Release notes — Cayosoft Administrator v13
NOTE: Some features listed below may not be available to all users yet. By default, Cayosoft Administrator utilizes the Mainstream channel to provide updates, which is the recommended option for most production environments. However, if you wish to try out new features before they become generally available, you can select the Early adopters update channel. Note that changing this setting will only impact future updates.
New features
Retirement of legacy Suspend configuration
As announced back in August 2025, the legacy Cayosoft Suspend™ configuration was retired on June 1, 2026. Legacy Suspend configuration is no longer supported; corresponding rules and web actions will be removed from Cayosoft Administrator in the upcoming release. If you still run legacy Suspend rules, migrate to the modern Suspend configuration now. Refer to the following article for additional information: Migrating to modern Suspend functionality .
Public API documentation
Automation teams no longer start from a blank page. The Cayosoft Administrator Public API is now documented with PowerShell and REST call samples, organized by object type: AD Users, AD Groups, AD Computers, Microsoft 365 Users, and Microsoft 365 Groups. Ready-made samples shorten the path from purchase to a working integration. For access details, contact your sales representative.
Indirect membership and object counts
Access questions rarely stop at direct membership. Web Portal now shows indirect membership in Active Directory and Microsoft 365 web actions, so admins and helpdesk staff see effective membership without tracing nested groups by hand. Tables also show highlighted and total object counts, making the scope of any view or selection visible at once.
Search by additional AD attributes
Active Directory web queries for users, computers, groups, and contacts now support search by a configurable list of custom attributes. Staff can find objects by the attributes your processes actually rely on, not just by name, which shortens lookups and reduces mistargeted changes.
Manager-based Family Groups for Microsoft 365
Family Groups now support manager-based membership rules in Microsoft 365. Select a manager and set the included hierarchy levels to build a Family Group by recursively reviewing the reporting hierarchy. To enable flat distribution list scenarios, use the option to treat the top manager as the direct manager for all nested subordinates. Query and post-query filters let you refine membership further.
Dynamic Group membership by manager hierarchy for Microsoft 365
Dynamic Groups now support hierarchy-based membership rules for cloud distribution and security groups. Set inclusion and exclusion rules to automatically populate a group with users reporting to the specified manager; configure the management hierarchy depth and additional query filters to further customize the group. This brings the Direct reports rule to Microsoft 365, replacing PowerShell workarounds and on-prem group syncing (previously known as the 'Employees under manager' rule).
Account expiration date on new user creation
The new user wizard for AD users now includes an Account Expires field in the Settings step. Set expiration dates for contractor and temporary accounts at provisioning time instead of editing each account after creation. The chosen date is logged in Change History; the field visibility is managed via Attribute Policies.
Kerberos delegation management for computers and users
A new Delegation tab in Properties web actions for AD users and AD computers provides full Kerberos delegation configuration from the web portal. Toggle between no delegation, unconstrained, or constrained delegation (Kerberos-only or protocol transition), and manage allowed SPNs within Web Portal. All changes are logged in Change History; the tab visibility is managed via Attribute Policies and role-based delegation scopes.
Automatic Microsoft 365 license cache updates
Cayosoft Administrator now updates license cache automatically on session start, eliminating manual updates and daily Licensing Change Detected notifications. The legacy Licensing Change Detection rule is deprecated; existing Attribute Policies are preserved through the migration. The manual update button remains available for on-demand updates.
What's new in v13.2.1
NOTE: Cayosoft Administrator v13.2 was not part of the mainstream release cadence.
| ID | Category | Description | Product area | Version |
|---|---|---|---|---|
33933 |
Improvements |
Cayosoft Administrator v13.2.1 features architectural changes and improvements for the replication mode:
|
Product configuration | 13.2.1 |
| 26907 | Improvements |
Cayosoft Administrator Public API is now documented with call samples for PowerShell and REST, organized by object type: AD Users, AD Groups, AD Computers, Microsoft 365 Users, and Microsoft 365 Groups. For additional information, refer to your sales representative. Related requests: 22373, 22375, 22376, 22377, 22379, 22380, 22381, 22382, 22383, 22385, 23135, 26517, 26906, 30113. |
Public API | 13.2.1 |
| 10178 | Improvements |
Cayosoft Administrator introduces service principal authentication replacing the user-based connection account in the Microsoft 365 extension. When you upgrade to v13.2.1, you can transition to the service principal authentication at your own pace. For additional information, refer to the following article: Configure service principal connection account in Microsoft 365 extension. Related requests: 22770, 22771, 22772, 22773, 22774, 22775, 22776, 22777, 22778, 22779, 25202, 26492, 27155, 27219, 30168, 30410, 32781, 32970, 33231. |
Product configuration | 13.2.1 |
| 34210 | Improvements | The Microsoft 365 user suspend configuration now features the Fallback group owner setting to improve group lifecycle and group ownership management in Microsoft 365. For additional information, refer to the following article: Microsoft 365 User Suspend (default configuration). | Cayosoft Suspend™ | 13.2.1 |
| 33857 | Improvements | The Calendar Properties web action now correctly displays names of users. |
Web Portal | 13.2.1 |
| 33814 | Improvements |
The Mailbox web action for Microsoft 365 now features a Read Microsoft 365 sign-ins setting. You can now choose between two options of collecting logon data; for additional information, refer to the following article: Mailbox web action (Microsoft 365). Related requests: 33812. |
Web Portal | 13.2.1 |
| 33522 | Improvements | The Membership web action now supports the Disable Partial Name Search setting in the My AD Groups web queries. |
Web Portal | 13.2.1 |
| 32918 | Improvements | The End User License Agreement (EULA) has been updated to reflect the latest Terms of Service and Subscription Agreement of Cayosoft effective June 2026. | Other | 13.2.1 |
| 30479 | Improvements |
Using the New Computer web action, administrators can now select a principal user or group from a different managed domain, as long as both domains belong to the same Active Directory forest. Related requests: 30448. |
Web Portal | 13.2.1 |
| 30434 | Improvements | Family groups in Cayosoft Administrator now support AD distribution groups and mail-enabled security groups in environments using the Direct Attribute Updates and Exchange Management Tools modes with the Exchange extension disabled. | Family groups | 13.2.1 |
| 30244 | Improvements |
The Self-Service - Update Account Properties web action now features a setting to display an assistant. Related requests: 30224. |
Web Portal | 13.2.1 |
| 29755 | Improvements |
Active Directory extension now features a Use local Active Directory schema metadata cache setting. When set to Enable, Cayosoft Administrator references a local schema instead of accessing domain controllers during every request. This reduces network traffic and improves performance when you use post-query filters and when you filter by virtual attributes. Related requests: 29590, 33439. |
Product configuration | 13.2.1 |
| 29358 | Improvements |
Web Portal now supports display of indirect membership in Active Directory and Microsoft 365 web actions. Additionally, Web Portal now features object counters in tables to make highlighted and total counts of objects in views available at a glance. For additional information, refer to the following article: Web Portal settings. Related requests: 22134, 27092, 27093, 28529, 28528, 29327, 29329, 29399, 29457, 29571. |
Web Portal | 13.2.1 |
| 29121 | Improvements |
Cayosoft Administrator now features a new setting to prohibit users from editing Dynamic Groups manually in Web Portal. The restriction applies to 11 web actions, ensuring group membership remains governed by Dynamic Group rules rather than manual edits. For additional information, refer to the following article: Web Portal settings. Related requests: 26371. |
Web Portal | 13.2.1 |
| 29041 | Improvements |
A new setting Maximum number of users has been added to the AD Users | Update Workday Data and Import Workday Data | Create or Update AD Users rules limiting the number of user records processed per rule execution. Related requests: 29013. |
Rules and runbooks | 13.2.1 |
| 28910 | Improvements |
The Import Workday Data | Create or Update AD Users rule now supports future-dated users and viewing edits as of a future date. This allows administrators to retrieve and act on attribute values that will become effective on a specified future date. For additional information, refer to the following article: Import Workday Data | Create or Update AD Users rule. Related requests: 28913. |
Rules and runbooks | 13.2.1 |
| 15658 | Improvements |
The Import Workday Data | Create or Update AD Users rule now allows skipping additional AD attributes during synchronization. In the Create mode, only CN, SamAccountName, and password are now required. In the Update mode, no attributes are mandatory. Related requests: 29049. |
Rules and runbooks | 13.2.1 |
| 27693 | Improvements |
Cayosoft Administrator now features a new AD Organizational Units web query to create and manage organizational units in Active Directory. You can manage the OU lifecycle with New Organizational Unit, Properties, and Delete web actions. The implementation supports protection from accidental deletion, child delete operations, and Change History logging. Related requests: 27546, 27688, 28698. |
Web Portal | 13.2.1 |
| 24817 | Improvements |
Tables in the AD Groups web query now feature group icons to help visually distinguish group types. For additional information, refer to the following article: Icons for Active Directory groups. Related requests: 24816. |
Web Portal | 13.2.1 |
| 13551 | Improvements |
The New User and Properties web actions for Microsoft 365 users now support Employee hire date, Employee ID, and Employee type attributes. For additional information, refer to the following articles: Properties web action (Microsoft 365 user) and New User web action in Microsoft 365 extension. Related requests: 28889, 31606. |
Web Portal | 13.2.1 |
| 3436 | Improvements |
Active Directory web queries for users, computers, groups, and contacts now support searching by custom attributes. Configure a custom list of attributes and search for specific values in attributes of your AD objects. Related requests: 21738, 21739, 21740, 21741, 21742, 21743, 27548, 30312, 31576. |
Web Portal | 13.2.1 |
| 34276 | Fixes | Performance of the Membership web action has been improved. | Web Portal | 13.2.1 |
| 34098 | Fixes | The subscription limits in Cayosoft Administrator now correctly reflect the amount of hybrid and non-hybrid users. | Product configuration | 13.2.1 |
| 34000 | Fixes | The Group Mail Properties web action has been updated to correctly apply Send as permissions to the Exchange Online delegate for a mail-enabled distribution list in hybrid environments. |
Web Portal | 13.2.1 |
| 33769 | Fixes | The New User web action for Microsoft 365 has been updated to correctly assign a manager after the user is created. | Web Portal | 13.2.1 |
| 33267 | Fixes | The Import Workday Data | Create or Update AD Users rule logic has been updated to correctly perform the uniqueness check in existing users. |
Rules and runbooks | 13.2.1 |
| 33233 | Fixes | The AD Users with Microsoft 365 Licenses rule has been updated to correctly execute within a runbook. | Rules and runbooks | 13.2.1 |
| 33202 | Fixes | The Mailbox web action has been updated to correctly display UPNs in Delivery options. |
Web Portal | 13.2.1 |
| 33196 | Fixes | The Rename User web action logic has been updated to follow attribute policies when copied. |
Web Portal | 13.2.1 |
| 33093 | Fixes | API logic has been updated to correctly manage and search for objects that have a forward slash (/) in their names. |
Public API | 13.2.1 |
| 33089 | Fixes | The My AD Groups web query has been updated to correctly calculate current group SIDs for users with an external forest SID in their |
Web Portal | 13.2.1 |
| 33038 | Fixes | The rule update process has been updated. | Product configuration | 13.2.1 |
| 32851 | Fixes | The Group Mail Properties web action now correctly records all changes in Change History. | Web Portal | 13.2.1 |
| 32760 | Fixes | The Microsoft 365 Users web query now correctly displays synced and unsynced users (including users with the OnPremisesSyncEnabled attribute set to false). |
Web Portal | 13.2.1 |
| 30327 | Fixes | Performance of the AD Groups web query has been improved. | Web Portal | 13.2.1 |
| 29036 | Fixes | The Import Workday Data | Create or Update AD Users rule now correctly creates users with optional XPath properties missing. |
Rules and runbooks | 13.2.1 |
| 28497 | Fixes | The Properties web action for Microsoft 365 groups now correctly updates group descriptions. | Web Portal | 13.2.1 |
What's new in v13.1.1
| ID | Category | Description | Product area | Version |
|---|---|---|---|---|
| 32798 | Improvements | The AD Users Inactive improvements implemented in Cayosoft Administrator v13.1 have been streamlined. |
Rules and runbooks | 13.1.1 |
What's new in v13.1
| ID | Category | Description | Product area | Version |
|---|---|---|---|---|
| 30588 | Improvements |
The following items have been updated to prevent circular nesting in AD groups:
Related requests: 30578. |
Product configuration | 13.1 |
| 29910 | Improvements | Performance of Dynamic Groups rules in Windows Server 2025 deployments has been improved. | Product configuration | 13.1 |
| 29663 | Improvements |
Following rules now feature a Write Change History setting to log changes to objects in Change History:
The global setting is featured in the Change History menu in the Cayosoft Administrator console. In addition, the Custom properties web action now logs Ticket# field changes to Change History. Related requests: 21765, 29469, 29581. |
Product configuration | 13.1 |
| 29603 | Improvements |
The Utils extension for SQL Server now supports the Override connection string setting. Related requests: 29601. |
Product configuration | 13.1 |
| 29491 | Improvements |
The Authentication Methods web action has been updated to align the display of authentication methods in Cayosoft Administrator and the Entra admin center. Related requests: 29490. |
Web Portal | 13.1 |
| 28993 | Improvements |
The Related requests: 28992. |
Product configuration | 13.1 |
| 28774 | Improvements | The AD Users | Set Account Expiration Date rule has been updated; the rule is now supported as a post-action rule. | Rules and runbooks | 13.1 |
| 28756 | Improvements |
The Extend Expiration Date web action now features a Use current date as start checkbox to efficiently manage expired objects. Related requests: 21900, 21904. |
Web Portal | 13.1 |
| 27674 | Improvements | In Cayosoft Administrator 13.1.0, the Public API (CGraph) page now displays a non‑dismissible informational banner when API functionality is enabled. This is a pre‑release licensing notice in preparation for the upcoming API launch planned for early Q2. | Product configuration | 13.1 |
| 27107 | Improvements | The Text File | Create AD Users and Text File | Update AD Users rules now support multi-valued attributes. For additional information, see the rule documentation: Text file | Create AD users rule and Text file | Update AD Users rule. | Rules and runbooks | 13.1 |
| 26487 | Improvements |
The AD Users Inactive rule has been updated:
Related requests: 28495. |
Rules and runbooks | 13.1 |
| 26386 | Improvements |
The Properties web actions for AD users and AD computers now feature a Delegation tab to configure delegation for computer and user objects. Related requests: 25963. |
Web Portal | 13.1 |
| 18134 | Improvements |
A new membership rule Microsoft 365 - Direct reports (FG) has been introduced for Microsoft 365 Family Groups. Manage users filtered by their manager via groups or by the top/root manager of the user group. Related requests: 21283, 29438, 30277. |
Family groups | 13.1 |
| 7970 | Improvements |
Cayosoft Administrator now automatically updates the license cache; the update occurs once every 24 hours. You can force the cache update in the Microsoft 365 extension settings.
The Stop rule if tenant licensing change detected setting has been removed from the following Cayosoft Administrator rules:
Related requests: 22538, 22540, 22541, 22542, 24324, 25339, 22539, 22543, 22544, 22545, 22546, 30095. |
Product configuration | 13.1 |
| 4695 | Improvements |
A new membership rule command Microsoft 365 - Direct reports has been introduced. Manage the Microsoft 365 group membership based on the defined manager. Refer to the following article for additional information: Microsoft 365 - Direct reports membership rule command. Related requests: 21370, 22076, 22077, 22078, 22079, 22080, 29052. |
Dynamic groups | 13.1 |
| 4111 | Improvements |
The New User web action now features a dedicated Account expires field to set the expiration date for a new user. Related requests: 21901, 21902, 21903, 24533, 27417, 27418, 27588. |
Web Portal | 13.1 |
| 4018 | Improvements | Cayosoft Administrator now identifies new license plans added to the tenant. The plans are added and displayed as Report assigned only. | Rules and runbooks | 13.1 |
| 31724 | Fixes | Objects using |
Web Portal | 13.1 |
| 31666 | Fixes | Cayosoft Administrator now correctly adds domains in untrusted AD forests to managed domains. |
Product configuration | 13.1 |
| 31639 | Fixes | The New User web action for Microsoft 365 now correctly assigns a Manager value to new objects. | Web Portal | 13.1 |
| 31560 | Fixes | Performance in the Discover Groups picker has been improved. | Web Portal | 13.1 |
| 30446 | Fixes | The error Unable to find type [short] when running the Mailbox web action has been resolved. | Web Portal | 13.1 |
| 30371 | Fixes | The Active Directory extension has been updated to correctly discover global catalog servers. | Product configuration | 13.1 |
| 30370 | Fixes | Cayosoft Administrator now prompts an error message on attempts to complete the enrollment wizard with insufficient permissions. | Web Portal | 13.1 |
| 30369 | Fixes | Links in certification review emails have been updated to correctly resolve. | Web Portal | 13.1 |
| 30248 | Fixes | The error Resource * does not exist when you create a new Microsoft 365 contact with the Hide from my organization global address list checkbox enabled has been resolved. |
Web Portal | 13.1 |
| 30242 | Fixes | Performance of the New User web action has been improved. | Web Portal | 13.1 |
| 29839 | Fixes | The Archive Change History rule has been updated to correctly archive and clean up database contents. | Product configuration | 13.1 |
| 29834 | Fixes | The Run | Unsupported Script rule has been updated to correctly execute scripts with paths containing whitespace characters. | Rules and runbooks | 13.1 |
| 29785 | Fixes | The upgrade process in Cayosoft Administrator has been updated to prevent rollbacks to the previous version. | Product configuration | 13.1 |
| 29635 | Fixes | The Mailbox web action now correctly unassigns automatic reply messages in AD users with Exchange Online mailboxes. | Web Portal | 13.1 |
| 29632 | Fixes | The Mailbox web action now correctly reports assignment of the automatic reply message to AD users with Exchange Online mailboxes. | Web Portal | 13.1 |
| 29572 | Fixes | The error Could not find a property named 'UMEnabled' on type 'Exchange.Mailbox' when running the Analytics collection | Microsoft Office 365 rule has been resolved. |
Rules and runbooks | 13.1 |
| 29446 | Fixes | The Text File | Create AD Users and AD Users | Send Email Notification rules now support semicolons as separators when listing multiple emails in CC and BCC fields; the change affects other rules with CC and BCC fields as well. | Rules and runbooks | 13.1 |
| 29394 | Fixes | The Microsoft 365 Users | DynamicAttributes Add to Azure Cloud Groups rule now correctly operates as a post-action rule. | Rules and runbooks | 13.1 |
| 29372 | Fixes | The Properties to display picker in the My Request Status web query has been updated. | Web Portal | 13.1 |
| 29317 | Fixes | The Sign out of MS 365 sessions web action correctly displays in Microsoft 365 web queries after disabling the Active Directory extension. | Web Portal | 13.1 |
| 29141 | Fixes | Duplicate requests to join a restricted group no longer generate duplicate notification emails. | Rules and runbooks | 13.1 |
| 29087 | Fixes |
Cayosoft Administrator now correctly enables the IIS-HttpRedirect feature in Windows Server 2025 deployments. |
Web Portal | 13.1 |
| 29073 | Fixes | The Server has returned the following error: invalid enumeration context error in the AD Users with Microsoft 365 Licenses rule has been resolved. |
Rules and runbooks | 13.1 |
| 27295 | Fixes | Virtual Admin Units have been updated to automatically remove references to deleted items in attribute policies and delegation roles. | Product configuration | 13.1 |
| 25899 | Fixes | The Membership web action has been updated to correctly report insufficient permissions of the connection account when a user attempts to modify group membership. | Web Portal | 13.1 |
| 19244 | Fixes | The Add members from file feature now prompts a correct error message when users attempt to modify a Restricted Group. | Web Portal | 13.1 |
Comments
0 comments
Article is closed for comments.