Safeguard 9.0 by One Identity is now available, built around three things privileged access teams care about most: less infrastructure to manage, a stronger case to bring to auditors, and coverage that reaches further into the systems your teams already rely on. Here's what's new.
Less hardware and licensing to manage
For years, appliance refreshes relied on the vendor. Safeguard customers also had to source and renew their own Windows license. Safeguard 9.0 changes that, as it now runs on a Windows 11 Long-Term Servicing Channel (LTSC) base operating system with the license embedded and pre-installed, and Privileged Sessions move to Ubuntu 24.04 LTS. Both are hardware-agnostic, so you can deploy on hardware that meets the system requirements, with validated performance available on current Dell PowerEdge and HPE ProLiant generations.
Day-to-day operation gets lighter too. The part of Safeguard that manages and records privileged sessions no longer needs a separate license file just to keep working, and software updates install faster with less disruption. Less to buy, less to track, and fewer maintenance windows to negotiate.
A security policy you can put in front of an auditor
Compliance frameworks keep raising the bar on encryption standards and Safeguard 9.0 meets it. The platform now supports Transport Layer Security (TLS) 1.3 and adds a cipher selector that lets you set exactly which ciphers are allowed, so instead of accepting a fixed, generic list, you can show auditors a policy you defined and enforce yourself. Older systems that haven't caught up yet still connect safely, so nothing breaks during the transition.
The session management side of Safeguard also adds broader protection against the Terrapin attack. Stronger algorithms come by default, with a documented path for the legacy peers that cannot be upgraded yet. The result is a named, enforceable cryptographic policy you can put in front of an auditor instead of a fixed list you have to explain.
Less standing privilege, fewer blind spots
A key element of Zero Trust is the removal of standing privilege, and this release gives you a further enablers. Safeguard 9.0 makes this easier: by elevating a group membership just-in-time (JIT) for a single access request and demote it afterward, but scoped to a specific asset rather than granted everywhere the group applies. The standing-privilege footprint shrinks with no extra accounts or groups to manage.
Coverage gets broader too. Safeguard 9.0 adds account discovery for ESXi hosts, which closes a common blind spot in the virtual estate that usually gets filled by manual tracking. Safeguard 9.0 will also manage remote desktop access using an account from Microsoft's cloud identity service (Entra ID), with the password and multi-factor authentication still safely stored and managed by Safeguard. Teams moving their identity systems to the cloud no longer have to choose between that move and keeping remote access properly controlled.
A first look at AI-assisted support
Safeguard 9.0 also introduces a built-in assistant in the web interface. Administrators can ask configuration and troubleshooting questions directly in the product instead of searching documentation or opening a support ticket for something routine. It's a useful convenience on its own, and the first step in a broader effort to build AI assistance into Safeguard through 2026.
Learn more
Full details on every feature are in the release notes. If you'd like to talk through what Safeguard 9.0 means for your environment, your One Identity team is ready to help. Connect with us here.