Skip to main content
Version: Omada Identity on-premises 16.0.1

Resolved Issues and Bug Fixes

Read more about resolved issues and bug fixes in this release.

Access request​

Access request interpretation issue​

We resolved an issue where the description of a text-based access request was not available to the Request interpreter. In the new UI, the original request is now displayed in the side panel of the interpretation form.

For more information, see Interpret text-based access requests in the new UI.

Enable search filter in Access menu items​

We have fixed a bug in the Access menu where reopening the filter panel on a column did not retain the previously applied filter. The applied filter is now correctly retained when the filter panel is reopened.

INC-314707

Enterprise Server​

Underscored extension attributes break account export filters​

There was an issue with the dynamic filter parser mishandling extension attribute names containing an underscore when referenced through a linked identity property in an account filter. Part of the name was misinterpreted, causing a member not found error. The handling of extension attribute names containing underscores has been corrected.

INC-317178

Adapting failure on DateTime field lookups​

We have resolved an issue where export view lookups using DateTime fields caused the adapting phase to fail. The adapting stage now initializes as expected.

INC-316822

Restarting timer service caused schema upgrade to fail​

We've fixed a bug where the XML schema folder could be returned as a relative path instead of an absolute path. This could prevent schemas from being updated by the timer service when running as a Windows service.

INC-306896

Changeset import could hang during data object type updates​

We've fixed an issue where importing a changeset with changes to data object types could hang when the import triggered a large number of updates to related data objects.

info

Changing certain data object type properties, such as Display Name Format or Singular Name, may trigger updates to all existing data objects of that type. In large environments, this can take significant time, so consider applying these changes during a maintenance window or splitting them into smaller changesets. For more information, refer to the Changesets documentation.

INC-315407

Changeset incorrectly recording unchanged AuthRole modifications​

We've fixed an issue where a mass update on UserGroups caused Authorization Roles to be incorrectly recorded as removed in the changeset, even when those roles had not changed.

INC-315979

Context type update failure​

There was an issue where an Enterprise Server portal instance would fail when processing a change to a context type data object if it was the first data object change since the portal's startup. The error was caused by an internal cache not being properly populated. The cache is now initialized correctly, preventing the context type update from failing.

INC-316121

Inefficient loading over OData​

Loading resources through OData could be slower than expected due to repeated property checks during data loading. We have improved OData performance by removing unnecessary repeated property checks when loading resources.

INC-295376

Surveys​

Duplicate fields in survey form​

We have fixed a bug where it was possible to add duplicate fields to a survey form. An error message now appears if you try to save a survey template that contains a duplicate field in the form.

INC-307383

Security​

Fixed reflected cross-site scripting (XSS) in affected dialogs​

We've fixed a reflected cross-site scripting (XSS) vulnerability in dialogs that shared an unencoded reflection pattern.

INC-317450

UI and UX​

Recalculate button not visible for Service Desk Agents​

We've fixed an issue where user permissions were not correctly checked to determine whether the Recalculate action should be displayed. As a result, users with the Service Desk Agent role who had the Queue identity for calculation permission could not see the Recalculate button in the Identities list or on the Identity details page. The button is now shown for all users with the required permission.

INC-312596

Issue in identity view after upgrade​

We've fixed an issue in the new UI where forms did not work correctly for Set properties configured with the radio control type. Radio button selections for Set properties are now handled correctly.

INC-318557

Omada Provisioning Service​

Unresponsive OPS​

In environments with a large number of target systems, OPS could take longer to initialize than the Windows Service Control Manager allowed by default. As a result, OPS could be marked as not responding and terminated before startup completed.

We have increased the time the Service Control Manager waits for OPS to start, and made this configurable so the wait time can be tuned to your environment. For more information, see Configuring OPS startup wait time.

INC-314604

SetProvisioningAdvancedSettingsOPS setting invalid values​

The input validation for OPS provisioning advanced settings has been improved to prevent invalid values from being accepted.

INC-304333

Role and Policy Engine​

Issue with ActualManager VirtualPropertyResolver parameters in RoPE​

We have fixed RoPE configuration with an AttributeValueResolver reference path using a virtual reference property that carries arguments.

INC-294765

Fixed incorrect deprovisioning claims for consecutive SAP assignments​

We've fixed an issue where RoPE could issue a deprovisioning claim for an assignment that should remain active. This occurred when an SAP account had two actual assignments for the same resource with non-overlapping validity periods, such as one assignment ending on 2026-03-07 and another running from 2026-03-09 to 2026-04-05.

INC-309365

Reduced memory allocations in RoPE and OE model layers​

We've improved memory usage in the RoPE and OE model layers by refactoring how properties related to data object versions are handled. This eliminates redundant allocations that previously scaled with the number of data object versions processed.

INC-288005

Expired resource assignments included in provisioning calculation for re-joiner identity​

When an identity with resource assignments that had become obsolete due to expiration rejoined, and its validTo date was set to a future date within the pre-validity gap, the expired resource assignments were incorrectly included in the calculation, resulting in provisioning tasks being created.

Expired resource assignments are no longer included in the calculation for re-joining identity scenarios.

INC-311114

Missing account type preventing parent disable propagation to children​

We've fixed an issue where assignments were calculated for one or more possible account types for a resource and then removed because no corresponding account resource existed. This could prevent child assignments with the correct account type from being disabled when the parent assignment was disabled due to a prioritization policy, a remove verdict, or a violation.

INC-317273

RoPE repeatedly removes and adds the same group for multiple users​

We've fixed an issue where assignments were sometimes created for a non-existent account in the same system. This occurred when two account resources in the same system had different account types but the same actual account name.

INC-317061

RoPE DB timeouts when fetching LoadExplicitlyOwnedObjects​

The RoPE SelfManagementExtension now loads explicitly owned objects more efficiently, improving processing speed and reducing memory consumption.

INC-316939

Provisioning jobs created for AD groups that were already assigned​

We have fixed an issue where provisioning jobs were created for resources, such as AD groups, that were already assigned. A large number of these jobs could exceed the provisioning threshold and put the provisioning queue on hold.

Paging in the IDS GraphQL client has been improved. All existing resource assignments are now retrieved between imports, and provisioning jobs are no longer created for resources that are already assigned.

INC-318652

Emergency Lockout calculation not rerun after SubmitBatch failure​

The Emergency Lockout identity calculation was not rerun when SubmitBatch failed in OPS due to a SQL deadlock or timeout. We have improved RoPE-to-OPS communication so that transient errors are handled more reliably.

INC-315677

Omada Data Warehouse​

Import errors not handled and reported correctly​

We have fixed an issue where import errors from the SCD package, or errors with an error code below -1,000,000,000, were not reported correctly. As a result, imports such as MS Graph imports could fail without a meaningful error message.

Error handling in the ODW import packages has been corrected. Import errors are now reported with their error code and description.

INC-319591

Connectors​

Authentication request body field is now optional​

In OAuth2 custom authentication scenarios, the Auth request body field is now optional. This allows APIs to authenticate through headers only.

INC-309113

Preview Service – event source for logs​

The installation of the Preview Service has been adjusted. It now creates an event source for logs.

INC-304575

SSH connector – support for a tab character (\t)​

The SSH connector now supports the tab character (\t) as a CSV column separator.

INC-314621

OAuth2 JWT support in the Okta connector​

The Okta connector now supports OAuth2 client credentials JWT as the authentication type.

INC-314828

Microsoft Exchange connectivity – Hide from address lists not disabled​

We have fixed an issue where disabling the Hide from address lists option or webmail access on Exchange mailboxes had no effect.

INC-316435

SAP HR connectivity – error handling​

Handling of errors related to HTTP requests aborted due to timeout or cancellation has been improved.

INC-307434

Scope parameter could be omitted from OAuth2 Test connection requests​

We have fixed an issue where the Scope parameter was sometimes omitted from the OAuth2 token request generated by a Test connection action if it was serialized after the client_assertion parameter. Import and provisioning tasks using the same OAuth2 configuration were not affected; only Test connection could report the Scope parameter as missing, even though it was correctly configured.

INC-314897

Exchange Online queries failing with the "BadRequest" message​

We have fixed an issue where Exchange Online queries failed, returning the BadRequest message.

INC-318331, INC-318606, INC-318693

SQL collector changes the import type from delta to full​

The SQL collector's import mechanism has been improved. Previously, a delta operation could erroneously run as a full import, resetting the high watermarks. The following enhancements were implemented:

  • No source field is returned for action mappings, so the action is set to null (as required for full imports).
  • Command performance and execution – the same as for full imports when delta is not configured.

#INC-277873

Other​

Preview unavailable for system owner​

We have resolved an issue where system owners were not able to run the preview for the systems they owned.

INC-310208

Boolean properties handling​

We have fixed the handling of Boolean properties in export mappings that use accounts and resource assignments as a source.

INC-316805

Policy Scope Views were not available to non-admin users​

We fixed an access issue that prevented non-admin users from viewing Policy Scope Views and their names on the Policies page.

INC-312911, INC-316123

Documentation​

No documented way to disable AI-assisted mappings​

A customer setting to enable or disable AI-assisted mappings for connectivity has been added, along with documentation covering it. See Enable AI Assisted Queries and Mappings in the Customer settings documentation.

Unclear documentation on Control policies​

We have updated the documentation about Control policies.

INC-315152

Search behavior with special characters, Unicode symbols, and emoji was undocumented​

Search tokenization behavior for special characters, Unicode symbols, and emoji in Display name values was not previously documented. We've added guidance on how Omada Identity generates and tokenizes search data, and documented a related known issue where a display name containing a Unicode symbol or emoji may not be found by plain-text search alone.

For more information, see Special characters, Unicode, and emoji in search and the known issue.

INC-319750

Calculation log error documentation​

We have added documentation for the Cleared - Identity doesn't exist calculation log message, including its cause, impact, and recommended troubleshooting steps.

For more information, see the Calculation log section.

INC-314706