Noteworthy Information
These are cumulative release notes. If a release does not appear in this section, then there were no associated noteworthy information or enhancements.

-
ISAC launch through URL is disabled by default, this feature can be enabled by administrators from Advanced client configuration or by using installer command line options. This feature is supported for windows only. For more information, see Ivanti Secure Access Client NachoVPN mitigation.
-
For windows, Dynamic certificate trust is disabled by default, administrators can enable using ICS UI or through installer command line. For more information, see Ivanti Secure Access Client NachoVPN mitigation.
-
For TDI driver deprecation information refer to Deprecation of TDI Fail-Over Option.

- From Release 22.7R3, JAM commands for user mode are not supported. However for admin mode, there are no changes.
-
Auto upgrade or browser base upgrade is not supported from Release 22.7R1 or earlier versions to 22.7R3. Refer Noteworthy upgrade path.

-
Due to code signing certificate expiry on Windows, the auto upgrade and browser based scenarios of Ivanti Secure Access Client is impacted. ISAC 22.7.3 and later releases uses updated code signing certificate.
To upgrade from 22.7R1 or earlier releases to 22.7R3 and later ISAC releases, first upgrade to the latest respective dot release (22.3R3->22.3R3.1) before upgrading to required release version. For detailed upgrade procedure, refer to Upgrade Procedure for Ivanti Secure Access Client (ISAC) for Windows Desktop due to change in code signing certificate.Code signing certificate expiry does not impact ISAC upgrade through SCCM. Users can directly upgrade to required main release version.

- Ivanti Secure Access Client is upgraded to OpenSSL version 3.2.
- CentOS 7 is not supported.
- On Ubuntu 22, Ivanti Secure Access Client does not support CEF and SAML.

- Ivanti Secure Access Client does not support Windows 32-bit (x86). Latest ICS do not list the x86 installers.
- On existing version of ICS when 22.7.1 ISAC packages are updated, Windows 32-bit (x86) installers link will not work and when a user connects to ICS, an upgrade prompt displays but the upgrade fails.
- Auto upgrade is not supported for Windows 32-bit (x86) platform. An upgrade prompt may display but the upgrade fails on Windows 32-bit systems. Refer Deprecation of Windows X86/32-Bit.
-
macOS Big Sur is not supported from 22.7R1.
-
When AOVPN and nZTA connections co-exists, users can access any resources by connecting to either the lockdown connection (L3) or the nZTA connection. If one connection is active, the client lifts the lockdown irrespective of other connection.

- Ivanti Secure Access Client is not supported on macOS Catalina.
- Ivanti Secure Access Client installer is enhanced to support dynamic Windows ISAC driver Interface IfType Ethernet/Virtual.
-
The dynamic driver type functionality does not work when the client is auto-upgraded or upgraded through the Web Browser from 22.5Rx or older builds to 22.6R1.

- Ivanti Secure Access Client is enhanced to fix security issues. For more information, refer Security Article CVE-2023-34298.

- On macOS13 Venture, PSAL/Setup client upgrade with the browser does not work. Manually click Download and install to install the client.
- Ivanti Secure Access Client may trigger infinite browser tabs when "Allow user to override connection policy" is set to false when using SAML authentication. Use embedded browser when using SAML authentication or set the "Allow user to override connection policy" to true.

-
Pulse Secure Client is re-branded as Ivanti Secure Access Client. Complete UX rebranding and the UI upgrade is implemented. There is also an option to switch between the Classic UI and New-UI to maintain user experience. The Pulse Secure client icon is replaced by Ivanti Secure Access Client icon
. For more information refer KB45301.
-
No FIPS specific client is available from release 22.2R1.
-
Cache-cleaner, IE ActiveX are deprecated from release 22.2R1.
-
Increased number of Split tunneling networks from 512 to 1024.
-
DSA Certificate Authentication is not supported in FIPS mode.