The product you bought keeps getting better. Here's what shipped.
A running record of what's new in PK Protect, updated each quarter.
April 2026 Release
v20.5Agent v20.50 · PK M365 v1.50
Moving to SaaS used to mean a Professional Services engagement. Now it's a wizard.
The new SaaS Migration Tool walks you through migrating an entire on-prem PK Protect instance to PKWARE-hosted SaaS. End to end. From inside the admin console.
When the migration completes, the source server flips into redirect mode and endpoints reconnect automatically.
See migration documentationProtect a single SharePoint subsite. Not the whole tenant.
Stop over-applying policy across a whole tenant to cover one department. Protection now scopes to specific subsites and OneDrive subfolders.
Deploy the Windows Agent the way you deploy everything else.
The Windows Agent now ships as a standard MSI. SCCM, Intune, and the rest of your endpoint tooling handle it without PKWARE-specific workarounds.
Patch and you're covered for several disclosed CVEs.
Including a critical OpenSSL CMS fix and a multi-version cluster API fix. The cluster API fix is backported to every supported server version (20.0 through 20.5), so you don't have to upgrade to get it.
See advisory detailsOpt-in features customers can ask their account team to enable.
These ship in 20.5 as opt-in entitlements. No extra cost. Ask your account team if you'd like any of them turned on for your environment.
The modern Admin UI keeps growing.
New Global Search, revised navigation, and a redesigned Target Results page. Data tables now support column show/hide, per-column search, dropdown filters, and async loading on large lists.
Ask your account team to enableFind sensitive data hiding in your company's email.
Discovery now reaches into Microsoft Exchange Online, scanning subject lines, email bodies, and attachments. In-Place Archive is supported.
Ask your account team to enableProtect files even when they can't be scanned.
Discovery Fallback Remediation now runs on the Cloud Agent. Build remediation policies that safeguard files whether they're unsupported types, encrypted, or simply can't be scanned for any other reason. Target Status reporting shows which files were caught by the fallback.
Ask your account team to enableAlready a customer? Most of this is included.
If you're not sure whether you're on the latest version, or you want the new UI entitlement enabled, your account team can sort it in a day.