Release summary
IVX Cloud 26R2 release enhances integration visibility, data loss prevention capabilities, and threat analysis efficiency. By optimizing threat analysis efficiency and centralizing security data monitoring, this update allow administrators to better protect and audit their environments.
View Connector Action Status in Submissions and Alerts to monitor automated integration actions in real time.
Extends Data Security Engine support to Google Chat workspaces for advanced data loss prevention.
Adds support for additional Windows and macOS profiles, expanding submission coverage across modern endpoint environments.
Introduces API key expiration notifications to help administrators proactively renew credentials to maintain uninterrupted automated workflows.
Release date: 03 Aug, 2026
What's new
View Connector Action Status in Submissions and Alerts — View the status of automated actions performed by integrations directly from the Submissions and Alerts pages. The new Connector Action Status column provides real-time visibility into whether actions initiated by connected integrations completed successfully or failed, helping administrators monitor and troubleshoot integration activity more effectively.
Enhanced Connector Health and Activity Statistics — Enhances integration troubleshooting by tracking detailed health and activity metrics across third-party connectors. Administrators can review operational metrics, failure details, active user counts, and connector-specific configuration information for supported integrations, including Dropbox, Google Cloud Storage, OneDrive, SharePoint, Microsoft Teams, Salesforce, ServiceNow, Webex, Workday, Zendesk, and Zoom.
Optimized Submission Quota — IVX Cloud no longer consume your operational submission quota for files already pre-marked as malicious by external service providers. This change optimizes resource allocation while maintaining comprehensive reporting within IVX Cloud across integrations including Google Drive, ServiceNow, OneDrive, SharePoint, and Zendesk preserving capacity for unverified files.
Updated AI Models for Trellix Wise — Trellix Wise now uses the latest supported AI models, replacing legacy models that have reached end-of-life (EOL). This update improves platform usability, reporting quality, and overall user experience while ensuring continued access to supported AI capabilities.
Data Security Engine support for Google Chat — Extend Data Security Engine protection to Google Chat workspaces. IVX Cloud can now automatically analyze Google Chat content to help identify sensitive information and enforce data loss prevention (DLP) policies, reducing the risk of data exposure across non-privileged communication channels.
Note
This feature is currently limited to U.S. Commercial regions and is not available in Government environments.
Updated Sandbox Guest Images — Upgrades sandbox guest images to version 25R1.1 to optimize detection coverage.
Extended OS Profile support — Added support for additional operating system profiles during API and UI submissions, including Windows 11 (
win11x64m) and macOS 10.11.3 (osx-10.11.3). These new profiles provide broader analysis coverage and improved detection accuracy across modern endpoint environments.Note
Legacy macOS 10.8.2 (
osx-10.8.2) is not supported.Track submission sources in API Workflows — Adds tracking capability for IVX Cloud submissions across internal and external accounts using context variables. This feature provides administrators with deep visibility into submission origins to streamline tracking and monitoring workflows.
API Key Expiry notifications — Administrators can now configure email and in-application notifications for upcoming API key expirations. These alerts help teams proactively renew API keys, maintain uninterrupted access to integrations and automated workflows, and reduce the risk of service disruptions caused by expired credentials.
Note
This feature is not available for trial accounts.
Chrome Extension for new accounts — The Chrome extension is now available for newly provisioned customer accounts. The existing extension has been republished under a new hosting account, restoring customer access and enabling deployment for new tenants.
Customizable dashboards — This release introduces a customizable dashboard experience that replaces the fixed system view. The modular layout provides enhanced visibility into integration submissions, data security posture, DLP activity, quota utilization, and platform health metrics enabling users to customize the view to their operational and security needs. Use the dashboard toggle to switch between the new and legacy dashboard views.
Note
This feature is currently in Beta. Use the BETA UI toggle located in the top header of the IVX Cloud portal to switch between the new and legacy dashboard views or access it by selecting New Dashboard (Beta) under the Investigate section in the Trellix IAM mega menu.
Health Integration API enhancements — Added the
connector_registration_idkey to the response payload of the/health/integrationAPI endpoint. Administrators can now view unique connector IDs directly inside health check data. This simplifies connecting with external monitoring tools such as Splunk to automate incident tracking and identify specific integrations.Tracking malicious messages in Google Chat — The system now automatically delivers malicious content alerts as direct inline replies to the original message thread in Google Chat spaces and direct messages using Google Workspace APIs. This capability enables users to immediately identify which specific message triggered the threat verdict.
Unified notification interface — Introduces a notification bell icon to the console navigation interface. This provides administrators with a single, centralized view of activity alerts and operational updates aggregated across multiple platform components, including API key modifications and integration status changes. This unified view ensures immediate visibility into critical system events and security operations.
Global geographic tracking for submissions — Integrates Geo IP lookup capability into IVX Cloud to resolve the geographic origins of submitted IP addresses and mapped URL domains. This integration automatically populates an interactive Global Threat Map dashboard widget, enabling administrators to visually track submission sources on a world graph, analyze regional trends, and map attack origins.
Resolved issues
Issue ID | Description |
|---|---|
DOD-4417 | Submissions Settings does not allow users to input file extensions containing numerical digits such as .mp3, .mp4, or .7z. As a result, specific filetype exceptions cannot be configured, preventing the system from automatically blocking submissions with those extensions. |
DOD-4432 | Files uploaded to the configured S3 bucket are scanned and moved despite settings of DO-NOT-SCAN policy. |
Known issues
This release does not contain any known issues.
Deprecated items
This release does not contain any deprecated items.
Additional information
Trellix Thrive: Access the unified portal for technical support, product downloads, support case management, diagnostic tools, knowledge base articles, product training, webinars, and community interaction.
Note
Access to the Trellix Thrive Portal requires login using valid Trellix customer support, partner, or employee credentials.
Trellix IVX Cloud Documentation: For detailed technical information, including product guides, release notes, and configuration instructions of IVX Cloud, visit our documentation portal.