13.0.0 Release Notes
Release Schedule
Privilege Manager Release: August 8, 2026
Privilege Manager On-Premises Release: August 24, 2026
Windows Agent Software
Supported Agents
Do not enroll any Windows workstations into insider preview update channels. The operating systems builds provided via the channel are not generally available or officially supported by Delinea. We recommend using the mainstream Windows update channel.
-
13.0.1041 Bundled Privilege Manager Agent Installer (x64 and ARM64)
-
13.0.1041 Core Delinea Agent (x64)
-
13.0.1041 Core Delinea Agent (ARM64)
-
13.0.1041 Application Control Agent (x64)
-
13.0.1041 Application Control Agent (ARM64)
-
13.0.1041 Local Security Solution Agent (x64)
-
13.0.1041 Local Security Solution Agent (ARM64)
-
13.0.1041 Bundled Core Delinea and Directory Services Agent (x64)
-
13.0.1041 Directory Services Agent (x64)
macOS Agent
13.0.0.194 Privilege Manager macOS Agent (macOS Sonoma 14 and later)
Operating System Support
Privilege Manager agent version 13.0.0 drops support for several operating systems which are retiring soon. Agent versions 13.0.0 and newer will not install on these unsupported operating system versions.
Deprecated Windows agents:
-
x86/32bit is no longer supported
-
Windows 11 22H2
-
Windows 10 22H2
-
Windows 10 LTSC 2021/21H2
-
Windows 10 LTSC 2019/1809
-
Windows 10 LTSB 2016/1607
Deprecated Windows Server agents:
-
Windows Server 2016
Deprecated macOS agents:
-
macOS Ventura 13
Deprecated Unix or Linux agents:
-
Privilege Manager for Unix/Linux
Features
Windows ARM-64 Support
- The Privilege Manager Windows agent version 13.0.0 and newer is officially supported on ARM-64 processor architecture.
- The ARM-64 compatible agent can be installed using the Bundled Privilege Manager Agent installer, see Software Downloads . The bundled installer detects the host architecture and installs the correct version automatically.
macOS Application Control
Authorization Database rights can now be discovered via endpoint security framework events.
Browser Extension Control
-
Privilege Manager can now discover browser extensions and perform permission-based risk scoring, AI extension detection, and policy-based control for Chrome, Edge, and Firefox on Windows and macOS workstations.
-
Added a Safari browser extension control for macOS.
Automatic Approvals for Just-in-Time Access
Just-in-time admin access requests can now be automatically approved using new out-of-the-box actions and approval processes.
Approval Life Cycle History
Approvals now show a full lifecycle history including who made each change and when they made it.
Windows Agent Re-branding
The Windows agents have been re-branded from Thycotic to Delinea. The changes below affect installer names, installation paths, service names, installer UI, and binary metadata.
Installer File Names
All Thycotic agent installer MSI file names have been updated to reflect Delinea branding:
DelineaAgent_x64_*.msiDelineaAgent_x86_*.msiDelinea_ApplicationControlAgent_x64_*.msiDelinea_ApplicationControlAgent_x86_*.msiDelinea_LocalSecurityAgent_x64_*.msiDelinea_LocalSecurityAgent_x86_*.msiDelinea_DirectoryServicesAgent_x64_*.msi
The executable (.exe) installer names are unchanged: PMAgents_*.exe and PMDirectoryServicesAgent_*.exe.
File Paths
- Existing MSI-based installations keep their current paths (for example,
C:\Program Files\Thycotic\...) unless all three MSIs are removed and the product is reinstalled. - Upgrading an existing bundled installation, or performing a new install, uses the new path (for example,
C:\Program Files\Delinea\Privilege Manager\...).
Documentation has been updated to reflect the Delinea-branded file paths.
Service Display Names
The Windows service display names for the Privilege Manager agent have been renamed:
- Thycotic Agent → Delinea Agent
- Thycotic Application Control → Delinea Application Control
ArelliaACSvc.exe also registers a new policy provider service, DPEACSvc (Delinea Platform Agent PEAC Service). This service is expected, required, and should not be disabled. Its executable is located at C:\Program Files\Delinea\Privilege Manager\Agents\ApplicationControl\DPEAC.Core\DPEACSvc.exe.
Installer UI
The installer UI for the following agents has been re-branded to Delinea standards:
- Core Agent (x64 and x86)
- Application Control Agent (x64 and x86)
- Local Security Solution Agent (x64 and x86)
- Directory Services Agent (x64)
Binary File Metadata
Windows agent binaries now report:
- Company: Delinea Inc.
- Product: Privilege Manager
- Copyright: Copyright (c) Delinea Inc., All rights reserved
Improvements
| ID | Title | Release Notes |
|---|---|---|
| 570268 | Improved: Certificate-Based Filters Now Support .dmg Files on macOS | Privilege Manager reads certificate and subject name metadata directly from .dmg files, so certificate-based application control filters apply to .dmg installers without additional configuration. This extends file-type-based controls to better support macOS software distribution. |
| 617393 | Improved: User Context Filter Picker Now Displays sAMAccountName and FQDN | The user context filter search and report picker display sAMAccountName along with External ID / FQDN, reducing ambiguity when multiple users share the same name in the same domain. |
| 621893 | Improved: Automatic Approvals for Just-in-Time Access | Privilege Manager supports automatic approval of just-in-time access requests, allowing qualifying elevation requests to be granted without manual review. See the Privilege Manager documentation for configuration details. |
| 627360 | Improved: One-Time JIT Approvals Can Now Be Revoked or Extended | One-time JIT approvals on Windows and macOS remain visible as Active in the Approvals table after being granted, so administrators can revoke or extend them during the session — consistent with duration-based approvals. Previously, approving a one-time JIT request moved it straight to the History tab with no further control. |
| 652204 | Improved: Email Report Results Tasks Can Attach a CSV | Tasks created with the Email Report Results command now have the option to attach the report to the email as a CSV file. |
| 663008 | Improved: Privilege Manager for Unix/Linux Templates Removed | Delinea discontinued support and product availability for Privilege Manager for Unix/Linux on August 1, 2026, and its templates have been removed to prevent new items from being created. Delinea recommends transitioning to Privilege Control for Servers on the Delinea Platform, which enforces least standing privilege on Windows, Linux, and Unix servers with just-in-time and just-enough privilege elevation. |
| 673809 | Improved: One-Time JIT Approvals Now Record Start and End Dates | One-Time JIT approvals display start and end dates in the Approvals History tab, bringing them in line with time-based approvals. Previously, a granted One-Time approval moved immediately to History as Completed with no start or end time recorded, making it difficult to audit when the session occurred. |
| 674615 | Improved: Customized Agent Registration Values Persist Through Upgrades | Customized values in the Agent Registration XML, such as the minutes used in the registration range, are now preserved when the Privilege Manager server is upgraded. Previously these values were overwritten with defaults on every upgrade. |
| 678050 | Improved: Syslog Tasks Only List Supported Data Sources | The data source dropdown on syslog tasks now shows only a supported selection of data sources rather than every data source in Privilege Manager. Important: a bespoke syslog data source must include the pm.syslogcompatible tag in its XML <adc:Tags> element to continue working. |
| 682641 | Improved: Reduced macOS Agent Memory Footprint | The pmagentutilityhelperd helper daemon has been removed and its functionality consolidated into the core agent process (pmcored), reducing the overall memory footprint of the macOS agent. No change in behavior or functionality is expected. |
| 682772 | Improved: macOS Agent Installer Requires Sonoma 14.0 or Later | The 13.0.0 and later macOS agent installer will not run on macOS Ventura. The macOS agent is supported on Sonoma (macOS 14.0) and later. |
| 682774 | Improved: macOS Ventura Support Removed | Privilege Manager 13.0.0 of the macOS agent no longer supports macOS Ventura (13.x), which Apple stopped supporting in November 2025. Privilege Manager follows the common practice of supporting the macOS versions Apple itself covers with security updates — the current and two previous releases. Upgrade to a supported version of macOS to continue receiving the latest features and security updates. |
| 683173 | Improved: Policy Import Can Remove Domain Information | A new option is available when importing items to remove domain information from the XML being imported. Selecting it strips domain-specific items that reference resources which may not be present, which is recommended when importing policies from a different environment. |
| 684193 | Improved: Secret Audit Comment Recorded for Vaulted Secret Rotations | When Privilege Manager secrets are vaulted in Secret Server and protected with the Require Comment option, any password rotation now produces a log entry recording that Privilege Manager viewed the secret and updated the password. |
| 686580 | Improved: Purge Old Computers Deletions Recorded in Item Change History | Computers removed from the Privilege Manager server by the Purge Old Computers maintenance task now appear in the Item Change History report. |
| 687331 | Improved: Certificate Filter Picker Supports Serial Number and Item ID Search | The digital certificate filter picker supports searching by serial number and item ID, improving the experience of selecting and using certificates in the console. |
| 688332 | Improved: Policy Event Logging During macOS JIT Approvals | Enabling Log Policy Events in the macOS JIT Admin Privileges policy audits processes launched during an elevated session for the JIT-approved administrator user. A separate policy is no longer needed. |
| 689375 | Improved: Out-of-the-Box Elevation for Device Removal on Windows | A new client system setting, Remove Devices, supports elevation of device removal operations within the Devices and Printers interface, backed by a new "Remove device (Devices and Printers) COM Elevation Filter." |
| 692000 | Improved: New Configuration Options for the Microsoft Entra ID Authentication Action | The Microsoft Entra ID Authentication action adds three options. Use Default Browser opens authentication in the user's default browser instead of the embedded web view, supporting Chromium-based browsers and Firefox and enabling YubiKey authentication; it requires agent 13.0.0 or later and is ignored by older agents. OAuth Scopes accepts a space-separated list of scopes for additional Entra ID resource applications so conditional access policies can be evaluated against them; when specified, the default Privilege Manager scope is not added automatically. Force Re-Authentication After defines how long a previous Entra ID authentication is trusted before the user must authenticate again, from 5 seconds to 1 hour. |
| 697542 | Improved: HEC Sink Endpoint Field Removed from Devo Cloud Services (HTTPS) Syslog | The HEC Sink Endpoint field has been removed from the Devo Cloud Services (HTTPS) syslog integration option because it is not required. |
| 697788 | Improved: Syslog Foreign System Creation Now Lets You Select a Protocol | When creating a Syslog foreign system, you now provide a name, a protocol, and the syslog server address, rather than relying on protocol auto-detection. |
| 701496 | Improved: macOS Authorization Database Rights Discovery | Privilege Manager discovers macOS Authorization Database rights via Endpoint Security Framework events on macOS Sonoma and later. An AuthDB action can target multiple rights, actions can be created directly from file inventory using discovered rights, and an out-of-the-box sample monitoring policy for AuthDB rights discovery is included. |
| 702477 | Improved: Purge Maintenance - Files Undiscovered Query Reliability | The "Purge Maintenance - Files Undiscovered" query now completes reliably in environments with large numbers of undiscovered files. |
| 702807 | Improved: New macOS Sample Policy for Silent Elevation of the Dropbox Installer | A new sample workstation policy, Silent Elevation of Dropbox Installation (Sample), has been added to the macOS Workstation Policy Framework. It silently elevates the Dropbox installer for standard users without requiring administrator credentials. Note: once Dropbox has been installed on a macOS endpoint, subsequent reinstallations are always silently elevated regardless of whether this policy is enabled. This is expected behavior of the Dropbox installer and is not controlled by Privilege Manager. |
| 705565 | Improved: Application Actions Drilldown Report Adds a UPN Field | A new option on the Drilldown of Application Actions report includes an additional UPN field. |
| 706726 | Improved: Windows Agent Installer File Names Re-branded to Delinea | All Thycotic agent installer MSI file names now use Delinea branding, such as DelineaAgent_x64_*.msi and Delinea_ApplicationControlAgent_x64_*.msi. The .exe installer names, PMAgents_*.exe and PMDirectoryServicesAgent_*.exe, are unchanged. See Windows Agent Re-branding. |
| 706727 | Improved: Windows Agent Installation Paths Re-branded to Delinea | New installations and upgrades of a bundled installation use C:\Program Files\Delinea\Privilege Manager\.... Existing MSI-based installations keep their current path unless all three MSIs are removed and the product is reinstalled. See Windows Agent Re-branding. |
| 706728 | Improved: Windows Agent Service Display Names Re-branded | Thycotic Agent is now Delinea Agent, and Thycotic Application Control is now Delinea Application Control. ArelliaACSvc.exe also registers a new policy provider service, DPEACSvc (Delinea Platform Agent PEAC Service), which is required and should not be disabled. See Windows Agent Re-branding. |
| 706729 | Improved: Windows Agent Installer UI Re-branded | The installer UI for the Core, Application Control, Local Security Solution, and Directory Services agents has been re-branded to Delinea standards. See Windows Agent Re-branding. |
| 707206 | Improved: Create a Standard Administrative User at First Login Without NTLM | When no administrative user is detected and NTLM is disabled, the login page offers to create a Standard Administrative user, eliminating the NTLM requirement for initial on-premises setup. |
| 707930 | Improved: Full Approval Lifecycle History in the Approvals UI | The Approvals UI shows the full history of every approval request: who originally approved or denied it, every subsequent change such as time adjustments and revocations, and which user made each change. System-initiated actions, such as auto-approved JIT requests, are attributed to System. Existing approval records and all reports are unaffected. |
| 708215 | Improved: Soft License Enforcement for Privilege Manager Cloud | Privilege Manager Cloud no longer halts agent data processing when a license limit is exceeded or a license expires. An informational banner is still displayed to administrators, but there is no functional impact on the system. |
| 708438 | Improved: Server Performance Under High Policy Event Volume | Server performance has been improved when many policy events are received from agents simultaneously. |
| 710821 | Improved: Syslog HEC Connector Performance | Event sending performance of the Syslog HEC connector has been improved through batching. |
| 712706 | Improved: Two Additional macOS Workstation Policies | Two macOS workstation policies have been added in 13.0.0: Silently Elevate Dropbox Installer and Block Console. |
| 712960 | Improved: Windows Agent Binary Metadata Re-branded | Windows agent binaries now report Delinea Inc. as Company, Privilege Manager as Product, and Copyright (c) Delinea Inc., All rights reserved. See Windows Agent Re-branding. |
| 713306 | Improved: Safari Browser Extension Control for macOS Agents | The macOS agent supports Safari browser extension control. See the Privilege Manager documentation for configuration details. |
| 713307 | Improved: Browser Extension Discovery and Control on Windows | Browser extension management provides endpoint visibility and policy-based control over browser extensions on managed Windows endpoints. Extensions across Chrome, Edge, and Firefox are inventoried for all user profiles on the machine, with automatic risk scoring based on requested permissions and AI extension detection. Browser Extension Management is a Windows-only feature in this release. |
| 730184 | Improved: Legacy Arellia Event Log Registration Removed | After the Windows agent is updated to 13.0.0, the installer removes the legacy SYSTEM\CurrentControlSet\services\eventlog\Arellia registry key and its Arellia Agent and Arellia C++ Agent subkeys, and removes "Arellia" source entries from Event Viewer. Applications and Services Logs > PMAgent > Operational remains. Existing .evtx files are preserved on disk but are no longer reachable through Event Viewer because the registration has been removed. |
| 735980 | Improved: New Extended Application Control Policy Feedback Syslog Data Source | A new out-of-the-box syslog data source, Application Control Policy Feedback - Extended, adds product version, product name, file version, company name, and original file name from Win32 executable metadata when available. |
| 740474 | Improved: Support Procedures for Removing Agent Hardening from an Unresponsive Windows Agent | New support procedures are available for removing agent hardening from an unresponsive Windows agent. For more information, see Agent Hardening and Installer Issues. |
| 745199 | Improved: Thycotic Monitor Renamed to Privilege Manager Log View Monitor | The Thycotic Monitor application has been renamed Privilege Manager Log View Monitor. |
| 751605 | Improved: Enabling processor affinity has changed slightly in the 13.0.0 agent version. | Processor affinity forces the agent to use fast processor cores on older laptop versions rather than the default behavior fast processor cores to do its processing. Processor affinity is still disabled by default. Setting the registry value OverrideUseSpecificCores under HKEY_LOCAL_MACHINESOFTWARE\Arellia\Agent to 1 enables legacy processor-affinity logic.
If the registry value OverrideAffinityMask has a non-zero value, it is used as the processor affinity mask. Otherwise, only processor cores with hyper-threading are used.
The only applies on x64 systems. Processor affinity manipulation is not enabled for ARM64 systems. |
Fixed Issues
| ID | Title | Release Notes |
|---|---|---|
| 626942 | Fixed: Task History Refresh Button Does Nothing | Fixed an issue where the Refresh button on the Task History page did not refresh the page's content. |
| 628911 | Fixed: SAML Configuration Could Be Deleted While In Use as an Authentication Provider | A SAML configuration can no longer be deleted while it is also being used as an authentication provider. |
| 648736 | Fixed: Incorrect Total Endpoint Count for Policies in Multiple Computer Groups | Fixed an issue where an incorrect number was displayed for the total count of endpoints with a policy when the policy was applied to multiple computer groups. |
| 663980 | Fixed: Agent Upgrade Could Leave Windows Unbootable with a Black Screen | Fixed an issue where upgrading the Privilege Manager agent on machines with strict security policies, such as CrowdStrike or WDAC, could leave Windows in an unbootable state, causing a black screen and "no endpoints available" RPC errors at login. The installer now correctly restores the Windows Appinfo service registry entry if the upgrade rolls back, preventing UAC and login failures. |
| 681815 | Fixed: Reports Showed UTC Receipt Time Instead of Local Execution Time | The Application Justification and Application Action reports now show the execution time of the event from the machine rather than the UTC timestamp of when the server received the event, which had caused confusion. |
| 688981 | Fixed: macOS User Not Removed from Admin Group When a Digital Certificate Filter Is Used with a JIT Action | Fixed an issue in the macOS agent where a user was not always removed from the admin group after closing an application matched by a digital certificate filter combined with a JIT Group Membership action. |
| 689930 | Fixed: System Crash from Pending I/O Operations in the Application Control Driver | Resolved a rare issue where pending I/O operations in progress with ArelliaACDrv.sys led to a system crash. |
| 695600 | Fixed: Serial Number Displayed Incorrectly in Digital Certificate Details | Fixed an issue where the SerialNumber field in Digital Certificate Details was displayed incorrectly. |
| 697835 | Fixed: Existing Incorrect Certificate Serial Numbers Corrected on Upgrade | On upgrade to Privilege Manager 13.0.0, the Correct Certificate Serial Numbers task runs and updates serial numbers that were previously displayed incorrectly in Digital Certificate Details. |
| 701567 | Fixed: User Name Missing in the Entra Authentication Modal for Local Users | Fixed an issue in the Windows agent Entra authentication modal where the User field did not display the username when authentication was initiated from a local user account. |
| 703350 | Fixed: Select All in Policy Events Ignored the Active Policy Filter | Fixed an issue in Policy Events where Select All selected all events instead of only those matching the active Policy filter. |
| 707806 | Fixed: Unquoted Path Caused MSIElevateHost Elevation Failures | Fixed an issue where an unquoted path in CreateProcess caused MSIElevateHost elevation failures on some elevation policies when using agent versions 12.0.5289 and 12.0.5290. |
| 713522 | Fixed: macOS Policy Events Logged for Child Process Matches | Policy event logging in the macOS agent now sends events only for direct process matches rather than child process matches, improving the fidelity of events sent to the server and downstream reporting. |
| 715753 | Fixed: Update Licensing Task Failed in Certain Server Time Zones | Fixed an issue where the Update Licensing server task failed when the server was set to certain time zone values. |
| 715949 | Fixed: Services Picker Spins Indefinitely in the Agent Service Clear Restrictions Task | Fixed an issue where the Services picker in the Agent Service Clear Restrictions (Windows) task would spin indefinitely and never load. The picker attempted to bulk-load all Windows service resources at once, which could time out in environments with large amounts of service inventory data. The picker now uses a search-based approach consistent with other resource selectors in the product. |
| 717922 | Fixed: macOS Filter Created from Inventory Used the Full Executable Path | When creating a file filter from a macOS inventory item or audit event, the File Path field was populated with the full executable path (for example, /usr/libexec/mdmclient) instead of the directory only (for example, /usr/libexec/), which prevented the filter from matching as expected. Path extraction now handles macOS forward-slash paths correctly, consistent with existing Windows behavior. |
| 719866 | Fixed: Agent Installer Failed Under AllSigned or RemoteSigned PowerShell Policies | All .ps1, .psd1, and .psm1 files shipped in the agent MSIs have been re-signed with valid Authenticode signatures, allowing installation on endpoints with AllSigned or RemoteSigned execution policies. |
| 721191 | Fixed: Jamf Connector Computer Sync Failure from a Numeric Overflow | Fixed an issue where the Jamf connector failed to sync computer records due to a numeric overflow in the last_cloud_backup_date_epoch field. |
| 721465 | Fixed: Install Log Link Not Shown Until Installation Completed | Fixed an issue where the log links for Privilege Manager Server installation and upgrade were not displayed until the installation completed. |
| 723066 | Fixed: Log Viewer Displayed No Data | Fixed an issue where server logs at /TMS/LogViewer were not being displayed. |
| 725769 | Fixed: Redundant Database Index Removed from the Application Action Table | The duplicate IX_Application_Action_Date index has been dropped from the [Ams.Event].[Application_Action] database table. |
| 737288 | Fixed: Upgrade to 12.0.4 or Later Failed with SQL72030 on Case-Sensitive Databases | Resolved an issue where upgrading Privilege Manager to 12.0.4 or later failed with error SQL72030 on databases using a case-sensitive collation. Azure SQL customers, who previously had no workaround, can now upgrade successfully. |
| 739403 | Fixed: Global Search Failed for Japanese and Other Non-ASCII Characters | Searching for a Japanese or other non-ASCII term in the global search box now returns the matching items. |