Looking for a bug fix list for all versions of PingCastle?
All bug fixes will automatically be added here!
3.5 Updates
PingCastle Patch Version 3.5.1.33 Released
June 9, 2026
What’s New — Bug Fixes
Escalation Fix
PingCastle Pro — Unable to Access Website After Upgrade (HTTP 400 Error)
Escalation #439100
PingCastle Pro now applies the same secure cookie authentication configuration as PingCastle Enterprise. Session cookies are marked HttpOnly, use a server-side ticket store, and respect a configurable expiry (defaulting to 2 days) with sliding expiration enabled. This brings authentication session behaviour in Pro into parity with Enterprise and closes a gap in session-security hardening.
GitHub Reported Issues — HotFix Scanner
PingCastle.exe Detected by Windows Defender
GitHub Issue #354
A recent release added a CIM collector option to the HotFix scanners (for MS14-068 and MS17-010) to improve collection speeds. This improvement inadvertently triggered Windows Defender antivirus definitions.
The CIM collection option has been removed. This will be revisited after the 4.0 release to deliver a working CIM collector that does not trigger antivirus definitions.
Original community idea: Optimize WMI Queries to Be Modern and Faster
False Positives for MS17-010
GitHub Issue #333
Certain operating systems were still producing false positives in the HotFix scanner for MS17-010. Two issues have been resolved:
- The fallback mechanism was not being invoked in certain circumstances.
- The KB HotFix lists were incomplete for some operating systems.
PingCastle Version 3.5.1.31 Released
May 19, 2026
| ID | Title | Type | Escalation # | Escalation Summary |
|---|---|---|---|---|
| 360982 | Detailed Cartography: Expand after collapse shows error | Bug | — | Fixed console error when expanding nodes after collapse in domain cartography view |
| 408398 | Wrong links in Documentation part of report | Bug | 408398 | Documentation links corrected to point to valid resources |
| 410767 | Documentation of required roles | Bug | 410767 | Documentation has been updated with detailed role requirements |
| 413093 | “Wrong License” Text Update | Bug | — | Updated error message text for clarity |
| 414399 | Entra ID: No MFA Column | Bug | — | Added MFA status column to Entra ID reporting |
| 414458 | Edit User Role Info Icons different to others | Bug | — | Standardized icon styling in user role management UI |
| 414526 | Webhooks are unclear | Bug | — | Improved webhook configuration documentation and UI labels |
| 414538 | Editing an agent resets its last login date | Bug | — | Fixed agent editor to preserve last login timestamp |
| 414544 | User-Based Licensing Note | Bug | — | Clarified user-based licensing messaging |
| 414714 | Scheduler: Refresh page doesn’t work in Edge | Bug | — | Fixed page refresh functionality in Microsoft Edge browser |
| 414984 | Custom Rules: Type Info Icon shows no info | Bug | — | Restored tooltip information for custom rules type selector |
| 415122 | Password Change not required on email change | Security Fix | — | A security gap where users could change email without password reset has been fixed; password reset is now enforced when email address changes |
| 415128 | Configuration and Mapping of External Logins is broken | Bug | — | Critical functionality for external authentication was non-functional; fixed to restore external login support |
| 415708 | Creating external users with password vulnerability | Security Fix | — | External user accounts were being created with explicit passwords; system now enforces passwordless authentication for external users |
| 416037 | Fixing release 3.5 build pipeline | Task | — | Updated build configuration for release process |
| 416104 | Low privilege users able to see/create/delete Scheduler | Security Fix | — | A privilege escalation vulnerability allowed non-admin users to access scheduler; access controls have been tightened to administrators only |
| 416129 | Custom Rules Download still produces XML | Bug | — | Custom rules export was generating legacy XML format instead of current format; corrected output format |
| 417468 | appsettings.console.json is not generated on update | Escalation | 417468 | Configuration file missing after running updates; deployment process now properly generates required config files |
| 418050 | Update Trust Types | Bug | — | Refreshed trust relationship type definitions |
| 418327 | Configuration Migration doesn’t work | Bug | — | Restored configuration migration functionality between instances |
| 418334 | Exceptions | Bug | — | Fixed exception handling in scanner engine |
| 418509 | Honeypot exclusions are not working in 3.5.0.40 | Bug | 418509 | Honeypot exclusion functionality has been restored |
| 418730 | GitHub PR - Typo in LDAP Filter (BuiltinDomain) | Bug | — | LDAP filter contained typo affecting BuiltinDomain detection; filter syntax corrected |
| 419388 | Config missing after running manual scan | Escalation | 419388 | Manual scans were deleting configuration files; scan process now preserves configuration state |
| 419591 | All links to “stigviewer” are broken | Escalation | 419591 | Documentation links to external STIG viewer resource were incorrect; links updated to valid URLs |
| 420381 | PingCastle Auto-Updater breaks configurations (~80 servers) | Escalation | 420381 | CRITICAL: Auto-updater in versions 3.5.0.37+ was corrupting config files on affected servers; update mechanism rewritten to prevent data loss |
| 420428 | DC vulnerability (MS17-010) | Escalation | 420428 | Check for MS17-010 (EternalBlue) vulnerability missing reporting; added detection for unpatched domain controllers |
| 422097 | Scan entraID | Feature | 422097 | Entra ID scanning capability has been added |
| 422172 | PWDNeverExpires doesn’t account for recent password changes | Bug | — | Enhanced check to properly evaluate recently changed passwords |
| 422175 | Computer Analysis: Delegation confusion | Bug | — | Clarified delegation reporting in computer analysis |
| 422249 | Exclusions taking ages to add and delete for AD Risks | Bug | — | Bulk exception operations were causing performance degradation; optimized database queries for exception handling |
| 422878 | Exception not in use | Escalation | 422878 | Exceptions configured in the system were not being applied to scan results; exception filtering logic fixed |
| 423164 | Exception for Windows Server 2012 not working | Escalation | 423164 | Exceptions targeting Windows Server 2012 systems were being ignored; corrected version matching logic |
| 423476 | There is no delete API for reports | Bug | — | Added report deletion capability to REST API |
| 423757 | Slow speed for bulk exceptions on enterprise | Bug | — | Optimized bulk exception operations for large environments |
| 423914 | Pingcastle exception | Bug | 423914 | Exception handling has been improved |
| 423921 | “Number of domains NOT audited” showing wrong information | Escalation | 423921 | Dashboard maturity detail incorrectly filtering domains audited/not audited. Filter links pointed to empty results; corrected to show proper domain audit status. |
| 424072 | Remove AI-assisted taglines from public repo | Task | — | Cleaned up source code comments in public GitHub repository |
| 425012 | Create domain action plan gives blank page | Bug | — | Fixed UI blank page error when generating domain action plans |
| 425072 | Changes to Multi-Schema UI | Bug | — | Multi-domain schema UI was not properly reflecting recent changes; UI state management corrected |
| 425245 | KB Scanner Slow in Compute Risks | Bug | — | Optimized knowledge base scanning performance |
| 426194 | Error opening file “ad_gc_rules_3.5.0.44.xlsx” | Escalation | 426194 | Custom rules file download was corrupted or inaccessible; file generation and delivery pipeline repaired |
| 426386 | S-AesNotEnabled - RC4 deprecation score issue | Escalation | 426386 | RC4 deprecation check (S-AesNotEnabled) was returning incorrect scores due to algorithm change; scoring logic updated for RC4 phase-out |
| 426591 | Slow Migration for high numbers of domains | Bug | — | Improved migration performance for multi-domain environments |
| 426793 | Bulk import: Reapply exceptions is dead slow | Escalation | 426793 | CRITICAL: Bulk exception reapplication operations timing out on large datasets; rewrote batch processing to use async operations |
| 431913 | SMTP configuration in appsettings.console.json not being read | Bug | — | Fixed configuration file parsing for console SMTP settings |
| 432143 | appsettings.console.json missing from download links | Bug | — | Console configuration file was not included in downloads; added to package manifest |
| 433142 | Bulk actions crash Enterprise with large domains | Bug | — | Bulk operations crashing when processing very large Active Directory domains; optimized memory handling and added pagination |
| 434171 | Schema Change UI: Codeblock display | Bug | — | Improved code block display in schema UI tabs with better formatting and copy functionality. |
| 434415 | PingCastle Date Format is in US? | Bug | — | Standardized date formatting to use local browser formats with 24-hour clock instead of US format. |
| 434419 | Standardise PingCastle Date Formats | Bug | — | Unified inconsistent date formats across domains view, report view, and compare reports to use consistent 24-hour format stored in UTC. |
| 435001 | Auto-Redirect when making exceptions failing | Bug | — | Fixed issue where Enterprise failed to redirect page after creating an exception. |
| 435360 | Deleting an action plan after you use the dropdown filters the page is returned unfiltered | Bug | — | Corrected filter persistence; page now maintains dropdown filters after deleting an action plan. |
| 435500 | A-MembershipEveryone: BUILTIN\Users exclusion causes false positive | Bug | — | Fixed string mismatch in exclusion logic that prevented BUILTIN\Users from being correctly excluded from A-MembershipEveryone risk assessment. |
| 435829 | OIDC logout does not end the provider session | Bug | — | Enhanced OIDC logout to properly redirect to provider’s end-session endpoint, terminating IdP session in addition to local cookie clearing. |
| 435867 | Remove System.Private.Uri 4.3.0 transitive dependency | Task | — | Removed obsolete System.Private.Uri 4.3.0 transitive dependency; .NET 8 runtime implementation takes precedence eliminating CVE-2019-0980, CVE-2019-0981, CVE-2019-0657 risk. |
| 435947 | S-AesNotEnabled incorrectly includes disabled accounts in risk score | Bug | — | Corrected S-AesNotEnabled rule to exclude disabled accounts from risk count, as disabled accounts cannot be AS-REP Roasted. |
| 436767 | Conflicting warnings when setting up login on fresh system | Bug | — | Fixed password requirement validation to display only one correct error message instead of conflicting inline and header warnings on initial admin setup. |
| 436841 | Entity - missing error handling for missing permissions | Bug | — | Improved authorization error handling; users without permission to access an entity now receive clear “Access Denied” message instead of redirect to login. |
PingCastle Patch Version 3.5.0.44 Released
March 5, 2026
- Fixed Authentication issues with PingCastle.exe using the --user and --password options to scan remote domains from both standalone systems and domain joined systems.
- Fixed Windows Authentication issues where Windows Authentication was creating accounts as internal users, working for the first sign in and then not working for subsequent sign ins.
- Fixed a SQL Migration issue in PingCastle Pro. This manifested as Report Import issues, emails not being sent and a specific sql error in the windows event log.
Netwrix PingCastle 3.5 Released
February 3, 2026
| Description | Case # | Escalation # |
|---|---|---|
| LAPS pie charts display incorrect data | 450719 | 395623 |
| Owner permissions for ‘Rule Exception’ are misconfigured | 455140 | 400752 |
| PingCastle Web UI does not start after EntraID credential update | 454716 | 400184 |
| [SMB2SignatureNotEnabled] Invalid SMB2_NegotiateResponse structure. | 395483 | |
| [Standard] The --services collection option is not listed in help | 394006 | |
| [Enterprise] Infrastructure → Domains: Filters behave unexpectedly | 393666 | |
| [Enterprise] Add new Functional Levels for filtering | 392262 | |
| [Standard] Exit option incorrectly terminates the program. Expected behavior: go back one level | 361697 | |
| Running PingCastle from a non-domain-joined machine does not work | 391121 | |
| [Security] Update vulnerable packages | 400967 | |
| Report email notification not showing the maturity level | 411955 | 00466815 |
| Microsoft Defender ASR (attack surface reduction) | 410439 | 00463820 |
| “Bulk actions” are never ending - even if “done” | 407346 | 00460760 |
| Page Refresh on “Delete” of Rule Exception removes Filter | 407345 | 00460757 |
| “ActiveComputers” broken after exclusion of Win10 ESU | 407258 | 00460739 |
| For some large HTTP GET requests, PCE web application takes far too long | 406078 | 00459735 |
| Unable to delete Domain and Entity from PingCastle Enterprise. | 401714 | 00456124 |
| False Positive for A-SMB2SignatureNotEnabled on PingCastle 3.4.1.31 | 395206 | 00450402 |
| Exception: Some or all identity references could not be translated. | 395205 | 00450400 |
| Change UK spelling of Licence to US License | 410486 | |
| A-LimitBlankPasswordUse Check looking in wrong GPO list. | 410082 | |
| Healthcheck crashes Pingcastle when the domain name doesn’t match the domains in the license | 409982 | |
| PingCastle Interactive asks for server name twice when running scanners | 409659 | |
| A-AnonymousAuthorizedGPO healtcheck rule broken | 407648 | |
| DnsZoneUnsecureUpdate1 uses case-sensitive comparisons for zone name | 407576 | |
| Typo | 406128 | |
| PingCastleAutoUpdater Multiple Section Error | 405649 | |
| SMB1 Scanner signing check is invalid | 404003 | |
| Inconsistent Line Spacing on Domain Page | 398865 | |
| Change description for --server parameter in Help message | 397490 | |
| Can’t reproduce HealthCheck Rule P-DelegationDCsourcedeleg | 397380 | |
| Wrong technical explanation for HealthCheck Rule P-DelegationDCsourcedeleg | 397377 | |
| HealthCheck Rules StaledMS14_068 Should Validate Actual Patch Status and Configuration | 397283 | |
| HealthCheck Rule StaledMS17_010 Should Validate Installed Updates and SMBv1 Status | 397282 | |
| Wrong description to HealthCheck Rule P-PrivilegeEveryone | 397272 | |
| Can’t reproduce HealthCheck Rule A-DnsZoneAUCreateChild on 2025 domain. | 397270 | |
Update outdated docs.microsoft.com links to learn.microsoft.com for long-term reliability |
396943 | |
| Unclear Mapping Between Filters and Table Columns for domain page | 396550 | |
| Change Support Page link to Netwrix Support | 396310 | |
| Remove PingCastleUpdateService from installer folders | 396305 | |
| Entra: Ensure all authentications use oauth2/v2.0/token | 392840 | |
| AzureAD Scan - Random Blank Line | 390393 | |
| LAPS: Change MS LAPS to Windows LAPS. | 357401 |
Looking for a bug fix list for all versions of PingCastle?
All bug fixes will automatically be added here!
3.4 Updates
Patch Version 3.4.2.66 Released
October 02, 2025
Updated ESC2 Check
-
Privileged Mode Added: The ESC2 check now supports Privileged Mode to validate enrollment permissions on the Certification Authority.
-
Clearer Rule Text: Updated messaging makes it obvious when the risk is identified as ESC2.
-
Improved Guidance: Expanded technical explanations and remediation steps for easier issue resolution.
Entra ID Terminology Standardization
- All terminology has been standardized to align with Entra ID, replacing legacy Azure AD language for consistency and clarity.
Modern Authentication for Email Notifications (Enterprise / Pro)
-
PingCastle now supports Modern Authentication with Office 365.
-
Uses an Entra app registration to send emails directly from the application instead of legacy SMTP basic auth.
-
By default, the app can send on behalf of anyone in the tenant—we strongly recommend restricting this to a dedicated PingCastle mailbox via the setup process.
UI Improvement: Remove Domain from the Interface
-
Previously, domains could only be removed through a hidden link (
/Database/DeleteDomain/{DomainId}). -
A Delete Domain button is now available directly on the Domain Report page for a smoother user experience.
Enhanced DNS Zone Update Rules (A-DnsZoneUpdate1 / A-DnsZoneUpdate2)
-
DistinguishedName property added to
HealthcheckDnsZones. -
LDAP collection now captures DNs for
(objectClass=dnsZone)objects. -
Filters out CNF (conflict) and InProgress replication artifacts.
-
AddRawDetail outputs now include both DN and partition context (DomainDnsZones vs DefaultNamingContext) for precise object identification.
Bug Fixes
| Description | Case # | Escalation # |
|---|---|---|
| LAPS pie charts display incorrect data | 450719 | 395623 |
| Owner permissions for 'Rule Exception' are misconfigured | 455140 | 400752 |
| PingCastle Web UI does not start after EntraID credential update | 454716 | 400184 |
| [SMB2SignatureNotEnabled] Invalid SMB2_NegotiateResponse structure. | 395483 | |
| [Standard] The --services collection option is not listed in help | 394006 | |
| [Enterprise] Infrastructure → Domains: Filters behave unexpectedly | 393666 | |
| [Enterprise] Add new Functional Levels for filtering | 392262 | |
| [Standard] Exit option incorrectly terminates the program. Expected behavior: go back one level | 361697 | |
| Running PingCastle from a non-domain-joined machine does not work | 391121 | |
| [Security] Update vulnerable packages | 400967 |
Patch Version 3.4.1.38 Released
July 16, 2025
| Title | DevOps ID | Case Number |
|---|---|---|
| False Positive for A-SMB2SignatureNotEnabled on PingCastle 3.4.1.31 | 395206 | 00450402 |
| Exception: Some or all identity references could not be translated. | 395205 | 00450400 |
Minor Version 3.4 Released
July 10, 2025
| Id | Title | Type | Case | |||
|---|---|---|---|---|---|---|
| 391119 | [Enterprise] The order of the buttons for Entities organization | Bug | ||||
| 392262 | Add new Functional Levels | Bug | ||||
| 393263 | Found legacy risk code. Convert or remove from repo | Bug | ||||
| 391011 | After the new exe file is copied with autoupgrade, the client will receive a non-working product | Bug | ||||
| 391976 | [Enterprise] push from the GlobalRiskScore page to the page with domains filtered by score does not work | Bug | ||||
| 391576 | [Pro/Enterprise] we need to revert or change the HTTPS Redirection change that was implemented with the HSTS changes... | Bug | ||||
| 391004 | [hilbert_map][Enterprise] The legend is not located near the mouse cursor, but somewhere to the side | Bug | ||||
| 359448 | Scanner: SMB detection of 3.1.1 does not work | Bug | ||||
| 391288 | [Enterprise] View details on Agent differents versions card do not redirect anywhere | Bug | ||||
| 391270 | [Pro] The Update page is missing / we should remove this option from configuration | Bug | ||||
| 390789 | [Enterprise] The product version is not added into the MSI | Bug | ||||
| 390673 | Entity "All Data" is missing in "Dashboard => All Domains" | Escalation | 447492 | |||
| 390790 | [Enterprise] the pingcastle exe is not part of the enterprise msi setup anymore | Bug | ||||
| 388602 | Claims Permissions on Entities not showing the Dashboard? | Bug | ||||
| 387290 | False Positives in S-Inactive | Escalation | 445547 | |||
| 389313 | Fix extensions in S-FolderOptions | Bug | Bug | |||
| 387441 | POST /api/AnomalyException Issue | Bug | ||||
| 387281 | Entra Scans: Application Missmatch | Bug | ||||
| 387329 | Configuring 'Number of Days' on Settings causes crash | Bug | ||||
| 386600 | [Enterprise] PingCastleEnterprise.Controllers.AccountController.Login / An exception was thrown while deserializing the token. | Bug | ||||
| 382141 | [Enterprise] When loading a report, n identical warning messages are written to the Application log | Bug | ||||
| 386246 | [OData] Parsing Select and Expand failed: Term '@odata.type' is not valid in a $select or $expand expression. | Bug | ||||
| 385980 | Installer: Destination Email | Bug | ||||
| 378558 | [Object reference not set to an instance of an object.] None of the buttons for generating data for the demo on POK work | Bug | ||||
| 380747 | [AzureAD checks] The amount of properties we request has changed and decreased. | Bug | ||||
| 361560 | [Str] The version of the product that we currently build is lower than the one that has already been released to the public | Bug | ||||
| 376492 | [Enterprise] The AutoUpdater should be hidden from the product | Bug | ||||
| 378389 | [Report Import] Manual report loading is limited to 25 MB / hardcoded value in import.js file | Bug | ||||
| 381819 | [Standard] The risk model section is clickable and allows you to collapse this table / based on the formatting it shouldn't be like this | Bug | ||||
| 384119 | [Enterprise] Email field is not mandatory and is not checked for completeness user creation /edit | Bug | ||||
| 380181 | Error on Duplicate Email | Escalation | 440217 | |||
| 378617 | [Enterprise] Remove "New" tags from non-new functionality. | Bug | ||||
| 381947 | Umlaute are replaced with a "?" | Escalation | 441483 | |||
| 380204 | [Standard] launched from [Enterprise] folder - Could not load assembly when trying to collect AzureAD | Bug | ||||
| 380699 | [Checks] Typo in LDAP query for P-RODCKrbtgtOrphan | Bug | ||||
| 380169 | [Pro] AzureAD Config in installer results in non-working product. | Bug | ||||
| 375107 | [Pro/Enterprise] Enhance installer checks for IIS and ASP.NET | Bug | ||||
| 377326 | Deprecation of ProvisioningAPI | Feature | ||||
| 374720 | Implement filtering of ASR Rule based on presence of Exchange | Escalation | 435268 | |||
| 374636 | PingCastle not collecting Azure data | Escalation | 435212 | |||
| 377741 | Add AdminSDHolder to critical infrastructure list | User Story | ||||
| 364407 | Update the Windows SunBurst OS List | User Story | ||||
| 376493 | The Sunburn OS selector is unfull of version | Bug | ||||
| 376494 | The windows sunburn is incomplete with version | Bug | ||||
| 374321 | Client license is not automatically replaced at start | Escalation | 434838 | |||
| 374942 | [Pro/Enterprise] After installation, the customer will receive a non-working product. | Bug | Feature | |||
| 375105 | [Pro] EF Core Version Mismatch / Leads to a non-working product | Bug | ||||
| 374567 | Issue with LAPS Reporting in Pie Charts and Table | Escalation | 435091 | |||
| 368888 | Permissions on Entities | Escalation | 430048 | |||
| 365582 | PwdLastSet is missing in some of the outputs | Bug | ||||
| 392269 | Fix Typo | Bug | ||||
| 392270 | Fix Typo | Bug |
3.3 Updates
Patch Version 3.3.0.12 Released
May 20, 2025
PingCastle.exe
-
Resolved issue with Operating Systems
-
Feature: 365862
-
Support Case: 00445084
-
Related GitHub Issues:
Fixed detection logic for Windows 10/11 22H2 where versioning caused incorrect reporting.
PingCastle was marking supported Windows versions as obsolete due to outdated end-of-support dates. The lifecycle data has now been corrected.
PingCastle Pro and Enterprise
-
Fixed “Compare” button issue in UI
-
Bug: 385557
-
Support Case: 00444805
Clicking the “Compare” button previously led to a broken report/compare/undefined path due to failed report translation. This issue is now resolved.
Patch Version 3.3.0.11
May 01, 2025
| Description | Item Type (Escalation, Bug or Feature) | Case Number | Item ID |
|---|---|---|---|
| Umlaute are replaced with a "?" | Escalation | 00441483 | 381947 |
| SAML2 users can create a local Password | Escalation | 00440173 | 380100 |
| How do "Claim permissions" work? | Escalation | 00439906 | 379835 |
| Dashboard Viewer Claim: Does not work with claims-based authentication | Bug | N/A | 383400 |
| Deprecation of ProvisioningAPI | Feature | N/A | 377326 |
| PingCastle Error when creating or deleting a rule exception | Escalation | 00436107 | 376052 |
| internal exception occured | Escalation | 00442277 | 383432 |
| [ProvisioningAPI] rootDomain is not defined in the domains section | Bug | N/A | 380725 |
| Error on Duplicate Email | Escalation | 00440217 | 380181 |
| Implement filtering of ASR Rule based on presence of Exchange | Escalation | 00435268 | 374720 |
| PingCastle not collecting Azure data | Escalation | 00435212 | 374636 |
Merged Open Source Contributions
Updated ReportHelper.cs to support Windows Server 2025
Contributed by @FlorianGross
See: Pull Request #269
Bugfix List for PingCastle 3.3
February 27, 2025
No bugs were fixed in this update.
Version 3.3 - Release Notes & Bug Fixes
November 14, 2024
See the PingCastle v3.3 Bug Fix List for a list of bugs fixed in this version.
