//

//

Introducing Saporo v4.2 - Built for Larger, More Complex Identity Environments

mock-up Advanced Query Engine
mock-up Advanced Query Engine

Saporo v4.2 expands how organizations can use Saporo across distributed teams, domains, and Windows fleets. This release introduces two major capabilities — Scope, which tailors data visibility by user or team without weakening Saporo’s graph analysis, and WinLocal, a new Windows local collection capability that brings endpoint-level permissions, weaknesses, and lateral movement paths into the attack-path model.

Together, these updates help security teams reduce identity risk at enterprise scale: more teams can work from the same Saporo environment, more Windows exposure becomes visible, and attack paths remain modeled end to end.

  • Scope-based visibility controls to restrict access by domains, tenants, and more.

  • WinLocal support to uncover local Windows misconfigurations, privileged access, session exposure, and lateral movement paths.

  • Expanded graph analysis with Windows-local relationships that show how attackers move from identities to individual machines.

  • Improved Explore workflows with richer graph interactions, better filtering, and more contextual investigation panels.

  • Profile theming and dark mode so users can tailor the Saporo interface to their working preferences.


One Saporo environment, controlled data visibility

Many organizations operate across multiple branches, business units, AD domains, or regional teams. Until now, giving these teams access to the same Saporo instance meant a tradeoff: share too much sensitive information, or split the work across separate environments.

Scope in Saporo v4.2 removes that tradeoff. Administrators can now assign allowed scopes to users directly from Settings > User Management. A user with no assigned scope keeps full visibility; a user with one or more assigned scopes works in Saporo while data outside their scope is obfuscated in the interface.


Privacy without losing attack-path accuracy

Scope is designed to protect what users see without breaking Saporo’s analysis. Out-of-scope data is masked in the interface, but it is not removed from the underlying graph. Saporo can still account for attack paths that start in one scope and end in another — essential in real enterprise environments where risk rarely stops at organizational boundaries.

Scoped users get a cleaner, safer working view. Security leaders retain the complete identity risk picture across domains and teams.

Scope-aware behavior spans findings, inventory, dashboards, reports, logs, Explore, graph visualizations, and related exports. Where unrestricted access could expose sensitive out-of-scope details, Saporo masks or restricts the data while preserving the integrity of the security model.


Visibility into the Windows risks attackers use every day

Attackers do not only move through domain-level permissions. They often start with one workstation or server, then use local administrator rights, weak remote access settings, cached credentials, scheduled tasks, and insecure protocols to move laterally. WinLocal brings those Windows-local risks into Saporo.

With v4.2, Saporo can collect and analyze local Windows configuration and access data, then connect it to the existing identity graph. Teams can see not only which identities exist in Active Directory or cloud directories, but how those identities interact with individual Windows machines.


What WinLocal helps uncover

  • Local administrators and other powerful local group memberships.

  • Users who have logged into specific machines, including active and historical session exposure.

  • Weak authentication and protocol configurations such as NTLMv1, SMB, WinRM, RDP, and PowerShell logging gaps.

  • Risky user rights assignments that can enable privilege escalation or lateral movement.

  • Suspicious or over-privileged scheduled tasks.

  • Domain Controller hardening issues such as risky local access, privileged group exposure, and Print Spooler exposure.

  • LAPS-backed access patterns, including modern per-host local administrator password management.


Windows-local data in the Saporo graph

WinLocal adds Windows-local relationships to Saporo’s graph model — local administration, Remote Desktop access, PowerShell Remoting, DCOM execution paths, backup privileges, remote SAM access, local group membership, and session history.

This is where WinLocal becomes more than a collector. It turns endpoint-level Windows exposure into attack-path intelligence teams can prioritize, investigate, and remediate inside Saporo.


Faster investigations, richer graph context

Saporo v4.2 strengthens the Explore experience with richer contextual blades, improved graph interactions, better query-builder controls, more useful node labels and tags, and refined filtering for graph and framework context. Users can save and reuse chart presets to quickly apply their preferred filters and visualizations.

For teams working with large identity graphs, these improvements make day-to-day investigation more efficient. Analysts can pivot through relationships, inspect connected objects, and understand why a path matters without leaving the exploration workflow.


A Saporo interface that adapts to how users work

Saporo v4.2 introduces profile-level theme support, including dark mode. Users can adjust the visual theme from their profile, making the product more comfortable for long analysis sessions, different lighting conditions, and personal preferences.

It matters operationally: analysts spend significant time in dense findings tables, graph views, dashboards, and reports. A cleaner, more adaptable interface reduces friction during investigation and remediation work.


More ways to operate Saporo at scale

v4.2 also includes a broad set of improvements that make the platform smoother to administer in complex environments — stronger findings and inventory workflows, better dashboard and reporting behavior under scoped access, last-login visibility in user management, expanded dynamic OIDC support, role-aware API key behavior, and updated licensing foundations for Core and Enterprise editions.

Under the hood, v4.2 adds collector reliability improvements, upgrade stability work, stronger validation, more consistent API behavior, and expanded detection coverage across Active Directory, ADCS, Azure, SMB, and Windows local configuration — plus hundreds of refinements across the full daily workflow.


Scale. Visibility. Control.

That’s Saporo v4.2 — built for larger, more hybrid, and more distributed identity environments.

Now available for all Saporo customers.

Scope can be managed from Settings > User Management. WinLocal can be configured as part of Saporo’s collection workflow — your Saporo Customer Success or Partner representative can help choose the deployment model that best fits your Windows environment, including least-privilege, domain account, or LAPS-based approaches.

6 minutes