduling and Targets
Automatic scanning has been expanded with more granular scheduling options and new scan targets:
-
Scheduling options: scans can be scheduled as one-time, weekly, or monthly, with configurable start dates and times.
-
Scan priorities: administrators can assign priority levels to control scan execution order when multiple scans are active.
-
Resource-aware constraints: scans can be paused based on battery level, CPU usage, and user activity, minimizing disruption to endpoint users.
-
Removable devices as scan targets: data-at-rest discovery now extends beyond fixed storage. Removable devices (USB drives, external storage) can be added as scan targets per policy.
-
Scan progress tracking: the eDiscovery Scans table now displays a live progress bar showing scan completion percentage and a Found Objects counter.
User-Initiated Scans
End users can now initiate data-at-rest scans directly from the EPP agent on their endpoint:
-
User-initiated scan settings — administrators can configure scan retention (number of scans or days to keep), log rollover limits (by MB or disk percentage), and whether user-initiated scan results are sent to the server.
-
Event filtering — user-initiated scan events can be filtered separately in the log view, distinguishing them from server-initiated scans.
Note: User-initiated scans can generate a substantial number of event entries. The “Send user-initiated eDiscovery scan event data to the server” toggle is OFF by default.
Scan Results
The scan results experience has been significantly enhanced:
One file per row: each discovered file is displayed on its own row for improved readability, with expand/collapse icons to view detection details (matched policy, content type, matched items).
Inspect Found Items: from the eDiscovery Policies and Scans view, administrators can click “Inspect found items” on any policy scan to navigate directly to a filtered log view showing only the items discovered by that specific scan.
Action status tracking: remediation actions are tracked through Pending → Sent → Completed/Failed states, providing full visibility into remediation progress.
Reporting and Export
eDiscovery reporting has been consolidated and expanded:
-
Reports under Reports and Analysis: eDiscovery scan results are now accessible from the Reports and Analysis section, consolidating all log reporting in one location.
-
Export Logs integration: eDiscovery logs are included in the Export Logs section alongside Device Control and Content Aware Protection exports. Exports support CSV format with configurable batch sizes and automatic ZIP archiving.
-
Pagination and display settings: configurable maximum records per page and total records pulled from the database, enabling fast loading on servers with large scan result sets.
Log Handling Improvements
Stop and Clear Logs: when a scan action is set to “Stop and Clear Logs”, eDiscovery logs are now properly exported to the Export Log List before deletion. The Audit Log Backup integration for eDiscovery logs has been removed.
Log rotation: eDiscovery logs and log details are included in the automated log rotation schedule, with configurable retention periods.
Admin Roles
All new modules and sections introduced with the new eDiscovery, including eDiscovery Policies and Scans, Scan Results and Actions, Log Alerts, and Log Alerts History, have been integrated with the Admin Roles system. Administrators with restricted roles will see only the sections their role permits.
CAP Improvements
AI/LLMs Application Category
Content Aware Protection now includes a dedicated AI/LLMs application category in policy configuration. AI tools previously grouped under Cloud Services, including Claude, ChatGPT, Gemini, Microsoft Copilot, and others, have been moved to this new category. This gives administrators clearer, more targeted control over how AI applications are handled in their CAP policies.
-
The new category is available under Content Aware Protection > Policy > Applications.
-
Existing policies that included these applications under Cloud Services should be reviewed to confirm correct category assignment.
Autodesk Fusion File Type
Autodesk Fusion file extensions (.f3z) have been added to the file type list in Content Aware Protection and eDiscovery policy configuration, covering both Denylists and Allowlists.
DuckDuckGo Browser Support
DuckDuckGo has been added as a policy exit point for Windows and macOS under Content Aware Protection > Policy > Web Browsers. DPI is also supported for this browser.
Jira and Confluence Apps
Jira and Confluence apps have been added as two exit points under the Content Aware Protection > Policy > Apps section
Parasolid File Types Added to CAD Files
Parasolid file extensions (MIME type: model/parasolid) have been added to the CAD Files file type category in Content Aware Protection and eDiscovery policies. Organizations handling CAD data can now include Parasolid files in their policy scope without manual configuration.
WeChat: Weixin Process Name Added
The process name “Weixin” has been added under the WeChat application entry for Windows, ensuring EPP correctly intercepts WeChat file transfer activity on Windows endpoints where the Weixin process is active.
New Process Names for Brave, Firefox, and Chrome
Updated process name entries for Brave (Windows and macOS), Firefox (Windows, macOS, and Linux), and Chrome (Windows, macOS, and Linux).
Zoho WorkDrive TrueSync
The process name “Zoho WorkDrive TrueSync” has been added to the Cloud Services / File Sharing application category on Windows, extending CAP coverage to this sync client.
Device Control Improvements
DPI Status in Computer List
Administrators can now view the DPI (Deep Packet Inspection) enforcement status for managed computers directly in the Device Control > Computers list. The DPI Status column is hidden by default and can be enabled via the Show/Hide Columns control.
Note: DPI status is available only for computers actively communicating with the server. Status reflects the last known state, real-time DPI status is not supported.
External CD/DVD Drive Device Category
A new device type, External CD or DVD RW, has been added under Device Control > Global Rights > Device Types. External optical drives are now treated as a distinct category, separate from USB Storage devices. This enables more granular policy control across Windows, macOS, and Linux endpoints.
Audio Card Category Split (Input / Output)
The existing Audio Card device type has been renamed to Audio Card Output. A new Audio Card Input device type has been added with standard Allow Access / Deny Access rights. This enables separate policy enforcement for audio input (microphones) and audio output (speakers/headphones) on Windows.
Tamper Mode Extended to All OS Platforms
The Tamper Mode toggle in Device Control > Global Settings now applies to all supported operating systems. Previously scoped to Windows only, Tamper Mode protection against malicious client manipulation can now be enforced consistently across Windows, macOS, and Linux endpoints.
Migration Status Filter in Computer List
The Status filter dropdown in Device Control > Computers now includes migration-specific status values (e.g., “Migration successful”). Previously, these statuses were visible in the results table but could not be filtered on.
General Improvements
Post-Quantum Cryptography for Client-Server Communication
Endpoint Protector Server now enables Post-Quantum Cryptography (PQC) hybrid key exchange ciphers in the client-server TLS configuration, including X25519MLKEM768 and SecP256r1MLKEM768. This prepares customer environments for long-term cryptographic resilience in line with NIST-recommended standards, while maintaining backward compatibility with TLS 1.2/1.3.
Persistent Filters and Column Views
Administrators can now save, load, and manage predefined filter queries across all filter-enabled pages. In each section where filters are available, a new “Save” option allows storing the current filter configuration with a custom name. Saved filters can be loaded or deleted at any time, providing a consistent way to reapply frequently used views across the following sections:
Device Control: Devices, Computers, Users, Groups
Reports and Analysis: Device Control Logs, Content Aware Protection Logs, Scan Results and Actions, Admin Actions.
WGET, CURL, and AWS CLI Visibility
WGET, CURL, and AWS CLI have been added to the Deep Packet Inspection Applications list for Windows, macOS, and Linux. Previously these applications were only available under CAP file system monitoring; they now have full DPI-level visibility.
EntraID Sync: Azure Government (GCC High) Support
Endpoint Protector now supports Microsoft Entra ID synchronization for organizations operating in Azure Government (GCC High) environments. The sync configuration now accepts GCC High-specific endpoints, enabling user and group synchronization against the government-isolated Azure cloud.
Client Software Upgrade Improvements
The Client Software Upgrade page has been improved:
-
A new “Created by” column shows which administrator initiated each upgrade job, with a corresponding filter option.
-
Upgrade job statistics now auto-refresh when clicking the Reload button, without requiring a full page refresh.
Windows ARM Client Support
The server now supports Windows ARM client packages. The upload validator, client download page, and automated client upgrade mechanism have been extended to handle combined x64/ARM installer packages. ARM clients can be downloaded from the EPP Server UI and upgraded via the standard Client Software Upgrade mechanism.
Enhancements
Expanded REST API
This release significantly expands the Netwrix Endpoint Protector REST API, transforming it from a read-only reporting interface into a full management API for automating your endpoint DLP operations.
Previously, the API allowed you to retrieve log data. You can now programmatically manage the core Device Control entities, creating, reading, updating, and deleting Users, Computers, Devices, and Groups, making it possible to automate onboarding, keep your endpoint inventory in sync with external systems, and script routine administrative tasks that previously required the admin console.
The release also adds full Offline Temporary Password (OTP) management through the API, including password generation, revocation, bulk deletion, and transfer-limit checks, enabling helpdesk and self-service integrations for users who need temporary access while offline.
Log access has been broadened well beyond the original scope and now covers Device Control, Content Aware Protection, eDiscovery, Enforced Encryption, SCIM, System Alerts, and Admin Actions, giving you a single programmatic source for feeding SIEMs, dashboards, and compliance reporting.
On the security and integration side, the API now uses standards-based OAuth 2.0 authentication (Client Credentials grant) with signed access tokens, the machine-to-machine standard that most integration platforms support out of the box. Every endpoint is documented through interactive API documentation accessible directly from your browser, so your development and integration teams can explore, test, and validate requests without leaving the application. A dedicated health-check endpoint is also available to support monitoring and automated uptime checks.
URL Categories: Increased Limits
The URL Categories feature now supports up to 1,000 URL Category dictionaries, with each dictionary supporting up to 50,000 entries. The previous limits were 15 categories and 100 entries per list. The maximum number of categories is controlled via a server-side flag (max_nr_url_category) and can be adjusted at any time.
SIEM: File Shadow Association Indicator
SIEM event logs now include flags indicating whether a log event has an associated File Shadow and the repository type where the shadow is stored. This improves incident investigation workflows for organizations correlating EPP events with SIEM platforms.
SIEM: Additional Event Log Fields
Additional fields have been added to SIEM event exports, providing richer context for security analysis and correlation.
-
Shadow exists: indicates whether the logged file transfer has an associated file shadow (YES or NO), enabling SIEM rules to quickly identify events where file content was captured for forensic review.
-
Repository type: identifies the shadow repository storage type (for example, Samba or S3), so security teams can correlate file shadow availability with storage infrastructure.
-
Department ID: the numeric department identifier of the endpoint that generated the event, useful for building department-scoped SIEM dashboards and alert rules.
-
Certificate state: (Content Aware Protection logs only) the DPI certificate deployment state of the endpoint, helping identify machines where content inspection may be limited due to missing or expired certificates.
All new fields are included automatically in both standard and JSON SIEM output formats. No SIEM server reconfiguration is required, update your SIEM parsing rules or field mappings to take advantage of the additional data.
Domain Field Auto-Refresh in Computer List
The Domain field in the Device Control Computer List now refreshes automatically at each policy refresh interval, rather than only updating during agent installation or license re-registration. Empty or invalid domain values do not overwrite existing valid data.
File Type Allowlist: Archive Types Unchecked by Default
Archive file types are now unchecked by default in the MIME Type Allowlist on new EPP Server instances. This reduces the risk of policy bypass through archive file formats. Note: This change applies to new EPP Server deployments only. On servers upgraded from a prior version or restored from backup, the existing Allowlist configuration is preserved.
Improved Login Lockout Logic
The login lockout mechanism now uses improved timestamp-based comparison to calculate lockout durations.
SCIM API: Computer Column Added
The SCIM API response now includes a computer column, enabling integration with external device inventory and management systems.
SCIM: User Active Status Indicator
The SCIM user list now includes an active/inactive status indicator. When users are deprovisioned in the identity provider (e.g., Okta), they are deactivated rather than deleted, this indicator now surfaces that status in the EPP UI.
Bug Fixes and Miscellaneous Updates
| Module | Title & Description | ADO Number | Salesforce Number |
|---|---|---|---|
| General | Backup import fails with old database schema — Fixed issue when system backup import failed with an old database schema — importing a backup taken on an earlier EPP version failed due to schema compatibility issues. | 412033 | 00466840 |
| General | Diagnostic artifacts not downloadable from server UI — Fixed issue when EPP Client artifacts and diagnostic files were not downloadable from the server UI. | 366535, 389189 | 00428733, 00446646 |
| General | SMTP notifications failing with error 421 — Fixed issue when SMTP notifications failed with error 421 (Service Unavailable). | 379463 | 00439536 |
| General | Device Control alert emails not sent — Fixed issue when Device Control alert emails were not sent. | 422756 | 00472954 |
| General | Audit Log Backup not enforcing retention threshold — Fixed issue when Audit Log Backup did not remove logs older than the configured retention threshold — logs due for removal remained on the server after the backup job completed. | 432539 | 00475601 |
| General | Scheduled Audit Log Backup enters infinite retry loop and never completes — Fixed issue when the Scheduled Audit Log Backup entered an infinite retry loop and never completed — in certain conditions the job retried indefinitely without completing (workaround at the time was to use a one-time backup). | 441482, 440702, 437803 | 00479915, 00478217 |
| General | Logging level reset to Error after restoring global settings — Fixed issue when the logging level was incorrectly reset to Error after restoring global settings with file tracing enabled — affected individual computers and groups. | 441346 | 00480317 |
| General | User not available in OTP dropdown menu — Fixed issue when a user was not available in the OTP dropdown menu — when logged in as a non-super administrator assigned to multiple departments, searching for a specific user in the OTP dropdown did not return all matching users. | 355792 | 00419825 |
| Administration and User Management | Users absent from CAP after Entra ID synchronization — Fixed issue when users were absent from CAP after Microsoft Entra ID synchronization — users and groups synced from Entra ID appeared correctly in Device Control, but users were missing from the CAP entity picker; root cause was the sync script stopping processing of all subsequent groups when it encountered a previously deleted group in Entra ID. Note: users who have not had an EPP client installed do not appear as selectable entities in CAP until the client is deployed — this is expected behavior and is unchanged. | 422196 | 00472683 |
| Administration and User Management | Cannot change admin role for SSO/Okta/Azure AD-provisioned accounts — Fixed issue when admin role could not be changed for SSO/Okta-provisioned accounts, Azure AD-imported administrators (could not be changed from Super Administrator to Regular Administrator), or administrators provisioned via SSO generally — root cause was the SSO Administrator edit page being broken on load (JS crash) and missing several settings toggles (Account is active, Failed Login Alert, Enforce login IP restrictions), plus an empty email field for Azure SSO users. | 438442, 438116, 438175, 439843, 444560 | 00478387, 00478406, 00479385, 00481547 |
| Administration and User Management | Department-restricted admin sees all computers on login — Department-restricted admin sees all computers on initial login. | 444564 | 00481562 |
| Administration and User Management | Repeated failed logins block the login page — Repeated incorrect login attempts block the login page for multiple minutes. | 432072 | 00473869 |
| Administration and User Management | Login fails after removing an IP Access Restriction — Login fails after removing an IP Access Restriction. | 445643 | 00482109 |
| Administration and User Management | Login Time Restrictions intervals do not work — Fixed issue when Login Time Restrictions intervals did not work properly under System Configuration > System Administrators — the validator rejected valid values between 5 and 60 minutes, and the Login Attempt Restrictions inputs disappeared from the UI after disabling and re-enabling the option. | 451432 | 00483928 |
| Device Control | Group membership editing shows no selected members after 2604 upgrade — Fixed issue when group membership editing displayed no selected members following an upgrade to 2604 — computers and users were correctly assigned to groups but appeared unselected in the group edit view, and searching for users or computers within groups also returned no results. | 435876, 435920, 437552, 439728, 440182 | 00477423, 00477460, 00478034, 00479323, 00479680 |
| Device Control | Replicated group content does not match source — Fixed issue when replicated group content did not match the source (Group Replication feature). | 441072 | 00480162 |
| Device Control | False “missing serial number” error on device rename — Fixed issue when editing only the Device Name of a device record and saving triggered a false “missing serial number” error. | 438509 | 00478653 |
| Device Control | Policy reorder arrows missing from Widget View — Fixed issue when policy reorder arrows were missing from Widget View. | 438339 | 00478540 |
| Device Control | Allow rules scoped to computer and user not evaluated correctly — Fixed issue when allow rules scoped to both computer and user were not evaluated correctly. | 383749 | 00442556 |
| Device Control | Bulk device import blanks description with special characters — Fixed issue when special characters in a device description caused bulk device import to leave the description blank. | 422447 | 00472814 |
| Device Control | Unable to delete more than 10 computers/host entries in bulk — Fixed issue when deleting host entries from Device Control > Computers only worked for 3–5 entries at a time — selecting 10 or more silently failed to delete. | 424106 | 00473516 |
| Device Control | EasyLock client list filter panel renders blank — Fixed issue when the EasyLock client list filter panel rendered blank. | 436844 | 00477696 |
| Device Control | Web console freezes reordering Device Control groups via drag-and-drop — Fixed issue when reordering Device Control group priority via drag-and-drop froze the web console and eventually returned a 502 error, with no changes applied. | 432229 | 00475443 |
| Device Control | Diagnostics artifacts cannot be downloaded from server UI — Fixed issue when diagnostics artifacts could not be downloaded from the server UI. | 372622 | 00428246 |
| Device Control | Audio device incorrectly allowed by Windows Sound Recorder — Audio device incorrectly allowed by Windows Sound Recorder. | 432668 | 00475101 |
| Device Control | TightVNC file transfer logging via Extended VNC Policy Exit Point misbehaves — Extended VNC Policy Exit Point / TightVNC file transfer logging does not behave as intended. | 435616 | 00480546 |
| Device Control | Bulk import missing on Custom Classes — Fixed issue when clicking Import Content while creating a Custom Class in Device Control with “Bulk List of Devices” selected as the Adding method produced no response — the file import UI did not appear. | 440703 | 00479902 |
| Content Aware Protection | Actions menu dropdown mispositioned in CAP policy list — Fixed issue when accessing the actions menu at the bottom of the CAP policy list — the dropdown appeared at an incorrect position when the list was scrolled to the bottom. | 396733, 401244 | 00451651 |
| Content Aware Protection | MIME allowlist selections revert on save — Fixed issue when MIME file types deselected in the CAP allowlist reverted to selected on save. | 440033 | 00479560 |
| Content Aware Protection | Custom threat threshold not applied with regex-based rules — Fixed issue when the custom threat threshold was not applied when using regex-based Content Detection Rules. | 434607 | 00476714 |
| Content Aware Protection | URL denylist not enforced on Brave and Chrome — Fixed issue when the URL denylist was not enforced on Brave and Chrome — blocking worked only on Edge. | 424945 | 00473863 |
| Content Aware Protection | CAP conditions not evaluated with special characters in names — Fixed issue when CAP policy conditions were not evaluated if dictionary or regex names contained special characters or spaces — double-encoding of &, <, > and incorrect whitespace handling in condition names caused conditions to never match on the client, allowing files through instead of being blocked. | 426395 | 00474838 |
| Content Aware Protection | CAP policies sent from server to agent incorrectly — Fixed issue when CAP policies were sent from the server to the agent incorrectly under specific rights configurations. | 326875 | 00409969 |
| Content Aware Protection | iPhone Messages synced to macOS logged as CAP false positives — Fixed issue when iPhone Messages synced to macOS were logged as CAP false positives — when the CAP policy for Instant Messaging > Messages is enabled, messages synced from an iPhone to macOS via iCloud were incorrectly detected as policy events. | 412457 | 00467246 |
| Content Aware Protection | Wrong Destination Type displayed in CAP logs — Fixed issue when the wrong Destination Type was displayed in CAP logs — when a file was copied from a removable device to the local machine, the Destination Type incorrectly showed “USB Storage Device” instead of the local drive. | 319732 | 00409911 |
| Content Aware Protection | Regex Denylist Test tool rejects case-insensitive patterns — Fixed issue when the Regex Denylist Test tool rejected case-insensitive patterns — the Test button failed on patterns using the (?i) modifier, incorrectly flagging valid patterns as invalid; policy enforcement itself was unaffected, only the server-side Test tool was broken. | 445749 | 00482252 |
| Content Aware Protection | Regex not detected consistently with Boolean operators — Fixed issue when regex was not detected consistently when combined with Boolean operators — regex-based Content Detection Rules combined with other rules using AND/OR did not reliably detect all specified threats, and some terms were missed depending on operator and rule order. | 444158 | 00481191 |
| Content Aware Protection | Content Aware Report not loading — Fixed issue when the Content Aware Report failed to load, causing the EPP portal to become unresponsive when opening it. | 444030 | 00481117 |
| Content Aware Protection | AWS SES configuration for Email Server Settings stopped working after upgrade — AWS SES configuration for “E-mail Server Settings” stopped working after upgrade, resulting in missing alert notifications. | 383157 | 00436586 |
| Content Aware Protection | Content Aware email notifications missing attachment with “Native” mail settings — Content Aware email notifications are sent without the expected attachment when using “Native” mail server settings. | 449233 | 00483046 |
| Content Aware Protection | Unable to change Content Aware Protection policy priority — Unable to change Content Aware Protection policy priority. | 446134 | 00482384 |
| DPI | DPI Allowlist edit form missing file upload fields — Fixed issue when the DPI Allowlist edit form was missing file upload fields for entries with existing imported content. | 437887 | 00478275 |
| eDiscovery | eDiscovery logs not visible to read-only admin users — Fixed issue when eDiscovery logs were not visible to read-only administrative users. | 397798 | 00452708 |
| Reports and Analysis | Effective Rights report returns empty with filters applied — Fixed issue when the Effective Rights report returned empty when filters were applied — filtering by computer name or username returned no results despite data being present in the unfiltered view; some customers also observed mismatched computer-user pairs in the full export. | 394400, 399153, 418207 | 00449797, 00453974, 00470496 |
| Reports and Analysis | Report export stuck as “export currently running” — Fixed issue when the Content Aware Report / Logs Report export got stuck showing “export currently running.” | 413495 | 00467724 |
| Reports and Analysis | Audit Log Backup export file contains repeated header lines — Audit Log Backup export file (ofiletrace.csv) contains the same header line repeated multiple times. | 401383 | 00455638 |
| Reports and Analysis | Artifact log files cannot be downloaded — Artifact log files cannot be downloaded. | 426325 | 00473021 |
| Reports and Analysis | DNS display issue — Fixed issue with the DNS display. | 444703 | 00480718 |
| SCIM | SCIM log entries truncated at 65,535 characters — Fixed issue when SCIM log entries were truncated at 65,535 characters — request_body and response_body were cut off for large payloads, hindering troubleshooting; the character limit has been increased. | 432826 | 00475770 |
| SCIM | Okta SCIM subset PUT overwrites full group membership — Fixed issue when a subsequent subset PUT request from Okta SCIM overwrote full group membership — when Okta sent a second PUT with a membership subset shortly after the first, EPP replaced the complete membership with the subset. | 434480 | 00476615 |
Known Limitations
| Component | Description | — |
|---|---|---|
| General | CAP logs generated before version 2602 display incorrect policy types after upgrading to 2602 or later. |
Deprecated
| Component | Description | Targeted Release |
|---|---|---|
| General | Contextual Detection under System Parameters will be discontinued and replaced by Context Detection Rules in the Content Detection Summary section of CAP Policies. | 2608 |
Upcoming Deprecations
| Component | Description | Targeted Release |
|---|---|---|
| General | The File Shadow Maintenance feature, which provides functionality for listing and managing File Shadows stored locally on the EPP Server will be discontinued in future. | Upcoming release |
Need help with this update?
There are many different ways to get help with our products!
| Situation | Action |
|---|---|
| If you feel the product is broken and not working as intended… | Contact Support |
| If you have a question you’d like to ask other experts… | Create a discussion in the community: Endpoint Protector > Discussions & Questions |
| If you have a feature request… | Let our product team know directly: Endpoint Protector > Ideas |
| If you have something cool to show… | Show everyone what you built: Endpoint Protector > Show & Tell |
What are your thoughts?
We are always happy to hear from our users on what you like, and what you hope to see in the future. Please, share your thoughts below!


