Skip to content
← Back to release notes
v0.88.0 stable major release

Release v0.88.0

Jul 01, 2026

Self-hosted UniFi controller support, an EDR-aware Incidents page that unifies live endpoint detections with your tracked incidents, the ability to manage Windows Update exclusively through Breeze, a Pi-hole v6 DNS Security integration, and a native detail page for network-discovered devices — plus ticketing, billing, and patch-accuracy improvements.

Network & Visibility

  • Self-hosted UniFi controller support. If you run your own UniFi Network controller (one server hosting many customers as separate sites), Breeze can now manage it end to end through an agent on the controller's network — no UniFi cloud account or cloud API key required. That single controller fans out to all of your customer organizations for both device inventory and deeper telemetry, so the common MSP topology of one self-hosted controller per shop finally works.
  • Native detail page for network-discovered devices. Devices found through Network Discovery now open a proper detail page with their own view, instead of being limited to a row in a list.
  • Pi-hole v6 DNS Security integration. DNS Security gains support for Pi-hole v6, so you can bring Pi-hole deployments into Breeze's DNS visibility.
  • UniFi cloud integration fixes. The existing cloud UniFi Site Manager integration got a round of corrections to parsing, paths, and site-mapping, plus a safer re-sync that replaces mapped sites cleanly.

Security & Incidents

  • EDR-aware Incidents page. The Incidents page now shows a single, severity-ranked feed that combines live detections from your connected endpoint-security (EDR) tools with the incidents you track manually — no more flipping between the two. Each EDR finding links straight back to the originating security console.
  • Elastic Defend recognized as antivirus. Breeze now identifies Elastic Defend as an installed antivirus product, so endpoints running it report accurate protection status.
  • Security & Compliance Posture report in the UI. The client-facing posture report is now available directly from the reports interface.
  • Hardened PAM signer matching. Privileged Access Management rules can now match an application by its signing certificate's exact thumbprint rather than just the certificate name, closing a gap where a differently-issued certificate with the same name could satisfy a rule.
  • Correct antivirus detection order. When both are present, Bitdefender is now identified before Windows Defender, fixing cases where the wrong product was reported.

Patch Management

  • Manage Windows Update exclusively through Breeze. A new Patches setting lets you suppress an endpoint's built-in Windows Update auto-install, so updates only ever flow through Breeze's approval rings and schedules — no surprise reboots or patches installed outside your policy. It's off by default and enabled per configuration policy, so existing setups are unchanged until you opt in.
  • More accurate Windows Update scanning. Update categories are now classified from all of Windows' own category data, release dates are populated on scanned updates, and a patch policy that targets only firmware or drivers now fails loudly instead of silently doing nothing.
  • Deploy software by .exe and .msi with detection rules. Software deployments can now use detection rules for .exe and .msi installers to tell whether the app is already present, alongside a fix to how reboot exit codes are handled.

Automation & Configuration

  • Partner-wide configuration policies. When creating a configuration policy you can now choose an 'all organizations' owner so a single policy applies across every customer, instead of having to attach it to one organization.
  • Reboot pending-reboot devices during maintenance windows. Maintenance windows can now reboot devices that are waiting on a pending reboot, so deferred restarts get cleared on your schedule rather than interrupting the workday.
  • Clearer agent update policy labels. The agent update-policy modes were relabeled to match what they actually do, removing a source of confusion about which setting controls automatic agent updates.

Ticketing & Email

  • Drop unknown or unverified senders. Inbound email-to-ticket adds a 'drop' option for mail from unrecognized senders — silently ignored with an audit record, so unmapped spam never reaches your review queue — plus a separate option to drop mail that fails SPF/DKIM/DMARC. The default is unchanged (unknown senders still go to the review queue), and that review queue now lives on the Tickets tab.
  • Partner-level SLAs in Priorities. Partner-wide SLA targets are now surfaced in the ticket Priorities settings, with a corrected note explaining how organization and partner SLAs take precedence.
  • More reliable inbound email delivery. Breeze now correctly trusts genuine Mailgun inbound mail servers and checks every authentication header on a message, so legitimate customer email is less likely to be misjudged.

Billing & Catalog

  • AI-assisted catalog imports. Importing hardware and subscriptions from your distributors can now clean up and enrich messy product listings with AI, and a 'Polish with AI' helper tidies catalog entries on demand.
  • Prefilled Pax8 pricing on subscription contracts. Linking a subscription to a Pax8 product now prefills the sell price in the subscription-link dialog, so contract line items start from the right number.
  • Roomier line descriptions. Quote and invoice line-item description boxes are now full-width and expandable, making long descriptions much easier to write and read.

Console & Fixes

  • Smarter alert suppression. Resolved alerts can be muted again, there's now a 'Forever' suppression option, and a background reaper automatically clears expired suppressions so muted alerts come back when they should.
  • Report templates load again. Opening report templates no longer fails with a server error.
  • Offline-aware device actions. Connect Desktop and Power actions are now disabled for devices that are offline, instead of appearing available and then failing.
  • API keys can update custom fields. Automations authenticating with an API key can now write device custom-field values.
  • Reliable MCP access for org-scoped keys. AI tool access using an organization-scoped API key now resolves the owning partner's role correctly, including for keys without an explicit membership.
  • Longer network interface names. Network interface names are no longer truncated, so devices with long adapter names record correctly.

Version 0.88.0 is a broad release that pushes hardest on networking, security visibility, and patch control.

The headline is self-hosted UniFi controller support. If you run your own UniFi Network controller with each customer as a site inside it, Breeze can now manage that entire setup through an agent on the controller’s network — no UniFi cloud account or API key — and fan that one controller out to every customer organization for inventory and deep telemetry. Network Discovery also grows up: discovered devices get a native detail page, and DNS Security adds a Pi-hole v6 integration.

On the security side, the Incidents page is now EDR-aware — a single severity-ranked feed that unions live detections from your endpoint-security tools with the incidents you track by hand, each linking back to its originating console. And patch management gets real teeth: you can now manage Windows Update exclusively through Breeze, suppressing the OS’s own auto-install so updates only flow through your approval rings — off by default and enabled per policy, alongside a batch of fixes that make Windows Update scanning genuinely accurate.

The rest of the release rounds out day-to-day work: partner-wide configuration policies, maintenance-window reboots for pending restarts, a drop mode for unknown or unverified inbound email, AI-assisted distributor catalog imports, roomier quote and invoice descriptions, and smarter alert suppression (including a proper “Forever” option and automatic expiry). It’s a recommended upgrade.