Parallels RAS Core
Parallels RAS Core v21.0.0-26247 (11 November 2025)
- Security Fix: Upgraded to OpenSSL 3.0.17.
- Security Fix: Upgraded .NET to 8.0.18.
- Security Fix: Ensure only the public key is exported in the Registration.crt file, which is required to verify the launch-token signatures in case using SAML SSO.
- New: Add support for capturing the public IP address of client connections and passing it as a RADIUS attribute during multi-factor authentication, enhancing security and access control across all Parallels Clients.
- New: Add support for launching AVD resources using the Microsoft Windows App. Administrators can now define the preferred client for connecting to AVD resources and manage Windows App versions and updates through RAS policies, offering enhanced control and flexibility. Parallels Client for Mac, Linux and the User Portal have been updated to use the new Microsoft Windows App for Web to launch AVD sessions.
- New: Introduce Cost Insights dashboard for Azure Virtual Desktop, enabling administrators to monitor and visualize estimated cloud service costs as well as cloud cost savings directly in RAS Console.
- New: Add support for Windows Server 2025 as a Hyper-V provider and cluster.
- New: Drop support of VMware vCentre/ESXi v6.5 and v6.7.
- New: AVD Client feature sets “Advanced” and “Advanced with fallback” are deprecated.
- New: Add conditional Radius automation, allowing administrators to streamline multi-factor authentication and action assignments based on username patterns.
- New: Enable specific Organizational Unit (OU) traversal during provisioning, supporting cross-domain deployments.
- New: Update FSLogix supported versions to include v25.06.
- New: Prevent creation of new templates or template versions if the RAS agent is outdated. Admins are notified to update the agent before proceeding, reducing the need for later auto-upgrades on cloned machines and minimizing potential issues.
- New: Validate domain credentials during template creation and notify administrators if credentials are incorrect, helping administrators prevent issues early and avoid failed clone attempts.
- New: Add an option to reassign orphaned hosts to a host pool, enabling recovery without deleting and recreating hosts.
- New: Expand clipboard redirection restrictions to include Rich Text Format (RTF), HTML, files, and images, in addition to plain text, providing administrators with finer control over clipboard data transfers.
- New: Allow server-side clipboard content to be configured to appear in the client-side clipboard history using the Parallels Client for Windows.
- New: Allow server-side clipboard content to be seamlessly synced across Windows devices using the Parallels Client for Windows, improving user experience and productivity.
- Improved: Restrict the use of the following reserved words as theme names: userportal, rashtml5gateway, 2xhtml5gateway, getclientip, urlschemaredirector, and rasgeolocatorinfo.
- Improved: Improve error messages when uploading large system reports that exceed server size limits.
- Improved: Ensure proper context help is shown throughout RAS Console.
- Improved: Move "Add from network browse" option in publishing filtering to the last position to avoid confusion when no devices are found.
- Improved: Rename the "Application ID" column to “Credential” for VDI Providers to give better clarity on the provided data.
- Improved: Update bandwidth units in the Session Information screen to match standard terminology.
- Improved: Remove the deprecated “Include Skype Data” option from FSLogix settings.
- Improved: Hide the provisioning page for standalone RDSH host pools unless a template is set.
- Improved: Streamline the data exchange between Guest agent and Provider agent.
- Improved: Various logs improvements.
- Improved: Handling of reconnections, using the Parallels Client for Windows, when network changes occur which could result in duplicated sessions (requires Windows Registry setting ReconnectBehavior).
- Improved: Refine orphaned hosts detection by excluding template replicas from SQL queries.
- Improved: Support third-party scanning applications with custom features in Fujitsu scanner TWAIN drivers (requires Windows Registry setting PaperstreamApps).
- Improved: Enrollment Server agent no longer searches for the certificate after creating a new user certificate during logon.
- Improved: Enhanced performance when browsing deep directory structures over redirected drives from Java applications.
- Improved: Automatically redirect printers when their status changes from error to available, enabling users to access them in their session.
- Improved: Show “Invalid registration certificate” as the Enrollment Server agent state when an invalid registration certificate on the Enrollment Server is found.
- Improved: Applications specified in the GDIHookApplications registry key now correctly print to redirected printers when printing to “FILE:”.
- Critical Fix: Promoting a server to Primary Connection Broker may cause the controller service to crash and the server status to remain "Not Verified".
- Critical Fix: Reverting a certificate change from Audit may cause the redundancy service to crash.
- Critical Fix: RAS Console could crash when powering off a host in the Host dialog during host pool creation.
- Critical Fix: Crash could occur when RAS farm has a VMware provider added and the Provider Agent service is stopped.
- Critical Fix: Possible crash in Connection Broker after changing settings of an RDSH templated Host pool with auto scaling enabled.
- Critical Fix: The primary RAS Redundancy service may hang briefly if the MAC address changes.
- Critical Fix: Possible crash during autoscaling check processing.
- Fixed: Policy details remain visible in the Session Information window for sessions connected using Parallels Client for Mac after the policy is removed and the user reconnects to the published resource.
- Fixed: Farm names with ansi characters appear corrupted in logs.
- Fixed: Virtual machines may be removed from a VDI host pool and become unavailable, even though they are present and accessible in the provider.
- Fixed: Templated RD Session Hosts may be unlinked from the hypervisor if the state of the VDI host agent is “Failed to create”. This could cause assignment of duplicate IP addresses which result in login failures.
- Fixed: AVD personal host pools may fail to create clones when deployment settings cannot be found.
- Fixed: Deleting multiple hosts from a templated host pool does not prompt for confirmation, increasing the risk of accidental deletion.
- Fixed: Deleting multiple hosts from a templated host pool only deletes the first selected host instead of all selected hosts.
- Fixed: Templated RD Session Hosts may remain in drain state indefinitely if a recreation is performed during autoscaling action, preventing proper removal or shutdown.
- Fixed: Multi-factor authentication fails when one MFA server is down in Active-Active HA mode.
- Fixed: Autoscaling does not trigger drain and power off actions as configured, leading to inconsistent host pool behavior.
- Fixed: Cloning from an RDSH or VDI template with Sysprep and FSLogix may fail, leaving hosts in a "not applied" state.
- Fixed: Reverting site settings from Audit may break certificate format, causing the Enrollment Server to show a status of Invalid CA configuration.
- Fixed: Connection Broker assigned a VDI clone to a user before preparation was complete, causing users to be connected to machines that were not yet ready.
- Fixed: Connection Broker service may crash during shutdown.
- Fixed: AVD hosts were unexpectedly initiated for creation when the provider lost connectivity with the Connection Broker, resulting in failed host creation and potential resource issues.
- Fixed: Search markers in Policies could be hidden or incorrectly displayed due to control alignment issues and hidden items.
- Fixed: Editing a theme with a linked SAML IdP incorrectly displayed a warning about removing the IdP.
- Fixed: Multiple consecutive validation errors for the same field could appear when creating an RDSH Host Pool.
- Fixed: Wrong alignments in Let’s Encrypt settings dialog, Guest agent status, and AD Integration page.
- Fixed: Example hostname in the host pool wizard was truncated.
- Fixed: OK button in the filtering rules dialog for published items required two clicks to apply changes.
- Fixed: Pressing Enter while typing a username in the User Management dialog for MFA reset field closed the dialog instead of searching for the user.
- Fixed: Reverting deleted access addresses did not refresh the list in the site properties window until it was closed and reopened.
- Fixed: The Certificate Properties window restricted visibility of the "Alternative Names" field due to fixed size and lack of scrolling.
- Fixed: SSO login to the console could fail on Windows Server 2025 and Windows 11 unless a specific group policy was manually enabled.
- Fixed: Notification for valid credentials in the template wizard showed an incorrect alert icon.
- Fixed: Accessing the VDI Hosts tab was blocked for additional administrators if another admin already had the tab open, preventing concurrent viewing.
- Fixed: Device Manager page did not sort items by vendor or model.
- Fixed: Connection Broker "Take Over" failed when Connection Broker was installed to a non-default path, leaving the process incomplete and repeatable.
- Fixed: Enabling "Prohibit saving username" in policy did not automatically enforce "Prohibit saving password".
- Fixed: Distribution details for RDS templates displayed datastore IDs instead of names.
- Fixed: Static Remote PC provider configuration produced unclear errors and lacked guided links to the admin guide on agent installation steps.
- Fixed: The “Check Credentials” button and “Browse for Username” button were missing in some provider wizards, resulting in an inconsistent experience.
- Fixed: The “Check Credentials” button caused issues in scenarios where the domain was not provided with the username.
- Fixed: Theme changes in properties were not reflected in the theme list until the window was refreshed.
- Fixed: Email OTP content included a trailing space, causing pasted OTPs to be rejected as invalid in the User Portal.
- Fixed: "Suspended" state was missing from the "power state after creation" dropdown in the host pool wizard.
- Fixed: Template wizard allowed proceeding even if the selected provider was not in a valid state, resulting in errors later in the process.
- Fixed: Deleting a templated RDSH host showed a confirmation message referencing autoscale instead of templated.
- Fixed: Open dialogs remained visible when RAS Console loses connection with the Redundancy service.
- Fixed: Newly added AVD Workspaces, Host Pools, and Templates disappeared after logging off and back into the RAS Console.
- Fixed: Users failed to change their password when "User must change password at next logon" was enabled in Active Directory.
- Fixed: Scanners may disconnect from published applications after a period of time due to a crash in device redirection.
- Fixed: Printer and scanner redirection may fail when many TWAIN scanners are redirected.
- Fixed: Templated RD Session Hosts deleted from vSphere could remain listed as "Not verified" in RAS Console.
- Fixed: Templates could incorrectly display a status of "OK" in RAS Console even though distribution to datastores was still in progress.
- Fixed: ESXi Provider status was not being updated correctly when it was not supported or connected to vCenter.
- Fixed: Hyper-V template distribution allocated hosts unevenly.
- Fixed: Multi-provider template remains in "Deployment in progress" status after distribution.
- Fixed: Deleting a template version did not clean up all VMDK files on VMware.
- Fixed: Detecting Hosts deletion during recreation on VMware.
- Fixed: Host notifications were not being pushed immediately when adding a new VMware Host.
- Fixed: Provider information may be missing after resolving incorrect Provider credentials.
- Fixed: Datastores from an unrelated VMware template were being listed.
- Fixed: Unable to delete RDSH from RAS Console after deleting the host directly from the Hyper-V provider.
- Fixed: Hosts recreation after template maintenance could fail for VMware ESXi, with some Hosts stuck in "Cloning" or "Failed to create" states.
- Fixed: Removing templated AVD host pool on RAS might fail to remove the Azure host pool resource.
- Fixed: Scanning on the Parallels Client for Windows may hang when using Fujitsu FI series scanners with third party scanning applications.
- Fixed: The upgrade dialog warning administrators about critical steps when upgrading from version 19.x to 20.x appeared in farms with two Sites and one Connection Broker each.
- Fixed: Control session on AVD Session Hosts (enable and disable drain mode) could fail or show incorrect information.
- Fixed: Unassigning a user from a host in a personal host pool causes the host to lose its pool membership in Azure Virtual Desktop environments.
- Fixed: Warning messages were logged when guest deployment settings fail to be retrieved during replica deployment.
- Fixed: Possible error when users print with the same font simultaneously.
- Fixed: Secure Gateway may not reconnect to the preferred Connection Broker when it comes back online.
- Fixed: Parallels Client attempts to connect to a host even though its preparation process failed due to a timeout.
- Fixed: Hosts persistence may be lost when switching desktop assignment type and restarting the Connection Broker.
- Fixed: Hosts prepared with sysprep may not join the host pool.
- Fixed: Deleting a stale duplicate host with the same name as another host also removed the associated computer account in Active Directory.
- Fixed: Session information incorrectly showed FSLogix status in User profile when FSLogix was not enabled.
- Fixed: Launching published resources using Web Auth (SAML) would fail with “Incorrect username or password” if the distinguished name contains the character #."
- Fixed: Search for the Enrollment Agent certificate could fail when the Enrollment Agent user logon name does not match the value configured in AD Integration settings, resulting in the Enrollment Server agent state getting stuck in “Enrollment is Unavailable”.
For all known issues and resolutions, please see Parallels KB article https://kb.parallels.com/en/131048 or contact support directly at Support | Parallels RAS.
RAS REST API
RAS REST API v21.0.0-26247 (11 November 2025)
- Security Fix: Upgraded to OpenSSL 3.0.17.
- Security Fix: Upgraded .NET to 8.0.18.
- New: Add support to add and manage tags on template versions.
- Improved: Update rate limiting defaults to better support API scripts (new installations only).
- Improved: Simplify the Add-RASVDIHostPoolMember command by no longer requiring all the VM IDs when using AllHostsInProvider.
- Improved: Add YesTLS13IfAvailable (Use TLS 1.3 if available) value to MailboxTLS enum.
- Improved: Add keyboard layouts for French (Belgium), French (Switzerland), and German (Switzerland) to the KeyboardLayout enum in ClientPolicy.
- Improved: Restrict the use of the following reserved words as theme names: userportal, rashtml5gateway, 2xhtml5gateway, getclientip, urlschemaredirector, and rasgeolocatorinfo.
- Improved: Various documentation improvements.
- Fixed: Published objects remain locked after Add-RASCriteriaSecurityPrincipal fails, preventing further modifications.
- Fixed: LoginTime and LastUpdate fields in Get-RASDevicesInfo output use epoch time instead of a human-readable date format.
- Fixed: Adding or updating MFA Radius automation incorrectly required both action message and description fields, preventing automation from being added or updated.
- Fixed: Session information for AVD resources was missing in the RDSession response.
- Fixed: Setting logoffDisconnectedSessionAfter or disconnectActiveSessionAfter on a session host, using Set-RDSHost, caused both values to be synchronized.
- Fixed: Creating a new RDS host pool with the HostsToCreate parameter did not clone the requested number of hosts.
- Fixed: Adding a remote PC required the MAC address and set subnet to 0 if not specified; MAC address is no longer mandatory and subnet is handled properly.
RAS PowerShell
RAS PowerShell v21.0.0-26247 (11 November 2025)
- Security Fix: Upgraded to OpenSSL 3.0.17.
- New: Add datastore creation locations for RDSH and VDI hosts.
- New: Add support to add and manage tags on template versions.
- Improved: Various documentation improvements, including correcting header formatting in module pages and adding missing details for the AutoIds parameter in the Set-MFARadiusAutoCondition command.
- Improved: Simplify the Add-RASVDIHostPoolMember command by no longer requiring all the VM IDs when using AllHostsInProvider.
- Improved: Add YesTLS13IfAvailable (Use TLS 1.3 if available) value to MailboxTLS enum.
- Improved: Add keyboard layouts for French (Belgium), French (Switzerland), and German (Switzerland) to the KeyboardLayout enum in ClientPolicy.
- Improved: Restrict the use of the following reserved words as theme names: userportal, rashtml5gateway, 2xhtml5gateway, getclientip, urlschemaredirector, and rasgeolocatorinfo.
- Improved: Reduce redundant remote settings calls when retrieving published RDS applications with Get-RASPubRDSApp.
- Improved: Provide more detailed error information when Send-RASSupportRequest fails.
- Improved: Remove the obsolete AgentStatus property from Get-RASTemplateStatus output.
- Improved: Various documentation improvements.
- Fixed: Published objects remain locked after Add-RASCriteriaSecurityPrincipal fails, preventing further modifications.
- Fixed: LoginTime and LastUpdate fields in Get-RASDevicesInfo output use epoch time instead of a human-readable date format.
- Fixed: Get-RASAgent returns "Unknown" agent state for VDI clones that are actually in an OK state.
- Fixed: AVD type was missing from AgentDiagnosticType in the Get-RASAgentDiagnostic command.
- Fixed: License details did not report when the license was disabled after failover grace period expiration on a promoted Connection Broker.
- Fixed: Setting logoffDisconnectedSessionAfter or disconnectActiveSessionAfter on a session host, using Set-RDSHost, caused both values to be synchronized.
- Fixed: Creating a new RDS host pool with the HostsToCreate parameter did not clone the requested number of hosts.
- Fixed: Session information for AVD resources was missing in the Get-RASRDSession response.
- Fixed: Adding or updating MFA Radius automation incorrectly required both action message and description fields, preventing automation from being added or updated.
- Fixed: Get-DeviceInfo command fails with large number of devices, causing errors and incomplete device information retrieval. Introduced an optional timeout parameter (default 60 seconds) to handle large queries.
Management Portal
Management Portal (11 November 2025)
- Security Fix: Migrated to Vue3.
- Security Fix: Upgraded to OpenSSL 3.0.17.
- Security Fix: Upgraded .NET to 8.0.18.
- New: Add conditional Radius automation, allowing administrators to streamline multi-factor authentication and action assignments based on username patterns.
- Improved: Rename the "HTML5" tab in Secure Gateway Site Defaults to "User Portal".
- Fixed: Session information for AVD resources was not being populated.
- Fixed: Adding or updating MFA Radius automation incorrectly required both action message and description fields, preventing automation from being added or updated.
- Fixed: Disconnecting or logging off VDI sessions resulted in a “vdihostid is a mandatory parameter” error.
- Fixed: The disconnect option was not disabled for already disconnected sessions.
- Fixed: The Add button in Publishing was incorrectly enabled for custom administrators when no folder or published item was selected, leading to permission errors when publishing applications.
- Fixed: Empty modal appears when clicking the test button for Client IP Detection Service URL.
User Portal (Web client)
User Portal (Web client) (11 November 2025)
- Security Fix: Cookie SameSite attribute was not always set to Strict.
- Security Fix: Upgraded to OpenSSL 3.0.17.
- Security Fix: Internal host IP addresses were exposed in requests when launching a published application.
- Security fix: User passwords appeared in plain text in Secure Gateway logs when users changed their passwords.
- New: Enable multi-process support for the User Portal server, improving scalability and performance.
- New: Add support for URL redirection policy, enabling administrators to redirect users to a different farm with a user notification.
- New: Add support for large cursors.
- New: Add support for capturing the public IP address of client connections and passing it as a RADIUS attribute during multi-factor authentication.
- Improved: Updated launching of Azure Virtual Desktop (AVD) sessions to use the new Microsoft Windows App for Web.
- Improved: Various accessibility improvements to align with WCAG 2.2 Level AA standards.
- Improved: Optimize file download and upload speeds.
- Improved: Update remote session network errors for consistency between published desktops and applications.
- Fixed: Users restricted from the default theme could not change their password in other themes.
- Fixed: Password change did not redirect to the configured custom change password URL when Web Authentication was enabled.
- Fixed: Email OTP content included a trailing space, causing pasted OTPs to be rejected as invalid in the User Portal.
- Fixed: Opening published applications on a slow network could return a connection error [0x0108].
- Fixed: Application list remained open in the foreground after launching an app multiple times, instead of closing automatically.
- Fixed: “Start items over” option values in settings did not update when switching interface language after login.
- Fixed: Opening a published desktop in the browser on Android devices with a slow network sometimes redirected users to the login screen instead of starting the session.
- Fixed: Custom mouse cursor does not display correctly in a published application, showing a black box instead of the cursor.
- Fixed: Secure Gateway originator validation during Parallels Client detection and launch was unreliable, causing incorrect logs and error handling.
- Fixed: The last focused application did not regain focus after switching tabs or reopening the application list.
- Fixed: Remote sessions froze and timed out on Chrome and Edge when using browser back/forward navigation in SAML-enabled environments.
- Fixed: The User Portal ignored the “Start Mode” policy when launching applications via the Parallels Client, altering the Parallels Client Connection Mode settings.
- Fixed: User Portal settings remained locked after disabling or deleting the policy that enforced them.
- Fixed: Inconsistent redirect behavior when the custom "Default URL" matches a theme URL in Secure Gateway.
- Fixed: Change password method did not update immediately after configuration changes until the user logged out and back in or refreshed the page.
Parallels Client (Windows)
Parallels Client (Windows) v21.0.0-26247 (11 November 2025)
- Security Fix: Username and password may remain stored on disk when a policy prohibiting credential storage is applied while a user is logged in, until the user logs off.
- Security Fix: Upgraded to OpenSSL 3.0.17.
- Security Fix: Upgraded .NET to 8.0.18.
- New: Expand clipboard redirection restrictions to include Rich Text Format (RTF), HTML, files, and images, in addition to plain text, providing administrators with finer control over clipboard data transfers.
- New: Allow remote clipboard content to be optionally saved to the local clipboard history and synchronized across devices. This is also configurable via RAS policies, offering administrators greater flexibility in managing clipboard behavior.
- New: Store credentials in Windows Credential Manager for improved security.
- New: Enhanced the overall user experience during reconnections for published desktops by persisting the desktop window until the connection is re-established. This ensures users are aware that the session is attempting to reconnect and no data is lost.
- New: Add support for launching AVD resources using the Microsoft Windows App. Administrators can now define the preferred client for connecting to AVD resources and manage Windows App versions and updates through RAS policies, offering enhanced control and flexibility. The fallback has been updated to use the new Microsoft Windows App for Web.
- New: Add support for capturing the public IP address of client connections and passing it as a RADIUS attribute during multi-factor authentication.
- Improved: Add keyboard shortcut support for the “Connect” and “Create Connection” buttons in the main window to improve accessibility and usability.
- Improved: Set appropriate permissions for the client dumps directory during installation.
- Improved: Various logs improvements.
- Improved: Handling of reconnections when network changes occur, which could result in duplicated sessions (requires Windows Registry setting ReconnectBehavior on all Connection Brokers).
- Critical Fix: A possible crash occurs when RemoteApp application startup failed. An error message is now displayed instead of terminating the client.
- Fixed: Override computer name setting may not work on Windows Server 2022 after installing the July 2025 cumulative update (KB5062572), causing the session to display the server name instead of the specified override.
- Fixed: Renaming files or folders and deleting empty directories was allowed in read-only drive redirection mode on Windows Server 2022 after installing the July 2025 cumulative update (KB5062572).
- Fixed: Allow logon with an alternative user account when accessing published resources via the User Portal.
- Fixed: The option to add RAS connection automatically when starting web or shortcut items failed on fresh installs, causing missing or duplicate prompts.
- Fixed: Excluding a monitor from a 2x2 display setup resulted in a black screen on the excluded monitor.
- Fixed: Importing a 2XA file with an existing connection ignored the specified authentication type, resulting in incorrect credential prompts.
- Fixed: The "Connection advanced settings" button was disabled when a policy was pushed, even if the local proxy address section was not restricted.
- Fixed: OTP prompts continued after clicking "Cancel" during RAS session reconnection with MFA.
- Fixed: Reconnection failed to retry the primary connection after secondary connections failed.
- Fixed: Opening a published resource via CLI command did not update the port parameter for existing connections unless the connection was deleted.
- Fixed: Password change did not redirect to the configured custom change password URL when Web Authentication was enabled.
- Fixed: Smart card authentication with the "Save credentials" option selected was prompting the user for the PIN again on subsequent logins.
- Fixed: Smart card authentication could fail or repeatedly prompt for credentials when launching published applications.
- Fixed: Audio quality issues may be experienced when recording audio remotely (requires Windows Registry setting GWTCPNoDelay).
- Fixed: Scanning may hang when using Fujitsu FI series scanners with third-party scanning applications.
Parallels Client (Mac)
Parallels Client (Mac) v21.0.0-26247 (11 November 2025)
- Security Fix: Upgraded to OpenSSL 3.0.17.
- New: Add support for macOS 26.
- New: Drop support of macOS 12.
- New: Add support for capturing the public IP address of client connections and passing it as a RADIUS attribute during multi-factor authentication.
- Improved: Updated launching of Azure Virtual Desktop (AVD) sessions to use the new Microsoft Windows App for Web.
- Improved: Update the shortcut folder selector in Application Settings to use a more native and intuitive control.
- Improved: Ensure published applications launched during session initialization are queued and opened once the session is ready, preventing launch failures.
- Improved: Option+Q and Option+E keys do not produce the expected characters when using the Dutch keyboard layout.
- Fixed: Reconnection settings remain enabled and editable when a reconnection policy is enforced, instead of being correctly disabled.
- Fixed: Error message appears immediately when the network is disconnected, instead of only after all reconnection attempts fail.
- Fixed: Actions from the “Manage Connection” menu are applied to the previously selected RDP connection instead of the currently selected one.
- Fixed: Text in the New Connection dialog does not wrap correctly for the French locale.
- Fixed: Idle timer, set through the “Automatically log out idle client connection after” setting, does not reset when opening or closing the connection properties or change password window, causing unexpected logouts even when activity occurs.
- Fixed: Microphone redirection option remains enabled when remote audio output is set to "Leave at remote computer".
- Fixed: Typo in the New Connection dialog ("emall" instead of "email").
- Fixed: Policy details remain visible in the Session Information window in the RAS Console after the policy is removed and the user reconnects to the published resource.
- Fixed: Printed output does not match the print preview when using custom print scaling with RAS Universal Printing.
- Fixed: The ‘Open PDF in macOS Preview’ printer in MS Basic printer redirection does not work.
- Fixed: Cursor does not change correctly or may disappear when using "span across all monitors" with multiple displays.
- Fixed: Updated the default experience settings for new connections.
Parallels Client (Linux)
Parallels Client (Linux) v21.0.0-26247 (11 November 2025)
- Security Fix: Upgraded to OpenSSL 3.0.17.
- New: Support for Debian 13, Fedora 40, 41, and 42, and Mint 22.
- New: Drop support of Ubuntu 20.04, Fedora 37, 38, and 39, and Mint 20.
- New: Add support for capturing the public IP address of client connections and passing it as a RADIUS attribute during multi-factor authentication.
- Improved: Updated launching of Azure Virtual Desktop (AVD) sessions to use the new Microsoft Windows App for Web.
- Fixed: Webcam stream may stop or the client may crash when using webcam redirection on Linux, especially when multiple cameras are connected or accessed simultaneously.
- Fixed: Changing the "Automatically log out idle client connection after" setting while a client is connected does not take effect until the next session.
- Fixed: Idle timer, set through the “Automatically log out idle client connection after” setting, does not reset after refreshing the connection, causing unexpected logouts even when activity occurs.
- Fixed: Certificate warnings may appear when connecting with valid certificates.
Parallels Client (iOS)
Parallels Client (iOS) v21.0.0-26240 (11 November 2025)
- Security Fix: Upgraded to OpenSSL 3.0.17.
- New: Add support for iOS 26 and iPadOS 26.
- New: Drop support of iOS 15 and 16 and iPadOS 15 and 16.
- New: Add support for capturing the public IP address of client connections and passing it as a RADIUS attribute during multi-factor authentication.
- Improved: Streamline local resource redirection controls by consolidating audio and microphone settings, aligning with other Parallels Clients, and properly supporting separate policies for audio playback and recording.
- Improved: Refine error handling logic to improve messages shown when a remote connection is disconnected.
- Improved: Update color and menu items position of the “more” menu.
- Improved: The email body for technical reports was updated to include device and OS details, ensuring consistent reporting across different device versions.
- Improved: Add Sentry event ID to client logs for better error tracking.
- Improved: Update the microphone permission message and behavior to improve user experience and standardize behaviour.
- Improved: Update log file compression method used for error reporting.
- Improved: Optimize and standardize image storage and caching for better performance and maintainability.
- Improved: Optimize memory management.
- Fixed: Correct keyboard layout display in Client Settings to show the language code.
- Fixed: Various audio redirection behavior improvements to properly handle focus changes, such as incoming calls or background audio from other apps.
- Fixed: OTP prompts continued after clicking "Cancel" during RAS session reconnection with MFA.
- Fixed: Some connections are missing when importing a 2xc file exported from Parallels Client for Windows.
- Fixed: Navigation returns to the server list instead of the previous screen when creating a new RDP connection.
- Fixed: Unable to paste server address when adding a new RAS Connection.
- Fixed: Toolbar is incorrectly positioned after switching between apps and returning to Parallels Client.
- Fixed: Pasting formatted text from Universal Clipboard inserts HTML with inline CSS instead of plain text in published applications.
- Fixed: Idle client connections do not automatically log out when the RDP session is closed using Task Switcher.
- Various bug fixes and improvements to improve stability.
Parallels Client (Android)
Parallels Client (Android) v21.0.0-26241 (11 November 2025)
- Security Fix: Upgraded to OpenSSL 3.0.17.
- New: Add support for Android 16.
- New: Drop support of Android 9.
- New: Add support for capturing the public IP address of client connections and passing it as a RADIUS attribute during multi-factor authentication.
- Improved: Streamline local resource redirection controls by consolidating audio and microphone settings, aligning with other Parallels Clients.
- Improved: Add Sentry event ID to client logs for better error tracking.
- Fixed: OTP prompts continued after clicking "Cancel" during RAS session reconnection with MFA.
- Fixed: Touch input is delayed or unresponsive on certain devices, such as Zebra scanners, requiring multiple taps for a single interaction.
- Fixed: Server remains stuck in the connecting state on the server list screen after cancelling a reconnect attempt.
- Fixed: Double taps in touch mouse mode do not always register correctly, causing inconsistent interaction with published applications.
- Fixed: Desktop icon in the app switcher displays a generic icon instead of a live thumbnail of the desktop session.
- Fixed: Certificate warnings are being shown even when “Gateway authentication” is set to “Do Not Warn” in client settings.
- Fixed: Close button in File Manager acts as a back button instead of closing the File Manager and returning to the Connections screen.
- Fixed: Application crashes when switching to landscape mode and accessing certain screens such as Add Server, Help, Export Server on foldable devices.
- Fixed: Audio redirection fails to resume after an incoming call on Android devices running OS versions below 12.
- Fixed: Reading and writing of the microphone redirection option in the 2xc file.
- Fixed: Idle client connections do not automatically log out when the RDP session is closed using Task Switcher.
- Various bug fixes and stability improvements.
RAS Reporting
Reporting v21.0.0-26247 (11 November 2025)
- Improved: Rename the "Total Time" sort option to "Total Time Used" in the “Device usage for user” report, the "Disconnection Reasons" sort option to "Disconnect Reasons" in session disconnect reports, and "Disconnected Time" to "Disconnect Time" in session activity reports to match the column name.
- Improved: The RAS Reporting installer no longer sets the database recovery model to full, keeping the SQL Server default instead.
- Fixed: The reporting tab on RAS Console could not be opened after upgrading due to the rapid growth of the SQL transaction log.
- Fixed: User Experience data retention setting was ignored for some table, causing data to be kept for the default 4 weeks regardless of configuration.
- Fixed: Some Host pool actions were not being stored in the reporting database.
RAS Performance Monitor
RAS Performance Monitor v21.0.0-26247 (11 November 2025)
- Security Fix: Upgraded InfluxDB to 1.11.8.
HALB
HALB v21.0.0-26247 (11 November 2025)
- Security Fix: Upgraded to OpenSSL 3.0.17.
- New: Modernized and hardened the HALB appliance to improve its security, stability, and long-term maintainability. Upgraded third-party packages and isolated HALB services within a container inside the appliance.
- Fixed: HALB settings failed to synchronize correctly when using SSL offloading, causing incorrect status and service reporting in the RAS Console and HALB Appliance screens.
Parallels Remote Application Server v20 Release Notes can be found in the following article
For any assistance or direct support inquiries, please reach out to our support team by visiting Support | Parallels RAS
Was this article helpful?
Tell us how we can improve it.