Secure Endpoint 10.0 release notes

This topic describes the software updates included in Secure Endpoint 10.0, along with subsequent hotfixes and upgrades. In addition to the specific changes detailed here, each release also includes broader system enhancements designed to strengthen security, optimize performance, and enhance overall stability.

To view the software updates that apply to the Secure Endpoint Agent, see the Secure Endpoint Agent release notes - Version 10.0 hotfixes.

Depending on the Absolute product licenses associated with your account, some of the following features, enhancements, and fixes may not be available to you.

The following features, enhancements, improvements, and fixes were introduced in the August 2025 update of Secure Endpoint 10.0.

Features and enhancements

Improvements and fixes

Feature/Area Details
Absolute APIs
Applications
  • The ability to collect application usage data as part of an Installed Applications policy has been expanded to include Evaluation licenses.

Application Resilience
  • Application Resilience policies for Forescout Secure Connector now support version 11.3.x or higher, including the ability to upload the application's installer as an EXE file within a ZIP archive.

  • Application Resilience policies for Sophos Endpoint Protection now support optional software packages, such as Fixed Term Support (FTS) and Long Term Support (LTS) versions. This added support requires the latest version of the Secure Endpoint Agent (10.0.0.3) installed on devices.

  • Resolved an issue where successful application reinstalls of ManageEngine Desktop Central and Cisco Secure Client were not properly recorded on the Events page in the History area. These reinstall actions are now accurately tracked.

Bulk actions
  • When the uploaded file contains Inactive and/or Disabled devices, the devices are now processed correctly. To show these devices on the Devices from uploaded file page, remove the Agent status is Active filter.

  • When you export the list of invalid devices, the file name of the downloaded file is now Invalid device identifiers from <uploaded file name>_<date>.csv instead of Invalid rows from <uploaded file name>_<date>.csv.

  • When the file name of the upload file contains more than one period (.) character, the file is now processed as expected.

  • Previously, after dragging a device list file over the console without dropping it, the Upload device list full-screen message failed to close when you moved your cursor away from the console. This issue is now fixed.

  • Previously, if the Perform permission for Device Groups and folders was added to a custom Guest User role, the icon was not available in the quick action toolbar. This issue is now fixed.

Chromebook support
  • Previously, if you submitted an Unenroll device request for a Chromebook that had been deactivated in the Google Admin console and then only partially reactivated, the device failed to be unenrolled. This issue is now fixed.

Dashboards (Customizable)
  • When viewing a Devices widget in expanded view, and EDD match score or EDD risk score is used as a metric, the respective column is now displayed in the results grid.

  • Previously, when you hovered over a point on a timeline, and the point applied to multiple applications, the tooltip showed only one application name. This issue is now fixed. The tooltip now lists all applications.

  • The time interval (Daily/Weekly/Monthly) filter is now available in widgets that meet the following criteria:

    • Data source is device usage, web usage, or application usage
    • Chart type is bar or donut
    • Aggregation is Average
Custom fields
Device Details
  • Previously, the following message may have been displayed momentarily while the History page was loading: No events to show on this date range.. This issue is now fixed.

  • Performance of the Device Details area has been improved and its pages may now load faster.

Geolocation
  • Previously, when the Turn Location Services on when required setting was enabled in Account settings, Wi-Fi and OS locations failed to be reported in the console when the following conditions applied:
    • Devices are running Windows 11, version 24H2
    • Location Services are disabled on the devices using the following settings in Group Policy:

      • Turn off location is enabled
      • Let Windows apps access location is set to Force Deny

    This issue is now fixed.

Investigations
  • On the Reported Stolen page in the Devices area, filtering the page by the Investigator field using one of the following conditions now returns the expected results:

    • is
    • is not
    • contains
    • does not contain
License management
  • The banner that shows when licenses are due to expire within the next 30 days is now removed after the licenses are renewed, or a purchase order for an equivalent license is added to your account.

Playbooks
  • User-initiated playbooks can now be downloaded to a device using a Wi-Fi network connection. Previously, a physical ethernet cable was required.

    After the device user enters the Playbooks passcode on the device, they can now select a Wi-Fi network and enter credentials. Learn more

  • The playbook configuration for a Restore from image playbook now includes a BitLocker recovery key field. If a device's drive is encrypted by BitLocker Drive Encryption, ensure that you enter the device's recovery key in this field.

Reports
  • Exporting a page or report is now more consistent across the console:

    • The default file format is now Excel (.xlsx), or CSV (.csv) if Excel is not applicable.
    • By default, all dates and times in the report are presented in the time zone set in your user profile.

Roles
  • When dual approval is configured for custom roles on device actions, approval emails now include the requester's full name so approvers can easily identify who submitted the request.

Vulnerabilities and Workflows
  • To inform you that a trial of the Vulnerability Management feature is available, a dialog is now displayed when you click Vulnerabilities or Workflows on the navigation bar. Click Start 30 day trial to join the trial. Conversely, if a Trial Setup unavailable message shows, contact Absolute Technical Support to request access to the trial.

User profile
  • The maximum character limit for Absolute usernames (which are users' email addresses) has been increased to 255 characters.

Features at end-of-life

Absolute has retired the following features:

Feature Details
Application Health

The following features, enhancements, improvements, and fixes were introduced in the July 2025 update of Secure Endpoint 10.0.

Features and enhancements

Improvements and fixes

Feature/Area Details
Bulk actions
  • The Search field on the Devices from uploaded file page now contains the following helper text: Search by device name, identifier, or serial number.
  • Commas (,) included in the uploaded file of identifiers are now treated as field separators. Note that device names that contain a comma (for example, Smith, Mary) will fail to be processed.
Chromebook support
  • A new version of the Chromebook extension has been released. Version 2.6.6.3 of the extension contains updates to support a future data center enhancement.

Dashboard (Classic)
  • When viewing the console in Japanese, the Report on <#> devices link at the bottom of each dashboard widget is now displayed correctly.
Dashboards (Customizable)
  • In each widget, the tooltip that shows when you hover over a bar, slice, or line has been improved. The most important information, such as the device count, is now more prominent.
  • The following improvements have been added to the metric filter:

    • The following filter conditions are not applicable and have been removed:

      • Is empty
      • Is not empty
    • For the Time in use and CPU in use metrics, you can now specify hours and minutes.
    • For the Memory in use metric, you can now specify the unit, such as KB or MB.
Device groups
Geolocation
  • In the Wi-Fi errors report column, Location services not enabled is now displayed for devices running Windows 11, version 24H2 or higher when the following conditions apply:
    • Location Services is disabled on the device, and
    • The new Turn Location Services on when required setting is not enabled. Learn more
History > Actions
  • Although a device was appropriately licensed, a Send Message request may have failed to be processed on the device for the following reason: License upgrade required. This issue is now fixed.
License management
  • A new filter is now available on the Products page in License Management. To show only Base licenses, add the following filter: Product type is Base is Yes.
  • Previously, when a device was re-enrolled, the default license assignment settings may not have been automatically applied, so the device was unlicensed. This issue is now fixed.

Reports
  • Resolved an issue where the Estimated cost exposure (USD) column in the Data Risk Assessment report was not displaying data in certain environments.

The following features, enhancements, improvements, and fixes were introduced in the June 2025 update of Secure Endpoint 10.0.

Features and enhancements

Improvements and fixes

Feature/Area Details
Absolute APIs
  • The Agents resource has been added to the API. Learn more

Absolute Community
  • A new and improved Absolute Community is now available.

    Absolute Community is the unified hub for knowledge sharing across customers, partners, and Absolute. The new hub integrates the existing Knowledge Base and Support areas with the added features of discussion groups, webinars, and product updates. Go to this online space to collaborate with other members, find answers to product questions, and grow your knowledge.

Applications
  • In the Applications area, an application's Installations chart erroneously limited total installations to a maximum of 1000, which may have caused incorrect data to be shown in the chart. This issue is now fixed.

  • Previously, when viewing a device's Application Health, if the installed version of an application didn't match the expected version, the two versions may have been displayed as dates instead of version numbers. This issue is now fixed.

Application Resilience
  • Application Resilience now supports Eclypsium. Learn more

  • Application Resilience policies for Omnissa Horizon Client now support version 8.15.x or higher (VMware Horizon Client was renamed to Omnissa Horizon Client in version 8.15).

Chromebook support
  • A new version of the Chromebook extension has been released. Version 2.6.6.2 of the extension updates the format of the Chromebook extension version number shown in the console to x.x.x.x.

  • In some rare cases, a blank screen showing the text [object Object] was displayed on a frozen Chromebook device instead of the configured Freeze message. This issue is now fixed.

Device Details
  • Following the release of Secure Endpoint 10.0, the interface elements on a device's Device Details page may have been slower to load. This issue is now fixed, and the page now loads as expected.

Device groups
  • To help improve the performance of smart device groups, data fields that are not in use by any Absolute account have been removed from smart group filters. In addition, the following filter fields are no longer available for selection:
    • Application Resilience:

      • Became unhealthy
      • Events last 30 days
      • Failures last 30 days
      • Last updated
      • Status checked

    • Geolocation technology

      • Accuracy (meters)

    To view the complete list of filter fields that are currently available:

    1. Go to the Devices page and open an existing smart device group.
    2. Click the icon.
    3. Click the first field and scroll through the list of available fields.

Freeze
  • When you submit a Remove Freeze request, the system no longer checks to confirm that a valid product license is assigned to each device. Devices can now be unlicensed.

Geolocation
  • A new checkbox, Show IP locations, is now available on the Location History page in Device Details. If the timeline includes IP locations, you can clear this checkbox to show only Wi-Fi and OS locations. Note that IP locations are always included when you export the page.

History > Actions
  • Previously, on a device's History page, if you set the Start date and End date in the date range filter to the same date, the date's events may have failed to be displayed on the timeline. This issue is now fixed.

License management
  • Since the Devices page in the License management area does not support scheduling a report of the page, the (Schedule...) icon has been removed.

Playbooks
  • When deleting a custom policy group that is assigned a higher agent version than the Global Policy Group, the PER component on each moved device is now successfully downgraded to the lower version. Note that this action prompts a device to restart three times to complete the downgrade process.

Reports
  • Previously, when many values were specified in a single report filter, the filter may not have been displayed correctly if the report was saved as a new report. This issue is now fixed.

Secure Endpoint Agent
  • If you are signed in to a Windows device as an Administrator, you can now successfully run the Full agent or Core agent installer without extracting (unzipping) the installer zip file first. Note that if you are logged in as a Standard user, or you want to run the installer at the command line, you still need to extract the zip file. Learn more

Time zone support
  • When the Date & Time setting on a Windows device is set to one of the Co-ordinated Universal Time options, such as Co-ordinated Universal Time-08, the console now loads as expected upon login.

User profile
  • Your name is now always visible at the top of the Settings menu, regardless of the resolution of your display or the size of your device's screen.

Web Usage
  • Previously, clicking a link in the Webpage title column on the Web Usage (Trending) report failed to open its usage information if the webpage's URL contained a space character. This issue is now fixed.

The following features, enhancements, improvements, and fixes were introduced in Secure Endpoint 10.0.

Features and enhancements

Improvements and fixes

Feature/Area Details
Absolute APIs
Absolute Community
  • A new and enhanced Absolute Community is now available.

    Absolute Community is the unified hub for knowledge sharing across customers, partners, and Absolute. The new hub integrates the existing Knowledge Base and Support areas with the added features of discussion groups, webinars, and product updates. Go to this online space to collaborate with other members, find answers to product questions, and grow your knowledge.

Account settings
  • To work with the Script signature validation configuration, the following permissions are now required:

    • To view the configuration, the View permission for Reach Script is required.
    • To enable or disable the configuration, the Manage permission for Reach Script is required.

Agent management
  • After clicking the Copy ID button on the Absolute for Chromebooks extension dialog, a tooltip now confirms that the ID is copied.

API management
  • After clicking the Copy ID button on the Create API token dialog, a tooltip now confirms that the ID is copied.

Application Resilience
  • Application Resilience now supports Okta Verify. Learn more

  • For Microsoft BitLocker, the Location of the MBAM Status reporting service endpoint field is now optional to allow for instances where a reporting service endpoint is not set up in a BitLocker with standalone MBAM environment.

Bulk device actions
  • On the Upload File for Bulk Device Action dialog, you can no longer select IMEIs under File List Types.

Geolocation
  • When you select Show geofences in map view, any geofences that are associated with a location-based Action rule are now shown on the map and in the rule list.

  • A new method for detecting when public IP addresses are associated with a proxy or VPN has been introduced. As a result, IP locations are now more accurate.

  • When any of the following device location fields are used to filter a smart group, they are now re-evaluated whenever a location change occurs:

    • City

    • Country

    • State/Province

History > Actions
  • On the Actions page:

    • If an Action rule created the request, the Requester column now shows the name of the rule. For users with the View permission for Rules, click the linked name to view the rule details.
    • When filtering actions by Requester, you can now select Action rules.
History > Action Requests
  • In the Status details column, the value Pending request has been updated to Previous request pending to better convey the reason for the failure.
  • Previously, the Ready action status was not displayed in the progress chart. This status is now shown, and the clockwise order of the statuses is now Completed, Ready, Processing, Pending, Failed, and Canceled.
Reports
  • Since you can't add filters to the Web Usage (Trending) report, the icon has been removed from this report.

  • You can now successfully select a location in Antarctica in the Exported time zone field.
Rules
  • When creating or editing an Alert rule, you can now add multiple IP addresses for the following System information updated events when the condition is set to is or is not:

    • Local IP address
    • Public IP address
    • Local IPv6 address
    • Public IPv6 address
  • The On/Off toggle has been removed from the dialog that shows when you're creating, copying, or editing a rule. Now, click Save and activate to activate the rule.
User Management and permissions
  • If your user account is assigned to a single device group, you can now assign a user to All active devices when adding or editing users.

User profile
  • The following enhancements have been added to the Time zone field in the User profile dialog:

    • The value selected in the field now sets the default time zone for scheduling and exporting reports.
    • You can now select a new option, Set time zone automatically, which allows dates and times in the console to update automatically when you travel. Learn more
    • You can now successfully select a location in Antarctica.
Web Usage
  • On the Web Subscriptions report, the Time period filter has been redesigned so that only one time period can be selected.