.Loading..Loading.
Readme Rev
Service Updates
When the downloaded patch is run, it will extract a .zip file to a folder. This file should be extracted and then the contained Setup.exe can be run. This table shows the name of the zip file.
Component | Core/Console |
---|
Installation Instructions
The following outlines instructions for installing this update.
This patch requires that Ivanti Endpoint Manager 2024 be installed. For more information about current service packs please see: Download the Latest Service Update for Ivanti Software Products
** For a list of Supported Platforms and Compatibility Matrix for this release of Ivanti Endpoint Manager please see this Community Atrticle: Supported Platforms and Compatibility Matrix for Ivanti Endpoint Manager
Prior to installing a patch on the Core Server it is recommended to make a backup of the Ivanti database.
Installing on the Core and Rollup Core
Because Alternate Data Streams (ADS) may block files on Windows systems, it is recommended that you extract the patch on the machine you are going to install it on.
Prior to installing a patch on the Core Server it is recommended to make a backup of the Ivanti database.
Steps
- Disable any services on other machines that interact with the Core Server
- Double-click on the self-extracting executable and extract it
- Extract the files for the Core patch
- From the extracted files, run Setup.exe
- When Setup completes, reboot the machine if a reboot is required
- After applying the patch, you may need to re-activate your Core Server using the Core Server Activation Utility
- Restart any services stopped in Step 1
Note: The installer included with this release writes a detailed log that can be used to help troubleshoot installation problems. After running setup.exe from the patch, the log is located in the \ManagementSuite\log folder.
Installing on Remote Consoles
A Remote Console is any machine that is not the Core Server and has the Ivanti Endpoint Manager Console installed. Console Machines need to be updated to the same version as the core server to be able to connect to the updated Core Server and Database.
Because Alternate Data Streams (ADS) may block files on Windows systems, it is recommended that you extract the patch on the machine you are going to install it on.
Steps
- Close the Console
- Double-click on the self-extracting executable and extract it
- Extract the files for the appropriate patch
- From the extracted files, run Setup.exe
- When Setup completes, reboot the machine if a reboot is required
Note: The installer included with this release writes a detailed log that can be used to help troubleshoot installation problems. After running setup.exe from the patch, the log is located in the \ManagementSuite\log folder.
Updating the Agent
The patch should be installed on the Core Server before updating Agents
Use one of the following methods to re-deploy the agent once the patch has been applied to the Core or to apply the patch manually.
Methods of agent deployment
-
Manual: Map a drive to \\Coreserver\ldlogon and run 'EPMAgentInstaller.exe'
This is best suited for single client installs and testing. - Push: Schedule a push of the full agent
- Self-Contained EXE: Create an EXE that can be installed
- Advance Agent: This is a two stage process. The Advance Agent consists of a small MSI and a self-contained EXE. The MSI is deploy to the client and then the MSI downloads and installs the EXE. This allows for bandwidth friendly downloads.
For more information on agent configuration and deployment see Agent Deployment for Ivanti Endpoint Manager and Endpoint Security
Manual installation of the client patch
The client patch is no longer available. For more information see this Community Article: Ivanti Community Doc - EPM SU Client Patch
Updating the Agent With Patch Manager
Agent updates are no longer supported using Patch Manager. For more information see this Community Article: Ivanti Community Doc - EPM SU Client Patch
Release Information
This section has information about changes that are new to this service update. This service update is inclusive of changes made in all previous service updates for EPM 2024. For the changes made in previous service updates, see the readme files for each of those. See the Ivanti Endpoint Manager (EPM) Version Information page.
Please review the following important information about this release BEFORE installing this update.
Feature Changes and Updates
The following features have been changed or updated
Agent Common
- 1373407 Support for Windows 11 (24H2)
- Added support for the Windows 11 24H2 release.
- 1506432 Support for Windows Server 2025 as a Managed Device
- Added support for Windows Server 2025 as a managed device.
Linux Agent
- 1536420 Support for Ubuntu 24.04 as a Managed Device
- -
Mac
- 1246232 Chat feature for macOS Remote Control
- Mac users now have access to chat features in remote control.
- 1390303 Support macOS 15 Sequoia as a Managed Device
- Added support for macOS 15 Sequoia as a managed device.
Patch Management
- 1144568 Minimizing non-essential reboots
- Reboot prompts have been optimised to occur only when necessary, reducing non-essential restart requests.
- 1376138 Check for updates option in EPM console
- A new option has been added under the Help dropdown menu in the Windows console to check for product updates.
- 1486148 Add Office 2024 product in Patch Download filters
- Supports for patching filtering for Microsoft Office LTSC 2024 application.
Provisioning
- 956431 BitLocker Controls available as an Action in Provisioning
- BitLocker controls have been added to Provisioning as an action.
Web Console
- 925859 Run Inventory and Patch Compliance Scan from Web Console 2.0
- Inventory and Patch Compliance scans can now be initiated from Web Console 2.0.
- 926214 Full Inventory View in Web Console 2.0
- Web Console 2.0 now shows full device inventory view.
Defects Fixed
Adaptive Settings
- 1482629 When "adaptive settings" is enabled based on IP range, if the network is not able to connect to EPM core, it takes 10-15 minutes to change security policy
- When Adaptive Settings uses an IP address range and is unable to connect to the EPM core server, it now switches the security policy more quickly.
Agent Common
- 1378284 The Diagnostics tool does not gather full EBA logs
- Updated the Diagnostics tool to collect logs from C:\ProgramData\Ivanti\EPM Agent\Logs
- 1417629 EPMAgentInstaller.exe gets deleted when creating EBA install files inside LDLogon folder
- Updated the process of creating EBA install files to prevent them from being created in the ldlogon folder on the core server.
Agent Configuration
- 1475943 Agent Configuration is not available when a non-admin account in Windows to launch the remote console
- Agent Configuration is now available when launching the Windows remote console with a non-admin account.
Alerting
- 1281416 Email alerts not sending
- Email alerts are being sent out as expected.
- 1281429 Unable to log alerts HDD usage and RAM Usage
- Fixed the issue where Alert ruleset XML files were not being copied to the cbaroot directory on the client, preventing alert logs from being generated in the console under " Tools > Reporting/Monitoring > Logs ".
- 1281495 Duplicate entries in Alert ruleset
- The issue is resolved
- 1281637 When installing the EBA agent on a computer with 2 hard drives, some driver files are incorrectly installed on the second hard drive
- Corrected the EBA installer to ensure all installation files are properly placed on the system drive.
- 1281641 Health Dashboard reports: Error An unknown error was encountered
- Health Dashboard reports work as expected.
- 1478937 Unable to create "Device Monitor System Connectivity" Alert in custom ruleset
- The issue is fixed, that prevent ability to create "Device Monitor System Connectivity" Alert in custom ruleset
Data Analytics
- 1281619 Error when trying to Archive Asset but Archive may still work.
- Archiving assets completes successfully.
- 1482638 Data Translation Services Import Data rule does not populate tables data
- The DTS import issue has been fixed.
Endpoint Security
- 1281505 Manual Network Isolation Crashes EPS on Off-Network Devices
- Network isolation in EPS is working as expected.
- 1281511 EPS Prevents Upgrade to Windows 11
- The issue is fixed
- 1281645 The printer is allowed to print when connected with USB, regardless of what Device Control settings
- Device Control properly block printers
- 1281657 Error when downloading File Reputation files
- This issue is fixed
- 1389796 Unable to retrieve BitLocker keys after side-by-side migration
- BitLocker keys are now accessible through the Windows console after a side-by-side migration.
- 1396353 Vulscan UI is shown while installing EBA with EPS enabled
- The vulscan UI no longer appears when the EBA Agent is installed with EPS enabled.
- 1408921 Fail to Import Windows Firewall Settings
- Windows firewall settings import issue has been fixed.
- 1421027 LdUrlHandler.Installer.exe is being flagged by AV vendors as a bad file
- LdUrlHandler.Installer.exe is updated and signed with by Ivanti.
- 1431392 Unable to import Endpoint Security or Device Control agent setting from EPM 2022 to EPM 2024
- Endpoint Security and Device Control agent settings can now be imported from EPM 2022 to EPM 2024.
- 1480230 Adaptive settings is not able to change EPS settings properly
- Adaptive Settings can correctly modify EPS settings.
- 1482492 Error Device Control String not found
- The UI has been updated to display the correct string for Device Control in the Devices list.
- 1482587 'Show start menu shortcut in Ivanti Management group' does not work for EPS in the EBA agent.
- Start Menu shortcut for EPS is now working
- 1482630 Switch off button does not function on EPS client UI
- The issue with the main toggle switch that disabled all settings in the EPS UI has been fixed and is now working as expected.
- 1482659 EPS installs daily on EBA agents due to EPMAgentInstaller.exe not detecting the WSCFG path correctly
- In the EBA agent, the EPS installation issue has been fixed to prevent daily installs.
Engine-Based Agent
- 1281443 Issues with building EBA Agent from Agent Configuration from a Remote Console
- Fixed the right-click option in the Windows Console to create EBA installers from a remote Windows console.
- 1482650 EBA does not run "Include software in inventory scan during installation"
- The EBA now runs the action for "Include software in inventory scan during installation".
- 1482655 The SelfContainedEpmAgentInstall.msi requires elevation but does not prompt for it so the installation does not run
- SelfContainedEpmAgentInstall.msi corrected to elevate permissions for the agent install.
Ivanti Antivirus
- 1475314 The edit button for File Protection Exclusions is not working
- The issue is fixed
- 1482654 In Ivanti Antivirus 2017, Mac Agent settings not allowing some Characters to be used in Exclusions list
- In Ivanti Antivirus 2017, Mac Agent settings have been corrected to allow characters in the exclusions list.
Mac
- 1281490 macOS MDM profiles are being consistently re-applied to customer's devices
- macOS MDM profiles are now applied correctly.
Patch Management
- 1281358 Patch campaign progress doesn't update the "% of device" field
- This issue is fixed where the "% of device" field was not updating correctly.
- 1281592 Office Updates, All language packs and proofing tools are not being downloaded
- Customers can now download Office updates that include multiple language packs and proofing tools, with the proofing tools also included in the download.
- 1356194 Duplicate storage of patch files when using "Download patches from manufacturer"
- The duplicate file has now been removed.
- 1408922 Some Patch Vulnerability Summary Reports are not reporting correctly.
- Patch Vulnerability Summary reports are now fully functional and visible for all options.
- 1418596 Office 365 Repair task does not work if any Microsoft Office application is open
- When performing a repair on a managed device with a Microsoft Office application open, and if the permission to terminate the open process is enabled, the repair task will close the Office application, allowing the patches to be successfully applied.
- 1427732 Scheduled Content Download task freezes if expiration date is less than 30 days
- The issue is fixed
- 1427738 Patch Automation created "June 2024" task twice
- Patch automation tasks will no longer have duplicates.
- 1430111 No longer download HTTPS files via preferred server
- Downloading files through preferred server should now work fine.
- 1476407 ESU patches are not working
- Extended Support Update (ESU) patching is now fully functional.
- 1482598 "Failed to Create Package" during EPM Patch
- The issue has been resolved
Power Management
- 1281596 Power Management Shutdown does not always succeed
- Power Management soft shutdown scheduling is now working as expected.
Provisioning
- 1514096 Unzip handler fails after January 2025 security update
- Fixed an issue with the unzip action in Provisioning.
Remote Control
- 1482641 Remote Control Summary report is blank
- The Remote Control Summary report has been corrected.
- 1484554 RC Unable to Reconnect after Signing off or Switching User Account
- The issue is fixed
Software Distribution
- 1281646 Distribution and Patch Settings MSI "Run as information" being applied for non-MSI files
- The issue is fixed, where the "Run as information" setting in Distribution and Patch Settings MSI was applied to non-MSI files.
- 1432455 Distribution Packages GUI View doesn't adjust size correctly.
- Window sizing has been corrected.
- 1475913 Package Studio does not load in EPM 2024
- Package Studio now works as expected in EPM 2024.
- 1482640 Delete Scheduled Task event logged the wrong user in Auditing
- The correct user is now logged in the Delete Scheduled Task event logged in Auditing.
- 1529953 Blank UI in software distribution Windows Actions packages after Jan hotpatch
- The issue is resolved, for the blank UI issue in the Windows Actions dialog
Software License Monitoring
- 1465538 Software License Monitoring for blocked application shown in English instead of Japanese on Japanese OS
- SLM Blocked application now displays in correct language.
Web Console
- 1417667 Web Console 2.0 is not displaying dashboard information for Reporting / Vulnerabilities
- The dashboards for reports and vulnerabilities have been fixed.
Windows Console
- 1297088 Help URL Fails for Unsupported Languages, Should Fall Back to English
- The Help URLs in non supported languages will default to English.
- 1482356 CPU Load climbs every time you change layout in the Windows Console
- Resolved issues with CPU resources for the Windows Console related to changing the layout.
Known Issues
Endpoint Security
- 1299430 During Agent Upgrade to EBA, Uninstalling Old Agent Fails when EPS Protection is Enabled
- In some environments using Endpoint Security (EPS), sometimes upgrading an old agent to EBA (Engine-Based Agent) the upgrade fails. EPS prevents access to the registry key containing the path to the old agent files in SOFTWARE\LANDesk\ManagementSuite. This leaves some old agent services running, such as softmon, and leaves the client in a broken state with some old agent and new agent services installed. The workaround for this is to disable EPS protection before the agent upgrade. This can be done a single machine by doing the following: 1) Enable the EPS UI icon to show up in the system tray by going into the EPS configuration on the core. 2) Right-click the system tray icon on the client device and disable EPS protection. 3) Install the agent. 4) The EpmAgentInstaller.exe log will show "Attempting to remove old EPM agent" which confirms its working and then the upgrade succeeds. To upgrade multiple machines at once, first disable EPS and then install the EBA agent.
Install
- 1565503 Service Update Install Fails at "Configuring Certificate for Inventory Web Service”
- The following article explains more details: Configuring Certificate for Inventory Web Service
Provisioning
- 1566355 New Bitlocker feature in provisioning is missing
- The following article explains more details: New Bitlocker feature in provisioning is missing