Database upgrade required
DVLS 2026.3 is required with this version (only if you're already using DVLS)
NEW FEATURES
BREAKING CHANGE Removed support for RDM Jump — Use Devolutions Agent instead
Added a "Deprecated entries" report to identify and convert deprecated entries
Added a "Shrink tabs to fit" option for the session tab bar, with scroll arrows that now appear only when tabs actually overflow
Added a customizable toolbar interface mode, with a customization view for choosing which buttons appear and how they are labelled
Added a local workspace to a Devolutions Cloud workspace migrator
Added a new DNS Manager tool for browsing and managing DNS records on remote systems
Added a new Raw Terminal entry type
Added a satisfaction rating on the About screen and the update available screen, with a group policy to turn it off
Added a search-everywhere box in the main window header
Added a Webcam asset type to IT Asset entries
Added a Windows DNS dashboard entry type
Added back the Tera Term Pro add-on
Added custom user tags to the user management screen for Devolutions Cloud and DVLS workspaces, with a tag color rules configuration in the system setting
Added Devolutions XServer to the tools, with X11 forwarding options in SSH terminal entry settings
Added Jira ticketing dashboard as a new connection type, allowing users to view and manage Jira tickets directly within RDM
Added license administration support for Devolutions Cloud workspaces
Added possibility to edit Devolutions Cloud system settings directly in RDM
Added the ability to create, update, and delete Devolutions Cloud user groups directly from RDM
Added the possibility to add and edit users in Devolutions Cloud workspace
Added vault template support to Devolutions Cloud workspaces, so templates can be created and applied from vault management
Migrated DVLS vault assignments to a role-based permission system
IMPROVEMENTS
DEPRECATED Removed Dropbox and OneDrive data source support
DEPRECATED Removed RDM Jump as a log-off method for RDP entries
DEPRECATED Removed the deprecated PAM dashboard
DEPRECATED Removed the legacy RDM Jump from RDP sessions
DEPRECATED Removed the obsolete "Open embedded" option from the Quick Connect user interface settings
Added a "Custom fields" results option to the "Field options" of the navigation pane search
Added a "My roles" view to role assignments so users can see the roles assigned to them
Added a "Show hidden files" option for FTP entries
Added a "Windows authentication (custom user)" login option to Microsoft SQL Server workspaces, allowing sign-in as a different Windows user
Added a clear button and a loading indicator to the quick search bar
Added a configurable maximum number of backups to keep
Added a confirmation before raising a Devolutions Cloud vault to the High security level, which revokes offline access, and excluded privileged account (PAM) entries from the offline cache
Added a confirmation of the current password when changing the application password in the security options
Added a content preview to the entry overview so note, document and script content can be read without opening the entry
Added a copy action to completed AI assistant responses that preserves line breaks and Markdown
Added a custom naming option when extracting passwords from a password list into their own entries
Added a destination folder picker to the Move to Vault feature
Added a group policy to enforce the Enhanced security option of the offline mode
Added a Help menu tool that captures a performance dump and sends it to support
Added a high contrast sub-theme
Added a keep password in memory option and a configurable multi-factor authentication delay for CyberArk credentials
Added a loading indicator on the entry tree when switching workspace or vault, naming what is loading instead of showing an empty tree
Added a loading indicator when switching vaults so the delay is no longer silent
Added a new Hybrid mode for CyberArk credentials that uses a PSM proxy connection for supported session types (RDP and web) and falls back to credential injection for others
Added a one-time password (OTP) field to the quick search result detail panel
Added a per-entry Ignore certificate errors option toVMWare synchronizer, VMRC and VMware Console entries, and enforced proper certificate validation
Added a segment timeline to the session recording player showing which segments are still being processed, so seeking into one no longer stalls for several seconds before failing
Added a startup logs tab to the Profiler view to help diagnose startup issues
Added a status bar widget showing active VPN connections
Added a warning in the recording player when a recording segment is still being processed, explaining that playback continues but seeking inside that segment is unavailable
Added accent dots in the user and local specific entry settings so active overrides are easy to spot
Added Agent Tunnel management to the devolutions gateway administration panel
Added an automatic migration to a linked credential for entries still using the deprecated embedded credential mode
Added an experimental embedded terminal you can use instead of launching Windows Terminal, enabled from the Windows Terminal entry type options
Added an expired/expiring badge to password list entries
Added an option to configure the auto-close timer for the one-time password and password viewing windows
Added an option to enable or disable just-in-time mode on Azure AD and domain user accounts in the privileged account (PAM) account settings
Added an option to include the mouse cursor in RDP session recordings
Added an option, also enforceable by policy, to reposition or hide the Domain field in the RDP credential prompt
Added automatic clearing of completed transfers in the file explorer, along with an option to control it
Added automatic hiding of sensitive actions (reveal password, copy, open URL) in an entry's overview and menus when the entry still requires a check-out
Added automatic migration of legacy website entries to the current website session type
Added Azure Bastion support for virtual machine scale set instances
Added certificate trust management for Active Directory privileged account (PAM) providers, so domain controller certificates can be reviewed and trusted from the provider settings and the PAM onboarding wizard
Added chart editing to the spreadsheet editor for document entries
Added Chat and Remote Log modes for ControlR entries
Added clickable links for URL hosts shown in the password list entry overview
Added CPU and memory usage display for Hyper-V virtual machines
Added CPU and memory usage display to the status bar
Added date and random character tokens to the password generator's pattern mode, making it possible to create patterns that automatically embed the current date or a block of random characters each time a password is generated
Added Delete and Preserve recording options in the Recordings tab
Added Description and Username columns to the Passwordstate account selection list, making it easier to pick the right account
Added Devolutions Cloud maintenance and outage details to connection error notifications, pointing you to the status page during a service disruption
Added Devolutions Gateway routing for PowerShell and SSH script tools, so scripts can now reach hosts that are only accessible through a gateway
Added Devolutions Send region support
Added display of PSU license information in the license details
Added drag multi-selection to the file explorer entries (selection square)
Added error handling to the Submit ticket flow so failures now report a message instead of failing silently
Added granular privileged access management (PAM) usage policies for add-on entry types, so administrators can enable PAM for a specific add-on such as SQL Server Management Studio instead of all add-ons at once
Added HaloPSA as a ticketing vendor
Added keyboard simulator, key delay and Unicode-to-scan-code options to the Clipboard settings, so Type clipboard behavior can be tuned without editing the configuration file
Added license, user and user group management for Devolutions Cloud workspaces through RDM
Added local AI voice dictation support
Added local caching and cache cleanup for contact entry avatar (Gravatar) images
Added main menu items, shortcuts, and reports to the quick search (Ctrl+K)
Added more drag and drop support to the embedded file explorers, including Amazon S3 and Azure Blob Storage
Added multi-selection in the attachments list so several files can be sent at once with the Devolutions Send feature
Added OTP support for Hudu entries
Added PAM checkout extension support for Devolutions Cloud workspaces, letting users request an extension on an active checkout and approvers review, approve, deny, or assign a reviewer
Added PAM default settings for DVLS workspaces
Added PAM permission sets to the batch grant permission dialog
Added Password Depot REST API v2 support
Added password rotation for privileged account (PAM) providers, with a new provider credential setup screen
Added per-column search in the application's data grids
Added possibility to encrypt local files with Windows Hello
Added possibility to manage cached authentication for Secret Server and CyberArk credentials
Added PowerShell Remoting over SSH support, using RDM's own SSH and gateway flow with native host-key prompts
Added privileged access management (PAM) provider self-rotation for Devolutions Cloud workspaces, so a provider's own account can be created, viewed, checked out and edited from the PAM management view
Added security key support to the Keeper sign-in flow
Added separate keyboard shortcuts for quick search and search everywhere in the header
Added session recording log support, including a new recording log viewer tab and activity logging in the Active Directory console
Added Simple and Advanced modes to the SSH VPN (tunnel) type for easier configuration
Added single sign-on to Proxmox entries, with the authentication realm list provided by the server
Added SSH key support to the Bitwarden synchronizer
Added support for configuring a custom AI proxy provider (with custom headers) in the AI assistant settings
Added support for entering a verified domain instead of the directory ID in the Azure Bastion tenant field
Added support for moving PAM entries, including by drag and drop in the entry tree and through the PowerShell module
Added support for multiple active ticketing systems
Added support for requesting, approving, and tracking time extensions on privileged account (PAM) checkouts, with approval workflow and expiration warnings
Added support for tags in the Proxmox dashboard
Added support for the just-in-time account mode option on privileged account (PAM) entries in Devolutions Cloud workspaces
Added support for upgrading PostgreSQL workspaces
Added symbolic link icons for linked folders and files, plus broken link indicators in SCP entries
Added system settings for Devolutions Cloud workspace
Added the ability to configure the position of the AI chats panel
Added the ability to create entries directly from the CyberArk dashboard
Added the ability to download a whole session recording as a single ZIP file from the recordings list
Added the ability to extend your trial period
Added the ability to import and export vaults that contain privileged account (PAM) entries; PAM accounts and providers are excluded automatically, with a caution banner when any are left out of an export
Added the ability to inject secrets into AI agents through the Devolutions CLI
Added the ability to print or save your Devolutions Cloud recovery key as a PDF, and redesigned the recovery key validation screen
Added the ability to reset a contractor user's password from the Users management view when connected to a Devolutions Server that supports it
Added the ability to select several PAM providers at once when assigning an administrative role
Added the ability to set a custom message before an entry's status expires in the entry properties
Added the ability to use the Move action on a sub-entry to detach it from its parent
Added the account expiration date to user management
Added the Attachments tab to the dashboard of synchronizer entries
Added the auto-assign group limit for Devolutions Cloud licenses (previously available only for DVLS)
Added the configuration state of each YubiKey slot, so you can see which slot is already programmed before overwriting it
Added the Devolutions Desktop Extension, letting Windows applications and browsers use passkeys stored in RDM
Added the user vault to the tray icon menu
Added ticket number and reviewer selection to privileged account (PAM) check-out and extension requests on Devolutions Cloud, with a required-field indicator when a reason or ticket number is mandatory
Added ticketing operations (list pending tickets, look one up, add comments, log work, and change status) to the AI assistant
Added transfer type, text file extension list, and local and remote line ending settings to SFTP and SFTP-in-SSH connections
Added trial status screens shown when your trial is active or has expired
Added user and user group import and synchronization, with scheduling and cleanup, to DVLS user management
Added vault selection to the credential reference report
Added voice dictation to the AI assistant chat input and the contextual AI prompt
Changed privileged account (PAM) vault creation and listing to follow the general vault permissions instead of separate PAM-specific rights (on DVLS 2026.3 and newer)
Further improved the trial workflow, refining the messaging and available actions on the license and trial screens
Improved Apple Remote Desktop connection settings with a tabbed layout (General, Advanced, and Settings tabs)
Improved application startup performance
Improved compatibility when the embedded terminal launches a Windows Terminal profile, including Store-installed profiles and profiles that run elevated
Improved entry loading speed by no longer re-requesting attachment and documentation counts that were already retrieved
Improved favicon, Gravatar, and contact image caching while offline
Improved forbidden passwords to be able to create and configure multiple password lists
Improved IT asset search by merging it into Advanced search as a preset
Improved link handling when opening a browser, now restricting URLs to HTTP/HTTPS and defaulting to HTTPS when no scheme is provided
Improved Linked External Vault credential entries to support list-based selection
Improved move to vault, keeping credentials that stay in the previous vault linked as cross-vault links so they still resolve
Improved performance when opening entry properties by loading time zone data only when needed
Improved session recording performance
Improved startup time by no longer running the application signature check unless analytics are actually being sent
Improved startup time by no longer waiting on the Devolutions Account check at launch, so an unreachable account service no longer delays the application
Improved the "Clear all" action for server notifications so it clears everything in a single operation while keeping pinned notifications intact
Improved the AI Assistant, including the conversation transcript, activity feedback, tool approvals and support for more model providers
Improved the automation experience by splitting the combined Macro, Script & Tools area into separate Tools and Automation sections
Improved the check-out selection prompt to expand all folders when it opens
Improved the dark theme to use the Devolutions dark blue palette
Improved the Devolutions Cloud sign-in during onboarding by collapsing the two separate logins into a single step
Improved the Devolutions Send integration
Improved the existing log file prompt in SSH entries with an explicit "Proceed without logs choice", while Cancel now aborts the connection
Improved the layout of the application logs view
Improved the main window search and changed the default Quick Connect shortcut to Ctrl+K
Improved the MCP server configuration dialog with an explicit Login action
Improved the quick search results experience
Improved the session comment dialog to load ticketing-system tickets in the background, so it no longer stalls while opening
Improved the startup experience so the toolbar and search bar stay hidden until the app finishes loading, showing a "Loading…" title in the meantime
Improved the template entry-name options when creating an entry from a template, replacing the "keep template name" checkbox with a clearer selector (unchanged, template name, or custom name)
Improved the workspace selector with favorites, grouping, and local branding
Improved ticketing system settings for Jira, ServiceNow and HaloPSA to be able to reference a credential entry
Improved VNC server key trust so a key you approve for a host is now recognized by every VNC engine instead of only the one you approved it with
Made the status-bar license indicator clickable to open license details
Merged PAM vaults with regular vaults for Devolutions Cloud workspaces
Moved the account view into the main window title bar
Moved the security settings into the entry properties simplified view
Multiple startup performance improvements
Prevent the application from stealing focus when launching
Removed obsolete local and user-specific settings for information type entries
Removed privileged account entry types from user vaults and from vaults that are not marked high security
Removed the JIT account mode section from privileged account (PAM) entries for a provider's own managed account, where it never applies
Removed the Jump Approach selector so all jumps now use the Devolutions Agent, and existing entries keep working automatically
Renamed the "Linked (external vault)" label to "cross vault"
FIXES
Added automatic recovery from a corrupt offline cache file, so a damaged file no longer causes errors on every refresh
Fixed a failed SFTP file drop giving no error
Fixed a linked credential being ignored as the Azure Bastion sign-in hint
Fixed Advanced search results not letting you navigate to an entry located in a user vault or the System vault, and stopped listing entries that cannot be opened from the tree (templates, overrides and forbidden password lists)
Fixed application freezing while waiting on 1Password
Fixed application not closing when it was exited while still waiting on a background task
Fixed Azure Bastion tunnels interfering with each other when several sessions are opened at the same time
Fixed changing the application password re-encrypting shared key (.shk) files of workspaces that do not use it, which left those key files unusable
Fixed clicking the taskbar button not restoring the application when it was minimized and set to stay hidden from the taskbar
Fixed Devolutions Send attachments being capped at 1 MB instead of 30 MB
Fixed editing a PAM provider's managed account erasing its stored password, which silently broke that provider's heartbeats and rotations
Fixed encrypted XML workspaces saved by older versions failing to open
Fixed encryption issue when changing the application PIN code
Fixed free Devolutions Cloud users being unable to start a trial while working in their user vault
Fixed FreeRDP sessions reconnecting endlessly when smart reconnect is enabled
Fixed Gateway recording playback failing when the Gateway certificate is not trusted, so the certificate prompt now applies to the recording clips too
Fixed Gateway recordings showing an SSL error when viewed and saving nothing when downloaded, on Gateways with an untrusted certificate
Fixed issue where vault assignments report was available to users without the vault assignments view permission
Fixed issues connecting with the Veeam add-on
Fixed keyboard input lag in other applications while the application was starting up
Fixed loading speed for Devolutions Cloud users without access to any shared vault
Fixed managed account actions and heartbeat status not working on the PAM providers dashboard
Fixed Microsoft sign-in being prompted again for every session opened through a shared Azure Bastion entry
Fixed offline access to vaults that do not allow to be cached in Devolutions Cloud workspace
Fixed offline data becoming unreachable for the whole workspace after switching to a vault that has offline access disabled
Fixed privileged accounts managed by a newly created PAM provider showing no provider at all, which left them impossible to edit or save
Fixed RDP sessions showing password and certificate prompts, or reconnecting, on a tab that was already closing
Fixed Secret Server entries that connect through a proxy showing the proxy address instead of the original host in the session tab information
Fixed session recording through MsRdpEx failing because a required native component was missing from the installation
Fixed temporary access ending at the time originally requested instead of the time the approver granted
Fixed the $HOST$ variable resolving to the proxy address instead of the entry's original host when resolving CyberArk and Secret Server credentials
Fixed the Delinea Secret Server single sign-on flow stalling on the intermediate login page instead of continuing automatically
Fixed the destination vault list in PAM account discovery offering vaults that cannot receive the imported accounts
Fixed the DVLS login loop and the freeze after cancelling a login
Fixed the privileged account (PAM) check-out prompt refusing a start time scheduled later than the current time
Fixed the Secret Server account selection dialog listing every account twice on first load
Fixed the thumbnails view not showing previews for RDP sessions that use the new ActiveX client
Fixed the title-bar quick action buttons (Edit, Quick Connect) staying interactive while RDM is locked; they are now hidden on the lock screen
Fixed vaults missing from the target vault list when configuring privileged account (PAM) account discovery
Fixed web autofill field discovery to honor the connection's Ignore certificate errors setting, so fields can now be detected on sites using self-signed certificates