Blog
Stay up to date with the latest from InfraScout — product releases, new features, and announcements.
A Passkey or Nothing
August 12, 2026 · InfraScout Team
A recommended Conditional Access baseline for InfraScout — why ordinary MFA is the wrong bar for a platform that reaches your whole estate, and the one exception our own installer forces us to be honest about. Read more →
Ask for the Capability, Not the Host List
August 6, 2026 · InfraScout Team
Filter agents by the capability you actually need, page host inventory past 100 systems, and stop mistaking a truncated result for proof that nothing matches. Read more →
Usage Guidance the Model Actually Reads
August 5, 2026 · InfraScout Team
A new field for telling the AI what an external MCP server is for, an allowlist that asks what to withhold rather than what to permit, and a fix for custom groups that reported themselves empty. Read more →
Steer While It Streams, and Thinking That Stays Where You Put It
August 5, 2026 · InfraScout Team
A visible button for redirecting a response mid-flight, and reasoning blocks that stop overriding your decision to open or close them. Read more →
Tool Groups Now Answer to Your Entra Groups
July 30, 2026 · InfraScout Team
Every tool group can be scoped to the security groups that may use it — built-in groups included — with one action to take in your tenant before your users notice. Read more →
Task Agents Get a Scoped Toolset and a Real Brief
July 27, 2026 · InfraScout Team
Delegated runs were receiving the entire tool catalog on every spawn, and briefs that offered a menu instead of a method. Scoping, a structured brief, and a stated no-memory contract — measured against thirty-eight real runs. Read more →
Copy an Answer, Read a Server's Manual, Keep Ten Threads Open
July 27, 2026 · InfraScout Team
Copy a reply as raw markdown with its sources intact, let the AI read a registered MCP server's own instructions, ten concurrent chat tabs, and titles that appear without a reload. Read more →
A Log Reader That Was Also a Credential Reader
July 26, 2026 · InfraScout Team
A security review found the log reader would open any file the agent could — which, running as SYSTEM, made it a privilege escalation for read-only callers. Plus rate limiting and two PowerShell policy bypasses. Read more →
Who Decides an External Tool Is Read-Only?
July 26, 2026 · InfraScout Team
External MCP tools now keep the annotations their servers declare — and because 591 discovered tools yielded exactly one server that declares any, a tenant admin can classify them per tool. Read more →
MCP Servers That Run Inside Your Network
July 23, 2026 · InfraScout Team
Nominate one of your agents as the host for an MCP server and its tools reach the AI without the server ever becoming internet-reachable — a child process it supervises, or a server already running on that network. Read more →
InfraScout Is Now an OAuth Client for Remote MCP Servers
July 23, 2026 · InfraScout Team
Connect a remote MCP server with a consent popup instead of a pasted token. Tokens refresh themselves, and the card warns you before an Entra refresh grant expires. Read more →
Following an Attack Path Backward
July 21, 2026 · InfraScout Team
Two tools read the Microsoft Security Exposure Management graph — start at the asset you care about protecting and find what can reach it, in readable relationships rather than graph queries. Read more →
The Insights Page Opens on Work You Still Have to Do
July 21, 2026 · InfraScout Team
Triage lands on open, acknowledged, and in-progress findings, filters combine instead of replacing each other, and a dashboard deep link finally applies the filter it promised. Read more →
Enrolling an Agent Is Now One Command
July 19, 2026 · InfraScout Team
Sign in to Entra ID with a device code and the agent provisions itself, enrolls, and installs its service. No token to generate, no UUIDs to transcribe. Read more →
Heatmaps, Treemaps, and Diagrams That Match the Question
July 19, 2026 · InfraScout Team
Charts gain pie, heatmap, and treemap with color ramps that carry meaning; diagrams gain timelines, mindmaps, and quadrant charts — all drawn on the portal's own palette. Read more →
A Two-Minute Cap That Wasn't Supposed to Be There
July 19, 2026 · InfraScout Team
Chat wrapped every tool call in a hard two-minute limit regardless of what the AI asked for — which reported long commands as timed out while they kept running, and provoked a retry that broke a host. Read more →
Sensor Coverage, Phishing Results, and What's Worth Patching First
July 16, 2026 · InfraScout Team
Nine new read-only tools close the gaps a security review kept hitting — Defender for Identity sensor posture, attack simulation outcomes, and organization-wide Vulnerability Management. Read more →
Linux Performance Reads and the systemd Journal
July 16, 2026 · InfraScout Team
A Linux host now answers performance questions in the same shape a Windows host does, and the systemd journal is queryable with structured filters instead of a shelled-out journalctl. Read more →
Agents on Routers and Appliances
July 16, 2026 · InfraScout Team
A MIPS build makes OpenWrt-class hardware a first-class target, and the services inventory now reads procd, OpenRC, and SysV instead of assuming systemd. Read more →
Intune Compliance in One Call, and Which Devices Run That App
July 16, 2026 · InfraScout Team
Four new Intune tools — the tenant-wide compliance rollup, per-setting failure counts, a per-user device lookup, and the devices a detected app is installed on. Read more →
How InfraScout Secures Your Infrastructure
July 15, 2026 · InfraScout Team
The InfraScout trust model in one place — agents that dial out over mutually authenticated TLS, Microsoft Entra ID sign-in, role-scoped tool access, closed-by-default visibility, and an audit trail behind every finding. A companion to the new Security Architecture reference. Read more →
Portal Polish: Tool Details, Safer Token Limits, and Resilient Health
July 15, 2026 · InfraScout Team
Tool Groups cards now open a read-only tool-details view, AI provider token limits validate before they cause a confusing save failure, and the API health banner recovers the moment the network returns. Read more →
Role-Scoped MCP Tool Access
July 14, 2026 · InfraScout Team
Standard users are now confined to read-only tools — an enforced least-privilege boundary that covers raw MCP clients too, not just the chat UI. Read more →
Read-Only PowerShell With an Admin Command Policy
July 14, 2026 · InfraScout Team
A dedicated read-only PowerShell tool validates every script against an admin-managed command policy before it runs, so anything that would mutate host state is blocked and never dispatched. Read more →
Pop-Out Chat, Starter Prompts, and a Shared Live View
July 14, 2026 · InfraScout Team
Chat pops out into a floating panel that keeps streaming as you move around the portal, greets a new thread with curated starter prompts, and mirrors mid-turn tool calls to a second device instantly. Read more →
The Onboarding Script Is Now Digitally Signed
July 14, 2026 · InfraScout Team
The script you run in your own tenant to create the InfraScout Entra app registration is now Authenticode-signed with a publicly-trusted certificate — no more execution-policy or unknown-publisher warnings. Read more →
Windows Agent Binaries Are Now Digitally Signed
July 12, 2026 · InfraScout Team
The Windows agent — x64 and ARM64 — is now signed with a publicly-trusted, Microsoft-issued certificate via Azure Trusted Signing, with the publisher identity verifiable right in Windows. No more unknown-publisher warnings slowing down install and update, though behavior-based detection in Defender and other EDR products still applies as before. Read more →
InfraScout Is Coming to iPhone and Apple Watch
July 12, 2026 · InfraScout Team
A native iOS app is in the works: the full agentic chat with streamed thinking and tool calls, your dashboard and fleet, insights, and the audit trail — plus a glance on the wrist. Here's what's built, how we're handling tenant data on a personal device, and where it stands. Read more →
A Log File Reader That Doesn't Flood the Conversation
July 12, 2026 · InfraScout Team
Reading a log no longer means the AI improvising tail and grep and paying for a raw dump. A dedicated cross-platform tool reads log files on Windows, Linux, and macOS — filtering, deduping, and time-windowing on the host, with timestamps that finally respect the host's clock. Read more →
Cheaper Conversations and Fewer Failed Tool Calls
July 12, 2026 · InfraScout Team
Long, tool-heavy assessments now cost meaningfully less for exactly the same work. Alongside that, a long tail of avoidable tool-call failures — Unified Audit Log searches worst among them — and a bug that could permanently break a live chat. Read more →
Resource Visibility Is Now Closed by Default
July 11, 2026 · InfraScout Team
A resource with no visibility groups assigned is now visible to admins only, not to the whole tenant — a safer default, and one that needs a pass from every tenant admin. Plus an explicit Everyone option, per-agent block inheritance for sensitive hosts, and a three-state visibility shield. Read more →
Azure AI Foundry Joins Anthropic and OpenAI
July 11, 2026 · InfraScout Team
You can now point an AI provider connection at Azure AI Foundry and run assessments on models hosted inside your own Azure subscription — with the Claude and GPT surfaces as separate provider choices and a clear table of what each provider can and cannot do. Read more →
The AI Can Now Ask You a Question — and Wait for Your Answer
July 11, 2026 · InfraScout Team
When an assessment hits an ambiguity, the AI asks with a card you answer by clicking — and the same turn carries straight on from where it paused, instead of ending so you can type a reply. Read more →
What a Deep Security Audit of InfraScout Found — and What We Fixed
July 11, 2026 · InfraScout Team
We ran an adversarial audit across InfraScout's critical surfaces — the agent transport, the AI tool surface, the web API, tenant isolation, and the portal. Here is what it found, what it did not find, and the fixes that shipped, including the false "certificate expiring" badge and the revocation gap behind it. Read more →
Task Agents: The AI Plans Its Work and Delegates It
July 9, 2026 · InfraScout Team
The AI now keeps an explicit task plan you can watch take shape, and hands self-contained work to isolated Task Agents that report back only a distilled result — read-only by default, fully auditable, and with their cost finally visible. Read more →
Portal Polish: Faster Charts, Keyboard-Friendly Menus, Sharper Session Records
July 8, 2026 · InfraScout Team
Chat stays smooth with a dozen charts in the thread, every dropdown responds to the keyboard, admin session records identify the iOS app correctly, and editing a shared playbook module now reaches the playbooks that include it. Read more →
Sharper Chat Audits, Smoother Chat, and Steadier Runs
July 7, 2026 · InfraScout Team
The admin Chat Audit gains a Model column and accurate cost for Agentic Workflow runs, the chat view picks up a round of polish, and a set of quieter fixes steadies workflow runs, agent auto-update, and web research. Read more →
The AI Confirms Before It Changes Anything — and Logs Every Change
July 6, 2026 · InfraScout Team
In a live conversation, the AI now spells out exactly what a change will do — what, where, and the expected impact — and waits for your explicit go-ahead before it acts. Every change it makes or notices is written to a dated change log you can browse right in Memory. Read more →
Watch Windows Hosts Over Time: Performance Counters and Live Tracing
July 5, 2026 · InfraScout Team
InfraScout can now watch a Windows host over time — read performance counters as a snapshot or a short series, run background traces that keep recording for hours or days, and reach for ready-made capture profiles, including boot-time profiles for the logon failures a live trace can't reach. Read more →
Diagrams, Now in Chat
July 4, 2026 · InfraScout Team
The AI can now draw flowcharts, sequence diagrams, and other structural visuals inline in the chat — the companion to charts. Click any diagram to zoom in, and one that doesn't render cleanly retries itself or offers a one-click fix. Read more →
Charts, Now in Chat
July 3, 2026 · InfraScout Team
The AI can now render interactive line, area, bar, and donut charts right in the chat, built from data it gathered earlier in the same conversation — ask for a trend, a comparison, or a breakdown and get an actual chart instead of a wall of numbers. Read more →
OpenAI Models, Now Side by Side with Anthropic
July 2, 2026 · InfraScout Team
You can now run InfraScout assessments on OpenAI as well as Anthropic. Point an AI provider connection at OpenAI, add its own encrypted key, and pick from the GPT-5 reasoning family or the GPT-5.4 family — with full chat parity across streaming, the agentic tool loop, reasoning, cited web search, and long-run compaction. Anthropic stays the default, so nothing changes unless you opt in. Read more →
Chat Update: Sonnet 5, Data Region, and Clearer Safety Refusals
July 2, 2026 · InfraScout Team
Three chat improvements land together. Claude Sonnet 5 joins the model picker with a 1 million token context window, Anthropic connections gain a per-connection data region so inference runs where your residency requirements need it, and safety refusals now render as a clear card in the thread — partial answers preserved, surviving reloads, on both Anthropic and OpenAI connections. Read more →
Defender for Office 365 Analyzed Emails, Now in Chat
June 30, 2026 · InfraScout Team
InfraScout now reads the Defender for Office 365 Analyzed emails feed — the data behind Threat Explorer — directly during an assessment. Sweep a time window for the messages Defender analyzed, then pull the full record for any one of them, with every attachment, URL, and detection detail behind the verdict. Built for false-positive triage, phishing hunts, and delivery forensics. Read more →
Audit Enterprise App Access and Delegated Consent
June 30, 2026 · InfraScout Team
Reviewing an enterprise app takes three answers: what it can do on its own, who can use it, and what it can do as your signed-in users. Two new read-only Entra ID tools fill in the last two — listing who is assigned to an app and what delegated permissions were consented on people's behalf, org-wide consent included. "List every app with org-wide consent to read mail, and who granted it" is now a question you can ask mid-assessment. Read more →
Event Log Queries Go Self-Sufficient
June 30, 2026 · InfraScout Team
The Windows Event Log tool no longer needs a fallback to hand-written PowerShell. It now accepts a raw XPath filter for questions the structured filters can't express, answers "how many" directly with a match count and per-Event-ID breakdown, and — across every InfraScout tool — rejects an unrecognized argument up front instead of quietly running an unfiltered query. Read more →
Sharper Audit Trails and Fewer Failed Tool Calls
June 30, 2026 · InfraScout Team
Your executions trail now names the exact tool behind every call — cloud or agent — and the admin Chat Audit shows each conversation's lifetime cost at a glance. On the reliability side, tolerant arguments, normalized directory searches, and an audit-log status check that waits instead of spinning mean assessments waste fewer turns on failures that never had to happen. Read more →
Mid-Loop Chat Steering: Talk to the AI While It Works
June 28, 2026 · InfraScout Team
Keep typing while the AI works — send a message mid-stream and it gets folded into the running assessment at the next safe point, with no restart and no lost progress. Stop now pauses the turn instead of ending the chat, so an interruption is a pause, not a dead end. Read more →
Filter the Executions Audit by a Specific User
June 28, 2026 · InfraScout Team
The admin Audit and Compliance Executions view now has a user picker. Filter the trail to one person to see everything they caused — their own AI and tool calls plus any workflows that ran on their behalf. Read more →
Three Fixes: Consistent Agent States, Newest-First Event Logs, and a Clean Sign-Out
June 28, 2026 · InfraScout Team
Three small fixes land together: agent status labels and filters now agree across the agents and admin views (reachable agents read "Connected" everywhere), "last N" event log reads return the newest N entries, newest-first, and signing out lands on a clean signed-out page instead of looping. Read more →
A Dedicated Inventory Page for Every Agent
June 25, 2026 · InfraScout Team
Inventory now has a home in the dashboard. Each agent gets a dedicated page to browse its latest snapshot, see what changed in the last 24 hours, review past collections, and refresh on demand — no chat prompt required. Read more →
Agentic Workflows: Assessments That Run Themselves
June 15, 2026 · InfraScout Team
Agentic Workflows let InfraScout run AI-driven assessments on their own — define a workflow once, then trigger it on a schedule, from a webhook, or by hand. Each run executes headlessly under a scoped, non-admin service account, with full transcripts and run history. Read more →
Why Is This Device Non-Compliant? Per-Device Intune Security Assessment
June 15, 2026 · InfraScout Team
InfraScout now drills into a single Intune-managed device to explain exactly which compliance policy and setting drove its non-compliant verdict, checks on-device Defender and malware health, and reads the baselines, ASR rules, and Settings Catalog profiles being pushed to it — all read-only. Read more →
Server-Side Sign-In Aggregation for Spray and Brute-Force Triage
June 11, 2026 · InfraScout Team
InfraScout now aggregates Entra ID sign-in logs server-side and returns a compact, faceted roll-up — top source IPs, failure reasons, distinct users per IP, and success-after-failure candidates — so an AI assessment can triage password spray and brute force without drowning in raw rows. Read more →
Claude Fable 5 Is Now Available for Assessments
June 10, 2026 · InfraScout Team
Claude Fable 5, Anthropic's most capable model and a tier above Opus, is now selectable when you configure an AI provider — a premium option for long playbook runs and deep, multi-step investigations. Read more →
What's Shared Right Now: A Standing Sharing-Link Inventory for SharePoint and OneDrive
June 9, 2026 · InfraScout Team
InfraScout now reports the current standing state of active sharing links across SharePoint Online and OneDrive — classifying each link as anonymous, never-expiring, edit, or external, defaulting to the highest-risk links, scoping the crawl wherever you point it, and pairing it with the org-wide sharing policy. All read-only and conversational. Read more →
The Microsoft 365 Unified Audit Log, Now in Chat
June 9, 2026 · InfraScout Team
InfraScout now searches the Microsoft 365 Unified Audit Log — the workload activity trail across Exchange, SharePoint, OneDrive, and Teams — directly from an assessment, with incident-response shortcuts for non-owner mailbox access, suspicious inbox rules, and external file sharing. Read more →
Find Shadow IT and Shadow AI with Cloud App Discovery
June 5, 2026 · InfraScout Team
InfraScout now reads Microsoft Defender for Cloud Apps Cloud Discovery data — surfacing the cloud apps your org actually uses with per-app risk and compliance profiles, connecting apps to the users and devices reaching them, and bringing emerging shadow-AI into view. All read-only and conversational. Read more →
Live Status for Slow Cloud Queries
June 5, 2026 · InfraScout Team
Slow cloud queries — advanced hunting, cost reports, large list pages — now show a live running row in the execution view while the call is in flight, so you can see work is happening instead of waiting for it to appear once finished. Read more →
Microsoft 365 Service Health and Message Trace, Now in Chat
June 4, 2026 · InfraScout Team
InfraScout now reads Microsoft 365 service health and traces Exchange Online mail-flow during assessments — ask whether a service is degraded or whether an email was delivered, all read-only and in the same conversation. Read more →
What's New in Chat: Opus 4.8 and Tool-Group Controls
June 4, 2026 · InfraScout Team
Claude Opus 4.8 is now selectable for complex assessments, chat cost reporting attributes spend to the right period with a per-message breakdown, and tool groups are easier to control — with the core agent and inventory tools now reliable on every model. Read more →
More Defender Hunting Tables, and a Future-Proof Transport
June 2, 2026 · InfraScout Team
Four new typed Advanced Hunting tools cover device file, network, registry, and image-load events, and the feature now runs on Microsoft's current hunting query API so it keeps working past the older endpoint's early-2027 retirement. Read more →
Web Search and Web Fetch, Now in Chat
May 13, 2026 · InfraScout Team
The AI can now search the web and fetch pages during an assessment — enriching findings with vendor advisories, CVE lookups, and Graph permission details — with every answer's sources cited and per-connection admin controls for domain allow/block lists and usage caps. Read more →
Smarter Windows Event Log Queries
May 12, 2026 · InfraScout Team
Windows Event Log queries now filter by Event ID and Event Data fields directly, so AI-driven investigations get precise, structured results in one step instead of improvised PowerShell. Read more →
Session Groups: Every Conversation Owns Its Work
May 11, 2026 · InfraScout Team
Chat assessment sessions are now organized under their conversation as a session group with a clean lifecycle — conversations create their group automatically, sessions close together when a chat ends, an ended-chat banner replaces the message box, admins and reviewers get a first-class view for audit, and each agent has at most one running session per group. Read more →
Defender Advanced Hunting, Now in Chat
May 4, 2026 · InfraScout Team
Microsoft Defender Advanced Hunting is now reachable through InfraScout via dedicated MCP tools, and Defender has its own toolset namespace so the right tool is picked every time and audit logs group activity sensibly. Read more →
Chat Polish — Task Budget and Adaptive Thinking
May 1, 2026 · InfraScout Team
A live task budget tracks what each AI-driven assessment is consuming, and the chat now reveals the model's extended thinking only when a step actually used it. Long playbook runs are easier to trust, and short questions are easier to read. Read more →
Inventory: A Persistent Record of Every Host You Audit
April 28, 2026 · InfraScout Team
Every connected agent now keeps a persistent, queryable record of system info, software, services, and certificates — refreshed on a schedule and on demand, surfaced in the dashboard, and answerable directly through chat. Read more →
A Focused Dashboard and a Cleaner Split for Executions
April 27, 2026 · InfraScout Team
The dashboard is now a three-zone workspace with a My work / All visible toggle, and Executions splits cleanly into a personal view and an admin Audit and Compliance view for security teams and auditors. Read more →
Agent Auto-Update — End-to-End
April 26, 2026 · InfraScout Team
Update policies, maintenance windows, a four-lane pipeline (Queued → Sent → Acked → Done), and per-agent history mean keeping a fleet of agents on the latest version no longer involves SSH, RDP, or hand-copied binaries. Read more →
Faster, Quieter Windows Agents
April 25, 2026 · InfraScout Team
Native Windows collectors replace the PowerShell wrappers behind event log and WMI queries — collections finish in a fraction of the previous time, the agent stops pinning CPU during scheduled sweeps, and errors finally name what failed. Read more →
Dynamic Agent Groups
April 24, 2026 · InfraScout Team
Define rules once and let InfraScout keep group membership in sync as agents come and go. OS defaults cover the common groups every fleet wants, and policies attached to a group apply automatically to every host that matches. Read more →
Introducing InfraScout — Infrastructure as Chat
April 23, 2026 · InfraScout Team
InfraScout turns infrastructure assessments into a chat-driven workflow — AI clients like Claude orchestrate audits across Windows, Linux, and macOS agents via the Model Context Protocol, with built-in tools for Entra ID, Azure, Microsoft 365, and Microsoft Defender. Read more →
Questions or want to prioritize a feature? Reach out at info@infrascout.cloud.