.Loading..Loading.
Readme Rev
Service Updates
When the downloaded patch is run, it will extract to a folder and there will be zip files. Those files should be extracted and then Setup.exe can be run. This table outlines the names of the zip files and where they should be run.
Component | Core/Console | Client |
---|
This Service Update changes how Proxyhost, a component of the EPM agent shared across Windows, Mac, and Linux, validates communication with the Core Server and CSA.
Once updated, agents will not be able to communicate if there is an SSL Proxy between the agent and the Core, or between the agent and the CSA.
Before applying this update please ensure you have a complete backup of your core and database. For more information about these changes
please see Updates to Proxyhost in Endpoint Manager 2020.1 SU4
Installation Instructions
The following outlines instructions for installing this update.
This patch requires that Ivanti Endpoint Manager 2021.1 be installed. For more information about current service packs please see Ivanti Community Doc 1001
Installing on the Core and Rollup Core
Because ADS may block files on Windows systems, it is recommended that you extract the patch on the machine you are going to install it on.
Prior to installing a patch on the Core Server it is recommended to make a backup of the Ivanti database.
Steps
- Disable any services on other machines that interact with the Core Server
- Double-click on the self-extracting executable and extract it
- Extract the files for the Core patch
- From the extracted files, run Setup.exe
- When Setup completes, reboot the machine if a reboot is required
- After applying the patch, you may need to re-activate your Core Server using the Core Server Activation Utility
- Restart any services stopped in Step 1
Note: The installer included with this release writes a detailed log that can be used to help troubleshoot installation problems. After running setup.exe from the patch, the log is located in the \ManagementSuite\log folder.
Installing on Remote Consoles
A Remote Console is any machine that is not the Core Server and has the Ivanti Endpoint Manager Console installed. Console Machines need to be updated to be able to connect to the updated Core Server and Database.
Because ADS may block files on Windows systems, it is recommended that you extract the patch on the machine you are going to install it on.
Steps
- Close the Console
- Double-click on the self-extracting executable and extract it
- Extract the files for the appropriate patch
- From the extracted files, run Setup.exe
- When Setup completes, reboot the machine if a reboot is required
Note: The installer included with this release writes a detailed log that can be used to help troubleshoot installation problems. After running setup.exe from the patch, the log is located in the \ManagementSuite\log folder.
Updating the Agent
The patch should be installed on the Core Server before updating Agents
Use one of the following methods to re-deploy the agent once the patch has been applied to the Core or to apply the patch manually.
Methods of agent deployment
-
Manual: Map a drive to \\Coreserver\ldlogon and run 'wscfg32.exe -f'
This is used for single client installs and testing - Push: Schedule a push of the full agent
- Self-Contained EXE: Create an EXE that can be installed
- Advance Agent: This is a two stage process. The Advance Agent consists of a small MSI and a self-contained EXE. The MSI is deploy to the client and then the MSI downloads and installs the EXE. This allows for bandwidth friendly downloads.
For more information on agent configuration and deployment see Ivanti Community Doc 23482
Manual installation of the client patch
Because ADS may block files on Windows systems, it is recommended that you extract the patch on the machine you are going to install it on.
- Double-click on the self-extracting executable and extract it
- Extract the files for the appropriate patch
- From the extracted files, run Setup.exe
- When Setup completes, reboot the machine if a reboot is required.
Updating the Agent With Patch Manager
Ivanti Patch Manager can also be used to update agent machines with the patch. Content and definitions can be found in Patch Manager as Ivanti Updates and can be used to detect and repair agents that have not been updated. The Core Server must be updated with the Core patch before updating agents.
Not all Component Patches will have Patch Manager Content created. Once it is generally available, this method can be used to update agents. For more information about updating agents using Ivanti Patch Manager see Ivanti Community Doc 24384
Release Information
Please review the following important information about this release BEFORE installing this update.
Feature Changes and Updates
The following features have been changed or updated
Agent
-
Added support for Windows 11 and Windows Server 2022
- Windows 11 and Windows Server 2022 are supported for the Ivanti EPM Windows Agent.
Agent Common
-
Implement dismiss timeout and app timeout in Notifications Manager
- We added an optional time out for notification manager to exit with OnDismiss action, if defined, when there is no user action. We also added an optional timeout for OnDismiss if a notification has been dismissed into the Action Center for a certain time.
Autopilot
-
Windows Autopilot Pre-provisioning Support
- Ivanti Endpoint Manager will allow customers to seamlessly deploy devices to end-users, regardless of where they are located and without infrastructure changes. Additionally, Ivanti Endpoint Manager will continue to be the trusted solution to manage modern devices anywhere within the device lifecycle.
Inventory
-
Add Support for ARM Devices
- Endpoint Manager Admins will now benefit by being ablet to manage their ARM devices with EPM. Management includes comprehensive Inventory data specific to the newest ARM processors, in addition to the existing inventory data that is already being collected.
-
Add Display Version to Inventory for Windows OS
- After deploying the latest release of Windows 10 (21H1) to an endpoint, the "Release ID" value of the device's Inventory Record still shows a value of "2009". This makes the device difficult to distinguish from other endpoints that are using the 20H2 Release of Windows 10. We now use the Display Version.
-
Collect TPM version data in Inventory
- EPM Inventory now collects the TPM version on devices to help admins identify if the device is Win 11 compliant.
-
Detect Windows 11 OS in inventory
- We now detect Windows 11 with the inventory scanner.
-
Add Windows Server 2022 detection to the inventory scanner
- We now detect Windows Server 2022 with the inventory scanner.
-
Collect the User Profile Data in Inventory
- Endpoint Manager Admins can now see how many profiles are on a specific device, how big those profiles are, and what areas (types of files) make up that profile size. This enables admins to be better prepared, and execute efficiently, for OS migrations.
-
Add Windows 11 readiness report default queries to the core install
- Windows 11 Readiness Reports: Endpoint Manager provides an easy way to see which devices are ready to have Windows 11 installed and which aren’t. This provides the basis for OS rollout as well as hardware refresh plans.
iOS
-
iOS 15 Updates Day One Support
- Ivanti Endpoint Manager will continue to run (without loss of functionality) when customers migrate devices to iOS 15 throughout their environments.
macOS
-
macOS Monterey updates (Q3 2021 Test with Pre-Release Builds)
- Ivanti Endpoint Manager will continue to run (without loss of functionality) when customers migrate devices to Monterey throughout their environments and have Day One Support.
MDM
-
VPP Caching manager service
- We added a new service to reduce the web traffic and speed up the display of avaialbe VPP packages UI in an intelligent way. We now download and cache all the metadata in the database and images on disk (HASH of adamIdStr). We refresh this data on demand and also have it scheduled to automatically refresh once a day at midnight.
-
MDM Enroller Mac: add support for QR codes
- To bring parity to our MDM Mac enroller we added the QR code capability we first released in our iOS enroller.
Patch Manager
-
Patch option to check for disk space requirements
- As an EPM Admin, when deploying and installing patches, I want the ability to check available disk space so that I can ensure I avoid upfront endpoints that will no be able to be updated, and save up time and potential bandwidth (for partially/downloading a file that cannot be installed) After the disk space issue has been solved, I will run another patching campaign for those specific endpoints to bring them in line with my patching strategy. In the current solution, the patch fails (for not having enough disk space), but the error code is a generic one, that leads to a lot of time spent investigating.
RC
-
Remote Control - AZERTY Keyboard Issue
- When typing on an AZERTY keyboard in a Remote Control Session, we now get the correct results.
-
Improve Remote Control Connection Times
- Provide a better/faster experience for users enabling them to feel confident in Ivanti Remote Control. For larger customers, the reduced connection times result in significant saved man-hours and improved productivity.
-
RC - Smart Card Support
- EPM RC user can use a smart card locally on their machines to authenticate on a machine that is being remote controlled that requires smart card to log in.
Tutorial
-
Remove What's New Static Box
- Today, Clicking on What's New button on the EPM bar, will lead to a static box, highlighting Top Sections of interest for the version of the core the users is looking from (4 features, 1 general section). Each section has a link pointing to its respective page in the help.ivanti.com Current Challenge The customers are only seeing the new features relevant for the version they are using Usually customers jump between releases. The way the current functionality works makes it hard for a customer to see all that was released. High Level Requirements The desired outcome is to remove the static box entirely, and Clicking the What's New button in EPM will directly lead to a general page of the help.ivanti.com
Web Console
-
New Web Console - technology refresh
- The New WebConsole will provide a simple, easy to use and modern experience helping IT Helpdesk Analysts to better manage and support the organization's devices.The objective is to reduce the high entry barrier for less specialized roles (e.g., Helpdesk Agent vs System Admin) The New WebConsole will start with an initial focus on IT Helpdesk role. Our focus will be on extensibility and building a foundation for future development of business flows.
Defects Fixed
Agent
-
790208 Addressed issue around core agent communication
- -
-
795161 Addressed issue around agent communication
- -
-
799441 Error message 'Ending IP address less than starting IP address' when creating a trigger that contains all IP addresses
- An issue with comparing IP addresses in the Adaptive Settings trigger editor was fixed.
-
817444 Downloader (lddwnld.dll) fails to get credentials for servers that have the port number after the server name in the URL.
- If the host name in the request has :443 or :80 after it, and the request required credentials, it would fail to get the credentials. This is because the servername:443 or servername:80 was sent to the core requesting credentials. With this fix we strip of the :port from the servername before requesting credentials.
-
832828 Advance Agent: Peer-to-peer download not working over wireless networks
- Advance agent runs before agent settings are available, so modified the default for allow multicast on wireless to be true. This will allow peer discovery on wireless networks to work for advance agent.
Alerting
-
707652 Alertsync.exe is calling lddwnld.dll repeatedly, and re-downloads the Alert Settings
- Alerts behavior (alert rulesets) will be downloaded even though there are no updates, this will be changed in the next release
-
791206 Real-time monitoring and Inventory: Russian characters displayed as "?" in Event Viewer logs
- Real Time and Monitoring Logs -> Application logs for Russian characters are correctly displayed.
-
803058 Send syslog action on certain alerts fails.
- Some application control alerts were not properly sent to a syslog server. Such alerts should properly reach the syslog server now.
-
805839 SMTP alerting network port setting feature is by default set to 0
- SMTPs for alerting will default to port 25 instead of 0.
Anti-Virus
-
792291 BitDefender pattern files out of date - submitavdata switch failing with error 16389
- Fix for certain scenarios where updating pattern files for Ivanti Antivirus 2017 on endpoints, fails with error 16389.
-
793629 Panda AV not displayed in Inventory Record
- Panda Antivirus solution will be properly reported in the Inventory record under Security->Antivirus Software
-
806251 AV2017 - Unable to delete quarantined files ("Clear in selected computers")
- Quarantined files can be deleted from the Endpoint Manager console.
-
852600 Archives setting is enabled on client when it is disabled in the AV setting.
- Enable Archive setting was incorrect mapped to Bitdefender parameter.
Data Analytics
-
690073 "Allow free text typing" does not work in Barcode web forms. The form fails with a NullReferenceException error
- The Barcode forms are now loading in the browser as expected and an item in the dropdown list can be easily found by typing its name.
-
757592 Using 22 or more Asset Control queries in DTS rules configured as targets returns "no targets" even when the queries return results as expected.
- The DTS rules can be used now with as many Asset Control queries as needed, not being limited to 22 queries anymore.
-
759416 Attributes does not exist Device.SNMP Data.Login Name error in Data Analytics Discovery Services when executing SNMP scan
- The error is not thrown anymore and The SNMP Login Name is saved alongside the other SNMP data.
-
763614 Data Analytics Discovery Services duplicate attributes not saving properties
- The duplicate settings for discovery services are now successfully saved.
-
796139 DTS Import Data "Don't overwrite existing values" does not work
- When running an Import Data Rule with the "Don't Overwrite existing values" option checked, the already existing attributes are not overwritten anymore.
-
798106 Data Analytics Aggregate Data rule defaults to Management Suite when saving.
- The Aggregate Data rules can be successfully saved now with the "Asset Control" option.
-
799112 Asset Control SNMP Entries Freeze Console
- The SNMP Entries tree loads fast, without freezing the console.
-
806736 Rapid Deployment: Queries specified to target agent configurations are ignored when creating deployment tasks
- A separate configuration task is now created based on the specified target query and the assigned agent deployment configuration.
-
810135 DA's "SoftwareManager.exe" doesn't respect start-up time configured in its config-file.
- SoftwearManager is now working as expected and respects the start-up time set in the configuration file.
-
817794 Scheduled data import tasks are not running when started as normal scheduled taks
- The tasks scheduled to run data import rules are now working as expected and running at the given time.
-
817815 Unable to run "Check Scan Files" in Database Doctor. Error: "You may only run this on the core server."
- The "Check Scan Files" option in Database Doctor is not raising an error anymore and it working as expected.
-
826408 XML Corrupted when Editing a Rule in Web Import from the Data Translation Services.
- The export option for the Web Import rule is now working properly as the generated XML files have a valid format.
Endpoint Security
-
776016 Device Control Blocking SCSI Devices
- We have fixed and issue where secondary storage volumes or partitions on a computer are not accessible if the DCM setting is deployed with Read-Only, Encrypted or No Access security level.
-
793704 Registry keys under HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\landesk\... can be modified with EPS installed
- Certain Endpoint Manager registry keys cannot be edited anymore, for security reasons.
-
799069 EPSUI crashing
- Fix for possible EPSUI crash under certain scenarios.
-
815725 LDSECDRV.SYS Incompatible HVCI Driver for Microsoft Credential Guard
- LDSECDRV.SYS made compatible HVCI Driver for Microsoft Credential Guard
-
834966 Unable to import Application File List properly
- Updating LANDeskTrustValue & OverrideTrustValue with the imported values. CSV files are now imported from Application File List.
Inventory
-
778106 Inventory does not report all video adapters under Video.Adapter
- Modified the video adapter detection to be more accurate. (using WMI)
-
796846 Duplicate Inventory Attributes have been Created (Related to Defect 657616)
- Fix for duplicate meta-data being added when using an English remote console with a core of a different language.
-
803677 There is an upper limitation to the number of extensions that can be added/collected by 'ScanExtensions' option
- increased the supported number of extensions from 40 to 100.
-
810642 Computer Static Location in the Registry is written in European alphabet, but in inventory it is showing up in Chinese
- Fix to handle wide characters for the Computer Static Location data
-
813589 Duplicate FileInfo records from the same file with the same hash
- Fix to get a consistent file version. There was a bug in the parsing of the ldappl3.ini file when the version had a "," in it.
-
816550 SNMP Scan Fails When Run with "All" Group Selected in the Configuration
- When running an SNMP Scan configuration that has the "All" group selected, all the OIDs that exist in Discovery Services will be gathered for the scanned devices.
-
821813 GatherBitLocker fails when volume does not have a letter assigned and stops processing drives following next in sequence
- An issue was corrected in GatherBitLocker.exe that prevented the inventory of drives without letters. Additional error handling was also added to prevent errors occurring within one drive from aborting the entire scan.
Licensing
-
802255 Activate Core Dialog doesn't use current proxy settings
- Disabling proxy settings in the Core Server Activation UI now takes effect immediately.
Mac
-
593266 Crash in LCFolderManager when two threads call FetchFolder concurrently (actual crash in PortalManager)
- Fixed a problem that could sporadically cause PortalManager to crash when updating policies.
-
636263 Catalina/DarkMode: various UI glitches for ldswprogress
- Ivanti Provisioning icon is compatible with dark mode. App switcher shows proper display name: "Ivanti Provisioning." The standard menu bar is visible when the provisioning window is front-most.
-
702449 Investigate Remote Control - AZERTY Keyboard Issue
- Mac RC now supports alternative keyboard language layouts, for example AZERTY keyboards. This can be especially important when typing passwords.
-
784739 iOS MDM Enroller: User defaults and show/hide fixes
- If the user chooses to hide the CSA/core or group, launching the app clip workflow hides CSA/core or group.
-
795508 Two MDM unit tests failing due to a expired embedded APNS cert
- Obtained a new APNS cert, embedded it into the code, and reenabled the two tests and they now succeed.
-
795691 RC engine: File transfer and remote execute don't work on macOS
- File transfer from the Cloud RC viewer works as expected. Remote Execute, for manually entered paths and browsing the file hierarchy for executables, also works as expected.
-
796068 Updating agent version via MDM for Mac
- When the agent manifest package has an updated agent version, it is selected in the Agent Configuration for MDM enrollment dialog, and a Mobile Sync is run from the core with any mac enrolled in MDM, the agent version updates via MDM.
-
797079 Inventory truncates application name when it contains several dots
- When an application name contains several dots, Inventory shows the whole application name and does not truncate.
-
797495 Portal Manager: "Install" button remains active during package installation while package is being installed
- When a package is installing, Portal Manager's "Install" button in the side bar is disabled just like the install button in the main content view is.
-
799544 iOS inventory storage is reported in MB and not GB
- iOS Inventory storage is displayed in GB or has three zeros to the amount displayed in MB.
-
802110 Tab order in Mac MDM Package dialog is incorrect, making it virtually impossible to tab through items when filling in data
- While setting up the "Mac Agent" MDM manifest package, you can now tab through the entries when filling them in.
-
802149 Mac AV reports versions different from Windows AV
- Mac IvantiAV reports versions in same locations as Windows IvantiAV.
-
804049 Ending the Remote Control WS session from the user side is "Problematic" with Mac
- Improved behavior when user terminates RC session from the remote machine by clicking on the red stop button. Viewer will no longer automatically reconnect.
-
804757 Reboot action in provisioning does not work in Big Sur
- When a reboot action is included in the macOS provisioning template, the macOS device with Big Sur installed will reboot.
-
812207 RC: screen indicator frame should let mouse clicks through
- During a Remote Control session, if you click on a menu locally on the controlled Mac by moving the mouse all the way up into the menubar area where the green frame is, the mouse click goes through the green frame and pulls down the menu.
-
815720 MacOS patch Reboot/autofix issue
- Fixed an issue with automatic rebooting during auto fix
-
818913 Crash in ivremote when terminating RC session
- When terminating a Remote Control session, ivremote terminates without crashing.
-
821812 macOS BitDefender events not reporting to Core.
- BitDefender events now properly report to the core.
-
822402 RC: "save file" dialog, login window password field & Activity Monitor search field have problems accepting keyboard input through RC
- Remote controlling a Mac will now interact properly with save dialogs.
-
823334 IvantiAVControl returns nothing for --status if BitDefender not installed
- Running "IvantiAVControl --status" without BitDefender installed will now produce output indicating that it is not installed.
-
824507 CPE: Incorrect payload value key written for "Allow multiplayer gaming" restriction
- The label for the "Allow Multiplayer gaming" now indicates that this option only exists for supervised devices.
-
825525 IvantiAV does not work on M1 Macs
- Ivanti Antivirus now works on M1 Mac.
-
827004 MDM Enroller does not work on macOS 10.14
- MDM Enroller will now recognize QR codes and display the enrollment details properly in macOS 10.14 (Mojave).
-
827095 EPM macOS Agent fails to connect to core due to App Transport Security issues
- App Transport Security issues with ldiscan and vulscan are now resolved.
-
827394 ldiscan log line "Temp file deleted" is type fault, it should be info only
- The ldiscan log levels have been adjusted. "Temp file deleted" is now an info log, not a fault log.
-
828421 Importing a second APNS cert causes the cert to stop working
- Updating your APNs certificate with a new certificate will no longer stop APNs functionality.
-
828962 IVRemote listener does not restart on a network change
- ivremote re-connects to the tunnel when the network changes (VPN on/off, switch to/from WiFi, etc.) Remote Control through the tunnel works after turning off the VPN.
-
831584 APNS Push Commands Fail
- If there is more than one certificate in the ApplePushChannelStore, and the service may pick the wrong certificate which will result in the commands not being able to be pushed to the device, but just queued on the EPM Core Server. When the device reboots it will check in with the server and ask what commands have been queued and execute them. This can be fixed by manually clearing the store and importing only the correct certificate.
-
838599 Apple MDM - Factory Reset PINs (macOS EraseDevice) are not exportable from the Client Data Storage
- PIN export following a macOS factory reset will now work.
-
838967 macOS RC will connect over the Tunnel once and then does not work again after that.
- macOS Remote Control will connect to the RC Tunnel every time it is off-network.
-
844617 Mac agent lost some local scheduler tasks after the upgrade to version 2021.1
- Macs will now always send full Inventory sync scans, send security scans, and synchronize policies when expected.
-
857696 macOS 11.3 and 11.3.1 patches not detecting
- When machines show that a patch is needed when Apple Software Updates is ran, macOS 11.3 and 11.3.1 patches are now detecting properly.
MBSDK \ API
-
792440 MBSDK ApplyPatchToMachines - TaskType is now obligatory and doesn't default to "push" 3 as indicated on the method page
- Since 2020.1 SU2 TaskType parameter became obligatory and if it's not provided an error will be thrown:System.InvalidOperationException: Missing parameter: TaskType.However the main issue in the problem is that when the parameter is provided empty it does not work as described on the ApplyPatchToMachines description page which says "TaskType can be PushPull = 1, Pull = 2, Push = 3. If TaskType is empty the default is push". Solution: ApplyPatchToMachines - TaskType is now obligatory and doesn't default to "push" 3 as indicated on the method page
-
836549 Compliance API not returning information
- MBSDK API The following POST call to query a specific device using its device ID:https://{Core server}/PatchApi/api/v1/Devices(4)/Compliance?= is returnning the proper results.
MDM
-
823613 Unable to search App Store Apps
- Add re-try logic in case network interrupted during app internet request.
Patch Manager
-
722682 ldReboot.exe when the prompt is left open for extended periods it will use excess amounts of memory
- A memory leak caused by not releasing a service handler after use was corrected.
-
795994 Patch Automation service will not start if it cannot reach the database
- The patch automation service was not starting if it could not reach the database, now it will try to start silently until it manages to connect to the database.
-
821855 Filter Definitions -- Filter not placing Linux definitions in Group or Rollout Project
- Patch filtering - Filter Definitions -- Filter is placing Linux definitions in Group or Rollout Project. Edit Filtering Definitions is working properly.
-
829178 Patch Campaign not responsive
- After deleting a Patch Campaign template, Patch Automation commands for unavailable campaigns are marked as Failed in the database.
-
831533 Filter not working properly after editing the filter (removing selection)
- Now when existing content download filters are modified, the content will properly be assigned at download time based on the filter's rules.
-
850677 Windows 10 Vulnerabilities are also applicable (detect/repair) for devices running windows 11
- Vulnerabilities can be detected and repaired for endpoints running Windows 11.
Provisioning
-
569497 Core name in WinPE image fails in some environments because it is short name
- The logic to stamp the Windows Preinstallation environment image used in Provisioning was updated to get the core name from the default client connectivity setting. If the setting does not exist, it will use the core's FQDN.
-
836429 Provisioning template Options Remove client provisioning folder does not remove c:\ldprovisioning when the last Provisioning action is a Shutdown
- When using the shutdown action in Provisioning, the ldprovisioning directory is queued for deletion upon next boot.
-
846202 BIOS based computers fail to boot to Windows after being Provisioned with the Ivanti Endpoint Manager ( EPM ) core server version 2021.1
- The UEFI detection logic was updated to address changes in the Microsoft Win32 Api.
Remote Control
-
706215 Users added via group do not inherit the groups roles
- Remote Control uses Identity Server to authenticate. When a user would connect, Remote Control was using the username to attempt the connection but had no way to check the user's groups.Updated to use an Identity Server user ID. The check for permissions using this method includes permissions in groups, not just by the user. These permissions will be used by the EPM console without having to manually add each user.
-
793755 RC Viewer fails with user scope message in the logs
- Fix to restore a database connection when necessary.
-
815721 2021.1 Agentless Remote Control fails to connect
- Fix for Agentless Remote Control not working.
-
837624 During the Remote Control WS session a second virtual adapter "WLAN Adapter- LAN connection* 2" (Drahtlos-LAN-Adapter LAN-Verbindung* 2) is created and the connection gets lost.
- Fixed an issue that some VPN caused RC to stop when connected.
Reporting
-
818230 Getting "email send successful" notification even though invalid SMTP server in SMTP configuration for scheduled report is set
- If SMTP server in SMTP configuration is not responding or the connection can't be established, the user will be correctly informed about this instead of always throwing a "successful" message.
SLM
-
755004 SLM is not showing usage although usage data is gathered in the inventory
- Updated the code to do a proper insert into the SLM product usage file database table.
Software Distribution
-
425992 New scheduled tasks show as Policy Supported Push in My Task View
- Fixed the method that was returning the task types by their string name to point to the right property.
-
645162 Problem with detection logic for dependencies where only 32-bit registry is analyzed
- Reset root key for vulscan specified 64 bit syntax based on if architecture set to 64-bit or 'System architecture' and running on x64 platform.
-
758642 Maintenance Windows do not work correctly for SWD in a specific situation
- Check if maintenance start time should be in yesterday.
-
763126 Specific scope user can see all SLM discovered info with all devices
- Needed to add a scope clause to the queries that control discovered information.
-
764208 Link package task is executing on clients hourly (caused by policysync /enforce)
- Also check public desktop and common start menu for created link.
-
765992 Unable to add folder as additional file from an Azure Blob cloud storage source to a distribution package
- For recursive file list, passed-in is already directory, do not go to parent dir.
-
772937 Custom actions have length limitations that is cumulative
- An issue with executing large Windows Action packages on the client was fixed.
-
791279 Software distribution blocked even when Powerpoint window is maximized on endpoint: agent setting- do not disturb - full screen
- Removed app maximized check and only check if app running in full screen.
-
799554 Some custom script based tasks are failing with "unable to find the agent"
- Correctly get MachineNode point from pong data in PDS2 ping callback. If osType is unknown, set by OS type using OS family and OS name in pong data.
-
805704 Endpoint that's not applicable in a query became a target
- Fixed an issue where the allowed machines for a task were not being properly determined with prerequisite queries.
-
806861 Pre-requisite queries doesn't work in the package bundles
- Fixed an issue where the allowed machines for a task were not being properly determined with prerequisite queries.
-
825083 WOW not using previous supported port
- If current configured port does not work for write target list to MDR, fallback to try the older port used before 2020.1 SU3 release.
-
837167 Win10 Updated Notifications in Task Bundles
- The client was only checking one of the facility codes (DB5) for SWD when calculating the result code. The other facility code (DAC) needed to be checked as well.
-
838601 Modifying the primary file of a package inside of a bundle causes the download to fail
- APM webservice maintains a cache for SWD packages. That cache handler needed to be updated to recurse into bundles in order to determine if a particular cache entry needed to be refreshed from the DB.
Win Console
-
789076 SWD Tutorial link invalid
- The URL for the SWD Tutorial was corrected.
-
797632 Remote Console Default Core Server Name Defaulting to Hostname
- The login form for the Console now looks up the core name in the following order: 1. C:\Users\
\AppData\Local\LANDesk\CoreConnectionMRU.xml 2. HKLM\SOFTWARE\LANDesk\ManagementSuite - CoreServer OR HKLM\SOFTWARE\LANDesk\ManagementSuite\Install\Data\CommonActions - GetFQDNEx_hostName (if the machine is joined to a domain) 3. Machine name (if a core) or blank (if a remote console)
- The login form for the Console now looks up the core name in the following order: 1. C:\Users\
-
801882 Changing Windows Scaling breaks WPF apps (Autopilot and SLM)
- A scaling issue that prevented controls from rendering correctly in the Console under certain circumstances was corrected.
-
803118 Remote Console Reports the Wrong Action to Take in Error Message
- The error message that appears when the core version and console version are mismatched was clarified.
-
830216 When deleting users in the Console, some other users lose their scope assignments
- Fixed the query that deleted the user from the ConsoleUserScope table. It was using the wrong column for the match on which user to delete.
XDD\UDD
-
794610 UDD on NT Domain triggers NMAP scan as well
- Removed redundant UDD scanning technology for NT Domains.
-
817216 Scanning network for unmanaged devices is stuck on step "OS detection completed"
- Fixed an issue where UDD scans could get stuck during the OS detection phase.
Known Issues
Agent
- 883482 EPM 2021.1 SU1 installs incorrect vulscan.sig file.
Vulscan
- 881646 Vulscan fails to run on macOS devices that are on network.