3.9.0 Release Notes
15 min
These release notes give an overview of the enhancements, new features, and improvements included in Kron PAM 3.9.0. For detailed instructions and information, please consult the Reference Guide. Contact us at [email protected]. Please note that only registered users can contact the support team. Below is a summary of the key changes and additions made in the 3.9.0 version of Kron PAM.
AI Agent Security
- The Kron PAM MCP Gateway has been introduced as the controlled access point for registered MCP servers. AI clients call the gateway instead of the MCP server directly. Users are authenticated through PAM login and existing MFA rules, access is checked against realms, and every request is written to the audit log.
- A Kron PAM MCP Server has been added. It gives people and AI agents read-only, governed access to Kron PAM logs for audit, compliance, and troubleshooting.
AI-Powered Threat Analytics
- Actions on Vault accounts are now analyzed by the ML engine and shown on the Threat Analytics screen in a more meaningful way.
Password Vault
- A Web Password Filler browser extension has been introduced. Users can now sign in to web applications with the vault accounts they are authorized for in a single click, and the extension checks the target login field and its origin before filling in any credential.
- Ephemeral credentials are now supported. A unique username and password is generated on demand with a defined TTL, and the credential is revoked and the target device user dropped automatically when it expires.
- Lease renewal and early revocation have been added for dynamic secrets, so a lease can be extended before it ends or cancelled immediately when it is no longer needed.
- Just-in-time (JIT) access has been implemented for Active Directory and Microsoft Entra ID. Group membership is granted at check-out and removed automatically at check-in or expiry.
- Password rotation for Entra ID (Azure) accounts has been added.
- Password management for Active Directory accounts now works over the Kerberos protocol, as an alternative to NTLM.
- Custom pre- and post-rotation workflows and hooks can be defined around password changes, including custom WinRM scripts triggered through Application Triggering.
- Application Trigger management is no longer limited to Vault admins. It can now be delegated to authorized users and user groups.
- Integration with AWS Secrets Manager, Azure Key Vault and Google Cloud Secret Manager has been added, allowing Kron PAM to create, control, and change secrets stored there.
- Passwords defined during Active Directory/LDAP user and device integration can now be managed as dynamic credentials and rotated periodically.
- A manual password change option has been added for static accounts. The new password is applied in both Kron PAM and Active Directory.
- Newly discovered users can now be marked as local or domain users.
- Multiple Vault accounts can now be selected at once in Assigned Credentials, and users or user groups that still have assigned credentials can no longer be deleted by mistake.
Secrets Manager
- JWT token support has been added to Secrets Manager and Secrets Management Agent password requests. Kron PAM can also accept and validate JWT tokens signed by Entra ID for workload authentication.
- The Secrets Management Agent C++ SDK is now available on Linux, and error messages across the SDKs have been made clearer.
- A "Source" column has been added to the audit logs, showing whether a secret request came from an Agent, the API, or an SDK.
- A license-based limit on the number of Secrets Management application tokens has been introduced.
- The Heartbeat chart has been redesigned for easier monitoring of AAPM Agent status.
Privileged Session Manager
- Ephemeral (just-in-time) access for RDP and SSH sessions has been added. The required account is created at the time of the request and cleaned up automatically once the session ends.
- IP and user-based blocking has been added to SFTP sessions.
- Approval workflows and MFA are now supported on the OT/ICS Session Manager.
- The HTTP Proxy now shows a clear message on the login page when the authentication service cannot be reached, and video replay now sits in the Session Log menu.
- SFTP Proxy now supports symbolic links in MobaXterm, and slow download speeds have been resolved.
- A notification email can now be sent to the group manager whenever an RDP or SSH connection is made.
- The "Wire to" feature can be restricted so users only see and join sessions of users in their own groups.
Secure Remote Access
- SAML integration has been added as an alternative login method.
- Secure Remote Access users can now sign in to the Kron PAM GUI and Desktop Client, with access limited to the Device Inventory page.
Endpoint Privilege Management
- A new Event Inbox screen lists the application events on Windows and Linux endpoints, with allow/block details for each event and sortable columns.
- Multiple applications or commands can now be added to a single rule in Advanced Policy, and the "contains" match type is supported on both agents.
- Advanced Policy now includes a default Run as Admin right on Windows and a default sudo right on Linux.
- MSI packages can now be managed with Run as Admin, in the same way as EXE files. Policies are also applied to PowerShell commands, and Run as Admin access with a one-time code is supported.
- The Windows agent now supports offline authentication and authorization, bulk uninstall, and performance improvements.
- Sudo commands on the Linux agent can require a one-time password or managerial approval, and commands run through sudo and SFTP are now written to the session logs.
- Linux binaries can be discovered on a schedule, and their hashes reported to Kron PAM for use in policy rules.
- Policies can now be applied to the root user, and exceptions can be defined for subprocesses of blocked processes on the Linux agent.
- Session video recording can be turned on or off for the Linux agent, and active Linux agent sessions can be ended from the Active Sessions screen.
- Heartbeat charts have been redesigned for both agents.
Database Access Manager (DAM)
- A new Kron JDBC Driver is now available for MySQL, PostgreSQL, Oracle, and Microsoft SQL Server connections. Single sign-on (SSO) and multi-factor authentication (MFA) are supported on all four database types.
- MongoDB support has been added to the SQL Proxy.
- Oracle connections can now be defined with either a Service Name or an SID.
- The DB Firewall can now be managed from the Kron PAM GUI, with rules by tenant. It covers buffer overflow per session, packet rate limits per user and per server, and connection rate limits per IP address and globally.
- If session or query logging fails persistently, the SQL Proxy now stops accepting new connections instead of allowing activity to go unlogged, and the shutdown is visible in its health status.
- OTP caching can now be enabled on the SQL Proxy, so users are not asked for a one-time password repeatedly within a defined period.
- Several database accounts can now be assigned to a single database for SSO, and SSO and manual access can be used side by side.
- Connection approvals now work correctly when only a single device or only a device group is approved, and the right rule is applied when the same device sits in two realms with different approval settings.
- Standard reports for Database Access Manager compliance have been added, aligned with standards such as PCI-DSS.
Multi-Factor Authentication
- Login with password and OTP has been added for RADIUS-based 2FA, and error handling during RADIUS authentication has been improved.
- Integration with external MFA providers through RADIUS has been added, with Kron PAM acting as the RADIUS client.
- Notifications can now be delivered through Telegram, which helps in environments where an email server is not available.
Cloud Infrastructure Entitlement Management (CIEM)
- New and improved Dashboard, IAM, Compute Engine, Storage, and Database screens have been added for Google Cloud Platform (GCP).
- Dashboard, Users, VM, Blob, and Database screens have been improved for Microsoft Azure.
Privileged Task Automation
- Command output from scripts running on many devices is now retrieved and displayed in batches, which prevents memory errors in large device groups.
- The Scripts page layout has been improved, and screen visibility, data scope, and realm management are now controlled by separate portal functions.
Kron PAM Desktop Client & Kron PAM Mobile App
- Desktop Client idle timeout can now be configured separately from the web GUI timeout.
- Desktop Client connection settings can be stored automatically, and the client can now be installed on a network share.
- A download progress indicator has been added for files transferred from RDP sessions.
- The Kron PAM Mobile App has been redesigned.
Multitenancy & Licensing
- The Tenant Manager page and the License Manager screens have been redesigned.
- A new license client has been implemented, along with support for license files that cover multiple PAM instance UUIDs.
- A one-time, 7-day emergency extension can now be used for an expired license. It becomes available again only after a new license is uploaded.
Platform Features
- Department-based administrative isolation has been added. Administrative teams working in the same PAM deployment can now be kept apart from each other.
- Active Sessions now supports group-scoped visibility, and the Approval Workflow tab and Ownership screen now follow realm and portal function authorization.
- The Kron PAM-initiated SAML login flow has been aligned with standard SAML behavior.
- Log search time ranges can be limited to a configurable maximum period. Logging screens also show tamper-evident records first for the selected time range.
- SIEM forwarding has been improved: unauthorized events are now sent, session duration calculations are corrected, and duplicate log entries have been removed. The syslog output has also been enriched with account details.
- Additional standard reports have been added on reporting module, including Database Access Mamager compliance reports for PCI-DSS.
- Maintenance Mode can now be cancelled from the interface and warns when the required policy is missing.
- Bulk actions have been added for users on the Users screen.