Network Admins with All Sites access can now create and manage support tickets directly from the Juniper Mist portal. Previously, only Super Users, Org Admins, MSP Admins, and Helpdesk users could manage and create support tickets. Note that Network Admins assigned to specific sites cannot create or manage support tickets.
Marvis Minis now supports using site variables in configurations, providing a flexible way to reference site-specific values. The variables can resolve to different values for each site, allowing a single configuration to be applied consistently across multiple locations. You can add site variables using the {{variable_name}} format in the following fields under the Marvis Minis section on the Site Configuration page:
Excluded VLANs—VLAN IDs mapped to the variables are excluded from the Marvis Minis validations.
Endpoints— Marvis Minis uses the URL or IP address associated with each variable to validate application and network reachability.
VLANs in tests—Variables used to define the VLAN scope for individual tests enables Minis to run validations on the specified VLANs at each location.
This enhancement allows you to define a single configuration at the organization or site-level, while leveraging site variables to dynamically adapt the test parameters (VLANs, endpoints, and exclusion lists) to each site's specific network environment. This is useful in large deployments where VLAN IDs and test targets differ between locations.
Note that site variables must be defined in the Site Variables section of each site's settings.
The self-driving capability is now available for the Missing VLAN Marvis action. This action automatically detects situations where a VLAN is configured on an AP but is missing from the connected switch port. When this occurs, clients on the affected VLAN may be unable to communicate on the network or obtain an IP address from the DHCP server.
With the self-driving capability enabled, Marvis can automatically add the missing VLAN to the affected switch port, restoring connectivity for impacted clients. The Missing VLAN pop-up window provides information about the affected port, scope ID, issue start time, last observed time, Minis result, and the most recent client event related to the issue. If the self-driving action completes successfully, the outcome is displayed as Success.

We have enhanced the self-driving capabilities of Marvis to proactively manage Layer 2 loops. When Marvis detects a Layer 2 loop on a port, it can now automatically take remedial action by disabling that port. The View More link provides a Marvis Self-Driven Actions table showing the execution details and outcomes. After an administrator physically removes the looped cable, ports disabled by Marvis can be re-enabled through the Enable Port option.
The self-driving capability for the Loop Detected Marvis action is disabled by default.

We have made the following enhancements to the Authentication Failure Marvis action to provide deeper visibility, precise root-cause identification, and actionable recommendations:
Authentication failures are classified with detailed reason codes that pinpoint the exact root cause.
The View Details page provides more details so you can quickly understand the scope of the issue. You can view time-series trends of success versus failure rates by failure reason for affected WLANs, making it easier to correlate issues with specific timelines or events. You can also see the results from the Marvis Minis validations.
Recommended actions are now dynamically adapted based on the detected failure code.
Authentication failures from the same authentication server across multiple WLANs or sites are grouped into a single organization-level action, which is also visible at the site-level. This provides a consolidated view of server-side connectivity problems.
The NAC Endpoints page now includes an optional Sites field, allowing endpoints to be associated with one or more sites. Endpoint registration can therefore be enforced based on the endpoint’s location. Endpoints that are not assigned to any site remain accessible from all sites.

Mist Access Assurance now supports site variables in VLAN labels, making it easier to manage Auth Policies across large, multi-site environments. This enhancement enables a single Auth Policy to return a VLAN label containing a site variable, such as {{printer}}. During client authentication, Mist Access Assurance automatically resolves the variable to the VLAN value configured for the client’s site. For example, the same policy can assign: VLAN 100 for printers at Site A and VLAN 101 for printers at Site B. This eliminates the need to create separate policy rules for each site and use case, significantly reducing policy complexity and operational overhead.

Mist now extends its cloud-managed networking experience to HPE Networking AOS-CX switches, simplifying operations across mixed-vendor network environments. The following CX switches are supported:
CX5420 Series
CX6300 Series (CX6300M and CX6300F)
CX6400 Series (CX6405 and CX6410)
The CX Series switches are high-performance switches designed for enterprise access, aggregation, and core network deployments. They provide a foundation for scalable, resilient networks that support IoT, mobile, and cloud applications.

You can now onboard, configure, monitor, upgrade, and troubleshoot supported CX switches directly from the Juniper Mist portal. CX switches support key capabilities, including template-based configuration, Layer 2 and basic Layer 3 functions (static routes, OSPF, VRF), preformed Virtual Switching Framework (VSF), dynamic port configuration, upgrades and upgrade orchestration, Mist NAC, remote shell and diagnostics, Marvis Actions, and Marvis SLEs.
You must upgrade CX Series switches to the AOS-CX version 10.18.1002 or later before onboarding them to Mist.
In this release, these switches do not support a few Mist features, which are listed in Explore Juniper Mist Features.
For steps to onboard a switch to Mist, refer to Onboard Switches to Mist Cloud.
You can now view and manage Marvis Actions for a switch directly from the Front Panel view on the switch details page, eliminating the need to navigate to the dedicated Marvis > Marvis Actions page when troubleshooting switch and port-level issues.
When you select the Marvis Actions overlay on the front panel, ports with active Marvis Actions are highlighted along with the action count per port. Hovering over a port displays a summary of the active port-level actions for that port, and clicking the port opens a sidebar with detailed root-cause insights and available remediation workflows. Device-level actions, such as switch offline, high CPU or memory utilization, and switch-wide configuration issues, are not tied to a specific port. They are displayed separately in the sidebar outside the front panel port context.

The following user roles can view Marvis Actions on the switch details page with an active Wired Marvis subscription: Super User, Network Admin, Helpdesk, and Observer.
You can now enable organization-wide cleanup of stale switch configurations directly from the Mist portal. This option, applicable to EX and QFX Series switches, removes all configurations on managed switches that were not pushed by the Mist cloud, including any configurations applied natively through the switch CLI.
By default, the Mist cloud only removes cloud-managed configuration elements such as VLANs, interfaces, and protocols during a configuration push. However, configurations added directly through the switch CLI remain on the device. Over time, these unmanaged configurations can accumulate and cause configuration drift, potentially leading to unexpected behavior or conflicts with cloud-managed settings. With the new Clean Up Stale Configuration option, you can ensure that your switches remain in a known-good state, fully aligned with the configurations defined in the Mist cloud.
To enable this feature, navigate to Organization > Settings and locate the Switch Management tile. Set Clean Up Stale Configuration to Enabled and click Save.

Note that configurations defined via the Additional CLI Commands option in Mist are not affected by this cleanup.
The event type filter on the Insights > Switch > Switch Events page now supports both Include and Exclude filter modes, giving administrators greater flexibility when reviewing switch event data.
Previously, the event type filter only allowed users to select specific event types to display. With this enhancement, users can now choose to exclude specific event types from the results, making it easier to filter out high-frequency, low-value events (such as Port Up and Port Down) and focus on more relevant operational data.

Juniper Mist now supports private VLAN (PVLAN) configuration for switch management, enabling granular Layer 2 micro-segmentation directly from the Juniper Mist portal. Private VLANs isolate client traffic within the same VLAN without requiring additional Layer 3 subnets or IP address space allocation. Devices remain on the same network and can access shared services such as the gateway, DHCP server, and firewall, while communication between devices is blocked.
To create a private VLAN, select the Enable Isolation checkbox and specify an Isolated Network VLAN ID when editing or creating a Network from a switch template or switch details page.

When configuring a port profile on a switch, you can use the Allow communication to isolated network option to allow clients on that port to communicate with isolated networks (private VLANs). For profiles configured in Trunk mode, you can also use the Inter Switch Isolation Link to extend the isolation to upstream switch or interconnected switch. This option must be configured on both ends of the switch-to-switch link.
Campus fabric deployments do not support private VLANs.
For more information, refer to Configure Private VLAN (EX and QFX Series Switches).
Mist now supports configuring Link Aggregation Control Protocol (LACP) in passive mode on aggregated Ethernet (AE) interfaces. Available from the port configuration tile at both the device and template levels, this option allows an interface to wait for the remote peer to initiate LACP negotiation rather than actively initiating it.
Previously, when port aggregation with LACP was enabled on switch interfaces managed through the Juniper Mist portal, interfaces operated exclusively in LACP active mode, with no option to configure passive behavior. This enhancement provides greater flexibility to support a wider range of interoperability and deployment requirements.

The Switch Insights page now provides an OSPF summary table that displays near real-time status of OSPF neighbors and peers. The data is refreshed automatically every 3 minutes. You can also refresh the data manually to retrieve the latest status. The summary is available when OSPF is enabled on the switch and at least one neighbor has established full adjacency.

We have added support for RADIUS-based admin authentication for Juniper EX and QFX Series switches managed through the Mist cloud, providing an alternative to the existing TACACS+ option. RADIUS authentication enables switch administrator logins to be authenticated against RADIUS servers configured at the device, site, or organization level.

RADIUS for switch authentication can be configured using one of the following options:
Shared RADIUS server—Reuses the existing RADIUS servers already configured for user authentication, simplifying deployment and minimizing additional infrastructure requirements.
Dedicated RADIUS server—Uses separate RADIUS servers exclusively for switch admin authentication. This option can be used in the following scenarios:
The RADIUS infrastructure used for switch administration is separate from the RADIUS infrastructure used for end-user authentication.
Mist Auth is used for user authentication, whereas a dedicated RADIUS infrastructure is required for switch admin authentication.
RADIUS-based authentication is required for switch admin access, but no RADIUS infrastructure currently exists for user authentication.
Based on customer feedback, we have improved the port configuration editing experience from the Switch Details front panel.
When administrators select a switch port and use the Modify Port Configuration option on the front panel, Mist now reopens the existing port-specific configuration when one is already present, allowing it to be updated directly. Changes to individual attributes, such as interface descriptions, administrative status, or PoE alerts, preserve the existing port profile and all associated settings, including VLAN assignments, authentication configurations, and trunk parameters.
Previously, when administrators selected switch ports from the front-panel view on the switch details page and clicked Modify Port Configuration, Mist defaulted to creating a new port configuration instead of reopening the existing port-specific configuration.
We have expanded our third-party cellular edge integrations to include support for the Ericsson Cradlepoint W2255 5G adapter. You can now view and monitor your W2255 devices alongside existing cellular edge devices directly within the Juniper Mist Cloud Portal. To view your W2255 devices, navigate to Organization > Inventory > Cellular Edges, or go to Monitor > Service Levels > Insights and select your W2255 device from the site/device drop-down menu.

Key Capabilities:
View device connection status, uptime, firmware version, MAC address, and active SIM status under Organization > Inventory > Cellular Edges and Monitor > Service Levels > Insights > Cellular Edge Insights.
Monitor real-time and historical cellular signal quality metrics, including RSRP, RSRQ, SINR, and RSSI, to ensure optimal 5G/LTE WAN connectivity.
Graphically inspect physical RJ-45 ports, active SIM slots, LAN interface assignments, and WAN cellular details (carrier, IP, Rx/Tx bytes, IMEI, IMSI).
Track lifecycle events (such as cellular connection state changes and reboot logs) and initiate remote device reboots directly from the device details page.
Mist now provides a new infrastructure alert, AP L2TP Tunnel Down, that notifies administrators when an access point's (AP's) L2TP tunnel to a Mist Edge (or other L2TP peer) goes down and fails to reconnect.
Previously, tunnel outages were only visible through AP health indicators in the dashboard, and administrators had to investigate manually or open support tickets to determine the cause. With this new alert, the system proactively notifies administrators when an AP's tunnel to a Mist Edge goes down and remains disconnected. Note that a tunnel-down alert is generated only when the AP fails to reconnect to the Mist Edge. Temporary tunnel interruptions that successfully recover do not trigger an alert.
You can enable the AP L2TP Tunnel Down alert from the Infrastructure section on the Monitor > Alerts > Alerts Configuration page. You can enable this alert for your entire organization or for specific sites, and configure email notifications to organization admins, site admins, or additional email recipients.

You can now enable ultrawideband (UWB) for your Juniper Mist Location Services deployments. Ultrawideband provides more precise accuracy by using 500 MHz channel bandwidths that do not interfere with other channels. It also produces time series signals, rather than signals in the frequency domain, and provides a more precise measurement using Time of Flight (ToF), which provides sub-meter accuracy.
With this release, Mist supports and adheres to the Omlox ultrawideband standard.
For this release, Mist AP47s work strictly with ultrawideband tags from third-party vendor SICK (formerly known as Zigpos). The AP47 participates as a passive listener while time synchronization and broader real-time location system (RTLS) control remain with the external SICK-based infrastructure. This combination enables you to extend sensor density and improve tracking coverage.
To enable ultrawideband:
1. Navigate to Organization > Site Configuration, or to Organization > Wireless > Device Profiles.
Under UWB Settings, select the Enable SICK RTLS checkbox and enter the Host Name and Port.

NOTE: Currently, AP47D/E models support ultrawideband, and it is recommended that you enable ultrawideband at the site-level so that all APs in the site inherit the necessary configuration. If you choose to enable at the device-profile level, that configuration will override the site-level configuration.
With Mist’s introduction of ultrawideband (UWB) comes support for the Omlox ultrawideband standard. In this, AP47D/E models can now be used as passive UWB sensors for Omlox-compliant asset-tracking deployments.
AP47s collect UWB tag data from third-party vendors such as TRUMPF, LEEDARSON, or SICK (formerly known as ZigPos), and forward it to the third-party’s real-time location system (RTLS). In other words, the AP47 participates as a passive listener while timing synchronization and broader RTLS control remain with the external infrastructure.
This combination enables you to extend sensor density and improve asset tracking coverage in environments that already use an external Omlox infrastructure, making it ideal for deployments that use AP47s with a pre-existing Omlox setup.
You can now enable Juniper Access Points (APs) to stream BLE tag RSSI data directly to a configurable MQTT (Messaging Queuing Telemetry Transport) broker or HTTP(S) server. This enhancement removes the dependency on the Mist cloud and Wiliot Bridge, as it provides a lightweight, real-time, and scalable BLE telemetry framework suitable for enterprise and partner integrations.
This is supported in cloud, on-premises, and hybrid environments. For on-premises deployments, local offload is provided by the AP streaming BLE RSSI data to a local MQTT broker within the customer network. In cloud deployments, the AP sends BLE RSSI telemetry via HTTPS POST to a cloud-hosted RESTful API or webhook endpoint. In hybrid environments, the AP filters assets and routes some telemetry to the local MQTT broker and others to the cloud webhook, based on asset type or name filters.
To enable BLE RSSI streaming to a MQTT broker or HTTP(S) server:
Ensure that you have an active Asset Visibility subscription and that your APs are on firmware version 0.15.34930 or later.
Navigate to Organization > Site Configuration, then select the site where you want to enable BLE RSSI streaming.
In the Location Services section, under Bluetooth based Location Services, select the Asset Visibility checkbox, then select the MQTT checkbox. Then, fill in the fields including the broker information and Data Format (Raw or Parsed).

NOTE: It is recommended that you enable MQTT at the site-level so that all APs in the site can stream BLE tag RSSI data. However, if you choose to enable this at the device-profile level, that configuration will override the site-level configuration.
Juniper Mist is deprecating the legacy site-level Marvis Insights API endpoint and its corresponding UI view—previously accessible under Monitor > Marvis Actions—in favor of the unified Alerts framework. Customers and integrations currently relying on this endpoint must migrate to the replacement Alerts endpoints before the End-of-Support date.
The following will not be supported after December 2026.
API Endpoint—GET /api/v1/sites/{site_id}/insights/marvis
UI View—Analytics > Events
Customers should migrate to the following alerts API endpoints:
Purpose | Endpoint |
Search site-level alerts | GET /api/v1/sites/{site_id}/alarms/search |
Search org-level alerts | GET /api/v1/orgs/{org_id}/alarms/search |
Retrieve alarm definitions | GET /api/v1/const/alarm_defs |
Manage org-level alarm templates | GET /api/v1/orgs/{org_id}/alarmtemplates |
The UI view corresponding to the site-level Marvis Insights API endpoint will be incorporated under Monitor > Alerts.
Milestone | What to Expect | Target Date |
Deprecation Announcement | Official notice issued; legacy endpoint remains fully functional | June 2026 |
UI Deprecation | The Analytics > Events page removed from the Mist portal | September 2026 |
API End-of-Support (EOS) | Legacy API endpoint removed; all calls will return HTTP 410 (Gone) | December 2026 |
All customers and API integrations using GET /api/v1/sites/{site_id}/insights/marvis must complete the following before December 2026:
Migrate to GET /api/v1/sites/{site_id}/alarms/search (or the org-level equivalent) with equivalent query parameters.
Use GET /api/v1/const/alarm_defs to map legacy Marvis insight types to their corresponding alarm definitions.
For organizations managing alarm policies via API, switch to GET /api/v1/orgs/{org_id}/alarmtemplates for template management.
Test the new endpoint responses against your existing workflows and integrations prior to the end-of-support date.
To enhance security and align with industry best practices, we have deprecated Basic Authentication for all use cases—including admin logins and scripts.
Why we are making this change
Basic authentication poses several security risks:
No multi-factor authentication (MFA) support
Credentials transmitted with every request (even over HTTPS)
No scope limitations
Vulnerable to credential theft and reuse
Industry security organizations (OWASP, NIST, CIS) strongly recommend token-based authentication as a more secure alternative.
Required actions
Update all applications and integrations to use token-based authentication.
Remove basic authentication from your implementations.
Migration resources
Documentation: Mist API Tokens
Support: Contact us at support@mist.com for assistance
The Marvis Minis page will be deprecated at the end of Q4 2026 and all information related to the Marvis Minis validations will be available on the Marvis Minis SLE page (Marvis > Marvis Minis SLE). We recommend that users begin using the Marvis Minis SLE page ahead of this transition to ensure a seamless experience. APIs will be supported until the end of Q1 2027.