IT Portal 4.6.41 Beta - IT Glue & AD Import, More Integrations, and a Big Reliability Pass

Beta

Overview

This is the running changelog for our 4.6.41 beta, covering everything since the 4.6.27 release. We update this post roughly every two weeks as new builds land, so check back for the latest. This cycle is headlined by two brand-new migration/import tools, a wave of integration work, and a deep reliability pass on credentials, access control, and the ongoing .NET Core backend migration.

How to beta test 4.6.41

Cloud customers: Go to Admin → Settings and enable testing. The next day, once testing is active, a dedicated testing site will be listed for you — open it to try the beta against a copy of your own database. Your live portal is never touched.

On-premise customers: Please only beta test with the guidance of our support team. Some betas apply schema changes, and depending on the build, rolling back may not be straightforward. Reach out to [email protected] before you begin and we'll help you test safely.

New Migration & Import Tools

Migrate from IT Glue — A free, built-in importer brings your IT Glue export directly into IT Portal — organizations, contacts, sites, devices, passwords, knowledge base articles, and flexible assets. It maps IT Glue's flex-asset columns onto the fields classic IT Portal already uses, pulls embedded passwords and 2FA secrets in with the records they belong to, imports SSL certificates, and lets you choose exactly which organizations to bring over. Long steps run as background jobs and imports are resumable, so a large migration keeps going even on a slow connection, and runs on cloud with no special SQL rights.

Active Directory & device-agent import — A new JSON device agent imports from Active Directory — contacts, computers, sites, subnets, and groups — and supports offline upload and remote WMI collection. The agent runs in either RMM or device-import mode, dedupes machines by their AD objectGUID, and skips already-imported records on a refresh so repeat runs stay clean. The import honors the same options as the classic AD importer, with per-machine logging so you can see exactly what happened.

Integrations

N-Central — New N-Central device sync with a configurable device-matching strategy and an async import pattern, plus detailed HTML sync logging so you can see what matched, what imported, and what failed.

We also put real work into making existing integrations more reliable:

  • SyncroMSP — Per-device subnet assignment is now isolated, and the nightly sync no longer crashes on tenants with orphaned contact rows or unmapped customers.
  • Autotask — The two-way push now actually writes back, contact sync typos are fixed, and company resync is hardened (and sends the correct ClientID).
  • ConnectWise — Object and company saves no longer fail on tenants using two-way sync or when a ConnectWise field is NULL.
  • Datto — Fixed JSON double-encoding and stale device-mapping refreshes.
  • Atera — The nightly sync is hardened against partial page fetches and null payloads.
  • Domotz — Fixed a NULL subnet-size import abort and brought IP import to classic parity.
  • SolarWinds — Full handler audit fixing Portal5-vs-classic parity defects.
  • Itarian — Fixed a nightly-sync abort when the administrator row couldn't be loaded.
  • Office 365 — Fixed a device-import timeout and a TemplateAdmin NULL error.

Credentials & Passwords

This release includes a focused pass on credential integrity, so nothing you save gets quietly lost or mangled:

  • Full UTF-8 / non-ASCII support — Credentials containing non-ASCII characters are now accepted and preserved instead of being corrupted on save, and ASCII credentials encrypt with AES rather than the old unreadable format.
  • Save credentials without a username — A lone password or single field no longer blocks a save, and blank passwords are allowed where your policy permits.
  • Re-import missing passwords — An insert-only re-import mode safely backfills credentials that went missing, without overwriting what's already there.
  • Additional credentials — Fixed delete returning an empty response, a TOTP 400 on single-field credentials, QR auto-clone behavior, and an issue that collapsed imported rows into a single record.
  • Field password reveal — Restored the endpoint behind field-password reveal (no more 404s), and fixed sharing credentials after creation.
  • Credential visibility — Rows show on view while reveal stays correctly gated by access control, and a popup now appears on access denial instead of a silent failure.

Security & Access Control

  • Row-level security throughout — Tenant-connection SQL now routes through RLS views instead of base tables, and draft/note saves and public-password lookups resolve the correct tenant.
  • Tighter ACL enforcement — Fixed "All Sites" access unexpectedly granting objects that have no site, enforced company-scoped "All <Type>" global deny rules, and stopped internal ACL diagnostics from leaking into access-denied responses.
  • MFA-gated password resets — Forced-reset redirects now sit below the MFA gates, and the reset token is withheld until multi-factor is satisfied.
  • Encryption hardening — Internal string constants are no longer decrypted at runtime, and a custom encryption key is validated against the session key before it's saved.

Admin, Branding & Usability

  • Login background image — Upload a custom background image for your login screen, served to anonymous visitors.
  • Per-customer favorites — Mark favorites per customer, with a new "Show In Global Dashboard" toggle to surface them where you want them.
  • Global Search CLI toggle — A new site option (with an admin toggle and confirmation) lets you enable or disable the Global Search command line.
  • Template fields as grid columns, everywhere — Facilities, Cabinets, IP Networks, and Contacts grids now show template-field columns too, matching the other object types.
  • Notes & pop-ups — Note acknowledgements are honored, the default audience is now "All," and pop-up frequency and the tag-triggered "new" flag behave correctly.
  • Knowledge base — Fixed the markdown editor deleting an article's body on load, and scoped the subcategory dropdown to the selected category.
  • Agreements — Vendor, expiration, and issue dates now auto-populate on domain and SSL agreements, and expiry notifications are re-armed reliably.

Backend Modernization Update

The migration from our legacy Classic ASP backend to the modern .NET Core API continues. In this cycle the Pulseway, SolarWinds, and Meraki admin screens were moved onto Portal5 endpoints, the Password List now loads in pages instead of one large request, and more datagrids, detail views, and security endpoints were migrated and de-duplicated for faster, lighter page loads. Dozens of smaller fixes landed across device dropdowns, access logs, document/image handling on S3 cloud tenants, and change-control notifications.

Looking Ahead

We remain on track to have the complete backend fully migrated to .NET Core by the end of the year. This post will keep growing through the 4.6.41 beta — if something you test doesn't behave the way you expect, or there's a migration source or integration you'd like us to prioritize, tell us at [email protected].

Author Bio
Leslie Salvan

Leslie Salvan

Leslie Salvan is the Social Media Manager and SEO Lead at IT Portal, where she shapes the brand's digital presence and drives strategic growth across multiple platforms. With a strong focus on content clarity, search performance, and community engagement, she helps connect IT teams to smarter documentation solutions.