Release Notes
MetaDefender Managed File Transfer 3.11.5
Release Date: 24 August 2026
MFT 3.11.5 delivers per-group predefined folders, full SSO role mapping across every MFT role, designated folder upload restrictions, a consolidated MFT-to-MFT transfer status column, and over 30 bug fixes and reliability improvements.
New Features & Enhancements
Security
User Manager Role
Assign a read-only User Manager role for user management and audit, grantable via an AD group.
Designated Folder Upload Restrictions
Restrict uploads and downloads to folders an administrator assigns, keeping transfers out of unauthorized locations.
Full SSO Role Mapping
Assign any MFT role to an SSO user, extending mapping beyond Admin and Automation Coordinator.
External User Password Enforcement
Enforce a password creation or change prompt for external users at first login, matching the existing local-user requirement.
User Management
Per-Group Predefined Folders
Define a fixed set of root-level folders per user group, replacing free-form My Files access.
Configure the folder list per group from Group Settings
Folder changes propagate automatically as group membership changes
Per-Group Navigation Visibility
Configure Shared With Me and User Management navigation visibility per user group.
Automation
MFT-to-MFT Destination Workflow Selection
Assign a distinct destination scan workflow for each MFT-to-MFT synchronization direction.
Integrations
SMTP Sender Email Override
Set a single override sender address for all outbound SMTP messages, replacing the default administrator sender.
Minor Enhancements
File Integrity Email Clarity — view clearer checksum terminology and a direct link to the affected file in integrity verification failure emails.
Platform
SQL Server LocalDB Removal
Enforce migration off SQL Server LocalDB before upgrading, so unsupported database configurations no longer receive new installer updates.
HA Max Request Body Size
Configure the maximum allowed request body size for HA deployments to match workload requirements.
Minor Enhancements
HA Controller Version Display — view HA Controller version numbers alongside MFT version numbers on the HA Configuration Tool Overview page.
LibreOffice Preview Engine Update — preview Office documents using the latest LibreOffice release, incorporating upstream security fixes.
Administration
Filtered File Security Export
Export the File Security Report table in its currently filtered, sorted, and configured state.
TCP Syslog Forwarding
Configure Syslog forwarding over TCP in addition to UDP for reliable audit event delivery.
Audit Log Sanitization Hashes
View file hashes captured before and after sanitization directly in the audit log entry.
Database Health Status Banner
View a banner alerting administrators when the database connection is degraded or unreachable.
Minor Enhancements
Managed Folder Delete Confirmation — view a confirmation dialog before a managed folder is deleted, preventing accidental removal.
Monitoring
MFT-to-MFT Transfer Status Column
View a single file transfer status column in My Files and File Analysis showing sync state and time.
Bug Fixes & Improvements
Security Fixes
SMTP Verification Response Disclosure
SMTP server validation responses no longer reveal whether internal services on the MFT server or connected servers are reachable, closing a service enumeration path.
MFT API Denial of Service
The MFT API applies rate limiting and validation controls to close a Denial of Service exposure path identified during a customer security assessment.
AD Credential and API Key Exposure
AD credentials and the MD Core API key are no longer exposed through the access path identified during a penetration test.
SSO Email Role Uniqueness
An SSO email address can be assigned to only one role at a time, preventing the same identity from being mapped to multiple conflicting roles.
Stability Fixes
Processor Service Deadlock
File transfer delete operations in the processor service complete without triggering a database deadlock that previously caused the operation to fail.
Automation Job Log Page Rendering
The automation job execution log page renders correctly for jobs with a large number of log entries, rather than displaying a blank screen.
Upload Progress Indicator Freeze
The floating upload progress indicator updates and clears correctly during a Pull from MFT operation, rather than remaining frozen on screen.
File Status After Version Upgrade
Files retain their correct processing status after upgrading from version 3.9.4 to 3.11.3, rather than becoming stuck in a Processing state.
Automation Jobs Page Crash
The automation jobs page loads without crashing due to a missing pipe provider.
Email Template Configuration Modal
The General Configuration modal for email templates opens without console errors.
Reliability Improvements
Audit Logging Completeness
Audit log entries are captured for actions that previously left no trail.
User mapping import/export — importing or exporting the user mapping list is recorded in the audit log
Interrupted uploads — interrupted file uploads are recorded in the audit trail
User Creation Orphaned Record Conflicts
User creation completes without conflicting against orphaned records left behind by incomplete prior operations.
Aggregated Data Reporting Toggle
The Aggregated Data Reporting toggle displays its true configured state, and telemetry metrics are captured accurately for every instance.
Shared Folder Email Direct Link
Share invitation emails for an upload-only folder link directly to the target folder or the Shared With Me landing page.
Scheduled SFTP Push Timing
Scheduled SFTP Push jobs with no files to send complete without an unnecessary 15-second delay.
Behavior Corrections
File Storage Move Status Message
The success message shown after a storage move operation reflects whether files were actually moved to active storage, rather than reporting success when none were moved.
MFT-to-MFT Manual Sync Toggle Enforcement
The manual sync-to-destination action is unavailable when Allow Users to Start Manual Synchronization is turned off, matching the configured setting.
Imported Configuration External User Settings
Importing a configuration file from a previous MFT version preserves the Show My Files and Allow to Share Files settings for external users.
SSO Redirect URL Update
The SSO configuration redirect URL can be updated and saved successfully.
Shared Folder Upload Actor Attribution
Email notifications for an upload to a shared folder credit the user who performed the upload, rather than always crediting the folder owner.
MFT-to-MFT Guest User Deletion Scope
Deleting an auto-created guest user at the destination MFT no longer deletes the corresponding local user at the source MFT.
File Status After Scan Completion
A file's status updates correctly once its scan completes, rather than remaining in Processing indefinitely.
Group File Policy Behavior
A group's file policy applies its managed folders correctly across membership and naming changes.
Folder creation after group assignment — folders defined in a group's file policy are created for members assigned to the group after the policy was configured
Policy scope to like-named folders — a group's file policy applies only to its managed folder, rather than to every folder at the My Files root sharing the same name
Share Menu Group Restriction Visibility
Users in a group with sharing disabled are hidden from the share menu, rather than appearing as available recipients.
Share Dropdown Duplicate Supervisor Entry
The share-with dropdown for a shared folder lists its supervisor once instead of twice, so folder sharing notifications reach the intended recipient.
UI & Usability Fixes
File Security Report Size Filter Unit — the file size filter slider on the File Security Report displays values in a readable unit rather than raw bytes.
Upload Modal Share Field State — share-related fields in the file upload modal are disabled when file or folder sharing is not allowed for the user.
Local Users Page Role Display — special user roles display their actual role on the Local Users page, rather than appearing as a simple user.
External Password Hint Text — the hint text for Enforce Random Password for External Users accurately describes which accounts can set a password and notes the required SMTP configuration.