Skip to main content

126 docs tagged with "Release Notes"

View all tags

Access approval submit button

We have introduced a new change in the Access approval procces, there has been a modification to the Submit button functionality. Previously, the button would be disabled when nothing was selected. However, with the latest update, the Submit button remains active regardless of whether any item is selected. Now, the button attempts to submit all rows that meet the validation criteria. If none of the rows pass the validation, a yellow message is displayed, indicating that 0 questions were submitted successfully.

Access approval warning message

We fixed a bug that displayed a warning message even when there wasn't any data modified. Now, the Access approval table resets when users perform actions like filtering, sorting, or changing the page. A warning dialog informs users about the data reset before they proceed, following a one-time acknowledgment pattern. The warning won't reappear until the page is refreshed.

Access request button

The button to request access in the Access Requests and in the Extend Access Requests list views will now be hidden if the logged in user does not have permission to request access.

Access Request date pickers

In the Access Request process, the date picker for Valid from to Valid to dates will display according to your language browser and not the language is chosen in the 01.

Access request for technical identities

We have found an issue when requesting access for technical identities in the new UI. Please, use the old UI if you need to request access for technical identities.

Access request shows the same context multiple time

We fixed a bug that showed the same context multiple times. Now multiple context assignments with the same ContextId will no longer appear in the business context selection dropdown on the Access Request form.

Access request slow performance

We fixed a bug that slowed down the functioning of the access request process validation stage for resources with child resources. This was fixed by modifying the order of conditions and implementing a queries cache.

Accesss approval Policy & Risk check

We have introduced a new feature in Access Approval. You can now review the violations identified during the Policy & Risk check by clicking on the See More button. The summary will open, enabling you to assess the results of the Peer Access Analysis check, Segregation of Duties check, and General Risk check in accordion-style sections.

Account types are not displayed

There is a known issue when selecting account types in the Resource step when requesting access. If the account type in a resource doesn't match the account type associated with the identity you are requesting access for, then the dropdown will be empty.

After hiding all columns rows are clickable

On the new UI Tasks, Access Requests and Delegations views, if you hide all of the rows and columns you can still click on the rows. When hovering over a row, the row is highlighted and the pointer is changed to indicate that the row is clickable. When clicking, it navigates to the details of the hidden items. To fix it, always show at least one column.

Application error on a scheduled survey

Resolved an issue where survey adminstrators were not assigned to the verify activity when the Confirm before launch flag was set on the survey schedule. Now, survey admins are correctly assigned to the activity upon survey launches.

Application form enhancement

We have enhanced the Application form by defaulting the fulfillment section to a hidden state. You can adjust the visibility of the section in the configuration.

Application form shows irrelevant fields

Resolved a bug that shows irrelevant fields in the Application form. We fixed that by setting to hide the section. Go to Application form enhancement to know more.

Attribute type property

In the new UI, for an attribute type based on the Integer data type, if you set the Max. length value to 0, you won't be able to enter any number. You need to leave the field value empty.

Attribute values in the legacy access request process

In the legacy request access process, you will be asked for an account type when the resource allows more than one account type, the resource has visible attributes, and a request is being made for the resource for more than one identity, where each identity has one valid account.

Bugs

Read more about resolved issues and bug fixes in this release.

Cannot add custom process to service shortcuts

We have found a known issue that prevents the addition of custom processes to service shortcuts in Omada Identity. To avoid this, before upgrading, back up the UIHomePageActions value in the customer settings to preserve customizations made in the JSON value of the customer setting. The value of the customer setting will be overwritten. Once the upgrade is complete, you can add the changes back into the JSON.

Changes

Read more about the changes and bug fixes introduced in this release.

Classification tags are not displayed

Some classification tags used in the classification process do not have multilingual functionality, and they always display in English, even if you have configured your regional settings and your language settings are in a different language. We are actively working to address this issue in upcoming releases.

Code methods in event definitions

We have fixed the description of the CheckIfSetPropertyHasValue code method in the event definition, which previously contained methods with an obsolete status.

Code methods limitiation

We have added a limitation to our documentation related to code methods and triggering event definitions if a code method action results in an update of a data object. Refer to Code methods for more information.

Compensating control must be chosen

We resolved the issue where you had to select a compensating control after resolving a conflict. Now, you only need to choose a compensating control when a conflict actually occurs.

Data object properties throws error

We resolved a bug that was preventing the data object type property quickform from loading when the property is configured as a Set property with a Listbox control type. The default value is now displayed as a dropdown selection.

Deprecation

Here, you can find a list of deprecated or removed features in Omada Identity.

Deprovisioning assignments pending in SoD

Assignments pending deprovisioning will no longer be included in the SoD violation evaluation process. The Assignments Explorer will display a message for each of the assignments excluded from the process.

Discontinued or deprecated features

Here, you can find a list of deprecated features in Omada Identity. The features are still available in the release in which they are deprecated. This 12-month notice period is designed to allow for the transition to new features.

Discrepancy in ValidTo datetimes possible

For consumers using Omada Identity Graph API version 2.3, all datetimes will adhere to the UTC time standard. A known issue arises concerning the ValidTo date of a resource assignment displayed in the Extend Access process versus other places in the system; the dates may not match.

Duplicated UIDs in tblAppstr

There was an issue with duplicated UIDs in tblAppstr. We've changed the DataObjectType XMLSCHEMA Descriptions of property UID as it was duplicated with other one and the issue has been fixed.

Error in accessApprovalPolicyChecks in GrapghQL v2.7

We identified a known issue in GrapghQL API version 2.7. You will get an error when trying to query the createdBy field of the identity, resource or context fields in the accessApprovalPolicyChecks query. We are working to fix this in the next release.

Error in calculated assignments surveys

Fixed a bug that caused an error when submitting the Access Review Survey. This issue has been resolved through an update to the survey templates Calculated Assignment for Managers and Calculated Assignments for Resource Owners.

Extensive memory consumption in the REST connector

To improve handling of the REST connector failed jobs with multiple tasks, consuming extensive amounts of memory resulting in OutOfMemory issues the existing errorResponseFilter setting was enhanced and new responseFilter setting was added. They allow to provide JsonPath that are applied to responses limiting their size:

Invalid validation for Access to field

There was an issue with incorrect validation when attempting to input an invalid date range that resulted in inconsistent error handling. Initially, entering a valid from value that higher than the valid to value appropriately triggered a red border and displayed the following error message: Access to must be higher than Access from. However, upon subsequently entering a valid to value higher than the valid from value, the red border persisted, and the error message failed to disappear when it should.

Issue in the RoPE Initial Password extension

We've fixed an issue within the RoPE Initial Password extension. Previously, only newly created account assignments would receive an initial password attribute value. With our recent fix, existing account assignments, without a direct reason, will now be assigned an initial password by the RoPE extension during the provisioning task. This adjustment ensures a seamless notification flow and successful completion of the process.

Issue with calculated assignment for deleted resources

An issue has been solved in the OData API for calculated assignments. If the scope of the call contained an assignment for a deleted resource, the whole API call was failing. This is contrary to how the calculations look in the user interface. This has been improved.

Issue with cleanup import profile

An issue was identified where the cleanup import profile could lead to fact violation errors, such as: 3 ResourceAssignment objects have no fact row with IsRowLatest = 1. This problem occurred specifically when a referenced account or resource was deleted and recreated in the past.

Issue with configuring AD connector without Domain Controller

Provisioning with the Active Directory connector configured resulted in some instances with the Current security context is not associated with Active Directory domain or forest or The RPC server is unavailable. The issue has been resolved and those errors should no longer be encountered.

Issue with deprovisioning jobs

An enhancement has been implemented in the calculation of the provisioning statuses Pending Deprovisioning and Deprovisioning Failed.

Issue with error on missing system ID from resource

An issue occured when working on a process that generates identities of the type "secondary." Upon requesting access to a custom resource through Legacy Access Request, an error occurred indicating that system id was missing from resource. This issue has been resolved, and Technical Identity Validation will no longer be triggered for custom Identity Types.

Issue with exporting Identities from ODW to ES

There was an issue with the Identity export from Omada Data Warehouse to the Enterprise Server. This problem has been resolved by making the extension attribute case-sensitive in the export mapping.

Issue with filter

There was an issue with the Requested by filter in the Access Request. The problem has been resolved. Currently, the values searched for using the Requested by filter in the RequestedBy column align with those displayed in this column.

Issue with Preview service

The preview service failed to multiply results when a multivalue source attribute was used in mapping for a single value target attribute. We have resolved this issue, and the preview service now functions as intended.

Known Issues

Read more about the issues that are known to still exist at the moment of introduction of the Omada Identity update.

Left-side menu option is blank

We have identified a known issue within the left-side option menu in my Access Staging environment. Some group permissions, such as Employee or Manager, may not display all available options in the menu.

List views paging

We have fixed a bug that prevented paging from starting on the second page. Now, it resets the currentPage to the first page upon rendering a new data grid, ensuring that the data grid always starts from page one for every listView.

Manual provisioning tasks

Resolved an issue in the AssignmentAttributeValueDifferentiator that was creating duplicate provisioning tasks due to an extra assignment when the differentiator value is empty, as it pertains to provisioning claim reasons.

Missing info in StatusDescription and authentication

There was an issue with information missing in the WWW-Authentication header and the StatusDescription. The issue has been resolved and for the REST-based systems, the test connection, when failed, error messages are available in both HTTP header and response body.

Multiple activities in the survey process template

Configuring duration for the activities in the survey process template, requires ensuring that appropriate amount of time is allocated for each of the activities. Currently, when a survey is launched, all activities start simultaneously. This may result in lack of sufficient time for assignees in subsequent activities to complete their tasks effectively.

Multiple import threads issue

Transferring a large volume of identities between organizations may result in an import issue. It is caused by multiple import threads updating transfer surveys from a single manager.

New Access approval UI

We introduce version 1 of the new UI Access approval for answering your survey questions. You find a dedicated tab in the navigation pane named Access approvals. This view has tabs for each approval step, such as manager approval, resource owner approval or system administrator. These tabs are always visible, even if you don't have any questions assigned. To check for assigned questions, click on each tab.

New column in the Access Request list view

We have introduced the Children resources column to the Access Request list view. Now when there are children resources associated with a particular resources, the See more button displays in the row. You can click See more to open a secondary grid that presents all children resources that have been assigned to the given resource.

New link in the Navigation pane to Omada Identity Academy

We have incorporated a direct link to Omada Academy within the Navigation pane. Clicking on the tab will promptly redirect you to our Omada Academy portal. This tab is initially visible exclusively to administrators, but it can be configured to be accessible to other roles as well.

New List Views (Beta) menu section

We have introduced a new menu section that enhances the user experience for administrators. This section provides access to critical list views, such as Identities, Resources, Technical Identities, Applications and Surveys, each featuring an updated user interface. To access the menu, click on the List views (Beta) tab on the navigation pane. This menu item is availalbe to Administrators and Service Desk users.

New queries in Omada Identity Graph API

We have introduced new queries in the Omada Identity Graph API. policyCheckConfiguration to check if any policy and risk check is enabled for the approval survey and accessApprovalPolicyChecks to run a policy and risk check for the question assigned to the active user in the Access approval survey.

Omada Identity Governance

We've introduced the Omada Identity Governance feature to efficiently manage the users and user group memberships of the Enterprise Server.

Policy check shows violation from all steps

We have identified a known issue in the Policy Check for Access Approval. The policy checks currently display violations for resources in all steps of the survey, rather than just the selected step. We are actively working to address this issue in upcoming release.

Popular resources are always displayed first

The arPopularityEnabled customer setting enables customers to enable sorting resources by popularity on Resources Search field in Access Request flow. Introducing the filtering version for the resources autocomplete, coexsting with the exisiting paged version, can be configured with the EnableSearchFiltering setting. Configuring it to true results in replacing the Paged version with Filtering version.

Preview request issue

An issue, where a duplicated preview request resulted in the preview service error has been resolved. In a situation when a duplicate request is registered, the existing preview query request is removed.

Preview update button is missing

We have identified an issue where the preview update button is missing in System Queries & Mappings. If you encounter an error during upgrading, you'll need to perform the update manually by adding the script jsinc/OIM.SystemOnboarding.DataMapping.Preview.QandM.js to System onboarding > Script files.

Release Notes

The Omada Identity Update releases bring exciting improvements and enhancements in a variety of the product areas. Read more about the changes and bug fixes introduced in each of the Releases.

Removal of deprecated code

Since we have updated the API, the code that was marked as deprecated in V12, that is, ObsoletedInVersion12, is now removed.

Removal of RoPE tblServiceEvent

Since we have consolidated target logs and stopped writing records to the tblServiceEvent table in the Role and Policy Engine database, this table is now removed.

Removal of VBScript CodeMethods

We no longer support the VBScript CodeMethods. The Omada.OE.UtilityCodeAssembly.VBScript and Omada.OE.Solution.OIM.Assembly.CallVBScript code methods are now removed.

Removing objects issue

There was an issue with removing objects during reconciliation from simple arrays. The issue has been resolved.

Resource status update issue

When either ValidFrom or ValidTo fields are empty in a Resource object (but not both), the Resource status is not updated correctly with the associated event definitions.

Revocation of Password Reset Service

The Password Reset Service, which was previously a distinct feature in the Enterprise Server installer, has been removed. This feature allowed the reset of passwords generated through the Enterprise Server password reset processes. The process specifically targeted systems and accounts connected to MIM using the PCNS service.

RoPE fails to calculate identities

It is not possible to recover references between resources and resources assignments once they have been deleted. If you have deleted them, then you should create them again. The issue extends to all references between data objects.

RoPE failure of validity and parent context

Fixed an issue in the context of a Parent/Child relationship where no overlap existed in their validity periods. This problem resulted in calculations failing due to an invalid validity period.

Rope gives warnings prior to PreValidity

We have enhanced RoPE for identities with a validity period starting after the PreValidity. Previously, the calculation of such identities could trigger a warning related to a missing account. With this update, the warning has been eliminated, and assignments are still not generated.

SAP connector Framework related error in OPS

There were Omada Provisioning Service issues related to the way security protocols were implemented in the SAP connector. The issue has been resolved with the SOAP, Entrust, and MijnCaress connectors setting the TLS security protocol on the connection directly instead of using the global value.

Set new Access Approval as default

We've introduced a new customer setting called Use new UI for approval. This setting enables you to switch all approvals to the updated Access Approval flow. This includes a Task card on the home page which will redirect to the relevant tab on the access approval page.

SoD blocking of resources shows error

In some cases, a violating assignment with multiple reasons, including a ReviewOK reason, triggers an unhandled exception in the SoD evaluation feature. We've now fixed the underlying logic to ignore the order of reasons in an assignment.

SoD blocks resources

Fixed a bug that triggered an exception when assignments were blocked in the SoD evaluation process and an expiration date was selected.

SoD evaluation is missing resources

The grid will now display the name of the business process in conflict with another resource. If the process is a child of another process, the parent process will not be mentioned. This differs from the constraint, which only shows the parent business processes.

SoD Expiration day

It is now possible to select Today as Expiration date in the Segregation of Duties evaluation process.

SQL Collector using quotes for the UID

There was an issue with column names containing key words or special characters, causing the collector to break. Now to ensure that names are processed correctly the SQL queries generated by the SQL Query Collector for Generic databases encapsulates column names in special characters:

Survey log entries

We have resolved a recent bug that was causing the Log Entries button to be hidden when opening the survey questions of a completed survey.

Survey questions are assigned to a user but the respective activity is not

There is an issue in the Access Request approval process in the new UI. While using the text description of the resource, you use the Cannot find the resource? link, where you can write your description of the resource you want. When submitted, the request interpreter gets a task but the description is not copied over and it only displays "test".

Survey status filter

In Surveys, when applying a filter to the Status column and choosing the Missing answers option, the appropriate questions are now loaded.

Survey templates transition object

We fixed an issue that was preventing the editing of transitions when creating a survey. Now, it is possible to create new transitions from the process designer and the list of transitions.

Survey verdict incorrectly prolongs CRA validity

For CRAs with no actual state, a survey verdict will not extend its validity through the using the days before verdict expires field in the survey form. Instead, it will maintain the initial validity established on the direct assignment.

The Map null values setting for specific operations

The Map null values setting in the Advanced settings section is enahnced with the possibility to set it for specific operations. It can be configured to true value for the combination of the following operations:

Transfer identity assignments survey template

The Title, Description, and Estimate fields are no longer editable when modifying a published Transfer Identity Assignments survey template. You can make changes to these fields directly in the associated activity within the published survey process template.

Unable to set days in forms

We've identified a known issue related to setting the number of days in a form when using the Timespan format for the value property. Please, use the legacy UI if you want to set days.

Updated Calculated Assginment survey templates

We have introduced new updates to the survey templates: Calculated Assignment for Managers and Calculated Assignments for Resource Owners. These updated survey templates now incorporate the option Days before verdict expires in the post-action handler.

UTC Timezone discrepancies

We have identified a known issue when switching timezones from user settings (to the day before or after), the dates entered during the submission of an Access Request may differ from the dates displayed in the access list or resource assignments list.