Changelog

See the new features, improvements and bug fixes of FileAudit.


6.7 Beta

June 7, 2026

New features

  • Updated user interface to align with the latest IS Decisions visual identity, including refreshed colors and various display improvements.

  • New service warning to notify lack of disk space when using SQLite database.

Improvements

  • Adjusted Cloud trial management and license information display. The Cloud audit view did not work as expected.

Bugfixes

  • Access denied when trying to open the console with a non-administrator user configured with all permissions allowed except Settings, which was denied.

  • FileAudit service not starting on a new installation if the maintenance task could not be created.

  • Drop-down list not resetting to "No operation" if scheduled maintenance could not be created.

  • Warning message displayed during database cleanup when using MySQL.

  • Error handling during performance counter initialization.

  • Error displayed in the group's filter sections when the machine is in a workgroup.

  • Unnoticed configuration error that could prevent the logoff script from running.

  • Error when generating a report with a configured filter from a remote console.

  • Changing the database path on the server where the FileAudit service is installed caused an error in the console.

  • In some circumstances, logoff did not work in the predefined script 3Alerts-LogoffAndDisable.

  • In some circumstances, logoff did not work in the predefined script LogoffAndDisable-UserAndComputer.

  • Logo configuration being reset unexpectedly.

  • SQL error when filtering alert history by access type.

  • MySQL ODBC Connector 9.x not being detected properly.

  • In Cloud reports with an archived database, events from non-cloud audited paths were displayed when no filter was selected.

  • Unable to modify an alert name.

  • Unhandled exception when printing a report if print spooler is not running.

  • When adding a new script using the Browse button, the script could be saved without a name.

  • An unnamed alert could be created when an execution script was added.

  • Incorrect error message displayed during a major upgrade when using a MySQL database.

  • Alerts created using the button in the configuration wizard did not use the same path format as alerts created manually, causing alerts to fail when the network was unavailable.

6.6

July 17, 2025

New features

  • Support for x64 architectures – the service now runs as a 64-bit process.

  • Display of archived databases in a dedicated list.

  • New report filter to switch between archived and production databases.

  • Predefined scripts to automate alert responses.

Improvements

  • Permission change reports now consume less memory.

  • Support for long file paths.

  • Logging of the cluster name (if available) in the AccessEventAnalyzer.

  • Report generation performance by using a new query that excludes OldSD and NewSD in all reports except permission and owner changes.

  • Memory is now released for report data when refreshing a report in the console.

  • Refactored archiving and migration logic to use event blocks based on time rather than database event IDs.

  • Additional log entries during the database archiving process.

  • Enhanced logging during OAuth2 authentication.

  • Additional log entries during maintenance processes.

Changes

  • Removed: Option to deploy all permission changes at once from within the report.

  • Removed: Cloud debug and informational log entries.

Bugfixes

  • Archiving using SQL Server with Windows Authentication indicates success even if it was a fail.

  • Configured path state incorrectly changed to "Not Configured" if the remote server was unreachable during a maintenance task.

  • Maintenance task doesn't ignore manually configured paths.

  • Under certain conditions, some data could remain in the database after archiving.

  • Granular archiving failed when source and destination SQL Server databases contained identical records.

  • Infinite loop when disconnecting from FileAudit Cloud.

  • Events not displayed in real time for reports using the new improved query excluding OldSd and NewSd.

  • Memory leak when translating OldSD and NewSD for permission change detection.

  • Maximum packet size exceeded when streaming WCF messages.

  • Lock protection on streaming access events after direct database access failure in the console.

  • Duplicate script names appearing in the list of executable scripts.

  • Error message in alert configuration after open and cancel scripts settings without doing any changes.

  • "To" date and time selection was not greyed out when set to "Last Event".

  • Memory leak during scheduled maintenance.

  • After the trial period ends, the service continued to connect to the cloud and triggered service events.

  • Error while checking for @ONEDRIVE during the FileAudit maintenance task.

  • Memory leak during report generation using streaming.

6.5

November 30, 2023

New features

  • New alert history report.

  • Ability to export and schedule the new Alert history report.

  • Automation for audit configuration maintenance.

  • OAuth2 authentication for email notifications.

Improvements

  • Database Manager view becomes Maintenance view.

  • Faster loading speed for FileAudit reports.

  • MSP web communication errors.

Bugfixes

  • Archiving process doesn't remove source access events data if the snapshots archiving fails.

  • Reset Layout doesn't work with the group box in the Advanced permissions report.

  • Connecting to SQL server database without permissions doesn't generate an error message.

  • Setting SQL server database with no server name is allowed generating an error message.

  • Database migration from SQL Server to MySQL database never ends.

  • The permission report can be incomplete if a file cannot be accessed.

  • Database version not detected properly.

  • Database information is not loaded when changing the database.

  • Tab to get next field in "Add new script" dialog goes in disorder.

  • No French translating on Impersonation accounts view.

  • Favorites setting is not keept after closing the console.

  • Only the first path is displayed on a PDF export of the "File and folder properties" report.

  • Unhandled exception is generated with a Token's permission change event.

  • Error when opening "Change permission" report on a remote console.

6.4

October 6, 2022

New features

  • Ability to audit changes to NTFS permissions.

  • New report "Permission changes" including "old" and "new" permissions.

  • Ability to migrate and archive the production database on demand.

  • Ability to schedule the archiving of the database.

Improvements

  • New dynamic variable with the new path location of a moved file or folder for the single alerts.

  • Performance scan of the NTFS audit configuration for diagnostics.

  • Added translated fields in the RAW data format for the scheduled reports "Simple Permissions" and "Advanced Permissions".

Bugfixes

  • At service start-up an exception can be triggered when accessing the events analyze queues dictionary.

  • Error login with the impersonation account when connecting to an audited server if the account belongs to the Protected Users group in Active Directory.

  • Japanese characters in the header slogan are not displayed in the reports.

  • The event analyze queue sometimes freezes if the impersonation fails.

6.3

November 30, 2021

New features

  • Detection of the access event "move" on an audited server.

  • Filter alerts, reports, and scheduled reports with the new access type "move".

  • New predefined report for the access event "move".

  • Ability to export reports in .xlsx format.

Improvements

  • New dynamic variable with the top local folders for the mass alert notification.

  • Ability to exclude accounts in the scan options for cloud access audit.

Bugfixes

  • In some circumstances the database is not updated when the service starts.

  • The access audit fails if the audited path name contains special characters with accents.

  • Files with a path longer than 260 characters generate a PathTooLong exception.

  • Changes in the parameter to define the days to keep snapshots is not refreshed correctly in the view.

  • Unhandled exception exporting reports with more than 65000 lines in XLS format.

  • Renaming a scheduled access event report is not possible.

  • Mass alert doesn't work for cloud access events.

  • When UseFullPathForCloudProviders advanced settings is enabled the file name contains slash and not backslash as usual.

  • TopFolders dynamic variable can display the same path because it is case sensitive.

  • Changes in scan options are not displayed properly.

  • In audit paths report, the filtering of paths doesn't work.

  • In Windows servers report, the filtering of servers doesn't work.

  • Diagnostic process loses the connection with FileAudit service if the "Log System Information" take more than 2 minutes to be retrieved.

  • A console when remotely connected to the service, uses the local SQLite database if exists, when it should use the remote service SQLite database.

  • Unhandled exception when accessing to audit paths report for an user with only audit permissions.

  • Changes in the permissions of FileAudit are not saved.

  • Snapshots tile should be denied for a user with only audit permission.

  • Filtering on a group with more than 1000 members with a SQLite database is generating an error.

  • Under some specific circumstances file deletions are displayed as read events.

  • The system cannot find the file specified error (2) while scanning permissions.

  • Cloud Audit view is disabled after a subscription.

  • The TruncatePath advanced settings doesn't work in the snapshot generation.

  • Memory not disposed properly when scanning folders and files.

  • Unhandled exception checking the object access audit policy generates a service warning every half hour.

  • Changes in the access type or object type filters are not saved in the alerts.

  • A false rename access event could be registered under certain circumstances.

  • Unhandled exception displaying advanced permissions report.

6.2

July 29, 2020

New features

  • SQLite database as default database.

  • Ability to exclude events from not configured paths.

  • Ability to select your favourite reports in the dashboard.

  • New filters for simple/advanced permissions and file and folders properties reports.

  • New scheduled reports, simple/advanced permissions and file and folder properties, related to scheduled snapshots.

  • Ability to audit rename access events.

Improvements

  • Subscription to Cloud providers, by using an external browser.

Bugfixes

  • Unhanded exception when selecting to display the auto filter row option on the grid view of the permission reports.

  • The access event scan can be blocked if there is a snapshot running at the same time.

  • Unhanded exception getting the snapshot list just after removing one of them.

  • In the file/user views some icons can be removed.

  • Unhanded exception when clicking in top files/users in Statistics view.

  • Snapshot generation can get stuck in running state if there are some scan warnings.

  • In access reports the status icons are not according with the text.

  • Deadlock scanning events under certain conditions.

  • The service tries to connected to the Cloud provider when it shouldn't be.

  • Unhanded exception by clicking on the top 5 files but outside the bar and the text in the user view.

  • Activating the audit from the servers view can lost the IP address of the configured server.

  • The monitoring of the server stays disabled when disabling and enabling the audit on the servers view.

  • Scripts with commands which need privilege elevation cannot be executed as a no default administrators in the servers.

  • In the users view the filter doesn't work properly according to the date and hours selected.

  • Alerts are not triggered when the process filter is used.

  • Memory leak scanning AD groups.

  • Events scanned several times when RecordID needs to be truncated to be registered in a MS Access database.

  • On a Turkish platform, OneDrive auditing cannot be enabled.

6.1

November 25, 2019

New features

  • Ability to scan file/folder permissions and properties, on demand or scheduled.

  • New reports to analyse file/folder properties, basic permissions and advanced permissions.

  • New predefined reports for access events.

  • Supports SQLite database.

Improvements

  • Excluded hours from Alerts to allow configuration ranges between two different days.

  • Advanced setting UseFullPathForCloudProviders to allow to display in the path file the owner of the resource.

Bugfixes

  • Changes in the alert execution tab are not updated in other alerts using the same script.

  • Alert script execution doesn't work if there is an impersonation account and no working directory in the script settings.

  • Scheduling Denied access report doesn't keep predefined filters.

  • Communication error loading statistics view in a remote console.

  • Client IP addresses are shown in top 5 sources, of statistics view, instead of client names.

  • Access Evolution graph doesn't load all the figures if there are more than 500000 events.

  • Access denied when exporting from All Access view using a remote console with just Audit permission.

  • The MySQL 8.0 drivers ODBC are not supported.

  • In the view audited servers, a server is displayed as audit inactive, when the object access is disabled but it has been configured manually.

  • Disable the audit, in the server view, doesn't work when the advanced object access policy has been configured manually.

  • The servers view is not updated after opening the server details popup, due to a change in the object access policy check.

  • Unhandled exception thrown when loading statistics view.

  • Unhandled exception when clicking on the numbers of statistics view.

  • Web shortcuts in the Help menu do not work in some cases.

  • The console may hang when displaying the audited servers and there is much file access activity.

6.0

May 15, 2019

New features

  • Ability to audit accesses on files stored by OneDrive, Box, Dropbox and Google Drive.

  • New accesses on files stored by OneDrive, Box, Dropbox and Google Drive (Copy, Rename, Move, Shared etc...).

  • New Cloud Audit view in the console.

  • Ability to start a process when an alert is triggered.

  • New Subscription licenses.

  • Ability to remove service events in console Warnings view.

Improvements

  • Windows Servers and Windows Paths views.

  • Event Details view.

  • Sync process of Active Directory group members.

  • Console Statistics view.