<style> /* comment-ok: load-bearing Sparkle no-JS fallback doc (WEB-3164/WEB-3201). Reveal x-cloak content so sidebar branch lists and closed-state chips render — EXCEPT the mobile slide-in backdrop, which would otherwise cover the whole viewport in black/40 with no way to dismiss (the dismiss handler is x-on:click="mobileHeader = false" and can't fire without Alpine). */ [x-cloak]:not([x-show="mobileHeader"]) { display: revert !important; } /* comment-ok: load-bearing Sparkle no-JS fallback doc (WEB-3164/WEB-3201). (1) Force every version card OPEN so all release-notes content is visible. Overrides the default `.rn-ver-body { grid-template-rows: 0fr }` from release-notes.css, which is normally lifted to `1fr` via Alpine's `:class="{ 'rn-ver-body--open': open }"`. */ .rn-ver-body { grid-template-rows: 1fr !important; } /* comment-ok: load-bearing Sparkle no-JS fallback doc (WEB-3164/WEB-3201). (1b) Strip `hidden="until-found"` from collapsed card bodies. WEB-3164 added that attribute on cards 2..N (the first card omits it; see the first-item check in ReleaseNotesCards.astro) so Chrome/Edge browser find-in-page can reveal text inside collapsed bodies and fire a `beforematch` event Alpine catches to pop the card open. Alpine's `x-effect` directive normally removes the attribute when `open` flips true — but without JS that directive never runs, so cards 2..N stay hidden via either `content-visibility: hidden` (Chrome/Edge/Safari 17+ resolve `hidden="until-found"` to that) or `display: none` (older Safari / unknown browsers treat it as a plain boolean `hidden`). Rule (1) above lifts the SCSS-based grid-rows collapse but does NOT override `[hidden]` — the attribute applies a higher-priority `display: none` / `content- visibility: hidden` that wins over grid-template-rows. This rule covers both browser-engine paths: `display: revert` restores the element's normal display (the `grid` utility on the wrapper), `content-visibility: visible` overrides the modern-browser path. */ .rn-ver-body[hidden] { display: revert !important; content-visibility: visible !important; } /* comment-ok: load-bearing Sparkle no-JS fallback doc (WEB-3164/WEB-3201). (2) Hide controls that can't do anything without JS so the UI doesn't lie about being interactive: the expand/collapse chevron, the closed-state category chips (Security 3 / Features 5 / …), the section-level expand-all toggle if reintroduced, and the cursor-pointer hint on the header. */ .rn-ver-chevron, .rn-ver-chips, .rn-toggle-all { display: none !important; } .rn-ver-header { cursor: default !important; } /* comment-ok: load-bearing Sparkle no-JS fallback doc (WEB-3164/WEB-3201). (3) Hide status pills (Current / Beta / Extended maintenance) and the matching sidebar dots. Pills are rendered server-side from productInfo.json at build time and are accurate at publish — but a stale cached page in Sparkle could surface them on a version that is no longer "Current" by the time the user opens RDM, so hiding them entirely under no-JS removes the whole class of misleading-stale-pill failure modes. */ .rn-ver-tag-line, .rn-status-pill, .rn-status-dot { display: none !important; } /* (4) Sidebar branch chevrons stay frozen in the "closed" rotation without Alpine to flip them — drop them since the branch lists below are already revealed by the x-cloak rule above. */ .rn-toc-branch-head > span:first-child { display: none !important; } /* comment-ok: load-bearing Sparkle no-JS fallback doc (WEB-3164/WEB-3201). (5) Hide mobile-only chrome whose Alpine click handlers can't fire: the top mobile menu-open bar and the sidebar's mobile close bar. Both gate `mobileHeader`, which never toggles without JS. */ .rn-main-header, .rn-sidebar > div:first-child { display: none !important; } </style>

Release notes

Release notes

Version 2026.3

Table of contents

Thank you for updating Remote Desktop Manager (RDM) to version 2026.3!

Below, we'll take a quick look at the most exciting updates. For the full list of changes, check out the release notes.


A rebuilt Windows interface

The migration of the Windows interface to Avalonia is complete in 2026.3. Nearly every screen was rebuilt on the new foundation, so the change reaches the whole application rather than a handful of windows. RDM also starts faster and ships in a smaller installer.

The ribbon and the main menu are redesigned around a consistent set of actions. A streamlined Toolbar mode is the new default for anyone who wants less chrome. In the tree, columns are sortable, entries carry status badges, and a multi-selection carries across a vault switch.

Sessions run on a native rendering path, including tabs, docking, thumbnails, and full screen. An undocked window reopens where you left it. Dozens of per-type dashboards are now a single layout that previews notes, documents, and scripts without opening the entry.

The interface scales cleanly on high-DPI displays, includes a true high-contrast theme, and supports keyboard navigation and screen readers throughout.

Manage access with roles on Devolutions Server and Devolutions Cloud

Vault access on Devolutions Server and Devolutions Cloud workspaces now comes from roles. You can open a vault only when one of your assigned roles grants access to it. This change does not affect local or SQL Server data sources in Remote Desktop Manager.

On Devolutions Server, a new set of roles now manages all access and permissions at the workspace, vault, and privileged-provider levels. Every existing administrator receives the Workspace Owner role and keeps their current access. When you create a new user, you assign the roles that match the access they need.

On Devolutions Cloud, every existing administrator now holds the Vault owner role on every vault. You can remove that role from any vault that an administrator should not see. A new administrator gets the Administration menu only until you assign them a role on a vault.

Store PAM credentials in shared vaults

You can now store Devolutions PAM credentials in a regular shared vault, alongside standard entries. A vault must be at the High security level before it can hold PAM accounts. A vault at Standard refuses a PAM entry and asks an administrator to convert the vault first. High-security vaults are not available offline, and a vault that holds PAM accounts cannot return to Standard until you move or delete those accounts.

Extend active PAM checkouts

You can now request more time on an active PAM checkout, instead of checking the credential in and starting a new request. Extensions are off by default. The checkout policy controls whether extensions are available, whether approval is required, and the maximum extension duration.

PAM checkout extension in RDM on Windows.

Manage PAM provider credentials with self-rotation

A PAM provider signs in with its own account to run discovery, heartbeat, and password rotation. When you save a provider, you can now choose Manage with self-rotation, Keep credentials in the provider, or Skip for now. You can also convert an existing provider to a Managed PAM account. The managed account appears under the provider and follows the provider's rotation schedule.

PAM provider credentials in RDM on Windows.

Manage Devolutions Cloud users in RDM

You can now manage Devolutions Cloud users in RDM, as an alternative to the Devolutions Cloud web interface. You can search for and filter users, add users, administrators, or contractors, and send or resend invitations. You can also view licenses, user groups, registered devices, and user activity.

Devolutions Cloud user administration in RDM.

Manage Devolutions Cloud system settings in RDM

You can now manage the supported Devolutions Cloud system settings in RDM, instead of the Devolutions Cloud web interface. RDM could already manage system settings for SQL Server and Devolutions Server workspaces.

Devolutions Cloud system settings in RDM.

Use a built-in X Window server

RDM now includes a built-in X Window server. You can forward X11 from an SSH terminal session without installing a third-party X server. X11 forwarding options are in the SSH terminal entry settings, and Devolutions XServer is available from Tools.

Discover PAM accounts with the RDM SQL Server data source

For an RDM SQL Server data source, Account Discovery Preview shows the accounts a scan would discover, along with their risk signals. Any RDM user can run the preview, and you do not need a PAM license to view the results. The preview is read-only: results stay in memory for the session and are cleared when the window closes. Acting on what you find, including import, export, scheduling, and account management, requires a PAM license.

Keep existing just-in-time PAM accounts between checkouts

The just-in-time (JIT) account mode now includes Enable account on checkout, alongside None and Create the account on checkout. The new mode allows an existing account to be used at checkout, instead of creating a new one. At check-in, it disables the account again.

Create a vault from a template

When you create a vault, you can select a vault template to copy its folders and entries with their nesting. Templates are available when you create a vault for a Devolutions Server workspace or a Devolutions Cloud workspace. Permissions are not copied from the template, so entries inherit them in the new vault. The template itself does not change when you apply it.

Create multiple forbidden password lists

Each list has its own match mode (Exact or Contains) and its own case-sensitivity setting. With the Forbidden password check on, a password that matches any list is refused before you save it.

Existing settings are migrated to a list named Default. Importing entries with forbidden passwords completes with a warning instead of being blocked. The warning identifies each affected entry by name and path, names the rule it matched, links to the filtered Entry Security Analyzer, and includes a CSV export.

Forbidden password lists in RDM on Windows.