tencent cloud

Release Notes

Download
Focus Mode
Font Size
Last updated: 2026-09-08 20:58:50
AI-Translated & Reviewed

September 2026

Update
Description
Release Date
Documentation
Tencent iOA Officially Released
Tencent iOA Zero Trust Security Management System is an integrated office security platform independently designed and developed by Tencent. Guided by the zero trust principle of "never trust, always verify", it centers on a single client and deeply integrates multiple security capabilities such as zero trust secure access, terminal management, terminal security protection, and software management, empowering enterprises to achieve secure, stable, and efficient office operations in any network environment.
Tencent iOA was officially released in September 2026. Covering everything from perimeter-less secure access to comprehensive terminal protection, and from sensitive data leakage prevention to integrated office terminal management, Tencent iOA reshapes enterprise security defenses with a unified capability matrix. It transforms security capabilities from fragmented and isolated to integrated and collaborative, helping enterprises build a secure, stable, and efficient office environment.
2026-09-08
Employee and Identity Management

Supports importing and creating organizational structures.
Provides multi-dimensional and differentiated authentication and security control capabilities. Authentication policies support flexible configuration of combinations of primary authentication, two-factor authentication, secondary authentication, and challenge authentication methods by organizational domain, department, custom group, and user dimension to meet the security requirements of different login scenarios.
Authentication policies support exempting two-factor authentication based on the primary authentication method, enforcing enhanced authentication for logins from non-frequently used devices, and dynamically assigning authentication factors based on abnormal behavior risk levels to balance security and user experience.
The client supports single sign-on (SSO) for third-party applications through OIDC ticket forwarding and self-signed user tickets. It also supports binding trusted identities with trusted devices, and allows you to set upper limits on the number of devices bound per account and the number of accounts bound per terminal to prevent credential abuse.
2026-09-08
Asset Management

Unified cross-platform terminal management: supports unified cross-platform management, seamlessly onboarding Windows, macOS, Linux, Android, and iOS terminals. The console enables unified policy delivery across all terminals and centralized presentation of asset status for each operating system.
Unified asset management: the terminal details page aggregates comprehensive information such as hardware, software, policies, security, and tasks, enabling closed-loop management of "policy-risk-log" on a single screen. IT admins can centrally manage and operate all network assets from a single entry point.
Software execution control: admins can quickly restrict non-compliant software from running by directly selecting and disabling it in the built-in software library under "Software Control - Software Behavior Control".
Software installation control: standardizes software installation channels from the source by integrating built-in software allowlists/blocklists under "Software Control - Installation Control", reducing security risks.
Terminal policy visibility: the terminal information list now includes an effective policy display and overview panel, presenting real-time operational metrics such as online status, compliance status, installed software quantity, and effective policy quantity. It supports click-through filtering to access details directly, eliminating the need for multi-page navigation during troubleshooting.
2026-09-08
Terminal Intrusion Prevention
As a core defense of terminal security, terminal intrusion prevention builds a multi-layered defense against ransomware and phishing for terminals through five key capabilities: virus detection, vulnerability remediation, real-time protection, ransomware protection, and anti-phishing. It comprehensively defends against malicious programs and advanced threats.
All business modules adopt a standardized closed loop of "risk discovery → policy configuration → task execution → log audit", providing a clear and intuitive operational path from risk perception to remediation audit. All operations and information for a business can be completed and viewed within a single menu page, effectively improving security operations efficiency.
At the task level, the scan task details display is optimized. Whether tasks are delivered from the console or triggered locally by the client, detection and remediation results can be viewed uniformly in the task list. Policy management in multi-platform environments is also simplified to ensure consistent security protection baselines across terminals running different operating systems and reduce the complexity of policy maintenance.
2026-09-08
Non-Border Access
Based on the zero trust concept, this solution enables employees to securely access internal business systems outside the company through connector reverse connections, service hiding, dynamic authorization, and encrypted transmission, without the need for VPNs or exposed ports, achieving unified secure access and cross-border acceleration in multi-cloud environments.
2026-09-08
Network Access Control
Supports identity authentication and permission management for enterprise network access.
Employee 802.1x authentication: supports certificate authentication, where the system delivers authentication credentials automatically, enabling seamless network access for employees.
Dynamic network permission delivery: supports delivering various permissions such as VLANs, VLAN groups, User Profiles, and ACLs to achieve fine-grained network access control.
Multi-scenario VLAN management: provides three dynamic VLAN switching options, including Guest VLAN (unauthenticated), Auth-Fail VLAN (authentication failed), and Critical VLAN (server failure), ensuring network availability and user experience.
MAB authentication for dumb terminals: supports MAC address authentication for IoT devices such as cameras and access control systems, and supports device grouping and custom Tag management.
Guest Portal authentication: supports multiple authentication methods including account password/SMS/QR code scanning, supports inviter verification, and records visitor phone numbers and visit reasons, providing visitors with a convenient network access channel.
2026-09-08
iOA Client Ops
The iOA Ops management module provides full-lifecycle client configuration and Ops control capabilities.
Client login settings support multi-dimensional authentication identity recognition configuration, including account recognition, phone number recognition, and email recognition, to meet the login requirements of different account systems.
Client policies support the delivery of policies such as self-protection, upgrade, module customization, and zero trust access configuration, enabling fine-grained and differentiated terminal control.
Personalization settings support brand definition through the Banner library, client icon display, help center customization, and enterprise branding display requirements. The client homepage supports delivering business resources and common tools, configuring business resource sites, and displaying them based on user authorization scopes across multiple systems including Windows, macOS, Linux, Android, and iOS. It also provides client operation log auditing capabilities to ensure full traceability of client Ops operations.
2026-09-08
System General Settings
The general system settings module provides feature configurations such as basic network configuration, admin permission management, alert and notification services, authorization management, upgrade settings, upload and download rate limiting, enterprise private network management, and system log cleanup, supporting comprehensive Ops and management of the iOA platform.
2026-09-08
-


Help and Support

Was this page helpful?

Help us improve! Rate your documentation experience in 5 mins.

Feedback