Blog

Stay up to date with the latest from InfraScout — product releases, new features, and announcements.


A Passkey or Nothing

August 12, 2026 · InfraScout Team

A recommended Conditional Access baseline for InfraScout — why ordinary MFA is the wrong bar for a platform that reaches your whole estate, and the one exception our own installer forces us to be honest about. Read more →


Ask for the Capability, Not the Host List

August 6, 2026 · InfraScout Team

Filter agents by the capability you actually need, page host inventory past 100 systems, and stop mistaking a truncated result for proof that nothing matches. Read more →


Usage Guidance the Model Actually Reads

August 5, 2026 · InfraScout Team

A new field for telling the AI what an external MCP server is for, an allowlist that asks what to withhold rather than what to permit, and a fix for custom groups that reported themselves empty. Read more →


Steer While It Streams, and Thinking That Stays Where You Put It

August 5, 2026 · InfraScout Team

A visible button for redirecting a response mid-flight, and reasoning blocks that stop overriding your decision to open or close them. Read more →


Tool Groups Now Answer to Your Entra Groups

July 30, 2026 · InfraScout Team

Every tool group can be scoped to the security groups that may use it — built-in groups included — with one action to take in your tenant before your users notice. Read more →


Task Agents Get a Scoped Toolset and a Real Brief

July 27, 2026 · InfraScout Team

Delegated runs were receiving the entire tool catalog on every spawn, and briefs that offered a menu instead of a method. Scoping, a structured brief, and a stated no-memory contract — measured against thirty-eight real runs. Read more →


Copy an Answer, Read a Server's Manual, Keep Ten Threads Open

July 27, 2026 · InfraScout Team

Copy a reply as raw markdown with its sources intact, let the AI read a registered MCP server's own instructions, ten concurrent chat tabs, and titles that appear without a reload. Read more →


A Log Reader That Was Also a Credential Reader

July 26, 2026 · InfraScout Team

A security review found the log reader would open any file the agent could — which, running as SYSTEM, made it a privilege escalation for read-only callers. Plus rate limiting and two PowerShell policy bypasses. Read more →


Who Decides an External Tool Is Read-Only?

July 26, 2026 · InfraScout Team

External MCP tools now keep the annotations their servers declare — and because 591 discovered tools yielded exactly one server that declares any, a tenant admin can classify them per tool. Read more →


MCP Servers That Run Inside Your Network

July 23, 2026 · InfraScout Team

Nominate one of your agents as the host for an MCP server and its tools reach the AI without the server ever becoming internet-reachable — a child process it supervises, or a server already running on that network. Read more →


InfraScout Is Now an OAuth Client for Remote MCP Servers

July 23, 2026 · InfraScout Team

Connect a remote MCP server with a consent popup instead of a pasted token. Tokens refresh themselves, and the card warns you before an Entra refresh grant expires. Read more →


Following an Attack Path Backward

July 21, 2026 · InfraScout Team

Two tools read the Microsoft Security Exposure Management graph — start at the asset you care about protecting and find what can reach it, in readable relationships rather than graph queries. Read more →


The Insights Page Opens on Work You Still Have to Do

July 21, 2026 · InfraScout Team

Triage lands on open, acknowledged, and in-progress findings, filters combine instead of replacing each other, and a dashboard deep link finally applies the filter it promised. Read more →


Enrolling an Agent Is Now One Command

July 19, 2026 · InfraScout Team

Sign in to Entra ID with a device code and the agent provisions itself, enrolls, and installs its service. No token to generate, no UUIDs to transcribe. Read more →


Heatmaps, Treemaps, and Diagrams That Match the Question

July 19, 2026 · InfraScout Team

Charts gain pie, heatmap, and treemap with color ramps that carry meaning; diagrams gain timelines, mindmaps, and quadrant charts — all drawn on the portal's own palette. Read more →


A Two-Minute Cap That Wasn't Supposed to Be There

July 19, 2026 · InfraScout Team

Chat wrapped every tool call in a hard two-minute limit regardless of what the AI asked for — which reported long commands as timed out while they kept running, and provoked a retry that broke a host. Read more →


Sensor Coverage, Phishing Results, and What's Worth Patching First

July 16, 2026 · InfraScout Team

Nine new read-only tools close the gaps a security review kept hitting — Defender for Identity sensor posture, attack simulation outcomes, and organization-wide Vulnerability Management. Read more →


Linux Performance Reads and the systemd Journal

July 16, 2026 · InfraScout Team

A Linux host now answers performance questions in the same shape a Windows host does, and the systemd journal is queryable with structured filters instead of a shelled-out journalctl. Read more →


Agents on Routers and Appliances

July 16, 2026 · InfraScout Team

A MIPS build makes OpenWrt-class hardware a first-class target, and the services inventory now reads procd, OpenRC, and SysV instead of assuming systemd. Read more →


Intune Compliance in One Call, and Which Devices Run That App

July 16, 2026 · InfraScout Team

Four new Intune tools — the tenant-wide compliance rollup, per-setting failure counts, a per-user device lookup, and the devices a detected app is installed on. Read more →


How InfraScout Secures Your Infrastructure

July 15, 2026 · InfraScout Team

The InfraScout trust model in one place — agents that dial out over mutually authenticated TLS, Microsoft Entra ID sign-in, role-scoped tool access, closed-by-default visibility, and an audit trail behind every finding. A companion to the new Security Architecture reference. Read more →


Portal Polish: Tool Details, Safer Token Limits, and Resilient Health

July 15, 2026 · InfraScout Team

Tool Groups cards now open a read-only tool-details view, AI provider token limits validate before they cause a confusing save failure, and the API health banner recovers the moment the network returns. Read more →


Role-Scoped MCP Tool Access

July 14, 2026 · InfraScout Team

Standard users are now confined to read-only tools — an enforced least-privilege boundary that covers raw MCP clients too, not just the chat UI. Read more →


Read-Only PowerShell With an Admin Command Policy

July 14, 2026 · InfraScout Team

A dedicated read-only PowerShell tool validates every script against an admin-managed command policy before it runs, so anything that would mutate host state is blocked and never dispatched. Read more →


Pop-Out Chat, Starter Prompts, and a Shared Live View

July 14, 2026 · InfraScout Team

Chat pops out into a floating panel that keeps streaming as you move around the portal, greets a new thread with curated starter prompts, and mirrors mid-turn tool calls to a second device instantly. Read more →


The Onboarding Script Is Now Digitally Signed

July 14, 2026 · InfraScout Team

The script you run in your own tenant to create the InfraScout Entra app registration is now Authenticode-signed with a publicly-trusted certificate — no more execution-policy or unknown-publisher warnings. Read more →


Windows Agent Binaries Are Now Digitally Signed

July 12, 2026 · InfraScout Team

The Windows agent — x64 and ARM64 — is now signed with a publicly-trusted, Microsoft-issued certificate via Azure Trusted Signing, with the publisher identity verifiable right in Windows. No more unknown-publisher warnings slowing down install and update, though behavior-based detection in Defender and other EDR products still applies as before. Read more →


InfraScout Is Coming to iPhone and Apple Watch

July 12, 2026 · InfraScout Team

A native iOS app is in the works: the full agentic chat with streamed thinking and tool calls, your dashboard and fleet, insights, and the audit trail — plus a glance on the wrist. Here's what's built, how we're handling tenant data on a personal device, and where it stands. Read more →


A Log File Reader That Doesn't Flood the Conversation

July 12, 2026 · InfraScout Team

Reading a log no longer means the AI improvising tail and grep and paying for a raw dump. A dedicated cross-platform tool reads log files on Windows, Linux, and macOS — filtering, deduping, and time-windowing on the host, with timestamps that finally respect the host's clock. Read more →


Cheaper Conversations and Fewer Failed Tool Calls

July 12, 2026 · InfraScout Team

Long, tool-heavy assessments now cost meaningfully less for exactly the same work. Alongside that, a long tail of avoidable tool-call failures — Unified Audit Log searches worst among them — and a bug that could permanently break a live chat. Read more →


Resource Visibility Is Now Closed by Default

July 11, 2026 · InfraScout Team

A resource with no visibility groups assigned is now visible to admins only, not to the whole tenant — a safer default, and one that needs a pass from every tenant admin. Plus an explicit Everyone option, per-agent block inheritance for sensitive hosts, and a three-state visibility shield. Read more →


Azure AI Foundry Joins Anthropic and OpenAI

July 11, 2026 · InfraScout Team

You can now point an AI provider connection at Azure AI Foundry and run assessments on models hosted inside your own Azure subscription — with the Claude and GPT surfaces as separate provider choices and a clear table of what each provider can and cannot do. Read more →


The AI Can Now Ask You a Question — and Wait for Your Answer

July 11, 2026 · InfraScout Team

When an assessment hits an ambiguity, the AI asks with a card you answer by clicking — and the same turn carries straight on from where it paused, instead of ending so you can type a reply. Read more →


What a Deep Security Audit of InfraScout Found — and What We Fixed

July 11, 2026 · InfraScout Team

We ran an adversarial audit across InfraScout's critical surfaces — the agent transport, the AI tool surface, the web API, tenant isolation, and the portal. Here is what it found, what it did not find, and the fixes that shipped, including the false "certificate expiring" badge and the revocation gap behind it. Read more →


Task Agents: The AI Plans Its Work and Delegates It

July 9, 2026 · InfraScout Team

The AI now keeps an explicit task plan you can watch take shape, and hands self-contained work to isolated Task Agents that report back only a distilled result — read-only by default, fully auditable, and with their cost finally visible. Read more →


Portal Polish: Faster Charts, Keyboard-Friendly Menus, Sharper Session Records

July 8, 2026 · InfraScout Team

Chat stays smooth with a dozen charts in the thread, every dropdown responds to the keyboard, admin session records identify the iOS app correctly, and editing a shared playbook module now reaches the playbooks that include it. Read more →


Sharper Chat Audits, Smoother Chat, and Steadier Runs

July 7, 2026 · InfraScout Team

The admin Chat Audit gains a Model column and accurate cost for Agentic Workflow runs, the chat view picks up a round of polish, and a set of quieter fixes steadies workflow runs, agent auto-update, and web research. Read more →


The AI Confirms Before It Changes Anything — and Logs Every Change

July 6, 2026 · InfraScout Team

In a live conversation, the AI now spells out exactly what a change will do — what, where, and the expected impact — and waits for your explicit go-ahead before it acts. Every change it makes or notices is written to a dated change log you can browse right in Memory. Read more →


Watch Windows Hosts Over Time: Performance Counters and Live Tracing

July 5, 2026 · InfraScout Team

InfraScout can now watch a Windows host over time — read performance counters as a snapshot or a short series, run background traces that keep recording for hours or days, and reach for ready-made capture profiles, including boot-time profiles for the logon failures a live trace can't reach. Read more →


Diagrams, Now in Chat

July 4, 2026 · InfraScout Team

The AI can now draw flowcharts, sequence diagrams, and other structural visuals inline in the chat — the companion to charts. Click any diagram to zoom in, and one that doesn't render cleanly retries itself or offers a one-click fix. Read more →


Charts, Now in Chat

July 3, 2026 · InfraScout Team

The AI can now render interactive line, area, bar, and donut charts right in the chat, built from data it gathered earlier in the same conversation — ask for a trend, a comparison, or a breakdown and get an actual chart instead of a wall of numbers. Read more →


OpenAI Models, Now Side by Side with Anthropic

July 2, 2026 · InfraScout Team

You can now run InfraScout assessments on OpenAI as well as Anthropic. Point an AI provider connection at OpenAI, add its own encrypted key, and pick from the GPT-5 reasoning family or the GPT-5.4 family — with full chat parity across streaming, the agentic tool loop, reasoning, cited web search, and long-run compaction. Anthropic stays the default, so nothing changes unless you opt in. Read more →


Chat Update: Sonnet 5, Data Region, and Clearer Safety Refusals

July 2, 2026 · InfraScout Team

Three chat improvements land together. Claude Sonnet 5 joins the model picker with a 1 million token context window, Anthropic connections gain a per-connection data region so inference runs where your residency requirements need it, and safety refusals now render as a clear card in the thread — partial answers preserved, surviving reloads, on both Anthropic and OpenAI connections. Read more →


Defender for Office 365 Analyzed Emails, Now in Chat

June 30, 2026 · InfraScout Team

InfraScout now reads the Defender for Office 365 Analyzed emails feed — the data behind Threat Explorer — directly during an assessment. Sweep a time window for the messages Defender analyzed, then pull the full record for any one of them, with every attachment, URL, and detection detail behind the verdict. Built for false-positive triage, phishing hunts, and delivery forensics. Read more →


June 30, 2026 · InfraScout Team

Reviewing an enterprise app takes three answers: what it can do on its own, who can use it, and what it can do as your signed-in users. Two new read-only Entra ID tools fill in the last two — listing who is assigned to an app and what delegated permissions were consented on people's behalf, org-wide consent included. "List every app with org-wide consent to read mail, and who granted it" is now a question you can ask mid-assessment. Read more →


Event Log Queries Go Self-Sufficient

June 30, 2026 · InfraScout Team

The Windows Event Log tool no longer needs a fallback to hand-written PowerShell. It now accepts a raw XPath filter for questions the structured filters can't express, answers "how many" directly with a match count and per-Event-ID breakdown, and — across every InfraScout tool — rejects an unrecognized argument up front instead of quietly running an unfiltered query. Read more →


Sharper Audit Trails and Fewer Failed Tool Calls

June 30, 2026 · InfraScout Team

Your executions trail now names the exact tool behind every call — cloud or agent — and the admin Chat Audit shows each conversation's lifetime cost at a glance. On the reliability side, tolerant arguments, normalized directory searches, and an audit-log status check that waits instead of spinning mean assessments waste fewer turns on failures that never had to happen. Read more →


Mid-Loop Chat Steering: Talk to the AI While It Works

June 28, 2026 · InfraScout Team

Keep typing while the AI works — send a message mid-stream and it gets folded into the running assessment at the next safe point, with no restart and no lost progress. Stop now pauses the turn instead of ending the chat, so an interruption is a pause, not a dead end. Read more →


Filter the Executions Audit by a Specific User

June 28, 2026 · InfraScout Team

The admin Audit and Compliance Executions view now has a user picker. Filter the trail to one person to see everything they caused — their own AI and tool calls plus any workflows that ran on their behalf. Read more →


Three Fixes: Consistent Agent States, Newest-First Event Logs, and a Clean Sign-Out

June 28, 2026 · InfraScout Team

Three small fixes land together: agent status labels and filters now agree across the agents and admin views (reachable agents read "Connected" everywhere), "last N" event log reads return the newest N entries, newest-first, and signing out lands on a clean signed-out page instead of looping. Read more →


A Dedicated Inventory Page for Every Agent

June 25, 2026 · InfraScout Team

Inventory now has a home in the dashboard. Each agent gets a dedicated page to browse its latest snapshot, see what changed in the last 24 hours, review past collections, and refresh on demand — no chat prompt required. Read more →


Agentic Workflows: Assessments That Run Themselves

June 15, 2026 · InfraScout Team

Agentic Workflows let InfraScout run AI-driven assessments on their own — define a workflow once, then trigger it on a schedule, from a webhook, or by hand. Each run executes headlessly under a scoped, non-admin service account, with full transcripts and run history. Read more →


Why Is This Device Non-Compliant? Per-Device Intune Security Assessment

June 15, 2026 · InfraScout Team

InfraScout now drills into a single Intune-managed device to explain exactly which compliance policy and setting drove its non-compliant verdict, checks on-device Defender and malware health, and reads the baselines, ASR rules, and Settings Catalog profiles being pushed to it — all read-only. Read more →


Server-Side Sign-In Aggregation for Spray and Brute-Force Triage

June 11, 2026 · InfraScout Team

InfraScout now aggregates Entra ID sign-in logs server-side and returns a compact, faceted roll-up — top source IPs, failure reasons, distinct users per IP, and success-after-failure candidates — so an AI assessment can triage password spray and brute force without drowning in raw rows. Read more →


Claude Fable 5 Is Now Available for Assessments

June 10, 2026 · InfraScout Team

Claude Fable 5, Anthropic's most capable model and a tier above Opus, is now selectable when you configure an AI provider — a premium option for long playbook runs and deep, multi-step investigations. Read more →


June 9, 2026 · InfraScout Team

InfraScout now reports the current standing state of active sharing links across SharePoint Online and OneDrive — classifying each link as anonymous, never-expiring, edit, or external, defaulting to the highest-risk links, scoping the crawl wherever you point it, and pairing it with the org-wide sharing policy. All read-only and conversational. Read more →


The Microsoft 365 Unified Audit Log, Now in Chat

June 9, 2026 · InfraScout Team

InfraScout now searches the Microsoft 365 Unified Audit Log — the workload activity trail across Exchange, SharePoint, OneDrive, and Teams — directly from an assessment, with incident-response shortcuts for non-owner mailbox access, suspicious inbox rules, and external file sharing. Read more →


Find Shadow IT and Shadow AI with Cloud App Discovery

June 5, 2026 · InfraScout Team

InfraScout now reads Microsoft Defender for Cloud Apps Cloud Discovery data — surfacing the cloud apps your org actually uses with per-app risk and compliance profiles, connecting apps to the users and devices reaching them, and bringing emerging shadow-AI into view. All read-only and conversational. Read more →


Live Status for Slow Cloud Queries

June 5, 2026 · InfraScout Team

Slow cloud queries — advanced hunting, cost reports, large list pages — now show a live running row in the execution view while the call is in flight, so you can see work is happening instead of waiting for it to appear once finished. Read more →


Microsoft 365 Service Health and Message Trace, Now in Chat

June 4, 2026 · InfraScout Team

InfraScout now reads Microsoft 365 service health and traces Exchange Online mail-flow during assessments — ask whether a service is degraded or whether an email was delivered, all read-only and in the same conversation. Read more →


What's New in Chat: Opus 4.8 and Tool-Group Controls

June 4, 2026 · InfraScout Team

Claude Opus 4.8 is now selectable for complex assessments, chat cost reporting attributes spend to the right period with a per-message breakdown, and tool groups are easier to control — with the core agent and inventory tools now reliable on every model. Read more →


More Defender Hunting Tables, and a Future-Proof Transport

June 2, 2026 · InfraScout Team

Four new typed Advanced Hunting tools cover device file, network, registry, and image-load events, and the feature now runs on Microsoft's current hunting query API so it keeps working past the older endpoint's early-2027 retirement. Read more →


Web Search and Web Fetch, Now in Chat

May 13, 2026 · InfraScout Team

The AI can now search the web and fetch pages during an assessment — enriching findings with vendor advisories, CVE lookups, and Graph permission details — with every answer's sources cited and per-connection admin controls for domain allow/block lists and usage caps. Read more →


Smarter Windows Event Log Queries

May 12, 2026 · InfraScout Team

Windows Event Log queries now filter by Event ID and Event Data fields directly, so AI-driven investigations get precise, structured results in one step instead of improvised PowerShell. Read more →


Session Groups: Every Conversation Owns Its Work

May 11, 2026 · InfraScout Team

Chat assessment sessions are now organized under their conversation as a session group with a clean lifecycle — conversations create their group automatically, sessions close together when a chat ends, an ended-chat banner replaces the message box, admins and reviewers get a first-class view for audit, and each agent has at most one running session per group. Read more →


Defender Advanced Hunting, Now in Chat

May 4, 2026 · InfraScout Team

Microsoft Defender Advanced Hunting is now reachable through InfraScout via dedicated MCP tools, and Defender has its own toolset namespace so the right tool is picked every time and audit logs group activity sensibly. Read more →


Chat Polish — Task Budget and Adaptive Thinking

May 1, 2026 · InfraScout Team

A live task budget tracks what each AI-driven assessment is consuming, and the chat now reveals the model's extended thinking only when a step actually used it. Long playbook runs are easier to trust, and short questions are easier to read. Read more →


Inventory: A Persistent Record of Every Host You Audit

April 28, 2026 · InfraScout Team

Every connected agent now keeps a persistent, queryable record of system info, software, services, and certificates — refreshed on a schedule and on demand, surfaced in the dashboard, and answerable directly through chat. Read more →


A Focused Dashboard and a Cleaner Split for Executions

April 27, 2026 · InfraScout Team

The dashboard is now a three-zone workspace with a My work / All visible toggle, and Executions splits cleanly into a personal view and an admin Audit and Compliance view for security teams and auditors. Read more →


Agent Auto-Update — End-to-End

April 26, 2026 · InfraScout Team

Update policies, maintenance windows, a four-lane pipeline (Queued → Sent → Acked → Done), and per-agent history mean keeping a fleet of agents on the latest version no longer involves SSH, RDP, or hand-copied binaries. Read more →


Faster, Quieter Windows Agents

April 25, 2026 · InfraScout Team

Native Windows collectors replace the PowerShell wrappers behind event log and WMI queries — collections finish in a fraction of the previous time, the agent stops pinning CPU during scheduled sweeps, and errors finally name what failed. Read more →


Dynamic Agent Groups

April 24, 2026 · InfraScout Team

Define rules once and let InfraScout keep group membership in sync as agents come and go. OS defaults cover the common groups every fleet wants, and policies attached to a group apply automatically to every host that matches. Read more →


Introducing InfraScout — Infrastructure as Chat

April 23, 2026 · InfraScout Team

InfraScout turns infrastructure assessments into a chat-driven workflow — AI clients like Claude orchestrate audits across Windows, Linux, and macOS agents via the Model Context Protocol, with built-in tools for Entra ID, Azure, Microsoft 365, and Microsoft Defender. Read more →


Questions or want to prioritize a feature? Reach out at info@infrascout.cloud.