PolicyPak v26.7.4689 — Release Notes

This release brings a major new layer of download protection, more flexible script scheduling, and finer control over policy evaluation order, along with a batch of admin quality-of-life improvements across Windows and macOS.

Want the full details? Click the link below!

What’s Changed in PolicyPak 26.7.4689

Secure Download Manager

You can now create a global policy that prevents downloaded files from being executed directly after they’re downloaded from the internet, reducing the risk of malware and unauthorized software running on end-user machines. As with other policies, exclusions can be configured to allow execution for trusted websites or specific file extensions, so you get protection without sacrificing flexibility. Secure Download Manager is supported for Google Chrome, Microsoft Edge, Opera, and Mozilla Firefox.

Multiple Triggers for Script and Software Package Manager Policies

Script and Software Package Manager policies can now be configured with multiple triggers at once (for example, user logon and user logoff). Each trigger is evaluated independently, and when an event occurs, the associated script runs and the execution is recorded in the policy log. If a script is already running when a second trigger fires for the same policy, the duplicate execution is suppressed and logged so administrators can diagnose unexpected behavior. Note: Software Package Manager does not support the shutdown trigger.

Configurable RSOP Scope Evaluation Order for NSM and LPM

A new Group Policy setting, “Set RSOP scope order,” lets administrators configure the order in which Network Security Manager and Least Privilege Manager evaluate policies across the Machine, Switched, and User scopes. Previously this order was hardcoded as Machine, Switched, User. All six permutations are now available and configurable through Group Policy (ADMX) for all managed endpoints.


Bug Fixes and Miscellaneous Updates

New Features

  • Added a new ADMX policy, “DLL Hijack Protection: Enable Blocking of Signed DLLs,” allowing administrators to block digitally signed DLLs loaded from hijackable locations such as user-writable directories. When disabled or not configured, signed DLLs remain exempt and only unsigned DLLs are blocked.
  • Added a new audit event (6211) for Command Prompt inline commands that would have been blocked by SecureRun, logged when auditing is enabled and SecureRun is disabled or using the legacy processing method.
  • Added the ability to set an action for Admin Approval response codes, so an approved response code can be configured to run the process as Administrator instead of a standard Allow.
  • Added a “Run as soon as possible after a scheduled start is missed” setting for Script policies with Monthly, Weekly, and One-Time triggers. When enabled, a missed scheduled run executes as soon as the endpoint becomes available; this is unchecked by default and is reflected in the ADM report.
  • Added PolicyPak log file analysis to the PolicyPakAdmin tool for macOS. Alongside existing .ppcands files, the tool can now parse policypakd.log files (including numbered variants) and generate ready-to-deploy, XML-based policies from detected installer authorization events. When multiple events exist for the same installer, only the latest verdict is used. Note: converting elevate rules that require admin credentials is not yet supported.

Improvements

  • Improved handling of UWP apps that include a manifest attribute forcing Windows to show a UAC prompt even though CSE elevates the process.

Bug Fixes

  • Fixed a GPO foreground/background update issue where a large number of shortcuts could freeze the Taskbar, Start menu, and Explorer.
  • Fixed DLL Hijack event logs not showing the associated policy, collection, and entry names.
  • Fixed audit events being logged for processes that were elevated or already allowed by a parent rule.

Need help with this update?

There are many different ways to get help with our products!

Situation Action
If you feel the product is broken and not working as intended… Contact Support
If you have a question you’d like to ask other experts… Create a discussion in the community: PolicyPak > Discussions & Questions
If you have a feature request… Let our product team know directly: PolicyPak > Ideas
If you have something cool to show… Show everyone what you built: PolicyPak > Show & Tell

What are your thoughts?

We are always happy to hear from our users on what you like, and what you hope to see in the future. Please, share your thoughts below!