KSA Domain Migration Status for Qualys Cloud Agent
Table of Contents
Following our earlier announcement of the introduction of KSA domain update notifications, Qualys has introduced new .sa domain endpoints to enhance regional performance and service delivery. This update provides the latest status of the Qualys Cloud Agent migration and outlines the required actions to ensure continued connectivity.
Note: This notification applies only to customers with subscriptions on the Kingdom of Saudi Arabia (KSA) platform. To identify your platform, please visit Identify your Qualys platform.
Automatic Migration Status
All supported Qualys Cloud Agents will be migrated from the legacy .com domain to the new .sa domain by July 20, 2026, in a phased rollout. Once migrated, they will communicate with the updated endpoints without requiring any customer action.
Endpoint Mapping
| Old Domain | New Domain | IP Address |
| qagpublic.qg1.apps.qualysksa.com | qagpublic.qg1.apps.qualys.sa | 141.147.134.190 |
| cask.qg1.apps.qualysksa.com | cask.qg1.apps.qualys.sa | 150.230.54.51 |
Container-Based Platforms
Automatic migration does not apply to the following container-optimized operating systems:
- Container-Optimized OS from Google
- Bottlerocket
- CoreOS
Required Action
Customers must redeploy containers using updated YAML configurations that reference the new .sa domain. Existing deployments will not transition automatically.
Availability of Updated Agent Binaries
By July 10, 2026, updated agent binaries with the new domain configuration will be available for download on the KSA pod.
Note: Cloud Agent for Windows is not platform-specific; therefore, no new binary will be released.
| Platform | Version |
| Linux Intel | 7.3.0-47 |
| Linux ARM | 6.1.2-4 |
| Mac Intel | 6.2.1-42 |
| Mac M1 | 6.3.1-40 |
| AIX | 6.0.0-44 |
| BSD | 7.1.0-31 |
| PPCLE | 3.21-9 |
| Solaris SPARC | 7.1.0-21 |
| ZLinux | 3.31.1-15 |
Important: Locally Stored Agent Binaries Require an Update
Customers deploying agents from internally stored or previously downloaded binaries should note the following:
- These binaries are still configured to use the legacy
.comdomain. - Agents installed using these binaries will continue to connect to the legacy
.comdomain. - They will not automatically switch to the new
.sadomain.
Required Action
Customers must download and deploy the latest agent binaries from the KSA platform to ensure that agents connect to the new .sa domain.
Manual Update for Agents Connecting to the Legacy .com Domain
If an agent is deployed using an older binary and continues to communicate with the legacy .com domain, customers can manually update it to point to the new endpoint. This can be done by executing the following command on the host system:
/usr/local/qualys/cloud-agent/bin/qualys-cloud-agent.shServerUri=https://qagpublic.qg1.apps.qualys.sa/CloudAgent/
This immediately switches the agent to the new .sa domain without requiring redeployment.
Timeline and Impact
- Migration for supported Qualys Cloud Agents: July 20, 2026
- Updated agent binaries available: July 10, 2026
- Legacy
.comdomain retirement: November 30, 2027
After the retirement date, any agent still configured to use the legacy .com domain will lose connectivity.
Identifying Agents Using the Legacy Domain
Customers can identify impacted agents by using:
QID 45781 – Qualys Cloud Agent Configured with Legacy KSA .com Endpoint
Available in: VULNSIGS-2.6.622-3
Token: vulnerabilities.vulnerability.qid:45781

Recommended Next Steps
- After the auto-migration is complete by July 20, 2026, validate that agents are communicating with the
.sadomain using QID 45781 to identify any remaining legacy configurations. - Replace any locally stored binaries with the latest versions.
- Redeploy container-based agents using updated YAML files.
- If you have questions or need assistance, contact your TAM or Qualys Support.