Altiris ITMS 8.8.1 released

On February 9, 2026, Broadcom released version 8.8.1 of its IT Management Suite (ITMS 8.8.1). The release can now be installed via Symantec Installation Manager (SIM).
We are happy to assist you with updating to the new version. Please contact us.

These new features wer implemented with release 8.8.1:

New Symantec Management Platform Features

Checklist task token value separation enhancementsIn addition to the previously existing value separation markers sde (defines delimiter in results) and nvde (defines delimiter of name and value in source pairs), ITMS 8.8.1 introduces the new checklist task token separation marker, csvde, which is used to define a delimiter for source values.

Example:
CheckList:Csv|required=1|sde=+|csvde=?|nvde=~|source=Value 1~1?Value 2~2?Value 3~3
Output '1+2+3'
Ability to edit multiple security rolesRole Security Policies can now be created in Settings Notification Server Account Management Role Security Policies to automate granting or removing privileges for multiple roles at once.
Option to Restart System upon opening of maintenance windowA new option, Maintenance Window Startup Power Action added to maintenance window settings. This option performs a system restart when a maintenance window opens if a pending restart is detected to ensure that previous changes are applied to a device prior to executing other actions during the maintenance window.
Data Connector Support for 3rd party REST APIsData Connector component enhanced with ability to call REST APIs in third party products to extract data and then call ITMS’ REST APIs to insert such data into the ITMS database (or vice-versa).
Additional REST API methods to facilitate integration with external systems.Four new REST API methods were added to provide more flexibility in importing/exporting data to/from the ITMS database. These API methods can operate over multiple resources and data classes in one call, support multiple data formats (JSON, XML, CSV) as input and output, and match resources by GUID, name, resource type, etc.

/api/v1/ns/ResourceManagement/resourcedata/export
/api/v1/ns/ResourceManagement/resourcedata/export/ex
/api/v1/ns/ResourceManagement/resourcedata/import
/api/v1/ns/ResourceManagement/resourcedata/import/ex
Ephemeral certificates for CEM AuthenticationNewly introduced ephemeral certificates eliminate the need to regenerate CEM certificates (which could be burdensome given industry shift to 47-Day SSL/TLS Certificate validity by 2029): certificates are automatically generated by the Symantec Management Agent on each device as needed. Security is enhanced by reducing the exposure window and automatically rotating the certificates. Both permanent and ephemeral certificates simultaneously supported during transition (preference given to ephemeral).
Azure Key Vault SupportTasks executed under specific user accounts now support the real-time retrieval of passwords from Azure Key Vault (Entra), so that admin does not need to update tasks when there is a password change.
Prevent independently running tasks included in jobsThe new option, Grant Run Task in the Jobs permission set (in combination with disabled Run Task permission) provides the ability permit technicians to execute tasks within jobs, but not independently.
Schedule repeat configuration default values removedThe Schedule Repeat option now requires users to enter appropriate values for repeat frequency, rather than defaulting to repeat every minute. This reduces the possibility of accidentally creating a task that executes too frequently.
Customer Defined Token Values for tasksThe new task token type Task Input Token is introduced to provide an ability to select a value for tokens from a customer-defined dropdown list when running tasks and not require to manually type the values of these tokens each time they are used.
The Task Input Token can provide pre-defined values using a drop-down menu, a check box list, or a radio button select list.
The Task Input Token can be created from the main Tokens page in the SMP Console (Settings All Settings Notification Server Task Settings Tokens).
The Task Input Token can be used in the following tasks:

End User Notification Task
∙ All available Run Script tasks
Run SQL Query on Server
Write Entry to Server Log
Send Email
Database SupportSymantec Management Platform now supports Microsoft SQL Server 2025 for CMDB.
Support for SQL Server 2014 dropped in ITMS 8.8.1.
Support for IPv6-Only NetworksThe following components/functionality have been updated to support IPv6 only environments in ITMS 8.8.1:

∙ Notification Server
∙ Task Services
∙ Site Services
∙ Package Services
∙ Windows Agent (except P2P)
∙ ULM Agent
∙ Deployment Solution (including PXE server)
∙ Software Management Solution
∙ Patch Management Solution
∙ Inventory Solution (except agentless inventory)
∙ Cloud Enabled Management / Internet Gateway
∙ Time Critical Management

The following components/functionality do not support IPv6-only environments in ITMS 8.8.1 (IPv4 or hybrid IPv4/IPv6 environment supported):

∙ Network Discovery
∙ Pluggable Protocol Architecture (PPA)
∙ Real Time System Manager
∙ Monitor Solution (agentless monitoring)
∙ Workflow Solution
∙ Peer to Peer (P2P)
∙ Agentless Inventory
∙ Modern Device Management
Task Server to Notification Server tickleThis release introduces support for Task Server to Notification Server communication through web sockets.
This provides an optional alternative to the legacy tickle TCP/IP port requirement. The New Server to NS tickle strategy option is provided in the Task Server Settings configuration page to select the preferred approach, where Web socket, TCP/IP is the default value.
The default behavior will use a Web Socket connection for trickle first, and fall back to TCP/IP if necessary.
Package Server Assignment HEP optionThe Package Server Assignment HEP (Hierarchy Editable Property) option has been added to software packages to allow control of Package Server options in hierarchy replication.
You can access this option through the right-click context menu on package resource > Hierarchy Properties.

New Symantec Management Agent Features

Retrieve logs over CEM connectionA new task, Get Agent Troubleshooting Data , can retrieve log files from CEM-connected devices without the requirement to open the network port 445 for SMB traffic. Mini Support Package or Full Support Package retrieval options are also available.
New OS SupportThe following operating systems are now supported for the installation of the Symantec Management Agent and solution plug-ins:

Windows 11 25H2
MacOS 26 Tahoe
∙ Red Hat Enterprise Linux 9.710 and 10.1
∙ Oracle Linux 9.710 and 10.1
SUSE 16 (without Patch and Deployment at this moment)
Collect Computer Description inventoryBasic inventory capabilities are extended to collect data regarding the description of each device. Collected data is displayed in the Computer ViewResource Manager and Computers reports.

New Symantec Management Console Features

Report Viewer ModernizationA new UI framework has been introduced for out-of-the-box and custom reports in the Symantec Management Console. It provides the following new capabilities:
• Multi-Level Sort Order
• Filter on Values in Individual Columns
• Create Grouping from Column Headers
• The ability to save report output as PDFs
• Flexible and sophisticated graph and chart capabilities

A new core setting, ReportsModernDataViewByDefault allows administrators to revert to the legacy reporting framework if required.
Support for multiple Microsoft Entra tenants without Trust RelationshipMSPs are now provided with ability to create a single instance of ITMS that can integrate with multiple Entra tenants in a way that does not require end users to choose among multiple tenants when logging into the Software Portal or SMP Console.

New Inventory Solution Features

Collect BitLocker Data InventoryStandard inventory capabilities are extended to collect data regarding BitLocker. This new collected data is displayed in Resource Manager (BitLocker Info dataclass) and new BitLocker Status report.
Collect ODBC Data Source Name InventoryStandard inventory capabilities are extended to collect data regarding the names of ODBC Data Sources associated with Windows devices. Collected data is displayed in new ODBC DSN Information report.
File/Registry Baseline Inventory Functionality deprecatedFile Baseline and Registry Baseline inventory tasks are no longer available.
Collect Plug and Play Entities inventoryStandard inventory capabilities are extended to include the device name for each PnP device.
Collect Windows Features inventoryStandard inventory capabilities are extended to collect information about Windows Features from Windows Servers.
The collected data includes the Feature ID, its display name, and its status (Installed/Available/Removed). This information is stored in the new Srv Features Windows data class and is also available in the dedicated Windows Features report.

New IT Analytics Features

SQL Server 2025 Power BI Report Server supportMicrosoft has announced that there will be no new version of SQL Server Reporting Services (SSRS) for SQL Server 2025. Power BI Report Server is now the default reporting solution. Starting from version 8.8.1, the IT Analytics component supports the Power BI Report Server for data processing and display.

New Patch Management Solution Features

Installation of device drivers updatesIntegration with the Windows Update Agent is enhanced in this release, with the ability to install and update device drivers.
Limitation: after using this method to install new drivers on a workstation, that driver disappears from the assessment results and corresponding updates are not shown as applicable/installed in Patch Compliance reports.

See KB 184969 to learn how to enable integration with Windows Update Agent.

New Software Management Features

Software Imported from Microsoft Store viewA new out-of-the-box filter, Software Imported from Microsoft Store has been added to the Software Catalog view to display the list of APPXMSIX apps and bundles imported from Microsoft Store.
Support version ranges in APPX/MSIX detection rules to align with constant update of apps in Microsoft storeAPPX/MSIX detection rules are enhanced with ability to check for Package Family ID in addition to Full Package ID and specify a range for package version. The Microsoft Store Import Wizard is enhanced with an option to create an applicability rule to detect superseding versions.
Filter Microsoft Store Apps by MarketApp Market selection added to the Microsoft Store Import Wizard (previously only US was supported).
Software Normalization rules updatedOut-of-the-box Software Catalog resources used for software normalization of software identified in the environment are updated with the recent versions of software. Additional resources could be imported using Settings Software Data Provider Providers Software Catalog Data Provider UI.
Combine multiple publications on single tile in Software PortalNew Group publications on the same tile in Software Portal option is added to the Software Publishing tab of the software resource page and Select Software step of Software Publication wizard.
It allows to you to combine all specified command lines for better organization of actions possible for this software in Software Portal (including all available install, repair and uninstall options). The Manage Publications page is updated with Grouping filter to see All, grouped, or not grouped publications.
Relational operators support for version evaluation in Windows version ruleThe Software Management Windows version inventory rule functionality has been updated to support relational operators (>, <, >=, <=) for version evaluation. You can also specify a range of versions by using a combination of two rules.

New Workflow Solution Features

Microsoft Entra authentication support in Workflow Process Manager portalWorkflow Process Manager component of ITMS enhanced to support multi-factor authentication using Microsoft Entra in the same manner as the SMP console and Software Portal.

This whitepaper is available here.

New Symantec Installation Manager Features

Symantec Installation Manager licensing changesInstalling or upgrading to ITMS version 8.8.1 or newer requires an active license, to be provided in Symantec Installation Manager (SIM). The previous built-in 30-day evaluation functionality is no longer supported.
Customers interested in evaluating the product must work with their Broadcom sales team or their Broadcom partner to request an NFR (Not for Resale) license.
Symantec Installation Manager 8.8.1 does not provide the ability to automatically upgrade to future versions of SIM. Users are notified to download an upgraded version of SIM through the Broadcom support portal.

New Deployment Solution Features

WebDAV requirement eliminatedWebDAV (Web Distributed Authoring and Versioning) is no longer required for Deployment solution functionality on SMP Server and Site Servers and can be uninstalled or disabled on corresponding IIS servers.

ITMS 8.8.1 also addresses various fixed issues and known issues, which you can find in the original release notes.

Release Notes and User Guides

The release notes and other useful documents for Altiris can be conveniently found at:

Altiris links & downloads

As with all updates, there are a few things to consider, especially if you are running multiple clients and servers. We have profound experience in this area and would be happy to advise you on updating to the latest version. Feel free to contact us.