Highlights
- Network scan (Beta) — Discover devices on the network automatically and take them straight under monitoring.
- QuickSupport (Beta) — Support customers through a download link – no agent installation, and only after their consent.
- AI assistants over MCP — Operate a remote desktop with your consent, edit devices and customers and create custom SNMP checks – within your permissions.
- Acknowledgeable checks — Temporarily silence known warnings and critical states with a reason while monitoring keeps running.
- Enforce SSO & two-factor authentication — Require SSO sign-in or an authenticator for every user, plus Italian and Spanish for the web interface, agent and e-mails.
- Better reports & testable automations — New patch status and software change reports, flexible recipients, and automations you duplicate and test step by step.
New
Settings & access
- Central settings — Administration → Settings now also holds custom domain, email sender, agent enrollment and branding next to authentication, beta features, MCP clients and repositories – one searchable area.

- SSO & two-factor authentication — SSO sign-in or setting up an authenticator can be required for every user – SSO users included.

- Support platform access — The Support platform switch is also offered in the invite dialog and is enforced server-side.
- Italian & Spanish — New languages for the web interface, agent window and e-mails. A language chosen through Ctrl+K is saved to your profile.
AI assistants
- Remote desktop over MCP — Assistants can operate screen, mouse and keyboard – after your Control remote computers consent and within your remote desktop permissions.
- Configuration & checks — Assistants can edit devices, aliases, customers and custom fields, and create SNMP checks with a live test. Permissions and auditing match the web interface.
Monitoring & rules
- Acknowledge checks — Warnings and critical states can be acknowledged via Acknowledge on the device's Checks tab, with a reason, until the next success or for a chosen period. The check keeps running; alerts, cases and dashboard counts are suppressed.

- Dashboard check filter — The dashboard can be filtered by Check names.
- More rule conditions — One condition holds several values with Add value, and rules can target Server role or feature from your inventory.
- Custom fields — Multi-select is its own field type, and custom-field tokens in check inputs appear as linked fields with label and source.
Automation & remote support
- Involve the user — The Send notification dialog on a device can request a Yes/No/Cancel answer or a written reply and shows what the user picked; later automation steps branch on that answer.
- Easier to build & test — Automations can be duplicated and individual steps tested on a device. New conditions check device tags and chassis type.

- Terminal as a user — The Toolbox terminal picker lists Logged-in users next to SYSTEM / root; the shell runs in that user's profile on Windows and macOS.
- Remote desktop — Ctrl+Shift+X types the clipboard (also on login and UAC screens), Ctrl+Shift+M switches display, Ctrl+Alt+End sends Ctrl+Alt+Del. Windows supports the native H.264 codec WmfH264 for lower latency.
Beta features
- QuickSupport — Customers → Quick Support creates a download link for remote support without installing the agent. After the customer's consent, remote desktop, terminal, registry and event log are available until they close the window.

- Network scan — Scanner devices you designate per site discover devices on the customer network; the Network tab on the customer page lists the findings, which you take over in bulk, dismiss or let Auto-add monitor. You switch network discovery on under Settings → Beta features.

- Also in beta — Proxmox VE host management and the UniFi Site Manager integration have been available since the previous release; switch them on under Settings → Beta features.
Patches, software & reports
- Patch reports — Current Patch and Action Status separates approval from installation; the former detailed report is now Patch Performance Evidence, and definition updates can be condensed or hidden.
- Software Change Report — A new built-in report lists software installed, updated or uninstalled in the selected period.
- Flexible report recipients — One combined PDF for all customers or separate PDFs for several selected sites.
Integrations & device information
- TANSS — Network devices are synced as peripheries with type and firmware instead of as PCs; UniFi identifiers and Securepoint serial numbers are carried over.
- c-entron Service-Board — Configurable ticket language, ticket texts without octoja branding and ticket numbers in the delivery log.
- macOS Server — New device type for tables, filters, TV View and the macOS templates; Change Device Type now works for Macs, too.
- Hardware details — The device page shows battery, power profile and enrollment date.
Improved
Settings & branding
- Dedicated settings pages — Custom domain, email sender and the enrollment policy with Allow open deployment each have their own page.
- Branding — E-mails use the window title as fallback sender name. Mobile home-screen shortcuts take your icon and title; the octoja copyright line on the login page is gone.
Remote support
- Remote desktop & Toolbox — The remote cursor shape is shown, on Windows hosts without a monitor too. Toolbox windows remember their size and position, and the Services view shows the account each Windows service runs under.
- File explorer — Archive actions read Compress to ZIP file and Extract all, and long paths stay on one line.
Automation & software
- Automation assignments — The device's Automations tab shows each assignment's trigger and hides manual automations.
- Software automation — The step is now called Install or update software and restores saved selections when editing; outputs keep up to 64 KB.
- Update exclusions on Linux — Never update these packages also applies to APT.
- Custom packages — The package wizard shows the maximum upload size up front and rejects oversized installers and companion files before analysis.
Patches & agent updates
- Patch execution — Alerts are suppressed while a device runs a patch cycle. Disabling the Windows Update interface now hides all of its notifications, too.
- Device log — Completed update-all runs are recorded in the device log.
- Agent updates — Smaller downloads through binary deltas. The Windows quick installer points out an installed Visual C++ runtime; the deployment page explains the settings file more clearly.
- Maintenance mode — The maintenance banner on the device page lists the reasons for active windows. Patch cycles set maintenance under the patch policy's name and only for the actual window.
Monitoring & reports
- Network checks — Agentless devices automatically use their stored address and SNMP or TR-064 connection; separate credentials in the check are gone.
- Check configuration — Size thresholds offer a unit selector (KB to TB); custom SNMP probes collect values without thresholds, too; the monitoring device picker suggests the matching customer.
- Reports — Check widgets can be filtered by monitoring checks, antivirus coverage by device types. Check details show last user and last seen.
- Mappings & Securepoint — Auto-match is available in every site and host mapping dialog. The Securepoint setup hint names portal.securepoint.cloud as the place to create the API key.
- MCP tools — Clearer input descriptions and explicit error messages. Tools for custom checks support result text templates.
Usability
- Search & pickers — The global search finds devices and customers by custom field values. Enter picks the first filtered result in pickers.
- NFR customer — The customer list marks the NFR customer with a badge, and it cannot be deleted.
Fixed
Remote access & agents
- Remote desktop — After a logoff on the remote device you land on the session chooser, and the console reopens at the login screen. Italian keyboards type the period correctly, NumLock is restored and numpad keys type the right characters.
- Web Console & file explorer — Heavy device pages load completely and sessions work in Safari. Downloads of growing files complete; dropping folders shows a notice instead of creating empty files.
- Linux agent — Agents stay online after long uptime, too.
- Windows agent — Failed installations are cleaned up properly, and launcher and agent no longer stop each other during recovery. Duplicate tray icons are gone.
- AI screen capture — Screenshots for assistants over MCP keep working across Windows sign-in, lock and UAC transitions.
- Hardware inventory — RAM slot counts include every memory array, so multi-array systems no longer under-report slots.
Patch & software management
- Patch approvals — Manual approvals are never overwritten by a later background refresh.
- Patch cycles — Clearer notes on auto-approved and emergency cycles. Deleted policies cancel unstarted cycles; expired maintenance windows are handled correctly.
- Patch execution — The same Windows update is never submitted twice in one batch.
- Software deployment — WinGet works without the Microsoft Store source and reports failed uninstalls correctly; deployments scheduled for restart are not missed when the agent starts before the network is ready.
- Patch policies — A failed policy reconciliation on the agent is retried after about a minute instead of waiting for the next regular interval.
Reports & integrations
- Reports — Widgets, previews and PDFs respect user access. Scheduled reports do not run when access is revoked, and patch and antivirus ratios count only agent-capable device types.
- Bitdefender, UniFi & Securepoint — Mappings saved during a sync are kept. Bitdefender respects GravityZone rate limits and no longer shows stale endpoint counts after a disconnect.
- Acronis — Devices are linked deterministically via the local Acronis agent ID, and domain-joined devices listed with a full DNS name are matched, too.
- Service-Board tickets — When a ticket cannot be created because settings are incomplete, the delivery log shows the reason instead of failing silently.
- Securepoint — Connected Securepoint devices keep a fresh last-seen timestamp instead of appearing stale.
Monitoring
- Availability — Brief outages no longer show as 100 % availability.
Interface & usability
- Sign-in & language — Expired sessions return you after signing in. The language choice sticks; translations, date displays and German BitLocker details were corrected.
- Sorting & mappings — Devices sort by their displayed alias, and the customer mapping dialog stays fast even with hundreds of customers.
- Navigation & layout — Device tabs scroll instead of wrapping, the collapsed sidebar scrolls, the device list uses the same row height as every other table, and expanded vulnerability rows wrap their text.
- Custom domain — Rejected changes show a clear error message.
Checks
Check updates are rolled out separately from the octoja release.
New checks
- Backup & telephony — Veeam Backup for Microsoft 365 monitors backup and copy jobs across all organizations; STARFACE checks licence, certificate, NTP, call load and SIP reachability.
- Antivirus — Acronis Cyber Protect Antivirus and VIPRE Endpoint Security check services, protection state and definitions on Windows.
- Location — Earthquake Monitor warns about quakes near the device's location.
- Proxmox cluster & services — Proxmox Cluster & Quorum monitors quorum, node membership, Corosync links and pmxcfs. Proxmox Services & HA checks essential Proxmox VE services, cluster HA problems and failed storage replication jobs.
- 3CX Phone System — Monitors a 3CX V20 PBX through the official Configuration API: licence and TLS certificate expiry, services, firewall, phones, trunk and extension registration, call capacity, backups and automatic updates.
Improvements
- ESET Security — Supports macOS from ESET 7 and reliably warns when the firewall or network protection is disabled.
- Printer (SNMP) — Brother printers report their ink levels.
- Warranty & end of support — HP Warranty reads the warranty locally via HP's Client Management Script Library, so API credentials are only needed for extra serial numbers. Alert timing and severity for HP Warranty, Lenovo Warranty and OS End of Life are configurable.
- APC UPS — Configurable temperature thresholds for warnings and critical states.
- Veeam Backup & Replication — Agent policies are evaluated per protected computer.
- Hyper-V — The VM status check can optionally monitor each VM's CPU usage with warning and critical thresholds.
Fixes
- Backup — The Acronis check works on macOS. Synology reports unreadable task lists and counts failures correctly, Comet recognises server-side schedules and MailStore evaluates runs without a profile ID separately.
- Security — SentinelOne determines console connectivity from the heartbeat. Antivirus Status handles Defender next to third-party products on Windows Server correctly.
- Hardware & network — Unknown Fujitsu subsystems no longer degrade the result, iDRAC wear warnings apply to SSDs only and ZFS capacity bars use the right colours. SMART no longer hangs storage on Windows RAID hosts; SNMP text with trailing control bytes decodes cleanly.
- Operating system — Failed logins are detected on Debian 13.


































































