26.8.0 Release Notes

Subject to change until official general availability announcement. Linked documentation may be incomplete or missing until the GA milestone is announced.

This release introduces enhancements across Cloud Control Center, IdentityGraph, Policy, Data Plane, UX / UI, and Data Visibility—along with API changes and configuration command updates.

Release 26.8.0

IdentityGraph

Cloud Workload Enhancements
IdentityGraph extends cloud workload support with Microsoft Azure VM discovery, duplicate IP detection, and Distribution Zone assignment for identity-based microsegmentation:

  • Microsoft Azure VM Discovery and Enforcement — Cloud Control Center now discovers Microsoft Azure virtual machines as cloud workloads. Administrators onboard an Azure tenant using a service principal client secret, and the connector discovers VMs across the tenant, keeping workload attributes and status synchronized with Azure.
  • Duplicate IP Detection — IdentityGraph detects when a cloud workload shares an enforcement IP with a campus device or another workload and determines which identity's policy takes precedence, with campus devices given priority. Workload-to-workload IP conflicts are flagged for administrator resolution.
  • Distribution Zone Assignment and Visibility — Administrators can assign an AWS or Azure discovery endpoint to a specific Distribution Zone, directing discovered workloads into the intended zone. The Workload Details page and IdentityGraph API now include each workload's assigned Distribution Zone.

Entra ID User Display Name
Entra ID users' display names now appear alongside email addresses on the IdentityGraph device details page and when listing or selecting users in Policy Group match criteria, making it easier to identify users at a glance.

User Logon Source Identification
The device details logon history, now labeled User Logons, includes a source column indicating whether each logon event originated from Active Directory or Entra ID, helping administrators who run both identity sources distinguish related events at a glance.

Claroty SSID and Domain Name Policy Group Match Criteria
Policy authors can now match on Claroty-sourced SSID and domain name attributes when building Policy Groups.

Tenable One IP-Only Lookup
The Tenable One connector now supports IP-Only Lookup, matching assets in the Tenable One database by IP address alone for enrichment into IdentityGraph.

ServiceNow Hostname Match Toggle
The ServiceNow connector's advanced settings now include a toggle to enable or disable last-resort hostname matching.

Hostname Source Tooltip
The Elisity Native layer in IdentityGraph now displays a tooltip on the hostname attribute indicating whether the hostname was learned via CDP/LLDP or Reverse DNS.

Device Description Editing
Administrators can now add, edit, and clear a device's description directly from the device static-edit page in Cloud Control Center.

Policy

Policy Matrix Enhancements
The Policy Matrix introduces detailed Custom policy and Security Profile tooltips:

  • Custom Policy Tooltip Details — Hovering over a Custom security profile cell now displays up to five of the profile's actual rule details in the tooltip, with a count of any remaining rules.
  • Security Profile Details — Security Profile details are visible for each policy intersection directly in the Policy Matrix by hovering over a policy cell.

Policy Configuration Review
Administrators can now record that a policy's configuration has been reviewed even when no changes were made, providing an auditable trail for periodic policy reviews. A "Complete Policy Review" button on the policy details Events tab opens a dialog for optional comments and records a timestamped review event with the reviewer identity and any notes.

Trust-Aware Policy Group Suggestions
Policy Group suggestions from Insights now incorporate each connector's verified and trusted status from IdentityGraph, ensuring suggestions stay accurate as connector trust designations change. Staleness checks automatically re-evaluate against current connector trust data, and users can create nested Policy Groups directly from Insight suggestions.

Data Plane

Juniper Mist Virtual Edge Node Enhancements

Juniper Mist Virtual Edge Nodes gain managed flow telemetry configuration, improved endpoint discovery and scalability, and per-port device discovery visibility:

  • Managed Flow Telemetry Configuration — The Virtual Edge now manages NetFlow collector configuration on Juniper Mist switches, automatically keeping the export destination pointed at the active Virtual Edge during failover or rebalancing. Only Elisity-managed configuration lines are added or removed, leaving all other switch configuration intact.
  • Endpoint Discovery and API Scalability — Endpoint discovery on Mist-managed switches classifies ports as user-facing (UNI) or uplink (NNI) and filters out infrastructure devices and endpoints belonging to other switches at the same site. Virtual Edges managing many Mist Virtual Edge Nodes under one organization consolidate API calls behind a shared connection, preventing rate-limit exhaustion at scale.
  • Device Discovery Port Visibility — Device discovery display for Juniper Mist Virtual Edge Nodes now distinguishes user-facing (UNI) ports from uplink (NNI) ports, surfacing only directly connected endpoints.

Discovery Only Mode for Aruba Virtual Edge Nodes
Aruba switches running Elisity's Access Policy implementation now support Discovery Only mode. Turning off the Enable Policy Enforcement toggle in the Add or Edit Virtual Edge Node workflow removes all enforcement configuration from the switch while endpoint discovery and flow telemetry continue uninterrupted.

Workload Distribution Zone Type
Administrators can now create Workload Distribution Zones, a new zone type that isolates cloud and workload mappings from Access and Core zones while supporting import into a Core Distribution Zone and tag distribution via Intelligent Tag Distribution.

Policy and Policy Group Capacity Utilization
The Virtual Edge Node details page now displays Policy and Policy Group capacity utilization alongside Memory, CPU, and Device Mapping metrics, with color-coded thresholds and alerts that give administrators advance notice before policy capacity is exhausted.

Observability

Compliance Snapshot Reports
Snapshot reporting now includes compliance reports that map Elisity capabilities to industry framework controls, starting with IEC 62443, producing coverage scores and evidence-backed audit documentation from live tenant data. Reports can be generated on demand from the Snapshots UI or API, or on a configurable recurring schedule. Snapshot reports can now also be exported in Markdown format, integrating directly into version-controlled workflows and ticketing systems.

Policy Suggestions for Ungoverned Policy Group Pairs
Insights now identifies source-destination policy group pairs with no governing policy and uses a private LLM via AWS Bedrock to recommend an explicit allow or deny policy for each pair, ensuring every communication path is explicitly governed. The LLM evaluates each policy group's configuration directly to generate a tailored suggestion that administrators review and approve before applying.

DNS Analytics
A new DNS Analytics page provides network-wide DNS visibility with request trends over time, top domains, DNS servers, and devices, and a DNS Activity table that can be grouped by device, domain, or server. Selecting a device opens a details view that compares the device's IdentityGraph attributes with a classification derived from its observed DNS activity, helping administrators validate device identity using DNS behavior.

General UX/UI

Device List Readability and Navigation
The Device List page now displays up to 2–3 connector logos per device at a fixed readable size, with a chip indicator that reveals any additional connectors on click. The Hostname column can be pinned to the left side of the list so it remains visible while scrolling, with the pinned position persisting per user.

Custom Connector Import Default
The Custom Connector import UI now defaults to the Merge action, ensuring existing connector data is preserved during imports.

Interface Display in Device Location
The Elisity-discovered interface is now displayed in the Device Location box.

API Updates

API endpoints may be added or updated to accommodate new functionality. Track updates to the API schema in the API Schema Updates Per Release article.

 

New/Updated Commands (Config Command Authorization)

New/Updated Global Config Commands:

Coming Soon

Interface-Level Config Commands:

Coming Soon
Was this article helpful?
0 out of 0 found this helpful