Skip to main content

142 docs tagged with "Release Notes"

View all tags

Access Request date pickers

In the Access Request process, the date picker for Valid from to Valid to dates will display according to your language browser and not the language is chosen in the 01.

Access request new tab

We have introduced a new tab to improve your access management process. Now, there is a new tab that displays any access you requested manually by typing in the box when accessing request. To view it, go to the Access tab in your navigation pane and you will see the new tab added.

Active Directory task error when updating object

The Active Directory (AD) connector reported errors for modify provisioning tasks for users sharing the name with a computer object in AD. The issue has now been resolved and errors no longer occur.

Add attribute chip in Access request

We have fixed an issue in the Review step in the Access request form where there was a chip to modify the attributes even though you cannot modify them.

After hiding all columns rows are clickable

On the new UI Tasks, Access Requests and Delegations views, if you hide all of the rows and columns you can still click on the rows. When hovering over a row, the row is highlighted and the pointer is changed to indicate that the row is clickable. When clicking, it navigates to the details of the hidden items. To fix it, always show at least one column.

Archive view logic fails for NULL values

There was an issue with the custom view failing on null values. The issue has been resolved and if it can't be determined if an attribute is single or multivalued it is registered as a multivalued one, not returning null.

Attribute type property

In the new UI, for an attribute type based on the Integer data type, if you set the Max. length value to 0, you won't be able to enter any number. You need to leave the field value empty.

Attribute values in the legacy access request process

In the legacy request access process, you will be asked for an account type when the resource allows more than one account type, the resource has visible attributes, and a request is being made for the resource for more than one identity, where each identity has one valid account.

Attribute values not copied on child assignments

We fixed an issue in RoPE where attribute values originating from the AttributeResolver extension were not being copied onto child assignments. The resolver was updated in version 14.0.15, in response to a reported issue of attributes from the same extension not being aggregated, and it has now been further improved.

Azure application insights

We are launching our integration to Azure Application Insights. This tool will help us to gain valuable insights into the usage of our product. It's crucial for us to communicate the following points clearly:

Changed the link on the access request button

The + button on the access request list view will now link to the Technical Preview New UI Access request process instead of the legacy access request. The default shortcut on the homepage will still link to the legacy access request.

Comparing times in calculated assignment

We have fixed a bug that happened when running a timer on an Event Definition for a Calculated Assignment if you filtered the dates using Valid from or Valid to and compared them to Now.

Connectivity package export issue

There was an issue with creating connectivity package to be exported. In the dialog box allowing the user to override export parameter values, an integer type parameter had a non-empty value and the connectivity package was not created. The issue has been resolved.

Copy rule bug with access requests

We resolved a bug associated with the default copy rule Onboarding contractor to Access request (v2). Previously, if the copy rule included additional fields apart from the default Contractor Identity to Request is for, the value in the Request is for field would be cleared during the request access process initiated after the contractor completed onboarding.

Data model JSON converter

There was an issue with the appropriate conversion of JSON payload into data model. The issue has now been fixed and the properties are specified as multivalued, by the converter, if the JSON payload contains array tokens.

Deleting single resource issue

Deleting a single resource that was part of a prioritization policy made the edit prioritization policy show no resources. The issue has been fixed.

Disable written-request access

It is possible now to disable written access requests. To do that go to Set up > Forms and select the Request access (ed2) - Submit form.

Enhanced information boxes in Access page

Boxes displaying information about your requested accesses have been improved. When you check the access you requested, the text will now appear in a user-friendly box, even if it is long, making it easily readable.

Error in account trust after CU24 April update

We've fixed an issue in RoPE where Direct Assignments to a permission resource referencing the system of the permission resource but depending on an account in a trusted system weren't linked to the trusted account.

Error when sorting resources

There was an issue causing an error when sorting by resource on the Identity page, in the Resource Assignment section. This has been fixed.

Error when sorting resources

There was an issue causing an error when sorting by resource on the Identity page, in the Resource Assignment section. This has been fixed.

Error when updating survey objects

If you submitted a survey question and tried to edit multiple survey questions afterwards, it was resulting in an error. Now, this will not cause an error.

Exchange migration fails

An issue with the migration of the extension attributes during the Exchange migration process has been resolved and is now successful.

Export survey questions in CSV format

As the survey administrator or the survey respondent, you can now export survey questions in a CSV (Comma-Separated Values) format, in addition to the existing option of exporting them as PDFs. This feature empowers our users to obtain a comprehensive and structured overview of survey questions, facilitating seamless audits and analysis.

Extend access list view

You will find a new tab under Access tab called Extend Access Requests. A new list view lists only the extend access requests.

Improvements to SQL Query Collector and SQL Query Collector for Generic Database

Both SQL Query Collector and SQL Query Collector for Generic Database have been enhanced with the support of synonyms for the Oracle Database. The performance on the Queries and Mappings is also improved if in the connection details the database schema is provided. Furthermore, SQL Query Collector for Generic Database, multiple system deployment, performs a comparison (case insensitive) of the system business key in the query.

Incorrect links in Access request

On the Access request page, when a user was on any page with a nested route, such as /access/access-requests, clicking on the required updates link would navigate to the incorrect URL.

Issue with applying SystemInfo.sql

There was an issue with applying SystemInfo.sql to OIS v14u15 database. We have fixed the diagnostic of the SystemInfo SQL script to work on latest version of Omada Identity Database.

Issue with Attributes on deprovisioning jobs

We've fixed an issue in the calculation of attribute values for an assignment in the Disabled state. Previously, under some circumstances, the attributes were not added which could cause a challenge during deprovisioning. With the introduced fix, the attributes for disabled assignments can be assigned.

Issue with duplicating delete tasks

Fixed an issue where the OPS claimed for a completed account removal task and got a Add/Modify action instead of Remove. This caused a duplicate deleted task.

Issue with mailboxes in Exchange Hybrid

We have fixed an issue with mailboxes in the Exchange Hybrid. The personal mailbox was set to be deprovisioned if another mailbox for the admin account existed.

Issue with migrating collectors

There was an issue with migrating two Active Directory systems trusting each other. The issue has been resolved and the migration process is successful.

Issues during system import

When import was failing for all systems, it could lead to import lock and result in integrity errors and import rollback afterwards. Now if import for all systems has failed, the Resolve primary identities step of the process is skipped to avoid unnecessary processing.

Link header for REST connectivity

The choice of paging mechanism for REST collector has been extended with the Link header option. It allows the collector to verify if the response header contains link with the rel="next", pointing to the next page.

Multiple activities in the survey process template

Configuring duration for the activities in the survey process template, requires ensuring that appropriate amount of time is allocated for each of the activities. Currently, when a survey is launched, all activities start simultaneously. This may result in lack of sufficient time for assignees in subsequent activities to complete their tasks effectively.

My identities - access modifier handles parameter wrong

When utilizing the Service Desk Agent mode within the Omada.OE.Solution.OIM.AppLogic.AccessModifiers.IdentitiesAccessModifier access modifier, we now only load identities associated with the active user, provided that the user has access to these identities through membership in the Service Desk Agents user group.

New access request icon

We have introduced a new icon for the new access request flow in the new UI. Now, you will see two different icons in the Home page for requesting access.

New icon in Access Request

We have added a new icon in the Access request process for resources which belong to Omada Identity system. This will make it easier to differentiate the resources when selecting them in the Access request.

New IGA Classification Chapter for IdentityPROCESS+

In this release, we've added a new chapter to the IdentityPROCESS+ document that focuses on IGA classifications. This chapter emphasizes the importance of classifying access in your IGA solution and explains the distinction between data classification and IGA classification. This new chapter aligns with prominent cybersecurity frameworks like NIST, ISO 27002, COBIT, and CIS, highlighting the significance of IGA classification in the realm of IGA.

New lookup field in access request

We've improved the lookup field for selecting attributes during the access request process. Now, you can easily add values by clicking the Add value chip or the arrow icon. Upon clicking either, a second panel will open up. To enhance the overall user experience, we have also introduced filters in the grid.

New translations

We have changed our translation process in an effort to enhance the quality of our translations. As a result, you may notice some changes in the output for certain languages and maybe some quality issues. This adjustment is part of our ongoing commitment to providing the best possible translation experience. While we strive for improved quality, we kindly ask for your patience as it may take a few months to fully reach the desired level of quality.

New UI list print

Now, the table control buttons are not visible in the printed output when Export > Print functionality is used in React view specifically in the Access Requests, Access Delegations, and Tasks sections.

New UI Main menu icons

We have updated the New UI Main menu document, and now the document contains the updated icons.

New UI sorting columns

The Access Request tab on the Access Request page now allows you to receive paged results from the server. The server executes the list sorting and filtering, improving the performance of exploring the Access request list.

New warning message in access request

We have enhanced the experience when requesting access. Now, a warning message pops up to notify you that your changes may not be saved. This message will appear when:

Omada Identity Graph API datetimes

For Omada Identity Graph API version 2.3 consumers, the user's selected timezone is now available in the API. All datetimes will be in the UTC time standard. You can convert the time using the following query and the baseUtcOffsetInMinutes property:

Omada Identity Graph API extended for Access Approvals

The Omada Identity Graph API has been extended to include endpoints for managing access approvals. This extension allows you to integrate with Omada Identity's approval process, enabling you to create your own UI for approval workflows.

Omada Identity Graph API search filtering

In Omada Identity Graph API version 2.5, the accessRequestComponents/resources query offers enhanced filtering capabilities. It allows filtering based on attributes such as resourceOwnerId, resourceTypeId, and contextObjectId, which points to objects belonging to a context associated with the resource.

Popular resources are always displayed first

By default the customer setting arPopularityEnabled is always turned on for the filtering version. In parallel, this parameter can be turned on or off for the paged version. As a result, Resources on the filtering version can't be sorted alphabetically unless the context is disabled.

Potential memory leak

For the REST connector failed jobs with multiple tasks consumed extensive amounts of memory resulting in OutOfMemory issues. The issue is resolved by the addition of the errorResponseFilter parameter. Enabling it overrides the default behavior during error occurrance, when the whole response is logged. Instead, it provides JsonPaths to properties which should be extracted from the response body.

Preview update button is missing

We have identified an issue where the preview update button is missing in System Queries & Mappings. If you encounter an error during upgrading, you'll need to perform the update manually by adding the script jsinc/OIM.SystemOnboarding.DataMapping.Preview.QandM.js to System onboarding > Script files.

Release Notes

The Omada Identity release bring exciting improvements and enhancements in a variety of the product areas. Read more about the changes and bug fixes introduced in the Omada Identity version 14 update 16 (14.0.16).

Resource status update issue

When either ValidFrom or ValidTo fields are empty in a Resource object (but not both), the Resource status is not updated correctly with the associated event definitions.

RoPE calculation resolves incorrect attributes

We've improved RoPE's calculation of effective attribute values when the identity data object is updated during the transition from the RoPE batch phase to the RoPE identity calculation phase.

SAP HANA Database connectivity package

New connectivity package for SAP HANA Database systems has been added. It is capable of creating, reading, updating, and deleting users. Additionally, reading database roles and user groups, and managing assignments to both of them. On top of that it also supports password reset.

Scope is omitted while provisioning an account

The validation for user objects was not included if dn in the provisioning task was defined in the scope in the connector settings resulting in the scope being omitted during provisioning. The validation has been added and the provisioning process runs correctly.

Scroll bar disappears in Activity History

Before the fix, when you expanded an entry in Activity History, that had no modified fields (table with Field, Changed from and Changed to columns is empty), the scroll bar disappeared, even if it was visible before.

Security check for surveys

We have modified the security check for surveys. Members of the Operation administrators user group now possess complete read access to all surveys, except for the Role Certification Survey.

Setting attributes values

A known issue when setting attribute values in the new UI has been fixed. You can now set the value as "0" when editing the value property, indicating that it's equivalent to "unlimited" as it was in the old UI.

Submitting survey tasks without the decision

When selecting tasks, it was possible to submit the survey, before the page was rendered. As a result, the tasks without a decision of approval or rejection could be submitted.

Survey Completed while Progress is 0% and ResourceAssignment is in Pending state

In certain situations, a rare condition may occur when one user submits a significant number of survey questions all at once, while another user simultaneously submits a large batch of questions in a subsequent step. This scenario often results in the user in the second step unintentionally closing work items for assignees who were anticipating new questions from the user in the first step.

Switching between alphabetical and popularity sorting in Access Request search page

On the new Access Request page, we have moved the Show assigned resources toggle to a new settings menu. We've added an option to toggle between alphabetical and popularity sorting on the access request search page. This enhancement makes it easier to understand which sorting option is applied and to choose your preferred sorting options.

Time zone set property values

We've fixed an issue where some time zones failed from loading data. Now, we've improved the function to keep zones up to date.

TLS version selection for SAP connector

Choosing the transport layer security (TLS) protocol for the SAP connector was unavailable. It has been resolved and the TLS version can be configured in the web services task.

TraceEvent fails to reset

We've fixed an issue that prevents the event from being reset on an exception when using the customer setting TraceEventOnEntry.

Undocumented form field setting

We've fixed a bug in the form field of the Access request template, ensuring that the complete information on field button is now displayed. The field now allows you to provide additional parameters. The available settings are:

Validation for account types

In the new UI Access request process, there is an additional server-side validation performed after you click the Next button. This validation also includes the implicit set of the default account types that you defined in the customer setting RoPE:Default Account Type UID. The purpose of this validation is to ensure that the Access request meets certain requirements.