sapio365 4.2.2
July 22 2026
What’s new in version 4.2.2
- Fixed a regression where PowerShell‑based features did not work in newly installed sapio365 version 4.2.1 because Microsoft reverted a recent change for which we previously adjusted sapio365. Now sapio365 PowerShell‑based features like loading ‘Mailbox Info’ work properly.
- Fixed an issue in ‘Privileged Identity (PIM)’ where application‑scoped roles were wrongly shown as directory‑scoped.
- Improved message rules with more reliable data because they are now queried with PowerShell instead of the Microsoft Graph API, which previously returned incomplete data.
- Improved access to sapio365 collaboration data and settings by moving the buttons from the ‘About sapio365’ section into a new ‘Collaboration Settings’ area in the backstage of the main sapio365 window, making them easier to find and manage.
- Improved the ‘Registered Applications’ module by making most ID columns technical so they are hidden by default in the ‘Data Viewer’, making it easier to read attributes.
- Clarified some text in the ‘Quick Lookup from cache’ query and results dialogs.
- Improved the behavior of the ‘Value Filter’ by disabling ‘Apply’ when ‘Clear and Close’ is being processed, to prevent the user from reapplying the filter and prolonging the process for nothing.
- Fixed an issue where the ‘Cosmos DB configuration’ dialog could not be closed.
- Fixed an issue where a long tenant name caused problems in setting up collaboration on SQL Server because some identifier names in the tables were too long.
- Fixed a regression where, when loading events for a ‘Calendar View’, it was not possible to set a date older than today.
sapio365 4.2.1
July 15 2026
What’s new in version 4.2.1
- Improved the Roles and administrators view by allowing it to be enriched with cached user and group properties.
- Improved the Dashboard by splitting the Tenant entries into two sections: Tenant Management and Reports.
- Improved collaboration settings management by moving these settings to a new dedicated panel in the backstage of the main sapio365 window.
- Improved the session information panel in the Dashboard by showing whether sapio365 is using a local or shared cache. Previously, it only indicated shared cache usage.
- Fixed an issue in Message Trace where loading details for a message sent to or received by a specific mailbox could sometimes load the wrong mailbox because the email address was incorrectly cross-referenced with non-email properties.
- Fixed a regression in the Groups module where it was not possible to archive a Team or edit Team settings because the dialog did not display the Team Archiving and Team Settings sections.
- Fixed a regression where Usage Reports did not display system views other than Ytria default.
- Fixed an issue in the Groups module where loading channels on non-Team groups was not skipped. These groups are now skipped correctly, improving efficiency.
sapio365 4.2
July 2 2026
What’s new in the latest version?
IMPORTANT – Updating sapio365 may impact how you use sapio365!
Learn more about updating sapio365.
This version of sapio365 uses a new application and new permissions, which are required to access Message Trace and Viva Engage data and are not available in National Cloud Deployment environments such as GCC High.
For full functionality, a one-time Global Admin consent must be granted to the enterprise application “Ytria sapio365 – with Admin Consent (3.4)”. If a Global Admin is not available to grant consent, sapio365 will fall back to the previous version. Admin consent is also required when connecting to any additional tenants via Partner Access.
ExchangeMessageTrace.Read.All
Community.ReadWrite.All
Using Collaboration?
If you use the Collaboration feature in sapio365, make sure that a Global Admin or a sapio365 General Manager upgrades first. Until one of them completes the upgrade, collaboration sync will be paused.
New features
- Added a Message Trace module to the Tenant section of the Dashboard to list messages and their delivery status, and to retrieve detailed information for selected messages.
- Added a Search Query option when loading users’ mailbox messages. This returns all messages that match the entered query, based on the email properties available to eDiscovery search in the Microsoft Purview portal.
- Added the ability to load custom directory extension attributes in the Users and Group modules.
- Added the ability to choose drives when loading files for a single site or OneDrive. When loading files for multiple sites or users’ OneDrive, the options to load the default drive or all drives remain available. If you load the entire file and folder hierarchy, sapio365 now uses a faster delta-based grid refresh, although sensitivity label information is not returned with this option.
- Reworked the loading of file permissions to make it more efficient, adding options to exclude root permissions (Members, Visitors, etc.) and filters for sharing type (links, direct access), role (can view, edit, etc.), and who it’s been shared with (target type and name).
- Added some computed file permission columns to identify the sharing target’s type and domain to assess internal vs external sharing.
- Added the ability to delete service principals.
- Added a Last Sign-in column in Service Principals, whose values can be loaded using the button of the same name.
- Added a preference option ‘Enable On-premises for cloud-only tenants.’ to allow adding on-premises Domain Connections in cloud-only tenant sessions. Previously, this was only available for hybrid tenants.
- Added the ability to deactivate or activate registered applications.
- Added property columns ‘Application Display name – Created By’ and ‘Application ID – Created By’ in modules Registered Applications and Service Principals.
- Added the ability to load subsites of SharePoint Online sites in elevated, app, and role sessions, which was previously not available in those sessions. You can choose to load the full subsite hierarchy or only the first level.
- Added a Quick Lookup for Registered Application since the data is now cached.
- Added the ability to filter based on selected rows via the value filter.
Users
- Added a Microsoft Azure portal URL column that opens the selected user directly in the Microsoft Azure portal in the default browser.
- Improved view with the addition of the user property ‘Authentication Info :: Last Used On’.
- Improved the loading time of users’ licenses by skipping users with no assigned licenses.
- Improved updating users’ on-premises manager from a file by allowing the manager’s user principal name as input, in addition to the distinguished name or ID.
- Also fixed an issue where manager changes from file updates were not previewed in the ‘Manager (Friendly)’ column, which now correctly shows the new values when applied to the grid.
Groups
- Added a Microsoft Azure portal URL column that opens the selected group directly in the Microsoft Azure portal in the default browser.
- Improved identification of groups associated with Viva Engage communities by adding a dedicated Viva Engage button in the Load section of the ribbon, which retrieves Viva Engage data for all groups. This replaces the previous selection-based Viva Engage info option from Additional Info.
- Fixed the Group Members module so devices are now shown as nested group members.
- Fixed an issue where editing the group properties ‘allowExternalSenders’ and ‘autoSubscribeNewMembers’ in elevated and role sessions resulted in errors.
- Fixed an issue in on-premises users’ group memberships where adding a member to a group loaded the full directory from cache in the dialog instead of showing only what was already in the grid. Adding members now uses the current grid content without triggering an unnecessary full directory load.
Miscellaneous general fixes and improvements
- Improved new user experience by adding Data Viewer and Views/Jobs identification text on the grid’s side panel bands when they are closed.
- Reorganized the Views/Jobs panel by moving description below title and hiding details.
- Improved handling of file permissions that contain several multivalue levels so they now correctly show who a file is shared with. Previously, only the first level was exploded.
- Improved the behaviour of the value filter dialog for large sets of values by showing a spinner and a running count before loading the full list. Previously, it displayed an empty list and appeared frozen while values were being retrieved.
- Improved the time to apply Comments to large volumes of rows. It’s now much faster.
- Improved Comments so that the eye icon now evaluates formulas for the first selected row rather than the first row in the grid.
- Improved multivalue management with the addition of buttons View Multivalue and Index Count in the ribbon’s Explode Cells’ section. Previously the View Multivalue feature was only available from the right-click menu while the Index Count button lets you toggle the count display of unexploded cells.
- Improved working with multivalues by making ‘View Multivalue’ available when an exploded multivalue row is selected. This is especially helpful when other exploded values are hidden by filtering or grouping, since it lets you see the full set of multivalues in the mini-grid at any time.
- Improved copying and exporting of raw values for cells with nested multivalues, which previously showed only a count instead of the actual values.
- Improved sapio365 RBAC role configuration by adding an option to grant full-scope access without assigning scopes when the ‘Treat any unassigned scope type as No Access’ setting is left unchecked.
- Improved the Registered Applications view by adding a column that shows the name of the permission API corresponding to each permission API ID.
- Improved running Summary Reports with the addition of a cancellation option.
- Improved how date range options are displayed when loading data by standardizing their order (month, day, hour) across sapio365.
- Improved deleting a single email attachment from an exploded multivalue so remaining exploded attachments stay as separate rows after saving. This applies to email, calendar event, and group post attachments.
- Improved managing the effective last query date display when data is loaded from cache by turning the ‘Effective last query date for each object is available’ banner button into a ‘Show/Hide column’ toggle, making it easier to hide or show that column in the grid.
- Clarified the ‘Extra info from cache’ tooltip in Usage Reports to specify that the extra properties are for the user, group, site, or service principal.
- Improvement the behaviour of temporary Column Comments saved in a view by showing them only in that view. Switching to another view now removes them.
- Improved uncommon cases where a blank grid was shown after certain actions because the grid failed to rebuild. Clicking F5 will rebuild the grid.
- Removed certain URL columns in the Service Principals module as these are always empty.
- Improved views in Files and OneDrive Files by removing empty columns ‘Shared on’ and ‘Shared by’.
- Improved overall stability resulting in less random crashes.
- Removed the site description column from the directory selection grid when copying files to a site.
- Fixed a refresh issue after editing a registered application.
- Fixed an issue where turning off the ‘Show empty’ option in hierarchies now hides all empty levels, showing only the hierarchy for visible files. Previously, the full folder hierarchy was displayed even when no files were visible.
- Fixed a grid Comment issue where the comment value was duplicated in the tooltip when it used a reference column. Tooltips now show the comment only once.
- Fixed the cause of a PowerShell error that occurred when running a custom job or the job ‘Execute a PowerShell command’ with a sapio365 RBAC role, even when the permissions ‘Run custom job’ and ‘Run PowerShell Command job’ were correctly set. These jobs now run as expected when the role has the appropriate permissions.
- Fixed an issue that prevented disabling On-Prem when no valid Domain Connection was configured.
- Fixed a refresh issue in filtered cached views where saving an update reloaded the entire cache instead of only the loaded entries, so saves are now faster and more efficient.
- Fixed an issue where transferring sapio365 data to another machine without the last sync collaboration data (when collaboration was enabled) caused sapio365 to freeze during import. This data is now included so imports complete without hanging.
- Fixed an issue where system columns and the vertical scroll bar could disappear in various scenarios when working with multivalues.
- Fixed an issue in Registered Applications where applying a view that includes owner columns did not trigger the additional data load as expected.
- Fixed an issue in Service Principals where refreshing did not write changes to the cache, so opening a new module could show outdated data.
- Fixed the ‘Homepage’ column so it now appears as a hyperlink in Service Principals.
- Fixed an issue where deleting a comment column included in a saved view and used in a calculation caused the computed value to be wrong when the view was reapplied.
- Fixed issue causing crash when closing a window during refresh.
- Fixed an issue where collapsing the RBAC role Permissions section cleared previously selected permissions.
- Fixed an issue where the on-prem domain connection did not accept usernames with spaces.
- Fixed the Registered Applications view by splitting the ‘Request Signature Verification’ column value into its two components: ‘Is Signed Request Required – Request Signature Verification’ and ‘Allowed Weak Algorithms – Request Signature Verification’.
- Fixed a job scheduling issue where sapio365 could hang if an error was caught but the job could not complete because PowerShell access was unavailable. Jobs in this situation now fail gracefully instead of causing the application to hang.
- Fixed an issue where a job scheduled to run monthly on the ‘last day’ did not execute. Jobs using this schedule now run correctly on the last day of each month.
- Fixed missing entry points ‘Personal Sites’ and ‘On-Premises Users/Groups’ so they are now shown even when Dashboard counts are not loaded.
- Fixed an issue where files and folders that had a deletion applied in the grid could not be renamed instead. You can now rename items even if they were previously flagged for deletion.
- Fixed an issue where a file’s multivalue permission opened in the Multivalue Viewer grid showed some columns with only the Open icon and no URL value. These columns now correctly display both the icon and the underlying URL.
- Fixed an issue where a silent error occurred when loading some PowerShell‑based data (user and group Mailbox info, Distribution Group additional info, Delivery Management, etc.), which caused related properties to appear empty in the grid. These properties now load correctly and display their values as expected.
- Fixed an issue where sapio365 appeared frozen after deleting a large number of items in a module (except Users and Groups). The freeze occurred after saving but before the grid refreshed, and the product now remains responsive during this process.
- Fixed a Dashboard issue where the Group count was not calculated or opening a module showed an empty grid when using MySQL or MariaDB for storing the cache.
- Fixed an issue in Summary Reports where dates were missing because they were not read from the MySQL or MariaDB cache.
- Fixed an issue in the Registered Applications module where the ‘Role Allowed member types’ column multivalue could not be exploded because it contained a nested multivalue.
Automation
- Added new automation tags and fixed various automation issues, listed in our help documentation: https://docs.ytria.com/automation/sapio365-latest-automation-additions.
sapio365 4.1.1
April 20 2026
Miscellaneous general fixes and improvements
- Improved access to Visio and Project activity reports’ data in sapio365 by making it easier to grant the Reports Reader role to the sapio365 app for elevated, app, and role sessions. You can now add this role directly in the app’s configuration section.
- Improved sapio365 for large environments by making Dashboard count loading optional, since slow count retrieval could interfere with other sapio365 tasks. You can turn this off in the Preferences section.
- Improved the User RBAC Scopes list by removing the non-functional scope ‘Organizational Unit (calculated)’.
- Improved the copy feature by standardizing the clipboard format. Previously, whether text was copied as raw or formatted depended on selecting cells in a column or entire rows, which was confusing. Now, clipboard text matches what you see in the grid (except for hyperlinks and rich text), so pasted values are predictable and consistent.
- Fixed the new Visio Activity and Project Activity usage reports so they correctly handle pagination, preventing partial results. Also updated the reports to show columns with 0 or empty values when there is no data, instead of displaying “no data.”
- Fixed an issue where the new Visio Activity and Project Activity usage reports did not work when using cross-tenant role sessions or Partner sessions.
- Fixed an issue in the Registered Applications module where saving a Display name change did not show the usual ‘Changes saved’ message or green cell highlight when Additional Info was already loaded for that application.
- Fixed the cause of a PowerShell error that occurred when more than one sapio365 session was active, where PowerShell requests from different sessions could become mixed up.
- Fixed a crash that occurred when applying the ‘X days ago’ date format to dates beyond the year 2038, which relates to how some systems handle dates after 19 January 2038.
- Fixed an issue where closing a module before Dashboard counts finished loading could leave sapio365 stuck in a ‘forever loading’ state.
- Fixed an issue in Freeze Points where, after deleting all rows, the grid appeared completely blank instead of refreshing to show the empty columns.
- Fixed a crash that could occur when closing the Users, Groups, Sites, or Service Principals modules while they were still loading.
- Fixed an issue in the Data Viewer where, when you expanded or collapsed sections, it kept scrolling back to the field of the column that was in focus.
- Fixed a crash that could occur in the Quick GridView.
- Fixed an issue where sapio365 license verification could loop endlessly during registration when some network communications were blocked, and it now times out so you can retry or adjust your settings.
- Fixed an issue where the Regex history (for example, in Regex filters) could not be loaded and therefore was not available.
- Fixed an issue where, after updating the signed-in user’s username in sapio365 and then reloading that session, sapio365 could get stuck on the “loading session” spinner and never finish.
sapio365 4.1.0
April 6 2026
What’s new in the latest version?
New features
- Significantly improved overall grid processing time, from data retrieval to applying filters and other configuration changes, making the grid much faster and more responsive.
- Added a ‘Quick Lookup from cache’ option in the Dashboard to quickly search cached Users, Groups, Sites, and Service Principals.
- Added counts to the Dashboard to show the number of on-premises user accounts and groups in hybrid Active Directory environments.
- Added Visio Activity and Project Activity to Usage Reports, which can now be combined or enriched with cached user properties like other user-based reports.
- Added the ability to turn the Welcome Message setting on or off for selected Microsoft 365 groups and Teams, which controls whether new members automatically receive a customized welcome message.
- Redesigned the license editing dialog for a more modern look and easier use.
- Optimized the retrieval, display, and update of user license assignments, resulting in a lighter grid where service plans are shown only for assigned licenses, greatly reducing grid processing time.
- Added new mailbox statistics properties in the Users and Groups modules. These are retrieved via Mailbox Info and include Total Item Size, Total Deleted Item Size, Item Count, Deleted Item Count, and Last Interaction Time.
- Added the ability to set the retention policy of selected users’ mailboxes.
- Added a new Permission Type (Friendly) column in the Registered Applications module to indicate whether a permission is Delegated or Application.
- Added new columns ‘Key – Additional targets’ and ‘Value – Additional targets’, and improved data loading in the Admin Audit Logs module.
- Added new Service Provisioning Errors columns to the grid for assigned licenses in Users and Groups modules.
- Added the ‘Load All’ button and the ability to add Users, Groups, and Service Principals from the cache or remove them from the grid in their respective Details submodules.
Users
- Improved User Licenses submodule by adding a column Oldest Plan Assigned date to indicate when each license was assigned.
- Improved the OneDrive submodules by displaying aggregate File Count, Folder Count, and Size for each user.
- Improved handling of Microsoft errors when retrieving messages from Recoverable Items folders that previously caused failed request loops. You can now skip the problematic query in the retry dialog and continue retrieving other valid results.
- Improved the edition dialog to indicate when fields cannot be edited because the current selection includes an incompatible user.
- Fixed an issue where edited mailbox properties were not correctly escaped in the generated PowerShell request.
- Fixed an issue where saving on-premises changes for an exploded user account did not work.
- Fixed issues in the Users Details module where a yellow saved state was returned and where Refresh was not handled correctly.
Groups
- Improved the Files submodules by displaying aggregate File Count, Folder Count, and Size for each group, channel or site.
- Improved edition of security groups by hiding the irrelevant section ‘Mail Config’.
- Improved the edition dialog to indicate when fields cannot be edited because the current selection includes an incompatible group.
- Fixed an issue in the Groups grid where applying changes caused the previously loaded Viva Engage value to disappear.
- Fixed issues in the Groups Details module where a yellow saved state was returned and where Refresh was not handled correctly.
Miscellaneous general fixes and improvements
- Improved the Data Viewer by always displaying the list of property columns, even when no grid item is selected, and added a toggle to show fields in either a compact or more spaced-out (normal) layout.
- Improved loading time for Dashboard Apply Filter options for Users, Groups, Sites, and Service Principals by leveraging the cache.
- Improved the dialogs for the ‘Reinitialize’ and ‘Reload’ refresh options and added information about the duration of the previous refresh.
- Improved the Export dialog to show how many rows are selected for export and removed the default selection of ‘Selected rows only’ and ‘Include locked technical columns’.
- Improved how currency symbols are managed in the grid so that when the symbol of a column changes, all referencing columns, including Comments, display the updated symbol.
- Improved the grid processing progress bar styling and added a display of the number of grid rows being processed.
- Improved grid processing time when loading a large Snapshot or Freeze Point.
- Improved on-prem settings for multiple domains by adding a button to reorder connections, with the last connection in the list taking precedence for any overlapping information.
- Improved various message boxes and dialogs by updating them to a more modern, HTML-based design.
- Improved grids in the Sites and Groups modules by consolidating document library quota properties into single-value columns for sites and groups with multiple libraries, since these quotas represent the overall site.
- Improved the use of Snapshots, which can now be loaded without an active sapio365 session as long as there is an activated sapio365 license.
- Improved the password auto-renewal option in the sapio365 RBAC credential creation dialog by adding a 45-day frequency choice and clarifying that sapio365 automatically renews the application client secret at the selected frequency, setting the new secret’s expiration date to twice that interval.
- Improved PowerShell-based functionality by ensuring that PowerShell no longer loads outdated versions of the ExchangeOnlineManagement module.
- Improved the ‘Add Data from file’ feature in general and with the addition of options in the dialog to skip rows, include headers, and information about any merged rows in the imported file.
- Fixed an issue where importing data from Excel into the grid using ‘Add data from file’ incorrectly converted numbers into dates.
- Improved grid display with a ‘Show Grid Entry Viewer’ option that hides the Data Viewer area to maximize grid space, accessible from the right-click menu under Grid Tools & Options – Grid Options.
- Improved dialogs for exploding and unexploding multivalue cells with clearer text.
- Improved the alternate sapio365 license activation process with clearer text and links to the help page in dialogs. Added a warning dialog when enabling the Alternate sapio365 license activation option in Preferences, plus an indicator in the About sapio365 section showing if reactivation is needed via the Refresh Offline Access button.
- Improved the Sites module for elevated, app, and role sessions so that previously empty Description and Last Modified Date properties can now be retrieved using the ‘Load Info’ button.
- Improved the RBAC scope configuration dialog with a smaller scroll window for the scoped property and now require users to explicitly choose a property instead of preselecting the first one by default.
- Improved first-time user session setup by adding an option to copy a link that can be sent to a global admin to obtain consent for the application.
- Fixed a regression where value filter entries starting with capital letters were listed in the value filter dialog before being sorted alphabetically.
- Fixed an issue where applying a view that includes on-prem columns prompted the user to ‘Load on-premises info for this view?’ even when on-prem configuration was not enabled.
- Fixed Future Cutoff-Date/Time criteria when applying a Conditional Format on a column.
- Fixed the behavior of the column with ‘Freeze up to’ applied where increasing its width or resizing the window could make the column unmanageable.
- Fixed an issue with scheduled tasks and reports when Windows was configured to hide known file extensions, which caused the scheduled task path to miss the .exe extension.
- Fixed the ‘Reinitialize’ feature in Service Principals, which was not working.
- Fixed an issue causing mismatched column titles for ‘Transferred columns’, which enrich the Users and Groups submodules as well as Usage reports.
- Fixed an issue where changing the sapio365 license capacity multiple times showed an incorrect preview of increased capacity costs unless sapio365 was restarted.
- Fixed an issue where hierarchy count columns were not correctly updated when hiding children.
- Fixed an issue where, when several columns of the same column family were grouped, ungrouping one column incorrectly displayed the ‘Confirm unexplode’ dialog.
- Fixed an issue with alternate sapio365 license activation where canceling Refresh license exited the application instead of falling back to Lite mode.
- Fixed an issue where the multivalue status was not refreshed when an entry’s multivalue property was updated with an additional value.
- Fixed an issue where Conditional Format was not applied to non-text multivalues, such as unexploded date and number multivalues.
- Fixed issue where deleting a Comment that had been exploded into multiple rows now correctly removes all associated exploded rows from the grid.
- Fixed an issue where exploding another multivalue column in a view that already had a first multivalue exploded resulted in duplicate rows.
- Fixed an issue where canceling the explosion of a new multivalue, when another multivalue was already exploded in the grid, caused the cancel button not to work.
- Fixed a crash that occurred when cancelling a multivalue explosion and when deleting an entry while it was expanded across multiple rows.
- Fixed issue where it was not possible to edit a Column comment that was in a saved View.
- Fixed an issue where multivalue comments that were part of a column family could not be removed.
- Fixed an issue where the grid did not display the comment value for an exploded multivalue Column Comment while the Comment edit dialog was open to update that comment.
- Fixed an issue where changes to a multivalue comment were not reflected in the grid while it was exploded.
- Fixed an issue where multivalue comments were not exploded when a view saved with exploded comments was applied, requiring the view to be reapplied to explode the comments.
- Fixed an issue where applying a view that requires loading on-prem data resulted in incorrect grid category headers.
- Fixed an issue where sapio365 could freeze if a recent Partner session failed to load.
- Fixed sapio365 RBAC scopes by removing non-functional scope properties such as dates, booleans, and multivalues.
- Fixed issue where a user with a sapio365 RBAC role was not able to enable ‘Load On-Premises’ functionality for their session.
- Fixed issue where a user with only one assigned sapio365 RBAC role was not able to remove the role to go back to a regular user session.
- Fixed a regression in the Service Principals module where loading Custom Security Attributes for a Service Principal with no results failed to display an empty grey cell.
- Fixed an issue where canceling an automatic job triggered a cancel progress dialog in an open sapio365 module (Freeze Point), which previously required closing the module to clear.
- Fixed a crash that occurred when sapio365 was throttled while copying files to another drive.
- Fixed a crash that occurred when performing a ‘Starts with…’ quick search in a grid with no visible rows.
- Fixed a regression that caused a crash when loading Admin Audit Logs.
- Fixed a regression affecting RBAC roles created before version 4.0 that caused a sync error with the message ‘Unable to store record, missing value, no default for DelegationPrivileges’.
- Fixed a regression that caused sapio365 to freeze when the connection to MariaDB could not be established.
- Fixed issue causing the error ‘Error while deleting tables’ when purging MariaDB and MySQL server databases.
- Fixed a shared cache issue on MariaDB and MySQL server databases that caused errors when certain unicode characters like emojis were not handled properly.
- Fixed the cause of the error ‘An error occurred with the data storage SQL ERROR’ when loading a session.
sapio365 4.0.2
January 12 2026
Miscellaneous general fixes and improvements
IMPORTANT – We’ve made some important updates to how sapio365 connects to your on-premises Active Directory environment.
In version 4.0, sapio365 briefly used Invoke-Command to call Get-ADDomainController for Active Directory (AD) connections. This required extra permissions that some users didn’t have. We’ve now reverted to using Active Directory Web Services (ADWS) for on-premises data access. This change means you no longer need additional permissions to connect to AD.
The only feature that still uses Invoke-Command is Force Sync, just as before.
New features and improvements
- Added support for editing user and group on-premises attributes extensionAttribute1 through extensionAttribute15 in each module’s edition dialog.
- Added the ability to load additional files and folders for selected folders, with an option to load only first-level items.
- Added MySQL as a supported SQL database option for storing collaboration data and shared cache.
- Added an alternate activation option for new sapio365 licenses when online activation is unavailable.
- Improved Files modules by adding a Direct child count column to show the number of direct items in a folder.
- Improved Files modules by replacing the separate Total Size and File Size columns with a single column to align with Graph API changes and avoid incorrect calculated values.
- Improved Summary Reports by adding a consolidated view of all saved summary report snapshots, independent of the current selection.
- Improved querying of Admin Audit Logs with new filter options and removed nonfunctional filters.
- Improved comment management by displaying the title of the column referenced by each comment in the Comment History grid.
Miscellaneous general fixes
- Fixed a regression where the value for ‘User ID – Initiated by’ was not displayed in Admin Audit Logs.
- Fixed a regression where a Past/Future CutOff Date/Time filter saved in a View was not applied in a Freeze Point.
- Fixed a regression where sapio365 froze when the connection to MariaDB could not be established.
- Fixed a regression that prevented creating a password-protected Freeze Point.
- Fixed a regression where some information was not displayed at the bottom of the About sapio365 section.
sapio365 4.0.1
December 16 2025
Miscellaneous general fixes and improvements
- Improved Admin Audit Logs by adding more filter options and removing nonfunctional ones.
- Improved getting users’ chats by handle paginated results.
- Improved MariaDB text columns by making them accent-sensitive.
- Improved the Users, Groups, and Service Principals by adding a Last Updated column that shows when entry data was last retrieved from the server, whether via Additional Info loading or Refresh (delta).
- Fixed an inconsistency in on-prem domain connection status that caused Freeze Points and Snapshots to incorrectly show no domain connection during login.
- Fixed an issue where on-prem columns were not displayed in the grid after applying a View that included and loaded them.
- Fixed missing icon for transferred ‘Sign-in status’ user property column in Chats.
- Fixed regression in Messages where editing an email was disabled.
- Fixed regression which resulted in the inability to edit or create a sapio365 RBAC role.
- Fixed the default SQL Server port number used when configuring the MariaDB connection for shared cache in RBAC credentials.
sapio365 4.0
December 11 2025
What’s new in the latest version?
IMPORTANT – Updates to sapio365 sessions may impact how you use sapio365!
Learn more about updating sapio365.
- We’ve created a new enterprise application to handle new permissions required for PIM management. So, for full functionality, a Global Admin will need to provide one-time Global Admin consent to the enterprise application ‘Ytria sapio365 – with Admin Consent (3.3)’. If a Global Admin is not available to give consent, sapio365 will fall back to the previous version. This must also be provided when connecting with any additional tenants via Partner Access.
Using Collaboration?
- If you are using the Collaboration feature of sapio365, be sure that a Global Admin, or a sapio365 General Manager role holder does their upgrade first. Otherwise, collaboration sync will pause until this is performed.
New features
- Added the ability to connect a sapio365 session to multiple on-premises Domain Connections to retrieve and manage their data.
- Added ability to activate and deactivate eligible Privileged Identity (PIM) roles directly in sapio365.
- Added option for certificate-based sessions which enables the use of sapio365 features requiring Exchange PowerShell without prompting the user to sign-in. This also allows you to schedule automations using these features in elevated sessions, app sessions and RBAC credentials.
- Refreshed the design and enhanced the functionality of the Data Viewer and major dialogs (sessions, filters, RBAC, comments, etc).
- Added the ability to apply column filters, sorting, formatting and more directly from the Data Viewer, plus a new section that clearly displays which filters are currently applied in the view.
- Added MFA to the sapio365 application Master password for enhanced security.
- Added ‘China operated by 21Vianet’ to the list of supported cloud deployments, alongside GCC High and DoD. This option requires a special license.
- Added MariaDB as a storage option for collaboration data and shared cache, with the shared cache also able to reside in any custom local folder.
- Added the ability to list instances of recurrent calendar events.
- Added the Microsoft 365 Copilot User Count Trend usage report.
Users
- Added the ability to edit the list of sponsors for selected guests.
- Improved updating cloud user accounts from a file by adding basic properties ‘Preferred Data Location’, ‘Age Group’ and ‘Consent Provided For Minor’ to the fields list.
- Improved on-premises user editing which now lets you clear any existing Account Expiration Date.
- Improved updating users’ manager on-premises by moving this feature from the edition dialog to the ribbon button ‘Set Manager’.
- Removed ‘Sign-ins’ option from Load additional Info since this information is handled more effectively by the ‘Last Sign-in’ (for all users) feature.
- Fixed cache refresh issue where some users were shown as User (partial data) Object Type and enabled ‘Load Additional’ info on them if needed.
- Fixed issue where ‘Authentication Methods Overview’ data was partially missing in the grid if loaded without ‘Authentication Methods Details’.
- Fixed issue where ‘Authentication Methods Overview’ data was partially lost when loading another set of additional info data or when making an unrelated change.
- Fixed issue where during the creation of a user on-premises using a template, changing the set OU was not saved.
- Fixed refresh issue where saving an applied ‘Revoke Session Tokens’ action resulted in a lingering ‘…revoke pending…’ status.
- Fixed ‘Set Manager’ dialog which was missing the list of users that were selected.
- Fixed issue where editing users was not functioning when combining multi-value explosion and filtering.
- Improved MFA authentication information by adding grid property columns specific to the QR code authentication method type.
- Removed deprecated ‘User Info :: Refresh tokens, session cookies valid from’ column.
Groups
- Added the ability to retrieve and manage authorized mail senders for distribution lists and mail-enabled security groups with the ‘Delivery Management’ button and submodule.
- Added ‘Channel Count’ to the list of Additional Info loading options to retrieve the number of channels (All, Internal and External) for selected Teams.
- Added the ability to update the list of email aliases of Microsoft 365 groups.
- Improved Group Members submodule by retrieving devices that are members of the groups.
- Improved M365 group creation with behaviour options including disabling a welcome email to new members.
- Improved data loading process by disabling irrelevant features and buttons for non-M365 groups.
- Improved group creation dialog with a ‘Mandatory Information’ category.
- Improved group submodules with the addition of a calculated column ‘Organization Unit’ wherever there is a ‘Distinguished Name’ property available.
- Improved on-prem group members submodule with the addition of the ‘Enabled’ property for group members.
- Added the ability to directly add missing members resulting from a comparator analysis with the ‘Add to’ function.
- Fixed issue importing groups on-premises where the designated OU was not saved.
- Fixed cause of row duplication when saving the addition of members or owners in the Group members module.
- Fixed issue where creating a group always prefills the ‘Security Enabled’ property as unset regardless of the selected template group.
- Fixed issue where some members of synced groups were displayed with ‘cloud’ sync status in the Group Members submodule.
- Fixed issue where during the creation of a M365 group, the owner that is set in the dialog is not added to the group.
- Fixed issue where during the creation of a group on-premises using a template, changing the set OU was not saved.
Miscellaneous general fixes and improvements
- Changed Exchange PowerShell minimum requirement to 3.9.
- Added the ability to apply conditional colour formatting on a column for values that meet a set criteria.
- Improved Audit Logs report with new filters and removed nonfunctional filter options.
- Improved grid Comments dialog in general, and you can now add column titles and comment titles during creation, as well as reuse previous values when creating new comments.
- Improved Comment management by letting you delete comments at all levels directly from the grid, which removes the entire comment column when cleared.
- Improved Files submodules with the option to load only first-level files.
- Improved ‘Copy To’ feature in Files submodules with the option to include version history.
- Improved the values filter with the option to view visible rows only.
- Improved the Graph API Usage report with properties from Service Principals as ‘Extra Info from cache’, enriching the report and helping identify applications.
- Improved sapio365 RBAC credentials configuration with an option to omit the use of a service account.
- Improved management of RBAC credentials with an option to change the password renewal frequency.
- Improved collaboration options ‘See current SQL Server database information’ and ‘Force a resynchronization’ by making them available without a subscription code.
- Improved Devices module with the addition of two URL columns ‘Intune URL’ and ‘Microsoft Azure portal URL’.
- Improved Restore Points and Snapshots by disabling non-functional features to create or save a view.
- Improved column settings with option to always auto-explode muti-values.
- Improved the Dashboard by enabling to run Scheduled Tasks directly from there.
- Improved Data Viewer on the right side with 2 copy-to-clipboard shortcuts: Ctrl + Click will copy the value and Alt + Click will copy the column ID.
- Improved messages when loading views that require loading of on-premises information.
- Renamed Business Reports as Summary Reports.
- Improved managing permissions in Files modules and deleting attachments in Messages and Events modules with the addition of specific ‘Status’ column values. Edits or deletions applied to a specific type of object are now clearer.
- Improved handling of license unit cost rights by non-admins without collaboration. Non-admins were previously not able to set a unit cost in the Licenses and service plans module.
- Improved Snapshot and offline Freeze Point session by disabling the buttons for the creation or update of views.
- Improved loading owners in Registered Applications module by handling app owners that are service principals.
- Improved the ‘Copilot Activity Overview’ Summary Report with text clarification.
- Improved ‘Load Status – Attachment Info last queried’ to show date and time in Events, Messages, and Group Conversation Posts.
- Improved RBAC configuration with new scopes, and all scopes are now listed alphabetically for easier navigation.
- Fixed an RBAC issue where renaming a multi-credential role did not update the delegated user’s session name to match the new credential name.
- Fixed issue where sessions using certificate-based authentication were being automatically signed out every hour.
- Fixed regression in Sites modules where library storage info columns were not associated to each library (shown as multi-values).
- Fixed Quick GridView for Sites where the Apply button was disabled for Additional Info options.
- Fixed issue where moving between different types of usage reports options sometimes resulted in no time range selected. Now, the first option is selected by default in these cases.
- Fixed crash issue when signing out of a loaded Freeze Point. Fixed issue where, during app session creation or elevating a session, creating a new app prompted users to delete the newly created app instead of properly replacing the existing one.
- Fixed issue where creating a session with the same credentials as the currently loaded session led to the a buggy state.
- Fixed issue in Audit Logs where ‘Refresh’ unexploded multi-values that were already exploded in the view.
- Fixed issue where data with an outdated delta prevented the cache from refreshing correctly, and addressed a problem where no view was applied after reloading from an old cache.
- Fixed editing time issue in Calendar Events where applying the local time value set from the dialog did not match the value shown in the grid.
- Fixed issue where set time filters were not properly applied in saved views.
- Fixed issue in Messages and Events modules where “Click ‘Load Attachment Info’ button (Ctrl-L) to load this property value for selected rows.” text was shown for rows where there are no attachments and for rows whose attachments were loaded.
- Fixed issue in Service Principals module where clicking ‘Show in a new window’ for selected Applications opened in the same frame.
- Fixed issue where Comment columns where shown under a ‘ghost category’ in the grid.
- Fixed issue where sapio365 prompted for the master password either at the end of a scheduled job run, or after running an edited scheduled job, even when it hadn’t previously required it.
- Fixed regression where the tooltip of link properties (URL) was no longer showing the actual link address.
- Fixed issue with the sapio365 update notice shown in the dashboard but not in the backstage.
Automation
- Added new automation tags and fixed various automation issues, listed in our help documentation: https://docs.ytria.com/automation/sapio365-latest-automation-additions.
