> For the complete documentation index, see [llms.txt](https://docs.autopilotmonitor.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.autopilotmonitor.com/changelog/platform-changelog.md).

# Platform Changelog

Significant platform changes — portal, backend, and data-flow updates, newest first.

This changelog tracks significant platform changes — architecture updates, data flow changes, and anything else that might briefly affect the UI or monitoring data. If something looks off, check here first. A recent entry might explain it.

The same entries appear in the portal under **Help (?) → What's new** and behind the bell on the website; in the portal a red counter marks entries you have not looked at yet.

Found a bug or want to give feedback? Use **Help (?) → Send feedback** in the portal or [open a GitHub Issue](https://github.com/okieselbach/Autopilot-Monitor/issues) — it helps more than you might think.

## October 2026

* **Sessions wait for the Windows update at the end of OOBE** — A session no longer fails while Windows installs its quality update during OOBE. Without a sign-in afterwards it ends as Awaiting User or Incomplete. See [Sessions & Statuses](/concepts/sessions-and-statuses.md#windows-quality-update-at-the-end-of-oobe).
* **Teams Legacy Connector removed** — Microsoft switched it off in May 2026. Teams channels use a Workflow webhook. See [Notifications](/integrations/notifications.md).
* **Windows Update while the enrollment runs** — Session Details shows the quality update at the end of OOBE as it happens: how long it has been running, its restarts, and the wait for the user after the restart. The Progress Portal tells the user that Windows is installing updates and when to sign in. See [Session Details](/portal-guide/session-details-and-diagnosis.md#session-detail).
* **Send feedback from the portal** — Help (?) → Send feedback takes ideas, problems and praise straight to the Autopilot Monitor team. No GitHub account needed; every member with a role can use it.
* **More room for logs and screenshots** — Submit Logs and Report Session share one size budget for all attachments, and the form shows how much is used. Logs are compressed before sending, so far more than the previous 5 MB fits. See [Diagnostics & Log Collection](/troubleshooting-and-support/diagnostics-and-log-collection.md#reporting-a-session).
* **Operators can report sessions** — Report Session is now open to Operators as well as Tenant Admins. Viewers no longer see the button. See [Roles & Permissions](/concepts/roles-and-permissions.md#tenant-roles).
* **OOBE quality updates that did not install** — Enrollment analysis flags a quality update at the end of OOBE that failed to download or install, one Windows did not offer to an out-of-date device after an earlier failure, and an update check that ended without a result. See [Built-in Rules Reference](/rules/analyze-rules/built-in-rules.md#device).
* **How the Windows update ended, in the time attribution** — The Windows Update segment names whether the update installed, failed or was skipped, and lists the KBs it worked on without installing them separately. When the agent started only after the update page had begun, the segment now begins at the update's first recorded step instead of counting the update toward Apps (ESP). See [Session Details](/portal-guide/session-details-and-diagnosis.md#time-attribution).
* **Windows Update in the time attribution** — The quality update Windows installs at the end of OOBE is now a segment of its own, with the installed KBs and restarts, followed by the wait until the user signs in again. Until now that time counted toward Apps (ESP) or Identity & Hello. See [Session Details](/portal-guide/session-details-and-diagnosis.md#time-attribution).
* **Windows updates in the enrollment analysis** — Enrollment analysis flags a Windows or .NET update that failed to download or install during the enrollment and notes one that installed. See [Built-in Rules Reference](/rules/analyze-rules/built-in-rules.md#device).
* **A clearer Vulnerabilities view** — Software → Vulnerabilities shows the CVEs by severity in a donut with the remediation priority below it, and the most exposed software with each product's most urgent CVEs. Known-exploited CVEs stay in the list even when they affect only a few devices. See [Software Inventory & Vulnerabilities](/portal-guide/software-inventory-and-vulnerabilities.md#vulnerabilities).
* **AI integration filters by your gather rules' event types** — The event tools accept the output event type of your own gather rules. An empty result for a type that is not built in names the closest built-in types. See [AI Integration (MCP)](/integrations/ai-integration-mcp.md#available-tools).
* **A compact member list in Access Management** — One line per member with a search and role filters; click a member to change the role, which applies when you save it. Viewer can now also be assigned as an Entra app role. See [Settings Reference](/reference/settings.md#access-management).
* **Progress Portal points to your admins** — Members without a role now see that their organization already uses Autopilot Monitor and whom to ask for access. See [Progress Portal](/portal-guide/progress-portal.md#members-without-a-role).
* **Session links for members without a role** — A member without a portal role who opens a link to a session now sees whom to ask for access instead of an empty page. See [Signed in, but only the Progress Portal](/troubleshooting-and-support/progress-portal-only.md).
* **Fixed: platform scripts showing another script's output** — Script Executions shows such a run with the script's own output, as the Intune Management Extension saved it, and the exit code as n/a. See [Session Details](/portal-guide/session-details-and-diagnosis.md#session-detail).
* **Fixed: Windows updates stretching session durations** — Windows update activity from before the agent started no longer moves the session start earlier.
* **Fixed: app details for names with a slash** — Apps whose name contains a slash now open their detail page. See [Software Inventory & Vulnerabilities](/portal-guide/software-inventory-and-vulnerabilities.md#per-app-deep-dive).
* **Fixed: outdated live views after returning to a tab** — The Progress Portal, Session Details and the notification bells show the current state as soon as the live connection is back.
* **Fixed: software with padded registry entries** — Programs whose installer pads their registry entries now appear in the software inventory and are checked for vulnerabilities. See [Software Inventory & Vulnerabilities](/portal-guide/software-inventory-and-vulnerabilities.md#inventory).
* **Fixed: data from deleted sessions** — Telemetry that arrives after a session was deleted or was never registered is now refused, so it no longer shows up in the software inventory or the app statistics. See [Software Inventory & Vulnerabilities](/portal-guide/software-inventory-and-vulnerabilities.md#inventory).
* **Fixed: empty pages from the session search by event** — The MCP tool `search_sessions_by_event` now reads on until it has matches or the index is exhausted, instead of answering an empty page with a continuation. See [AI Integration (MCP)](/integrations/ai-integration-mcp.md).

## September 2026

* **Hello Wait Timeout up to one hour** — The setting under Settings → Agent now accepts 30 to 3600 seconds. Values up to 300 seconds keep the 5-minute wait, larger values extend it. See [Settings Reference](/reference/settings.md#agent-collectors).
* **Enrollment sessions are bound to the device that started them** — No other device can write into a session, not even one of your own tenant. A device re-enrolled without a wipe now starts a new session instead of continuing the old one. See [Security & Privacy FAQ](/trust-and-security/security-faq.md#how-does-a-device-prove-it-is-allowed-to-send-data).
* **RealmJoin packages in the Software view** — Packages the RealmJoin agent installs during enrollment now appear under Software → Installs next to your Intune apps, with a RealmJoin label and a filter. They count in the app reports and the app install SLA. Needs the RealmJoin Watcher setting. See [Software Inventory & Vulnerabilities](/portal-guide/software-inventory-and-vulnerabilities.md#installs).
* **Apps that send a user's token must be members** — A user's token is now accepted only when the portal, the MCP sign-in or an app a Tenant Admin added under Settings → Access Management requested it. Through such an app, for example a self-hosted AI client in on-behalf-of mode, users can only read. See [AI Integration (MCP)](/integrations/ai-integration-mcp.md#your-own-app-on-behalf-of-users).
* **Monitor Autopilot device preparation without pre-registration** — The new **Intune Enrollment Validation** accepts devices enrolled in your Intune tenant, matched by the device's MDM certificate. No Autopilot hash, corporate identifier or device association is needed. It needs the optional `IntuneDeviceBinding` Graph permission. See [Autopilot Device Preparation](/getting-started/autopilot-device-preparation.md#without-pre-registration).
* **Validation banner for device preparation tenants** — The dashboard warns only when no validation method is enabled. Tenants that validate by device association alone no longer see it.
* **Link straight to a device in the Progress Portal** — `/progress?serial=<serial number>` opens the page with that device already looked up, so you can send users a link to follow their own device. Sign-in and the serial check stay as they are. See [Progress Portal](/portal-guide/progress-portal.md#link-straight-to-a-device).
* **AI Integration in the tenant settings** — Settings → Tenant → AI Integration shows the MCP server URL for Claude, ChatGPT and VS Code. See [AI Integration (MCP)](/integrations/ai-integration-mcp.md#client-setup).
* **Connect a self-hosted AI client** — For an AI client your organization hosts itself, a Tenant Admin registers its callback URL under Settings → Tenant → AI Integration. The client then uses the normal browser sign-in, limited to your tenant's accounts. Deleting the registration ends its access, including refresh tokens copied out of the client. See [AI Integration (MCP)](/integrations/ai-integration-mcp.md#self-hosted-ai-clients).
* **MCP sign-in works for clients that expect a client secret** — The server now tells clients that it issues none, so they complete the sign-in instead of failing at the token step.
* **Faster portal loading** — The portal's program files stay cached in your browser between visits, pages start loading as soon as you point at a link, and the dashboard's first data loads alongside your sign-in check.
* **MCP: every tool description reaches your AI client in full** — The tool catalog is about a fifth smaller, and no tool description or server instruction exceeds the 2,048 characters some AI clients cut off at.
* **SLA page and alerts judge the same 30 days** — The banner and the success-rate and duration gauges now cover the last 30 days, the same period the SLA breach alerts judge; a period without finished enrollments shows **No data** instead of a breach. A lasting breach is reported again only after new enrollments have finished. See [SLA Compliance](/portal-guide/sla-compliance.md#which-period-each-number-covers).
* **Additional Log Paths accept a folder** — Enter a folder and every file in it is collected; a path to the Security, PowerShell or Sysmon event log is flagged before you save it. Needs agent 2.0.1462. See [Diagnostics & Log Collection](/troubleshooting-and-support/diagnostics-and-log-collection.md#the-diagnostics-package).
* **Your profile photo in the navigation bar** — The avatar shows your Microsoft 365 profile photo; your browser loads it directly from Microsoft and it never reaches our servers.
* **Pro is available** — Buy Pro through Microsoft Marketplace or Cleverbridge, or let a tenant administrator start a one-time, free 30-day trial under Settings → Tenant → Plan. The Get started page asks you to accept the Terms of Use and the Data Processing Agreement before you sign in. See [Plans](/plans.md#buy-pro).
* **Device Setup and Account Setup in the app and script panels** — Download Progress, Install Progress and Script Executions draw a thin divider where the Enrollment Status Page entered Account Setup, and user-assigned apps carry a **User** pill. The divider shows when a row started, not how it is assigned: device-assigned scripts and apps run under Account Setup too, routinely on Cloud PCs. See [Session Details](/portal-guide/session-details-and-diagnosis.md#session-detail).
* **Pick optional Graph features to build the grant command** — Under Settings → Tenant → Optional Graph capabilities, tick the features you want and the grant command and **Copy permissions** follow your selection; the command also runs in Azure Cloud Shell. See [Optional Graph Permissions](/reference/optional-graph-permissions.md#running-the-script).
* **AI (MCP) usage of delegated administrators is charged to their own organization** — A read into a tenant you manage now counts against your organization's and your account's budget, never against the customer's; a managed tenant is never blocked by its manager's AI usage. Every managed-tenant slot bought beyond the two included in Pro extends both budgets, and the MCP Usage page shows the breakdown. See [AI Integration (MCP)](/integrations/ai-integration-mcp.md#rate-limits-and-usage-plans).
* **Scripts still running at session end are marked Incomplete** — A script with no result by the time the agent stopped no longer shows as running forever; the row says **Incomplete**, outside the succeeded and failed counts. `get_session_summary` lists such scripts under `coverage`. See [Session Details](/portal-guide/session-details-and-diagnosis.md#session-detail).
* **Completed-by-timeout is marked in the Network Timeline** — When an enrollment counted as complete because a wait ran out (Windows Hello not set up within the wait, or no user phase after device setup), the Completed marker is drawn hollow and labelled *(timeout)*, with its own legend line. Such a marker can sit inside an Asleep block: nothing happened on the device at that instant, the wait simply expired.
* **MCP: results that are too large say so** — Instead of a cut-off page you get a short answer with the page size that fits. Cancelling a call in your AI client now stops it on the server too.
* **Apps still installing at session end are marked Incomplete** — The Install and Download Progress panels no longer run a timer forever for an app that had no result when the agent stopped; the row says **Incomplete** with the watched time as a lower bound. The app metrics disclose the same rows in their own bucket, outside the failure rate, and `get_session_summary` lists them under `coverage`. See [Session Details](/portal-guide/session-details-and-diagnosis.md#session-detail).
* **Contribute a rule from the portal** — A **Contribute a rule** button on the Analyze Rules and Gather Rules pages submits your custom rules for the community rule pool; you choose the credit (anonymous by default), follow the review status on the same page, and accepted rules ship to every tenant as community rules. See [Contribute a Rule](/rules/contribute-a-rule.md).
* **ANALYZE-ESP-004 only fires on a real ESP timeout** — The soft-failure finding now needs the agent's own verdict that the ESP gave up while a blocking app was still installing; an ESP failure with a specific error code goes to the rule for that code, and the configured ESP limit is shown as a limit, not as elapsed time. See [Built-in Rules](/rules/analyze-rules/built-in-rules.md#esp).
* **Entra device-registration error codes explained** — The error-code catalog now covers the `0x801C…` family that hybrid joins and the account-setup phase report, so timeline badges and `lookup_error_code` name the code's meaning instead of leaving it unknown. See [AI Integration (MCP)](/integrations/ai-integration-mcp.md#available-tools).
* **A gather rule's target is judged the way the device judges it** — The rule editor and the rule validator now expand `%ProgramData%` and the other environment variables before checking a target, so a path that works on the device is no longer reported as blocked; a folder in the signed-in user's profile is shown as allowed only when it is genuinely on the allow-list. See [Gather Rules](/rules/gather-rules.md#security-guardrails).
* **Product updates in your notification channels** — A new **What's new** toggle per notification channel sends one digest to Teams, Slack, Discord or a JSON webhook whenever new changelog entries go live. Off by default. See [Notifications](/integrations/notifications.md#triggers).
* **Gather rules can have their error codes explained** — A new rule option resolves `exitCode`, `errorCode` and `hresult` against the Windows/MSI/Intune catalog; off by default, because a vendor tool's own exit codes would be explained wrongly. Needs an updated agent. See [Gather Rules](/rules/gather-rules.md#explaining-error-codes).
* **System Health: a waking AI endpoint no longer warns** — The MCP Server card says *Starting instance…* and keeps probing for about a minute while the endpoint scales up from zero. See [System Health](/portal-guide/audit-log-and-system-health.md#system-health).
* **What's new in the portal** — The Help menu, the Help page and the website navigation open a What's new panel with the Platform and Agent changelog entries; in the portal a red counter shows how many you have not seen yet and resets once you have looked, per user across browsers.
* **Geographic Performance says what its numbers are based on** — A note under the Location Performance table and tooltips on Avg Duration, P95 and vs Global state which sessions each figure covers and that the benchmark is your own fleet. A new concept page explains averages, medians and P90/P95/P99 for everyone. See [How the numbers are calculated](/portal-guide/geographic-performance.md#how-the-numbers-are-calculated) and [Averages, Medians & Percentiles](/concepts/averages-medians-and-percentiles.md).
* **Vulnerabilities: filter by priority** — The exposure panel shows Act and Attend as tiles, and every severity or priority chip filters the top-CVE list. See [Software Inventory & Vulnerabilities](/portal-guide/software-inventory-and-vulnerabilities.md#vulnerabilities).
* **Timeline search looks into the event details** — Searching the event timeline now also matches the JSON under an expanded event, so a phrase such as `"Installation completed"` finds the log line a gather rule extracted even though no message contains it; `type=`, `message=`, `source=` and `data=` pin a term to one field. See [Filtering the event timeline](/portal-guide/session-details-and-diagnosis.md#filtering-the-event-timeline).
* **Dashboard search understands `model=` and `manufacturer=`** — Several terms now narrow each other down, a leading minus excludes, and `field=value` pins a term to one column; the Fleet Health model rows link into the dashboard with exactly that search, which previously came back empty. See [Dashboard & Sessions](/portal-guide/dashboard-and-sessions.md#search-syntax).
* **New rule: an app's return code asked for a reboot** — ANALYZE-APP-018 fires when an installer exit code is mapped to *Soft reboot* or *Hard reboot* in the app's Intune return-code table; the app timeline and the Install Progress panel now show the exit code of completed apps with that mapping. Needs an agent with the return-code class (see the [agent changelog](/changelog/agent-changelog.md)). See [Built-in Rules](/rules/analyze-rules/built-in-rules.md#apps).
* **Rules pages grouped by category** — The Analyze Rules and Gather Rules pages now list rules in collapsible category groups with counters; **Expand All** / **Collapse All** sit above the list and your collapsed groups are remembered per browser. See [Analyze Rules](/rules/analyze-rules.md#managing-rules-in-the-portal).
* **AI session summary reports what the agent could not see** — `get_session_summary` now starts with a `coverage` block: from when the agent watched, the health of its log tracker, collectors, upload path and diagnostics package, and a `gaps` list with one line per blind spot. Rule authors get the matching guidance and a `validate_rule` warning for rules that assert the absence of an IME-log event without a coverage gate. See [Analyze Rules: Concepts](/rules/analyze-rules/concepts.md#absence-is-not-evidence).
* **Error codes explained** — The catalog behind the timeline badges now covers about 600 Windows, MSI, Windows Update, AppX and Intune codes with their symbols, and the new MCP tool `lookup_error_code` explains one code by hex, decimal, symbol or enforcement state. See [AI Integration (MCP)](/integrations/ai-integration-mcp.md#available-tools).
* **MCP can be switched off for a whole organization** — On request your entire tenant is closed for AI assistants; members cannot connect and delegated readers cannot read it through MCP, while portal and API access stay unchanged. See [AI Integration (MCP)](/integrations/ai-integration-mcp.md#prerequisites).
* **Hybrid user-affinity finding rebuilt on the observed token** — ANALYZE-ID-004 now fires on the agent's *user affinity pending* warning and stays silent once the Intune Management Extension acquired the user's Entra token; the JoinInfo placeholder is no longer treated as evidence. Gather-rule output events (`gather_*`) can now be used as filters in the MCP session tools. See [Hybrid Join: stuck in Account Setup](/troubleshooting-and-support/hybrid-join-stuck-in-account-setup.md).
* **Service principals for unattended MCP automation** — Add an application from your Entra tenant as a read-only member under Settings → Access Management and let a pipeline or agent query the MCP server with its own client-credentials token; it needs the `access_as_application` permission granted in your tenant and shows up marked as App on the MCP Usage page. See [AI Integration (MCP)](/integrations/ai-integration-mcp.md#service-principals-and-automation).
* **Filter the Performance Map from its legend** — Click a legend bucket under the Geographic Performance map to show only the locations in it. See [Geographic Performance](/portal-guide/geographic-performance.md#reading-the-map).
* **Migration banner names missing add-on permissions** — If the previous app holds optional Graph add-on permissions the new app lacks, the switch now pauses with the exact list and a grant command for the new app; **Detect existing access** then completes it. See [App Registration Migration](/troubleshooting-and-support/app-registration-migration.md#optional-graph-add-on-permissions).
* **Color the Performance Map by any metric** — The Geographic Performance map now has a **Color by** selector (enrollment duration, success rate, API latency, DO peer efficiency, App-Load-Score) and a legend, using the same thresholds as the table badges. See [Geographic Performance](/portal-guide/geographic-performance.md#reading-the-map).
* **Self-service delegated (MSP) administration** — Pro tenants can now invite customer tenants with a single-use link under Settings → Tenant → Delegated Access, assign their own members as read-only readers, and every tenant sees and can end who reads it; Pro includes two managed tenants. See [Roles and Permissions](/concepts/roles-and-permissions.md#msp-fleet-access).
* **Managed tenants get Pro** — A tenant managed by an organization on the Pro plan is on Pro for as long as it is managed and shows a "Pro (MSP)" badge; it does not gain delegation rights of its own. See [Roles and Permissions](/concepts/roles-and-permissions.md#msp-fleet-access).
* **MCP quota for delegated (MSP) reads follows the managed tenant** — A delegated administrator's requests into a managed tenant now count against that tenant's own MCP budget and plan, tenant admins see every account charged to their organization budget on the MCP Usage page, and MSPs get a `get_fleet_overview` tool for a bounded overview across all managed tenants. See [AI Integration (MCP)](/integrations/ai-integration-mcp.md#rate-limits-and-usage-plans).
* **The new app registration is the default sign-in app** — New browsers and devices now sign in with the new Autopilot Monitor app; tenants still on the previous app keep working, see a one-time consent prompt on a new browser, and get a dashboard banner for the one-time switch. See [App Registration Migration](/troubleshooting-and-support/app-registration-migration.md).
* **Company name in the Contact settings** — Next to the contact email address you can now store your organization's name; both are optional on Community and required before starting a Pro trial. See [Settings Reference](/reference/settings.md#contact).
* **Documentation links in Settings** — Every settings section now has a "Read the docs" link in its header that opens the matching documentation page in a new tab. See [Settings Reference](/reference/settings.md).
* **Documentation links on every page** — Session details, Fleet Health, Geographic Performance, SLA Compliance, Software, Usage Metrics, Audit Log, System Health, Annotations and the rules pages now carry a small "Docs" link in their header that opens the matching guide. See [Portal Guide](/portal-guide/dashboard-and-sessions.md).
* **Organization-wide MCP quota** — Next to the per-account daily and monthly MCP limits, every tenant now has a shared daily and monthly budget that all members' requests count against; the MCP Usage page shows both. See [AI Integration (MCP)](/integrations/ai-integration-mcp.md#rate-limits-and-usage-plans).
* **MCP access follows your tenant role** — Members of your tenant (Admin, Operator, Viewer) can connect an AI assistant without a separate per-user entry; accounts without a role cannot, and individual accounts can still be blocked. See [AI Integration (MCP)](/integrations/ai-integration-mcp.md#prerequisites).
* **Select several sessions and delete or block them at once** — A new **Select** button on the dashboard (Admin Mode) adds checkboxes to the session list; pick rows, a page, or a Shift+click range, then delete them or block their devices in one confirmation. A bulk action covers at most 100 sessions, and deleting more than 10 at once asks you to type `DELETE` first. See [Roles and Permissions](/concepts/roles-and-permissions.md#admin-mode).
* **Find annotated sessions by note** — The Annotations page has a search box over notes and verdicts, and `list_session_annotations` accepts a `query` parameter for the same search. See [Session Details](/portal-guide/session-details-and-diagnosis.md#annotations).
* **Readable MCP results on request** — Results stay compact JSON by default; a client that sends the header `X-MCP-Pretty: 1` gets indented results. See [AI Integration (MCP)](/integrations/ai-integration-mcp.md#optional-readable-indented-results).
* **Error messages carry a reference** — When a portal action or an MCP call fails, the message includes a short reference such as `Ref 3f2a9c1d`; quote it when you report a problem.
* **Fixed: Progress Portal could not find older enrollments** — Looking up a device by its exact serial number or device name now works regardless of how long ago it enrolled.
* **Security hardening** — A series of backend and portal hardening fixes across roles, device blocking, exports and input validation; nothing changes for day-to-day use.
* **Fixes & polish** — Dialogs now dim the whole page including the navigation bar, the live timeline refreshes once per upload burst instead of once per batch, and the Hardware Whitelist editor splits a pasted comma list into separate entries.
* **Polish across the portal** — Layout fixes, the rule cards carry a clearer two-row header, and the session Vulnerability Report names its inventory badge *Identification Confidence*. See [Software Inventory & Vulnerabilities](/portal-guide/software-inventory-and-vulnerabilities.md#inventory).
* **Dashboard and navigation polish** — Every dashboard stat card has its own icon and Failed Today turns red only when sessions failed; the Monitoring menu now leads with Fleet Health, Geographic Performance and Software. Operators and Viewers see that contributing a rule is admin-only instead of an error, and a Fleet Health model row without failures opens all enrollments of that model.
* **A newly published agent version shows up within minutes** — The What's new panel and the outdated-agent badges in the session list read the published version every few minutes instead of once every twelve hours.
* **Custom rules: `not_exists` on a field matches a missing field** — A condition with a `dataField` and `not_exists` now fires when no event of that type carries the field, as the concepts page describes. See [Analyze Rules: Concepts](/rules/analyze-rules/concepts.md#absence-is-not-evidence).
* **Fixed: standby time on the session page** — The Duration cell in Session Info now shows the standby time with seconds and counts only standby inside the enrollment window, so it matches the time-attribution chip below.
* **Fixed: script run times off by hours** — When a script's start and end log lines were read with different time-zone assumptions, Script Executions shows **n/a** with an explanation instead of a wrong run time, also for sessions from older agents.
* **Fixed: farewell feedback after offboarding** — The feedback form shown after you offboard your organization is delivered again, and a suspended organization sees an explanatory page with sign-out instead of a browser alert.

## August 2026

* **EPSS exploitation scores and a remediation priority on every CVE** — Vulnerability findings now show FIRST.org's EPSS score (how likely a CVE is exploited within 30 days), the CVSS vector, and an Act / Attend / Track priority that combines KEV, EPSS, and CVSS. See [Vulnerabilities](/portal-guide/software-inventory-and-vulnerabilities.md#vulnerabilities).
* **Fixed: vulnerability lookups no longer go blank after NVD rate limiting** — A throttled NVD answer was cached as "no vulnerabilities" for a week; it is now retried later and existing data keeps being served.
* **MCP server on the current MCP specification** — The AI integration now implements the 2026-07-28 MCP revision (stateless transport, Client ID Metadata Document registration) while older clients keep working unchanged. See [AI Integration (MCP)](/integrations/ai-integration-mcp.md#protocol-support).
* **Progress Portal for every enrollment scenario** — The self-service status page now follows Device Preparation, self-deploying, pre-provisioned, and Windows 365 Cloud PC enrollments with the right steps and live app progress instead of the Autopilot ESP phases only. See [Progress Portal](/portal-guide/progress-portal.md).
* **Windows Autopilot device association support** — Devices associated with your tenant through Microsoft's newly released device association can now be validated directly: enable **Device Association Validation** in Settings; no corporate identifier upload needed. See [Autopilot Device Preparation](/getting-started/autopilot-device-preparation.md#device-association).
* **New failure insights: blocked installers and blocked diagnostics uploads** — Enrollment analysis now pinpoints app installs that failed because another installation was already running on the device (a classic install-order race that fails deterministically around the same minute on every retry), and warns when a web security gateway answers the diagnostics upload with a block page — the case where failure evidence silently never arrives. See [Analyze Rules](/rules/analyze-rules.md).
* **Exclude events from the session timeline** — The timeline search box now combines several terms and hides everything matching a term written with a leading minus, e.g. `-app_install_progress`. See [Session Details](/portal-guide/session-details-and-diagnosis.md#filtering-the-event-timeline).
* **Device certificates are now bound to your tenant** — The backend verifies that the Microsoft Entra tenant stamped into a device's Intune certificate matches the tenant the data is sent for. See [Agent Lifecycle & Security](/concepts/agent-lifecycle-and-security.md#authentication).
* **Diagnostics package contents are now visible** — Settings → Agent → Diagnostics Package lists the built-in collection and the platform-wide paths read-only above your own entries, one line per path. See [Diagnostics & Log Collection](/troubleshooting-and-support/diagnostics-and-log-collection.md#the-diagnostics-package).
* **RealmJoin Watcher and Keep Awake moved to Agent Settings** — Both toggles now live under Settings → Agent → Agent Settings instead of Agent Analyzers. See [Settings Reference](/reference/settings.md#agent).
* **Discord notifications** — Discord is now available as a notification provider; enrollment alerts arrive as embeds in your Discord channel. See [Notifications](/integrations/notifications.md#discord).
* **Signed webhook requests** — Generic JSON webhooks can now carry an HMAC signature so your endpoint can verify each request really came from Autopilot Monitor. See [Verifying signed requests](/integrations/notifications.md#verifying-signed-requests).
* **App install times now measure the actual install attempt** — App durations now measure the final install attempt instead of the span since the app was first observed; multi-pass apps carry a ×2 marker, and download time is reported separately. Values recorded before the change keep the old measurement, so averages step down visibly around the changeover.
* **Analyze rules can now run during the enrollment** — Rules can declare additional **evaluation triggers** — at the WhiteGlove seal or when specific events arrive — instead of only running at enrollment end. Early findings appear live as **Preliminary** and are confirmed or resolved by the final analysis. See [Concepts → Evaluation triggers](/rules/analyze-rules/concepts.md#evaluation-triggers-when-a-rule-runs).
* **App version duration regression alerts** — When a newly rolled-out app version installs markedly slower than its predecessor, the app's detail page shows a regression banner and tenant admins get a one-time notification. Version charts now include median install duration by version. See [Software](/portal-guide/software-inventory-and-vulnerabilities.md#per-app-deep-dive).
* **Fleet context on analysis findings** — Each finding on a session now shows in how many enrollments the rule fired over the last 14 days; **View sessions** opens the dashboard filtered to those enrollments. See [Session Details](/portal-guide/session-details-and-diagnosis.md#session-detail).
* **Gather rules: guardrail-aware enabling and clearer attribution** — WMI gather rules can now select specific properties of an allow-listed class (requires the latest agent). Custom rules whose target is not allow-listed can no longer be enabled and show a **Blocked on devices** badge; new custom rules record the creating admin as **Author**.
* **Windows 365 Cloud PC support** — Cloud PC first-connect enrollments can now be monitored via the new opt-in **Windows 365 Cloud PC Validation** check — enable it in Settings and deploy the latest bootstrapper script. Rejected Cloud PCs in *Devices Not Registered* now carry a Cloud PC badge.
* **AI-assisted rule authoring** — An AI assistant connected via MCP can draft an analyze or gather rule, validate it against the real schemas and guardrails, and dry-run it against one of your sessions — without changing anything in your tenant. See [AI-Assisted Rule Authoring](/rules/ai-assisted-rule-authoring.md).
* **Test log patterns with the agent's real engine** — Log-parser patterns can now be tested against pasted sample log lines using the exact matching engine the agent runs on the device. See the [worked example](/rules/ai-assisted-rule-authoring.md#example-from-a-log-file-to-timeline-events).
* **Fixed: healthy enrollments settling as Incomplete after the agent went quiet** — A session with Device Setup finished, the desktop reached, and no failed apps now reconciles to **Succeeded** ("completed (assumed)") once the grace window expires, instead of turning Incomplete; a session whose agent hit its lifetime limit is decided immediately instead of waiting for evidence that can no longer arrive. See [Sessions & Statuses](/concepts/sessions-and-statuses.md#timeouts-what-happens-to-stuck-sessions).
* **Fixed: self-deploying (kiosk) enrollments shown as Awaiting User or Incomplete** — A self-deploying device whose agent goes quiet after Device Setup is now reconciled to Succeeded instead of waiting for a user that never signs in; affected sessions have been corrected. See [Sessions & Statuses](/concepts/sessions-and-statuses.md#timeouts-what-happens-to-stuck-sessions).
* **Fixed: enrollment durations inflated by time-zone-skewed log timestamps** — Session start times are now guarded against stray log timestamps from a different time zone; affected sessions have been corrected.
* **Fixed: Pre-Provisioning completion webhook fired twice** — It now fires once. Notification titles also switched from emojis to neutral status indicators.
* **Fixed: disabling device validation did not stick** — Turning off Autopilot or Corporate Identifier validation in Settings now actually saves.
* **Mobile & UX polish** — Public-site navigation now works on phones, the dashboard session list gained a **Load all** option, plus pagination, dialog, and dark-mode fixes.

## Late July 2026

* **Publicly available — sign-in with tenant activation** — Autopilot Monitor left the invite-only phase: any organization can sign in with a work account; new tenants are activated automatically after a short activation step — no access request needed. See [Requirements & Access](/getting-started/requirements-and-access.md).
* **Updated bootstrapper script (action recommended)** — The bootstrapper script (`Install-AutopilotMonitor.ps1`) now downloads the agent from the dedicated distribution endpoint `download.autopilotmonitor.com` and supports enrollments that restore settings via **Windows Backup for Organizations** (previously such devices were skipped as "already in use"). If you deployed it via Intune, replace it with the latest version from the repository — see [Deploy the Agent](/getting-started/deploy-the-agent.md). Existing deployments keep working.
* **Time attribution — where enrollment time goes** — Finished enrollments now show a breakdown of where the time went — device preparation, apps, identity & Hello, user ESP, desktop handoff — including reboot time and the ESP-blocking apps on the critical path. Fleet Health shows the same split as fleet-wide medians. See [Fleet Health](/portal-guide/fleet-health.md#time-attribution) and [Session Details](/portal-guide/session-details-and-diagnosis.md#time-attribution).
* **First-time-right — wipe-and-retry is now visible** — Enrollment attempts of the same device are grouped into a [device journey](/concepts/sessions-and-statuses.md#device-journeys--attempts): Fleet Health shows how many devices needed a second run, the weekly trend, and the repeat devices with their last failure reason. See [Fleet Health](/portal-guide/fleet-health.md#first-time-right).
* **Device history on the session** — A session whose device enrolled before now opens with *"Attempt N for this device"* and an expandable list of that device's previous enrollments.
* **Rule regression detection** — When an analyze rule starts firing far above its own 28-day baseline, its card shows a **↑ Regression** badge and tenant admins get a notification — including the OS build, model, or agent version the affected sessions concentrate on, where one exists. See [Analyze Rules](/rules/analyze-rules.md#regression-detection).
* **On-demand log collection** — **Collect Logs** on a running session asks the agent to build and upload a diagnostics package right away — no waiting for the enrollment to finish; a package typically arrives within a minute. See [Session Details](/portal-guide/session-details-and-diagnosis.md#on-demand-log-collection).
* **App durations count real installs only** — Apps that Intune reported as *skipped* no longer count as 0-second installs; duration stats and the slowest-apps ranking cover measured installs only, with skipped counts shown separately.
* **Rates count finished work only** — Success rate and app failure rate are now computed over finished enrollments and installs, so sessions still in progress no longer skew the numbers.
* **Install rows say where they come from** — Rows in Install Progress that are not plain Intune app installs now carry a **Click-to-Run** or **RealmJoin** pill, so an app and the installer it triggers no longer look like a duplicate.
* **Incompatible-TPM devices are surfaced** — Devices whose TPM cannot sign with RSA-PSS (and can therefore never be monitored on Windows 11 25H2+) now appear in the Hardware Whitelist with remediation guidance, plus a one-time notification.
* **Gather rules: phase-aware and quieter** — Rules can now collect once at a phase's start or end, be scoped to specific enrollment phases, and — for interval rules — emit only when the collected result actually changes (the default for new rules). See [Gather Rules](/rules/gather-rules.md).
* **Fixed: toggling a custom gather rule no longer clears its definition** — Toggles now only change the enabled state instead of wiping title, target, and parameters.
* **Fixed: portal could freeze on navigation** — Tabs no longer hang on a spinner for minutes after navigating; the hosting plan was also upgraded.
* **Portal recovers from deployments** — If a portal update ships while a tab is open, the app now recovers with a single automatic reload instead of a broken page.
* **Mobile & dark-mode polish** — Better readability for rule cards and phase timelines on small screens, tap-to-expand for truncated labels, and dark-mode contrast fixes.

## Early July 2026

* **Missing Autopilot profile is now flagged** — Devices that go through OOBE without their Autopilot deployment profile (not assigned, or the assignment hadn't propagated yet) are highlighted with a warning — across tenants, these enrollments fail far more often than normal ones.
* **Evidence for why the profile was missing** — The agent records Windows' own deployment-service verdict, the Autopilot diagnostic registry values, and a reachability check of the deployment service.
* **Device Validation shown on the session** — Session Info now shows which check admitted the device to the platform: Autopilot registration, Corporate Identifier, or Bootstrap token.
* **Pre-install errors are backfilled** — Autopilot errors logged before the agent was installed (e.g. TPM attestation retries that later succeeded) now appear in the session timeline, marked as backfilled.
* **New built-in rules for documented Autopilot known issues** — TPM attestation error codes, the hybrid-join 0x80004005 timeout (including which Windows update fixes it), and clock-skew warnings known to break attestation and ESP.
* **Two new session states — timeout is no longer a failure** — A silent session is now classified as Awaiting User (still waiting on the account phase) or Incomplete (expired, but not a failure) instead of always being marked Failed. See [Sessions & Statuses](/concepts/sessions-and-statuses.md).
* **Late completions now reconcile to Succeeded** — If a genuine completion signal arrives later, the session is upgraded to Succeeded even from Failed, Incomplete, or Awaiting User.
* **Honest Fleet Health** — Success Rate now excludes Incomplete sessions instead of counting them as failures; Incomplete gets its own stat card.
* **Windows Update during OOBE is now visible** — The agent detects a quality/cumulative update installing during enrollment and reports it, graded by two new analyze rules. See [Built-in Rules](/rules/analyze-rules/built-in-rules.md#device).
* **Self-maintaining rule lifecycle** — Gather rules now get the same automatic sunset/cleanup as analyze rules, and community rules are no longer mistaken for removed ones.

## June 2026

* **Software hub with self-service vulnerability exposure** — App installs, installed-software inventory, and CVE/KEV vulnerability exposure are now combined in one tabbed Software hub, with per-tenant Fleet Exposure available to tenant admins.
* **Faster Fleet Health on large fleets** — Fleet Health now loads from server-aggregated metrics instead of the browser, so it opens far faster on big fleets.
* **"Not registered" devices overview** — A new view lists devices rejected over the last 14 days because they weren't in the tenant's Autopilot or Corporate Identifier registry.
* **Richer session detail** — Session Info now shows Reboots, Enrollment Type, Join Type, and last-contact time.
* **Office & RealmJoin install rows** — Microsoft 365 Apps and RealmJoin packages now appear as their own rows in Install Progress alongside Intune apps.
* **Expanded MCP tools** — New software-inventory and app-install-metrics tools, richer audit-log filters, and role-aware tool access.
* **Clearer error reporting** — Event and error views now distinguish a detection failure from an install failure from a "likely stuck" enrollment.
* **Deep links survive re-authentication** — Opening a shared link in a new tab now returns you there after login instead of the dashboard.
* **Health dashboard MCP card** — The Health dashboard now shows MCP Server status alongside the SignalR quota card.
* **Device auto-block on runaway sessions** — Devices emitting an excessive number of session events can now be auto-blocked with one click.
* **CPU architecture** — Device hardware now reports CPU architecture (`x86` / `x64` / `ARM` / `ARM64`).
* **Security hardening** — Stricter header and query-filter validation, plus a patched dependency advisory.

## Mid May 2026

* **Safe session cascade-delete with restore window** — Session deletion is now crash-safe and includes a 33-day restore window.
* **Async tenant offboarding** — Tenant offboarding now runs as a background cascade with a progress countdown — you can close the tab while it finishes.
* **Optional Graph add-on — real script names** — Tenant admins can opt in to a scoped Graph permission so Intune Platform Script and Remediation names show in session timelines instead of bare IDs.
* **Full Intune Remediation lifecycle** — Detection, remediation, and post-detection are now shown as a single Remediation cycle card with a live "running" indicator.
* **SLA notification spam fix** — SLA breach notifications now fire exactly once per breach, with a configurable cooldown.
* **Dashboard stats overhaul** — Dashboard cards are now server-aggregated over the full 7-day window, so they no longer drift as the session table grows.
* **Agent V2 robustness** — Several completion and recovery fixes, including Hello-disabled enrollments no longer deadlocking.
* **Fail-soft runtime handoff** — A blocked WMI process creation (e.g. by Defender ASR) can no longer strand a freshly-bootstrapped device.
* **Intune dual-stack certificate fix** — On devices with both MDM and MMP-C certificates, the agent now picks the correct one for mTLS, resolving some certificate-related enrollment failures.
* **"Likely stuck" app-install hedge** — When ESP times out on Apps, the in-flight app is now shown as "likely stuck" instead of silently disappearing.
* **Notifications & UX polish** — Opt-in "enrollment started" webhook, an always-visible notification bell, and sidebar usage telemetry.
* **Bugfixes & polish** — Various fixes throughout the whole platform.

## Early May 2026

* **Agent V2 rollout (action recommended)** — The agent was rebuilt on a new internal architecture for more reliable session detection. Replace your Intune bootstrapper script with the latest version from the repository.
* **Submit Logs page** — Send diagnostic files to the Autopilot Monitor team without needing an active session.
* **Real-time notifications** — The notification bell now updates instantly via push instead of polling.
* **Graph-style pagination** — Large list endpoints (sessions, events, audit, reports) now support cursor-based pagination.
* **MCP server improvements** — New `get_resource` tool, leaner payloads, and a security hardening pass.
* **Backend security hardening** — Client-certificate trust is now pinned to the embedded Intune root certificate.
* **Web hardening** — Tightened Content Security Policy and a cleaner separation of the public site from the authenticated portal.
* **Web performance** — Duplicate parallel fetches are now collapsed, speeding up dashboard load.
* **Delivery Optimization** — Download breakdowns now include Microsoft Connected Cache (MCC) and LinkLocal sources.
* **WhiteGlove improvements** — Timeline now splits Part 1 / Part 2 at the correct event, and the summary dialog no longer shows after Part 1.
* **Bugfixes & polish** — Tenant ID resolution fallbacks, software-inventory fixes, a full-width dashboard option, and various smaller fixes.

## April 2026

* **Session completion state machine** — The agent now combines multiple signals (ESP exit, Hello, Desktop arrival) to decide when an enrollment is truly done, fixing several WhiteGlove and Hybrid Join misclassifications.
* **SLA tracking dashboard** — New SLA monitoring page with per-tenant configuration and breach notifications.
* **App Health dashboard** — New global view of app deployment health with scoped drill-downs.
* **Ops Events & Ops Alerts** — Operational event log plus admin alerts for backend health, blob storage, and runaway sessions.
* **Agent emergency / distress channel** — A separate low-overhead channel so the agent can still report critical errors when normal telemetry is impaired.
* **Enhanced analyze rule engine** — New compare operators, a mark-as-failed action, and template variables for rules.
* **Delivery Optimization** — OS-level download tracking with peer-to-peer totals.
* **Vulnerability matching improvements** — Fuzzy CPE matching, confidence levels, and WhiteGlove sessions now get vulnerability reports too.
* **Device Preparation groundwork** — The agent now distinguishes Classic vs. v2 Autopilot flow; full support is still in active validation.
* **IME version history** — Intune Management Extension version history is tracked, with alerts for outdated versions.
* **Known Issues page** — Dedicated docs page for ongoing issues.
* **MCP server** — Now a stateless endpoint with domain-organized tools and improved search.
* **Security hardening** — Centralized tenant-isolation middleware and additional request-integrity guards.
* **Web performance** — Lazy session loading, response compression, and an internal restructuring for maintainability.
* **Bugfixes & UX polish** — Quick search, bootstrap scripts, webhook notifications, and many smaller fixes.

## Late March 2026

* **Updated bootstrapper script (action recommended)** — The bootstrapper script (`Install-AutopilotMonitor.ps1`) now uses SHA-256 integrity verification for agent downloads instead of MD5. If you deployed it via Intune, replace it with the latest version from the repository.
* **Agent crash detection** — The agent now detects and reports unexpected crashes with automatic recovery, alongside platform-level metrics (CPU, memory, disk).
* **Global quick search** — A fuzzy search across sessions, devices, and users is now available from the navigation bar.
* **Rate limiting** — Per-user request rate limiting protects the backend from excessive API usage.
* **Bugfixes** — Vulnerability report rescan persistence, orphaned session handling, and NTP clock-skew warnings improved.
* **Software Inventory & Vulnerability Analysis** — The agent discovers installed software across Registry, WMI, AppX/MSIX, and per-user sources and correlates it against NVD and CISA KEV databases, shown as a vulnerability report with CVSS scores.
* **SecureBoot & time sync** — The agent collects SecureBoot certificate details, auto-detects the timezone, and checks NTP offset to catch time-related enrollment failures.
* **Security hardening** — Request size limits on submission endpoints and symlink detection in diagnostic paths.
* **Settings reorganization** — The sidebar now uses expandable sections; tenant settings were restructured and consolidated.
* **OOBE Config viewer** — A modal dialog decodes the OOBE configuration bitmask and detects the enrollment profile type.
* **FAQ page** — New Docs section covering supported scenarios, deployment, and troubleshooting.

## Mid March 2026

* **Unified sidebar** — The entire navigation has been redesigned with a global sidebar; mobile layout also reworked.
* **Session index table** — Session storage has been fundamentally re-architected for better scalability and reliability.
* **New agent signals** — The agent now reports clean shutdown, hardware inventory, network interface changes, and clock skew deviations.
* **Self-deploying mode detection** — The agent automatically detects self-deploying scenarios and tracks enrollment finalization with dedicated events.
* **Notification providers** — Webhook notifications now support Teams Legacy, Teams Workflow, and Slack — selectable per tenant.
* **Community rules** — A community rule set for gather and analyze rules has been added, with a JSON view and severity override.
* **Geographic drill-down** — The geographic performance view now supports drill-down to region and country level.
* **Mark as success** — Sessions can now be manually marked as successful, e.g. after manually resolved enrollments.
* **Feedback system** — An integrated feedback system allows direct feedback from within the portal.
* **Tenant settings UX** — Individual section save buttons replace the central save button; a new Unrestricted Mode option disables most guardrails per tenant request.
* **Docs expanded** — New general documentation section and IME pattern explanation.
* **Backend reliability** — Improved cache invalidation and retry logic for transient errors.

## Early March 2026

* **Role-based access control** — Admin and Operator roles with role management in Settings.
* **Agent self-update** — Agents can now update themselves automatically, replacing outdated versions in the field without manual intervention.
* **Bootstrap sessions** — New bootstrap session flow with explicit token enablement for initial device onboarding.
* **Raw event timeline** — A new raw view of the event timeline with full search support for deep-dive troubleshooting.
* **Enrollment summary dialog** — Optional summary dialog shown at the end of enrollment.
* **Original ESP tracking** — The agent tracks the original ESP provisioning status to catch non-IME errors such as certificate failures.
* **Analyze & gather rules** — Negative compare operators for analyze rules, XML/JSON gather options, and a built-in "old OS version" warning rule.
* **Email notifications** — Welcome and instructions email when a tenant joins the service.
* **Agent version management** — Block specific agent versions from connecting, plus expanded data-retention configuration.
* **Install progress** — The agent install progress page now shows download and install phases with elapsed time.
* **TPM info collection** — TPM details are now collected at enrollment time.
* **Firewall compatibility** — The agent sends a dedicated User-Agent header to simplify firewall allowlisting.
* **Pre-Provisioning (White Glove) improvements** — Ongoing accuracy improvements to the session timeline for Pre-Provisioning scenarios.

## Late February 2026

* **Configurable Diagnostic Package** — More flexible diagnostic data collection, example gather rules, and updated documentation.
* **Pre-Provisioning (White Glove) session timeline** — First implementation of session timeline support for Pre-Provisioning enrollments.
* **Real-time event delivery rework** — Reworked how live session events reach the dashboard timeline, for better reliability and accuracy.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://docs.autopilotmonitor.com/changelog/platform-changelog.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `automate deployments from our CI pipeline` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
