- Administration - Added a system setting to disable the AI Assistant
- Administration - Added the ability to create a new entry template directly from the Entry templates page
- Administration - New admins no longer access all vaults by default; current admins retain access as Vault Owners
- Entries - Added support for importing Password Safe (PwdSafe) files in Devolutions Cloud
- Entries - Added the ability to duplicate elements within a Password List entry
- Gateway - Improved gateway configuration saving so changes aren't blocked when the connection can't be tested
- PAM - Added mandatory ticket number and reviewer assignment options for PAM checkout requests
- PAM - Renamed the "Disable account on check-in" PAM option to "Enable account on checkout"
- PAM - Shared vaults can now hold PAM entries
- Security - Added new password generator modes (LessPass, Stanford policy, XKCD) along with UI improvements
- Security - Redesigned the recovery key validation flow
- Vaults - Added support for allowing linked vault credentials in user vaults from the web interface
- Administration - Fixed administration logs so "Recovery key generated" and "Recovery key email sent to hub owner" appear as separate, distinct filter options
- Entries - Fixed the entry-lock notification not showing the name of the user holding the lock
- PAM - Fixed checkout comments and log metadata not being recorded when checking out a Cloud-vault entry with "Prompt for comment" enabled
- PAM - Fixed PAM license being bypassed when copying or moving entries across vaults
- PowerShell - Fixed PowerShell entry retrieval to include the full folder path
- PowerShell - Fixed PowerShell export incorrectly including PAM vaults, which should be excluded like in the manual export dialog
- PowerShell - Fixed the PowerShell export obfuscation option behaving opposite to what its label and tooltip described
- Security - Fixed the default password policy dropdown staying empty instead of showing "None" after deleting the only custom policy
- Sessions - Fixed session recording fields being editable when they no longer applied due to inherited recording settings
- Sessions - Fixed web gateway sessions incorrectly showing as active after they were actually closed
- Users - Fixed mass-invite success/failure counters not counting users with inactive accounts as failures
- Users - Fixed the authentication mode field becoming stuck after selecting Contractor when editing a user
- Users - Fixed the invitations sent dialog missing a scroll bar when more than 20 recipients were listed
- Users - Fixed user icon incorrectly switching to the contractor icon when an expiration date was added
- Vaults - Fixed missing checkout button for entries in the System Vault
- Vaults - Fixed the vault access user/group search not matching by email address