Winter (Q1) 2026 Release

Secret Server on the Delinea Platform

  • Remote Password Pre-Validation (GA) — Password rotation now automatically validates the health and connectivity of all configured systems before making any changes. If validation fails, the entire process stops—preventing partial updates, service downtime, and emergency recovery scenarios. For more information, see Pre-Run Validation for Dependencies.

  • Platform Upgrade Center Enhancements

    • Event Subscriptions now support Platform User and Group events (Public Preview). For more information, see Event Subscription Overview.

    • Upgrade flow now dynamically skips unnecessary steps based on your Secret Server Cloud configuration.

    • Pre-checks now detect older distributed engine issues and recommend upgrades before data synchronization.

Analytics

Authentication Risk Scoring (GA) — Real-time risk assessment during user authentication when risk-based identity policies are configured. Risk scores are determined by login location, time, and user agent, captured in audit logs, and evaluated independently from overall user risk. For more information, see Analytics Findings and Risk.

Iris Auditing

Iris Auditing for Full RDP Sessions (GA) — Analyze end-to-end Remote Desktop sessions, extracting session intent, key actions, and noteworthy events from interactive Windows admin activity. Produces structured, searchable session summaries for investigations and compliance reporting. For more information, see Delinea Auditing Powered by Iris AI.

Privileged Remote Access (PRA)

  • Session Recording Downloads (Private Preview) — Download remote session recordings from PRA or Audit Collector. Authorized users can request downloads asynchronously, with files available for 3 days before auto-expiring. For more information, see Downloading Session Recordings.

  • VNC Support (Public Preview) — PRA now supports VNC connections alongside RDP and SSH. Access VNC servers directly from your browser without a VPN, launch from the same Inventory UI, and use Ctrl+Alt+Del through the menu for OS login prompts. Ideal for operational technology and Linux desktop environments. For more information, see Launching Remote Connections with VNC.

Privilege Control for Servers (PCS)

  • Platform Engine Download Logs (GA) — Engine and all workload logs now consolidated into a single zip file download.

  • Linux Group Management (GA) — Native management of Linux/UNIX group profiles. Create group profiles at global or machine-override levels, import groups in bulk, and leverage RFC2307 attributes. Simplifies mapping to Active Directory while preserving existing structures during AD bridging. For more information, see Linux/UNIX Group Profiles.

Identity

  • External Directory Service Users (Public Preview) — Use existing directory-based accounts (for example, Active Directory) for programmatic API access instead of creating separate local service users. For more information, see Service Users.

  • Active Directory and Entra ID Interoperability (GA) — When both native Entra ID integration and Delinea AD Connector are configured on the same tenant, MFA redirection is based on the priority user, which is determined by the directory service order. Resolves previous identity collisions when AD and Entra ID users share the same UPN but have different Object IDs. For more information, see:

  • SCIM Connector for Delinea Platform (Private Preview) — Enhanced SCIM service now supports flexible IdP configuration beyond SAML-only. Implement SCIM provisioning with any authentication method, including direct Entra ID API integration. Improved UID mapping aligns with industry-standard IdP and IGA specifications for reliable identity synchronization. For more information, see Delinea SCIM Connector.

Identity Threat Protection (ITP) and Privilege Control for Cloud Entitlements (PCCE)

  • Active Directory Security / ISPM (GA) — Gain visibility into AD environments, visualize human and non-human accounts, computers, local users/groups, services, scheduled tasks, and IIS apps. Surfaces critical AD misconfigurations around privileged access, local admins, and weak authentication.

  • CIEM Permission Refactoring for Azure & AWS (GA) — Extended capabilities now detect excessive permissions across accounts, groups, and roles. Analyzes the last 90 days of activity to identify over-privileged entities and recommends least-privilege custom roles. Supports both out-of-the-box and custom roles. For more information, see Refactor Excessive Privileges for User.

  • Non-Human Identity Support for Microsoft Entra (GA) — Visibility into Entra service principals, app registrations, and enterprise applications. Identifies stale and overprivileged entities with refactoring recommendations. Detects non-rotated or unvaulted app registrations with one-click vaulting to Secret Server Cloud. For more information, see ITP-PCCE Checks.

Marketplace & Integrations

  • SailPoint IdentityIQ Integration (Private Preview) — Automated identity lifecycle management with SailPoint IdentityIQ (v8.3+) through Delinea Platform's native SCIM SaaS service. Supports user/group provisioning in Platform Identity and folder/secret permission management in Secret Server. Compatible with most SCIM 2.0 IGA providers. For more information, see Integrating SailPoint IdentityIQ with Delinea Platform.

  • ServiceNow Zurich Certification (GA) — All Delinea integrations with ServiceNow are certified and validated for the Zurich release. For compatibility details, see ServiceNow Release Integration Matrix.

Mobile

  • Credential Manager Mobile 3.2 (GA)

    • Download a folder's secrets, including all subfolders

    • Remove folders from the downloads list for offline access

    • New color-coded password display for easier reading (characters, numbers, symbols)

    • Resolved iOS biometry bug

    • For full feature and bug fix details, see 3.2.0 Release Notes.

  • Credential Manager Mobile 3.1 (GA)

    • Request and approve/deny secret access requests from mobile devices

    • For full feature and bug fix details, see 3.1.0 Release Notes.

Delinea Credential Manager

DCM 1.3 (GA)

Folder creation and management with hierarchical organization and folder-level permissions. For full feature and bug fix details, see 1.3.0 Release Notes.

Other Updates

  • Connection Manager 2.8 — Windows: Session Connector launchers now available directly from Connection Manager; new user rights options for debug configuration and installation without admin privileges. macOS: RDP sessions support dynamic resizing without reconnecting; added FIDO2 WebAuthn for passwordless authentication during remote sessions. For full feature and bug fix details, see 2.8.0 Release Notes.

  • UX Inventory Updates — Favorite assets and launch sessions directly from the platform home page. Expanded detail panel provides quick actions without drilling down.

  • IBM Verify Privileged Identity Platform (GA) — IBM-branded version of Delinea Platform, sold exclusively through IBM and partners. See the press release, Delinea Expands OEM Agreement with IBM to Deliver Privileged Identity and Access Management Capabilities.