Release Notes
This page provides public release notes for StrongDM software features, updates, and fixes. You may search the release notes by version number, software type, and/or text. For older release notes not shown on this page, please see the Archive.
To learn about new features and major updates for each month, please see the Monthly Recap.
Versioning Information
For all software, StrongDM currently increments versions as follows:
- n.0-100.0 for each release (such as
32.97.0
,32.98.0
,32.99.0
,33.0.0
) - a.b.1 for patch releases (such as
32.97.1
) - Non-listed versions are internal (numbers missing from the sequence, such as
32.97.0
,32.98.0
,33.2.0
,33.3.0
)
Release Notes Atom Feeds
To see all releases (including those that have no public notes) see the Atom feed for each software:
- CLI
- Server (includes Admin UI changes starting in January 2024)
- StrongDM Desktop
- SDK - Go
- SDK - Java
- SDK - Python
- SDK - Ruby
- Terraform
Date | Software | Version | Description |
2024-11-12 | Server | 95.96.0 | This release allows users to be able to request multiple resources at the same time in the Admin UI. |
2024-11-12 | Terraform | 11.18.0 | This release of the StrongDM Terraform Provider adds support for unstable GCP Workforce Identity Federation based resources. |
2024-11-12 | CLI | 45.60.0 | This release adds two new filters applicable to filtering queries through the sdm audit CLI or the Queries vertical in the SDKs: policyID filters queries affected by the specified policy and authzDecision filters queries by authorization decision (either "allow" or "deny"). These filters do not match queries that were not associated with a policy authorization. |
2024-11-12 | Server | 95.90.0 | This release adds two new filters applicable to filtering queries through the sdm audit CLI or the Queries vertical in the SDKs: policyID filters queries affected by the specified policy and authzDecision filters queries by authorization decision (either "allow" or "deny"). These filters do not match queries that were not associated with a policy authorization. |
2024-11-09 | CLI | 45.57.0 | This release changes the name of "GCP" resources as displayed in the Admin UI and CLI from "GCP" to "GCP (Service Account)". This change only affects the displayed name and is intended to disambiguate this resource from the future introduction of other GCP resources using different authentication mechanisms. |
2024-11-09 | Server | 95.87.0 | This release changes the name of "GCP" resources as displayed in the Admin UI and CLI from "GCP" to "GCP (Service Account)". This change only affects the displayed name and is intended to disambiguate this resource from the future introduction of other GCP resources using different authentication mechanisms. |
2024-11-08 | CLI | 45.56.0 | This release allows customers engaged with us for GCP Workforce Identity Federation based resources to utilize the CLI, SDKs, and Terraform provider to create resources. |
2024-11-08 | Server | 95.84.0 | This release allows customers engaged with us for GCP Workforce Identity Federation based resources to utilize the CLI, SDKs, and Terraform provider to create resources. |
2024-11-08 | Java SDK | 11.18.0 | This release allows customers engaged with us for GCP Workforce Identity Federation based resources to utilize the CLI, SDKs, and Terraform provider to create resources. |
2024-11-08 | Python SDK | 11.18.0 | This release allows customers engaged with us for GCP Workforce Identity Federation based resources to utilize the CLI, SDKs, and Terraform provider to create resources. |
2024-11-08 | Go SDK | 11.18.0 | This release allows customers engaged with us for GCP Workforce Identity Federation based resources to utilize the CLI, SDKs, and Terraform provider to create resources. |
2024-11-08 | Ruby SDK | 11.18.0 | This release allows customers engaged with us for GCP Workforce Identity Federation based resources to utilize the CLI, SDKs, and Terraform provider to create resources. |
2024-11-08 | Server | 95.83.0 | This release adds a new column under the Admin UI Roles page called "Users", which displays how many users are assigned to the role. In addition, the "Managed By" column is always displayed, and results can be filtered by "Managed By" when the organization has a provisioner. |
2024-11-08 | Server | 95.80.0 | This release fixes an issue that may cause integration connected service disconnect calls to fail due to deleted StrongDM users. |
2024-11-07 | Server | 95.76.0 | This release fixes an occasional issue where the All Requests page would error loading. |
2024-11-06 | CLI | 45.54.0 | This release adds a new configuration value to the Active Directory secrets engine that can be changed using:

sdm admin secretengines update active_directory -id <eng-id> --do-not-validate-timestamps=true

The default value for this configuration option is false and is only used in case of active_directory . |
2024-11-06 | Server | 95.59.0 | This release adds a new configuration value to the Active Directory secrets engine that can be changed using:

sdm admin secretengines update active_directory -id <eng-id> --do-not-validate-timestamps=true

The default value for this configuration option is false and is only used in case of active_directory . |
2024-11-05 | Server | 95.56.0 | This release fixes an issue with redirection when switching accounts during workflow integration setup process. |
2024-11-05 | Server | 95.53.0 | This release improves the login state upon entering a bad password. The login screen no longer refreshes, resetting the login state. Instead, an error appears and the email is retained. |
2024-11-01 | Server | 95.32.0 | This release improves lazy loading for the Policy Editor. |
2024-11-01 | Server | 95.31.0 | This release fixes an issue where collapsing/expanding Policy Editor columns would increase column width unexpectedly. |
2024-10-31 | Server | 95.27.0 | This release fixes an issue where when a user navigates directly to /app/login and attempts to log in using a password, they are redirected to /auth/login . |
2024-10-31 | CLI | 45.44.0 | This release adds support for the AWS (Instance Profile) resource. The AWS (Instance Profile) resource type is generally available across the Admin UI, CLI, SDKs, and StrongDM Terraform Provider. The sdm aws cli commands support this resource type. |
2024-10-31 | Terraform | 11.17.0 | This release adds support for the AWS (Instance Profile) resource. The AWS (Instance Profile) resource type is generally available across the Admin UI, CLI, SDKs, and StrongDM Terraform Provider. The sdm aws cli commands support this resource type. |
2024-10-31 | Server | 95.22.0 | This release adds support for the AWS (Instance Profile) resource. The AWS (Instance Profile) resource type is generally available across the Admin UI, CLI, SDKs, and StrongDM Terraform Provider. The sdm aws cli commands support this resource type. |
2024-10-31 | Python SDK | 11.17.0 | This release adds support for the AWS (Instance Profile) resource. The AWS (Instance Profile) resource type is generally available across the Admin UI, CLI, SDKs, and StrongDM Terraform Provider. The sdm aws cli commands support this resource type. |
2024-10-31 | Go SDK | 11.17.0 | This release adds support for the AWS (Instance Profile) resource. The AWS (Instance Profile) resource type is generally available across the Admin UI, CLI, SDKs, and StrongDM Terraform Provider. The sdm aws cli commands support this resource type. |
2024-10-31 | Ruby SDK | 11.17.0 | This release adds support for the AWS (Instance Profile) resource. The AWS (Instance Profile) resource type is generally available across the Admin UI, CLI, SDKs, and StrongDM Terraform Provider. The sdm aws cli commands support this resource type. |
2024-10-30 | CLI | 45.43.0 | This release adds a new healthcheck service for fetching an organization's most recent healthchecks. |
2024-10-30 | Server | 95.19.0 | This release adds a new healthcheck service for fetching an organization's most recent healthchecks. |
2024-10-30 | Java SDK | 11.16.0 | This release adds a new healthcheck service for fetching an organization's most recent healthchecks. |
2024-10-30 | Python SDK | 11.16.0 | This release adds a new healthcheck service for fetching an organization's most recent healthchecks. |
2024-10-30 | Go SDK | 11.16.0 | This release adds a new healthcheck service for fetching an organization's most recent healthchecks. |
2024-10-30 | Ruby SDK | 11.16.0 | This release adds a new healthcheck service for fetching an organization's most recent healthchecks. |
2024-10-29 | Server | 95.3.0 | This release enables environment variables that set the HTTP/HTTPS proxy specifically for the StrongDM client. If SDM_HTTPS_PROXY is set, the client sets HTTPS_PROXY for itself. If SDM_HTTP_PROXY is set, the client sets HTTP_PROXY for itself. |
2024-10-28 | Server | 94.99.0 | This release fixes an issue where an update to organization IDs caused reports to break. |
2024-10-28 | Server | 94.94.0 | This release fixes an issue where changes to a resource's health state (and certain other properties, such as the subdomain of HTTP resources) may not be reflected immediately in the desktop app. |
2024-10-28 | Server | 94.93.0 | This release fixes the Admin UI Integrations table to update when an integration is disconnected. |
2024-10-28 | Server | 94.92.0 | This release fixes an issue where Log Stream may fail to upload large record sets to encrypted S3 buckets due to a lack of "kms:Decrypt" permission. |
2024-10-25 | Server | 94.83.0 | This release updates the credential retrieval modal to close after 30 minutes or when the password expires. |
2024-10-17 | CLI | 45.35.0 | This release updates Kubernetes drivers to support version 1.31 so that SSH session recordings are properly supported. |
2024-10-17 | Server | 94.64.0 | This release makes all actionable buttons under the Identity Aliases tab within the Account Details page of the Admin UI disabled and hidden while logged in with an Auditor account. |
2024-10-14 | Server | 94.40.0 | This release fixes an issue where multi-select on table rows incorrectly updated the selected row count. |
2024-10-14 | Server | 94.38.0 | This release fixes layout inconsistencies and a scroll issue with policy logs. |
2024-10-14 | CLI | 45.31.0 | This release makes the SSHPassword resource type available. |
2024-10-14 | Java SDK | 11.15.0 | This release makes the SSHPassword resource type available. |
2024-10-14 | Terraform | 11.15.0 | This release makes the SSHPassword resource type available. |
2024-10-14 | Python SDK | 11.15.0 | This release makes the SSHPassword resource type available. |
2024-10-14 | Ruby SDK | 11.15.0 | This release makes the SSHPassword resource type available. |
2024-10-14 | Go SDK | 11.15.0 | This release makes the SSHPassword resource type available. |
2024-10-11 | Server | 94.32.0 | This release fixes a bug where an account grant could be considered revoked by an access request when it expires naturally. |
2024-10-08 | Server | 94.22.0 | This release updates resource configuration to prohibit @ and = characters in the names of new resources when they are created. |
2024-10-08 | Server | 94.18.0 | This release fixes an issue to allow for correct email rerouting to logs/rdp-replays . |
2024-10-07 | CLI | 45.22.0 | This release adds the ImpersonationUser and ImpersonationGroups fields to the sharedkernel.Capture model, allowing it to be auditable via sdm audit k8s and in query logs. These fields are populated when the client performs user and group impersonation in Kubernetes (that is, --as user --as-group group ). |
2024-10-07 | Java SDK | 11.14.0 | This release adds the ImpersonationUser and ImpersonationGroups fields to the sharedkernel.Capture model, allowing it to be auditable via sdm audit k8s and in query logs. These fields are populated when the client performs user and group impersonation in Kubernetes (that is, --as user --as-group group ). |
2024-10-07 | Ruby SDK | 11.14.0 | This release adds the ImpersonationUser and ImpersonationGroups fields to the sharedkernel.Capture model, allowing it to be auditable via sdm audit k8s and in query logs. These fields are populated when the client performs user and group impersonation in Kubernetes (that is, --as user --as-group group ). |
2024-10-07 | Python SDK | 11.14.0 | This release adds the ImpersonationUser and ImpersonationGroups fields to the sharedkernel.Capture model, allowing it to be auditable via sdm audit k8s and in query logs. These fields are populated when the client performs user and group impersonation in Kubernetes (that is, --as user --as-group group ). |
2024-10-07 | Go SDK | 11.14.0 | This release adds the ImpersonationUser and ImpersonationGroups fields to the sharedkernel.Capture model, allowing it to be auditable via sdm audit k8s and in query logs. These fields are populated when the client performs user and group impersonation in Kubernetes (that is, --as user --as-group group ). |
2024-10-04 | CLI | 45.20.0 | This release updates the sdm admin users add --csv CLI command help text to include the necessary tags column. |
2024-10-04 | Server | 94.8.0 | This release makes the email Identity Set unable to be edited. |
2024-10-03 | Server | 94.6.0 | This release fixes a 404 error that could be encountered when connecting the StrongDM app for Slack to a new workspace. |
2024-10-03 | Terraform | 11.14.1 | This release updates the Terraform Provider documentation to include the API host . |
2024-10-03 | CLI | 45.15.0 | This release enables users to be logged in automatically to Couchbase Web UI resources, so users no longer have to log in with fake credentials. |
2024-10-03 | Server | 94.0.0 | This PR adds constants for the API host across different control planes. |
2024-10-03 | Java SDK | 11.13.0 | This PR adds constants for the API host across different control planes. |
2024-10-03 | Terraform | 11.14.0 | This PR adds constants for the API host across different control planes. |
2024-10-03 | Python SDK | 11.13.0 | This PR adds constants for the API host across different control planes. |
2024-10-03 | Go SDK | 11.13.0 | This PR adds constants for the API host across different control planes. |
2024-10-03 | Ruby SDK | 11.13.0 | This PR adds constants for the API host across different control planes. |
2024-10-03 | Server | 93.99.0 | This release fixes an issue where the "Enroll Here" button that appears in the desktop app when the user attempting to log in is not enrolled in Okta MFA was not clickable. |
2024-10-02 | Server | 93.92.0 | This release ensures that only nodes that pass healthcheck for a secret store are taken into account when contacting a secret store. |
2024-10-01 | Terraform | 11.13.1 | This release fixes an issue that prevented custom timeouts from being respected. |
2024-10-01 | Terraform | 11.13.0 | This release adds support for custom timeouts for all operations on all resources in the StrongDM Terraform provider. |
2024-10-01 | Server | 93.87.0 | This release fixes an issue where deleting an approval workflow could cause pending requests and access workflows bound to that approval workflow to be unchangeable. |
2024-09-30 | Terraform | 11.12.1 | Terraform data sources can now filter by more than one tag. Previously a bug prevented this from working properly. |
2024-09-27 | Server | 93.74.0 | This release gives database-admin users read-only access to gateways and relays. |
2024-09-27 | Server | 93.72.0 | This release is the one of the few to enable support for email pass through Identity Sets, where all Identity Aliases in the set will be the user's corresponding email address or last name. This release adds Email Identity Alias creation and updates whenever a new account is created or updated. Deletion of Identity Aliases upon account deletion was already supported. The Identity Alias creation and update will only apply to user and service account types. For users, the Identity Alias username is the user's email address. For service accounts, the Identity Alias username is the last name, which is the nickname for the service account. |
2024-09-27 | Server | 93.69.0 | This release fixes an issue so that an error page is no longer shown momentarily while the user is logged out of the Admin UI for stale or invalid credentials. |
2024-09-26 | Server | 93.64.0 | This release cleared the name form value for the Add Role form on submission. |
2024-09-25 | CLI | 45.4.0 | With the release of time in context attributes, users should expect to see policies being reevaluated, approximately once every minute, even after the initial "Allow" for "connect" actions on Postgres resources. If no time attributes are accessed by relevant policies, and no updates are made to the policies, the evaluation should continue to evaluate to "Allow." If the relevant policies make use of the time attributes, however, reevaluating relevant policies may result in "Deny," in which case, the client will sever the connection. |
2024-09-25 | Server | 93.59.0 | With the release of time in context attributes, users should expect to see policies being reevaluated, approximately once every minute, even after the initial "Allow" for "connect" actions on Postgres resources. If no time attributes are accessed by relevant policies, and no updates are made to the policies, the evaluation should continue to evaluate to "Allow." If the relevant policies make use of the time attributes, however, reevaluating relevant policies may result in "Deny," in which case, the client will sever the connection. |
2024-09-25 | Server | 93.58.0 | This release fixes an issue where SAML users could not finish logging in when the email they entered did not match the capitalization of the email in the system. |
2024-09-24 | Desktop App | 21.87.0 | This release adds an alert on the desktop app when another user on the machine is currently running the desktop app. The second user will have to quit the app and wait until the other desktop app instance is closed in order to continue. This release also fixes an issue where clicking the dock icon in macOS showed the desktop app's Resource Center window. |
2024-09-23 | CLI | 44.97.0 | This release adds a new context.utcNow.timestamp attribute for context-based policy allowing policies to be written against properties of the time at which authorization is performed. The value of this attribute is the current time (in UTC) as a Cedar datetime value. |
2024-09-23 | Server | 93.46.0 | This release adds a new context.utcNow.timestamp attribute for context-based policy allowing policies to be written against properties of the time at which authorization is performed. The value of this attribute is the current time (in UTC) as a Cedar datetime value. |
2024-09-19 | CLI | 44.95.0 | This release adds new temporal attributes for context-based policy, allowing policies to be written against properties of the current time (in UTC) when authorization is performed. The new context attributes include context.utcNow.dayOfWeek (a number representing the current day of week from 1-7, which is Sun-Sat), context.utcNow.day (a number representing the current day of the month, such as 31), context.utcNow.month (a number representing the current month from 1-12, which is Jan-Dec), and context.utcNow.year (a number representing the current four digit year, such as 2024). |
2024-09-19 | Server | 93.33.0 | This release adds new temporal attributes for context-based policy, allowing policies to be written against properties of the current time (in UTC) when authorization is performed. The new context attributes include context.utcNow.dayOfWeek (a number representing the current day of week from 1-7, which is Sun-Sat), context.utcNow.day (a number representing the current day of the month, such as 31), context.utcNow.month (a number representing the current month from 1-12, which is Jan-Dec), and context.utcNow.year (a number representing the current four digit year, such as 2024). |
2024-09-18 | Server | 93.15.0 | This release enables support for email to pass through Identity Sets, so that all Identity Aliases in the Identity Set are the user's corresponding email address. This release also adds the new read-only email Identity Set for new organizations. Existing orgs will be backfilled at a later release. |
2024-09-17 | Server | 93.5.0 | This release updates the StrongDM Admin UI with a new navigation menu and updates both the Admin UI and desktop app with a refreshed layout, colors, and styling. |
2024-09-16 | Server | 92.97.0 | This release adds a new organization setting, Enforce Single Session. This setting allows organization admins to restrict concurrent sessions for logged in users to a single session for the StrongDM Admin UI and a single session for desktop. With this setting enabled, if a user who is logged in to the Admin UI on one machine (or browser) logs in on another machine (or browser), the first session is revoked and the user is logged out of that session. The second session will still be preserved. |
2024-09-16 | Java SDK | 11.10.1 | This release adds a new organization setting, Enforce Single Session. This setting allows organization admins to restrict concurrent sessions for logged in users to a single session for the StrongDM Admin UI and a single session for desktop. With this setting enabled, if a user who is logged in to the Admin UI on one machine (or browser) logs in on another machine (or browser), the first session is revoked and the user is logged out of that session. The second session will still be preserved. |
2024-09-16 | Python SDK | 11.10.1 | This release adds a new organization setting, Enforce Single Session. This setting allows organization admins to restrict concurrent sessions for logged in users to a single session for the StrongDM Admin UI and a single session for desktop. With this setting enabled, if a user who is logged in to the Admin UI on one machine (or browser) logs in on another machine (or browser), the first session is revoked and the user is logged out of that session. The second session will still be preserved. |
2024-09-16 | Ruby SDK | 11.10.1 | This release adds a new organization setting, Enforce Single Session. This setting allows organization admins to restrict concurrent sessions for logged in users to a single session for the StrongDM Admin UI and a single session for desktop. With this setting enabled, if a user who is logged in to the Admin UI on one machine (or browser) logs in on another machine (or browser), the first session is revoked and the user is logged out of that session. The second session will still be preserved. |
2024-09-16 | Go SDK | 11.10.1 | This release adds a new organization setting, Enforce Single Session. This setting allows organization admins to restrict concurrent sessions for logged in users to a single session for the StrongDM Admin UI and a single session for desktop. With this setting enabled, if a user who is logged in to the Admin UI on one machine (or browser) logs in on another machine (or browser), the first session is revoked and the user is logged out of that session. The second session will still be preserved. |
2024-09-13 | CLI | 44.75.0 | This release adds support to the Account update API and SDKs for setting the password of a user account. This ability to set a user password is only permitted by new API keys that have been explicitly assigned a new Password Set permission. |
2024-09-11 | Server | 92.79.0 | This release adds support to the Account update API and SDKs for setting the password of a user account. This ability to set a user password is only permitted by new API keys that have been explicitly assigned a new Password Set permission. |
2024-09-11 | Java SDK | 11.10.0 | This release adds support to the Account update API and SDKs for setting the password of a user account. This ability to set a user password is only permitted by new API keys that have been explicitly assigned a new Password Set permission. |
2024-09-11 | Python SDK | 11.10.0 | This release adds support to the Account update API and SDKs for setting the password of a user account. This ability to set a user password is only permitted by new API keys that have been explicitly assigned a new Password Set permission. |
2024-09-11 | Ruby SDK | 11.10.0 | This release adds support to the Account update API and SDKs for setting the password of a user account. This ability to set a user password is only permitted by new API keys that have been explicitly assigned a new Password Set permission. |
2024-09-11 | Go SDK | 11.10.0 | This release adds support to the Account update API and SDKs for setting the password of a user account. This ability to set a user password is only permitted by new API keys that have been explicitly assigned a new Password Set permission. |
2024-09-11 | CLI | 44.65.0 | This release adds support for Couchbase resources. The Couchbase and Couchbase (WebUI) resource types are now generally available across the Admin UI, CLI, SDKs, and StrongDM Terraform Provider. |
2024-09-11 | Terraform | 11.9.0 | This release adds support for Couchbase resources. The Couchbase and Couchbase (WebUI) resource types are now generally available across the Admin UI, CLI, SDKs, and StrongDM Terraform Provider. |
2024-09-11 | Server | 92.75.0 | This release adds support for Couchbase resources. The Couchbase and Couchbase (WebUI) resource types are now generally available across the Admin UI, CLI, SDKs, and StrongDM Terraform Provider. |
2024-09-11 | Java SDK | 11.9.0 | This release adds support for Couchbase resources. The Couchbase and Couchbase (WebUI) resource types are now generally available across the Admin UI, CLI, SDKs, and StrongDM Terraform Provider. |
2024-09-11 | Python SDK | 11.9.0 | This release adds support for Couchbase resources. The Couchbase and Couchbase (WebUI) resource types are now generally available across the Admin UI, CLI, SDKs, and StrongDM Terraform Provider. |
2024-09-11 | Go SDK | 11.9.0 | This release adds support for Couchbase resources. The Couchbase and Couchbase (WebUI) resource types are now generally available across the Admin UI, CLI, SDKs, and StrongDM Terraform Provider. |
2024-09-11 | Ruby SDK | 11.9.0 | This release adds support for Couchbase resources. The Couchbase and Couchbase (WebUI) resource types are now generally available across the Admin UI, CLI, SDKs, and StrongDM Terraform Provider. |
2024-09-09 | CLI | 44.60.0 | This release makes two changes have been made to the JSON format of the authorization information that is included in the authz field in query event logs. The "policy" field has been removed in favor of a "policyId" field. The type has also changed from an int to a string, which is the appropriate Cedar JSON format for policy IDs. The keys of the "position" objects have changed to lower case from Pascal case. |
2024-09-09 | Server | 92.66.0 | This release makes two changes have been made to the JSON format of the authorization information that is included in the authz field in query event logs. The "policy" field has been removed in favor of a "policyId" field. The type has also changed from an int to a string, which is the appropriate Cedar JSON format for policy IDs. The keys of the "position" objects have changed to lower case from Pascal case. |
2024-09-09 | Server | 92.65.0 | This release adds the support_login_user filter for listing activities via the sdm audit activities --filter command. |
2024-09-03 | Server | 92.46.0 | This release adds support for selecting LDAP schema by setting the schema query param in the URL. By default it is ad (Active Directory) but can be set to openldap by providing the schema query param (ldaps://127.0.0.1?schema=openldap ). |
2024-09-03 | CLI | 44.55.0 | This release updates the GCP Secret Manager to store paths relative to secret manager root path (/projects/<project-id>). It also normalizes the names of managed secrets into the secret path by changing '/' characters into double underscore characters. |
2024-09-03 | Server | 92.43.0 | This release updates the GCP Secret Manager to store paths relative to secret manager root path (/projects/<project-id>). It also normalizes the names of managed secrets into the secret path by changing '/' characters into double underscore characters. |
2024-08-29 | CLI | 44.48.0 | This release fixes a rare memory leak in the gateway that can occur when connections are forwarded through a relay and there are repeated egress connection failures to one or more resources on the relay. |
2024-08-28 | Server | 92.22.0 | This release fixes an issue with Slack access requests where duplicate resources made granting access impossible. |
2024-08-27 | CLI | 44.44.0 | This release fixes potential interoperability issues between the StrongDM CLI and some third-party vendor firewall and packet filtering applications due to a recent change in Go to enable a experimental post-quantum key exchange mechanism in TLS negotiations by default. This mechanism has been temporarily disabled until such issues are resolved. |
2024-08-27 | Server | 92.17.0 | This release fixes potential interoperability issues between the StrongDM CLI and some third-party vendor firewall and packet filtering applications due to a recent change in Go to enable a experimental post-quantum key exchange mechanism in TLS negotiations by default. This mechanism has been temporarily disabled until such issues are resolved. |
2024-08-27 | Desktop App | 21.83.0 | This release updates the desktop app with new icons and colors, enhances the user experience around layout and filters, and adds tabs for navigation. |
2024-08-26 | CLI | 44.42.0 | This change updates the output of sdm audit access-requests to add requester name, reason, duration, and account grant(s) information to the output. |
2024-08-24 | Server | 92.9.0 | This change updates the output of sdm audit access-requests to add requester name, reason, duration, and account grant(s) information to the output. |
2024-08-24 | Java SDK | 11.8.0 | This change updates the output of sdm audit access-requests to add requester name, reason, duration, and account grant(s) information to the output. |
2024-08-24 | Ruby SDK | 11.8.0 | This change updates the output of sdm audit access-requests to add requester name, reason, duration, and account grant(s) information to the output. |
2024-08-24 | Go SDK | 11.8.0 | This change updates the output of sdm audit access-requests to add requester name, reason, duration, and account grant(s) information to the output. |
2024-08-24 | Python SDK | 11.8.0 | This change updates the output of sdm audit access-requests to add requester name, reason, duration, and account grant(s) information to the output. |
2024-08-23 | Server | 92.4.0 | This release fixes an issue in the Policy Editor where incorrect completion suggestions may be provided based on other content in the policy. |
2024-08-22 | Server | 92.1.0 | This change adds a new "PingID (OIDC)" SSO provider. |
2024-08-21 | Server | 91.98.0 | This release resolves an issue where some resources were not able to be updated due to a unique validation on a field that was not required or visible to the user. |
2024-08-20 | Server | 91.96.0 | Policy-based action control for PostgreSQL databases is now supported for Aurora PostgreSQL, Cockroach, GreenPlum, and RDS PostgreSQL IAM resources. |
2024-08-14 | Server | 91.73.0 | This release adds a few activity verbs involving workflows to SDKs for completeness. These verbs are no longer used currently, but in audit trails, can still be requested. The verbs in question: ActivityVerbDeprecatedWorkflowResourceAssigned , ActivityVerbDeprecatedWorkflowResourceUnassigned , ActivityVerbDeprecatedWorkflowResourceMultipleAssigned , ActivityVerbDeprecatedWorkflowResourceMultipleUnassigned , ActivityVerbDeprecatedWorkflowApproversUpdated , ActivityVerbDeprecatedWorkflowAutoGrantUpdated , ActivityVerbDeprecatedWorkflowApprovalCriteriaUpdated |
2024-08-14 | Terraform | 11.7.0 | This release adds a few activity verbs involving workflows to SDKs for completeness. These verbs are no longer used currently, but in audit trails, can still be requested. The verbs in question: ActivityVerbDeprecatedWorkflowResourceAssigned , ActivityVerbDeprecatedWorkflowResourceUnassigned , ActivityVerbDeprecatedWorkflowResourceMultipleAssigned , ActivityVerbDeprecatedWorkflowResourceMultipleUnassigned , ActivityVerbDeprecatedWorkflowApproversUpdated , ActivityVerbDeprecatedWorkflowAutoGrantUpdated , ActivityVerbDeprecatedWorkflowApprovalCriteriaUpdated |
2024-08-14 | Java SDK | 11.7.0 | This release adds a few activity verbs involving workflows to SDKs for completeness. These verbs are no longer used currently, but in audit trails, can still be requested. The verbs in question: ActivityVerbDeprecatedWorkflowResourceAssigned , ActivityVerbDeprecatedWorkflowResourceUnassigned , ActivityVerbDeprecatedWorkflowResourceMultipleAssigned , ActivityVerbDeprecatedWorkflowResourceMultipleUnassigned , ActivityVerbDeprecatedWorkflowApproversUpdated , ActivityVerbDeprecatedWorkflowAutoGrantUpdated , ActivityVerbDeprecatedWorkflowApprovalCriteriaUpdated |
2024-08-14 | Python SDK | 11.7.0 | This release adds a few activity verbs involving workflows to SDKs for completeness. These verbs are no longer used currently, but in audit trails, can still be requested. The verbs in question: ActivityVerbDeprecatedWorkflowResourceAssigned , ActivityVerbDeprecatedWorkflowResourceUnassigned , ActivityVerbDeprecatedWorkflowResourceMultipleAssigned , ActivityVerbDeprecatedWorkflowResourceMultipleUnassigned , ActivityVerbDeprecatedWorkflowApproversUpdated , ActivityVerbDeprecatedWorkflowAutoGrantUpdated , ActivityVerbDeprecatedWorkflowApprovalCriteriaUpdated |
2024-08-14 | Go SDK | 11.7.0 | This release adds a few activity verbs involving workflows to SDKs for completeness. These verbs are no longer used currently, but in audit trails, can still be requested. The verbs in question: ActivityVerbDeprecatedWorkflowResourceAssigned , ActivityVerbDeprecatedWorkflowResourceUnassigned , ActivityVerbDeprecatedWorkflowResourceMultipleAssigned , ActivityVerbDeprecatedWorkflowResourceMultipleUnassigned , ActivityVerbDeprecatedWorkflowApproversUpdated , ActivityVerbDeprecatedWorkflowAutoGrantUpdated , ActivityVerbDeprecatedWorkflowApprovalCriteriaUpdated |
2024-08-14 | Ruby SDK | 11.7.0 | This release adds a few activity verbs involving workflows to SDKs for completeness. These verbs are no longer used currently, but in audit trails, can still be requested. The verbs in question: ActivityVerbDeprecatedWorkflowResourceAssigned , ActivityVerbDeprecatedWorkflowResourceUnassigned , ActivityVerbDeprecatedWorkflowResourceMultipleAssigned , ActivityVerbDeprecatedWorkflowResourceMultipleUnassigned , ActivityVerbDeprecatedWorkflowApproversUpdated , ActivityVerbDeprecatedWorkflowAutoGrantUpdated , ActivityVerbDeprecatedWorkflowApprovalCriteriaUpdated |
2024-08-13 | Java SDK | 11.6.1 | This release updates javadocs for the Java SDK. |
2024-08-08 | Server | 91.50.0 | This release causes dead relays or gateways that are pruned (30 days old without a heartbeat) to also emit an activity log. |
2024-08-07 | Server | 91.48.0 | This release adds policy fields AuthzJSON and Target to the queries API. |
2024-08-07 | Python SDK | 11.5.1 | This release adds policy fields AuthzJSON and Target to the queries API. |
2024-08-07 | Ruby SDK | 11.5.1 | This release adds policy fields AuthzJSON and Target to the queries API. |
2024-08-07 | Go SDK | 11.5.1 | This release adds policy fields AuthzJSON and Target to the queries API. |
2024-08-06 | CLI | 44.28.0 | This release adds the --permissions-help flag to the admin tokens add command to show all available permissions and their descriptions. sdm admin tokens add --permissions-help will list all of the allowed permissions. |
2024-08-06 | Server | 91.45.0 | This release adds the --permissions-help flag to the admin tokens add command to show all available permissions and their descriptions. sdm admin tokens add --permissions-help will list all of the allowed permissions. |
2024-08-06 | CLI | 44.27.0 | This release deprecates the KubernetesBasicAuth and AKSBasicAuth resource types. |
2024-08-06 | Server | 91.44.0 | This release deprecates the KubernetesBasicAuth and AKSBasicAuth resource types. |
2024-08-06 | Terraform | 11.4.0 | This release deprecates the KubernetesBasicAuth and AKSBasicAuth resource types. |
2024-08-06 | Python SDK | 11.4.0 | This release deprecates the KubernetesBasicAuth and AKSBasicAuth resource types. |
2024-08-06 | Ruby SDK | 11.4.0 | This release deprecates the KubernetesBasicAuth and AKSBasicAuth resource types. |
2024-08-06 | Go SDK | 11.4.0 | This release deprecates the KubernetesBasicAuth and AKSBasicAuth resource types. |
2024-08-05 | CLI | 44.25.0 | This release adds sdm audit policies command to the CLI to list policies existing at a given timestamp. |
2024-08-02 | CLI | 44.23.0 | This release adds sdm admin policies commands to the CLI to manage policies. It provides create, update, delete and list operations for policies. |
2024-08-01 | Server | 91.29.0 | This release resolves a bug introduced in 91.24.0 where users, when unauthenticated via a session timeout, could enter an error page without the ability to log out. |
2024-08-01 | Server | 91.28.0 | This adds support for the Policies API. |
2024-08-01 | Java SDK | 11.3.0 | This adds support for the Policies API. |
2024-08-01 | Python SDK | 11.3.0 | This adds support for the Policies API. |
2024-08-01 | Go SDK | 11.3.0 | This adds support for the Policies API. |
2024-08-01 | Ruby SDK | 11.3.0 | This adds support for the Policies API. |
2024-08-01 | Server | 91.26.0 | This release updates the CrowdStrike integration to use the full set of network interfaces collected from the CrowdStrike API to detect the device agent corresponding to a given StrongDM client. Previously, devices with multiple network interfaces could potentially have been unable to identify a device trust score. |
2024-07-29 | Server | 90.98.0 | Policy-Based Action Control (PBAC) is now generally available to all Enterprise customers. Fine-grained authorization is now performed against all PostgreSQL database actions and the Policy Editor in the Admin UI has been enhanced to support creating policies to authorize these actions. |
2024-07-29 | CLI | 44.4.0 | This release adds support for the VAULT_TOKEN_RENEW_BEHAVIOR environment variable. Supported values are STOP_ON_ERROR , which, if the token renewal fails it will stop renewal process, and login will be attempted on the next healthcheck attempt; and DISABLED , which will disable token renewal, and login will happen again after the current token is expired. |
2024-07-26 | Server | 90.88.0 | This change updates the format of some metadata in various emails sent from the StrongDM control plane. |
2024-07-25 | Desktop App | 21.80.0 | This release updates the desktop app to show the following menu items when the dock icon (on macOS) or the tray icon (for Windows) is right-clicked: Open app.strongdm.com, which opens the Admin UI in the web browser; and Connect All, which connects to all assigned resources and is only visible when authenticated. In addition, this release fixes the main desktop app menu options in macOS to be About StrongDM and Quit StrongDM instead of About desktop and Quit desktop. The main desktop app menu also adds the Log Out option when authenticated and Log In when unauthenticated. |
2024-07-23 | Server | 90.71.0 | This release ensures there will be no more friction for updating resources if your resource has Strong Vault as its default secret store and you have disallowed credentials to be stored with StrongDM. |
2024-07-23 | CLI | 43.94.0 | This release fixes a bug in the sdm audit permissions CLI command where a filter specified by the --filter parameter was being ignored, causing results not to be filtered. |
2024-07-23 | Server | 90.69.0 | This release fixes a bug with explicit routing enabled in strict or exclusive enforcement mode, where relays may be incorrectly reported as "isolated" in the Admin UI. |
2024-07-23 | Server | 90.61.0 | This release fixes a connection error for Mongo legacy resource types when used with older gateways, reverting to continue using an old behavior mode. |
2024-07-22 | Server | 90.56.0 | This change fixes a presentation bug that caused shrunken dashboards in the Reports Library. |
2024-07-22 | CLI | 43.91.0 | This release resolves an incompatibility using the RDS PostgreSQL (IAM) resource type with policies, introduced in version 43.84.0. |
2024-07-19 | Server | 90.53.0 | When creating a website resource, the subdomain field will provide an error about max length when longer than 256 characters. |
2024-07-19 | CLI | 43.88.0 | This change augments sdm doctor -v and the desktop app's diagnostic output to include short descriptions of some common problems (for example, inability to reach gateways or api.strongdm.com). |
2024-07-19 | Server | 90.47.0 | This release adds an example to the Log Stream page of the Admin UI, indicating how to set up CMK usage. |
2024-07-18 | Server | 90.41.0 | This release adjusts StrongDM's syncing logic with CrowdStrike to prevent delays in updates to retrieved device trust scores when invalid API tokens are provided to StrongDM. |
2024-07-18 | Server | 90.40.0 | This release fixes an issue where an idle timeout duration greater than 24 days caused users to log out immediately. |
2024-07-17 | Java SDK | 11.1.0 | This release updates which Mongo drivers are unstable per their legacy naming. |
2024-07-17 | Terraform | 11.1.0 | This release updates which Mongo drivers are unstable per their legacy naming. |
2024-07-17 | Python SDK | 11.1.0 | This release updates which Mongo drivers are unstable per their legacy naming. |
2024-07-17 | Ruby SDK | 11.1.0 | This release updates which Mongo drivers are unstable per their legacy naming. |
2024-07-17 | Go SDK | 11.1.0 | This release updates which Mongo drivers are unstable per their legacy naming. |
2024-07-16 | Server | 90.32.0 | This release addresses the following third party CVEs: CVE-2024-36138,CVE-2024-22020,CVE-2024-22018,CVE-2024-36137,CVE-2024-37372 |
2024-07-16 | Server | 90.30.0 | This change adds support for ALTER EXTENSION statements as parsed SQL actions |
2024-07-15 | CLI | 43.73.0 | Fix filters help responses for approval workflows commands |
2024-07-12 | Server | 90.19.0 | This release adds the egressNodeID field to log stream query outputs, reflecting the final node which processed a query and sent it directly to a resource. |
2024-07-12 | Server | 90.17.0 | This release adds Okta Verify as a supported MFA provider. |
2024-07-11 | CLI | 43.69.0 | This release removes the outdated flags --connect-to-replica and --replica-set from the sdm admin resources create mongo command. |
2024-07-11 | Terraform | 11.0.0 | This release removes some deprecated fields from Mongo resource types. |
2024-07-11 | Java SDK | 11.0.0 | This release removes some deprecated fields from Mongo resource types. |
2024-07-11 | Python SDK | 11.0.0 | This release removes some deprecated fields from Mongo resource types. |
2024-07-11 | Go SDK | 11.0.0 | This release removes some deprecated fields from Mongo resource types. |
2024-07-11 | Ruby SDK | 11.0.0 | This release removes some deprecated fields from Mongo resource types. |
2024-07-10 | Server | 90.7.0 | This release addresses the following third party CVEs: CVE-2024-6104, CVE-2024-6257 This release addresses the following third party CVEs: CVE-1984-12345,CVE-1984-12346 |
2024-07-10 | CLI | 43.65.0 | Add loopback range to the organization history API |
2024-07-10 | Java SDK | 9.7.0 | Add loopback range to the organization history API |
2024-07-10 | Python SDK | 9.7.0 | Add loopback range to the organization history API |
2024-07-10 | Ruby SDK | 9.7.0 | Add loopback range to the organization history API |
2024-07-10 | Go SDK | 9.7.0 | Add loopback range to the organization history API |
2024-07-10 | CLI | 43.63.0 | Many CLI commands currently do not have validation against incorrect number of arguments being provided. This release adds those validations. |
2024-07-09 | Server | 89.99.0 | In the event an access request has more than one resource associated with it, typically through an approval workflow associated with a policy, all resources will now be listed in the access request details. |
2024-07-08 | Server | 89.92.0 | Fixed issue in the Admin UI where resources could not be created if there are no identity sets |
2024-07-05 | CLI | 43.58.0 | On Linux, "sdm install" has a new -nostart flag that can be used when users want to complete the installation without actually starting the service. |
2024-07-03 | Terraform | 10.5.0 | This change adds a resource type for SSH password authentication. |
2024-07-03 | Java SDK | 9.6.0 | This change adds a resource type for SSH password authentication. |
2024-07-03 | Ruby SDK | 9.6.0 | This change adds a resource type for SSH password authentication. |
2024-07-03 | Python SDK | 9.6.0 | This change adds a resource type for SSH password authentication. |
2024-07-03 | Go SDK | 9.6.0 | This change adds a resource type for SSH password authentication. |
2024-07-02 | Server | 89.81.0 | This release allows the Port Override field to be set when creating or updating a cloud resource, as with other resources. Previously this field was only visible and editable for cloud resources through the CLI or SDKs. |
2024-07-01 | CLI | 43.53.0 | This release removes the "alterUser" SQL action, treating such calls as aliases for ALTER ROLE. |
2024-07-01 | Server | 89.74.0 | This release removes the "alterUser" SQL action, treating such calls as aliases for ALTER ROLE. |
2024-07-01 | Desktop App | 21.76.0 | This release updates colors within the desktop app. |
2024-06-27 | Desktop App | 21.74.0 | This release updates the desktop app so that when clicking the taskbar icon, the Resource Center window opens or is in focus instead of the Account menu opening. This change also puts the Account menu within the header of the Resource Center window. |
2024-06-27 | Server | 89.59.0 | This release fixes a duplicate footer and image for TOTP MFA enrollment success. |
2024-06-26 | Server | 89.54.0 | This fixes an issue for DBAs that caused the resource page not to load. |
2024-06-26 | CLI | 43.31.0 | This changes the Microsoft Defender Device Trust checks to be evaluated against the required trust level "as expected" (fixing a previously present in the code bug). |
2024-06-26 | Server | 89.52.0 | This changes the Microsoft Defender Device Trust checks to be evaluated against the required trust level "as expected" (fixing a previously present in the code bug). |
2024-06-25 | Server | 89.45.0 | This release resolves an issue where the navigation layout sometimes flickered before the login screen. It also resolves an issue with idle timeouts not correctly logging users out, and an issue with Parent-Child organization logins via the Admin UI. |
2024-06-24 | CLI | 43.15.0 | This release changes connection behavior to proactively close idle connections when proxying HTTP requests in order to reduce the memory profile of high volume HTTP requests for both nodes and clients. |
2024-06-21 | CLI | 43.4.0 | This release addresses the following third party CVEs: CVE-2024-35255 |
2024-06-21 | Server | 89.22.0 | This release addresses the following third party CVEs: CVE-2023-49559 |
2024-06-18 | Java SDK | 9.4.0 | This release adds the ability to configure the following cluster type resources for discovery to the CLI, SDKs and the SDM Terraform Provider: Kubernetes, KubernetesServiceAccount, AKS, AKSServiceAccount, AmazonEKS, AmazonEKSInstanceProfile, GoogleGKE. The feature is not yet Generally Available and may not be available to your organization yet. |
2024-06-18 | Server | 89.10.0 | This release adds more informational links to the MFA settings section in the Admin UI, including separate links for Duo, Okta, and TOTP setup. |
2024-06-18 | Server | 89.5.0 | This release updates the text on the Microsoft Defender option for Device Trust in the Admin UI. |
2024-06-18 | CLI | 42.97.0 | This release renames the CLI's admin relays tree to admin nodes with accompanying help text updates. Node is the more generic term that encompasses both gateways and relays. An alias for relays remains to prevent breakage in existing scripts. Similarly, the CLI's audit relays command has been renamed to audit nodes with accompanying help text updates. An alias for relays remains to prevent breakage in existing scripts. |
2024-06-18 | CLI | 42.96.0 | This release adds support for Mongo 7 and Mongo 8 (tested with RC8). |
2024-06-18 | CLI | 42.95.0 | This change adds support to parse ALTER DEFAULT PRIVILEGES statements as actions for Postgres resources. |
2024-06-18 | Server | 89.4.0 | This change adds support to parse ALTER DEFAULT PRIVILEGES statements as actions for Postgres resources. |
2024-06-17 | CLI | 42.93.0 | This release adds the ability to configure the following cluster type resources for discovery to the CLI, SDKs and the SDM Terraform Provider: Kubernetes, KubernetesServiceAccount, AKS, AKSServiceAccount, AmazonEKS, AmazonEKSInstanceProfile, GoogleGKE. The feature is not yet Generally Available and may not be available to your organization yet. |
2024-06-17 | Server | 89.3.0 | This release adds the ability to configure the following cluster type resources for discovery to the CLI, SDKs and the SDM Terraform Provider: Kubernetes, KubernetesServiceAccount, AKS, AKSServiceAccount, AmazonEKS, AmazonEKSInstanceProfile, GoogleGKE. The feature is not yet Generally Available and may not be available to your organization yet. |
2024-06-17 | Terraform | 10.4.0 | This release adds the ability to configure the following cluster type resources for discovery to the CLI, SDKs and the SDM Terraform Provider: Kubernetes, KubernetesServiceAccount, AKS, AKSServiceAccount, AmazonEKS, AmazonEKSInstanceProfile, GoogleGKE. The feature is not yet Generally Available and may not be available to your organization yet. |
2024-06-17 | Go SDK | 9.4.0 | This release adds the ability to configure the following cluster type resources for discovery to the CLI, SDKs and the SDM Terraform Provider: Kubernetes, KubernetesServiceAccount, AKS, AKSServiceAccount, AmazonEKS, AmazonEKSInstanceProfile, GoogleGKE. The feature is not yet Generally Available and may not be available to your organization yet. |
2024-06-17 | Python SDK | 9.4.0 | This release adds the ability to configure the following cluster type resources for discovery to the CLI, SDKs and the SDM Terraform Provider: Kubernetes, KubernetesServiceAccount, AKS, AKSServiceAccount, AmazonEKS, AmazonEKSInstanceProfile, GoogleGKE. The feature is not yet Generally Available and may not be available to your organization yet. |
2024-06-17 | Ruby SDK | 9.4.0 | This release adds the ability to configure the following cluster type resources for discovery to the CLI, SDKs and the SDM Terraform Provider: Kubernetes, KubernetesServiceAccount, AKS, AKSServiceAccount, AmazonEKS, AmazonEKSInstanceProfile, GoogleGKE. The feature is not yet Generally Available and may not be available to your organization yet. |
2024-06-17 | Terraform | 10.3.0 | This release changes the Remote Identity references to Identity Alias in the header and JSON keys for sdm audit queries , and for Log Sync. |
2024-06-17 | CLI | 42.92.0 | This release changes the Remote Identity references to Identity Alias in the header and JSON keys for sdm audit queries , and for Log Sync. |
2024-06-17 | Server | 89.1.0 | This release changes the Remote Identity references to Identity Alias in the header and JSON keys for sdm audit queries , and for Log Sync. |
2024-06-17 | Python SDK | 9.3.0 | This release changes the Remote Identity references to Identity Alias in the header and JSON keys for sdm audit queries , and for Log Sync. |
2024-06-17 | Ruby SDK | 9.3.0 | This release changes the Remote Identity references to Identity Alias in the header and JSON keys for sdm audit queries , and for Log Sync. |
2024-06-17 | Go SDK | 9.3.0 | This release changes the Remote Identity references to Identity Alias in the header and JSON keys for sdm audit queries , and for Log Sync. |
2024-06-17 | CLI | 42.90.0 | This release renames the Remote Identity activities to Identity Alias and Identity Sets. This release also renames the Remote Identities header to Identity Aliases for sdm audit users and sdm audit queries . |
2024-06-17 | CLI | 42.91.0 | This release updates some CLI commands to now show the correct default value (instead of 0) for the --page-limit option. |
2024-06-17 | Server | 89.0.0 | This release renames the Remote Identity activities to Identity Alias and Identity Sets. This release also renames the Remote Identities header to Identity Aliases for sdm audit users and sdm audit queries . |
2024-06-17 | Terraform | 10.2.0 | This release renames the Remote Identity activities to Identity Alias and Identity Sets. This release also renames the Remote Identities header to Identity Aliases for sdm audit users and sdm audit queries . |
2024-06-17 | Python SDK | 9.2.0 | This release renames the Remote Identity activities to Identity Alias and Identity Sets. This release also renames the Remote Identities header to Identity Aliases for sdm audit users and sdm audit queries . |
2024-06-17 | Ruby SDK | 9.2.0 | This release renames the Remote Identity activities to Identity Alias and Identity Sets. This release also renames the Remote Identities header to Identity Aliases for sdm audit users and sdm audit queries . |
2024-06-17 | Go SDK | 9.2.0 | This release renames the Remote Identity activities to Identity Alias and Identity Sets. This release also renames the Remote Identities header to Identity Aliases for sdm audit users and sdm audit queries . |
2024-06-14 | CLI | 42.81.0 | This change causes nodes to restart if they detect they have lost their authentication state, so they can either restore it or sever themselves from the network and cut idle traffic if they cannot (because they were remotely deleted, for example). |
2024-06-14 | Server | 88.91.0 | This release implements a default behavior to forbid self-approvals in the workflow settings. Existing configurations will be unaffected. |
2024-06-13 | Server | 88.85.0 | This change resolves a bug where deleted nodes would not be notified of their deletion, causing them to continue to fruitlessly send requests to a StrongDM control plane until they were manually cut off. |
2024-06-12 | Server | 88.72.0 | This release allows Resources to be filtered by identityEnabled and identitySetID "identityEnabled" has a Boolean value and indicates if a resource is configured to use an Identity Alias on connection. "identitySetID" has a string value, and is the specific Identity Set that the resource is configured to use. Filtering by remoteIdentityEnabled is still supported but is deprecated. |
2024-06-11 | CLI | 42.69.0 | This change reveals the sdm admin network subtree for working with peering groups. |
2024-06-11 | CLI | 42.66.0 | This PR adds support for special JSON functions and the IS JSON clause to the SQL actions parser. |
2024-06-11 | Server | 88.68.0 | This PR adds support for special JSON functions and the IS JSON clause to the SQL actions parser. |
2024-06-11 | CLI | 42.61.0 | This changeset supports DROP DATABASE, DROP CAST, DROP TRANSFORM, and DROP OPERATOR CLASS in the PostgreSQL action parser. |
2024-06-11 | Server | 88.64.0 | This changeset supports DROP DATABASE, DROP CAST, DROP TRANSFORM, and DROP OPERATOR CLASS in the PostgreSQL action parser. |
2024-06-11 | CLI | 42.59.0 | This changeset adds action parsing support for SQL MERGE statements. |
2024-06-11 | Server | 88.63.0 | This changeset adds action parsing support for SQL MERGE statements. |
2024-06-11 | CLI | 42.58.0 | This change adds support for UESCAPE clauses in PostgreSQL query parsing. |
2024-06-11 | Server | 88.62.0 | This change adds support for UESCAPE clauses in PostgreSQL query parsing. |
2024-06-10 | CLI | 42.57.0 | This PR augments SQL parsing to correctly handle cases around type copying in function creation and some forms of type casting. |
2024-06-10 | Server | 88.57.0 | This PR augments SQL parsing to correctly handle cases around type copying in function creation and some forms of type casting. |
2024-06-10 | CLI | 42.54.0 | This release augments the Postgres policy action parser to understand more edge cases of the Postgres grammar. |
2024-06-10 | Server | 88.46.0 | This release adds Microsoft Defender as a supported Device Trust provider. |
2024-06-06 | Server | 88.24.0 | This release fixes a bug preventing configured Okta MFA settings from appearing in the Admin UI. |
2024-06-06 | Server | 88.23.0 | This release updates the error message received when a user is not enrolled in Okta MFA, for clarity. |
2024-06-05 | Server | 88.22.0 | This release changes the behavior of the 'default' Identity Set. New organizations will no longer have a 'default' Identity Set automatically created. 'default' Identity Sets will also be able to be deleted. |
2024-06-03 | Server | 88.4.0 | SCIM requests can now include a list of identity aliases to be assigned to a user. |
2024-06-03 | Server | 88.3.0 | This change deprecates some older forms of creating healthchecks. Specifically, when gateways come online after being offline for over 60 seconds, they would formerly enqueue a healthcheck for every resource at that time; this has been removed. In addition, legacy clients used a less efficient mechanism for healthchecking resources on sdm connect ; this has been removed. All CLI versions released within the last year, or greater than 38.13.0, will see no change in behavior here. Newer clients will (still) efficiently healthcheck resources on sdm connect , for any unhealthy resource, and this in combination with manual checks, checks on resource updates, and periodic automatic checks will keep gaps from causing access problems. Switching to explicit routing is also recommended for users with large, complicated networks. |
2024-05-29 | CLI | 42.34.0 | This release adds the Identity Set Create, Update, and Delete commands to the CLI and SDKs. It also changes sdm admin identities create to take in a required identity-set-id or identity-set-name , instead of creating all Identity Aliases with the default Identity Set. |
2024-05-29 | Server | 87.78.0 | This release adds the Identity Set Create, Update, and Delete commands to the CLI and SDKs. It also changes sdm admin identities create to take in a required identity-set-id or identity-set-name , instead of creating all Identity Aliases with the default Identity Set. |
2024-05-29 | Java SDK | 9.1.0 | This release adds the Identity Set Create, Update, and Delete commands to the CLI and SDKs. It also changes sdm admin identities create to take in a required identity-set-id or identity-set-name , instead of creating all Identity Aliases with the default Identity Set. |
2024-05-29 | Terraform | 10.1.0 | This release adds the Identity Set Create, Update, and Delete commands to the CLI and SDKs. It also changes sdm admin identities create to take in a required identity-set-id or identity-set-name , instead of creating all Identity Aliases with the default Identity Set. |
2024-05-29 | Python SDK | 9.1.0 | This release adds the Identity Set Create, Update, and Delete commands to the CLI and SDKs. It also changes sdm admin identities create to take in a required identity-set-id or identity-set-name , instead of creating all Identity Aliases with the default Identity Set. |
2024-05-29 | Go SDK | 9.1.0 | This release adds the Identity Set Create, Update, and Delete commands to the CLI and SDKs. It also changes sdm admin identities create to take in a required identity-set-id or identity-set-name , instead of creating all Identity Aliases with the default Identity Set. |
2024-05-29 | Ruby SDK | 9.1.0 | This release adds the Identity Set Create, Update, and Delete commands to the CLI and SDKs. It also changes sdm admin identities create to take in a required identity-set-id or identity-set-name , instead of creating all Identity Aliases with the default Identity Set. |
2024-05-29 | Server | 87.74.0 | This release addresses a race condition in native login that could cause the user to be redirected to the login page when they should not be. |
2024-05-22 | CLI | 42.26.0 | This release renames sdm admin remote-identities to sdm admin identities , the sdm admin remote-identities tree is deprecated.
Similarly for SDKs, the old Remote Identity and Remote Identity Group surfaces have been deprecated and renamed to Identity Alias and Identity Set.
For Drivers, the RemoteIdentityHealthcheckUsername and RemoteIdentityGroupId have been renamed to IdentityAliasHealthcheckUsername and IdentitySetId .
When creating resources using the CLI, the user would need to use identityAliasHealthcheckUsername and identitySetId , instead of remoteIdentityHealthcheckUsername and remoteIdentityGroupId as the JSON keys. |
2024-05-22 | Server | 87.53.0 | This release renames sdm admin remote-identities to sdm admin identities , the sdm admin remote-identities tree is deprecated.
Similarly for SDKs, the old Remote Identity and Remote Identity Group surfaces have been deprecated and renamed to Identity Alias and Identity Set.
For Drivers, the RemoteIdentityHealthcheckUsername and RemoteIdentityGroupId have been renamed to IdentityAliasHealthcheckUsername and IdentitySetId .
When creating resources using the CLI, the user would need to use identityAliasHealthcheckUsername and identitySetId , instead of remoteIdentityHealthcheckUsername and remoteIdentityGroupId as the JSON keys. |
2024-05-22 | Java SDK | 9.0.0 | This release renames sdm admin remote-identities to sdm admin identities , the sdm admin remote-identities tree is deprecated.
Similarly for SDKs, the old Remote Identity and Remote Identity Group surfaces have been deprecated and renamed to Identity Alias and Identity Set.
For Drivers, the RemoteIdentityHealthcheckUsername and RemoteIdentityGroupId have been renamed to IdentityAliasHealthcheckUsername and IdentitySetId .
When creating resources using the CLI, the user would need to use identityAliasHealthcheckUsername and identitySetId , instead of remoteIdentityHealthcheckUsername and remoteIdentityGroupId as the JSON keys. |
2024-05-22 | Terraform | 10.0.0 | This release renames sdm admin remote-identities to sdm admin identities , the sdm admin remote-identities tree is deprecated.
Similarly for SDKs, the old Remote Identity and Remote Identity Group surfaces have been deprecated and renamed to Identity Alias and Identity Set.
For Drivers, the RemoteIdentityHealthcheckUsername and RemoteIdentityGroupId have been renamed to IdentityAliasHealthcheckUsername and IdentitySetId .
When creating resources using the CLI, the user would need to use identityAliasHealthcheckUsername and identitySetId , instead of remoteIdentityHealthcheckUsername and remoteIdentityGroupId as the JSON keys. |
2024-05-22 | Python SDK | 9.0.0 | This release renames sdm admin remote-identities to sdm admin identities , the sdm admin remote-identities tree is deprecated.
Similarly for SDKs, the old Remote Identity and Remote Identity Group surfaces have been deprecated and renamed to Identity Alias and Identity Set.
For Drivers, the RemoteIdentityHealthcheckUsername and RemoteIdentityGroupId have been renamed to IdentityAliasHealthcheckUsername and IdentitySetId .
When creating resources using the CLI, the user would need to use identityAliasHealthcheckUsername and identitySetId , instead of remoteIdentityHealthcheckUsername and remoteIdentityGroupId as the JSON keys. |
2024-05-22 | Ruby SDK | 9.0.0 | This release renames sdm admin remote-identities to sdm admin identities , the sdm admin remote-identities tree is deprecated.
Similarly for SDKs, the old Remote Identity and Remote Identity Group surfaces have been deprecated and renamed to Identity Alias and Identity Set.
For Drivers, the RemoteIdentityHealthcheckUsername and RemoteIdentityGroupId have been renamed to IdentityAliasHealthcheckUsername and IdentitySetId .
When creating resources using the CLI, the user would need to use identityAliasHealthcheckUsername and identitySetId , instead of remoteIdentityHealthcheckUsername and remoteIdentityGroupId as the JSON keys. |
2024-05-22 | Go SDK | 9.0.0 | This release renames sdm admin remote-identities to sdm admin identities , the sdm admin remote-identities tree is deprecated.
Similarly for SDKs, the old Remote Identity and Remote Identity Group surfaces have been deprecated and renamed to Identity Alias and Identity Set.
For Drivers, the RemoteIdentityHealthcheckUsername and RemoteIdentityGroupId have been renamed to IdentityAliasHealthcheckUsername and IdentitySetId .
When creating resources using the CLI, the user would need to use identityAliasHealthcheckUsername and identitySetId , instead of remoteIdentityHealthcheckUsername and remoteIdentityGroupId as the JSON keys. |
2024-05-20 | Java SDK | 8.4.0 | Added support for Hashicorp Vault AWS IAM and EC2 authentication methods for use as a secret store. |
2024-05-20 | Python SDK | 8.4.0 | Added support for Hashicorp Vault AWS IAM and EC2 authentication methods for use as a secret store. |
2024-05-20 | Go SDK | 8.4.0 | Added support for Hashicorp Vault AWS IAM and EC2 authentication methods for use as a secret store. |
2024-05-20 | Ruby SDK | 8.4.0 | Added support for Hashicorp Vault AWS IAM and EC2 authentication methods for use as a secret store. |
2024-05-20 | Desktop App | 21.71.0 | Added support for Hashicorp Vault AWS IAM and EC2 authentication methods for use as a secret store. |
2024-05-20 | CLI | 42.25.0 | Added support for Hashicorp Vault AWS IAM and EC2 authentication methods for use as a secret store. |
2024-05-20 | Server | 87.49.0 | Added support for Hashicorp Vault AWS IAM and EC2 authentication methods for use as a secret store. |
2024-05-17 | Server | 87.44.0 | This release updates the display and visibility of the Log Stream Admin UI component based on payment tier. |
2024-05-16 | Server | 87.32.0 | When using the Context-Based Policy feature, the default "Global Access" policy shown in the Policy Library in the Admin UI can now be modified or deleted. Modifying or deleting this policy may prevent users with pre-assigned role or temporary account grants from accessing resources, as access to resources must be permitted by both grants and by policy. In addition, when using the Context-Based Policy feature, the policy editor in the Admin UI can now be used to create permit policies without specifying a location, device trust, or user requirements. Such policies can be used to permit access to resources in conjunction with existing role and account grants. |
2024-05-16 | Server | 87.30.0 | This release fixes an issue where queries logged for context-based policy were not populating the source and client IP address fields in the query. The source and client IP address information was still present in the authorization data included with the logged query. |
2024-05-15 | Server | 87.25.0 | This release fixes a bug where SCIM token rotation would not present a new token to copy. |
2024-05-13 | Server | 87.13.0 | This release fixes a bug related to opening app.strongdm.com from the desktop app and fixes a bug related to SSO logins. |
2024-05-13 | CLI | 42.9.0 | sdm install now supports the --domain flag, which allows you to instruct the client or relay to connect to a StrongDM control plane other than strongdm.com . For example, customers using GovCloud should connect to strongdm-gov.com . |
2024-05-13 | Server | 87.8.0 | This release adds the ability to reference Identity Aliases and Identity Sets in the context of policies. It also adds Identity Set as an entity (that is, StrongDM::IdentitySet ).
Example usage:

@justify("Please provide justification")
permit (
 principal,
 action in [StrongDM::Action::"dial"],
 resource == StrongDM::Resource::"rs-25599cd76579dac5"
) when {
 context.identityAlias.username == "ssh_superuser" && 
 context.identitySet == StrongDM::IdentitySet::"is-111111111111"
};
 |
2024-05-09 | Server | 86.98.0 | Added support for a new certificate authority integration: Keyfactor EJBCA SSH CA |
2024-05-09 | Java SDK | 8.3.0 | Added support for a new certificate authority integration: Keyfactor EJBCA SSH CA |
2024-05-09 | Terraform | 9.3.0 | Added support for a new certificate authority integration: Keyfactor EJBCA SSH CA |
2024-05-09 | Ruby SDK | 8.3.0 | Added support for a new certificate authority integration: Keyfactor EJBCA SSH CA |
2024-05-09 | Python SDK | 8.3.0 | Added support for a new certificate authority integration: Keyfactor EJBCA SSH CA |
2024-05-09 | Go SDK | 8.3.0 | Added support for a new certificate authority integration: Keyfactor EJBCA SSH CA |
2024-05-09 | CLI | 42.4.0 | This release addresses the following third party CVEs: CVE-2024-28180 |
2024-05-09 | Server | 86.97.0 | This release addresses the following third party CVEs: CVE-2024-28180 |
2024-05-08 | Server | 86.91.0 | This release resolves a bug where timed out Admin UI sessions would not redirect users back to the login screen. |
2024-05-08 | CLI | 41.98.0 | This release removes the client key password environment variable field for configuration of Keyfactor RDP CAs. |
2024-05-08 | Server | 86.86.0 | This release removes the client key password environment variable field for configuration of Keyfactor RDP CAs. |
2024-05-06 | Server | 86.79.0 | This release adds a page in the Admin UI that informs users that they are logging out prior to showing the login screen. |
2024-05-06 | Server | 86.76.0 | This release addresses the following third party CVEs: CVE-2024-33883 |
2024-05-06 | CLI | 41.94.0 | This release changes the Request Access form in the integration for Slack so that the duration component now allows times that are less than 1 hour. |
2024-05-06 | Server | 86.75.0 | This release changes the Request Access form in the integration for Slack so that the duration component now allows times that are less than 1 hour. |
2024-05-02 | Server | 86.64.0 | This release fixes a bug in the rendering of the query panel for policy logs, where it would take some time to fill the screen on large displays. |
2024-05-02 | Server | 86.62.0 | Fixes a bug in integration with Slack where non-approvers could mark channel-based request as approved, which would result in no actual access to the resource since they are not approvers. |
2024-04-30 | Server | 86.55.0 | This release fixes a bug in the rendering of routes via sdm admin network topology . |
2024-04-30 | CLI | 41.82.0 | The FIPS-compliant variant of our linux CLI binary is now compatible with glibc versions as old as 2.27. This does not affect normal, non-FIPS-compliant linux binaries. |
2024-04-30 | Server | 86.48.0 | The Download & Install page on the Admin UI now directs Docker users to public.ecr.aws/strongdm instead of quay.io/sdmrepo . quay.io will continue to be supported. |
2024-04-25 | Java SDK | 8.1.0 | This release adds support for the Keyfactor EJBCA Certificate authority type. |
2024-04-25 | Terraform | 9.1.0 | This release adds support for the Keyfactor EJBCA Certificate authority type. |
2024-04-25 | Python SDK | 8.1.0 | This release adds support for the Keyfactor EJBCA Certificate authority type. |
2024-04-25 | Go SDK | 8.1.0 | This release adds support for the Keyfactor EJBCA Certificate authority type. |
2024-04-25 | Ruby SDK | 8.1.0 | This release adds support for the Keyfactor EJBCA Certificate authority type. |
2024-04-23 | CLI | 41.70.0 | This release addresses the following third party CVEs: CVE-2023-45288 |
2024-04-23 | Server | 86.25.0 | This release addresses the following third party CVEs: CVE-2023-45288 |
2024-04-23 | Server | 86.23.0 | This release adds the Remote Identity group ID (i.e. ig-123 ) field to the resource filters. |
2024-04-23 | CLI | 41.67.0 | This release adds support for a new third party certificate authority: Keyfactor for RDP. |
2024-04-23 | Server | 86.22.0 | This release adds support for a new third party certificate authority: Keyfactor for RDP. |
2024-04-23 | Desktop App | 21.69.0 | This release updates the installers to provide better support for managed
installations where the SDM user may be a standard user, not an administrator.
To allow auto-updates to work without requiring an administrator, the SDM
application is now installed by default into the user's program directory
($HOME/Applications on macOS and $PROFILE/AppData/Local/Programs on Windows). The Windows and macOS installers both provide a way for an administrator to
install the application on behalf of a standard user
and both install the latest StrongDM Virtual Network Adapter when the
installation is performed with administrator privileges. |
2024-04-22 | CLI | 41.64.0 | This release enhances proxied HTTP requests for website resources to now include the X-Forwarded-Proto header indicating the protocol scheme (HTTP or HTTPS). Some HTTP servers may relay on this header being present. |
2024-04-22 | CLI | 41.63.0 | This release enables the ability to refer to a resource by name when requesting access via the CLI (sdm access to <resource name> ). This release also fixes a bug where the requested resource IDs would not populate in the sdm access requests command. |
2024-04-22 | Server | 86.20.0 | This release enables the ability to refer to a resource by name when requesting access via the CLI (sdm access to <resource name> ). This release also fixes a bug where the requested resource IDs would not populate in the sdm access requests command. |
2024-04-22 | CLI | 41.62.0 | This release augments logging for the Snowsight driver to include any UUIDs that are found in responses when connection attempts fail. Snowsight documentation indicates that these may be used to query the LOGIN_HISTORY or LOGIN_HISTORY_BY_USER views to get more details about the error. |
2024-04-22 | Server | 86.17.0 | This release augments logging for the Snowsight driver to include any UUIDs that are found in responses when connection attempts fail. Snowsight documentation indicates that these may be used to query the LOGIN_HISTORY or LOGIN_HISTORY_BY_USER views to get more details about the error. |
2024-04-18 | Server | 86.5.0 | This release addresses the following third party CVEs: CVE-2024-29041,CVE-2024-28863 |
2024-04-17 | Server | 86.2.0 | This release fixes a bug that caused the minimum CrowdStrike score not to appear correctly in the Admin UI. |
2024-04-15 | CLI | 41.52.0 | This release fixes a bug with context-based policy where justification and MFA prompts may no longer appear through the desktop app when logging back in to the client after a log out or session expiration. |
2024-04-15 | Server | 85.95.0 | This release fixes a bug with context-based policy where justification and MFA prompts may no longer appear through the desktop app when logging back in to the client after a log out or session expiration. |
2024-04-12 | Terraform | 9.0.0 | This release adds the ability to query tokens on the sdm_account resource type in the StrongDM Terraform provider. |
2024-04-09 | Server | 85.88.0 | This release refactors Slack token refreshes to be more tolerant of Slack outages. |
2024-04-09 | Server | 85.87.0 | This release includes the following changes: - Write operations are limited to Create and Delete operations for API keys and tokens. Furthermore, Update is valid for changing the name of these token types, but no other fields are allowed to be updated. - Read operations support all token types (API Key, Admin Token, SCIM Token, and ServiceNow Tokens) in addition to the existing users and service account types. Note that the default behavior of the List operation on all accounts without any filters on account type will now return token types in addition to the users and service account types. - API keys and admin tokens now can be attached with permissions to create new tokens. The permissions on the tokens created must be a subset of the permissions that the parent token has. |
2024-04-09 | Java SDK | 8.0.0 | This release includes the following changes: - Write operations are limited to Create and Delete operations for API keys and tokens. Furthermore, Update is valid for changing the name of these token types, but no other fields are allowed to be updated. - Read operations support all token types (API Key, Admin Token, SCIM Token, and ServiceNow Tokens) in addition to the existing users and service account types. Note that the default behavior of the List operation on all accounts without any filters on account type will now return token types in addition to the users and service account types. - API keys and admin tokens now can be attached with permissions to create new tokens. The permissions on the tokens created must be a subset of the permissions that the parent token has. |
2024-04-09 | Python SDK | 8.0.0 | This release includes the following changes: - Write operations are limited to Create and Delete operations for API keys and tokens. Furthermore, Update is valid for changing the name of these token types, but no other fields are allowed to be updated. - Read operations support all token types (API Key, Admin Token, SCIM Token, and ServiceNow Tokens) in addition to the existing users and service account types. Note that the default behavior of the List operation on all accounts without any filters on account type will now return token types in addition to the users and service account types. - API keys and admin tokens now can be attached with permissions to create new tokens. The permissions on the tokens created must be a subset of the permissions that the parent token has. |
2024-04-09 | Ruby SDK | 8.0.0 | This release includes the following changes: - Write operations are limited to Create and Delete operations for API keys and tokens. Furthermore, Update is valid for changing the name of these token types, but no other fields are allowed to be updated. - Read operations support all token types (API Key, Admin Token, SCIM Token, and ServiceNow Tokens) in addition to the existing users and service account types. Note that the default behavior of the List operation on all accounts without any filters on account type will now return token types in addition to the users and service account types. - API keys and admin tokens now can be attached with permissions to create new tokens. The permissions on the tokens created must be a subset of the permissions that the parent token has. |
2024-04-09 | Go SDK | 8.0.0 | This release includes the following changes: - Write operations are limited to Create and Delete operations for API keys and tokens. Furthermore, Update is valid for changing the name of these token types, but no other fields are allowed to be updated. - Read operations support all token types (API Key, Admin Token, SCIM Token, and ServiceNow Tokens) in addition to the existing users and service account types. Note that the default behavior of the List operation on all accounts without any filters on account type will now return token types in addition to the users and service account types. - API keys and admin tokens now can be attached with permissions to create new tokens. The permissions on the tokens created must be a subset of the permissions that the parent token has. |
2024-04-09 | Server | 85.86.0 | This release fixes a regression where user agents weren't being populated for requests originating from Slack requests or anonymous HTTP requests. |
2024-04-02 | Desktop App | 21.65.0 | This release fixes a bug where failing MFA during login would require quitting the application to re-attempt login. |
2024-03-26 | Server | 85.70.0 | This release fixes some broken documentation links in the Admin UI. |
2024-03-26 | Server | 85.68.0 | This release fixes a bug where retrieving large replays through the API could fail with a resource exhausted error due to exceeding maximum GRPC message size limits. |
2024-03-26 | Python SDK | 7.1.1 | This release fixes a bug where retrieving large replays through the API could fail with a resource exhausted error due to exceeding maximum GRPC message size limits. |
2024-03-25 | Server | 85.64.0 | This release adds a new Default Service Account Enforcement setting in the Admin UI Device Trust security settings in the Settings > Security page and a matching Service Account level setting in the Access > Users > Service Account > Settings page. The new settings allow for setting the default Device Trust enforcement policy for service accounts to be either required or exempt at the organization level, and also to set an overriding setting on individual service accounts. The effective Device Trust state is now shown for service accounts on the Access > Users page in the Device Trust column. |
2024-03-21 | Server | 85.63.0 | This release fixes an issue that could cause a manual approval flow to be converted to an automatic one that would fail to save. |
2024-03-21 | Server | 85.62.0 | This release fixes an issue where automatic approval workflows couldn't be saved unless an approver was selected. |
2024-03-21 | Server | 85.61.0 | This release reduces the number of error emails that may be sent due to Device Trust provider issues. In addition, a "resolved" email will now be sent when the issue is no longer present. |
2024-03-19 | Server | 85.59.0 | This release fixes an issue where only the first 25 Approval Workflows would list in the Admin UI. |
2024-03-19 | Server | 85.58.0 | This release fixes an issue where the MFA screen did not take up the whole screen in the desktop app. |
2024-03-19 | Server | 85.56.0 | Third Party Certificate Authorities are generally available, including AWS Private CA RDP, Active Directory Certificate Services, GCP Certificate Authority Service RDP, HashiCorp Vault SSH, HashiCorp Vault SSH (AppRole), HashiCorp Vault SSH (Token), HashiCorp Vault RDP, HashiCorp Vault RDP (AppRole), HashiCorp Vault RDP (Token) Each third party Certificate Authority has a details page which includes Diagnostics, Settings, and Resources (if resources have been applied). |
2024-03-19 | Server | 85.55.0 | If an access request is automatically denied due to there being no approvers on the bound workflow a reason is added to indicate why the request was denied. |
2024-03-18 | Server | 85.53.0 | This release fixes an issue where the IP Allowlist settings page could not be accessed even with the feature enabled. |
2024-03-18 | Desktop App | 21.64.0 | The installer for Windows (EXE file) and macOS (PKG file) have been changed.
When the installer is run by a privileged user (run as Administrator on Windows; with sudo or as root on macOS), the installation also includes a virtual networking component.
The installer now provides a way for an administrator to install the application for the use of specified standard user that makes auto-updates work properly for that end user. To do this on Windows, run the installer as Administrator with an extra --SDMUSER=<OtherUserName> on the command line. On MacOS, run the command HOME=/Users/<OtherUserName> sudo installer -pkg <SDMInstaller.pkg> -target / .
Standard (non-admin) users can still run the installer. When executed without admin, the installer acts as it did before. It installs the SDM application to a per-user location and does not install the virtual networking component. |
2024-03-15 | CLI | 41.34.0 | This release fixes an issue with AWS resources where where retrieving objects through S3 with certain special characters in the object key could fail with a signature error. |
2024-03-15 | Desktop App | 21.63.0 | This release addresses the following third party CVEs: CVE-2024-24786,CVE-2024-27303 |
2024-03-15 | CLI | 41.33.0 | This release addresses the following third party CVEs: CVE-2024-24786,CVE-2024-27303 |
2024-03-15 | Server | 85.49.0 | This release addresses the following third party CVEs: CVE-2024-24786,CVE-2024-27303 |
2024-03-15 | CLI | 41.32.0 | This release adds the Issued Certificate TTL Minutes field, as a required field, to the Certificate Authorities configurations for AWS Private CA, Google Certificate Authority Service and HashiCorp Vault SSH and PKI. This field allows for the specification of the lifetime of the requested certificate. This release also marks the Certificate Authority category Secret Stores as stable. |
2024-03-15 | Server | 85.48.0 | This release adds the Issued Certificate TTL Minutes field, as a required field, to the Certificate Authorities configurations for AWS Private CA, Google Certificate Authority Service and HashiCorp Vault SSH and PKI. This field allows for the specification of the lifetime of the requested certificate. This release also marks the Certificate Authority category Secret Stores as stable. |
2024-03-15 | Java SDK | 7.1.0 | This release adds the Issued Certificate TTL Minutes field, as a required field, to the Certificate Authorities configurations for AWS Private CA, Google Certificate Authority Service and HashiCorp Vault SSH and PKI. This field allows for the specification of the lifetime of the requested certificate. This release also marks the Certificate Authority category Secret Stores as stable. |
2024-03-15 | Terraform | 8.1.0 | This release adds the Issued Certificate TTL Minutes field, as a required field, to the Certificate Authorities configurations for AWS Private CA, Google Certificate Authority Service and HashiCorp Vault SSH and PKI. This field allows for the specification of the lifetime of the requested certificate. This release also marks the Certificate Authority category Secret Stores as stable. |
2024-03-15 | Python SDK | 7.1.0 | This release adds the Issued Certificate TTL Minutes field, as a required field, to the Certificate Authorities configurations for AWS Private CA, Google Certificate Authority Service and HashiCorp Vault SSH and PKI. This field allows for the specification of the lifetime of the requested certificate. This release also marks the Certificate Authority category Secret Stores as stable. |
2024-03-15 | Ruby SDK | 7.1.0 | This release adds the Issued Certificate TTL Minutes field, as a required field, to the Certificate Authorities configurations for AWS Private CA, Google Certificate Authority Service and HashiCorp Vault SSH and PKI. This field allows for the specification of the lifetime of the requested certificate. This release also marks the Certificate Authority category Secret Stores as stable. |
2024-03-15 | Go SDK | 7.1.0 | This release adds the Issued Certificate TTL Minutes field, as a required field, to the Certificate Authorities configurations for AWS Private CA, Google Certificate Authority Service and HashiCorp Vault SSH and PKI. This field allows for the specification of the lifetime of the requested certificate. This release also marks the Certificate Authority category Secret Stores as stable. |
2024-03-15 | CLI | 41.31.0 | This release adds the ability to modify user permission levels via the SDKs. |
2024-03-15 | Server | 85.46.0 | This release adds the ability to modify user permission levels via the SDKs. |
2024-03-15 | Terraform | 8.0.0 | This release adds the ability to modify user permission levels via the SDKs. |
2024-03-15 | Java SDK | 7.0.0 | This release adds the ability to modify user permission levels via the SDKs. |
2024-03-15 | Python SDK | 7.0.0 | This release adds the ability to modify user permission levels via the SDKs. |
2024-03-15 | Go SDK | 7.0.0 | This release adds the ability to modify user permission levels via the SDKs. |
2024-03-15 | Ruby SDK | 7.0.0 | This release adds the ability to modify user permission levels via the SDKs. |
2024-03-15 | Server | 85.43.0 | This release replaces Support chat links during organization trials with documentation links. |
2024-03-14 | Server | 85.39.0 | This release changes the Admin UI Access Workflows page's table header checkbox to show an indeterminate state when some but not all rows have been selected. |
2024-03-12 | Server | 85.35.0 | This release makes approval workflows unable to be saved unless an approver is selected. |
2024-03-12 | Server | 85.33.0 | This release updates the Device Trust settings in the Admin UI with more flexible controls globally and per user. |
2024-03-08 | CLI | 41.26.0 | This release sets the TTL for issued certificates using certain third-party CAs to a lower default TTL of 5 minutes. |
2024-03-08 | Server | 85.24.0 | This release makes new Policy features available to Enterprise customers in the Admin UI. These features allow admins to require MFA or text justifications or to require approval workflows to be followed for some access. Policies can consider conditions such as the geographic location of the user and the device trust score of the user's machine when making access decisions. |
2024-03-08 | CLI | 41.25.0 | This change hides the account field returned by sdm ready by default, replacing it with account_info , a new object containing more specific information about the logged in account. This also adds the -v or verbose flag to sdm ready which restores this deprecated field temporarily, and adds additional fields as well. |
2024-03-07 | Server | 85.21.0 | This release fixes a bug where access workflows did not save when unlinking a manual approval flow. |
2024-03-07 | Server | 85.19.0 | In this release, the default value of the Access filter in the Access Catalog has been changed from "Any" to "Available", so that the default results will now be restricted to resources that are currently available for the user to request. |
2024-03-06 | Server | 85.18.0 | This release modifies the presentation of user and global settings for device trust in the Admin UI. |
2024-03-05 | Server | 85.15.0 | This adds an Access component to the Catalog Search form in the Slack app. The default value for the Access filter is still "Available", but users now have the option to change it. |
2024-03-04 | Server | 85.10.0 | This release adds Approval Workflows permissions and Approval Workflows audit permissions for API token creation and admin token creation. |
2024-03-04 | Terraform | 7.7.0 | This release adds support for managing approval workflows. Using the SDKs/CLI, users can now Create, Update, List, Get, and Delete approval workflows. Users can also Create, List, Get, and Delete approval workflow steps and approval workflow approvers. |
2024-03-04 | Ruby SDK | 6.9.0 | This release adds support for managing approval workflows. Using the SDKs/CLI, users can now Create, Update, List, Get, and Delete approval workflows. Users can also Create, List, Get, and Delete approval workflow steps and approval workflow approvers. |
2024-03-04 | Python SDK | 6.9.0 | This release adds support for managing approval workflows. Using the SDKs/CLI, users can now Create, Update, List, Get, and Delete approval workflows. Users can also Create, List, Get, and Delete approval workflow steps and approval workflow approvers. |
2024-03-04 | Java SDK | 6.9.0 | This release adds support for managing approval workflows. Using the SDKs/CLI, users can now Create, Update, List, Get, and Delete approval workflows. Users can also Create, List, Get, and Delete approval workflow steps and approval workflow approvers. |
2024-03-04 | Go SDK | 6.9.0 | This release adds support for managing approval workflows. Using the SDKs/CLI, users can now Create, Update, List, Get, and Delete approval workflows. Users can also Create, List, Get, and Delete approval workflow steps and approval workflow approvers. |
2024-03-04 | Server | 85.7.0 | This release adds the ability to create, update, and delete Approval Workflows. |
2024-03-04 | Terraform | 7.6.0 | This change adds Approval Workflows and related verticals. |
2024-03-04 | Java SDK | 6.8.0 | This change adds Approval Workflows and related verticals. |
2024-03-04 | Python SDK | 6.8.0 | This change adds Approval Workflows and related verticals. |
2024-03-04 | Go SDK | 6.8.0 | This change adds Approval Workflows and related verticals. |
2024-03-04 | Ruby SDK | 6.8.0 | This change adds Approval Workflows and related verticals. |
2024-03-04 | Server | 85.4.0 | This release adds a link to the settings page on the access workflows page of the Admin UI. |
2024-03-02 | Server | 85.3.0 | This release fixes an issue where the resource catalog might appear empty when fetched in ServiceNow. |
2024-03-01 | CLI | 41.20.0 | The release fixes a bug where the SourceIP field of queries as returned in the sdm audit queries and associated CLI commands, the Queries API, and Log Stream query log entries incorrectly included a port number in addition to an IP. Queries created since this fix will contain only an IP address in the SourceIP field.
In addition, this release adds a new ClientIP field to the sdm audit queries and associated CLI commands, the Queries API, and Log Stream query log entries. This is the public-facing IP address that the client that performed a query used to authenticate with the StrongDM servers. This may differ from the SourceIP which is the IP address the client used to connect to the gateway through which the query was performed. These IP addresses may differ when the gateways are on a different network, such as behind a VPN.
Lastly, this release adds the --extended option to the sdm audit k8s|rdp|ssh CLI commands, which includes some additional extended fields in the query output. |
2024-03-01 | Server | 85.2.0 | The release fixes a bug where the SourceIP field of queries as returned in the sdm audit queries and associated CLI commands, the Queries API, and Log Stream query log entries incorrectly included a port number in addition to an IP. Queries created since this fix will contain only an IP address in the SourceIP field.
In addition, this release adds a new ClientIP field to the sdm audit queries and associated CLI commands, the Queries API, and Log Stream query log entries. This is the public-facing IP address that the client that performed a query used to authenticate with the StrongDM servers. This may differ from the SourceIP which is the IP address the client used to connect to the gateway through which the query was performed. These IP addresses may differ when the gateways are on a different network, such as behind a VPN.
Lastly, this release adds the --extended option to the sdm audit k8s|rdp|ssh CLI commands, which includes some additional extended fields in the query output. |
2024-03-01 | Java SDK | 6.7.1 | The release fixes a bug where the SourceIP field of queries as returned in the sdm audit queries and associated CLI commands, the Queries API, and Log Stream query log entries incorrectly included a port number in addition to an IP. Queries created since this fix will contain only an IP address in the SourceIP field.
In addition, this release adds a new ClientIP field to the sdm audit queries and associated CLI commands, the Queries API, and Log Stream query log entries. This is the public-facing IP address that the client that performed a query used to authenticate with the StrongDM servers. This may differ from the SourceIP which is the IP address the client used to connect to the gateway through which the query was performed. These IP addresses may differ when the gateways are on a different network, such as behind a VPN.
Lastly, this release adds the --extended option to the sdm audit k8s|rdp|ssh CLI commands, which includes some additional extended fields in the query output. |
2024-03-01 | Python SDK | 6.7.1 | The release fixes a bug where the SourceIP field of queries as returned in the sdm audit queries and associated CLI commands, the Queries API, and Log Stream query log entries incorrectly included a port number in addition to an IP. Queries created since this fix will contain only an IP address in the SourceIP field.
In addition, this release adds a new ClientIP field to the sdm audit queries and associated CLI commands, the Queries API, and Log Stream query log entries. This is the public-facing IP address that the client that performed a query used to authenticate with the StrongDM servers. This may differ from the SourceIP which is the IP address the client used to connect to the gateway through which the query was performed. These IP addresses may differ when the gateways are on a different network, such as behind a VPN.
Lastly, this release adds the --extended option to the sdm audit k8s|rdp|ssh CLI commands, which includes some additional extended fields in the query output. |
2024-03-01 | Go SDK | 6.7.1 | The release fixes a bug where the SourceIP field of queries as returned in the sdm audit queries and associated CLI commands, the Queries API, and Log Stream query log entries incorrectly included a port number in addition to an IP. Queries created since this fix will contain only an IP address in the SourceIP field.
In addition, this release adds a new ClientIP field to the sdm audit queries and associated CLI commands, the Queries API, and Log Stream query log entries. This is the public-facing IP address that the client that performed a query used to authenticate with the StrongDM servers. This may differ from the SourceIP which is the IP address the client used to connect to the gateway through which the query was performed. These IP addresses may differ when the gateways are on a different network, such as behind a VPN.
Lastly, this release adds the --extended option to the sdm audit k8s|rdp|ssh CLI commands, which includes some additional extended fields in the query output. |
2024-03-01 | Ruby SDK | 6.7.1 | The release fixes a bug where the SourceIP field of queries as returned in the sdm audit queries and associated CLI commands, the Queries API, and Log Stream query log entries incorrectly included a port number in addition to an IP. Queries created since this fix will contain only an IP address in the SourceIP field.
In addition, this release adds a new ClientIP field to the sdm audit queries and associated CLI commands, the Queries API, and Log Stream query log entries. This is the public-facing IP address that the client that performed a query used to authenticate with the StrongDM servers. This may differ from the SourceIP which is the IP address the client used to connect to the gateway through which the query was performed. These IP addresses may differ when the gateways are on a different network, such as behind a VPN.
Lastly, this release adds the --extended option to the sdm audit k8s|rdp|ssh CLI commands, which includes some additional extended fields in the query output. |
2024-03-01 | Server | 85.0.0 | This release fixes an issue that caused the Request Access page and its tabs not to load properly in the Admin UI. |
2024-03-01 | Server | 84.98.0 | This change adds a notification email sent to organization admins for non-transient Device Trust API failures. |
2024-02-29 | Server | 84.93.0 | This release fixes an issue with dynamic access rules on access workflows, where they couldn't be updated under certain conditions. |
2024-02-28 | Server | 84.88.0 | This release introduces a change to the file format and path location of replay data stored to Amazon S3 with Log Stream enabled, to improve the performance of storing that data. Replay data is no longer stored under individual objects (one object per chunk), but is instead aggregated so that multiple chunks from different replays may be stored in the same object, up to a limit of 1000 entries or 100 MB per object.
Replay data from Log Stream is now stored similarly to activity and query data. Specifically:
* The path under which replays are stored in S3 changes from <prefix>/replays/YYYY/MM/DD/HH/MM/<queryUUID>/<chunkID>.json to <prefix>/replays/YYYY/MM/DD/HH/MM/<randomUUID>.json .
* The content of each JSON object changes from a single chunk per object ({"formatVersion":"v1.0.0", "chunkID":"1" ...} ) to N chunks separated by new lines (that is, in JSON lines format, as with queries and activities). |
2024-02-28 | Server | 84.87.0 | This changeset clarifies text for access workflows and approval workflows throughout the Admin UI. |
2024-02-28 | Terraform | 7.5.0 | This change introduces the new AWS Private CA X.509 Certificate secret store. This secret store is marked as unstable and, as such, is not available for general use yet. |
2024-02-27 | CLI | 41.18.0 | This change introduces the new AWS Private CA X.509 Certificate secret store. This secret store is marked as unstable and, as such, is not available for general use yet. |
2024-02-27 | Java SDK | 6.7.0 | This change introduces the new AWS Private CA X.509 Certificate secret store. This secret store is marked as unstable and, as such, is not available for general use yet. |
2024-02-27 | Python SDK | 6.7.0 | This change introduces the new AWS Private CA X.509 Certificate secret store. This secret store is marked as unstable and, as such, is not available for general use yet. |
2024-02-27 | Go SDK | 6.7.0 | This change introduces the new AWS Private CA X.509 Certificate secret store. This secret store is marked as unstable and, as such, is not available for general use yet. |
2024-02-27 | Ruby SDK | 6.7.0 | This change introduces the new AWS Private CA X.509 Certificate secret store. This secret store is marked as unstable and, as such, is not available for general use yet. |
2024-02-27 | Server | 84.75.0 | This change reports a mocked version of a legacy variable to CLI versions older than 37.0.0 (released February 14, 2023). This variable was removed on February 24, 2024. The absence of this variable could cause the CLI to fail to respect port overrides on new connections. |
2024-02-26 | Java SDK | 6.6.0 | This release adds the approval flow ID field to access workflows. |
2024-02-26 | Go SDK | 6.6.0 | This release adds the approval flow ID field to access workflows. |
2024-02-26 | Python SDK | 6.6.0 | This release adds the approval flow ID field to access workflows. |
2024-02-26 | Ruby SDK | 6.6.0 | This release adds the approval flow ID field to access workflows. |
2024-02-26 | Desktop App | 21.58.0 | Installer behavior has changed to allow silent installations on macOS and Windows and for installations to include updates to Virtual Networking Mode.
On macOS, all PKG installers always require admin privilege, always install StrongDM in /Applications (but are owned by the end user so that update-in-place can still work), and always install the Virtual Networking Mode helper application.
If macOS users want to install the desktop app without Virtual Networking Mode,
they should use the DMG distribution. For a silent installation, macOS users should run the installer command line tool with the PKG file as a command line argument.
On Windows, the EXE installers now install Virtual Networking Mode whenever the installer
runs as Administrator. If the EXE installer is run as a non-administrator,
StrongDM gets installed, but Virtual Networking Mode is not installed or updated.
If Windows users want to install the desktop app without Virtual Networking Mode,
they should run the installer as a non-administrator.
Note that the EXE installers on Windows can be executed from the Command Prompt,
and the installation will be in silent mode if the /S flag is used with
the command. |
2024-02-23 | Server | 84.67.0 | This release adds the Update Admins scope to API keys. This is a sensitive scope that allows your key to update admin users. |
2024-02-23 | CLI | 41.15.0 | This change removes some deprecated capabilities around disabling port overrides. In particular, some CLI commands under sdm admin ports have been removed. |
2024-02-23 | Server | 84.63.0 | This release updates the StrongDM app for Slack with improved tag search functionality that matches the way tag searching works in the Admin UI. |
2024-02-23 | CLI | 41.14.0 | This change adds the --download option to the sdm replay rdp CLI command, which allows users to download formatted query logs from StrongDM and immediately render an MP4 from them. Previously, the logs had to be manually retrieved from a relay's logs directory. This does not currently support user-encrypted RDP logs. |
2024-02-22 | Server | 84.61.0 | This release fixes a bug that caused resources assigned to peering groups to sometimes incorrectly show as reachable from nodes not in the resource's peering group on the Resources tab of the Admin UI Network > Relays page, the Admin UI Network > Gateways page, and the output of the sdm admin relays list in the CLI. In addition, this release fixes a bug that caused resources shown on the Resources tab of those Admin UI pages not to be ordered by name. |
2024-02-22 | Server | 84.55.0 | This release adds support for all filters documented by the CLI help text for sdm admin resources list --filters-help . |
2024-02-22 | CLI | 41.10.0 | This release adds support for all filters documented by the CLI help text for sdm admin resources list --filters-help . |
2024-02-21 | Server | 84.53.0 | This change fixes a bug in device trust calculations which would prevent assessment storage from CrowdStrike for a CrowdStrike account with over 500 agents. |
2024-02-21 | Server | 84.51.0 | User names will no longer prevent creation of service accounts with the same name. |
2024-02-20 | CLI | 41.8.0 | This release introduces the GCP Certificate Authority Service, which is not yet available for general use. |
2024-02-20 | Terraform | 7.3.0 | This release introduces the GCP Certificate Authority Service, which is not yet available for general use. |
2024-02-20 | Server | 84.42.0 | This release introduces the GCP Certificate Authority Service, which is not yet available for general use. |
2024-02-20 | Java SDK | 6.5.0 | This release introduces the GCP Certificate Authority Service, which is not yet available for general use. |
2024-02-20 | Go SDK | 6.5.0 | This release introduces the GCP Certificate Authority Service, which is not yet available for general use. |
2024-02-20 | Python SDK | 6.5.0 | This release introduces the GCP Certificate Authority Service, which is not yet available for general use. |
2024-02-20 | Ruby SDK | 6.5.0 | This release introduces the GCP Certificate Authority Service, which is not yet available for general use. |
2024-02-20 | Server | 84.40.0 | This release fixes an issue where access requests which were automatically approved would not show the correct approved timestamp when viewing the request details page in the Admin UI. |
2024-02-20 | Server | 84.38.0 | This release fixes an issue where activities would not live feed into the Admin UI page on initial load. |
2024-02-16 | Server | 84.36.0 | This release fixes an issue where the access requests page of the Admin UI would not load in some instances. |
2024-02-16 | CLI | 41.6.0 | This release fixes an issue with the CLI where the sdm doctor -v command did not return any output. |
2024-02-12 | Server | 84.6.0 | This release fixes the access details text shown on the Admin UI Request Access page to not reference a reason if there is none. |
2024-02-09 | Server | 84.2.0 | This release fixes a bug that caused the /sdm access to command in the StrongDM integration for Slack not to work for non-admin users. |
2024-02-09 | Ruby SDK | 6.4.0 | This release adds the new resource type, RDP (Certificate Based) server, which supports Remote Identities. |
2024-02-09 | Java SDK | 6.4.0 | This release adds the new resource type, RDP (Certificate Based) server, which supports Remote Identities. |
2024-02-09 | Terraform | 7.2.0 | This release adds the new resource type, RDP (Certificate Based) server, which supports Remote Identities. |
2024-02-09 | Python SDK | 6.4.0 | This release adds the new resource type, RDP (Certificate Based) server, which supports Remote Identities. |
2024-02-09 | Go SDK | 6.4.0 | This release adds the new resource type, RDP (Certificate Based) server, which supports Remote Identities. |
2024-02-08 | Server | 83.93.0 | This release adds the Request timeout duration setting to the Settings > Workflows page of the Admin UI. |
2024-02-07 | Server | 83.83.0 | The StrongDM integration for Slack has been updated to a new version. This version offers: - Channel-based approvals - Multiple-resource requests - Easier request/resource filtering - UI/UX improvements |
2024-02-07 | Server | 83.79.0 | Creating an access request with a reason now has max length validation that matches the server. |
2024-02-05 | Server | 83.59.0 | This release adds the Certificate Authority field to the RDP (Certificate Based) and SSH (Certificate Based) resource forms, allowing users to select a desired Certificate Authority (default is Strong CA). Strong CA is the StrongDM RDP Certificate Authority or StrongDM SSH Certificate Authority, depending on the selected server type. Strong CA is selected by default and is always the default, even if the Allow Credentials to be Stored with StrongDM option is set in the Admin UI > Settings > Security. Strong CA may be managed in the Admin UI > Network > Certificate Authorities. |
2024-02-03 | Server | 83.52.0 | This release fixes a bug when running the sdm audit queries and related CLI commands, where including a filter using the query field to filter by query content would return an error that the filter was invalid. |
2024-02-02 | Server | 83.49.0 | This release changes the application of the security setting "Allow Credentials to be Stored with StrongDM." Certificate-based resources, such as SSH (Certificate Based) and RDP (Certificate Based), may be created without assigning a secret store, even if the "Allow Credentials to be Stored with StrongDM" security setting is set to "No." |
2024-02-01 | Server | 83.43.0 | This release adjusts the text in the enterprise banner at the top of workflow related pages to no longer reference Reports Library but rather Access Workflows. |
2024-02-01 | CLI | 40.89.0 | This PR adds secret stores that will request signed x509 certificates from the PKI configured in the secret store. The initially supported PKI is HashiCorp Vault PKI. This new secret store is marked unstable and, as such, is not available for use yet. |
2024-02-01 | Server | 83.40.0 | This PR adds secret stores that will request signed x509 certificates from the PKI configured in the secret store. The initially supported PKI is HashiCorp Vault PKI. This new secret store is marked unstable and, as such, is not available for use yet. |
2024-01-31 | Server | 83.34.0 | This release removes the option to select suspended users as approvers for access workflows. |
2024-01-31 | Java SDK | 6.3.2 | This release upgrades the GRPC dependency of the Java SDK to version 1.59.1. This version of the GRPC library fixes an incompatibility with newer versions of the Netty library, which may prevent the SDK from working with frameworks such as recent versions of Spring Boot. |
2024-01-31 | Server | 83.32.0 | This release adjusts the logout condition for SentinelOne Device Trust. Previously devices would be logged out if SentinelOne reported them as not live, but testing revealed this value was not being consistently reported; live agents would sometimes be marked offline, causing random logouts. The replacement for this condition requires that a device is offline for 15 minutes before that results in an automatic logout. |
2024-01-30 | Server | 83.24.0 | This release allows new certificates to be created for both SSH and RDP without immediately making them active. You can create a certificate, add it to your infrastructure, and then make it active in StrongDM. This enables the certificate rotation process to happen without downtime due to the delay from adding a new certificate. Additionally, previous certificates may be reactivated as a rollback option until they are removed. Certificate Authorities can be managed in the new Network > Certificate Authorities section of the Admin UI. |
2024-01-29 | Desktop App | 21.54.0 | This release restores the missing Connect All menu item to the desktop app menu. |
2024-01-29 | Server | 83.9.0 | This release fixes an issue where some organizations could not see reports in the Reports Library. |
2024-01-26 | Server | 83.4.0 | This release marks the standing access report as no longer in beta. |
2024-01-26 | Server | 83.3.0 | This release fixes a bug in filter functionality for the Access Workflows dashboard. |
2024-01-25 | Java SDK | 6.3.0 | This release adds an SDK vertical to request checks for and retrieve the healthiness of the connections between nodes and secret stores. |
2024-01-25 | Go SDK | 6.3.0 | This release adds an SDK vertical to request checks for and retrieve the healthiness of the connections between nodes and secret stores. |
2024-01-25 | Python SDK | 6.3.0 | This release adds an SDK vertical to request checks for and retrieve the healthiness of the connections between nodes and secret stores. |
2024-01-25 | Ruby SDK | 6.3.0 | This release adds an SDK vertical to request checks for and retrieve the healthiness of the connections between nodes and secret stores. |
2024-01-25 | Server | 82.90.0 | Add pkg and msi installers to the downloads page |
2024-01-25 | Server | 82.89.0 | This release fixes a bug where in rare cases a valid authentication with an admin token or API key would return an unauthenticated error. |
2024-01-25 | Server | 82.88.0 | Slack tokens are no longer revoked after a failed refresh attempt. |
2024-01-25 | Server | 82.87.0 | Update the default filter on the Standing Access Dashboard. |
2024-01-25 | Server | 82.86.0 | This release augments resource update validation in the case when the secret store of the resource is modified. See also Server 82.80.0. |
2024-01-24 | CLI | 40.78.0 | This release allows the Secret Store field on resources to be updated after creation. When transitioning from using a non-Strong Vault secret store to any other, or vice versa, all sensitive credential field values (those hidden in the AdminUI) are reset to ensure they are not exposed in plaintext. The Terraform Provider still recreates resources when their secret store is updated to ensure it doesn't lose track of its state because of the reset sensitive fields. |
2024-01-24 | Server | 82.80.0 | This release allows the Secret Store field on resources to be updated after creation. When transitioning from using a non-Strong Vault secret store to any other, or vice versa, all sensitive credential field values (those hidden in the AdminUI) are reset to ensure they are not exposed in plaintext. The Terraform Provider still recreates resources when their secret store is updated to ensure it doesn't lose track of its state because of the reset sensitive fields. |
2024-01-23 | Server | 82.75.0 | This release fixes a broken banner link for StrongDM email alerts. |
2024-01-23 | Server | 82.74.0 | This release fixes a condition where authentications could take up to several seconds before they were available to use after logging in. |
2024-01-23 | Server | 82.73.0 | This change fixes the filter parameters for the Approvers list in the Access Workflows dashboard. |
2024-01-23 | Server | 82.70.0 | This release overhauls the presentation of Reports Library dashboards. |
2024-01-22 | Server | 82.68.0 | This change fixes a bug with a deprecated authentication mode used by clients beneath 33.17.0, where those authentications were frequently revoked without reason. |
2024-01-19 | Java SDK | 6.2.1 | This change removes some unimplemented snapshot APIs. |
2024-01-19 | Python SDK | 6.2.1 | This change removes some unimplemented snapshot APIs. |
2024-01-19 | Ruby SDK | 6.2.1 | This change removes some unimplemented snapshot APIs. |
2024-01-19 | Go SDK | 6.2.1 | This change removes some unimplemented snapshot APIs. |
2024-01-18 | CLI | 40.73.0 | This release fixes an issue that prevented successful authentication for SSH certificate-based resources that had Secret Store IDs set. |
2024-01-18 | CLI | 40.59.1 | This release fixes an issue that prevented successful authentication for SSH certificate-based resources that had Secret Store IDs set. |
2024-01-18 | Server | 82.54.0 | Added a checkbox in the Admin UI to allow requesters to approve their own requests when they meet the approval criteria for the associated workflow. |
2024-01-16 | Java SDK | 6.2.0 | This release updates the SDKs to enable retrieving configured RDP CAs. |
2024-01-16 | CLI | 40.67.0 | This release adds the 'sdm admin rdp view-ca' CLI command to retrieve the CA used for certificate-based RDP connections. |
2024-01-16 | Python SDK | 6.2.0 | This release updates the SDKs to enable retrieving configured RDP CAs. |
2024-01-16 | Go SDK | 6.2.0 | This release updates the SDKs to enable retrieving configured RDP CAs. |
2024-01-16 | Ruby SDK | 6.2.0 | This release updates the SDKs to enable retrieving configured RDP CAs. |
2024-01-16 | Terraform | 7.1.0 | This release updates the SDKs to enable retrieving configured RDP CAs. |
2024-01-12 | Server | 82.35.0 | This release modifies the behavior of the integration with Slack, including help text and welcome message frequency changes. |
2024-01-12 | Server | 82.30.0 | This release restores the presence of some missing release notes from the /release-notes endpoint. |
2024-01-11 | CLI | 40.63.0 | This release renames the columns of CSV query output to be more consistent between query categories. It also adds three new fields for features in development. |
2024-01-11 | CLI | 40.61.0 | This release adds a new, non-stable server type: SSH (Cert Based with User Provisioning). This new server type is in closed beta and not available at this time. |
2024-01-09 | CLI | 40.57.0 | This release deprecates the sdm admin ssh rotate-ca command. The correct way to rotate SSH CA is through the credential management area in the Admin UI. |
2024-01-09 | Server | 82.11.0 | Admins can now set a fixed duration for access requests on the Workflows settings page of the Admin UI. |
2024-01-08 | CLI | 40.55.0 | This release updates the permissions checked when calling sdm ssh resource-name , fixing a recent regression which prevented user-level accounts from executing this action. |
2024-01-08 | CLI | 40.54.0 | This release fixes an issue that prevented connections to certain resources with an "unable to load credential type for db type" error. This error is resolved. |
2024-01-08 | Python SDK | 6.1.0 | This release adds a Healthcheck verb to the SDKs and the sdm admin <resource-category> CLI trees. From the CLI, one may request a healthcheck via a resource's ID or its name. Note admin tokens are not able to request checks by name if they lack the permission to list resources, as they will not be able to look up the resource. |
2024-01-08 | CLI | 40.51.0 | This release adds a Healthcheck verb to the SDKs and the sdm admin <resource-category> CLI trees. From the CLI, one may request a healthcheck via a resource's ID or its name. Note admin tokens are not able to request checks by name if they lack the permission to list resources, as they will not be able to look up the resource. |
2024-01-08 | Java SDK | 6.1.0 | This release adds a Healthcheck verb to the SDKs and the sdm admin <resource-category> CLI trees. From the CLI, one may request a healthcheck via a resource's ID or its name. Note admin tokens are not able to request checks by name if they lack the permission to list resources, as they will not be able to look up the resource. |
2024-01-08 | Go SDK | 6.1.0 | This release adds a Healthcheck verb to the SDKs and the sdm admin <resource-category> CLI trees. From the CLI, one may request a healthcheck via a resource's ID or its name. Note admin tokens are not able to request checks by name if they lack the permission to list resources, as they will not be able to look up the resource. |
2024-01-08 | Ruby SDK | 6.1.0 | This release adds a Healthcheck verb to the SDKs and the sdm admin <resource-category> CLI trees. From the CLI, one may request a healthcheck via a resource's ID or its name. Note admin tokens are not able to request checks by name if they lack the permission to list resources, as they will not be able to look up the resource. |
2024-01-05 | Server | 82.2.0 | This changeset adds support for IDP initiated logins for SAML, if enabled within one's StrongDM SSO configuration. |
2024-01-04 | Admin UI | 86.20.0 | This release makes some minor bug fixes for filters within dashboards. |
2024-01-04 | Ruby SDK | 6.0.1 | This release unlocks the gemspec for the strongdm ruby SDK expanding openssl from ~> 3.1.0 to ~> 3.1. |
2024-01-03 | Admin UI | 86.19.0 | This release adjusts and improves the user experience for filters within dashboards. |
2024-01-02 | Server | 81.81.0 | This release adds a feature to alert organization admins for when the StrongDM RDP CA is close to expiring. It will send alert emails for the following stages: 30 days before expiration, 2 weeks before expiration, 1 week before expiration, 2 days before expiration, 1 day before expiration, and 2 days after expiration. |
2023-12-22 | CLI | 40.46.0 | This release fixes a regression in the CLI that prevented listing resources with the sdm admin datasources|servers|... list commands with an admin token that had resources list permission but not resource locks list permission. The commands now function when run without resource lock list permission by omitting resource lock status information. |
2023-12-21 | Go SDK | 6.0.1 | This release includes documentation updates. |
2023-12-20 | Admin UI | 86.14.0 | In this release, the Workflows settings page of the Admin UI now allows admins to forbid users from setting a custom duration on requests. Instead, admins can define a fixed duration. |
2023-12-19 | Server | 81.61.0 | This change modifies query storage logic to be more tolerant of queries that may be awaiting processing from recently deleted gateways or relays. |
2023-12-13 | Admin UI | 86.10.0 | This release adds a validation error in the Admin UI if a duplicate ServiceNow URL is configured. |
2023-12-13 | Admin UI | 86.9.0 | This release internally simplifies the flow for requesting RDP replays in the Admin UI, removing possible failure modes. |
2023-12-12 | Server | 81.44.0 | Quotas have been enforced on all customers in order to prevent usage by one customer from impacting StrongDM's availability for other customers. If you see an error due to a quota being exceeded, please submit a request to StrongDM Support to have your quota increased. |
2023-12-12 | Admin UI | 86.7.0 | This release fixes a bug where the revoke option was presented for access requests that can't be revoked. |
2023-12-12 | Server | 81.40.0 | This release modifies the format of the content in access request emails to refer to request duration. |
2023-12-12 | Admin UI | 86.6.0 | This release fixes typos in the integrations page. |
2023-12-11 | Admin UI | 86.3.0 | This release allows non-enterprise users to see reports in a limited manner. |
2023-12-11 | Admin UI | 86.1.0 | This release fixes a bug which prevented the creation of some RDP resource types with specific settings selected. |
2023-12-08 | Server | 81.30.0 | This release expands the time range of valid RDP queries to request replays for in the Admin UI. This range looked back 4500 replays historically, but recent changes brought this limit down to 200. This release expands it to search all historical queries up to an organization's complete query retention range. |
2023-12-08 | Java SDK | 6.0.0 | This release renames approver_id to account_id and adds role_id to the workflow approver vertical. |
2023-12-08 | Python SDK | 6.0.0 | This release renames approver_id to account_id and adds role_id to the workflow approver vertical. |
2023-12-08 | Ruby SDK | 6.0.0 | This release renames approver_id to account_id and adds role_id to the workflow approver vertical. |
2023-12-08 | Go SDK | 6.0.0 | This release renames approver_id to account_id and adds role_id to the workflow approver vertical. |
2023-12-07 | CLI | 40.28.0 | This release adds roles to the CLI interface for workflow approvers, renaming the 'approver-id' flag to 'account-id' in the process. |
2023-12-07 | CLI | 40.27.0 | There was in issue with the SDM client Docker image starting at version 40.8.0 that prevented it from running properly. This issue has now been fixed. |
2023-12-06 | Admin UI | 85.98.0 | This release adjusts the presentation of the auditor report dashboard. |
2023-12-06 | Admin UI | 85.97.0 | When making an access request users can now specify a start date and time. |
2023-12-05 | Admin UI | 85.96.0 | This change migrates some secret stores to be Enterprise bundle features. |
2023-12-05 | Admin UI | 85.95.0 | This change reveals the Admin UI version number at the bottom of the navigation sidebar. |
2023-12-04 | CLI | 40.24.0 | The RDP cert-based driver now supports DRDYNVC, which should allow the driver to support more environments. |
2023-12-01 | Admin UI | 85.91.0 | This change adds cards on the Admin UI's Integrations page for existing integrations, such as secret stores and logging options. |
2023-11-30 | Server | 80.82.0 | StrongDM now enforces a limit of 1,000 resources per organization for new customers. Customers who require more than this should submit a request to StrongDM Support to get their quota increased. Existing customers have been assigned enough quota to at least double their current resource count. |
2023-11-28 | Server | 80.65.0 | This release modifies an error message displayed on one OIDC login error, to more clearly point to the cause of the problem; when a POST to an OIDC server to verify that they did send us a login request occurs, if the response is lacking a token, it usually implies that the configured client secret is invalid, or expired. |
2023-11-28 | Server | 80.64.0 | Fixed an issue where the CLI command sdm access to executed with only a duration would immediately time out. |
2023-11-28 | Server | 80.61.0 | This change restores the ability to provide a start from time for access requests. |
2023-11-27 | CLI | 40.20.0 | This change modifies the proxy used by sdm aws commands to include http:// in the HTTPS_PROXY variable, which otherwise can cause some programs like terraform modules in TF 1.6.3 to reject the variable for the lack of a schema. |
2023-11-22 | Admin UI | 85.90.0 | This change enables the use of Roles to define workflow approvers. |
2023-11-21 | CLI | 40.19.0 | This release resolves an issue where some relays hosted in AWS, using AWS secret stores, but without permission to use IMDSv2, could panic due to an updated AWS Go SDK version introduced in CLI version 40.2.0. |
2023-11-20 | Admin UI | 85.87.0 | This release allows users of the Auditor permission level to interact with access requests as Users, if they belong to the appropriate roles. |
2023-11-17 | Admin UI | 85.85.0 | This release adjusts the presentation of queries in the Admin UI to address bugs where replays would not show as replayable. |
2023-11-17 | Server | 80.50.0 | This release adjusts the presentation of queries in the Admin UI to address bugs where replays would not show as replayable. |
2023-11-17 | Server | 80.47.0 | This release fixes a an issue where, since server version 80.41.0, it would take a manual refresh of the Admin UI for live, complete replays to present as replayable. |
2023-11-16 | Server | 80.44.0 | This release increases the limit of workflows that an organization can have from 25 to 50. |
2023-11-16 | Admin UI | 85.80.0 | This release enables viewing older historical queries in the Admin UI. Previously this view was limited to between 30 and 4500 results, depending on resource category. Now, using date filters, the same query range that can be viewed by users of any given organization can be viewed by those users in the Admin UI as well. |
2023-11-15 | Admin UI | 85.77.0 | This change prevents auditors from being able to see access request approval and reject buttons even if they are selected as an approver. |
2023-11-09 | Terraform | 6.0.6 | This release makes the resource types Aurora PostgreSQL (IAM) and RDS PostgreSQL (IAM) generally available. |
2023-11-09 | Admin UI | 85.72.0 | This release augments the access request workflow modal to respect organization-wide workflow settings for maximum durations. |
2023-11-09 | Java SDK | 5.0.5 | This release makes the resource types Aurora PostgreSQL (IAM) and RDS PostgreSQL (IAM) generally available. |
2023-11-09 | Admin UI | 85.71.0 | This release makes the resource types Aurora PostgreSQL (IAM) and RDS PostgreSQL (IAM) generally available. |
2023-11-09 | Python SDK | 5.0.5 | This release makes the resource types Aurora PostgreSQL (IAM) and RDS PostgreSQL (IAM) generally available. |
2023-11-09 | Ruby SDK | 5.0.5 | This release makes the resource types Aurora PostgreSQL (IAM) and RDS PostgreSQL (IAM) generally available. |
2023-11-09 | Go SDK | 5.0.5 | This release makes the resource types Aurora PostgreSQL (IAM) and RDS PostgreSQL (IAM) generally available. |
2023-11-09 | Server | 80.16.0 | This release makes the resource types Aurora PostgreSQL (IAM) and RDS PostgreSQL (IAM) generally available. |
2023-11-08 | Server | 80.12.0 | This release fixes a bug causing '/sdm access catalog' to not display if it contained resources with more than 6 tags. |
2023-11-08 | Admin UI | 85.70.0 | Notification settings have been added to the Settings > Workflows page which allows you to enable/disable the sending of email notifications. This does not affect Slack notifications (if using the Slack integration). |
2023-11-08 | Admin UI | 85.69.0 | This release adjusts the display of duration text in Access Requests. |
2023-11-08 | Admin UI | 85.68.0 | This release adjusts the display of revoked access request details. |
2023-11-08 | Admin UI | 85.67.0 | This release fixes a bug where the Access Requests page sometimes displayed blank timestamps. |
2023-11-08 | CLI | 40.8.0 | This release upgrades the 'rdpreplay' Docker image to be based on Ubuntu 22.04. |
2023-11-07 | Admin UI | 85.65.0 | This release adds a workflow settings page to the Admin UI. This page currently only has one setting, allowing admins to specify the maximum duration access may be requested for. |
2023-11-06 | Admin UI | 85.64.0 | This release changes the Access Request form to base requests on total duration instead of a 'valid until' time. |
2023-11-06 | CLI | 40.4.0 | This release fixes a rare edge case in idle timeout calculation, where if a user sent over one query per second for the entire duration of their idle timeout, the idle timeout would never be reset and it would log them out as if they had sent no queries. |
2023-11-02 | CLI | 40.1.0 | This release fixes a bug in sdm audit users , restoring visibility into service accounts via this command. |
2023-11-02 | Admin UI | 85.61.0 | This release adds the ability to view and change a user's External ID in the Admin UI. |
2023-11-02 | Terraform | 6.0.5 | This release specifies the weight fields of the Workflows domain as computed in the SDM Terraform Provider. When a computed field is not provided in the configuration, Terraform will not try to update the computed value to null in subsequent execution plans. |
2023-11-01 | Admin UI | 85.60.0 | This release fixes an issue where the Member CID field was not optional as described when setting up the CrowdStrike provider in Device Posture settings. |
2023-11-01 | Terraform | 6.0.4 | This release fixes a bug in the API in which the creation and deletion of WorkflowRoles were not concurrency safe. The bug affected the SDM Terraform provider and any other API consumer that tried to do concurrent creation and deletion of WorkflowRoles. |
2023-11-01 | Server | 79.87.0 | This release fixes a bug in the API in which the creation and deletion of WorkflowRoles were not concurrency safe. The bug affected the SDM Terraform provider and any other API consumer that tried to do concurrent creation and deletion of WorkflowRoles. |