Changelog

Follow new updates and improvements to octoja GmbH.

September 15th, 2026

New

Improved

Fixed

Highlights

  • Network scan (Beta) — Discover devices on the network automatically and take them straight under monitoring.
  • QuickSupport (Beta) — Support customers through a download link – no agent installation, and only after their consent.
  • AI assistants over MCP — Operate a remote desktop with your consent, edit devices and customers and create custom SNMP checks – within your permissions.
  • Acknowledgeable checks — Temporarily silence known warnings and critical states with a reason while monitoring keeps running.
  • Enforce SSO & two-factor authentication — Require SSO sign-in or an authenticator for every user, plus Italian and Spanish for the web interface, agent and e-mails.
  • Better reports & testable automations — New patch status and software change reports, flexible recipients, and automations you duplicate and test step by step.

New

Settings & access

  • Central settings — Administration → Settings now also holds custom domain, email sender, agent enrollment and branding next to authentication, beta features, MCP clients and repositories – one searchable area.
    Central settings
  • SSO & two-factor authentication — SSO sign-in or setting up an authenticator can be required for every user – SSO users included.
    SSO & two-factor authentication
  • Support platform access — The Support platform switch is also offered in the invite dialog and is enforced server-side.
  • Italian & Spanish — New languages for the web interface, agent window and e-mails. A language chosen through Ctrl+K is saved to your profile.

AI assistants

  • Remote desktop over MCP — Assistants can operate screen, mouse and keyboard – after your Control remote computers consent and within your remote desktop permissions.
  • Configuration & checks — Assistants can edit devices, aliases, customers and custom fields, and create SNMP checks with a live test. Permissions and auditing match the web interface.

Monitoring & rules

  • Acknowledge checks — Warnings and critical states can be acknowledged via Acknowledge on the device's Checks tab, with a reason, until the next success or for a chosen period. The check keeps running; alerts, cases and dashboard counts are suppressed.
    Acknowledge checks
  • Dashboard check filter — The dashboard can be filtered by Check names.
  • More rule conditions — One condition holds several values with Add value, and rules can target Server role or feature from your inventory.
  • Custom fields — Multi-select is its own field type, and custom-field tokens in check inputs appear as linked fields with label and source.

Automation & remote support

  • Involve the user — The Send notification dialog on a device can request a Yes/No/Cancel answer or a written reply and shows what the user picked; later automation steps branch on that answer.
  • Easier to build & test — Automations can be duplicated and individual steps tested on a device. New conditions check device tags and chassis type.
    Easier to build & test
  • Terminal as a user — The Toolbox terminal picker lists Logged-in users next to SYSTEM / root; the shell runs in that user's profile on Windows and macOS.
  • Remote desktop — Ctrl+Shift+X types the clipboard (also on login and UAC screens), Ctrl+Shift+M switches display, Ctrl+Alt+End sends Ctrl+Alt+Del. Windows supports the native H.264 codec WmfH264 for lower latency.

Beta features

  • QuickSupport — Customers → Quick Support creates a download link for remote support without installing the agent. After the customer's consent, remote desktop, terminal, registry and event log are available until they close the window.
    QuickSupport
  • Network scan — Scanner devices you designate per site discover devices on the customer network; the Network tab on the customer page lists the findings, which you take over in bulk, dismiss or let Auto-add monitor. You switch network discovery on under Settings → Beta features.
    Network scan
  • Also in beta — Proxmox VE host management and the UniFi Site Manager integration have been available since the previous release; switch them on under Settings → Beta features.

Patches, software & reports

  • Patch reports — Current Patch and Action Status separates approval from installation; the former detailed report is now Patch Performance Evidence, and definition updates can be condensed or hidden.
  • Software Change Report — A new built-in report lists software installed, updated or uninstalled in the selected period.
  • Flexible report recipients — One combined PDF for all customers or separate PDFs for several selected sites.

Integrations & device information

  • TANSS — Network devices are synced as peripheries with type and firmware instead of as PCs; UniFi identifiers and Securepoint serial numbers are carried over.
  • c-entron Service-Board — Configurable ticket language, ticket texts without octoja branding and ticket numbers in the delivery log.
  • macOS Server — New device type for tables, filters, TV View and the macOS templates; Change Device Type now works for Macs, too.
  • Hardware details — The device page shows battery, power profile and enrollment date.

Improved

Settings & branding

  • Dedicated settings pages — Custom domain, email sender and the enrollment policy with Allow open deployment each have their own page.
  • Branding — E-mails use the window title as fallback sender name. Mobile home-screen shortcuts take your icon and title; the octoja copyright line on the login page is gone.

Remote support

  • Remote desktop & Toolbox — The remote cursor shape is shown, on Windows hosts without a monitor too. Toolbox windows remember their size and position, and the Services view shows the account each Windows service runs under.
  • File explorer — Archive actions read Compress to ZIP file and Extract all, and long paths stay on one line.

Automation & software

  • Automation assignments — The device's Automations tab shows each assignment's trigger and hides manual automations.
  • Software automation — The step is now called Install or update software and restores saved selections when editing; outputs keep up to 64 KB.
  • Update exclusions on Linux — Never update these packages also applies to APT.
  • Custom packages — The package wizard shows the maximum upload size up front and rejects oversized installers and companion files before analysis.

Patches & agent updates

  • Patch execution — Alerts are suppressed while a device runs a patch cycle. Disabling the Windows Update interface now hides all of its notifications, too.
  • Device log — Completed update-all runs are recorded in the device log.
  • Agent updates — Smaller downloads through binary deltas. The Windows quick installer points out an installed Visual C++ runtime; the deployment page explains the settings file more clearly.
  • Maintenance mode — The maintenance banner on the device page lists the reasons for active windows. Patch cycles set maintenance under the patch policy's name and only for the actual window.

Monitoring & reports

  • Network checks — Agentless devices automatically use their stored address and SNMP or TR-064 connection; separate credentials in the check are gone.
  • Check configuration — Size thresholds offer a unit selector (KB to TB); custom SNMP probes collect values without thresholds, too; the monitoring device picker suggests the matching customer.
  • Reports — Check widgets can be filtered by monitoring checks, antivirus coverage by device types. Check details show last user and last seen.
  • Mappings & Securepoint — Auto-match is available in every site and host mapping dialog. The Securepoint setup hint names portal.securepoint.cloud as the place to create the API key.
  • MCP tools — Clearer input descriptions and explicit error messages. Tools for custom checks support result text templates.

Usability

  • Search & pickers — The global search finds devices and customers by custom field values. Enter picks the first filtered result in pickers.
  • NFR customer — The customer list marks the NFR customer with a badge, and it cannot be deleted.

Fixed

Remote access & agents

  • Remote desktop — After a logoff on the remote device you land on the session chooser, and the console reopens at the login screen. Italian keyboards type the period correctly, NumLock is restored and numpad keys type the right characters.
  • Web Console & file explorer — Heavy device pages load completely and sessions work in Safari. Downloads of growing files complete; dropping folders shows a notice instead of creating empty files.
  • Linux agent — Agents stay online after long uptime, too.
  • Windows agent — Failed installations are cleaned up properly, and launcher and agent no longer stop each other during recovery. Duplicate tray icons are gone.
  • AI screen capture — Screenshots for assistants over MCP keep working across Windows sign-in, lock and UAC transitions.
  • Hardware inventory — RAM slot counts include every memory array, so multi-array systems no longer under-report slots.

Patch & software management

  • Patch approvals — Manual approvals are never overwritten by a later background refresh.
  • Patch cycles — Clearer notes on auto-approved and emergency cycles. Deleted policies cancel unstarted cycles; expired maintenance windows are handled correctly.
  • Patch execution — The same Windows update is never submitted twice in one batch.
  • Software deployment — WinGet works without the Microsoft Store source and reports failed uninstalls correctly; deployments scheduled for restart are not missed when the agent starts before the network is ready.
  • Patch policies — A failed policy reconciliation on the agent is retried after about a minute instead of waiting for the next regular interval.

Reports & integrations

  • Reports — Widgets, previews and PDFs respect user access. Scheduled reports do not run when access is revoked, and patch and antivirus ratios count only agent-capable device types.
  • Bitdefender, UniFi & Securepoint — Mappings saved during a sync are kept. Bitdefender respects GravityZone rate limits and no longer shows stale endpoint counts after a disconnect.
  • Acronis — Devices are linked deterministically via the local Acronis agent ID, and domain-joined devices listed with a full DNS name are matched, too.
  • Service-Board tickets — When a ticket cannot be created because settings are incomplete, the delivery log shows the reason instead of failing silently.
  • Securepoint — Connected Securepoint devices keep a fresh last-seen timestamp instead of appearing stale.

Monitoring

  • Availability — Brief outages no longer show as 100 % availability.

Interface & usability

  • Sign-in & language — Expired sessions return you after signing in. The language choice sticks; translations, date displays and German BitLocker details were corrected.
  • Sorting & mappings — Devices sort by their displayed alias, and the customer mapping dialog stays fast even with hundreds of customers.
  • Navigation & layout — Device tabs scroll instead of wrapping, the collapsed sidebar scrolls, the device list uses the same row height as every other table, and expanded vulnerability rows wrap their text.
  • Custom domain — Rejected changes show a clear error message.

Checks

Check updates are rolled out separately from the octoja release.

New checks

  • Backup & telephony — Veeam Backup for Microsoft 365 monitors backup and copy jobs across all organizations; STARFACE checks licence, certificate, NTP, call load and SIP reachability.
  • Antivirus — Acronis Cyber Protect Antivirus and VIPRE Endpoint Security check services, protection state and definitions on Windows.
  • Location — Earthquake Monitor warns about quakes near the device's location.
  • Proxmox cluster & services — Proxmox Cluster & Quorum monitors quorum, node membership, Corosync links and pmxcfs. Proxmox Services & HA checks essential Proxmox VE services, cluster HA problems and failed storage replication jobs.
  • 3CX Phone System — Monitors a 3CX V20 PBX through the official Configuration API: licence and TLS certificate expiry, services, firewall, phones, trunk and extension registration, call capacity, backups and automatic updates.

Improvements

  • ESET Security — Supports macOS from ESET 7 and reliably warns when the firewall or network protection is disabled.
  • Printer (SNMP) — Brother printers report their ink levels.
  • Warranty & end of support — HP Warranty reads the warranty locally via HP's Client Management Script Library, so API credentials are only needed for extra serial numbers. Alert timing and severity for HP Warranty, Lenovo Warranty and OS End of Life are configurable.
  • APC UPS — Configurable temperature thresholds for warnings and critical states.
  • Veeam Backup & Replication — Agent policies are evaluated per protected computer.
  • Hyper-V — The VM status check can optionally monitor each VM's CPU usage with warning and critical thresholds.

Fixes

  • Backup — The Acronis check works on macOS. Synology reports unreadable task lists and counts failures correctly, Comet recognises server-side schedules and MailStore evaluates runs without a profile ID separately.
  • Security — SentinelOne determines console connectivity from the heartbeat. Antivirus Status handles Defender next to third-party products on Windows Server correctly.
  • Hardware & network — Unknown Fujitsu subsystems no longer degrade the result, iDRAC wear warnings apply to SSDs only and ZFS capacity bars use the right colours. SMART no longer hangs storage on Windows RAID hosts; SNMP text with trailing control bytes decodes cleanly.
  • Operating system — Failed logins are detected on Debian 13.
Write a comment...

August 27th, 2026

New

New

  • Remote support for Macs — View and control Macs through Remote Desktop, including display switching and clipboard text.
  • octoja MCP server for AI assistants — Connect compatible MCP clients under Settings → MCP Clients; existing administrator groups receive the required permission automatically during the upgrade.
    octoja MCP server for AI assistants
  • Remediate Lywand vulnerabilities across multiple devices — Run matching Winget or Chocolatey updates immediately or keep them as a permanent Update Only rule.
  • More automation capabilities — Automations can involve users and manage services, processes, local accounts, Registry values, maintenance mode, and cases.
  • Offer custom Windows packages through Software Kiosk
  • Use customer fields in checks and automations
  • Control support access for external users — Block cases and conversations without blocking help articles and release notes.

Improved

  • Filter and evaluate devices faster — New filters, custom-field columns, and direct inventory links shorten the path to the relevant device list.
    Filter and evaluate devices faster
  • Multi-select custom fields — Choose several values; tables and exports show every saved selection.
  • Manage custom checks directly in the Check Library — Preview different inputs without saving the check.
    Manage custom checks directly in the Check Library
  • More useful check results — Cases, Dashboard, and TV View show clearer results in the selected language.
  • View shared configurations with limited customer access — Relevant configuration packages, automations, and patch policies remain visible as read-only.
  • TANSS synchronization without a personal user account — A TANSS token is enough for device matching, and missing PCs can be created with their IP addresses.
  • View and change schedule time zones — New schedules use the browser time zone.
    View and change schedule time zones
  • Hide devices in maintenance mode from TV View — No maintenance also removes them from totals.
    Hide devices in maintenance mode from TV View
  • Open network-device web interfaces reliably from octoja — Sign-in, navigation, and downloads work with modern web apps and in a separate tab.
  • Failover monitoring for agentless network devices — Configure an ordered list of monitoring devices that take over automatically when one becomes unavailable.
  • Remote Times reports show session notes — The per-session view includes the note recorded for each remote-support session.
  • More meaningful executive report — Patch status, antivirus, backups, and monitoring determine the score instead of a snapshot of reachable devices.

Fixed

  • Update All retains exclusions and minimum age
  • Approved patch cycles remain unchanged — New updates or revisions no longer reset approval or timing, or replace an existing selection.
  • The Mac agent stays usable after updates and wake-ups — A temporarily unavailable display no longer prevents startup.
  • Acronis loads deeply nested tenants
  • Custom-check history shows the correct status
  • Fewer false alerts after agent restarts — Transient check failures are reported only after they are confirmed again.
  • Bitdefender installs work with current vendor filenames
  • Authentication for external check repositories works again
  • Custom-field defaults work in automations — This also applies to existing customers and devices.
  • Manual automations respect customer access
  • Devices can be found by their displayed IP address
  • Event logs sort chronologically again
  • SNMPv3 settings persist through testing and editing
  • Agentless-device cases belong to the monitored device
  • OQL rules can be removed completely

Checks

  • New checks for Dell iDRAC, ZFS, DataCore SANsymphony, TR-064 gateways, Acronis Cyber Protect Cloud, and Software Allowlist — They monitor server hardware, storage, gateways, backups, and allowed software.
  • More accurate checks for OPNsense, printers, Windows Firewall, network interfaces, Windows services, and user accounts
  • More complete Windows update and ESU detection
  • More reliable backup and system checks for Veeam, Acronis, Hyper-V, and Securepoint
Write a comment...

August 16th, 2026

New

Improved

Fixed

Highlights

This release is about control and evidence. You decide which updates reach your devices and when — a config package can skip the packages you name and hold back versions younger than a few days — and you can narrow the device list to fleet questions the quick filters cannot express. The audit log now records every sign-in with the IP address behind it, filters by source, severity, user and date, and downloads as a CSV file. Acronis Cyber Protect Cloud joins the integrations and three new checks arrive; the rest is polish and reliability — Windows patch runs finish and count what they did, devices stop dropping offline after an octoja update, and a long tail of remote-session and check fixes lands behind it.

New

  • Skip packages and hold back new versions — A config package set to Update all can now skip packages listed under Never update these packages and hold back versions younger than the Minimum update age (days). The age gate covers winget and Chocolatey only. Under every other package manager everything updates, and a version octoja cannot date installs anyway. winget dates from when octoja's catalog first saw the version, Chocolatey from the real publish date. Use the manager's ID (Mozilla.Firefox, not Firefox); max 200 per deployment, 0–365 days.
  • Filter the device list with a rule or a query — The device list gains an Advanced filter, built with the same rule builder as config packages, tag rules and patch policies, or typed as an OQL query, octoja's own filter language. It combines with the quick filters instead of replacing them and travels with saved views and shared links, so a view restores layout and filter together. It can never widen what you are allowed to see. If octoja cannot read a shared or edited filter, it warns you and drops your rule — the list still shows only what your permissions allow.
    Filter the device list with a rule or a query
  • Sign-ins, IP addresses and a CSV export in the audit log — The Audit Log now logs every sign-in, password and SSO separately, with the IP address behind each entry. Narrow by source, severity, user and date with All sources, All severities, All users and From / To, then download that with Export CSV. Every entry kind carries an IP from now on; older ones stay blank in that column. Large exports are capped: octoja tells you how many entries it wrote and asks you to narrow the filter for the rest.
    Sign-ins, IP addresses and a CSV export in the audit log
  • Acronis Cyber Protect Cloud integration — Connect octoja to Acronis Cyber Protect Cloud under Integrations and match each customer to their Acronis tenant with Match customers; backup protection status and Acronis alerts appear on those devices automatically. Setup needs an API client from the Acronis management console: Data center URL, Client ID and Client secret. A companion check reads last-backup age and result and active Acronis alerts from Acronis itself, nothing extra on the device. Assign it yourself, like any other check.
    Acronis Cyber Protect Cloud integration
  • Bulk actions: schedule device actions, close cases at once — Select devices and use Run or schedule action to restart, shut down or run a saved automation, Now or Schedule for later; cancel pending ones before they fire. In Cases, close several at once or add one time entry to all, max 100 cases per bulk request, shown in case history as created manually in bulk. Device-list checkboxes are always visible now, the Multiselect toggle is gone, and every action lands in the device's run history, restarts and shutdowns included.
    Bulk actions: schedule device actions, close cases at once
  • Share a saved view with your colleagues — Hand a saved device-list or dashboard view to colleagues with Share with other users; they find it under Other shared views in the view menu. It is read-only for them: they can adjust columns, sorting and filters for their own session and take a copy with Duplicate as new view…, but nothing they change reaches yours. Views saved before this update stay private until their author shares them explicitly.
  • Three additions to automations — Target devices gains an Advanced editor for query-written rules; automations with nested rule groups, uneditable before, now open there. A Roll out Bitdefender agent step installs it where missing: Windows only, needs the Bitdefender integration connected and customer matched, up to 25 minutes. A View Automations permission gives read-only access, running saved automations and run history included, while changes still need Manage Automations, and nobody loses access on upgrade. One side effect: automations now respect customer and device scope, so users limited to certain customers see fewer entries than before.
  • A TV View board with one card per device — TV View can now show one card per device carrying that device's worst result instead of one row per failing check. Switch with the Checks and Devices buttons in the header; the check board stays the default, and device cards open the device honouring your open-in-new-tab preference. The single criticality dropdown is replaced by three toggles — Critical, Warning and Offline — that combine freely, none selected meaning all, and both boards obey them.
    A TV View board with one card per device
  • Update FRITZ!OS from octoja — A monitored FRITZ!Box now shows the newest firmware available and whether an update is pending, and Install update starts it after a confirmation — the box restarts and the internet connection drops for several minutes, so it needs the Run Maintenance permission. Two readings were corrected too: Max upstream and Max downstream were a thousand times too low, and the traffic counters are relabelled to show they count only since the current connection was established.
  • Synology NAS hardware on the device page — The page of a monitored Synology NAS now carries a Hardware card with model, serial number and DSM version, a NAS card with system, power supply and fan status, DSM update status and temperature, and tables of its Drives and Volumes — the page previously showed only CPU, memory and interfaces. It needs SNMP to be reachable and the device typed as a NAS in octoja; models without a temperature sensor show no value rather than a zero.
  • Odoo 18 and older now connect — octoja now talks to on-premises Odoo 18 and older as well as Odoo 19, works out by itself which one an instance speaks, and asks for the Username (Odoo 18 and older) that the older ones need. A connection can no longer be saved without a successful Test connection, so a wrong key is rejected at setup instead of saving and returning nothing. Existing Odoo 19 connections keep working untouched, with the username left empty.
  • Send agent logs to octoja support — A device's Agent logs entry, previously Download logs, now opens a dialog first: Send logs to octoja support uploads that agent's logs and returns a reference number for the support chat, while Download now is the old one-click download. Sending shares your name and email, the device name and your Note (optional); the archive is capped at 50 MB and each upload is written to the device's log. It needs the same right that opens a device's files.
  • Two additions for remote sessions — Under Auto-lock after remote desktop, On Terminal Servers, lock only the console session locks only the console when a session ends. Switch it on yourself — it is off by default and stays greyed out until the parent setting is on. Set it per device or fleet-wide in a config package. After a drag-and-drop upload, Show in Explorer opens the remote Downloads folder with the file selected — Windows only, and only with a new enough agent. Typed keys now reach the remote machine, not octoja's toolbox shortcuts.
  • An RPM package for Red Hat-family Linux — You can now install the octoja agent on Red Hat-family Linux systems from a published RPM package, alongside the Debian package that was already available. Linux agent packages are also built to run on RHEL 8-era systems and newer, so a later agent update can no longer replace a working RHEL 8 installation with binaries that machine cannot start.
  • Links in custom fields are clickable — A link kept in a text or multiline custom field is now clickable straight from a device or customer page: Open link opens a single one, and several are offered in a dropdown. Full addresses — including rdp:// and ssh:// — are recognised, as are ones beginning with www, which open over https; duplicates within the same field collapse to one entry.

Improved

  • The update catalog and patch cycles read straight — Update Catalog entries now show status across All Devices and let you switch between every covering policy. Identifiers read as KB5034123 in patch cycle tables, update details and CSV exports; exclusions match with or without the prefix, and devices with no update yet read Pending, not Scheduled. Open patch cycles refresh at service start, hourly and on Refresh now. Affected-device counts now come from the devices listed, and ownership follows today's policy targeting. Expect both to change on updates you never touched.
    The update catalog and patch cycles read straight
  • Search, filter and export a device's inventory history — You can now search a device's Inventory History, narrow it to one change type — Software, Services, Pending updates, Local users, Network adapters, System information, Hardware or Security — and download the result with Export CSV, which covers every page of the filter, not just the rows on screen. Search also finds coalesced software updates, where an old and a new version share one entry. The time-range picker has moved out of the card header into the new toolbar row.
    Search, filter and export a device's inventory history
  • octoja stays responsive on large fleets — The device list, dashboard, patch-cycle and Update Catalog lists, and a customer's Alarm History (Last 14 Days) load faster; alert evaluation uses far less memory; an octoja restart no longer brings a wall of agent requests. Nothing changes about what they list, which alerts fire or what notifications contain. A check repository change reaches agents served by another instance of the service after up to five minutes; a run you start yourself and server-side evaluation are immediate. A device moved to another customer shows no Lywand Score until the next synchronization re-scores it.
  • Three improvements where checks are written and configured — Script rules — status reporting, non-zero exit codes, privileges — and the SNMP helper reference now sit beside the editor in Custom Checks and an automation's Run script step, which had none. Custom checks ask only for a Name; octoja derives the identifier, so duplicates are impossible, and repository credentials can generate, show and copy a password. Whole-number settings refuse decimals, and a decimal you saved earlier is rounded on its way to the device — 92.5 arrives as 93 — so review the thresholds you typed with a decimal. Only whole-number custom fields insert as a token.
  • Agentless SNMP checks take the device's own credentials — A check against a network device now uses that device's own address and stored SNMP settings automatically, so one config package covers devices with different credentials; a live test resolves them the same way. If you typed an SNMP community or version into the package, octoja now ignores it and uses the device's stored settings, so check that those are right on each network device. Devices with different credentials start working, and stale hand-typed values stop being used. Nothing is written back into the package.
  • The dashboard tree follows your filters — The customer and site tree now lists only customers and sites with devices matching your active filters, and its counts match the device list exactly. The dashboard's default severity filter — critical and warning — applies to the tree too, so on first load customers with no current issues drop out; a saved default view with no severity selected brings the full tree back. Selecting a customer or site in the tree still does not filter the tree itself.
  • Alert configurations say which field is wrong — When an alert configuration is incomplete, Save stays clickable and the field at fault is ringed in red, instead of a Save button that quietly did nothing with no hint which field was to blame. Thresholds, windows, schedules and names are now checked in the browser, and nothing that used to save stops saving.
  • woasi tickets arrive readable — Alerts handed to woasi now carry a readable ticket subject and a plain-text problem description — check, device, status, how often it tripped, the check result and a direct link to the device — instead of raw machine data. You choose the language in octoja, not in woasi: the Ticket language field on octoja's woasi integration page sets it for both and defaults to German, so set it explicitly if your technicians work in another. Recovery has its own subject and wording; every other alert receiver keeps the neutral wording.
  • Prerequisites and permissions for the agent rollout — The one-line agent install now checks the age of the Microsoft Visual C++ Redistributable, not just its presence, and replaces an outdated one before installing the agent. Without administrator rights it stops and tells you to install the newer redistributable first. The Group Policy (GPO) steps under Automatic Rollout now also tell you to give the Domain Computers group read access to the installer share and add it to the policy's security filtering — without them a rollout silently skips machines.
  • One German word per concept — The German interface now uses one word per concept: Prüfung becomes Check, Fall becomes Meldung, Vorfälle becomes Incidents, Registrierung in the Windows sense becomes Registry, Anmeldedaten becomes Zugangsdaten in most places, and the check library's Datensicherung becomes Backup. Two maintenance-window options on a device now read Checks and Softwareverteilungen. English and the other languages are untouched.
  • Run or schedule action moved to the Automations tab — On a device's page, running or scheduling an action now sits as a Run or schedule action button on the Automations tab, next to the automations assigned to that device and its Run history, instead of being buried in the three-dot menu at the top. The entry is gone from that menu, so it is worth knowing where it went; who may run what is unchanged.
  • TV View opens devices in a new tab — Clicking an alarm in TV View now opens the device in a new browser tab if your profile is set that way, and alarm rows are real links, so Ctrl-click and middle-click open a device in a background tab where they previously did nothing of the sort. The device Alias is available as an extra column — off by default, turn it on from the Columns menu above the table.
  • A dangling plug and cobwebs on idle devices — A device that has not reported in for more than seven days now carries a clearly visible cobweb on its page. The rest is decoration: an offline device's page shows a power plug dangling from its icon, and starting Wake device plays a short octopus animation that plugs it in; the plug drops back if the wake fails or the device has not returned after about 90 seconds. Nothing about how waking a device works changed.
  • Two-factor entries file under octoja — Setting up two-factor authentication now files the entry in your authenticator app under octoja rather than the company's legal name, on both the admin user page and your own profile. Anyone already enrolled keeps the old entry name and keeps working — the name is fixed at enrolment and plays no part in verifying codes, so it only changes if they set two-factor up again.

Fixed

  • Windows patch runs finish, and count what they did — A run no longer fails wholesale over one conflicting update, no longer reports success when the scan failed on every source, and counts installs finishing just after the window closes. A device still installing shows Incomplete, not Missed, and Incomplete blocks automatic ring promotion. Patch windows now fire at the scheduled time zone's hour on Windows versions that previously used the device's local time, as last release described. Finished runs name every update, By Update lists approved updates no device reported on, and not-applicable updates sit behind Show not applicable. Plan for two side effects. Any device under a patch policy now keeps Windows Update suppressed continuously, not only during its window, so anything relying on Windows patching itself in between loses that. Pending updates carry their current release date, so some dates shift forward and a few become eligible on a different day.
  • Devices stop dropping offline after an octoja update — Devices no longer drop offline in waves after an octoja update, and a restart of the service no longer briefly reports healthy devices as offline before their connections have settled. Affected agents recover by themselves — there is nothing to re-enter, reinstall or re-approve. A browser that runs into the sign-in rate limit now says so plainly instead of showing a generic unexpected error.
  • Five fixes for remote desktop sessions — On a multi-monitor Windows device, the screen you pick now receives the picture, the mouse and any resolution change, and a screen that used to stay black now streams. A held mouse button no longer sticks on the remote machine when the pointer leaves the session area or the browser loses focus; from a Mac, accented and Option-produced characters such as backslash now type into a remote Windows session instead of firing menus and shortcuts. Very large screens no longer trip a broken scaling option that forced a fall back to slower software encoding. Where an administrator has already switched on Allow physical console access without consent on Terminal Servers, connecting to that server's physical console no longer asks you whether to request the user's consent first. RDP sessions on the same server still ask.
  • Software deployment and the kiosk install what they should — Devices octoja could not set Chocolatey up on now repair themselves at the next deployment attempt. They used to fail every Chocolatey package, not just the setup step, so expect long-stuck deployments to start succeeding on their own. Your own packages published with Show in Software Kiosk now install when a user presses Install instead of failing with a missing-payload error. A kiosk install also follows the package's Install for setting rather than always installing for all users: this corrects last release's note, so Current user only lands in the signed-in user's profile. winget installs work on a freshly signed-in Windows 10 session, and a Windows deployment whose one-off prerequisite download hits a network hiccup is retried, so one doomed by the network takes about half a minute longer to fail.
  • Two integration fixes: TANSS matching and woasi reassignments — Matching your customers to TANSS companies opens straight away, even on instances with many thousands of companies. Companies read as Name (12345) with their TANSS customer number, so you can search by it; the list is cached for about 15 minutes, so a company created in TANSS moments ago may not appear yet. Devices moved to another customer or site reach woasi again, stop showing up there under their old customer, and no longer deliver inventory twice. Connecting woasi is lighter too: octoja sends only the changes from that point on instead of pushing the whole fleet up front, so reconnecting no longer re-sends everything.
  • Local user accounts appear on the device page again — Devices that showed no local user accounts now list them again under Local Users — a single unusable value on one account, typically one that has never signed in, used to wipe the whole list. There is nothing to re-enrol; the list fills again at the device's next inventory run. The same fix stops a literal {} appearing as a value in network shares, server features and license key inventory.
  • Browser translation no longer blanks the interface — The octoja web interface no longer freezes or goes blank when the browser's built-in page translation is switched on. Chromium browsers no longer offer to translate octoja at all, so anyone who was relying on that has to pick their language in octoja's own display-language setting instead, which covers English, German, French and Dutch.
  • Two fixes for the macOS agent — On macOS the octoja agent no longer restarts in a loop when it cannot rewrite its own file metadata. A Mac that dropped offline this way, shortly after an agent update, comes back on its own once the fixed agent reaches it — nothing to reinstall. On a small Mac screen the Allow remote support window now fits: the instructions scroll while the button that closes it stays reachable, and a permission's Set up button disappears once granted instead of sitting greyed out.
  • A failing check stops re-running every 30 seconds — A check that is alerting no longer re-runs every 30 seconds; once its failure has been reported it goes back to the interval you configured for it. The short retry is kept only for the window between the first failure and the confirmed one, so the result history of a long-failing check stops filling with an entry every half minute and gets far shorter and easier to read.
  • Wake-on-LAN works through a Wi-Fi relay — Waking an offline device over the local network now works when the only online device available to pass the signal on is connected over Wi-Fi rather than by cable. Such a site used to report that no eligible device was available, so the wake could not be attempted at all.
  • Automation conditions and scheduled action details — Automation step conditions on Device class match again, and you pick the device type from a searchable list instead of typing it. Conditions saved with an English value keep matching; ones typed in German — Drucker, USV, Unbekannt — still need re-picking, and switching an existing condition's variable to Device class resets its value to Unknown, so re-pick there. Scheduled and immediate restarts and shutdowns show their proper name in the run title and breadcrumb; cancelling a pending one uses scheduled-action wording.
  • Ctrl+K search results stop reshuffling — Results in the Ctrl+K search no longer reshuffle as the slower ones arrive, and the entry you highlighted with the arrow keys stays highlighted, so pressing Enter opens what you were actually looking at. Instant matches keep a fixed first tier and everything that has to be fetched appears together beneath them in a stable order.
  • A Linux-only check is tested the way a Mac runs it — The custom-check editor's Live test against a Mac now runs the script exactly the way the agent will, so a check that only has a Linux script gets the same verdict in the test as it does on the device, instead of failing on a wrapper the fleet never runs there.
  • Two fixes your users see — Alert phone calls no longer speak the backslashes in a Windows file path: octoja replaces them with a space in the customer, site, check name and error text before placing the call, so C:\Users is spoken as “C: Users”. The restart prompt that appears on a device after updates install no longer overlaps or cuts off its buttons in German and the other languages, and the countdown sits centred above them.
  • Three pieces of interface polish — Scrolling down a device's page no longer tints the pinned header strip at the top or leaves flickering artefacts behind it; devices actually in maintenance keep their coloured border and hazard stripe. In the Check Library, hovering a check's description no longer shows a help cursor that made the text look clickable, and the check details dialog no longer scrolls sideways on a small window.

Checks

Checks reach your devices separately from this release: a new or changed check arrives once that check itself is published, not with the update below.

  • Three new checks — HP Warranty, DATEV and WatchGuard EPDR — HP Warranty reads a device's serial number and warns before its HP hardware warranty expires; it needs an API key and secret HP grants per business through your account manager, polls daily, and skips HPE servers, which get their own verdict pointing at HPE's warranty service. DATEV — Windows only, every 10 minutes — checks DATEV services (found automatically), the DATEV SQL instance, program path and that drive's free space, License Manager and license-server reachability; every service set to start automatically must be running, so a broad assignment can turn machines red until you fill Services to ignore, which takes wildcards. WatchGuard EPDR reports installation, running services, active protection and current definitions, including on Windows Server. One fix lands outside the three: the existing Antivirus Status check now recognises EPDR and the older Panda Adaptive Defense name, so servers stuck on a false “no antivirus” result turn green at their next run.
  • Windows Update Agent Health reports the real install date — Up-to-date devices stop being flagged overdue for patching, and devices whose real last install predates your threshold start warning for the first time; expect movement both ways. The check now fails instead of warning silently when it cannot collect data at all, and stops printing Automatic updates disabled while Alert if automatic updates are disabled is off. The System Updates minimum-update-age filter no longer follows the device's time zone.
  • Exclude the virtual machines you do not want watched — In Hyper-V VM Status, switch on Monitor all VMs and fill VMs to exclude, which — like VMs to monitor — accepts wildcards. In Microsoft Hyper-V Host you pick the VMs to ignore from the machines the host last reported, and a new Per-VM integration service exceptions list silences one integration service on named machines while the rest stays watched. Both lists default to empty, so existing assignments behave as before; one side effect: a degraded-integration warning now names the service and is raised once per degraded service instead of once per VM.
  • Three Synology fixes — The Synology NAS check now names why it cannot read a NAS — no response, denied access, failed authentication or an invalid configuration — and flags a wrong community string as a likely cause. Denied access used to return an empty result, so expect some Synology devices to move from silence to a visible failure. Check that device's SNMP community and its access rights on the NAS; the failure was there before, just invisible. Synology Backup finds the Active Backup for Microsoft 365 tasks that really exist and says so when the NAS refuses the list, so devices stuck on a false “no backup task configured” warning turn healthy at their next run, listing jobs under their configured name instead of a numbered placeholder such as Task 1.
  • Backup checks stop alarming on backups that worked — Comet Backup splits jobs by schedule and grades by log severity, not wording; index rebuilds and manual runs are listed, never graded. Permanently red devices should turn green, Warn on unconfirmed results is gone, next-run dates show per-schedule estimates prefixed ≈, and devices with no scheduled backup runs warn. Flip side: a run that finished with warnings now counts as successful, so a job that only ever warned can look healthy. Veeam Backup & Replication stops calling weekday-only jobs overdue on unscheduled days; Veeam Backup Agent tells failed queries from empty output.
  • Failed Logins ignores a server's logins to itself — A domain-joined server no longer sits on critical because of its own routine failed logins, and the card states how many events it suppressed. Every event names the Reason it failed and severity follows it — only credential-type failures go critical, so devices red from clock skew, a Windows defect, an unreachable logon server or an unspecified logon error drop back; account, time and workstation restrictions still alarm. Where the regional format is not English the check was discarding every event. Those devices report real results for the first time, so expect new alarms there.
  • UniFi RAM figures match the device's own dashboard — The UniFi (SNMP) check no longer counts reclaimable cache as used RAM on switches and gateways, so warnings firing on cached memory clear at the next run. Devices that publish no used-memory figure showed 0%; they now report the real value where one exists and nothing where none does, which can cross your RAM thresholds and raise alarms that never fired before. The check also waits longer for a slow reply, so gateways that intermittently reported nothing now answer.
  • No offline result while octoja is still starting — The hold now covers checks you trigger by hand, and a device with a live connection counts as online even when its last recorded contact looks out of date — closing last release's settling-period gaps, where a manual evaluation could still write a false critical result and fire an alert. Trade-off: right after an octoja restart, device-online results are held back a little longer, so a genuine outage in that window is reported later.
  • Two disk checks report what they really know — Missing disks stay critical in Disk Presence until you approve them under Approved missing disks, pre-filled with the currently missing disks. An alert that used to clear itself after three days now stands until you act, so expect more standing criticals. SMART Disk Health stops warning about undeterminable health on RAID-controller volumes, which RAID Status owns, so servers amber purely on that turn green. Unreadable health shows a neutral state, not a warning; real faults and temperature breaches report as before.
  • NSLookup completes a short host name — NSLookup completes a short name such as SRV-DC with the device's own DNS suffix, and the result shows which name was Queried. Checks failing purely on a short name now pass, so expect a batch of criticals to clear once the check updates. Only the device's primary and per-connection suffix are tried, not a pushed search list, so fleets relying on several search suffixes still need the qualified name. Names that already carry a domain, end in a dot, or are reverse lookups of an IP address are sent unchanged.
  • Two checks name the obstacle instead of showing nothing — On hosts running Docker older than 23.0, the Docker Container check now reports that Docker is too old and must be updated instead of claiming no containers were found, so hosts showing an empty list turn red once the new version lands. When ESET blocks the octoja agent from reading protection status, ESET Security tells you to exclude the complete octoja program folder including all subfolders — the path changes with every agent update — then restore any quarantined octoja files.
  • The printer share counts as an admin share — With Include admin shares turned off, the Network Shares check now also leaves out the printer share Windows creates by itself, while custom hidden shares such as Data$ keep being monitored, so print servers that were flagged over open permissions on that share go quiet. Where admin shares are included, it is badged as an Admin share instead of looking like a normal one.
Write a comment...

August 6th, 2026

New

Improved

Fixed

Highlights

This release is about reach and control. Devices gain a maintenance mode and bulk actions, so a whole set can be taken out of the firing line or changed in one go. Device tables gain saved views, you can create local user accounts and search a registry straight from a device, and send mail from your own address. Seven new checks arrive, and monitoring starts running on AlmaLinux 8, Rocky Linux 8, RHEL 8, Debian 10 and Ubuntu 18.04 as each check publishes its next version. The rest is polish and reliability — software deployment through winget works again, several checks stop crying wolf, and a handful start reporting problems they used to hide.

New

  • Maintenance mode for devices — Take a device out of service now, on a schedule or recurring: under Pause during this window all five boxes — Checks, Automations, Alerts, Deployments and Patches — are ticked from the start; untick Deployments and Patches if the device must keep deploying and patching. Config packages carry fleet-wide windows that Clear maintenance never removes; administrator groups hold the new Maintenance mode permission already, every other group has to be granted it.

    Maintenance mode for devices
  • Act on many devices at once — Switch a device list into Multiselect from the table's overflow menu — there are no row checkboxes until you do — then pick your rows and use Assign customer, Assign tag or Maintenance; Clear maintenance mode removes only the window set directly on each device, never one coming from a config package. More actions adds Send notification, Wake, Export selection, Delete and Run automation — that last entry is hidden outright, not greyed out, without the global Manage Automations permission. Every row stays selectable now: devices you lack the right for are skipped and counted, and Delete asks you to type DELETE before it removes the selected devices and their history for good.

    Act on many devices at once
  • Send email from your own address — Under Branding, the new Email tab picks a Sending method — octoja default, Custom SMTP or Microsoft 365 — so alerts, reports and invitations leave your own domain. Saving needs a test email that actually went through; existing instances stay on the octoja default until an administrator switches.

    Send email from your own address
  • Saved views for device tables — Save the columns, sorting, widths and filters you use on Devices and the dashboard as a named view, and mark one as your default from the view menu (Set as my default). The page address carries your layout, so a link shares it.

  • Manage local users from a device — Create a local account, enable or disable one, or change its password from the Local Users section, on Windows, Linux and macOS. The new Local user management permission governs it, and administrator groups have it already.

    Manage local users from a device
  • Zammad integration — Connect Zammad under Integrations: a check alert opens a ticket in your Ticket group, and your Recovery state applies when the check clears. Map each customer to a Zammad organisation, or import them from Zammad. Matching is optional — tickets still open in your Ticket group either way, with the customer name in the ticket text.

  • Filter devices by tag, and see every tag you use — Device lists gain a tag filter that travels in the page address and into saved views. Inventory gains a Tags tab listing every tag with its device count and Source — Own or From rule; click a count to open that device list.

    Filter devices by tag, and see every tag you use
  • Schedule patch rings around Patch Tuesday — A patch policy can hang off Patch Tuesday: pick the Patch Tuesday at 02:00 template, then set Days after the reference Tuesday — up to 31 days after the month's second or third Tuesday. Build rings: one on the day, the next a week later.

  • Export a device's event log — Export an Event Log as an XML archive (.zip) carrying every filter you set, search text included, or a Native log (.evtx) that applies only the level, event ID and date filters, so it holds more than the list shows. With no date range picked, octoja warns before exporting the whole log. The existing Event Log permission governs this — anyone who could read a device's log can now download all of it, and there is no separate export right to withhold.

  • Screen-text recognition and mapped network drives — Search screen text (OCR in the toolbar) reads a box you draw on the remote screen: Copy text or Search with Google, all in your browser. The file explorer lists mapped drives as Network drive — Windows only, and a share opens only while the user who mapped it is signed in.

  • Share your own checks with another octoja instance — On Custom Checks, Repository access hands out a repository URL and credentials exposing the checks you pick. Another octoja instance syncs them in under Add community repo. A community repository with a username now needs an HTTPS URL — loopback addresses excepted — so an existing HTTP entry with credentials fails the next time you edit it.

  • Customer custom fields everywhere — Fields you keep on a customer are now available as columns in the customer list, as a rule criterion (Customer Custom Field) and as automation variables (under Custom fields (Customer)); device fields sit beside them under Custom fields (Device).

  • Four new automation building blocks — An On boot trigger that fires once per actual reboot, plus Enable BitLocker, Create user account and Wake device steps. Create user account is the same operation you can run on a single device, now scriptable across the fleet.

    Four new automation building blocks
  • Stop a running automation — Open a run from its history and cancel it with Cancel run — the button sits in a run's detail view, not in the run list. The current step finishes, then nothing further starts. A run that hangs now ends as Timed out.

  • Scope a report to specific devices — Restrict a report template to matching devices — only servers, or everything with a certain tag; the pending-patches widget gained a filter of its own. You can also hide individual checks from the monitoring widgets and the Management scorecard.

  • Partial tag matching in rules — Tag conditions everywhere the rule builder appears — Groups, Tag Rules, Config Packages, patch policies and automations — now offer “matches text” and “does not match text”, so one rule catches every tag containing a word.

  • See which config packages apply to a device — A device's three-dot menu gains Config Packages, listing every rule-based package that reaches it with its description, its Contents — checks, deployments, automations or agent settings — and a link into the package. If none matches, the empty state says so and points to the Checks tab.

  • More of a device's hardware on the page: monitors and memory modules — Connected Monitors lists each screen's Manufacturer, Model, Connection and Serial Number; changes land in Inventory History. Memory Modules add Slot, Type, Vendor and Part Number on Windows, Linux and macOS. Monitors are Windows only, the card stays hidden until one is reported, rows with no identifier at all — headless machines and RDP phantom adapters — are dropped, unreported details show as Not available, and on Apple Silicon the built-in memory reports no slot, so Bank no longer falls back to the memory type there.

  • Decide what the customer sees before a remote session starts — A user's Remote Support Display Name replaces the technician's name in the consent prompt on the customer's device, and shows up only where a prompt appears at all; leave it empty and the user name shows as before. On terminal servers, Allow physical console access without consent on Terminal Servers (off by default) skips the prompt at the console, but only while Require user consent for remote desktop is still on; RDP sessions on that server still ask. The consent-bypass right, used with a reason, still overrides both.

  • See who is in an Active Directory group — On a domain controller, the Manage members button in the Active Directory Groups table opens a dialog that reads the group live. Add or remove members there.

  • Remote Times report — Shows the time spent in the remote toolbox on a customer's devices — terminal, files and remote desktop all count towards one session. The built-in report lists it per device and per session.

  • Search a device's registry — and keep browsing while it runs — Press Ctrl+F in the Registry Editor to search key names, value names or value data, under All hives or This key. The search keeps running when you close the box, so you can browse on and find the hits waiting. Deeply nested keys open faster.

  • Your personal referral link — My Profile gains a Recommend octoja section with your own referral link: copy it, pass it to colleagues and partners, and if they become octoja customers, a surprise is waiting. The section stays hidden on instances without a referral address configured.

Improved

  • Patch screens say what happened and why — Alongside release dates, categories and the covering policy, every update in a Windows patch run carries a Selection line with the reason, plus Satisfied rules, Matched exclusions and Blocked KBs. The free-text Skipped by the device message is gone, and update titles link into octoja.

  • TANSS now needs your 2FA secret — plus a remitter and close-on-recovery — An account with two-factor authentication now needs its 2FA secret (2FA accounts only); the one-time code field is gone, so set those connections up again and octoja derives every sign-in code from the secret. Alert tickets now reach TANSS reliably instead of failing a few hours after you connect, and each new ticket hangs off the device that raised the alarm. Two new settings sit next to Assigned department: Close ticket on recovery, and Remitter — the employee new tickets are reported by, so the TANSS instances that demand one stop rejecting the ticket; leave it empty to keep using the connected account.

    TANSS now needs your 2FA secret — plus a remitter and close-on-recovery
  • Device search: faster, and it finds a serial number — Ctrl+K, device lists and pickers keep up with your typing, and search now matches manufacturer, serial number, operating system and public IP. The new fields work from a device's next inventory run. Search still matches the exact characters you type — a name with ä, é, ø, ñ, å or ç is only found by typing the accented character — and an operating system or public address now hits every device sharing it.

  • Custom fields and checks now work in both directions — Custom check and SNMP outputs still write into a device custom field; now a number-typed check setting can read one, falling back to the field's Default value, and SNMP probes gained a Unit next to the OID, so a temperature reads 42 °C instead of a bare 42. Checks already using a field token therefore change behaviour on devices with no value of their own: they evaluate against that default instead of against nothing, so a threshold suddenly compares against a real number. The mapping lives on the check itself — set it again there if a config package set it; Insert custom field appears only once the tenant has a number-typed device field, and Unit only on numeric SNMP probe kinds — switch a probe to a text kind and a unit you entered stops taking effect.

  • What your customers receive: their language, your brand — SMS, calls and app push now follow each person's profile language, replacing the per-group Language setting. Scheduled reports take a language per receiver; existing receivers stay on English until you open the schedule and set Language there. The report preview no longer names octoja; the PDF's per-page footer is unchanged.

  • Automations survive more, and take their own time limit — A run now survives an octoja service restart, and Run script takes its own limit — empty still means four minutes. Restart device gained Wait for reconnect (seconds); new steps wait 300, existing ones sit at 0 and do not wait — set the field once there.

  • Tables remember the columns you picked, and list them alphabetically — Tables outside Devices and the dashboard now remember which columns are visible, their order and their widths; on those two, saved views do that job. Columns are listed alphabetically in your language. The layout stays in that browser and covers columns only — not sorting, filters or page size.

  • The dashboard filter sidebar, tidied and multi-select — The dashboard filters on several customers and sites at once, each row showing critical and warning counts next to the device total. Hold Ctrl or Cmd to add one, Shift for a range. The sidebar lists only customers with devices, and each group scrolls in its own capped section.

  • Clipboard in remote desktop — Copied text now reaches the remote machine at once; a paste no longer hands over the previous contents. When your browser cannot sync the clipboard, Paste sends yours to the remote machine. The older button is now Type Clipboard, for sign-in and UAC screens.

  • Writing a custom check is easier to read and to judge — Scripts are now colour-coded as you type, in the Custom Checks editor and the Run script step, for Windows (PowerShell), Linux (Bash) and macOS (Bash) — a typo catches your eye sooner. Line numbers now keep pace with the code when you scroll a long script. The test still reports separately whether the script ran and what the check returned.

  • Network devices counted per customer — The customer list gains a Network devices column and each customer's page a matching tile, so switches, firewalls, NAS and ESXi hosts are visible without filtering by hand.

  • IP addresses for every device — Switch on the IP Address column from the Columns menu and it now shows the local address of devices with an agent, not just of network devices. Network devices no longer show their IP in the Operating System column.

  • Alert windows in minutes — Alert rules can measure their window in minutes as well as hours, so you can react to a short burst of failures. Schedules running past midnight are marked (next day).

  • Remote desktop shows locked sessions — A session on a locked Windows device is marked Locked, so you know the user has to unlock before they can approve the connection.

  • Backup reports cover the checks you run — They counted only three built-in checks. They now include the newer built-in ones plus any check of your own whose category you set to “backup” — lowercase in the editor, shown as Backup in the check library — listed by name.

  • Filter a device's event log by source — A Source box in the event-log toolbar narrows the list to the applications or services whose name contains what you type.

  • Downloaded logs cover the whole agent — The log package now includes every part of the octoja agent, including the app running in the user's session.

Fixed

  • winget deployments install again — and say so when they do not — Deployments through winget failed on almost every package — fixed, and a failed one no longer reports success but names the reason. Software Kiosk installs now land for every user of the device, not just the signed-in one. Some deployments will now show as failed; that is the truth.

  • Patch runs reach devices they used to skip — Updates Windows reports without a severity — Defender definitions and the Malicious Software Removal Tool among them — were approved but silently skipped while the run claimed success; they install now, so expect a bigger first cycle. Patching also stalled where a device does not know the scheduled time zone; it now falls back to that device's own local time. That fallback is a stopgap, not the configured zone: the window can fire at a different wall-clock hour than the schedule says.

  • Four fixes for remote desktop sessions — Passwords from a password manager arrive complete, and typing returns to the remote screen after a toolbar click. A session at a Windows sign-in screen survives someone logging in, moving to their desktop and asking consent again. A brief network hiccup no longer stutters the rest of the session.

  • Agents, checks and scripts stop tripping over what Linux and macOS do not ship — Checks now start on AlmaLinux 8, Rocky Linux 8, RHEL 8, Debian 10 and Ubuntu 18.04, from each check's next published version onward — problems those devices hid will surface. The Linux install brings ICU and jq and stops with the last log lines instead of claiming success. Custom checks need no Python on a Mac, and Bash ones re-fetch their wrapped script once.

  • Three fixes in the custom-check editor — The Windows, Linux and macOS switches under Check Scripts now follow the scripts a check actually has — no more macOS switched on for a check with no macOS script — and saving no longer attaches a platform nobody wrote a script for. SNMP probes fill Parameters, Output Schema and Detail Layout as you add them. Live test reaches a network device through its Monitoring asset — you need script-execution rights on both the network device and that monitoring asset, and the asset must be present and online.

  • The dashboard shows your whole fleet again — The dashboard's device list no longer drops devices without a customer, so it finally matches the totals above. Each customer also gets a Without site row, so those devices can be opened, not just counted. The list gets longer, with a dash in the Customer column.

  • A Redis tool alone no longer tags a device as a database server — A device with only a Redis-named tool such as RedisInsight no longer gets the database tag. octoja rewrites the built-in rule for you, even if you never touched it. Devices losing the tag also leave every group, config package and patch policy targeting it.

  • Servers with more than one processor report all their cores — CPU cores and Logical processors counted only the first socket; a multi-processor Windows machine now reports all of them. Affected devices show higher numbers after their next inventory run — the old figures were too low, not the new ones too high.

  • Dialogs and pickers stop handing you settings you never chose — A new automation now starts on the Manual trigger instead of Device added, which could fire before you picked one. Closing the add-check dialog clears the alert configuration, so the next check does not inherit it. Check pickers list entries alphabetically in your language under category headings, Custom first.

  • The quick install adds a missing Visual C++ Redistributable — Run as administrator, the one-line PowerShell install now downloads and installs the matching Microsoft Visual C++ Redistributable before the agent, so the agent starts on a fresh Windows 10 or Server 2016 box.

  • Config Packages deploy software on save — A package containing only software deployments reaches its devices as soon as you save it, instead of at the next check-in.

  • Network checks from Config Packages find their host — Checks rolled out from a config package to network devices now use the device's IP automatically, and adding a network device pre-fills the standard SNMP community. The SSL / HTTP check and the HTTP Content Check are no longer offered for network devices.

  • Tag overflow badges open instead of navigating — Clicking the “+2” badge shows the hidden tags instead of jumping into the device.

  • Your branding survives an offline start — The octoja app on your users' devices opens with your logo, product name and colours even when it starts before the network. It used to come up in octoja's default look until the branding had loaded.

  • Config packages reach agentless devices — Create or rename a switch, firewall, NAS or ESXi host, or change its type, and octoja matches it against your rule-based config packages straight away. Devices that sat outside a package they should have had pick it up on their next edit.

  • A saved view keeps an empty Status filter — A dashboard view you deliberately saved with no Status selected no longer comes back with the default; the empty selection survives. Views saved before this update load with Status empty too.

Checks

Checks reach your devices separately from this release: a new or changed check arrives once that check itself is published, not with the update above.

  • Seven new checks — NAKIVO Backup & Replication, Comet Backup, LAPS Passwords, Dell Warranty and NSLookup are joined by GPU and Secure Boot Certificates. GPU grades utilisation, memory (VRAM) and temperature per card on Windows and Linux — temperature comes from NVIDIA cards, and from AMD cards on Linux; other GPUs report none — and Secure Boot Certificates finds Windows devices still missing the 2023 CAs, which keep booting but no longer receive DB/DBX updates, bootkit revocations or boot manager updates. Before you assign them: Comet Backup, LAPS Passwords, Dell Warranty and Secure Boot Certificates are Windows-only, NAKIVO needs read-only access to the Director's database, Dell Warranty an API key and secret from Dell TechDirect and polls once a day, a broad LAPS assignment turns machines red that never had LAPS, and a device with no readable GPU warns until you set When no GPU is found to ignore it.

    Seven new checks
  • Narrow the SQL Server check to the instances, databases and jobs you care about — Microsoft SQL Server Health now narrows by instance as well as by database, and by SQL Agent job while Monitor SQL Agent jobs is on. Each of the three has its own monitor list and exclude list, and an exclusion always beats an inclusion. If you already limited the check to certain databases, you now get fewer disk-space and availability-group alerts — those finally honour the filter.

  • The MailStore check now covers MailStore Server too — The check now covers a plain MailStore Server: it is called MailStore (Server & SPE), and Edition picks the product — MailStore SPE (Management API) or MailStore Server (Administration API) — along with its default port. Unreachable servers come with a reason, and umlaut passwords work. Existing checks stay on the Service Provider Edition until you change Edition.

  • More control over which volumes the storage checks measure — In Disk Space, Monitor all drives is on by default and Drives to exclude picks the exceptions. Disk Fragmentation now lists ReFS volumes as n/a and measures folder-mounted ones, which may start alerting where nothing alerted before; use Exclude volumes to leave them out.

  • Four checks report more precisely — CPU Temperature now reports a failed or timed-out sensor query on Windows instead of a missing sensor; ignoring missing sensors no longer silences it, so silenced devices report again. APC UPS warns before a battery cartridge expires, and Pending Reboot can ignore pending file renames. Microsoft SQL Server Activity honours an Error log lookback (minutes) below five, which it used to stretch back to five.

  • Checks read command output correctly on non-English Linux and macOS — RAID Status, Firewall Status, Service Status, Disk I/O and a dozen more no longer misread other-language devices, so results on existing Linux devices change: those checks now report states they simply could not see before. The invented extra pending update on Linux is gone. User Account Audit stops counting Linux accounts as inactive when they never were, so those false entries disappear, and it gains an Excluded accounts list with wildcards.

  • Four hardware and SNMP checks stop crying wolf — HP iLO ignores drive bays the server cannot read and grades real faults harder: a Failed drive is critical, and Memory now warns on Degraded, a state it could not flag at all before, so a server with a degraded module starts warning. SMART Disk Health drops impossible temperatures and shows a dash. Network Interface counts the connected adapter, and Printer (SNMP) reads Brother devices reliably.

  • Antivirus checks report what is really going on — Antivirus Status stops double-listing a product and stops turning critical when Windows backgrounds Defender for another antivirus. Securepoint Antivirus Pro no longer calls Real-time protection Inactive on a quiet machine — it reads the newest status entry. Devices stuck on that false alarm turn green at their next run.

  • Synology Backup signs in, and stops inventing failed runs — Signing in to DSM failed outright on some installations; that is fixed, and a rejected sign-in now names the reason — wrong credentials, a disabled account, missing permissions, a two-factor code or a blocked address. Active Backup for Microsoft 365 tasks that ran cleanly are no longer reported as failed — a warning-level log entry alone no longer fails one of those runs, so devices stuck red turn green. The flip side: a task that has only ever warned can now look healthy.

  • Event Log counts only the severities you picked — With Minimum severity on Critical only, Critical + Error or Critical + Error + Warning, informational events no longer count towards the thresholds, while All levels (including Verbose) now takes everything. Devices that alerted on those three settings may fall silent; All levels may report more than before.

  • No offline alarm while the connection is still settling — Device online no longer turns critical just because octoja restarted or an agent dropped briefly; the previous result stands until the connection settles. A device back within 30 seconds stays green, and an outage just after an octoja restart may be reported up to six minutes later.

  • No warning when octoja itself turned automatic updates off — Windows Update Agent Health no longer warns that automatic updates are disabled when octoja's own patch management switched them off, so you can leave Alert if automatic updates are disabled on for the devices octoja patches.

  • OS End of Life reads long-term support — Debian, SUSE Linux Enterprise and Oracle Linux releases are no longer critical while extended support still covers them. That is the default, End of extended support (security updates only); alert on End of active/mainstream support instead and the earlier regular date still counts, so some turn critical instead of warning.

  • Mount Point Free Space skips unmounted volumes — Volumes with no mount point at all — typically EFI, recovery and reserved partitions — are no longer measured, and the details say how many were skipped.

Write a comment...

July 27th, 2026

New

Improved

Fixed

Highlights

This release adds four new monitoring checks — disk-space trend, file size, CPU temperature and Synology NAS backups — so you catch storage, heat and backup problems earlier. A new SLA report turns your check history into incident counts, resolution times and uptime, and a report widget lists every check that no alerting covers. The rest is polish and reliability — a much sturdier TANSS integration, finer-grained permissions, and a long tail of check fixes.

New

  • Disk Space Change check — Tracks how much the free space on a drive changes over a period you choose, with thresholds in MB or as a percentage. It also projects when the drive will fill up and plots the trend.
  • File Size check — Alerts you when a specific file crosses an upper or lower size threshold.
  • Synology Backup check — Monitors Hyper Backup, Active Backup for Business and Active Backup for Microsoft 365 jobs on your Synology NAS, and alerts you on stale or failed backups and unreachable targets.
  • CPU Temperature check — Warns you from the device's own sensors when it runs too hot. Set Warning and Critical in °C (80 and 90 by default), and choose whether a device with no sensor at all raises a warning or is skipped.
  • SLA report — Shows incident count, mean time to resolve and time-weighted uptime, plus a timeline of check failures and recovery times. Check results are kept for 30 days.
  • Checks without alerting — report widget — Lists every active check that no alerting covers, with a Source column showing whether it came from a shared configuration package or was added individually.
  • List view on Reports, Custom Checks and Integrations — All three pages gain a cards/table toggle in the toolbar, with cards staying the default.
    List view on Reports, Custom Checks and Integrations
  • Device counts per customer site — The customer dashboard now shows a searchable, sortable table of the customer's sites with the number of devices you can reach at each.
  • "No Customer" device filter — The device list's customer filter gains a “No Customer” entry; previously you could reach these devices only through the dashboard tree.
  • Per-check alarm indicator on the checks tab — Every check now shows a filled bell when a package alert configuration applies and a muted bell when none is configured. The “Custom alarm” and “Alarms off” badges still take precedence.
    Per-check alarm indicator on the checks tab

Improved

  • Dialogs stay open on an accidental outside click — Once you've entered or changed something, a click outside the dialog no longer discards it. This applies to every dialog.
  • Choose which Lywand score scope to show — octoja keeps separate All, Managed and Unmanaged scores per customer and device. It remembers your choice, and checks, dashboards and report widgets all follow it.
  • Per-drive thresholds on the disk-space check — Set threshold exceptions per drive, so you no longer have to raise the system drive's thresholds just because a data drive legitimately runs nearly full.
  • File Age check watches the newest file in a folder — Give it a folder and a pattern and it checks the newest matching file — a backup folder whose filenames change, for example. Watching one exact file still works.
  • Reliable clipboard in remote desktop — Copying out of a session no longer fails silently when your browser blocks the clipboard. Recent failures retry on their own, and older ones get a retry button in the toolbar.
  • Resizable Storage Analyzer columns — Resize columns so long nested paths stay readable. Row actions now sit in the name cell, and File Explorer and the Storage Analyzer use the same ones.
  • Event Log check: alert on a missing event, and match message text — The “Expected events (alert when missing)” option warns you when an event you expect never arrives. Its “message contains” matching now reads the text as shown in Event Viewer, umlauts included.
  • Check "Custom fields" tab — The former “Write-back” tab now carries this name, with a tooltip explaining that it maps check-result values into a device's custom fields.
    Check "Custom fields" tab
  • Alarm badge shows the real minimum severity — The badge now shows the minimum severity configured for the channel instead of always saying “failed” — Warning, for example, when the channel fires from Warning.
  • Finer-grained permissions across admin surfaces — Changing group membership now needs the group-management permission. You can grant the custom-fields permission in the group editor, and alarm editors can pick alert-channel targets without needing full integration access.
  • Device context on the patch and automation screens — Device names on patch cycles, automation runs, configuration packages and the customer dashboard are now links, and hovering one opens a preview card. The patch-cycle results table also gains a Customer column.
  • Pick the SNMPv3 protocols for an agentless device — “Auth protocol (v3)” offers SHA-1 and SHA-256, “Privacy protocol (v3)” offers AES-128, AES-192 and AES-256. Both can be set to None.
  • The SMART check reads drives it used to skip — On Windows, when a drive's usual self-test data can't be read, the check now falls back to what Windows itself reports about its health.
  • TANSS setup finds the server on its own — Enter just the server address and octoja locates the API path itself. The ERP token works with or without a “Bearer” prefix, and the company list fills correctly.
  • Steadier picture in remote desktop on a busy connection — The session now adjusts its frame rate on the device itself rather than in your browser. On a tight connection the picture softens evenly instead of stuttering and catching up in bursts.

Fixed

  • Blocking the Windows Update page now works — The block coexists with a Windows policy the customer already applies, and octoja withdraws it again once the patch policy no longer applies.
  • Custom SNMP checks work on Windows
  • SNMP check no longer reports a false offline — A device that returns an empty description no longer counts as offline.
  • Network Interface check runs on Linux — The check also no longer drops Linux adapters and VLAN sub-interfaces that share a hardware address or have none at all.
  • Service rule suggestions show the right value — Suggestions now display the service's display name while saving its internal name, so the rule matches.
  • Windows agent updates no longer restart the old version
  • PowerShell automations report the right result — A leftover exit code from an earlier command no longer fails the run, and octoja now captures values you assign inside functions as outputs.
  • Package-manager list refreshes when you switch — Switching between Chocolatey and winget in a device's “Software” tab now refreshes the list and badge each time.
  • Agentless check changes take effect immediately — A per-device check setting on an agentless device, a PDU for example, now applies right away instead of only being stored.
  • Local-admins quick command works in every language
  • Dashboard filter column scrolls as one
  • Dashboard pagination stays at the bottom while searching
  • Tag-rules page opens on large fleets — The page no longer counts matching devices for every rule up front; you still see the count on each individual rule.
  • Resolving a vulnerability no longer installs unrelated software — “Resolve” on a Lywand finding could match the wrong product and install software nobody asked for. It now only ever updates software already on the device, and warns you when nothing matches.
  • You only see the enrollment tokens for your customers — If you're limited to certain customers, octoja shows and manages only their tokens. Tokens that cover all customers stay with accounts that can reach all of them.
  • Firewall check reads non-English systems — The “Firewall Status” check now understands a German-language system that reports its status as “Aktiv”.
  • A Network Interface check that watches nothing now says so — When its filters excluded every adapter on a device, the check reported OK while monitoring nothing. It now warns, and records which filter step removed them.
  • The “Network Firewall (Appliance)” check reads FortiGate firmware and licence details correctly
  • Scripts no longer lose their output — A script that left a background process running came back with its output cut short. Script automations, software deployments and check runs now capture all of it.
  • Continuous deployment no longer looks scheduled — A configuration package that keeps software continuously up to date now shows “No schedule set” instead of a Deployment schedule it never used.
  • Live-updating lists no longer jump back to page one — When a list refreshes in the background, you stay on the page you're reading as long as nothing about the data has changed.
  • BitLocker details stay open while you read them
Write a comment...

July 21st, 2026

New

Improved

Fixed

Highlights

octoja’s biggest release yet: 112 updates — two-thirds more than our previous record. It shapes octoja around how you work — custom fields that flow through checks, automations and rules, automatic patch approval, SMS and phone-call alarms, Active Directory on domain controllers, light/dark white-label branding, and a new Freshservice integration, plus a 2–3× faster dashboard and a long tail of check and patch fixes.

New

  • Custom fields for devices and customers — Define your own fields in seven types, fill them in on the device or customer page, and manage them under "Administration" > "Custom fields".
    Custom fields for devices and customers
  • Checks, automations and rules can use your custom fields — Checks read and write a device's custom field, automations use them as variables and can set or clear one, and the rule builder gains a "Custom Field" condition.
  • Approve patches automatically by rule — Set "Approval mode" to "Automatic approval" and add rules on "Severity", "Category" or "Title" to approve matching updates for the next maintenance window and defer the rest; a rule can also hold an update back until it is a set number of days old.
    Approve patches automatically by rule
  • Hold back Windows updates with a known Microsoft issue — A separate "Exclude updates with known problems" switch withholds any update flagged with an unresolved Microsoft known issue or a red or yellow community warning, until that flag is lifted.
  • Alarms by SMS and phone call — Alarms now reach your team by SMS or phone call alongside the mobile app, via a group under "Integrations" > "Mobile notifications"; 500 SMS and 500 calls per month are included. Each group sets one language for all its SMS, call and app texts, and a new "History" tab shows which notifications were sent.
  • Freshservice ticket integration — Connect Freshservice under "Integrations" and match your customers, and the new "Freshservice ticket" alert channel opens a ticket for every alarm and closes it on recovery.
  • Device sync to the Freshservice inventory — Turn on "Sync devices to Freshservice hourly", or use "Sync now", to push your matched customers’ devices into Freshservice’s asset inventory. Works only on Freshservice accounts created after 31 March 2026.
  • Invite users by email — "Invite User" emails an invitation; the recipient sets a password or uses your identity provider, and user management splits into "Users" and "Invitations" tabs where pending invites can be resent or revoked.
    Invite users by email
  • Active Directory management on domain controllers — Domain controllers gain an "Active Directory" tab listing the users, computers and groups from the domain, where you create, disable or delete accounts and reset passwords without a remote session.
  • Prevent local uninstall of the octoja agent on Windows — "Prevent local uninstall" hides the octoja agent from the Windows program list so everyday users can't remove it. Set it per device or through a configuration package — a deterrent rather than a hard block.
  • Light and dark white-label branding — Branding now carries a separate logo, icon, brand colour and secondary colour for light and dark mode, in paired "Light mode" / "Dark mode" fields on the "Branding" page.
    Light and dark white-label branding
  • New Network Shares check lists every SMB share and its permissions — Lists every SMB share on a Windows device with its share and NTFS permissions, flagging any open to Everyone, Authenticated Users, Anonymous or Guests.
  • New OS End of Life check for Windows, macOS and Linux — Detects the installed Windows, macOS or Linux release and shows its active-support and end-of-life dates from the endoflife.date catalog.
  • More Windows and Office inventory on the device page — The "System" tab of a Windows device gains "License Keys", "Network Shares" and "Mapped Network Drives" tables, "Roles & Features" on Windows Server, and an "OS build" row.
  • Scope new automations and cases to a customer — A new "Customer" field in the "New Automation" and "Create Case" dialogs: limited accounts must set it, full-access accounts can leave it blank to run across every device.
  • New CyberPower UPS, ATS and PDU check over SNMP — Reports battery status, load, remaining runtime, voltages, redundant supplies and transfer-switch state against your own thresholds.
  • New Wortmann Warranty check reads the TERRA service portal — Looks a Windows device up in the Wortmann/TERRA service portal by serial number and reports its warranty period, remaining days and booked service.
  • New DNS Blacklist (RBL) check watches mail-server reputation — Checks the IPv4 addresses you specify against DNS blocklists (Spamhaus, SpamCop, Barracuda by default) and alerts when one is listed.
  • New Volume Shadow Copy Age check for Windows volumes — Reports how old the newest shadow copy is on each Windows volume that has one — an early warning for backups and Previous Versions that have quietly stopped working.
  • vCenter check reads ESXi host hardware temperature sensors — It now judges every temperature sensor against the ESXi host's own firmware health.
  • Open a past check result from the History view — Click a point on the history chart or a row in "History" to reopen that run's full result details instead of just its time and status; 51 more checks now carry that per-run detail.
    Open a past check result from the History view
  • Ignore a single Lywand vulnerability from the device page — It stops counting toward the device's score but stays listed as "Ignored", and you can un-ignore it later.
  • A Managed Lywand Score card on the customer dashboard — Customers with a Lywand assessment get a "Managed Lywand Score" card first — an A–F grade covering only the findings on products in your Lywand service package.
  • Zip and extract files in the remote file explorer
  • Wake an offline device — Choose "Wake device" and octoja sends a Wake-on-LAN packet from another online device sharing the target's subnet, or name the sender via "Wake using a specific relay". A gateway monitored over TR-064 also offers "Send Wake-on-LAN" for the inactive clients in its "Connected clients" table.
  • Reuse an existing enrollment token when setting up deployment — The deployment configuration dialog gains a "Use existing" tab alongside "Create new".
  • New Lightning Radar check warns about nearby lightning strikes — Enter an address or coordinates, or switch on "Use device location"; the result view plots the nearest strikes, names the closest one's distance and direction, and shows a thunder countdown to when its thunder would be heard.
  • Connect DocBee with an access token instead of a username and password — The integration then runs on a token rather than a stored account password.
  • Save your display language to your profile — octoja then applies your choice wherever you sign in, not just in the browser where you picked it.

Improved

  • Faster dashboard — The dashboard opens roughly two to three times faster and stays responsive as you scroll long device lists.
    Faster dashboard
  • Group permissions now use access levels — Group permissions moved to their own "Permissions" tab, where each row has a single access-level picker — "No access", "Read" or "Read & write" — instead of a long checkbox list.
    Group permissions now use access levels
  • Audit Log now records more than 85 administrative actions — Integrations, webhooks, enrollment tokens, alert configurations, patch cycles and more are now covered, and edits name the field that was touched.
  • Per-device Asset Logs record remote actions and check changes — A device's "Asset Logs" now capture ad-hoc script runs, test package deployments and opening the "Web Console".
  • Lywand vulnerabilities split into managed and unmanaged — A new "General view / Managed / Unmanaged" filter separates findings on products you cover (managed) from those outside your support scope (unmanaged); the "Managed Lywand Score" counts only the managed ones.
  • Patch policies: optional deployment rings and hourly maintenance windows — Turn off "Use deployment rings" to patch every covered device together in a single maintenance window, and windows can now repeat as often as hourly.
  • Schedule automations and reports to run every few hours — Automation triggers, a config package's "Schedule override" and report schedules now offer the "Every few hours" mode, repeating every 1, 2, 3, 4, 6, 8 or 12 hours.
  • Rule builder suggests real fleet values and previews matches — Application and service conditions now suggest names actually found across your fleet with a device count each, preview which devices match, and a new "All Devices" template matches every device; the chassis-type condition also offers a pick list instead of free text.
  • Rule templates in automation targeting and group device access — "Add from Template" now also appears under "Target devices" for an automation and "Device rules" for a permission group.
  • Case comments update live — New comments appear in an open case automatically, with no reload — whether from a colleague or the person who reported it.
  • Smoother remote desktop on slow connections — When the viewer cannot keep up, octoja lowers the frame rate and skips frames instead of building a backlog, then recovers with a fresh full image.
  • Lists fill the page height with pinned column headers — Long lists use the whole window and keep column headers pinned as you scroll, so you don’t lose track of which column is which.
  • The whole device row is clickable, not just the name — This applies in the device list and the Inventory "Hardware" tab; middle-click or Ctrl-click opens the device in a new tab.
  • Check Library is faster and more informative — The Check Library opens noticeably faster and adds a sortable table view alongside the cards, and clicking a check opens a read-only preview of its full configuration.
    Check Library is faster and more informative
  • TV View runs as a full-screen wall board — The dashboard TV View now fills the entire window with no sidebar or app header, shows your branding logo, and adds a "Fullscreen" toggle.
    TV View runs as a full-screen wall board
  • Failed Logon Alert is now Failed Logins, and covers Linux and macOS — It lists each failed attempt with time, user, origin and logon type, and uses its own time window and minimum count per severity.
  • SentinelOne now reports a clear threat status — The SentinelOne check now reports a "Threat status" of "None" or "Not mitigated" on Windows and macOS, instead of counting quarantined files that linger after a threat is contained.
  • Network Firewall check adds Sophos XG / XGS over SNMP — The "Network Firewall (Appliance)" check adds "Sophos XG / XGS (SNMP)" alongside the local variant, reporting CPU, memory and disk use, uptime, VPN tunnels and interfaces.
  • Altaro and Hornetsecurity VM Backup 9 report in more detail — The Altaro Backup check now reports "Local backup", "Offsite copy" and "Restore / verification" separately, each with its last success, recognises Hornetsecurity VM Backup 9 too, and shows the reason (VM name and message) on a warned or failed backup.
  • TERRA CLOUD Backup adds Hyper-V and expected backup days — The TERRA CLOUD Backup check now covers Hyper-V backups per virtual machine, and "Expected backup days" with a "Grace period (hours)" govern when a backup counts as "Overdue".
  • Windows event log check can include events, not just exclude — Matches on event ID, source and message text, and „Minimum severity" now extends coverage through Information and Verbose.
  • Network Interface check can ignore dead ports — An „Interfaces to ignore" option suggests the device's last-seen interfaces, so disconnected ports stop alerting while unlisted ones stay monitored.
  • UniFi (SNMP) check can watch specific interfaces — Pick the ports the check should monitor, so on busy switches it reports only the interfaces you care about.
  • System Updates can count optional and preview Windows updates — Turn on „Show advanced options", then „Include optional / preview updates (Windows)" to count optional, non-security updates like preview cumulative updates.
  • QNAP check reports RAID health per storage pool — A "Storage Pools" section flags a degraded or rebuilding array as Critical, so you don't have to open the NAS interface; CPU temperature also gains its own warning and critical thresholds.
  • Printer (SNMP) check picks up Brother toner and jam detail — Reads per-colour toner state, a paper-jam warning with location, and a „Colour" versus „Mono" page split from Brother printers.
  • MailStore SPE check adds archiving runs and certificate expiry — „Check archiving profile runs" flags profiles whose latest run failed, and „Monitor certificate expiry" warns before the SPE management server's certificate expires.
  • Custom checks can run longer than five minutes — A new „Timeout (min)" field accepts up to 60 minutes; existing checks keep the five-minute default until you change it.
  • Manual check runs name the real failure reason
  • Monitoring checks wait five minutes after a device restarts — This way a check's first result reflects a fully started system rather than one still booting; manual runs stay immediate.
  • Remote actions and single sign-on linking show the real error
  • Tracked Time, Logs and Inventory History move under Activities — The device page now groups these into a single "Activities" tab with sub-tabs, and old links still open the matching sub-tab.
  • TANSS setup now takes a 2FA code and an ERP API token — "Set up TANSS" takes both from your TANSS configuration, and octoja keeps the session alive on its own.
  • Agent logs survive updates and include check diagnostics — "Download logs" now returns error output from monitoring checks and background tasks too.
  • Add your own parameters when creating or editing a package version — Define your own package parameters on any version of a custom package, not only while creating the package itself.
  • More config package templates: physical servers, Hyper-V and warranty — "Start from Template" on "Config Packages" now also offers "Physical Windows Server Add-on", "Hyper-V Host", "Hyper-V Virtual Machine", "Lenovo Warranty" and "Wortmann / TERRA Warranty".
  • Clearer reasons when a macOS update cannot be installed — A failed macOS update now shows the actual error, and updates that macOS will only install for a signed-in user are now listed as "Not Applicable" rather than "Failed".
  • Add network device preselects your customer and site — "Add network device" preselects the customer and site you filtered by, lists only that customer's devices in the "Monitoring" picker, and adds "IP Camera" as a device type.
  • Remote Desktop only appears on Windows devices — On Linux and macOS the entry led nowhere, so nothing is lost.
  • Customer and site lists appear in alphabetical order — Sites on the customer edit page and the integrations' site pickers, plus the customers list, now sort by name regardless of capitalisation.
  • Device tag rows adapt to the width instead of cutting off at three — A count badge opens the ones that don't fit.

Fixed

  • Built-in patch-policy templates with tag-based rings work again — A policy created from one used to produce no patch cycles at all.
  • Scheduled patch cycles no longer run twice, or repeat after a restart
  • Checks from a config package template now use their real defaults — Any setting a template leaves out now comes from the check's own defaults instead of falling back to zero.
  • A config package can no longer assign the same check twice
  • Windows devices report every pending update again — Update sources are now scanned in parallel with a 120-second per-source timeout, so a slow source is no longer dropped from the scan.
  • winget updates report a failure instead of a false success
  • Bitdefender GravityZone servers are no longer flagged as unprotected
  • Bitdefender and Securepoint checks stop reporting stale threats — Both now count only quarantine entries from the last 24 hours instead of the entire local vault, and the window is adjustable.
  • Rules match Sophos firewalls and other agentless devices — Rules filtering on "Manufacturer", "Model" or "Serial Number" now match agentless devices such as firewalls, switches and routers.
  • Automation installs no longer hang at "Running" — Software-install steps now run as background jobs that report back on completion, so the step shows its real outcome.
  • The TANSS integration now works against real TANSS servers — Requests now use the "/backend" prefix live servers serve under, and the beta integration was rebuilt and checked against a live instance.
  • Multi-language MSI installers import correctly
  • Windows and Mac devices report their real name — Windows names longer than 15 characters now report in full, and Macs keep their stable System Settings name instead of flipping to a generic "Mac".
  • Ubuntu 26 and newer Linux devices list their physical drives again
  • Firewall Status check stops warning about healthy Windows firewalls — The check now reads the firewall state from the Windows registry instead of a service-and-WMI query that collapsed every failure into the same warning.
  • ESET and Veeam checks name the real error instead of a false alert — A failed local query used to raise a critical alert whose empty health fields looked like protection was switched off.
  • SMTP, FTP, IMAP, POP3 and SSH checks show their results again
  • Failed runs show the right colour in a check's "History" view
  • A check you start by hand gets its full time limit — A manually started check now waits its full configured time limit, up to about an hour, instead of reporting a false failure after 30 seconds.
  • Scheduled reports run at the time you set — Reports now send in your instance's time zone instead of UTC.
  • FortiGate and Check Point firewall checks show their own settings — Picking FortiGate (SNMP) or Check Point (SNMP) as the "Vendor" now shows the settings that belong to them, including the SNMP community string and the v3 credential fields.
  • WatchGuard CPU readings are no longer pinned to 100%
  • QNAP NAS check no longer reports empty drive bays as "Critical"
  • Drives without SMART data now report "OK" instead of a warning
  • UniFi (SNMP) checks on large switches return results again
  • "Save" works when overriding a check on a network device
  • Rotated and portrait monitors on Windows display upright
  • Devices return to their original screen size after a session
  • Typing in PowerShell no longer inserts stray "@" characters
  • Remote sessions no longer drop when the session list refreshes
  • The on-screen notice names every connected technician — When several technicians connect to the same machine at once, the on-screen notice now lists all their names instead of only one.
  • TV View shows accurate, clearly coloured status — TV View no longer counts checks removed from their config package, tiles show green at zero, and "Servers offline" turns red when a server goes down.
  • Reuse one email, Teams or webhook target across alert channels — The same email recipient, Teams channel or webhook can now sit at both "Warning" and "Critical" and escalate independently.
  • Changing a check's alert settings no longer leaves alarms open forever — Detaching or changing a check's alert configuration now ends its open alarms and closes the linked PSA tickets, and a dialog warns you first how many active alarms that affects.
  • Automations no longer print literal placeholders for a missing customer — When a device has no customer assigned, customer and site values now render empty in generated Cases, Teams messages and webhooks instead of raw placeholder text.
  • "Run script" steps set to "Logged-in user" work on Windows again
  • The service list is complete again and the "Start Type" picker stays usable — The "Services" tab now lists everything the machine is currently reporting, and the "Start Type" dropdown stays open while you choose.
  • Long-offline devices no longer count toward your usage — Usage counts sent to octoja now include only devices seen in the last 90 days.
  • Account scope now hides "Add Customer" and "Import Customers" — These actions and clearing a customer now require access to every customer; limited accounts have the first two hidden and the third refused.
  • Autotask, HaloPSA and Lywand customer matching gains a usable menu — "Auto-match by name" and "Show only unmatched" have moved into the customer-matching dialog's "…" menu.
  • "Custom Domain" now shows the correct CNAME "Target" — The "Target" now comes from your instance's configured address instead of echoing whatever address you were browsing.
  • "Feedback portal" and "Help & docs" now open with you already signed in
  • "Kill process" confirmation stays open while the list refreshes
  • Dropping several files on a single-file upload area now warns you — Dropping more than one file now shows "Only one file can be uploaded at a time." instead of quietly keeping the first.
Write a comment...

July 11th, 2026

New

Improved

Fixed

Highlights

This release widens what octoja can watch and makes big lists easier to live with. You can now monitor whole classes of equipment without installing an agent — network switches, routers and firewalls, VMware hosts, even FRITZ!Box gateways — and a broad wave of new checks covers databases, printers, backups, disks, network services and more. A new full-screen TV View puts your fleet's warnings, critical issues and offline servers on one board, while the device list gains bulk actions, optional columns and the same controls now shared by every list in the product. The rest is polish and reliability — steadier remote desktop, calmer inventory history, and a long tail of check-accuracy fixes.

New

  • Monitor network devices without an agent — You can now add and monitor network devices — switches, routers, firewalls, printers and other agentless equipment — without installing an agent; a designated agent monitors them on your behalf. Each device offers SSH, SNMP and an experimental Web Console (open the device's web admin interface securely tunnelled through its monitoring agent) from its hover card and the command menu, shows its IP in device lists, and can be isolated with a new Network device-type filter on the dashboard.
    Monitor network devices without an agent
  • Manage VMware ESXi and vCenter — You can now add VMware ESXi hosts and vCenter servers as agentless devices and manage them from octoja: live host CPU, memory and performance metrics, virtual-machine inventory, datastores, and power control to start or stop VMs. A Test connection button lets you verify host access before saving.
  • Monitor FRITZ!Box-class internet gateways without SNMP — octoja can now inventory FRITZ!Box-style internet gateways over TR-064 when SNMP isn't available, pulling device details directly from the gateway. The add/edit network-device form gains Test connection buttons for both SNMP and TR-064 so you can confirm access before saving.
  • New TV View for live fleet status — The new TV View puts your fleet's active warnings, critical issues and offline servers on a full-screen board — colour-coded tiles above a sortable, filterable table whose rows link straight to the device. New issues flash briefly as they arrive and can play a configurable alert sound when a critical issue appears or a server goes offline, and the list scrolls while the header, tiles and pagination stay pinned. It auto-refreshes and is gated behind its own permission.
    New TV View for live fleet status
  • New database monitoring checks — You can now monitor your database servers. Microsoft SQL Server gets a Health check (service and connectivity, database status, backup age, disk space, failed Agent jobs, Always On) and an Activity check (blocking sessions and severe error-log entries), while PostgreSQL and MySQL/MariaDB each get a health check (reachability, response time, active sessions, size/uptime) plus a check that runs your own read-only query and alerts on its row count or run time. Query checks run read-only, so they can never change your data.
  • New printer monitoring checks — You can now monitor printers three ways: a network-printer check over SNMP (v2c and v3) reports status, remaining toner and consumable levels and the lifetime printed-page count; a local-printer check watches Windows-installed printers for error states (out of paper or toner, jams, offline, service required); and a print-queue check for print servers alerts on offline printers, errored or blocked jobs, or a backed-up queue.
  • New disk and storage monitoring checks — Several new checks watch disks and storage. Disk Presence tracks the physical disks in a device and alerts when one is removed, reporting serial and model (external/USB drives ignored by default). Others verify BitLocker encryption on fixed drives, flag a volume scheduled for a chkdsk repair at next boot, measure disk fragmentation (SSDs excluded), watch free space on folder-mounted volumes that ordinary disk checks overlook, and report Windows Storage Spaces pool and virtual-disk health.
    New disk and storage monitoring checks
  • New backup monitoring checks — New checks keep an eye on backups. A Xopero ONE check watches the Backup & Recovery Agent on Windows, Linux and macOS, flagging failed or overdue backups and naming the affected plan; two TERRA CLOUD checks cover backup job status (result, age, error/warning counts, ransomware-detection state) and satellite replication health; and a shadow-copy writer check flags problems with the Windows Volume Shadow Copy writers backups rely on — an early warning of backup failures.
  • New network and internet service checks — A family of new checks watches network services by connecting to them and alerting when one is unreachable, times out or responds incorrectly: SMTP, IMAP and POP3 mail servers, FTP and SSH servers, and a TCP port check for any host and port. A DNS check resolves hostnames and alerts on failures, slow lookups or unexpected addresses, and a domain-expiry check warns before a domain registration lapses. Most are cross-platform and let you require a specific response banner.
  • New Windows Server infrastructure checks — New checks cover Windows Server roles: DFS Replication backlog between two members, DHCP scope utilization (how full each address pool is), WSUS health (last sync result and age plus managed-computer compliance — how many have update errors, still need updates, or have stopped reporting), and network-adapter team health (degraded or down teams, with active member count).
  • New Windows system and activity checks — New checks report on day-to-day system state: system uptime (cross-platform, to catch missed reboots), whether a machine is waiting for a reboot and why, named Task Scheduler tasks that failed or were disabled, the health of the Windows Update agent itself, active and disconnected terminal/RDP sessions, and who is interactively logged on (with modes to warn when someone is or isn't present).
  • New custom and advanced metric checks — For monitoring beyond the built-in checks, you can now run a read-only WMI query, sample any Windows performance counter, watch a specific process's CPU usage across all cores, count files in a folder (too many for a stuck spool, too few for missing output), check whether specific files or folders are present or absent, and monitor Microsoft Message Queue depth — each alerting on your own thresholds.
  • New security monitoring checks — Two new Windows checks help you spot attacks and misconfiguration: a failed-logon check counts failed sign-in attempts over a window you choose and alerts when the volume looks like a brute-force attempt, and an AppLocker check counts blocked-application events (optionally including audit-mode) so you notice when software is being blocked or policies are wrong.
  • New change-detection monitoring checks — New stateful checks alert you when something you're watching changes: the contents of files or folders, Windows registry values (useful for autorun and security-policy keys), or file/folder access permissions on Windows and Unix. Each offers an “accept current” option to acknowledge an expected change and reset the baseline, so you're only alerted on the next one.
  • Lenovo hardware warranty monitoring — You can now monitor Lenovo hardware warranty expiry. A new check reads the device's serial number, looks up the warranty end date and warns you a configurable number of days before it expires. It uses the latest end date across base, extended and contract coverage, so purchased extensions are not reported as already expired, and warranty dates delivered in different formats now render correctly.
  • Bulk actions on the device list — Turn on Multiselect from the device list's menu to pick several devices at once, then assign them all to a customer or assign tags in a single action from a floating selection bar. Devices you aren't allowed to edit can't be selected.
  • See and undo per-device check overrides in config packages — The Checks tab of a config package now flags how many devices have drifted from the package with an overrides badge on each check. Open it to see which devices changed a check — disabled it, or overrode its inputs or alert thresholds — compare their settings against the package, and pull a single device or every drifted device back to the package config in one step.
  • Change service startup type from the Services tab — On a device's live Services tab you can now change a service's startup type between Automatic, Manual and Disabled, alongside starting and stopping it. Available on Windows devices when you have permission to control services.
  • Read-only access to the customers area — You can now give technicians read-only access to the customers area with a new view permission, separate from the permission to create or edit customers. Previously the whole area required manage access, so technicians without it saw nothing; on upgrade, existing users who could manage customers keep their access automatically.
  • Let users postpone a patch restart — When installing patches needs a reboot, the person signed in to the device can now be prompted to delay the restart a limited number of times before it goes ahead. You set how many times they can defer and how long each delay lasts per patch-policy ring, and the countdown survives a routine agent restart. Off by default.
  • Lock down the Windows Update interface from a patch policy — A new patch-policy option lets you disable the Windows Update interface on managed Windows devices. When turned on, the Windows Update settings page is hidden and manual scans and installs are blocked, so users can't patch outside your policy; it applies only while the policy owns the maintenance window and reverts automatically afterward.
  • Ready-made templates for patch policies and automations — Creating a patch policy or an automation is faster with built-in starter templates. Pick from ten curated patch policies (staged rollouts, rapid deployment, compliance, servers) or thirty automation templates (device onboarding, scheduled maintenance, software hygiene) and clone one as your starting point instead of building from scratch.
    Ready-made templates for patch policies and automations
  • New "Ensure Lywand agent" automation action — You can add an “Ensure Lywand agent” step to an automation that checks whether the Lywand security agent is installed on a Windows device and silently installs it if it's missing, using the customer's matched Lywand license. If the install fails, the run records the underlying installer error so you can see why.
  • New automation step: add or remove a tag — Automations can now add or remove a tag on a device as part of a run. A condition on the step decides whether to add or remove, so one automation can tag the devices that match a rule and untag the ones that don't. Only tags you manage are touched, not ones derived automatically from inventory.

Improved

  • Consistent, more capable lists across octoja — Every list in octoja — devices, Cases, patches, customers, reports, admin and the device-detail tabs — now shares the same controls: resize, reorder and hide columns, search from the toolbar, and export the full list (not just the current page) to CSV. Many lists can also switch to a card view, and the device-detail Tracked Time, Updates and Cases tables are now searchable.
    Consistent, more capable lists across octoja
  • Choose which columns to show in the device list, and page size — The device list now offers roughly 30 additional optional columns — manufacturer, model, serial, device type, CPU, RAM, storage, domain, OS build, uptime, IP addresses, agent version, tags, dates and more — that you can show or hide from the column menu. A new page-size selector lets you view 25, 50, 100, 250 or 500 devices per page.
    Choose which columns to show in the device list, and page size
  • New device-targeting fields in the rule builder — You can now target devices in rules by chassis type, whether they have a battery (laptops vs desktops), directory membership (Workgroup, Domain, Azure AD, Hybrid), serial number, agent version and OS architecture. These fields work everywhere rules apply, including config packages, tag rules, patch policies, automations and device group access.
  • Device aliases shown everywhere — Device aliases now appear everywhere a device is named — check alert emails, push and Teams notifications, reports, Cases, time entries, dashboards and device pickers — not just the main device and inventory lists. Lists sort by the displayed name where possible, and automations can reference the alias with a new deviceAlias token while the device-name token still resolves to the real hostname.
  • Audit log now covers admin changes across the platform — The admin audit log records much more than before. Changes to branding, config and custom packages, custom checks, automations, users, customers and patch policies are now logged, each entry showing which item was changed.
    Audit log now covers admin changes across the platform
  • More control and detail in webhooks — In a webhook's settings you can again pick which events it delivers from a simple checklist, and you can leave inventory updates unselected to create a webhook that carries only monitoring-check alerts. Check-alert messages (failed, warning and recovered) now also include the device name and the customer's name, ID and external reference, so you no longer have to cross-reference a separate inventory message to see which customer an alert belongs to.
  • Securepoint and ESET antivirus checks now run on the device — The Securepoint Antivirus Pro and ESET checks now run directly on each Windows device through the product's local interface instead of pulling status from a vendor cloud portal. Monitoring is more reliable and no longer needs the Securepoint or ESET PROTECT integration connected in admin settings — both integration cards have been removed and your existing checks keep working automatically.
  • RAID check names the failed disk — The RAID check now lists the individual disks in an array and names the exact disk that has failed or degraded, across ZFS pools, Linux software RAID and Windows Storage Spaces. Degraded arrays are detected reliably on more Linux distributions, and a disk logging errors while the pool still reads healthy is now flagged as a warning.
  • Firewall check adds Securepoint and Check Point — The firewall monitoring check now covers Securepoint UTM and Check Point appliances alongside the existing vendors. It reports firmware and update state, license expiry, VPN tunnels, cluster and failover status, and CPU and memory usage, plus disk usage on Check Point.
  • Exclude specific event IDs in the Event Log check — The Event Log check can now exclude individual event IDs, optionally only for a specific source, so you can silence known-noisy events without switching off the whole check. It also reports when it cannot read the event log instead of failing silently.
  • Full check output always visible — Large check outputs are no longer hidden behind a “truncated” banner. The full latest result is now always shown at full size, while only the stored history is trimmed. Updating the agent is required for this to take effect.
  • Clearer Last Seen vs Last Inventory columns — The device list's “Last Reported” column is now labelled “Last Inventory”, and both it and “Last Seen” have tooltips explaining the difference: Last Seen is the most recent contact of any kind and drives online/offline status, while Last Inventory is the last full hardware and software inventory upload, which can lag behind.
  • Cleaner device inventory history for changed services — When a Windows service changes its configuration (for example its startup type), a device's inventory history now shows a single “changed” entry instead of a confusing pair of “removed” and “added” lines.
  • Resolving a vulnerability no longer freezes the app — When you resolve a vulnerability finding on a device, the app no longer locks up while the fix runs. The dialog now closes immediately and a notification reports success or failure when the device finishes, instead of dimming the whole screen for up to several minutes.
  • Edit report-schedule recipients inline — Adding and editing recipients on a scheduled report now happens directly in cards on the schedule page instead of a separate popup. Each card lets you pick a customer, site and email addresses, and a single Save persists the whole schedule. A note clarifies that recipients are set per customer.
  • Warning before leaving a page with unsaved changes — octoja now prompts you before you navigate away or close the tab with unsaved edits open. It covers the customer, user, group, patch policy, report template, report schedule, custom check, config package, tag rule and automation editing pages, so you no longer lose work by clicking away by accident.
  • Open any list row in a new tab — You can now middle-click or Ctrl/Cmd-click a row in any list to open it in a new browser tab, exactly like a normal link. Left-click still opens it in place.
  • See the full customer or site name in the dashboard tree — Long customer and site names in the dashboard tree were cut off with no way to read them. Hovering or focusing a row now shows the full name in a tooltip.
  • Confirm before uninstalling software from a device — Uninstalling a package from a device's software list now asks you to confirm first, guarding against an accidental removal.
  • Software Kiosk toggle when creating deployments — You can now set “Show in Software Kiosk” while creating a software deployment, not only when editing one, and deployment rows now show a badge indicating which packages are visible in the kiosk.
  • Automations can update all outdated software at once — Software-installation automations gained an “update all outdated” mode that upgrades every outdated package a device reports, instead of naming a specific package. In this mode the form hides the version and package-name fields.
  • Clearer DocBee connection-test errors — When a DocBee integration connection test fails during setup, octoja now shows the failure in a clear alert with a hint to double-check the base URL — it usually needs to end with /restApi and the casing must match exactly.
  • Faster file downloads in deployments and scripts — Software deployments, custom checks and installer scripts that download files complete noticeably faster on Windows.

Fixed

  • Devices no longer disappear after their customer is deleted — A device that reconnected after its assigned customer had been deleted could vanish from every view and stay hidden permanently. These devices now stay visible and can be reassigned, and any already-affected devices are restored automatically.
  • Remote desktop recovers cleanly when a user logs off — If the signed-in user logs off, the device restarts, or the remote session disconnects during an active remote-desktop session, the viewer no longer freezes on the last frame. It now shows a clear “the remote session ended” message and returns you to the session chooser so you can reconnect to the login screen or another session.
  • On-device prompts and indicators follow screen changes — After a screen-resolution change, the octoja agent's notifications, consent prompts and the remote-desktop session indicator now appear in the correct place on screen instead of floating mid-screen. Open overlays also reposition immediately when the resolution changes during a session.
  • macOS agent interface no longer stuck in a restart loop after an update — On macOS, the octoja agent's on-device interface could get caught in a restart loop after an update. The agent now repairs itself before launching the interface, so it opens normally.
  • Pending updates no longer flicker away on a scan hiccup — The Updates tab on a device no longer briefly empties or shows every pending update as removed when an update scan hits a temporary error. The previously known list is kept until a scan genuinely completes.
  • Dashboard check-type and severity filters now match per check — When you filter the dashboard by a specific check type together with a severity, the severity now applies to that check's own result. Previously, combining an “online” check filter with “Critical” also returned devices whose online check was fine but that had some unrelated check in a critical state.
  • Device Checks badge ignores disabled checks — The warning and error count badges on a device's Checks tab now ignore disabled checks, so they reflect only the checks that are actually running.
  • SMART check recovers immediately after a disk is removed — Fixed the SMART disk-health check staying red for up to three days after you removed or decommissioned a disk, which had hidden the health of the remaining disks. Disk-removal detection now lives in its own check, so SMART recovers as soon as the surviving disks are healthy.
  • Veeam backup check no longer fails on healthy machines — The Veeam Backup Agent check no longer reports a failure on machines whose backups are actually fine. Previously it could stop early and show an error instead of the real backup status; it now finishes and reports the correct result even when a single event-log entry can't be read.
  • HP iLO check stops false-alarming on servers with empty bays — The HP iLO hardware check no longer raises a permanent warning on HP ProLiant servers that have empty fan or power-supply bays. Empty bays are now hidden and ignored, while genuine fan, power, memory, drive and temperature faults still alert.
  • MailStore SPE user-count check now works — The MailStore Service Provider Edition (SPE) check used to fail every time instead of returning results. It now runs correctly and reports how many users are in each MailStore instance.
  • Accurate example payloads in webhook help — The webhook help dialog now shows correct example payloads for every event that carries data — inventory updates and all check alerts — including the new device and customer fields. Previously the check-alert examples were the wrong shape and only the inventory example ever appeared.
  • Links to ticketing systems and notifications respect your custom domain — Device, object and remote-support links that octoja passes to connected ticketing systems and notifications now use your configured custom domain instead of falling back to an octoja.cloud address. Previously customers on a custom domain received links pointing at the wrong domain.
  • Clearer empty alert channel targets — When editing an alert's notification channels, a target you haven't picked yet now shows a readable “select a channel” prompt instead of a meaningless string of zeros.
  • Automation and schedule configuration polish — Cleaned up the automation and schedule configuration screens. The schedule-override popup no longer runs off the edge in narrow panels, human-readable schedule descriptions now appear in your language on every page, the options for linking an existing automation are fully translated in German, French and Dutch, and a step you haven't renamed no longer shows its type label twice.
Write a comment...

July 6th, 2026

New

Improved

Fixed

Highlights

This release sharpens reporting and remote support. Reports gain a device-availability widget and a dedicated set of Sophos widgets with a ready-made template, so you can show uptime and protection at a glance. Remote desktop is steadier all round — the "connected" notice now stays with the person being helped, sessions no longer fail to start on some machines or lock mid-session, and they fill the screen properly on high-DPI displays. Underneath sit a batch of monitoring-check accuracy fixes for Sophos and Cove Backup, calmer device inventory, and smaller polish across rules, patches, webhooks, and integrations.

New

  • New "Availability" widget for reports — Build reports that show, at a glance, the percentage of time your devices were online over the reporting period. Add the new Availability widget and optionally limit it to specific devices. It counts only devices that have the “Device online” check assigned. Read more

    New "Availability" widget for reports
  • Dedicated Sophos widgets and a ready-made Sophos report — Reports can now show Sophos antivirus detail directly: add the “Sophos protection active” KPI and the “Sophos status (table)” block, which lists each device's real-time protection, definition currency, detected threats, health and product version. A built-in “Sophos Report” template combines both, so you can add a finished Sophos report without building it from scratch. Read more

Improved

  • Webhook inventory updates only fire when device details actually change — If you send device inventory to another system through a Webhook, octoja now only delivers an update when a device's core details — its hardware, network adapters, or identifying information — actually change. Routine background changes like a new installed program or a pending update no longer trigger a fresh delivery every hour, so the receiving system gets far fewer redundant inventory updates. Read more

  • Rule builder flags conditions that are missing a value — When you build a rule and pick a field and operator but leave the value blank, that condition now stands out in amber with a warning icon and a hint, so you can spot and finish incomplete conditions before saving. It works everywhere you build rules, including config packages, patch policies, tag rules, and access groups. Read more

  • Kiosk and ticketing settings now follow the tray icon — In device and configuration-package agent settings, “Software kiosk enabled” and “Ticketing enabled” now sit under “Show agent in system tray” and grey out when the tray icon is turned off, since both features only reach people through that icon. Read more

    Kiosk and ticketing settings now follow the tray icon
  • Tidier help menu in the header — The row of look-alike icons in the top bar has been cleaned up: Feature Request stays as its own button, and Tickets, Feedback portal, and Help & docs now sit together under a single “…” menu, each shown with a clear label so the options are easy to tell apart. The old Community link has been removed.

Fixed

  • Remote desktop notice now reaches only the person being helped — On shared machines where several people are signed in at once, the on-screen notice that a technician has connected — including the technician's name — used to appear for everyone, not just the person actually being helped. It now shows only to that person, so a technician's name is no longer visible to other signed-in users. Read more

  • Remote desktop no longer fails to connect on some machines — Remote desktop sessions could fail to connect on certain devices — often at the Windows login screen — with a “Connection failed” error. Sessions now automatically switch to a working video method when the first one can't start, so the connection goes through.

  • Remote machine no longer locks mid-session — Fixed an issue where the remote computer could unexpectedly lock in the middle of a remote desktop session, especially when switching between the machine's monitors. The “Lock remote on disconnect” setting now stays in sync for every technician viewing the same session, so it only locks when the session actually ends.

  • Remote Desktop shows the full screen on high-DPI displays — On devices with scaled or high-DPI monitors, a Remote Desktop session could show only the top-left corner of the screen instead of the whole display. The full desktop now appears correctly.

  • Revoke button now appears on the Installation Tokens page — The button for revoking an installation token was missing from the Installation Tokens page, so there was no way to turn off a token from the list. It now shows up in a labeled Actions column next to each token. Read more

    Revoke button now appears on the Installation Tokens page
  • Imported customers now appear for team members with group-limited access — Customers added through Import Customers could stay hidden from team members whose view is limited to specific groups, even though the customers imported successfully. Bulk-imported customers now show up for everyone who should be able to see them, just like customers you add one at a time. Read more

  • Integration customer-matching count now respects your access — On an integration's Customer mapping card, the “X of Y customers matched” count now reflects only the customers you can access, instead of showing the total for the whole account. Team members with limited access no longer see a total that includes customers outside their scope.

  • More reliable Sophos protection reporting — The Sophos check now reports an accurate definitions date, no longer flags a false warning on Windows Servers where it couldn't read how current the definitions were, and no longer comes back empty on certain Sophos versions. Read more

  • Cove Backup check no longer flags healthy backups — The Cove Backup monitoring check sometimes showed a warning even when a device's backups had completed successfully. It now reads the backup history correctly, so healthy backups report as healthy. Read more

  • No more phantom "Last boot" changes in device history — A device's inventory history no longer fills up with repeated “Last boot” change entries where the before and after times are the same. The recorded boot time now stays put between restarts, so the history only shows a change when the device actually reboots.

  • Patch screens display correctly with large policies and long update names — The Emergency rollout dialog no longer runs off the screen when a policy has many updates or rings — its contents now scroll and the Cancel and Create buttons stay reachable. In the Update Catalog, the update column is now wide enough that titles are no longer cut off, including in the per-policy view. Read more

    Patch screens display correctly with large policies and long update names
  • Command bar stays ready to type — Opening the command bar with Ctrl+K now reliably lets you start typing right away. Previously the help widget loading in the background could quietly take the keyboard, so your first keystrokes went nowhere until you clicked back into the search box. Read more

  • More reliable agent installs on Linux and Windows — Installing the octoja agent now works on ARM-based Linux devices like Raspberry Pi, which were previously rejected, and on minimal Ubuntu servers that lack the unzip tool and used to fail during install. On Windows, if a firewall, proxy, or web-protection product intercepts the download and returns a fake page instead of the installer, you now get a clear message pointing at the likely cause instead of a confusing error. Read more

Write a comment...

July 1st, 2026

New

Improved

Fixed

On 1 July at 2 PM CEST, we present this release and much more in the octoja webinar.

https://us05web.zoom.us/webinar/register/WN_6RqlhYeaRL6DxbiTv_5hrA#/registration

Highlights

This is octoja's biggest release yet. The headline is Automations, a visual workflow builder that lets you wire triggers, conditions, and a growing library of actions into workflows that run across your devices. Alongside it comes a self-service app that lives right on your team's computers, on-device antivirus checks that no longer depend on a vendor cloud, one-click vulnerability fixing, scheduled report delivery, and an audit log for administrative changes. Tables across the whole product now sort, filter, and export the same way, the device page gained live per-adapter network speed and a full inventory history, and there's a long batch of patch-management, remote-desktop, and cross-platform reliability work underneath. The rest is polish and stability throughout.

New

  • Automations: a visual workflow builder — Build multi-step workflows that run across your devices under Configuration → Automations. Drag actions onto a flow canvas, pick a trigger (Device added, on a Schedule, or Manual), and choose which devices it targets, with a live preview of exactly which devices match before you save.
    Automations: a visual workflow builder
  • A library of automation actions — Each workflow runs an ordered list of actions on every matched device: run a script, install software, restart or shut down the device, send a webhook or Teams message, or open a ticket. Add a condition so a step only runs when it should, pass one step's result into the next, and use Test run to try the whole thing against a single device, watching each step on a live timeline before you commit.
  • A self-service app on your team's computers — octoja now installs a small desktop app on each managed device so the people using those computers can help themselves: open support requests and follow the helpdesk's replies, with a desktop notification when an answer arrives. It carries your own branding and a product name you choose, and sits quietly in the system tray, always a click away.
  • A software kiosk for self-service installs — The desktop app includes a Software Kiosk: a curated list of the apps you've approved for that device. People browse or search it and install with one click, so routine software requests never have to reach you, and each entry shows whether it's already installed or has an update available.
  • Audit log — A new admin-only Audit Log page records notable administrative changes, starting with who opened or restricted device enrollment, and when.
  • Resolve a vulnerability in one click — On a Windows device's Vulnerabilities tab, each finding now has a Resolve button: octoja matches the vulnerable product to the installed software, updates or removes it, and re-scans so the finding clears. No more jumping to software management to guess the right package.
  • New monitoring checks — Fresh coverage joins the catalog: a UniFi Access Point (SNMP) and a UniFi Switch (SNMP) check for full per-device health where the generic UniFi check came up blank, a G DATA Antivirus check running directly on the device, and a server-side Lywand Vulnerabilities check that turns each device's scan results into a monitored alert. The Network Firewall (Appliance) check also gains WatchGuard and SonicWall as SNMP options.
    New monitoring checks
  • c-entron Service-Board integration — Connect c-entron Service-Board so a check alarm automatically raises a ticket on the matching customer and a recovery closes it, with customer matching and ticket type, priority, and category mapping under Administration → Integrations.
  • Schedule and email your reports — You can now have report PDFs generated and emailed automatically on a recurring schedule. Open Scheduling on the reports page, pick which templates to send and who receives them, and octoja emails the report PDFs to your recipients each time it runs.
    Schedule and email your reports
  • Live network speed, now per adapter — The live Network card on a device page shows throughput for each network adapter separately instead of one combined figure, so the speed you see reflects real traffic rather than being inflated by stacked virtual interfaces. When a device has several adapters you can pick which to watch.
  • Inventory history for every device — A new Inventory History tab shows a timeline of what changed and when: installed and removed software, services, pending updates, local users, and network adapters, plus hardware details as a clear before-and-after, scoped to the last 7, 30, 90, or 365 days.
  • Send a notification to a signed-in user — From a device's action menu you can send a message straight to whoever is signed in on that machine. They get a pop-up they must acknowledge, and you immediately see whether it was shown, whether no one was signed in, or whether the device was offline.
  • Digital signature for every service — The Services tab on a device gains a Signer column showing who signed each Windows service's program file and whether that signature is trusted, so you can spot unsigned or tampered service files across your fleet at a glance.
  • Ask the user before you connect — You can now require the signed-in user to allow each remote desktop session before it starts. A permitted technician can still connect without consent in an emergency by entering a reason, which is always recorded. While the prompt is up, the connecting screen now tells you it's waiting for the user to approve, instead of looking like it's stuck waiting for the picture.
  • Deploy .exe installers as custom packages — Custom packages now accept .exe installers, not just .msi. Drop an installer into the New Custom Package wizard, octoja reads its details automatically, and you can test it live on a device, publish it, and choose how it uninstalls.
    Deploy .exe installers as custom packages
  • Quiet hours for each alert channel — Each channel in an alert configuration can be limited to a weekly window of weekdays and times, so you're only paged when that channel should be active. Switch on Catch up missed alerts and an alarm that would have fired off-hours is delivered once the window reopens, as long as the issue is still ongoing.
  • Starter alert configurations — A fresh octoja instance now ships with four ready-made alert configurations (Immediate – Critical, Standard, Sustained Issue, and Critical – Multi-stage), so you have sensible escalation profiles from day one. Rename, edit, or delete them freely.
  • Finer-grained permissions — Several capabilities are now their own permissions you can grant independently: opening a device's terminal (per device), creating brand-new custom tags, and managing the custom-check catalog and check repositories separately from the rest of monitoring. octoja now also matches each user's view to those grants — a device's buttons, the global search commands, and the device lists only offer the actions that user's group allows (Remote Desktop, Terminal, File Browser, Software Management, and so on), instead of showing an action that fails when clicked. Existing administrator groups keep these automatically.
  • Password inputs in your own checks — When you build a check in Custom Checks, you can now mark an input as a Password so a secret like an API key is masked while you type it.
    Password inputs in your own checks
  • Manage your single sign-on logins yourself — Your profile page now has an Authentication section where you can link a single sign-on account to your own login (Link Account), unlink one you no longer use, and even remove your password so you sign in through single sign-on only. octoja always keeps at least one way for you to sign in, so you can't lock yourself out.
  • Lock a device automatically after remote desktop — A new Auto-lock after remote desktop agent setting locks a device the moment a remote desktop session ends, so a machine never sits unlocked after you disconnect. Set it as the default for matched devices in a configuration package or per device, and a technician can still override it for a single session.
  • Manage your agent settings across the whole fleet — Config packages now carry an Agent tab where you switch on four agent settings for every device a package matches — Require user consent for remote desktop, Show agent in system tray, Software kiosk enabled, and Ticketing enabled (which lets people on the device raise support cases). A device gets a setting if any of its packages turns it on, so you set the rule once and it follows your fleet. Need a different answer on one machine? Open Agent settings from that device's action menu and set any setting to Default (from its packages) or Override it On or Off, just for that device.

Improved

  • Sort, filter, and export across every table — Tables throughout octoja (users, customers, groups, the access overview, inventory, Cases, patch policies and cycles, integrations, and more) now share one layout. Click a heading to sort, drag to resize, reorder or hide columns, search the rows, and export the current view as CSV.
    Sort, filter, and export across every table
  • Antivirus checks now run on the device — The Bitdefender, SentinelOne, ThreatDown, and Sophos checks now read protection status (agent health, real-time protection, definition age, and threats) directly on each device instead of polling the vendor's cloud console. You no longer need cloud credentials or tenant matching for these checks, most let you set your own warning and critical thresholds, and existing assignments keep working as they switch over.
  • Group-scoped access reaches further — When a user's access is limited to certain customers, that limit now also covers patch policies and cycles, the update catalog, and configuration packages, so they only ever see and change items belonging to their own customers.
  • A clearer integrations page — Administration → Integrations now groups connectors into clear sections, including Ticketing systems and Other platforms, each sorted alphabetically, and adds a search box so you can jump straight to the one you need.
    A clearer integrations page
  • Richer report widgets — Check widgets in the report builder now show the check's name on the card, and you can narrow any check widget to specific devices or statuses. A new per-device check-history widget plots each device's own history chart inside a report, and check output now renders exactly as it does on the device page.
  • Full per-job detail in Veeam results — The Veeam Backup & Replication check now shows ten more details for each job (last run, state and progress, backup type, app-aware processing, compression, the run's bottleneck, encryption, and more), so you no longer have to open the Veeam console to see them.
  • SMART check watches every disk by default — Adding a SMART Disk Health check now starts with Monitor all disks switched on, so a new check covers every drive without you typing any device paths.
  • Redesigned patch policy editor — The patch policy editor has a cleaner, card-based layout with at-a-glance ring summaries, and creating a policy is now a quick dialog that only asks for a name and drops you straight into editing.
    Redesigned patch policy editor
  • Software installs for all users by default — Deployments now install for every user of the device by default, so unattended rollouts succeed even when no one is signed in. Choose to install for the signed-in user only when a package belongs in just their profile.
  • A faster Install Software dialog — Opening Install Software on a device now loads quickly instead of stalling while it gathers the device's installed packages; octoja warms the list the moment you hover the Install Software button.
  • Alert timestamps in local time, not UTC — The time on Teams alert cards and alert emails now shows in the instance's configured time zone with the correct offset (default Europe/Berlin; your provider can set it), so recipients no longer have to convert from UTC in their head.
  • Only connected ticket systems appear as channel types — When you add a channel to an alert configuration, the type picker now lists a ticketing system only if it's actually connected, instead of showing every possible integration.
  • Lywand at a glance — The Vulnerabilities tab now shows when a device was last scanned, and the customers overview gains a colour-coded A–F security rank column you can sort by, so you can read your whole fleet's posture without opening each customer.
    Lywand at a glance
  • A cleaner, sticky device page — The device detail page got a visual tidy-up (consistent cards, proper empty states, and live metrics that no longer wrap awkwardly on narrow screens), and the device's name and action buttons now stay pinned to the top as you scroll.
  • See on the device when a technician is connected — The on-device app now shows a clear indicator while someone is connected remotely, so the person at the machine always knows a session is active.
  • Repeat a schedule every few hours — Deployment schedules gain an interval mode, so you can run a software rollout every few hours instead of only daily, weekly, or monthly.
  • Clearer error messages — Error messages now appear in your own language instead of occasionally falling back to English, and unexpected failures include a copyable reference code you can quote to support.
  • Refresh a patch cycle on demand — A new Refresh now button on draft and approved patch cycles re-checks the cycle against your current devices right away, picking up newly pending updates and dropping ones that no longer apply, while keeping every decision you've already made.
  • Alarm-config editing limited to alert managers — The buttons to add, edit, or delete alert configurations now appear only for users who can manage alerts, with a clear message if you lack the permission instead of a generic error.
  • A more antivirus-friendly Windows agent — The Windows agent now does its update, inventory, and check work in a way that security tools are far less likely to flag, so it's less likely to be blocked or quarantined.
  • Create a site while setting up a token — When you pre-assign a customer while configuring agent deployment or creating an installation token, you can now add a new site for that customer right there with the Add site button, instead of leaving to create it first. The site field appears as soon as you pick a customer, so even a customer's very first site can be created in the flow.
  • A consistent Save button and Ctrl+S on every settings page — The Save button now sits in the same place — at the top of the page — across every edit, profile, and integration settings screen, and pressing Ctrl+S (Cmd+S on a Mac) saves from anywhere on the page. Saving with the keyboard now always applies the value you just typed, so changes like tag rules and branding no longer quietly revert.
  • Smarter SMART disk monitoring — A SMART Disk Health check on a device with no SMART-capable disk (a VM or hardware-RAID box) no longer sits at a permanent Warning, so it stops nagging you for a state that is perfectly normal. And if a disk a device used to report suddenly disappears, octoja now raises a Critical alert reading “SMART disk is no longer detected — it may have failed or been removed”, catching a drive that died or was pulled.
  • See your version on the login screen — The login page now shows your octoja version (for example v1.0.1314) just below the Sign in card. Click it to open the changelog and see what's new in this release.
  • More reliable single sign-on, and link accounts for users — Two single sign-on improvements. First, sign-in works for more setups: some providers (notably Microsoft Entra) send a sign-in token without an email address, which used to be rejected even when the account was correct. octoja now also checks the username the provider sends, so those people sign in normally. Second, an admin can link a single sign-on account to someone else's login on their behalf. Open a user in user management, and under Authentication → Linked Logins pick the provider and choose Link now — octoja runs the sign-in once and connects that identity to the chosen user, so their future logins are matched reliably instead of relying on a matching email address.

Fixed

  • Two-factor codes are now required with SSO — If you have two-factor authentication turned on, signing in through your SSO provider now asks for your authenticator code, just like a password login.
  • Automatic patch cycles no longer silently go missing — A ring's next patch cycle could quietly stop appearing, for example after a cycle was cancelled or a window passed without it running. octoja now always lines up the next cycle, and one whose window passed without running is clearly marked Missed instead of vanishing.
  • Patch cycles keep generating even with an odd ring schedule — An unusual maintenance-window schedule on one ring no longer quietly stops patch cycles from being generated, and the editor now warns you when none of a policy's rings has a valid window.
  • Known-issue advisories show in the catalog — Windows update advisories that flag a problematic update now correctly appear against the matching updates in the Update Catalog, instead of staying hidden.
  • Unmanaged devices keep their own Windows Update settings — Devices that aren't covered by any patch policy no longer have their built-in Windows Update settings taken over; octoja only manages updates on a device once a policy actually applies, and restores the original settings if it stops.
  • RAID check sees Intel RST arrays — On Windows machines with Intel RST or hardware-controller RAID, the RAID Status check no longer reports a false failure for a healthy array, and a machine with no arrays at all no longer shows a false failure either.
  • Network Interface check no longer fails on macOS — On Macs, the Network Interface check used to fail with an empty result; it now runs correctly and reports every interface on the device.
  • The "-" key types correctly on German keyboards — Connecting from a Mac to a Windows machine on a German layout no longer mistypes “-” and other punctuation keys.
  • Select and scroll again in remote terminals from a Mac — When connecting from a Mac, you can once again drag to select text and scroll inside a remote command window.
  • Sessions open without a false failure — Opening a remote-desktop, terminal, file-transfer, or log-download session could report “connection failed” even when it had actually opened. These now open without that false error.
  • Integration pages stay usable when a saved key goes bad — If a stored key for a ticketing or PSA integration became invalid, the whole detail page used to disappear, taking the Disconnect button with it. The page now renders through the error so you can always reconnect or disconnect.
  • Codemeta OS connection is checked before it's saved — Connecting Codemeta OS now confirms your token and address actually work and shows a clear error if they don't, instead of saving a broken connection that failed on every later use.
  • Customer matching no longer gets stuck — Saving customer matches for an integration could fail with a duplicate error you couldn't fix, because the conflicting entry belonged to a deleted customer. Saving now clears those stale matches so it goes through.
  • Device status filters span your whole fleet — Filtering the Devices list by Critical, Warning, or Healthy now searches every device rather than just the current page, and counts a device under each status it actually has, so a device with both a critical and a warning check shows up under either.
  • Rules and checks apply right after enrollment — A newly enrolled device's rule-driven tags and checks could take hours to appear; now a tag assigned by a rule immediately re-evaluates any check package or further rule that depends on it, so they show up within seconds.
  • No more failed-logon noise on your servers — On domain-joined and remote-desktop servers, every inventory cycle was logging repeated failed-logon and security warnings in the Windows event log. The agent now collects the same information without triggering them.
  • Delete a customer that has no devices left — Deleting a customer could fail saying it still had active devices even after you'd moved them all away; an empty customer now deletes cleanly.
  • Switching an open alarm's delivery now takes effect right away — If a check was still failing and you changed an alert channel's delivery — say, switching it to Teams or pointing it at a different ticket system — the new delivery used to stay silent until the check recovered and failed again. octoja now picks up the change immediately, so the next failure goes out through the new channel. The check editor also shows an active-alarm badge next to the alert summary when a config has open alarms.
  • Virtual machines now report their manufacturer and model — Some virtual machines, especially Hyper-V guests, were inventorying with an empty Manufacturer and Model, which broke rules that target devices by model. octoja now fills in these fields reliably, so model-based targeting works on those machines again.
  • Special characters work in your own checks — A custom PowerShell or shell check that contained special characters — umlauts like Lüfter, a degree sign like °C, or an em-dash — could come back garbled, and in some cases broke the check entirely. It was worse for a saved check: it could fail when it actually ran even though the Test on its editor page looked fine. octoja now runs these scripts with the right text encoding, so the characters you typed in Custom Checks are exactly what runs on the device. Saved checks pick up the fix automatically — no agent update needed.
Write a comment...

June 22nd, 2026

New

Improved

Fixed

Highlights

This release is all about connecting octoja to the rest of your stack. Six antivirus and EDR platforms, nine helpdesk and PSA systems, and two documentation tools can now be wired straight into octoja — so protection status, alarm tickets, and your asset inventory stay in sync without manual work. Alongside that: a one-glance executive report for your customers and a new check for UniFi networks. The rest is polish and reliability — clearer patch policies, sortable tables, and a batch of cross-platform fixes for macOS and Linux.

New

  • Antivirus & EDR integrations — Connect Bitdefender GravityZone, Sophos Central, ESET PROTECT, Securepoint Antivirus Pro, ThreatDown, and SentinelOne. octoja pulls each platform's protection status — such as agent health, definition currency, real-time protection, and active threats — and surfaces it as a check, so unprotected or at-risk devices show up next to everything else. Marked BETA.
  • Helpdesk & PSA integrations — Open a ticket automatically when a check alarms and close it on recovery, across DocBee, HaloPSA, Autotask, Inserve, Odoo Helpdesk, Jira Service Management, TOPdesk, TANSS (BETA), and Codemeta. Most also map your customers and sites and sync devices into the connected system.
  • Documentation sync: IT Glue & Hudu — Sync your octoja devices straight into IT Glue Configurations or Hudu Assets, kept up to date automatically per customer.
  • Executive report — A new customer-scoped report (Chefbericht) that opens with an at-a-glance scorecard — devices online, patches current, AV protection, backups, and monitoring — followed by the key metrics and the proactive work done during the period. Built to hand straight to a customer's management.
    Executive report
  • Access overview — A new admin page that shows who can access which customers and devices, and why — by user, by customer, or by device, including the groups that grant the access.
    Access overview
  • UniFi network check — A new check monitors Ubiquiti UniFi switches, gateways, and access points over SNMP, on Windows, macOS, and Linux.
  • Remote-desktop resolution control — Change the resolution of the Windows display you're remoting into, right from the session settings, applied live.
  • View Reports permission — A new permission lets you grant read and run access to reports separately from the ability to manage report templates.

Improved

  • Integrations grouped by category — The connected-platforms area now groups integrations by what they do and floats your connected platforms to the top, so the list stays readable as it grows.
    Integrations grouped by category
  • Sortable admin tables — The email, webhook, and Teams channel tables and the patch-cycle tables can now be sorted; severity sorts by rank rather than alphabetically.
  • Clearer patch policies — The Auto-Promotion and Exclusions sections of a patch policy now explain in plain terms what each setting does, with a hint on every threshold.
    Clearer patch policies
  • Hide disabled checks — In a device's Checks tab, disabled checks are now hidden by default, with a “Show disabled” toggle to bring them back.
  • Richer Teams alert cards — Teams alerts now carry the same detail as email: device and customer context, the check's output, and a button that jumps straight to the device — in the channel's language.
  • Clickable customer & site in the breadcrumb — On a device page, the customer and site in the navigation path are now links that open a device list already filtered to that customer or site.
  • Cadence-aware backup age (Veeam) — The Veeam backup-age check can now derive the expected age from each job's schedule, so weekly or monthly jobs no longer false-alarm just for running less often. Fixed thresholds remain the default.
  • Localized keyboard shortcut hint — The search shortcut hint is now localized — German shows Strg+K instead of Ctrl+K.
  • Links use your own domain — The device links in alarm emails and integration tickets now use your tenant's own domain when you've set one, instead of the default octoja address.
  • Tag rules apply immediately — Creating a tag rule now tags all matching devices right away, instead of waiting for each device's next check-in.

Fixed

  • macOS & Linux user details — On macOS and Linux, the user-account check no longer shows “Unknown” for last login, the Local users table now fills in Last login and Password last set, and the live status column shows who is currently logged in.
  • Remote NumLock left alone from a Mac — Controlling a Windows machine from a Mac no longer silently switches the remote NumLock off, which had broken click-and-drag text selection.
  • macOS agent uninstall — Removing a device now fully uninstalls the agent on macOS, instead of reporting success while leaving files behind.
  • Report PDF layout — Report PDFs no longer overlap widgets or split them awkwardly across page breaks.
  • Customer matching in integrations — Deleting a matched customer no longer breaks an integration's matching dialog, so you can save your customer assignments again.
  • Synology check — A healthy Synology NAS is no longer falsely reported as 100% full, and RAID status is now read correctly.
  • Email channels in the check dialog — Email recipients in a check's alert summary are now labeled correctly — they previously showed as “Webhook” — and show the inactive badge when disabled.
  • SNMP custom checks report the cause — Simple-mode SNMP custom checks now show why they failed instead of a bare “Failure”, and no longer report success when the community string is wrong or the value doesn't exist.
Write a comment...