26.7.0 Release Notes

Subject to change until official general availability announcement. Linked documentation may be incomplete or missing until the GA milestone is announced.

This release introduces enhancements across Cloud Control Center, IdentityGraph, Policy, Data Plane, UX / UI, and Data Visibility—along with API changes and configuration command updates.

Release 26.7.0

IdentityGraph

AWS Cloud Workload Policy
Elisity now extends identity-based segmentation to AWS cloud workloads. Administrators connect Cloud Control Center to an AWS account using an IAM role, then view each workload's network interfaces alongside their Policy Group assignments and lock status. Workload Policy Groups appear in the Policy Matrix beside campus device groups, so one matrix defines and enforces policy across campus and cloud.

Device Label Management
Device labels are now managed centrally from a label library in Settings, organized into shared hierarchical folders, with bulk move and delete, search, filtering, and XLS import. Role-based access control governs who can create, modify, or delete labels. Labels can be assigned or removed from the Devices page, from within Policy, and through the device API.

Tenable One OT and Vulnerability Enrichment (Beta)
The Tenable One connector, now labeled Beta in Cloud Control Center, brings a much richer set of OT data into IdentityGraph. Device Details shows OT criticality, risk, vendor, model, firmware, location, and tags, along with vulnerability and weakness counts by severity. Several of these are available as Policy Group match criteria, bringing OT risk context into segmentation policy.

Palo Alto Cortex XDR IdentityGraph Connector
Elisity now supports Palo Alto Cortex XDR as an IdentityGraph connector, enriching device records with endpoint security data. The connector supports multiple instances per tenant, so organizations can ingest endpoint data from separate Cortex XDR environments.

Connector Page Enhancements
The Connector List now shows how many devices each connector has enriched, and the count links to the Device List pre-filtered to that connector. Connector settings now open in a dedicated full-page view instead of a side drawer, split into a primary section for common settings and an Advanced section.

Custom Connector Enhancements
Custom Connectors support more custom attributes and finer control over enrichment:

  • Expanded Attribute Limits — Up to 30 predefined string attributes, up from 15, and 10 integer attributes, up from 5, per connector.
  • Offline Enrichment Toggle — Advanced settings now control offline device enrichment per connector instance.

Multiple RBAC Roles per User
Users can now hold more than one RBAC role. Cloud Control Center accepts every group an identity provider returns rather than only the first, and administrators can assign multiple roles to local users from User Management. A user's site scope is the union of the sites granted by their roles, so access spanning several sites no longer requires a dedicated role for each combination.

Policy

Nested Policy Groups
Nested Policy Groups now cover workloads, add role-based access control per branch of the hierarchy, and make inherited policy easier to read in the Policy Matrix:

  • Hierarchical Workload Groups — Workloads organize into a folder tree, for example by cloud provider, account, and environment, with per-interface detail for the selected node.
  • Parent-to-Child Policy Cascade — A policy applied to a parent group cascades to every group nested beneath it. Child groups can also carry their own policies, which may differ from the parent and from one another.
  • Role-Based Access Control per Branch — Administrators can grant a user management access to a single branch of the hierarchy, delegating policy management for a business unit without granting it everywhere.
  • Inheritance Display — Policy Matrix tooltips and cell labels distinguish overwritten from inherited policies, and folded groups show a policy count.

Workload Policy Groups
Workloads such as VMs and containers are now a full policy dimension alongside devices. A Workload Policy Groups tab supports creation, editing, duplication, nesting, and deletion with the same filtering, CSV export, and role-based permissions as Device Policy Groups. Enforcement models a workload as a distinct entity with multiple IP addresses, and Policy Matrix filters let each side target Devices or Workloads independently.

Access Policy for Aruba CX
Policy for Aruba CX deployments is configured through Access Policy, a dedicated view of the Policy Matrix where each Policy Group is assigned an ordered set of allow and deny rules. Three profiles are included: Deny Default, Permit All, and Internet Only.

Policy-Scoped Asset Counts
Asset counts on Policy Sets and in the Policy Matrix now reflect the assets affected by each policy intersection, giving reviewers an accurate view of how many assets a change will impact before approval.

Policy Matrix Filter Enhancements
Selecting a Policy Group already chosen on the opposite side of a filter now moves it to the new side, and a one-click button swaps Side A and Side B including their entity types. Policy Group options are scoped per side to the selected entity type, and switching a side's type clears that side's filters.

Data Plane

HPE Aruba CX Switch Support
Elisity now supports HPE Aruba CX switches as Virtual Edge Nodes. Devices connected to Aruba CX switches are discovered, enriched, and classified in Cloud Control Center like any other device, and Elisity enforces policy on them using the switch's native Aruba roles.

Virtual Edge Support for AWS
The Virtual Edge is now available as a versioned AWS AMI for deployment into a customer's AWS VPC. Once launched on EC2, it registers with Cloud Control Center and integrates with standard VPC networking including subnets, security groups, and ENIs.

External Endpoint Discovery Management
Individual Virtual Edge Nodes can be designated as externally managed for endpoint discovery on Cisco switches, allowing coexistence with third-party device-tracking tools. The Virtual Edge continues to discover and classify endpoints from the switch's existing device-tracking data without overwriting the external tool's configuration, and the Endpoint Discovery tab becomes read-only. An Actual Status column shows the configuration running on the switch beside the expected state, highlighting mismatched interfaces.

Observability

Extended Analysis Periods for Insights and Elastic Access
Insights and Elastic Access adhoc analysis, including simulated policy, activation readiness, overly permissive policy, and custom policy checks, now supports time ranges spanning multiple months. Longer lookback captures infrequent patterns such as monthly backups and quarterly maintenance windows.

API Updates

API endpoints may be added or updated to accommodate new functionality. Track updates to the API schema in the API Schema Updates Per Release article.

 

New/Updated Commands (Config Command Authorization)

New/Updated Global Config Commands:

No Updated Global Config Commands

Interface-Level Config Commands:

No New Interface-Level Config Commands
Was this article helpful?
0 out of 0 found this helpful