Security Center
Ubuntu 26.04’s Security Center application displays some system security state and provides the control surface for experimental Home directory permission prompting. It is not a replacement for every security tool; firewall, automatic updates, Ubuntu Pro, and compliance hardening still use their dedicated tools.
Overview
Security Center is part of the Ubuntu 26.04 desktop security experience. According to the current official release notes, the confirmed focus is security-state visibility and experimental permission prompting together with prompting-client.
Launching Security Center
# Via the application menu
# Search for "Security Center" in the Activities overview
# Via command line
snap run security-centerKey Features
Security Status Overview
Security Center can show relevant system security state. The exact displayed items may change in later updates, so treat it as a desktop security-status entry point rather than a full audit tool.
Permission Prompting Toggle
Ubuntu 26.04’s permission prompting system can be enabled or disabled from Security Center. The current focus is experimental Home directory permission prompting.
Related components include:
security-center: graphical management entry pointprompting-client: seeded snap for handling permission prompts
For more details, see Permission Prompting.
Features That Still Use Dedicated Tools
System Updates
# Check for security updates
sudo apt update
apt list --upgradable 2>/dev/null | grep -i security
# Install security updates only
sudo unattended-upgrade -vFirewall
# Check firewall status
sudo ufw status verbose
# Enable firewall
sudo ufw enable
# Add rules
sudo ufw allow 22/tcp
sudo ufw allow 'Nginx Full'Security Audit
Security Center is not a full audit tool. For login, security event, or service-state investigation, continue to use logs and dedicated commands:
# View failed login attempts via command line
journalctl -u ssh.service | grep "Failed"
# View recent login records
last -n 20
# View failed login attempts
lastb -n 20
# View sudo usage records
journalctl _COMM=sudo --since todayCommon Security Baseline Commands
# Enable automatic security updates
sudo dpkg-reconfigure -plow unattended-upgrades
# Enable firewall
sudo ufw enable
sudo ufw default deny incoming
sudo ufw default allow outgoing
# Set screen auto-lock (5 minutes)
gsettings set org.gnome.desktop.session idle-delay 300
gsettings set org.gnome.desktop.screensaver lock-enabled true
gsettings set org.gnome.desktop.screensaver lock-delay 0
# Disable automatic login
sudo nano /etc/gdm3/custom.conf
# Ensure AutomaticLoginEnable=falseUbuntu Pro
# Check Ubuntu Pro status
pro status
# Attach Ubuntu Pro subscription
sudo pro attach TOKEN
# Enable ESM (Extended Security Maintenance)
sudo pro enable esm-infra
sudo pro enable esm-appsLivepatch (live kernel patching)
Livepatch is a separate Ubuntu Pro service that applies critical kernel security patches without a reboot. AMD64 has supported it for years; Arm64 reached GA in June 2026. Full background, pro enable livepatch and canonical-livepatch commands are in Post-release news — June 23 Arm64 Livepatch GA.
Security Compliance
Ubuntu Pro users can use USG (Ubuntu Security Guide) for CIS benchmark auditing and hardening:
# Enable USG (Ubuntu Security Guide) for CIS benchmark compliance
sudo pro enable usg
# Run CIS compliance audit
sudo usg audit cis_level1_server
# Apply CIS security hardening
sudo usg fix cis_level1_serverTroubleshooting
Security Center Won’t Launch
# Check snap status
snap list security-center
# Reinstall
sudo snap remove security-center
sudo snap install security-center
# View logs
journalctl --user -u snap.security-center* --since "1 hour ago"Security Status Displays Incorrectly
# Manually refresh security status
# Click the refresh button in Security Center
# Or cross-check state via command line
sudo ufw status
pro status
apt list --upgradable
sudo dmsetup statusRelated Articles
- Permission Prompting — How Ubuntu 26.04’s new app permission prompting system works and how to configure it
- UFW Firewall — Detailed UFW firewall configuration guide with common rule examples
- SSH Security — SSH service hardening including key authentication and Fail2Ban configuration