Summer (Q3) 2026 Release
Secret Server on Platform
External Secrets: Google Cloud Secret Manager (Public Preview)
Secret Server's external secrets capability now extends to Google Cloud Secret Manager, bringing secrets stored in GCP under Secret Server's governance without moving them or replacing your existing vault. For more information, see External Secrets.
Distributed Engine Routing for External Vaults (Public Preview)
External vault operations can now be routed through a Distributed Engine, extending external secrets support to vaults on private networks, behind private endpoints, or inside VPCs and VNets that Secret Server's web server can't reach directly. Applies to Azure Key Vault, AWS Secrets Manager, and Google Cloud Secret Manager. For more information, see Distributed Engine Routing for External Vaults.
Security Key Support Through RDP Proxy (GA)
The Secret Server RDP proxy now supports external physical security keys. Users log in with their key exactly as they would on a direct connection, while retaining every protection the proxy provides — session recording, access control, and auditing. For more information, see RDP Proxy.
IRIS Authorization
IRIS Authorization (Private Preview)
Error handling and guidance during configuration have been enhanced for Zendesk, ServiceNow and Jira Service Management (JSM) connectors. Support has been extended to JSM projects that use scoped API tokens. Decision engine & evaluation quality has been improved for user risk level checks, datetime comparisons and local secret server user accounts. Bug fixes to address user messaging, observability, alerting issues have also been included. For more information, see IRIS Authorization.
Identity
Manage Active User Sessions (GA)
Admins now have full visibility into every active platform login session for a user, along with the ability to revoke them instantly. Revoke individual sessions or terminate all sessions at once — the user is forced to re-authenticate on next access. For more information, see Manage Active User Sessions.
SCIM Cloud Platform Service (Public Preview)
The Delinea SCIM Cloud Platform Service — a cloud-native, multi-tenant SCIM 2.0 service for automated provisioning, deprovisioning, and synchronization of users and groups between an IAM/IGA provider and the Delinea Platform — is now in Public Preview. This release scales to large tenant user bases through a dedicated SCIM identity store, adds event-based incremental sync for faster joiner/mover/leaver updates, expands SCIM filtering to support all filters including AND/OR operators, and distinguishes local from external-directory identities to reduce failed syncs and manual cleanup. Validated integrations with SailPoint, Okta, and Entra are included, and the service works with most SCIM 2.0-compatible IGA/IAM solutions. For more information, see SCIM Provisioning Integration.
Subscription and Licensing
Entitlement Utilization Trend (GA)
The Subscription page now includes a Utilization Trend chart for each entitlement, plotting consumed license count against your allocated limit over the last 30 days. Admins can spot climbing usage, identify spikes, and plan renewals or expansions before running out of headroom. For more information, see Subscriptions.
Inventory
Manual Asset Tagging (Private Preview)
Tags can now be applied manually to assets directly from the asset detail page in Inventory. Teams can label, organize, and filter assets with custom metadata by owner, environment, risk, or any criteria they choose, making it easier to build collections and target the right assets in downstream workflows. For more information, see Tagging Assets.
Manual Computer Deletion (Private Preview)
Admins can now manually delete a computer record from the Computers inventory, giving them a way to clear out stale or duplicated machines and keep the inventory accurate. For more information, see Manual Computer Deletion.
Privileged Remote Access (PRA)
Per-Asset VNC Configuration (GA)
VNC-based remote access is now configured per asset rather than through a single global setting. A new Remote Access tab on each computer asset lets admins selectively enable VNC and override the port when needed. The "Launch PRA with VNC" link now appears only on assets explicitly configured for VNC, eliminating failed connection attempts and user confusion on machines without a VNC server. The legacy global VNC setting is deprecated and will be removed in a future release. For more information, see VNC Configuration.
Marketplace and Integrations
Download Center Installer Type Column (GA)
The Download Center grid and Package Detail view now display an Installer Type column, so endpoint and packaging teams can see at a glance whether a package contains an MSI, an EXE, or a platform-native installer — no more downloading a package just to find out what's inside.
New and Updated Integrations
-
Sumo Logic Integration: Forward Delinea Platform events to Sumo Logic using webhooks.
-
Cyera DSPM Integration: Data security posture management integration for the Delinea Platform.
-
AWS CloudTrail for ITP Discovery: Ingest AWS CloudTrail data for Identity Threat Protection discovery.
-
New Remote Password Changers: JAMF Pro, Azure App Registrations, Splunk Enterprise, SailPoint IdentityIQ, Snowflake, and Nutanix Prism.
Delinea Credential Manager
DCM Extension Language Selection (GA)
The Delinea Credential Manager browser extension is now available in 11 additional languages. Language preference is configured in your Settings menu, with an Automatic option that sets the browser's language as your Credential Manager language. For more information, see the DCM 1.4 Release Notes.
Platform Agent
Platform Agent (Private Preview)
The Delinea Platform Agent is a single agent for Windows and Linux endpoints that brokers identities from any identity provider integrated with the Delinea Platform — Entra ID, Okta, Active Directory, and others — to enforce privileged access controls fully decoupled from Active Directory. Admins can require MFA at logon and MFA at privilege elevation using any authentication option supported by the Platform. Policy uses the same model as Privilege Control for Servers, so Platform Agent and PCS targets can share a single policy. For more information, see Platform Agent.
Reporting
Platform Reports (Public Preview)
Reporting extends beyond Secret Server to cover the Delinea Platform. A new Report Library launches with 15 reports across categories such as MFA login activity, top active users, and computers with or without agents. Save customized reports to My Reports, run them on demand, or schedule them to run on a weekly or monthly cadence with snapshots retained for review. Reports can be shared with users on the platform or delivered securely to external recipients. For more information, see Platform Reporting.