Skip to content
DnsLister Forum

Where domain hunters compare notes

The last two weeks in TridentStack Control: scheduled reboot waves, stuck-update visibility, shared dashboards, .NET Framework vulnerability detection, and a big multi-session Windows reliability pass

Since our August 17 roundup we have not posted a standalone announcement, so everything below is new. The full changelog is always at tridentstack.com/changelog; these are the highlights worth calling out.

Reboot your fleet in controlled waves Deployment rings can now run a scheduled reboot sequence at the end of each maintenance window. Define ordered waves that pick endpoints by hostname, tag, or operating system, and TridentStack Control reboots each wave in turn once the window's patching has settled, verifies every endpoint actually came back up, and only then moves to the next wave.

  • Choose per wave whether a failed reboot halts the rest of the sequence or lets it continue, with an optional wait between waves.
  • A live preview shows how many endpoints each wave will match, with sample hostnames, while you edit.
  • Every run is recorded on the ring with per-endpoint results, reboots show in endpoint history with dispatch, reboot, and verification steps, and a failed or halted sequence raises notifications through your channels.

See exactly which updates are stuck, and why The Rollout Status page has a new Stuck Updates tab. It lists system updates that keep installing without taking effect or cannot finish, shows which endpoints are still affected, and tells you why: the last install needs a reboot, a pre-install check is blocking it, the install was blocked before it could start, or the update reports success but is still applicable. Updates that are expected to reinstall regularly, like self-updating Microsoft tools, are listed separately so real problems stand out. When an update reports success but a follow-up check shows it did not take effect, TridentStack Control now reschedules that endpoint for another attempt in the next maintenance window, with a safety cap on retries.

Dashboards are now shared, linkable, and yours to favorite Dashboards became collaborative.

  • Every dashboard is now visible to everyone in your account, so a dashboard a teammate builds is immediately available to you. Creators keep edit and delete rights, and administrators can manage any dashboard.
  • Dashboards have shareable links: the address bar reflects the dashboard you are viewing, so you can bookmark one or send the URL to a teammate.
  • Set any dashboard as your personal favorite and it loads when you sign in, without affecting anyone else. Administrators can also set an organization default landing dashboard.

Chart your Endpoint Checks on any dashboard New dashboard widgets for Endpoint Checks: pie and time series panels that chart check policy compliance across passing, failing, and exempt endpoints. Counts combine across the policies you select, so a Windows and a Linux policy for the same requirement chart as one series. Compliance history starts recording when this ships, so trends fill in from day one.

Vulnerability detection for the .NET Framework built into Windows TridentStack Control now detects vulnerabilities in the .NET Framework that ships as a built-in Windows component, not just the separately installed kind. It reads the installed version on the endpoint and flags any endpoint running below the fixed release for a given vulnerability. Those findings now also show the correct fix and a working remediation action whenever an applicable cumulative .NET Framework update resolves them, and Windows endpoints reliably see and receive combined .NET Framework updates that cover more than one version.

A big reliability pass for shared and remote desktop servers Multi-session Windows machines, like terminal servers with many signed-in users, got a lot of attention:

  • The tray app now loads its interface only when you open it and fully releases it when you close it, running as a small tray icon the rest of the time. On busy remote desktop servers this cuts the per-session memory, processes, and background disk activity substantially, and update checks from multiple sessions are coordinated so one check serves them all.
  • The app now launches for every signed-in user instead of only the first, every session receives live install and update progress, and the tray icon stays a single stable icon instead of multiplying into a cluster of duplicates.
  • The tray app recovers on its own if its interface ever stops responding, and stays a single instance per user.

Add notes to any endpoint You can now attach a note to any endpoint to record its owner, location, or handling instructions. The note shows in the endpoint header, expands to full text on click, and records who last edited it and when. Notes are shared with everyone in your account.

Tighter control over Windows security and configuration policy A broad accuracy and coverage pass on policy:

  • The full set of seven Windows Restrict NTLM settings is now available in security policies, including the outgoing, incoming, auditing, in-domain, and server exception options, and Group Policy imports that carry them match automatically.
  • The Effective Policy view now flags leftover security settings that remain on an endpoint after the policy that set them was removed, or that no current policy manages, and shows how to take ownership by adding them to a policy. Only values that differ from the Windows default are reported, so a clean stock endpoint shows none.
  • A large batch of configuration policy deployment fixes: policies with adjustable values (log sizes, folder and path lists), dropdown choices, checkbox settings that write several values, and settings that pair a switch with a list now deploy completely instead of partially, and disabling a security setting now restores the Windows default instead of silently doing nothing. The editor now states plainly what Enabled, Disabled, and Not Configured each do.
  • Clearer editing too: settings that share a name show their full category path, search returns results immediately, and the configured view shows every setting including custom registry entries.

An endpoint list you can actually sort and scroll

  • Several columns that looked sortable but quietly reordered by last check-in (last reboot duration, reboots in 30 days, last vulnerability scan, installed and managed software, current user, architecture, edition, external IP, directory join, and secure boot) now each sort by their own values.
  • Blank values now sort consistently as the lowest value instead of always sticking to the bottom.
  • The list no longer reshuffles or snaps back to a shorter view while you scroll during its background refresh; rows hold position and update in place.

Faster vulnerability dashboards and honest compliance scores

  • The fleet vulnerability summary tiles, most-at-risk endpoints list, and executive most-improved report now return the same figures with far less work behind the scenes, so they stay quick for large fleets.
  • Compliance scoring now discloses its data basis everywhere it appears: how many endpoints have current data, which are stale or incompletely evaluated, a "Data as of" date and control count per endpoint, and coverage and freshness stated in PDF reports. Evaluation errors are now reported distinctly instead of folded into "unknown."

Linux: older distributions and self-re-arming rings

  • The Linux agent installer now runs on older distributions including CentOS 7 and RHEL 7, where it previously stopped partway through; newer distributions keep the full set of service protections.
  • On CentOS, RHEL, and Amazon Linux, the agent now refreshes package repository metadata before each update check, so a newly published update is detected right away instead of waiting for the cache to expire.
  • Automatic deployment rings for Linux now re-arm on their own when new updates arrive, matching how Windows and macOS rings already behave, and a ring's final phase stays open while approved updates are still pending.

Close your account yourself, with clearer data commitments

  • You can now close your account from Settings under Privacy and Data. Closing locks the account immediately, keeps your data restorable for 90 days, and then deletes it permanently; an admin can restore it during that window.
  • Our published data retention commitments now describe the closure and deletion lifecycle precisely, and the same wording appears on the security page, Terms of Service, privacy policy, and product documentation.
  • Audit log entries are now enforced as append-only at the database layer as well as the application layer, so recorded events cannot be edited.

Plus a lot of polish

  • Endpoints protected by a third-party antivirus now report Windows Defender status accurately, instead of showing a stale "up to date" signature badge when Defender is standing by in passive mode.
  • Resolved vulnerabilities now always leave an entry in the vulnerability history timeline, including ones cleared by uninstalling software or, on Linux, by a backport or newer kernel.
  • Uninstalling the Windows agent no longer clears a Windows Update or WSUS server setting your organization had in place before the agent was installed; that setting is restored on uninstall.
  • Newly enrolled endpoints begin reporting installed software and pending updates right away instead of showing "Collecting…" for up to half an hour.
  • Endpoints with a pending Windows feature upgrade keep receiving their monthly cumulative, .NET, Defender, and malicious-software-removal updates while the upgrade waits, instead of falling behind on security updates.
  • Package Catalog search updates in place without redrawing the page, the pending application updates panel fits without a horizontal scroll bar, and on iPhone and iPad the endpoint Health tab no longer overlaps its panels.
  • Rejected report queries now name the specific table or rule that blocked them, and compliance PDF reports now reliably generate instead of sitting queued.

Full details for every item are in the changelog at tridentstack.com/changelog. If there is something you want next, drop it in the comments, weigh in on the roadmap at tridentstack.com/roadmap, or come find us in the Discord. A lot of this came straight from customer requests.

Source: r/TridentStack · by /u/Ad3t0

Leave a Reply

Your email address will not be published. Required fields are marked *