> For the complete documentation index, see [llms.txt](https://docs.keeper.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.keeper.io/release-notes/enterprise/endpoint-privilege-manager/endpoint-privilege-manager-2.1.1.md).

# Endpoint Privilege Manager 2.1.1

Released on Sep 10, 2026

### EPM 2.1.1 Overview

Release 2.1.1 delivers security hardening, platform stabilization, faster privilege workflows, and expanded policy coverage across Windows, macOS, and Linux.  It also introduces the Linux real-time monitoring foundation and improves reliability for agentic-AI, File Access, registration, and approval workflows.

### New Features

* **Linux Real-Time Process and File Monitoring** — introduces the `KeeperLinuxAgent` monitoring foundation, including Fanotify execution monitoring, process metadata extraction, auto-allow filters, MQTT lifecycle management, policy request/response envelopes, timeout and fail-open safety, dual logging, startup and mount-namespace coordination, parent-chain trust handling, and reduced per-event overhead.

<figure><img src="https://1549319098-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LSGErxSfzX6xZALob42%2Fuploads%2FBW3BoarfzUJLdi1TTABA%2Fimage.png?alt=media&amp;token=b7f757bb-e142-4e69-bd76-7a7fdcc3eb4f" alt=""><figcaption></figcaption></figure>

* **Registration Continuity Across Hostname Changes** — administrators can preserve and reapply agent registration when an endpoint hostname changes.
* **Enterprise-Aware macOS Setup** — managed macOS deployments use a silent enterprise-default path, while unmanaged or explicitly requested installations continue to use the setup wizard.

### Enhancements

* **Command Line Policy Modernization** — matching now evaluates `ApplicationCheck` against the executable and `AllowCommands`/`DenyCommands` against arguments; legacy policies receive migration warnings and automatic normalization.

<figure><img src="https://1549319098-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LSGErxSfzX6xZALob42%2Fuploads%2FA6Q3IsxGscM22YA3Bm16%2Fimage.png?alt=media&amp;token=fd09e0ef-4f86-4745-b533-62bd607c843d" alt="" width="563"><figcaption></figcaption></figure>

* **Policy Matching Coverage** — user filters now try login, UPN, and other valid account names; Azure AD and SCIM user collections resolve more consistently; Azure AD group membership supports domain global and universal groups; OS collections are honored; and Azure AD privilege-elevation group filters are evaluated correctly.
* **File Access Policy Consistency** — wildcard matching is aligned across platforms, leading-wildcard paths resolve correctly, macOS `.app` bundles are covered consistently, protected-path behavior is defined, and policy scope is limited to the intended applications and binaries.
* **Network and Protocol Coverage** — intercepted DNS queries can resolve against a substitute domain, and TCP traffic is intercepted through the **Keeper Filter Driver**.
* **Notification and Registration Experience** — job notifications are grouped and rate-limited per user; registration status and menus are consistent across platforms; internet connectivity is checked before registration requests; and default administrator protection is maintained on Linux.
* **Agentic Grant Defaults** — one-time Agentic AI grants use the configured 240-minute policy default rather than an unintended 24-hour duration.

### Security

* **Command-Line Policy Enforcement** — hardened substring matching policies to ensure an unprivileged user cannot obtain root execution.
* **MQTT and Elevation Request Validation** — strengthened MQTT authorization and validated elevation file paths instead of trusting request-supplied values.
* **Linux Certificate and Registration Protection** — tightened certificate validation and restricted Linux agent registration to administrators.
* **AI-Agent File Access Enforcement** — WMI process creation is covered by AI-agent File Access controls, and additional AI-agent application exclusions improve classification accuracy.

<figure><img src="https://1549319098-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LSGErxSfzX6xZALob42%2Fuploads%2F3Qt0oVxrmpH0ANKDlWXI%2Fimage.png?alt=media&amp;token=c5160680-6621-405a-a527-8b680b19be44" alt="" width="375"><figcaption></figcaption></figure>

* **Elevation Path Validation** — temporary paths containing curly braces, including Visual C++ Redistributable bootstrapper paths, are handled correctly during elevation.
* **Privilege-Deny Enforcement** — deny policies are consistently applied through ***KeeperClient*** Request Elevation, including command files and scripts.

### Improvements

#### Windows

* Privilege elevation is faster by reducing work on the critical path for scheduled tasks and ephemeral accounts.
* Approval requests reattach to the existing request while waiting, preventing duplicate requests and improving approval continuity.
* Deny, approval, MFA, and monitor dialogs now show accurate policy and process details, including clearer acknowledgement text.
* History-based elevation requests use current file information, and endpoint state is preserved when registration or removal does not complete successfully.
* Azure AD auto-update prompting and policy evaluation are more reliable; endpoint registration remains stable during hostname and network changes.
* Windows process ancestry and application identity reporting are more accurate, including Claude and other AI applications.
* MSIX OAuth protocol activation continues to use the correct Windows activation mechanism.
* Updater logs are stored under `C:\ProgramData\Keeper Security\Endpoint Privilege Manager` for consistent supportability.
* `%ProgramData%` exclusions resolve to the correct Windows path during file evaluation.

#### macOS

* ***KeeperClient***, privilege elevation, and `.app` launches work together reliably, including elevated GUI applications and Agentic AI workflows.
* ***KeeperTrash*** intercepts file deletion consistently from the desktop, drag-and-drop, and context-menu workflows.

<figure><img src="https://1549319098-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LSGErxSfzX6xZALob42%2Fuploads%2FGE3nof4tNXl4j7wffSit%2Fimage.png?alt=media&amp;token=a0ee2d7e-8dbb-40cc-900f-999008b78e52" alt=""><figcaption></figcaption></figure>

* Ephemeral elevation accounts are created as system accounts, improving compatibility with macOS elevation flows.
* Agentic AI wildcard approvals handle missing or invalid likelihood settings safely, and operator approval responses are processed reliably.
* Post-install presentation is streamlined, while policy and process launch handling remains compatible with macOS system integrations.

#### Linux

* Agent registration and operator approval are more reliable, including fresh installs, administrator restrictions, default-admin preservation, and correct `keepersudo --approval` argument handling.
* GNOME-launched applications no longer inherit an unrelated AI-Agent Access requirement from earlier activity, while fork/exec and bundled-install ancestry are resolved more accurately.
* Linux builds and packaging are more resilient, including stable x64 signing and release pipeline behavior.
* `KeeperLinuxAgent` logging honors ***Keeper Privilege Manager*** settings and remains concise for system-UID decisions.

#### Cross-platform and service reliability

* Agentic AI audit events use consistent policy types, correlation identifiers, ancestry, and event boundaries; unnecessary subprocess events are no longer emitted.

<figure><img src="https://1549319098-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LSGErxSfzX6xZALob42%2Fuploads%2FbcES4TgbQvrSH0SBpEt2%2Fimage.png?alt=media&amp;token=f5d3a8b7-1ee1-4db8-ae99-22c7857135ca" alt="" width="561"><figcaption></figcaption></figure>

* Elevation and File Access audit streams avoid spurious status events and preserve accurate policy attribution, while users without policies do not receive unrelated audit messages.
* Startup, update, and service lifecycle coordination reduces AI application launch storms, retry storms, orphaned profiles, and upgrade conflicts.
* Ephemeral account and profile cleanup is more efficient and avoids conflicts with active elevation sessions.
* ***KeeperUSession***, AOT JSON parsing, and endpoint file-access availability are more resilient during startup and registration.
* Automated cloud-approval coverage, baseline tests, shared helper extraction, and test-harness maintenance improve release confidence.
* Reboot warnings, duplicate notifications, and user-facing policy messages are clearer and more consistent.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.keeper.io/release-notes/enterprise/endpoint-privilege-manager/endpoint-privilege-manager-2.1.1.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
