Feature Request

Feature Request

Feature request forum for Devolutions Cloud

Newest

Most active

Most votes

avatar

bbultitude

Expose Session GUID in Hub SIEM Cmdlets

Why this is needed Due to the lack of a central method for viewing all Devolutions Gateway session recordings across multiple Gateway servers, we are developing an internal solution to collect recording metadata from each Gateway. To correlate recordings with session activity, we need to match the Session GUID contained within the recording metadata to the session information returned by the Hub SIEM PowerShell cmdlets. Currently, there is no supported method to perform this correlation. Requested Enhancement Add the Gateway Session GUID (SessionId) to the output of the following PowerShell cmdlets: Get-HubSiemLogsDaily Get-HubSiemLogsWeekly Get-HubSiemLogsMonthly Technical Requirement The Session GUID returned by the SIEM cmdlets should match the Session GUID embedded within Gateway session recording metadata. This would allow customers to: Correlate Gateway recordings with SIEM log entries. Associate recordings with users, accounts, vault entries, approvals, and session events. Perform audit, compliance, and forensic investigations using supported APIs and cmdlets. Eliminate the need for unsupported workarounds to match recordings to session activity via timestamps. Expected Outcome A unique Session GUID field is included in the SIEM cmdlet output, allowing direct correlation between Gateway session recordings and the corresponding Hub session records.

1

13

1

avatar

Luc Fauvel

avatar

martin_tsaguekifack

Add Security Audit Events as Webhook Triggers

Hello Devolutions Support Team, We are currently configuring a webhook integration with Splunk to forward security-relevant events from Devolutions. In the current webhook configuration screen, only a limited set of triggers appears to be available [image] For security monitoring and SIEM ( Splunk ) integration purposes, we would like to request that additional security audit events be made available as webhook triggers. The goal is to send these events in near real time to Splunk for alerting, investigation, and compliance monitoring. Could you please add support for the following security-related events as webhook triggers? AttachmentPasswordRevealed EntryPasswordRevealed EntrySensitiveRevealed EntryPasswordUsed EntrySensitiveUsed EntryCredentialsViewed EntryPasswordCopied EntrySensitiveCopied EntryPasswordReset EntrySendPasswordCopyInApp EntryExported EntriesExported VaultPasswordsAnalyzed VaultUsedOffline VaultUsedAutofill VaultEntriesWithStatesUsed LoginSuccess Logout UserDeleted UserEdited UserCreated GroupDeleted GroupEdited GroupCreated SystemSettingsEdited ChangeOwner InvitationCreated InvitationRevoked EntryCheckout EntryCheckin EntryCheckoutApprovalRequestCreated EntryCheckoutApprovalRequestApproved EntryCheckoutApprovalRequestDenied EntryCheckoutApprovalRequestGranted EntryCheckoutApprovalRequestRejected EntryCheckoutApprovalRequestCancelled EntryCheckoutApprovalRequestCompleted EntryCheckoutApprovalRequestUpdated EntryCheckoutApprovalRequestRevoked EntryTemporaryAccessRequestCreated EntryTemporaryAccessRequestApproved EntryTemporaryAccessRequestDenied EntryTemporaryAccessRequestRevoked EntryTemporaryAccessRequestGranted EntryTemporaryAccessRequestRejected EntryTemporaryAccessRequestCancelled EntryTemporaryAccessRequestRevokedByApprover EntryTemporaryAccessRequestRevokedForUser EntryTemporaryAccessHasExpired EntryTemporaryAccessRequestGrantedWithDependencies EntryTemporaryAccessRequestApprovedWithDependencies VaultAccessRequestCreated VaultAccessRequestApproved VaultAccessRequestCancelled VaultAccessRequestDenied LucidSyncUserAdded LucidSyncUserEdited LucidSyncUserDeleted LucidSyncUserDisabled LucidSyncGroupAdded LucidSyncGroupEdited LucidSyncGroupDeleted GatewayDeleted GatewayAdded GatewayEdited GatewaySessionTerminated GatewaySessionOpen GatewaySessionFailed GatewaySessionClosed PAMProviderDeleted PAMProviderAdded PAMProviderEdited PAMAnyIdentityTemplateDeleted PAMAnyIdentityTemplateCreated PAMAnyIdentityTemplateUpdated PAMScriptTemplateDeleted PAMScriptTemplateCreated PAMScriptTemplateUpdated PAMCheckoutPolicyDeleted PAMCheckoutPolicyCreated PAMCheckoutPolicyUpdated PAMAccountLifecyclePolicyDeleted PAMAccountLifecyclePolicyCreated PAMAccountLifecyclePolicyUpdated PAMSshJitTemplateDeleted PAMSshJitTemplateCreated PAMSshJitTemplateUpdated PAMSecurityGroupRiskDeleted PAMSecurityGroupRiskCreated PAMSecurityGroupRiskUpdated RegenerateAppIdentitySecrets GenerateEmergencyKey GenerateRecoveryKey SharedPasswordWithDevolutionsSendEmail SharedPasswordWithDevolutionsSendLink SendEmail SendLink These events are important for detecting and investigating actions such as: Credential or sensitive data access Password reveal, copy, reset, or sharing Entry and vault exports Temporary access requests and approvals Checkout and check-in activity PAM configuration changes User, group, and permission changes Emergency or recovery key generation Application identity secret regeneration This enhancement would significantly improve our ability to integrate Devolutions with Splunk and strengthen our security monitoring posture. For context, before recommending the use of Azure Log Analytics or PowerShell commands to extract these logs, we would like to clarify that we have already evaluated both approaches. Unfortunately, neither option provided satisfactory results for our security monitoring requirements. In the case of Azure Log Analytics, we also submitted a feature request, but it appears that implementing the requested functionality may not be straightforward. Azure Log Analytics Integration – Log Content Enrichment & Structured Fields for SIEM - Devolutions Forum Because of these limitations, we explored the webhook option. This approach produced much better results and appears to be a more suitable solution for forwarding security events to Splunk in near real time. However, the current webhook implementation is significantly limited by the small number of available triggers. To support effective SIEM integration and security monitoring, we would need additional security-related audit events to be exposed as webhook triggers.

6

39

1

avatar

Luc Fauvel

avatar

Yoffstr

Scheduled reports - test report button

Hi guys, Are we able to have a "test report" button implemented, so that when we test and see ehow the reports will come out and make adjustments accordingly, without having to wait for the report scheduleed time?

1

22

1

avatar

Luc Fauvel

avatar

Yoffstr

Cloud Services - Reporting Service - High Availability

As per the guidance of the devolutions team in thread: Cloud Services - Encryption and Reeporting Services - High Avilability I am creating this thread, for the discussion around Cloud Services - reporting service - high availability feature request. kind regards

1

37

3

avatar

Luc Fauvel

avatar

clacombe

Devolutions Cloud - Possibility to move popup windows when entering information instead of a fixed one .

When I edit an entry, the popup windows is fixed in the center but frequently I need to check previous entries I already did specially for password lists. I understand to keep the focus on that windows but if we could move it .... [image]

1

32

1

avatar

Dominic Dansereau

avatar

Yoffstr

Cloud Services - Encryption service - high availability

As per the guidance of the devolutions team in thread: Cloud Services - Encryption and Reeporting Services - High Avilability I am creating this thread, for the discussion around Cloud Services - Encryption service - high availability feature request. kind regards

1

46

5

avatar

Yoffstr

avatar

Yoffstr

Duplicated

Cloud Services - Encryption and Reeporting Services - High Avilability

Hi, is it in the roadmap, like the PAM servie high avilability. that the encryption and reporting services will be able to have the same high availability setup, controlled from within Dev Cloud. Kind regards

1

61

7

avatar

Luc Fauvel

avatar

Yoffstr

Session recordings stored within devolution Cloud

Hi, Instead of having the recording of sessions stored on the gateways / RDM / externally stored. Can we have it that the sessions recordings are stored in devolutions cloud, as this will help prevent tampering and ease of management.

1

88

3

avatar

Luc Fauvel

avatar

clacombe

Password list entry type

Have the possibility to duplicate entry and then enter in edit mode to modify only user and password for example, Keeping type host , description etc. To reduce number of entries we use password list to specify all entry types for servers for admin users EX: 2 or 3 ssh account, 2 or 3 mysql account for different usages etc.

1

47

5

avatar

Dominic Dansereau

avatar

marcgauthier

Rust Desk Entry Detail

Hello, In Devolution Password Manager Web Interface for a RustDesk entry See the HOST and Password like other entry. Allow modifications and copy Thank Youl

1

75

3

avatar

William Alphonso

avatar

renecharbonneau

Whitlist more than one IP(v4) address for Application identity

When we enforced SSO for our admin users on Devolutions Hub Business, we were adviced to create an application identity with admin level access to our business hub so we could connect via Powershell and disable SSO enforcement in case of emergency. We did that and wanted to "lock down" the public IP addresses that are allowed to sign into the Powershell API. Sadly we realized that - as of now - only one IP(v4) address per application identity can be whitelisted (automatically during first powershell connection). Since we have multiple offices and each offices has one to two WAN connections with different public IPs, we would like the ability to (manually) whitelist more than one IP(v4) address per application identity.

1

275

2

avatar

Erica Poirier

avatar

hnn

Add the Entra ID SSO for web interface

I can't start the session from web interface due to the account use Entra ID SSO authenticate into the target server. I would like the web interface to support the "Enable Entra ID SSO" option in the future

1

40

1

avatar

ddansereau444

avatar

martin_tsaguekifack

Add Native Password Safe / PwdSafe Import Support in Devolutions Cloud

We are migrating from Password Safe / PwdSafe to Devolutions Cloud , but there does not appear to be a dedicated import template for Password Safe. Devolutions Cloud supports CSV/JSON imports from several password managers, but Password Safe/PwdSafe requires manual reformatting and field mapping. This creates additional migration effort and increases the risk of missing data or incorrect imports. Please consider adding a native Password Safe / PwdSafe import option under Help & tools → Import , with support for common fields such as title, group/folder, username, password, URL, notes, custom fields, created/modified dates, and password expiry. This would make migrations from Password Safe to Devolutions Cloud much easier, safer, and faster.

5

86

4

avatar

martin_tsaguekifack

avatar

garethjohnstone

Google Workspace SSO

For Hub Business, Similar to how you have Microsoft and Okta, it would be great if you could also support Google Workspace as an SSO provider.

1

321

3

avatar

Luc Fauvel

avatar

tobiasschiessl

search for username

Hi all, maybe there is already a feature for this and I don't find it :-) It would be great to have the possibility to search for different fields in the entries. E.g. to search for the "username" in an entry. in RDM we have the possibility to active "include username" in the search filed options. This would be great to have it also in Password Hub Web. Best regards Tobias

0

392

3

avatar

ddansereau444

avatar

rvosmeijer

Disable export functionality for users's personal vault.

Hello, I would like admins to be able to disable the export functionality for a User's personal vault. ideally i would like to set this as default for the whole system/tennant. thanks in advance!

1

353

8

avatar

rvosmeijer

avatar

mariuszkunicki

Implemented

Send request for Temporary access to more than 1 approvers

Hello, Can we please get the ability to send requests for temporary access to more than a single approver at a time? There're situations in life like sick days, vacations, days off, g eneral unavailability and these requests sometime 'sit' for days... It would be nice to have a fallback or a secondary person receiving them at the same time. [image]

2

330

5

avatar

Maxim Robert

avatar

Fabian

Automatic RDM Updates via Devolutions Cloud

We want to update our users to specific versions via Settings in our Business HUB. On the SQL Database version, it was possible to set it to a minimum, so our users would get prompted on next RDM start. We don't want to use the 'always build new MSI and deploy it' method. It interrupts our users while they work and can be buggy.

2

310

4

avatar

Hubert Mireault

avatar

clacombe

Tree structure: Have the choice to change sorting order

I would like to be able to see Entries before Subfolders when I look at Vault content. In a subfolder I prefer to see main entries on top and less important Entries stored in subfolders ! I asked Chatgpt : Current behavior The tree view is typically sorted as follows: Folders (subfolders) first Entries second Sorted alphabetically within each group This behavior is fixed in the web interface and in Remote Desktop Manager when connected to Hub Business.

1

150

1

avatar

Hubert Mireault

avatar

patrick_alphonso

Azure Log Analytics Integration – Log Content Enrichment & Structured Fields for SIEM

Summary: The current Azure Log Analytics integration (cutom log) sends logs that are too sparse for real-world SIEM usage (Microsoft Sentinel, Splunk, etc.). We are requesting enrichment of the log schema and the Message field content. Issues Identified: 1. No readable user identity The UserID field only contains a GUID. A workaround using Get-HubUser was suggested, but this requires a manual PowerShell join and is not viable at scale in a SIEM. The UserDisplayName / Username should be natively included in each log entry. (Note: We understand a dev ticket has been opened for this — thank you. We are adding it here for community visibility and prioritization.) 2. Message field is too vague The current content of the Message field does not allow an analyst to determine what action was performed (read, create, modify, delete, login, etc.), on which resource (vault, entry, group, policy), from which source IP or client, or with what result (success, failure, denied). 3. Missing structured/queryable columns For a SIEM like Sentinel or Splunk, a flat text blob is insufficient. Logs should expose distinct, typed columns. At minimum, the following fields are expected: ActionType — e.g. EntryRead, VaultModified, UserLogin, PolicyChanged ResourceName — name of the vault or entry affected ResourceType — e.g. Vault, Entry, Group, Policy SourceIPAddress — origin IP of the request Result — e.g. Success, Failure, Denied UserDisplayName — human-readable username VaultName — name of the parent vault 4. No User Behavior Analytics (UBA) logs UBA is currently not a supported log type. We are formally requesting it as a feature. UBA is essential for detecting anomalous access patterns, privilege abuse, and insider threats in environments with PAM solutions. 5. Native Splunk HEC integration Azure Log Analytics works as an intermediate, but a direct Splunk HTTP Event Collector (HEC) output would be strongly preferred. Many enterprise security teams use Splunk as their primary SIEM, and routing through LAW adds latency and complexity. Business Impact: Without these improvements, the Azure Log Analytics integration cannot be used for security alerting and threat detection, privileged access reviews, or audit and compliance reporting. The logs as-is confirm that something happened, but provide no actionable context. Expected behavior: Each log entry sent to LAW should contain enough structured information to answer: Who did what, on what resource, from where, and with what result — without requiring any post-processing or external joins.

10

444

7

avatar

Dominic Dansereau

avatar

mmedouard

Security issue on Devolutions Password Manager

Hello, After the last updates, I don't know which one, the problem of the security already discuss 2 years ago comes back. ( https://forum.devolutions.net/topics/41460/security-problem-on-personal-hub#190146 ). If there is an option to enable the disconnection I dont' find it. My request is the same, when I close the browser with extension Devoltuion workspace I must be logged out of Devolution Workspace. Currently somebody who is using my session (my children, a hacker) he has got all my passwords with Devolution whitout having to enter a password. That is bad. I hope you can update the version to make it more secure. Many thanks Marc

1

173

2

avatar

mmedouard

avatar

jm2

Support for linked account credentials in propagation script parameters

Hello, Would it be possible to accommodate using linked PAM accounts for the credential properties of propagation scripts? Similar to how DVLS allows a linked account to be used for connecting to a PAM identity provider. Being limited to explicit static credentials is somewhat incompatible with PAM lifecycle password rotation of all of a systems' privileged credentials. For example, if the built in Windows Administrator is used for a propagation script to update the password for a system service, the script parameters need to be manually updated whenever the Administrator password changes. Another way this feature would be useful is when multiple propagation scripts use the same credential. Without being able to use a linked account, the use of propagation scripts at scale becomes problematic because a password needs to be manually updated in multiple locations every time it changes. Please let me know if any additional info is required. Thanks Joe

1

123

2

avatar

jm2

avatar

jm2

Email alerts for administrators

Hello, With DVLS, email alerts are configurable to be sent to administrators when certain events occur, such as scheduler being offline or PAM heartbeat failures etc. Would it be possible to have equivalent behavior in Devolutions cloud. In particular, it would be very useful to be alerted when a hub services instance goes offline, or auto updates. Please let me know if you would like any additional info. Thanks Joe

1

142

2

avatar

jm2

avatar

hnn

Devolutions Cloud web interface integrate with Bitwarden for authentication.

the Bitwarden entry is not currently supported directly in the Devolutions Hub Business web interface for launching and pushing credentials to an RDP session. To use this workflow, you will need to open the session through Remote Desktop Manager or, at minimum, Devolutions Launcher.

1

177

2

avatar

Sébastien Aubin

avatar

jm2

WebUI support for 'Hub privileged account' type entries

Hello, Somewhat related to existing feature requests, could 'Hub privileged account' type entries be accommodated Cloud WebUI please? Credential type "DVLS Privileged Account" support in Web version of Devolutions Server WebUI unable to launch sessions using 'find by name (uservault)' that resolves to a PAM credential Thanks Joe

1

138

1

avatar

Luc Fauvel

1 - 25 of 282 items