> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getprimo.com/llms.txt
> Use this file to discover all available pages before exploring further.

# March

> Product updates from March 2026

<Update label="March 27, 2026">
  ## Workspaces

  You can now organize multiple companies under a single workspace. This lets managed service providers and multi-entity organizations manage all their companies from one place, with the ability to rename workspaces and switch between them easily.
</Update>

<Update label="March 25, 2026">
  ## Bootstrap token management

  Bootstrap token status now syncs and is tracked from your devices. You can see whether a token has been escrowed, and a warning appears when an admin action requires a valid token — helping you avoid blocked operations during device management.

  ## IdP end-user authentication for MDM

  A new toggle in [MDM settings](/mdm/settings) lets you enable identity provider-based authentication for end users during enrollment. This connects your IdP to the enrollment flow so employees authenticate with their existing credentials.
</Update>

<Update label="March 23, 2026">
  ## Google Workspace data mapping

  You can now map employee attributes from Google Workspace, just like with other HR sources. Configure which fields sync and set the cadence for how often data is pulled in.

  ## Default SaaS deprovisioning date

  A new setting lets you define a default deprovisioning date for SaaS applications during offboarding. This saves time when processing employee departures by applying your preferred timeline automatically.
</Update>

<Update label="March 20, 2026">
  ## Multiple OS update controls per platform

  You can now create more than one [OS update control](/mdm/policies/enforce-minimum-os-version) per platform. This means you can set different update policies for different device groups -- for example, a stricter policy for engineering devices and a more relaxed one for shared devices.

  ## Windows Autopilot with Entra ID

  You can now configure [Windows zero-touch deployment](/mdm/zero-touch/zero-touch-windows) with Microsoft Entra ID. Manage Autopilot settings directly from the dashboard for a smoother Windows enrollment experience.

  ## New API endpoints

  New public API endpoints are available to create devices and employees programmatically. Use these to integrate Primo with your existing provisioning workflows. See the [API reference](/api/create-primo-api-key) for details.
</Update>

<Update label="March 19, 2026">
  ## Custom OS update profiles

  You can now upload custom OS update configuration profiles for more granular control over how and when updates are delivered to your fleet.

  ## Saved views on identities

  The [Identities](/saas/identities) page now supports saved views, so you can create and switch between filtered views tailored to your workflow.

  ## Device group label sync

  Device groups now sync their labels with FleetDM, keeping your grouping consistent across the dashboard and your underlying MDM infrastructure.
</Update>

<Update label="March 17, 2026">
  ## USB blocking mode for Windows

  The [USB storage blocking](/mdm/policies/usb-storage-blocking) control now supports configurable modes on Windows, letting you choose between fully blocking or selectively allowing USB storage devices.

  ## SaaS contract management via API

  You can now manage SaaS contracts through the [Primo API and MCP server](/get-started/primo-mcp-server), enabling programmatic control over your SaaS contract data.
</Update>

<Update label="March 16, 2026">
  ## Offboarding email reminders

  Employees approaching their offboarding date now receive an email notification 30 days before departure, giving them time to prepare and wrap up access to company tools.

  ## Identity audit log

  A new audit log panel is available on identity records, so you can track changes and actions taken on each identity over time.
</Update>
