[BESAdmin-Announcements] BigFix Platform 11.0 Patch 7 is now available!
Announcements for BES Administrators
besadmin-announcements at bigmail.bigfix.com
Tue Sep 29 13:58:43 PDT 2026
The BigFix Team is pleased to announce the release of Version 11 Patch 7
(11.0.7.61) of the BigFix Platform. This release strengthens integrations
and data access, extends compliance coverage, improves performance at
scale, and broadens platform support — helping your team manage a more
diverse, secure, and efficient environment. The main features in this
release are as follows:
Custom content, managed like code!
-
External Repository Sites: BigFix can now connect to the Git source
control system and use it as an “External Repository Site”. This provides a
single, unified source of truth for custom content with clear
cross-environment history and authorship tracking. It brings BigFix in line
with modern DevOps practices by working with CI/CD and automation
pipelines, and strengthens governance with better visibility into how
content evolves. For more information please see External Repository
Sites
<https://help.hcl-software.com/bigfix/11.0/platform/Platform/Config/c_repository_site.html>
.
Bring Identity Provider users and computers information into BigFix!
-
User-based management: BigFix is now able to retrieve computer data from
Active Directory and Microsoft Entra ID, such as the User associated with
the Computer, the User Groups and Computer Groups it belongs to, and more.
This data is made available as computer properties, allowing BigFix
operators to achieve user-centric endpoint management, advanced dynamic
targeting, and reporting. This simplifies governance and aligns enterprise
instruments to meet business goals. For details, see User-based
management
<https://help.hcl-software.com/bigfix/11.0/platform/Platform/Config/c_user_base_mgt.html>
.
Performance at scale!
-
Boosted BigFix Relay Scale: 11.0.7 Relays on Windows and RHEL implement
architecture improvements to allow up to 20000 endpoints connected to a
single Relay, whether it is non-authenticating or authenticating. This is
up to a 4x improvement over previous figures! Also Persistent
Connections are boosted on the same Relays: up to 20000 per Relay, a 20x
improvement over the past limit. Note: BigFix 11.0.7 Root Server and
Relay on RHEL now require RHEL 7.6 as minimum OS version. For more
information please see BigFix Performance & Capacity Planning Resources
<https://help.hcl-software.com/bigfix/landing/Technical+Documents/Landing_page_shared/Technical_Documents.html>
.
-
Faster client performance on multi-core systems: A new client setting
(_BESClient_Resource_ScaleWorkTimeWithCPUCores, disabled by default) lets
the BigFix Client take fuller advantage of available CPU cores, helping
actions and evaluations complete faster on modern multi-core hardware. For
details, see List of settings and detailed descriptions
<https://help.hcl-software.com/bigfix/11.0/platform/Platform/Config/r_client_set.html>
and BigFix Performance & Capacity Planning Resources
<https://help.hcl-software.com/bigfix/landing/Technical+Documents/Landing_page_shared/Technical_Documents.html>
.
-
Faster onboarding and operation for large cloud deployments: The Plugin
Portal now evaluates Fixlets, properties, and actions concurrently across
computers, decouples computer registration from execution, and batches
registration requests to the BigFix Server. Together, this cuts onboarding
time in large-scale cloud environments and keeps policy enforcement timely
even as new virtual machines register. In addition, one Plugin Portal now
supports up to 100000 cloud devices. For more information please see BigFix
Performance & Capacity Planning Resources
<https://help.hcl-software.com/bigfix/landing/Technical+Documents/Landing_page_shared/Technical_Documents.html>
.
-
Improved Console search engine: Searching objects in the Console
(Fixlets/Tasks, Baselines, Analyses, Actions) is now more efficient,
contributing to improving user experience.
Compliance and security, reinforced!
-
FIPS 140-3 readiness: Organizations operating in regulated or government
environments can now enable FIPS 140-3 mode, helping meet current federal
cryptographic standards. For details, see FIPS 140-3 cryptography in the
BigFix environment
<https://help.hcl-software.com/bigfix/11.0/platform/Platform/Config/c_fips_crypto_fips1403.html>
and Configuring FIPS 140-3 on the BigFix Server
<https://help.hcl-software.com/bigfix/11.0/platform/Platform/Config/c_setting_fips_crypto_fips1403.html>.
BigFix encryption module is also FIPS 140-3 certified!
https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/5159
-
Automatic protection for idle consoles: A new setting lets you configure
a BigFix Console lock timeout, so unattended, logged-in sessions are
automatically locked — helping enforce security policy with no extra
process required. For details, see Setting the BigFix Console lock
timeout
<https://help.hcl-software.com/bigfix/11.0/platform/Platform/Console/c_setting_lock_timeout.html>
.
-
Stronger download integrity: Action scripts that fetch files (“add
prefetch item” and “prefetch”) now support SHA-512, giving teams a stronger
integrity-checking option for downloaded content. For details, see add
prefetch item
<https://developer.bigfix.com/action-script/reference/download/add-prefetch-item.html>
and prefetch
<https://developer.bigfix.com/action-script/reference/download/prefetch.html>
.
-
Tighter control over MCP access: A new “blockIncomingMCPRequests” option
on the BigFix root server lets administrators disable incoming MCP
requests, giving security teams a simple control to restrict this interface
where it isn’t needed. For details, see Installing and configuring
BigFix Platform MCP Server
<https://help.hcl-software.com/bigfix/11.0/platform/Platform/MCP/c_installing.html>
.
More resilient administration!
-
Preventing conflicting admin operations: BigFix now blocks more than one
instance of BESAdmin from running at the same time on a given computer,
reducing the risk of conflicting configuration changes and administrative
errors. For details, see BESAdmin Windows GUI
<https://help.hcl-software.com/bigfix/11.0/platform/Platform/Installation/c_besadmin_windows_gui.html>,
BESAdmin Windows Command Line
<https://help.hcl-software.com/bigfix/11.0/platform/Platform/Installation/c_besadmin_windows_cli.html>
and BESAdmin Linux Command Line
<https://help.hcl-software.com/bigfix/11.0/platform/Platform/Installation/c_besadmin_linux_cli.html>
.
Expanded platform support!
BigFix Agent now supports additional platforms, extending consistent
management and visibility to more of your modern infrastructure footprint:
-
New! Linux distributions on ARM processor:
-
Ubuntu 24.04, 26.04 LTS ARM 64
-
Red Hat Enterprise Linux 9, 10 ARM 64
-
Debian 13 ARM 64
-
macOS 27 (Golden Gate) ARM 64
-
Ubuntu 26.04 LTS x86 64-bit
-
VIOS 4.1.1, 4.1.2 PPC 64-bit on Power 11
-
AIX 7.2, 7.3 PPC 64-bit on Power 11
-
Red Hat Enterprise Linux 9, 10 PPC 64-bit LE on Power 11
-
SUSE Linux Enterprise Server (SLES) 15, 16 PPC 64-bit LE on Power 11
Inspector changes
-
New inspector types named “idp group” and “idp user” were added to
return information about the groups and users associated with a computer
joined to an Identity Provider (IdP). For details, see idp group
<https://developer.bigfix.com/relevance/reference/idp-group.html> and idp
user <https://developer.bigfix.com/relevance/reference/idp-user.html>.
-
New properties were added to the “cryptography” inspector. These
properties return whether BigFix components in the deployment should
operate in FIPS 140-2 or FIPS 140-3 mode. List of added properties:
-
fips_140_2 mode of
-
fips_140_3 mode of
For details, see cryptography
<https://developer.bigfix.com/relevance/reference/cryptography.html>.
-
New properties were added to the “license” inspector. These properties
return whether BigFix components in the deployment should operate in FIPS
140-2 or FIPS 140-3 mode. List of added properties:
-
fips_140_2 mode of
-
fips_140_3 mode of
For details, see license
<https://developer.bigfix.com/relevance/reference/license.html>.
-
New properties were added to the “client” inspector. These properties
return various information if the computer is joined to an Identity
Provider (IdP). List of added properties:
-
idp directory type of
-
idp distinguished name of
-
idp group of
-
idp id of
-
idp display name of
-
idp sam account name of
-
idp user of
For details, see client
<https://developer.bigfix.com/relevance/reference/client.html>.
-
A new cast named “as xml string” was added to the “bes action”, “bes
computer group”, “bes fixlet” and “bes property” session inspectors to
convert the specified BES object to an XML string. The new cast was
introduced exclusively for the BigFix Console and BigFix Explorer. It is
not supported in Web Reports. For details, see bes action
<https://developer.bigfix.com/relevance/reference/bes-action.html>, bes
computer group
<https://developer.bigfix.com/relevance/reference/bes-computer-group.html>,
bes fixlet
<https://developer.bigfix.com/relevance/reference/bes-fixlet.html> and bes
property
<https://developer.bigfix.com/relevance/reference/bes-property.html>.
Upgraded libraries, binaries and 3rd party tools
-
The libgit2 library was introduced at version 1.9.7.
-
The boost library was upgraded to Version 1.91.0.
-
The libcURL library was upgraded to Version 8.22.0.
-
The OpenSSL library was upgraded to Version 3.5.8.
Additional information about this release
-
The standalone BigFix tools are published under the 11.0 Utilities
section in the BigFix Enterprise Suite Download Center
<https://support.bigfix.com/bes/release/>.
-
A Non-Functional Requirements checklist, covering both performance and
security management of your BigFix deployment, is available at BigFix
Performance & Capacity Planning Resources
<https://help.hcl-software.com/bigfix/landing/Technical+Documents/Landing_page_shared/Technical_Documents.html>
.
References
-
See the full technical changelist
<https://support.bigfix.com/bes/changes/fullchangelist-110.txt>.
Pre-Upgrade Considerations
Important considerations to keep into account before upgrading to BigFix
Platform Version 11 are:
-
BigFix Version 10.0.7 is the minimum version supporting the upgrade of
the BigFix server components to Version 11.
-
You must enable the “Enhanced Security” in the BESAdmin tool before
upgrading BigFix Platform to Version 11.
-
The minimum TLS supported protocol in BigFix v11 is TLS 1.2.
-
The SHA1 hashing algorithm for content and action signature will no
longer be supported. SHA1 is still supported for file download in
actionscript. For details, see BigFix Platform V11 Overview Page
<https://help.hcl-software.com/bigfix/11.0/platform/Platform/Installation/c_overview.html>
.
-
The msodbcsql18 RPM package is a prerequisite for the Server components
on Linux systems. This applies to installations with an MSSQL database.
-
For detailed information on the specific changes to minimum supported
versions of operating systems and databases for BigFix 11, see Detailed
system requirements
<https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0104120>
.
-
Before getting started with the upgrade process, stop any active
application that is connected to the BigFix database (such as Web Reports,
WebUI, BigFix Inventory, or BigFix Compliance).
Useful links
-
BigFix downloads and release information
<https://support.bigfix.com/bes/release/>.
-
BigFix 11 Platform Documentation
<https://help.hcltechsw.com/bigfix/11.0/platform/welcome/BigFix_Platform_welcome.html>
.
-
Upgrade considerations
<https://help.hcl-software.com/bigfix/11.0/platform/Platform/Installation/c_upgrading1.html>
.
-
Detailed system requirements
<https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0104120>
.
Upgrade Fixlets are available in BES Support version 1516 (or later).
Continue to discuss on the forum
<https://forum.bigfix.com/t/bigfix-platform-11-0-patch-7-is-now-available/55891>
— HCL BigFix — Platform Team
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://bigmail.bigfix.com/pipermail/besadmin-announcements/attachments/20260929/e82877fe/attachment.html>
More information about the Besadmin-announcements
mailing list