Transcript
April release. In this section, we do have the expanded coverage. So as well as talking about the core, so we talk about the platform discovery workspace healing that make up the DEX capabilities as part of the overall autonomous endpoint management. We also more broadly cover the, we're also covering UWM and EPM, which are the on-prem and hybrid components that we have as well. So as we look at the neuron centric capabilities, here's a review of what we're going to be talking about today. So we'll be covering off items across the platform, discovery workspace healing, the app control module, and then we will cover the on-prem components towards the end. So with that said, kicking things off from a platform perspective, we've got a trio of really exciting features together, and I believe Gerald, you're going to kick things off for us there. A couple of things that we've done more recently in the product is some work to our device view, right? There's been a couple of things that we wanted to get into the product for a while now, and we finally got to it. One of them being the ability to export our devices using the secondary columns. So we've had in the product the ability to do primary columns for a while now, but the secondary columns was always a popular enhancement request. And so we got to it, and now you're able to export these, and we'll show you what this looks like in the product in just a second here. I just will go through the features first and then do a little show and tell. So yeah, exporting of the device views. And then the second thing we've done is, you know, when you, you've always been able to modify your column sets, but when you exit out of the console or want to change your column sets and you want to go back and forth between two different views, that was an arduous task that required manually configuring your column sets every time you wanted to flip between different views in the console. So we've now given you the ability to save column sets as a saved view. Again, I'll show you this in the console, but you have the ability here to add a primary and secondary columns and then save those views. You can have those as public or private, and then you can also pin views to a favorites menu, so they'll show up at the top of the list here. And so the idea here is to be able to quickly allow you to navigate between different views without having to do a bunch of configuration going between the different views there. And last but not least, we are launching a new feature called AI Query Builder. So this allows you to build your filter list and filter your devices using natural language. And so this was going into tech preview. So if you're interested in this feature, talk to your customer success managers. They'll get in touch with us on the product side and we'll enable it on your tenant. But it'll go general availability later this year. But what this will do is it'll allow you using natural language to create these queries, and it'll automatically build out your query. And then you can actually either continue to add to it using the natural language, or you can even add to it using the query that's built out there in the console. Then you can also save that as a device group. So a couple new features that allow you to have better interaction with your device. You quickly get access to the information that you need to. Let me show you that now. All right. So the first thing I was mentioning is the exporting of secondary columns. But to do that, I'll also show you at the same time our saved views. And so here's a good example of I have a saved view with secondary columns. I can quickly go in there. Now you can see that it changed my column set, and it also added that secondary column. In here, I have a pinned view. Then I have the rest of my saved views. And then any of the public views that are available here. So any view that you want to save, like I said, you could either do it public, which would show up under the public views. Or if you mark it as private, it shows up under my views. So kind of what that looks like is here. And so you have the is pinned, that's your favorites, is public, and is default. Then that gives you that ability to have that secondary column. Now if you want to export that, we have this new button under export, called export secondary columns. If you do that, you can either do it as select devices or all devices. I'll just select all devices for fun. That does give you a toast message here, indicating that that is running in the background. These do take a few minutes to generate. So that's why we do that. And then once it's complete, it'll show up in your notifications. And then you can download it. It also shows up in your reports. And so behind the scenes, we're actually using our reporting service to generate this report. So it will show up in your report section as well. So if you're looking for the download link, you can either go into your notifications, or you can go directly into your reports. And then just to kind of show you the natural language piece, we have this new button here. It opens up the AI window here. And I kind of have one that's already been there for a while. It's showing me all my Windows 11 devices. And you hit go. And then you'll see here that it builds out this query. And so now we have this kind of new filter here. And you could add to it or modify it either manually by clicking the add buttons, or you can actually continue to just type in here and hit the regenerate button, and it will generate the new filter. And so those are kind of the three new features within Device View. So the first innovation we want to showcase is ability to deep link into a device. So let's say you are looking into our out-of-the-box device dashboard, or it's a device dashboard you made, and you looked at it, huh, surprisingly, I can see some Mac OS, iOS. And maybe you say, oh, why am I having seeing Android? Maybe this is something unexpected to you. So you want to drill down into the Android. So currently, you can do that. You can say, well, I want to drill down to, say, by Android. But what we're adding here is now you can easily access that device. So you say, hmm, Galaxy S23. I'm not familiar with this device. I'm not sure why it's showing up here. Now you can just right-click, open in a new tab, and it will direct you directly to the device detail page of that device. So that would make it so much more easier for you to, say, troubleshoot, looking into anomalies of devices. And not only you can do that while in an already-created chart or when you're doing charts, when you are creating a new chart, this access column, it's available in pretty much all our dataset that has devices information. So that includes device patch deployment, devices, devices deck score, devices patch scan. So across all four datasets, you can see that. Let me demo it with devices. And this is the first column in it. It's very easy. Even if you just want to create a table, for example, you can easily do that. It is the name of the device. So it just makes everything looking into detail about a device so much more easy. So for this quick demo, let's say I just have device type. And once again, this URL works here as well. And even if doing your data exploration, data analysis phase, you can easily access the device detail. So I'm quite excited for this little feature. I think that will help a lot to make our dashboard so much more actionable. So that is the features we are adding on Dashboard Designer. Another feature we are introducing is on the report side. We are introducing two new out-of-the-box reports. We are introducing two new remote control reports. So in remote control, we all know it's a very powerful tool in the IT organization. And so far, currently, you can get the information from audit trail. But with the out-of-the-box report, now we are presenting it in PDF, Excel, CSV. And if you want a beautifully, fully formatted report, schedule, say, every week or every month sent to you or the key stakeholders, now you can easily do it with reports. And we are introducing two out-of-the-box remote control reports. So the first one is remote control by device. So this is more like a timestamp-based, more detailed view of all the remote control section done. And as you can see here, we are also adding something that we haven't seen other reports before. We are adding a KPI session. We all love looking at KPIs, don't we? So in this new report, you're able to see the total number of sessions, devices, operator, and even connection success rate clear and simple in the form of KPI. And we also support devices deep linking as well. Again, making the report actionable, easily drill down. Although the deep linking, it's only supported for devices starting in April 1st. Since this is quite a new feature, the deep linking will only support starting April 1st. And then the other report we introduce out-of-the-box is by operator. Now, this one is a summarized view by operator. And this is particularly useful for IT organization, IT support organization. You want to see if the operators in your team, how many sections are they doing? What is the connection success rate? How many unique devices they have access of remote control? This is going to be a good report to give you that view in a single report. And once again, we're adding key KPIs. So you can see that the key information easily. So let me just demo a little bit to show you how easy to do that. If you're familiar with our reports, it is we're following our standard report process. So the first step after you choose the report template you want, then you can give it a name. Of course, the description is optional if you want. And we support PDF, Excel, and CSV. If you ask me, what's the difference between the CSV and Excel? Excel, we do support the device's deep linking, whereas the CSV is more plain, less formatting, and no deep linking. But in this case, let's demo with a PDF. And of course, we support on-demand and recurring. And if you are familiar with our scheduling report, the ability, the process to scheduling is exactly the same. So it should be very familiar to you who have used it before. Because this is an on-demand report, you can choose the time frame. But once again, since this is a new feature, if you want to, say, do a report that is slightly longer time, then the device group filter is also not going to be able to support until after April 1st. But that brings in another key feature of the Outlook Box remote control report is we do support device groups. And I know a lot of you, device group is a key mechanism for you to organize your device, manage your device. And now you can also do that for your remote control report. So that, I think, is going to be very helpful for a lot of you. Of course, you can also filter by operator. Let's see if Susan is doing anything naughty, or even by device names. And then after you select the filter, you can email it to any members on the platform. So if you just want to send it directly to, say, your manager or for your team every month, you can easily set it up like that. And that's it. Submit report. It's a very simple four-step process. So that's all the update I for me, Robin. So power management, as we look at the settings inside of power management, we're continually trying to enhance them. Windows 11 has added some new items. So we've done some updates to add in processor state, minimum and maximum processor states, and the ability to look in at some of the battery capabilities there. So if you're using power management, jump on in. And update those settings for your Windows 11 boxes. So as we look about discovery, you've heard us talking about building a generic connector. Generic connector is a framework. We're using it internally. We're testing through it. As we continue to test through this, it'll be something that you'll see coming out. We'll be using it for us to accelerate. And as we get it to stable points, we'll be looking at using it in additional formats. Making it so it's more extensible. A couple of interesting things that are new connectors that have come out. One, we have G, I always want to say it wrong, GCCH support. So for those of you that aren't in this space with Office, you can have the secure versions of Office. So there's national, there's secure, and there's Canadian. And we support and give you the ability to go in and connect to the GCCH tenant. So if you're using Microsoft and GCCH, you can connect to that and use that. As we work with the exposure management team, Tenable and Qualys have scoring for the asset criticality. So in Tenable and Qualys, you can go in and set a score that says, this is how important or critical this device is to my environment. So that you know and you can monitor, hey, if I see exposure on the most important devices, that's a lot more important than fixing Rex's machine right up. Let's make sure we fix them in the right order. And as part of our imports to support exposure management, we do now support the, and they refer to it as the ACR, for both Tenable and Qualys. We do not rover right. We have those fields, one for Tenable, one for Qualys, and one that you can set inside of Avanti. So you can use these to help drive and understand what's going on. All right. I think it's back to you, Robin. I think actually, while you've got the ball, if you go to- I can hit the scanner settings. This one. I knew I had to do it, but I thought it was in the other order. So inventory scanner settings. Our inventory scanner is highly configurable. We'll let you take a lot of settings and that on it. We've enhanced and added a few new settings. One is there is a custom attribute. It allows you to put a name value pair. That name value pair is deployed with the agent when the agent's installed. It is assigned into that device and will report with inventory. We find some people who need to do segmentation of devices and they don't have good IP address ranges or domains, they really want to know, hey, this came from this area. So they can put those name value pairs right inside the agent. When the agent installs, it will report those as part of inventory. So that's custom attributes. We did exclude some additional folders. You can see the list there. When they're old, servicing, when access. These are folders that are used in the Windows update process. They have a lot of old things in them. They don't really provide a lot of value. It has sped up the inventory scan time by reducing those out. So very helpful for us to be able to remove those. Marvelous. Thanks, Rex. In fact, if you keep this slide on, we'll be transferring over to Jason in just a moment for OS provisioning. But before we get there, if we just bring up the execution history, I can just briefly cover this one. So one of the requests that we've had, we've continued to enhance. And really, there's a couple of experiences that we have within the platform for tracking the execution of automation. First of all, if you're using bots, it has its own transaction history. Anything that uses automation fabric goes into execution history. And then more recently, we've introduced the audit trail as well. So over time, really, we're paring away the audit capability is no longer the execution history component. It belongs in the audit history component. The execution history still has a role to provide additional context in terms of what ran, how long did it take, and really more of the operational visibility. But with that said, one of the areas that we've been missing, both in execution history and the audit history, we've been able to track a PowerShell script was triggered against this device. What we didn't show was what the payload of that script was. So in this release, we are enhancing. So initially in the execution history, but then that will also be coming into the audit history as well. So that is, in fact, that should be live now. So we have the ability there to be able to show the payload of the script. So we are doing just some additional work with the plumbing, where it comes to the execute script capability within the device view UI to make its way into audit. But this will provide that ability. You can see an example in the screenshot there to see what was actually executed against the device. So that really rounds off what we had to share for workspace. Of course, we've got a lot to talk about when it comes to bots, which really straddles both workspace and healing. We're covering the bots related section in the healing section. So with that said, I believe now we're over to Jason to give the latest from an OS deployment perspective. All right. Thanks, Robin. Yeah, you just want to pop the screen up, Rex. Thanks. For those of you that weren't with us last quarter, we did enter OSD in neurons for VBoot, which means it requires an agent to be on the system. But then we can go ahead and do the traditional OS imaging process that we have on that. That is a tech preview or a beta. We are looking to go GA at some point in H2. We don't have an exact date today that we can give you, but we will be doing it later this year, H2 of 26. And if you haven't already jumped on the beta and you're interested, please send me a message in Teams or an email and we'll get you access to that in your tenants. And we'll be adding on additional capabilities throughout the next 18 months or so. Schedule bot transaction limits. So this is a feature that we've introduced. This is exclusive to the schedule trigger today. And when you schedule a bot to run, you will choose one or more device groups which contain devices that you want that bot to run against. So that's great. The schedule is going to run, the bot's going to run according to the schedule that you define. Now, what happens if you take that device group and you make some adjustments? Maybe you start to add some additional rules. Maybe you start to subtract some additional rules. What that can result in is the bot targeting different devices, which can be entirely intentional, but it could also be unintentional as well. So what we want to do is to have a blast radius control in there. And this helps you accomplish a couple of things. First of all, where you go to run a bot interactively, either from within the bot's experience or when you're configuring the trigger type, what we'll do now is we will provide an approximate value of the number of devices that are contained. So, you know, this can just help delineate, you know, are the four devices, are the 40,000, are the 400,000 devices. Again, if you've got devices that straddle multiple groups, it'll double count them. So it's not an exact science in there. What we didn't want to do is to hold up the UI while we go and count and dedupe and things like that. So we've gone, you know, we've aired on the side of speed just to do the kind of worst case scenario count. And this provides an indicative view of how many devices are contained. So as you go and target the groups, it just gives you that view there to, you know, understand, hey, you know, I didn't want to target 40,000. I only wanted to target four. Let's make sure I've selected the right group. Second, it means you can identify a high watermark for the bot. So you could say, okay, for the use case for this particular bot, I never envisaged a scenario where I want to run it against more than 10 concurrent devices. So this is optional. It's off by default, but if you want to limit the number of devices on that schedule, if you know the approximate number of devices and you want to say, okay, I will take that and add maybe 5% on there. If for some reason that rule changes, the device group changes, you suddenly get more devices than you expected to have. And in the context of the bot you're executing, that is definitely something you wouldn't want to do. Then you can have it automatically fail the bot if that limit is exceeded. So again, most of you won't use that feature, but just to know that it's there. And again, the calculation of the devices in the groups is always there. Okay, next. So, oh, and I do have a slide for this one as well. That's great. So as we talk about, Gerald showed earlier the saved views within there. What's useful with the saved views is that you can potentially create those different views for different use cases. So you might build things out, for example, devices with expired batteries that's still in warranty or dynamic groupings of useful use cases you start to accrue those things. As you start to accrue those saved views, what we want to do is to preempt the question, hey, wouldn't it be great if I could bring these views into automation in an easy way? Of course, you could always go and select the same columns, the same data points. This is really a time saver to let you jump straight from those pinned items into the ability to extract those data sources and populate them into a bot. If you remember the last release, we also had the ability to get to array level items. So those secondary columns within the device inventory query. So originally we had an additional early access stage called device inventory query advanced. As we GA'd that stage, we rolled that capability into the existing stage as an upgrade. So now we just have the device inventory query, the people inventory query, and we have the universal equivalent of those within the universal mode bots as well. They all now support the array level attributes. So additional content. So the team have been really, really busy across the last couple of releases in terms of more and more powerful stages. So we'll talk a little bit about some of those. The first ones are additional AI stages. And if you'll recall, across the last couple of releases, we had introduced AI PowerShell. So that was the ability to type in a use case, for example, return the temperature of a device or use the specified input to search the specified file for a line matching the following string or all of those kinds of use cases. It provides an easy route to be able to type in what you want to be able to do and it'll generate the requisite script. You can then test it on a device and then you've got the ability to go and mark it as active and then use it from that point forward. So what we've done in this release is we've extended that capability both to the bash stages. We now have a bash action AI stages. So that is exclusively for Mac devices and a Windows command action AI as well. So that just, again, is geared towards just making it easy to use, reduce the time to value and just really enhance the capabilities of the product. So again, these are also controlled by the overall toggle. So in the tenant settings, we have a generative AI section within there where you can toggle on and off the various features that we have. And so those are also controlled by that. They're also subject to the artificial intelligence RBAC section that we have within the permissions tree as well. So they need to be turned on in order for these to show up. So we've also taken the opportunity as we've been creating the AI versions of those existing customer stages to backport some of the capabilities to support inputs as well. So with both the bash and the Windows command, they didn't used to be able to support inputs. And so the reason why you want to be able to specify an input is so that you can use context from either preceding stages or a bot level input that is information that's asked for at the time when the bots run to inject that into the script. So what that means is you can have a fairly general purpose script and you can use that preceding context to decide exactly what that script is going to do. So again, a value multiplier to make those much more powerful, much more effective and negate the need to have different versions of the same script with different payloads in it. So what else? So, well, identity stages. So first of all, we've created a new category of stage. So these are within the universal mode of bots. And these are early access at the moment. So this is going to be an incremental journey for us. So we're starting with Active Directory. We will be extending into Entra ID as well. And really this is arming bots with the capability to do much more powerful identity centric capabilities. So for example, Active Directory group manipulation. And so what this means is that it empowers bots the ability to, for example, modify group memberships. And that could be something that is either run interactively with bots. It could be something that's done based on particular logic or it could be triggered externally through the API. So again, this multiplies the capability when we think about decks also being a person centric construct in terms of we want to be able to solve issues that relate to the user, the user's access. And when it comes to onboarding or changes to that user, again, there's a variety of use cases that can be fulfilled by having identity level stages. So we are near the start of the journey with this one. We'd love to get some feedback from this group. But again, if you're interested in test driving these, do get in touch and we can start to make these available. So some additional stages that we've brought in, and these are really quick wins as we've worked with various customers on use cases. You know, one example is, hey, it'd be great if you had the ability to randomize the delay, for example. So as we're rolling things out across devices, we've got the ability to introduce artificial delays of a random interval between different time windows. So rather than just upgrade the stage on its own, what we've done is we've introduced both random number and random text string stages that give the ability to go and generate randomized data points based on specified criteria. So you can see some examples within that you can choose a range. You can input them from tokens. You can again, choose different criteria for the text and string. So with that said, I will just show a quick example of these stages within here. So again, the device inventory query. Again, this is an early access tenant within here, so you won't quite see this yet in your tenant, but that's where you can go and view the pinned, my views, public views, and go and pull in those data points straight away to be able to take that. They are now being retrieved by that device inventory query. I can then start to use the context from that one in downstream stages. For example, I might want a log message. And if I go and do control and space, I have access to those data points. Or if I want to filter downstream of those, again, they are also all available now for my conditions as well. As we look at the new and updated stages, I'm actually just going to go to a different tenant over here, which has the complete list within here. So again, you can see this has got really the stages across the last couple of releases. So a tremendous quantity in there. We have all of the string level stages in there. Again, the PowerShell AI, the updated device inventory query. But as well, we have, again, the new ones for this release are the bash, the command action. So again, in there, you've got the ability to go type to use case. It will go out, files and directory, for example, and it'll go and generate the appropriate script for that one. So that rounds off a summary of what we had to talk about today from bots, and that is going to take us now into app control. So again, a bumper release for app control. So a number of things that we'll talk about here. And the first is system control. So system controls is a feature that we've had in the on-premises application control and hybrid application control. So it's a capability that we've had within the agent. So it's a capability that we've had within the agent for a while. We haven't ported that into app control until now. And it's a really important part of the experience for a number of reasons. One is when we think about privilege management, typically the experience has been mostly additive from the perspective of being able to take a standard user and give them just what they need to be productive without over-provisioning the privilege or granting them from being a full admin. So that's the desired case security modeling in most cases. Now, when you apply the product to an existing organization that maybe you already have administrators, and maybe that is a more difficult challenge to start to revert those users to local admins just culturally and the way that those users work. So one of the capabilities that you can use as a transient step there is to harden the system against reducing the ability of administrators to be able to perform things that you don't want them to be able to do. For example, process termination, stopping services, uninstalling mandatory software and things like that. So of course, if you're an administrator, there's always a way around these things. But what this can do is make it really difficult to do. So you have to go out of your way to try and circumvent. So system controls, it's effectively a hardening technology. It's an aspect of the privilege management function of app control. And it covers on installation service, the ability to clear event logs and stop people from terminating processes. So it also aligns with multiple compliance frameworks as well. So another key use case to have there. The other example is signature items. And so when we talk about identifying a running file that we want to apply privilege management to, so we want to elevate it. For example, we want to be absolutely sure that that process is really the process we're talking about. It's not something pretending to be that process. So there's multiple strategies in terms of how you can identify the process. You start out with a process name, which isn't very secure because you can rename a process to make it look like that same process. So the product supports metadata level where you can start to pull in the vendor name, versions and things like that, other attributes. The most secure way of doing it is to use the actual digital signature of the file. So that means that you're effectively taking the fingerprint of that file, which again is going to uniquely identify as a thing that you want to elevate. So we've brought the capability into both populate the signature items, both from events of things that are there within the events database, but also the ability to manually populate that metadata as well. Trusted ownership checking sits at the heart of the app control experience. And that is really what transforms it from being an allow and block list product into something that's more of a gray list that sits in between to reduce the administrative burden. So this works by looking at the NTFS file owner attributes of files. So it looks at effectively the user account that put those files on the disk. So I could take something that's been put there by the system or trusted installer or administrator. If I right click that, copy it and paste it somewhere else, or if I edit it, I'm going to replace the original file owner. So that becomes then owned by me. So the premise behind the product in its default configuration with trusted ownership checking enabled is it looks for anything that is owned by not one of the trusted owners, i.e the end user, and then that becomes subject to the additional checks. Is there anything configured to be allowed to run for this user? On the basis that most things that are put there by the organization for the user are going to be put there administratively, the user. There'll be a subset of those things. So that's what makes it easy to manage. However, not all organizations are going to use the same trusted owners. Some will extend out to, for example, a specified installer account, for example. So in those scenarios, we've provided the flexibility in the product to be able to add or change the trusted ownership configuration for additional flexibility. Again, not everyone will use that. This is more of a glimpse of what the team are working towards. So you saw Gerald's demo before where we had the generative group creation. Again, we are taking that same paradigm and applying it to other areas in the product with the goal of reducing that time to value as well. So when it comes to creating rules, again, there's different approaches that you can take. So to really help the admin with the boilerplate approach of being able to generate a draft rule for review, AI is a great capability to be able to augment that. Again, you might also have multiple configurations and you want to be able to understand what the net access to a particular location is across those configurations. So a future phase of this experience will be to parse across the configurations and be able to identify where a given rule applies as well. So these are just areas as we continue to work with customers, understand which, with the maintenance of the product, again, the premise behind it that spoke about trusted ownership is to really keep it as simple and low maintenance as possible. This really builds on that to just really accelerate the time to go and create rules or react to changes. If a vendor goes and makes a change to a product and then the organization's impacted, you want to be able to resolve that as quickly as possible. So that's where AI is going to continue to help. So quick time check. So we have about 15 minutes. So I think I've probably got time to just very quickly show within this. If I go to configuration, this is a demo tenant and I'll just show. Let's see. So I've got an example of a configuration within here. I can go and edit. So as I go and edit within here, again, you'll see in there the system controls. You've got a dedicated message that you can configure in there. So if someone tries to clear down an event log, for example, you can define the pop-up message that the user is going to get in response to that. As we go and look at the rules in there, as I go and manage the user privileges, the next dialogue I'm going to get in there is going to show me some of those new controls. So in there, I can look at signature items, for example. So within there, if I had the event files, I could choose from there. Alternatively, I can go and add a hash manually. So that shows where those exist. When it comes to system controls, again, this is going to let me choose particular applications. I don't want the user to be able to uninstall particular services. I want the user to be able to restart, for example. You might have a particular service that the service desk has to get involved every time something happens, where users will be happy, but they don't have the appropriate rights. So if you want to grant them Elevate on a specific service for them to be able to start and stop it at their leisure, that could be a great way of reducing enabling self-service and avoiding service desk load. And again, you can control the event logs in there as well, Elevate or Restrict. And process termination, again, is the other example in there. So you can choose particular paths or explicit files and restrict the ability to be able to terminate those processes. OK, so with that said, the next couple of items here really talking about on-prem. So first of all, we've been on the journey with ARM support across UWM. So we introduced in 2025.3 application control support. We also then enhanced the management service support to be able to install a management agent on ARM devices. The team have also been busy working on environment manager capability. So our April release for on-prem ships at the end of April. And so we will be shipping the environment manager with ARM support. From a Neurons perspective, we are also on the journey with ARM support. So UWM will follow in due course. We are working incrementally on upgrading engines within Neurons for ARM support as we move forwards. As we talk about the whole suite, so between on-prem and hybrid, one of the new capabilities we're bringing into environment manager and app control is MSIX support. So we've had what I'd categorize as rudimentary levels of support. That was primarily script based for MSIX. What we're doing is really doubling down on that capability and providing a new publish MSIX package action in environment manager policy. And we are also enhancing support in app control at the same time for MSIX as well. So via Windows Store app items and as part of that, improving the handling of app alias and symlinks as well. So with that said, Jason, do you want to bring us home on Endpoint Manager? EBM, we've been working on product security for the last couple of quarters. As you guys are probably aware, if you're an EPM customer and the update we'll have for this quarter is a release of EPM 2024 SU6. And that is scheduled for mid Q2. We're looking probably May. It won't be with the April release like the rest of the product lines that we've talked about today. The first one we're working on is we're working a lot within the web console 2.0 you'll see over the next couple of quarters. We're really wanting to round out web console 2.0 so that it is the console that your non-administrative task can be done in. Whether that's remote control, kicking off scans, and various items. We want to do that in the new web console or web console 2.0. We'll eventually give it a better name. But this one is to do multiple devices so you can do scans. Whether it's an inventory or a patch security scan, you will be able to select multiple devices and then tell it to scan just like you can in the .NET console or the Windows console. We're also working on being able to do new queries within the web console. Right now you can view any publicly existing query but you can't do anything to create a new one or you can't edit it. If you want to do something as simple as changing a column set you have to go back to the Windows console. We are working to get those out so that you can do an existing query. Both of these are slated as a stretch. We're hoping to get them done through the finish line. But as we're still in active development, I can't promise they'll make the release. If not, they will follow up closely within the SU7 time frame. We're also continuing to do Windows Checkpoint Updates. Windows released the Checkpoint Update idea about a year ago at this point and they have released a couple of those. We're continuing to improve and enhance the process that we handle within EPM. We initially offered this in SU4. We did some additional work in SU5 and we're continuing to work on it through SU6 and beyond as needed. So it'll work a little better for the automation for the Windows Checkpoint so that you can take advantage of the new Windows 11 Checkpoint. There we go. That rounds us off. One bonus item I didn't have covered on the slide for the on-prem and hybrid UWM console is if there's any French speaking customers out there, we are supporting localization for the French language as well in the April release. Fantastic. Well, thank you, everybody.