CHANGELOG

What's new in Implora

Every update to Implora, as it ships. A monthly summary goes out by email.

77 updates

Sep 28 - Oct 4, 2026

4 changes
  • Each tenant keeps its currency in License Advisor

    An analysis uses the currency the tenant had last time, so totals stay comparable run to run.

  • OpenIntuneBaseline v3.8 in the package catalog

    Windows Devices and Users move to v3.8. macOS and BYOD app protection are new.

Across Implora2
  • Smoother scrolling in the sidebar and panels

    The sidebar, the Baselines settings list, Lora Graph panels and the Chaos Score dialogs scroll with the browser's own smooth scrolling and a slim scrollbar without arrow buttons.

  • What's new in the sidebar

    The What's new button at the bottom of the sidebar lists what we ship, newest first. It opens on what is new since you last looked; search by page or text for the rest. Home shows the latest three.

Sep 21 - 27, 2026

19 changes
Tenants1
  • See which permissions are missing

    "2 new" and "N missing" open one list of the permissions, and "Allow configuration changes" replaces "Configuration Import".

  • Savings over time and a departments heatmap

    Findings come first, one row per tenant. Pick the overview graph: savings over time, or where to act first.

  • What-If pricing for Azure SQL

    Compare what your current SQL setup costs with other tiers, serverless included, on a What-If tab.

  • Check-first results for Azure Security and Cloud Security

    Results list each check once with its affected resources and the full scanner evidence in the detail sheet. Past Cloud Security scans can be deleted.

  • Zero Trust 2.6.0 reports, with SecOps and AI pillars

    Upload Zero Trust 2.6.0 reports; SecOps and AI join the pillars findings are grouped by.

  • Policies deploy in the state they were saved in

    On, Report-only or Off as packaged. Override it per deploy - you are warned before a policy goes On for all users, and told up front when Security defaults would refuse it.

  • Microsoft's Conditional Access baselines

    P1 (10 policies) and risk-based P2 (2 policies), built from Microsoft's June 2026 deployment plan.

  • Pick roles and guests per policy at deploy

    Add directory roles and guest types to each Conditional Access policy before it is written.

  • Autopilot rows say whether the tenant has the profile

    When you deploy a package, Autopilot rows show whether the tenant already has the profile.

  • Dynamic group rules sync to every tenant

    Sync sets each dynamic group's membership rule and records only what Entra ID shows back.

  • Group sets and tenant pages

    Bundle group templates into sets and deploy them to many tenants, see each tenant on its own page and which packages use a group. Verify all runs in the background.

  • 47 more settings, admin consent requests included

    Settings found across the admin portals, admin consent notifications and request expiry, and a tenant copy that shows its progress in the job monitor.

  • 68 new Intune and tenant settings

    Intune tenant settings join Baselines, most "Not managed yet" rows are now settings, and number settings take any value in range.

Conditional Access1
  • Identities table and readiness trend in CA Analyzer

    Headline tiles, readiness by reason and over time, and an identities table of everyone behind every number, with each sign-in method they have.

  • Create a missing group from a drift row

    "Create here" makes a missing group in the tenant, even when it has no group template.

  • Push a renamed policy from its row

    A Targeting badge marks assignment-only changes, and a renamed policy can be pushed straight from its row.

  • Config Drift rebuilt for scale

    Overview, template, tenant and scan pages rebuilt: one banner, progress while scanning, older scans read-only, and quick actions on scan rows.

  • Tables sort by every column

    Data tables in Config Drift, Groups and CA Analyzer sort by any column, and License Advisor lists followed.

  • Pushes align Conditional Access targeting by name

    A push translates a template's groups, locations and custom authentication strengths to the tenant by name.

Sep 14 - 20, 2026

3 changes
Conditional Access2
  • Readiness before a policy goes On

    CA Analyzer shows who a policy change would affect, with the names behind every number.

  • CA Analyzer

    See who each Conditional Access policy covers, who satisfies it and who it would block, with Microsoft's What If verdict beside ours and observed sign-in numbers.

Sep 7 - 13, 2026

6 changes
Tenants3
  • Exchange and Teams access as one grant

    Exchange and Teams access is one shared grant, Teams Administrator included, and consent links can be copied from the row menu.

  • A tenant access page

    Each tenant has an access page with what is left to hand off, a nightly access check and an access history. A consent counts the moment it lands.

  • Read-only or read-and-write, per workload

    Choose read-only or read-and-write access for Exchange, Teams and other workloads, with a manual setup path checked by a read-only verification.

  • Accepted deviations, Rules and Map views

    Accept a deviation per tenant, fix one rule across tenants, and see how long a rule has failed.

  • Baselines cover Exchange, Teams and Defender

    One Baselines page for Entra, Exchange, Teams and Defender settings, checked in the background. A baseline can be captured from a tenant.

  • Passkey settings and find-a-setting search

    Manage passkey (FIDO2) settings in a full-page editor, and search for any setting in a baseline.

Aug 31 - Sep 6, 2026

1 change
  • Custom and template device configurations in drift

    Device configuration profiles, custom profiles down to each payload key included, are compared and pushed like Settings Catalog policies.

Aug 24 - 30, 2026

3 changes
  • Checks a scanner stops reporting are marked Not detected

    When a scanner update drops a check, it shows as Not detected instead of vanishing. Cloud Security gains a workload column and a framework filter.

Billing1
  • Prices in NOK, SEK and GBP

    Pick your currency beside the plans, and billing pages are private to the account owner.

Aug 17 - 23, 2026

1 change
  • Read a package policy as settings

    Package policies read as settings instead of raw JSON, and a policy is edited where it is kept.

Aug 10 - 16, 2026

10 changes
  • Packages tell you when their source changed

    A scheduled check flags packages whose source tenant changed, with an opt-in auto-update and a section in the weekly summary.

  • Create missing groups in one step

    Create every group a deploy is missing in one step, linked and selected.

  • Update a package from its source tenant

    Packages remember the tenant they came from; update one from there, with its default assignments pre-filled.

  • Adopt an existing group into a template

    Link a group that already exists in a tenant to a group template instead of creating a duplicate.

  • Push buttons explain read-only access

    When a tenant has read-only access, the push button says so instead of failing when clicked.

  • Renamed policies are recognised, not reported missing

    A renamed policy is paired with its original and shown as renamed; accept a name once and it stays accepted.

  • Exempt single settings in a template

    Exclude single settings of a template policy for a tenant, and see the exemptions in the policy and rules views.

  • The template page is the home of the standard

    Link tenants, update from the source, scan all and read the history from the template page. Pushes are batched and verified with one scan.

  • A timeline behind every drift row

    See the whole story of a drifted policy: when it changed, what was accepted and why.

Aug 3 - 9, 2026

8 changes
Schedules1
  • Schedules show what ran and what it covered

    Each schedule names the state of every tenant, shows its runs and says which tenants it really covers.

  • Cost per user, coverage and year over year

    An insight pack with cost per user, commitment coverage, year-over-year change and realized savings.

  • Templates grouped by source tenant

    The overview is rebuilt around your workflow: templates in one table grouped by source, tenant search, and the source tenant follows its own standard.

  • Keep or enforce when you push

    A push shows which differences you keep and which you enforce, and every push is recorded.

  • Settings Catalog assignments drift

    Assignment changes on Settings Catalog policies show as drift, and a push aligns them.

  • Accept part of a drifted policy

    Accept only the settings or elements that differ; the rest stay enforced, and pushes respect what you accepted.

  • Drift reads like the portal

    Detected changes and a full policy tree in portal wording, with users, locations and roles shown by name.

Conformance1
  • Conformance explains its badges

    A How it works sheet explains the status badges and how the reference compares with each tenant.

Jul 27 - Aug 2, 2026

4 changes
Tenants1
  • A permission rollout shows once, not per tenant

    New permissions read as one rollout with a re-consent badge in the sidebar, instead of a warning on every tenant.

  • Lora Ops checks, verifies and plans

    Lora Ops runs read-only checks, verifies what they found and plans from the checks that failed.

  • Many more configuration types can be deployed

    macOS scripts and custom attributes, remediations, named locations, assignment filters, terms and conditions, update policies, Endpoint Security, ADMX templates, app configuration and custom authentication strengths.

  • Deploys link Conditional Access prerequisites

    Named locations and authentication strengths a Conditional Access policy needs are linked on deploy, and the history shows each policy's result.

Jul 20 - 26, 2026

2 changes
Schedules1
  • Schedules: one place for recurring work

    Run drift scans, Entra checks and assessment scanners on a schedule, with batched alerts and an optional weekly summary email.

  • Device quota, B2B direct connect and inbound trust

    Entra baselines manage the device quota, B2B direct connect and inbound trust settings.

Jul 13 - 19, 2026

1 change
  • Package capture picks up where you left off

    Discovery resumes after a reload and reuses a recent export, marked in the tenant list.