Secure Endpoint 11.1 release notes

This topic describes the software updates included in Secure Endpoint 11.1, along with subsequent hotfixes and upgrades. In addition to the specific changes detailed here, each release also includes broader system enhancements designed to strengthen security, optimize performance, and enhance overall stability.

To view the software updates that apply to the Secure Endpoint Agent, see the Secure Endpoint Agent release notes - Version 11.1.

Depending on the Absolute product licenses associated with your account, and your Absolute data center, some of the following features, enhancements, and fixes may not be available to you.

Features and enhancements

The following features, enhancements, improvements, and fixes were introduced in the June release of Secure Endpoint 11.1.

Features at or nearing end-of-life

Improvements and fixes

Feature/Area Details
Absolute APIs
  • The following enhancements have been added to the Wipe resource:
    • In addition to Cryptographic Wipe requests, you can now use the POST /actions/requests/wipes endpoint to submit Firmware Wipe and Delete All Files wipe requests. Learn more
    • A wipeType parameter has been added to the response for the following endpoints:
      • POST /v3/actions/wipe/get-actions/{requestUid}

      • POST /v3/actions/wipe/get-actions

  • The permissions required to run endpoints in the Delete File resource have been updated. For example, the Perform permission for Wipe Device is now required to run the POST /v3/actions/requests/file-delete endpoint when wipeType is set to wipeAllUserFiles or wipeAllUserFilesAndOs. Learn more

    In a future release, the following wipeTypes will be deprecated from the Delete File resource: wipeAllUserFiles and wipeAllUserFilesAndOs. Use the POST /actions/requests/wipes endpoint to delete all files from a device.

AI Assistant
  • You can now cancel an in-progress request in AI Assistant to stop the generation of a response.

Applications
  • The Policies > Application page is now visible to users with the View permission for Policies, providing them with read-only access to application policy configurations and compliance rates. While these users can view policy details, all administrative actions, such as creating, editing, or duplicating policies, remain restricted to users with the Manage permission for Policies.

Application Resilience
  • Application Resilience policies now allow you to persist the following application versions:

    • BitLocker on Windows version 10.0.29591.x or higher

    • Version 5.00.9146.x or higher of Microsoft SCCM

    • Version 1.101.111.x or higher of Microsoft Intune Management Extension

    • Version 7.37.20907.x or higher of CrowdStrike Falcon

    • Version 11.5.x or higher of ManageEngine Desktop Central

    • Version 135.x or higher of Netskope

  • Application Resilience policies no longer support the following applications:

    • eClinicalWorks Plug-in

    • Ziften Zenith

Authentication
  • To improve the administrative experience, all authentication settings, including Single Sign-On (SSO) and Two-Factor Authentication, have been moved to the Account settings page under the Login & Security section. As a result, the Authentication area has been removed from Settings.

    For accounts with pan-tenant capabilities, the Authentication area has been renamed to Login & Security to better reflect its expanded scope.

  • When Single Sign-On is enabled for your account, you can now allow select users to log in to the Secure Endpoint Console using their Absolute username and password by adding them to the SSO exclusion list. Learn more

Dashboards
  • You can now include Serial number as a dimension in dashboard widgets that use Devices as a data source. This enhancement provides more granular control when analyzing device data within dashboards.

  • In widget filters, the Geolocation accuracy filter now supports the measurement system (Metric or Imperial) configured in your user profile. In addition, when you save or export a widget's data and include the Geolocation accuracy report column, the measurement unit is now shown in the column.

Device Compliance
  • Fixed an issue where a device's overall compliance status was incorrectly reported as Non-compliant in the Secure Endpoint Console, even when the associated Application Resilience policy was satisfied. This issue occurred because the application's compliance status, as reported by the Secure Endpoint Agent, failed to synchronize correctly with the device's compliance record.

Device Details
  • The following enhancements have been added to the History page:

    • The page now includes a Device usage events category, providing visibility into the following session state changes:

      • Device login
      • Device logout
      • Device unlocked
      • Device locked
      • Device slept
      • Device woke up
      • Device shutdown

      You can view these events individually or alongside other event types to better understand device activity and user behavior. Additionally, the total time in use for each day is now included in the timeline, and usage data can be exported directly from the History page.

    • Public IP Location updated events now show when the Location updated events filter is applied to the timeline instead of the System updated events filter.

    • When exporting the page, you can now:

      • Specify the time zone to apply to dates and times in the exported report

      • Select the event types to export. The following options are available: Export location events, Export device usage events, and Export all other events.

    • On the timeline, Run Playbook events now indicate how the playbook was initiated. One of the following values now shows next to the event name:

      • (device-initiated)

      • (console-initiated)

      • (automatic)

  • On the Location History page, IP locations now show on the map. A blurred marker indicates the approximate location, without connectors to other markers. Each marker’s tooltip shows:

    • City, State/Province, Country

    • <ISP provider> via IP Location

    • Date and time when the device moved to the location

    Learn more

Device groups
  • Previously, if you tried to create a smart device group from either of the following pages in the Devices area, a 404 Resource not found error occurred:

    • Missing Devices

    • Create Theft Report

    This issue is now fixed.

Hardware
  • For Windows devices, the Details > Hardware page now shows graphics card/GPU information on its own tab. Click the Video Controllers tab to view adapter details and resolution information for each adapter detected on the device. You can also add this information to a device report by adding Video controller report columns.

Playbooks (Absolute Rehydrate)
  • In the Run Playbook configuration dialog, the User initiated playbook toggle has been replaced by a checkbox, and its label has been changed to Device-initiated playbook.

  • When configuring a playbook, you can now use the Encryption > bitlocker recovery key variable in the BitLocker Recovery key field. Learn more

    Note that to use this variable, you need to configure the Secure Endpoint Agent to collect recovery keys from your Windows devices. You can enable this option after the Full Disk Encryption Status policy is activated in your policy groups. Learn more

Policies
  • Fixed an issue where the status of a Custom Data policy or a Required Applications policy failed to update automatically after the last enabled data point or application was unassigned. Previously, a green checkmark would persist in the License Status area of a policy group’s page until the page was manually refreshed.

User Management and permissions
  • On the Settings > User Management > Roles > Permissions page, the Device Analytics reports permission is now the Device Usage reports permission. This permission is required to view the Device Usage report and device usage information on the Dashboard.

Features and enhancements

The following features, enhancements, improvements, and fixes were introduced in Secure Endpoint 11.1.

Improvements and fixes

Feature/Area Details
Absolute APIs
  • The Application Resilience resource has been added to the Absolute API. This new resource allows you to export and import Application Resilience policies between policy groups or accounts. It includes the following endpoints:

  • The following enhancements have been added to the Geofence resource:

    • In addition to custom geofences, you can now use the POST endpoint to create location geofences and super fences.
    • You can now use the GET endpoint to query all geofences and super fences for your account.

    The Manage permission for Geofences is now required to use the POST and DELETE endpoints, while the View permission is required to use the GET endpoint. To add these permissions, you'll need to create a new API token. You can't add a permission to an existing API token.

  • In the Freeze resource, unfreeze codes now support:

    • Alphabetical characters (a-z, A-Z) in addition to numerals

    • Passcodes up to 20 characters in length

AI Assistant
  • AI Assistant now correctly filters geolocation details from its answers for users who do not have the required permissions. If a user requests restricted location data, AI Assistant provides a clear notification regarding the permission limitation instead of referencing the restricted fields.

  • You can now cancel an active prompt in AI Assistant while it is processing, allowing you to stop the current response and immediately start a new request. When a prompt is stopped, a Retry button becomes available to resubmit the request if needed.

  • Fixed an issue where AI Assistant did not display the total count of devices or records in its response when the user locale was set to Japanese.

Applications
  • The values that show in the Application Compliance > Status details column have been updated to ensure that they are consistent across Application Resilience and Required Application policies.

  • By default, the Application Compliance report is now sorted by application version in addition to policy name and device name.

  • Fixed an issue where the Application Compliance > Status updated column displayed an incorrect timestamp when an application's compliance status changed. The report now correctly reflects the date and time of the most recent status update.

  • Previously, when viewing application details for a device from the Application Summary page, and the error Check failed showed, the reasons for the failed health check may not have been displayed correctly. This issue is now fixed.

  • Fixed an issue where Application Resilience was unable to distinguish between a missing application and a health check failure. Health check errors are now correctly identified and reported.

Application Resilience
  • Application Resilience policies now allow you to persist the following application versions:

    • Version 26.x or higher of Teramind Agent

    • Version 25.11.x or higher of Citrix Workspace

    • Version 5.1.16.x or higher of Cisco Secure Client

    • Version 6.4.1.x or higher of Qualys Cloud Agent

    • Version 11.1.2.x or higher of Tenable Nessus Agent

    • Version 4.8.x or higher of Zscaler Client Connector

Authentication
  • The following login pages have been deprecated, meaning you can no longer use them to log in to the Secure Endpoint Console:

    • signin.absolute.com
    • signin.us.absolute.com

    A link to each data center's active login page is provided on the deprecated page.

Dashboards
  • The widget settings interface now features a grouped drop-down menu for Data source selection, replacing the previous button-based layout.

  • The Dark devices widget on the Asset management and At risk dashboards has been updated to display a single total count of dark devices over time. By removing the chart's Series dimension, the widget now provides a clearer high-level view of endpoint connectivity trends.

Device Details
  • To improve the accuracy of hardware reporting, the Secure Endpoint Console now uses a more comprehensive data field to populate the Processor number in a device's Details page. This update ensures that processor information is correctly displayed for a wider range of endpoint configurations.

  • In the Actions toolbar, device actions, such as Wipe and Run Script, are now grayed out in the following scenarios:

    • The device's assigned license doesn’t support the action

    • The action is not supported on the device's operating system

  • Event timestamps on the History tab and the Location History tab now include the user’s time zone.

  • Fixed an issue where the Primary Technology report column was left blank in an exported Location History report when IP location was the only available technology. The column now correctly displays IP Location, and all address report columns now show Not Available.

  • Fixed an issue where the History page in Device Details incorrectly displayed street addresses for IP location updated events. These events now display only the city, state or province, and country.

Endpoint Data Discovery
  • To improve usability and provide consistency with other areas of the console, the user interface of the following EDD-related pages has been updated:

    • Endpoint Data Discovery Rules page in the Policies area Learn more

    • Create EDD rules page accessed from the Endpoint Data Discovery Rules page Learn more

    • Configure Endpoint Data Discovery scan page in a policy group Learn more

    • EDD Summary page in a device's Device Details Learn more

  • The Personal Health Information (PHI) rule now uses the latest version of the National Institutes of Health Medical Subject Headings (MeSH) thesaurus, expanding coverage for medical and health terminology while reducing misclassifications. In addition, the rule now handles date values more efficiently and reliably, improving performance of EDD reports.

    For EDD policies that include the PHI rule, these updates will not be applied until the next scheduled EDD scan.

  • Previously, customers with a large device inventory may have experienced slow performance and potential timeouts when viewing the Devices with At-Risk Files in Cloud report. By optimizing the underlying query, this issue is now fixed.
Freeze
  • Unfreeze codes now support:

    • Alphabetical characters (a-z, A-Z) in addition to numerals

    • Passcodes up to 20 characters in length

  • RealVNC can no longer be used to gain remote access to a frozen device.

History > Events
  • The History > Events page has been updated to a new version that provides improved performance and a more streamlined viewing experience. You can now click any row on the page to open a sidebar that displays detailed property changes for that event, with changed properties prioritized at the top for easier review. This update also includes enhanced filtering and export capabilities, allowing for more granular visibility into system and device events.

License Management
  • For new accounts, an error message may have been displayed the first time you clicked License assignment settings. This issue is now fixed.

Playbooks (Absolute Rehydrate)
  • When configuring a policy group's Playbooks policy for the first time, the System restart setting is now preconfigured as follows:

    • Time window of 12 a.m. to 6 a.m. (local device time)

    • Device user can delay the restart once for 2 hours

    Learn more

  • The Initiated by field is now shown in the request overview of a Run Playbook request on the following console pages:

    • History > Actions

    • Actions tab in Device Details

  • If the agent version assigned to a policy group does not support a particular Playbook policy configuration, the configuration is now grayed out and the following message is displayed:

    A newer version of Absolute agent is available for additional features.

  • On the Playbook configuration page, when a user selected the Restart device automatically after updates option, but did not enable a time window or delayed restarts, the device restarted without warning the device user. This issue is now fixed. A restart notification is now displayed stating that a restart will begin in 10 minutes.

Reach Scripts
  • The following PowerShell scripts are now available in the Script library:

    • Intune connection management utility for Windows devices

    • Absolute recovery image deployment utility

Reports
  • Fixed an issue where Application Resilience and Application Compliance reports incorrectly displayed a status of Drive not encrypted for devices with suspended BitLocker protection. The reports now accurately reflect this state with the status detail BitLocker protection suspended.

  • When exporting a report that includes the Geolocation technology > Accuracy column, the measurement system (Imperial or Metric) configured in your user preferences is now shown in the exported report.

ServiceNow integration
  • The Absolute Connector for ServiceNow is now supported in the following data centers:

    • cc.in1.absolute.com

    • cc.uk1.absolute.com

    If your account is in one of these data centers and you use ServiceNow® IT Service Management (ITSM) to manage your devices, you can now set up an integration with Absolute Secure Endpoint using the Absolute Connector. This integration gives ServiceNow users real-time access to Absolute asset data for computers with out-of-date or inaccurate data in the CMDB. Users can also perform select Absolute security actions, such as Freeze and Run Script, directly from your ServiceNow instance. Learn more

Windows support
  • The Secure Endpoint Agent now supports Windows Server 2025 Datacenter Edition. Note that the following features aren't supported on this platform:

    • The detection of installed anti-malware applications

    • Device Wipe

    • Geolocation tracking

    • Playbooks (Absolute Rehydrate)