Focus

New Features - Device Security - September 2026

Download PDF

Bulk Create Network Segments in Device Security

Release Date: September 2026 | Last Updated: October 2026

You can now upload a CSV file to bulk create or update network segments in Device Security, so you no longer have to manually add or edit each segment one at a time. With bulk creation and updates, you can manage large environments with multiple blocks of overlapping IP addresses more easily.

Device Security provides a CSV template for you to download. When you upload the file, you can choose to create new segments, update existing ones, or both. If a row contains an error, Device Security skips that row and continues processing the file, so a single mistake doesn't block your import.

After the upload completes, a results table shows the outcome for each row, including whether it succeeded or was skipped and the reason for each skipped entry. This gives you a clear record of what was applied and what to correct before you re-import.

Device Security Integration with Arista CloudVision

Release Date: September 2026 | Last Updated: October 2026

You can integrate Device Security with Arista CloudVision to discover Arista-managed switches, routers, and the endpoints connected to them. This integration enriches Arista network device and endpoint data for assets that you already have in your Device Security asset inventory. For new devices, this integration creates the device record in your Device Security asset inventory.

Through the integration, Device Security queries CloudVision for information such as the device identifiers, software version, and end-of-life and end-of-support dates for Arista devices managed by CloudVision. Additionally, the integration can read the ARP and MAC address tables from those devices to find endpoint devices connected to your Arista infrastructure, adding context for assets that might not otherwise appear in Device Security from network traffic observations.

Bringing in the Arista network device and endpoint data from CloudVision gives you a more complete view of your network infrastructure in Device Security . With a consolidated view, you can monitor your environment and track potential security issues that might not otherwise be visible without knowing your full network topology.

Device Security Integration with Cisco Meraki

Release Date: September 2026 | Last Updated: October 2026

( September 2026 enhancement ) The Device Security integration with Cisco Meraki can now collect switch interface data, giving Cisco Meraki-managed switches the same port-level visibility as your SNMP-integrated switches. For each switch port, Device Security learns the interface name, VLAN assignment, operational status, and LLDP neighbor information. On Layer 3-capable Meraki switches, Device Security also collects IP address, subnet, and default gateway for routed interfaces.

( February 2026 ) When configuring a Cisco Meraki integration instance with Device Security, you can specify Service Set Identifiers (SSID) to include or exclude from the scope of the data ingestion. If an SSID appears in both the include and exclude lists, causing a conflict, then the exclusion takes priority. Configure SSID filtering to prioritize which SSIDs you want to actively monitor through the Cisco Meraki integration.

( December 2025 enhancement ) Device Security can now learn network details when integrating with Cisco Meraki. The network details include information about subnets, VLANs, static IP addresses, and DHCP leases. Device Security and Cortex XSOAR use a new playbook, Import Cisco Meraki Networks to Device Security, to get the network information. The Cisco Meraki integration instance in Cortex XSOAR also includes a new field, Networks, to specify which networks to learn network information for. To pull the network information from your Cisco Meraki solution to Device Security, update your Cisco Meraki integration instance and configure a new Cortex XSOAR job with the new playbook.

Device Security integrates with Cisco Meraki Cloud through Cortex XSOAR to enrich your asset inventory with detailed data about devices accessing your network through Cisco switches and wireless access points. This integration enables you to import device attributes, such as MAC and IP addresses, VLANs, and OS details, directly into Device Security . For wired clients, you gain visibility into the connecting switch, while wireless client data includes the associated access point. Use this feature to correlate network-layer data with traffic logs from next-generation firewalls. This integratio helps you maintain visibility of both online and recently offline devices, so you can base your security policy decisions on the most current context available.

Device Security Integration with Google Workspace

Release Date: September 2026 | Last Updated: October 2026

You can integrate Device Security with Google Workspace to import enrolled Chromebook and mobile device records into your asset inventory. The integration updates existing devices in your asset inventory with more detailed information about management status. For new devices, the integration can add them to your asset inventory. Through the integration, you can track your Google Workspace-managed devices in the same unified view as other assets in Device Security .

Device Security queries Google Workspace to pull a rich set of attributes for each enrolled device, including management information such as enrollment status, assigned user, organizational unit (OU) path, and security configuration details. For mobile devices, the integration can also include installed application data. These details enrich your asset inventory by providing information that Device Security can't discover through network traffic alone.

With Google Workspace-managed devices reflected in Device Security, you can identify unmanaged or out-of-compliance devices, enforce policies based on enrollment status or OU membership, and maintain an accurate asset inventory across Chromebooks and mobile devices alongside other devices in your network.

Device Security Integration with Jamf School

Release Date: September 2026 | Last Updated: October 2026

You can integrate Device Security with Jamf School to import managed Apple devices. Education environments often include large numbers of devices managed through Jamf School. The endpoint management status can't easily be discovered through network-based monitoring. Integrating Device Security with Jamf School gives your security team visibility into those device attributes and MDM security posture that network traffic alone can't identify.

When you integrate with Jamf School, Device Security ingests device details such as model, hostname, OS, and serial number, along with MDM security attributes such as managed and supervised status, passcode compliance, and hardware encryption. You can also import information about installed applications for each managed device and location data.

Bring your Jamf School inventory into Device Security to give your security team a more complete view of every managed Apple endpoint. A consolidated view of managed education devices alongside other assets in your network helps improve risk scoring and policy decisions without needing to manually cross-reference your MDM console.

Device Security Integration with Mindray Device Management

Release Date: September 2026 | Last Updated: October 2026

You can integrate Device Security with Mindray Device Management to pull the device inventory from Mindray, giving you accurate device profiles for medical equipment where encrypted traffic prevents passive network inspection. With the enriched asset inventory, you can monitor your medical devices more effectively, including identifying vulnerabilities or setting alerts for behavior specific to your healthcare environment.

The integration imports device attributes for Mindray medical devices, such as patient monitors, ultrasound systems, in-vitro diagnostic equipment, and ventilators. Device Security syncs this information with your asset inventory to better identify existing devices, as well as adding new devices to your inventory for security monitoring.

Mindray medical devices use proprietary encrypted protocols that Device Security cannot passively inspect, leaving these devices unclassified or only partially identified in your inventory. Importing attributes directly from the Mindray management platform fills that gap and helps differentiate medical devices from other assets on your network, so your medical device inventory in Device Security remains complete, accurate, and secure.

Matched Security Policy Rules for Devices in Device Security

Release Date: September 2026 | Last Updated: October 2026

When you have telemetry enabled on your firewalls, you can now see which firewall security rules actively matched traffic for a device from the device's Device Detail page. Device Security displays the matched security policy rules in the AssetsDevice DetailBehaviorsObserved Security Policy Rules table. Check the table to verify whether device traffic is governed by targeted policies with security profiles or permissive generic rules, without having to query each firewall separately.

The table displays each matching rule's context, including rule name, source and destination, applications, security profiles, and the last time the rule was hit. You can filter results by rule name or firewall hostname, to inspect the rules that the device's traffic matched. When a device's traffic passes through multiple firewalls, the table shows which firewall reported each rule hit.

This visibility lets you confirm that virtual patching and segmentation policies match the intended devices. You can also check if traffic falls through to overly permissive rules during a security review or vulnerability investigation.

Network Discovery Plugin 2.4.x and 3.2.x

Release Date: September 2026 | Last Updated: September 2026

( September 2026 ) The Network Discovery plugin version 3.2.2 addresses two issues. See Known Issues in Network Discovery 3.2 for a full list of addressed issues.

There are no equivalent updates to the Network Discovery version 2.4.x branch currently.

( September 2026 ) The Network Discovery plugin version 3.2.1 adds support for PA-1500 series firewalls (PA-1510, PA-1520, and PA-1530), expanding the range of hardware on which you can run network discovery. It also addresses two issues: WinRM OT polling jobs failed when the OT polling configuration was pushed from Panorama, and Network Discovery jobs continued to run after being explicitly disabled. See Known Issues in Network Discovery 3.2 for a full list of addressed issues.

There are no equivalent updates to the Network Discovery version 2.4.x branch currently.

( July 2026 ) The Network Discovery plugin version 2.4.0 and Network Discovery plugin version 3.2.0 add expanded polling protocol support and on-demand troubleshooting CLI commands so you can discover a broader range of devices on your network and investigate plugin issues more in-depth before escalating.

SNMPv3 polling now supports the SHA-224, SHA-256, SHA-384, and SHA-512 authentication protocols and the AES-192, AES-256, and 3DES privacy protocols, so you can align polling with stricter cryptographic standards. OT polling adds support for Beckhoff (UDP), Siemens Webserver, Codesys (TCP), and GE Carescape patient monitors, so you can discover a broader range of industrial and medical devices on your network.

The new CLI commands let you selectively enable verbose logging by component, list operational files so they are captured in the Technical Support File (TSF), run a diagnostic playbook against a specific IP address, test SNMP and OT polling queries, and check the health of the asset polling, neighbor discovery, and data refreshment daemons.