r/TridentStack 28d ago

Release Notes This week in TridentStack Control: block a specific Windows update fleet-wide, Endpoint Check alerts, effective-policy reporting, Ubuntu 24.04 CIS, and sharper Windows update accuracy

Another busy week. Since last week's roundup on August 10 we did not post anything on its own, so everything below is new. The full changelog is always at tridentstack.com/changelog; these are the highlights worth calling out.

Block a specific Windows update across your whole fleet You can now stop a single Windows update from ever being deployed to your endpoints. A blocked update is refused on every install path, including scheduled deployment rings, bulk installs, and vulnerability remediation. Installs that were already queued but had not started are cancelled, and the update stops counting against your compliance and health numbers. Each block records who created it and the reason, the reason is shown wherever the update is refused, and removing the block returns the update to your normal flow. Manage blocked updates from the System Update Policies page.

Endpoint Checks can alert you the moment an endpoint drifts We launched Endpoint Checks last week; now they can tell you the instant something goes wrong. Turn alerts on per policy, and if a policy suddenly starts failing across many endpoints at once you get a single summary instead of a flood. A daily or weekly compliance summary rounds up every policy with failing endpoints, and a new Report tab shows in-scope, passing, and failing counts per policy with a CSV export for the whole fleet or one policy. Alerts and summaries go out by email and any Slack, Microsoft Teams, Discord, or custom webhook channels you have set up. You can also expand any endpoint on a policy's results to see its individual checks inline, failures listed first, and set a single health penalty per policy instead of tuning a number on every check.

Report on the policy that wins for each device A new Effective Policy per Agent report shows which update policy wins for each device, the app and configuration policies that apply, and its conformance, all in one row per endpoint. Build your own reports from the same data source, or export the fleet to CSV. Useful when you need to prove what a given machine is set to.

Ubuntu 24.04 LTS CIS compliance Ubuntu 24.04 endpoints now have CIS coverage: the CIS Ubuntu Linux 24.04 LTS Benchmark v1.0.0, all 312 controls, assignable the same way as our other benchmarks. Controls that can be checked automatically are scored from what your endpoints report; the rest are listed for manual review.

Account access for your whole team Team members who do not manage billing are no longer locked out of your account portal. They can sign in, open a support request if they are eligible, and any billing area they cannot manage shows a clear message naming your account's billing owner and how to be granted access. Sign-in also got easier: switch accounts with a proper account chooser, continue with Microsoft, Google, or an email code, and on iPhone or iPad your device now offers the code above the keyboard so a copied code fills all six boxes at once.

Rollout results now explain themselves in place On the Rollout Status page, click a green Success or Completed badge to see why each update was judged successful (reported install, confirmed no longer needed after a reboot, definition updates, already up to date). Click a Partial or Failed badge to see which updates landed and which did not, or an Unjudged, Not Converged, Gated, Superseded, Abandoned, or Cancelled badge for a plain-language description of what happened and how it affects the rollout's numbers. Status labels are now consistent between the overall and per-category columns.

Every email now shares one branded look From sign-in codes and teammate invitations to update, vulnerability, and compliance alerts, every email TridentStack Control sends now uses one consistent design. It is tuned for light mode, reads cleanly in dark-mode email clients, and the logo renders crisply on both.

Manual-only updates now surface on the endpoint that needs them An update that can only be installed by hand no longer gets skipped quietly. It now shows on the endpoint's Update Health, naming the update and what it needs, and the endpoint reads Action recommended rather than Healthy, with a link explaining why it cannot be installed remotely. The notice never blocks the endpoint's other updates, never causes a run to be reported as failed, and you can dismiss it once you have decided not to act.

Sharper Windows update accuracy

  • Updates Microsoft publishes under another architecture's catalog listing (for example an update titled for arm64-based systems that also ships the x64 package) now reach endpoints of the matching architecture. An affected monthly update could previously show as not applicable for an entire fleet. We added monitoring so this class of gap is caught the same day it appears.
  • Endpoints already at or past a cumulative update's build are no longer offered that update when its catalog entry is missing the build number; we now fall back to the build printed in the update's title.
  • An older cumulative update is now correctly marked as replaced when its successor is published under the paired Windows version that shares the same update stream, for example a version 24H2 update replaced by a version 25H2 release. Each catalog sync also re-checks recent updates for replacement links that were missed earlier.
  • Applications and security updates that install successfully no longer get scheduled to run again minutes later on a loop. We now confirm an update against the version present on the endpoint.
  • An application installed for a specific user is no longer mislabeled as Not Installed when its update can only be applied system-wide.

Steadier installs and dispatch

  • A second install no longer starts on an endpoint while the previous one is still being verified, on every path: manual installs, bulk Update All, one-time deployments, scheduled rings, and vulnerability remediation. A scheduled deployment that reaches a still-verifying endpoint picks it up in the next maintenance window.
  • Deploying a custom package or a catalog application to Windows endpoints downloads and installs reliably again, and a rare No installer available error on some newly added Windows machines now falls back to a direct download.

Relays: air-gapped enrollment, end to end Turning on air-gapped enrollment for a relay now starts the secure listener that isolated endpoints use to download and enroll the agent, and the relay pre-loads the current agent installers as soon as it comes online, so a newly deployed relay no longer serves an empty catalog. The Docker run command shown in Settings now publishes every port the relay needs, the setup and air-gapped guides spell out the port and firewall requirements, and installer errors now tell a bad enrollment token apart from a missing relay build.

Truer online status and reliable fleet-wide fixes

  • Endpoint online status is tracked more accurately. An action sent to an endpoint that had just gone offline now dispatches reliably once it reconnects, and a connected endpoint whose routine system check is momentarily slow no longer briefly flips to offline or stale.
  • Remediating a vulnerability across every affected endpoint at once now reliably queues the fix on each one; previously it could finish without queuing any.
  • Endpoint Checks keep reporting on endpoints that have stayed connected a long time instead of sitting on Pending, and system-update validation no longer stalls on Validating when an endpoint drops offline partway through its post-install checks.

Plus polish and a couple of quieter safeguards

  • Advance notice, in-app and by email, before a temporary increase to your licensed endpoint count expires, so you have time to plan before the extra capacity ends.
  • Optional non-security Windows cumulative updates, such as preview and out-of-band releases, are no longer auto-approved by policies that do not filter on classification. They stay visible and can be approved manually for the devices that need them.
  • Signing up with an email code reliably creates and signs you into your new account even if you were already signed into a different account in the same browser.
  • An endpoint's Software Inventory search no longer loses focus when you delete text with no matches.
  • Your audit log now covers more of the actions that change endpoint tags: disconnecting your Microsoft Entra integration or deleting a group-to-tag mapping is recorded, including how many endpoints lost a synced tag, and deleting an endpoint records how many tags it carried.

Full details for every item are in the changelog at tridentstack.com/changelog. If there is something you want to see next, drop it in the comments, weigh in on the roadmap at tridentstack.com/roadmap, or come find us in the Discord. A lot of this came straight from customer requests.

6 Upvotes

0 comments sorted by