What's new in PK Protect

The product you bought keeps getting better. Here's what shipped.

A running record of what's new in PK Protect, updated each quarter.

April 2026 Release

v20.5
5Features shipped
Apr 30Release date
Administrator v20.5
Agent v20.50  ·  PK M365 v1.50
Migration wizard · v20.5 ON-PREM VERIFIED HANDSHAKE SAAS SYNC 68% Pre-migration checks passed · Redirect mode ready
Live now Headline

Moving to SaaS used to mean a Professional Services engagement. Now it's a wizard.

The new SaaS Migration Tool walks you through migrating an entire on-prem PK Protect instance to PKWARE-hosted SaaS. End to end. From inside the admin console.

When the migration completes, the source server flips into redirect mode and endpoints reconnect automatically.

For all customers PK Endpoint Manager
See migration documentation
SHAREPOINT TENANT contoso.sharepoint.com /sites/marketing UNSCOPED /sites/finance PROTECTED · /reports subfolder SCOPED /sites/engineering UNSCOPED
Live now

Protect a single SharePoint subsite. Not the whole tenant.

Stop over-applying policy across a whole tenant to cover one department. Protection now scopes to specific subsites and OneDrive subfolders.

For all customers PK M365 Cloud Agent
.MSI pk-endpoint agent.msi v20.50 SCCM INTUNE YOUR TOOLING
Live now

Deploy the Windows Agent the way you deploy everything else.

The Windows Agent now ships as a standard MSI. SCCM, Intune, and the rest of your endpoint tooling handle it without PKWARE-specific workarounds.

For IT admins PK Endpoint Agent
v20.0 ✓ v20.1 ✓ v20.2 ✓ v20.3 ✓ v20.4 ✓ v20.5 ✓ CLUSTER API FIX · ALL SUPPORTED VERSIONS
Live now

Patch and you're covered for several disclosed CVEs.

Including a critical OpenSSL CMS fix and a multi-version cluster API fix. The cluster API fix is backported to every supported server version (20.0 through 20.5), so you don't have to upgrade to get it.

For all customers PK Endpoint Manager
See advisory details
Also in technical preview

Opt-in features customers can ask their account team to enable.

These ship in 20.5 as opt-in entitlements. No extra cost. Ask your account team if you'd like any of them turned on for your environment.

ENDPOINT USER STATUS LAST SEEN FILTER Active Inactive Pending WS-08293 m.kowalski Active 2 min ago WS-08312 j.alvarez Active 8 min ago LT-01044 s.tanaka Active 14 min ago
Available on request

The modern Admin UI keeps growing.

New Global Search, revised navigation, and a redesigned Target Results page. Data tables now support column show/hide, per-column search, dropdown filters, and async loading on large lists.

For all customers PK Endpoint Manager
Ask your account team to enable
MICROSOFT EXCHANGE ONLINE FROM d.brennan@acme.com TO finance-team@acme.com SUBJECT Q3 invoice for client SSN 234-... SSN FOUND CARD # IN BODY payroll-2026.xlsx PII IN ATTACHMENT
Available on request

Find sensitive data hiding in your company's email.

Discovery now reaches into Microsoft Exchange Online, scanning subject lines, email bodies, and attachments. In-Place Archive is supported.

For Microsoft 365 customers PK M365 Cloud Agent
Ask your account team to enable
FILE SCAN STATUS PROTECTION report.docx scannable PII detected Protected standard policy design.cad unsupported ? cannot scan Protected fallback policy vault.zip encrypted cannot scan Protected fallback policy
Available on request

Protect files even when they can't be scanned.

Discovery Fallback Remediation now runs on the Cloud Agent. Build remediation policies that safeguard files whether they're unsupported types, encrypted, or simply can't be scanned for any other reason. Target Status reporting shows which files were caught by the fallback.

For all customers PK M365 Cloud Agent
Ask your account team to enable
Get more out of PK Protect

Already a customer? Most of this is included.

If you're not sure whether you're on the latest version, or you want the new UI entitlement enabled, your account team can sort it in a day.