Resolved Issues and Bug Fixes
Read more about resolved issues and bug fixes in this release.
UI and UX
Recalculate button not visible for Service Desk Agents
We've fixed an issue where user permissions were not being correctly checked to determine whether the Recalculate action should be displayed. As a result, users with the Service Desk Agent role who had the Queue identity for calculation permission could not see the Recalculate button in the Identities list or in the Identity details page menu. The button is now correctly shown for all users with the required permission.
INC-312596
Horizons
Import failure due to dynamic expression inconsistency between environments
Imports were failing due to a dynamic expression inconsistency between environments. The issue causing the import adaptation failure, when export mappings were using filters containing dynamic expressions based on String.IsNullOrEmpty, has been resolved.
INC-316948
Access request
Access request interpretation issue
We resolved an issue where the description of a text-based access request was not available to the Request interpreter. In the new UI, the original request is now displayed in the side panel of the interpretation form.
See Release notes June 2026 to know more.
Enable search filter in Access menu items
We have fixed a bug in the Access menu where reopening the filter panel on a column did not retain the previously applied filter. The applied filter is now correctly retained when the filter panel is reopened.
INC-314707
Enterprise Server
Revert application string to defaults is not recorded as a changeset
We've fixed a problem where reverting application strings was not recorded as a changeset.
The Revert to defaults action in Application Strings no longer attempts to revert Data Object Type (DOT) multilingual property values to their default values. To modify DOT multilingual property values, use the Mass Edit option.
Reverting application strings only affects translations stored in the database. Custom translation files are not modified. For more information, refer to the Translations section.
INC-307262
Underscored extension attributes brakes account export filters
There was an issue with the dynamic filter parser mishandling extension attribute names containing an underscore when referenced through a linked identity property in an account filter. It resulted in a misinterpretation of a part of the name and caused a member not found error. The issue has been resolved, and the handling of extension attribute names containing underscores has been corrected.
INC-317178
Adapting failure on DateTime field lookups
We have resolved an issue with the export-view lookups using DateTime fields, resulting in the adapting phase failing. It is now working correctly, with the adapting stage initializing as expected.
INC-316822
SystemBoot fails when configuring AzureLog target with Vault Secret
We've fixed an issue where the system failed to start if a logging configuration used Vault‑backed secrets.
INC-306795
Restarting timer service caused schema upgrade to fail
We've fixed a bug where the XML schema folder could be returned as a relative path instead of an absolute path. This could prevent schemas from being updated by the timer service when running as a Windows service.
INC-306896
Changeset import could hang during data object type updates
We've fixed an issue where importing a changeset with changes to data object types could hang when the import triggered a large number of updates to related data objects.
Changing certain Data Object Type properties, such as Display Name Format or Singular Name, may trigger updates to all existing data objects of that type. In large environments, this can take significant time, so consider applying these changes during a maintenance window or splitting them into smaller change sets. For more information, refer to the Changesets documentation.
INC-315407
Fix changeset incorrectly recording unchanged AuthRole modifications
We've fixed an issue where a mass update on UserGroups caused Authorization Roles to be incorrectly removed in the recorded changeset, even when those roles hadn't actually changed.
INC-315979
Context type update failure
There was an issue where an instance of the ES portal would fail when processing a change to a context type data object if it was the first data object change since the portal's startup. The error was caused by an internal cache not being properly populated. This cache is now initialized correctly, preventing the context type update from failing.
INC-316121
Inefficient loading over OData
Loading resources through OData could be slower than expected due to repeated property checks during data loading. We have improved OData speed by reducing unnecessary repeated property checks when loading resources.
INC-295376
Role and Policy Engine
Issue with ActualManager VirtualPropertyResolver parameters in RoPE
We have fixed RoPE configuration with an AttributeValueResolver reference path using a virtual reference property that carries arguments.
INC-294765
Fixed incorrect deprovisioning claims for consecutive SAP assignments
We've fixed an issue where RoPE could issue a deprovisioning claim for an assignment that should remain active. This occurred when an SAP account had two actual assignments for the same resource with non-overlapping validity periods, such as one assignment ending on 2026-03-07 and another running from 2026-03-09 to 2026-04-05.
INC-309365
Reduce memory allocations in RoPE and OE model layers
We've improved memory usage in the RoPE and OE model layers by refactoring how properties related to data object versions are handled. This eliminates redundant allocations that previously scaled with the number of data object versions processed.
INC-288005
Expired resource assignments included in provisioning calculation for re-joiner identity
The identity previously had resource assignments that later became obsolete due to expiration. After the identity rejoined the system, its validTo date was set to a future date within the pre-validity gap. This caused the expired resource assignments to be incorrectly included in the calculation, resulting in provisioning tasks being created.
This has been fixed so that expired resource assignments are no longer included in the calculation for re-joining identity scenarios.
INC-311114
Missing account type preventing parent disable propagation to children
We've fixed an issue where assignments were calculated for one or more possible account types for a resource and then removed because no corresponding account resource existed. This could prevent child assignments with the correct account type from being disabled when the parent assignment was disabled.
This could affect child assignments when the parent assignment was disabled due to a prioritization policy, a remove verdict, or a violation.
INC-317273
Surveys
Duplicate fields in survey form
We have fixed a bug where it was possible to add duplicate fields in a survey form. An error message now appears if you try to save a survey template that contains a duplicate field in the form.
INC-307383
Omada Identity Analytics
Report Generator dashboard – table details not displaying in PDF
There was an issue where table details were not displayed when downloading the Report Generator dashboard as a PDF. The fix ensures that table data now appears correctly in both the preview and PDF download, consistent with the behavior of other dashboards.
INC-301731
Untranslated widget descriptions
We've fixed an issue where analytics dashboard content would display widget descriptions in the previous language after changing your language preference in My settings. This occurred in dashboards using lazy loading, which loads only the initially selected tab first, and loads additional tabs on demand to improve performance.
The fix ensures that all widget descriptions correctly reflect your selected language.
Untranslated dashboard tab names
Due to an issue, tab names on dashboards (for example, Access Navigator) could display as untranslated text, despite the rest of the dashboard being correctly translated. We have now fixed it, and all tab names are displayed in the selected language.
PDF download failure for grids
We've fixed an issue with PDF download from OIA dashboards where the PDF could be partially blank. The fix ensures a correct download and display of PDF files.
Access Intelligence – filtering on Role Overview page
On the Access Intelligence dashboard, we've fixed an issue where filtering was not working correctly on the Role Overview page for the List of Resources in Role view. The fix reconfigures the filtering for the Status Name field, ensuring that all filter selections are applied as expected.
INC-314006
Connectors
Authentication request body field is now optional
In OAuth2 custom authentication scenarios, the Auth request body field is now optional. This allows APIs to authenticate through headers only (a request body is no longer required).
INC-309113
Preview Service – event source for logs
The installation of the Preview Service has been adjusted. It now creates an event source for logs.
INC-304575
SSH connector – support for a tab character (\t)
The SSH connector now supports the tab character (\t) as a CSV column separator.
INC-314621
OAuth2 JWT support in the Okta connector
The Okta connector now supports OAuth2 client credentials JWT as the authentication type.
INC-314828
Microsoft Exchange connectivity – hideInAddressList is not disabled
An issue has been fixed where disabling the Hide from address lists option or webmail access on Exchange mailboxes had no effect.
INC-316435
SAP HR connectivity - error handling
Handling of errors related to HTTP requests aborted due to timeout or cancellation has been improved.
INC-307434
Scope parameter could be omitted from OAuth2 Test connection requests
We have fixed an issue where the Scope parameter was sometimes omitted from the OAuth2 token request generated by a Test connection action, if it was serialized after the client_assertion parameter. Import and provisioning tasks using the same OAuth2 configuration were not affected. Only a spontaneous Test connection check could report the Scope parameter as missing, even though it was correctly configured.
INC-314897
Security
Fixed reflected cross-site scripting (XSS) in affected dialogs
We've fixed a reflected cross-site scripting (XSS) vulnerability in dialogs that shared an unencoded reflection pattern.
INC-317450
Other
Download format has been changed to UTF-8
We have fixed a bug where CSV downloads were generated in standard UTF-8 instead of UTF-8 with BOM, which caused special characters to display incorrectly when the files were opened in Excel. Downloading a CSV file now includes UTF-8 with BOM information.
INC-314910
Preview unavailable for system owner
We have resolved an issue where system owners were not able to run the preview for the systems they owned.
INC-310208
Boolean properties handling
We have fixed the handling of Boolean properties in export mappings that are using account and resource assignment as a source.
INC-316805
Omada Provisioning Service
Unresponsive OPS
In environments with a large number of target systems, OPS could take longer to initialize than the Windows Service Control Manager allowed by default. As a result, OPS could be marked as not responding and be terminated before startup completed.
We have increased the time the Service Control Manager waits for OPS to start, and made this configurable so the wait time can be tuned to your environment. For more information, go to the Configuring OPS startup wait time documentation.
INC-314604
SetProvisioningAdvancedSettingsOPS setting invalid values
The input validation for OPS provisioning advanced settings was improved to prevent invalid values from being accepted.
INC-304333
Documentation
No documented way to disable AI-assisted mappings
A customer setting to enable or disable AI-assisted mappings for connectivity has been added, along with documentation covering it. See Enable AI Assisted Queries and Mappings in the Customer settings documentation.
Unclear documentation on Policy and Risk Check Options
We have fixed an ambiguous Policy & Risk check documentation. See Policy & Risk check to know more.
INC-303638
Unclear documentation on Control policies
We have updated the documentation about Control policies.
INC-315152