Elisity Blog

Elisity Release 26.6: Cleaner policy, richer identity, and easier edge operations

As microsegmentation programs grow, the hard work shifts from rollout to day-to-day control. More devices, more sites, more Policy Groups, and more identity sources all add useful context, but they also create more places for stale policy, missing context, or operational friction to hide.

Elisity Release 26.6 focuses on that operating reality. It helps teams keep least-privilege policy current, navigate larger Policy Matrices, add more trusted context to Elisity IdentityGraph™, and simplify common Elisity Virtual Edge and Virtual Edge Node workflows.

Keep least privilege current with policy insights

Least privilege is not a one-time project. Policies that made sense during rollout can become too broad as traffic patterns change, applications move, or device groups evolve.

Release 26.6 adds an Overly Permissive Policy category in Elisity Insights. It identifies Policy Sets that contain unused Allow or Custom policies and surfaces one insight per affected Policy Set, so administrators can review and tighten policy where it matters. The analysis window can be configured from 30 to 180 days through Elisity Assistant and applied globally, by Security Level, or by Policy Set.

The review path is built for action. From the insight, administrators can open the Policy Matrix with the relevant context already loaded, review the affected rules, and adjust policy without hunting through the matrix manually.

Make large Policy Matrices easier to manage

Policy scale is useful only if operators can still understand and manage it. Release 26.6 adds several Policy Matrix improvements for larger environments.

The Policy Matrix adds a chip-based Universal Filter Bar with Side A and Side B selectors, grouped filters, saved filters, and per-user, per-Policy Set filter persistence. Existing Policy Matrix views can be migrated into saved filters on first login, preserving prior work while moving users into the new filtering model.

Custom views within Policy Sets also improve in this release. Dynamic Security Level groupings update as Policy Groups change levels, view names can be reused across different Policy Sets, Policy Group counts are more accurate, and custom views can be reordered.

Add more context to Elisity IdentityGraph

Release 26.6 expands the set of signals that can feed Elisity IdentityGraph and inform identity-based Policy Group assignments.

The new Tenable One connector for Elisity IdentityGraph brings vulnerability and exposure management context into Elisity. The AWS connector now supports IAM role assumption, reducing reliance on long-lived static credentials. CrowdStrike enrichment now resolves Host Group membership and Prevention Policy assignment to human-readable names and stores them as Elisity IdentityGraph attributes that can be used as Policy Group match criteria. The xDome connector now enriches devices whose online status is reported as NA, in addition to online and offline devices.

Together, these updates give administrators more usable context when building and maintaining dynamic Policy Groups.

Improve visibility and classification evidence

Release 26.6 adds new visibility into device behavior and classification decisions.

Device classification evidence is also clearer. Devices with observed network flows can be classified through Elisity’s private machine learning pipeline, and the Device Insight modal shows supporting evidence such as confidence score, MAC OUI, and RDAP signals. Reports that group activity by device now include each device’s IP address alongside its MAC address, making review and triage easier.

Simplify Elisity Virtual Edge operations

Several Release 26.6 updates reduce routine work around Virtual Edge and Virtual Edge Node operations.

The Download Software dialog now includes Microsoft Hyper-V (.vhdx) as a selectable deployment platform alongside VMware and Cisco App-hosted options. Bulk export and import for Virtual Edge configurations now supports an export-then-import workflow using an import-ready XLSX format, with group, credential, and Virtual Edge selection moved into the spreadsheet.

Decommission and recommission workflows are more flexible. Operators can force-delete Virtual Edge Nodes in Decommission Started or Decommission In Progress status after confirming the warning, and they can recommission nodes from Decommission Failed, Decommission Started, or Decommission In Progress states.

Release 26.6 also adds a Status Details column to the Virtual Edge Nodes table, making degraded service reasons visible inline, and adds an IP Address Check step during Virtual Edge Node onboarding to confirm that the configured IP address is the primary interface address on the target switch.

A cleaner operating model for scaled segmentation

Release 26.6 is about making mature microsegmentation environments easier to operate. Policy insights help teams keep least privilege current. Better filters make large Policy Matrices more manageable. New Elisity IdentityGraph context improves dynamic policy decisions. Visibility and Elisity Virtual Edge updates reduce the time operators spend chasing missing context or routine lifecycle issues.

Availability

Elisity Release 26.6 is available now. For every change, including API updates and configuration details, read the 26.6.0 release notes.(Customer Login Required)

Want to see how Elisity helps you implement microsegmentation in weeks instead of years? Schedule a demo at elisity.com/demo-request.

No Comments Yet

Let us know what you think