XPressEntry Desktop

Release Notes

3.7.7748

September 4, 2026 3.7.7748

XPressEntry 3.7.7748


This release modernizes how XPressEntry connects to SQL Server, brings live updates to the web

console, and hardens the server against SQL injection.


Highlights


Support for SQL Server 2025 and stricter encryption

XPressEntry can now connect to SQL Servers that require strict encryption, with the matching

options in the database setup screen. Existing connections keep working as before.


The web console updates without a refresh

Badge scans, occupancy and zone changes, muster activity and guard tour progress appear in the web

console as they happen.


System-use notification at login

A configurable acceptable-use notice can be shown after login, on both the server and handhelds.

Blank by default, which keeps it off.


Integrations no longer slow the database over time

Pending integration events were never fully cleaned up, so on a busy site they could build up until

the database slowed down. They are now purged automatically.


Security


  • SQL injection hardening across the server and the OnGuard, CCURE 9000, Bosch, Galaxy and

Avigilon Unity integrations.

  • Zone occupant and activity history searches treat wildcard characters as literal text.

Server


  • A stray line break in a user's name no longer stops handhelds downloading their user list.
  • The handheld setup wizard no longer creates a duplicate door on every run when auto-create doors

is enabled.

  • Reader profiles gain a Guard Tour tab: tappable map coordinates, verification that a user is

permitted in a checkpoint's area, and routes assigned per profile.

  • Guard tour routes gain a scan mode — automatic within range, manual within range, or no location

check — with a validation radius on each checkpoint.

  • Data managers are listed in a grid with their status, and a new button checks every enabled one's

connection at once.

  • A manually requested sync always writes a sync summary, even when nothing changed.
  • Data manager custom field mapping no longer offers destination fields that the sync silently

discards.

  • The muster settings report name is chosen from a list of existing reports instead of typed by

hand.

  • Clicking a User Defined Fields column header no longer raises an application error.
  • Dead REST API and Web Occupancy settings have been removed from the Server General tab.
  • The data manager full-test suite and its button have been removed.

Config Tool / Database


  • The database connection string can be edited directly, for setups the standard fields cannot

express.

  • Config Tool failures appear in the inline message banner with the full reason, instead of being

cut short.

  • Saving no longer damages the web console's configuration file, and more of its settings can be

set from the Web tab.

  • The partition list loads when the Config Tool is run on its own.
  • Server logging no longer stops permanently on long-lived installations.
  • The diagnostic report includes considerably more detail about the database.
  • A failed database migration now records why it failed.

Integrations


OnGuard


  • A large sync no longer gives up partway through when the OnGuard server becomes busy. XPressEntry

now slows down and keeps going.

  • An incomplete sync can no longer be mistaken for a finished one and remove live cardholders and

badges.


Honeywell Pro-Watch


  • Pro-Watch handles an overloaded server the same way OnGuard now does. No change in behavior.

Genetec


  • Cardholder, credential and access rule changes now apply when MSMQ is disabled. They were

previously discarded.

  • The Genetec data manager can now be configured from the Config Tool.

CCURE 9000


  • Disabling one user no longer marks every valid badge in the system as User Disabled.
  • Bulk pulls can be narrowed to mapped columns only, with optional filters on the personnel, badge

and group pulls. A filter does not suppress deletion.


Velocity


  • Badge templates sync as badge types, and each badge takes its type from its credential.
  • Access granted through a function group is now honored. It was previously read and dropped.
  • Badge activation and expiration dates sync, with expiration taken only when Velocity is

enforcing it.

  • A door zone set by hand is no longer overwritten when Velocity has no zone to supply.
  • Software events arrive regardless of the occupancy and activity sync settings, and partial syncs

run far fewer queries.


Galaxy


  • A broken query has been removed from the occupancy sync.

Available Builds

Build Number Name Description Date Downloads
#7752 3.7.7752 No description September 4, 2026
#7751 3.7.7751 No description September 4, 2026
#7750 3.7.7750 No description September 3, 2026
#7749 3.7.7749 No description September 3, 2026
#7748 3.7.7748 No description September 1, 2026
#7747 3.7.7747 No description September 1, 2026
#7699 3.7.7699 No description August 14, 2026
#7454 3.7.7454 No description May 7, 2026
#7240 3.7.7240 No description January 26, 2026
#7191 XPressEntry Desktop: 7191 No description January 5, 2026
#7187 XPressEntry Desktop: 7187 No description January 5, 2026
#7000 XPressEntry Desktop: 7000 No description January 5, 2026
#6952 XPressEntry Desktop: 6952 No description January 5, 2026
#6896 XPressEntry Desktop: 6896 No description January 5, 2026
#6870 XPressEntry Desktop: 6870 No description January 5, 2026
#6801 XPressEntry Desktop: 6801 No description January 5, 2026
#6786 XPressEntry Desktop: 6786 No description January 5, 2026
#6647 XPressEntry Desktop: 6647 No description January 5, 2026
#6645 XPressEntry Desktop: 6645 No description January 5, 2026

Related Products