PingCastle 4.0 released

This release is our biggest step yet toward closing the gap between on-premises AD security and cloud identity security, plus a set of operational improvements based directly on your feedback.

Want the full details? Click the link below!

We’re excited to announce that Netwrix PingCastle 4.0 is now generally available.

The new capabilities described below are available in PingCastle Enterprise. Other editions receive applicable maintenance updates. PingCastle Pro will follow a separate release schedule and will be released in the future, with applicable updates delieverd through future Pro releases.

What’s New in PingCastle Enterprise 4.0

100+ new Entra ID risk indicators
PingCastle 4.0 extends its Entra ID risk indicators to 102 risks, from common gaps like missing MFA and excessive admin roles, to easily overlooked risks like unsafe app consent grants and conditional access gaps, all mapped to MITRE ATT&CK®. This brings the same depth of coverage you already rely on for on-prem AD to the cloud side of your hybrid identity.

SCIM and Just-in-Time (JIT) provisioning
Account lifecycle management is now tied to real identity events instead of manual admin work. With JIT provisioning, accounts are created automatically the first time a user signs in via OAuth or SAML, so claims-based authentication no longer requires setting up accounts ahead of time.

Full audit logs
A built-in, queryable log of administrative and user actions, so you can answer “who changed this, and when” without piecing it together after the fact.

A rebuilt scan scheduling engine
Scan scheduling has moved off Windows Task Scheduler and into PingCastle itself, built on Quartz.NET. This removes the local admin requirement for scheduled scans and adds new options for privileged, targeted scans, including scans against a specific domain controller.

Bulk domain updates
Apply configuration changes across multiple domains at once instead of repeating the same change domain by domain.

A modernized foundation
PingCastle now runs on .NET 10, keeping the platform current on security and performance. Configuration has also moved to database-backed storage, so you no longer need to manually edit flat files or the registry to configure the tool.

Want to see the new Entra ID coverage plus all the new cool features in action?
Join our webinar on 2026-09-10T14:00:00Z
Register here.


Bug Fixes and Miscellaneous Updates

The Free Community Edition

Fix Reference
Resolved false positive detections by Windows Defender caused by the HotFix scanner’s CIM collector option GitHub #354
Resolved false positives in the MS17-010 HotFix scanner GitHub #333
Fixed an issue where the SMB2SignatureNotEnabled scanner produced an invalid response structure Esc. 395483
Fixed incorrect data displayed in LAPS pie charts Case 450719
Fixed PingCastle failing to run when launched from a non-domain-joined machine Esc. 391121
Fixed an invalid signing check in the SMB1 scanner 404003
Fixed the A-LimitBlankPasswordUse check referencing the wrong GPO list 410082
Fixed the A-AnonymousAuthorizedGPO health check rule 407648
Fixed a case-sensitivity issue in the DnsZoneUnsecureUpdate1 zone name comparison 407576
Fixed a random blank line appearing in Entra ID scan output 390393
Standardized Entra ID authentication to use the oauth2/v2.0/token endpoint 392840
Updated terminology from “MS LAPS” to “Windows LAPS” throughout the product 357401
Corrected rule text and reproduction issues for P-DelegationDCsourcedeleg, P-PrivilegeEveryone, and A-DnsZoneAUCreateChild 397377, 397272, 397270
Fixed OS version detection and obsolescence status for Windows 10/11 22H2 GitHub #282, #285
Updated vulnerable third-party packages Esc. 400967

Standard, for Service Providers

Includes all Community edition fixes above, plus:

Fix Reference
Added the missing --services collection option to the help text Esc. 394006
Fixed the Exit option terminating the program instead of returning one menu level Esc. 361697
Fixed the risk model section being incorrectly clickable/collapsible 381819
Fixed an assembly load failure when launching Standard from an Enterprise install folder 380204

Enterprise Edition

Includes all Community and Service Providers fixes above, plus:

Fix Reference
Fixed unexpected filter behavior on Infrastructure → Domains Esc. 393666
Added new Functional Levels for filtering Esc. 392262
Fixed an issue preventing deletion of a Domain or Entity Case 401714
Improved performance for large HTTP GET requests in the web application Case 406078
Fixed “Bulk actions” appearing to run indefinitely even after completion Case 407346
Fixed bulk exception “reapply” operations timing out on large datasets Esc. 426793
Fixed the auto-updater corrupting configuration files on large server fleets Esc. 420381
Fixed bulk actions crashing when processing very large Active Directory domains 433142
Restored Configuration Migration functionality between instances 418327
Improved migration performance for environments with a high number of domains 426591
Fixed Multi-Schema UI not reflecting recent changes 425072
Fixed the Scheduler page failing to refresh in Microsoft Edge 414714
Added a delete API endpoint for reports 423476
Improved error handling to show a clear “Access Denied” message for entity permission errors 436841
Fixed Entities button ordering, Hilbert map legend positioning, and GlobalRiskScore navigation 391119, 391004, 391976
Fixed product version missing from the installer package 390789, 390790

For the complete, continuously updated bug fix history, see the Netwrix PingCastle Bug Fix List on Netwrix Community.


Need help with this update?

There are many different ways to get help with our products!

Situation Action
If you feel the product is broken and not working as intended… Contact Support
If you have a question you’d like to ask other experts… Create a discussion in the community: PingCastle > Discussions & Questions
If you have a feature request… Let our product team know directly: PingCastle > Ideas
If you have something cool to show… Show everyone what you built: PingCastle > Show & Tell

What are your thoughts?

We are always happy to hear from our users on what you like, and what you hope to see in the future. Please, share your thoughts below!

4 Likes