v4.1 Release Notes
v4.1.0 — September 2026
Section titled “v4.1.0 — September 2026”This release brings password management into the admin console, makes Microsoft 365 setup dramatically shorter, and refreshes the sign-in experience for returning users.
Password Management
Section titled “Password Management”Password management is a new paid add-on. Once BlokSec enables it for your organization, a Passwords section appears in the admin console, alongside a Launchpad for one-click access to saved credentials.
- Credential vault. Store, organize and launch the credentials your team still needs for sites that don’t support modern sign-in
- Built-in two-factor codes. Add a 2FA seed to any credential and BlokSec generates the six-digit codes for you, so you no longer need a separate authenticator app for those sites. Seeds can be replaced or removed at any time
- Password health. BlokSec now identifies passwords reused across multiple credentials and flags them for attention. Health status updates as you make changes rather than on a fixed schedule, so the view always reflects reality
- Launchpad. A read-first view of your credentials that opens the target site and signs you in, with editing behind an explicit action so nothing changes by accident
Microsoft 365 and Entra ID
Section titled “Microsoft 365 and Entra ID”Setting up Microsoft 365 federation used to mean several passes through the Azure portal. It is now a three-step wizard on a single tab.
- One admin consent. The wizard asks for administrator consent once instead of at multiple points in the process
- One Microsoft Integration panel. Everything for a Microsoft 365 application — federation status, domain configuration and provisioning — now lives in a single panel on the application page rather than being spread across tabs
- Import your existing users. Bring your Microsoft 365 or Entra ID users into BlokSec directly from the admin console. Review the list before committing, match people who already exist in BlokSec instead of creating duplicates, and optionally send invitations as part of the import
- Safer imports. Imports verify each change against Microsoft before reporting success, and can be rolled back if something goes wrong partway through
Signing In
Section titled “Signing In”- Remembered accounts. The sign-in page now offers the accounts you’ve used on that device, so returning users can pick rather than retype
- Fewer prompts across applications. Once you’ve signed in, moving between applications that use BlokSec no longer asks you to identify yourself again during the same session
- Smoother handoff from applications. When an application already knows who you are, it can pass that along and the sign-in page fills it in for you. You keep the final say — the page no longer submits on your behalf before you’ve had a chance to review it
- Several layout and keyboard-focus fixes on the sign-in page, including on SAML sign-in
Admin Console
Section titled “Admin Console”- Applications and accounts. Clearer applications table, corrected Microsoft attributes on account pages, and consistent initials avatars where a logo isn’t available
- Application templates. Fixed templates in the marketplace that listed the wrong protocol or marked optional configuration as required
- Branding on sign-in. The sign-in page now shows the name and logo of the organization that owns the application
Reliability and Security
Section titled “Reliability and Security”- Resolved an issue where some accounts could be left with limited access after sign-in
- Continued hardening across our services, including tighter separation between organizations and stricter validation of incoming requests
- Improvements to how vault data is protected at rest