Chat now with support
Chat with Support

Security Guardian Current - Release Notes

Release History

The following lists the new features, enhancements and resolved issues by deployment.

Current Deployment

December 16, 2025

Resolved an issue where the vulnerability check for “User accounts in protected groups that are not protected by AdminSDHolder (SDProp)” could return false positives when user objects had the same Distinguished Name value.

Previous Deployments

December 12, 2025

You now have the ability to view the trends by day (7, 30, 60, or 90), by weeks (26, 52, or 78), or by months (12, 24, 36, or 48). When the selected range is greater than 7 days, the chart shows average values for the chosen time unit (such as day, week, or month).

December 9, 2025

  • Ability to see " AD security changes that can prevent object enumeration detected" as critical activity in the dashboard.
  • Ability to specify whether you require the system to send email notifications.
  • Ability to add notification recipients by role.

November 25, 2025

  • Workload Identity columns renamed. "Total owners" changed to "Owners" and "Total Risky Permissions" changed to "Risky Permissions".

November 18, 2025

  • Hybrid Audit which allows you to monitor and analyze activity across both your on-premises and cloud-based Microsoft environments from a single, unified interface.
  • Ability to view and edit the templates used to protect Active Directory and Group Policy objects.

November 4, 2025

The following Active Directory vulnerability has been added to Discoveries:

  • Security changes that can prevent object enumeration detected.
  • Previously reported inactive Tier Zero Users that may have become active.

October 16, 2025

  • Ability to gain visibility into service principals and their associated security posture within your Entra ID environment. The Workload Identity feature helps administrators identify risky permissions, assess sign-in status, and monitor compliance with security standards.
  • Users can build searches using clause groups with support for AND/OR logical operators both within and between groups, enabling more flexible and precise query construction.

 

September 9, 2025

An AI-powered Assessment Summary report that interprets your organization’s assessment data to highlight trends and deliver a clear, high-level overview of results.

 

August 11, 2025

The following Active Directory Assessments have been added to Discoveries:

  • Privilege Escalation
    • Non-Tier Zero account with write or extended permission on Tier Zero object

For certain vulnerabilities, you can click the Principal Name or Display Name link to view detailed information about the object. This may include object properties, any affected Tier Zero objects, and group members (for group objects only).

 

July 31, 2025

Addition of Security Guardian Intelligence which is a powerful new feature that uses AI assistance to enhance your organization’s security management. With this feature, you can:

  • Ask focused questions tailored to your specific environment.
  • Gain valuable insights into the security health of your Active Directory and Entra ID systems.
  • View critical vulnerabilities and issues identified during assessments.
  • Receive practical, actionable recommendations for remediation.

New Security Guardian built in searches:

  • Shields Up enabled in the past 30 days
  • Shields Up disabled in the past 30 days
  • Shields Up override account changes in the past 30 days

July 23, 2025

Shields Up is a new rapid-response feature that helps organizations protect their most critical Active Directory assets during periods of elevated cyber risk or active security incidents. It applies a strict, pre-configured lockdown to Tier Zero objects—such as privileged users, groups, computers, and policies—blocking unauthorized changes, deletions, or policy updates. While designed for short-term emergency use, Shields Up can also be enabled continuously as a proactive defense strategy.

 

Incident response management

Quest Operations and Quest Support have procedures in place to monitor the health of the system and ensure any degradation of the service is promptly identified and resolved. On Demand relies on Azure and AWS infrastructure and as such, is subject to the possible disruption of these services. You can view the following status pages:

System Requirements

The following web browsers are supported with On Demand:

  • Microsoft Edge
  • Google Chrome (latest version)
  • Mozilla Firefox (latest version)

Additional component requirements

See the Security Guardian User Guide for more details.

Component Purpose
Hybrid Agent

Gives Security Guardian access to the Active Directory domains that you want to keep secure.

Quest Change Auditor

Sends Active Directory events to On Demand for reporting in Security Guardian Findings and allows you to protect Tier Zero objects.

NOTE: A minimum of version 7.3 is required to send critical activity events to On Demand, and a minimum of version 7.4 is required to protect Tier Zero objects.

 

Hybrid Audit Agent Sends Active Directory events to Audit for reporting in Security Guardian Findings and allows you to protect Tier Zero objects.

SpecterOps BloodHound Enterprise

(Optional)

Identifies Tier Zero assets in your organization's Active Directory domain(s), which you can monitor assess for security vulnerabilities in Security Guardian.

NOTE: If BloodHound Enterprise is not configured, Security Guardian will be used as your organization's Tier Zero provider once the Hybrid Agent is configured.

SIEM solution: 

  • Microsoft Sentinel

  • Splunk Cloud or Enterprise

(Optional)

Allows Security Guardian Findings to be forwarded to a configured SIEM tool for further analysis.

NOTE: Regardless of whether your organization uses a SIEM solution, you can also have Finding alerts sent via email.

Product licensing

Quest On Demand is a Software as a Service (SaaS) application where application software is hosted in the cloud and made available to users through quest-on-demand.com.

Use of this software is governed by the Software Transaction Agreement found at www.quest.com/legal/sta.aspx and the SaaS Addendum at www.quest.com/legal/saas-addendum.aspx. This software does not require an activation or license key to operate.

You can sign in to Quest On Demand as a Guest user and sample the solutions the product can offer. As a Guest user, you can add your Azure AD tenant and look for problems that can be solved by Quest On Demand. To sign in as a Guest user, go to quest-on-demand.com and click Continue as Guest.

Trial licenses are available. To enable a trial license, you must use a Quest account to sign up for Quest On Demand. Use one of the following procedures:

To enable a trial license with an existing Quest account

  1. Go to https://www.quest.com/on-demand/
  2. Scroll down to the module you are interested in and click Try Online.
  3. On the Free Trial of <Module Name> page, click Sign In for your Free Trial.
  4. Fill in your Quest account credentials and click Sign In. The Welcome to Quest On Demand page opens.
  5. In the Add organization name field, enter a name for your Quest On Demand organization.
  6. In the Select Region field, select the region where you want your data to reside.
  7. Click Create New Organization.

You can now add your Azure AD tenant and begin using the module. See the Global Settings User Guide for more information on working with Quest On Demand.

To create a Quest account and enable a trial license

  1. Go to https://www.quest.com/on-demand/
  2. Scroll down to the module you are interested in and click Try Online.
  3. To try online, you must create a Quest account and then sign up for Quest On Demand.
  4. Create a Quest account.
    1. Click Create a Trial Account.
    2. Fill in the fields on the Create Account page. Note that the email and password entered here will be the credentials you use to sign in to Quest On Demand.
    3. Click Create Account. The “We’ve sent you an email” page opens.
  5. Sign in to Quest On Demand.
    1. Go to your email account and open the email from support.quest.com. Click on the verification link. The Welcome to Quest On Demand page opens.
    2. In the Add organization name field, enter a name for your Quest On Demand organization.
    3. In the Select Region field, select the region where you want your data to reside.
    4. Click Create New Organization.

You can now add your Azure AD tenant and begin using the module. See the Global Settings User Guide for more information on working with Quest On Demand.

Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating