Transcript
So just as a reminder, our goals, we are constantly monitoring the ideas portaled in AHA providers and the most upvoted customer ideas. So please keep submitting your idea at the AHA portal. So we are looking forward to the journey to cloud. We are constantly keeping in touch with our customers on what they need to move to cloud. For more updates, look forward for murals for patch management from Steve. So this is one of the big things that's coming up for our current release. So support for Windows Checkpoint updates. So with Windows 11, 24H2 and Windows Server 2025, Microsoft introduced a checkpoint-based cumulative update model to improve serving efficiency. Instead of continuously expanding cumulative packages, the company now creates periodic checkpoints, new baselines for future updates, include only changes made after the latest checkpoint. So this reduces the package size and download overhead. However, because these updates build incrementally on each checkpoint, applying multiple updates may require separate installation phases, potentially leading to multiple reboots. So as a part of phase one, we have made some UI UX enhancements for this. So in the phase one, also we have worked on the change in EPM score behavior. So if currently there is a requirement of checkpoint patch missing, EPM will download both patches before they repair. So which helps to ensure that the admins always include prerequisite checkpoint patches before performing the repair. And for the agent side, there's a slight change in behavior. So during the scan or repair, if the checkpoint prerequisite is missing, WorldScan shows the missing prerequisite patch detected. So it will thus prevent failed or incomplete patch installations on the endpoint. So we are looking to completely support this end-to-end with some minor changes in the backend for phase two, and end users would now see less amount of reboots with the smaller and faster updates. So moving to the next one. So for, yeah, you want the device and application control on the next slide. So for IDAC, our main aim is to maintain the current capabilities, resolve the security fixes, fix customer defects, and zero-day support for the latest OSs, and prioritize minor enhancement based on customer request. So for 2026.2 this quarter, we're coming up with enhancement of temporary notifications. So currently the end users miss the temporary permission expiry alerts because notifications are sent out only minutes before expirations, and administrators cannot configure reminder timing or messaging, limiting the ability to tailor reminders to organizational needs. So this will now ensure users receive proactive configurable reminders to renew temporary permissions, reducing disruption and strengthening the compliance. So enhanced performance in Log Explorer by using IDAC's SMCx64 version. So currently we use 32-bit SMC, thus it limits the memory usage and in turn slows down performance, which is a big pinpoint from a lot of our customers who are currently using this application regularly. So with this upgrade, customers will have seamless experience with faster log loading, improved stability, and better performance. Thus this is going to give a better overall end user experience. With this, I'll hand this over to Parijat for security controls. Thank you, Subhajit. Hi, everyone. We have short and crisp updates for security controls this time. We are adding support for Ubuntu, specifically for version 22.4, 24.4. We have tested successfully that admins would be able to scan, deploy, and fetch reports for updates deployed on Ubuntu endpoints. There is a demo in the next slide that we have that we're going to play, but before we play it, just wanted to tell that, so Ubuntu is a Debian-based Linux operating system, so these are package-centric. Hence, we won't be able to see some of the details that we see for RPM Linux-based systems, which are Red Hat Package Manager Linux systems. So there would be some columns, as you see in the slide here, that would be empty like CVSS, which is normal for Debian-based systems. More details we can see in this demo. Console up and running with a scanning of all those four VMs which we have added. Now you can see we are able to scan all the four VMs. There are no issues as such, and we are able to deploy also. If we go to the deployment history, we are able to see the exact status, like the success or something. The only difference what we have with respect to other Linux flavors and Ubuntu is if we see the, suppose, the Red Hat, so we have the title, CV, everything populated for any of the advisories, but whereas in Ubuntu, it's all the packages, so we will not have any of those details. We will have only the name and the repository and the status, like it's missing or installed. This is the main difference between the Debian and the RPM what we have. And coming on to the report part, so for the Linux, we have basically three reports, deployment status by machine, executive, and the machine path state summary. All this should work for Ubuntu, so here we are able to get the Ubuntu, so we can generate the deployment status by machine for specifically to Ubuntu. That's also working fine. And the executive summary is, it gives a summary of all the VMs we have and all the machines, whatever we have in the console. And the machine path state summary, again, we have here the Ubuntu. Excellent, thank you very much. And so let's start with the new Linux support that we'll be introducing for Ivanti Neurons for Patch Management, starting with, obviously, you see here is Ubuntu, and we are doing this platform-wide. You'll see a theme going on, I think, across all of the Ivanti patching products. Well, Ubuntu is something that we introduced in the January release, in the first quarter release, as a beta, and we got a lot of great feedback on that, and we're ready to deploy this as a GA solution with the April release. So look forward to that. It is contentless, just like all other Linux deployments in Neurons. And if you go to the next slide, we also are introducing Red Hat Enterprise Linux 10 support as well with this release. Moving on, and continuing our theme of across consistent support, we are also doing checkpoint cumulative update support with this release for Neurons Patch. And as Sapojit and Parijat noted earlier for EPM and security controls, for Neurons for Patch, we are also providing the same kind of reconciliation around the checkpoint chain. Just to reiterate, with the release that Microsoft introduced last summer, they are doing this checkpointing process where an initial deployment is released. You see in the graphic at the top here. And then any updates to that patch, they release a checkpoint that includes only the bits that have changed since the previous version. So you can see there is a chain of checkpoints. Well, what can happen is you could potentially deploy multiple checkpoints in a day, and that could cause multiple reboots on the endpoint. We don't like that experience. We wanna create a single reboot, great experience for the customer. So what we're doing is reconciling all that. And so it is all deployed as a single deployment on the endpoint, and then a single reboot to resolve that. Now, most of this is actually gonna happen behind the scenes. Customers probably don't even need to know this is happening. This is all invisible to them. But there are certainly circumstances you could get in where you need to diagnose an issue. For example, if one piece of the chain, one checkpoint in the chain fails to download, but all the other pieces download, well, then you're going to want to know where the challenge is, what's the cause of that problem. To provide an indicator for this in Neurons for Patch, we've introduced this little, you see in the graphic at the bottom, a little flag icon that we are now putting next to the patch name. That flag icon will, if you put your cursor over it, will pull up a little dialog box there that will note that this is part of a Microsoft checkpoint chain. That is really just to provide guidance in case you need to diagnose, that you understand that this particular patch deployment, if it did not successfully deploy, it might have something to do with the chain of checkpoints that are being distributed. Go on to the next slide. We also are introducing, finally, enhanced search. So for those of you who've been using the platform for a while, it can be a little bit frustrating because if you wanted to do a search, if you wanted to do a search for a particular string, let's say Windows, you'd have to type the entire word W-I-N-D-O-W-S. You can't just type W-I-N-D and then find all the Windows patches. Well, we are now, in order to fix that problem, we had to replace the entire search engine, right? So that took us a while to do. We've actually been working on this for several quarters. And onto the next slide. We are also enabling support for sideloading patches greater than 650. So just a reminder, sideloading is a process for introducing patches that are hosted behind a firewall or a paywall, right? Obviously, we can't just bring in patches that are sitting behind some kind of a wall. The customers need to download those patches themselves, and then they can use this process of sideloading in order to bring them into the Neuron's patch platform. But currently, we have a limit of 650 megabytes for importing that patch. Well, we are removing that restriction as we are noting that a number of products are exceeding that 650 limit, and in particular, we've found a lot of feedback from customers using Tableau and Citrix that patches in both those cases have exceeded that 650 megabyte limit. So we are eliminating that. We've made changes to the platform. So now you should be able to sideload patches of any size. And onto the next one, we get to my favorite topic, something I've been talking about for quite a while, very excited about this one, continuous compliance. And this is phase two for this project. Now, just to reiterate for those of you who are unfamiliar with this new feature, most organizations have a requirement to achieve a certain level of compliance within their organization for patching. For example, they may have all devices or 95% of devices in their organization need to be fully patched within seven days of Patch Tuesday. That might be a requirement in an organization. But what we're finding from feedback from customers is they're coming close, but not quite reaching their compliance goals. And to be clear, the problem has nothing to do with the patch platform. The problem has to do with the endpoints. Something happened on that endpoint. It's off the network. It crashed. It had a conflict in the system. Something happened to prevent that patch from being deployed on that endpoint. And then by the time that issue is resolved, it is now outside of the deployment window or the scheduled deployment time. So now you have to wait for the next scheduled deployment, which may be outside of that, for example, one week compliance window. And then it's too late to get it remediated. What we're finding customers are doing in those cases is they're doing ad hoc deployments of the patches to catch them up within that compliance window. We don't like customers having to do that. There shouldn't be all this manual effort to bring the endpoint devices back into compliance. So we've introduced this concept of continuous compliance, and we introduced it in two phases. Now, phase one, which we delivered in January, automatically curates a special patch group. And that patch group is created for every single patch policy that you create in your environment. You will now see there will be a gear icon in your patch group list, identifying a compliance baseline patch group for that policy. And inside that, we are automatically creating a list of patches that are being deployed to that policy, to the devices that have that policy installed. So as long as a patch gets deployed to any device on those endpoints, it automatically adds that to the compliance baseline patch group. Now, what that means is that we now have a list of all the patches that were expected to be deployed in your environment. And that leads us up to what we're delivering in phase two, a deployment process, a new schedule that you can set up in your environment to automatically deploy those missing patches. You'll see here on the deployment behavior screen, just below our routine maintenance, priority updates and zero day response deployment options, you have a new option called continuous compliance. Now, to be clear, if you don't want to use continuous compliance, it's off by default, you don't have to do anything. Just don't turn it on if you don't want to use it. However, if you do want to turn it on, you will have the option to schedule a out of bands patch deployment. You see here that in the example in the graphic here, that it is set for daily, a daily deployment. So what that means is that once a day, neurons will check each one of the endpoints using this policy to see if all the patches that are in the compliance baseline patch group have been deployed on each one of those endpoints. And if not, if they have not deployed those patches, it will automatically deploy those patches for you to bring them back into compliance. Now, if you go to the next slide, you can see the scheduling options for this. The schedule on the bottom half, you'll see there is a schedule here that showcases the same kind of scheduling options that you would see in a normal schedule. You can deploy daily or weekly at a fixed time, and then you can set your pre-deployment options and your reboot options. I wanna draw your attention to the top portion of this, the portion that says, delay adding to compliance baseline patch groups. Now, the reason we put this option in there is because we recognize that you may not want to have a device recognized as being out of compliance immediately after patches are deployed to their peer devices. You may want to have a day or two to wait until administrators resolve the issue on that device before calling it out of compliance. So with the phase one release, which was released in January, as I mentioned, as soon as a patch is deployed to any one device using that policy, it is added to the compliance baseline patch group. Well, if you set this delay time, it will then delay adding that to the patch group until one, two, three, four days, whatever you set it to after the initial deployment actually occurred. So another added configuration option for you with this. Moving on real quick onto the patch content catalog, this particular update, for instance, the last Innovator Preview, I grabbed as many as I could here. You can see we have a nice mix of Windows and Mac updates as well. We added the .MSI installer for Notepad++. We had been supporting the .exe for a long time and had some requests for the new MSI that came out recently. You can look through the list. You can see that we've added a lot of applications that are pretty common. Smartsheet was a good one to add. We had a lot of people use that particular app. IntelliJ IDEA, we added the ARM64 version. We're continuing to expand out our ARM support. We only have a handful of products left that have added ARM64 support, but we are pulling those into the Windows platform. So continue to expand our catalog. We're very excited to keep that moving. In addition to new products, of course new major versions of supported products continue to be released. Seems like in the last month, there were a lot of Windows apps that got updates and we've added those in. You can see from user apps like Camtasia to developer apps like the latest versions of Visual Studio. So continuing to pull those in and expand our catalog with new versions of supported products as well. The latest of course being Firefox and Thunderbird 149 coming out for both the Mac and Windows platforms here just recently, the end of March. So we added those as well. So again, continuing to expand our catalog of patch products. And again, please, if you do have requests, include them in our ideas portal. We will prioritize them and pull them in depending upon the number of votes that we get. With that, I'm going to turn it back over to Subhojit or is Vijay going to pick it up on RVVM and ASP? Hey Todd, thanks. Thank you. I'll talk about the RVVM slide. Let's move on from here. Yep. So in this release, we have focused on improving visibility automation and risk prioritization across platform. So this update for 2026.2 introduces the new policy compliance widget. We are a trend. We are a timeline trend. Playbook enhancements includes and actions of delete post post findings from playbook rules. Set custom attributes value with a playbook. Inclusion of EPS score in custom severity. Patch to the system views, update automation. And on the integration side, we are having flawless integration with IPV6 support. CrowdStrike Falcon Spotlight rating inclusion and inclusion of generate upload of errors. So for the platform enhancements, we have additional actions for playbook. So improve management options for administration for administrators by inclusion of delete set custom attribute actions in playbook. So this will help in reduction of manual work. This will help administrator gain greater control and flexibility through enhanced playbook actions, reducing manual efforts and repetitive tasks. This leads to faster remediation, improve operational efficiency, and more consistent policy enforcement across environments. The next one is VR timeline. So the VR timeline provides the historical visibility into how risk levels evolve over time, not just the static snapshots. So this will help specifically the security team, that means to identify which vulnerabilities are trending upwards in the risk and require immediate attention versus those that are stable or are decreasing. So improve remediation planning and more strategic evidence-based security governance. The final one for the platform enhancements, we have EPS's custom severity. So we integrate the EPS's alongside the CVSS, VR, and normalized scanner severity. So this helps in strengthening the risk-based vulnerability management by adding likelihood of exploitation into severity calculations. So this will help in better risk prioritization, move beyond theoretical severity CVSS scope to focus on vulnerabilities most likely to be exploited in the wild, and which will help in, you know, making more precise threat informed prioritization that improves the remediation efficiency. Moving to the next one. For the integrations and enhancements, we have the Qoalys enhancements for IPv6. So Qoalys integration would now support IPv6, adding IPv6 support ensures that vulnerability on IPv6 enabled assets are discovered, assessed, and managed, just like IPv4 system. This was one of the major customer ask. We have received a lot of vote around this one. So the value that we see is no assets are now left unmonitored, reducing the blind spots in the environment. So Qoalys patch publication date, the next one. So Qoalys patch publication date is a combination which has patch filter to provide enhanced filtering for remediation efforts. So we are seeing some potential delay, but that's in pipeline for the upcoming quarter. So we are not doing it based on scan of specific fields. We are making database level changes so that we can retrieve data from vulnerability intelligence feeds from external things. So there is going to be some architectural changes in the backend. If the connector doesn't run for some time, still this data will get pulled from vulnerability intelligence feeds and not dependent only from scanner. So moving to the next one, the Qoal export AI rating. So this will help customers to prioritize vulnerabilities effectively in combination with the existing PRR rating. And the final one, the generate upload of errors. We have included specific fields for the generate upload error based on customer request. This is from one of the key customers in Latin America. This will help admins quickly spot and resolve issues boosting the troubleshooting efficiency. So this is our new widget that we have delivered under the SLA overview based on feedback from customers. So this is the policy compliance overview widget. So this widget is going to show how many assets you have across your groups, right? So this will show how many are compliant, how many are non-compliant, and this will give you an eye level overview of assets that are compliance across each groups. Now we have created this capability not only for Qoalys, but for various other scanners, like you can call it Tenable, Nessus, Veracore, whichever supports this, right? And currently with this, we have an ability to select nine groups by default. And based on that, you can see what is your current compliance state. So, yep, moving to the next one, the VRR trend. So earlier we were just showing the VRR score, but now we've introduced this VRR trend. This spans over the six months timeline. So with this, this will give the historical visibility into how the risk level has evolved over time, right? So this will help the security admins identify which vulnerabilities are important based on their score changes or which needs to be prioritized. So this is the latest addition with our current release. So the IPv6, so today we now support the IPv6 for Qoalys. So as you can see here for this one, I've selected Qoalys, it has 32 assets, right? 32 findings, sorry. So as I click on this, I should be able to see, it's taking some time to load. So we should be able to see the IPv6 address for all the findings for Qoalys. So now you'll be able to actively support the IPv6 as same as we would have done for IPv4 in the past. So with the playbook addition, so this is the latest change that we have made for the playbook custom attributes. So this will help in automation and better management of the admins capabilities, right? So for example, I'm putting a rule here, let's say test. Selecting the custom attributes from here, I'm setting the set custom attribute and moving to let's say host findings or host, yeah. So these are the filters that I have created in the past and based on my requirement, I'm gonna use the Boolean value true or false and let's say test. So these filters were already created by me in the past so that I can easily make a selection of this or when I add new hosts here, this gets already added into the filter. So with this custom attributes, this will help the admins reduce their effort and manage time efficiently with this automation that we're bringing with this playbook. And the final one that we have is the EPSS custom severity. So earlier in the severity configurations, we had just VRR, CVSS scores or the scanner severity. Now we are adding the EPSS score also to be considered. So integrating this alongside CVSS and VRR and the normal scanner severity strengthens the RVVM likelihood of exploitation into the severity calculation. So this is going to provide more precise threat information prioritization that improves remediation efficiency.