PingCastle Bug Fix List

:pushpin: Looking for a bug fix list for all versions of PingCastle?
All bug fixes will automatically be added here!

3.5 Updates

PingCastle Patch Version 3.5.1.33 Released

June 9, 2026

What’s New — Bug Fixes

Escalation Fix

PingCastle Pro — Unable to Access Website After Upgrade (HTTP 400 Error)
Escalation #439100

PingCastle Pro now applies the same secure cookie authentication configuration as PingCastle Enterprise. Session cookies are marked HttpOnly, use a server-side ticket store, and respect a configurable expiry (defaulting to 2 days) with sliding expiration enabled. This brings authentication session behaviour in Pro into parity with Enterprise and closes a gap in session-security hardening.


GitHub Reported Issues — HotFix Scanner

PingCastle.exe Detected by Windows Defender
GitHub Issue #354

A recent release added a CIM collector option to the HotFix scanners (for MS14-068 and MS17-010) to improve collection speeds. This improvement inadvertently triggered Windows Defender antivirus definitions.

The CIM collection option has been removed. This will be revisited after the 4.0 release to deliver a working CIM collector that does not trigger antivirus definitions.

Original community idea: Optimize WMI Queries to Be Modern and Faster


False Positives for MS17-010
GitHub Issue #333

Certain operating systems were still producing false positives in the HotFix scanner for MS17-010. Two issues have been resolved:

  • The fallback mechanism was not being invoked in certain circumstances.
  • The KB HotFix lists were incomplete for some operating systems.

PingCastle Version 3.5.1.31 Released

May 19, 2026

ID Title Type Escalation # Escalation Summary
360982 Detailed Cartography: Expand after collapse shows error Bug Fixed console error when expanding nodes after collapse in domain cartography view
408398 Wrong links in Documentation part of report Bug 408398 Documentation links corrected to point to valid resources
410767 Documentation of required roles Bug 410767 Documentation has been updated with detailed role requirements
413093 “Wrong License” Text Update Bug Updated error message text for clarity
414399 Entra ID: No MFA Column Bug Added MFA status column to Entra ID reporting
414458 Edit User Role Info Icons different to others Bug Standardized icon styling in user role management UI
414526 Webhooks are unclear Bug Improved webhook configuration documentation and UI labels
414538 Editing an agent resets its last login date Bug Fixed agent editor to preserve last login timestamp
414544 User-Based Licensing Note Bug Clarified user-based licensing messaging
414714 Scheduler: Refresh page doesn’t work in Edge Bug Fixed page refresh functionality in Microsoft Edge browser
414984 Custom Rules: Type Info Icon shows no info Bug Restored tooltip information for custom rules type selector
415122 Password Change not required on email change Security Fix A security gap where users could change email without password reset has been fixed; password reset is now enforced when email address changes
415128 Configuration and Mapping of External Logins is broken Bug Critical functionality for external authentication was non-functional; fixed to restore external login support
415708 Creating external users with password vulnerability Security Fix External user accounts were being created with explicit passwords; system now enforces passwordless authentication for external users
416037 Fixing release 3.5 build pipeline Task Updated build configuration for release process
416104 Low privilege users able to see/create/delete Scheduler Security Fix A privilege escalation vulnerability allowed non-admin users to access scheduler; access controls have been tightened to administrators only
416129 Custom Rules Download still produces XML Bug Custom rules export was generating legacy XML format instead of current format; corrected output format
417468 appsettings.console.json is not generated on update Escalation 417468 Configuration file missing after running updates; deployment process now properly generates required config files
418050 Update Trust Types Bug Refreshed trust relationship type definitions
418327 Configuration Migration doesn’t work Bug Restored configuration migration functionality between instances
418334 Exceptions Bug Fixed exception handling in scanner engine
418509 Honeypot exclusions are not working in 3.5.0.40 Bug 418509 Honeypot exclusion functionality has been restored
418730 GitHub PR - Typo in LDAP Filter (BuiltinDomain) Bug LDAP filter contained typo affecting BuiltinDomain detection; filter syntax corrected
419388 Config missing after running manual scan Escalation 419388 Manual scans were deleting configuration files; scan process now preserves configuration state
419591 All links to “stigviewer” are broken Escalation 419591 Documentation links to external STIG viewer resource were incorrect; links updated to valid URLs
420381 PingCastle Auto-Updater breaks configurations (~80 servers) Escalation 420381 CRITICAL: Auto-updater in versions 3.5.0.37+ was corrupting config files on affected servers; update mechanism rewritten to prevent data loss
420428 DC vulnerability (MS17-010) Escalation 420428 Check for MS17-010 (EternalBlue) vulnerability missing reporting; added detection for unpatched domain controllers
422097 Scan entraID Feature 422097 Entra ID scanning capability has been added
422172 PWDNeverExpires doesn’t account for recent password changes Bug Enhanced check to properly evaluate recently changed passwords
422175 Computer Analysis: Delegation confusion Bug Clarified delegation reporting in computer analysis
422249 Exclusions taking ages to add and delete for AD Risks Bug Bulk exception operations were causing performance degradation; optimized database queries for exception handling
422878 Exception not in use Escalation 422878 Exceptions configured in the system were not being applied to scan results; exception filtering logic fixed
423164 Exception for Windows Server 2012 not working Escalation 423164 Exceptions targeting Windows Server 2012 systems were being ignored; corrected version matching logic
423476 There is no delete API for reports Bug Added report deletion capability to REST API
423757 Slow speed for bulk exceptions on enterprise Bug Optimized bulk exception operations for large environments
423914 Pingcastle exception Bug 423914 Exception handling has been improved
423921 “Number of domains NOT audited” showing wrong information Escalation 423921 Dashboard maturity detail incorrectly filtering domains audited/not audited. Filter links pointed to empty results; corrected to show proper domain audit status.
424072 Remove AI-assisted taglines from public repo Task Cleaned up source code comments in public GitHub repository
425012 Create domain action plan gives blank page Bug Fixed UI blank page error when generating domain action plans
425072 Changes to Multi-Schema UI Bug Multi-domain schema UI was not properly reflecting recent changes; UI state management corrected
425245 KB Scanner Slow in Compute Risks Bug Optimized knowledge base scanning performance
426194 Error opening file “ad_gc_rules_3.5.0.44.xlsx” Escalation 426194 Custom rules file download was corrupted or inaccessible; file generation and delivery pipeline repaired
426386 S-AesNotEnabled - RC4 deprecation score issue Escalation 426386 RC4 deprecation check (S-AesNotEnabled) was returning incorrect scores due to algorithm change; scoring logic updated for RC4 phase-out
426591 Slow Migration for high numbers of domains Bug Improved migration performance for multi-domain environments
426793 Bulk import: Reapply exceptions is dead slow Escalation 426793 CRITICAL: Bulk exception reapplication operations timing out on large datasets; rewrote batch processing to use async operations
431913 SMTP configuration in appsettings.console.json not being read Bug Fixed configuration file parsing for console SMTP settings
432143 appsettings.console.json missing from download links Bug Console configuration file was not included in downloads; added to package manifest
433142 Bulk actions crash Enterprise with large domains Bug Bulk operations crashing when processing very large Active Directory domains; optimized memory handling and added pagination
434171 Schema Change UI: Codeblock display Bug Improved code block display in schema UI tabs with better formatting and copy functionality.
434415 PingCastle Date Format is in US? Bug Standardized date formatting to use local browser formats with 24-hour clock instead of US format.
434419 Standardise PingCastle Date Formats Bug Unified inconsistent date formats across domains view, report view, and compare reports to use consistent 24-hour format stored in UTC.
435001 Auto-Redirect when making exceptions failing Bug Fixed issue where Enterprise failed to redirect page after creating an exception.
435360 Deleting an action plan after you use the dropdown filters the page is returned unfiltered Bug Corrected filter persistence; page now maintains dropdown filters after deleting an action plan.
435500 A-MembershipEveryone: BUILTIN\Users exclusion causes false positive Bug Fixed string mismatch in exclusion logic that prevented BUILTIN\Users from being correctly excluded from A-MembershipEveryone risk assessment.
435829 OIDC logout does not end the provider session Bug Enhanced OIDC logout to properly redirect to provider’s end-session endpoint, terminating IdP session in addition to local cookie clearing.
435867 Remove System.Private.Uri 4.3.0 transitive dependency Task Removed obsolete System.Private.Uri 4.3.0 transitive dependency; .NET 8 runtime implementation takes precedence eliminating CVE-2019-0980, CVE-2019-0981, CVE-2019-0657 risk.
435947 S-AesNotEnabled incorrectly includes disabled accounts in risk score Bug Corrected S-AesNotEnabled rule to exclude disabled accounts from risk count, as disabled accounts cannot be AS-REP Roasted.
436767 Conflicting warnings when setting up login on fresh system Bug Fixed password requirement validation to display only one correct error message instead of conflicting inline and header warnings on initial admin setup.
436841 Entity - missing error handling for missing permissions Bug Improved authorization error handling; users without permission to access an entity now receive clear “Access Denied” message instead of redirect to login.

PingCastle Patch Version 3.5.0.44 Released

March 5, 2026

  • Fixed Authentication issues with PingCastle.exe using the --user and --password options to scan remote domains from both standalone systems and domain joined systems.
  • Fixed Windows Authentication issues where Windows Authentication was creating accounts as internal users, working for the first sign in and then not working for subsequent sign ins.
  • Fixed a SQL Migration issue in PingCastle Pro. This manifested as Report Import issues, emails not being sent and a specific sql error in the windows event log.

Netwrix PingCastle 3.5 Released

February 3, 2026

Description Case # Escalation #
LAPS pie charts display incorrect data 450719 395623
Owner permissions for ‘Rule Exception’ are misconfigured 455140 400752
PingCastle Web UI does not start after EntraID credential update 454716 400184
[SMB2SignatureNotEnabled] Invalid SMB2_NegotiateResponse structure. 395483
[Standard] The --services collection option is not listed in help 394006
[Enterprise] Infrastructure → Domains: Filters behave unexpectedly 393666
[Enterprise] Add new Functional Levels for filtering 392262
[Standard] Exit option incorrectly terminates the program. Expected behavior: go back one level 361697
Running PingCastle from a non-domain-joined machine does not work 391121
[Security] Update vulnerable packages 400967
Report email notification not showing the maturity level 411955 00466815
Microsoft Defender ASR (attack surface reduction) 410439 00463820
“Bulk actions” are never ending - even if “done” 407346 00460760
Page Refresh on “Delete” of Rule Exception removes Filter 407345 00460757
“ActiveComputers” broken after exclusion of Win10 ESU 407258 00460739
For some large HTTP GET requests, PCE web application takes far too long 406078 00459735
Unable to delete Domain and Entity from PingCastle Enterprise. 401714 00456124
False Positive for A-SMB2SignatureNotEnabled on PingCastle 3.4.1.31 395206 00450402
Exception: Some or all identity references could not be translated. 395205 00450400
Change UK spelling of Licence to US License 410486
A-LimitBlankPasswordUse Check looking in wrong GPO list. 410082
Healthcheck crashes Pingcastle when the domain name doesn’t match the domains in the license 409982
PingCastle Interactive asks for server name twice when running scanners 409659
A-AnonymousAuthorizedGPO healtcheck rule broken 407648
DnsZoneUnsecureUpdate1 uses case-sensitive comparisons for zone name 407576
Typo 406128
PingCastleAutoUpdater Multiple Section Error 405649
SMB1 Scanner signing check is invalid 404003
Inconsistent Line Spacing on Domain Page 398865
Change description for --server parameter in Help message 397490
Can’t reproduce HealthCheck Rule P-DelegationDCsourcedeleg 397380
Wrong technical explanation for HealthCheck Rule P-DelegationDCsourcedeleg 397377
HealthCheck Rules StaledMS14_068 Should Validate Actual Patch Status and Configuration 397283
HealthCheck Rule StaledMS17_010 Should Validate Installed Updates and SMBv1 Status 397282
Wrong description to HealthCheck Rule P-PrivilegeEveryone 397272
Can’t reproduce HealthCheck Rule A-DnsZoneAUCreateChild on 2025 domain. 397270
Update outdated docs.microsoft.com links to learn.microsoft.com for long-term reliability 396943
Unclear Mapping Between Filters and Table Columns for domain page 396550
Change Support Page link to Netwrix Support 396310
Remove PingCastleUpdateService from installer folders 396305
Entra: Ensure all authentications use oauth2/v2.0/token 392840
AzureAD Scan - Random Blank Line 390393
LAPS: Change MS LAPS to Windows LAPS. 357401

:pushpin: Looking for a bug fix list for all versions of PingCastle?
All bug fixes will automatically be added here!

3.4 Updates

Patch Version 3.4.2.66 Released

October 02, 2025

Updated ESC2 Check

  • Privileged Mode Added: The ESC2 check now supports Privileged Mode to validate enrollment permissions on the Certification Authority.

  • Clearer Rule Text: Updated messaging makes it obvious when the risk is identified as ESC2.

  • Improved Guidance: Expanded technical explanations and remediation steps for easier issue resolution.

Entra ID Terminology Standardization

  • All terminology has been standardized to align with Entra ID, replacing legacy Azure AD language for consistency and clarity.

Modern Authentication for Email Notifications (Enterprise / Pro)

  • PingCastle now supports Modern Authentication with Office 365.

  • Uses an Entra app registration to send emails directly from the application instead of legacy SMTP basic auth.

  • By default, the app can send on behalf of anyone in the tenant—we strongly recommend restricting this to a dedicated PingCastle mailbox via the setup process.

:light_bulb: This idea was submitted in the community by @RC-1234!

UI Improvement: Remove Domain from the Interface

  • Previously, domains could only be removed through a hidden link (/Database/DeleteDomain/{DomainId}).

  • A Delete Domain button is now available directly on the Domain Report page for a smoother user experience.

Enhanced DNS Zone Update Rules (A-DnsZoneUpdate1 / A-DnsZoneUpdate2)

  • DistinguishedName property added to HealthcheckDnsZones.

  • LDAP collection now captures DNs for (objectClass=dnsZone) objects.

  • Filters out CNF (conflict) and InProgress replication artifacts.

  • AddRawDetail outputs now include both DN and partition context (DomainDnsZones vs DefaultNamingContext) for precise object identification.

Bug Fixes

Description Case # Escalation #
LAPS pie charts display incorrect data 450719 395623
Owner permissions for 'Rule Exception' are misconfigured 455140 400752
PingCastle Web UI does not start after EntraID credential update 454716 400184
[SMB2SignatureNotEnabled] Invalid SMB2_NegotiateResponse structure. 395483
[Standard] The --services collection option is not listed in help 394006
[Enterprise] Infrastructure → Domains: Filters behave unexpectedly 393666
[Enterprise] Add new Functional Levels for filtering 392262
[Standard] Exit option incorrectly terminates the program. Expected behavior: go back one level 361697
Running PingCastle from a non-domain-joined machine does not work 391121
[Security] Update vulnerable packages 400967

Patch Version 3.4.1.38 Released

July 16, 2025

Title DevOps ID Case Number
False Positive for A-SMB2SignatureNotEnabled on PingCastle 3.4.1.31 395206 00450402
Exception: Some or all identity references could not be translated. 395205 00450400

Minor Version 3.4 Released

July 10, 2025

Id Title Type Case
391119 [Enterprise] The order of the buttons for Entities organization Bug
392262 Add new Functional Levels Bug
393263 Found legacy risk code. Convert or remove from repo Bug
391011 After the new exe file is copied with autoupgrade, the client will receive a non-working product Bug
391976 [Enterprise] push from the GlobalRiskScore page to the page with domains filtered by score does not work Bug
391576 [Pro/Enterprise] we need to revert or change the HTTPS Redirection change that was implemented with the HSTS changes... Bug
391004 [hilbert_map][Enterprise] The legend is not located near the mouse cursor, but somewhere to the side Bug
359448 Scanner: SMB detection of 3.1.1 does not work Bug
391288 [Enterprise] View details on Agent differents versions card do not redirect anywhere Bug
391270 [Pro] The Update page is missing / we should remove this option from configuration Bug
390789 [Enterprise] The product version is not added into the MSI Bug
390673 Entity "All Data" is missing in "Dashboard => All Domains" Escalation 447492
390790 [Enterprise] the pingcastle exe is not part of the enterprise msi setup anymore Bug
388602 Claims Permissions on Entities not showing the Dashboard? Bug
387290 False Positives in S-Inactive Escalation 445547
389313 Fix extensions in S-FolderOptions Bug Bug
387441 POST /api/AnomalyException Issue Bug
387281 Entra Scans: Application Missmatch Bug
387329 Configuring 'Number of Days' on Settings causes crash Bug
386600 [Enterprise] PingCastleEnterprise.Controllers.AccountController.Login / An exception was thrown while deserializing the token. Bug
382141 [Enterprise] When loading a report, n identical warning messages are written to the Application log Bug
386246 [OData] Parsing Select and Expand failed: Term '@odata.type' is not valid in a $select or $expand expression. Bug
385980 Installer: Destination Email Bug
378558 [Object reference not set to an instance of an object.] None of the buttons for generating data for the demo on POK work Bug
380747 [AzureAD checks] The amount of properties we request has changed and decreased. Bug
361560 [Str] The version of the product that we currently build is lower than the one that has already been released to the public Bug
376492 [Enterprise] The AutoUpdater should be hidden from the product Bug
378389 [Report Import] Manual report loading is limited to 25 MB / hardcoded value in import.js file Bug
381819 [Standard] The risk model section is clickable and allows you to collapse this table / based on the formatting it shouldn't be like this Bug
384119 [Enterprise] Email field is not mandatory and is not checked for completeness user creation /edit Bug
380181 Error on Duplicate Email Escalation 440217
378617 [Enterprise] Remove "New" tags from non-new functionality. Bug
381947 Umlaute are replaced with a "?" Escalation 441483
380204 [Standard] launched from [Enterprise] folder - Could not load assembly when trying to collect AzureAD Bug
380699 [Checks] Typo in LDAP query for P-RODCKrbtgtOrphan Bug
380169 [Pro] AzureAD Config in installer results in non-working product. Bug
375107 [Pro/Enterprise] Enhance installer checks for IIS and ASP.NET Bug
377326 Deprecation of ProvisioningAPI Feature
374720 Implement filtering of ASR Rule based on presence of Exchange Escalation 435268
374636 PingCastle not collecting Azure data Escalation 435212
377741 Add AdminSDHolder to critical infrastructure list User Story
364407 Update the Windows SunBurst OS List User Story
376493 The Sunburn OS selector is unfull of version Bug
376494 The windows sunburn is incomplete with version Bug
374321 Client license is not automatically replaced at start Escalation 434838
374942 [Pro/Enterprise] After installation, the customer will receive a non-working product. Bug Feature
375105 [Pro] EF Core Version Mismatch / Leads to a non-working product Bug
374567 Issue with LAPS Reporting in Pie Charts and Table Escalation 435091
368888 Permissions on Entities Escalation 430048
365582 PwdLastSet is missing in some of the outputs Bug
392269 Fix Typo Bug
392270 Fix Typo Bug

3.3 Updates

Patch Version 3.3.0.12 Released

May 20, 2025

PingCastle.exe

Fixed detection logic for Windows 10/11 22H2 where versioning caused incorrect reporting.

PingCastle was marking supported Windows versions as obsolete due to outdated end-of-support dates. The lifecycle data has now been corrected.

PingCastle Pro and Enterprise

  • Fixed “Compare” button issue in UI

  • Bug: 385557

  • Support Case: 00444805

Clicking the “Compare” button previously led to a broken report/compare/undefined path due to failed report translation. This issue is now resolved.


Patch Version 3.3.0.11

May 01, 2025

Description Item Type (Escalation, Bug or Feature) Case Number Item ID
Umlaute are replaced with a "?" Escalation 00441483 381947
SAML2 users can create a local Password Escalation 00440173 380100
How do "Claim permissions" work? Escalation 00439906 379835
Dashboard Viewer Claim: Does not work with claims-based authentication Bug N/A 383400
Deprecation of ProvisioningAPI Feature N/A 377326
PingCastle Error when creating or deleting a rule exception Escalation 00436107 376052
internal exception occured Escalation 00442277 383432
[ProvisioningAPI] rootDomain is not defined in the domains section Bug N/A 380725
Error on Duplicate Email Escalation 00440217 380181
Implement filtering of ASR Rule based on presence of Exchange Escalation 00435268 374720
PingCastle not collecting Azure data Escalation 00435212 374636

Merged Open Source Contributions

Updated ReportHelper.cs to support Windows Server 2025

Contributed by @FlorianGross

See: Pull Request #269


Bugfix List for PingCastle 3.3

February 27, 2025

No bugs were fixed in this update.


Version 3.3 - Release Notes & Bug Fixes

November 14, 2024

See the PingCastle v3.3 Bug Fix List for a list of bugs fixed in this version.