This release is our biggest step yet toward closing the gap between on-premises AD security and cloud identity security, plus a set of operational improvements based directly on your feedback.
Want the full details? Click the link below!
We’re excited to announce that Netwrix PingCastle 4.0 is now generally available.
The new capabilities described below are available in PingCastle Enterprise. Other editions receive applicable maintenance updates. PingCastle Pro will follow a separate release schedule and will be released in the future, with applicable updates delieverd through future Pro releases.
What’s New in PingCastle Enterprise 4.0
100+ new Entra ID risk indicators
PingCastle 4.0 extends its Entra ID risk indicators to 102 risks, from common gaps like missing MFA and excessive admin roles, to easily overlooked risks like unsafe app consent grants and conditional access gaps, all mapped to MITRE ATT&CK®. This brings the same depth of coverage you already rely on for on-prem AD to the cloud side of your hybrid identity.
SCIM and Just-in-Time (JIT) provisioning
Account lifecycle management is now tied to real identity events instead of manual admin work. With JIT provisioning, accounts are created automatically the first time a user signs in via OAuth or SAML, so claims-based authentication no longer requires setting up accounts ahead of time.
Full audit logs
A built-in, queryable log of administrative and user actions, so you can answer “who changed this, and when” without piecing it together after the fact.
A rebuilt scan scheduling engine
Scan scheduling has moved off Windows Task Scheduler and into PingCastle itself, built on Quartz.NET. This removes the local admin requirement for scheduled scans and adds new options for privileged, targeted scans, including scans against a specific domain controller.
Bulk domain updates
Apply configuration changes across multiple domains at once instead of repeating the same change domain by domain.
A modernized foundation
PingCastle now runs on .NET 10, keeping the platform current on security and performance. Configuration has also moved to database-backed storage, so you no longer need to manually edit flat files or the registry to configure the tool.
Want to see the new Entra ID coverage plus all the new cool features in action?
Join our webinar on 2026-09-10T14:00:00Z
Register here.
Bug Fixes and Miscellaneous Updates
The Free Community Edition
| Fix | Reference |
|---|---|
| Resolved false positive detections by Windows Defender caused by the HotFix scanner’s CIM collector option | GitHub #354 |
| Resolved false positives in the MS17-010 HotFix scanner | GitHub #333 |
| Fixed an issue where the SMB2SignatureNotEnabled scanner produced an invalid response structure | Esc. 395483 |
| Fixed incorrect data displayed in LAPS pie charts | Case 450719 |
| Fixed PingCastle failing to run when launched from a non-domain-joined machine | Esc. 391121 |
| Fixed an invalid signing check in the SMB1 scanner | 404003 |
| Fixed the A-LimitBlankPasswordUse check referencing the wrong GPO list | 410082 |
| Fixed the A-AnonymousAuthorizedGPO health check rule | 407648 |
| Fixed a case-sensitivity issue in the DnsZoneUnsecureUpdate1 zone name comparison | 407576 |
| Fixed a random blank line appearing in Entra ID scan output | 390393 |
| Standardized Entra ID authentication to use the oauth2/v2.0/token endpoint | 392840 |
| Updated terminology from “MS LAPS” to “Windows LAPS” throughout the product | 357401 |
| Corrected rule text and reproduction issues for P-DelegationDCsourcedeleg, P-PrivilegeEveryone, and A-DnsZoneAUCreateChild | 397377, 397272, 397270 |
| Fixed OS version detection and obsolescence status for Windows 10/11 22H2 | GitHub #282, #285 |
| Updated vulnerable third-party packages | Esc. 400967 |
Standard, for Service Providers
Includes all Community edition fixes above, plus:
| Fix | Reference |
|---|---|
Added the missing --services collection option to the help text |
Esc. 394006 |
| Fixed the Exit option terminating the program instead of returning one menu level | Esc. 361697 |
| Fixed the risk model section being incorrectly clickable/collapsible | 381819 |
| Fixed an assembly load failure when launching Standard from an Enterprise install folder | 380204 |
Enterprise Edition
Includes all Community and Service Providers fixes above, plus:
| Fix | Reference |
|---|---|
| Fixed unexpected filter behavior on Infrastructure → Domains | Esc. 393666 |
| Added new Functional Levels for filtering | Esc. 392262 |
| Fixed an issue preventing deletion of a Domain or Entity | Case 401714 |
| Improved performance for large HTTP GET requests in the web application | Case 406078 |
| Fixed “Bulk actions” appearing to run indefinitely even after completion | Case 407346 |
| Fixed bulk exception “reapply” operations timing out on large datasets | Esc. 426793 |
| Fixed the auto-updater corrupting configuration files on large server fleets | Esc. 420381 |
| Fixed bulk actions crashing when processing very large Active Directory domains | 433142 |
| Restored Configuration Migration functionality between instances | 418327 |
| Improved migration performance for environments with a high number of domains | 426591 |
| Fixed Multi-Schema UI not reflecting recent changes | 425072 |
| Fixed the Scheduler page failing to refresh in Microsoft Edge | 414714 |
| Added a delete API endpoint for reports | 423476 |
| Improved error handling to show a clear “Access Denied” message for entity permission errors | 436841 |
| Fixed Entities button ordering, Hilbert map legend positioning, and GlobalRiskScore navigation | 391119, 391004, 391976 |
| Fixed product version missing from the installer package | 390789, 390790 |
For the complete, continuously updated bug fix history, see the Netwrix PingCastle Bug Fix List on Netwrix Community.
Need help with this update?
There are many different ways to get help with our products!
| Situation | Action |
|---|---|
| If you feel the product is broken and not working as intended… | Contact Support |
| If you have a question you’d like to ask other experts… | Create a discussion in the community: PingCastle > Discussions & Questions |
| If you have a feature request… | Let our product team know directly: PingCastle > Ideas |
| If you have something cool to show… | Show everyone what you built: PingCastle > Show & Tell |
What are your thoughts?
We are always happy to hear from our users on what you like, and what you hope to see in the future. Please, share your thoughts below!


