> For the complete documentation index, see [llms.txt](https://docs-beta.openiam.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs-beta.openiam.com/whats-new-in-openiam/readme.md).

# What's new in OpenIAM

New updates and improvements

Every OpenIAM release since 2026.1.1, newest first, each one split into new features, improvements, bug fixes and security. Use the **tags** filter to narrow the whole feed to one of those, or open *Jump to a release* to go straight to a version.

<details>

<summary>Jump to a release</summary>

| Release      | Date              | In this release                                                                                                                                                                         |
| ------------ | ----------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **2026.9.1** | 14 September 2026 | [New features](#openiam-v2026.9.1-new-features) · [Improvements](#openiam-v2026.9.1-improvements) · [Bug fixes](#openiam-v2026.9.1-bug-fixes) · [Security](#openiam-v2026.9.1-security) |
| **2026.8.2** | 7 September 2026  | [New features](#openiam-v2026.8.2-new-features) · [Improvements](#openiam-v2026.8.2-improvements) · [Bug fixes](#openiam-v2026.8.2-bug-fixes) · [Security](#openiam-v2026.8.2-security) |
| **2026.8.1** | 18 August 2026    | [New features](#openiam-v2026.8.1-new-features) · [Improvements](#openiam-v2026.8.1-improvements) · [Bug fixes](#openiam-v2026.8.1-bug-fixes)                                           |
| **2026.7.2** | 4 August 2026     | [New features](#openiam-v2026.7.2-new-features) · [Improvements](#openiam-v2026.7.2-improvements) · [Bug fixes](#openiam-v2026.7.2-bug-fixes) · [Security](#openiam-v2026.7.2-security) |
| **2026.7.1** | 21 July 2026      | [New features](#openiam-v2026.7.1-new-features) · [Improvements](#openiam-v2026.7.1-improvements) · [Bug fixes](#openiam-v2026.7.1-bug-fixes)                                           |
| **2026.6.2** | 6 July 2026       | [New features](#openiam-v2026.6.2-new-features) · [Bug fixes](#openiam-v2026.6.2-bug-fixes)                                                                                             |
| **2026.6.1** | 22 June 2026      | [New features](#openiam-v2026.6.1-new-features) · [Improvements](#openiam-v2026.6.1-improvements) · [Bug fixes](#openiam-v2026.6.1-bug-fixes)                                           |
| **2026.5.2** | 1 June 2026       | [New features](#openiam-v2026.5.2-new-features)                                                                                                                                         |
| **2026.4.2** | 11 May 2026       | [New features](#openiam-v2026.4.2-new-features) · [Improvements](#openiam-v2026.4.2-improvements) · [Bug fixes](#openiam-v2026.4.2-bug-fixes)                                           |
| **2026.4.1** | 27 April 2026     | [New features](#openiam-v2026.4.1-new-features) · [Bug fixes](#openiam-v2026.4.1-bug-fixes) · [Security](#openiam-v2026.4.1-security)                                                   |
| **2026.3.3** | 14 April 2026     | [New features](#openiam-v2026.3.3-new-features) · [Improvements](#openiam-v2026.3.3-improvements) · [Bug fixes](#openiam-v2026.3.3-bug-fixes) · [Security](#openiam-v2026.3.3-security) |
| **2026.3.2** | 2 April 2026      | [New features](#openiam-v2026.3.2-new-features) · [Bug fixes](#openiam-v2026.3.2-bug-fixes)                                                                                             |
| **2026.3.1** | 16 March 2026     | [New features](#openiam-v2026.3.1-new-features) · [Bug fixes](#openiam-v2026.3.1-bug-fixes)                                                                                             |
| **2026.2.1** | 4 March 2026      | [New features](#openiam-v2026.2.1-new-features) · [Improvements](#openiam-v2026.2.1-improvements) · [Bug fixes](#openiam-v2026.2.1-bug-fixes)                                           |
| **2026.1.1** | 4 February 2026   | [New features](#openiam-v2026.1.1-new-features) · [Improvements](#openiam-v2026.1.1-improvements) · [Bug fixes](#openiam-v2026.1.1-bug-fixes)                                           |

</details>

<details>

<summary>Looking for an earlier release? The 4.2.x line</summary>

**2025**

* [OpenIAM v4.2.2](/whats-new-in-openiam/earlier-releases/2025/v4-2-2.md)
* [OpenIAM v4.2.1.15](/whats-new-in-openiam/earlier-releases/2025/v4-2-1-15.md)
* [OpenIAM v4.2.1.13](/whats-new-in-openiam/earlier-releases/2025/v4-2-1-13.md)
* [OpenIAM v4.2.1.12](/whats-new-in-openiam/earlier-releases/2025/v4-2-1-12.md)

**2024**

* [OpenIAM v4.2.1.11](/whats-new-in-openiam/earlier-releases/2024/v4-2-1-11.md)
* [OpenIAM v4.2.1.10](/whats-new-in-openiam/earlier-releases/2024/v4-2-1-10.md)

</details>

{% updates format="full" %}
{% update date="2026-09-14" tags="feature" %}

## OpenIAM v2026.9.1 — New features

**2026.9.1** brings **machine identities** under governance, extends Privacy Management with enforcement and a self-service center, and accepts any standard authenticator app.

### Non-Human Identity (NHI) module

With the module introduction, the things such as

* service accounts,
* API keys,
* CI/CD credentials,
* certificates,
* cloud workloads; and/or
* AI agents

are now governed as **their own class of identity**, with a registry carrying inventory, lifecycle, ownership and expiry. Four governance jobs ship as standard [batch tasks](/administration-guide/reference/shipped-batch-tasks.md) — health recompute, dormancy notice, expiry notice and expiry auto-suspend — configurable from the *Webconsole*.

Each identity becomes a [Cedar](/glossary.md#cedar) policy principal, so [policy-based access control](/administration-guide/pbac.md) can reason about it. Declared scope is captured as structured grants — a resource type, a concrete resource and an access right — through a scope builder, rather than free text.

This release is **detection, not enforcement**. A batch drift evaluator asks the policy engine whether each declared access is still permitted, logging the denial and alerting the owner — but **nothing is blocked**, and there is no evaluation in an NHI's live access path. Credential age feeds the health score.

**You can also use synchronization from CSV** within a module, which loads an existing inventory straight from a spreadsheet or another tool's export, without writing a [connector](/glossary.md#connector). It accepts the same lifecycle attributes as the admin screens.

### Privacy Management

Privacy state is now **enforced, not just recorded**. A decision layer answers whether an action is allowed given the subject's current privacy state, returning

* *Allow*,
* *Deny*,
* *Conditional*; or
* *Review required*

together with the obligations that apply — minimize, mask, restrict, retain, delete, notify, log, step up or send for human review. Those decisions are enforced at the [Access Gateway](/administration-guide/gateway/access-gateway.md) for applications sitting behind it, and through an **application integration path** for workloads that do not — so a workload does not have to be gateway-fronted to be covered. **Shadow mode** shows what your privacy policies would decide before you turn them on, so you can see the impact without changing anything. Withdrawing [consent](/administration-guide/consent.md) invalidates the caches at once, so nothing is served against stale consent.

**Your users get a Privacy Center of their own** — a branded, self-service page where they see and change their consent, opt-outs and communication preferences, review notice history, and start a privacy rights request. Preferences are modelled separately from legal consent, and an anonymous cookie choice is reconciled with the person's own preferences once they sign in.

### Third-party authenticator apps

Any RFC 6238 [TOTP](/glossary.md#acronyms) app — Google Authenticator, Microsoft Authenticator, Authy — now works as a second factor alongside the OpenIAM app. The enrolment QR code is **rendered locally**, so the shared secret never leaves the OpenIAM server. See [OTP authentication](/administration-guide/security/totp.md).
{% endupdate %}

{% update date="2026-09-14" tags="improvement" %}

## OpenIAM v2026.9.1 — Improvements

### Segregation of Duties

OE-4506 – **SoD Policies page retains selected page size**\
The page size an administrator picks on the SoD policies list is now retained across edits, so the list no longer resets to 10 rows after saving a policy.

OE-4511 – **Notify SoD managers when SoD configuration changes**\
Whenever an SoD policy is created, updated, or deleted, the members of that policy's manager group now receive a formatted email summarizing the policy, who made the change, when, and the exact fields that changed — including added or removed segments, controls, and per-field before/after values.

### Connectors and synchronization

OE-5027 – **Faster user matching during synchronization**\
The matcher now indexes each batch of candidates once and looks each source row up against that index, instead of scanning the whole candidate list per row — so work grows with the batch size rather than its square. Managed-system attribute matching was also corrected to compare values exactly; the previous substring compare could pair a source row with a candidate belonging to a different row.

OE-5058 – **"Sync now" returns immediately**\
Starting a synchronization no longer holds the caller while internal group and role user-count caches are refreshed. Those refreshes now run at the start of the synchronization job itself, so clicking Sync now returns as soon as the job is enqueued.

### Administration

OE-4906 – **Duplicate syslog settings removed from System Audit Log page**\
The syslog dispatch settings — Activate Syslog, Export child rows, Logging Options, Syslog Severity — have been removed from *System Configuration → System Audit Log*. Syslog dispatch is configured per connector under **Audit Export Connectors**, the single authoritative place. Existing values are preserved and still used by the audit pipeline.

OE-5085 – **Fewer unnecessary requests on Webconsole forms**\
A search dropdown for an optional field with no value now waits until it is opened before fetching its options, instead of loading them on page open. Required or preloaded fields continue to load on page open unchanged. On the synchronization edit screen, the CSV file list is fetched only when the source is CSV.
{% endupdate %}

{% update date="2026-09-14" tags="fix" %}

## OpenIAM v2026.9.1 — Bug fixes

### SelfService and UI

OE-4529 – **Date range filter on Pending Approvals now works**\
The From/To date filter on SelfService v2 → Pending Approvals → View My Requests now correctly limits results to records whose created date falls inside the selected window.

OE-4530 – **Change Password from user profile no longer 404s**\
After successfully answering security questions during the Change Password step-up, the browser now redirects to the Change Password screen instead of a 404.

OE-4533 – **Notifications panel items now clickable**\
Items in the notifications panel and the View All Notifications action now respond to clicks and navigate to the corresponding notification target.

OE-4534 – **Global search results now clickable**\
Results in the global search dropdown are now clickable and navigate to the corresponding record.

OE-4536 – **Cancelling a request from the details page now works**\
Cancelling a request from the Request Details page now performs the cancellation, updates the request status, and shows a confirmation — matching the behavior available from the Request Administration grid.

OE-4667 – **Request Administration column and filter behavior**\
Column removal on the Request Administration grid is now validated so the grid always retains a usable set of columns. The row-selection highlight now persists through interactions that previously cleared it.

OE-4668 – **Filter values match column headers on Request Administration**\
Each filter on the Request Administration grid now offers the values of the column it belongs to.

OE-4672 – **Create Request opens on the selection screen**\
Create Request now opens on the initial selection screen where the user picks the request type, instead of jumping straight into a specific path.

OE-4673 – **Dashboard "View All" for Pending Approval now works**\
The View All button on the Pending Approval dashboard tile now navigates to the full Pending Approval list instead of a blank screen.

OE-4676 – **Delegation confirmation now updates the page**\
After a successful delegation the page now updates or navigates away so the outcome is immediately visible.

OE-4687 – **First-time login for new users in SelfService v2**\
After completing the challenge (security question) enrollment phase, new users now land on the SelfService v2 home instead of a 404 error page.

OE-4688 – **Bulk user upload results now visible**\
Bulk uploads now visibly complete synchronization so uploaded users appear in the Webconsole and on the View Synchronized Users screen.

OE-4692 – **SSH Key Manager filter and grid consistency**\
Each column filter on the SSH Key Manager now offers values that match its header, and column removal is validated so the grid always keeps a usable set of columns.

OE-4715 – **Consent History filter and grid consistency**\
Each column filter on the Consent History screen now offers values that match its header, and column removal is validated.

OE-4735 – **"Manage User" separated from "View Direct Reports"**\
The Access Management menu offered one **Manage Users** entry that actually opened View Direct Reports, leaving no way to search for an arbitrary user. It is now two entries — **View Direct Reports**, correctly labelled, and a new **Manage User** opening a user search. The new entry follows the V1 access rules and honours delegated administration scope server-side.

OE-5046 – **Description column added to reviewer's User Details grid**\
The entitlements grid shown to a reviewer inside a user's details during an Access Certification campaign now includes a Description column immediately after the Entitlement name column. Long descriptions truncate with a hover tooltip.

OE-5048 – **Password reset activation email renders correctly**\
The activation email sent through the standard self-service reset password flow now renders the recipient's name and the activation URL correctly instead of showing raw template markup.

OE-5050 – **Login page no longer flashes an authentication-methods error**\
The Verify Your Identity page now waits until the available authentication methods are known before deciding what to display, so the transient "No Authentication methods available" error is no longer shown.

### Workflow and approvals

OE-5070 – **Email delivery when adding a comment on general workflow approval tasks**\
The email notification for a comment on a general workflow approval task (for example, a manager sign-off task) is now sent when Send Email is checked. The duplicate Send Email toggle visible on the comment dialog has been removed.

OE-5087 – **Self-service access requests enforce SoD on the entitlements being requested**\
The check now evaluates the state the user would reach if the request went through — entitlements held today, items already in the cart, and the incoming one — across roles, groups, organizations and resources, rather than only what they hold now. HARD violations refuse the request before any approver is asked; SOFT violations proceed with a warning naming each violated policy. Custom SoD validation scripts still run alongside.

### Connectors and synchronization

OE-5035 – **IPA connector synchronization**\
The FreeIPA connector now sends requests with a proper Content-Length header, resolving intermittent "411 Length Required" failures during group synchronization.

### Authentication

OE-5045 – **First-login password change on new users**\
Newly created users with no prior password history can now complete the first-login password change. The change was previously rejected as a password-history violation. A retried attempt is now recognized as such and completes the login without re-applying the password.
{% endupdate %}

{% update date="2026-09-14" tags="security" %}

## OpenIAM v2026.9.1 — Security

OE-4310 – **Command injection in Linux connector provisioning**\
Attribute values passed through the Linux connector (user names, group names, file names, key material) are now validated and safely passed to the remote shell instead of being embedded in shell command strings. A caller able to provision a Linux account can no longer influence execution beyond the intended provisioning operation.

OE-4314 – **Filter injection in SCIM 1.0 connector**\
The SCIM 1.0 filter is now built using the SDK's safe filter API, so identity values containing SCIM filter characters can no longer alter the filter sent to the target identity provider.

OE-4316 – **Rexx connector credentials no longer written to disk in cleartext**\
The Rexx connector no longer persists its bearer token to a temporary file on disk. Where the connector needs to persist accumulation state, credentials are stripped from the persisted object.

OE-4318 – **Phone and email verification codes are generated server-side**\
Verification codes used for phone and email ownership verification during self-service registration, account recovery, and step-up second-factor challenges are now generated server-side, stored bound to the specific recipient and session with a server-set expiry, and compared on confirmation. A code delivered to one recipient can no longer be replayed to confirm a different recipient.
{% endupdate %}

{% update date="2026-09-07" tags="feature" %}

## OpenIAM v2026.8.2 — New features

**2026.8.2** is a Privacy Management release: notices gain a real authoring lifecycle, and people gain a place to manage their own choices.

### Privacy notice authoring

Privacy notices — the legal texts people see when they consent, opt out or exercise a right — now have an authoring surface, with a lifecycle running

* draft,
* legal review,
* approval,
* publish,
* supersede; and
* retire

Each language is versioned independently with its own owner and approval state, so one translation can move through review without holding up the rest. **Separation of duties is enforced** — an author cannot approve their own notice — and every edit is audited. Before publishing a material change you can preview its impact and choose what happens to people who already accepted: nothing, a notification, a re-prompt, or a block. See [Privacy Management](/administration-guide/privacy.md).

### Privacy Center

An authenticated, brandable page where people see and change their own [consent](/administration-guide/consent.md), opt-outs, objections, restrictions and communication preferences in one place. **Non-legal preferences are modelled separately from consent**, so no choice is silently relabelled as another, and the effective value shows where it came from and what overrode what. An anonymous cookie choice is reconciled with the person's own preferences once they sign in.

### Certification reporting

Certification reports now carry a **reviewer email column** for every campaign step, and on supervisor-review steps it resolves to the reviewed user's actual supervisor rather than a generic address. See [Certification reporting](/administration-guide/governance/certification/campaign-history-and-evidence.md).

### SoD violations page

Each conflicting role or group on the Violations page now shows **which managed system it belongs to**, so a reviewer can see which application a violation applies to without opening every conflict. See [Segregation of Duties](/administration-guide/governance/sod/sod-policies-and-rule-sets.md).
{% endupdate %}

{% update date="2026-09-07" tags="improvement" %}

## OpenIAM v2026.8.2 — Improvements

### Access certification

OE-4988 – **Campaign History loads on large campaigns**\
Campaign History endpoints now aggregate the campaign in the database and return the summary directly, instead of loading every item and rolling them up in memory. Screens that previously timed out on large campaigns now respond in seconds. See [Campaign dashboard](/administration-guide/governance/certification/operate-a-live-campaign.md).

OE-4989 – **Certification preview browse tabs respond reliably**\
Preview browse endpoints now pre-compute the roll-ups they need instead of rescanning the item index for every tab, and they merge updated field mappings into an existing preview instead of failing when the shape has changed. Preview browse tabs no longer time out on realistic campaign sizes. See [Campaign dashboard](/administration-guide/governance/certification/operate-a-live-campaign.md).

OE-4993 – **Campaign History drill-down tables paginate on the server**\
Drill-down tables under Campaign History now fetch one page from the server at a time instead of downloading the entire campaign and paging in the browser. See [Campaign dashboard](/administration-guide/governance/certification/operate-a-live-campaign.md).

OE-4994 – **Certification report downloads scale past 128 MB**\
Large report files are now streamed to the browser in bounded chunks over the internal message bus instead of being shipped in a single message. Downloads that previously failed once the report exceeded roughly 128 MB now complete successfully. See [Certification reporting](/administration-guide/governance/certification/campaign-history-and-evidence.md).

### Platform

OE-4996 – **Automatic retry on MariaDB snapshot-isolation conflicts**\
When MariaDB refuses a transaction due to concurrent row access, OpenIAM now retries automatically. Password changes and other operations already applied on a retry are recognized and completed cleanly instead of being rejected as duplicates.

OE-5003 – **Managed system lookup on the synchronization screen**\
The Synchronization search page now resolves all managed system names for a page of results in a single request instead of one lookup per row, opening noticeably faster in environments with many managed systems.

OE-5009 – **Faster synchronization when transform scripts are in use**\
Each transform script is now compiled and initialized once per part of the run instead of once per source record. Configuration validation no longer builds and discards a full script context for every check. Synchronization runs that use transform scripts complete faster, especially on large sources.
{% endupdate %}

{% update date="2026-09-07" tags="fix" %}

## OpenIAM v2026.8.2 — Bug fixes

### Segregation of Duties

OE-3584 – **Resolving one side of a conflict keeps the user on the violations page**\
Allowing or deleting one side of a conflict could remove the user from the violation view altogether, hiding the remaining conflicting entitlement. Resolving one side now keeps the user on the page with the remaining entitlement shown.

OE-4070 – **Locked identity shown as locked**\
A locked identity was not visibly marked as such in the Webconsole, and the lock flag could be toggled from the UI incorrectly. Locked identities now display the lock indicator and the lock state cannot be changed from the identity view.

OE-4122 – **Violations no longer list deleted SoD policies**\
Violations under a deleted policy kept appearing on the Violations page and re-detection ran whenever the page was opened. Violations belonging to deleted policies are no longer listed, and opening the page does not trigger a re-detect.

OE-4844 – **Blocked SoD grant not emailed to managers as a violation**\
A grant refused by a Hard SoD policy was still being recorded as an active violation and emailed to the user's manager. Refused Hard grants no longer generate manager notifications and are not stored as active violations.

### Access certification

OE-4460 – **Deleting the last campaign returns to Configurations**\
Deleting the last campaign from a configuration left the dashboard trying to display a campaign that no longer existed. Deleting the last campaign now navigates back to the Configurations tab.

OE-4568 – **Delegated review shows the correct list after submit**\
Pressing Back after submitting a review showed "No Data Available" until re-authentication, and review counts could overflow on very large review sets. Back now returns to the up-to-date review list without requiring re-login, and counts are stored in a wider type.

OE-4631 – **The same certification decision cannot be submitted twice**\
Submitting a decision while a previous bulk save was still processing could record the same decision more than once, with no feedback that a save was in progress. A submit is now refused with a clear "save in progress" message while a previous save is running, and all decision controls are held during that window.

OE-4995 – **Campaign-deleted notification renders actual campaign details**\
The email notifying stakeholders of a deleted campaign arrived with unresolved placeholder variables in the body instead of the campaign details.

OE-5025 – **Attestation stored against the reviewed membership**\
Attestations from a review were applied to the entitlement rather than to the specific membership that was reviewed. Attestation state is now stored against the reviewed membership.

OE-5039 – **Decision summaries name the entitlement when grouped by application**\
Decision summary rows showed the user's name where the entitlement name was expected when the reviewer had grouped by application. The row now names the entitlement alongside the application it belongs to.

### Administration

OE-4196 – **User search shows employee type name**\
The Employee Type column in User Search results showed the internal type ID instead of the human-readable display name.

OE-4197 – **Adding an attribute to a managed system works reliably**\
Adding or editing a managed system attribute could silently drop the value unless the field was submitted with Enter. Attribute values are now captured as typed and preserved on save.

OE-4457 – **Authentication loop resolved for affected users**\
A subset of users could get stuck in a continuous authentication loop in multi-node deployments. Key management is now re-initialized consistently on every node so sessions issued on one node are valid on the others.

OE-4967 – **Failed report write no longer marks the sync record as failed**\
A report-write failure after a successful save caused the record to be marked failed. A successful save is no longer overridden by a subsequent report-write failure.

OE-4983 – **Test Connection returns a readable error**\
Test Connection on a managed system showed a bare 500 error when the connector did not respond. The Webconsole now reports a readable message explaining that no response was received.

OE-4987 – **Groovy Manager search field stays readable when zoomed**\
Zooming the browser caused the Groovy Manager search field to collapse to an unusable width.

OE-4990 – **Webconsole configuration downloads preserve non-ASCII content**\
CSV configuration downloads truncated non-ASCII text, and in some places the download button was wired to the wrong endpoint. Downloads now preserve international characters and use a filename supplied by the server.

OE-4997 – **CSV uploads audited correctly**\
The full file contents were written into a single audit event, and a rejected upload was audited as a success. The audit record now describes the upload — filename, size, outcome — instead of storing the file inline, and rejections are recorded as rejections.
{% endupdate %}

{% update date="2026-09-07" tags="security" %}

## OpenIAM v2026.8.2 — Security

OE-4295 – **Password reset token no longer reflected unescaped**\
The reset token is now URL-encoded when returned to the browser, closing a reflected cross-site scripting path on the password reset flow.

OE-4301 – **Groovy scripts run in a sandboxed engine**\
Groovy scripts are now executed inside a sandboxed script engine rather than an unrestricted shell. Scripts that reached outside their intended scope — system properties, arbitrary classes, filesystem, network — will need to be reworked to use approved APIs before deploying this release.

OE-4306 – **Oracle user provisioning parameterized against SQL injection**\
User, role, and grant statements are now built with quoted identifiers and parameterization, closing an SQL injection path in Oracle DDL construction.

OE-4307 – **PostgreSQL role provisioning parameterized against SQL injection**\
Role name, password, and privilege inputs are now validated and quoted before being applied, closing an SQL injection path in PostgreSQL role DDL.

OE-4308 – **Tableau connector uses proper TLS verification**\
The Tableau provisioning connector now uses standard certificate and hostname verification instead of a JVM-wide TLS bypass.

OE-4311 – **SAP UME connector uses proper TLS verification**\
The SAP UME provisioning connector now uses standard certificate and hostname verification instead of a JVM-wide TLS bypass.

OE-4312 – **Thales connector uses proper TLS verification**\
The Thales provisioning connector now uses standard certificate and hostname verification instead of a JVM-wide TLS bypass.

OE-4313 – **Salesforce search escapes query input against SOQL injection**\
Search input is now escaped before being embedded in SOQL, closing an injection path in the Salesforce connector's user and group search.
{% endupdate %}

{% update date="2026-08-18" tags="feature" %}

## OpenIAM v2026.8.1 — New features

**2026.8.1** introduces Privacy Management as a platform module, and gives certification reviewers a way to compare one person's access against another's.

### Privacy Management

Privacy Management arrives as a **new platform module**, and this release is its foundation. Underneath sits a canonical privacy schema tied to OpenIAM identities and a durable event backbone — a consent given, a purpose activated, an evidence item recorded all travel through a reliable envelope, so a consumer that misses a message can reconcile from source rather than lose the record.

Consent itself lives in an **event-sourced ledger**. Every grant, withdrawal and modification is appended and never overwritten, while a live projection answers what a person's consent state is right now. Consent events are only accepted where consent is genuinely the lawful basis for processing, so the history behind any decision is there when a regulator or a subject-access request asks for it.

Alongside the ledger, a governed registry records

* processing purposes, with owner, data categories, audience and permitted channels,
* the activities that use those purposes; and
* the lawful authorities that justify them, typed and carrying validity windows

One version of each stays active and earlier ones deprecate automatically. A non-consent authority lets processing proceed without consulting the ledger at all. Every state change writes an **evidence record** — actor, subject, purpose, outcome — feeding OpenIAM's audit views or shipping to a SIEM.

Operators get a **Privacy Administration Console** for day-to-day work on purposes, consents, activities and events, with a queue for what needs attention — a missing authority, a reconciliation gap — and health readouts for the backbone. See [Privacy Management](/administration-guide/privacy.md).

### Peer access comparison

Reviewers can now pick a **baseline user** — a peer in the same job, say — and see a paged, side-by-side diff of direct and inherited memberships against the person under review. Memberships not yet effective or already expired are left out, and past outcomes and revoker names appear where available. See [The reviewer experience](/administration-guide/governance/certification/the-reviewer-experience.md).

### PBAC console

A **PBAC console** for authoring policies and rolling them out gradually — [shadow mode](/administration-guide/pbac/roll-out-a-policy.md), partial rollout by percentage, or full enforcement. A [simulation runner](/administration-guide/pbac/simulate-a-policy.md) shows what a policy would decide for a given user and request without changing anything and without writing audit entries, and the [decision log](/administration-guide/pbac/trace-a-decision.md) records which policies applied and the mode each was in.

Delegated access requests can also be **switched off per application** from Managed System settings, so for regulated or personal-account systems access can only be requested by the person who will hold it.
{% endupdate %}

{% update date="2026-08-18" tags="improvement" %}

## OpenIAM v2026.8.1 — Improvements

### Access certification

OE-4695 – **Certified vs. revoked split on grouped review rows**\
Grouped rows in the UAR v2 User and Entitlement views now show how many items were certified versus revoked, not just how many are complete. Campaign managers can spot rows with a high revoke rate at a glance without opening every grouped row. See [Campaign dashboard](/administration-guide/governance/certification/operate-a-live-campaign.md).

OE-4764 – **Reviewer improvements in SelfService v2 certifications**\
Items auto-certified by system rules are visible by default and marked as such, so a reviewer can see and override them, and the dashboard's "due today" and "past due" counts now match what the campaign search returns for the same filters.

### Platform

OE-4628 – **PostgreSQL 18 support**\
OpenIAM is now validated for use with PostgreSQL 18. Database schema migrations run cleanly on PostgreSQL 18, and reference container images used for testing and demonstration are updated accordingly.

OE-3817 – **Refreshed localization for nine languages**\
Translations are refreshed for English, French, Spanish, German, Portuguese, Chinese, Japanese, Danish and Swedish. Danish and Norwegian locale codes now take their standard forms (`da_DK` and `nb_NO`), so the right bundle resolves and those users no longer see the interface fall back to English.
{% endupdate %}

{% update date="2026-08-18" tags="fix" %}

## OpenIAM v2026.8.1 — Bug fixes

### Segregation of Duties

OE-3579 – **Stale violations cleared after a policy is removed**\
Violations recorded against a deleted or deactivated policy kept appearing on the Violations tab indefinitely. A full detection sweep now confirms which violations still apply and clears the ones tied to policies that no longer exist or are no longer active.

OE-3582 – **Clear error when a Hard SoD policy blocks a grant**\
Adding a user to a role or group conflicting with a Hard SoD policy returned a generic "unknown error." The blocked grant now returns a clear message identifying the conflicting policy and is no longer recorded as an active violation for the user.

OE-3583 – **Policy rename reflected on existing violations immediately**\
Existing violation records kept showing the old policy name after a rename. The rename is now applied to violation records in the same operation that saves the policy, and deactivating a policy clears its violations at the same time.

OE-4118 – **Consistent Hard SoD error in the classic user view**\
Adding a conflicting entitlement via the classic user view returned an unhelpful generic error. The classic view now returns the same "blocked by policy X" message that the modern views produce.

OE-4119 – **Same start and end date no longer bypasses the Hard SoD check**\
Setting identical start and end dates on an entitlement caused the Hard SoD check not to fire, allowing a conflicting grant through. The Hard SoD check now runs regardless of date shape.

OE-4134 – **Deleted policies no longer listed on the Violations tab**\
Deleted policies kept appearing as sources of violations long after removal. A full unscoped detection sweep now prunes violations belonging to deleted or recreated policies from every user's record.

OE-4579 – **Hard SoD violations visible while the policy is active; no phantom entries after deletion**\
Hard policy violations were never listed on the Violations tab while the policy was active, deleting the policy produced phantom entries, and a save carrying a "skip SoD check" flag could wipe a user's violations for unrelated policies. Hard policies now show their violations while active, deletion leaves nothing behind, and skip-check saves no longer touch other policies.

OE-4635 – **Specific error message for invalid CSV uploads to the SoD Rule Set Catalog**\
An invalid CSV upload was rejected with "unexpected error." The catalog now returns a specific validation message identifying what was wrong — empty file, file too large, unsupported format, or too many rules. See [Rule Set Catalog](/administration-guide/governance/sod/sod-policies-and-rule-sets.md).

OE-4636 – **Invalid JSON or XML rule sets explain the parse failure**\
An unparseable JSON or XML rule set silently reported "0 valid rules" with no explanation, and rule element names with different casing were rejected. Malformed uploads now explain what could not be parsed, and element names are matched flexibly. See [Rule Set Catalog](/administration-guide/governance/sod/sod-policies-and-rule-sets.md).

OE-4637 – **SoD Rule Set Catalog activation buttons readable in all states**\
The "Activate Selected" and "Confirm Activation" buttons showed black text on a black background when disabled on hover. The disabled state now uses a contrasting label.

OE-4719 – **Violations tab search filter returns correct results**\
Filtering the Violations tab by a generated policy's rule key returned every policy in the rule set, and filtering by policy name could return no rows. The filter now matches on the actual policy name and rule key without over-matching or dropping rows.

OE-4754 – **SoD rule set activation reports per-rule failures and runs atomically**\
A rule referencing an entitlement with no name aborted the whole activation with "Operation Failed" and left the catalog in a partial state. Rules needing attention are now reported per rule; name validation happens at save time; and activation runs in a single transaction. See [Rule Set Catalog](/administration-guide/governance/sod/sod-policies-and-rule-sets.md).

OE-4755 – **Entitlements created during rule set activation carry the target managed system**\
Entitlements created as a side effect of rule set activation did not carry the target managed system, so they appeared to belong to no system and did not show up in the expected views. See [Rule Set Catalog](/administration-guide/governance/sod/sod-policies-and-rule-sets.md).

OE-4792 – **SoD detection sweep reports progress and no longer silently skips users**\
Every failure mode of the detection sweep was invisible: a violator missing from the search index was dropped silently, one user's failure aborted the rest, paging could skip users, and a run unable to take its lock said nothing. The sweep now reports users evaluated, violators found, entries cleared and users skipped, and a single failure no longer stops it.

OE-4843 – **Failed SoD evaluation no longer deletes the user's violation records**\
A failed evaluation — caused by a broker or authorization-manager outage — produced an empty violation set that was treated as "no violations," silently deleting every affected user's records. Failed evaluations are now excluded from the stale-violation cleanup, and blocked Hard grants no longer produce active violation records.

OE-4845 – **"Allow selected" hidden until exemption workflow is available**\
The Violations tab's "Allow selected" action referred to a policy exemption workflow that has not yet been reimplemented, so choosing it did nothing useful. The action is hidden until the exemption feature returns.

### Access certification

OE-4724 – **Original reviewer retains campaign visibility after delegating**\
A reviewer was removed from the campaign's reviewer set once their delegate finished, losing visibility of the items they had kept for themselves. Delegation now adds the delegate without removing the original reviewer.

OE-4725 – **Certification reviewers see their campaigns in SelfService**\
Users assigned as certification reviewers did not see any certifications listed under UAR in SelfService. Reviewers now see the certifications assigned to them in the SelfService UAR list.

OE-4741 – **Whole-row certify in UAR v2 runs the SoD gate**\
Certifying a grouped row in one click bypassed the Segregation of Duties check that individual-item certification runs. Whole-row certify now shows the reviewer any warning the gate raises before the certification proceeds.

### Connectors and synchronization

OE-4718 – **CSV sync no longer drops all rows due to inverted empty-row filter**\
The filter meant to skip blank rows was inverted, causing every populated row to be skipped and every sync to produce an empty batch.

OE-4743 – **Sync no longer drops records under concurrent writers**\
Concurrent writers to the shared save buffer could overwrite each other, causing already-processed records never to reach the save call. Buffer access is now synchronized so every processed record is saved.

OE-4750 – **Sync report complete under concurrent writers**\
Concurrent writes to the sync report could overwrite each other, leaving entries missing from the final report. Report writes are now safe under concurrent access.

OE-4752 – **Current State report complete on multi-node clusters**\
Report chunks were written to local disk on whichever node produced them, so a report assembled on a different node was missing chunks. Report chunks now go to shared storage so any node can assemble the full report.

OE-4757 – **Sync audit correctly attributes actions to the initiating user**\
Overlapping sync runs could record one user's identifier against another user's login. The audit now verifies the cached requester belongs to the current run before reusing it; a service account without a default login is recorded as "UNDEFINED" and the batch continues.

OE-4768 – **Unpaired sync records reported for all source types**\
Unmatched source rows were only recorded in the sync report for CSV syncs; on connector, RDBMS, and LDAP sources they disappeared silently. Unpaired records are now reported for every source type with the specific reason they could not be matched.

### Authentication

OE-4413 – **Reset password methods appear in the dropdown**\
The Reset Password Methods dropdown under Administration → System Configuration → Password displayed no methods.

OE-4721 – **Forgot Password page shows available authentication options**\
The Forgot Password page loaded with an empty authentication section — no security questions, no OTP options. Available options are now displayed.

OE-4728 – **Reconciliation runs when triggered from the console**\
Reconciliation endpoints were not reachable, so reconciliation operations initiated from the console did not run.

OE-4729 – **Removing a phone number syncs to Google Workspace**\
Removing a phone number in OpenIAM did not clear the number in Google — the deleted value was still being sent. Removed phone numbers are now excluded from the update sent to Google.

OE-4745 – **Template saves succeed with supervisor and email field configurations**\
Saving with a supervisor field could fail even when the supervisor was set correctly, and a template that excluded the email field threw an error on save from the Webconsole. Both now save, and when a required field is missing the error message names it.

OE-4749 – **New Hire Approval workflow completes after upgrade**\
In-flight approvals stored using pre-2022 class names failed to deserialize after upgrade. The workflow engine now recognises the old class names and reads persisted data using the current data types, allowing in-flight approvals to continue and complete.

OE-4790 – **Forced first-login password change fires exactly once**\
Users completing the forced first-login password change were redirected back to the change-password screen on every subsequent login. The forced-change state is now cleared once the user has changed their password and successfully re-authenticated.
{% endupdate %}

{% update date="2026-08-04" tags="feature" %}

## OpenIAM v2026.7.2 — New features

**2026.7.2** gives the SoD Rule Set Catalog two operational tools, and moves policy evaluation into a service of its own.

### Segregation of Duties

A **Scheduled Detection** tab runs detection sweeps on a schedule you set, against an audience you choose, and emails a styled digest of the findings. The task behind it is created the first time you configure it and rebuilt if it is ever deleted; configuration changes and manual runs are audited.

A **Compare** dialog shows the difference between two rule sets, or between a rule set and the policies currently active, so a candidate can be checked against what it would replace before you activate it. See [Rule Set Catalog](/administration-guide/governance/sod/sod-policies-and-rule-sets.md).

The SoD violation page now also names the **managed system** the conflicting entitlements belong to, so an investigator can see which application a violation concerns without cross-referencing another screen. See [SoD detection and violations](/administration-guide/governance/sod/sod-detection-and-violations.md).

### Review list filters

Managers can filter their review list by **All**, **Pending** or **Certified**, and the filtered view stays responsive on large campaigns. See [Campaign dashboard](/administration-guide/governance/certification/operate-a-live-campaign.md).

### PBAC microservice

Policy-based access evaluation moves into a **microservice of its own** — separately deployable, independently scalable, with a dedicated evaluation endpoint the other OpenIAM services call for decisions. See [Policy-based access control](/administration-guide/pbac.md).
{% endupdate %}

{% update date="2026-08-04" tags="improvement" %}

## OpenIAM v2026.7.2 — Improvements

### Access certification

OE-3986 – **Distributed certification report generation**\
Report generation is now distributed across cluster nodes instead of running on a single node. Large certification reports complete faster and no longer concentrate load on one server. See [Certification reporting](/administration-guide/governance/certification/campaign-history-and-evidence.md).

OE-4569 – **Certification performance improvements**\
New indexes on review items make list and filter operations faster on large campaigns. Certification entities now use lazy loading and JDBC batching where they did not before.

OE-4573 – **Bulk reviewer decisions no longer block each other**\
Large bulk approve/revoke decisions are broken into per-user chunks and processed on a dedicated queue, so one reviewer's large submission no longer holds up other reviewer actions. Completion detection uses a single grouped query instead of per-item lookups.
{% endupdate %}

{% update date="2026-08-04" tags="fix" %}

## OpenIAM v2026.7.2 — Bug fixes

### Access certification

OE-4572 – **Campaign metadata preserved on state transition**\
Transitioning a certification campaign from **Started** to **In Progress** wiped the campaign's core metadata including its name, causing the save to fail. Campaign metadata is now preserved across the transition.

OE-4576 – **Reliable audit logging for large certification campaigns**\
Per-user certification audit entries embedded the entire campaign scope in the request body, making entries too large for downstream audit-log consumers on large campaigns. The campaign scope is now trimmed out of per-user audit entries.

OE-4577 – **Accurate campaign launch progress**\
The campaign was marked launched before participant and review-item creation had finished, redirecting administrators prematurely, and the progress bar offered no explanation for the wait. The launch signal now waits until population is complete, progress steps are numbered and localized, and administrators are told they can safely leave the page. See [Campaign dashboard](/administration-guide/governance/certification/operate-a-live-campaign.md).

### Segregation of Duties

OE-4574 – **SoD detection stability after activating a new rule set**\
Certain policies created by activating a rule set could cause the next SoD detection run to fail before it completed. SoD detection now handles rule-set-created policies safely.

OE-4575 – **Deleted SoD policies clear from the Violations tab**\
Deleting an SoD policy left the violations it produced behind on affected users' Violations tabs. Violations tied to a deleted policy are now removed at the same time the policy is deleted.

### Authentication

OE-4567 – **Last-login timestamp updates for SSO logins**\
Logins that skipped the OpenIAM password check — SSO and other single-sign-on flows — did not update the user's last-login timestamps. The timestamps now update on every successful login, including SSO.
{% endupdate %}

{% update date="2026-08-04" tags="security" %}

## OpenIAM v2026.7.2 — Security

OE-3477 – **TLS for Redis in the RPM cluster**\
Redis client and Redis Sentinel connections in the RPM cluster deployment now use TLS, using the deployment's own keystore and truststore. Traffic between OpenIAM and Redis is encrypted in transit.

OE-4176 – **Signed RPM packages and container images**\
Container images and RPMs are now signed with Cosign as part of the release pipeline. Customers can verify the authenticity and integrity of every OpenIAM artifact they deploy, supporting supply-chain security requirements.
{% endupdate %}

{% update date="2026-07-21" tags="feature" %}

## OpenIAM v2026.7.1 — New features

**2026.7.1** ships a catalog of ready-made Segregation of Duties rule sets, and sharpens what a reviewer sees during a certification.

### SoD Rule Set Catalog

Segregation of Duties no longer starts from a blank page. A **catalog of pre-built rule sets** ships with OpenIAM: browse it in the Webconsole, activate what you need, and re-sync when new versions are published without losing local customizations. The platform tracks **drift**, so you can see when an active copy has diverged from the catalog version, and a bulk CSV upload extends any rule set with rules of your own.

The libraries included are

* Manufacturing — a production-grade set of high- and medium-severity rules,
* HR and Payroll,
* Financial Services,
* Plant Maintenance; and
* SAP Basis and cross-application privileged access

each in US and EU regulatory variants. An SAP-heavy site gets an audit-ready baseline for its most sensitive administrative access without hand-authoring rules. See [Rule Set Catalog](/administration-guide/governance/sod/sod-policies-and-rule-sets.md) and [SAP SoD analysis](/administration-guide/governance/sod/sap-sod-analysis.md).

### Access certification

A campaign now has a **mandatory sign-off gate**: it cannot reach a closed state until the responsible reviewer explicitly signs off, and sign-off status is tracked on the campaign, so a compliance team reads "review complete" from the campaign itself rather than inferring it from line-item decisions.

Reviewers **confirm before a revoke is finalized**, so a revoke cannot be submitted by accident.

Each entitlement's **description** appears wherever the entitlement does — in the user's detail view and in the campaign's entitlement view — so the decision to keep or revoke rests on what the access grants rather than on its name.

A **pending-review-only filter** hides users already fully reviewed. It sits in the toolbar across the user view, the entitlement view and per-user detail, and stays applied as a reviewer drills in.

A per-certification **beta toggle** opts a campaign into features still being finalized — currently automation rules — and flows from the certification definition to every campaign it produces.

### Forgotten-password email

The activation email in the forgotten-password flow now carries the user's name and company name, so it reads as a personal notification rather than a generic system message. Redundant parameters that could surface incorrect data were removed.
{% endupdate %}

{% update date="2026-07-21" tags="improvement" %}

## OpenIAM v2026.7.1 — Improvements

### SelfService and UI

OE-4229 – **Bulk Password Reset on SelfService v2**\
The administrator's Bulk Password Reset screen has been rebuilt on the SelfService v2 design. Step-up authentication, password-policy enforcement, and managed-system routing now run correctly on the new screen.

OE-4233 – **Change Password on SelfService v2**\
The end-user Change Password screen has been migrated to the SelfService v2 design, with the "Verify Identity" step-up correctly enforced before the password change proceeds.

OE-4379 – **SelfService v2 fully localized**\
Every screen in the SelfService v2 UI has been switched from hard-coded English text to the localized string catalog. Registration, Manage Users, Group Management, View User, My Tasks, User Access, Security Keys, IT Policy History, Bulk Upload, Directory Lookup, Password History, My Device, User Sessions, Register Device, and My Groups screens now render in the user's selected language. A lint guardrail prevents new v2 screens from shipping with English text baked in.

OE-4390 – **SelfService v2 consistency polish**\
A batch of consistency fixes across SelfService v2 screens ensures tables, forms, tabs, dates, and empty states all look and behave the same way:

* Unified table-toolbar filters and a single "clear filters" control across list screens.
* One canonical date format and shared date picker across all screens.
* Shared status badges, empty-state component, and error boundary across the app.
* Consistent form-footer alignment and full-height layout across entity edit screens.

### Access certification

OE-4519 – **Faster reviewer user view in large campaigns**\
Metadata lookups that previously ran per row in the reviewer user view are now batched, and the default managed-system resolution is done once and reused rather than repeated per row. Reviewers opening large campaigns see the user list load noticeably faster.

### Connectors and synchronization

OE-3614 – **Out-of-the-box Active Directory configuration**\
The bundled AD PowerShell provisioning scripts have been reorganized so a new customer can wire up AD synchronization with less customization. New AD integrations reach a working state faster, and existing deployments can pick up the updated scripts as a cleaner baseline.
{% endupdate %}

{% update date="2026-07-21" tags="fix" %}

## OpenIAM v2026.7.1 — Bug fixes

### Access certification

OE-3958 – **Campaigns no longer show "Resume Review" before any items are reviewed**\
New campaigns could display "Resume Review" on first access even though the reviewer had not yet reviewed any items. Campaigns now show a starting status on first access; "Resume Review" only appears after the reviewer has started working through items.

OE-4358 – **End users can reach their certification reviews again**\
Users assigned only the End User role were missing the certification review menu entry and received a 401 response if they navigated to it directly. The End User role now has the correct permission to reach and complete access reviews from SelfService.

OE-4458 – **Role and group descriptions visible in the entitlement view**\
The description text on role and group entitlements was not shown in the entitlement view. Reviewers now see the description alongside the entitlement name.

OE-4459 – **Campaign Manager can review their own delegated items**\
A Campaign Manager who self-delegated a review could not perform review actions on the delegated items. The original reviewer is now removed from the step on delegation, and the Campaign Manager is navigated to the user tab so their new work is visible.

OE-4500 – **Access Certification reminder emails deliver correctly**\
Certification reminder emails reached the original reviewer even after delegation, and could show unresolved placeholder text. Reminders now go to the current assignee and render every reviewer- and campaign-specific detail.

OE-4367 – **Deleting an organization no longer breaks certifier-owned users**\
Deleting an organization could cascade into removal of the certifier user attached to it. Organization deletion now cleanly detaches the certifier relationship instead of removing the user.

### SelfService and UI

OE-4329 – **Larger CSV uploads no longer fail with a size error**\
CSV uploads larger than \~3 MB failed with a generic size-limit error. The upload path now accepts files up to the current configured limit, and when a file does exceed the limit the error message clearly states the maximum size.

OE-4331 – **Users with very large direct-report populations can be updated again**\
Updating the IGA profile of a user with roughly 1,000 or more direct reports failed with an "unknown error." The profile update path now handles large direct-report populations cleanly.

OE-4352 – **Policy Map Template screen recovers cleanly from delete-and-back**\
On the Policy Map Template screen, deleting a saved row and clicking Back produced a server error, and deleted rows were still checked during attribute-name validation on save. Back now returns cleanly and deleted rows are ignored.

OE-4502 – **SoD bulk upload template downloads and accepts typed references**\
The SoD Rule Set Catalog bulk upload landed on a blank page instead of downloading its CSV template, and the parser rejected typed entitlement references. The template now downloads, and typed references are accepted end to end.
{% endupdate %}

{% update date="2026-07-06" tags="feature" %}

## OpenIAM v2026.6.2 — New features

**2026.6.2** lets you rehearse a certification campaign before committing to it, and moves seven more screens onto the SelfService v2 portal.

### Access certification

**Campaign preview** runs the full scope and reviewer calculation against real identity data without creating a campaign, review items or workflow tasks. It runs asynchronously behind a progress card, and shows every user and entitlement that would be included or excluded, the precise reason for each exclusion, and the reviewers each item resolves to — **grouped by reviewer**, so you can see the queue each one would receive before they receive it. Every preview table filters by exclusion reason or by column.

That makes a fix-and-re-run loop possible: inspect the exclusions, correct the configuration or the data, cancel, preview again. When it looks right, **launch from the preview snapshot** — nothing is recomputed, so what you previewed is exactly what launches. Change the configuration after previewing, and launching asks whether to recompute or go with the preview as it stands. Scheduled certifications now produce a preview for review rather than launching directly, and each preview carries a validity window so a stale one cannot be launched. See [Campaign preview](/administration-guide/governance/certification/preview-and-launch.md).

**Extended User Search** builds the campaign population without SQL: nested include and exclude rule groups over user attributes, roles, groups and organizational criteria, saved under a name, reused across campaigns, and previewed before you save.

A **History tab** keeps a permanent record of every launch — status, execution dates and a report download for each — opening into the full outcome: who was included and who excluded, which review items, which reviewers took part, what was delegated, and the certified and revoked decision tables. Each drill-down is paged and filterable down to per-row user detail. An auditor reads a campaign's history from the campaign itself, rather than reconstructing it from exported reports.

Reviewers get a **bulk approval mode** — certify all, revoke all, submit, with a live count of marked items — switched on per certification by an **Allow Bulk Approval** toggle carrying a risk disclaimer. Bulk decisions are recorded as `BULK` in the audit trail and flagged in the certification report, so they can be reviewed apart from individual ones. The mode hides once a campaign is fully reviewed, and stays disabled on rows already completed individually.

### SelfService portal redesign

Seven more screens move onto SelfService v2:

* Directory Lookup,
* Manage Users (direct reports),
* New User Registration, with CAPTCHA and one-time-passcode confirmation,
* Bulk Upload,
* Edit Profile,
* Challenge Response security questions; and
* FIDO Authenticator enrolment for hardware security keys

### Segregation of Duties report

The Segregation of Duties report gains a **Segment Description** column, so a compliance reviewer reads each segment's context in the report itself rather than looking it up.
{% endupdate %}

{% update date="2026-07-06" tags="fix" %}

## OpenIAM v2026.6.2 — Bug fixes

### Access certification

OE-4362 – **Certification User View fails on Microsoft SQL Server with large campaigns**\
The Certification User View failed to display users on Microsoft SQL Server-backed deployments when a campaign contained a large user population, because the query exceeded SQL Server's query-size limit. The User View query now stays within the limit regardless of population size.

### Platform

OE-4249 – **User provisioning status stuck in multi-instance deployments**\
A user's account provisioning status could stick in a pending update state after an update, blocking further updates to that account — a concurrency problem in multi-instance deployments. Provisioning-status updates now settle correctly under concurrent activity from several instances.

### SelfService and UI

OE-3551 – **Page Template deletion now removes its associated resource**\
Deleting a Page Template left its underlying resource behind in the system. Deleting a Page Template now also removes the associated resource.

OE-3869 – **Bulk Operations on Organizations: search and layout fixed**\
The Webconsole Bulk Operations screen returned the wrong search results and sized its panel wrongly when the target entity type is Organizations.

OE-4143 – **Synchronization History JSON view no longer freezes the Webconsole**\
Opening the JSON details of a synchronization run from the Synchronization History screen could freeze the entire Webconsole tab.

OE-4207 – **Audit report generation reliability fix**\
The Audit report could generate with incorrect formatting or fail to generate cleanly. The report now generates reliably with the expected fields and layout.
{% endupdate %}

{% update date="2026-06-22" tags="feature" %}

## OpenIAM v2026.6.1 — New features

**2026.6.1** moves certification out of the ESB into a service of its own.

### Certification microservice

Certification becomes **its own microservice**, `certification-manager`, owning a new `certification` database. Large campaigns can be scaled and tuned independently of the ESB, memory pressure during campaign windows drops, and a certification job can no longer disturb ESB API traffic. The Activiti review workflow stays in the `workflow` service and delegates its certification steps to the new one.

Existing certification data migrates on first start. Deployment, the database and the migration are covered in [Release-specific steps](/installation/rpm/rpm-upgrade/release-specific-steps.md). See also [Batch tasks](/administration-guide/automation/batch-tasks.md).

**Custom Groovy scripts need their imports updated.** `CustomCertificationHelper` moved package as part of the extraction, so a script referencing the old one will not compile. The package moves are listed alongside the upgrade steps. See [Operate certification services](/administration-guide/governance/certification/operate-certification-services.md).

### Campaign scope by employment state

Campaign scope can now be set by employment state — **active users only, terminated users only, or both** — so someone terminated who still holds active entitlements can be pulled into a security-focused review rather than silently dropped.

### PowerShell connector hardening

PowerShell connectors gain **query-injection protection**, enforced at the connector rather than in the script. Harmful operations are detected at the language and execution-tree level, and file writes, external POST calls and dangerous cmdlets such as `Remove-Item` are refused regardless of where the script came from.
{% endupdate %}

{% update date="2026-06-22" tags="improvement" %}

## OpenIAM v2026.6.1 — Improvements

### Platform

OE-3884 – **RPM installations run on Amazon Corretto 21**\
`rpm-utils` now installs Amazon Corretto 21 in place of the deprecated OpenJDK, so an RPM deployment runs the same JVM as a Docker one. A customer moving between JVMs keeps the certificates imported into `cacerts`.

OE-3887 – **Improved RPM init and upgrade scripts**\
The RPM `init` and `upgrade` scripts are now more flexible to reduce the need for customization in non-standard environments, including VMs hardened by STIG where mounted volumes have insufficient space or `/tmp` has the `NOEXEC` flag set.

### SelfService and UI

OE-3945 – **Resource name filter narrows the list when adding a resource to a role**\
In *Webconsole → Access Control → Roles → Role Entitlements*, the resource name filter under **Add Resource to Role** now narrows the results. It previously left the list unchanged, so an administrator had to scroll the full resource catalog.

OE-4192 – **Improved display of completed certification campaigns**\
Due dates on completed campaigns now render in a muted style so they read as historical rather than upcoming. Composite campaigns are also excluded from the emergency filter so it accurately reflects only active emergency reviews.
{% endupdate %}

{% update date="2026-06-22" tags="fix" %}

## OpenIAM v2026.6.1 — Bug fixes

### Access certification

OE-3968 – **Certification reports download failure**\
Certification reports failed to download from the UAR Reports section.

OE-4191 – **Completed campaigns disappear from reviewer dashboard**\
Campaigns were no longer visible to reviewers after transitioning to COMPLETED status when filtering by reviewer.

The reviewer filter previously resolved reviewers from `AccessReviewItem.currentReviewer`, a field that is cleared on campaign completion. The filter now queries `CampaignStep.reviewers` (the `CAMPAIGN_REVIEWERS` table), which persists all step reviewers — including escalated and delegated ones — for the full campaign lifecycle.

See [Campaign dashboard](/administration-guide/governance/certification/operate-a-live-campaign.md).

### Authentication

OE-4056 – **Password reset via security questions fails within grace period**\
`/idp/rest/api/password/public/auth-questions` returned a 500 error when a user's password was expired but still inside the grace period. The `RESULT_SUCCESS_PASSWORD_EXP` code was not handled in `AbstractPasswordController.doQuiteLogin()` and fell through to the default 500 branch.

OE-4144 – **SelfService: Change Password Extended fails after question-based authentication**\
In SelfService Center → Change Password Extended, the password change failed with a generic error after the security questions had been answered correctly.

OE-4145 – **SelfService: password recovery methods fail with generic error**\
TOTP, voice, and email authentication methods in the Change Password Extended flow all returned a generic error instead of proceeding with the password reset workflow.

OE-4215 – **Force password change prompt fires on every login**\
The "Force password change on first login" prompt appeared on every login rather than only the first, trapping users in an infinite password-change loop.

OE-4250 – **"Password Never Expires" no longer conflicts with expiry fields**\
Enabling "Password Never Expires" did not suppress Password Expiration Days and Grace Period, so a policy that intended no expiry still produced `RESULT_PASSWORD_EXPIRED` errors.

See [Password policy](/administration-guide/security/password-policy.md) for configuration details.

### Connectors and synchronization

OE-3889 – **Linux connector: NullPointerException in RabbitMQ message processing**\
A `NullPointerException` in `TestConnectorConnectionListener.processingRequest()` made the Linux connector fail while processing provisioning requests through the Spring AMQP RabbitMQ listener.

OE-3911 – **rpm-utils: rproxy configuration updated for mobile app support**\
RPM installations carried an rproxy configuration that did not support the mobile app. `rpm-utils` now ships the socket push auth fix, so mobile app functionality works on an RPM install.

OE-4128 – **Orphan Management: orphan users not visible on the Orphan Management page**\
The orphan search endpoint (`/rest/api/orphans/orphan-search`) returned 404, so no orphan users appeared on the Orphan Management page. See [Orphan management](/administration-guide/identities/resolve-orphan-accounts.md).

OE-4140 – **Workday connector: employee sync fails due to RabbitMQ message size limit**\
The Workday connector serialized the entire employee dataset into a single RabbitMQ message, exceeding the 128 MB broker limit and silently failing after \~1.8 hours of data fetching.

The fix implements batching in `SearchUserCommandExecutor.collectWorkerData()` so the employee list is split into smaller chunks sent as multiple MQ messages, each staying within the size limit. See Workday connector.

OE-4185 – **Role: old managed system not removed after changing to a new one**\
Changing the managed system assigned to a role left the previous managed system visible alongside the new one in Role Entitlements.

OE-4194 – **Connector: screen goes blank when adding a policy map template**\
Clicking Add under Provisioning → Connector → Policy Map Template produced a blank screen.

OE-4202 – **Connector: duplicate custom fields allowed in connector configuration**\
The same custom field could be added more than once to a connector configuration.

### SelfService and UI

OE-4117 – **Classic user entitlement view: start/end date save fails for Organization**\
Adding or editing an organization entitlement in the classic user entitlement view failed with an invalid date format error, so start and end dates could not be saved.

OE-4168 – **Webconsole: Managed System Viewer fields missing after clicking Edit**\
Fields in the Managed System Viewer were not displayed or not retained after clicking the Edit (pencil) icon on a user's managed system record.

OE-4169 – **Webconsole 500 error on Connector List page after fresh RPM install**\
On a fresh RPM installation, any Webconsole page using the `<t:head_common>` tag returned a 500 error — a `ClassNotFoundException` for `head_common_tag`, from a JSP classloader issue with Spring Boot's embedded Tomcat.

OE-4182 – **Access control: adding parent role causes blank screen and console error**\
Adding a parent role under Access Control → Roles → Organization left the Webconsole blank, from a React rendering error.

OE-4183 – **Access control: parent group not saved in group entitlements**\
Adding a parent group in Group Entitlements failed to save.

OE-4184 – **Business Rule Action Group: group and role search not filtering correctly**\
In Business Rule Action Groups, entering a search term did not narrow the list of AD groups or roles returned.

OE-4195 – **Droppable item list: UI elements break when dragged**\
Dragging an item in the System Configuration system tab or in Page Template duplicated entries or misaligned the whole template.

OE-4201 – **Page template: metadata type lists all types regardless of grouping**\
Selecting a metadata grouping did not filter the metadata type dropdown — all types were displayed regardless of the selected group.

OE-4205 – **Mail and phone validation errors when saving new user**\
Creating a user from a template that includes phone and email fields raised false validation errors for area code, country code, phone number and email, even with every value correctly filled in.

### Platform

OE-4252 – **Backported 4.2.1.x client fixes**\
Seven fixes previously delivered as hotfixes to 4.2.1.x customers are now in the main line:

* Fixed provisioning principal status for non-OpenIAM managed systems when there is nothing to send.
* Fixed an rproxy log error caused by an incorrect date format received from ESB for the token.
* Fixed user search when combining phone, email, address, and attributes in a single `searchBean`.
* Fixed a possible record creation issue in `BATCH_SCHEDULE`.
* Fixed `findAllById` for login by splitting into parts to stay within SQL `IN` clause limits.
* Fixed recursion in the batch scheduler.
* Added attribute, phone, email, and address details to audit logs in OpenSearch.
  {% endupdate %}

{% update date="2026-06-01" tags="feature" %}

## OpenIAM v2026.5.2 — New features

**2026.5.2** moves batch processing out of the ESB, and makes Groovy scripts portable between environments.

### Batch task microservice

The batch task subsystem becomes **its own microservice**, `batch-task-manager`, owning a new `batchtasks` database. Batch jobs no longer share heap with the ESB, so the ESB can be sized for API traffic while the batch manager is sized and scaled for job load — fewer GC spikes during heavy batch windows, and a stuck or memory-hungry job no longer reaches the ESB request path. It also settles the cache-consistency errors that used to surface as `EntityNotFoundException` on `BatchTaskScheduleEntity`.

Existing batch configuration migrates on first start. Deployment, the database and the migration are covered in [Release-specific steps](/installation/rpm/rpm-upgrade/release-specific-steps.md).

### Groovy Script Management

Groovy scripts can now move between environments, or be backed up, without copy-paste. From the **Groovy Manager** screen or the REST API you can export every script as one archive, export a selection from the file-browser tree, or import a zip to create and update in bulk — the importer matches on path, name and version, so existing scripts are updated in place rather than duplicated. Both operations are audited. See [Manage Groovy scripts](/administration-guide/automation/manage-groovy-scripts.md).
{% endupdate %}

{% update date="2026-05-11" tags="feature" %}

## OpenIAM v2026.4.2 — New features

**2026.4.2** makes connector upgrades less manual and adds end-to-end request tracing.

### Connector installer upgrades

The **.NET and PowerShell v5 connector installer** now upgrades in place from older versions, with a migration mechanism built in, so moving forward no longer means reconfiguring from scratch. One connector can serve multiple instances, which removes much of the configuration an upgrade used to carry.

The **PS Graph connector** can send user invitations across tenants.

### Request tracing

Logs are enriched with a **RequestId** that propagates across execution threads, so a single request can be followed through backend and client logs end to end. Custom logging implementations pick it up without being changed.

### Reviewer comments

Entitlements gain a **comment field** in the user view, so a reviewer can record why access was revoked and the justification lands in the audit trail beside the decision. The default entitlement page size in a review also moves from 10 to 100, cutting the pagination on large campaigns. See [The reviewer experience](/administration-guide/governance/certification/the-reviewer-experience.md).
{% endupdate %}

{% update date="2026-05-11" tags="improvement" %}

## OpenIAM v2026.4.2 — Improvements

### Access certification

OE-3718 – **One notification per campaign step instead of one per user**\
Certification notification has been reworked to cut the volume reviewers receive:

* Reviewers receive one notification per campaign step instead of per user.
* Initial notification informs downstream reviewers of pending requests.
* Follow-up notification is sent when previous review steps are completed.
* Emails include aggregated request details for better usability.

OE-3263 – **Supervisor Type limits when User Supervisor is the reviewer**\
A campaign that names **User Supervisor** as its reviewer and also assigns a Supervisor Type does not resolve reviewers the way the configuration implies. The behavior and its limits are now documented; the product itself is unchanged.

OE-4021 – **Faster entitlement loading in the User Manager**\
A user's entitlements now load without the noticeable delay the User Manager previously showed.
{% endupdate %}

{% update date="2026-05-11" tags="fix" %}

## OpenIAM v2026.4.2 — Bug fixes

### SelfService and UI

OE-3753 – **Incorrect property type displayed in Set Header metadata**\
Editing metadata properties resulted in incorrect property type/value display.

OE-3787 – **Unable to create new Resource Type**\
New resource types could not be created.

OE-3809 – **Agency field value not persisting in self-service**\
Updates to the Agency field were not saved in the SelfService application despite successful workflow execution.

OE-3928 – **User attribute values missing from My Info page**\
Only attribute names were displayed without corresponding values in newer versions.

OE-3929 – **Email update failure via simple email field**\
Updating email through the simple email field did not persist unless additional fields were present.

OE-3949 – **Page navigation issues in entitlement views**\
Navigating pages that contain entitlements redirected to the wrong place.

OE-4020 – **Managed system viewer performance and UI issues**\
Three problems in the Webconsole:

* Connector configuration UI freezing without loading indicator.
* Errors during reconciliation view.
* Broken simulation mode page.

### Access certification

OE-3769 – **User profile deletion blocked by active access review**\
A user referenced in an active certification could not be deleted — the delete failed on database integrity errors.

OE-3905 – **Missing Supervisor Type-based reviewer resolution**\
Reviewer resolution by the selected Supervisor Type had stopped working in Access Certification. It resolves again.

OE-3971 – **Orphan management user creation failure**\
User creation failed in orphan management workflows.

OE-3976 – **SQL exception during large certification runs**\
Running a certification over a large dataset raised database errors.

OE-3988 – **Certification campaign view failure for large datasets**\
The campaign view failed when a campaign manager opened a large-scale certification campaign.

OE-4039 – **Certification delegation inconsistencies**\
Delegated access review requests showed incorrect counts and missing user data.

OE-4040 – **Improved commenting experience in certification**\
Four changes to commenting in certifications:

* Separation of access-level and task-level comments.
* Comments visible across views.
* Inclusion of comments in notification emails.
* Added dedicated email template for delegation events.

### Authentication

OE-3687 – **Ambiguous URL mapping causing incorrect error response**\
Conflicting controller mappings returned a 500 error during an authentication failure, where the 401 error page was expected.

OE-3989 – **User remains locked after unlock action**\
Users remained locked out after being unlocked until server restart due to cache inconsistencies.

OE-3990 – **Forgot password flow error for new users**\
Password reset failed for newly migrated users who had not completed initial setup or consent.

### Platform

OE-4015 – **Fanout MQ exchange delivery issue in clustered environments**\
Fanout exchanges delivered messages to only one node due to shared queue names.

This fix ensures:

* Unique queue creation per node.
* Proper broadcast message delivery across all cluster nodes.
* Consistent cache synchronization across services.
  {% endupdate %}

{% update date="2026-04-27" tags="feature" %}

## OpenIAM v2026.4.1 — New features

**2026.4.1** adds a scripting hook after access is revoked, and lets reviews be reassigned mid-campaign.

### Post-revoke scripting hook

A **Groovy hook now runs after the revoke-access workflow completes**, so revocation can drive downstream work. The worked case is raising a ServiceNow ticket when privileged access is removed at termination or expiry: each affected privileged role generates its own ticket, routed to the right support group and carrying the original questionnaire data. See [Manage Groovy scripts](/administration-guide/automation/manage-groovy-scripts.md).

### Mid-campaign delegation

Review tasks can be **delegated while a campaign is running**. An administrator or campaign manager reassigns manually, pending items move to the new reviewer and leave the original's queue, and the delegation is audited.

### Session management from the command line

Session tokens can be managed **from the command line** — list active sessions for users and service accounts, see who owns a token and when it expires, and clear one or all of them.

Upgrades now **detect and stop running Windows connector services** before replacing files, removing the file-lock failures that made connector upgrades unreliable. The health-check endpoint used by external framework consumers was also narrowed to expose only the operational data it needs to. See [Session management](/administration-guide/security/session-management.md).
{% endupdate %}

{% update date="2026-04-27" tags="fix" %}

## OpenIAM v2026.4.1 — Bug fixes

### SelfService and UI

OE-3663 – **Log Viewer theme actions displayed as NOT\_SPECIFIED**\
UI theme-related log events incorrectly displayed the action name as `NOT_SPECIFIED`.

OE-3665 – **Webconsole user creation validation error**\
User creation failed when page templates included organization fields or validation rules.

Validation errors are now properly surfaced instead of causing backend save failures.

OE-3807 – **Organization and agency field template properties not applied**\
Required and non-editable properties were not correctly applied to Organization and Agency fields in page templates.

OE-3872 – **Groovy scripts cleared after save**\
In the Groovy Manager, saved script content appeared blank after refreshing the page.

OE-3894 – **Business rule group search field reset**\
The search field was reset after selecting multiple groups in business rule actions.

OE-3947 – **Validation errors not shown in self-service profile updates**\
Field-level validation errors were not shown during a self-service profile update.

OE-3987 – **Logout functionality failure**\
Users could not log out of the Webconsole or SelfService.

### Connectors and synchronization

OE-3767 – **Response consumers not auto-created after upgrade**\
RabbitMQ response consumers for connectors were not automatically initialized after upgrade, causing response queue backlogs.

OE-3875 – **Synchronization history delay after restart**\
Synchronization connectors entered an unbound state after restart, preventing synchronization history events from appearing until manual connector save.

OE-3893 – **Synchronization history details missing**\
Detailed user-level synchronization results were not visible in Synchronization History despite successful job completion.

### Administration

OE-3895 – **Managed system filter missing in role and group selection**\
Role and group selection in business rules had lost its managed system filter, leaving similarly named objects indistinguishable. The filter is back.

OE-3902 – **Metadata type reference usability improvements**\
In Business Rule expressions, a metadata type could only be referenced by its internal ID rather than by a name a person recognises.

### Platform

OE-3900 – **Graph rebuild incorrectly updating LAST\_UPDATE fields**\
`/rebuildGraph` modified `LAST_UPDATE` timestamps for users, groups, roles, resources and organizations, although it only refreshes internal metadata. It now leaves them alone.

OE-3903 – **Rehire related account handling fixes**\
Rehire workflows had three problems:

* Incorrect activation of terminated historical accounts.
* Failure to support multiple related accounts.
* Exceptions during related account assignment.

Historical accounts now retain their original status and multiple related accounts are properly supported.

### Access certification

OE-3937 – **SoD violation page rendering issues**\
On the Segregation of Duties violation page, policy segments, affected roles, entitlements and impacted users did not display correctly.

OE-3965 – **Certification performance degradation with large datasets**\
Campaign review screens paginated and navigated slowly over large user and entitlement datasets.

OE-3967 – **Eligible users missing from certification campaigns**\
Campaign filtering left some eligible users out of certification campaigns.

OE-3977 – **Missing entitlements in manager review**\
Not all assigned entitlements were displayed during manager certification review.
{% endupdate %}

{% update date="2026-04-27" tags="security" %}

## OpenIAM v2026.4.1 — Security

OE-3860 – **Platform vulnerability remediation**\
Reported vulnerabilities remediated:

* Spring Framework denial-of-service exposure.
* JMX authentication configuration gaps.
* Outdated Node.js runtime detection.
* Legacy Log4j vulnerability exposure.

OE-3951 – **PCI security vulnerability fixes**\
PCI findings remediated:

* Session token exposure in URLs.
* Insecure browser storage of session data.
* Unauthenticated access paths.
* Username enumeration risks.
  {% endupdate %}

{% update date="2026-04-14" tags="feature" %}

## OpenIAM v2026.3.3 — New features

**2026.3.3** adds bulk movement of business rules, and stops Active Directory being asked the same question repeatedly.

### Bulk rule export and import

Business rules and their linked objects can be **exported and imported in bulk** — which is what makes an environment holding hundreds or thousands of them workable, since mass loading and migration stop being hand work. Roles and rules are covered. See [Import, export and promotion](/administration-guide/platform/import-export-and-promotion.md).

### RootDSE caching

**RootDSE queries are cached**, so repeated requests stop going back to the domain controller. RootDSE changes rarely, which is what makes caching it safe, and AD-heavy deployments feel it most.

Logging in `ADLoginModule` now separates business events from internal ones and uses its log levels deliberately — trace, debug and operational — so a failed login is easier to follow.

### Custom product code

A **custom product code** can be passed on the installer command line, for connector builds and deployment scenarios that need one.
{% endupdate %}

{% update date="2026-04-14" tags="improvement" %}

## OpenIAM v2026.3.3 — Improvements

### Platform

OE-3824 – **Connector Helm charts ship independently**\
Connector Helm charts are published from the `java-connectors` repository rather than living inside the monolithic Kubernetes project, so a connector chart is versioned and deployed on its own.

OE-3852 – **SelfService v2 deploys from the standard packages**\
The configuration and assets the SelfService v2 single-page application needs are now carried by the standard deployment packages, so it comes up without hand-assembly:

* `rpm-utils`
* `openiam-docker-compose`
* `kubernetes-docker-configuration`

OE-3846 – **Route checks available over REST**\
A REST endpoint validates a route against the same filters and logic that apply to JSP pages, so a caller can check whether a route is permitted without rendering the page.

### Connectors and synchronization

OE-3879 – **Teams connector provisions users**\
The Teams connector now provisions users, including phone number assignment and enterprise voice configuration.

OE-3917 – **PsGraph connector resets MFA**\
The PsGraph connector can now reset a user's MFA as part of a SAVE operation.
{% endupdate %}

{% update date="2026-04-14" tags="fix" %}

## OpenIAM v2026.3.3 — Bug fixes

### Platform

OE-3797 – **Multi-instance installer naming issue**\
Custom product names were ignored when installing multiple instances using MSI transforms.

OE-3938 – **Increased max file size in `nginx` RPM**\
An upload larger than the `nginx` RPM's configured maximum failed on the size limit. The maximum is now higher.

OE-3885 – **RabbitMQ timeout during high-volume operations**\
Role and group assignments timed out on RabbitMQ while a large synchronization job — more than 5,000 users — was running.

OE-3974 – **Audit log export issues**\
Audit log export had TLS configuration problems, transformed the log format unreliably, and did not retry after a failed export. All three are addressed.

See [Audit export](/administration-guide/operations/audit-and-export.md).

### Authentication

OE-3871 – **New user login loop**\
New users were repeatedly redirected to the password entry page during login.

### Connectors and synchronization

OE-3859 – **AD sync failure due to RabbitMQ message size**\
Oversized message payloads failed AD synchronization when processing users with large group memberships.

OE-3882 – **Performance degradation during AD synchronization**\
AD synchronization over roughly 13,000 objects slowed the whole system down while it ran.

### Access certification

OE-3881 – **Certification campaign performance delays**\
Certification campaign execution was slow in large environments:

* Reduced processing time for high-volume datasets (\~91K entitlements / 7K users).
* Improved notification timing and batching behavior.

### SelfService and UI

OE-3897 – **SelfService portal timeout**\
Inefficient workflow history queries timed the SelfService portal out. The queries are optimized and the load from large historical datasets reduced.
{% endupdate %}

{% update date="2026-04-14" tags="security" %}

## OpenIAM v2026.3.3 — Security

OE-3906 – **Consul exposure and weak authentication vulnerability**\
The Consul administration console was reachable without authentication. Authentication is now enforced, the default security configuration hardened, and the password policy enforcement guidance strengthened.
{% endupdate %}

{% update date="2026-04-02" tags="feature" %}

## OpenIAM v2026.3.2 — New features

**2026.3.2** opens up where audit events can go, and makes session and token handling predictable.

### Audit log export

Audit logs can be **exported to external systems** in syslog-compatible format, with filters and a schedule you set, so only the events you care about leave the platform. Connector-based streaming feeds them to something like Splunk in real time, with authentication and session management around it. See [Audit export](/administration-guide/operations/audit-and-export.md).

The logging module also gains **pluggable sinks with rotation** — SQLite for structured persistence, plain text for everything else.

### Concurrent session handling

Concurrent sessions now behave predictably: what happens when a user holds several is defined, superseded and revoked sessions are handled consistently, and the UI responds the same way whenever a session is invalidated. The **OIDC discovery document advertises `revocation_endpoint`**, which token-lifecycle and compliance requirements ask for. See [Session management](/administration-guide/security/session-management.md).

### PsGraph and connection testing

The **PsGraph connector can reset passwords** during save operations, widening what it can provision.

A **standardized CSV synchronization script** covers the joiner, mover and leaver process without customer-side modification for the common cases. See [PsGraph connector](/connector-configuration/microsoft/14-psgraph.md).

### Dependency updates

Core dependencies move to current Spring Boot and Java versions.
{% endupdate %}

{% update date="2026-04-02" tags="fix" %}

## OpenIAM v2026.3.2 — Bug fixes

### Authentication

OE-3821 – **Forgot Password workflow issues**\
The "Forgot Password" process failed to send reset emails and incorrectly handled authentication flow. Also improved handling of unused authentication types.

OE-3891 – **Authorization failure for PTS application**\
Accessing the PTS application returned a 500 error unless authorization was disabled for the /\* URI pattern.

OE-3815 – **Session invalidation inconsistencies**\
An invalidated session or a revoked token still allowed partial access instead of redirecting to login.

### Connectors and synchronization

OE-3890 – **JDBC connector `NullPointerException`**\
A `NullPointerException` in the RabbitMQ listener blocked the JDBC connector and failed provisioning.

OE-3898 – **Enum deserialization failure after Jackson 3.x upgrade**\
Jackson 3.x changed how enums are handled, which broke message deserialization in RabbitMQ. Compatibility with existing message formats is restored.

OE-3865 – **PowerShell connector stuck RabbitMQ connections**\
Stalled RabbitMQ connections prevented connector services from stopping, impacting installer and lifecycle operations.

OE-3909 – **Push notification failure on password reset**\
Push notifications were not triggered during password reset workflows.

### Access certification

OE-3722 – **Certification saved without reviewers validation**\
A certification configuration could be saved with no reviewers defined. Validation now requires them, and the screen says so.

### Platform

OE-3916 – **Missing database indexes causing performance degradation**\
Missing indexes on foreign keys caused excessive table scans, deadlocks and system-wide slowdowns affecting:

* Certification processing
* Workflow execution
* Provisioning and JML jobs
* SelfService access

Indexes are now properly created to prevent locking and improve query performance.

OE-3796 – **Windows installer handles whitespace in service names and paths**\
Whitespace in a Windows service name or installation path caused the WIX installer to fail. Installation now completes with either.

OE-3877 – **Mobile application published to Google Play and the Apple App Store**\
The OpenIAM mobile application is now published through both stores, so it reaches users and receives updates through the normal distribution channels.
{% endupdate %}

{% update date="2026-03-16" tags="feature" %}

## OpenIAM v2026.3.1 — New features

**2026.3.1** lets an SoD violation be accepted against a documented control, rather than only cleared.

### Mitigating controls

Administrators can define **mitigating controls** for an SoD policy — a name, a manager or owner, and effective and expiry dates — and record an accepted risk against a violation instead of having to resolve it. See [SoD triage and evidence](/administration-guide/governance/sod/sod-triage-remediation-and-evidence.md).

### Teams connector

A **Teams connector** arrives, built on PowerShell, syncing numbers, Auto Attendants, Call Queues and named users.

The SCIM connector's **Java 21** incompatibility is fixed — a missing `jakarta.annotation.Priority` dependency had it restarting continuously. See [Teams connector](/connector-configuration/microsoft/16-teams.md).

### Forgot Password email

The Forgot Password email template was rewritten for clarity. See [Password recovery](/administration-guide/security/password-recovery.md).
{% endupdate %}

{% update date="2026-03-16" tags="fix" %}

## OpenIAM v2026.3.1 — Bug fixes

### Access certification

OE-3839 – **Pagination displays excess blank pages for reviewer**\
Pagination offered blank pages past the end of a reviewer's user records. It now reflects the number of records there actually are.

OE-3829 – **Inconsistent pagination and duplicate users in User View**\
The User View paginated inconsistently and listed the same reportee more than once.

OE-3828 – **Duplicate users and entitlements in active certification campaign**\
Certification review showed duplicate user entries and duplicate entitlement records.

OE-3827 – **Incorrect entitlement user count in the certification entitlement view**\
The entitlement view's summary count did not match the actual user-entitlement associations.

OE-3826 – **Entitlement view displays only first page**\
The entitlement view in a User Certification Campaign showed only its first page. Every page is now reachable.

OE-3819 – **Campaign batch save & reviewer-scoped views**\
Campaign batch save carried stale state, cascade deletes went wrong, and reviewer-scoped views paginated incorrectly.

### Authentication

OE-3866 – **SAML SP-Initiated SSO via HTTP Redirect binding fails**\
SP-initiated SAML login failed for an unauthenticated user — the SAML request could not be parsed.

OE-3668 – **Revoke User OAuth Token issue**\
Revoking a user's OAuth token left old tokens uncleared and mishandled the refresh, and "Expires On" carried a typo.
{% endupdate %}

{% update date="2026-03-04" tags="feature" %}

## OpenIAM v2026.2.1 — New features

**2026.2.1** starts checking passwords against known breaches, and lets an administrator's whole view be scoped to their own organization.

### Breached password detection

After a successful login OpenIAM checks the password against **Have I Been Pwned**, asynchronously and using k-anonymity — only a five-character SHA-1 prefix ever leaves the platform. If it appears in a known breach the user is emailed and prompted to change it. See [Compromised passwords](/administration-guide/security/compromised-passwords.md).

### Segregation of Duties

A **Mitigating Controls** tab under *Access Control → Segregation of Duties* lets administrators define compensating controls — name, manager or owner, effective and expiry dates — and attach them to policies, so an accepted risk can be documented where strict enforcement is not feasible.

Managers assigned to a policy now get **email when a violation is detected or resolved**, with separate templates for soft detection, hard detection and resolution.

Reviewers see **SoD violations on the User Details view** and can resolve a conflict or pass it to the next reviewer. In the entitlement view, rows carrying an active violation are highlighted and their approve and revoke buttons stay disabled until it is dealt with.

### Delegated administration scope

Organization administrators can be **scoped to their own organizations** — a virtual tenant — seeing only the users, roles, groups, resources and entitlements that belong to them, in both SelfService and the Webconsole. Super administrators keep full visibility. See [Resources and organizations](/administration-guide/access/resources-and-organizations.md) and [Delegated administration](/administration-guide/identities/delegated-administration.md).

### Password management

The SelfService **Change Password screen was redesigned**, and a generated password can now be delivered by **email or SMS**, with the recipient address selectable.

### Direct reports

The direct reports screen gains an **employee type** column.
{% endupdate %}

{% update date="2026-03-04" tags="improvement" %}

## OpenIAM v2026.2.1 — Improvements

### Platform

OE-3823 – **UI Helm charts separated into standalone chart**\
All UI-related Helm charts have been moved out of the monolithic Kubernetes project and published independently via the `iam-ui` repository.

OE-3822 – **ESB Helm charts separated into standalone chart**\
All ESB Helm charts have been moved out of the monolithic Kubernetes project and published independently via the `iam-services` repository.

OE-3790 – **Automated Helm chart versioning in CI**\
The CircleCI `start_new_sprint` job now automatically updates the version field in all relevant `Chart.yaml` files (`configmap`, `gremlin`, `nginx`, `pvc`, `rabbitmq`, `vault`) at the start of each release cycle.

### Connectors and synchronization

OE-3832 – **SCIM connector runs on Java 21**\
The SCIM connector now starts and stays up on Java 21. A missing `jakarta.annotation` dependency in the Jersey client `classpath` previously raised `NoClassDefFoundError`: `javax/annotation/Priority` and left the connector restarting continuously.
{% endupdate %}

{% update date="2026-03-04" tags="fix" %}

## OpenIAM v2026.2.1 — Bug fixes

### Segregation of Duties

OE-3783 – **SoD role search fix in segments**\
Roles could not be found via the search bar within a SoD segment when that segment already had 20 or more roles. The entitlement selection UI has been redesigned with a per-type modal for managing entitlements.

OE-3781 – **SoD violations not cleared after policy update**\
Users remained listed in the Violations tab even after the related SoD policy was updated (e.g., inactivated, segment removed, or entitlement removed).

OE-3794 – **SoD mitigating control: Manager/Owner type update error**\
Changing the Manager or Owner type on a Mitigating Control — user to group, or group to user — threw an unexpected error. The change now succeeds, and resets the Manager or Owner value with it.

OE-3793 – **SoD mitigating control: Friendly deletion error message**\
When attempting to delete a Mitigating Control that is linked to one or more SoD policies, the system now shows a clear, user-friendly message: "Mitigating control linked to one or more SoD policies" instead of a generic error.

OE-3792 – **SoD mitigating control: Date field issues**\
Dates on Mitigating Controls saved one day off, adding a second date lost the first, and saving any field update cleared both dates. All three are fixed, and the Expiration Date must now be on or after the Effective Date.

### Authentication

OE-3752 – **"Set Header" metadata: Incorrect propagate flags on save**\
Newly added "Set Header" metadata properties on a content provider URI would always save with both "Propagate Through Proxy" and "Propagate on Error" flags enabled, regardless of the user's selections.

OE-3730 – **Human-readable resource names in OAuth scopes**\
OAuth client scopes and Groovy script references displayed raw internal resource IDs instead of names a person recognises, from 4.2.2 onward. A scope now displays as `coorelatedName`(name).

### Administration

OE-3748 – **Supervisor principal missing in user profile**\
The Principal column was blank for supervisors listed under **User Profile** → **Supervisors & Subordinates**.

OE-1305 – **Email checkbox state retained on user create**\
Email flag checkboxes — active, published, default — were not retained when creating a new user, a long-standing bug. Where a user has only one email address the backend now sets all three.

OE-3619 – **Phone number field bug on user forms**\
The out-of-the-box Phone Number field prevented the form saving and appended the area code to the phone number. The area code is now taken from the selected country or region.

### SelfService and UI

OE-3733 – **Cart validation Groovy script: Missing `requesterId`**\
`currentlySelectedData.getRequesterId()` returned `null` in the CartValidation Groovy script on the first "Add to Cart" of a session.

OE-3696 – **UI theme broken on RPM environment**\
A Thymeleaf template parsing error stopped the IDP page rendering when a custom UI theme was applied on an RPM installation.

OE-3813 – **UAR dashboard pagination improvement**\
Pagination on the UAR Dashboard grid view was hard to read: pages other than the last were not filled, so partially filled rows looked like the end of the results. A page is now filled before a new one starts.

### Platform

OE-3731 – **MSSQL: Missing `LANGUAGE_MAPPING` for `CONNECTORTEMPLATE`**\
The "**Connector configuration**" menu item did not display in some UI languages — the `LANGUAGE_MAPPING` database entries for the `CONNECTORTEMPLATE` resource were missing. They are now present for all active languages.
{% endupdate %}

{% update date="2026-02-04" tags="feature" %}

## OpenIAM v2026.1.1 — New features

**2026.1.1** adds a native SoD violations report, and makes connector deployment less repetitive.

### SoD violations report

A **built-in violations report** lets administrators review and analyse SoD violations without building custom reporting. Policy configuration and reporting were both extended, giving more visibility into what enforcement is actually doing.

### Profile switching

A **profile switcher** moves between user profiles quickly, which matters most to administrators and support staff working across accounts.

### Compromised password alerts

**A compromised password now raises an urgent notification** when it is detected. See [Compromised passwords](/administration-guide/security/compromised-passwords.md).

### Connector deployment

.NET v6 connectors get a **multi-instance Windows installer**, so several instances deploy from one installer, and **PowerShell connectors can be shared between production and non-production**, removing a duplicate set to maintain.

### Build and packaging

Groovy scripts can be **compiled in bulk with the failures reported together**, which turns a hunt into a list. Artifacts publish to Azure Artifacts through a dedicated pipeline, and container registry references standardise on `registry.openiam.com`.
{% endupdate %}

{% update date="2026-02-04" tags="improvement" %}

## OpenIAM v2026.1.1 — Improvements

* Improved the accuracy and visibility of **Certification campaign statistics**.
* Improved **URI federation performance**.
* Applied security hardening to **Apache `mod_ssl`**.
  {% endupdate %}

{% update date="2026-02-04" tags="fix" %}

## OpenIAM v2026.1.1 — Bug fixes

* Fixed an issue where **SoD violation records** were incorrectly created multiple times for the same user.
* Resolved a problem with **UI themes not working in RPM-based environments**.
* Fixed **cart validation issues** when adding items.
* Corrected an issue where the **out-of-the-box "Email Address" field** did not persist changes after saving.
* Fixed **access control resource filtering** where the entered value was not applied correctly.
* Resolved an issue where **IDP resources could not be discovered via search**.
* Fixed an issue in **Access Certification** where the Manager dropdown retained the previous search value until a page refresh.
  {% endupdate %}
  {% endupdates %}

{% hint style="info" %}
That is the 2026 line in full, back to 2026.1.1. Releases before it — the 4.2.x line, back to 4.2.1.10 — are on [**Earlier releases**](/whats-new-in-openiam/earlier-releases.md).
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs-beta.openiam.com/whats-new-in-openiam/readme.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
