Resolved Issues and Bug Fixes
Read more about resolved issues and bug fixes in this release.
Access request
Access request interpretation issue
We resolved an issue where the description of a text-based access request was not available to the Request interpreter. In the new UI, the original request is now displayed in the side panel of the interpretation form.
For more information, see Interpret text-based access requests in the new UI.
Enable search filter in Access menu items
We have fixed a bug in the Access menu where reopening the filter panel on a column did not retain the previously applied filter. The applied filter is now correctly retained when the filter panel is reopened.
INC-314707
Enterprise Server
Underscored extension attributes break account export filters
There was an issue with the dynamic filter parser mishandling extension attribute names containing an underscore when referenced through a linked identity property in an account filter. Part of the name was misinterpreted, causing a member not found error. The handling of extension attribute names containing underscores has been corrected.
INC-317178
Adapting failure on DateTime field lookups
We have resolved an issue where export view lookups using DateTime fields caused the adapting phase to fail. The adapting stage now initializes as expected.
INC-316822
Restarting timer service caused schema upgrade to fail
We've fixed a bug where the XML schema folder could be returned as a relative path instead of an absolute path. This could prevent schemas from being updated by the timer service when running as a Windows service.
INC-306896
Changeset import could hang during data object type updates
We've fixed an issue where importing a changeset with changes to data object types could hang when the import triggered a large number of updates to related data objects.
Changing certain data object type properties, such as Display Name Format or Singular Name, may trigger updates to all existing data objects of that type. In large environments, this can take significant time, so consider applying these changes during a maintenance window or splitting them into smaller changesets. For more information, refer to the Changesets documentation.
INC-315407
Changeset incorrectly recording unchanged AuthRole modifications
We've fixed an issue where a mass update on UserGroups caused Authorization Roles to be incorrectly recorded as removed in the changeset, even when those roles had not changed.
INC-315979
Context type update failure
There was an issue where an Enterprise Server portal instance would fail when processing a change to a context type data object if it was the first data object change since the portal's startup. The error was caused by an internal cache not being properly populated. The cache is now initialized correctly, preventing the context type update from failing.
INC-316121
Inefficient loading over OData
Loading resources through OData could be slower than expected due to repeated property checks during data loading. We have improved OData performance by removing unnecessary repeated property checks when loading resources.
INC-295376
Surveys
Duplicate fields in survey form
We have fixed a bug where it was possible to add duplicate fields to a survey form. An error message now appears if you try to save a survey template that contains a duplicate field in the form.
INC-307383
Security
Fixed reflected cross-site scripting (XSS) in affected dialogs
We've fixed a reflected cross-site scripting (XSS) vulnerability in dialogs that shared an unencoded reflection pattern.
INC-317450
UI and UX
Recalculate button not visible for Service Desk Agents
We've fixed an issue where user permissions were not correctly checked to determine whether the Recalculate action should be displayed. As a result, users with the Service Desk Agent role who had the Queue identity for calculation permission could not see the Recalculate button in the Identities list or on the Identity details page. The button is now shown for all users with the required permission.
INC-312596
Issue in identity view after upgrade
We've fixed an issue in the new UI where forms did not work correctly for Set properties configured with the radio control type. Radio button selections for Set properties are now handled correctly.
INC-318557
Omada Provisioning Service
Unresponsive OPS
In environments with a large number of target systems, OPS could take longer to initialize than the Windows Service Control Manager allowed by default. As a result, OPS could be marked as not responding and terminated before startup completed.
We have increased the time the Service Control Manager waits for OPS to start, and made this configurable so the wait time can be tuned to your environment. For more information, see Configuring OPS startup wait time.
INC-314604
SetProvisioningAdvancedSettingsOPS setting invalid values
The input validation for OPS provisioning advanced settings has been improved to prevent invalid values from being accepted.
INC-304333
Role and Policy Engine
Issue with ActualManager VirtualPropertyResolver parameters in RoPE
We have fixed RoPE configuration with an AttributeValueResolver reference path using a virtual reference property that carries arguments.
INC-294765
Fixed incorrect deprovisioning claims for consecutive SAP assignments
We've fixed an issue where RoPE could issue a deprovisioning claim for an assignment that should remain active. This occurred when an SAP account had two actual assignments for the same resource with non-overlapping validity periods, such as one assignment ending on 2026-03-07 and another running from 2026-03-09 to 2026-04-05.
INC-309365
Reduced memory allocations in RoPE and OE model layers
We've improved memory usage in the RoPE and OE model layers by refactoring how properties related to data object versions are handled. This eliminates redundant allocations that previously scaled with the number of data object versions processed.
INC-288005
Expired resource assignments included in provisioning calculation for re-joiner identity
When an identity with resource assignments that had become obsolete due to expiration rejoined, and its validTo date was set to a future date within the pre-validity gap, the expired resource assignments were incorrectly included in the calculation, resulting in provisioning tasks being created.
Expired resource assignments are no longer included in the calculation for re-joining identity scenarios.
INC-311114
Missing account type preventing parent disable propagation to children
We've fixed an issue where assignments were calculated for one or more possible account types for a resource and then removed because no corresponding account resource existed. This could prevent child assignments with the correct account type from being disabled when the parent assignment was disabled due to a prioritization policy, a remove verdict, or a violation.
INC-317273
RoPE repeatedly removes and adds the same group for multiple users
We've fixed an issue where assignments were sometimes created for a non-existent account in the same system. This occurred when two account resources in the same system had different account types but the same actual account name.
INC-317061
RoPE DB timeouts when fetching LoadExplicitlyOwnedObjects
The RoPE SelfManagementExtension now loads explicitly owned objects more efficiently, improving processing speed and reducing memory consumption.
INC-316939
Provisioning jobs created for AD groups that were already assigned
We have fixed an issue where provisioning jobs were created for resources, such as AD groups, that were already assigned. A large number of these jobs could exceed the provisioning threshold and put the provisioning queue on hold.
Paging in the IDS GraphQL client has been improved. All existing resource assignments are now retrieved between imports, and provisioning jobs are no longer created for resources that are already assigned.
INC-318652
Emergency Lockout calculation not rerun after SubmitBatch failure
The Emergency Lockout identity calculation was not rerun when SubmitBatch failed in OPS due to a SQL deadlock or timeout. We have improved RoPE-to-OPS communication so that transient errors are handled more reliably.
INC-315677
Omada Data Warehouse
Import errors not handled and reported correctly
We have fixed an issue where import errors from the SCD package, or errors with an error code below -1,000,000,000, were not reported correctly. As a result, imports such as MS Graph imports could fail without a meaningful error message.
Error handling in the ODW import packages has been corrected. Import errors are now reported with their error code and description.
INC-319591
Connectors
Authentication request body field is now optional
In OAuth2 custom authentication scenarios, the Auth request body field is now optional. This allows APIs to authenticate through headers only.
INC-309113
Preview Service – event source for logs
The installation of the Preview Service has been adjusted. It now creates an event source for logs.
INC-304575
SSH connector – support for a tab character (\t)
The SSH connector now supports the tab character (\t) as a CSV column separator.
INC-314621
OAuth2 JWT support in the Okta connector
The Okta connector now supports OAuth2 client credentials JWT as the authentication type.
INC-314828
Microsoft Exchange connectivity – Hide from address lists not disabled
We have fixed an issue where disabling the Hide from address lists option or webmail access on Exchange mailboxes had no effect.
INC-316435
SAP HR connectivity – error handling
Handling of errors related to HTTP requests aborted due to timeout or cancellation has been improved.
INC-307434
Scope parameter could be omitted from OAuth2 Test connection requests
We have fixed an issue where the Scope parameter was sometimes omitted from the OAuth2 token request generated by a Test connection action if it was serialized after the client_assertion parameter. Import and provisioning tasks using the same OAuth2 configuration were not affected; only Test connection could report the Scope parameter as missing, even though it was correctly configured.
INC-314897
Exchange Online queries failing with the "BadRequest" message
We have fixed an issue where Exchange Online queries failed, returning the BadRequest message.
INC-318331, INC-318606, INC-318693
SQL collector changes the import type from delta to full
The SQL collector's import mechanism has been improved. Previously, a delta operation could erroneously run as a full import, resetting the high watermarks. The following enhancements were implemented:
- No source field is returned for action mappings, so the action is set to null (as required for full imports).
- Command performance and execution – the same as for full imports when delta is not configured.
#INC-277873
Other
Preview unavailable for system owner
We have resolved an issue where system owners were not able to run the preview for the systems they owned.
INC-310208
Boolean properties handling
We have fixed the handling of Boolean properties in export mappings that use accounts and resource assignments as a source.
INC-316805
Policy Scope Views were not available to non-admin users
We fixed an access issue that prevented non-admin users from viewing Policy Scope Views and their names on the Policies page.
INC-312911, INC-316123
Documentation
No documented way to disable AI-assisted mappings
A customer setting to enable or disable AI-assisted mappings for connectivity has been added, along with documentation covering it. See Enable AI Assisted Queries and Mappings in the Customer settings documentation.
Unclear documentation on Control policies
We have updated the documentation about Control policies.
INC-315152
Search behavior with special characters, Unicode symbols, and emoji was undocumented
Search tokenization behavior for special characters, Unicode symbols, and emoji in Display name values was not previously documented. We've added guidance on how Omada Identity generates and tokenizes search data, and documented a related known issue where a display name containing a Unicode symbol or emoji may not be found by plain-text search alone.
For more information, see Special characters, Unicode, and emoji in search and the known issue.
INC-319750
Calculation log error documentation
We have added documentation for the Cleared - Identity doesn't exist calculation log message, including its cause, impact, and recommended troubleshooting steps.
For more information, see the Calculation log section.
INC-314706