Changelog

Follow up on the latest improvements and updates.

RSS

We've released Relay Manager v0.2.1 with an improvement to the default installation path for binary deployments on Linux.
🛠️
Improvement
Improved Linux Binary Installation Path
– The default relay home directory has been updated to
/opt/dnsfilter/relay
for binary installations on Linux. This resolves an issue where the relay service could get stuck in a restart loop on certain enterprise Linux distributions due to system permission restrictions on the previous default location.
What's New
Redesigned DNS Query Log
  • The Query Log has been fully rebuilt with a new top-level filter bar supporting multi-select across Sites, Roaming Clients, Relays, and Users
  • MSP admins can now toggle between organizations directly from the Query Log without losing active filters — making cross-org investigation significantly faster
  • Introduced a custom timeline picker to narrow search windows down to the second
  • Active filters persist in the URL, so views can be bookmarked, shared, and kept consistent across sessions
  • Added new data columns to enhance usability: Resolved IPs, Query Type, and Roaming Client OS Type
🛠️
Improvements
Set Any Page as Your Default Landing Page
– You can now bookmark any page in the app to open automatically upon login, setting the homepage (or Organization default) that is best for your use case.
Clearer Mobile Agent Auto-Registration Status
– The Automatic Registration toggle now displays its 7-day duration and an explicit end date when enabled, replacing the previous helper text for easier at-a-glance visibility.
Tooltip for Disabled Site Field
– When the Site field is unavailable because no organization has been selected yet, hovering it now shows a clear prompt to select an organization first — removing a common point of confusion during Relay and Roaming Client setup.
🪲
Bug Fixes
MSP Users and Collections Policy Display
– Resolved an issue where Policy and Block Page columns were either hidden or displaying incorrect values when viewing Users and Collections at the MSP level. Both views now correctly reflect each organization's actual assigned values without requiring a switch into individual organizations.
Roaming Client Install Drawer Entitlement Handling
– Resolved an issue where the Install Roaming Client drawer did not correctly reflect plan entitlements. Customers without mobile RC access now see appropriate disabled fields and an upgrade prompt instead of interactive controls.
Top Active Clients Widget Row Limit
– Resolved an issue where the Top Active Clients widget on the CyberSight Activity Overview was capped at 5 results. The widget now displays up to 10 clients as intended.
Roaming Client Detail View Layout
– Resolved a display issue where Device ID and Created At values overlapped in the Roaming Client detail view across multiple browsers.
Plus general performance and stability improvements across the dashboard.

new

Mac Roaming Client

RC Release Channels

07/16 July 16 – macOS Roaming Client v2.4.3 Beta

Version 2.4.3 of the macOS Roaming Client is now available on the
Beta channel
. To install, download the latest beta installer from the dashboard under
Deployments → Roaming Clients → Beta Channel
.
🪲
Stability & Connectivity Fixes
  • Fixed an issue where device hostnames were not automatically reported to the dashboard on fresh installs of v2.4.2, causing devices to appear with no hostname in the device list
  • Fixed an issue where reinstalling or upgrading the agent could create duplicate device entries in the dashboard
  • Resolved an issue where reassigning a device to a different site by changing the Site Key did not correctly update the device's site assignment and policy in the dashboard — the device now registers to the new site as expected on both live key changes and clean reinstalls
  • Fixed an issue where Travel Wi-Fi configuration settings (
    ALLOW_MANUAL_CAPTIVE_PORTAL
    ,
    ALLOW_PROXY_DISABLE
    , and
    CAPTIVE_PORTAL_DELAY
    ) were silently ignored when set in the
    dns_agent.conf
    file during CLI installation. These settings are now correctly applied on install

new

Active Directory Sync Tool

Identities Sync Tool

07/15 July 15 - Identities Connections Release

Identities
is now available in the DNSFilter dashboard. This unified framework manages users, collections, and policy assignment across your organization — designed to handle the scale and complexity of modern enterprise and MSP environments.
What's New
Direct Microsoft Entra Integration
– Connect your Entra ID directory directly to DNSFilter without the AD Sync Tool. Users and groups sync automatically via SCIM provisioning, with full support for Entra Hybrid environments where Active Directory identities flow through Entra.
Rebuilt Collections
– Collections have been redesigned to support large directories, multiple identity sources, and high-complexity group structures — reducing sync failures, stale data, and manual grouping overhead.
Unified Identities Hierarchy
– A new Identities view gives administrators a clear, consolidated picture of all identity sources, user objects, and Collections, and how policies are applied across them. Policy assignment is consistent and visible regardless of where identities originate.
MSP-Level Identity Management
– Users, Collections, and Identity Connections are now manageable directly from the MSP dashboard. Previously, AD Sync Tool configuration required navigating into each organization individually — MSPs can now set up and manage synced policy assignment across their organizations from a single view.
What This Means for You
  • No more dependency on the AD Sync Tool for Entra environments
  • Reliable sync at scale for large and complex directories
  • A consistent, predictable path for policy assignment across all identity sources
  • Reduced operational overhead for enterprise IT teams and MSPs managing cloud-first identity strategies

new

iOS Roaming Client

RC Release Channels

7/14 July 14 - iOS Roaming Client v1.4.4

A new version of the iOS Roaming Client is now available in the App Store and will begin rolling out to devices via Apple auto-updates today.
This release includes improvements to reliability, registration behavior, and MDM management.
What's New
  • Improved MDM Support
    User name, hostname, and device tag changes in the configuration profile now sync to the Dashboard without requiring a Site Secret Key change
  • Automatic Site Reassignment from MDM
    A Site Secret Key change in the configuration profile now re-associates the device to the new site automatically, enabling fleet migrations without reinstalls or policy gaps
  • Stronger Admin PIN Protection
    Progressive delays are now applied between incorrect admin PIN attempts, making automated guessing impractical while keeping legitimate retries fast
  • Refreshed Branding
    App icons, visuals, and UI elements have been updated to match current DNSFilter branding
🪲
Bug Fixes
  • AirPrint and printer discovery
    Single-label and DNS-SD queries now route to Local Resolvers when configured, so discovered printers appear reliably while the Roaming Client is active
  • More reliable filtering after login
    Configuration now refreshes on a short interval instead of on every DNS query, fixing a brief window where a device could show blocked content right after login
  • Diagnostic logging on by default
    New installs now capture debug logs from the first run so Support can diagnose early issues; users can still disable it in the app
What's New
CyberSight Data Export
– CyberSight Data Export is now available to all customers utilizing Data Export, enabling reliable export of CyberSight data to your SIEM of choice alongside existing DNS log exports.
Clearer Auto-Registration Duration for Mobile Roaming Client
– The Automatic Registration setting now displays its 7-day duration and an explicit "Ends on [date]" status when enabled, replacing the previous helper text for easier at-a-glance visibility.
🪲
Bug Fixes
Pending Remote Uninstall Persistence
– Resolved an issue where restarting an offline Roaming Client's services could cancel a queued remote uninstall before it took effect. Pending uninstalls now persist correctly through agent restarts.
CyberSight Activity Logs Deep-Link Loading
– Resolved an issue where the Activity Logs page would hang indefinitely when opened via the "View Activity Logs" link from the Top Websites card in Activity Overview. The page now loads filtered results reliably.
Plus general performance and stability improvements across the dashboard.

new

Android Roaming Client

RC Release Channels

07/09 July 9 – Android Roaming Client v1.22.1

We've released
Android Roaming Client v1.22.1
with bug fix. Navigate to the Google Play store to download.
🪲
Bug Fixes
Android Client Stability When Switching Display Modes
– Resolved an issue where the Android Roaming Client would crash without notification when switching between tablet and desktop/PC mode (e.g. Samsung DeX). The client now handles display configuration changes correctly and remains active across mode switches.
🛠️ Improvements
Roaming Client Download Links Now Version-Specific
– Download links for Roaming Client installers now point directly to versioned files. The unversioned "latest" installer file is still available but may take up to 24 hours to reflect the most recent release. For the latest version immediately after release, use the versioned download link in the dashboard.
Plus general performance and stability improvements across the dashboard.

fixed

Web App

API

Mac Roaming Client

07/02 July 2 – Web Application and API Update

🪲 Hot Fix
macOS Roaming Client Duplicate Registrations
– Resolved a device identification issue on macOS Roaming Client 2.4.2 that could cause the same device to register more than once. Existing duplicates were consolidated.
✨What's New
DNSFilter Partner Portal Revamp
– The DNSFilter Partner Portal has been relaunched with a modernized experience. Partners access the portal by verifying their company email via a magic link — no account creation or SSO required. Lesson progress is saved locally on your device.
🪲 Bug Fixes
  • CyberSight Client and User Cards
    – Resolved an issue where client and user detail cards in CyberSight displayed raw ID values instead of human-readable names.
  • Add User Drawer Organization Access Field
    – Resolved an issue where the Organization Access restriction field appeared empty in the Add User drawer, causing confusion about what access level would be granted.
  • Improved Error Handling for Invalid API Privacy Mode Values
    – Resolved an issue where passing an invalid
    privacy_mode
    value to
    PATCH /v1/msps/:id
    returned an HTTP 500 server error instead of a structured 422 validation response. The endpoint now returns a clear, consistent JSON error response when an invalid value is provided.
  • IPv6-Only DDNS Hostname Resolution for Sites
    – Resolved an issue where DDNS hostnames that resolve exclusively to IPv6 addresses could not be added to a Site due to a validation error. These hostnames now resolve correctly during setup without requiring manual workarounds.
Load More