Duplicate » admin by request

What’s New in Admin By Request for Linux 4.1

Linux penguin logo beside the orange '4.1' on a dark hexagon tech background with circuit accents (banner image)

Admin By Request for Linux 4.1 is out now. The headline addition is policy-file scoping for sub-settings, which brings granular configuration control to local users and standalone Linux devices that aren’t joined to a directory service. The Linux GUI also scales better on HiDPI displays now.

Most of this release, though, is about making the Linux client more dependable day to day. It includes a long list of fixes across MFA and authorization, Break Glass, installation on RHEL, Rocky Linux, and Ubuntu, SSSD, SELinux, and audit logging, many of them driven directly by customer reports.

Policy-File Scoping for Linux Sub-Settings

Sub-settings let you apply different configurations to different groups of users and devices from a single portal. Until now, that targeting has leaned on directory membership, like Entra ID or Active Directory groups. Plenty of Linux estates don’t fit neatly into that model: build servers, lab machines, edge devices, and workstations running purely local accounts.

Linux 4.1 adds local policy files that can define pseudo user and computer groups on the endpoint itself. Sub-settings can then be scoped to those pseudo-groups, so local Linux users and standalone devices get their own configuration without needing to be joined to Entra ID or another directory.

The sub-setting model itself doesn’t change, so mixed environments can use the same approach for directory-joined machines and standalone ones. And because the policy lives in a file on the device, it fits naturally into however you already push configuration out to your Linux fleet.

Tighter MFA and Authorization Behavior

MFA arrived on Linux in version 4.0, and 4.1 refines how it behaves in real-world use. The main focus was making sure MFA and approval apply exactly where your policy says they should:

  • Sub-setting authentication providers are now respected, instead of always falling back to the global provider
  • When MFA mode is selected, sudo elevations use it, and non-pre-approved sudo commands prompt for MFA every time
  • MFA on pre-approvals triggers when configured, and only when MFA is enabled
  • Approved sudo commands follow the same approval and MFA rules on every run
  • Removing a pre-approval rule now takes effect right away, including for cached sessions

Account separation has been tightened up as well. Different valid users now succeed as expected, matching or external accounts are correctly rejected, and a failed attempt no longer blocks future MFA flows.

Error messages are clearer too. Local users who are denied now see a proper denial instead of a misleading identity-provider connectivity message, and pre-approval failures show the specific reason. Offline users are told their request will be sent once connectivity returns, and MFA SSO email details now appear in the audit log.

More Reliable Break Glass and Admin Sessions

Break Glass is your fallback when normal access isn’t an option, so it has to work the first time. This release fixes cases where Break Glass accounts were removed before the user could sign in. It also improves login on Rocky Linux 9 and access from the RHEL 9 login screen, and makes sudo behavior consistent across accounts and terminal sessions.

Expiry is handled more cleanly as well: when the timer runs out, the user is logged out and the account is removed.

On the Admin Session side, active sessions now carry the correct Polkit privileges, so users can perform administrative actions in the GUI without being asked for an extra administrator password. We’ve also fixed sessions that started without elevation and server sessions that exited unexpectedly. Separately, user sessions no longer get stuck marked as running, and revoking admin rights now behaves correctly for domain users on RHEL and Ubuntu. Portal settings for root login and root password changes are now enforced as configured.

Distribution-Specific Fixes

RHEL and Rocky Linux endpoints get their own set of fixes:

  • SELinux policy installation now runs in the right order, so no restart workarounds are needed.
  • Packages install on RHEL 9 without GPG check failures.
  • PAM install and upgrade on RHEL 9 handle German locale dates and CIS custom authselect profiles.
  • Uninstalling on Rocky Linux 9 now removes packages properly.

Ubuntu endpoints get their own set of fixes:

  • Install-time errors on Ubuntu 20.04 Server and Workstation are fixed.
  • Service crash and D-Bus exhaustion scenarios affecting Ubuntu 24.04 are resolved.
  • SSSD-joined devices and domain users on Ubuntu Server are now detected correctly.
  • The client no longer bypasses SSSD access filters.
  • Users on Ubuntu Server who already hold native sudo rights no longer run into hangs.
  • Sudo is no longer wrongly blocked when it should be allowed.
  • Polkit authentication on Ubuntu 20.04 Workstation has been hardened.
  • An intermittent loss of cloud connectivity on Ubuntu 20.04 Workstation has been fixed.

Compatibility With Your Existing Tools

The client now plays better with the tools already running on your machines. Ansible-managed devices no longer see their automation flows interrupted, Snap packages like microk8s install normally alongside the client, and sudo works as expected in non-standard remote root terminal sessions such as those opened by RMM tools.

Under the Hood

Alongside the HiDPI scaling improvements, the GUI and CLI picked up some smaller fixes:

  • Log timestamps now match the endpoint’s time zone.
  • Join status and domain names display correctly.
  • The GUI and CLI both show whether the endpoint is connected to the IoT hub, the cloud messaging service the client relies on.
  • Components are no longer viewable from the user interface: the About panel no longer links to them, and the unsupported abr version –components option has been removed from the CLI, so check any scripts that call it.

Audit and inventory data is more reliable too. Process trees for elevated commands now appear correctly in the audit log. Admin Session and Run As Admin events recorded offline are uploaded once the device reconnects. Linux device inventory and domain group reporting in the portal are now consistent.

Finally, 4.1 includes a round of stability work across the client: a service memory leak has been fixed, and the GUI and CLI now stay responsive when SSSD can’t reach the domain. Several crashes are fixed too: a GUI crash loop on Rocky Linux, GUI crashes on Ubuntu 24 for users signed in with Active Directory accounts, and GUI and service crashes when signing in with local Active Directory realm users. Password changes on RHEL no longer fail because of errors in the client’s service.

Wrapping Up

Linux 4.1 puts reliability first, and a lot of work also went into how the Linux client is built, tested, and deployed. That groundwork should mean quicker releases from here, as Linux keeps closing the gap with Windows and macOS under the same portal and policies.

Existing customers can grab 4.1 from the admin portal, and the full Linux release notes cover every change in detail. If you’re new to Admin By Request and want to see Admin By Request EPM on your Linux endpoints, book a demo and we’ll walk you through it.

Useful Resources for this Release:

About the Author:

Picture of Pocholo Legaspi

Pocholo Legaspi

Pocholo Legaspi is a content writer at Admin By Request, where he covers privileged access management, endpoint security, threat analysis, and the wider cybersecurity issues facing IT teams. With over a decade in content marketing and SEO and a master's in business informatics, he writes about complex security topics in a way that's clear and useful for the IT teams putting them into practice.

Share this blog to your channels:

Lifetime Free Plan for 25 Endpoints,
No Strings Attached.

Fill out the form to create your account and get started.

Book a Demo