Table of Contents
Main features of version 5.7
- Collaboration Protection: the ESG inspection engines — antivirus, URL sandboxing and data-loss prevention — extended to Microsoft Teams one-to-one chats, group chats and channel posts. An offending message is blocked in place and the sender can open a policy tip naming the rule that matched.
Configured per Microsoft 365 tenant, served on a dedicated web endpoint with its own TLS certificate and worker pool. Available as a licensed add-on. - Threat Breakdown: a per-message report for any message classified as a threat, explaining the verdict instead of dumping scan fields: risk and spam confidence, sender identity, SPF, DKIM and DMARC in words, the correlated signals behind the verdict, the reconstructed attack chain, the matched rules, DLP and payload status, and prioritized recommended actions. The narrative and the attack chain are written by a language model running entirely on the appliance, so no message data leaves the box. Requires the medium resource profile or above.
- SAML Single Sign-On: SAML 2.0 as a per-domain authentication scheme, against Microsoft 365 / Entra ID, Google Workspace or any other SAML 2.0 identity provider, alongside local, IMAP, POP3, LDAP and the existing connectors. Login and single logout are always started by ESG and a signature is always required.
Version 5.7.0 (Sep 7, 2026)
Security
- Database encryption: encryption at rest now covers every table of the appliance databases
Features
- Blocked networks: the overview now names who blocked each network — LibraCyber IoC, DoS Protection or an administrator — says what can be done about each, and shows the reason for the block where one is known
- LibraCyber Support: the "Remote Support" page is renamed "LibraCyber Support" and now pairs the session form with a checklist on how to ask for support, including where to find the Ticket ID the connection requires; the link to open a ticket points to the LibraCyber Help Center
Improvements
- Email Continuity: more reliable rendering of HTML messages that declare a character set other than UTF-8
- Message details: clearer explanation when the live blocked URL lookup no longer finds anything listed
- Threat Breakdown: AI-generated sections are cached for twelve hours, and the cache is dropped whenever a new model is installed
- TLS settings: cipher grade options now state which TLS versions and ciphers each grade permits, with the full detail for all three grades in the page help
- Web UI MIME parser: upgraded mime-parser codebase to leverage security, DoS protection for CPU/memory usage, and text encoding handling
API
- ADD: new
/account-takeover-protection/policy-groupto manage ATP policy groups - ADD: new
/account-takeover-protection/policy-group-memberto manage policy group members - ADD: new
/saml-loginto obtain the SAML sign-on URLs for a login identifier - ADD: new
/tls-certificateto manage TLS certificate configurations, withupload,{id}/upload,generate,{id}/csrandappliance-serviceoperations - IMPROVED:
/oauth-loginreturns the SAML sign-on URLs too, alongside the OAuth2 ones - IMPROVED: the
clientIpfilter on/auditaccepts a CIDR network as well as a single address
Breaking changes
- Message and audit history is migrated and restored by a background job: the data tables are converted online after the upgrade by a background job, newest records first, so the message log and the audit log may not be complete right away — the older history reappears progressively over the following hours. Mail flow, new messages and new audit records are unaffected, and restoring a backup taken before the conversion completed simply lets the background job run again.
Version 5.6
All upgrades from previous versions are included. See the full release notes of Libraesva ESG version 5.6.