{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":[]},"redocly_category":"Release notes","type":"markdown"},"seo":{"title":"v3.8.6 August 31, 2026","description":"Coro's support and product documentation portal","siteUrl":"https://docs.coro.net","keywords":"Coro docs portal, documentation, support, docs","lang":"en-US","llmstxt":{"hide":false,"sections":[{"title":"Table of contents","includeFiles":["**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"v386-august-31-2026","__idx":0},"children":["v3.8.6 August 31, 2026"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Version 3.8.6 includes:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"a","attributes":{"href":"#new-features"},"children":["New features"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"a","attributes":{"href":"#enhancements"},"children":["Enhancements"]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"new-features","__idx":1},"children":["New features"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This section describes the new features added in version 3.8.6."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"1---coro-console","__idx":2},"children":["1 - Coro console"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The following features have been added to the Coro console:"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"11---alphabetical-activity-log-filters","__idx":3},"children":["1.1 - Alphabetical activity log filters"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The Activity Log Types filter list is now alphabetized."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For more information, see ",{"$$mdtype":"Tag","name":"a","attributes":{"href":"/console/activity-log"},"children":["Activity Log"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"2---connectors","__idx":4},"children":["2 - Connectors"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The following features have been added to Connectors:"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"21---connectwise-psa-integration-bidirectional-ticket-status-updates","__idx":5},"children":["2.1 - ConnectWise PSA integration bidirectional ticket status updates"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For customers with a configured ConnectWise PSA connector, when a Coro-originated ticket is set to “closed” status in ConnectWise, Coro now automatically closes the related ticket in the Coro ticket log."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For more information, see ",{"$$mdtype":"Tag","name":"a","attributes":{"href":"/admin/connectwise"},"children":["Integrating with ConnectWise PSA"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"3---cloud-backup-module-improvements","__idx":6},"children":["3 - Cloud Backup module improvements"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The following features have been added to Cloud Backup:"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"31---new-screens-for-end-customer-workspaces","__idx":7},"children":["3.1 - New screens for end-customer workspaces"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This release introduces a new set of views for end customers of Managed Service Providers who are subscribed to the Cloud Backup module. These new views show a record of backup and restore tasks performed, as well as the health of connected cloud apps."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For more information, see ",{"$$mdtype":"Tag","name":"a","attributes":{"href":"/cloudbackup/intro"},"children":["Cloud Backups"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"enhancements","__idx":8},"children":["Enhancements"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Version 3.8.6 introduces the following additional changes:"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"1---coro-console-enhancements","__idx":9},"children":["1 - Coro console enhancements"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"11---console-security-improvements","__idx":10},"children":["1.1 - Console security improvements"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Coro console security has been improved in the following ways:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Admin user password strength increased"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Console inactivity timeout reduced"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Increased audit logging of console events"]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"12---msp-global-view-enhancements","__idx":11},"children":["1.2 - MSP Global View enhancements"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The MSP Global View pages have been improved in the following ways:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Bundle breakdown panel improved with new pie chart visualizer."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For more information, see ",{"$$mdtype":"Tag","name":"a","attributes":{"href":"/msp/overview"},"children":["MSP workspaces overview"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"2---connectors-1","__idx":12},"children":["2 - Connectors"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"21---azure-sentinel-connector-changes","__idx":13},"children":["2.1 - Azure Sentinel connector changes"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Because of an external process change, customers using Coro's Azure Sentinel SIEM connector must re-establish their connections to continue using the service."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For more information, see ",{"$$mdtype":"Tag","name":"a","attributes":{"href":"/admin/connectors"},"children":["Configuring and managing SIEM connectors"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"3---data-governance","__idx":14},"children":["3 - Data Governance"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"31---consolidated-device-data-scan-findings","__idx":15},"children":["3.1 - Consolidated device data scan findings"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Previously, each endpoint device scan might have resulted in Coro raising a new ticket, even if the findings were identical; Coro now consolidates findings from repeated scans of the same device into a persistent ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Endpoint Drive Containing Sensitive Data"]}," ticket."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Subsequent scans update the existing open ticket rather than creating a new one. Newly discovered files (since the last scan) surface at the top of the ticket, each annotated with a \"last seen\" timestamp."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For more information, see ",{"$$mdtype":"Tag","name":"a","attributes":{"href":"/console/ticket-logic-data"},"children":["Ticket types for Endpoint Data Governance"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"4---endpoint-security-and-edr","__idx":16},"children":["4 - Endpoint Security and EDR"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"41---disabled-devices-page-filter","__idx":17},"children":["4.1 - Disabled devices page filter"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Coro now includes a dedicated filter on the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Devices"]}," page to show only ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Protection-disabled"]}," devices. This new filter lets you quickly re-enable protection for these devices."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For more information, see ",{"$$mdtype":"Tag","name":"a","attributes":{"href":"/console/devices-list"},"children":["Devices"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"42---unencrypted-endpoint-drive-ticket-notifications","__idx":18},"children":["4.2 - Unencrypted Endpoint Drive ticket notifications"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This release improves the processing rules for Unencrypted Endpoint Drive tickets to ensure admin users receive the correct number and frequency of notifications. Improvements include:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Open and unresolved Unencrypted Endpoint Drive tickets close automatically after 10 days."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["If a ticket is marked closed, Coro does not add new detected events of the same type to it. Instead, Coro creates a new ticket for the event, which means it raises a new notification for admin users."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["When Coro detects that the drive has been re-encrypted (the issue is resolved), it automatically marks the open ticket as resolved and closes it. Coro does not add further detected events of the same type to the resolved ticket, even if an admin user manually reopens it."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["If the admin user allows no encryption, Coro closes the corresponding ticket."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For more information, see ",{"$$mdtype":"Tag","name":"a","attributes":{"href":"/endpointsecurity/unencrypted-endpoint-drive"},"children":["Unencrypted Endpoint Drive"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"43---edr-telemetry-process-ancestry-information","__idx":19},"children":["4.3 - EDR telemetry process ancestry information"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This release adds ancestry context to EDR telemetry data, so users can now view parent process IDs (PPIDs) for all listed processes."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For more information, see ",{"$$mdtype":"Tag","name":"a","attributes":{"href":"/edr/edr-telemetry-page"},"children":["Telemetry"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"5---email-security","__idx":20},"children":["5 - Email Security"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"51---seven-day-grace-period-after-email-proxy-gateway-disconnection","__idx":21},"children":["5.1 - Seven-day grace period after email proxy gateway disconnection"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To avoid the risk of lost email due to misconfigured mail settings, Coro now provides a seven-day grace period after a customer disconnects from the Inbound or Outbound Gateway. During this period, Coro will continue to deliver any emails received via either gateway."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"52---tld-based-email-blockingallowing","__idx":22},"children":["5.2 - TLD-based email blocking/allowing"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Admin users can now add entries to the Email Security blocklist or allowlist based on TLD (Top-Level Domain)."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For more information, see ",{"$$mdtype":"Tag","name":"a","attributes":{"href":"/emailsecurity/allowblock-domains"},"children":["Allow or block email senders"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"53---wildcard-subdomain-email-blocking","__idx":23},"children":["5.3 - Wildcard subdomain email blocking"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Admin users can now add Email Security blocklist entries based on wildcarded subdomains. For example, *.domain.com to block all subdomains (and any nested subdomains) identified at domain.com. The base domain continues to be allowed."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For more information, see ",{"$$mdtype":"Tag","name":"a","attributes":{"href":"/emailsecurity/allowblock-domains"},"children":["Allow or block email senders"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"54---merged-blocklisted-ip-and-blocklisted-sender-tickets","__idx":24},"children":["5.4 - Merged Blocklisted IP and Blocklisted Sender tickets"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Blocklisted IP tickets are now deprecated; from this release, detections are raised as Blocklisted Sender tickets."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For more information, see ",{"$$mdtype":"Tag","name":"a","attributes":{"href":"/console/ticket-logic-emails"},"children":["Ticket types for Email Security"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"6---security-awareness-training","__idx":25},"children":["6 - Security Awareness Training"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"61---user-search-in-reports","__idx":26},"children":["6.1 - User search in reports"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Security Training"]}," and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Phishing Summary"]}," reports, searching for a specific user record now searches all users and not just those shown in the report."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"62---predefined-date-ranges-in-reports","__idx":27},"children":["6.2 - Predefined date ranges in reports"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Coro now provides improved predefined date ranges in the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Date range"]}," selector for ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Security Training"]}," and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Phishing Summary"]}," reports to better fit typical usage."]}]},"headings":[{"value":"v3.8.6 August 31, 2026","id":"v386-august-31-2026","depth":1},{"value":"New features","id":"new-features","depth":2},{"value":"1 - Coro console","id":"1---coro-console","depth":3},{"value":"1.1 - Alphabetical activity log filters","id":"11---alphabetical-activity-log-filters","depth":4},{"value":"2 - Connectors","id":"2---connectors","depth":3},{"value":"2.1 - ConnectWise PSA integration bidirectional ticket status updates","id":"21---connectwise-psa-integration-bidirectional-ticket-status-updates","depth":4},{"value":"3 - Cloud Backup module improvements","id":"3---cloud-backup-module-improvements","depth":3},{"value":"3.1 - New screens for end-customer workspaces","id":"31---new-screens-for-end-customer-workspaces","depth":4},{"value":"Enhancements","id":"enhancements","depth":2},{"value":"1 - Coro console enhancements","id":"1---coro-console-enhancements","depth":3},{"value":"1.1 - Console security improvements","id":"11---console-security-improvements","depth":4},{"value":"1.2 - MSP Global View enhancements","id":"12---msp-global-view-enhancements","depth":4},{"value":"2 - Connectors","id":"2---connectors-1","depth":3},{"value":"2.1 - Azure Sentinel connector changes","id":"21---azure-sentinel-connector-changes","depth":4},{"value":"3 - Data Governance","id":"3---data-governance","depth":3},{"value":"3.1 - Consolidated device data scan findings","id":"31---consolidated-device-data-scan-findings","depth":4},{"value":"4 - Endpoint Security and EDR","id":"4---endpoint-security-and-edr","depth":3},{"value":"4.1 - Disabled devices page filter","id":"41---disabled-devices-page-filter","depth":4},{"value":"4.2 - Unencrypted Endpoint Drive ticket notifications","id":"42---unencrypted-endpoint-drive-ticket-notifications","depth":4},{"value":"4.3 - EDR telemetry process ancestry information","id":"43---edr-telemetry-process-ancestry-information","depth":4},{"value":"5 - Email Security","id":"5---email-security","depth":3},{"value":"5.1 - Seven-day grace period after email proxy gateway disconnection","id":"51---seven-day-grace-period-after-email-proxy-gateway-disconnection","depth":4},{"value":"5.2 - TLD-based email blocking/allowing","id":"52---tld-based-email-blockingallowing","depth":4},{"value":"5.3 - Wildcard subdomain email blocking","id":"53---wildcard-subdomain-email-blocking","depth":4},{"value":"5.4 - Merged Blocklisted IP and Blocklisted Sender tickets","id":"54---merged-blocklisted-ip-and-blocklisted-sender-tickets","depth":4},{"value":"6 - Security Awareness Training","id":"6---security-awareness-training","depth":3},{"value":"6.1 - User search in reports","id":"61---user-search-in-reports","depth":4},{"value":"6.2 - Predefined date ranges in reports","id":"62---predefined-date-ranges-in-reports","depth":4}],"frontmatter":{"seo":{"title":"v3.8.6 August 31, 2026"}},"lastModified":"2026-09-01T12:03:15.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/rn/v3.8.6","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}