↓ Skip to main content
  1. Posts/

What's new in Parallels RAS 21.2: the features that matter for admins

Author
Edwin Houben
Personal notes from the field. Opinions are my own and do not represent Parallels.

Parallels RAS 21.2 shipped on 23 June 2026, followed by 21.2 Update 1 in August. It’s a feature release rather than a hotfix: it brings new providers, more control at host-pool level, security hardening and a set of end-user improvements. Below is my take on what actually changes your day-to-day as an admin, and what I’d test first in a POC.

Where 21.2 sits in the RAS 21 timeline
#

RAS 21.0 arrived in November 2025, followed by 21.1 in February 2026 and 21.2 in June 2026. 21.2 is the current feature release. The Update 1 on top of it is mainly a stability release, with one critical fix you’ll want if you run Hyper-V clusters (more on that below).

Platform: more places to run your workloads
#

Nutanix Prism Central as a provider. You can now add Prism Central, not just individual Prism Element clusters. Parallels positions this as better multi-cluster and hybrid-cloud compatibility with the current Nutanix architecture. If your customer runs several Nutanix clusters, that’s one provider entry instead of many.

The Custom Provider Framework. This is the one I’m most excited about. It gives you a supported way to plug hypervisors that aren’t natively supported into RAS, while RAS keeps doing what it does best: brokering, host pools and application delivery. For POCs on “less common” platforms, this removes a big blocker.

Scale Computing HC3 9.6. Support for HC3 9.6 is added, and support for HC3 9.2 is removed. Check your customer’s HC3 version before upgrading RAS.

Azure and Azure Virtual Desktop. Two additions here:

  • Trusted Launch as a VM security type for Azure and AVD providers, which brings Secure Boot and virtual TPM to your session hosts.
  • Azure Availability Zones, so you can pick the zones for your Azure and AVD session hosts.

Together they make it a lot easier to meet the “secure by default, resilient by design” requirements that come up in almost every Azure security review.

Admin experience: more control per host pool
#

The change I expect to use the most is overriding settings at host-pool level:

  • VM sizing and specifications can now be set per host pool instead of only per template.
  • The Active Directory OU can be overridden per host pool too.

That means one template can serve several host pools: for example a “standard” pool and a “power users” pool with bigger VMs, each landing in its own OU with its own GPOs. Fewer templates means less image maintenance.

Other admin-side improvements:

  • Sessions in a “Down” state: you get clearer visibility, and you can configure how RAS handles them. Unresponsive sessions are a classic helpdesk ticket, so this is welcome.
  • Quarantined printers: new visibility and management controls, which helps when you’re troubleshooting redirected printing.
  • Cost Insights for AVD now supports custom time ranges, so you can report on a sprint, a month or a quarter.
  • Configurable thresholds for failed Secure Gateway session notifications, so you only get alerted when it matters.

Security: tighter Gateway and client controls
#

  • Granular access control for RAS Secure Gateways. You can now manage access to standard RAS sessions, the User Portal authentication pages, the Web API and the Connection Broker API independently. If a Gateway only needs to serve sessions, you can stop exposing the rest. That’s a quick win for any DMZ design review.
  • Automatic client logout while sessions stay active. Users can be signed out of the Client or User Portal while their remote sessions keep running. That’s useful for shared devices and for stricter compliance policies.
  • Crypto and runtime updates. OpenSSL moves to 3.5.6 and FIPS to 3.1.2 with FIPS 140-3 validation, and .NET moves to 10.0.7.

User experience: the Web Client grows up
#

  • Local file access and multi-file transfer in the Web Client. Users can upload and download files between their device and remote applications, several files at once. Admins can also suppress the “Save As” prompts to streamline multi-file uploads.
  • Experimental file-content caching for redirected drives, which improves save performance from a remote session with Parallels Client for Windows. It’s experimental, so try it on a pilot group first.
  • macOS users get richer clipboard redirection (including images) in the macOS Client, and Command+C/V/A/X support in the User Portal.
  • Linux Client and IGEL OS12 get extended USB redirection (including HID peripherals), and IGEL OS12 gets passthrough authentication.
  • Clearer launch feedback in the Windows and Web clients, so users can see that an application is still opening. That means fewer double-clicks and duplicate sessions.

21.2 Update 1: install it if you run Hyper-V clusters
#

Update 1 fixes a critical issue where the VDI Provider Agent could stop responding when it manages Hyper-V clusters. It also adds a registry setting to disable application monitoring on VDI Guest Agents, and runtime input-locale propagation so keyboard language changes are redirected correctly.

What I’d test first in a POC
#

  1. Host-pool overrides: one template, two host pools with different VM sizes and OUs.
  2. Secure Gateway granular access: lock a Gateway down to sessions only, and confirm the User Portal still works through the Gateway that is meant to serve it.
  3. Web Client file transfer: it’s the feature end users notice first.
  4. Trusted Launch on Azure/AVD, if the customer has a security baseline that requires it.

As always: read the full release notes before upgrading production, and check the supported versions of your hypervisors and clients.

Key takeaways
#

  • 21.2 adds Nutanix Prism Central, the Custom Provider Framework, Scale HC3 9.6 (9.2 dropped), and Trusted Launch plus Availability Zones for Azure/AVD.
  • Host-pool-level overrides for VM sizing and AD OU cut down on template sprawl.
  • Secure Gateways can now expose only the services they need.
  • The Web Client gets local file access and multi-file transfer.
  • Apply 21.2 Update 1 if you manage Hyper-V clusters.

Sources
#

Related