You can now organize multiple companies under a single workspace. This lets managed service providers and multi-entity organizations manage all their companies from one place, with the ability to rename workspaces and switch between them easily.
Bootstrap token status now syncs and is tracked from your devices. You can see whether a token has been escrowed, and a warning appears when an admin action requires a valid token — helping you avoid blocked operations during device management.
A new toggle in MDM settings lets you enable identity provider-based authentication for end users during enrollment. This connects your IdP to the enrollment flow so employees authenticate with their existing credentials.
You can now map employee attributes from Google Workspace, just like with other HR sources. Configure which fields sync and set the cadence for how often data is pulled in.
A new setting lets you define a default deprovisioning date for SaaS applications during offboarding. This saves time when processing employee departures by applying your preferred timeline automatically.
You can now create more than one OS update control per platform. This means you can set different update policies for different device groups — for example, a stricter policy for engineering devices and a more relaxed one for shared devices.
You can now configure Windows zero-touch deployment with Microsoft Entra ID. Manage Autopilot settings directly from the dashboard for a smoother Windows enrollment experience.
New public API endpoints are available to create devices and employees programmatically. Use these to integrate Primo with your existing provisioning workflows. See the API reference for details.
The USB storage blocking control now supports configurable modes on Windows, letting you choose between fully blocking or selectively allowing USB storage devices.
Employees approaching their offboarding date now receive an email notification 30 days before departure, giving them time to prepare and wrap up access to company tools.