The BigFix Team is pleased to announce the release of Version 11 Patch 7 (11.0.7.61) of the BigFix Platform. This release strengthens integrations and data access, extends compliance coverage, improves performance at scale, and broadens platform support — helping your team manage a more diverse, secure, and efficient environment. The main features in this release are as follows:
Custom content, managed like code!
- External Repository Sites: BigFix can now connect to the Git source control system and use it as an “External Repository Site”. This provides a single, unified source of truth for custom content with clear cross-environment history and authorship tracking. It brings BigFix in line with modern DevOps practices by working with CI/CD and automation pipelines, and strengthens governance with better visibility into how content evolves. For more information please see External Repository Sites.
Bring Identity Provider users and computers information into BigFix!
- User-based management: BigFix is now able to retrieve computer data from Active Directory and Microsoft Entra ID, such as the User associated with the Computer, the User Groups and Computer Groups it belongs to, and more. This data is made available as computer properties, allowing BigFix operators to achieve user-centric endpoint management, advanced dynamic targeting, and reporting. This simplifies governance and aligns enterprise instruments to meet business goals. For details, see User-based management.
Performance at scale!
-
Boosted BigFix Relay Scale: 11.0.7 Relays on Windows and RHEL implement architecture improvements to allow up to 20000 endpoints connected to a single Relay, whether it is non-authenticating or authenticating. This is up to a 4x improvement over previous figures! Also Persistent Connections are boosted on the same Relays: up to 20000 per Relay, a 20x improvement over the past limit. Note: BigFix 11.0.7 Root Server and Relay on RHEL now require RHEL 7.6 as minimum OS version. For more information please see BigFix Performance & Capacity Planning Resources.
-
Faster client performance on multi-core systems: A new client setting (_BESClient_Resource_ScaleWorkTimeWithCPUCores, disabled by default) lets the BigFix Client take fuller advantage of available CPU cores, helping actions and evaluations complete faster on modern multi-core hardware. For details, see List of settings and detailed descriptions and BigFix Performance & Capacity Planning Resources.
-
Faster onboarding and operation for large cloud deployments: The Plugin Portal now evaluates Fixlets, properties, and actions concurrently across computers, decouples computer registration from execution, and batches registration requests to the BigFix Server. Together, this cuts onboarding time in large-scale cloud environments and keeps policy enforcement timely even as new virtual machines register. In addition, one Plugin Portal now supports up to 100000 cloud devices. For more information please see BigFix Performance & Capacity Planning Resources.
-
Improved Console search engine: Searching objects in the Console (Fixlets/Tasks, Baselines, Analyses, Actions) is now more efficient, contributing to improving user experience.
Compliance and security, reinforced!
- FIPS 140-3 readiness: Organizations operating in regulated or government environments can now enable FIPS 140-3 mode, helping meet current federal cryptographic standards. For details, see FIPS 140-3 cryptography in the BigFix environment and Configuring FIPS 140-3 on the BigFix Server. BigFix encryption module is also FIPS 140-3 certified! Cryptographic Module Validation Program | CSRC
- Automatic protection for idle consoles: A new setting lets you configure a BigFix Console lock timeout, so unattended, logged-in sessions are automatically locked — helping enforce security policy with no extra process required. For details, see Setting the BigFix Console lock timeout.
- Stronger download integrity: Action scripts that fetch files (“add prefetch item” and “prefetch”) now support SHA-512, giving teams a stronger integrity-checking option for downloaded content. For details, see add prefetch item and prefetch.
- Tighter control over MCP access: A new “blockIncomingMCPRequests” option on the BigFix root server lets administrators disable incoming MCP requests, giving security teams a simple control to restrict this interface where it isn’t needed. For details, see Installing and configuring BigFix Platform MCP Server.
More resilient administration!
- Preventing conflicting admin operations: BigFix now blocks more than one instance of BESAdmin from running at the same time on a given computer, reducing the risk of conflicting configuration changes and administrative errors. For details, see BESAdmin Windows GUI, BESAdmin Windows Command Line and BESAdmin Linux Command Line.
Expanded platform support!
BigFix Agent now supports additional platforms, extending consistent management and visibility to more of your modern infrastructure footprint:
- New! Linux distributions on ARM processor:
- Ubuntu 24.04, 26.04 LTS ARM 64
- Red Hat Enterprise Linux 9, 10 ARM 64
- Debian 13 ARM 64
- macOS 27 (Golden Gate) ARM 64
- Ubuntu 26.04 LTS x86 64-bit
- VIOS 4.1.1, 4.1.2 PPC 64-bit on Power 11
- AIX 7.2, 7.3 PPC 64-bit on Power 11
- Red Hat Enterprise Linux 9, 10 PPC 64-bit LE on Power 11
- SUSE Linux Enterprise Server (SLES) 15, 16 PPC 64-bit LE on Power 11
Inspector changes
- New inspector types named “idp group” and “idp user” were added to return information about the groups and users associated with a computer joined to an Identity Provider (IdP). For details, see idp group and idp user.
- New properties were added to the “cryptography” inspector. These properties return whether BigFix components in the deployment should operate in FIPS 140-2 or FIPS 140-3 mode. List of added properties:
- fips_140_2 mode of
- fips_140_3 mode of
For details, see cryptography.
- New properties were added to the “license” inspector. These properties return whether BigFix components in the deployment should operate in FIPS 140-2 or FIPS 140-3 mode. List of added properties:
- fips_140_2 mode of
- fips_140_3 mode of
For details, see license.
- New properties were added to the “client” inspector. These properties return various information if the computer is joined to an Identity Provider (IdP). List of added properties:
- idp directory type of
- idp distinguished name of
- idp group of
- idp id of
- idp display name of
- idp sam account name of
- idp user of
For details, see client.
- A new cast named “as xml string” was added to the “bes action”, “bes computer group”, “bes fixlet” and “bes property” session inspectors to convert the specified BES object to an XML string. The new cast was introduced exclusively for the BigFix Console and BigFix Explorer. It is not supported in Web Reports. For details, see bes action, bes computer group, bes fixlet and bes property.
Upgraded libraries, binaries and 3rd party tools
- The libgit2 library was introduced at version 1.9.7.
- The boost library was upgraded to Version 1.91.0.
- The libcURL library was upgraded to Version 8.22.0.
- The OpenSSL library was upgraded to Version 3.5.8.
Additional information about this release
- The standalone BigFix tools are published under the 11.0 Utilities section in the BigFix Enterprise Suite Download Center.
- A Non-Functional Requirements checklist, covering both performance and security management of your BigFix deployment, is available at BigFix Performance & Capacity Planning Resources.
References
- See the full technical changelist.
Pre-Upgrade Considerations
Important considerations to keep into account before upgrading to BigFix Platform Version 11 are:
- BigFix Version 10.0.7 is the minimum version supporting the upgrade of the BigFix server components to Version 11.
- You must enable the “Enhanced Security” in the BESAdmin tool before upgrading BigFix Platform to Version 11.
- The minimum TLS supported protocol in BigFix v11 is TLS 1.2.
- The SHA1 hashing algorithm for content and action signature will no longer be supported. SHA1 is still supported for file download in actionscript. For details, see BigFix Platform V11 Overview Page.
- The msodbcsql18 RPM package is a prerequisite for the Server components on Linux systems. This applies to installations with an MSSQL database.
- For detailed information on the specific changes to minimum supported versions of operating systems and databases for BigFix 11, see Detailed system requirements.
- Before getting started with the upgrade process, stop any active application that is connected to the BigFix database (such as Web Reports, WebUI, BigFix Inventory, or BigFix Compliance).
Useful links
- BigFix downloads and release information.
- BigFix 11 Platform Documentation.
- Upgrade considerations.
- Detailed system requirements.
Upgrade Fixlets are available in BES Support version 1516 (or later).
— HCL BigFix — Platform Team