> For the complete documentation index, see [llms.txt](https://docs.defguard.net/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.defguard.net/in-depth/client-application-feature-compatibility.md).

# Client application feature compatibility

Defguard consists of multiple server-side components (Core, Gateway, and Edge) and multiple client applications (Desktop and Mobile).

For the purposes of compatibility and feature availability, this documentation assumes that:

* all server-side components are deployed using the same version and are collectively referred to as the **Server**;
* the desktop user-facing software is referred to as the **Desktop Client**;
* the mobile user-facing software is referred to as the **Mobile Client**.

Newer versions of the Desktop and Mobile Clients are always compatible with older Server versions. Therefore, you can update the client applications on your users’ devices before updating the Server.

Use this page to verify which client version is required to use specific features with your Server version, and whether updating the client applications is necessary after a Server upgrade.

The feature list focuses on cross-component features, meaning features that require cooperation between the Server and a client application. Server-only features are not included.

### Feature compatibility matrix

<table><thead><tr><th width="215.48828125">Feature</th><th width="96.0546875">Introduced in</th><th width="101.4453125">Min. Server version</th><th width="108.9140625">Min. Desktop Client version</th><th width="98.56640625">Min. Mobile Client version</th><th>Comment</th></tr></thead><tbody><tr><td><a href="/using-defguard-for-end-users/desktop-client/using-multi-factor-authentication-mfa.md#internal-mfa">Connecting to a location with Internal MFA (Email/TOTP codes)</a></td><td>1.4</td><td>1.4</td><td>1.4</td><td>1.5</td><td></td></tr><tr><td><a href="/using-defguard-for-end-users/desktop-client/using-multi-factor-authentication-mfa.md#external-mfa">Connecting to a location with External MFA (OIDC auth)</a></td><td>1.5</td><td>1.5</td><td>1.5</td><td>1.5</td><td></td></tr><tr><td><a href="/using-defguard-for-end-users/desktop-client/using-multi-factor-authentication-mfa.md#multi-factor-authentication-via-mobile-biometry">Connecting to a location with Biometric (using mobile client)</a></td><td>1.5</td><td>1.5</td><td>1.5</td><td>1.5</td><td></td></tr><tr><td><a href="/features/service-locations.md">Service Locations</a></td><td>1.6</td><td>1.6</td><td>1.6</td><td>Desktop-only</td><td>Older client applications won't get service locations in their configuration updates.</td></tr><tr><td><a href="/using-defguard-for-end-users/desktop-client/mtu-setting.md">Setting MTU</a></td><td>1.6</td><td>Client-only</td><td>1.6</td><td>Desktop-only</td><td></td></tr><tr><td><a href="/features/desktop-client-auto-provisioning.md">Desktop Client Auto Provisioning</a></td><td>1.6</td><td>1.6</td><td>1.6</td><td>Desktop-only</td><td></td></tr><tr><td><a href="/features/wireguard/behavior-customization.md#client-traffic-rules">Client Traffic Policy Selection</a></td><td>1.6</td><td>1.6</td><td>1.6</td><td>1.6</td><td>Older client applications ignore new "Force all traffic" option, but respect "Disable all traffic" because it maps to a legacy toggle</td></tr><tr><td><a href="/features/static-ip-assignment.md">Static IP assignment</a></td><td>2.0</td><td>2.0</td><td>1.4</td><td>1.5</td><td></td></tr><tr><td><a href="https://docs.defguard.net/2.1/features/device-posture-verification">Device Posture verification</a></td><td>2.1</td><td>2.1</td><td>2.1</td><td>1.7</td><td>Older client applications won't get posture-enabled locations in their configuration updates.</td></tr><tr><td><a href="/using-defguard-for-end-users/desktop-client/command-line-defguard-cli.md">CLI client</a></td><td>2.1</td><td>1.6</td><td>2.1</td><td>Desktop-only</td><td>Bundled with the desktop client.</td></tr><tr><td><a href="/features/service-locations.md">Service locations for Linux</a></td><td>2.1</td><td>1.6</td><td>2.1</td><td>Desktop-only</td><td>Older client applications won't get service locations in their configuration updates.</td></tr><tr><td></td><td></td><td></td><td></td><td></td><td></td></tr></tbody></table>
