Feature Request

Feature Request

Feature request forum for Devolutions Server

Newest

Most active

Most votes

avatar

lievenvandewalle

configuring read/write offline mode not available via the DVLS web UI

Hello. It's not possible to configure the read/write offline mode via the DVLS web UI. This server setting can only be configured via the RDM client. Would it be possible to make al these system settings available via the DVLS web UI? https://docs.devolutions.net/rdm/ribbon-menu-bar/administration/system-settings/application-specific/cache-offline#windows thank you, Lieven

1

13

1

avatar

Marc-Andre Bouchard

avatar

markusburkhardt

QoL-issue on DVLS-Updates when using sql logins with restriction on the

Good morning Devolutions community, today i updated my DVLS test enviroment for my upcomung update on our production enviroment and i ran into a little quality of life (QoL) issue which i wanted to share. The update went smooth till the DVLS Console started updating the database and wanted to set the permissions on the sql logins for the webapp and scheduler. The reason for this issue is also known and it comes from my end. Due to internal security policys i am not allowed to give permissons higher the default db role "db_owner" in sql server to an app login and since the scritps for setting the least privileges tries to use some sys-views i will run into an error. As workaround right now i always have to run the scripts for settings the permissions manually. This is no big deal, but i little bit anoying. Its also not possible to use domain credentials, because our DVLS is running on an isolated network without domain membership. Since i have a bunch of expirence with sql server i was wondering if it wouldn`t be better to use static database roles? I whould create specific roles for the management tools, scheduler and webapp and bind the permissions on database objects onto them. Then the database admin can add the users into those roles. This would solve this issue and is also more transparent to the database admin. Maybe this will also simplify the internal update process. I am looking forward to the feedback and let me know if further information is needed. Cheers, Markus

1

21

2

avatar

markusburkhardt

avatar

Maxim Robert

Implemented Backlog

Allow users with the Password Policies permission to edit generator templates

CLIENT REQUEST We noticed that only administrators can currently create or edit password generator templates/policies, even for users who have been granted the "password policies" permission, which seems intended to allow exactly that. One of our users mentioned that this was possible for non-admins before. Could this be restored/enabled so that users with the appropriate permission can actually manage password generator templates without needing full admin rights?

0

38

1

avatar

Marc-Andre Bouchard

avatar

gertvanniekerk

Devolutions Server side setting: Close idle sessions when using gateway

Hi Devolutions Were quite new to your product and just had a meeting with one of your Business Solutions Analyst. He confirmed that Devolutions Server does not currently have a server side setting to close out idle sessions. We are exclusively using Devolutions Gateway to reach infrastructure + customers (we're an MSP). In theory it should be possible for the Devolutions Server / Devolutions Gateway to be able to detect when an session is idle and then close it out. Types of entries should ideally include all types of entries used by an Devolutions Gateway, in our example 99% of them are RDP, SSH and web entries. It should be enforced server side, no matter if it's RDM for Windows/Mac or using the web console. Justifications for this feature: Prevent users from hugging entries, other users could think that an user is using an entry while it's actually not in use anymore, if the original user forgot to close the session, this leads to frustration because you would have to verify with that user if they are actually still using it or not. Prevent multiple hour Gateway Session Recordings. We are already seeing some recordings that lasts several hours because of this, we have Windows GPO's to lock the RDP after X amount of minutes, this though results in the recording keep going and showing the Windows lock screen. We only logoff the Windows users when it's been idle for 16 hours. Regards. Gert

1

13

1

avatar

Sébastien Aubin

avatar

cyraxan

Mass entry permissions edit

I'm trying to understand the intended workflow for managing permissions on a large number of entries. The Batch Grant Access dialog allows assigning permissions to multiple users and groups, but it appears to work only for a single entry, folder, or vault . However, I couldn't find a way to assign or modify permissions for multiple selected entries at once. For example, my workflow would be: Search for or select several hundred entries (e.g. all SSH sessions). Select them all (Ctrl+A or multi-select). Grant the LinuxAdmins group View/Connect permissions in a single operation. At the moment, Batch Edit does not include permission changes, and Batch Grant Access seems to support multiple principals but not multiple entries. Is there a supported way to apply permissions to multiple selected entries at once, or is this currently not possible? If this functionality is not available, I would like to submit it as a feature request. It would be extremely useful for administrators managing large DVLS environments with entry-level permissions. Thank you.

1

30

1

avatar

Jonathan Iannone

avatar

cyraxan

ACL-centric reports?

Greetings Is there any way to generate an ACL-centric report? Show every entry where user/group X has explicit or effective permissions. This is required for periodic access reviews and security auditing.

1

23

3

avatar

Hubert Mireault

avatar

tmashos

Configurable log cleanup lengths

We're having an issue with the amount of logs that are in the database. We have a process that logs into devolutions server quite often and that is making our DB grow quite large. I'm requesting the following 3 things A configuration to stop logging access to database and log to file only Configurable shorter than 1 month cleanup (maybe 1 week or less) Ability to prevent logging for a single machine user

1

20

1

avatar

Luc Fauvel

avatar

stephaneforand

Allow DVLS Admin set retention , rotation log period

Allow DVLS Admin set retention , rotation log period, Default = 5 day rotation/retention. and not adjustable ( hardcoded ) Either through a .conf file or via the GUI.. put at least let's allow more flexible, rotation logging

1

32

3

avatar

Luc Fauvel

avatar

swidmann

Restore-DSRole as new Devolutions.Powershell CMDlet

Hey everyone, in Devolutions.PowerShell version 2025.3.3, the Restore-DSDeletedUser cmdlet was introduced. We also require the ability to restore roles from the recycle bin via PowerShell. Unfortunately, the Update-DSRole cmdlet does not support this, and Restore-DSDeletedRole does not exist. I would greatly appreciate the implementation of this functionality. Thank you very much. Sandro Widmann

2

196

3

avatar

swidmann

avatar

Erdinger

Find by name in the PAM vault

Would it be interesting to be able to configure a search by name in the PAM vault? This is possible in the personal vault but not in the PAM vault. It is easy to automate the creation of PAM vaults and the privileged accounts there in via the Devolutions PowerShell module, but less easy to automate in PowerShell the creation of credentials in each user's personal vault. You have to go through a script made available in a shared vault, which will create a DVLS privileged account linked to the PAM credentials vault, not the simplest. Do you think this option is possible? thanks

2

806

25

avatar

Erdinger

avatar

jeremiecharpilloz

Deprecated entries -> Search

Hello, It seems you've decided to remove some entry types from Devolution's newest versions. Seems we will have to replace them all, dispatched on multiple vaults and containers, it could be great (at least !) to have the possibility to search for a specific entry type so we could address the problem more quickly. Thanks. Regards, Jérémie

2

87

8

avatar

Marc-Andre Bouchard

avatar

miccol

Sync licenses with Entra ID group membership

If I'm missing something, i apologize, otherwise I'd like to have something along the lines of the following: All users in our organization are able to access Devolutions Server via SSO and most don't have the need for any other license than WFM. We administer our licenses via en Entra ID group that has been enabled for auto-assign...my issue is when a user logs on to Devolutions Server prior to being a member of the Entra group that grants a license for e.g. Devolutions Launcher...The fact that I then add them to the Entra ID group does nothing within Devolutions. Would it not be possible to enable some sort of sync from Entra ID that runs at an interval? That way I would be able to simply add the user to the Entra group and wait 5-10-15 minutes for the sync to happen and then a license is added to the user. Hope the above makes sense :) Thanks.

1

48

3

avatar

Luc Fauvel

avatar

Maxim Robert

Backlog

Distinguishing Between a Normal Session End and a True Connection Error (Protocol-Independent Error)

CLIENT REQUEST When a session (e.g., RDP) is ended or logged out of normally via the browser on the Devolutions Server, the message “Protocol-Independent Error” still appears. The connection works perfectly fine; the message is purely cosmetic, but it confuses several of our users. Would it be possible to introduce a flag that distinguishes a regular session termination from an actual connection error, so that this message is no longer displayed when the session has been properly terminated?

1

24

0

avatar

Maxim Robert

Backlog

Reduce scheduler error-log noise for expected token validation events (SecurityTokenSignatureKeyNotFoundException)

CLIENT REQUEST Since a few updates ago, we've been seeing recurring "SecurityTokenSignatureKeyNotFoundException" errors from the Devolutions Server scheduler roughly every 10 minutes, even though we don't experience any actual disconnections or malfunction. It would help if this specific, apparently non-impactful event were logged at a lower severity (e.g., debug) instead of as an error, so it doesn't clutter the logs and cause unnecessary concern.

0

27

0

avatar

Maxim Robert

Backlog

Support for Special Characters (e.g., £) in RADIUS MFA Authentication

CLIENT REQUEST We have configured MFA via an external RADIUS server (RCDevs), which works correctly for most users. Users whose passwords contain special characters (e.g., £) are unable to log in because RDM does not correctly recognize these characters, causing the verification on the RCDevs side to fail. Other special characters (e.g., !) work normally. Broader support for special characters in the RADIUS MFA authentication flow would be helpful.

1

32

0

avatar

dave1

Adding the Delinea integration to the web interface of DVLS

Hi Devolutions team We would like to request that Delinea integration is added to the web interface of the DVLS. The reason for this is that our supporting partners and vendors could use web interface, and seamlessly retrieve/inject passwords from the Delinea secret server. This would give us the benefit of: Faster onboarding of a partner Partner does not need to maintain the lifecycle of the RDM/Launcher Partner does not need to "follow" our major version updates of the platform

1

50

1

avatar

François Dubois

avatar

silviedullaers

More functionalities in DVLS for Certificate (X.509) entry type

[image] [image] Hello, We would like to request a feature regarding the X.509 entry type. In RDM, the certificate entry type is deprecated and the recommendation is to use the Certificate (X.509) entry type instead. However, we use DVLS to share certificates with external partners. But in DVLS, this x.509 entry type is really basic and nothing can be done with it. The certificate cannot be opened, saved, viewed... For now, I suggested to continue using the old certificate entry type but I don't want to lose any certificates and certificate info in the near future. Is it possible to consider this in a future release? Thanks Silvie

2

103

2

avatar

Marc-Andre Bouchard

avatar

thibaut-Koesio

DSSO Okta

Bonjour, Une demande concernant l'intégration de Devolutions server - RDM et okta. Nous avons plusieurs application qui s'authentifie avec OKTA et quand nous avons validé une première authentification les suivante ne redemande pas de refaire toute la chaine de connexion (mdp + mfa) Est il possible de faire en sorte que lorsque la personne est validée sur une application par okta, Rdm ne redemande pas le mot de passe, mais envoi directement le push pour garder la sécurité mais gagner en souplesse vis a vis du mot de passe ? Actuellement, quelque soit le moment nous devons refaire l'authentification complète même si on vient de valider une autre application. Difficile d'expliquer correctement par écrit.

1

63

4

avatar

thibaut-Koesio

avatar

schif

Full customization capabilities on secret templates

Hello, To be able to fully customize a secret, eg. create entry templates with fully customized tabs - fields - checkboxes - requirements - required. There are many entry templates available but none of the entries fully fill our expectations and the lack of customization makes it a bit difficult. Currently we can only add custom fields (text/password) on a normally hidden tab that is only visible in advanced view. If there are "required" fields there then the user with simplified view can't even find it. Any other item would also be nice --> checkbox /dropdown menu Ideally we would love to be able to adapt the General tab to cater to our exact setup (adding checkboxes and dropdown menu's as well) Screenshot : 1: to be able to customize table (rename/add/remove) 2: to be able to customize tabe(rename/remove/add) 3: Customize entries --> customize titles 4: Customize fields --> add remove custom fields --> add checkbox / add password field / add dropdown menu with values (from Devolutions itself like Users or custom) / required yes or no 5: Fully customize table --> Default entries/ hide tabs / remove unused tabs [image]

1

47

1

avatar

Marc-Andre Bouchard

avatar

ITOTGuy

Export Vault to CSV or Excel

Devolutions Server currently allows exporting of a vault to an RDM files, but it does not allow exporting to any additional formats. RDM allows for exporting a vault to a number of different file formats. On a routine basis we need to export credentials for clients and customers for them to have hard copies to securely store at their facilities and comply with different requirements. Currently that process involves either a very tedious and manual copy and paste or purchasing RDM to allow us to perform the exports. Please implement the same export vault to CSV or Excel functionality that exists in RDM into Devolutions Server. Also, when initially researching and purchasing the product, I found references to methods to export. I later found out that even the API methods mentioned required purchasing RDM to function. RDM is also expensive just for this single function.

1

53

1

avatar

Marc-Andre Bouchard

avatar

micheleschelfi

Generic OIDC/SAML client for SSO login

Good morning, I am configuring a new DVLS 2026.2 environment. Our company needs to implement an SSO authentication process to allow users to authenticate to the Devolutions Server datasource from Remote Desktop Manager (RDM). From the options currently available in the administrative settings, I can see dedicated configuration sections for Okta and PingOne. Unfortunately, we do not use either of these platforms and would need the ability to configure a generic OIDC or SAML client instead. Ideally, this integration should also support the import and synchronization of users and groups. Is there already a way to achieve this today? If not, would it be possible to consider implementing this functionality in one of the upcoming releases? Thank you.

1

58

2

avatar

micheleschelfi

avatar

jp2000

Grant permissions on sub-entries without requiring read access on parent folders

Summary Currently it appears that you cannot explicitly grant "Connect/View" permissions on a sub-entry without also granting "View" permission on the parent folder containing that entry. I'd like to be able to permission an individual entry directly, so a user can see and connect to only that specific entry, without being granted read access to the parent folder (and by extension visibility of the folder's other contents). Example Folder: SERVER Entry: SVC-1 Entry: SVC-2 Entry: SVC-3 The user should be able to view and connect to SVC-2 only — not SVC-1, not SVC-3, and ideally without needing broad read access on the SERVER folder itself. Current behavior To grant "Connect/View" on a sub-entry, the user must also be given "View" on the parent folder, which exposes the folder structure and potentially other entries. Proposed behavior Allow assigning "Connect/View" permissions directly on an individual entry, independent of the parent folder's permissions. The folder would surface only as the minimal path needed to reach the permitted entry, without granting visibility into its other contents. Benefit Enables true least-privilege access at the entry level, avoiding over-provisioning of folder-level read access just to expose a single entry.

4

108

3

avatar

François Dubois

avatar

maximetremblay

Ajustement automatique de la largeur des colonnes dans les demandes d'accès temporaire

Nous souhaitons soumettre une demande d'amélioration concernant l'affichage de la page des Demandes d'accès temporaire dans Devolutions Server 2026.1 . Actuellement, la largeur des colonnes semble fixe, ce qui fait en sorte que certaines informations importantes, notamment le Nom de la connexion , sont tronquées alors qu'il reste de l'espace disponible dans la grille. Nous avons également constaté que si l'on dézoome le navigateur , les colonnes s'ajustent correctement et le contenu devient entièrement visible. Cela laisse croire que le comportement pourrait être amélioré afin que les colonnes utilisent automatiquement l'espace disponible, sans dépendre du niveau de zoom.

2

46

1

avatar

Simon Arsenault

avatar

support59

Expand Custom Field Options - Entry Templates - Devolutions Server

Please expand the data types available in custom fields. Common secrets people want to protect include the following which would be solvable by having a custom field data type that accepts a file attachment and stores in the DB as an encrypted blob. All of these field types would be addressed by allowing a custom field to be a blob/binary DB storage type. For performance/ease of implementation, I would recommend ~1MB size cap for this type of data, especially since customers can choose to zip/7z/rar/etc before uploading it. Configuration file backups that include passwords and other sensitive data Public/Private key pairs License files for software File-based encryption settings for app configurations API tokens/Azure service principal keys The SSH Keys template seems to have the ability to upload files, tho I would like to see an option to have it kept as a file rather than turned into data in a text field after upload. There are numerous storage formants for sensitive data, and not all of them are text (like a base-64 key pair is), so being able to truly upload a file for secure storage would be ideal.

1

69

3

avatar

Sébastien Aubin

avatar

Marcel Gerber

Schedule a report based on entries tag(s)

Hello. We would enjoy having the possibility to schedule a report based on tags set on entries. Example, we would like to create an automation to synchronize some entries to a different vault, and would set a deleted tag on the destination if the source disappears. Then we could see where there is a problem with such a report. Today we need to create a separate script for such a task. Thank you and best regards. Marcel

1

69

1

avatar

Marc-Andre Bouchard

1 - 25 of 596 items