Access approval warning message
We fixed a bug that displayed a warning message even when there wasn't any data modified. Now, the Access approval table resets when users perform actions like filtering, sorting, or changing the page. A warning dialog informs users about the data reset before they proceed, following a one-time acknowledgment pattern. The warning won't reappear until the page is refreshed.
Access request fields overlap when using mobile
There was an issue when requesting access from the mobile phone that overlapped the fields. This is now have been fixed.
Access request shows the same context multiple time
We fixed a bug that showed the same context multiple times. Now multiple context assignments with the same ContextId will no longer appear in the business context selection dropdown on the Access Request form.
Access request slow performance
We fixed a bug that slowed down the functioning of the access request process validation stage for resources with child resources. This was fixed by modifying the order of conditions and implementing a queries cache.
Application error on a scheduled survey
Resolved an issue where survey administrators were not assigned to the verify activity when the Confirm before launch flag was set on the survey schedule. Now, survey admins are correctly assigned to the activity upon survey launches.
Application form shows irrelevant fields
Resolved a bug that shows irrelevant fields in the Application form. We fixed that by setting to hide the section. Go to Application form enhancement to know more.
Break tag is displayed in Approval Status
There was a formatting issue that displayed unintended `` tag in Approval Status on Access List.
Code methods in event definitions
We have fixed the description of the CheckIfSetPropertyHasValue code method in the event definition, which previously contained methods with an obsolete status.
Code methods limitation
We have added a limitation to our documentation related to code methods and triggering event definitions if a code method action results in an update of a data object. Refer to Code methods for more information.
Compensating control must be chosen
We resolved the issue where you had to select a compensating control after resolving a conflict. Now, you only need to choose a compensating control when a conflict actually occurs.
Context is hidden in Access Request
We fixed a bug that hid a context. Now, even when the context field is hidden, the default identity context is added to Access Requests.
Data object properties throws error
We resolved a bug that was preventing the data object type property quickform from loading when the property is configured as a Set property with a Listbox control type. The default value is now displayed as a dropdown selection.
Duplicated UIDs in tblAppstr
There was an issue with duplicated UIDs in tblAppstr. We've changed the DataObjectType XMLSCHEMA Descriptions of property UID as it was duplicated with other one and the issue has been fixed.
Dutch translation
We fixed some Dutch translations.
Error in calculated assignments surveys
Fixed a bug that caused an error when submitting the Access Review Survey. This issue has been resolved through an update to the survey templates Calculated Assignment for Managers and Calculated Assignments for Resource Owners.
Error message in Services
Resolved an issue where an unnecessary warning message was being triggered in the Service page.
Evaluate identity violation process error
There was an issue with initiating a new violation evaluation task after approving an SoD violation evaluation.
Extensive memory consumption in the REST connector
To improve handling of the REST connector failed jobs with multiple tasks, consuming extensive amounts of memory resulting in OutOfMemory issues the existing errorResponseFilter setting was enhanced and new responseFilter setting was added. They allow to provide JsonPath that are applied to responses limiting their size:
German translation
We fixed some German translations in the Access Request process.
HandleProxyAddresses support for different protocols
The HandleProxyAddresses feature in the Active Directory collector was supporting only the SMPT protocol. The feature was enhanced to support any protocol.
Highwater mark missing for master data import from RoPE
There was an issue when the highwater mark was missing in the master database for the master data import from RoPE. It resulted in the import not storing the new highwater mark. The issue has been resolved.
Inability to exclude system objects using reference property lookup view
When attempting to exclude system objects using the reference property lookup view, the exclusion process failed to reset the reference property of system objects when the DOT number is greater than one. This has been fixed.
Invalid validation for Access to field
There was an issue with incorrect validation when attempting to input an invalid date range that resulted in inconsistent error handling. Initially, entering a valid from value that higher than the valid to value appropriately triggered a red border and displayed the following error message: Access to must be higher than Access from. However, upon subsequently entering a valid to value higher than the valid from value, the red border persisted, and the error message failed to disappear when it should.
Issue in the RoPE Initial Password extension
We've fixed an issue within the RoPE Initial Password extension. Previously, only newly created account assignments would receive an initial password attribute value. With our recent fix, existing account assignments, without a direct reason, will now be assigned an initial password by the RoPE extension during the provisioning task. This adjustment ensures a seamless notification flow and successful completion of the process.
Issue with calculated assignment for deleted resources
An issue has been solved in the OData API for calculated assignments. If the scope of the call contained an assignment for a deleted resource, the whole API call was failing. This is contrary to how the calculations look in the user interface. This has been improved.
Issue with cleanup import profile
An issue was identified where the cleanup import profile could lead to fact violation errors, such as: 3 ResourceAssignment objects have no fact row with IsRowLatest = 1. This problem occurred specifically when a referenced account or resource was deleted and recreated in the past.
Issue with configuring AD connector without Domain Controller
Provisioning with the Active Directory connector configured resulted in some instances with the Current security context is not associated with Active Directory domain or forest or The RPC server is unavailable. The issue has been resolved and those errors should no longer be encountered.
Issue with deprovisioning jobs
An enhancement has been implemented in the calculation of the provisioning statuses Pending Deprovisioning and Deprovisioning Failed.
Issue with error on missing system ID from resource
An issue occurred when working on a process that generates identities of the type "secondary." Upon requesting access to a custom resource through Legacy Access Request, an error occurred indicating that system id was missing from resource. This issue has been resolved, and Technical Identity Validation will no longer be triggered for custom Identity Types.
Issue with exporting Identities from ODW to ES
There was an issue with the Identity export from Omada Data Warehouse to the Enterprise Server. This problem has been resolved by making the extension attribute case-sensitive in the export mapping.
Issue with filter
There was an issue with the Requested by filter in the Access Request. The problem has been resolved. Currently, the values searched for using the Requested by filter in the RequestedBy column align with those displayed in this column.
Issue with Preview service
The preview service failed to multiply results when a multivalue source attribute was used in mapping for a single value target attribute. We have resolved this issue, and the preview service now functions as intended.
List views paging
We have fixed a bug that prevented paging from starting on the second page. Now, it resets the currentPage to the first page upon rendering a new data grid, ensuring that the data grid always starts from page one for every listView.
Manual provisioning tasks
Resolved an issue in the AssignmentAttributeValueDifferentiator that was creating duplicate provisioning tasks due to an extra assignment when the differentiator value is empty, as it pertains to provisioning claim reasons.
Missing exception details in SQL Data Exchange
There was an issue with a missing exception. The problem has been resolved by adding an app log for data exchange exceptions during unsuccessful imports.
Missing info in StatusDescription and authentication
There was an issue with information missing in the WWW-Authentication header and the StatusDescription. The issue has been resolved and for the REST-based systems, the test connection, when failed, error messages are available in both HTTP header and response body.
Missing translations in transfer ownership survey
Some grids in the transfer ownership survey lacked translations. We have resolved this issue by adding translations for captions used in the grid and form fields in the Transfer ownership survey.
New Access Request UI doesn't show entire attribute names
There was an issue with displaying long attribute names in the Access Request UI. This problem has been resolved, and we now fully support and accurately display unusually long attribute DisplayNames.
OData - viewId Parameter doesn't work as documented
We've fixed the OData viewId response to contain properties from View Displayed fields and basic DataObject properties, such as:
Possibility to set Valid To date from the past
We fixed a bug that was preventing to set a Valid to date from the past when requesting access.
Preview request issue
An issue, where a duplicated preview request resulted in the preview service error has been resolved. In a situation when a duplicate request is registered, the existing preview query request is removed.
QueueIdentity Webservice can be called by any authenticated user
There was an issue with QueueIdentity Webservice that could be called by any authenticated user. We have fixed that by introducing a new Queue identity for recalculation authorization element.
ReceiverFirstName and ReceiverLastName are not calculated
In any email template using the built-in email properties, the [ReceiverFirstName] and [ReceiverLastName] were not replaced with the actual values.
RefPath including filters doesn't work in expressions for the GenerateUniqueValue
ValueGenerator.GenerateUniqueValue code method failed if the expression contained a reference path with filters. This issue has been solved.
Release highlights
We've just released Omada Identity Cloud update! What's new?
Release highlights
We've just released Omada Identity Cloud update! What's new?
Release highlights
Upcoming changes to Approvals flow: We are excited to inform that starting from the August CU, the new Approvals flow will become the default one for all cloud customers. This change aims to enhance the experience with more streamlined and efficient approval processes. To help you prepare for this transition, we encourage you to familiarize yourself with the new Approvals flow and make any necessary adjustments ahead of time. Detailed information and resources about the new Approvals flow can be found in the Access section. If you have any questions or need assistance, please reach out to our support team.
Release highlights
We've just released Omada Identity Cloud update! What's new?
Release highlights
We've just released Omada Identity Cloud update! What's new?
Release highlights
We've just released Omada Identity Cloud update! What's new?
Release highlights
Upcoming changes to Approvals flow: We are excited to inform that starting from the August CU, the new Approvals flow will become the default one for all cloud customers. This change aims to enhance the experience with more streamlined and efficient approval processes. To help you prepare for this transition, we encourage you to familiarize yourself with the new Approvals flow and make any necessary adjustments ahead of time. Detailed information and resources about the new Approvals flow can be found in the Access section. If you have any questions or need assistance, please reach out to our support team.
Release highlights
We've just released Omada Identity Cloud update! What's new?
Release highlights
Upcoming changes to Approvals flow: We are excited to inform that starting from the August CU, the new Approvals flow will become the default one for all cloud customers. This change aims to enhance the experience with more streamlined and efficient approval processes. To help you prepare for this transition, we encourage you to familiarize yourself with the new Approvals flow and make any necessary adjustments ahead of time. Detailed information and resources about the new Approvals flow can be found in the Access section. If you have any questions or need assistance, please reach out to our support team.
Release highlights
We've just released Omada Identity Cloud update! What's new?
Release highlights
We've just released Omada Identity Cloud update! What's new?
Release highlights
We've just released Omada Identity Cloud update! What's new?
Removing objects issue
There was an issue with removing objects during reconciliation from simple arrays. The issue has been resolved.
RoPE failure of validity and parent context
Fixed an issue in the context of a Parent/Child relationship where no overlap existed in their validity periods. This problem resulted in calculations failing due to an invalid validity period.
Rope gives warnings prior to PreValidity
We have enhanced RoPE for identities with a validity period starting after the PreValidity. Previously, the calculation of such identities could trigger a warning related to a missing account. With this update, the warning has been eliminated, and assignments are still not generated.
SAP connector Framework related error in OPS
There were Omada Provisioning Service issues related to the way security protocols were implemented in the SAP connector. The issue has been resolved with the SOAP, Entrust, and MijnCaress connectors setting the TLS security protocol on the connection directly instead of using the global value.
SoD blocking of resources shows error
In some cases, a violating assignment with multiple reasons, including a ReviewOK reason, triggers an unhandled exception in the SoD evaluation feature. We've now fixed the underlying logic to ignore the order of reasons in an assignment.
SoD blocks resources
Fixed a bug that triggered an exception when assignments were blocked in the SoD evaluation process and an expiration date was selected.
SoD evaluation is missing resources
The grid will now display the name of the business process in conflict with another resource. If the process is a child of another process, the parent process will not be mentioned. This differs from the constraint, which only shows the parent business processes.
SoD Expiration day
It is now possible to select Today as Expiration date in the Segregation of Duties evaluation process.
SQL Collector using quotes for the UID
There was an issue with column names containing key words or special characters, causing the collector to break. Now to ensure that names are processed correctly the SQL queries generated by the SQL Query Collector for Generic databases encapsulates column names in special characters:
SQL filter for Identity Deletion Warehouse to Portal Mappings
The Identity Delete query in Data warehouse to Cloud management portal has been fixed to exclude identities that are deleted after their ValidTo date, since such identities are deleted already by the Enterprise Server.
Survey log entries
We have resolved a recent bug that was causing the Log Entries button to be hidden when opening the survey questions of a completed survey.
Survey status filter
In Surveys, when applying a filter to the Status column and choosing the Missing answers option, the appropriate questions are now loaded.
Survey templates transition object
We fixed an issue that was preventing the editing of transitions when creating a survey. Now, it is possible to create new transitions from the process designer and the list of transitions.
Survey verdict incorrectly prolongs CRA validity
For CRAs with no actual state, a survey verdict will not extend its validity through the using the days before verdict expires field in the survey form. Instead, it will maintain the initial validity established on the direct assignment.
Timeout while indexes are being rebuilt
There was an issue with the Cleanup timing out during the rebuilding of XML indexes for the Identity table.
Transfer identity assignments survey template
The Title, Description, and Estimate fields are no longer editable when modifying a published Transfer Identity Assignments survey template. You can make changes to these fields directly in the associated activity within the published survey process template.
Unresolved identity fails to calculate with NullReferenceException in ManualProvisioning Extension
The Manual Provisioning Extension had an issue where, upon disabling an Orphan Account, Omada Identity would check for the Previous Calculation of the Unresolved Identity and incorrectly assume that the Orphan Account Calculated Assignment also had a prior Calculated Assignment. We resolved this by fixing the logic, ensuring accurate handling in such scenarios.
View field title deletion isn't transported in CS
There was an issue with the changeset - it did not apply any changes to a view field title when it was supposed to be set to null. This has been fixed.
Views - User which is not in "Administrated by" can change "Process options"
Some options were not disabled to modify when a user had no permission to perform actions on the View page. This has been fixed.