New features summary
These are cumulative release notes. If a release does not appear in this section, then there were no associated new features and enhancements.
General features and enhancements
-
Enhanced macOS Package ID Handling: Improved macOS in-house PKG app deployment by automatically detecting and populating the correct package ID during app upload and ensuring the same package ID is sent to devices. This enhances app identification accuracy, resolves server-device install state mismatches, and improves installation status reporting. Bundle IDs can be reviewed and edited during upload before being locked after deployment.
-
Bundle ID Visibility for Installed Apps: The Installed Apps section on the Device Details page now includes a Bundle ID column, which can be enabled or hidden from the page settings.
- Automatic Retry for Failed Android App Installations: Android app installations that enter an Error Install state are now automatically retried starting one hour after device registration. Installation commands are re-sent every 30 minutes for up to five attempts to improve app deployment success.
-
Device Movement Audit Trails for Spaces: Added the Enable Audit Trails for Device Enrollment and Unenrollment in Spaces setting to track device movement between spaces. For more information, see Exporting Audit Trails.
-
OS Platform filter for Device Cleanup Settings: Administrators can now filter device cleanup actions by OS platform when removing Retired and Retire Pending devices. By default, all supported platforms remain selected, preserving the existing behavior. Administrators can modify the selection and restrict cleanup operations to specific platforms as required. For more information, see Device Cleanup Settings.
-
Office 365 App Protection Policy Synchronization: Previously, administrators could select apps directly within Ivanti Neurons for MDM while creating or modifying app protection policies. Microsoft has deprecated the API that was used to retrieve the available apps list, causing protected app lists to appear empty in Ivanti Neurons for MDM. Microsoft Office 365 App Protection policy management is updated to align with changes in Microsoft Intune. Applications configured in Intune are now automatically synchronized to Ivanti Neurons for MDM, ensuring continued visibility of protected apps. While app removal remains supported from Ivanti Neurons for MDM, new app assignments must be configured in Microsoft Intune and will be reflected automatically.
-
Device Movement Audit Logging for Spaces: Administrators can now track device movement between spaces through Audit Logs. When enabled, the new audit setting records events whenever a device is removed from one space and added to another, providing greater visibility into automated and rule-based space assignments. For more information, see Exporting Audit Trails.
-
Automatic Custom Attribute assignment using Device Groups: Administrators can now assign custom attributes at the device group level. Devices that are members of a device group automatically inherit the configured attribute values, reducing manual configuration and helping ensure consistent device categorization. For more information, see Device Groups.
-
OS-Level Device Registration Restrictions: Restrict device registration by platform, allowing only approved Apple, Android, and Windows devices to enroll. For more information, see User Settings.
Android features
-
Prevent App Updates While App Is in Use: Administrators can now prevent managed Android apps from being updated while they are actively in use. When Do Not Update While App Is In Use is enabled, app updates are deferred until the user closes the app or moves it to the background, helping minimize disruptions during active sessions. For more information, see App Configuration.
-
Maintain Kiosk Mode across Lockdown Policy changes:Added support for maintaining kiosk mode across lockdown policy changes. Devices automatically return to kiosk mode after a lockdown policy update, reducing manual intervention and minimizing disruptions on dedicated-purpose devices. For more information, see Lockdown & Kiosk: Android Enterprise.
-
Enable Unredacted Notifications: Added support for configuring lock screen notification visibility on Device Owner devices. Administrators can display, hide, or redact notification content on the lock screen to help protect sensitive information while maintaining notification functionality. For more information, see Advanced Android Passcode and Lock Screen.
-
Support for Device-to-User Mapping during Bulk Enrollment of Profiles: Added support for device-to-user mapping in bulk enrollment profiles. Administrators can assign a specific user to each device through the bulk enrollment CSV file or during manual device addition, enabling automatic user assignment during enrollment and reducing post-enrollment administrative tasks. Administrators can also update user assignments before device enrollment. For more information, see Device-to-User Mapping in Bulk Enrollment Profiles.
iOS, macOS, watchOS, visionOS, and tvOS features
-
New Skip Keys for Device Enrollment profiles: Administrators can now use the following Skip Keys when creating Device Enrollment profiles:
-
Skip Liquid Glass Pane (iOS 27.0+ and macOS 27.0+)
-
Skip Accessibility Appearance Pane (iOS 27.0+)
These skip keys help streamline the enrollment experience by allowing administrators to hide specific setup panes during device enrollment. For more information, see Device Enrollment.
-
-
Support for DDM Device System Health Status: Ivanti Neurons for MDM now supports the DDM Device System Health status on the Device Details page. Administrators can view this status under the Device Component Health section to monitor the system health reported by the Supervised devices. For more information, see Getting Started with Devices.
-
Added new Device Details fields for Apple devices: Added new Device Details fields to provide more visibility into Apple Device Management states. Administrators can now view the following details:
-
Multi-User Mode for devices operating on iOS 27.0+. This field indicates whether an iPad is configured as a shared device.
-
MDM Enrollment Type for devices operating on iOS 27.0+, macOS 27.0+, tvOS 27.0+, visionOS 27.0+, and watchOS 27.0+.
-
MDM Return to Service with app preservation for devices operating on iOS 27.0+ and visionOS 27.0+.
These fields help administrators review device configuration and enrollment information directly from the Device Details page. For more information, see Getting Started with Devices.
-
-
Support for App Privacy Defaults Configuration: Administrators can now configure App Privacy Defaults for one or more apps using Apple Device Declarative Management (DDM). When an app first launches, users receive a single consent prompt to allow or defer recommended permissions for supported privacy components, such as camera, microphone, location, Bluetooth, and local network access. For more information, see App Privacy Defaults.
The App Privacy Defaults configuration is now supported on macOS 27.0+ supervised devices.
-
Added new DDM app management attribute: Added the DDM app management attribute Apple DDM App Enabled field to the 'Advanced Search' and device listing pages. It shows which devices have apps distributed via DDM. Admins can turn this on through User Settings. For more information, see Getting Started with Devices.
-
Enhanced macOS Extensible SSO Configuration: Updated macOS Extensible SSO configuration to correctly map token attributes such as preferred_username and name. This resolves configuration errors caused by invalid token-to-user mappings and allows SSO profiles to be successfully deployed to devices.
-
Apple Enhanced Logging: Administrators can initiate Apple Enhanced Log Collection on supported Apple devices using an AppleCare-provided token. Device details display session status, token, and timestamp information, and active sessions can be canceled if required. For more information, see Apple Enhanced Logging.
-
Lockdown Mode Status (iOS 27+, macOS 27+): Added support for viewing and filtering devices by Lockdown Mode status using the new Security Lockdown Mode field on the Device Details page, Advanced Search, and device group rules. This field indicates whether Lockdown Mode is enabled (true) or disabled (false) on a device. For more information, see Getting Started with Devices, Device Groups, and Custom Policy.
-
macOS Software Update Settings Support Update: The macOS Software Update Settings configuration is no longer supported on macOS 27 and later devices. This configuration now applies only to supported versions up to macOS 26.x. For more information, see macOS Software Update Rules Configuration.
-
Restrictions Support Update (iOS 27+, macOS 27+): Updated the Allow Background Security Improvements Installation and Allow Background Security Improvements Removal restrictions to indicate that they are no longer supported on iOS 27 and later and macOS 27 and later devices. For more information, see iOS Restrictions and macOS Restrictions.
-
Updates to Siri Settings Configuration (iOS 27.0+, macOS 27.0+, tvOS 27.0+, and visionOS 27.0+): Added support for new restriction settings in the Siri Settings configuration . For more information, see Siri Settings.
-
Updates to Intelligence Settings Configuration (iOS 27.0+, macOS 27.0+, and visionOS 27.0+): Added support for new restriction settings in the Intelligence Settings configuration. For more information, see Intelligence Settings.
-
Safari Privacy Settings (iOS 27.0+, macOS 27.0+): Added support for Safari Privacy Settings in the Safari Extension and Settings configuration, allowing administrators to configure default Camera and Microphone permissions for specific websites using Apple Declarative Device Management (DDM). For more information, see Safari Extension and Settings Configuration.
Windows features
-
Windows AI Management Configuration: Windows AI Management now supports additional Windows AI CSP policies for managing Microsoft Copilot, Windows Recall, and Microsoft Paint AI features. Administrators can disable the Copilot hardware key, remove the Microsoft Copilot app, disable AI data analysis for Recall, configure Recall snapshot storage limits, and disable Image Creator, Cocreator, and Generative Fill in Paint. Support for both user-scoped and device-scoped policies has also been added, enabling more granular control of AI capabilities on Windows devices. For more information, see Windows AI Management Configuration.
Mobile Threat Defense features
Mobile Threat Defense (MTD) protects managed devices from mobile threats and vulnerabilities affecting device, network, and applications. For information on MTD-related features, as applicable for the current release, see the Mobile Threat Defense Solution Guide for your platform, available under the MOBILE THREAT DEFENSE section on the Ivanti Product Documentation page.
Each version of the MTD guide contains all Mobile Threat Defense features that are currently fully tested and available for use on both server and client environments. Because of the gap between server and client releases, new versions of the MTD guide are made available with the final release in the series when the features are fully functional.
General features and enhancements
- Enhanced Device Grouping Capabilities: A new Device Name attribute has been added to device groups, allowing you to create groups based on device names and assign them to configurations and policies. For more information, see Device Groups.
-
Added Space Name to Audit Trail Logs: Audit Trail logs now include the Space Name, making it easier to identify the space associated with an event. You can also filter Audit Trail records by Space Name using Advanced Search and include Space Name in CSV exports for improved reporting and analysis.
For more information, see Audit Trails. -
Read-Only Support Administrator Access: Newly created Support Administrator accounts now have read-only access by default. Custom roles are not automatically assigned, helping reduce the risk of unintended configuration changes. Additional roles and permissions can be granted later by an administrator as needed.
For more information, see Support Administrators. -
Space Management Enhancements: The Spaces page has been redesigned to improve navigation and management. Administrators can now create, view, edit, delete, prioritize and bulk-delete spaces, search for specific spaces, access recently viewed spaces, and maintain a consistent multi space selection across pages, except app page. Spaces are also displayed in alphabetical order for easier access.
For more information, see Managing Spaces. -
Introduction of Audit Trails in Reporting: Ivanti Neurons for MDM now supports Audit Trails in Reporting. Administrators can create, export, and download audit trail reports to review user and system activities across managed devices. For more information, see Working with Widgets.
-
Introduction of Audit Trails in Reporting: (Undefined variable: EE.product) now supports Audit Trails in Reporting. Administrators can create, export, and download audit trail reports to review user and system activities across managed devices. For more information, see Working with Widgets.
Android features
-
Improved Device Enrollment for Android Enterprise devices: You can now use Managed Google Domain Account (BTE) to manage the registration flow more effectively. This enhancement supports account registration with and without authentication, providing greater flexibility during device enrollment. For more information, see Managed Google Play Accounts (Android Enterprise Accounts).
-
Support for Global Proxy Configuration: Added support to create and apply Global Proxy configuration on Android devices enrolled in Device Owner (DO) and AOSP modes. This enhancement enables enforcement of a device-wide HTTP proxy, ensuring that all network traffic from system components and managed applications is routed through the configured proxy server for consistent control and monitoring. For more information, See Global Proxy Configuration (Android).
-
Enhanced Single App Kiosk Mode Settings Access: Administrators can now allow users to access Ivanti agent settings without exiting Single App Kiosk Mode. This enhancement provides controlled access to agent settings while maintaining kiosk restrictions. For more information, see Lockdown & Kiosk: Android Enterprise. For more information, see Lockdown & Kiosk: Android Enterprise.
-
Audit Trails logging for Clear App Cache requests: After a Clear App Cache request is completed, the Audit Trails page now logs the application's details, including version, name, platformAppId, displayVersion, and bundleVersion. For more information, see Audit Trails.
-
Managed Google Domain Account and Device Migration: Administrators can now upgrade Android Enterprise deployments from Managed Google Play to Managed Google Domain and migrate eligible enrolled devices using a dedicated migration configuration. The feature includes migration status tracking and supports filtering and grouping of devices based on migration state to simplify large-scale migration management. For more information, see Managed Google Play Accounts (Android Enterprise Accounts) and Upgrade to managed Google domain.
-
Integrated Tunnel Experience in Ivanti Go: Ivanti Tunnel functionality is now integrated directly into the Ivanti Go app for Android, eliminating the need for a separate Tunnel app and providing a more streamlined user experience. For more information, see Managed Configurations for Android.
iOS, macOS, watchOS, visionOS, and tvOS features
-
Support for DDM Automated Configurations: Ivanti Neurons for MDM now supports the following new Apple Declarative Device Management (DDM) configurations for iOS 26.4+, macOS 26.4+, watchOS 26.4+, visionOS 26.4+, and later devices and these configurations help administrators manage supported Apple device settings through DDM:
-
External Intelligence Settings
-
Intelligence Settings
-
Siri Settings
-
Keyboard Settings
-
Migration Assistant Settings
For more information, see Managing Configurations.
-
-
Declarative Device Management (DDM) App Management: Ivanti Neurons for MDM now supports Declarative Device Management (DDM) App Management for Apple devices. With DDM, the management server sends app management declarations to the device, and the device independently applies, monitors, and reports its state. This reduces the need for continuous server-initiated MDM commands. This feature is currently supported on iOS/iPadOS 26.0 or later, with Go Client 126.0.0 or later only. For more information, see Declarative Device Management (DDM) App Management.
-
App Version Pinning: Apple DDM App Management now supports app version pinning for iOS applications. Administrators can specify and enforce a target app version, preventing updates beyond the pinned version until the pin is modified or removed. App downgrades are not supported. For more information, see DDM App Management Settings.
-
App Updates via Cellular: Apple DDM App Management now supports configuration of cellular data usage for iOS application deployments. Administrators can allow app downloads and updates over cellular networks, restrict them to Wi‑Fi connections, or defer to the device's App Store settings, providing granular control over application delivery. For more information, see DDM App Management Settings.
Mobile Threat Defense features
Mobile Threat Defense (MTD) protects managed devices from mobile threats and vulnerabilities affecting device, network, and applications. For information on MTD-related features, as applicable for the current release, see the Mobile Threat Defense Solution Guide for your platform, available under the MOBILE THREAT DEFENSE section on the Ivanti Product Documentation page.
Each version of the MTD guide contains all Mobile Threat Defense features that are currently fully tested and available for use on both server and client environments. Because of the gap between server and client releases, new versions of the MTD guide are made available with the final release in the series when the features are fully functional.