What's new in PK Protect

The product you bought keeps getting better. Here's what shipped.

A running record of what's new in PK Protect, updated each quarter.

July 2026 Release

v20.6
7Features shipped
Jul 30Release date
Administrator v20.6
Agent v20.60  ·  PK M365 v1.60  ·  PK Secure Office v1.7
Encryption Discovery · post-quantum view ALGORITHMS DISCOVERED RSA-2048 AT RISK ECDH P-256 AT RISK AES-256-GCM SAFE ML-KEM-768 QUANTUM-SAFE PQC PROGRESS REPORT 42%
Beta Headline

See where quantum risk lives in your data. Years before it matters.

A new Encryption Discovery view surfaces post-quantum cryptography risk across the data you have already discovered, so you can see which encrypted data will need to move to quantum-safe algorithms.

A PQC Progress Report page in the Admin UI tracks migration status as you work through it, and the underlying cryptographic libraries have been updated to enable post-quantum algorithms.

For all customers PK Endpoint Manager
Ask your account team about the beta
CLOUD AGENT SCAN · LABEL FILTER SharePoint · OneDrive · Exchange General Confidential Highly Confidential /sites/finance · Q3-forecast.xlsx CONFIDENTIAL · SCANNED Exchange · team-lunch.msg GENERAL · SKIPPED OneDrive · draft-notes.docx DEFAULT LABEL APPLIED
Live now

Scan by sensitivity label. Not just by location.

Cloud Agent scans now filter on Microsoft Purview sensitivity labels across SharePoint, OneDrive, and Exchange, so you can scope actions to the classification your business already trusts. Unlabeled files can pick up a default Purview label.

Coverage widened at the same time: policies can target SharePoint subsites and OneDrive subfolders, and in-place archive mailboxes are scanned by default.

For Microsoft 365 customers PK M365 Cloud Agent
CLOUD SCAN HEALTH adaptive concurrency · token caching Target 01 · SharePoint COMPLETE Target 02 · OneDrive RUNNING 74% Target 03 · Exchange archive RESUMED 0 STALLED SLOTS RETRIES HANDLED FILENAMES PRESERVED
Live now

Large cloud scans finish cleaner.

Cloud scanning gets adaptive concurrency, per-scan token caching, and better error behavior, plus fixes for stalled scan slots, idle targets and label resolution. Original filenames are now preserved in encrypted output.

For all customers PK M365 Cloud Agent
QUARTERLY SECURITY UPDATE dependency audit · security review Platform packages updated Dependencies remediated Product hardening applied Details in the release notes
Live now

Patch and you are current on this quarter's advisories.

The release delivers quarterly package and security updates across PK Protect components, covering both product hardening and third-party dependency remediations found through dependency audits and security review.

Every fix is included in the base release, so there is nothing extra to license or enable. The specifics ship with the release notes.

For all customers PK Endpoint Manager
See advisory details
EMAIL POLICY · CONTENT LOCATION Outlook Add-In v1.7 Subject line SKIP Message body REMEDIATE Attachments REMEDIATE FILTER BUNDLE SCOPING POLICY-LEVEL SETTINGS DARK MODE
Live now

Decide exactly where in an email sensitive content gets remediated.

The Outlook Add-In adds per-location control over email content remediation, with content-location selection inside email rules and a filter-bundle scoping toggle on the email policy page. Global email settings have moved to the policy level, so control is finer grained.

Dark Mode styling and better handling of unsupported-file errors round out the release.

For all customers PK Secure Office
Also in technical preview

Version 21 groundwork you can try before it ships.

These arrive in 20.6 as opt-in, pre-release features at no extra cost. Use them for evaluation, testing, and training, and ask your account team if you'd like any of them turned on for your environment.

VIRTUAL APPLIANCE pre-release build APPLIANCE v2 CURRENT STACK MIGRATE CHECKLIST APPLIANCE v3 Ubuntu 26.04 LTS .NET 10 PostgreSQL REBUILT PLATFORM
Pre-release build

A rebuilt virtual appliance, ready ahead of version 21.

The new v3 appliance runs on a modern operating system and software stack, including Ubuntu 26.04 LTS, .NET 10, and PostgreSQL. A migration checklist and more tolerant schema migration make the move to it easier.

For IT admins PK Endpoint Manager
Ask your account team to try it
PEM ADMIN CONSOLE MODERN UI Dashboard Discovery Event Levels Event Log Configuration TARGET STATUS COLUMNS
Available on request

More of the Admin UI is now the modern UI.

This release converts additional administrator pages to the modern React interface, including the Events pages for levels, log, and configuration. Navigation has been reorganized into a simpler layout, and data tables keep gaining capability: column visibility, per-column search, and dropdown filtering.

The entitlement is off by default and available at no cost. SaaS customers have it enabled already.

For all customers PK Endpoint Manager
Ask your account team to enable

April 2026 Release

v20.5
5Features shipped
Apr 30Release date
Administrator v20.5
Agent v20.50  ·  PK M365 v1.50
Migration wizard · v20.5 ON-PREM VERIFIED HANDSHAKE SAAS SYNC 68% Pre-migration checks passed · Redirect mode ready
Live now Headline

Moving to SaaS used to mean a Professional Services engagement. Now it's a wizard.

The new SaaS Migration Tool walks you through migrating an entire on-prem PK Protect instance to PKWARE-hosted SaaS. End to end. From inside the admin console.

When the migration completes, the source server flips into redirect mode and endpoints reconnect automatically.

For all customers PK Endpoint Manager
See migration documentation
SHAREPOINT TENANT contoso.sharepoint.com /sites/marketing UNSCOPED /sites/finance PROTECTED · /reports subfolder SCOPED /sites/engineering UNSCOPED
Live now

Protect a single SharePoint subsite. Not the whole tenant.

Stop over-applying policy across a whole tenant to cover one department. Protection now scopes to specific subsites and OneDrive subfolders.

For all customers PK M365 Cloud Agent
.MSI pk-endpoint agent.msi v20.50 SCCM INTUNE YOUR TOOLING
Live now

Deploy the Windows Agent the way you deploy everything else.

The Windows Agent now ships as a standard MSI. SCCM, Intune, and the rest of your endpoint tooling handle it without PKWARE-specific workarounds.

For IT admins PK Endpoint Agent
v20.0 ✓ v20.1 ✓ v20.2 ✓ v20.3 ✓ v20.4 ✓ v20.5 ✓ CLUSTER API FIX · ALL SUPPORTED VERSIONS
Live now

Patch and you're covered for several disclosed CVEs.

Including a critical OpenSSL CMS fix and a multi-version cluster API fix. The cluster API fix is backported to every supported server version (20.0 through 20.5), so you don't have to upgrade to get it.

For all customers PK Endpoint Manager
See advisory details
Also in technical preview

Opt-in features customers can ask their account team to enable.

These ship in 20.5 as opt-in entitlements. No extra cost. Ask your account team if you'd like any of them turned on for your environment.

ENDPOINT USER STATUS LAST SEEN FILTER Active Inactive Pending WS-08293 m.kowalski Active 2 min ago WS-08312 j.alvarez Active 8 min ago LT-01044 s.tanaka Active 14 min ago
Available on request

The modern Admin UI keeps growing.

New Global Search, revised navigation, and a redesigned Target Results page. Data tables now support column show/hide, per-column search, dropdown filters, and async loading on large lists.

For all customers PK Endpoint Manager
Ask your account team to enable
MICROSOFT EXCHANGE ONLINE FROM d.brennan@acme.com TO finance-team@acme.com SUBJECT Q3 invoice for client SSN 234-... SSN FOUND CARD # IN BODY payroll-2026.xlsx PII IN ATTACHMENT
Available on request

Find sensitive data hiding in your company's email.

Discovery now reaches into Microsoft Exchange Online, scanning subject lines, email bodies, and attachments. In-Place Archive is supported.

For Microsoft 365 customers PK M365 Cloud Agent
Ask your account team to enable
FILE SCAN STATUS PROTECTION report.docx scannable PII detected Protected standard policy design.cad unsupported ? cannot scan Protected fallback policy vault.zip encrypted cannot scan Protected fallback policy
Available on request

Protect files even when they can't be scanned.

Discovery Fallback Remediation now runs on the Cloud Agent. Build remediation policies that safeguard files whether they're unsupported types, encrypted, or simply can't be scanned for any other reason. Target Status reporting shows which files were caught by the fallback.

For all customers PK M365 Cloud Agent
Ask your account team to enable
Get more out of PK Protect

Already a customer? Most of this is included.

If you're not sure whether you're on the latest version, or you want the new UI entitlement enabled, your account team can sort it in a day.