Release notes - Cayosoft Guardian v7
What's new in Cayosoft Guardian (versions 6 and below) | Product Lifecycle Matrix | Downloads
NOTE: Some features mentioned below may not be available to all users yet. By default, Cayosoft Guardian utilizes the Mainstream channel to provide updates, which is the recommended option for most production environments. However, if you wish to try out new features before they become generally available, you can select the Early Adopter channel. Note that changing this setting will only impact future updates. Learn more in: Configuration: Automatic product updates in Cayosoft Guardian.
What's new in Cayosoft Guardian 7.3
| ID | Category | Item | Product Area | Applies to* | Version |
|---|---|---|---|---|---|
| 33849 | Enhancements | Cayosoft Guardian now supports recovery of DNS zones whose names are no longer permitted by current Windows DNS service (such as zones containing localhost), which were valid on older operating systems where the forest was originally created. | Forest Recovery | Cayosoft Guardian and Forest Recovery | 7.3.1 |
| 33858 | Fixes | An issue where reading events from the Cayosoft Guardian Change Audit log could fail with the error "The description string for parameter reference (%1) could not be found" (Windows error 15030) when a Change History value contained a %-digit sequence, such as a randomly generated LAPS password. | Change Monitoring | All editions | 7.3.1 |
| 33813 | Fixes | An issue where generating a recovery site virtual machine name could produce an invalid name when truncation of a long name landed on a hyphen, causing recovery site deployment to fail with a resource-name validation error. | Forest Recovery | Cayosoft Guardian and Forest Recovery | 7.3.1 |
| 9842 | New Features |
Cayosoft Guardian now tracks nested, or transitive, group membership changes for Active Directory and Microsoft Entra ID groups. When a member is added to or removed from a group, Cayosoft Guardian generates Change History records for each parent group in the nesting chain. To learn more, see How Cayosoft Guardian collects changes . |
Change Monitoring | All editions | 7.3.0 |
| 33215 | Enhancements |
Cayosoft Guardian now supports deploying a standby forest recovery site into customer-provided Azure networking resources, including a virtual network, subnet, and network security group, instead of provisioning its own resources. This allows organizations with strict network governance, hub-and-spoke topologies, or pre-approved subnet allocations to use Guardian standby forest recovery while meeting internal networking standards. To learn more about the feature, see Manage cloud recovery sites and Forest Recovery: Create a cloud recovery site for Forest Recovery plan. |
Forest Recovery | Cayosoft Guardian and Forest Recovery | 7.3.0 |
| 33359 | Enhancements |
Cayosoft Guardian now supports registering an Azure subscription by using a customer-provided application account identified by Client ID and authenticated with a client secret or certificate. The registration and downstream Forest Recovery, backup, and Cloud Service wizards complete end to end without requiring Global Administrator privileges in the customer's Microsoft Entra tenant. To learn more about the feature, see Cloud Services. |
Forest Recovery | Cayosoft Guardian and Forest Recovery | 7.3.0 |
| 11169 | Enhancements |
Cayosoft Guardian now supports secure LDAP (LDAPS over port 636 and Global Catalog over SSL on port 3269) for Active Directory connections made by both the Cayosoft Guardian Service and the Forest Recovery agent. This allows Cayosoft Guardian to operate in hardened environments that require TLS-encrypted LDAP traffic for security and compliance mandates such as HIPAA, NIST, and PCI-DSS. To learn more about the feature, see Security guide. |
Service | Cayosoft Guardian and Forest Recovery | 7.3.0 |
| 20645 | Enhancements |
The Forest Recovery agent now supports WinRM over HTTPS (port 5986) when connecting to Domain Controllers to collect Active Directory topology metadata during backup, in addition to the existing HTTP transport (port 5985). This enables successful backups in hardened and mixed environments where some or all Domain Controllers allow only WinRM over SSL. To learn about the feature, see Security guide. |
Forest Recovery | Cayosoft Guardian and Forest Recovery | 7.3.0 |
| 33573 | Enhancements |
Cayosoft Guardian now lets administrators restrict public network access to temporary recovery site storage accounts used during Azure standby forest recovery, reducing the attack surface during deployment. New options under Service Settings > Forest Recovery settings allow administrators to scope public access to specific IP addresses or ranges and to allowed Azure virtual network subnets. By default, public access is not restricted to preserve previous behavior. To learn about the feature, see Forest Recovery Settings. |
Forest Recovery | Cayosoft Guardian and Forest Recovery | 7.3.0 |
| 14718 | Enhancements |
Cayosoft Guardian now optimizes DNS processing during Forest Recovery to reduce recovery time in environments with large DNS configurations. New options allow administrators to skip reverse lookup zone cleanup, skip DNS SRV record cleanup, and perform AD-integrated zone and record removal directly through LDAP. To learn more about the feature, see Forest Recovery settings. |
Forest Recovery | Cayosoft Guardian and Forest Recovery | 7.3.0 |
| 31653 | Enhancements |
Cayosoft Guardian now supports inclusion rules for AD Change Collection jobs, in addition to existing exclusion rules, allowing administrators to define a positive scope for monitored objects. Inclusion and exclusion rules can be combined on the same job. The more specific, deeper rule takes precedence, and rules can apply to a single object or to an object and its children. When no inclusion rules are configured, the job continues to monitor the full environment as before. To learn more about the feature, see Define collection scope for an AD Change Collection job. |
Change Monitoring | All editions | 7.3.0 |
| 5121, 29645, 29647, 29751 | Enhancements |
Cayosoft Guardian now restores links to re-created Microsoft Entra users and groups when a hard-deleted object is recovered through Rollback. After recovery, Cayosoft Guardian updates references to the object's new ID in Conditional Access Policies, including Named Locations, App Role Assignments, and PIM role assignments, so restored objects remain correctly linked. To learn more about the feature, see Objects supported by Cayosoft Guardian. |
Change Monitoring | All editions | 7.3.0 |
| 29596 | Enhancements |
Cayosoft Guardian now supports undelete through the Recycle Bin for Microsoft Entra security groups. Deleted security groups appear in the Deleted Objects container and can be undeleted from there or from a Change History deletion record, restoring the group with its original object ID. To learn more about the feature, see Objects supported by Cayosoft Guardian. |
Change Monitoring | All editions | 7.3.0 |
| 30613 | Enhancements |
Cayosoft Guardian now provides a consistent experience between the Add Azure Subscription wizard in Cloud Services and the Add Microsoft 365 Tenant wizard. The update aligns wizard steps, descriptions, sign-in behavior, and the name of the created Entra application. To learn more about the feature, see Cloud Services. |
Service | Cayosoft Guardian and Forest Recovery | 7.3.0 |
| 27003 | Fixes |
An issue where Forest Recovery could not create resources in Azure when a custom Azure Policy that blocks subnets without an assigned network security group was enforced. |
Forest Recovery | Cayosoft Guardian and Forest Recovery | 7.3.0 |
| 33573, 33680 | Fixes |
An issue where job settings for Configure Primary DNS Zones and Configure DNS Records recovery workflow steps displayed DNS optimization checkboxes that did not correctly represent the actual configuration. |
Forest Recovery | Cayosoft Guardian and Forest Recovery | 7.3.0 |
| 32643 | Fixes |
An issue where the connection to the built-in LocalDB history database could time out during service startup without being retried, which could cause Cayosoft Guardian to create a new, empty history database. Connection timeouts to LocalDB are now retried, consistent with external database handling. Related requests: 17338. |
Service | All editions | 7.3.0 |
| 33532 | Fixes |
An issue where SMTP communication channels using the default
Send timeout value of 0 failed immediately
with the following error:
New installations now default to a 15-second send timeout. Existing channels set to 0 are updated to 15 seconds on upgrade, and the value is limited to 1–300 seconds. |
Service | All editions | 7.3.0 |
What's new Cayosoft Guardian version 7.2
| ID | Category | Item | Product Area | Applies To* | Version |
|---|---|---|---|---|---|
| 32693 | Enhancements |
Cayosoft Guardian is now enhanced with stronger in-transit security by ensuring encrypted WinRM transport and by applying LDAP sealing across previously uncovered communication paths between Cayosoft Guardian and domain controllers, eliminating identified cases of unencrypted traffic. |
Service | Cayosoft Guardian and Forest Recovery | 7.2.3 |
| 32761 | Fixes | An issue where SMTP communication channels could not deliver test messages when credentials were not assigned to the channel. | Service | Cayosoft Guardian and Forest Recovery | 7.2.3 |
| 30606 | Fixes | An issue with memory leak in threat detection processing that could cause system instability. | Service | Cayosoft Guardian and Forest Recovery | 7.2.2 |
| 30511 | Enhancements |
Cayosoft Guardian now supports updating existing Azure subscriptions from legacy user account credentials to Entra application account credentials. When an existing subscription is re-added, Cayosoft Guardian updates the subscription to use Entra application account authentication. Related backup locations, including temporary locations in recovery sites, are updated automatically. To learn more about the feature, see How to switch Forest Recovery from a connection account to an Entra application account. |
Forest Recovery | Cayosoft Guardian and Forest Recovery | 7.2.1 |
| 25767 | New Features |
Cayosoft Guardian now supports using an Entra application account in the Add Cloud Service wizard when adding an Azure subscription for Forest Recovery. This allows administrators to create and manage Forest Recovery Azure resources under a dedicated Microsoft Entra application (instead of relying on a user account), with the required subscription permissions applied for resource deployment and ongoing credential management. To learn more about the feature, see Cloud Services |
Forest Recovery | Cayosoft Guardian and Forest Recovery | 7.2.0 |
| 29409 | Enhancements | Cayosoft Guardian now defaults the Remote access to Azure Recovery Site VMs deployment option to Azure Bastion Developer in Forest Recovery plans. This provides a secure, cost-effective remote access method by default and reduces manual configuration when deploying recovery site virtual machines. | Forest Recovery | Cayosoft Guardian and Forest Recovery | 7.2.0 |
| 26692 | Enhancements | Cayosoft Guardian now provides the ability to add comments when performing actions such as Resolve, Dismiss, or Exclude, and view or edit these comments directly from the alert’s Details tab. | Threat Detection | All editions | 7.2.0 |
| 29168 | Enhancements |
Cayosoft Guardian now lets administrators automatically resolve remediated alerts for supported threat signatures from Threat Detection > Threat Alerts. When triggered, auto-resolve evaluates all eligible supported alerts and marks remediated ones as Auto-resolved, reducing manual alert cleanup. For more information about changes, see Auto-resolve support for CTD-000001 and CTD-000033 threat signatures |
Threat Detection | All editions | 7.2.0 |
| 25876 | Enhancements | Threat definitions are now labeled as Threat signatures in the Cayosoft Guardian user interface. | Threat Detection | All editions | 7.2.0 |
| 29452 | Enhancements |
Cayosoft Guardian now supports LocalDB 2025 (SQL Express) for the built-in database option. This increases the default maximum size of the built-in database to 50 GB, reducing database-size limitations for new installations and upgrades that previously used the 10 GB limit. IMPORTANT: When using a local database, Cayosoft Guardian will upgrade the database to SQL Server Express 2025 during installation. Ensure the host runs Windows Server 2019 or later, as required by SQL Server Express 2025. For the full list of system requirements, see Planning and preparation: Cayosoft Guardian system requirements |
Service | All editions | 7.2.0 |
| 29495 | Enhancements |
Cayosoft Guardian now monitors changes to Microsoft Entra Agent Identity entities, including Agent Identity Blueprints, Agent Identities, Agent Identity Blueprint Principals, and Agent Users. This expands Change Monitoring coverage for Microsoft Entra ID objects and helps administrators review Entra agent-related activity directly in Change History. For the full list of objects supported by Cayosoft Guardian, see Objects supported by Cayosoft Guardian. |
Change Monitoring | All editions | 7.2.0 |
| 29548 | Enhancements | Cayosoft Guardian now streamlines the Add tenant wizard by removing legacy Microsoft 365 connection options. Administrators can now add a tenant using Entra application account only, which helps prevent configuring deprecated user-account based connections and aligns tenant onboarding with the recommended authentication model. | Change Monitoring | All editions | 7.2.0 |
| 29941 | Fixes |
An issue where Cayosoft Guardian could generate a false Member Added alert when a time-bound Microsoft Entra PIM activation expired for a role assigned as Eligible via group. Related requests: 17048 |
Change Monitoring | All editions | 7.2.0 |
| 29853 | Fixes | An issue where the AD Change Collection job could fail in environments with very large DirSync cookies (e.g. forests with many invocation IDs). | Change Monitoring | All editions | 7.2.0 |
| 19942 | Fixes |
An issue where Change Alerts could be raised even when the “Who” initiator was not detected while the alerting rule contained only “Who” exclusions (and no “Who” inclusions), resulting in false-positive alerts in Change History once the initiator was later discovered. Related requests: 13590 |
Change Monitoring | All editions | 7.2.0 |
*Learn more: Planning and preparation: Product licensing.
What's new in Cayosoft Guardian 7.1.0
| ID | Category | Item | Product Area | Version |
|---|---|---|---|---|
| 20233 | New Features |
Cayosoft Guardian introduces fine-grained Role-Based Access Control (RBAC) with six predefined roles, enabling administrators to delegate precise permissions aligned with operational responsibilities. A user or group may be assigned one or more of the following roles:
To learn more about the feature, see Role-based access control in Cayosoft Guardian. |
Service | 7.1.0 |
| 2900, 29010 | New Features |
Cayosoft Guardian introduces support for Write-Once-Read-Many (WORM) compliance mode for Azure and AWS S3 storages. Administrators can now enable Immutable and Retention Period options when adding Azure and AWS S3 storages. When configured, Cayosoft Guardian applies Time-Based Retention to the bucket and objects in Compliance mode, ensuring that stored backups cannot be modified or deleted during the retention period. To learn more about the feature, see Forest Recovery: Add backup locations. |
Forest Recovery | 7.1.0 |
| 25401 | New Features |
Cayosoft Guardian has added support for tracking QR code authentication method changes for Microsoft Entra ID users. Cayosoft Guardian now captures add, edit, and remove operations for the QR code (Preview) method, displaying correlated records in Change History and detailed property updates in the Event Log. For the full list of objects supported by Cayosoft Guardian, see Objects supported by Cayosoft Guardian. |
Service | 7.1.0 |
| 18983 | New Features | Cayosoft Guardian now includes archived object data in the dictionary used for filtering and searching in Archive > Change History. This allows administrators to select usernames, groups, or other identity objects directly from the dictionary, even if those objects originate solely from archived data and are not present in the current Active Directory or Microsoft Entra ID environment. | Change Monitoring | 7.1.0 |
| 27559 | New Features |
Cayosoft Guardian introduces a standardized ownership model across configuration and system objects bringing clarity, consistency, and control to how Cayosoft Guardian determines who can manage specific objects across the system. Three new metadata properties are now available for applicable entity types:
|
Service | 7.1.0 |
| 24795 | New Features | Cayosoft Guardian introduces new Data Collection Settings for Change Monitoring under Settings > Service Settings, allowing administrators to manage attributes excluded from Change History. Administrators can also create custom exclusions for frequently changing attributes in AD and Entra objects. | Change Monitoring | 7.1.0 |
| 28741 | Fixes |
An issue where domain trust password reset operations skipped domains whose DNS names contained uppercase characters. Related requests: 16347. |
Forest Recovery | 7.1.0 |
| 29167 | Fixes | An issue where the Health Check job reported successful Entra application certificate rotation, but the certificate was not actually updated in Entra App Registration. As a result, Cayosoft Guardian could lose access to the managed tenant once the certificate expired. | Service | 7.1.0 |
| 29422 | Fixes |
An issue where Microsoft Intune audit events generated by the Device Query Intune add-on failed to be collected. Related requests: 16685 |
Change Monitoring | 7.1.0 |
Comments
0 comments
Please sign in to leave a comment.