Skip to main content
Version: Omada Identity Cloud

Resolved Issues and Bug Fixes

Read more about resolved issues and bug fixes in this release.

UI and UX

Recalculate button not visible for Service Desk Agents

We've fixed an issue where user permissions were not being correctly checked to determine whether the Recalculate action should be displayed. As a result, users with the Service Desk Agent role who had the Queue identity for calculation permission could not see the Recalculate button in the Identities list or in the Identity details page menu. The button is now correctly shown for all users with the required permission.

INC-312596

Horizons

Import failure due to dynamic expression inconsistency between environments

Imports were failing due to a dynamic expression inconsistency between environments. The issue causing the import adaptation failure, when export mappings were using filters containing dynamic expressions based on String.IsNullOrEmpty, has been resolved.

INC-316948

Access request

Access request interpretation issue

We resolved an issue where the description of a text-based access request was not available to the Request interpreter. In the new UI, the original request is now displayed in the side panel of the interpretation form.

See Release notes June 2026 to know more.

Enable search filter in Access menu items

We have fixed a bug in the Access menu where reopening the filter panel on a column did not retain the previously applied filter. The applied filter is now correctly retained when the filter panel is reopened.

INC-314707

Enterprise Server

Revert application string to defaults is not recorded as a changeset

We've fixed a problem where reverting application strings was not recorded as a changeset.

info

The Revert to defaults action in Application Strings no longer attempts to revert Data Object Type (DOT) multilingual property values to their default values. To modify DOT multilingual property values, use the Mass Edit option.

info

Reverting application strings only affects translations stored in the database. Custom translation files are not modified. For more information, refer to the Translations section.

INC-307262

Underscored extension attributes brakes account export filters

There was an issue with the dynamic filter parser mishandling extension attribute names containing an underscore when referenced through a linked identity property in an account filter. It resulted in a misinterpretation of a part of the name and caused a member not found error. The issue has been resolved, and the handling of extension attribute names containing underscores has been corrected.

INC-317178

Adapting failure on DateTime field lookups

We have resolved an issue with the export-view lookups using DateTime fields, resulting in the adapting phase failing. It is now working correctly, with the adapting stage initializing as expected.

INC-316822

SystemBoot fails when configuring AzureLog target with Vault Secret

We've fixed an issue where the system failed to start if a logging configuration used Vault‑backed secrets.

INC-306795

Restarting timer service caused schema upgrade to fail

We've fixed a bug where the XML schema folder could be returned as a relative path instead of an absolute path. This could prevent schemas from being updated by the timer service when running as a Windows service.

INC-306896

Changeset import could hang during data object type updates

We've fixed an issue where importing a changeset with changes to data object types could hang when the import triggered a large number of updates to related data objects.

info

Changing certain Data Object Type properties, such as Display Name Format or Singular Name, may trigger updates to all existing data objects of that type. In large environments, this can take significant time, so consider applying these changes during a maintenance window or splitting them into smaller change sets. For more information, refer to the Changesets documentation.

INC-315407

Fix changeset incorrectly recording unchanged AuthRole modifications

We've fixed an issue where a mass update on UserGroups caused Authorization Roles to be incorrectly removed in the recorded changeset, even when those roles hadn't actually changed.

INC-315979

Context type update failure

There was an issue where an instance of the ES portal would fail when processing a change to a context type data object if it was the first data object change since the portal's startup. The error was caused by an internal cache not being properly populated. This cache is now initialized correctly, preventing the context type update from failing.

INC-316121

Inefficient loading over OData

Loading resources through OData could be slower than expected due to repeated property checks during data loading. We have improved OData speed by reducing unnecessary repeated property checks when loading resources.

INC-295376

Role and Policy Engine

Issue with ActualManager VirtualPropertyResolver parameters in RoPE

We have fixed RoPE configuration with an AttributeValueResolver reference path using a virtual reference property that carries arguments.

INC-294765

Fixed incorrect deprovisioning claims for consecutive SAP assignments

We've fixed an issue where RoPE could issue a deprovisioning claim for an assignment that should remain active. This occurred when an SAP account had two actual assignments for the same resource with non-overlapping validity periods, such as one assignment ending on 2026-03-07 and another running from 2026-03-09 to 2026-04-05.

INC-309365

Reduce memory allocations in RoPE and OE model layers

We've improved memory usage in the RoPE and OE model layers by refactoring how properties related to data object versions are handled. This eliminates redundant allocations that previously scaled with the number of data object versions processed.

INC-288005

Expired resource assignments included in provisioning calculation for re-joiner identity

The identity previously had resource assignments that later became obsolete due to expiration. After the identity rejoined the system, its validTo date was set to a future date within the pre-validity gap. This caused the expired resource assignments to be incorrectly included in the calculation, resulting in provisioning tasks being created.

This has been fixed so that expired resource assignments are no longer included in the calculation for re-joining identity scenarios.

INC-311114

Missing account type preventing parent disable propagation to children

We've fixed an issue where assignments were calculated for one or more possible account types for a resource and then removed because no corresponding account resource existed. This could prevent child assignments with the correct account type from being disabled when the parent assignment was disabled.

This could affect child assignments when the parent assignment was disabled due to a prioritization policy, a remove verdict, or a violation.

INC-317273

Surveys

Duplicate fields in survey form

We have fixed a bug where it was possible to add duplicate fields in a survey form. An error message now appears if you try to save a survey template that contains a duplicate field in the form.

INC-307383

Omada Identity Analytics

Report Generator dashboard – table details not displaying in PDF

There was an issue where table details were not displayed when downloading the Report Generator dashboard as a PDF. The fix ensures that table data now appears correctly in both the preview and PDF download, consistent with the behavior of other dashboards.

INC-301731

Untranslated widget descriptions

We've fixed an issue where analytics dashboard content would display widget descriptions in the previous language after changing your language preference in My settings. This occurred in dashboards using lazy loading, which loads only the initially selected tab first, and loads additional tabs on demand to improve performance.

The fix ensures that all widget descriptions correctly reflect your selected language.

Untranslated dashboard tab names

Due to an issue, tab names on dashboards (for example, Access Navigator) could display as untranslated text, despite the rest of the dashboard being correctly translated. We have now fixed it, and all tab names are displayed in the selected language.

PDF download failure for grids

We've fixed an issue with PDF download from OIA dashboards where the PDF could be partially blank. The fix ensures a correct download and display of PDF files.

Access Intelligence – filtering on Role Overview page

On the Access Intelligence dashboard, we've fixed an issue where filtering was not working correctly on the Role Overview page for the List of Resources in Role view. The fix reconfigures the filtering for the Status Name field, ensuring that all filter selections are applied as expected.

INC-314006

Connectors

Authentication request body field is now optional

In OAuth2 custom authentication scenarios, the Auth request body field is now optional. This allows APIs to authenticate through headers only (a request body is no longer required).

INC-309113

Preview Service – event source for logs

The installation of the Preview Service has been adjusted. It now creates an event source for logs.

INC-304575

SSH connector – support for a tab character (\t)

The SSH connector now supports the tab character (\t) as a CSV column separator.

INC-314621

OAuth2 JWT support in the Okta connector

The Okta connector now supports OAuth2 client credentials JWT as the authentication type.

INC-314828

Microsoft Exchange connectivity – hideInAddressList is not disabled

An issue has been fixed where disabling the Hide from address lists option or webmail access on Exchange mailboxes had no effect.

INC-316435

SAP HR connectivity - error handling

Handling of errors related to HTTP requests aborted due to timeout or cancellation has been improved.

INC-307434

Scope parameter could be omitted from OAuth2 Test connection requests

We have fixed an issue where the Scope parameter was sometimes omitted from the OAuth2 token request generated by a Test connection action, if it was serialized after the client_assertion parameter. Import and provisioning tasks using the same OAuth2 configuration were not affected. Only a spontaneous Test connection check could report the Scope parameter as missing, even though it was correctly configured.

INC-314897

Security

Fixed reflected cross-site scripting (XSS) in affected dialogs

We've fixed a reflected cross-site scripting (XSS) vulnerability in dialogs that shared an unencoded reflection pattern.

INC-317450

Other

Download format has been changed to UTF-8

We have fixed a bug where CSV downloads were generated in standard UTF-8 instead of UTF-8 with BOM, which caused special characters to display incorrectly when the files were opened in Excel. Downloading a CSV file now includes UTF-8 with BOM information.

INC-314910

Preview unavailable for system owner

We have resolved an issue where system owners were not able to run the preview for the systems they owned.

INC-310208

Boolean properties handling

We have fixed the handling of Boolean properties in export mappings that are using account and resource assignment as a source.

INC-316805

Omada Provisioning Service

Unresponsive OPS

In environments with a large number of target systems, OPS could take longer to initialize than the Windows Service Control Manager allowed by default. As a result, OPS could be marked as not responding and be terminated before startup completed.

We have increased the time the Service Control Manager waits for OPS to start, and made this configurable so the wait time can be tuned to your environment. For more information, go to the Configuring OPS startup wait time documentation.

INC-314604

SetProvisioningAdvancedSettingsOPS setting invalid values

The input validation for OPS provisioning advanced settings was improved to prevent invalid values from being accepted.

INC-304333

Documentation

No documented way to disable AI-assisted mappings

A customer setting to enable or disable AI-assisted mappings for connectivity has been added, along with documentation covering it. See Enable AI Assisted Queries and Mappings in the Customer settings documentation.

Unclear documentation on Policy and Risk Check Options

We have fixed an ambiguous Policy & Risk check documentation. See Policy & Risk check to know more.

INC-303638

Unclear documentation on Control policies

We have updated the documentation about Control policies.

INC-315152