> For the complete documentation index, see [llms.txt](https://docs.material.security/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.material.security/whats-new/previous-releases/version-1.49.md).

# Version 1.49

Phishing Issues now more clearly show you the full list of recipients on any given message so you can gauge blast radius immediately, and our automated similarity matching engine is now called Auto Threat Hunt for clarity’s sake. Same capability, more intuitive name.

\
We also snuck in some quality of life updates: you can now use arrow keys to move between items while an overlay is open, so investigating a list of issues, accounts, or issues no longer means jumping in and out.

***

## ✨ Enhancements

### Phishing Investigation

* **Similarity Matching is now called** **Auto Threat Hunt**: Same feature, clearer name. Admins can now easily understand how Material’s engine works. It automatically identifies related messages by examining multiple attributes of a message. These messages are then grouped and addressed collectively for efficient remediation.
* **See who else received a specific message more easily**: The Email Threats message view now has a recipients tab that shows everyone on To, CC, and BCC in a more upfront manner:&#x20;

  <figure><img src="/files/O2PxjTJjYr0wK3n97M3Q" alt=""><figcaption><p>From the issue detail view, click the message tab, then open message details</p></figcaption></figure>
* **Sender and recipient details front and center in the Message Detail view**: From and Recipients now appear at the top of the Message Details view along with full sender reputation signals for the address and domain.

  <figure><img src="https://3411262179-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FksjM8NywYRSHu1IlfxdP%2Fuploads%2FgM15Ac6rKNxGaCwE1gOO%2Fimage.png?alt=media&#x26;token=e807614c-e19e-4220-87a0-693032e5ad20" alt=""><figcaption></figcaption></figure>
* **Faster, more reliable Message Search:** We upgraded the backend logic for message search to provide a more consistent and performant experience.

### Platform Updates

* **Set severity levels for sensitive categories**:

  * Assign Critical, High, Medium, or Low severity to **any** sensitive category.
  * Material categories come pre-configured, and the sensitive categories list now sorts by severity. (If needed, override any severity from the detail panel):

  <figure><img src="https://3411262179-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FksjM8NywYRSHu1IlfxdP%2Fuploads%2FuVrE2jWbGcQ6JoRUr5sl%2Fimage.png?alt=media&#x26;token=cc466305-ddcb-421f-9994-114a3081d336" alt=""><figcaption></figcaption></figure>
* **Arrow through list items without leaving an overlay**: Keyboard navigation between items now works while an overlay is open across Accounts, Apps, Groups, Simulations, Detections, Investigations, Issues, and the File tables:

  <figure><img src="https://3411262179-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FksjM8NywYRSHu1IlfxdP%2Fuploads%2FwBAGdcoVXJgKuBQf9HCc%2Fimage.png?alt=media&#x26;token=61b8889c-76e5-4e0e-95ef-596af80537e2" alt="" width="182"><figcaption></figcaption></figure>
* **Jump to a Group by pasting its ID**: In the Groups Explorer tab, paste a Group ID into the search bar and find it immediately.
* **Detections created by deleted users are attributed correctly**: When a detection’s author has been removed, it now shows `Deleted user {id}` rather than assigning Material as the creator.
* **Only provision licenses to accounts with active mailboxes**: We introduced a new configuration option to restrict license allocation to accounts with a provisioned, active mailbox.
* **Trusted Entities search is now case-INsensitive**: No more worrying about capitalization when searching for a trusted entity.

  <figure><img src="https://3411262179-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FksjM8NywYRSHu1IlfxdP%2Fuploads%2FZI2lWgbSQvqMCveVThf0%2Fimage.png?alt=media&#x26;token=6d2a333a-4726-40b7-9350-3706460c460c" alt="" width="199"><figcaption></figcaption></figure>

### Email Bomb Protection now available in Essentials

Material can detect [email bomb attacks](#user-content-fn-1)[^1] and remediate to restore availability to the inbox. This feature is now **available in all packages**.

<figure><img src="https://3411262179-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FksjM8NywYRSHu1IlfxdP%2Fuploads%2F5qDDkHeViA32trKWvjGg%2Fimage.png?alt=media&#x26;token=422ff033-eef3-497a-9adf-75f545c2bb73" alt="" width="375"><figcaption></figcaption></figure>

Learn more about Email Bomb Protection here.

### New Role

* A new role, `Issue Responder` / `Global Issue Responder` , is now available. [Issue responders ](/learn-more/administration/admin-roles.md)have read-only access to the detections and settings that generated the issue and can't perform message or file searches.

  <figure><img src="https://3411262179-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FksjM8NywYRSHu1IlfxdP%2Fuploads%2F8FZ19C4kJoCRbPB6pa9j%2Fimage.png?alt=media&#x26;token=43470636-76eb-4efc-b75f-b0fd02c26038" alt=""><figcaption></figcaption></figure>

## 🐛 Fixes

* **Drive session activity renders correctly**: The session activity chart and file table in the evidence would sometimes not display. Both are fixed, with the full set of relevant activity types and no broken rows.
* **Adding permissions to Drive files works correctly**: Account and group selections in the Update External Permissions dialog were being dropped in the UI. Both paths work now.
* **Matching criteria showing up when editing a sensitive category**: The field was missing from the edit dialog. It’s back, pre-populated with your existing criteria.
* **Detection details load cleanly without flashing**: A re-render loop was causing the `Created by` field to flicker on load. Fixed.
* **Long sender addresses no longer run off the screen**: Truncated cleanly in phishing signals. Hover to see the full address.
* **The search shortcut stays out of your way**: It no longer steals focus when you’re typing elsewhere or when a dialog is open.
* **New threat categories labeled correctly in Email Threats Summary**: Categories with no prior-period history were showing a nonsensical percentage change. They now display “new this period.”

***

## :books: New and Updated Documentation

* Updated offboarding instructions for ATOR

#### Have you tried our doc assist?

You can start a conversation with the agent and it will search our docs to give you personalized answers and point you the the related pages. Give it a try and let us know what you think!

To try it out, click the icon to the right of the search box called **Ask Gitbook Assistant**:

<figure><img src="https://3411262179-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FksjM8NywYRSHu1IlfxdP%2Fuploads%2Fxv2BuGTNTav9Lpb8Wk90%2Fimage.png?alt=media&#x26;token=52980105-b78d-482e-a1ee-3a762efd5869" alt="" width="320"><figcaption></figcaption></figure>

Once you've asked it a question, let us know what you think of the answer with a thumbs up or down directly in the chat so we can update and improve our docs.

[^1]: an attack method that involves sending a large volume of emails within a short period, with the goal of overwhelming the receiver's inbox and potentially obscuring legitimate emails


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.material.security/whats-new/previous-releases/version-1.49.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
