AIMS 25.1
Release Highlights
Avatier Identity Anywhere 25.1 Release Highlights
Configuration
- Connectors page now saves user preferences (sorting, ordering, page) for smoother navigation.
- Clearer image upload guidelines added to UUI branding configuration.
- Improved handling of unselected images for a more intuitive experience.
- User collection process optimized for better performance and domain-based efficiency.
- Partial user collection feature added to track added, modified, and deleted users.
- Increased WebServerSignalThread priority for stability under high load.
- Reduced MapIdCollection processing time for faster performance.
- Updated MapId Collection core functionality to minimize overhead, especially for Oracle Connectors.
HR Feed
- Resolved an issue preventing HR Feed connections to Oracle after upgrading to the latest premium version of the Oracle License.
- Addressed an issue where accounts were not automatically provisioned into the AS400 system from HR Feed during Account Creator operations.
Reporting-Auditng
- Resolved an issue where date filters were not functioning correctly in both new and old Enrollment Trend reports. The filtering mechanism has been improved to ensure reliable and accurate report generation based on the selected date range.
- Enhanced Help-Desk reports on the Universal User Interface (UUI) to improve reliability and ensure accurate data representation for a smoother reporting experience.
- Addressed an issue where the Time Zone field in the Audit Log incorrectly added
&
when navigating between pages. The Time Zone field now displays correctly across all pages without encoding errors. - Improved Audit Log creation to ensure that after specific actions (e.g., Account Unlock, Password Reset, and Password Change), the target connector and mapped ID are properly stored.
Mobile App UUI
- Multi-Factor Authentication (MFA) List Upgrade: Now displays the provider name as configured in AIMS for OpenID Connect.
- Improved Connector Icons: Fixed broken images, enhancing performance for multiple connectors of the same type.
- New ‘Rename User’ Feature: Added to the Universal Interface for better user management.
- Hybrid Login Approach: Combines password entry with MFA for enhanced security.
- ‘Proxy My Authority’ Functionality: Added to UUI for flexible authority delegation.
Fixed issues
- Unlock Account & Forgot Password: Fixed issues preventing non-authenticated users from completing these processes.
- Change Password Feedback: Resolved issue where clicking ‘Change Password’ provided no user feedback.
- Performance Optimization: Improved connector fetching in Forgot Password and Unlock Account workflows for non-authenticated users.
Access Governance (AG3)
- Real-Time Connector & Group Status Check: Auditors and reviewers now receive real-time updates on user status within entitlements, ensuring accurate and informed decision-making.
- Push Notifications for Campaigns: Added push notifications to alert auditors about campaign details, including name, dates, and items to review, improving visibility and responsiveness.
- Automated Assignment Cleanup: Introduced a daily check to automatically remove assignments for deleted users, streamlining campaign reviews and reducing manual effort.
Credential Provider
- The Passwordless Avatier Credential Provider for Windows now supports OTP entry during passwordless authentication.
- Added support for multiple user identifiers (beyond DOMAIN\USERID) for greater flexibility and compatibility.
- Upgraded the MSI installer with passwordless authentication, using the latest software for better performance.
- Increased the challenge key length to maximum for enhanced security between the Credential Provider and AIMS server.
- Ensured backward compatibility with older key lengths for smooth deployment and testing.
Self-Service Password Management
- IP-Based MFA Workflows: Admins can now restrict MFA workflows to specific IP addresses or ranges. The workflow only applies if the user’s IP matches the defined range(s).
- PingID OTP Support: Added PingID OTP as a new MFA method, complementing existing PingID push, email, and SMS options. Users can enroll via Password Management.
- OpenID Connect MFA: Users can now log into the Avatier Identity Anywhere Universal Interface (UUI) without entering a User ID/Email. A special URL redirects them to the OpenID Connect IDP for seamless authentication.
- Flexible PingID Integration: Users can now authenticate using either their User ID or email for PingID MFA, improving account linking flexibility.
- Improved login functionality for Password Management via non-OpenLDAP LDAP connectors.
- Enhanced MapId mapping for Oracle connectors during user management operations.
Password Bouncer
- Performance Boost: Improved efficiency in retrieving and validating password policies, delivering a smoother user experience.
- LDAP Integration: Enhanced support for multiple custom password policies, offering greater flexibility for LDAP environments.
- NIST Compliance: Added a “Bad Passwords” check based on NIST guidelines to strengthen password security.
Passwordless Login
- Universal Integration: Passwordless login is now available across all modules, ensuring a consistent and streamlined experience for users.
- Top MFA Solutions: Leverage industry-leading MFA providers for secure, passwordless access, including options like PingID, OpenID Connect, and more.
- Enhanced Security: Reduce the risk of password-related breaches by replacing traditional passwords with advanced, phishing-resistant authentication methods.
- Improved User Experience: Simplify the login process, reducing friction and saving time for end-users while maintaining robust security.
Help Desk
- New Bypass Option: Added a checkbox to allow Help Desk super users to bypass authentication, ensuring the bypass functionality works seamlessly.
More MFA Options
- Avatier now supports leading MFA providers like CyberArk, DUO, FIDO2, Google Authenticator, Microsoft Authenticator, PingID, RSA SecurID, WhatsApp Magic Link, WeChat QR Code, and more. All MFA providers are free for new Avatier Cloud Hosted customers, offering unmatched flexibility and security at no extra cost.
Lifecycle Management
- Lifecycle Management Cache Optimization: Enhanced performance by reducing unnecessary agent calls during cache reloads for users owning non-existent privileges.
- License Counter: Added a license counter in the LCM licensing section, excluding non-manageable users for more accurate license usage tracking.
- Import Role Tool Upgrade: Enhanced the Avatier Import Role Tool with validation and error handling to ensure GUID accuracy during role imports.
- LCM License Status Page: Improved the License Status page to provide detailed insights into license utilization, including disabled and expired accounts.