PolicyPak Cloud v26.7.4696 — Release Notes

This release adds proactive DLL Hijack protection to PolicyPak Cloud, rolls out a more secure certificate architecture, and gives scheduled scripts more flexible triggers.

Want the full details? Click the link below!

What’s Changed in PolicyPak Cloud 26.7.4696

DLL Hijack Monitor

PolicyPak Cloud adds a new global policy type, DLL Hijack Monitor, that enables DLL Hijack Protection and controls how it behaves. It can run in Audit mode, where all events are logged but nothing is blocked, so admins can assess potential issues; Safe Elevated mode, where risky DLL loading is blocked only for elevated processes; or Anti-Hijack mode, which extends protection to block DLL loading for regular processes running from protected locations such as Program Files. Exclusion policies let administrators define exceptions for specific EXEs or DLLs based on file path, digital signature, or file hash.

Certificate Rotation

PolicyPak Cloud is moving to a more secure certificate architecture. Certificates on endpoints are now rotated at regular intervals, and the certificate-to-customer relationship has changed from one-to-one to one-to-many, so a customer can have multiple active certificates with different expiration dates, statuses, and types at the same time. Installation packages are now either customized (with the customer’s certificate embedded, generated when downloaded from the portal) or non-customized (shared across customers for a given installer version and architecture, used for automatic or manual client updates). The cloud no longer stores certificates with private keys or installation packages that contain them: once a certificate or installation package is generated and downloaded, it isn’t retained in the cloud, and each download generates a new key and a new MSI.

Multiple Triggers for Script and Software Package Manager Policies

Script and Software Package Manager policies can now be configured with multiple triggers at once (for example, user logon and user logoff). Each trigger is evaluated independently, and when an event occurs, the associated script runs and the execution is recorded in the policy log. If a script is already running when a second trigger fires for the same policy, the duplicate execution is suppressed and logged so administrators can diagnose unexpected behavior. Note: Software Package Manager does not support the shutdown trigger.

Bug Fixes and Miscellaneous Updates

New Features

  • Added a “Run as soon as possible after a scheduled start is missed” setting for Script policies with Monthly, Weekly, and One-Time triggers. When enabled, a missed scheduled run executes as soon as the endpoint becomes available; this is unchecked by default and is reflected in the ADM report.
  • Added a “Generate new Event API Access Code” option to the Action menu for more secure Event API access.
  • Added the “Manage customer certificates” option in the Action menu and the installer download experience to support the new certificate architecture.

Bug Fixes

  • Fixed Azure AD sync not displaying some Azure AD groups and/or devices.
  • Fixed Azure AD groups with valid PolicyPak endpoints not syncing to PolicyPak Cloud.
  • Fixed the Security Manager policy editor not properly saving the Max/Min Password Age setting.
  • Fixed being unable to re-login to the PolicyPak Cloud portal after being signed out due to a timeout.
  • Fixed PolicyPak Script in the cloud only allowing files with lowercase extensions to be selected.

Need help with this update?

There are many different ways to get help with our products!

Situation Action
If you feel the product is broken and not working as intended… Contact Support
If you have a question you’d like to ask other experts… Create a discussion in the community: PolicyPak > Discussions & Questions
If you have a feature request… Let our product team know directly: PolicyPak > Ideas
If you have something cool to show… Show everyone what you built: PolicyPak > Show & Tell

What are your thoughts?

We are always happy to hear from our users on what you like, and what you hope to see in the future. Please, share your thoughts below!