Product updates, tutorials, and announcements from the NetLock RMM team.
v3.3.0.4
Rule Engine
Latest
September 16, 2026
This update reworks the automations with multiple conditions, priorities, new condition types and rules that add sensors and jobs. The web interface of any remote device – agent or SNMP – opens from the devices page through the NetLock server, the web console mobile app is available for Android, and patch management gets fixes for DNF/YUM systems and for Windows servers that never restarted when nobody was signed in. App Hub script apps verify their result with the detection script, the Members Portal API key can be replaced in the web console, and the reports page gets a Community tab for templates shared by our support team.
⚠️
This update includes a new agent version - update your agents after the server and web console.
Upgrade your installation as usual: https://docs.netlockrmm.com/docs/part-iii/how-to-upgrade-netlock-rmm
✨ Automations: multiple conditions, priorities, inventory rules, sensors and jobs✨ Web interface access for any remote device✨ Web console mobile app for Android✨ Patch management fixes for DNF/YUM and unattended Windows restarts✨ App Hub detection scripts before and after every action
Automations
A rule can have several conditions that all have to hold, and each condition can be negated. Besides device, tenant, location, group, IP address and domain, a rule can match the platform, device attributes such as name, operating system or serial number, installed applications, services and custom field values.
Every rule has a priority; the lower number wins. Existing rules were converted and resolve as before.
A rule can also add sensors and jobs to the devices it matches, and rules on inventory data are evaluated by the server after every inventory upload, so a device receives its policy, sensors and jobs without a click in the console.
Web Interface Access
The web interface of a device, or of a host a remote device can reach, opens from the devices page in a browser window – for agent-managed devices and SNMP devices alike.
The page is served through the NetLock server over a temporary relay session to the agent, so nothing has to be exposed.
Mobile App for Android
The new web console mobile app is available for Android. It brings push notifications, an improved mobile view of the web console and native remote screen control that you can use directly from your phone or tablet.
Link the app to your web console on the account home page under the Mobile App tab (/home?tab=mobile_app).
On Fedora and RHEL-based systems, updates were sometimes not installed through DNF or YUM although the job reported them as installed. This is fixed.
A Windows device with an outstanding restart and the reboot behaviour "Ask user" asked nobody when nobody was signed in, so a server never restarted on its own and stopped patching. The Windows patch policy has a new setting for that case.
The devices page now shows for every pending update why the last scheduled run did not install it.
App Hub & Software Deployment
Script apps run their detection script before and after every install, update and uninstall, so an installer that returns before it has finished is no longer reported as done.
Update and uninstall items of script apps ran the install script before; this is fixed.
Licensing
The Members Portal API key can be replaced under Settings → Licensing, as the appsettings.json files are now encrypted after the initial deployment.
Community Report Templates
The reports page has a Community tab for the report templates our support team publishes through the Members Portal. Templates can be shared publicly or directly with your instance.
If you need a specific report template, request it at support@netlockrmm.com.
Other Improvements
The Relay App UI has been improved.
Various improvements and bug fixes across different features.
v3.3.0.3
Steady Stream
September 10, 2026
This update adds stream modes and automatic clipboard sync to remote screen control, gives Microsoft Defender notifications a switch of their own, and adds HTTP proxy support so devices that can only reach the internet through a proxy can be installed and managed. Patch installation on Proxmox VE and Debian hosts where apt installed nothing is fixed, and tenants can now get a default policy for devices that no automation covers.
⚠️
This update includes a new agent version - update your agents after the server and web console.
Upgrade your installation as usual: https://docs.netlockrmm.com/docs/part-iii/how-to-upgrade-netlock-rmm
✨ Remote screen control: stream modes and automatic clipboard sync✨ HTTP proxy support for installation and all three agents✨ Tenants get a default policy for devices no automation covers✨ Microsoft Defender notifications get their own switch✨ Patch installation fixed on Proxmox VE and Debian
Remote Screen Control
A session now has a stream mode, chosen in the viewer: Quality for sharp text with full colour resolution, Balanced as the default, Performance for smooth motion at up to 60 frames per second, Auto, which adapts frame rate, resolution and quality to the connection while the session runs, and Custom with the full set of advanced settings.
The clipboard of a session is synchronised on its own: with the clipboard switch of the viewer on, text the end user copies on the device arrives on the operator's clipboard without a keystroke.
Microsoft Defender Notifications
Microsoft Defender notifications get their own switch in the policy: they now work without NetLock managing the Defender settings.
HTTP Proxy Support
Devices whose only route to the internet is an HTTP proxy could not be installed at all before: the installer tested the server with a raw TCP connection that no proxy setting can influence, and the agents used the same check to work out the address they talk to, so such a device stayed offline even when the installation finished.
The proxy is now configured in the web console per agent configuration, or handed to the installer on the command line, and it is used by the installer and by all three agents.
Patch Management
The Comm Agent fixes patch installation on Proxmox VE and Debian hosts where apt installed nothing: with the complete pending set selected, apt now resolves the upgrade itself, and a new patch policy option decides whether it may remove packages on the way.
Tenant Default Policy
A policy chosen on the tenant settings page now applies to every device of the tenant that no automation assigns a policy to, so a tenant no longer needs an automation of its own just to give its devices a baseline; an automation of any kind still wins.
v3.3.0.0
Dark Fiber
September 6, 2026
This release brings NetMesh - end-to-end encrypted TCP tunnels between two managed devices, set up in the web console and relayed by the NetLock server - and a reworked sign-in in which a session belongs to the browser instead of a single tab. It also adds a device topology map, automatic SNMP network discovery with health monitoring, passkey sign-in, a Message of the Day shown by the tray icon at login, and script variables with custom field values on tenant, location, group and global level. The user interface has been reworked considerably in preparation for the mobile app releases, the phone layout was rebuilt, and the web console can now be installed as an app (PWA).
⚠️
Attention: every relay tunnel session that already exists has to be edited once after the update. A session now carries the list of web console accounts that may open a tunnel through it, that list is empty for the sessions that exist today, and the server refuses a connection to a session with nobody assigned. Nothing is assigned automatically. Screen control through the Relay App is not affected.
Everyone is signed out once when this version is rolled out.
On installations with a very large events table, the first start after the update takes noticeably longer while the new indexes are created.
If remote screen control does not work after the update, restart the target device once after the new agent has been installed.
Upgrade your installation as usual: https://docs.netlockrmm.com/docs/part-iii/how-to-upgrade-netlock-rmm
✨ NetMesh - end-to-end encrypted TCP tunnels and meshes between managed devices✨ Sign-in reworked: browser-wide sessions, "Stay signed in" and session management✨ Passkeys (WebAuthn) as a second factor or fully passwordless✨ Device topology map with subnets, SNMP devices and NetMesh links✨ Automatic SNMP network discovery with health monitoring✨ Reworked interface, rebuilt phone layout, installable as an app (PWA)
NetMesh
A new page "NetMesh" holds links between two managed devices. A link keeps a persistent, end-to-end encrypted TCP tunnel: a local port on the client device is forwarded through the NetLock server to a service on, or behind, the service device. Everything is relayed by the server - there is no direct connection between the two devices.
The forwarded port listens on the client device only or on all of its network interfaces, which makes the device a gateway for its network. The service host can name a host behind the service device, so a device can be used as a jump host to a system where no agent can be installed.
A mesh connects several devices with each other instead of pairing them one by one. Its members publish services, and every other member reaches them on a loopback alias address and, optionally, by hostname through a managed block in the device's hosts file. Every member has a role - publish and consume, publish only, or consume only - and a mesh holds at most 50 members and 20 services. A mesh is either always on, or on demand, where a tunnel is established at the first connection attempt and closed again after an idle timeout; on demand is the recommended mode from about ten members. The agents have to be updated for mesh links.
A Topology tab draws the devices and links with live traffic, and a panel per link shows the route, live counters, the traffic of the last hour to seven days and the last twenty times the tunnel was established. The page has its own permission with add, edit and delete rights; accounts with the user management permissions receive it when the web console starts.
Sign-in & Security
A sign-in creates a session for the whole browser instead of for a single tab, so a second tab no longer asks for the password again, and a new "Stay signed in" checkbox keeps the session across browser restarts. Single sign-on is covered the same way. Everyone is signed out once when this version is rolled out.
The Security tab of the account page lists the open sessions with device, browser, IP address, sign-in time and last activity, and ends a single one or all others; administrators see the same list per account under Users. A new page Settings > Sessions sets the idle timeout, the maximum lifetime and how long a "Stay signed in" session lives.
Passkeys (WebAuthn): every account can register passkeys on its account page - Windows Hello, Touch ID, phone passkeys and FIDO2 security keys. In the default mode the passkey is requested after the password and replaces the authenticator prompt; in passwordless mode it signs in on its own and the password remains the recovery path. Administrators see the registered passkeys of every user, can revoke them and set the account's passkey mode. Requires the console to be opened over https, and installations reached through several host names can set a relying party ID override under Settings > SSO.
SSO: a new option "Force https in redirect URLs" covers deployments behind a reverse proxy that terminates HTTPS but does not send the X-Forwarded-Proto header. It resolves the Keycloak error "Invalid parameter: redirect_uri" in such setups. If your proxy does send the header, nothing changes and the option can stay off.
Sign-in: the session, the second-factor prompt, the authenticator enrollment, the forced password reset and the audit trail are created from the account record that the credential check verified, rather than from the contents of the login form at that moment.
Devices & Remote Tools
A new page Devices > Topology draws the managed devices as a network map. Tenants contain locations, the subnets reported by the agents hang off the location's gateway, and the devices hang off their subnets. The external address the server sees each device connect from is drawn as a site node, so locations sharing an internet connection are visibly connected. SNMP devices are placed in the subnet that contains their address, and NetMesh links and meshes are drawn as an overlay. Virtual adapters and offline devices can be hidden, nodes and whole tenant boxes can be dragged into place with the arrangement stored per account, and a search dims everything that does not match. The page requires the new permission "Device Topology".
Eleven remote tools can be opened in a browser window of their own - Shell, File browser, Task Manager, Screen Control, End user chat, Windows Event Logs, Windows Registry, SNMP Tools, Network discovery, Disk usage and Patch Now. Every tool button in the device panel has a small "open in new window" button next to it, and the right-click menu of the device list has an "Open in new window" sub menu. The windows are subject to the same permissions and policy switches as the tools in the device page.
A new "Task manager" action opens a live task manager for Windows, Linux and macOS. It lists the running processes with name, PID, user, real CPU usage, RAM, start time, path and command line, refreshes at a selectable interval and can be paused, searched and sorted. A process can be terminated alone or with its whole process tree after a confirmation, which is written to the audit log. The Applications tab keeps the process snapshot of the last sync and gets a button that opens the live view. The agents have to be updated for this feature.
A new "Disk usage" action opens a disk usage analyzer for Windows, Linux and macOS. It lists the volumes with capacity, free space and a usage bar, and a click on a volume starts a scan on the agent that walks the volume in the background and reports its progress.
A new "Network discovery" action scans a network from a managed device. The agent sweeps the private subnets of the device itself, or a range you enter (private ranges only, at most 4096 addresses), with ICMP, adds hosts from its neighbor cache, and where switched on resolves names and probes ports. It requires the new permission "Network discovery" and the new "Network discovery" checkbox in the Remote Control tab of the policy, which is off in policies that predate it.
The chat with the logged-on user is no longer part of the screen control. A new "End user chat" action opens it on its own: it lists the users signed in to the device and opens the chat window in the session you pick. With exactly one user signed in the dialog goes straight through.
The device details get a new "Authentication" tab, and the unauthorized devices page a new "Authentication log" row action. Both list every agent check-in the server did not accept as a plain success, with the hardware ID the agent sent next to the stored one, the access key prefix, the endpoint, the remote address, the agent version and a reason. The log is written by the server; agents need no update. Requires the new permission "Authentication log"; retention is configurable and defaults to 90 days.
The device details get a new "Uptime" tab that shows, for the last seven days, when the agent was reachable from the server and when it was not. A background service checks every authorized device once a minute and stores only transitions, so a device that stays online writes nothing. No agent update is needed. Gated by the new permission "Uptime"; accounts that already hold "General" receive it with the upgrade.
The shutdown and reboot actions can warn the logged-on users first. A checkbox in the confirmation dialog reveals a message text and a delay in seconds (10 to 3600, default 180); the tray icon shows the message with a countdown to every logged-on user, RDP sessions included, and the action runs when the countdown expires. Without the checkbox the action executes immediately as before, and when nobody is logged on it runs immediately as well. The texts are configurable in the policy's Tray Icon tab. The agents have to be updated for this feature.
The remote file browser accepts multiple files in one pick, up to 500 per upload, with per-file progress; a failed file does not stop the rest and a running upload can be cancelled. A new "Upload folder" button transfers a local folder including its subfolders and recreates the structure on the device. Empty subfolders cannot be transferred because browsers do not report them.
SNMP Network Discovery
Policies have a new tab "SNMP Discovery", enabled by default. Every agent the policy is assigned to scans the private subnets of its own network interfaces and additional ranges you enter, using SNMP v2c with a v1 fallback, on the interval set in the policy (24 hours by default). Public address space and virtual adapters are never scanned, and SNMP v3 devices are still added manually. Turn it off in the policies of devices that should not scan, for example roaming laptops.
Found devices appear under Devices > SNMP with vendor, system description, name, location, contact and MAC address. They are matched by IP, then MAC, then sysObjectID and sysName, so a device that changes its DHCP address keeps its entry and a device seen by two jump hosts is listed once. Manually added devices are never duplicated. A device missing from two consecutive scans is marked offline and raises an event, but nothing is ever deleted automatically.
For each newly found device the server creates an availability check every 5 minutes and an inventory poll every 15 minutes and assigns them to the jump host that found it. The sensors appear in the sensor management marked "Discovery" and can be edited or deleted like any other. Devices > SNMP shows the last scan per location and a load indicator per jump host, new devices go to the least loaded host, and "Rebalance monitoring" redistributes the existing ones. A "Scan now" action starts a scan immediately, and a new event type "SNMP Discovery" carries the new-device, not-seen and capacity events.
Discovered devices get a third automatic sensor that raises an event when a port that was up goes down, error rates or link flapping exceed a threshold, the device rebooted, printer supplies run low, a UPS runs on battery, a disk crosses the usage threshold, or a hardware sensor leaves its normal state. Only standard MIBs are used and only the checks the device supports actually run; the capabilities are detected during discovery. The first run records the baseline only, and a resolved notification is sent when a problem clears. Everything is on by default and configurable per policy, and health monitoring can be switched off per device.
SNMP sensors on an agent are executed in parallel (32 at a time by default, adjustable per policy) instead of one after another, so a jump host can monitor well over a thousand SNMP devices. Stored monitor results are kept for 7 days. Deleting an SNMP device also removes the sensors discovery created for it and its results, and the dialog warns about other sensors that still reference it.
Patch Management
A new read-only "Patch Job History" tab lists the Patch Now and Uninstall Update runs across all devices with the result of each run, with a drill-down to the per-update results. The same tab exists per device in the device details. The existing Update History tab is unchanged.
Linux policies have a new option "Configuration file conflicts". When a package update on an apt-based system asks what to do with a configuration file that was modified on the device, the agent now answers automatically instead of aborting: by default the installed file is kept, optionally the maintainer's version is installed. dnf and yum systems never ask and are not affected.
MSIX framework packages (Microsoft.VCLibs, Microsoft.WindowsAppRuntime, Microsoft.UI.Xaml, App Installer, Windows App SDK) are no longer offered as winget updates, because Windows does not allow the agent's system account to deploy them. A Patch Now run with selected updates only runs the stages those updates belong to, so a winget-only selection no longer waits for a full Windows Update scan first.
The patch management overview gets a new "Software updates" card that shows failed and available software updates, the "Devices missing software updates" figure opens the list of those devices, and the per-device missing-patches dialog lists software updates with a source column.
Scripts & Custom Fields
Scripts can refer to variables. The device built-ins ({{device.name}}, tenant, location, group, platform, operating system, domain, IP addresses, serial number, agent version and more) need no setup; {{field.key}} reads a custom field of the device, and {{tenant.key}}, {{location.key}}, {{group.key}} and {{global.key}} read the value of one level. The editor has an "Insert variable" menu that lists the built-ins and every manual custom field with a search field and inserts the token at the cursor. Variables are resolved per device, so the script a device receives already carries its values.
A script can write custom field values back, with Set-NetLockField (PowerShell), nl_field_set (Bash, Zsh) or nl_field_set() (Python3). The helper is defined automatically whenever the script calls it, and the values are taken out of the output of a job, a script sensor and its action script before the output is stored. Write-back also works from the real-time terminal with any remote agent version.
Custom field values can be kept on tenant, location, group and global level. A field marked "inheritable" is resolved for a device from its own value, then the group, the location, the tenant and the global value, whichever is set first; a field without the flag keeps its device value only. Changing a value marks the affected devices for a policy re-sync.
A new field type "Secret" stores its values encrypted and shows them as a mask everywhere in the console, while handing them to scripts like any other field. Revealing one requires the new permission "Reveal secret custom field values" and writes an audit entry each time. Secret fields are manual fields only.
A field key must be a lowercase identifier and unique across all definitions; the builder rejects a new or renamed key that breaks either rule. Existing keys are kept as they are. Deleting a tenant, a location, a group or a definition removes the custom field values stored for it.
Relay Server & Relay App
Every relay tunnel session carries a list of the web console accounts that may open a tunnel through it, set in the create and edit dialog and enforced on the server. An account can only be added when it holds the relay server permission and is assigned to the tenant of the target device. A session can now be edited at all - its description, whether it is enabled, and that account list; the route stays as it is. An operator with the manage permission can create a relay API key for another account, within their own tenants.
Every relay tunnel session that already exists has to be edited once after the update before it can be used again, because the list of accounts allowed to connect is empty for existing sessions. The session counter column is now called "Streams" - it always counted the connections carried through the tunnel rather than the administrators using the session - and a click on the number lists the administrators actually connected. The "persistent" option is gone; every session is stored.
Relay App: the sessions window has "Whitelist my IP", "Remove my IP" and "Auto-whitelist every minute", so an operator can whitelist the address they are working from without an administrator editing the static list. The matching section "Dynamic whitelisting via Relay App" under Settings > IP whitelist is off after the upgrade and has to be switched on. An entry lives 1 to 168 hours (24 by default) counted from its last refresh, and the section lists the active entries.
Relay App: the local port of a session can be changed, and a port that is out of range or already taken is refused instead of quietly moving to another one. Sessions can connect by themselves when the app starts, marked per session with a checkbox. A "Connection tools" button on the Relay Server page holds a server-wide list of named command templates - RDP and SSH are seeded as defaults - with one command per operating system, and a connected session gets an "Open with…" button for them.
Relay App: the app is translated into the same nine languages as the web console - English, German, Spanish, French, Italian, Dutch, Polish, Portuguese and Chinese (Simplified) - chosen in the app itself. The app also asks the server which version belongs to it: an app older than the server refuses to sign in and offers the download page, and one that is already running when the server is updated closes its tunnels. Update the Relay App after the server.
Screen control through a relay identity now also requires the remote control permission on the account that owns the identity. An operator whose account does not hold it loses screen control through the Relay App until it is granted; opening a tunnel is unaffected. Connecting to a session another administrator is holding is now an explicit takeover that is confirmed first and really closes the other connection.
Interface & Mobile
Every list page has the same layout for its actions. The buttons above the table are the ones that act on the page - Add, the page's own actions, Refresh, Export data, the documentation link, and the AI buttons last; Edit and Delete have left the toolbar. The actions of a single entry are a column of icon buttons at the right end of its row, in a fixed order, and an enabled state is a switch in its own column. A double-click on a row opens the entry.
Dialogs use a common set of widths instead of a size chosen per dialog, their buttons sit in the same order and size everywhere, every two-way confirmation is the same shared dialog, and Escape closes a dialog. Notification toasts appear at the bottom right with a close icon and stay for a time that follows their severity - success 3 seconds, info 4, warning 6, error 8. Messages that were still English literals are translated.
The phone layout has been reworked, in the New theme and in Classic. Dialogs open full screen while short confirmations stay small prompts, tables stack with the column name in front of each value, wide tables scroll in place instead of widening the page, and small buttons get a tap area of 40 pixels.
The console can be installed as an app (PWA) on desktop and mobile devices. The app name and colors follow the whitelabeling title and theme, a custom 512x512 app icon can be uploaded under Settings > Whitelabeling, and an "Install app" button in the app bar triggers the install prompt. Requires HTTPS with a trusted certificate.
The app bar has an account menu. The home icon and the separate logout icon are replaced by an avatar that opens Profile, Personalization, Security, Mobile app and Logout, each opening the account page directly on that tab. Accounts can set a profile picture on the profile tab, reduced to 256 x 256 in the browser before it is uploaded.
The account page is organized into the tabs Profile, Personalization, Security and Mobile app, each with its own address. The Collections navigation entry "Device Control" is now called "USB Device Control", since it only ever covered USB device control.
Other
Message of the Day: a new page lets you publish announcements to your managed devices, for example maintenance windows or urgent notices. A message has a title, a body and a severity, can target all devices, a tenant or a location, and can carry a start and expiry date. The tray icon shows it at login, and signed-in users receive new messages within moments. Per message you choose whether it appears once per user or at every login while it is valid. Requires the tray icon to be enabled in the device's policy.
Retention: Settings > Retention & cleanup has a new section for event retention rules that gives single kinds of events a retention of their own, shorter or longer than the global events history. A rule matches the event text exactly, by prefix or by substring, and can be narrowed to an event type, a severity, a source, a tenant or the read state.
Sensors: the path fields of the file and directory sensors expand environment variables in the forms %VAR%, $env:VAR and ${VAR} on every platform. A path that starts with {user_profiles} is checked in every local user profile, and a registry key path of the Registry change watch sensor that starts with {user_sids} is watched in every user hive currently loaded, so a SID no longer has to be looked up by hand. Both keep a separate baseline per profile or user.
Sensors & jobs: the add and edit dialogs have a new "Assign to policies" action that activates the sensor or job in one, several or all policies directly from the dialog, and removes it from the ones that are unchecked. The add dialogs save the record first. Requires the policies edit permission.
Jobs: a new per-job option "No log" stops the job's executions from writing events, so its runs leave no trace under Events and are not delivered to API webhooks. Meant for jobs that run at very high frequency and would otherwise fill the events table. It takes effect for all devices immediately, including those whose agent has not been updated.
Notifications: every notification target (e-mail, Microsoft Teams, Telegram, ntfy.sh, webhook) has an on/off switch in its list. A disabled target keeps its configuration and tenants but receives no events until it is switched on again; the test button still works, so a channel can be verified before enabling it.
Tray icon: the support chat window, the support badge and the remote access request show the name and the profile picture of the admin who is connecting. Before, the request did not say who was asking. Each account decides on its account page whether its picture may be shown to end users; this is off until the account turns it on.
AI / LLM: the per-feature toggles are back and now cover ten surfaces instead of five: script analysis, remote shell, event analysis, sensor and job creation, event log analysis, ticket analysis, audit analysis, the automations assistant, the operator AI chat and the end-user chat in the agent tray. Each toggle only narrows what the master switch allows.
Policy settings: the custom tray icon buttons can be brought into a specific order with "Move up" and "Move down", and the tray menu lists them in exactly that order. Existing policies keep the order their buttons already have, and no agent update is required.
Public API: custom field values on tenant, location, group and global level are readable and writable, and the device endpoint can return the effective value per field with the level it comes from. SNMP device resources expose the discovery and health monitoring fields and can be filtered by discovered. Relay session endpoints take the accounts allowed to open a tunnel, and notification targets expose their on/off switch.
Mobile: the "Enroll mobile device" dialog shows the enrollment code as copyable text below the QR code, for a device that cannot scan it, and the Android app accepts that text form on its start screen. The agent app is translated into the same nine languages as the web console, can be set to a language of its own on Android 13 and newer, targets Android 16 (API 36) and carries the new launcher icon. Mobile device enrollment is not available in the web console yet: the app is awaiting Google Play approval, and the mobile areas show a notice instead.
Mini games: the gamepad icon in the app bar opens an Arcade with three games instead of starting Virus Defense directly, and the entry is now in the overflow menu of the phone layout as well, where the games could not be reached at all before. Virus Defense has been rebuilt with a campaign of three levels and a free play mode. The second game is Kernel Panic, a first-person game in which an administrator clears a data center over three levels. The third is Overclock Rally, a racing game with a career over four divisions, a quick race, a time trial with a saved ghost lap and an endless season.
Improvements
Events: the events list, the events panel of the dashboard and the Events tab of a device no longer load the complete result into the browser session before showing it. They request one page at a time, with search, sorting and filtering running in the database, so the list opens right away on installations with many events. The automatic refresh no longer rewrites the list while it is being read; new events are announced as a count. "Mark as read" now marks only what the current filter shows and the account may see, asks for confirmation and writes an audit entry - it previously marked every event of the installation.
Audit: the audit log gets the same treatment as the events list and is rebuilt on the layout the other pages use, with the filters in a grid, a column chooser and one "Export data" button. The exports escape every field, the AI analysis summarises everything the current filter covers, and a date range of a single day includes that whole day.
Devices: the process list is no longer a tab of its own - the processes of the last inventory run are a sub-tab of the Applications tab, directly after "Installed". Neither the task manager nor the software permission grants the other's content. The remote tool buttons run Shell, File browser, Task Manager, Screen Control, End user chat and Patch Now first, then the platform-specific tools.
Devices: the disconnection alert no longer follows the agent's connection directly. The server samples the connection state once a minute and writes "Device disconnected." only when a device has held no connection for longer than a confirmation period, set under Settings > Maintenance > Connection alerts and defaulting to three minutes. Short interruptions no longer raise an alert.
Devices: scrolling the device detail no longer stalls while a selected device is online. The detail panel builds only the tabs that have been opened instead of all of them on every update, and a live CPU or RAM reading redraws its own card instead of the whole page.
Server & web console: the appsettings.json configuration file is now stored encrypted at rest, since it contains database credentials and API keys. The existing file is encrypted automatically on the first start after the update; nothing needs to be done. To change it afterwards, stop the service, replace the entire file content with plain JSON and start again.
Server & web console: forwarded headers from the upstream reverse proxy are accepted by default, since running behind a reverse proxy is the supported way to operate NetLock RMM, so token IP allowlists, rate limiting and the request log work on the real client address without configuration. The web console takes the same "ForwardedHeaders" block under "Kestrel" the server uses, which allows trusting a whole network instead of listing single proxy addresses.
Web console: the static IP whitelist takes effect within a few seconds of saving instead of at the next restart. A list that would lock out the administrator editing it asks for confirmation instead of being saved silently.
Sensors: the event of a script sensor no longer carries the script body, since scripts are rendered per device and the body would contain the resolved variable values. Editing the path, pattern or recursion of a Directory change or File change sensor records a fresh baseline on the next run instead of comparing the new location against the old baseline once.
Tickets: the "Labels & Types" and "SLA" tabs under Settings > Ticket system now require the permissions "Manage labels and types" and "Manage SLA", which the public API already enforced. Grant them under Users > account > permissions to restore the tabs.
App Hub: install, update and uninstall scripts on Windows now count as failed when the script exits with a non-zero code, in addition to output that starts with "Error".
Jobs: the jobs page and the add/edit dialogs point out that a job only runs once it has been enabled in a policy assigned to the device. Creating the job alone does not schedule it on any device, which was easy to miss on a fresh installation.
Removed
Website uptime monitoring: the DNS record monitoring option of a website monitor is removed. Because resolvers hand back a different subset of the record set from one query to the next for round robin, GeoDNS and CDN names, it reported a change on nearly every check for records that had not changed. This is a breaking change on the public API; deploy the server before the web console.
Remote shell history: the Remote tab on the device page, its history table, the export and the "Remote Shell History" retention setting have been removed, and existing history rows are dropped by the upgrade. Instead, every completed classic remote shell command now writes an event "Remote shell command executed." of the new type "Remote Shell" on the device, carrying author, run-as user, shell and the output. The command text is not stored. Custom field sections that targeted the Remote tab have to be re-assigned.
Tray icon: the support chat window no longer opens with a preset greeting in the admin's name. The policy options "Show Welcome Message" and "Welcome Message Text" are gone; the conversation starts with the first message the admin actually writes.
Devices: the "Class" column is removed from the device list; the value is still kept per device.
Web console: the whitelabeling checkbox "Home" and the home icon it controlled are gone; the account menu in the app bar replaces them.
Bug Fixes
Patch management: no progress report of a patch job ever reached the server, silently and only visible with debug mode, so Patch Now and Uninstall update stayed on "Pending" in the web console. Reports now arrive, and one the server could not accept - during a server restart, for example - is delivered with the next sync instead of being dropped after three attempts.
Patch management: a Patch Now job could stay "Pending" when the remote agent's connection to the comm agent was down at that moment; the command is now held for up to 10 minutes and delivered when the connection returns. An on-demand run that queued behind a scheduled patch cycle now reports itself as soon as the device accepts it, waits at most 60 minutes and gives up with a clear reason. A job the device does not pick up is closed after 10 minutes instead of blocking the device for a full hour, and an open job can be ended from its progress view so the device is free for a new attempt right away.
Patch management: a device whose winget, Chocolatey or Windows Update query failed did not report any updates at all for that cycle; the sources that answered are now reported independently. winget items whose package is no longer installed, already up to date or not installable from the system context are reported as skipped with the reason. On Debian and Ubuntu devices, an update that asked what to do with a modified configuration file aborted and left the package system in an interrupted state that blocked every further update, and a Linux device that had installed all of its pending updates kept showing them as pending. Deploy the server before the agents.
Agent: the local channel between the remote agent and the tray icon on one side and the communication agent on the other handed every connection the stream of whichever program had connected last, so from the moment a second program connected, commands sent on the older connection went to the wrong place. This affected end-user AI chat answers on machines with several signed-in users, deployment steps that run in the user context, and patch reporting. The communication agent also wrote nothing at all on a device without debug mode, not even its error log; the situations in which requested work disappears are now logged.
Web console: every account was signed out whenever the container was updated. The key ring that encrypts sign-in cookies, antiforgery tokens and protected browser state lived inside the container's own filesystem and was generated again each time the container was recreated.
Web console: copy-to-clipboard buttons did nothing in Safari on macOS and iOS while still reporting success, and on consoles served over plain HTTP a copy action could disconnect the session. All copy actions now write to the clipboard directly in the browser click and fall back where the Clipboard API is unavailable. An SSO field that an administrator had cleared was also stored as an empty value instead of as unset, so the documented defaults never applied and the request pipeline answered every request with an error.
Remote screen control: session recordings were not being saved. Since remote control moved to the direct screen stream, the web console no longer received the frames it used to write to disk, so "Start recording" only reported "GIF saved" without storing anything. On Windows 8.1 and Windows Server 2012 R2, the remote agent could also not connect to a server reached through a reverse proxy enforcing the HTTP/2 cipher suite rules, for example Traefik in the documented Docker setup, so the device reported normally but remote control never worked.
Remote shell: a real-time terminal session that ran longer than five minutes stopped showing output while the shell on the device kept running, because the server's periodic cleanup removed the entry it needs to route the output back to the console. A classic-mode script that prompts for input hung until the timeout when "Run as user" was selected, and selecting a template in the real-time terminal typed it line by line so a prompting template got out of step - the template is now staged as a temporary script file and started with a single call. A command with empty output no longer keeps the dialog waiting until the timeout.
Remote file browser and event log: uploading a file whose name contains characters outside the ASCII range - German umlauts, accented letters, Cyrillic or Chinese characters - created the folder on the device and reported the upload as finished, while the file never arrived. The log name dropdown of the remote event log also only showed the first entries of the list reported by the agent, so on devices with many event channels the standard logs "Security", "System" and "Setup" were not offered unless their name was typed.
Relay App: the throughput of a tunnel was capped far below the available bandwidth, because all streams of a session share one connection whose replay buffer bounded the data in flight. No agent update is required.
Devices: a chat with an end user stopped delivering the user's replies after about five minutes, a message typed into the chat of the screen control dialog without opening the chat window first reached the user while their answer never arrived, and closing the screen control dialog left the chat window standing open on the end user's desktop. A device with the disconnection alert switched on could be reported as connected several times without the disconnection in between ever being reported. A reboot sent by an operator with the reboot permission but not the shutdown permission was silently rejected although the console offered the button, and the three permissions for the controlled folder access processes had no checkbox in the permissions tab.
Tray icon: the texts of the remote access request that can be set in the policy's Tray Icon tab were never applied; the request always showed the built-in English texts. The support badge for unattended access requested through the older access path also did not carry the admin's name. Requires updated agents.
BitLocker and App Hub: recovery keys of volumes that were already encrypted before the policy was assigned were never reported to the server, and in monitor mode no keys were collected at all. winget apps with a source other than 'winget' were always installed from the 'winget' source by the tray icon, uninstall strings without quotes around a path containing spaces were cut at the first space while the action still reported success, and a catalog download that stalls is now cancelled after 30 minutes and retried instead of blocking the catalog service.
Tickets, notifications, sensors and custom fields: department notification settings were saved but no e-mail was ever sent for them, and tickets created in the web console or by the e-mail import were stored without a tenant assignment, so GET /v1/tickets did not return them. A label could only be added with the pre-filled colour. The notification dialogs accepted removing every tenant and only failed after pressing Save. Changing the key path, the hive, the recursion or the value limit of a Registry change watch sensor compared the new key against the old baseline, the device selection in the SNMP sensor dialog listed devices of all tenants, and fields of type "job result" stayed empty for agents running with a German system language.
Android app and server: the app could report "Cannot reach the server" on an installation it was in fact reaching, because it identified itself with an HTTP header whose name contains an underscore and nginx drops such headers by default. Every answer other than success was also reported the same way, so a refused enrollment code was indistinguishable from a phone with no reception. While the database was unreachable, the check of an agent's package configuration could not run and the device was told its identity had been rejected; the mobile endpoints now answer that case as a temporary service problem. The end of an agent connection was also written to standard output with the device's full identity document, including its access key; it now goes to the debug log without the identity.
v3.2.0.0
Solar Eclipse
August 17, 2026
This release lays the groundwork for the upcoming MDM capabilities by introducing an Android app. It covers device details, ringing and locating devices, sending messages to end users, and accessing their screens; remote wipe and iOS management follow in later versions. The long-requested REST API also arrives with this release.
⚠️
Attention: this update adds features and quality of life improvements that require you to set or enable the corresponding permissions in the user management. Otherwise there will be things you do not see.
Upgrade your installation as usual: https://docs.netlockrmm.com/docs/part-iii/how-to-upgrade-netlock-rmm
✨ Android app as the groundwork for MDM✨ REST API v1 with 372 functions under /v1✨ Central BitLocker management✨ Web console fully translatable, in nine languages✨ Automatic session targeting in remote control
New Features
An Android app lays the groundwork for the upcoming MDM capabilities. It covers device details, ringing and locating devices, sending messages to end users, and accessing their screens. Full MDM capabilities such as remote wipe, along with iOS management, follow in later versions.
A REST API is available. The first version ships with 372 functions under /v1, covering devices and their inventory, events, tickets, patch management, policies, scripts, jobs, reports, notifications, and more.
BitLocker can now be managed centrally.
Sensors can be tested live against an online target device from the add and edit sensor dialog, so you no longer have to configure them blindly. Assign yourself the required permission in the user management first.
The remote screen control in the web console gained an OCR scanner for extracting text from the remote screen.
Improvements
The web console is now fully translatable and ships in nine languages.
Remote control picks its target session automatically: when a session starts, the agent probes each logged-in session for a working capture and connects directly when only one produces an image. If none does, you get a clear "no active session" state with a retry option instead of a black screen.
The experimental support for devices with no screen or with disabled screens has been extended; these devices should now be reachable reliably.
Patch management: patch status should be reliable now, various issues have been resolved, and quality of life improvements were added, such as a new view and status symbols in the device overview.
The agent download section has been completely overhauled; creating a config is no longer required.
Substantial performance improvements in the agent backend and the web console.
Removed
The per-sync device inventory history is gone. Device pages now show the current state only. CPU, RAM and disk history, device notes and remote shell history are not affected. The corresponding history tables are dropped during the upgrade, meaning their data is permanently deleted. The reason: even with strict retention settings, the amount of data being produced was hard to keep under control, causing server outages and support overhead.
Bug Fixes
Several hundred bugs were fixed across the platform; they are not listed individually.
Patch management received particular attention: various issues have been resolved.
v3.1.0.7
Audit Trail
July 14, 2026
This release adds notification delivery results to events. Sending notifications (SMTP, Microsoft Teams, Telegram, Ntfy.sh, webhook) was previously fire and forget — if a delivery failed, there was no way to see it. Each event now stores the result of every delivery attempt. This release also extends the audit log to cover nearly all administrative actions in the web console and records the acting user's IP address consistently.
⚠️
The Relay App was rebuilt for this release. If you use it, please download the new version from https://netlockrmm.com/downloads/.
✨ Notification delivery results stored per event and channel✨ Audit log now covers nearly all administrative actions✨ Relay sessions can reach a remote host through the device (jump host)✨ App Hub catalogs built centrally and pulled as prebuilt databases
New Features
Events store the delivery result of every notification per channel, including the target, success state, error message, attempt count and timestamp. The event details dialog gains a "Notification result" tab.
A new "Notification result" permission controls access to the tab. Enable it in your roles under user settings; existing roles do not receive it automatically.
The audit log now records nearly all administrative actions, including remote control, remote shell, file, registry and service operations, SQL console queries, software deployment, App Hub changes, tickets, reports, dashboards, relay sessions, notification channels, and SSO and IP whitelist changes. Data exports are logged as export events.
Relay sessions can now target a remote host reached through the device (jump host) — for example a printer web UI where no agent can be installed — instead of only a local port on the device.
Improvements
App Hub: the Winget, Flathub and Chocolatey catalogs are now built centrally by the Members Portal and pulled by each server every 6 hours as a prebuilt, versioned database. Servers no longer clone the winget repository or crawl the upstream feeds, and Chocolatey packages are now cached locally like Winget and Flathub.
Dashboard: the default "Online / Offline Devices" chart now uses a 24-hour window and is renamed "Online / Offline Devices (24h)". Charts you have renamed or customized are left untouched.
Audit: entries are queued in memory and written by a background service, so recording never delays the action. Security-sensitive actions are recorded with elevated severity, and saves containing credentials record only that the field changed, never the value.
Bug Fixes
Sensors: the script dropdown was empty when creating or editing script sensors (PowerShell, Bash, Zsh, Python3); the affected fields now receive the real values.
Devices: in a device's events tab, an event no longer disappears from the list after opening and closing its details dialog.
App Hub: the Winget catalog now keeps the highest version of each package instead of the last one enumerated.
Audit: SQL console executions on /settings are now recorded, and patch auto-approval rules store the real entity id instead of "0".
v3.1.0.6
Responsive Input
July 11, 2026
This release fixes the input lag in remote screen control. Remote sessions now respond smoothly, regardless of the codec in use. Note that the H.264 codec uses more bandwidth than JPEG.
⚠️
The Relay App was rebuilt for this release. If you use it, please download the new version from https://netlockrmm.com/downloads/ to get this fix.
✨ Remote screen control input lag fixed✨ User process launches reliably with UAC compatibility✨ Relay App: sessions and devices lists display correctly again
Improvements
Reworked how remote screen control processes keyboard and mouse input. The previous method could slow the new imaging path down heavily, which in turn delayed input and could drop keystrokes and clicks during a session.
The user process now launches reliably in the user session with UAC compatibility.
Bug Fixes
Relay App: fixed the sessions and devices lists showing up empty — both are displayed correctly again.
Some of you already know the Relay. The problem: there are a few hundred NetLock RMM installations out there by now, and setting up the relay was cumbersome for some of you — and caused quite a bit of support overhead on our end. The last version reworked how the remote screen control networking works. This update now moves the Relay App tunneling to the same technique. That removes the extra nl-relay subdomain, and no configuration changes are needed after updating. When I built the first relay prototype, it was the best approach I saw at the time — but the new technique is faster and works with your existing setups without any changes. Thanks for your patience! Alongside, this update ships a number of bug fixes and quality-of-life improvements.
⚠️
Please test and report back: this update includes an experimental change that should enable unattended remote screen control on machines with no display attached (or a disabled display), plus a fix for the multi-monitor mouse-cursor issue. If you can now connect to previously affected machines — or still can't — please let us know.
✨ Relay tunneling migrated to the new screen-control networking — no nl-relay subdomain, zero configuration changes✨ Missing permissions no longer log you out — you get a clear message instead✨ Table page-size selections are now remembered✨ Pending deployment jobs can be edited✨ Experimental: unattended screen control on devices without an active display✨ Mail notifications now work with on-premises Microsoft Exchange and other strict mail servers, and port 465 (SSL/TLS) is now supported✨ CSV export is back in all "Export Data" dialogs✨ Detection scripts for custom applications now work✨ SSO sign-in (e.g. Keycloak) now works behind a reverse proxy
Improvements & Quality of Life
The rows-per-page selection in tables is now remembered (stored in your browser's local storage).
Permission gating reworked: instead of being logged out, you now get a message telling you that you are not allowed to access the resource.
New Relay App release for Windows, built on the new tunneling technique.
Deployment jobs can now be edited as long as they are still pending.
Experimental: unattended remote screen control on machines with no display attached or a disabled display — this should enable remote screen control on more devices; please test and report back.
Mail (SMTP) settings now also support port 465 (SSL/TLS). Previously only STARTTLS (e.g. port 587) worked.
The SMTP test button now shows the actual response from your mail server if sending fails, instead of a generic error message — making it much easier to find the cause.
All "Export Data" dialogs now offer CSV export again, alongside JSON and HTML. The non-functional "Spreadsheet (.xlsx)" option was removed.
Custom applications: detection scripts are now evaluated. If the script reports the app as already installed, the installation is skipped and shown as "Skipped" in the deployment results. A how-to guide with examples will be available in the docs at docs.netlockrmm.com.
If an SSO sign-in fails, the login page now shows a clear message instead of an error page.
'Patch now' remote action: fixed a bug that caused Windows updates not to install — the action now also reports detailed status updates.
Attended remote screen control: after the user accepts the session request, screen access is now granted correctly.
The operator's first and last name is now shown correctly on the attended access request dialog.
Fixed a bug where Application Control & USB Device Control caused the agent to go unauthorized.
Scripts now display the author correctly.
Fixed a potential race condition in the agent's config loader that caused unattended access to fail.
Remote screen control: fixed a multi-monitor issue where the mouse cursor ended up on the wrong screen — please test and report back.
Fixed a bug where old relay sessions could not be deleted in the web console.
Fixed a bug that caused webhooks not to trigger correctly.
Fixed a bug that caused the remote control SNMP walker to fail.
Fixed mail notifications failing against certain mail servers, especially on-premises Microsoft Exchange ("5.7.57 ... not authenticated"). NetLock now always logs in with the configured username and password instead of letting the server pick a Windows-specific authentication method that is not available in Docker. This affected alert mails, report mails and the SMTP test button.
Fixed SSO sign-in (e.g. Keycloak) failing behind a reverse proxy with "Invalid parameter: redirect_uri". The web console now sends your public HTTPS address to the identity provider instead of its internal container address — no configuration changes needed. Note: if you restrict web console access by IP, the console now sees the real client IP instead of the proxy IP, so check your allowed-IP list after updating.
Fixed sensor webhook notifications never being sent when the event text contained line breaks or quotes.
v3.1.0.0
Sovereign AI
July 5, 2026
After 3.0.0.0 shipped a whole wave of flagship features, this update focuses on refining the platform: performance, stability and lots of fixes. But of course we brought a few new highlights along. First up: NetLock AI. You could already connect your own AI models to your NetLock RMM installation — for everyone without a suitable model at hand, we now offer NetLock AI, managed and operated by us: privacy-friendly AI hosting based on a strong open-source model, hosted in Germany, with a strict no-logs guarantee. Building on that, you can now offer your users an AI chat right in the NetLock RMM tray icon: users register an account in the tray icon, chat histories are stored end-to-end encrypted on your NetLock RMM installation, and you control and cap the token budget entirely from the web console — powered by your connected AI model or, on demand, by NetLock AI. This is the first step of our planned AI expansion, giving you and your users a sovereign experience without technical back and forth — and of course it is all optional and can be disabled. Next, our sensor offensive: we completely reworked and modularized the sensor system, and with a new partner on board we now offer 350+ sensor templates for countless NAS, firewall, antivirus and other vendors. Happy monitoring! Finally, our Relay app is now officially available: establish end-to-end encrypted TCP tunnels from your admin machine straight to the target device, or launch remote screen control directly — with performance benefits over the web console. The web console itself now also officially ships the relay mode for better remoting performance. We are looking forward to a strong future and your feedback!
✨ NetLock AI — managed, privacy-friendly AI hosted in Germany with a strict no-logs guarantee✨ End-user AI chat in the tray icon — end-to-end encrypted, with token budgets managed from the web console✨ 350+ new sensor templates for NAS, firewall, antivirus & more vendors✨ Relay app for Windows, macOS & Linux — E2E-encrypted TCP tunnels & high-performance remote control✨ Relay mode in the web console for faster remote sessions✨ Patch auto-approval, fleet patch overview & on-demand 'Patch now'
Remote Access & Remote Control
Relay app released for Windows, macOS and Linux — establish end-to-end encrypted TCP tunnels from your admin machine to the target device or start remote screen control directly, with noticeable performance benefits over the web console.
Remote Screen Control: full relay support for Windows.
Remote Screen Control: mouse wheel support (scroll up/down).
Remote Screen Control: improved copy & paste performance for text.
Remote File Browser: built-in previews for images and PDFs directly in the web console.
Remote File Browser: create and extract ZIP archives.
Remote Windows Registry Viewer: the destination path can now be copied & pasted.
Remote Service Control: now state-aware — shows the service state in the UI and automatically refreshes it after a remote action.
New remote feature: uninstall the agent remotely.
New remote feature: 'Patch now' — patch devices on demand.
Remote Shell (real-time): improved terminal visuals and readability.
Tray Icon
'Operator connected' indicator reworked — now closable and reappears automatically after 30 seconds.
Displays the support operator's first and last name instead of their web console username.
Chat: the operator username is now displayed correctly.
All texts and messages can now be customized via policies.
Linux & macOS: support for notification settings.
Patch Management
Configurable auto-approval to automatically approve specific patch types.
New fleet status overview for a better overall picture.
Clicking the 'Pending' / 'Installed' figures in the header shows the corresponding devices.
The view is now tenant-scoped — only approved tenants are shown.
Patches can be deleted from the approval overview.
Ticketing System
Tickets can now be merged — requires the new merge permission.
Replies are sent as a thread (last 10 messages) so customers can follow the conversation more easily.
Templates view reworked and improved.
Chat bubbles visually reworked for better readability.
White-Labeling
The custom title is now also applied to the browser tab.
The custom logo is now used as the favicon.
Other
NetLock AI: our new managed AI offering — privacy-friendly AI hosting based on a strong open-source model, hosted in Germany with a strict no-logs guarantee. Perfect if you don't have your own AI model to connect.
End-user AI chat with configurable limits and policy controls — chat histories are stored end-to-end encrypted on your installation, token budgets are managed in the web console.
Sensor system completely reworked and modularized: 350+ new sensor templates for countless NAS, firewall, antivirus and other vendors.
The device serial number is now shown in the general device information.
The OTP setup code can now be copied in both the members portal and the web console login.
Cloud: IP whitelisting can be disabled/reset via the members portal.
Cloud: SSO can be reset via the members portal.
Improvements
Remote agent connection gating overhauled: client-side gating of the remote sub-features (incl. Remote Screen Control) was removed and replaced with server-side gating. Policy changes are now applied to existing remote connections instantly.
CPU & RAM live display: refreshes 15 times after selecting a device, then pauses until manually resumed (to preserve performance).
Ubuntu: full Wayland support.
Linux (ufw) & macOS: improved firewall status detection.
Policies can now be renamed.
Policy save: affected devices sync their new configuration within one minute.
Deleting a tenant/location: the associated agents are now uninstalled automatically.
Renaming a tenant/location: stored names in existing events and related records (events, infrastructure events, performance monitoring, SNMP devices) are updated as well, so historical entries no longer keep the old name.
Wake-on-LAN: the jumphost can now be selected manually.
Moving devices & bulk remote shell: checkbox selection is preserved — the automatic 30-second refresh pauses during selection.
Agent configurations must now be alphanumeric.
Mobile: performance issues fixed, operation noticeably smoother; mobile view reworked.
Numerous UI improvements across the web console.
Bug Fixes
GUI installer (macOS): the remote service was not installed, making remote features unavailable — fixed.
Headless domain controller (Windows Server 2012): fixed a handle leak in a specific scenario that led to out-of-memory.
Wake-on-LAN (Linux & macOS): the magic packet could not be sent due to incorrect subnet formatting (no valid jumphost found) — fixed.
Windows event log sensor: fixed a timing issue that prevented the sensor from running at all.
Event browsing: showed no events when the start and end date were identical — the end-date filter now covers the entire day (dashboard, events, device view).
Ticketing system: webhooks failed (the upgrade SQL could not execute the webhook query) — fixed.
Ticketing system: fixed duplicated line breaks when replying.
SSO: integration with Keycloak and Auth0 now works as expected.
Patch management: maintenance windows were ignored — fixed.
Patch management: the 'updates installing' tray popup was triggered every 5 minutes — now only appears during an actual installation.
Patch management: the dialog showing the next installation time now displays the time correctly.
Removed
External IP automation removed (no practical benefit).
v3.0.0.0
Astaroth
May 5, 2026
We are working hard to become — over time — the best, most transparent, and fairest RMM out there. And yes, this is a massive upgrade. To be honest, the changelog only covers the main adjustments and highlights, but under the hood this has been a massive improvement in terms of performance and scalability. Thank you to everyone walking this journey with us and trusting us with their IT environment.
⚠️
If you are already running a NetLock RMM instance, this update requires you — after the server-side update completed — to go to /automations, open every automation and re-add the desired equal field. This was required to extend how the policy provisioning works. Otherwise upgrade as usual via the standard docker command (https://netlockrmm.com/docs/upgrade).
Heads-up: to use the new features, operators have to grant themselves the corresponding permissions in the user management first.
✨ Patch Management for Windows, Linux, macOS & third-party apps (winget, Chocolatey, Flatpak)✨ Integrated AI assistant with OpenAI-compatible LLM connector and feature-scoped permissions✨ Full ticket system with multi-department IMAP/SMTP, time tracking, SLA & CRM✨ Report Manager with builder, 53 pre-built templates, brand customization, PDF export & scheduling✨ Custom Fields, Custom Dashboards & a console-wide audit log✨ Remote Control overhaul: H.264 streaming, registry editor, Wake on LAN, 2FA gate, run-as-user shell
Patch Management
Patch management for Windows, Linux, macOS & Docker. Patch third-party applications through a winget, Chocolatey and Flatpak integration. Patching is no longer something you bolt on with sensors and scripts — it is now a first-class subsystem that knows about every device's OS, every pending update, and every reboot you owe your users. The goal was simple: turn 'I think we're patched' into 'I know we're patched, and here's the proof'.
Native handling for Windows, Linux and macOS, each with its own update vocabulary and severity model. Linux understands Security / Bugfix / Enhancement / Newpackage / Other crossed with Critical / Important / Moderate / Low. macOS distinguishes Security / Recommended / Other crossed with RequiresRestart / Recommended / Optional. No more pretending Patch Tuesday semantics map onto every platform.
Each operating system has its own switch and an 'informational only' mode that lets you collect a complete update inventory without installing anything — perfect for shadow-IT discovery before you flip the lights on.
An approval workflow on every detected update. Approve, defer, or leave a patch in its default state per device or in bulk; nothing gets pushed unless you said it could.
Deployment rings configurable per severity and per OS. Ship Critical patches to your pilot ring on day zero, Medium patches a week later, Informational once a month — your call, your cadence.
Patch Tuesday-relative scheduling. Roll out updates 'Patch Tuesday + 2 days', 'Patch Tuesday + 7 days', or 'the first weekend after'. Stop building this calendar yourself.
Allowed-weekday rules so you can blacklist days that matter to your customers (no patching on Thursdays for the accounting client, never on Fridays for the law firm).
Smart maintenance windows that respect reality on the device: don't patch while a user is active, only patch on AC power, never during an active RDP session.
A free-disk-space precheck so a patch run doesn't wedge a device on a full SSD.
Catch-up installs for devices that were offline during their slot — they pick up where they left off the moment they come back.
Separate policy lanes for OS patches and third-party application patches. The OS gets one schedule, winget / Chocolatey / Flatpak get another.
Reboot handling that an actual user can live with: fully automatic, prompt-with-deferral (with a max-deferral cap so deferrals can't run forever), or never. The Tray Icon talks to the Comm Agent and surfaces escalating reminders before a reboot, plus a live 'installing updates for you' status banner whose text you can customize from policy.
A pre-warning shown to the end user before a patch run starts at time X, so the workday doesn't get hijacked.
Patch rollback automation: when the failure rate of a patch crosses a threshold (default 5%), the approval flips so it stops getting deployed. You see it, you fix it, you re-approve.
Per-patch install duration tracking. Every install records how long it took, so you can spot the patch that turns a 5-minute reboot into a 45-minute coffee break.
Configurable retry count and retry interval on failed installs.
Toggle for installing patches over metered or cellular connections — off by default, because nobody wants a 700 MB cumulative update on tethered LTE.
Wait-until-all-pending-patches-are-installed before requesting or forcing a single reboot. One reboot for the whole patch run, not one per patch.
The reboot required state of a device is surfaced directly in the device list and on the device detail view, so the operator never has to dig.
For Windows, the install date pulled from the WUA QueryHistory is recorded in the update history. Real timestamps, not the agent's best guess.
AI & MCP
A pluggable LLM connector now sits inside the web console. It speaks the OpenAI API dialect, so you can point it at OpenAI itself, at Claude, or at a self-hosted open-source model — your choice, your keys, your data path. There is no vendor lock-in here.
The active LLM, its base URL, model name, and API key are configured in settings and changeable on the fly.
Streaming responses are supported end to end, so longer answers render token-by-token rather than waiting for a full payload — feels like a real terminal, not a 30-second spinner.
A persistent chat, scoped per operator account. Conversation history is stored in the database with proper retention controls — there is a configurable cleanup that purges old chats after N days.
Per-feature permission toggles are wired up so you can decide exactly where the assistant is allowed to operate.
Where the assistant actually plugs into the product:
Scripts page. The assistant can read a script and propose edits, surfaced as a Monaco-style diff you accept or reject. No silent rewrites.
Real-Time Remote Shell, classic Remote Shell, and bulk Remote Shell. Run a command, drop the output into the assistant, get back an analysis or a refined follow-up command.
Ticket System. Three concrete actions: summarize a ticket as an internal note, polish your reply before you send it, and chat about the ticket with full access to its thread and any text or log file attached. The polish-the-reply path alone has saved me hours.
Windows Event Log Viewer. Load up a log and ask your AI if it detects a specific issue or pattern.
Auditing. Let the AI crawl through your audit logs.
A short note on terminology: the section title says 'MCP' because that is what people are calling this category of feature this year, but to be precise — what shipped is a clean, OpenAI-compatible LLM connector with streaming, conversation persistence, and feature-scoped permissions. There is no separate Model Context Protocol server process. If you were expecting MCP-the-protocol, this is not that. If you were expecting 'AI assistant integrated into the parts of the product where it actually helps', this is that.
Ticket System
There is now a full helpdesk built into NetLock RMM. Multi-department, IMAP-driven, time-tracked, AI-assisted. If you run an MSP, you can stop juggling a separate ticket tool — the same console that fixes the device opens the ticket about it.
Multi-department ticketing. Each department is admin-assignable through the permission system, so the right operators see the right queues.
Per-department IMAP and SMTP configuration.
Email and ticket templates, scoped globally or per department, gated by permissions. Build your 'first response' template once, reuse it everywhere.
Time tracking on every ticket. Automatic mode (open the ticket, the timer starts) or manual start/stop. Idle detection raises a browser notification with a grace window before the timer auto-stops, so you don't bill 3 hours because you got pulled into another fire.
Billable time rounding rules — minute-accurate, or round up to N minutes — for clean invoicing.
A prominent ticket-summary field that every operator sees on first open. The 'what is this ticket actually about' lives at the top, not buried.
Auto-assign-on-first-open behavior, configurable globally. A warning banner shows when multiple operators have the same ticket open, so two people don't reply at once.
A full audit trail of every ticket change — who, what, when. This piggybacks on the new audit log, so it's centrally searchable.
Reminder-at-date-X. Park a ticket as 'Waiting for reply' with a reminder date and it flips back to 'Open' automatically when the date arrives.
Ticket labels and ticket types (service request, incident, maintenance, ...) — global presets plus per-department additions.
Outbound webhook notifications on ticket open / close / update for CRM integration. Fire your existing automations from ticket events.
A NetLock-native customer / CRM database with tenant linkage and SLA definitions. When a known customer emails in, the ticket is auto-routed and an SLA timer starts. Tickets can be linked to both tenants and devices, so the device that opened the ticket is one click away.
Customer-specific ticket prefixes and numbers. Real ticket IDs your customers can quote on the phone.
Email notifications on ticket events to configurable recipients.
Inline viewer for text and log attachments, with the AI assistant available right there to analyze them. Drop a 4 MB log file in, ask the assistant what stands out, get a summary.
Per-user conversation view preference: chat-bubble or CRM-style list. Some operators want Slack, some want Outlook — pick yours.
Per-user email signature, appended automatically to outbound replies.
Per-department IMAP polling result log, surfaced in the department editor, so when polling silently breaks you can see why.
Report Manager
Reports went from 'we have a couple of static dashboards' to a full report-building subsystem with templates, brand customization, scheduling, and export. If a customer ever asked you for a monthly compliance summary in PDF form, the answer used to involve screenshots — that's over.
A Report Builder with live preview in the console. Lay out your sections, drop in widgets, see what it looks like before you ship.
Template-driven: every report is a template that defines sections and the widgets within them.
A widget library covering sortable / paginated tables, metric tiles (Total Devices, Online Devices, Patch Compliance, and many more), pie / bar / line / trend charts, and free-text blocks for narrative copy.
Brand templates apply your logo (with positioning), name, address, contact details, and custom fields to every page of a generated PDF. White-label your reports to match your customer.
The Report Manager uses the same SQL Query Builder shared with Custom Fields and Custom Dashboards, so any source you can query for a dashboard you can put in a report.
Exports to PDF (rendered with QuestPDF), HTML, CSV, and JSON.
Scheduling covers Hourly, Daily, Weekly, Monthly, Quarterly, and Annually.
Distribution per scheduled report: download, email (with per-report subject, body and the report attached), or webhook for tooling integration.
53 pre-built report templates ship in the box — patch compliance, security posture, ticket throughput, asset inventories, license overviews, and more. Open them, run them, edit them, or use them as a starting point.
Per-template visibility: keep a report private to its author, share it to specific users, or publish it to everyone in the console.
Report templates can be exported and imported as files for backup or sharing.
Server-side generation runs through the NetLock RMM Server itself — no extra API surface, no headless browser. Generated reports land in a per-report folder under the File Server.
Community Reports & Branding
The Community Scripts pattern that worked for shared scripts now extends to reporting and branding.
Share and import Report Templates through the Members Portal API. Anonymous or attributed, your choice.
Share and import full Whitelabel themes — console title, effects, color palette, logo, background image — packaged with up to three preview screenshots and stored as signed JSON. Pick a theme that another MSP built, apply it, done.
Custom Fields & Custom Dashboards
The console is no longer a fixed UI — it's a UI you build for your team. Custom Fields lets you extend the device view with whatever data and actions matter to you. Custom Dashboards lets you stop staring at the same three charts.
A Custom Fields builder for the Devices page. Drop in tabs, panels, text blocks, tables — laid out with a live preview as you build.
Two data sources per field: a SELECT-only SQL query you define, or the latest result of a Job (parsed automatically from event data). Run a Job that returns a CPU spec sheet once a day, render it as a Custom Field, never look at the script's raw output again.
Action buttons that fire SQL queries or browser URL handlers (e.g. rustdesk://..., ssh://...) using values from the row as parameters. One click on the device, you're connected.
A 'Hidden Job' flag for jobs that should run quietly. Their results don't pollute /events or the per-device event view — they exist only to feed Custom Fields.
Custom Dashboards on /dashboard with a dropdown selector. Build one dashboard for the helpdesk, one for management, one for yourself; switch with one click.
The legacy three charts on /dashboard have been replaced with a fresh widget set. Roughly twenty chart templates ship as starting points so you have somewhere to begin.
The chart catalog includes bar, line, pie, doughnut, multi-series pie, radar, area, and scaled charts.
Tables and charts live inside drag-and-resize panels. Lay out a dashboard the way you want it, your layout persists.
A shared SQL Query Builder class powers Custom Fields, Custom Dashboards, and the Report Manager — learn it once, use it everywhere.
New per-section settings tabs for Dashboards and Custom Fields with a 'godmode' flag and an allowed-tables config, so you can tune how powerful the builders are in your environment.
Auditing
Every meaningful action an operator takes in the console is now recorded in a tamper-evident audit log. This was the single biggest gap when talking to compliance-minded customers and it's now closed.
Standardized vocabularies for actions and entity types. The same verbs and nouns everywhere — 'create user', 'execute script', 'delete policy', 'authorize device' — so log search actually works.
Three severity levels (Info / Warning / Critical) with sensible default rules: deletes and permission changes raise Warning, failed logins raise Critical.
Tenant-scoped logging on every entry, so multi-tenant deployments can slice the log per customer.
Filters for date range, severity, action, entity type, user, and free-text search.
Export to JSON and CSV — and the export is itself audited. You can audit the auditor.
Auto-cleanup with configurable retention (default 365 days). Set it to whatever your compliance regime says.
Remote Control Suite
A whole cluster of remote-control upgrades landed this cycle. Some are brand-new tools, some are deep rebuilds of existing ones. The common thread: do more from the console, do it faster, do it safer.
Remote Registry Editor (Windows): a real registry editor in your browser. Browse the keys, view values or edit them. No more 'open a remote shell, run reg query, parse the output, hope for the best'.
File Browser overhaul: rebuilt visually. Navigation is faster and the UI is consistent with the rest of the new web console design.
Relay App & Web Console with H.264 video streaming: the upgrade I'm most proud of in the remote-control area. The Relay App now streams remote-control video using H.264 with FFmpeg-backed decoding and an adaptive bitrate controller that scales quality to the available bandwidth. The legacy image-frame protocol is still there as a fallback, but the new path is dramatically smoother and dramatically smaller on the wire.
The Relay App ships as a standalone client for your operators — Remote Control without going through the web console.
Tenant-scoped device list with search, so a multi-tenant operator only sees what they're cleared for.
Uninstall Application from the device view: right-click an installed application on /devices → Applications → Installed and hit Uninstall. The agent handles the rest.
Windows: dispatches uninstall executables, MsiExec /X, or vendor-specific uninstallers as appropriate.
Linux: apt remove and the equivalents.
macOS: removes the .app bundle.
Status comes back over SignalR with a waiting-dialog UX so you actually see what's happening.
Wake on LAN via the Remote Agent: WoL that works, finally. A WoL button sits next to Reboot and Shell on /devices. The console picks an already-online device on the same LAN as the target — automatically, uses it as the jumphost, sends the magic packet, then pings the target until it answers.
Jumphost selection is automatic. The first authorized online device on the same internal subnet is used; the operator does not have to pick.
A status dialog shows the whole flow: jumphost found, packet sent, target responding.
A clean error path when no online jumphost exists on that subnet, so you're never left wondering.
2FA gate on remote actions: a new optional setting on the operator account requires a TOTP code before any remote-control action can run.
Real-Time Remote Shell + Run-As-User: Remote Shell got both an interactive mode and a context mode this release.
A real-time terminal mode runs alongside the existing fire-and-forget classic mode. Full VT100 / ANSI emulation. It feels like a real shell because it is one.
A mode selector at the top of the Remote Shell dialog lets you pick Classic or Real-Time before each session.
The mode is recorded on every shell history entry so you can audit which mode was used.
'Run as User' lands in classic Remote Shell. Pick a logged-in user session (from the same enumeration the Remote Control dialog uses) and the command runs through the User Process — Windows PowerShell, Linux Bash, macOS Zsh — in that user's context. Per-user environment variables, per-user paths, per-user permissions. Finally.
The chosen run_as_user is recorded on the history entry too, so it's clear at audit time which session executed which command.
Application Control & USB Device Control
Two features I had been working on around 2021 for a NetLock SaaS prototype, migrated from the old prototype and brought to the new version.
Application Control (Windows): a new ruleset management page under Collections → Application Control. Build allowlists once, apply them with policy.
Per-policy filter behavior under /policy_settings.
Comm Agent enforcement migrated from the legacy agent and hardened against the failure modes of the old implementation. If a ruleset payload is missing or corrupt, the agent logs a warning and skips enforcement instead of going nuclear and blocking everything. No more 'empty ruleset bricks the customer's PC' calls.
USB Device Control (Windows): per-policy enforcement, plus a new Hardware → USB Devices tab on /devices for visibility and per-device intervention.
Whitelisting can be scoped per device, per tenant, per location, or per group.
An aggregate overview shows, across the estate, which USB devices are whitelisted where, with drill-down to the specific devices.
Both features are Windows-only by design — same as the legacy implementations they replaced.
Linux UFW Firewall Manager
Linux fleets get a proper firewall management surface, driven from policy.
Enable / disable UFW on a device through policy. Basic and advanced rules, all expressed as policy data.
The agent enforces the policy ruleset over any locally-set rules. If somebody opens a port by hand, the policy puts it back.
Two non-removable default rules are always preserved to keep agent connectivity to the Comm and Remote backends alive — you cannot accidentally lock the agent out of the server.
An encrypted hash of the enforced ruleset is stored on the agent. On every cycle the agent compares current rules to the hash; drift triggers a re-apply. No more 'I don't know who changed the firewall, but it's wrong now'.
The Comm Agent reports current UFW status back to the console, surfaced as a new tab on the Linux device view.
SNMP Monitoring
Full SNMP monitoring is now part of the platform. It is integrated into the Sensors / Collections world rather than living as a separate top-level item, which means SNMP data flows through the same alerting and history pipeline as every other sensor result.
SNMP v1, v2c, and v3 — including v3 auth (MD5 / SHA) and priv (DES / AES).
SNMP devices are managed under Collections / Sensors with tenant and location scoping for parity with /devices filtering.
Each SNMP target is polled by an assigned NetLock agent. This gives you distributed polling for free — your branch-office switch is polled by the branch-office agent, not from the central console.
Sensor results record both a status (ok / warning / critical / error / timeout) and a value type (Integer / String / Counter / Gauge / TimeTicks) for clean dashboards.
A per-device SNMP Tools dialog gives operators a quick way to test a target without building a full sensor first.
Software Deployment & App Hub
A real software-deployment lane, with a curated catalog behind it.
App Hub: a curated software catalog with publisher, license, icon, tags, target OS, and a 'requires elevation' flag — the metadata you actually need to make deployment decisions.
Three source types: winget, Flatpak / Flathub, and custom scripts. Chocolatey was added on top of these.
Background sync services for the winget and Flathub catalogs keep the catalog fresh without manual intervention. Manual triggers exist for when you want it now.
Apps in the catalog carry an available_for_deployment flag, so you can curate which entries your operators are actually allowed to push.
App Hub is wired into /policy_settings → app hub for policy-side configuration.
Software Deployment: a Collections page for deployment jobs.
Deployment jobs are created and tracked in the web console, then pulled by the Agent on its normal sync cycle.
The Comm Agent installs as SYSTEM by default. For installers that need to run in the user context, the work is handed off to the Tray Icon's user-process path — no more 'this MSI silently fails because it wanted HKCU'.
Per-target result tracking on every deployment job so a single failed device doesn't hide inside an '85% successful' rollup.
Port Scanner
The legacy port scanner from the NetLock prototype did automatic scanning of agent devices' external IPs, which turned out to be a compliance hand grenade for home-office and BYOD scenarios. The recode strips that behavior out and replaces it with the right model: operators define the targets, the scanner scans those.
Operator-curated targets only. Nothing scanned without an explicit entry.
Per-port enabled flag, so admins can disable a port without losing its history or having to delete and re-add it.
The legacy UI shape was preserved; the underlying scanning code was optimized and modernized. Results emit events through the standard sender pipeline so they land alongside everything else in /events.
Website Uptime Monitoring
A proper external monitoring product, built into the same console you already log into. HTTP / HTTPS, SSL, DNS, content, the works.
HTTP and HTTPS checks: status code, timeout, redirect handling, SSL validity.
Retry logic before alerting, so you don't get paged because somebody sneezed on a load balancer.
Response-time monitoring with average, peak, and trend, broken down into TTFB, full load time, and DNS lookup time.
Performance alerts on configurable thresholds. Get paged when the site is slow, not just when it's down.
Performance history at 24h / 7d / 30d resolution.
Content monitoring: keyword check, missing-string alert, CSS-selector check, and defacement detection via HTML hash comparison.
SSL monitoring with configurable expiry thresholds (30 / 14 / 7 / 3 days). Certificate-change alerts catch issuer or cert swaps as a security signal — somebody re-issued the cert, you should know.
DNS monitoring: A, CNAME, MX, and TXT record checks with change and failure alerts.
An incident system that tracks the full timeline (down → retry → confirmed → notified → up) and computes MTTR and SLA metrics.
Smart Root Cause Detection: when a monitor goes down, the system automatically runs a layered diagnostic — DNS resolution, then TCP reachability, then HTTP, then content / SSL — and surfaces the failing layer in the incident. You don't have to start from scratch on every alert.
SSL alert deduplication so a single ongoing certificate-expiry doesn't spam your events table every cycle until the renewal lands.
Cleanup retention controls for uptime check results, DNS snapshots, and incidents so the database doesn't grow forever.
Maintenance Mode
The 'server reboot fired 3,000 disconnect alerts' problem is solved. There is now a proper maintenance mode in /settings → Maintenance.
Manual on / off toggle for ad-hoc maintenance windows.
Scheduled weekly windows: define a name, weekdays, time-from, and time-to, and the schedule is honored automatically.
Notifications are suppressed while a window is active. Note that events themselves are still written to the database — the suppression is at the notification layer only, so your audit and history stay intact.
Automations Overhaul
The matching engine for automations has been rewritten. The old engine compared on string fields, which broke the moment a tenant got renamed or a group got shuffled. The new engine matches on IDs.
Tenant, Location, Group, and Device matching are now ID-based. Rename your tenant, the automation still matches.
IP and Domain conditions stay on a strict string match — those are the cases where strings are actually the right primary key.
Priority weighting was reordered so the most specific match wins: Device → Internal IP → External IP → Domain → Group → Location → Tenant.
A new picker UI in the policy / automation editor mirrors the picker layout you already know from the Relay configuration. One vocabulary across the console.
Database indexes were added so policy resolution stays fast even with large automation counts.
This is also why there is a one-time required customer action after the upgrade — open every automation and re-pick the equal field — flagged at the top of this document. The backfill script does its best on existing automations (matching on the old name strings, with the lowest ID winning ties) but a manual re-save is the only guaranteed-correct migration. After you do it, you do not have to do it again.
Onboarding, GUI Installer, Code-Signed Installers
The first hour with a new NetLock RMM install was the part of the product I thought can be hard for some. It is now the part I like most.
First-run onboarding wizard: on a fresh install, /dashboard runs a setup wizard.
A backend reachability check kicks things off, with a friendly note that on a fresh install this can take a few minutes — so you don't think it's broken.
Steps cover date / time format, update settings, optional 2FA setup, contact info (first name, last name, email, phone), and an agent-download CTA.
A watchdog waits for the first device to actually appear in /devices and offers to redirect you there, so the first-device-online moment is a real moment.
Graphical agent installer for Windows: a clean install experience for end users with a real progress UI.
Per-deployment branding — window title, welcome description, completed description, error description — is configured per agent package, so the installer your customer sees can be themed to match the customer.
Code-signed installers (paid): a Members Portal API endpoint builds Windows x64 and Windows ARM64 installers just for you, signs them and ships them to you. No more SmartScreen warnings for your end users (hopefully, in most cases — depends on Microsoft's metrics).
ARM64 is fully supported alongside x64 — agent, installer, and GUI installer all ship signed for both architectures.
Device World Map
The new device world map renders every device on a real map, using GeoIP data.
The GeoIP database is shipped bundled with the console — no runtime download, no third-party API call per device. Resolution is local, fast, and offline-friendly.
Filters and detail views let you slice by tenant, location, status, and so on, and click through to a specific device from the map.
Quality of Life & Platform Improvements
A long tail of smaller upgrades that, taken together, make a noticeable difference to the day-to-day feel of the console.
Real-time CPU and RAM: a new live mode on the device view streams CPU and RAM directly from the Remote Agent over SignalR instead of stitching together the Comm Agent's history. Toggle a checkbox to switch between Live and History.
RAM percentage is now actually plotted in the history view — a long-standing bug where the field was being collected but not charted is fixed.
Visual refresh: a console-wide pass on button styling and color usage to align with modern standards. Less noise, more hierarchy.
A new 'Active Design' selector — Classic vs. New — with full backwards compatibility. Existing installs that have a custom theme_palette stay on Classic on upgrade so nothing surprises you the day after the update.
Login page polish: the login background can now be an image or video (WEBP, PNG, JPEG, GIF, MP4). White-label your sign-in screen properly.
A particles.js effect with presets and an advanced editor for the people who want to get fancy.
An optional particles effect on the appbar too, if you want it everywhere.
A new login_layout_style setting for layout variants.
AppBar settings cover icon visibility and seasonal effects (turn the snow on or off, your call).
A global date / time format setting (yyyy-MM-dd HH:mm:ss by default) so the console renders timestamps the way your team reads them.
Per-user navmenu ordering: each operator can now reorder their own nav menu. Tickets-first for the helpdesk team, devices-first for the on-call engineer.
Settings section overhaul: the single old settings_system_enabled permission has been split into a row of granular per-section flags: overview, licensing, updates, database, remote screen, IP whitelist, SSO, whitelabeling, custom fields, dashboards, AI / LLM. RBAC actually works at the settings level now.
Python3 support, end to end: Python3 is a first-class shell for scripts, jobs, and sensors. Write a sensor in Python3 on Windows, Linux, or macOS — there are dedicated sensor categories for each.
The agent reports python_version and python_path during preflight, so the console knows which devices have Python ready to go and which don't, before you try to run a Python sensor on them.
Relay Server reliability: the connection-establishment path the Relay App uses to reach the Remote Agent has been stabilized. Fewer flaky first-connections, faster retries when something does go wrong.
v2.6.1.2
Precision Patch
February 24, 2026
A minor update introducing several quality-of-life improvements and bug fixes.
⚠️
This agent update requires a reboot of remote machines for Remote Screen Control to function properly.
Added support for selecting the rendering mode. You can now switch between Software (CPU) and Hardware (GPU) rendering. Software rendering ensures compatibility with systems that have limited or no GPU resources, while GPU rendering provides significantly smoother performance when hardware acceleration is available.
Added the ability to elevate the permissions of the remote control user process within a specific user session, even when the logged-in user does not have administrative privileges. This is especially useful for Windows systems running multiple simultaneous sessions (e.g., RDS environments), enabling elevated access to restricted applications and UAC dialogs.
Improved session switching reliability and performance.
Agent Installation
Extended the agent installer with additional parameters, including the option to change the temporary directory to bypass permission restrictions on certain NAS devices.
We are excited to announce version 2.6.1.1, featuring two major enhancements: Remote Screen Control now experimentally supports Linux (Ubuntu 24.04/Wayland), greatly expanding your digital sovereignty capabilities. The tray icon is also available on Linux, providing deeper integration and a more seamless user experience.
✨ Linux Remote Screen Control (Ubuntu 24.04/Wayland)✨ GPU-based screen capturing on Windows✨ Virtual display driver for headless devices✨ MacOS auto-update support
Remote Screen Control
Added support for screen switching.
Updated mouse click transmission: now uses the modern SendInput method on Windows for improved reliability.
Seamless support for UAC dialogs (depending on Windows this will only work with the code signed version).
Instantly switches from the login screen to the user session without delay as soon as the user has been logged in.
Keystroke content is now hidden for enhanced privacy, toggle based.
The user chat window now opens automatically when a message is received.
Fixed chat interface issues where it appeared behind the screen control dialog.
The screen control dialog now stretches across the entire screen for better usability.
Added the ability to create and download screenshots directly from the interface.
Reduced the interval for checking the user process from 30 seconds to 5 seconds on Windows, enabling faster remote screen control after reboot.
Virtual display driver enables access to devices without a connected screen or with the screen disabled.
Transitioned from CPU-based to GPU-based capturing technique, significantly boosting performance.
Overhauled thread management for improved performance and elimination of thread-blocking issues.
Agent Installation
The Linux agent installation script generated from the web console now keeps the terminal open if an error occurs when run directly from the clipboard.
The script automatically installs 'unzip' if it is not present, ensuring smooth extraction of the installation package.
Communication Agent
Gathering information about running processes is now significantly faster. Reduced from one query per process to just two requests for ~300 processes — highly improved performance on Windows RDS.
Fixed Windows firewall state. The firewall state is now reported correctly.
If a job or sensor has the option 'boot' selected, it will not be instantly executed if it is new to the system. Only if the last boot was maximum ten minutes ago.
Updater
MacOS now auto updates correctly.
Web Console
General improvements to the UI.
Theme editor now covers more elements.
Changes to the theme don't require an application restart anymore.
Login page now always uses dark mode.
If a user has no permissions to the dashboard, they will be redirected to /home instead of being logged out.
Changes to the permissions system. The navbar & main layout now only shows items the user has permissions for.
Added rate limiter to the login page. After 10 failed attempts the user's IP will be blocked for 60 minutes.
Fixed a timing issue with Community Scripts that could cause scripts not to be displayed correctly in the script viewer.
Patch SLA System
Introduced a Patch SLA system to ensure all instances stay up-to-date and secure.
Up to 7 days after a new update: a friendly update icon is displayed in the web console.
After 14 days: a dialog popup appears in the web console reminding the administrator to update.
After 14 days: the instance will stop itself to prevent security risks from running outdated versions.
v2.6.0.0
Big Bang
January 5, 2026
Happy new year! We start 2026 with a big bang — tons of improvements and new features! This release introduces powerful additions such as Single Sign-On (SSO), webhook support, a Windows remote Event Log viewer, a fully customizable theme manager, and a fully functional Relay Server. The Relay Server allows you to securely tunnel to any machine from your admin machine running the NetLock RMM agent — no port forwarding, no VPN!
⚠️
Some features need to be configured before you can use them. Documentation for new features & videos will be released in the upcoming weeks.
✨ Single Sign-On (SSO)✨ Relay Server✨ Webhook Support✨ Windows Event Log Viewer✨ Theme Editor
Authentication
Extended SSO support: Keycloak, Entra ID, Auth0, and Okta.
Webhook
Webhook support has been added including custom variables to meet your requirements.
Remote
Relay Server — Create a secure tunnel from your admin machine to a target device with the NetLock RMM agent installed. Connections are managed within the web console. The local NetLock RMM Proxy Application allows you to connect with any tool you like: RDP, SSH, Database Tools & Web browser. Available for Windows, Linux, and macOS.
Remote Screen Control — Automatic detection of newly logged-in user sessions in unattended mode. No restart required after agent installation. Significantly improved unattended access stability. No user re-login required for the tray icon. Review recorded sessions in the web console under settings.
Remote Shell — Bulk execution support and configurable timeout.
Windows Event Log viewer — View and browse any event log, and view statistics about the event logs.
Real-time device connectivity status when remote features are enabled, indicated by a pulse animation. Active remote connections are additionally indicated by a pulsing platform icon.
Visual feedback indicating whether a policy is active or inactive, and whether a required feature is disabled in the policy.
Device values in the device overview are updated automatically in the background every 30 seconds, including remote status.
Installation & Deployment
Devices can now be moved across tenants, also supported as a bulk action.
Automatic device authorization until a specific date based on the package configuration.
After creating an installer, an installation script can now be downloaded based on the selected architecture.
You can now generate server config replacement scripts for each platform.
Brand-new NetLock RMM server instance installer in the Members Portal, guiding users through the installation process.
UI / UX & Design
New login design and new overall UI design with improved feedback.
Optimized dark mode.
Metric graphs improved for better visual readability.
Search bar added to filter tenants.
Dashboard events now reload automatically in the background every minute.
Fonts are no longer loaded from the internet — all fonts are now fully embedded.
Web console title and logo can now be customized via settings.
Full theme customization: all theme colors can be adjusted using a built-in editor.
Configurable IP whitelist for web console and agent backend.
Improved explanations in System → Updates and System → Database (cleanup behavior, processes, etc.).
Execute custom MySQL commands.
v2.5.3.0
Whitelabel
October 26, 2025
We're back with exciting news — our latest version is here! This update introduces a fully customizable Tray Icon, built-in chat, remote actions, device labels, and much more.
⚠️
With this update, you'll need to update all your agents to the latest version for remote access to function properly. Additionally, please review your policies and update the agent settings to enable remote capabilities. The new tray icon is required for attended remote access.
Introducing a fully customizable Tray Icon that gives you even more ways to engage with your users.
New remote access experience allowing users to accept or decline access requests — perfect for situations where confidentiality is essential.
As the administrator, you have full control over remote access behavior through your policy settings.
Device Labels & UI
New device labels provide a clearer overview.
The new automation policy preview allows you to see which policies are applied to each device.
Shutdown & Reboot Actions
You can now shut down or reboot your devices instantly — no more going through remote shell, select script, execute.
Agent Policy Controls
You can now decide how often a device synchronizes with the server and even override the global auto-update setting based on the assigned policy.
Enable or disable specific remote features — or the entire service — per policy.
Define whether unattended access is allowed or if user confirmation is required before connecting.
Additional Enhancements
The remote agent service connection behavior has been completely overhauled. After a system reboot, the remote connection is now re-established automatically as soon as the device regains network connectivity.
The last active user now correctly reflects RDP sessions.
Linux software inventory now supports additional package managers: Yum, Zypper, Pacman, and DNF.
Remote screen control now uses fewer CPU resources and about 33% less bandwidth.
The NetLock RMM agent installer now supports hidden and no-log parameters.
v2.5.2.5
Quality of Life
August 14, 2025
This release is on the smaller side, but it was an important one. We encountered issues with our code-signing provider that could cause problems with remote screen control and UAC access. After extensive communication, the issue is now fully resolved.
⚠️
This update requires an agent update. Please go to Settings → Updates and enable updates so that your devices receive the latest version.
✨ Code-signing fix✨ Remote Shell improvements✨ Keyboard ghosting fix✨ Linux last boot time fix
Highlights
Remote Shell — Input field is now collapsible for more workspace. You can also run commands instantly by pressing Enter.
Remote Screen Control — Fixed a long-standing keyboard ghosting bug.
Linux Agents — Corrected last boot time (now uses local time instead of UTC).
Location Renaming — Fixed a visual glitch when renaming locations (no database impact).
File Server — Added new right-click menu options: Copy Filename and Copy File Path.
Two-Factor Authentication — Enhanced QR code visual quality.
SMTP Settings — You can now use just a username without needing to provide a full email address.
Drive Overview — Redesigned for a more compact and efficient layout.
v2.5.2.4c
File Server Fix
August 6, 2025
Smaller additions and fixes. No agent update required.
Extended context menu in the file server browser — you now have more right-click options to interact with files.
Fixed
Keyboard ghosting during remote control sessions has been resolved — smoother typing ahead.
Devices disappearing after renaming a location — devices now remain correctly associated with their location after renaming. The issue was purely visual and did not affect backend or database operations.
v2.5.2.2
Remote Screen Control
July 21, 2025
This release introduces one of the most significant feature expansions to date: powerful Remote Screen Control for Windows, alongside performance optimizations, improved agent management, and a new all-in-one deployment script.
✨ Remote Screen Control for Windows✨ ARM64 Architecture Support✨ Agent Auto Updates✨ All-in-one deployment script
Remote Screen Control for Windows
Full support for session switching and display switching.
Unattended access.
Ctrl + Alt + Del support for elevated access.
Built-in session recording.
Send input as keystrokes, useful for automating password entry.
Major improvements in keyboard simulation, mirroring performance, bandwidth efficiency, and full DPI awareness.
ARM64 Architecture Support
Native support for ARM64-based systems, including fix for installer detecting the wrong architecture.
Agent Auto Updates
Linux and macOS agents now support automatic updates (older agents require manual upgrade).
New option to limit concurrent agent update pulls, preventing network overload.
Platform Enhancements
Tenant List now sorted alphabetically for improved navigation.
Last Active / Logged-In User added to device overview for better end user identification.
Fix for rare edge case where Remote Shell could hang indefinitely.
Several Remote Agent connection stability improvements.
Monitoring & Uptime Handling
Devices with pending updates will no longer trigger false offline alerts.
Devices connecting after a NetLock RMM server upgrade are ignored for 30 minutes to reduce notification noise.
Database & Disk Usage Optimization
New automatic database cleanup options: define retention periods for historical data.
Only new history data is now written to history to reduce disk load.
Networking & Deployment
Reverse Proxy Header Forwarding is now fully supported for better IP logging.
Incorrect antivirus reporting when multiple AVs had previously been installed is now resolved.
New all-in-one deployment script supports: Dedicated IP/Bare Metal/VPS setups, Reverse Proxy environments (NGINX, Traefik, etc.), and Local Testing.
v2.5.1.4
Hotfix
June 3, 2025
There were some problems with creating new jobs in the web console, which triggered error messages. These issues have now been fixed.
✨ Job creation fix
Fixes
Fixed an issue where creating new jobs in the web console triggered error messages.
v2.5.1.3
Hotfix
June 1, 2025
There were some problems with tenant creation and related operations, which triggered error messages. They are related to the latest authentication & permissions overhaul. These issues have now been fixed.
✨ Tenant creation fix
Fixes
Fixed issues with tenant creation and related operations that triggered error messages after the authentication & permissions overhaul.
v2.5.1.2
Auth Rewrite
May 25, 2025
While we typically include dependency updates as part of our regular releases, this update is a bit different — we've made significant changes to the core of NetLock RMM and are rolling out a major tech stack upgrade alongside it.
⚠️
You might run into errors if your browser cache isn't cleared. Depending on your browser, you can usually clear it just for the web console.
Reengineered the web console's authentication and permissions systems from scratch to ensure greater security, flexibility, and maintainability.
Added an initial graph displaying processor and RAM usage. More visualizations are planned for upcoming releases.
Remote tasks are now snappier and get processed faster. This rewrite sets the stage for the powerful remote screen control feature coming next.
v2.5.1.1
Community Scripts
May 20, 2025
We're excited to announce a powerful new feature: Community Scripts! Community Scripts are a curated collection of useful scripts shared by fellow NetLock RMM users. These scripts are designed to help you automate tasks, solve common challenges, and optimize your workflows.
✨ Community Scripts✨ GitHub Import✨ Automatic Cleanup
Community Scripts & Automatic Cleanup
You can now explore, share, and collaborate — all directly within NetLock RMM.
This feature uses the NetLock RMM Members Portal API to sync scripts between users.
You can also import scripts from GitHub to expand your collection.
v2.5.1.0
Uptime Monitoring
May 12, 2025
We're excited to announce that our latest update introduces the highly requested uptime monitoring feature!
By enabling the "Disconnection Alert" for a device, you'll be notified whenever it loses connection to the NetLock RMM server — whether due to shutdown, network issues, or other disruptions.
An event will be automatically generated and displayed in the system.
You can configure uptime monitoring alerts under the Notifications section to ensure they are sent to your selected recipients.
The notifications design has also been improved and now contains additional details.
v2.5.0.8
Hotfix
May 10, 2025
If you experienced the server application exiting during setup with a "package is invalid" message, this issue has been resolved in version 2.5.0.8.
✨ Invalid package fix
Fixes
Fixed the server application exiting during setup with a "package is invalid" message.
v2.5.0.7
High-Speed RAM
April 23, 2025
The new version includes some updates and performance improvements, along with a groundbreaking new package distribution system.
Implemented a new encryption method for communication and remote agents, resolving the issue of events being cut off and ensuring notifications (mail, Telegram, etc.) are sent correctly.
Improved connection checks in the web console under Settings → System.
Server info is now updated correctly.
High-Speed RAM Distribution & Supply Chain Protection
NetLock RMM now serves installation and update packages directly from memory. No disk I/O, no bottlenecks — just pure, uncompromised performance.
On server startup, all essential packages are preloaded into memory, enabling blazing-fast delivery speeds while eliminating wear and tear on your hardware.
All agent packages are encrypted and uniquely obfuscated before ever touching your systems. At runtime, they're securely decrypted and deobfuscated using proprietary algorithms, preventing reverse engineering and unauthorized tampering.
The NetLock RMM server is fortified with advanced code virtualization and deep tamper protection, raising the bar for what attackers would have to overcome.
v2.5.0.4
Minor Update
March 26, 2025
A minor update with usability improvements for the device tree view and bulk operations.
Devices with identical names are now correctly displayed and usable in the "All Devices" overview.
Unauthorized devices can now be bulk authorized and deleted.
v2.5.0.3
Transparency Report
March 26, 2025
This update fixes a remote authentication bug and replaces the custom encryption entirely. We also discuss upcoming technical and licensing changes.
✨ Encryption overhaul✨ Remote auth fix
Fixes
Fixed remote auth failing depending on password (GitHub Issue #23).
The custom encryption has been completely replaced with a new one.
v2.5.0.0
Cross-Platform
January 8, 2025
We're thrilled to announce the release of NetLock RMM 2.5.0.0, now with full Linux & macOS agent support! NetLock RMM now fully supports Linux & macOS device monitoring, including all available sensors, jobs, system details, remote shell, and even the remote file browser. Stay in control of your entire IT environment, no matter the platform!
✨ Full Linux & macOS Agent Support✨ One-Click Agent Installer✨ Zero Dependencies Installation✨ Members Portal API✨ Pay-as-You-Go Pricing
Linux & macOS Agent
This has been the most requested feature — Linux & macOS are now fully supported in NetLock RMM.
Full support for sensors, jobs, system details, remote shell, and the remote file browser on both platforms.
You no longer need to manually run PowerShell or provide parameters to install the agent.
With the new agent installer generator, you can embed your server configuration directly into the installer executable.
Simply right-click and run as administrator on Windows, or execute with sudo on Linux & macOS — fast, simple, and hassle-free.
No Dependencies Required
Installing the NetLock RMM agent is now easier than ever — no external dependencies needed.
Windows — Just run the installer, no installation of third-party dependencies required.
Linux & macOS — Execute with sudo, no additional packages needed.
Members Portal API
The Members Portal API now lets you effortlessly sync the latest packages & license information with your self-hosted NetLock RMM instance.
This is just the beginning — more powerful features are on the way to make the API even more useful.
Pay-as-You-Go
We now offer a Pay-as-You-Go option, starting at just 0.25€ per device.
Flexible & scalable — only pay for what you use.
Set hard limits to control your billing with ease.
v2.5.0.1
Minor Update
January 11, 2025
A minor update addressing several bug fixes and small improvements for the web console and server.
⚠️
The members portal will still show version 2.5.0.0, as this is tied to the server and agents update logic. Updating your agents is not required with this update.
Fixed an issue where, depending on the admin password, the remote connection between the web console and server could not be established due to an encoding issue.
Fixed the problem that allowed multiple admin users to be added with the same username.
Fixed missing translation on user add dialog.
Improvements
Improved error messages for the remote authentication dialog.
Removed the moderator role from the roles selection, as it was just a placeholder in the early stages of development and there is currently no difference between moderator and administrator.
Added a button to copy the one-time password to your clipboard in the user add dialog.
Added translation on remote authentication dialog.
v2.5.0.2
Minor Update
January 12, 2025
A minor update improving Docker awareness and fixing a certificate handling issue.
⚠️
The members portal will still show version 2.5.0.0, as this is tied to the server and agents update logic. Updating your agents is not required with this update.
✨ Docker-aware server & web console✨ Container restart detection✨ HTTPS certificate fix
Fixes & Improvements
When the server runs under Docker, it will no longer be reported as down in the web console if a container restarts and registers itself again. A warning message will be displayed under the system overview on how to handle the Docker version of the server.
The web console and server are now Docker-aware.
Fixed a bug where the HTTPS certificate is ignored if no password is provided.
v2.0.0.0
Gold Release
November 18, 2024
We are excited to announce the release of NetLock RMM version 2.0.0.0, marking the end of the Early Adopter phase ahead of schedule. With this milestone, NetLock RMM has achieved gold status, making it ready for use in productive environments. The documentation has been fully updated and includes comprehensive text and video guides.
⚠️
As the early adopter version was significantly different from the final release, with many major overhauls, individual fixes are not listed in this update. Numerous known and unknown issues have been addressed. If you experienced any issues, they are likely resolved in this version.
✨ Remote Control & Administration✨ File Server✨ System Overview Dashboard✨ Dark Mode & Monaco Editor✨ Docker Support
Remote
Remote Control — Support your employees effectively by remotely accessing their desktop environment, enabling seamless troubleshooting and collaboration.
Remote Shell — Establish a remote shell on your target system from anywhere, allowing you to perform background maintenance tasks efficiently and securely.
Remote File Browser — Access the file systems of your remote devices effortlessly. Upload and download files regardless of where the device is located, ensuring seamless file management and operational efficiency.
Remote Service Manager — Monitor and manage system services in real time. Check their status, and start or stop services instantly for enhanced administrative control.
Remote Task Manager — Terminate processes on remote systems with ease, allowing for efficient management and resolution of system issues from anywhere.
File Server
Access your preferred administrative tools from anywhere, seamlessly integrate them into scripts, remote shells, or explore the remote file browser history.
Benefit from a robust privilege system to manage file access, keeping them private or sharing them as needed.
System Overview
Identify and resolve issues with NetLock RMM backend components while ensuring their integrity.
Monitor active MySQL executions, verify the web console's connection to backend roles, and review the status of each running NetLock RMM backend server and its associated roles.
Appearance
The web console has undergone a significant overhaul, featuring a sleek new design, enhanced mobile optimization, and seamless navigation for an improved user experience.
Translations have been improved, and missing translations have been fixed, ensuring a more complete and accurate multilingual experience.
The Monaco code editor is now integrated for scripting, offering features like syntax highlighting, autocomplete, and debugging, just like in Visual Studio Code.
Dark mode for your tired eyes.
Other
Added support for Docker.
You can now monitor the current CPU and RAM utilization of your devices directly from the device details page, providing real-time insights into device performance.
Enhanced event filtering and added the Monaco editor for improved script management, allowing for more refined event searches and smoother scripting.
Open Source
NetLock RMM is currently open-source, but we are still working on finalizing a suitable OSI-compatible license model. For now, we are using our custom license until the legal details are fully sorted out.
We also offer an open-source membership, making it easy for you to acquire the latest version of NetLock RMM with minimal effort.
Cloud & Memberships
Managed cloud instances of NetLock RMM are available starting at just 30€ per month, providing hassle-free deployment and maintenance.
For self-hosting in professional environments, a membership is available that includes code signing and customer support, or code signing alone at a fair price.
The non-code-signed open-source version remains available for those who prefer it. Refer to the documentation for instructions.
Stay Updated
Join our Discord community to get the latest updates, or follow us on GitHub to watch for new releases.