Auto App: Teleport Connect
A new Auto App, Teleport Connect, has been added to the catalog and is now available for all customers.
See all available Auto Apps in the Library Items section of our website.
New features, improvements, and fixes shipping across the platform.
Follow @officiallyiru ↗A new Auto App, Teleport Connect, has been added to the catalog and is now available for all customers.
See all available Auto Apps in the Library Items section of our website.
A new Auto App, Gather, has been added to the catalog and is now available for all customers.
See all available Auto Apps in the Library Items section of our website.
A new Auto App, Foxit PDF Reader, has been added to the catalog and is now available for all customers.
See all available Auto Apps in the Library Items section of our website.
A new Auto App, Foxit PDF Editor, has been added to the catalog and is now available for all customers.
See all available Auto Apps in the Library Items section of our website.
A new Auto App, Dia, has been added to the catalog and is now available for all customers.
See all available Auto Apps in the Library Items section of our website.
A new Auto App, Cavalry, has been added to the catalog and is now available for all customers.
See all available Auto Apps in the Library Items section of our website.
A new Auto App, AppCleaner, has been added to the catalog and is now available for all customers.
See all available Auto Apps in the Library Items section of our website.
New Windows Auto Apps have been added to the catalog and are now available for all Iru Endpoint customers.
See all available Auto Apps in the Library Items section of our website.
Mac Custom App, Custom Script, and Custom Printer Library items now support being hidden in Liftoff or displaying a "friendly name" to the end user instead of the Library Item name.
Liftoff will show "Processing additional required configurations before proceeding…" when processing hidden items, and setting a friendly name does not change the ordering of...
We’ve released Iru Agent for Mac 5.1.28 (5393).
This release includes miscellaneous bug fixes and performance improvements. Additionally it brings support for the new Hide in Liftoff and Liftoff friendly name options for Custom App, Custom Script, and Custom Printer Library Items.
Highlights we cover this week in What's New in Iru:
Windows Update Library Item now features native Iru AI integration for a guided experience
Windows System Tray app gives employees visibility into pending updates with deadlines
New Auto Apps added for Windows and Mac
Device system health statuses for supported hardware components (such as camera, NFC, baseband, Touch ID, etc.) are now shown in Iru on the device record for supported devices running iOS or iPadOS 27 beta.
These values are also available in the enterprise API device details endpoint.
Select Sync Frequency for Directory Sync Integrations - It is now possible to choose the sync frequency interval for each directory sync integration. Choices include: Manual Only, Every 30 minutes, every hour, 2 hours, 4 hours, 8 hours, 12 hours, daily, every 2 days, or weekly.
Added Refresh and Sync Now...
We’ve released Iru Agent for Mac5.1.26 (5392).
This release includes miscellaneous bug fixes and performance improvements.
Admins can now require company-owned Android devices with a work profile to be signed in with a managed Google Account, ensuring end users have full access to the organization's Google Workspace services.
The Android Restrictions Library Item includes a new managed Google Account setting with two modes: allow any managed Google Account from the...
Iru admins can now control which apps are allowed to act as credential managers, such as password managers and passkey providers, in the work profile on managed Android devices. The Android Restrictions Library Item includes a new Credential managers setting that sets the default policy: block all credential managers, or allow the device's pre-loaded system...
Mac Auto Apps now support enforcing a specific version, selecting from a list of Iru hosted versions.
Devices installing the Auto App for the first time or that are out of date will install the selected version instead of the latest available.
Iru Vulnerability Response overrides these settings if applicable.
Single Sign On (SSO) pre-configuration templates are now available for 209 commonly used web applications, including Slack, Zoom, Google Workspace, and more! The templates guide Identity administrators through the steps needed to set up SAML or OIDC single sign-on and can also assist with SCIM user provisioning configuration. Iru is continuously adding new...
Managed OS for iOS and iPadOS has been updated. The latest approved versions are now 26.6.1 and 18.7.10, with the following release dates:
iOS 26.6.1 : Aug 17, 2026
iOS 18.7.10 : Aug 17, 2026
iPadOS 26.6.1 : Aug 17, 2026
iPadOS 18.7.10 : Aug 17, 2026
Managed OS for macOS has been updated. The latest approved version for Tahoe is now 26.6.2, with the following release date:
macOS 26.6.2 : Aug 17, 2026
Highlights we cover this week in What's New in Iu (Black Hat 2026 edition):
Windows devices now show a list of Auto App and Custom App updates that haven't installed yet right from the new Iru system tray app. End users can install one update at a time or use Update all, closing open apps when needed to complete the install, and the list clears itself as installs succeed.
Google Cloud Platform is now available in the Iru Compliance connector catalog, replacing the previous coming-soon placeholder.
Connect the Google Cloud project you want Iru to monitor using a read-only service account and JSON key, and Iru collects configuration and inventory evidence across Google Cloud IAM, Cloud Storage, Cloud KMS, Cloud Logging,...
We’ve released Iru Agent for Mac 5.1.25 (5391).
This release includes miscellaneous bug fixes and performance improvements.
The Owner and Delegate filters on the Actions list within Compliance Automation now include an Unassigned option, so admins can find the actions nobody owns yet without scanning the table. This pairs with the separate Owner and Delegate columns added in May.
Highlights we cover this week in What's New in Iru:
Devices held in Setup Assistant while Library Items install can now be released manually. This applies to devices enrolling via Automated Device Enrollment and devices migrating into Iru with managed apps preserved. While a device is held at the Configuring screen, a banner appears at the top of the device's record in the Iru web app showing when the hold...
Managed OS for macOS has been updated. The latest approved version for Tahoe is now 26.6.1; for Sequoia, 15.7.9; and for Sonoma, 14.8.9, with the following release dates:
macOS 26.6.1 : Aug 06, 2026
macOS 15.7.9 : Aug 06, 2026
macOS 14.8.9 : Aug 06, 2026
In the Software Update Library Item, Apple beta program enrollment can now be offered to end users to opt-in, or a specific program can be enforced without needing to enforce a specific version alongside the enrollment.
Iru now supports three different ways to manage Apple beta program enrollments and version enforcements:
The Single Sign-On Extension Library Item now supports configuring Authenticated Guest Mode when using Platform SSO with macOS.
The new phased rollout option previously introduced for Mac Auto Apps is now available for Apple Managed OS. Phased rollouts give admins more control over how updates are introduced across their fleet.
Instead of sending a new declaration to every device at the same time once a new version is available from Apple, admins can enable phased rollout and...
A new Auto App, Screen Studio, has been added to the catalog and is now available for all customers.
See all available Auto Apps in the Library Items section of our website.
A new Auto App, Glean, has been added to the catalog and is now available for all customers.
See all available Auto Apps in the Library Items section of our website.
A new Auto App, Elgato Stream Deck, has been added to the catalog and is now available for all customers.
See all available Auto Apps in the Library Items section of our website.
A new Auto App, AltTab, has been added to the catalog and is now available for all customers.
See all available Auto Apps in the Library Items section of our website.
New Windows Auto Apps have been added to the catalog and are now available for all Iru Endpoint customers.
See all available Auto Apps in the Library Items section of our website.
We’ve released Iru Agent for Mac 5.1.22 (5390).
This release includes miscellaneous bug fixes and performance improvements.
When using the Rolling Enforcement option with Managed OS for Apple devices, it's now possible to specify an automatic delay (up to 90 days) that will prevent Iru from sending a new target version declaration to devices.
This delay embedded in Managed OS can be combined with Apple software update deferrals (configured in a Software Update Library Item) to...
Exclude specific users from a policy assignment. When publishing or updating a policy, admins can now exclude specific users from the assignment. This is useful when a policy applies broadly but has a handful of exceptions who shouldn't be asked to acknowledge it.
Admins and auditors can now re-include a user who was previously excluded from a policy...
Version 1.2.4 of the Iru ServiceNow integration is now available on the ServiceNow store and supports the Australia release of ServiceNow.
A new Assignment Rule is now available on Assignment Maps to assign Library Items to devices based on beta program enrollment status. Assignments can be made on whether a device is enrolled in any beta program at all, or based on specific enrollment(s).
Managed OS for macOS has been updated. The latest approved version for Tahoe is now 26.6; for Sequoia, 15.7.8; and for Sonoma, 14.8.8, with the following release dates:
macOS 26.6 : Jul 27, 2026
macOS 15.7.8 : Jul 27, 2026
macOS 14.8.8 : Jul 27, 2026
Managed OS for iOS, iPadOS, and tvOS has been updated. The latest approved version is now 26.6, with the following release dates:
iOS 26.6 : Jul 27, 2026
iPadOS 26.6 : Jul 27, 2026
tvOS 26.6 : Jul 27, 2026
Highlights we cover this week in What's New in Iru:
Policy generation framework picker limited to available frameworks. The framework picker in the policy generation intake now only lists the frameworks a tenant is entitled to (SOC 2, ISO 27001, HIPAA, GDPR by default), so admins never see options they can't actually generate against.
Choose a framework for policy generation intake. Admins can now select the...
The following new restrictions are available in Iru for devices testing the macOS 27 Apple beta release:
ForceCaptivePortalConnectionFromLockScreenForceWifiConfigurationOnLockScreenAdditionally, the following existing restrictions can now be applied to visionOS 27+:
allowAutomaticAppDownloadsallowCameraallowListedAppBundleIDsblockedAppBundleIDsAppleCare enhanced log collection can now be requested from devices running iOS and iPadOS 27, currently in beta.
Support for requesting enhanced log collection from Mac computers will be coming later.
Bulk Device Exclusion
Bulk Device Exclusion lets you exclude multiple devices from Vulnerability Management in a single action, and remove exclusions the same way. Excluding a device hides that device from all vulnerability views, detection counts, and alerts, which is useful for taking a machine temporarily out of scope, such as a device pending...
When using the option to customize what gets installed during Automated Device Enrollment for Mac, Auto Apps or Okta Verify with Okta Device Trust now receive their Iru managed configuration profiles (PPPC, background items, etc.) during Setup Assistant, ensuring full functionality when the end user is released out of Setup Assistant.
Apple devices now show their public IP address on the device record > details tab, in the new optional Prism column, and in the enterprise API device details endpoint.
Devices' public IP addresses are captured during their daily full MDM check-in.
Apple beta program enrollment and version enforcement is now available for iOS and iPadOS in Managed OS and ADE Library Items. Support for macOS was previously added.
Additionally, any Apple device enrolled in an Apple beta program will now show its program enrollment on the device record > details tab, in the new optional Prism column, and in the...
We’ve released Iru Agent for Mac 5.1.21 (5389).
This release includes improvements to the MSDC registration process.
Highlights we cover this week in What's New in Iru:
The Artifacts table now shows a Status column that surfaces evidence sufficiency for each artifact, making it clear at a glance which artifacts still need review versus which fully cover their mapped controls.
We’ve released Iru Agent for Mac 5.1.20 (5388).
This release includes miscellaneous bug fixes and performance improvements.
Reminder emails for employees with pending policy acknowledgements now send once a week, on Mondays, instead of once a day. The content of the reminder is unchanged — the same pending acknowledgements arrive in one weekly email rather than a daily one.
Control names and descriptions for ISO 27001 and ISO 42001 frameworks are locked from edits to preserve the framework's official language. Local overrides can still be captured in your organization's implementation notes.
Framework deletion restricted to account owners.Only account owners can delete a framework from an organization now. This prevents accidental deletion of a framework mid-audit by admins or auditors who shouldn't have that authority.
Type-to-confirm before deleting a framework.Deleting a framework now requires typing the framework's name into a...
Highlights we cover this week in What’s New in Iru:
Managed OS for Apple Library Item updates
Managed OS for Windows now available
Proactive ServiceNow updates
The controls list on a framework now supports a "needs review" filter that surfaces only the controls whose actions still need admin attention, helping teams focus on the remaining work in a framework rollout.
We’ve released Iru Agent for Mac 5.1.18 (5387).
This release includes miscellaneous bug fixes and performance improvements.
Managed OS for macOS has been updated. The latest approved version for Tahoe is now 26.5.2, with the following release date:
macOS 26.5.2 : Jun 29, 2026
Managed OS for iOS and iPadOS has been updated. The latest approved version is now 26.5.2, with the following release dates:
iOS 26.5.2 : Jun 29, 2026
iPadOS 26.5.2 : Jun 29, 2026
Highlights we cover this week in What’s New in Iru:
The ability to exclude specific devices from Vulnerability Reports
Support for changes to Microsoft Entra ID Conditional Access
Updated Config as Code tooling, iructl, alongside other frameworks
Administrators can now enforce a specific Windows 11 feature version across their fleet using Managed OS Library Items. This gives you direct control over which build your Windows 11 computers run, so you can keep devices on a known-good version instead of relying on each computer to update on its own schedule.
Each Managed OS Library Item supports...
Wildcard support in the EDR Library Item provides greater flexibility when managing allow and block lists.
This update introduces recursive wildcarding. Administrators can establish dynamic, broad-matching rules rather than specifying exact paths or filenames individually, streamlining configuration within the interface.
A new Windows Auto App, Iru Access, has been added to the catalog and is now available for all Iru Endpoint customers.
See all available Auto Apps in the Library Items section of our website.
The Automated Device Enrollment Library Item for Apple devices has been updated with the following enhancements:
Managed OS Library Items for Apple devices now support enforcing beta releases using AppleSeed for IT beta tokens provided through Apple Business. These beta tokens synchronize to Iru automatically with configured Automated Device Enrollment (ADE) integrations.
Additionally, automated upgrade timing is now separate from updates and has its own enforcement...
Highlights we cover this week in What’s New in Iru:
Unified view for all Activities across the platform
Updated Managed OS Library Items for Endpoint Management
Helper tool prompts blocked for Mac Auto Apps
New side-by-side view for easier collaboration with Iru AI
Microsoft Entra ID (identity) and Arnica (developer security) are now available in the Iru Compliance connector catalog, adding two more sources for automated identity and code-security evidence.
We’ve rebranded and released updates to the following open source enterprise API utilities:
Kandji Sync Tool (kst) has been renamed to Iru Control (iructlv1.3.0) , Kandji Packages (kpkg) to Iru Packages (irupkgv2.1.0), and Kandji AutoPkg Processor Actions (KAPPA) to Iru Orchestration Tool for AutoPkg (IOTAv1.1.0). These rebrands are fully backwards...
Vulnerability Management now supports excluding specific devices from vulnerability reporting.
You can exclude a device directly from its device record or from the Devices tab within any CVE detail view. Excluding a device removes it from all CVE affected device counts across your fleet and stops vulnerability notifications from being sent for that device....
We’ve released Iru Agent for Mac 5.1.16 (5386), which now makes smarter decisions about when to download managed software if the current connection is believed to be constrained (like on Low Data Mode), expensive (like a mobile hotspot), or both.
The Trust Center editor now lets admins tune the opacity of their logo image so it looks right against different background treatments in their public trust page.
Endpoint Detection and Response for Windows is now generally available.
Endpoint Detection and Response (EDR) for Windows brings file-based threat detection and automated response to your Windows endpoints. Malicious files, PUPs, and unknowns are automatically categorized and acted on, keeping your fleet protected from the moment devices enroll.
Deploy via...
CMMC and ISO 27701 are now available as frameworks in Iru Compliance, with AI-generated controls and actions and coverage tracking across each framework's full requirement set.
Highlights we cover this week in What’s New in Iru:
New Iru AI features and capabilities
EDR alerts now deliverable via Microsoft Teams
New framework in Compliance Automation: NIST CSF 2.0
Auto App support for MSIX applications from our Windows Agent
The intake form for AI policy generation has been reorganized into clearer field groups, with tighter spacing and improved handling of long-form inputs.
A new unified activity experience is now available through our classic activity page for easier debugging and tracking across your environment. Unified Activity brings all of your events into one timeline across Endpoint, Detections, Vulnerabilities, and Compliance. You can switch to the new view whenever you're ready. The new experience includes full JSON...
The new phased rollout option for Mac Auto Apps gives admins more control over how updates are introduced across their fleet.
Instead of offering a new version to every device at the same time, admins can enable phased rollout and choose a rollout window between 1 and 7 days (in hours). Devices are then offered the update gradually over that period, helping...
Managed OS Library Items for Apple devices now have an updated look and feel and offer powerful new levels of control for IT teams, with more coming soon.
IT teams can now define a specific version (and optional build) to enforce on devices.
Time enforcement has also been enhanced to allow for any time instead of predefined 30 minute increments.
More...
Policies uploaded through the Policies overview now appear with a Draft status until an admin explicitly publishes them, replacing the previous behavior where uploads went straight to published.
The Policies list now surfaces AI generation jobs that are still running, along with any that failed, so admins never have to wonder whether their generation request is queued, in progress, or stuck.
We’ve released Iru Agent for Mac 5.1.13 (5385).
This release includes miscellaneous bug fixes and performance improvements. Additionally, it includes improvements for handling new Microsoft Conditional Access requirements in Iru Passport. For more details on these changes, reference our product documentation.
Microsoft Teams notifications give administrators the ability to receive alerts about detections directly within their communication platform.
This feature allows the configuration of Microsoft Teams notifications in the same manner as existing Slack integrations. Administrators can manage alert routing for the Detections section to ensure visibility into...
Managed OS for macOS has been updated. The latest approved version for Tahoe is now 26.5.1, with the following release date:
macOS 26.5.1 : Jun 01, 2026
Managed OS for iOS has been updated. The latest approved version is now 26.5.1, with the following release date:
iOS 26.5.1 : Jun 01, 2026
Iru Self Service for iOS and iPadOS will begin rolling out globally on June 3, 2026, at 10:00 AM PDT as an update to the existing Kandji Self Service app. Iru Self Service will show as Iru on the Home Screen. The bundle ID remains io.kandji.Self-Service-Mobile.
The Actions table now splits the previous single "Team" column into distinct Owner and Delegate columns, so it's clear at a glance who's responsible for driving each action versus who's supporting.
App inventory and usage information is now able to be sent from Iru to ServiceNow for customers licensed for SAM Pro.
For more details, consult our product documentation.
A new AD CS connector is now available for Iru tenants.
If you still use AD CS from a Kandji tenant, first upgrade your tenant to Iru, then install the new connector from your Iru tenant. During cutover, you can run the legacy and new connectors on different servers. You can reassign AD CS servers using Assign servers once the new server is approved, or...
Admins can now refresh the credentials of an already-enabled source directly from the source's row. There's no need to disconnect and reconnect the integration to rotate an expiring token.
Uploading a new questionnaire in the Trust Center is now restricted to admin roles, matching the permission model used elsewhere in the product.
We’ve released Iru Agent for Mac 5.1.12 (5384).
This release includes miscellaneous bug fixes and performance improvements.
Specifically, this release brings further performance enhancements to application inventory collection for customers using Iru Endpoint but not Iru EDR.
File and Behavioral Detections are combined into a single view. This update includes a filter to isolate either file detections or behavioral detections. The Threat Status column is normalized to align consistently across both detection types.
Note, this update modifies solely the interface and does not alter underlying data.
Settings to configure Windows Autopilot for MDM auto-enrollment to Iru during out-of-box experience (OOBE) on new Windows devices are now available under Integrations in Iru. The one-time setup covers app registration in Microsoft Entra ID and a custom domain for your tenant.
The setup provides a guided flow with step-by-step instructions and lists the...
Acknowledgement exports now include the specific policy each acknowledgement was for as well as the acknowledgement date, so audit-ready records are one click away.
Organizations using Iru's Okta Device Trust (ODT) integration can now configure the integration on the Okta Verify Auto App for Mac in addition to, or instead of, on the App Store App version. Assignment Maps ensure only one or the other will be installed on Mac computers at one time. Using the Auto App provides an easier setup process and improved update...
Iru MCP is a Model Context Protocol integration that exposes the Iru Endpoint Management API as MCP tools for assistants such as Claude, Cursor, and other MCP-enabled clients.
Create an API key and enable MCP for the API key in Iru. After setup, Iru displays the token once together with a ready-to-paste MCP configuration for HTTP transport: MCP server URL,...
A new Auto App, Okta Verify, has been added to the catalog and is now available for all customers.
See all available Auto Apps in the Library Items section of our website.
When the enforcement deadline for a Windows Custom App or Auto App arrives and a blocking process is still running, users now see a 5-minute countdown dialog. The dialog names the app, gives users time to save their work, and offers two options: Update now, which closes the app immediately and runs the install, or Delay for 1 hour, which defers the...
The Users table now supports filtering by a specific policy and sorting by acknowledgement count, so admins can quickly see, for example, who hasn't acknowledged a given policy yet.
Every published policy now shows its current acknowledgement count on the policy's detail page, giving admins immediate visibility into rollout progress without digging into the Users table.
We’ve released Iru Agent for Mac 5.1.12 (5383).
This version improves the sequencing of installing agent Library Items during the configuring stage (await_device_configured) of Automated Device Enrollment (ADE).
Managed OS for iOS, iPadOS, and tvOS has been updated. The latest approved versions are now 26.5, 18.7.9, and 17.7.11, with the following release dates:
iOS 26.5 : May 11, 2026
iOS 18.7.9 : May 11, 2026
iPadOS 26.5 : May 11, 2026
iPadOS 18.7.9 : May 11, 2026
iPadOS 17.7.11 : May 11, 2026
tvOS 26.5 : May 11, 2026
Managed OS for macOS has been updated. The latest approved version for Tahoe is now 26.5; for Sequoia, 15.7.7; and for Sonoma, 14.8.7, with the following release dates:
macOS 26.5 : May 11, 2026
macOS 15.7.7 : May 11, 2026
macOS 14.8.7 : May 11, 2026
NIST CSF 2.0 and NIST 800-53 are now available as frameworks in Iru Compliance, with AI-generated controls and actions and coverage tracking across each framework's full requirement set.
Policies can now carry a due date, giving admins a clear target for when an assigned policy should be acknowledged by employees.
Each row of the Users table now shows badges for the policies that user has (or hasn't) acknowledged, letting admins spot gaps across the workforce at a glance.
We’ve released Iru Agent for Mac 5.1.8 (5382).
This version addresses an issue where the Iru Agent for Mac may not have fully uninstalled itself after unenrolling a device.
The Migration Assistant Library Item for Mac provides the ability to customize what should be migrated or excluded during Mac-to-Mac migrations during Setup Assistant for target Mac computers running macOS 26.4 or later.
Using declarative device management (DDM), this declaration is automatically delivered to devices and applied during Setup Assistant if...
Settings to configure Platform Single Sign-On (PSSO) in Setup Assistant for macOS 26 Tahoe are now available in the Single Sign-On Extension Library Item.
To configure PSSO in Setup Assistant, configure the Install Library Items during Setup Assistant option in an ADE Library Item. Add a Single Sign-On Extension Library Item along with an app from a...
This version adds support to install Library Items during Setup Assistant that are specified in the Install Library Items during Setup Assistant option in ADE Library Items. Additionally, it brings performance enhancements to application inventory collection.
Library Items can now be installed during Setup Assistant for devices enrolling via Automated Device Enrollment. Inside the Automated Device Enrollment Library Item, turn on Install Library Items during Setup Assistant for a platform and add Library Items to install. The device is held at the Configuring screen during ADE enrollment until every Library Item...
A new scheduled job now sends reminder emails to newly onboarded employees who have policies pending acknowledgement, so nothing slips through the cracks in the first days on the job.
User-level policy acknowledgement tracking.Iru Compliance now tracks each user's policy acknowledgements individually, giving admins a durable, per-user record of every accept and re-accept for every policy.
Only PDF and DOCX allowed for policy artifacts.Policy artifact uploads are now restricted to PDF and DOCX file types to keep the policy library clean...
Employees now have a dedicated My Policies portal for reviewing and acknowledging the policies assigned to them, with assignments, reminders, and acknowledgement receipts all flowing through the same experience. Employees whose only role is the employee role are automatically routed there on sign-in instead of the full admin console.
New Windows Auto Apps have been added to the catalog and are now available for all Iru Endpoint customers.
A new Auto App, Wispr Flow, has been added to the catalog and is now available for all customers.
See all available Auto Apps in the Library Items section of our website.
A new Auto App, Snagit 2026, has been added to the catalog and is now available for all customers.
See all available Auto Apps in the Library Items section of our website.
A new Auto App, MacVim, has been added to the catalog and is now available for all customers.
See all available Auto Apps in the Library Items section of our website.
A new Auto App, GlobalProtect 6.4, has been added to the catalog and is now available for all customers.
See all available Auto Apps in the Library Items section of our website.
A new Auto App, Druva inSync, has been added to the catalog and is now available for all customers.
See all available Auto Apps in the Library Items section of our website.
The Actions list now includes a "No framework" filter option so admins can quickly surface actions that haven't yet been mapped to a framework. This is a common cleanup task before an audit.
Creating an action now takes you straight to its detail view, with an AI-generated preview of the mapped controls and evidence-plan defaults ready for inline editing.
We’ve released Kandji Agent 5.1.2 (5380).
This release includes miscellaneous bug fixes and performance improvements. Additionally, this version addresses an issue that may have caused slower than usual logins in Passport.
A new Auto App, Gemini, has been added to the catalog and is now available for all customers.
See all available Auto Apps in the Library Items section of our website.
A new Auto App, Codex, has been added to the catalog and is now available for all customers.
See all available Auto Apps in the Library Items section of our website.
We’ve released Kandji Agent 5.1.2 (5379).
This release includes miscellaneous bug fixes and performance improvements.
Managed OS for iOS and iPadOS has been updated. The latest approved versions are now 26.4.2 and 18.7.8, with the following release dates:
iOS 26.4.2 : Apr 22, 2026
iOS 18.7.8 : Apr 22, 2026
iPadOS 26.4.2 : Apr 22, 2026
iPadOS 18.7.8 : Apr 22, 2026
Every policy now has a dedicated detail view including inline artifact preview and the assigned policy owner. This replaces the previous list-only experience.
A new policy library lets admins browse a curated catalog of common policies, upload their own, and classify them into the right category with a single flow.
A wave of new sources landed in April, covering edge and networking (Cloudflare), recruiting (Workable), cloud infrastructure (DigitalOcean, five GCP services), collaboration (Slack), application monitoring (Sentry), and code security (Semgrep). This brought the connector catalog to a substantially broader footprint.
Related control link on artifact side panel.The artifact side panel now includes a direct link to the related control, so admins can jump from an evidence artifact into the control it supports without navigating manually.
Artifact indicator on the Actions table.The Actions table now shows an indicator when an action has attached artifacts, giving admins...
DOCX artifacts now render inline in the preview panel, matching the existing PDF preview experience. There's no need to download a file just to check its contents.
Managed OS for macOS has been updated. The latest approved version for Tahoe is now 26.4.1, with the following release date:
macOS 26.4.1 : Apr 09, 2026
We’ve released Iru Agent for Mac (5.1.1 (5378)) and Windows (1.7.14).
This update rebrands the Kandji agent to Iru across all end-user facing apps, including the menu bar app, Self Service, Liftoff, and Passport.
Additionally, the kandji CLI tool on Mac has been renamed to iru and now includes a terminal user interface (TUI). To use the TUI, invoke sudo...
A dedicated Windows system tray application gives end users a clear prompt to close applications that block an install when an Auto App or Windows Custom App deployment runs.
The tray icon uses the Iru jelly-style mark. When an install targets processes you configured to detect as open apps, the tray application surfaces a prompt so users can close those...
Managed OS for iOS and iPadOS has been updated. The latest approved version is now 26.4.1, with the following release dates:
iOS 26.4.1 : Apr 08, 2026
iPadOS 26.4.1 : Apr 08, 2026
Device Isolation gives you the ability to immediately sever a network connection for any macOS device suspected of compromise. This feature, accessible directly within the Detections section, allows for rapid containment of active threats like malware or unauthorized lateral movement.
This feature was released in preview mode on March 5, 2026. Today, this...
The Windows Custom App Library Item deploys Win32 applications via MSI and EXE packages to Windows devices, with full control over installation, detection, and enforcement.
Upload a zipped installer containing your MSI or EXE and any supporting files, define silent install and uninstall commands, and configure detection logic so the agent knows whether the...
The manual enrollment portal has been rebranded from Kandji to Iru. All functionality remains the same.
The udid attribute is now available in the main /devices enterprise API endpoint, meaning it's no longer necessary to loop through each device to read this attribute.
Reference the enterprise API documentation for more details.
The restriction to Disallow Rosetta usage awareness (allowRosettaUsageAwareness) is now available in the Apple Restrictions Library Item.
This restriction turns off Rosetta usage awareness, which prevents a pop-up dialog being displayed to the user indicating that Rosetta will be removed in a future version of macOS. It deploys to macOS 26.4 and later.
Windows Server Update Services (WSUS) settings in the Windows Update Library Item control where Windows devices receive updates: an internal Windows Server Update Services (WSUS) server, Microsoft Update, or a combination of both.
The Update service URL can be configured to route devices to a WSUS server, while the update source for feature updates, quality...
The Sources page now supports full-text search, filtering by source category, and grouping AWS-family sources together, so browsing a growing integrations catalog stays manageable.
We’ve released Kandji Agent 5.0.1 (5376).
This update includes an informational banner in the Menu Bar App to inform end-users about the upcoming branding change on April 8 from Kandji to Iru, shown below.
For more information about what to expect in the branding change, see our product documentation.
The Threats tab in left navigation panel has been renamed Detections.
Additionally, "Threats by severity" and "Threats over time" have been renamed to "Detections by severity" and "Detections over time" on the Home page, Devices page, and in Iru AI.
For more information, see our support article.
A new Auto App, Windsurf, has been added to the catalog and is now available for all customers.
See all available Auto Apps in the Library Items section of our website.
A new Auto App, Zotero, has been added to the catalog and is now available for all customers.
See all available Auto Apps in the Library Items section of our website.
A new Auto App, Ollama, has been added to the catalog and is now available for all customers.
See all available Auto Apps in the Library Items section of our website.
A new Auto App, claude-devtools, has been added to the catalog and is now available for all customers.
See all available Auto Apps in the Library Items section of our website.
A new Auto App, Screaming Frog SEO Spider, has been added to the catalog and is now available for all customers.
See all available Auto Apps in the Library Items section of our website.
A new Auto App, LM Studio, has been added to the catalog and is now available for all customers.
See all available Auto Apps in the Library Items section of our website.
New Windows Auto Apps have been added to the catalog and are now available for all Iru Endpoint customers.
We’ve released Kandji Agent 4.7.5 (5374).
This release includes miscellaneous bug fixes and performance improvements.
Security
CVE-2026-39118 — An access control issue existed in the Kandji Agent (macOS). A local attacker with standard user privileges could invoke restricted functionality. This issue was addressed with improved validation.
Affected: Kandji...
Managed OS for iOS, iPadOS, and tvOS has been updated. The latest approved versions are now 26.4 and 18.7.7, with the following release dates:
iOS 26.4 : Mar 24, 2026
iOS 18.7.7 : Mar 24, 2026
iPadOS 26.4 : Mar 24, 2026
iPadOS 18.7.7 : Mar 24, 2026
tvOS 26.4 : Mar 24, 2026
Managed OS for macOS has been updated. The latest approved version for Tahoe is now 26.4; for Sequoia, 15.7.5; and for Sonoma, 14.8.5, with the following release dates:
macOS 26.4 : Mar 24, 2026
macOS 15.7.5 : Mar 24, 2026
macOS 14.8.5 : Mar 24, 2026
Control badges across the product now show the framework's native control code (for example, ISO's A.5.1) instead of a synthetic identifier, matching how auditors and admins actually refer to controls.
Actions now include an AI-suggested cadence (daily, weekly, quarterly, etc.) and an AI-suggested owner role on their detail page. The cadence suggestion is based on the underlying control's frequency requirements, and the owner role suggestion is based on the control's subject matter. Admins can accept either suggestion or override it.
The Windows Update Library Item gives you control over how and when updates install on Windows devices.
Configure auto update behavior with options ranging from notify-only to fully silent installs. Set active hours to protect users from disruptive restarts during the workday, and remove the ability for users to pause updates from the Windows Update...
Specific ADE Library Items can now be assigned directly to devices in the Awaiting Enrollment table, providing further flexibility to the ADE enrollment process. These assignments can be made on a one-off basis, in bulk, or via the enterprise API, and override what is assigned to the Blueprint or Blueprint Routing.
For more information, see our product...
We've released Kandji Agent 4.7.3 (5373).
This release includes miscellaneous bug fixes and performance improvements. Additionally, the last opened date/timestamp for Mac apps is now collected by the agent and submitted to Prism during daily check-ins.
The Kandji Agent now keeps track of when Mac apps were last opened throughout the day, as reported by macOS. The most recently recorded date/timestamp is submitted daily to Prism during the Kandji Agent's daily check-in. macOS regularly updates the last opened date/timestamp of apps as they are used, making this data useful for license monitoring and...
Routing Config Edited activity entries, logged when changes are made to Blueprint Routing, now include full before and after details of what changed.
The reset work profile passcode command is now available for Android devices. This command can be sent from the Devices page and the Iru enterprise API.
The reset work profile passcode command clears the current work profile passcode and lets you optionally set a new one for the end-user. If the device has an Android Work Profile Passcode Library Item...
License utilization information is now accessible from the Billing tab in the organization flyover for migrated Iru tenants, providing administrators with a consistent entry point for viewing product entitlements.
Administrators can view purchased licenses, assigned usage, and remaining capacity, including product-specific license views, all within a single...
Device Isolation gives you the ability to immediately sever a network connection for any macOS device suspected of compromise. This feature, accessible directly within the Threats section, allows for rapid containment of active threats like malware or unauthorized lateral movement.
Administrators can choose between two levels of isolation based on the...
Managed OS for macOS has been updated. The latest approved version for Tahoe is now 26.3.1, with the following release date:
macOS 26.3.1 : Mar 04, 2026
Managed OS for iOS and iPadOS has been updated. The latest approved versions are now 26.3.1 and 18.7.6, with the following release dates:
iOS 26.3.1 : Mar 04, 2026
iOS 18.7.6 : Mar 04, 2026
iPadOS 26.3.1 : Mar 04, 2026
Trust Center invitations can now trigger a DocuSign NDA signature request as part of the invite flow, so external reviewers sign before they get access instead of after.
The admin "Add account" modal in Trust Center now supports triggering a DocuSign NDA as part of manual account creation, matching the invite-based NDA flow.
As of today, Iru has removed the following Auto Apps from our catalog:
Any deployed configuration profiles bundled with these titles will be automatically removed from Mac computers at their next MDM check-ins.
However, these apps will not be removed from Mac computers if currently installed. Uninstallers for...
A new Auto App, BetterDisplay, has been added to the catalog and is now available for all customers.
See all available Auto Apps in the Library Items section of our website.
A new Auto App, Antigravity, has been added to the catalog and is now available for all customers.
See all available Auto Apps in the Library Items section of our website.
A new Auto App, Text App, has been added to the catalog and is now available for all customers.
See all available Auto Apps in the Library Items section of our website.
A new Auto App, Duo Desktop, has been added to the catalog and is now available for all customers.
See all available Auto Apps in the Library Items section of our website.
A new Auto App, CapCut, has been added to the catalog and is now available for all customers.
See all available Auto Apps in the Library Items section of our website.
Questionnaire answers can now be sourced from your knowledge base. The previous restriction that limited data source selection to trust-center content has been removed.
We’ve released Kandji Agent 4.7.3 (5372).
This release includes miscellaneous bug fixes and performance improvements.
New Windows Auto Apps have been added to the catalog and are now available for all Iru Endpoint customers.
Uploading an artifact now runs an auto-categorization pass so the artifact lands with a reasonable classification and mapping suggestion, cutting down on manual triage after the fact.
Trust Center now supports a native user invitation flow, letting admins invite external reviewers directly instead of having to seed accounts by hand.
Notes can now be added to Library Items to more easily keep team members informed of changes, intent of configurations, and more.
Tags can now be applied to Automated Device Enrollment (ADE) devices before they enroll and carry over to the enrolled device record.
Additionally, tags can be used in Blueprint Routing rules to determine which Blueprint a device should be routed to.
Blueprint Routing provides a simplified enrollment experience across all platforms by dynamically assigning devices to the correct Blueprint during enrollment. Routing decisions are based on device and user attributes evaluated against admin-defined rulesets.
Blueprint Routing works alongside Assignment Maps:
Artifact uploads now run in the background with toast notifications for progress, success, and failure, so admins can keep working while large files finish uploading.
The CIS Level 1 and Level 2 Blueprint templates have been fully updated to align with the macOS 15 and macOS 26 CIS benchmark recommendations.
This includes the following new Parameters that can be turned on for any existing Blueprint and are automatically included in new Blueprints created from the CIS templates:
Managed OS for iOS, iPadOS, and tvOS has been updated. The latest approved versions are now 26.3 and 18.7.5, with the following release dates:
iOS 26.3 : Feb 11, 2026
iOS 18.7.5 : Feb 11, 2026
iPadOS 26.3 : Feb 11, 2026
iPadOS 18.7.5 : Feb 11, 2026
tvOS 26.3 : Feb 11, 2026
Managed OS for macOS has been updated. The latest approved version for Tahoe is now 26.3; for Sequoia, 15.7.4; and for Sonoma, 14.8.4, with the following release dates:
macOS 26.3 : Feb 11, 2026
macOS 15.7.4 : Feb 11, 2026
macOS 14.8.4 : Feb 11, 2026
Iru's bi-weekly collection of articles, videos, and research to keep IT & Security teams ahead of the curve.