What's New
Version 2026.1 January
Platform
The Amazon S3 Outbound Connector is now available in technical preview. This feature enables customers to export Ivanti Neurons Audit Trails to their own S3 buckets, supporting seamless downstream integration with ELK (Elasticsearch, Logstash, and Kibana) stacks.
The Splunk HTTP Event Collector (HEC) Outbound Connector is now generally available.
Learn more about Splunk HEC Connector.
Intel vPro® "Chip-to-Cloud" integration harnesses Intel vPro® technology and Intel® Active Management Technology (Intel® AMT) to provide secure, remote management of enterprise devices directly through the Ivanti Neurons Admin Console. Operating at the hardware level, this out-of-band management solution empowers IT administrators with robust capabilities, even when devices are powered off or the operating system is unresponsive.
Learn more about Intel vPro® "Chip-to-Cloud" feature in Device actions.
App Control
Scripted rules enable custom rule creation using PowerShell or VBScript to meet complex requirements. Applications can be dynamically allowed, blocked, or elevated based on a wide range of scripted conditions, providing powerful, flexible control over application behavior.
Learn more about Scripted Rule.
Neurons Connector
In MDM Connector, when a custom group is assigned to devices, it is imported with each attribute and its corresponding value. These values are used for tasks such as creating configurations and device groups. The Custom Attribute field appears in the device details if the device has an assigned custom attribute.
Enabling the new GCC High Tenant option lets you connect your environment to your Microsoft Entra ID tenant in Government Community Cloud (GCC) High.
A new field SoldTo provides more granular results about the device.
OAuth 2.0 lets users access instance resources through external clients by obtaining a token rather than by entering login credentials with each resource request.
External Attack Surface Management
Community scan capabilities are now available and includes open-source Nuclei templates. These capabilities are available for execution on demand or alongside weekly automatic EASM scans.
Learn more about Community Scans in Insights (Assets tab).
Workspace
Ability to search the custom action section of the device view to filter for the required bot/action.
The PowerShell and osquery stages have been enhanced to allow for automapping and type casting of the results. This removes the need to place data into variables to perform math operations for example.
Stage updates that don’t change functionality no longer requires each stage to be saved within each Bot. Instead, the bot/stage is highlighted blue, and the update can be acknowledged across all Bots from a single stage.
This is a new stage that allows for querying of array-based data within data services. This returns each element of data as its own list for use downstream.
Learn more about Inventory Array Support in Neurons Bots Stages.
Additional options to choose how a user is targeted by the Teams stage within a Bot workflow. This enhances support for a wider number of Entra configurations.
Learn more about MS Teams Bot User Identification enhancements in Neurons Bots homepage.
This enables the temporary ungrouping of Bot query results allowing for the data to be sorted on secondary columns. This was only previously able to be achieved by exporting the data into CSV then sorting the results.
This is a new stage that allows users to create PowerShell scripts (query and action) on the fly within the stage itself by stating what they want it to do. This stage also casts the types of the data output and map columns automatically for them.
Learn more about PowerShell AI Stage in Neurons Bots Stages and Custom Stages.
AI Diagnostics have now been released under open technical preview. This allows users to type a symptom in against a device, and the feature pulls back a summary and list of possible causes. Along with this, controls within both the admin settings and role based admin have been included to aid the control and rollout of AI based features in Bots. This feature is disabled by default.
Learn more about AI Diagnostics in Device details.
Added the ability to filter based upon a value either being “nul or white space” or “not nul or white space”. This improves workflow efficiency as it previously needed multiple stages to do this.
Several new stages that offer various different string manipulation functions. This allows for the modification of retrieved data for use later in the workflow. The operations that are available are as follows:
-
Trim
-
Change Case
-
Substring
-
Concat / Join
-
Replace / Remove
-
Validate
-
Search / Match
-
Encode / Decode
-
Length
-
URL-Safe (slugify)
-
To / From JSON / YAML
-
Regex Search / Extract
Learn more about String Function Stages in Neurons Bots Stages.
Patch Management
Directly from the Patches tab in the Deployment History and Ring Deployment pages, administrators can now select one or more advisories and add them to a patch group without needing to navigate to the Patch Intelligence page.
Microsoft’s Malicious Software Removal Tool (MSRT) is a commonly used security utility that helps detect and remove prevalent malware from Windows endpoints. Ivanti Neurons for Patch Management enables administrators to deploy MSRT directly from the console, enabling the delivery of the Security Tool as part of regular patch cycles.
To assist administrators with tracking and achieving patch compliance objectives, Ivanti Neurons for Patch Management dynamically curates a Compliance Baseline patch group that includes all patches that have been scheduled for deployment. A new option has been added to Compliance Reporting enabling reports to be generated against this Compliance Baseline. Organizations may use this report as a key metric for gauging the overall success of their patch deployment performance.
Learn more about Continuous Compliance Reporting at Compliance Baseline Patch Groups
The CSV export format for selected out-of-the-box Patch Management report templates has been updated to present clean, tabular data without layout formatting, making it easier for downstream processing and analysis. Affected reports include:
-
Patches by Device - Detailed
-
Devices by Patch - Detailed
-
Devices by CVE - Summary
-
Devices by CVE - Detailed
-
Deployment History - Detailed
-
Monthly Maintenance