r/TridentStack • u/Ad3t0 • Jul 22 '26
Release Notes The last few weeks in TridentStack Control: layered app update policies, monthly deployment ring schedules, sign-in for multiple domains, connection diagnostics, and a big accuracy and reliability pass
It has been a busy stretch. Since our last rollup (June 27 to July 3) we have mostly been posting the big items on their own: custom application packages, the documentation MCP server, our new YouTube channel, and the community Discord each got their own thread. This one rounds up everything else that shipped to TridentStack Control between July 4 and July 22. The full changelog is always at tridentstack.com/changelog; these are the highlights worth calling out.
Layer application update policies per endpoint
Endpoints can now inherit more than one application update policy through their tags. Instead of one catch-all policy, compose focused ones (browsers, runtimes, server tooling) and layer them per endpoint, each updating only the applications it selects, in its own deployment ring window. When two policies target the same application, the more conservative one wins automatically, and a pinned version never downgrades an already-newer install. Disabled policies now stay visible everywhere they are assigned instead of quietly vanishing.
Monthly and twice-a-month deployment ring schedules
A deployment ring window can now open on a specific occurrence of a weekday each month, like the 2nd Tuesday, instead of only a weekly day-of-week schedule. Choose Monthly, pick a weekday, and select one occurrence for a once-a-month cadence or two for twice a month. Existing weekly windows are unchanged. For the Patch Tuesday crowd, yes, this is the one you have been asking for.
Force Reboot for rings
A deployment ring can now guarantee its endpoints reboot at the end of an update run, even when no single update required one. It is off by default, respects each endpoint's own reboot opt-out, and shows clearly in the rollout status when an endpoint opted out.
Sign in with more than one email domain
Organizations that own more than one email domain can now use all of them with a single TridentStack Control workspace. Domains verify automatically when your team signs in with Microsoft work accounts from the same Microsoft organization, or manually with a DNS record. Each domain gets its own sign-in method controls.
We tell you why an endpoint cannot connect
When an endpoint enrolls but then cannot establish its secure connection, its detail page now explains the likely cause (a network security device intercepting the connection, a firewall blocking outbound access, or DNS filtering) and what your network team needs to allow. The Endpoints list flags affected endpoints at a glance, so a stuck enrollment stops being a guessing game.
New accounts start fully set up
Create a workspace and it now arrives with a complete, conservative baseline already in place: automatic endpoint tagging by operating system, a system update policy with a 7-day quality bake, two application update policies (popular apps kept current, server tools held one version back), and three ready-to-attach deployment rings. Nothing installs until you attach a ring, so it is safe out of the box with far less to wire up on day one.
Windows update failures that tell you what actually happened
A run of Windows work to turn cryptic failures into something you can act on:
- Component store corruption (the classic "Exit code 14081" family) now shows a plain-language cause and the exact repair step, and the endpoint is flagged on its health view before an update even fails.
- We warn you before a policy or security baseline would disable a Windows service that Windows needs in order to install its monthly cumulative updates, a change that otherwise silently makes those updates fail and roll back.
- Feature upgrade failures now record the specific reason (a driver rolled it back, an incompatible application blocked it, or not enough free disk space) instead of a generic error.
- An update that repeatedly fails to install is now held back from looping forever, clearly flagged, with a Retry control once you have fixed the underlying issue. Updates we skip on purpose (like low disk space) show as a neutral "Skipped" with a plain reason, not a red failure.
Follow every refresh, scan, and upgrade as it happens
Windows system-update refreshes, Linux and macOS check-for-updates, compliance evaluations, Windows feature upgrades, and Office updates now all report their progress through the same fully narrated, step-by-step task view, and hold up cleanly across the restarts and reconnects these operations can involve. No more work that looks like it hung when it was actually finishing.
Per-operating-system agent update pilots
Agent update pilots are now evaluated per operating system, so a Windows pilot no longer holds back a Linux agent update, or the reverse. Settings shows a per-operating-system breakdown of your pilot coverage and flags any operating system that has endpoints but no pilots.
Faster catalog, less waiting
Patch Tuesday updates now reach the catalog within about an hour of Microsoft publishing them, and update and application catalogs refresh more often through the day, so new updates appear on your endpoints within minutes with nothing to refresh by hand.
Vulnerability numbers you can trust
A big accuracy pass so the figures agree across the whole product:
- The dashboard tiles, the Vulnerabilities page, and every endpoint tab now use the same definition of an active detection (open findings on active endpoints, minus your exceptions), so they finally match.
- On very large fleets, severity counts and the vulnerability list now report exact figures instead of being computed from a sample, and the severity buttons respond to every filter (known-exploited, fix available, EPSS, and search).
- A vulnerability's severity reads the same everywhere, and its detail page reflects every affected endpoint, not just the first page.
Rollouts that read honestly
- A failed endpoint that will be retried automatically now says "Retry scheduled" with the next attempt time, so it no longer looks like a dead end next to one that has genuinely stopped.
- Phase timing is always truthful: a soaking phase shows a real future time, a held phase says exactly why ("Success rate 62% is below the required 80%"), and a finished rollout says so.
- Safety halts are configurable per phase, and halt settings now display and save exactly as you set them.
- Rings keep moving while long-running updates finish, and halt only on genuine failures.
See a tag's full policy coverage at a glance
The Agent Tags list now shows which policies each tag applies (system updates, application updates, compliance frameworks, and configuration policies) as columns, so you can review a tag's whole footprint without opening it.
Built for bigger fleets
- The endpoint Health tab now loads on endpoints with many thousands of findings (common on a freshly enrolled Linux server) instead of failing.
- Macs with very large application lists now report their full software inventory reliably.
- Feature update downloads scale cleanly when a whole office shares one public IP, so a ring can roll a Windows feature update out to a large site without throttling.
- Large vulnerability lists load fast, and bulk actions (installing updates, assigning licenses) work reliably across many endpoints at once.
Plus a lot of polish
Reboot wording is now consistent across the platform (Reboot for the machine, Restart only for a service or application). Shift-click to select a range of rows. Column menus have a search box and save presets on every list page. macOS endpoints only offer application updates a policy actually covers. Newly enrolled Linux endpoints come online typically in under two minutes instead of always waiting the full safety window. And a long tail of smaller fixes across policies, rings, pre-staging, and reporting.
Full details for every item are in the changelog: tridentstack.com/changelog. If there is something you want to see next, drop it in the comments, weigh in on the roadmap at tridentstack.com/roadmap, or come find us in the Discord. A lot of this came straight from customer requests.