BigFix Platform 11.0 Patch 7 is now available!

The BigFix Team is pleased to announce the release of Version 11 Patch 7 (11.0.7.61) of the BigFix Platform. This release strengthens integrations and data access, extends compliance coverage, improves performance at scale, and broadens platform support — helping your team manage a more diverse, secure, and efficient environment. The main features in this release are as follows:

Custom content, managed like code!

  • External Repository Sites: BigFix can now connect to the Git source control system and use it as an “External Repository Site”. This provides a single, unified source of truth for custom content with clear cross-environment history and authorship tracking. It brings BigFix in line with modern DevOps practices by working with CI/CD and automation pipelines, and strengthens governance with better visibility into how content evolves. For more information please see External Repository Sites.

Bring Identity Provider users and computers information into BigFix!

  • User-based management: BigFix is now able to retrieve computer data from Active Directory and Microsoft Entra ID, such as the User associated with the Computer, the User Groups and Computer Groups it belongs to, and more. This data is made available as computer properties, allowing BigFix operators to achieve user-centric endpoint management, advanced dynamic targeting, and reporting. This simplifies governance and aligns enterprise instruments to meet business goals. For details, see User-based management.

Performance at scale!

  • Boosted BigFix Relay Scale: 11.0.7 Relays on Windows and RHEL implement architecture improvements to allow up to 20000 endpoints connected to a single Relay, whether it is non-authenticating or authenticating. This is up to a 4x improvement over previous figures! Also Persistent Connections are boosted on the same Relays: up to 20000 per Relay, a 20x improvement over the past limit. Note: BigFix 11.0.7 Root Server and Relay on RHEL now require RHEL 7.6 as minimum OS version. For more information please see BigFix Performance & Capacity Planning Resources.

  • Faster client performance on multi-core systems: A new client setting (_BESClient_Resource_ScaleWorkTimeWithCPUCores, disabled by default) lets the BigFix Client take fuller advantage of available CPU cores, helping actions and evaluations complete faster on modern multi-core hardware. For details, see List of settings and detailed descriptions and BigFix Performance & Capacity Planning Resources.

  • Faster onboarding and operation for large cloud deployments: The Plugin Portal now evaluates Fixlets, properties, and actions concurrently across computers, decouples computer registration from execution, and batches registration requests to the BigFix Server. Together, this cuts onboarding time in large-scale cloud environments and keeps policy enforcement timely even as new virtual machines register. In addition, one Plugin Portal now supports up to 100000 cloud devices. For more information please see BigFix Performance & Capacity Planning Resources.

  • Improved Console search engine: Searching objects in the Console (Fixlets/Tasks, Baselines, Analyses, Actions) is now more efficient, contributing to improving user experience.

Compliance and security, reinforced!

More resilient administration!

Expanded platform support!

BigFix Agent now supports additional platforms, extending consistent management and visibility to more of your modern infrastructure footprint:

  • New! Linux distributions on ARM processor:
    • Ubuntu 24.04, 26.04 LTS ARM 64
    • Red Hat Enterprise Linux 9, 10 ARM 64
    • Debian 13 ARM 64
  • macOS 27 (Golden Gate) ARM 64
  • Ubuntu 26.04 LTS x86 64-bit
  • VIOS 4.1.1, 4.1.2 PPC 64-bit on Power 11
  • AIX 7.2, 7.3 PPC 64-bit on Power 11
  • Red Hat Enterprise Linux 9, 10 PPC 64-bit LE on Power 11
  • SUSE Linux Enterprise Server (SLES) 15, 16 PPC 64-bit LE on Power 11

Inspector changes

  • New inspector types named “idp group” and “idp user” were added to return information about the groups and users associated with a computer joined to an Identity Provider (IdP). For details, see idp group and idp user.
  • New properties were added to the “cryptography” inspector. These properties return whether BigFix components in the deployment should operate in FIPS 140-2 or FIPS 140-3 mode. List of added properties:
    • fips_140_2 mode of
    • fips_140_3 mode of

For details, see cryptography.

  • New properties were added to the “license” inspector. These properties return whether BigFix components in the deployment should operate in FIPS 140-2 or FIPS 140-3 mode. List of added properties:
    • fips_140_2 mode of
    • fips_140_3 mode of

For details, see license.

  • New properties were added to the “client” inspector. These properties return various information if the computer is joined to an Identity Provider (IdP). List of added properties:
    • idp directory type of
    • idp distinguished name of
    • idp group of
    • idp id of
    • idp display name of
    • idp sam account name of
    • idp user of

For details, see client.

  • A new cast named “as xml string” was added to the “bes action”, “bes computer group”, “bes fixlet” and “bes property” session inspectors to convert the specified BES object to an XML string. The new cast was introduced exclusively for the BigFix Console and BigFix Explorer. It is not supported in Web Reports. For details, see bes action, bes computer group, bes fixlet and bes property.

Upgraded libraries, binaries and 3rd party tools

  • The libgit2 library was introduced at version 1.9.7.
  • The boost library was upgraded to Version 1.91.0.
  • The libcURL library was upgraded to Version 8.22.0.
  • The OpenSSL library was upgraded to Version 3.5.8.

Additional information about this release

References

Pre-Upgrade Considerations

Important considerations to keep into account before upgrading to BigFix Platform Version 11 are:

  • BigFix Version 10.0.7 is the minimum version supporting the upgrade of the BigFix server components to Version 11.
  • You must enable the “Enhanced Security” in the BESAdmin tool before upgrading BigFix Platform to Version 11.
  • The minimum TLS supported protocol in BigFix v11 is TLS 1.2.
  • The SHA1 hashing algorithm for content and action signature will no longer be supported. SHA1 is still supported for file download in actionscript. For details, see BigFix Platform V11 Overview Page.
  • The msodbcsql18 RPM package is a prerequisite for the Server components on Linux systems. This applies to installations with an MSSQL database.
  • For detailed information on the specific changes to minimum supported versions of operating systems and databases for BigFix 11, see Detailed system requirements.
  • Before getting started with the upgrade process, stop any active application that is connected to the BigFix database (such as Web Reports, WebUI, BigFix Inventory, or BigFix Compliance).

Useful links

Upgrade Fixlets are available in BES Support version 1516 (or later).

— HCL BigFix — Platform Team

1 Like