<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
    <channel>
        <title>PingOne Release Notes | PingOne</title>
        <link>https://docs.pingidentity.com/pingone/release_notes/index.html</link>
        <description>PingOne Release Notes</description>
        <lastBuildDate>Thu, 16 Apr 2026 18:11:50 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <ttl>5</ttl>
        <copyright>Copyright 2026 Ping Identity. All rights reserved.</copyright>
        <item>
            <title><![CDATA[April 14]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#april-14</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#april-14</guid>
            <pubDate>Tue, 14 Apr 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="updated-ldap-gateway-client-application"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#updated-ldap-gateway-client-application"></a>Updated LDAP gateway client application</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We’ve released LDAP gateway client application version 4.1.1. This version updates the Docker base image and software dependencies to improve security.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[April 13]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#april-13</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#april-13</guid>
            <pubDate>Mon, 13 Apr 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="increased-limit-for-custom-language-key-value-pairs-in-davinci"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#increased-limit-for-custom-language-key-value-pairs-in-davinci"></a>Increased limit for custom language key-value pairs in DaVinci</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We’ve increased the limit for the number of custom language key-value pairs that can be added for PingOne DaVinci custom messages from 500 to 2000. Learn more in <a href="https://docs.pingidentity.com/pingone/user_experience/p1_adding_custom_key_davinci.html" class="xref page">Adding a custom key for DaVinci</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[April 9]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#april-9</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#april-9</guid>
            <pubDate>Thu, 09 Apr 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="pingone-notifications-syniverse-channels"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#pingone-notifications-syniverse-channels"></a>PingOne notifications - Syniverse channels</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>If you have defined channels in your Syniverse account, you can now create a <a href="https://docs.pingidentity.com/pingone/settings/p1_sender_syniverse_channels.html" class="xref page">PingOne notification sender that uses channels</a> rather than individual phone numbers.</p>
</div>
</div>
<div class="sect3">
<h4 id="otp-and-push-notification-status-for-user-devices"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#otp-and-push-notification-status-for-user-devices"></a>OTP and Push notification status for user devices</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>The information displayed for a user’s authentication devices now includes the current device status for OTP authentication and the current device status for receiving push notifications. If either of these are currently disabled, the reason is displayed as well. This applies also to use of the PingID app as an authentication method.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[April 7]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#april-7</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#april-7</guid>
            <pubDate>Tue, 07 Apr 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="application-metadata-properties"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#application-metadata-properties"></a>Application metadata properties</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>You can now add custom metadata properties to applications in PingOne for administrative purposes, such as contact information. You can only add metadata properties to applications created by your organization and not the built-in system applications. Learn more in <a href="https://docs.pingidentity.com/pingone/applications/p1_editing_applications.html" class="xref page">Editing an application</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[April 2]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#april-2</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#april-2</guid>
            <pubDate>Thu, 02 Apr 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="updated-ui-for-certificates-and-key-pairs"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#updated-ui-for-certificates-and-key-pairs"></a>Updated UI for Certificates and Key Pairs</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We’ve updated the <strong class="uicontrol">Certificates and Key Pairs</strong> UI with a new look and feel for a more streamlined experience. Learn more in <a href="https://docs.pingidentity.com/pingone/settings/p1_certs_and_keypairs.html" class="xref page">Certificates and key pairs</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[April 1]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#april-1</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#april-1</guid>
            <pubDate>Wed, 01 Apr 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="verification-code-notification-template-updates"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#verification-code-notification-template-updates"></a><strong class="uicontrol">Verification Code</strong> notification template updates</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span>
<span class="ping_product">PingOne DaVinci</span></p>
</div>
<div class="paragraph">
<p>We’ve released a new notification template for verification codes sent by email to users to verify their accounts. You can now also customize the verification code notification template to use in a DaVinci flow with the PingOne Connector. Learn more in <a href="https://docs.pingidentity.com/pingone/user_experience/p1_notifications.html" class="xref page">Notification Templates</a> and in the <a href="https://docs.pingidentity.com/connectors/p1_connector.html" target="_blank" rel="noopener">PingOne Connector</a> documentation.</p>
</div>
</div>
<div class="sect3">
<h4 id="account-created-notification-template"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#account-created-notification-template"></a><strong class="uicontrol">Account Created</strong> notification template</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span>
<span class="ping_product">PingOne DaVinci</span></p>
</div>
<div class="paragraph">
<p>We’ve released a new notification template for account creation. You can now use this template to send a notification to the user when an account is created using the PingOne Connector in DaVinci. Learn more in <a href="https://docs.pingidentity.com/pingone/user_experience/p1_notifications.html" class="xref page">Notification Templates</a> and in the <a href="https://docs.pingidentity.com/connectors/p1_connector.html" target="_blank" rel="noopener">PingOne Connector</a> documentation.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[March 31]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#march-31</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#march-31</guid>
            <pubDate>Tue, 31 Mar 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="introducing-ai-agents-in-pingone"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#introducing-ai-agents-in-pingone"></a>Introducing AI Agents in PingOne</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>AI Agents are now available in PingOne as part of our <a href="https://developer.pingidentity.com/identity-for-ai/" target="_blank" rel="noopener">Identity for AI solution</a>. Use AI Agents to:</p>
</div>
<div class="ulist">
<ul>
<li>
<p>Treat agents as first-class identities with unique credentials and clear ownership.</p>
</li>
<li>
<p>Onboard and manage AI systems the same way you manage users and applications today with centralized policies and strong authentication.</p>
</li>
<li>
<p>Apply least‑privilege access using fine-grained entitlements and tight access controls.</p>
</li>
<li>
<p>Increase visibility and auditability of agent activity alongside your human users.</p>
</li>
</ul>
</div>
<div class="paragraph">
<p>This helps you safely bring agentic and autonomous AI into production without relying on shared credentials or opaque access paths. Agent Identity is made available as part of our new Identity for AI solution. Contact your account executive to find out more.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/ai_agents/p1_ai_agents.html" class="xref page">AI Agents</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="pingone-protect-ai-agent-detection"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#pingone-protect-ai-agent-detection"></a>PingOne Protect AI agent detection</h4>
<div class="paragraph">
<p><span class="ping_changetype-info">Info</span>
<span class="ping_product">PingOne Protect</span></p>
</div>
<div class="paragraph">
<p>Using the bot detection predictor, PingOne Protect can detect agentic artificial intelligence (AI) automation acting on behalf of a user or system. It can also identify a subset of specific agent types in the risk evaluation response.</p>
</div>
<div class="paragraph">
<p>Agent Detection is made available as part of our PingOne Protect solution. Contact your account executive to find out more.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/threat_protection_using_pingone_protect/p1_protect_risk_predictors.html#bot-detection" class="xref page">Bot detection predictor</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[March 30]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#march-30</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#march-30</guid>
            <pubDate>Mon, 30 Mar 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="updates-to-api-usage-dashboard"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#updates-to-api-usage-dashboard"></a>Updates to API Usage Dashboard</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We’ve made the following improvements to the <strong class="uicontrol">API Usage Dashboard</strong>:</p>
</div>
<div class="ulist">
<ul>
<li>
<p><strong class="uicontrol">Historic Peak HTTP Request Rates</strong> table: Added a new <strong class="uicontrol">Base Limit</strong> column so that you can see what the default entitlements are for each rate group.</p>
</li>
<li>
<p><strong class="uicontrol">Daily Peak HTTP Request Rates</strong> table: When you hover over a date on the chart, the detailed view now includes information about the total number of requests per day and the percentage of requests that were throttled because they exceeded your daily entitlement.</p>
</li>
</ul>
</div>
<div class="paragraph">
<p>Additionally, adjustments have been made to correct inaccurate peak API usage data calculations recorded since January 2026.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/settings/p1_api_usage_dashboard.html" class="xref page">API Usage Dashboard</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[March 29]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#march-29</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#march-29</guid>
            <pubDate>Sun, 29 Mar 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="erasing-risk-related-data-for-user"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#erasing-risk-related-data-for-user"></a>Erasing risk-related data for user</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne Protect</span></p>
</div>
<div class="paragraph">
<p>Using the PingOne API, you can now erase all of the risk-related data that has been collected for a specific user. You can find details in the <a href="https://developer.pingidentity.com/pingone-api/protect/risk-data.html" target="_blank" rel="noopener">Risk Data section</a> of the PingOne API documentation.</p>
</div>
</div>
<div class="sect3">
<h4 id="mfa-dashboard"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#mfa-dashboard"></a>MFA dashboard</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>We’ve enhanced the MFA dashboard with improved chart rendering and interactivity. It now includes new data visualizations and expanded filtering options for MFA usage analysis.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[March 26]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#march-26</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#march-26</guid>
            <pubDate>Thu, 26 Mar 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="authentication-dashboard-early-access-updates"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#authentication-dashboard-early-access-updates"></a>Authentication Dashboard early access updates</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span>
<span class="ping_product">PingOne SSO</span>
<span class="ping_product">DaVinci</span></p>
</div>
<div class="paragraph">
<p>We’ve enhanced the PingOne Authentication Dashboard (early access) to include PingOne DaVinci-triggered authentication activity, providing a single, consistent view of sign-on activity from PingOne and DaVinci flows. Learn more in <a href="https://docs.pingidentity.com/pingone/early-access-features/ea-p1_auth_dashboard.html" class="xref page">New Authentication Dashboard (early access)</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[March 17]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#march-17</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#march-17</guid>
            <pubDate>Tue, 17 Mar 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="webhooks-protocol-selection"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#webhooks-protocol-selection"></a>Webhooks protocol selection</h4>
<div class="paragraph">
<p><span class="ping_product">PingOne</span>
<span class="ping_changetype-improved">Improved</span>
<span class="ping_changetype-beta">Beta</span></p>
</div>
<div class="paragraph">
<p>We’ve made an improvement to the webhooks UI. You can now choose between HTTPS or TCP/IP to determine how webhook events are delivered to your destination. HTTP sends events using HTTP POST requests and TCP/IP sends events over a TCP connection.</p>
</div>
<div class="paragraph">
<p>The protocol selection feature providing TCP/IP as an option for users is currently released only for beta testing.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[March 16]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#march-16</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#march-16</guid>
            <pubDate>Mon, 16 Mar 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="composite-predictors-number-of-items"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#composite-predictors-number-of-items"></a>Composite predictors - number of items</h4>
<div class="paragraph">
<p><span class="ping_changetype-info">Info</span>
<span class="ping_product">PingOne Protect</span></p>
</div>
<div class="paragraph">
<p>Composite predictors can now contain a maximum of 20 individual items. When the limit is reached, the buttons for adding an item or a group are grayed out.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[March 15]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#march-15</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#march-15</guid>
            <pubDate>Sun, 15 Mar 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="context-based-risk-policies-for-customer-pingone-mfa-mfa-use-cases"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#context-based-risk-policies-for-customer-pingone-mfa-mfa-use-cases"></a>Context-based risk policies for customer (PingOne MFA) MFA use cases</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>Administrators with a customer (PingOne MFA) environment can now configure policy-based multi-factor authentication (MFA) from PingOne by creating targeted risk policies for specific authentication flow types. This allows contextual and risk-based evaluation directly within MFA flows, even without a PingOne Protect license.
For example, administrators can specify different FIDO2 policies to use based on user group, application, and scenario (such as sign-on from a new device) by applying a different MFA policy in MFA mitigations.</p>
</div>
<div class="paragraph">
<p>With a customer (PingOne MFA) environment, you can leverage a subset of the risk predictors available with a full PingOne Protect license.</p>
</div>
<div class="paragraph">
<p>To access the complete set of risk predictors, a full PingOne Protect license is required.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/threat_protection_using_pingone_protect/p1_protect_risk_policies_mfa_only.html" class="xref page">Risk policies for MFA-only licenses</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[March 12]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#march-12</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#march-12</guid>
            <pubDate>Thu, 12 Mar 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="configurable-attribute-to-locate-users-based-on-username-tokens"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#configurable-attribute-to-locate-users-based-on-username-tokens"></a>Configurable attribute to locate users based on username tokens</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>When PingOne is the federated identity provider (IdP) for Microsoft Entra ID, you can now select the attribute PingOne uses to match user records to the username in the username token from request security token (RST) messages. PingOne automatically matches the Entra ID username (<code class="codeph">userPrincipalName</code> attribute from Active Directory by default) to the email address (<code class="codeph">mail</code> attribute) in PingOne.</p>
</div>
<div class="paragraph">
<p>This new setting allows you to configure the Microsoft 365 application in PingOne to match an alternative or custom attribute to the username token. This ensures PingOne can locate user records when obtaining and renewing primary refresh tokens (PRTs) from Entra ID. Learn more in <a href="https://docs.pingidentity.com/pingone/applications/p1_selecting_username_token_attribute.html" class="xref page">Selecting the attribute to identify users from username tokens</a> and <a href="https://docs.pingidentity.com/pingone/use_cases/p1_microsoft_hybrid_join_tasks.html#p1-update-microsoft-app-user-auth" class="xref page">Configuring PingOne as the federated IdP</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="audit-messages-for-ldap-gateway-user-migration-failures"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#audit-messages-for-ldap-gateway-user-migration-failures"></a>Audit messages for LDAP gateway user migration failures</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We’ve enhanced audit logging to include user migration failures. Learn more in <a href="https://docs.pingidentity.com/pingone/integrations/p1_troubleshooting_ldap_authentication.html" class="xref page">Troubleshooting LDAP authentication</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[March 10]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#march-10</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#march-10</guid>
            <pubDate>Tue, 10 Mar 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="support-for-ciba"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#support-for-ciba"></a>Support for CIBA</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>PingOne now supports client-initiated backchannel authentication (CIBA) with the new <a href="https://docs.pingidentity.com/pingone/applications/p1_grant_types.html" class="xref page">CIBA grant type</a>. CIBA enables an out-of-band authentication flow initiated by an end user from a consumption device, such as a point-of-sale system, and completed on the user’s authentication device. You can download a sample PingOne DaVinci CIBA flow to send email notifications to your end users, allowing them to seamlessly grant or deny authentication requests on their mobile device. Learn more in <a href="https://docs.pingidentity.com/pingone/use_cases/p1_configure_ciba_flow.html" class="xref page">Configuring a CIBA flow</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="oauth-2-0-token-exchange"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#oauth-2-0-token-exchange"></a>OAuth 2.0 token exchange</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>PingOne now supports OAuth 2.0 token exchange grant type (RFC 8693), allowing an application to exchange an existing security token it already has for an access token to access downstream resources.</p>
</div>
<div class="paragraph">
<p>OAuth 2.0 token exchange enhances security by allowing you to:</p>
</div>
<div class="ulist">
<ul>
<li>
<p>Refine token scope: Restrict the scope or audience of a token before passing it to a backend service.</p>
</li>
<li>
<p>Enable delegation: Allow applications to act on behalf of a user while maintaining visibility into which application is performing the action.</p>
</li>
<li>
<p>Improve user experience: Provide seamless access without requiring the user to re-authenticate when accessing multiple resources.</p>
</li>
</ul>
</div>
<div class="paragraph">
<p>To get started, enable the <a href="https://docs.pingidentity.com/pingone/applications/p1_grant_types.html" class="xref page">token exchange grant type</a> in your application configuration. Learn more about the supported use cases in <a href="https://docs.pingidentity.com/pingone/use_cases/p1_oauth_2_token_exchange.html" class="xref page">Configuring OAuth 2.0 token exchange</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="option-to-set-custom-resource-attributes-as-required"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#option-to-set-custom-resource-attributes-as-required"></a>Option to set custom resource attributes as required</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>You can now set attributes mapped in PingOne custom resources as required. If it can’t find a value for an attribute marked as required, PingOne doesn’t issue an access token for the resource and instead issues an error message in the token response. Learn more in <a href="https://docs.pingidentity.com/pingone/applications/p1_adding_custom_resource.html" class="xref page">Adding a custom resource</a> and <a href="https://docs.pingidentity.com/pingone/applications/p1_editresource.html" class="xref page">Editing a resource</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="notification-policies-default-deny-list"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#notification-policies-default-deny-list"></a>Notification policies - default deny list</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>When <a href="https://docs.pingidentity.com/pingone/user_experience/p1_creating_a_notification_policy.html" class="xref page">creating a PingOne notification policy</a>, the <strong class="uicontrol">Target Locations</strong> option is now selected by default, and the deny list contains a predefined set of countries. If you want to allow the relevant notification methods in some of these countries, manually remove them from the deny list.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[March 8]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#march-8</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#march-8</guid>
            <pubDate>Sun, 08 Mar 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="pingone-mfa-mobile-sdk-2-2-1"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#pingone-mfa-mobile-sdk-2-2-1"></a>PingOne MFA mobile SDK 2.2.1</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>We’ve released version 2.2.1 of the PingOne MFA mobile SDK. This version contains a number of bug fixes.</p>
</div>
<div class="paragraph">
<p>Learn more in the documentation for the <a href="https://github.com/pingidentity/pingone-mobile-sdk-android/blob/master/release-notes.md">Android version</a> and the documentation for the <a href="https://github.com/pingidentity/pingone-mobile-sdk-ios/blob/master/release-notes.md">iOS version</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[March 5]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#march-5</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#march-5</guid>
            <pubDate>Fri, 06 Mar 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="provisioning-dashboard"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#provisioning-dashboard"></a>Provisioning Dashboard</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>You can now use the <strong class="uicontrol">Circuit Breaker Events</strong> chart to view polling and sync failure for a specific rule and take the necessary action to resolve any failure. Learn more in <a href="https://docs.pingidentity.com/pingone/integrations/p1_provisioning_dashboard.html" class="xref page">Provisioning Dashboard</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[February 27]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#february-27</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#february-27</guid>
            <pubDate>Fri, 27 Feb 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="updated-ldap-gateway-client-application-2"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#updated-ldap-gateway-client-application-2"></a>Updated LDAP gateway client application</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We’ve released LDAP gateway client application version 4.1.0. This version includes improved provisioning support for Radiant Logic and OpenLDAP directories.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[February 25]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#february-25</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#february-25</guid>
            <pubDate>Wed, 25 Feb 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="anonymous-network-detection-fewer-false-positives"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#anonymous-network-detection-fewer-false-positives"></a>Anonymous network detection - fewer false positives</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">improved</span>
<span class="ping_product">PingOne Protect</span></p>
</div>
<div class="paragraph">
<p>Enhancements have been made to the anonymous network detection predictor to reduce the likelihood of a legitimate IP being identified as an anonymous network risk.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[February 24]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#february-24</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#february-24</guid>
            <pubDate>Tue, 24 Feb 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="new-pingid-desktop-app-1-0-for-a-consistent-passwordless-experience"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#new-pingid-desktop-app-1-0-for-a-consistent-passwordless-experience"></a>New PingID desktop app 1.0 for a consistent passwordless experience</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingID</span></p>
</div>
<div class="paragraph">
<p>PingID desktop app 1.0 provides users with a consistent passwordless authentication experience across different browsers from a Mac or Windows machine using the machine’s device biometrics.</p>
</div>
<div class="paragraph">
<p>This solution replaces the existing PingID desktop app, which has been renamed PingID desktop app (legacy).</p>
</div>
<div class="admonitionblock note">
<table>
<tbody><tr>
<td class="icon">
<i class="fa icon-note" title="Note"></i>
</td>
<td class="content">
<div class="paragraph">
<p>The <a href="https://docs.pingidentity.com/pingone/strong_authentication_mfa/p1_pid_desktop_app_v1.html" class="xref page">legacy</a> version will remain available while customers transition their users to the new version and until feature parity is reached.</p>
</div>
</td>
</tr>
</tbody></table>
</div>
<div class="ulist">
<ul>
<li>
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/strong_authentication_mfa/p1_pid_desktop_app_start.html" class="xref page">(Workforce only) Configuring the PingID desktop application</a>.</p>
</li>
<li>
<p>Learn more about the differences between the versions in <a href="https://docs.pingidentity.com/pingone/strong_authentication_mfa/p1_pid_desktop_app_version_overview.html" class="xref page">PingID desktop app (workforce only)</a>.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="context-based-risk-policies-for-workforce-pingid-mfa"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#context-based-risk-policies-for-workforce-pingid-mfa"></a>Context-based risk policies for workforce (PingID) MFA</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingID</span></p>
</div>
<div class="paragraph">
<p>Administrators with a workforce (PingID) environment can now configure policy-based multi-factor authentication (MFA) from PingOne by creating targeted risk policies for specific authentication flow types. This allows contextual and risk-based evaluation directly within MFA flows, with significantly greater granularity than was possible in the legacy PingID admin console.</p>
</div>
<div class="paragraph">
<p>For example, administrators can specify different FIDO2 policies to use based on user group, application, and scenario (such as login from an anonymous network) by applying a different MFA policy in MFA mitigations.</p>
</div>
<div class="paragraph">
<p>With workforce (PingID) environments, you can leverage a subset of the risk predictors available with a full PingOne Protect license.</p>
</div>
<div class="paragraph">
<p>To access the complete set of risk predictors, a full PingOne Protect license is required.</p>
</div>
<div class="paragraph">
<p>These new context-based risk policies can replace the legacy MFA authentication policies defined in the PingID admin console when using the PingID <a href="https://marketplace.pingone.com/item/pingid-authentication-subflow">out-of-the-box DaVinci subflows</a>.</p>
</div>
<div class="ulist">
<ul>
<li>
<p>Learn more about PingOne Protect policies in <a href="https://docs.pingidentity.com/pingone/threat_protection_using_pingone_protect/p1_protect_risk_policies.html" class="xref page">Risk policies</a>.</p>
</li>
<li>
<p>Learn more about the risk predictors available with an MFA-only license in <a href="https://docs.pingidentity.com/pingone/threat_protection_using_pingone_protect/p1_protect_risk_policies_mfa_only.html" class="xref page">Risk policies for MFA-only licenses</a>.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="support-for-multiple-mfa-policies"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#support-for-multiple-mfa-policies"></a>Support for multiple MFA policies</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">improved</span>
<span class="ping_product">PingID</span></p>
</div>
<div class="paragraph">
<p>PingOne now supports the use of multiple MFA policies in workforce (PingID) environments.</p>
</div>
</div>
<div class="sect3">
<h4 id="disable-the-pingid-mobile-app-as-an-allowed-method"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#disable-the-pingid-mobile-app-as-an-allowed-method"></a>Disable the PingID mobile app as an allowed method</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">improved</span>
<span class="ping_product">PingID</span></p>
</div>
<div class="paragraph">
<p>You can now remove the PingID mobile app method from the list of allowed authentication methods in a workforce (PingID) environment by clearing the checkbox in the relevant MFA policy.</p>
</div>
</div>
<div class="sect3">
<h4 id="configurable-grace-period-for-totp-passcodes"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#configurable-grace-period-for-totp-passcodes"></a>Configurable grace period for TOTP passcodes</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>The grace period for authenticator app (TOTP) passcodes is now configurable. As part of this change, the default grace period has been shortened. Learn more in <a href="https://docs.pingidentity.com/pingone/strong_authentication_mfa/p1_creating_an_mfa_policy_for_strong_auth.html" class="xref page">Configuring an MFA policy for strong authentication</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[February 19]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#february-19</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#february-19</guid>
            <pubDate>Thu, 19 Feb 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="phase-2-custom-domain-infrastructure-changes"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#phase-2-custom-domain-infrastructure-changes"></a>Phase 2: Custom domain infrastructure changes</h4>
<div class="paragraph">
<p><span class="ping_changetype-info">Info</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>As part of our continued efforts to support best practice security measures and advanced integrations in PingOne, we’ve begun the transition to using Cloudflare instead of Amazon CloudFront as our custom domain ingress infrastructure. This change is being deployed in a phased approach and affects you only if you use custom domains.</p>
</div>
<div class="paragraph">
<p>Phase 1 started March 17, 2025 with all new custom domains from that date on configured to use Cloudflare.</p>
</div>
<div class="paragraph">
<p>Now, in phase 2, you can migrate PingOne custom domains created before March 17, 2025 to Cloudflare. Learn more in <a href="https://docs.pingidentity.com/pingone/settings/p1_migrate_custom_domain_to_cloudflare.html" class="xref page">Migrating a custom domain to Cloudflare</a>.</p>
</div>
<div class="sect4">
<h5 id="new-inbound-traffic-policies-ui-for-cloudflare-custom-domains"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#new-inbound-traffic-policies-ui-for-cloudflare-custom-domains"></a>New Inbound Traffic Policies UI for Cloudflare custom domains</h5>
<div class="paragraph">
<p>Building on the migration to Cloudflare, we’ve also added a new <strong class="uicontrol">Inbound Traffic Policies</strong> UI under the <strong class="uicontrol">Settings</strong> menu in the PingOne admin console. If you have a custom domain that is currently routing to Cloudflare, you can use the <strong class="uicontrol">Inbound Traffic Policies</strong> page to configure custom request headers and accurate IP addresses when requests are proxied to the domain. Learn more in <a href="https://docs.pingidentity.com/pingone/settings/p1_inbound_traffic_policies.html" class="xref page">Inbound traffic policies</a>.</p>
</div>
<div class="admonitionblock note">
<table>
<tbody><tr>
<td class="icon">
<i class="fa icon-note" title="Note"></i>
</td>
<td class="content">
<div class="paragraph">
<p>If your custom domain was created before March 17, 2025 and hasn’t been migrated, you’ll need to migrate the domain before configuring and using inbound traffic policies.</p>
</div>
</td>
</tr>
</tbody></table>
</div>
<div class="paragraph">
<p>In the coming months, we’ll be releasing additional custom domain features that will be available only if your domain is configured for Cloudflare. Approximately a year from now, any custom domains that haven’t been migrated will be migrated automatically.</p>
</div>
</div>
</div>
<div class="sect3">
<h4 id="pingone-forms-now-support-an-extension-in-the-phone-number-field"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#pingone-forms-now-support-an-extension-in-the-phone-number-field"></a>PingOne Forms now support an extension in the phone number field</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span>
<span class="ping_product">DaVinci</span></p>
</div>
<div class="paragraph">
<p>We’ve added an <strong class="uicontrol">Extension</strong> field to the <strong class="uicontrol">Phone Number Input</strong> component in the drag-and-drop form builder. Learn more about customizable form fields in <a href="https://docs.pingidentity.com/pingone/user_experience/p1_form_configuration.html#custom-fields" class="xref page">Form configuration</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[February 18]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#february-18</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#february-18</guid>
            <pubDate>Wed, 18 Feb 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="gateway-version-deprecating-email-alert"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#gateway-version-deprecating-email-alert"></a>Gateway version deprecating email alert</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We’ve made improvements and added more expiry, recovery, and troubleshooting information to the <strong class="uicontrol">Gateway Version Deprecating</strong> email alert. Learn more in <a href="https://docs.pingidentity.com/pingone/integrations/p1_gateways.html#monitoring-gateways" class="xref page">Monitoring gateways</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="new-audit-event-types-for-languages"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#new-audit-event-types-for-languages"></a>New audit event types for Languages</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We’ve added auditing events for languages and language keys. Events will now be logged when a language or language key is created, updated, or deleted. Learn more about language management in <a href="https://docs.pingidentity.com/pingone/user_experience/p1_languages.html" class="xref page">Languages</a>.</p>
</div>
<div class="paragraph">
<p>You can review and report on these events in the <a href="https://docs.pingidentity.com/pingone/monitoring/p1_reporting.html" class="xref page">audit</a> log or create <a href="https://docs.pingidentity.com/pingone/integrations/p1_webhooks.html" class="xref page">webhooks</a> to monitor the events using your security information and event management (SIEM) system. You can also find a complete list of events logged in PingOne in <a href="https://developer.pingidentity.com/pingone-api/platform/reference/audit-reporting-events.html" target="_blank" rel="noopener">Audit Reporting Events</a> in the PingOne API documentation.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[February 17]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#february-17</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#february-17</guid>
            <pubDate>Tue, 17 Feb 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="update-for-user-searches"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#update-for-user-searches"></a>Update for user searches</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We’ve added support for the <code class="codeph">updatedAt</code> attribute in user searches. This attribute allows you to search for users who were added or updated at a certain time. Learn more in the <a href="https://developer.pingidentity.com/pingone-api/platform/users/users-1/read-all-users.html" target="_blank" rel="noopener">PingOne API documentation</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="webhooks-enhancements"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#webhooks-enhancements"></a>Webhooks enhancements</h4>
<div class="paragraph">
<p><span class="ping_product">PingOne</span>
<span class="ping_changetype-improved">Improved</span></p>
</div>
<div class="paragraph">
<p>We’ve updated the <strong class="uicontrol">Webhooks</strong> UI to improve the look and feel. Learn more in <a href="https://docs.pingidentity.com/pingone/integrations/p1_webhooks.html" class="xref page">Webhooks</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="limit-the-maximum-payload-size-per-webhook"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#limit-the-maximum-payload-size-per-webhook"></a>Limit the maximum payload size per webhook</h4>
<div class="paragraph">
<p><span class="ping_product">PingOne</span>
<span class="ping_changetype-improved">Improved</span></p>
</div>
<div class="paragraph">
<p>You can now limit the amount of data sent in the payload for a webhook by setting a maximum allowable size based on the number of PingOne events included or by size in KB. This setting helps you ensure that your security information and event management (SIEM) tools don’t reject the payload because of limits set on the receiving system.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/integrations/p1_create_webhook.html" class="xref page">Creating or editing a webhook</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[February 15]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#february-15</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#february-15</guid>
            <pubDate>Sun, 15 Feb 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="show-application-name-setting-ignored-for-totp-apps"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#show-application-name-setting-ignored-for-totp-apps"></a>'Show application name' setting ignored for TOTP apps</h4>
<div class="paragraph">
<p><span class="ping_product">PingID</span>
<span class="ping_ticket">TRIAGE-31838</span>
<span class="ping_changetype-fixed">Fixed</span></p>
</div>
<div class="paragraph">
<p>We’ve fixed an issue in workforce PingID where the <strong class="uicontrol">Show Application name</strong> text defined in the MFA policy for <strong class="uicontrol">Authenticator App (TOTP)</strong> wasn’t displaying.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[February 4]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#february-4</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#february-4</guid>
            <pubDate>Wed, 04 Feb 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="key-rotation-policies-for-token-signing"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#key-rotation-policies-for-token-signing"></a>Key rotation policies for token signing</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>PingOne can now use key rotation policies (KRPs) for token signing for OIDC-based applications, regardless of whether the application includes PingOne API scopes in its authorization requests. You can also now update worker applications to use the default KRP for token signing.</p>
</div>
<div class="paragraph">
<p>Beginning March 2, 2027, PingOne will only use signing keys from KRPs to sign ID tokens and access tokens, regardless of whether the audience for the access token is PingOne APIs or custom resources. Any OIDC-based applications not using the KRP will automatically update to use the default KRP on this date.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/settings/p1_key_rotation_policy.html" class="xref page">Key rotation policies</a> and <a href="https://docs.pingidentity.com/pingone/applications/p1_edit_application_worker.html" class="xref page">Editing an application - Worker</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[February 3]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#february-3</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#february-3</guid>
            <pubDate>Tue, 03 Feb 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="group-role-assignment-update"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#group-role-assignment-update"></a>Group role assignment update</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>Administrators can now assign a role to a group they’re a member of if that role is directly assigned to them. Learn more in <a href="https://docs.pingidentity.com/pingone/getting_started_with_pingone/p1_manage_admin_roles.html#managing-group-roles" class="xref page">Managing group roles</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="special-characters-in-notification-templates"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#special-characters-in-notification-templates"></a>Special characters in notification templates</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>To prevent problems related to special character encoding when passing PingOne variables to custom email/SMS/voice providers, you can now specify the format that’s passed to the provider API (for example, HTML or JSON). You can find detailed information in <a href="https://docs.pingidentity.com/pingone/settings/p1_using_custom_email_provider_for_notifications.html" class="xref page">Using a custom email provider for notifications</a> and <a href="https://docs.pingidentity.com/pingone/settings/p1_sender_configure_custom_provider.html" class="xref page">Configuring a custom notification provider for PingOne</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[February 2]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#february-2</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#february-2</guid>
            <pubDate>Mon, 02 Feb 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="preview-period-for-updates-to-pingone-forms-rendering"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#preview-period-for-updates-to-pingone-forms-rendering"></a>Preview period for updates to PingOne Forms rendering</h4>
<div class="paragraph">
<p><span class="ping_changetype-info">Info</span>
<span class="ping_product">PingOne</span>
<span class="ping_product">DaVinci</span></p>
</div>
<div class="paragraph">
<p>We’re introducing technical improvements to modernize PingOne Forms rendering. These updates don’t change the end-user experience, and most customers don’t need to take any action.</p>
</div>
<div class="paragraph">
<p>However, if you use automated testing tools that check for specific HTML structures, your tests could be affected. These updates will go live for all customers following a one-month preview period. Learn more in <a href="https://support.pingidentity.com/s/article/Updates-to-PingOne-Forms-Rendering-February-2026" target="_blank" rel="noopener">Updates to PingOne Forms Rendering</a> in the Ping Identity Support Knowledge Base.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[January 27]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#january-27</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#january-27</guid>
            <pubDate>Tue, 27 Jan 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="support-for-opaque-refresh-tokens"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#support-for-opaque-refresh-tokens"></a>Support for opaque refresh tokens</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>As part of our ongoing commitment to security, PingOne now supports issuing opaque refresh tokens for OIDC-based applications. You can currently choose JSON Web Token (JWT) or opaque refresh token on the <strong class="uicontrol">Configuration</strong> tab. Learn more in <a href="https://docs.pingidentity.com/pingone/applications/p1_editing_applications.html" class="xref page">Editing an application</a>.</p>
</div>
<div class="paragraph">
<p>Beginning March 2, 2027, PingOne will issue only opaque refresh tokens, and JWTs will be deprecated for refresh tokens. You must update existing applications to use opaque refresh tokens by March 1, 2027 to avoid your users being unable to access resources they need. Learn more in <a href="https://docs.pingidentity.com/pingone/applications/p1_refresh_tokens.html" class="xref page">Refresh tokens</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[January 25]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#january-25</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#january-25</guid>
            <pubDate>Mon, 26 Jan 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="issue-causing-otp-authentications-to-fail-when-using-radius-pcv"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#issue-causing-otp-authentications-to-fail-when-using-radius-pcv"></a>Issue causing OTP authentications to fail when using RADIUS PCV</h4>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">TRIAGE-31681</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We’ve fixed an issue that was causing RADIUS PCV authentications to fail if the user was using a one-time passcode (OTP) to authenticate with a secondary device. This issue only occurred when RADIUS PCV was in no-challenge mode and only affected PingID accounts that were migrated to PingOne.</p>
</div>
</div>
<div class="sect3">
<h4 id="specifying-maximum-retention-period-for-risk-data"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#specifying-maximum-retention-period-for-risk-data"></a>Specifying maximum retention period for risk data</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne Protect</span></p>
</div>
<div class="paragraph">
<p>You can now specify maximum retention periods for the risk data that’s used by the following risk predictors:</p>
</div>
<div class="ulist">
<ul>
<li>
<p>New Device</p>
</li>
<li>
<p>User Location Anomaly</p>
</li>
<li>
<p>User Based Risk Behavior</p>
</li>
</ul>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/threat_protection_using_pingone_protect/p1_protect_general_protect_settings.html" class="xref page">Protect settings</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[January 21]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#january-21</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#january-21</guid>
            <pubDate>Wed, 21 Jan 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="pingone-protect-signals-sdk-new-versions"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#pingone-protect-signals-sdk-new-versions"></a>PingOne Protect (Signals) SDK - new versions</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne Protect SDK</span></p>
</div>
<div class="paragraph">
<p>We’ve released new versions of the PingOne Protect (Signals) SDK:</p>
</div>
<div class="ulist">
<ul>
<li>
<p>iOS: 5.4.0</p>
</li>
<li>
<p>Android: 5.3.0</p>
</li>
<li>
<p>Web: 5.6.7</p>
</li>
</ul>
</div>
<div class="paragraph">
<p>You can find details in the <a href="https://developer.pingidentity.com/pingone-api/native-sdks/pingone-risk-sdks/protect_sdk_changelog.html">SDK Changelog</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[January 19]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#january-19</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#january-19</guid>
            <pubDate>Mon, 19 Jan 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="empty-fido2-transport-list-not-handled-correctly"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#empty-fido2-transport-list-not-handled-correctly"></a>Empty FIDO2 transport list not handled correctly</h4>
<div class="paragraph">
<p><span class="ping_product">PingID</span>
<span class="ping_ticket">TRIAGE-31834</span>
<span class="ping_changetype-fixed">Fixed</span></p>
</div>
<div class="paragraph">
<p>Fixed an issue that was considering a FIDO2 device incompatible with all communication methods (such as USB, NFC) if its transport list was not populated. Now a FIDO2 device with an empty transport list is considered compatible with all communication methods. This issue affected PingID accounts that migrated to PingOne environments and use Windows login.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[January 15]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#january-15</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#january-15</guid>
            <pubDate>Thu, 15 Jan 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="theme-improvements-and-additions"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#theme-improvements-and-additions"></a>Theme improvements and additions</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>Several improvements have been made to themes to enable more comprehensive customization for your end-user pages:</p>
</div>
<div class="ulist">
<ul>
<li>
<p>Footers have been moved to the bottom of the page, instead of the bottom of the card.</p>
</li>
<li>
<p>The editor for the global <strong class="uicontrol">Footer</strong> setting has been redesigned for both HTML and plain text options and now  includes support for localization. These changes also apply to a new component-specific <strong class="uicontrol">Header</strong> setting for PingOne DaVinci forms.</p>
</li>
<li>
<p>A group of component-specific settings were added for DaVinci forms.</p>
</li>
<li>
<p>Options were added to allow you to clone themes or to upgrade legacy themes to enable the new settings.</p>
</li>
</ul>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/user_experience/p1_branding_themes.html" class="xref page">Branding and Themes</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[January 12]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#january-12</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#january-12</guid>
            <pubDate>Mon, 12 Jan 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="microsoft-365-application-advanced-settings-for-passive-profile"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#microsoft-365-application-advanced-settings-for-passive-profile"></a>Microsoft 365 application advanced settings for passive profile</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="sect4">
<h5 id="ws-trust-version"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#ws-trust-version"></a>WS-Trust version</h5>
<div class="paragraph">
<p>PingOne now supports the ability to select the WS-Trust version to use when issuing security tokens for the Microsoft 365 application. The WS-Trust version only applies to passive profile sign-ons. Learn more in <a href="https://docs.pingidentity.com/pingone/applications/p1_setting_ws-trust_version.html" class="xref page">Setting the WS-Trust version</a>.</p>
</div>
</div>
<div class="sect4">
<h5 id="assertion-validity-duration"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#assertion-validity-duration"></a>Assertion validity duration</h5>
<div class="paragraph">
<p>You can now set the assertion validity duration before the SAML assertion expires for passive profile sign-ons to the Microsoft 365 application in PingOne. Learn more in <a href="https://docs.pingidentity.com/pingone/applications/p1_fine-tuning_assertion_validity_duration.html" class="xref page">Fine-tuning assertion validity duration</a>.</p>
</div>
</div>
</div>
<div class="sect3">
<h4 id="increased-limit-for-applications-per-environment"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#increased-limit-for-applications-per-environment"></a>Increased limit for applications per environment</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>Each PingOne environment now supports up to 4000 applications. Learn more in <a href="https://docs.pingidentity.com/pingone/getting_started_with_pingone/p1_platform_limits.html" class="xref page">PingOne standard platform limits</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="configure-minimum-length-for-fido-device-pin-during-user-verification"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#configure-minimum-length-for-fido-device-pin-during-user-verification"></a>Configure minimum length for FIDO device PIN during user verification</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne MFA</span>
<span class="ping_product">PingID</span></p>
</div>
<div class="paragraph">
<p>FIDO policy can now define a minimum PIN length for user verification with a security key and check compliance during registration and authentication flows. This feature brings compliance with the CTAP2.1 standard’s <code>minPinLength</code> extension.</p>
</div>
<div class="paragraph">
<p>Users must use a security key that supports the <code>minPinLength</code> extension and define a PIN that conforms to the <strong class="uicontrol">Minimum PIN length</strong> field defined in the FIDO policy to pass user verification.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/authentication/p1_creating_a_fido_policy.html" class="xref page">Adding a FIDO policy</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="after-migration-to-pingone-authonline-of-authtype-otp-not-working-as-expected"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#after-migration-to-pingone-authonline-of-authtype-otp-not-working-as-expected"></a>After migration to PingOne authOnline of authType OTP not working as expected</h4>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">TRIAGE-29909</span>
<span class="ping_product">PingID</span></p>
</div>
<div class="paragraph">
<p>Fixed an issue affecting PingID accounts that were migrated to a PingOne environment, where <code>authOnline</code> API requests with <code>authType</code> <code>OTP</code> were not actioned, causing a push notification to be sent instead.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[January 5]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#january-5</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#january-5</guid>
            <pubDate>Mon, 05 Jan 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="support-for-8-digit-codes-from-authenticator-apps"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#support-for-8-digit-codes-from-authenticator-apps"></a>Support for 8-digit codes from authenticator apps</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>When using authenticator apps for authentication, PingOne can now accept passcodes that are up to 8 digits long.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[December 14]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#december-14</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#december-14</guid>
            <pubDate>Sun, 14 Dec 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="pingone-mfa-mobile-sdk-2-2"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#pingone-mfa-mobile-sdk-2-2"></a>PingOne MFA mobile SDK 2.2</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>We’ve released version 2.2 of the PingOne MFA mobile SDK. In addition to security enhancements and minor bug fixes, this version includes the following changes.</p>
</div>
<div class="sect4">
<h5 id="android"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#android"></a>Android</h5>
<div class="paragraph">
<p>The Android version of the SDK is now targeted for Android 16.</p>
</div>
</div>
<div class="sect4">
<h5 id="ios"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#ios"></a>iOS</h5>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">TRIAGE-28957</span></p>
</div>
<div class="paragraph">
<p>For iOS applications using TOTP, there were situations where the passcode refresh duration was changed, but the timer continued to use the default 30-second setting. This issue has been fixed.</p>
</div>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">TRIAGE-30389</span></p>
</div>
<div class="paragraph">
<p>For iOS applications using TOTP, there were situations where authentication failed if the passcode refresh duration had been changed from the default 30-second setting. This issue has been fixed.</p>
</div>
</div>
<div class="sect4">
<h5 id="sample-applications"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#sample-applications"></a>Sample applications</h5>
<div class="paragraph">
<p>The sample applications for both iOS and Android now include code that demonstrates the use of automatic passkey creation.</p>
</div>
<div class="paragraph">
<p>Learn more in the documentation for the <a href="https://github.com/pingidentity/pingone-mobile-sdk-android/blob/master/release-notes.md">Android version</a> and the documentation for the <a href="https://github.com/pingidentity/pingone-mobile-sdk-ios/blob/master/release-notes.md">iOS version</a>.</p>
</div>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[December 7]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#december-7</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#december-7</guid>
            <pubDate>Sun, 07 Dec 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="custom-mail-from-domains"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#custom-mail-from-domains"></a>Custom MAIL FROM domains</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>To reduce the likelihood of PingOne email notifications getting flagged as spam when you are using Ping Identity as the notification sender, you can now define a custom MAIL FROM domain for trusted email domains that you have configured. Specifying a MAIL FROM domain results in SPF alignment with the FROM header, reducing the chances that the DMARC check will fail. You can find detailed instructions in <a href="https://docs.pingidentity.com/pingone/settings/p1_set_up_trusted_email_domain.html#p1-define-mail-from-subdomain" class="xref page">Setting up SPF and a custom MAIL FROM domain</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="time-zones-for-fields-in-user-device-reports"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#time-zones-for-fields-in-user-device-reports"></a>Time zones for fields in User Device reports</h4>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">TRIAGE-30153</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>In User Device reports there were some fields where the time was not expressed in UTC. This issue has been fixed.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[December 3]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#december-3</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#december-3</guid>
            <pubDate>Wed, 03 Dec 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="ida-in-pingone-verify"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#ida-in-pingone-verify"></a>IDA in PingOne Verify</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne Verify</span></p>
</div>
<div class="paragraph">
<p>We’ve added the ability to <strong class="uicontrol">Store Verified Claims</strong> in a verify policy. This enables you to store verified personally identifiable information (PII) within the PingOne Directory. Learn more in <a href="https://docs.pingidentity.com/pingone/identity_verification_using_pingone_verify/p1_verify_creating_verify_policy.html" class="xref page">Creating a verify policy</a>, <a href="https://docs.pingidentity.com/pingone/directory/p1_viewusers.html" class="xref page">Viewing users</a>, and <a href="https://docs.pingidentity.com/pingone/directory/p1_edituser.html" class="xref page">Editing a user</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[November 18]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#november-18</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#november-18</guid>
            <pubDate>Tue, 18 Nov 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="provisioning-dashboard-2"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#provisioning-dashboard-2"></a>Provisioning Dashboard</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>The <strong class="uicontrol">Provisioning Dashboard</strong> shows a summary of outbound and inbound provisioning activity for the selected environment. Learn more in <a href="https://docs.pingidentity.com/pingone/integrations/p1_provisioning_dashboard.html" class="xref page">Provisioning Dashboard</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[November 17]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#november-17</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#november-17</guid>
            <pubDate>Mon, 17 Nov 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="limiting-number-of-mfa-devices-waiting-for-activation"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#limiting-number-of-mfa-devices-waiting-for-activation"></a>Limiting number of MFA devices waiting for activation</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOneMFA</span></p>
</div>
<div class="paragraph">
<p>We’ve made the following changes to help limit the number of MFA devices that have never been activated:</p>
</div>
<div class="ulist">
<ul>
<li>
<p>Devices that have been in <code>ACTIVATION_REQUIRED</code> status for 24 hours are deleted from the system.</p>
</li>
<li>
<p>There can be a maximum of 50 devices per user in <code>ACTIVATION_REQUIRED</code> status. After this limit is reached, attempts to create a new device result in an error message.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="pingone-environment-properties-name-field-defines-the-pingid-mobile-app-organization-name"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#pingone-environment-properties-name-field-defines-the-pingid-mobile-app-organization-name"></a>PingOne Environment Properties Name field defines the PingID mobile app Organization Name</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">Strong Authentication</span>
<span class="ping_product">PingID</span></p>
</div>
<div class="paragraph">
<p>The PingOne Environment Properties <strong class="uicontrol">Name</strong> field now defines the name that represents your organization in the PingID mobile app and PingID push notifications.</p>
</div>
<div class="admonitionblock note">
<table>
<tbody><tr>
<td class="icon">
<i class="fa icon-note" title="Note"></i>
</td>
<td class="content">
<div class="paragraph">
<p>When creating a new PingID account in a PingOne environment, the PingID mobile app UI automatically displays both the organization name and environment name. To display only the PingOne Environment Name
in the app and push notifications, after creating the environment go to PingOne Environment Properties and edit the <strong class="uicontrol">Name</strong> field.</p>
</div>
</td>
</tr>
</tbody></table>
</div>
</div>
<div class="sect3">
<h4 id="pingid-activity-logs-missing-information-from-davinci"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#pingid-activity-logs-missing-information-from-davinci"></a>PingID activity logs missing information from DaVinci</h4>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">TRIAGE-29876</span>
<span class="ping_product">Strong Authentication</span>
<span class="ping_product">PingID</span></p>
</div>
<div class="paragraph">
<p>We’ve fixed an issue that was preventing the PingID Activity Log from displaying information related to the DaVinci <strong class="uicontrol">PingID Evaluate Policy</strong> node.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[November 11]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#november-11</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#november-11</guid>
            <pubDate>Sun, 11 Nov 2001 23:23:59 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="provisioning-rules"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#provisioning-rules"></a>Provisioning rules</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We’ve enhanced the provisioning rules UI. You can now configure both inbound and outbound provisioning rules faster and more effectively. Learn more in <a href="https://docs.pingidentity.com/pingone/integrations/p1_rules_provisioning.html" class="xref page">Provisioning rules</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[November 7]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#november-7</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#november-7</guid>
            <pubDate>Fri, 07 Nov 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="pingone-forms-now-support-dynamic-agreements"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#pingone-forms-now-support-dynamic-agreements"></a>PingOne Forms now support dynamic agreements</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>When configuring an agreement component for Forms, you can now select <strong class="uicontrol">Use Agreement ID from Form node</strong>. In DaVinci, the Form connector’s <strong class="uicontrol">Show Form</strong> node lets you select a specific agreement or provide a dynamic agreement ID using a variable.</p>
</div>
<div class="paragraph">
<p>This enhancement enables you to reuse one agreement form for any flow or user context. For example, you can now dynamically present different agreements to different populations.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[November 5]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#november-5</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#november-5</guid>
            <pubDate>Wed, 05 Nov 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="risk-policy-validation"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#risk-policy-validation"></a>Risk policy validation</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne Protect</span></p>
</div>
<div class="paragraph">
<p>When you save a risk policy, PingOne Protect now checks the scores you assigned to various risk predictors. If the scores assigned are likely to lead to missing high-risk or medium-risk situations, PingOne Protect displays a message that identifies the problem and asks if you want to adjust the assigned scores before saving the risk policy.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[November 4]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#november-4</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#november-4</guid>
            <pubDate>Tue, 04 Nov 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="gateway-alerts"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#gateway-alerts"></a>Gateway alerts</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>You can now configure gateway alerts to send error, warning, and information email notifications. Learn more in <a href="https://docs.pingidentity.com/pingone/integrations/p1_gateways.html" class="xref page">Gateways</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[October 30]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#october-30</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#october-30</guid>
            <pubDate>Thu, 30 Oct 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="forms-can-only-contain-a-single-agreement-component"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#forms-can-only-contain-a-single-agreement-component"></a>Forms can only contain a single Agreement component</h4>
<div class="paragraph">
<p><span class="ping_changetype-info">Info</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>Previously, you could add multiple <strong class="uicontrol">Agreement</strong> components to a single form. This made it difficult to determine which agreement ID was output by the Show Form node.</p>
</div>
<div class="paragraph">
<p>Now, you can add only one <strong class="uicontrol">Agreement</strong> component to each form. The agreement ID is output in a predictable location with a clear name.</p>
</div>
<div class="paragraph">
<p>This change also supports an upcoming ability to control the agreement selection from the Show Form node.</p>
</div>
</div>
<div class="sect3">
<h4 id="data-based-identity-verification"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#data-based-identity-verification"></a>Data-Based Identity Verification</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne Verify</span></p>
</div>
<div class="paragraph">
<p>You can now configure <strong class="uicontrol">Data-Based Identity Verification</strong> in your PingOne Verify policy. <strong class="uicontrol">US Data-Based Identity Verification</strong> allows you to verify user identity attributes with trusted third-party data. Learn more in <a href="https://docs.pingidentity.com/pingone/identity_verification_using_pingone_verify/p1_verify_creating_verify_policy.html" class="xref page">Creating a verify policy</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[October 29]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#october-29</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#october-29</guid>
            <pubDate>Wed, 29 Oct 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="audit-data-retrieval-changes"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#audit-data-retrieval-changes"></a>Audit data retrieval changes</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>Previously announced changes to how audit events older than 14 days are retrieved are now live. The following updates were made:</p>
</div>
<div class="sect4">
<h5 id="querying-recent-data"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#querying-recent-data"></a>Querying recent data</h5>
<div class="ulist">
<ul>
<li>
<p>Audit data up to 14 days old is available immediately from the PingOne admin console or using the PingOne APIs.</p>
</li>
<li>
<p>You can request a maximum of 14 days of data at a time. That is, whether you enter a relative or a date-specific time range, the time period can’t exceed 14 days.</p>
</li>
</ul>
</div>
</div>
<div class="sect4">
<h5 id="retrieving-older-data"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#retrieving-older-data"></a>Retrieving older data</h5>
<div class="ulist">
<ul>
<li>
<p>Audit data older than 14 days is still available, but must be requested from the <strong class="uicontrol">Audit</strong> page or using the PingOne APIs and is subject to a longer retrieval time.</p>
</li>
<li>
<p>To start a retrieval of older data, use the date filters on the <strong class="uicontrol">Audit</strong> page. Messages in the UI will let you know if data is immediately available or requires retrieval.</p>
</li>
<li>
<p>API GET operations for events older than 14 days require an additional request parameter to start the retrieval process. Learn more in <a href="https://developer.pingidentity.com/pingone-api/platform/audit-activities.html">Audit Activities</a> in the PingOne API documentation.</p>
</li>
<li>
<p>You can’t request additional data while another request is pending.</p>
</li>
<li>
<p>You’ll be notified by email when the data is retrieved, and at that point you can run queries against the data from the <strong class="uicontrol">Audit</strong> page or using the APIs. This data is available for 14 days from the retrieval date.</p>
</li>
<li>
<p>Depending on the number of days requested and the average number of events logged per day, the process can take from 2 to 24 hours.</p>
</li>
</ul>
</div>
</div>
<div class="sect4">
<h5 id="querying-older-data"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#querying-older-data"></a>Querying older data</h5>
<div class="ulist">
<ul>
<li>
<p>After the retrieval is complete you can run queries from the <strong class="uicontrol">Audit</strong> page as normal against a maximum of 14 days of data. This maximum includes both immediately available data and retrieved data.</p>
</li>
</ul>
</div>
<div class="admonitionblock note">
<table>
<tbody><tr>
<td class="icon">
<i class="fa icon-note" title="Note"></i>
</td>
<td class="content">
<div class="paragraph">
<p>PingOne maintains auditing data for end-user events for 90 days by default. Historical dashboard data and administration configuration change data is retained for two years. These retention periods haven’t changed.</p>
</div>
<div class="paragraph">
<p>PingOne DaVinci events are not stored in PingOne. Learn more about DaVinci data retention and retrieval in the <a href="https://docs.pingidentity.com/davinci/release_notes/davinci_release_notes.html#september-9">DaVinci release notes</a> and the <a href="https://docs.pingidentity.com/davinci/davinci_best_practices/davinci_best_practices_debugging_and_analytics.html">Debugging and analytics</a> section of the DaVinci documentation.</p>
</div>
</td>
</tr>
</tbody></table>
</div>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[October 28]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#october-28</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#october-28</guid>
            <pubDate>Tue, 28 Oct 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="support-for-microsoft-entra-id-hybrid-join"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#support-for-microsoft-entra-id-hybrid-join"></a>Support for Microsoft Entra ID hybrid join</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span>
<span class="ping_product">PingOne SSO</span></p>
</div>
<div class="paragraph">
<p>As organizations expand their on-premise Active Directory (AD) infrastructure to Microsoft Entra ID in the cloud, you can optionally hybrid join your organization’s Windows devices to Entra ID to simplify device management. As an identity provider (IdP) federated with Entra ID, PingOne can now issue security tokens for the hybrid join process, helping to accelerate adoption of Entra ID features and cloud services. This new capability is available as a limited access release for customers with a PingOne for Workforce Plus or Premium license in the North America region only. Learn more in <a href="https://docs.pingidentity.com/pingone/use_cases/p1_microsoft_entra_hybrid_join.html" class="xref page">Setting up PingOne as the federated IdP for Microsoft Entra ID</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="improved-pingone-davinci-integration"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#improved-pingone-davinci-integration"></a>Improved PingOne DaVinci integration</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span>
<span class="ping_product">DaVinci</span></p>
</div>
<div class="paragraph">
<p>You can now apply a PingOne DaVinci policy to the Microsoft 365 application. Learn more in <a href="https://docs.pingidentity.com/pingone/applications/p1_adding_microsoft_365.html" class="xref page">Adding Microsoft 365 to allow users to sign on using PingOne</a> and <a href="https://docs.pingidentity.com/davinci/integrating_flows_into_applications/davinci_launch_flow_redirect.html" target="_blank" rel="noopener">Launching a PingOne DaVinci flow with a redirect</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[October 26]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#october-26</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#october-26</guid>
            <pubDate>Sun, 26 Oct 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="updates-to-mfa-status-following-migration-of-an-existing-pingid-account-to-an-existing-pingone-environment"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#updates-to-mfa-status-following-migration-of-an-existing-pingid-account-to-an-existing-pingone-environment"></a>Updates to MFA status following migration of an existing PingID account to an existing PingOne environment</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">Strong Authentication</span>
<span class="ping_product">PingID</span></p>
</div>
<div class="paragraph">
<p>We’ve made some changes as to how the MFA status is updated following the integration of an existing PingID account to an existing PingOne environment, or migration of PingID management from the legacy PingID admin portal to a PingOne environment.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/strong_authentication_mfa/p1_what_to_know_before_integrating_existing_pid_account_to_p1.html" class="xref page">What you need to know before integrating or migrating a PingID account into a PingOne environment</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[October 24]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#october-24</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#october-24</guid>
            <pubDate>Fri, 24 Oct 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="updated-ldap-gateway-client-application-3"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#updated-ldap-gateway-client-application-3"></a>Updated LDAP gateway client application</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We’ve released LDAP Gateway client application version 4.0.3. This version fixes an issue where provisioning users from LDAP to PingOne failed to sync the Active Directory <code class="codeph">memberOf</code> attribute, which potentially resulted in a loss of group or role-based application access.</p>
</div>
<div class="admonitionblock important">
<table>
<tbody><tr>
<td class="icon">
<i class="fa icon-important" title="Important"></i>
</td>
<td class="content">
<div class="paragraph">
<p>LDAP Provisioning customers shouldn’t use LDAP Gateway 4.0.2 and are advised to upgrade to 4.0.3.</p>
</div>
</td>
</tr>
</tbody></table>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[October 23]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#october-23</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#october-23</guid>
            <pubDate>Thu, 23 Oct 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="import-and-export-forms-with-davinci-flows"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#import-and-export-forms-with-davinci-flows"></a>Import and export forms with DaVinci Flows</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We’ve made it easier to share your forms, such as when sending your flows to the Ping Identity Support team or collaborating with an implementation partner. This change will also allow Ping Identity to add flows to the <a href="https://marketplace.pingone.com/browse?products=davinci&amp;contentType=davinciConnectors" target="_blank" rel="noopener">Ping Identity Marketplace</a> that include easy drag-and-drop forms.</p>
</div>
<div class="paragraph">
<p>Now, when exporting a DaVinci flow, the forms associated with any <strong class="uicontrol">Show Form</strong> nodes are included in the exported flow JSON file. When importing a flow, DaVinci imports any forms into <strong class="uicontrol">User Experience &gt; Forms</strong>.</p>
</div>
<div class="paragraph">
<p>This feature is designed to share forms across unrelated environments, so exported forms don’t include external IdP information or custom user attributes.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/user_experience/p1_import_export_forms.html" class="xref page">Importing and exporting forms</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[October 22]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#october-22</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#october-22</guid>
            <pubDate>Wed, 22 Oct 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="support-added-for-up-to-100-million-identities-per-environment"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#support-added-for-up-to-100-million-identities-per-environment"></a>Support added for up to 100 million identities per environment</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>PingOne now supports up to 100 million identities in a single environment. Learn more in <a href="https://docs.pingidentity.com/pingone/getting_started_with_pingone/p1_platform_limits.html" class="xref page">PingOne standard platform limits</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[October 21]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#october-21</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#october-21</guid>
            <pubDate>Tue, 21 Oct 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="oauth-2-0-authorization-server-metadata"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#oauth-2-0-authorization-server-metadata"></a>OAuth 2.0 authorization server metadata</h4>
<div class="paragraph">
<p><span class="ping_changetype-info">Info</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>PingOne now includes OAuth 2.0 authorization server metadata in its <code class="codeph">/.well-known/oauth-authorization-server</code> response. This adds support for the OAuth metadata URI to enable consistency with the OAuth 2.0 metadata specification and interoperability across Ping Identity products.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[October 20]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#october-20</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#october-20</guid>
            <pubDate>Mon, 20 Oct 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="groups-ui-enhancements"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#groups-ui-enhancements"></a>Groups UI enhancements</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We’ve made several improvements to the UI for the <strong class="uicontrol">Groups</strong> page to give you a more organized and efficient experience. The groups list is now displayed in columns that bring important group information to the surface. Customize the display by showing and hiding columns as needed. Use our new filters to quickly refine the list further and show only the groups you want to see.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/directory/p1_groups.html" class="xref page">Groups</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[October 17]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#october-17</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#october-17</guid>
            <pubDate>Fri, 17 Oct 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="audit-data-retrieval-changes-deployed-in-singapore-region"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#audit-data-retrieval-changes-deployed-in-singapore-region"></a>Audit data retrieval changes deployed in Singapore region</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>The audit retrieval changes announced on <a href="https://docs.pingidentity.com/pingone/release_notes/index.html#audit-data-retrieval-changes-coming">October 2</a> have been deployed in the Singapore region. The changes will be deployed to the remaining regions by the end of the month.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[October 7]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#october-7</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#october-7</guid>
            <pubDate>Tue, 07 Oct 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="option-to-accept-acs-urls-found-in-signed-saml-authnrequests"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#option-to-accept-acs-urls-found-in-signed-saml-authnrequests"></a>Option to accept ACS URLs found in signed SAML AuthnRequests</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span>
<span class="ping_product">PingOne SSO</span></p>
</div>
<div class="paragraph">
<p>PingOne now supports always accepting an assertion consumer service (ACS) URL in a signed SAML AuthnRequest regardless of whether the ACS URL is added on the application’s <strong class="uicontrol">Configuration</strong> tab. This new setting is useful if a service provider (SP) generates ACS URLs dynamically. Learn more in <a href="https://docs.pingidentity.com/pingone/applications/p1_edit_application_saml.html" class="xref page">Editing an application - SAML</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[October 2]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#october-2</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#october-2</guid>
            <pubDate>Thu, 02 Oct 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="audit-data-retrieval-changes-coming"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#audit-data-retrieval-changes-coming"></a>Audit data retrieval changes coming</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>Starting October 27, 2025, the following changes will be made to how audit events older than 14 days are retrieved:</p>
</div>
<div class="ulist">
<ul>
<li>
<p>Audit data up to 14 days old will be available immediately from the PingOne admin console or using the API, as it is today.</p>
</li>
<li>
<p>Audit data older than 14 days will still be available, but must be requested from the <strong class="uicontrol">Audit</strong> page or using the API and is subject to a longer retrieval time.</p>
</li>
<li>
<p>You’ll be able to request a maximum of 14 days of data from storage at a time. That is, whether you enter a relative or a date-specific time range, the time period can’t exceed 14 days.</p>
</li>
<li>
<p>You can’t request additional data while another request is in progress.</p>
</li>
<li>
<p>You can run queries against a maximum of 14 days of data. This maximum includes both immediately available data and retrieved data.</p>
</li>
</ul>
</div>
<div class="paragraph">
<p>API GET operations for events older than 14 days will require an additional request parameter to start the retrieval process.</p>
</div>
<div class="paragraph">
<p>After you request data older than 14 days, you’ll be notified by email when the data is accessible, and at that point you can run queries against the retrieved data from the <strong class="uicontrol">Audit</strong> page or using the API. This data will be available for reporting for 14 days from the retrieval date.</p>
</div>
<div class="paragraph">
<p>Depending on the number of days requested and the average number of events logged per day, the process can take from 2 to 24 hours.</p>
</div>
<div class="admonitionblock note">
<table>
<tbody><tr>
<td class="icon">
<i class="fa icon-note" title="Note"></i>
</td>
<td class="content">
<div class="paragraph">
<p>PingOne maintains auditing data for user events for 90 days by default. Historical dashboard data and administration configuration change data is retained for 2 years. These retention periods are not changing.</p>
</div>
<div class="paragraph">
<p>PingOne DaVinci events are not stored in PingOne. Learn more about DaVinci data retention policies in the <a href="https://docs.pingidentity.com/davinci/release_notes/davinci_release_notes.html#september-9">DaVinci release notes</a>.</p>
</div>
</td>
</tr>
</tbody></table>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[September 30]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#september-30</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#september-30</guid>
            <pubDate>Tue, 30 Sep 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="domains"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#domains"></a>Domains</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We modernized <strong class="uicontrol">Domains</strong> in PingOne with a new look and feel. Learn more in <a href="https://docs.pingidentity.com/pingone/settings/p1_domains.html" class="xref page">Domains</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="updated-ldap-gateway-client-application-4"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#updated-ldap-gateway-client-application-4"></a>Updated LDAP gateway client application</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We’ve released LDAP Gateway client application version 4.0.2. This version includes:</p>
</div>
<div class="ulist">
<ul>
<li>
<p>A new Java required version, Java 21 LTS.</p>
</li>
<li>
<p>Upgraded packages to resolve security vulnerabilities.</p>
</li>
<li>
<p>Enhancement to LDAP connection pool and WebSocket connection logic to maintain healthy connections.</p>
</li>
<li>
<p>Health actuator endpoints to support container orchestration health checks. Learn more in <a href="https://docs.pingidentity.com/pingone/integrations/p1_ldap_gateway_endpoints.html" class="xref page">LDAP gateway health endpoints</a>.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="authorize-gateway-1-2-0"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#authorize-gateway-1-2-0"></a>Authorize gateway 1.2.0</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span>
<span class="ping_product">PingOne Authorize</span></p>
</div>
<div class="paragraph">
<p>We’ve released Authorize gateway version 1.2.0. This version includes:</p>
</div>
<div class="sect4">
<h5 id="bulk-decision-requests"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#bulk-decision-requests"></a>Bulk decision requests</h5>
<div class="paragraph">
<p>Authorize gateway instances now support bulk decision requests, allowing you to evaluate multiple access scenarios in a single API call. Bulk requests reduce both network overhead and overall decision latency, improving performance in high-throughput environments.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/integrations/p1_make_decision_requests_to_authz_gateway_instances.html" class="xref page">Making decision requests to Authorize gateway instances</a>.</p>
</div>
<div class="admonitionblock tip">
<table>
<tbody><tr>
<td class="icon">
<i class="fa icon-tip" title="Tip"></i>
</td>
<td class="content">
<div class="paragraph">
<p>You can find additional release details in <a href="https://docs.pingidentity.com/pingone/integrations/p1_authz_gateway_version_history.html" class="xref page">Authorize gateway version history</a>.</p>
</div>
</td>
</tr>
</tbody></table>
</div>
</div>
<div class="sect4">
<h5 id="end-of-support-notice"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#end-of-support-notice"></a>End of support notice</h5>
<div class="paragraph">
<p>Support for the previous Authorize gateway version (1.1.0) will end on October 31, 2026. Learn more in <a href="https://docs.pingidentity.com/pingone/integrations/p1_authz_gateway_support_lifecycle.html" class="xref page">Authorize gateway support lifecycle</a>.</p>
</div>
</div>
</div>
<div class="sect3">
<h4 id="improve-cache-performance-with-header-exclusions"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#improve-cache-performance-with-header-exclusions"></a>Improve cache performance with header exclusions</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne Authorize</span></p>
</div>
<div class="paragraph">
<p>You can now improve the cache hit rate by excluding certain HTTP headers from the authorization service cache key. This reduces unnecessary cache misses caused by headers that are unique to each request, change frequently, or don’t affect the service response.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/authorization_using_pingone_authorize/p1_az_service_caching.html" class="xref page">Service caching</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[September 15]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#september-15</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#september-15</guid>
            <pubDate>Mon, 15 Sep 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="api-usage-dashboard-and-maximum-throughput-assurance"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#api-usage-dashboard-and-maximum-throughput-assurance"></a>API Usage Dashboard and Maximum Throughput Assurance</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>To ensure that every PingOne customer has the share of resources they need at any given time, PingOne sets rate limits based on your purchased PingOne products, as well as the product APIs licensed in your product license. Rate groups, which are groups of endpoints related to a particular product or service, each have their own rate entitlements.</p>
</div>
<div class="paragraph">
<p>Our new <strong class="uicontrol">API Usage Dashboard</strong> lets you monitor your peak usage against the established entitlements so that you can plan effectively. Additionally, a new <strong class="uicontrol">Rate Limits and Allowed IPs</strong> page in <strong class="uicontrol">Settings</strong> allows you to bypass per IP rate limits for server-sourced traffic.</p>
</div>
<div class="admonitionblock note">
<table>
<tbody><tr>
<td class="icon">
<i class="fa icon-note" title="Note"></i>
</td>
<td class="content">
<div class="paragraph">
<p>Rate entitlement enforcement will begin at some point after September 2025. You can use the <strong class="uicontrol">API Usage Dashboard</strong> now to track your usage and determine if the existing entitlements will be sufficient to meet the needs of your business when enforcement starts. You can also use the <strong class="uicontrol">Rate Limits and Allowed IPs</strong> page
for reference now and preconfigure the <strong class="uicontrol">Server-Sourced Traffic</strong> list, if applicable to your deployment. The list will go into effect on the enforcement date.</p>
</div>
<div class="paragraph">
<p>Ping has established base entitlements that should provide adequate resourcing for the majority of our customers. Customers requiring additional capacity should contact Sales about our Maximum Throughput Assurance program.</p>
</div>
</td>
</tr>
</tbody></table>
</div>
<div class="paragraph">
<p>PingOne Integration Kits have been updated to support this new rate limiting model. Go to the <a href="https://support.pingidentity.com/s/marketplace-integration-home-page" target="_blank" rel="noopener">Ping Identity Integration Directory</a> and download the latest versions of your integration kits.</p>
</div>
<div class="paragraph">
<p>Learn more about rate limiting in PingOne in the following topics:</p>
</div>
<div class="ulist">
<ul>
<li>
<p><a href="https://docs.pingidentity.com/pingone/settings/p1_api_usage_dashboard.html" class="xref page">API Usage Dashboard</a></p>
</li>
<li>
<p><a href="https://docs.pingidentity.com/pingone/settings/p1_rate_limits.html" class="xref page">Rate Limits and Allowed IPs</a></p>
</li>
<li>
<p><a href="https://developer.pingidentity.com/pingone-api/platform/rate-limiting.html" target="_blank" rel="noopener">Rate Limiting</a> (in the PingOne API documentation).</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[September 14]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#september-14</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#september-14</guid>
            <pubDate>Sun, 14 Sep 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="migration-now-completes-successfully-even-if-some-user-accounts-fail-to-migrate"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#migration-now-completes-successfully-even-if-some-user-accounts-fail-to-migrate"></a>Migration now completes successfully even if some user accounts fail to migrate</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">Strong Authentication</span>
<span class="ping_product">PingID</span></p>
</div>
<div class="paragraph">
<p>When migrating a PingID account to a PingOne environment, PingOne allows migration to complete even if a small number of the PingID accounts fail to migrate successfully.</p>
</div>
<div class="paragraph">
<p>To identify any user accounts that failed to migrate, Admins should check the PingID administrative activity report. The report includes the total number of failed accounts as well as an entry identifying the username for each failed account.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/strong_authentication_mfa/p1_migrate_pingid_account_postrequisites.html" class="xref page">Considerations after integrating or migrating a PingID account into a PingOne environment</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[September 9]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#september-9</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#september-9</guid>
            <pubDate>Tue, 09 Sep 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="backward-compatibility-for-fallback-to-next-device-for-pingid-accounts"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#backward-compatibility-for-fallback-to-next-device-for-pingid-accounts"></a>Backward compatibility for fallback to next device for PingID accounts</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">Strong Authentication</span>
<span class="ping_product">PingID</span></p>
</div>
<div class="paragraph">
<p>We’ve added backward compatibility for PingID accounts on PingOne when the MFA policy is configured to <strong class="uicontrol">User selected default</strong>.</p>
</div>
<div class="paragraph">
<p>With this update, if a user signs in from a browser or application that does not support WebAuthn, they are now automatically prompted to authenticate with the next available method in their device list, instead of being asked to manually select a different device.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[September 5]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#september-5</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#september-5</guid>
            <pubDate>Fri, 05 Sep 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="bring-your-own-authorization-server"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#bring-your-own-authorization-server"></a>Bring your own authorization server</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne Authorize</span></p>
</div>
<div class="paragraph">
<p>API Access Management now validates access tokens from third-party authorization servers. This allows integration with PingOne Advanced Identity Cloud, PingOne Advanced Services, or your current third-party identity provider while leveraging PingOne Authorize for centralized API access control. Token claims are automatically mapped to built-in attributes, making them easy to use in claims-based access control policies.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/authorization_using_pingone_authorize/p1_az_external_oauth_servers.html" class="xref page">External OAuth servers in PingOne Authorize</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[September 2]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#september-2</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#september-2</guid>
            <pubDate>Tue, 02 Sep 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="require-users-to-perform-mfa-to-manage-myaccount"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#require-users-to-perform-mfa-to-manage-myaccount"></a>Require users to perform MFA to manage MyAccount</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>You can now configure the <strong class="uicontrol">Self-Service-MyAccount</strong> application to require users to authenticate with MFA before they can manage their authentication methods for customer (PingOne MFA) use cases.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/user_experience/p1_require_mfa_to_access_myaccount.html" class="xref page">Require users to perform MFA to manage MyAccount page (Customer only)</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="custom-notification-providers-support-for-additional-authorization-methods"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#custom-notification-providers-support-for-additional-authorization-methods"></a>Custom notification providers - support for additional authorization methods</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>When defining a custom provider for email or SMS/voice notifications, you can now also use providers that require OAuth2 authorization (Client Credentials) or  the use of a custom header.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[August 27]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#august-27</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#august-27</guid>
            <pubDate>Wed, 27 Aug 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="authorize-gateway-1-1-0"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#authorize-gateway-1-1-0"></a>Authorize gateway 1.1.0</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span>
<span class="ping_product">PingOne Authorize</span></p>
</div>
<div class="paragraph">
<p>We’ve released Authorize gateway version 1.1.0. This version includes the following features and enhancements.</p>
</div>
<div class="sect4">
<h5 id="more-powerful-policy-authoring"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#more-powerful-policy-authoring"></a>More powerful policy authoring</h5>
<div class="paragraph">
<p>You can now leverage PingOne user attributes, resolvers, the <strong class="uicontrol">Is Member Of</strong> and <strong class="uicontrol">Is Not Member Of</strong> condition comparators, and <strong class="uicontrol">Connector</strong> service risk signals in policies and rules. Learn more in <a href="https://docs.pingidentity.com/pingone/integrations/p1_policies_published_to_authz_gateways.html" class="xref page">Policies published to Authorize gateways</a>.</p>
</div>
<div class="paragraph">
<p>Service caching TTLs and timeouts for calls to PingOne are now configurable, giving you more control over performance and reliability. Learn more in <a href="https://docs.pingidentity.com/pingone/integrations/p1_service_caching_authz_gateway_instances.html" class="xref page">Service caching and timeouts for Authorize gateway instances</a>.</p>
</div>
</div>
<div class="sect4">
<h5 id="more-granular-control-over-administrator-permissions"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#more-granular-control-over-administrator-permissions"></a>More granular control over administrator permissions</h5>
<div class="paragraph">
<p>The new built-in <strong class="uicontrol">Authorize Gateway Policy Evaluator</strong> role grants least-privilege permissions for reading Authorize gateways and authorization deployments. For more advanced permissions, such as reading user details or evaluating risk scores, you can add custom roles on the new <strong class="uicontrol">Roles</strong> tab. Learn more in <a href="https://docs.pingidentity.com/pingone/integrations/p1_manage_authz_gateway_roles.html" class="xref page">Managing Authorize gateway roles</a>.</p>
</div>
</div>
<div class="sect4">
<h5 id="enhanced-logging"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#enhanced-logging"></a>Enhanced logging</h5>
<div class="paragraph">
<p>All service calls to PingOne are now logged, improving visibility into policy interactions with PingOne, such as user attribute resolution and group membership checks. Learn more about the <code class="codeph">PINGONE_SERVICE_AUDIT</code> log in <a href="https://docs.pingidentity.com/pingone/integrations/p1_logging_authz_gateway_instances.html" class="xref page">Logging for Authorize gateway instances</a>.</p>
</div>
<div class="admonitionblock tip">
<table>
<tbody><tr>
<td class="icon">
<i class="fa icon-tip" title="Tip"></i>
</td>
<td class="content">
<div class="paragraph">
<p>You can find additional release details in <a href="https://docs.pingidentity.com/pingone/integrations/p1_authz_gateway_version_history.html" class="xref page">Authorize gateway version history</a>.</p>
</div>
</td>
</tr>
</tbody></table>
</div>
</div>
<div class="sect4">
<h5 id="end-of-support-notice-2"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#end-of-support-notice-2"></a>End of support notice</h5>
<div class="paragraph">
<p>Support for the previous Authorize gateway version (1.0.0) will end on August 31, 2026. Learn more in <a href="https://docs.pingidentity.com/pingone/integrations/p1_authz_gateway_support_lifecycle.html" class="xref page">Authorize gateway support lifecycle</a>.</p>
</div>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[August 26]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#august-26</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#august-26</guid>
            <pubDate>Tue, 26 Aug 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="support-added-for-rfc-7914-password-encoding-format"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#support-added-for-rfc-7914-password-encoding-format"></a>Support added for RFC 7914 password encoding format</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We now support <a href="https://datatracker.ietf.org/doc/html/rfc7914.html" target="_blank" rel="noopener">RFC 7914</a> for Scrypt password encoding. The RFC-compliant encoding format uses the new  <code class="codeph">SCRYPT_RFC7914</code> identifier to distinguish it from the earlier encoding format using the <code class="codeph">SCRYPT</code> identifier. <code class="codeph">SCRYPT</code> uses the pre-RFC encoding format known as <code class="codeph">c2NyeXB0</code>.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://developer.pingidentity.com/pingone-api/platform/reference/password-encoding.html#scrypt-encoding" target="_blank" rel="noopener">Scrypt</a> in the PingOne API documentation.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[August 19]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#august-19</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#august-19</guid>
            <pubDate>Tue, 19 Aug 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="detection-of-compromised-accounts"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#detection-of-compromised-accounts"></a>Detection of compromised accounts</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne Protect</span></p>
</div>
<div class="paragraph">
<p>The <strong class="uicontrol">User-Based Risk Behavior</strong> predictor now includes an option to have PingOne Protect attempt to detect compromised user accounts and take this into account when calculating the risk level for the predictor.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[August 18]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#august-18</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#august-18</guid>
            <pubDate>Mon, 18 Aug 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="evaluate-all-child-authorization-policies-or-rules"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#evaluate-all-child-authorization-policies-or-rules"></a>Evaluate all child authorization policies or rules</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne Authorize</span></p>
</div>
<div class="paragraph">
<p>By default, combining algorithms stop evaluating once a final decision is reached. The new <strong class="uicontrol">Evaluate All</strong> option overrides this behavior, ensuring that all child policies or rules are evaluated. This is useful for scenarios like fraud control, where full evaluation is required for auditing, analysis, and more precise control over when policy statements are generated, without affecting the final decision.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/authorization_using_pingone_authorize/p1az_combining_algorithm.html" class="xref page">Combining algorithms</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[August 10]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#august-10</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#august-10</guid>
            <pubDate>Sun, 10 Aug 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="passcode-grace-period"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#passcode-grace-period"></a>Passcode grace period</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>To cover time synchronization issues, you can now configure the grace period during which the passcode can still be used even after the passcode has been refreshed. You can find details in <a href="https://docs.pingidentity.com/pingone/applications/p1_edit_application_native.html" class="xref page">Editing an application - Native</a> and <a href="https://docs.pingidentity.com/pingone/strong_authentication_mfa/p1_configuring_pid_mobile_application.html" class="xref page">(Workforce Only) Configuring the PingID mobile application settings</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[July 31]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#july-31</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#july-31</guid>
            <pubDate>Thu, 31 Jul 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="simplified-native-mobile-app-configuration-and-integration"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#simplified-native-mobile-app-configuration-and-integration"></a>Simplified native mobile app configuration and integration</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We’ve enhanced the application configuration and integration process for native mobile applications. The new <strong class="uicontrol">Integrate</strong> tab for native applications provides access to a selection of prefilled code examples, instructions, and sample apps for both iOS and Android. When the required configuration steps are completed for the application, you can select one of the following options in the <strong class="uicontrol">Language/Framework</strong> list on the <strong class="uicontrol">Integrate</strong> tab:</p>
</div>
<div class="ulist">
<ul>
<li>
<p><strong class="uicontrol">iOS - Swift - Embedded Login</strong> (DaVinci)</p>
</li>
<li>
<p><strong class="uicontrol">iOS - Swift - OIDC Direct Login</strong></p>
</li>
<li>
<p><strong class="uicontrol">Android - Kotlin - Embedded Login</strong> (DaVinci)</p>
</li>
<li>
<p><strong class="uicontrol">Android - Kotlin - OIDC Direct Login</strong></p>
</li>
</ul>
</div>
<div class="paragraph">
<p>Each snippet contains the <strong class="uicontrol">Client ID</strong>, <strong class="uicontrol">Redirect URI</strong>, and <strong class="uicontrol">OIDC Discovery Endpoint</strong> for the application, and these values update dynamically when you change the application configuration. Additionally, the instructions for each snippet include links to the relevant SDK tutorials that walk you through the steps to complete the integration.</p>
</div>
<div class="paragraph">
<p>These improvements reduce the risk of copy-paste errors, shorten the time to first sign-on, and encourage a deeper use of DaVinci orchestration by eliminating the need to use custom REST calls.</p>
</div>
<div class="paragraph">
<p>Learn more by going to <strong class="uicontrol">Applications &gt; Applications</strong> in the PingOne admin console, selecting or creating a native application, and clicking the <strong class="uicontrol">Integrate</strong> tab.</p>
</div>
<div class="paragraph">
<p>Learn more about configuring native applications in <a href="https://docs.pingidentity.com/pingone/applications/p1_edit_application_native.html" class="xref page">Editing an application - Native</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[July 27]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#july-27</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#july-27</guid>
            <pubDate>Sun, 27 Jul 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="senders-ui-enhancements"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#senders-ui-enhancements"></a>Senders UI enhancements</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We’ve made some improvements to the <strong class="uicontrol">Senders</strong> UI for clarity and ease of use.
Learn more in <a href="https://docs.pingidentity.com/pingone/settings/p1_sender.html" class="xref page">Senders</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="pingone-mfa-mobile-sdk-1-11-1"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#pingone-mfa-mobile-sdk-1-11-1"></a>PingOne MFA mobile SDK 1.11.1</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>On July 7, we released version 2.1.1 of the PingOne MFA mobile SDK for Android, removing custom support for Certificate Transparency verification, which was unstable and caused communication issues.</p>
</div>
<div class="paragraph">
<p>Because many customers are still using version 1.x of the PingOne MFA mobile SDK, we’ve now also released version 1.11.1 of the SDK, without support for Certificate Transparency verification.</p>
</div>
<div class="paragraph">
<p>You can enable Certificate Transparency verification natively in Android 16 as described in the  <a href="https://developer.android.com/privacy-and-security/security-config#CertificateTransparencySummary">Opt in to certificate transparency</a> section of the Android network security configuration guide.</p>
</div>
<div class="paragraph">
<p>To avoid end-user issues and disruptions, upgrade your apps using version 1.x of the SDK to version 1.11.1 as soon as feasible.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[July 23]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#july-23</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#july-23</guid>
            <pubDate>Wed, 23 Jul 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="conditional-component-visibility-in-pingone-forms"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#conditional-component-visibility-in-pingone-forms"></a>Conditional component visibility in PingOne Forms</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>Conditional component visibility allows you to create a form in PingOne Forms with components that you can configure to be hidden or shown in a user-facing form based on Boolean values pulled from your DaVinci flow. Learn more in <a href="https://docs.pingidentity.com/pingone/user_experience/p1_configuring_conditional_component_visibility.html" class="xref page">Configuring conditional component visibility</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="identifier-first-authentication-enabled-in-administrator-security"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#identifier-first-authentication-enabled-in-administrator-security"></a>Identifier First authentication enabled in Administrator Security</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We’ve updated the Administrator Security settings for the hybrid options (<strong class="uicontrol">PingOne &amp; External IdP</strong> and <strong class="uicontrol">PingID &amp; External IdP</strong>) to enable Identifier First authentication. When enabled, you can identify users before you authenticate them and configure discovery rules that take different authentication actions based on who the user is. Learn more in <a href="https://docs.pingidentity.com/pingone/settings/p1_configure_administrator_security.html" class="xref page">Configuring administrator security</a> and <a href="https://docs.pingidentity.com/pingone/settings/p1_configure_administrator_security_pingid.html" class="xref page">Configuring administrator security - PingID</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[July 16]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#july-16</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#july-16</guid>
            <pubDate>Wed, 16 Jul 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="identity-data-matching"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#identity-data-matching"></a>Identity data matching</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne Verify</span></p>
</div>
<div class="paragraph">
<p>You can now configure <strong class="uicontrol">Identity Data</strong> in your PingOne Verify policy. <strong class="uicontrol">Data Matching</strong> allows you to compare identity data extracted during verification with an identity record. Based on the results of this comparison, you can define policy logic to determine verification outcomes (pass or fail). Learn more in <a href="https://docs.pingidentity.com/pingone/identity_verification_using_pingone_verify/p1_verify_creating_verify_policy.html" class="xref page">Creating a verify policy</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[July 15]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#july-15</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#july-15</guid>
            <pubDate>Tue, 15 Jul 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="support-for-multiple-custom-resources-in-a-single-access-token"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#support-for-multiple-custom-resources-in-a-single-access-token"></a>Support for multiple custom resources in a single access token</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>OIDC-based applications in PingOne can now request an access token to access multiple custom resources in a single request. This capability simplifies the application authentication and authorization process and reduces the number of requests an application must make. Learn more about the <strong class="uicontrol">Request scopes to access multiple resources</strong> option in <a href="https://docs.pingidentity.com/pingone/applications/p1_edit_application_oidc.html" class="xref page">Editing an application - OIDC</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[July 14]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#july-14</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#july-14</guid>
            <pubDate>Mon, 14 Jul 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="support-for-multiple-mfa-policies-2"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#support-for-multiple-mfa-policies-2"></a>Support for multiple MFA policies</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">Strong Authentication</span>
<span class="ping_product">PingID</span></p>
</div>
<div class="paragraph">
<p>PingOne now supports multiple MFA policies for Workforce (PingID) environments.</p>
</div>
<div class="paragraph">
<p>Legacy security key and FIDO2 biometrics authentication methods aren’t supported with multiple MFA policies, so make sure to update any existing MFA policies that don’t yet support FIDO2.
Learn more in <a href="https://docs.pingidentity.com/pingone/strong_authentication_mfa/p1_creating_an_mfa_policy_for_strong_auth.html" class="xref page">Configuring an MFA policy for strong authentication</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="use-of-risk-policies-with-an-mfa-only-license"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#use-of-risk-policies-with-an-mfa-only-license"></a>Use of risk policies with an MFA-only license</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">Strong Authentication</span>
<span class="ping_product">PingID</span>
<span class="ping_product">PingOne Protect</span></p>
</div>
<div class="paragraph">
<p>For administrators with a Workforce (PingID) environment and an MFA-only license, you can now create targeted risk policies for authentication flow types. With an MFA-only license you can use a limited subset of the predictors  available with a full PingOne Protect license. You can also define the applications and user groups to which the risk policy will apply.</p>
</div>
<div class="paragraph">
<p>This feature is available as part of a limited access release to PingID administrators who created a new PingOne environment with PingID enabled, or migrated their PingID account to PingOne. To enroll in the limited access release, contact your Ping Identity representative.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/threat_protection_using_pingone_protect/p1_creating_risk_policies_for_mfa_only.html" class="xref page">Creating a risk policy with an MFA-only license</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[July 9]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#july-9</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#july-9</guid>
            <pubDate>Wed, 09 Jul 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="provisioning-to-zscaler-using-scim"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#provisioning-to-zscaler-using-scim"></a>Provisioning to ZScaler using SCIM</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>You can now use a SCIM connection to enable outbound provisioning from PingOne to a ZScaler ZPA and ZScaler ZIA account. Learn more in <a href="https://docs.pingidentity.com/pingone/integrations/p1_scim_certified_provisioners.html" class="xref page">SCIM certified provisioners</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[July 8]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#july-8</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#july-8</guid>
            <pubDate>Tue, 08 Jul 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="using-expressions-to-retrieve-microsoft-entra-attributes"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#using-expressions-to-retrieve-microsoft-entra-attributes"></a>Using expressions to retrieve Microsoft Entra attributes</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>PingOne supports using expressions to retrieve additional attributes from Microsoft Entra when <a href="https://docs.pingidentity.com/pingone/integrations/p1_add_idp_microsoft.html" class="xref page">Microsoft is configured as an identity provider in PingOne</a>. PingOne now supports three types of Microsoft Entra attributes:</p>
</div>
<div class="ulist">
<ul>
<li>
<p>Extension attributes</p>
</li>
<li>
<p>Directory extensions</p>
</li>
<li>
<p>Schema extensions</p>
</li>
</ul>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/pingone_expression_language/p1_expressionlang_expressions_concatenation.html#p1-expressions-microsoft" class="xref page">Using expressions to retrieve Microsoft Entra attributes</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[July 7]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#july-7</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#july-7</guid>
            <pubDate>Mon, 07 Jul 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="targeted-risk-policies"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#targeted-risk-policies"></a>Targeted risk policies</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne Protect</span></p>
</div>
<div class="paragraph">
<p>You can now create targeted risk policies with PingOne Protect to define risk policies for different targets, including flow types, applications being accessed, and user groups to which the risk policy will apply. During risk evaluations, PingOne Protect evaluates targeted policies in the order displayed in the <strong class="uicontrol">Targeted Policies</strong> list until the target criteria are met for a policy. Learn more in <a href="https://docs.pingidentity.com/pingone/threat_protection_using_pingone_protect/p1_protect_adding_risk_policy.html" class="xref page">Adding a risk policy</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="mitigations-in-risk-policies"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#mitigations-in-risk-policies"></a>Mitigations in risk policies</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne Protect</span></p>
</div>
<div class="paragraph">
<p>PingOne Protect now supports adding mitigations to risk policies. A mitigation is an action that you recommend if a given condition is met, such as deny access if a certain predictor returns high risk. When the condition is met, the recommended action you created is returned in the risk evaluation response. Learn more in <a href="https://docs.pingidentity.com/pingone/threat_protection_using_pingone_protect/p1_protect_adding_risk_policy.html" class="xref page">Adding a risk policy</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="external-applications"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#external-applications"></a>External applications</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>The <strong class="uicontrol">Application Portal</strong> page has been renamed <strong class="uicontrol">External Applications</strong>. You can now use the page also to define applications that you don’t want to include in the application portal but want to include in contexts such as targeted risk policies. Learn more in <a href="https://docs.pingidentity.com/pingone/applications/p1_external_applications.html" class="xref page">External applications</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="pingone-mfa-mobile-sdk-2-1-1"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#pingone-mfa-mobile-sdk-2-1-1"></a>PingOne MFA mobile SDK 2.1.1</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>We’ve released version 2.1.1 of the PingOne MFA mobile SDK. This version includes the following features and enhancements:</p>
</div>
<div class="sect4">
<h5 id="android-2"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#android-2"></a>Android</h5>
<div class="paragraph">
<p>Removed custom support for Certificate Transparency verification, which was unstable and caused communication issues. Certificate Transparency verification can now be enabled natively in Android 16 as described in the   <a href="https://developer.android.com/privacy-and-security/security-config#CertificateTransparencySummary">Opt in to certificate transparency</a> section of the Android network security configuration guide.</p>
</div>
<div class="paragraph">
<p>To avoid end user issues and disruptions, it is highly recommended that app owners upgrade to this version of the SDK as soon as feasible.</p>
</div>
</div>
<div class="sect4">
<h5 id="ios-2"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#ios-2"></a>iOS:</h5>
<div class="paragraph">
<p>Fixed an issue that was causing pairing of devices to fail in PingOne’s Australia and Canada regions.</p>
</div>
<div class="paragraph">
<p>Learn more in the documentation for the <a href="https://github.com/pingidentity/pingone-mobile-sdk-android/blob/master/release-notes.md">Android</a> and <a href="https://github.com/pingidentity/pingone-mobile-sdk-ios/blob/master/release-notes.md">iOS</a> versions.</p>
</div>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[July 3]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#july-3</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#july-3</guid>
            <pubDate>Thu, 03 Jul 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="new-pingone-verify-settings-available-in-themes"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#new-pingone-verify-settings-available-in-themes"></a>New PingOne Verify settings available in themes</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>You can now update the appearance of the image on your identity verification pages to better match your company styles and branding. Learn more in <a href="https://docs.pingidentity.com/pingone/user_experience/p1_branding_themes.html" class="xref page">Branding and Themes</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[July 2]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#july-2</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#july-2</guid>
            <pubDate>Wed, 02 Jul 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="updated-ui-for-branding-and-themes"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#updated-ui-for-branding-and-themes"></a>Updated UI for Branding and Themes</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We’ve updated the <strong class="uicontrol">Branding and Themes</strong> UI with a new look and feel for a more streamlined experience. This new UI includes search and sort capabilities that make it easier to find the theme you need. It also lets you preview the appearance of your PingOne forms when you switch themes or update theme properties. Learn more in <a href="https://docs.pingidentity.com/pingone/user_experience/p1_branding_themes.html" class="xref page">Branding and Themes</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[July 1]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#july-1</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#july-1</guid>
            <pubDate>Tue, 01 Jul 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="new-help-desk-admin-role-added"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#new-help-desk-admin-role-added"></a>New Help Desk Admin role added</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We’ve created the <strong class="uicontrol">Help Desk Admin</strong> role to delegate access for helping end users authenticate with PingOne. Administrators with this role can manage MFA methods and devices for users and reset passwords. This role can be assigned at the environment or population level. Learn more in <a href="https://docs.pingidentity.com/pingone/directory/p1_roles.html#_built_in_pingone_administrator_roles" class="xref page">Built-in PingOne administrator roles</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[June 30]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#june-30</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#june-30</guid>
            <pubDate>Mon, 30 Jun 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="new-singapore-domain"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#new-singapore-domain"></a>New Singapore domain</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We’ve expanded to add a new data residency region for Singapore. Customers can now register new PingOne organizations with data residency and processing contained within Singapore. These organizations will use the new .sg domain name. Learn more about regional domains in <a href="https://docs.pingidentity.com/pingone/introduction_to_pingone/p1_introduction.html#p1-organizations" class="xref page">Organizations</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[June 25]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#june-25</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#june-25</guid>
            <pubDate>Wed, 25 Jun 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="oidc-session-management"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#oidc-session-management"></a>OIDC session management</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>PingOne now supports OpenID Connect (OIDC) session management, allowing OIDC-based applications in the same browser mode to monitor the user session status. When enabled, PingOne includes the <code class="parmname">session_state</code> parameter in its authorization response with the session status, such as <code class="codeph">unchanged</code>, <code class="codeph">changed</code>, or <code class="codeph">error</code>. Learn more about OIDC session management in <a href="https://docs.pingidentity.com/pingone/applications/p1_edit_application_oidc.html" class="xref page">Editing an application - OIDC</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[June 22]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#june-22</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#june-22</guid>
            <pubDate>Sun, 22 Jun 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="pingone-mfa-mobile-sdk-2-1"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#pingone-mfa-mobile-sdk-2-1"></a>PingOne MFA mobile SDK 2.1</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>We’ve released version 2.1 of the PingOne MFA mobile SDK. This version includes the following features and enhancements:</p>
</div>
<div class="ulist">
<ul>
<li>
<p>Security enhancements</p>
</li>
<li>
<p>Bug fixes</p>
</li>
<li>
<p>Support for the new Singapore PingOne region</p>
</li>
<li>
<p>When developing apps with the MFA SDK, you now need to use version 1.8.1 or later of the SDK.</p>
</li>
<li>
<p>In the iOS version of the SDK, the <code class="codeph">setDevicePairedAfterReinstall</code> method has been deprecated.</p>
</li>
</ul>
</div>
<div class="paragraph">
<p>Learn more in the documentation for the <a href="https://github.com/pingidentity/pingone-mobile-sdk-android/blob/master/release-notes.md">Android version</a> and the documentation for the <a href="https://github.com/pingidentity/pingone-mobile-sdk-ios/blob/master/release-notes.md">iOS version</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[June 17]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#june-17</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#june-17</guid>
            <pubDate>Tue, 17 Jun 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="pingone-notifications-twilio-verify"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#pingone-notifications-twilio-verify"></a>PingOne Notifications - Twilio Verify</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>You can now use Twilio Verify for sending PingOne notifications. Learn more in <a href="https://docs.pingidentity.com/pingone/settings/p1_using_twilio_verify_for_notifications.html" class="xref page">Using Twilio Verify with PingOne</a> and in <a href="https://developer.pingidentity.com/pingone-api/platform/notifications/phone-delivery-settings.html" target="_blank" rel="noopener">Phone Delivery Settings</a> in the PingOne developer documentation.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[June 12]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#june-12</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#june-12</guid>
            <pubDate>Thu, 12 Jun 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="ability-to-delete-translatable-keys-for-language-management"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#ability-to-delete-translatable-keys-for-language-management"></a>Ability to delete translatable keys for language management</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>In addition to creating and updating key-value pairs, PingOne <strong class="uicontrol">Languages</strong> now includes the ability to delete unwanted or unused keys for a language. Learn more in <a href="https://docs.pingidentity.com/pingone/user_experience/p1_deleting_transtatable_keys.html" class="xref page">Deleting translatable keys</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[June 4]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#june-4</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#june-4</guid>
            <pubDate>Wed, 04 Jun 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="signals-pingone-protect-sdk-new-version-for-web"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#signals-pingone-protect-sdk-new-version-for-web"></a>Signals (PingOne Protect) SDK - new version for web</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne Protect SDK</span></p>
</div>
<div class="paragraph">
<p>We’ve released a new version of the Signals (PingOne Protect) SDK for web, 5.6.0. You can find details in the <a href="https://developer.pingidentity.com/pingone-api/native-sdks/pingone-risk-sdks/protect_sdk_changelog.html" target="_blank" rel="noopener">SDK Changelog</a> in the PingOne developer documentation.</p>
</div>
</div>
<div class="sect3">
<h4 id="multi-factor-authentication-enforced-for-all-access-to-the-admin-console"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#multi-factor-authentication-enforced-for-all-access-to-the-admin-console"></a>Multi-factor authentication enforced for all access to the admin console</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>Per announcements earlier this year, and as part of our continued efforts to support best practice security measures in PingOne, multi-factor authentication (MFA) is now required for all administrators accessing the PingOne admin console. Learn more about configuration options for administrator security in <a href="https://docs.pingidentity.com/pingone/settings/p1_administrator_security.html" class="xref page">Administrator security</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[June 3]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#june-3</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#june-3</guid>
            <pubDate>Tue, 03 Jun 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="virtual-server-ids-for-saml-applications"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#virtual-server-ids-for-saml-applications"></a>Virtual server IDs for SAML applications</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>You can now add custom virtual server IDs to SAML applications. This new capability allows you to identify your server differently when connecting to the same SAML application in various scenarios, such as from different environments or for different populations. Virtual server IDs also provide configuration flexibility and added protection against unauthorized access. Learn more in <a href="https://docs.pingidentity.com/pingone/applications/p1_edit_application_saml.html" class="xref page">Editing an application - SAML</a> and <a href="https://docs.pingidentity.com/pingone/applications/p1_virtual_server_ids_saml_apps.html" class="xref page">Virtual server IDs for SAML applications</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="configure-the-one-time-passcode-otp-length-for-workforce-use-cases"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#configure-the-one-time-passcode-otp-length-for-workforce-use-cases"></a>Configure the one-time passcode (OTP) length for Workforce use cases</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">Strong Authentication</span>
<span class="ping_product">PingID</span></p>
</div>
<div class="paragraph">
<p>You can now configure the length of the one-time passcode for Email, SMS, and Voice authentication methods in workforce use cases (PingID).</p>
</div>
<div class="paragraph">
<p>This feature was previously only available for customer use cases.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/strong_authentication_mfa/p1_creating_an_mfa_policy_for_strong_auth.html" class="xref page">Configuring an MFA policy for strong authentication</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[May 28]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#may-28</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#may-28</guid>
            <pubDate>Wed, 28 May 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="sms-notifications-for-users-in-china"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#sms-notifications-for-users-in-china"></a>SMS notifications for users in China</h4>
<div class="paragraph">
<p><span class="ping_changetype-info">Info</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>To adjust to regulatory changes, SMS notifications sent with the default Ping server to users in China now use the Twilio SMS template.</p>
</div>
<div class="paragraph">
<p>If you use the Ping server for sending PingOne SMS notifications, your users in China will now see notifications branded with Twilio’s name rather than Ping Identity.</p>
</div>
</div>
<div class="sect3">
<h4 id="major-update-to-pingone-forms"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#major-update-to-pingone-forms"></a>Major update to PingOne Forms</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span>
<span class="ping_product">DaVinci</span></p>
</div>
<div class="sect4">
<h5 id="new-form-templates"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#new-form-templates"></a>New form templates</h5>
<div class="paragraph">
<p>When you create a form in PingOne, there are now 18 templates to get you started. The following 11 templates have been added:</p>
</div>
<div class="ulist">
<ul>
<li>
<p>Two new MFA Device Selection templates. These templates prompt the user to select an MFA method to set up or authenticate with. Powered by your MFA policy.</p>
</li>
<li>
<p>Six new OTP Prompt templates. These templates present a UI for a user to register or authenticate with a one-time passcode (OTP) using email, text message, or voice call. The templates allow you to include the user’s phone number or email address as dynamic text and link to a passcode resend branch in your flow.</p>
</li>
<li>
<p>Two new Authenticator App Prompt templates. These templates prompt the user to scan a QR code to set up or authenticate with a TOTP authenticator app.</p>
</li>
<li>
<p>One new Magic Link Prompt template. This template prompts the user to click a magic link received by email.</p>
</li>
</ul>
</div>
</div>
<div class="sect4">
<h5 id="new-components"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#new-components"></a>New components</h5>
<div class="paragraph">
<p>The following seven components have been added to the form builder:</p>
</div>
<div class="ulist">
<ul>
<li>
<p>Fields</p>
<div class="ulist">
<ul>
<li>
<p><strong class="uicontrol">Checkbox</strong>: Show a single checkbox with a rich text label. This component allows you to link to an externally hosted Terms and Conditions document.</p>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/user_experience/p1_form_configuration.html" class="xref page">Form configuration</a>.</p>
</div>
</li>
</ul>
</div>
</li>
<li>
<p>Toolbox</p>
<div class="ulist">
<ul>
<li>
<p><strong class="uicontrol">Agreements</strong>: Show the title and full body text of a PingOne agreement.</p>
</li>
<li>
<p><strong class="uicontrol">Phone number input</strong>: Prompt a user to select a country code and enter their phone number.</p>
</li>
<li>
<p><strong class="uicontrol">Polling</strong>: Show a spinner or animated dots and enable Polling and Challenge controls in the Show Form node. Loop the flow or pause on this form while another branch of the flow finishes.</p>
</li>
<li>
<p><strong class="uicontrol">QR code</strong>: Show a scannable QR code that contains a value from your DaVinci flow, with optional human-friendly fallback text.</p>
</li>
<li>
<p><strong class="uicontrol">MFA Device Selection - Registration and Authentication</strong>: Prompt the user to select an MFA method to set up or authenticate with. Powered by your MFA policy.</p>
</li>
<li>
<p><strong class="uicontrol">FIDO2</strong>: Prompt a user to set up or authenticate with a FIDO2 authentication method, such as biometrics or a security key.</p>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/user_experience/p1_form_configuration.html" class="xref page">Form configuration</a>.</p>
</div>
</li>
</ul>
</div>
</li>
</ul>
</div>
</div>
<div class="sect4">
<h5 id="improved-components"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#improved-components"></a>Improved components</h5>
<div class="ulist">
<ul>
<li>
<p><strong class="uicontrol">Translatable Rich Text</strong>: You can now select an icon to show with your rich text.</p>
</li>
<li>
<p><strong class="uicontrol">Submit Button</strong>: You can now remove the <strong class="uicontrol">Submit Button</strong> to make room for a different submit method, such as MFA Device Selection, Polling, or FIDO2. Only one submit method is allowed per form.</p>
</li>
<li>
<p><strong class="uicontrol">Submit Button</strong>, <strong class="uicontrol">Flow Button</strong>, and <strong class="uicontrol">Flow Link</strong>: Enabling <strong class="uicontrol">Override Default Styles</strong> doesn’t affect the look of your form until you change a value. You can also override some colors while keeping others linked to the theme.</p>
</li>
</ul>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/user_experience/p1_form_configuration.html" class="xref page">Form configuration</a>.</p>
</div>
</div>
<div class="sect4">
<h5 id="new-features"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#new-features"></a>New features</h5>
<div class="paragraph">
<p>PingOne Forms now supports dynamic text in the <strong class="uicontrol">Translatable Rich Text</strong> component and field labels. This update allows you to take a value from your DaVinci flow, such as the user’s first name, and show it in the form as read-only text or target for a hyperlink. Learn more in <a href="https://docs.pingidentity.com/pingone/user_experience/p1_using_dynamic_text.html" class="xref page">Using dynamic text</a>.</p>
</div>
</div>
<div class="sect4">
<h5 id="other-improvements"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#other-improvements"></a>Other improvements</h5>
<div class="paragraph">
<p>We’ve improved the order and grouping of PingOne attributes on the <strong class="uicontrol">Fields</strong> tab.</p>
</div>
</div>
<div class="sect4">
<h5 id="changes-to-the-form-connectors-show-form-node"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#changes-to-the-form-connectors-show-form-node"></a>Changes to the Form connector’s <strong class="uicontrol">Show Form</strong> node</h5>
<div class="ulist">
<ul>
<li>
<p>We’ve added direct links to the <strong class="uicontrol">Forms</strong> and <strong class="uicontrol">Branding and Themes</strong> sections of the PingOne admin console.</p>
</li>
<li>
<p>We’ve renamed the <strong class="uicontrol">Pre-Populate Field Values</strong> table to <strong class="uicontrol">Initial Field Values</strong> and removed the unnecessary heading with the add and edit buttons.</p>
</li>
<li>
<p>We’ve added a <strong class="uicontrol">Dynamic Text</strong> table. This lets you populate dynamic text with a value from your flow.</p>
</li>
<li>
<p>We’ve added properties to support the new components.</p>
</li>
</ul>
</div>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[May 27]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#may-27</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#may-27</guid>
            <pubDate>Tue, 27 May 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="sign-off-method-for-application-portal-and-self-service-myaccount-app"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#sign-off-method-for-application-portal-and-self-service-myaccount-app"></a>Sign-off method for application portal and self-service (MyAccount app)</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span>
<span class="ping_product">PingOne SSO</span></p>
</div>
<div class="paragraph 2025-05-07T12:00:00Z">
<p>You can now choose the sign-off method PingOne uses when end users sign off from the application portal and the PingOne Self-Service - MyAccount app. You can select either <strong class="uicontrol">OIDC Logout</strong> or <strong class="uicontrol">SAML 2.0 Single Logout</strong> on the following pages in PingOne:</p>
</div>
<div class="ulist">
<ul>
<li>
<p><strong class="uicontrol">Applications &gt; External Applications</strong>: Learn more in <a href="https://docs.pingidentity.com/pingone/applications/p1_configuring_the_application_portal.html" class="xref page">Configuring the application portal</a>.</p>
</li>
<li>
<p><strong class="uicontrol">User Experience &gt; Self Service</strong>: Learn more in <a href="https://docs.pingidentity.com/pingone/user_experience/p1_configure_self_service.html" class="xref page">Configuring the Self Service portal end-user experience</a>.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="saml-2-0-slo-support-with-the-pingone-authentication-connector"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#saml-2-0-slo-support-with-the-pingone-authentication-connector"></a>SAML 2.0 SLO support with the PingOne Authentication connector</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span>
<span class="ping_product">PingOne SSO</span>
<span class="ping_product">DaVinci</span></p>
</div>
<div class="paragraph">
<p>PingOne now supports SAML 2.0 single logout (SLO) from identity providers (IdPs) configured as part of a DaVinci flow using the PingOne Authentication connector. End users can now sign off from IdPs through SAML 2.0 SLO for flows configured using the Sign On with External Identity Provider capability from the PingOne Authentication connector. Learn more about SAML 2.0 SLO in <a href="https://docs.pingidentity.com/pingone/applications/p1_saml_2_0_slo.html" class="xref page">Applications</a> and <a href="https://docs.pingidentity.com/pingone/integrations/p1_saml_slo_externalidp.html" class="xref page">External IdPs</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[May 20]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#may-20</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#may-20</guid>
            <pubDate>Tue, 20 May 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="mfa-with-multiple-authentication-policies"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#mfa-with-multiple-authentication-policies"></a>MFA with multiple authentication policies</h4>
<div class="paragraph">
<p><span class="ping_changetype-info">Info</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>To enhance security, in cases where multiple authentication policies are defined for accessing an application, PingOne no longer proceeds to the next authentication policy if a user has an MFA device that is unreachable, locked, or blocked.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[May 16]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#may-16</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#may-16</guid>
            <pubDate>Fri, 16 May 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="verify-users-in-india-with-aadhaar-verification-using-pingone-verify-policies"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#verify-users-in-india-with-aadhaar-verification-using-pingone-verify-policies"></a>Verify users in India with Aadhaar verification using PingOne Verify policies</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne Verify</span></p>
</div>
<div class="paragraph">
<p>You can now verify users in India using PingOne Verify policies. Indian residents are issued an Aadhaar ID, which is a 12-digit identification number. When you configure Aadhaar verification in PingOne Verify policies, PingOne Verify gains the ability to directly integrate with India’s Aadhaar National Registry. Learn more in <a href="https://docs.pingidentity.com/pingone/identity_verification_using_pingone_verify/p1_verify_creating_verify_policy.html" class="xref page">Creating a verify policy</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[May 13]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#may-13</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#may-13</guid>
            <pubDate>Tue, 13 May 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="fido-attestation-improvements"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#fido-attestation-improvements"></a>FIDO Attestation improvements</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">Strong Authentication</span>
<span class="ping_product">PingID</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>The following improvements are now available in FIDO2 policy:</p>
</div>
<div class="openblock">
<div class="content">
<div class="ulist">
<ul>
<li>
<p>Add enterprise attestation</p>
<div class="paragraph">
<p>You can now verify that a device is an Enterprise FIDO device. You can also check that the device matches the serial number configured for the user.</p>
</div>
</li>
<li>
<p>Additional User Display Name attributes</p>
<div class="paragraph">
<p>You can now include the <strong class="uicontrol">Environment Name</strong> and <strong class="uicontrol">Organization name</strong> with the <strong class="uicontrol">User Display Name</strong>.  This information displays when a user registers their FIDO device.</p>
</div>
</li>
</ul>
</div>
</div>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/authentication/p1_creating_a_fido_policy.html" class="xref page">Adding a FIDO policy</a></p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[May 12]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#may-12</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#may-12</guid>
            <pubDate>Mon, 12 May 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="use-of-short-codes-for-pingone-sms-notifications-united-states-and-canada"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#use-of-short-codes-for-pingone-sms-notifications-united-states-and-canada"></a>Use of short codes for PingOne SMS notifications - United States and Canada</h4>
<div class="paragraph">
<p><span class="ping_changetype-info">Info</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>To improve delivery reliability for PingOne SMS notifications sent with the default Ping server, the use of short codes has been expanded.</p>
</div>
<div class="paragraph">
<p>If you use the Ping server for sending PingOne SMS notifications, and you haven’t customized notification content, your users in the United States and Canada might see notifications coming from a different number than previously.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[May 11]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#may-11</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#may-11</guid>
            <pubDate>Sun, 11 May 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="oath-token-authentication-for-customer-use-cases"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#oath-token-authentication-for-customer-use-cases"></a>OATH token authentication for customer use cases</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">Strong Authentication</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>OATH token authentication is now available for customer (PingOne MFA) use cases.
Learn more in <a href="https://docs.pingidentity.com/pingone/strong_authentication_mfa/p1_pid_oath_tokens.html" class="xref page">Configuring OATH token authentication</a></p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[May 7]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#may-7</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#may-7</guid>
            <pubDate>Wed, 07 May 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="administrator-security-enhancements"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#administrator-security-enhancements"></a>Administrator Security enhancements</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We’ve added a new <strong class="uicontrol">Limit MFA to specific populations</strong> setting for environments using the <strong class="uicontrol">PingOne &amp; External IdP</strong> option for Administrator Security. If you select this option, you can select specific populations that will require secondary authentication through PingOne after the initial authentication with the IdP. Users in populations that are not selected will authenticate only once, through the IdP. Learn more in <a href="https://docs.pingidentity.com/pingone/settings/p1_configure_administrator_security.html" class="xref page">Configuring administrator security</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[May 1]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#may-1</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#may-1</guid>
            <pubDate>Thu, 01 May 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="invite-administrators-to-register-with-pingone"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#invite-administrators-to-register-with-pingone"></a>Invite administrators to register with PingOne</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>You can now invite other administrators to register for PingOne. To use this feature, you must use PingOne as your identity provider, have <a href="https://docs.pingidentity.com/pingone/settings/p1_administrator_security.html" class="xref page">administrator security</a> enabled with PingOne or a hybrid authentication source, and have the appropriate permissions.</p>
</div>
<div class="paragraph">
<p>In the invitation, provide their first and last name, their email address,
and specify the administrator roles that you want the administrator to have.
You can also set an expiration time on the invitation.
The maximum time allowed is 24 hours.</p>
</div>
<div class="paragraph">
<p>The new administrators receive an email indicating that they were added as an administrator in PingOne.
The email contains a registration link and instructs them to click the link, copy the invite code,
paste it into the appropriate field, and create a password to complete the registration process.</p>
</div>
<div class="paragraph">
<p>Learn more about this process
in <a href="https://docs.pingidentity.com/pingone/getting_started_with_pingone/p1_manage_administrators.html#invite_admin" class="xref page">Inviting administrators to register</a>
and <a href="https://docs.pingidentity.com/pingone/getting_started_with_pingone/p1_manage_administrators.html#accept_invitation" class="xref page">Accepting the administrator account registration</a>.</p>
</div>
<div class="paragraph">
<p>The PingOne administrator <strong class="uicontrol">Getting Started</strong> experience has also been updated and now includes this functionality.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[April 30]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#april-30</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#april-30</guid>
            <pubDate>Mon, 30 Apr 2001 23:23:59 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="production-environment-deletion-protection"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#production-environment-deletion-protection"></a>Production environment deletion protection</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>Production environments can now be deleted, but the environment will be in a recoverable state for 30 days before it is permanently deleted. Sandbox environments are still deleted immediately and are not recoverable. Additionally, you can promote Sandbox environments to Production, but you can no longer demote Production environments to Sandbox.</p>
</div>
<div class="admonitionblock bp">
<table>
<tbody><tr>
<td class="icon">
<i class="fa icon-bp" title="Best practice"></i>
</td>
<td class="content">
<div class="paragraph">
<p>Any Sandbox environment containing production resources or used for production purposes should be promoted to Production to prevent accidental deletion.</p>
</div>
</td>
</tr>
</tbody></table>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/introduction_to_pingone/p1_introduction.html#p1-env-types" class="xref page">Sandbox and Production environments</a>, <a href="https://docs.pingidentity.com/pingone/settings/p1_deleteenvironment.html" class="xref page">Deleting an environment</a>, and <a href="https://docs.pingidentity.com/pingone/settings/p1_recover_deleted_production_environment.html" class="xref page">Recovering a deleted Production environment</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[April 29]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#april-29</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#april-29</guid>
            <pubDate>Tue, 29 Apr 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="support-for-microsoft-entra-id-external-mfa-with-pingone-pingid-and-davinci"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#support-for-microsoft-entra-id-external-mfa-with-pingone-pingid-and-davinci"></a>Support for Microsoft Entra ID external MFA with PingOne, PingID, and DaVinci</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne SSO</span>
<span class="ping_product">DaVinci</span>
<span class="ping_product">PingID</span></p>
</div>
<div class="paragraph">
<p><a href="https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-authentication-external-method-manage" target="_blank" rel="noopener">External multi-factor authentication (MFA)</a> allows Microsoft Entra ID users to leverage external authentication providers for MFA. You can now use DaVinci with PingOne SSO and PingID to configure external MFA, formerly known as an external authentication method (EAM), for Entra ID. Learn more in <a href="https://docs.pingidentity.com/pingone/use_cases/p1_set_up_external_mfa_provider_microsoft_entra_davinci.html" class="xref page">Setting up PingOne SSO, DaVinci, and PingID as the external MFA provider for Microsoft Entra ID</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[April 28]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#april-28</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#april-28</guid>
            <pubDate>Mon, 28 Apr 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="whatsapp-as-an-authentication-method"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#whatsapp-as-an-authentication-method"></a>WhatsApp as an authentication method</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">Strong Authentication</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>You can now enable and configure WhatsApp as an authentication so that your users can receive a one-time passcode (OTP) by WhatsApp message.</p>
</div>
<div class="paragraph">
<p>This authentication method is available for customer (PingOne MFA) use cases only, and requires you to have your own WhatsApp Business Account.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/strong_authentication_mfa/p1-strong-auth_whatsapp.html" class="xref page">Configuring WhatsApp authentication</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="define-cooldown-period-for-sending-notifications"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#define-cooldown-period-for-sending-notifications"></a>Define cooldown period for sending notifications</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">Strong Authentication</span>
<span class="ping_product">PingOne MFA</span>
<span class="ping_product">PingID</span></p>
</div>
<div class="paragraph">
<p>To prevent the malicious use of notifications, you can now define a notification cooldown period during which the user must wait before sending another notification.
You can define notification cooldown periods for WhatsApp, Email, and  SMS/Voice notifications.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/user_experience/p1_creating_a_notification_policy.html" class="xref page">Notification Policies</a></p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[April 24]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#april-24</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#april-24</guid>
            <pubDate>Thu, 24 Apr 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="administrator-roles-ui-enhancements"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#administrator-roles-ui-enhancements"></a>Administrator Roles UI enhancements</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>The roles on the <strong class="uicontrol">Built-In Roles</strong> tab of the <strong class="uicontrol">Administrator Roles</strong> page are now organized into categories that clearly separate the roles used for single sign-on to other Ping products from the main PingOne roles. These categories are also used throughout the UI to simplify role assignment. Learn more in <a href="https://docs.pingidentity.com/pingone/directory/p1_roles.html" class="xref page">Administrator Roles</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="skip-account-lock-verification-during-authentication"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#skip-account-lock-verification-during-authentication"></a>Skip account lock verification during authentication</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">Strong Authentication</span>
<span class="ping_product">PingOne MFA</span>
<span class="ping_product">PingID</span></p>
</div>
<div class="paragraph">
<p>We’ve added the ability to skip account lock validation when applying an MFA policy.
Learn more in <a href="https://docs.pingidentity.com/pingone/strong_authentication_mfa/p1_creating_an_mfa_policy_for_strong_auth.html" class="xref page">Configuring an MFA policy for strong authentication</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[April 22]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#april-22</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#april-22</guid>
            <pubDate>Tue, 22 Apr 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="support-for-x5t-header-parameter-in-oidc-applications"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#support-for-x5t-header-parameter-in-oidc-applications"></a>Support for <code class="parmname">x5t</code> header parameter in OIDC applications</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>PingOne can now include the <code class="parmname">x5t</code> header parameter in access tokens, ID tokens, and JSON Web Token (JWT)-based refresh tokens for OIDC-based applications. This new capabiliity improves interoperability with applications, custom resources, or both that require the <code class="parmname">x5t</code> parameter in the digital signature verification process. Learn more in <a href="https://docs.pingidentity.com/pingone/applications/p1_edit_application_oidc.html" class="xref page">Editing an application - OIDC</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[April 11]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#april-11</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#april-11</guid>
            <pubDate>Fri, 11 Apr 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="amazon-web-services-integration-kit-1-4-0"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#amazon-web-services-integration-kit-1-4-0"></a>Amazon Web Services integration kit 1.4.0</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne Authorize</span></p>
</div>
<div class="paragraph">
<p>We’ve released version 1.4.0 of the Amazon Web Services integration kit. Now you can extend Amazon CloudFront’s authorization capabilities by deploying the integration kit as a Lambda@Edge function. Integrating PingOne Authorize with CloudFront enables optimized content delivery and globally distributed access control of web applications and APIs. Learn more in <a href="https://docs.pingidentity.com/pingone/authorization_using_pingone_authorize/p1az_configuring_cloudfront_lambda_edge.html" class="xref page">Configuring Amazon CloudFront</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[April 10]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#april-10</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#april-10</guid>
            <pubDate>Thu, 10 Apr 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="improvements-to-pingid-ootb-registration-and-authentication-davinci-flows"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#improvements-to-pingid-ootb-registration-and-authentication-davinci-flows"></a>Improvements to PingID OOTB Registration and Authentication DaVinci flows</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">Strong Authentication</span>
<span class="ping_product">PingID</span></p>
</div>
<div class="paragraph">
<p>PingID out-of-the-box (OOTB) registration and authentication flows in DaVinci have been expanded to include:</p>
</div>
<div class="ulist">
<ul>
<li>
<p><strong>FIDO2 (Passkey) support</strong>: FIDO2 device authentication is now supported.</p>
</li>
<li>
<p><strong>Rename device during pairing</strong>: The ability for users to specify a nickname for a device during pairing is now supported for PingID.</p>
</li>
<li>
<p><strong>PingOne branding support</strong>: PingOne branding and themes are now supported.</p>
</li>
<li>
<p><strong>Customizable Settings button</strong>: The MyAccount <strong class="uicontrol">Settings</strong> button is now supported. The Settings URL now points to the MyAccount URL and can be customized in the Flow settings if required.</p>
</li>
<li>
<p><strong>Define self-enrollment behavior</strong>: Admins can now choose whether users with no paired devices are directed to the registration screen or blocked from registering until they access their MyAccount or MyDevices page. This is defined in the DaVinci Flow settings for the relevant flow.</p>
</li>
<li>
<p><strong>OATH resync flow support</strong>: The OATH resync flow isn’t supported for OOTB PingID registration and authentication flows.</p>
</li>
<li>
<p><strong>Error screen improvements</strong>: Improvements to the error screens are now included in the OOTB PingID registration and authentication DaVinci flows.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[April 9]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#april-9-2</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#april-9-2</guid>
            <pubDate>Wed, 09 Apr 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="updated-ui-for-external-idps"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#updated-ui-for-external-idps"></a>Updated UI for External IdPs</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We modernized <strong class="wintitle">External IdPs</strong> in PingOne with a new look and feel. Learn more in <a href="https://docs.pingidentity.com/pingone/integrations/p1_external_idps.html" class="xref page">External IdPs</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[April 2]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#april-2-2</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#april-2-2</guid>
            <pubDate>Wed, 02 Apr 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="early-access-opt-in-for-new-features"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#early-access-opt-in-for-new-features"></a>Early access opt in for new features</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>You can now try out new PingOne features before they’re released and provide feedback directly to Ping from the admin console. You decide which features to enable during the early access period and the environments in which to enable them. You can also opt out of a previously enabled feature during the early access period. Learn more in <a href="https://docs.pingidentity.com/pingone/settings/p1_managing_opt_ins_for_ea_features.html" class="xref page">Managing opt-ins for early access features in PingOne</a> and <a href="https://docs.pingidentity.com/pingone/early-access-features/p1_early_access_features.html" class="xref page">PingOne Early Access Features</a>.</p>
</div>
<div class="admonitionblock note">
<table>
<tbody><tr>
<td class="icon">
<i class="fa icon-note" title="Note"></i>
</td>
<td class="content">
<div class="paragraph">
<p>Not all features will be available for early access. Early access feature availability is determined by Ping, and the features you can enable are dependent on a number of factors including licensing, environment configuration, and administrator permissions. All released features are enabled at GA. You can’t opt in or out of released features.</p>
</div>
</td>
</tr>
</tbody></table>
</div>
</div>
<div class="sect3">
<h4 id="pingone-mfa-mobile-sdk-2-0"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#pingone-mfa-mobile-sdk-2-0"></a>PingOne MFA mobile SDK 2.0</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>We’ve released version 2.0 of the PingOne MFA mobile SDK. This version includes the following features and enhancements:</p>
</div>
<div class="ulist">
<ul>
<li>
<p>You can now require users to carry out number matching when authenticating.</p>
</li>
<li>
<p>Apps can now be configured so the same device can be paired in multiple geographic regions.</p>
</li>
<li>
<p>Using the PingOne API, you can now cancel an authentication that has already begun. This option can be used for situations where the user wants to change to a different authentication device.</p>
</li>
</ul>
</div>
<div class="paragraph">
<p>Learn more in the documentation for the <a href="https://github.com/pingidentity/pingone-mobile-sdk-android/blob/master/release-notes.md">Android version</a> and the documentation for the <a href="https://github.com/pingidentity/pingone-mobile-sdk-ios/blob/master/release-notes.md">iOS version</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="authentication-using-number-matching"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#authentication-using-number-matching"></a>Authentication using number matching</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>You can now specify that a mobile push requires the user to match a number that they were shown when requesting access.
When you enable this option, you can have users select the correct number from a group of three numbers,
or you can require users to actually enter the number that was shown.</p>
</div>
<div class="paragraph">
<p>This feature requires version 2.0 or higher of the PingOne MFA SDK.</p>
</div>
</div>
<div class="sect3">
<h4 id="pairing-mobile-device-in-multiple-regions"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#pairing-mobile-device-in-multiple-regions"></a>Pairing mobile device in multiple regions</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>When developing mobile apps with the PingOne MFA SDK, you can now configure the apps such that it is possible for the same device to be paired in multiple geographic regions. Learn more about this feature in the documentation for the <a href="https://github.com/pingidentity/pingone-mobile-sdk-ios/">SDK for iOS</a> and the documentation for
the <a href="https://github.com/pingidentity/pingone-mobile-sdk-android/">SDK for Android</a>.</p>
</div>
<div class="paragraph">
<p>This feature requires version 2.0 or higher of the PingOne MFA SDK.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[March 31]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#march-31-2</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#march-31-2</guid>
            <pubDate>Mon, 31 Mar 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="manually-enter-number-for-number-matching"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#manually-enter-number-for-number-matching"></a>Manually enter number for number matching</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">Strong Authentication</span>
<span class="ping_product">PingID</span></p>
</div>
<div class="paragraph">
<p>You can now configure PingID mobile app’s number matching feature to require users to enter the correct number manually, rather than selecting from a list of three numbers.</p>
</div>
<div class="ulist">
<ul>
<li>
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/strong_authentication_mfa/p1_configuring_pid_mobile_application.html" class="xref page">(Workforce Only) Configuring the PingID mobile application settings</a>.</p>
</li>
<li>
<p>Learn about the user experience in <a href="https://docs.pingidentity.com/pingid-user-guide/secure_authentication_with_pingid/main_auth_pid_mobile_app_authentication.html#NumberMatching" target="_blank" rel="noopener">Authenticating using number matching</a>.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="expanded-management-capabilities-for-migrated-pingid-accounts-in-pingone"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#expanded-management-capabilities-for-migrated-pingid-accounts-in-pingone"></a>Expanded management capabilities for migrated PingID accounts in PingOne</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">Strong Authentication</span>
<span class="ping_product">PingID</span></p>
</div>
<div class="paragraph">
<p>The ability to migrate existing PingID accounts to a PingOne environment and fully manage them from PingOne is now available for all admins.
You can now migrate:</p>
</div>
<div class="ulist">
<ul>
<li>
<p>An existing PingID account to a new PingOne environment.</p>
</li>
<li>
<p>An existing PingID account to an existing PingOne environment.</p>
</li>
<li>
<p>If you integrated a PingID account with a PingOne environment before March 31, 2025, you can migrate the PingID management from the legacy PingID admin portal to PingOne.</p>
</li>
</ul>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/strong_authentication_mfa/p1_integrate_pingid_with_p1.html" class="xref page">Integrating a PingID account with a PingOne environment</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[March 26]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#march-26-2</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#march-26-2</guid>
            <pubDate>Wed, 26 Mar 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="updated-ldap-gateway-client-application-5"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#updated-ldap-gateway-client-application-5"></a>Updated LDAP gateway client application</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We’ve released LDAP gateway client application version 3.4.0. This version includes:</p>
</div>
<div class="ulist">
<ul>
<li>
<p>Added <code>correlationId</code> to LDAP gateway client application log to help troubleshoot issues.</p>
</li>
<li>
<p>Upgraded dependencies to improve security.</p>
</li>
<li>
<p>Updated base image to reduce Docker image size.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[March 25]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#march-25</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#march-25</guid>
            <pubDate>Tue, 25 Mar 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="specify-preferred-language-for-populations"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#specify-preferred-language-for-populations"></a>Specify preferred language for populations</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We’ve added the ability to select a <strong class="uicontrol">Language</strong> for <strong class="uicontrol">Populations</strong>, making it easier to specify the preferred language for a user when building authentication experiences in PingOne DaVinci. Learn more in <a href="https://docs.pingidentity.com/pingone/directory/p1_manage_populations.html" class="xref page">Managing populations</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="manage-microsoft-active-directory-user-passwords"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#manage-microsoft-active-directory-user-passwords"></a>Manage Microsoft Active Directory user passwords</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>For workforce contexts, you can now manage Microsoft Active Directory user passwords using a PingOne LDAP gateway with <strong class="uicontrol">User Types</strong>, where the <strong class="uicontrol">Password Authority</strong> section is set to <strong class="uicontrol">LDAP</strong> and <strong class="uicontrol">Password changes from PingOne enabled</strong>. You can enable the following requirements:</p>
</div>
<div class="ulist">
<ul>
<li>
<p><strong class="uicontrol">Force password reset on next sign on</strong>: To force users to reset their password, they must first authenticate using the current password. If the user provides the correct current password, they must provide the current password one more time and define a new password. The new password is sent to Active Directory.</p>
</li>
<li>
<p><strong class="uicontrol">Create or generate password</strong>: When you set a temporary password, it’s sent to Active Directory and the user must authenticate using the temporary password. If the user provides the correct current password, the user must re-enter the temporary password and define a new password, which is sent to Active Directory.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="aaguid-in-api-responses-for-fido2-devices"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#aaguid-in-api-responses-for-fido2-devices"></a>AAGUID in API responses for FIDO2 devices</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>When using the <code>devices</code> endpoint to request details of a single MFA device or all MFA devices, responses for activated FIDO2 devices can now include the authenticator attestation identifier (AAGUID) for the type of authenticator. For details, see the new <code>fidoDeviceMetadata</code> object under <a href="https://developer.pingidentity.com/pingone-api/mfa/users/mfa-devices.html">MFA devices</a> in the PingOne API documentation.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[March 23]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#march-23</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#march-23</guid>
            <pubDate>Sun, 23 Mar 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="pingone-protect-signals-sdk-new-versions-2"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#pingone-protect-signals-sdk-new-versions-2"></a>PingOne Protect (Signals) SDK - new versions</h4>
<div class="paragraph">
<p><span class="ping_product">PingOne Protect SDK</span></p>
</div>
<div class="paragraph">
<p>We’ve released new versions of the PingOne Protect (Signals) SDK:</p>
</div>
<div class="ulist">
<ul>
<li>
<p>iOS - 5.3.0</p>
</li>
<li>
<p>Android - 5.2.0</p>
</li>
</ul>
</div>
<div class="paragraph">
<p>You can find details in the <a href="https://developer.pingidentity.com/pingone-api/native-sdks/pingone-risk-sdks/protect_sdk_changelog.html">SDK Changelog</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[March 20]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#march-20</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#march-20</guid>
            <pubDate>Thu, 20 Mar 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="kong-gateway-integration-kit-enhancement"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#kong-gateway-integration-kit-enhancement"></a>Kong Gateway integration kit enhancement</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne Authorize</span></p>
</div>
<div class="paragraph">
<p>We’ve released version 1.2.0 of the <code class="codeph">ping-auth</code> plugin for Kong Gateway. This version improves security by supporting referenceable shared secrets in Kong.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/authorization_using_pingone_authorize/p1az_configuring_kong_for_p1az_integration.html" class="xref page">Configuring Kong Gateway for PingOne Authorize integration</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[March 19]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#march-19</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#march-19</guid>
            <pubDate>Wed, 19 Mar 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="configure-authentication-failure-limit-for-fido2-devices"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#configure-authentication-failure-limit-for-fido2-devices"></a>Configure authentication failure limit for FIDO2 devices</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">Strong Authentication</span>
<span class="ping_product">PingID</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>When configuring an MFA policy, you can now specify the maximum number of times authentication can fail when using a FIDO2 device, before the user is blocked. You can also specify the amount of time the user is blocked from authenticating with that device.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/strong_authentication_mfa/p1_creating_an_mfa_policy_for_strong_auth.html" class="xref page">Configuring an MFA policy for strong authentication</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[March 17]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#march-17-2</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#march-17-2</guid>
            <pubDate>Mon, 17 Mar 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="custom-domain-infrastructure-changes"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#custom-domain-infrastructure-changes"></a>Custom domain infrastructure changes</h4>
<div class="paragraph">
<p><span class="ping_changetype-info">Info</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>As part of our continued efforts to support best practice security measures in PingOne, we’ll be using Cloudflare instead of Amazon CloudFront as our custom domain ingress infrastructure. This change is being deployed in a phased approach and affects you only if you use custom domains. Learn more about custom domains in <a href="https://docs.pingidentity.com/pingone/settings/p1_set_up_custom_domain.html" class="xref page">Setting up a custom domain</a>.</p>
</div>
<div class="ulist">
<ul>
<li>
<p><strong>Phase 1</strong>: All custom domains added in PingOne after March 17, 2025 will use Cloudflare instead of CloudFront. There will be no change to existing custom domains in Phase 1.</p>
</li>
<li>
<p><strong>Phase 2</strong>: Some time in the next quarter, Ping will release a migration option that will enable you to migrate your existing custom domains to Cloudflare on your own schedule. When Phase 2 is released, detailed migration instructions will be provided.</p>
</li>
<li>
<p><strong>Phase 3</strong>: Approximately 1 year after the completion of Phase 2, any custom domains that you haven’t yet migrated will be migrated to Cloudflare automatically.</p>
</li>
</ul>
</div>
<div class="sect4">
<h5 id="action-required"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#action-required"></a>Action required</h5>
<div class="paragraph">
<p>In most cases, no action is required at this time, and this change should be largely unnoticeable. However, you should contact your organization’s network infrastructure team and direct them to review the <a href="https://docs.pingidentity.com/pingone/settings/p1_migrate_custom_domain_to_cloudflare.html" class="xref page">Custom domain migration to Cloudflare</a> documentation for more information. This content contains details about how to assess whether your network and firewall settings require updates to support the new infrastructure.</p>
</div>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[March 10]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#march-10-2</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#march-10-2</guid>
            <pubDate>Mon, 10 Mar 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="id-of-authenticating-device-in-id-token"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#id-of-authenticating-device-in-id-token"></a>ID of authenticating device in ID token</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>ID tokens now include a new claim called <code>p1.mfa_device_id</code>, the ID of the device that was used to authenticate. You can find more information about the content of ID tokens in <a href="https://developer.pingidentity.com/pingone-api/foundations/authentication-concepts/access-tokens-and-id-tokens/token-claims.html">ID Token claims</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[March 4]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#march-4</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#march-4</guid>
            <pubDate>Tue, 04 Mar 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="pingid-device-trust-predictor-in-risk-policies"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#pingid-device-trust-predictor-in-risk-policies"></a>PingID device trust predictor in risk policies</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span>
<span class="ping_product">PingID</span>
<span class="ping_product">PingOne Protect</span></p>
</div>
<div class="paragraph">
<p>For workforce contexts, risk evaluations can now include the new PingID device trust predictor if your users install the PingID device trust agent on their computers. This predictor requires a PingID and PingOne Protect license.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/strong_authentication_mfa/p1_using_the_workforce_trust_agent.html" class="xref page">Using the PingID device trust agent</a>, <a href="https://docs.pingidentity.com/pingone/threat_protection_using_pingone_protect/p1_protect_risk_predictors.html#pingid-device-trust" class="xref page">PingID device trust predictor</a>, and the <a href="https://developer.pingidentity.com/pingone-api/protect/risk-predictors.html" target="_blank" rel="noopener">Risk Predictors section</a> in the PingOne Protect API documentation.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[February 25]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#february-25-2</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#february-25-2</guid>
            <pubDate>Tue, 25 Feb 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="language-used-for-notifications"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#language-used-for-notifications"></a>Language used for notifications</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>When determining what language should be used for a notification sent to a user, PingOne now takes into account the language preference information included in the Accept-Language header sent by the browser. You can find a full description of the logic used for choosing a language in <a href="https://developer.pingidentity.com/pingone-api/platform/notifications/notifications-templates.html#notifications-templates-runtime-logic-for-content-selection">Runtime logic for content selection</a> in the API documentation.</p>
</div>
</div>
<div class="sect3">
<h4 id="push-notifications-removal-of-legacy-google-cloud-messaging-option"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#push-notifications-removal-of-legacy-google-cloud-messaging-option"></a>Push notifications - removal of legacy Google cloud messaging option</h4>
<div class="paragraph">
<p><span class="ping_changetype-info">Info</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>With Google dropping support for its legacy cloud messaging APIs, native applications in PingOne no longer let you choose between <strong class="uicontrol">Cloud Messaging</strong> and <strong class="uicontrol">Firebase Cloud Messaging</strong>. The HTTP v1 API is now used for push notifications, and you must provide your Firebase Admin SDK private key.</p>
</div>
</div>
<div class="sect3">
<h4 id="apply-a-specific-notification-policy-to-an-mfa-policy"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#apply-a-specific-notification-policy-to-an-mfa-policy"></a>Apply a specific notification policy to an MFA policy</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">Strong Authentication</span>
<span class="ping_product">PingOne MFA</span>
<span class="ping_product">PingID</span></p>
</div>
<div class="paragraph">
<p>You can now select which notification policy you want to apply to an MFA policy.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/strong_authentication_mfa/p1_creating_an_mfa_policy_for_strong_auth.html" class="xref page">Configuring an MFA policy for strong authentication</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[February 24]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#february-24-2</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#february-24-2</guid>
            <pubDate>Mon, 24 Feb 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="remember-me-option-in-mfa-policies"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#remember-me-option-in-mfa-policies"></a>Remember Me option in MFA policies</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>You can now use the PingOne API to implement "remember me" functionality in your web applications so that users do not have to authenticate when accessing applications from a remembered browser during the period specified, which can be from one hour to 90 days.</p>
</div>
<div class="paragraph">
<p>If you include this option, use the new <strong class="uicontrol">Remember Me Configurations</strong> section when defining MFA policies to specify which policies should allow the option. For instructions on implementing this feature, see <a href="https://developer.pingidentity.com/pingone-api/mfa/users/remembered-devices.html">Remembered Devices</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[February 20]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#february-20</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#february-20</guid>
            <pubDate>Thu, 20 Feb 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="ability-to-limit-custom-role-access-to-overview-page-added"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#ability-to-limit-custom-role-access-to-overview-page-added"></a>Ability to limit custom role access to Overview page added</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We’ve added a new <strong class="uicontrol">Display Environment Overview</strong> permission that controls access to the <strong class="uicontrol">Overview</strong> page for the environment. This permission is included in all built-in administrator roles in PingOne, but you can remove it from custom roles to restrict access to this page. This permission affects visibility in the admin console only and doesn’t affect API access. Learn more about built-in and custom roles in <a href="https://docs.pingidentity.com/pingone/directory/p1_roles.html" class="xref page">Administrator Roles</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[February 12]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#february-12</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#february-12</guid>
            <pubDate>Wed, 12 Feb 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="population-theme-updates"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#population-theme-updates"></a>Population theme updates</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>If a population doesn’t have a selected theme, the population now uses the active theme for the environment. This update ensures that preferred branding is displayed to users when building authentication experiences in PingOne DaVinci. Learn more in <a href="https://docs.pingidentity.com/pingone/directory/p1_manage_populations.html" class="xref page">Managing populations</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="using-expressions-to-access-authentication-jwt-for-token-fulfillment"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#using-expressions-to-access-authentication-jwt-for-token-fulfillment"></a>Using expressions to access authentication JWT for token fulfillment</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>You can now use expressions to retrieve information from the authentication JSON Web Token (JWT) for access token and ID token fulfillment. Expressions are supported when using private key JWT and client secret JWT as the token endpoint authentication method. This capability improves interoperability between OpenID Connect (OIDC) applications and resources. Learn more in <a href="https://docs.pingidentity.com/pingone/applications/p1_token_endpoint_authentication_methods.html" class="xref page">Token endpoint authentication methods</a> and <a href="https://docs.pingidentity.com/pingone/pingone_expression_language/p1_expressionlang_variables.html" class="xref page">PingOne expression language variables</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[February 5]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#february-5</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#february-5</guid>
            <pubDate>Wed, 05 Feb 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="pingone-notifications-multiple-custom-smsvoice-providers"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#pingone-notifications-multiple-custom-smsvoice-providers"></a>PingOne Notifications - multiple custom SMS/voice providers</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>You can now define up to three custom providers to use for SMS/voice notifications. After you’ve defined the providers, you can specify in your notification policies the order of provider preference to use in different geographical locations.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[February 4]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#february-4-2</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#february-4-2</guid>
            <pubDate>Tue, 04 Feb 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="multi-factor-authentication-required-for-access-to-admin-console-updates"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#multi-factor-authentication-required-for-access-to-admin-console-updates"></a>Multi-factor authentication required for access to admin console - updates</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>As part of our continued efforts to support best practice security measures in PingOne, we’ve made the following updates to enhance the multi-factor authentication (MFA) requirements introduced earlier this year:</p>
</div>
<div class="ulist">
<ul>
<li>
<p><strong class="uicontrol">Update Admin MFA Settings</strong> <strong>modal</strong>: Prompts administrators to update <strong class="uicontrol">Administrator Security</strong> settings when signing on to environments in which enhanced security is not yet enabled. Use the modal to:</p>
<div class="ulist">
<ul>
<li>
<p><strong class="uicontrol">Update Now</strong>: Enforces new default security settings based on current environment policies. Displays information about the authentication policy and settings that will be enabled when you update.</p>
<div class="paragraph">
<p>The confirmation message redirects you to the <strong class="uicontrol">Administrator Security</strong> page so that you can verify the updates and make changes if necessary.</p>
</div>
<div class="admonitionblock note">
<table>
<tbody><tr>
<td class="icon">
<i class="fa icon-note" title="Note"></i>
</td>
<td class="content">
<div class="paragraph">
<p>This update cannot be reversed from the admin console. Contact Ping Identity Support for changes during the opt-in period (until June 1, 2025).</p>
</div>
</td>
</tr>
</tbody></table>
</div>
</li>
<li>
<p><strong class="uicontrol">Remind me later</strong>: Delays the update. Administrators will be prompted again in the next browser session.</p>
</li>
</ul>
</div>
</li>
<li>
<p><strong>Policy mapping changes</strong>: The current default authentication policy for the environment is mapped to the new system security policy to ensure consistency.</p>
</li>
</ul>
</div>
<div class="sect4">
<h5 id="action-required-2"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#action-required-2"></a>Action Required</h5>
<div class="paragraph">
<p>Review and update the <strong class="uicontrol">Administrator Security</strong> settings to enhance the security of your environments. For assistance, contact Ping Identity Support during the opt-in period.</p>
</div>
<div class="paragraph">
<p>Ping Identity will require MFA for all PingOne administrators as of June 1, 2025. Learn more in the <a href="https://docs.pingidentity.com/pingone-admin-mfa-faq/p1_mfa_required_for_admins_faq.html">PingOne administrators MFA requirement - FAQ</a>.</p>
</div>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[January 31]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#january-31</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#january-31</guid>
            <pubDate>Fri, 31 Jan 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="access-token-enhancements"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#access-token-enhancements"></a>Access token enhancements</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>To reduce administrative and development tasks, PingOne now always includes the organization ID and environment ID in its access tokens. The claims are included in access tokens as <code class="codeph">org</code> and <code class="codeph">env</code>, respectively. If your organization’s processes require the organization ID, environment ID, or both, you can now retrieve this information by reading the JSON Web Token (JWT)-based access tokens or sending introspection requests and reviewing the results.</p>
</div>
</div>
<div class="sect3">
<h4 id="role-assignment-event-enhancements"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#role-assignment-event-enhancements"></a>Role assignment event enhancements</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>The role events in the PingOne audit report now use human-readable text instead of UUIDs for the role that was created or deleted and the scope or level at which the role change was made. Additionally, you can now easily monitor role assignment events by running a preconfigured audit report directly from the <strong class="uicontrol">Administrator Roles</strong> page. Learn more in <a href="https://docs.pingidentity.com/pingone/directory/p1_viewing_admin_role_events.html" class="xref page">Viewing administrator role events</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[January 30]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#january-30</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#january-30</guid>
            <pubDate>Thu, 30 Jan 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="detection-of-replay-attacks"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#detection-of-replay-attacks"></a>Detection of replay attacks</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne Protect</span></p>
</div>
<div class="paragraph">
<p>PingOne Protect now detects replay attacks that use an intercepted valid payload from the Signals SDK.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[January 29]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#january-29</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#january-29</guid>
            <pubDate>Wed, 29 Jan 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="updated-defaults-for-new-native-applications"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#updated-defaults-for-new-native-applications"></a>Updated defaults for new native applications</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>When adding a new native application, PingOne creates the application with the following new defaults to align with current security best practices:</p>
</div>
<div class="ulist">
<ul>
<li>
<p><strong class="uicontrol">Response Type</strong>: <strong class="uicontrol">Code</strong></p>
</li>
<li>
<p><strong class="uicontrol">Grant Type</strong>: <strong class="uicontrol">Authorization Code</strong></p>
</li>
<li>
<p><strong class="uicontrol">PKCE Enforcement</strong>: <strong class="uicontrol">S256_REQUIRED</strong></p>
</li>
</ul>
</div>
<div class="paragraph">
<p>Existing native applications won’t be updated to use the new defaults. You can update the settings for new and existing native applications as needed. Learn more in <a href="https://docs.pingidentity.com/pingone/applications/p1_edit_application_native.html" class="xref page">Editing an application - Native</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="format-of-phone-numbers-in-mexico"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#format-of-phone-numbers-in-mexico"></a>Format of phone numbers in Mexico</h4>
<div class="paragraph">
<p><span class="ping_changetype-info">Info</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>The format of Mexican phone numbers that was used prior to August 2019 (adding "1" before the area code) is no longer supported.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[January 28]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#january-28</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#january-28</guid>
            <pubDate>Tue, 28 Jan 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="pingid-as-a-digital-wallet"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#pingid-as-a-digital-wallet"></a>PingID as a digital wallet</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne Credentials</span></p>
</div>
<div class="paragraph">
<p>You can now add PingID as a digital wallet to issue verifiable credentials. Learn more in <a href="https://docs.pingidentity.com/pingone/digital_credentials_using_pingone_credentials/p1_credentials_creating_a_credential.html" class="xref page">Creating a credential</a>. You can find end user documentation in <a href="https://docs.pingidentity.com/pingid-user-guide/manage_and_share_creds/pid_c_manage_and_share_creds.html">Manage and share Credentials</a> in the PingID End User Guide.</p>
</div>
</div>
<div class="sect3">
<h4 id="terminate-user-sessions-with-only-id-token"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#terminate-user-sessions-with-only-id-token"></a>Terminate user sessions with only ID token</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>You can now enable OIDC-based applications to send a sign-off request for PingOne to terminate a user session using only the ID token. This is most useful for applications that don’t have access to the session token cookie. This capability is controlled by a new per-application setting, <strong class="uicontrol">Terminate User Session by ID Token</strong>. Learn more in <a href="https://docs.pingidentity.com/pingone/applications/p1_editing_applications.html" class="xref page">Editing an application</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[January 21]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#january-21-2</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#january-21-2</guid>
            <pubDate>Tue, 21 Jan 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="oidc-based-linkedin-external-identity-provider"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#oidc-based-linkedin-external-identity-provider"></a>OIDC-based LinkedIn external identity provider</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>The LinkedIn external identity provider (IdP) now uses an <span class="fr-alt fr-glossentry" title="<div class=&quot;paragraph&quot;>
<p>An authentication protocol built on top of OAuth that authenticates users and enables clients (relying parties) of all types to request and receive information about authenticated sessions and users. OIDC is extensible, allowing clients to use optional features such as encryption of identity data, discovery of OpenID Providers (OAuth authorization servers), and session management.</p>
</div>">OpenID Connect (OIDC)</span>-based connection to allow your users to sign on to an application with LinkedIn. The legacy OAuth 2.0-based IdP connection for LinkedIn has been deprecated. Existing applications using the legacy IdP will continue to work, but new applications default to the new OIDC-based connection. Learn more in <a href="https://docs.pingidentity.com/pingone/integrations/p1_add_idp_linkedin_prereqs.html" class="xref page">Adding an identity provider - LinkedIn</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[January 20]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#january-20</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#january-20</guid>
            <pubDate>Mon, 20 Jan 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="introducing-authorize-gateways"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#introducing-authorize-gateways"></a>Introducing Authorize gateways</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span>
<span class="ping_product">PingOne Authorize</span></p>
</div>
<div class="paragraph">
<p>We’ve released Authorize gateway version 1.0.0. To reduce authorization latency when you have demanding performance requirements, you can now deploy authorization policies managed in PingOne to Authorize gateway instances located on-premise or in your private cloud. In highly regulated environments, this also ensures data privacy by keeping sensitive data for authorization decisions within your secure trust boundary. Learn more in <a href="https://docs.pingidentity.com/pingone/integrations/p1_authz_gateways.html" class="xref page">Authorize gateways</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[January 14]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#january-14</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#january-14</guid>
            <pubDate>Tue, 14 Jan 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="custom-oauth-parameters-for-http-service-requests"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#custom-oauth-parameters-for-http-service-requests"></a>Custom OAuth parameters for HTTP service requests</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne Authorize</span></p>
</div>
<div class="paragraph">
<p>You can now send additional parameters in HTTP service requests. For HTTP services authenticated with the Client Credentials grant type, use the <strong class="uicontrol">Custom OAuth Parameters</strong> setting to add custom key-value pairs to the token endpoint request. This level of customization is useful when integrating with authorization servers that enforce specific configuration constraints. Learn more in <a href="https://docs.pingidentity.com/pingone/authorization_using_pingone_authorize/p1_az_connecting_an_http_service.html" class="xref page">Connecting an HTTP service</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="troubleshooting-ldap-authentication"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#troubleshooting-ldap-authentication"></a>Troubleshooting LDAP authentication</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We’ve added the following information to the gateway client application logs to help solve authentication issues reported by end users. Find out whether a user:</p>
</div>
<div class="ulist">
<ul>
<li>
<p>Entered an incorrect username.</p>
</li>
<li>
<p>Entered a correct username but an incorrect password.</p>
</li>
</ul>
</div>
<div class="admonitionblock note">
<table>
<tbody><tr>
<td class="icon">
<i class="fa icon-note" title="Note"></i>
</td>
<td class="content">
<div class="paragraph">
<p>For security reasons, this information is only visible to admins and isn’t displayed to end users. The end-user experience remains unchanged. The standard message is <code>Incorrect username or password. Please try again.</code></p>
</div>
</td>
</tr>
</tbody></table>
</div>
</div>
<div class="sect3">
<h4 id="improved-application-management-experience"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#improved-application-management-experience"></a>Improved application management experience</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>To improve the administrator experience, we’ve moved application endpoints and URLs from the <strong class="uicontrol">Configuration</strong> tab to the <strong class="uicontrol">Overview</strong> tab. This makes it easier and faster to navigate to the configuration details you need for day-to-day application management. Learn more in <a href="https://docs.pingidentity.com/pingone/applications/p1_viewapplications.html" class="xref page">Viewing application details</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[January 10]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#january-10</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#january-10</guid>
            <pubDate>Fri, 10 Jan 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="authorization-dashboard-enhancements"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#authorization-dashboard-enhancements"></a>Authorization Dashboard enhancements</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne Authorize</span></p>
</div>
<div class="paragraph">
<p>We’ve refreshed the <strong class="uicontrol">Authorization Dashboard</strong> to improve your user experience. You can track authorizations and decision counts by date, and view the average execution time for services, in addition to the maximum execution time. Learn more in <a href="https://docs.pingidentity.com/pingone/authorization_using_pingone_authorize/p1_az_dashboard.html" class="xref page">Authorization Dashboard</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[January 9]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#january-9</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#january-9</guid>
            <pubDate>Thu, 09 Jan 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="step-up-authentication-for-apis"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#step-up-authentication-for-apis"></a>Step-up authentication for APIs</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span>
<span class="ping_product">PingOne Authorize</span></p>
</div>
<div class="paragraph">
<p>You can now force step-up authentication when users access sensitive resources through APIs. When authenticated users try to access more sensitive resources, such as salary data, health records, or premium content, you can require a higher level of authentication and also set limits on the amount of time allowed since the last authentication event.</p>
</div>
<div class="paragraph">
<p>Use the new <strong class="uicontrol">Respond with authentication step-up challenge</strong> statement template to implement step-up authentication challenges in policies that protect API services and operations.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/authentication/p1_stepup_authentication_for_apis.html" class="xref page">Step-up authentication for APIs</a> and <a href="https://docs.pingidentity.com/pingone/authorization_using_pingone_authorize/p1az_statement_templates.html" class="xref page">Statement templates</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="define-public-key-credential-hints-in-the-fido-policy"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#define-public-key-credential-hints-in-the-fido-policy"></a>Define Public Key Credential Hints in the FIDO policy</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>You can now define Public Key Credential Hints. This field allows you to select the authenticating device that your users are most likely to choose during pairing. The selection is considered as a ‘hint’ to the authenticator.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/authentication/p1_creating_a_fido_policy.html" class="xref page">Adding a FIDO policy</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="radius-gateway-enhancements"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#radius-gateway-enhancements"></a>RADIUS gateway enhancements</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We’ve updated the RADIUS gateway client application to version 1.3.0.</p>
</div>
<div class="paragraph">
<p>This version includes the following enhancements:</p>
</div>
<div class="ulist">
<ul>
<li>
<p>Support for the use of a forward web proxy server to handle traffic between the RADIUS gateway client and PingOne.</p>
</li>
<li>
<p>Support for the EAP-MSCHAPv2 protocol when integrating the RADIUS gateway with a Network Policy Server (NPS).</p>
</li>
</ul>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/integrations/p1_radius_gateways_intro.html" class="xref page">RADIUS gateways</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="radius-gateway-security-enhancement"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#radius-gateway-security-enhancement"></a>RADIUS gateway security enhancement</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We’ve made some enhancements to the RADIUS Client security configuration to mitigate the risk of a BlastRADIUS attack.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/integrations/p1_add_radius_gateway.html" class="xref page">Adding a RADIUS gateway</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="radius-gateway-fails-to-forward-requests-to-the-nps-server"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#radius-gateway-fails-to-forward-requests-to-the-nps-server"></a>RADIUS gateway fails to forward requests to the NPS Server</h4>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">STAGING-24934</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We’ve fixed an issue that was preventing RADIUS gateway from forwarding requests to the NPS (Network Policy Server) in instances where the RADIUS client and the NPS shared the same IP address.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[January 6]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#january-6</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#january-6</guid>
            <pubDate>Mon, 06 Jan 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="pingid-account-in-pingone"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#pingid-account-in-pingone"></a>PingID account in PingOne</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">Strong Authentication</span>
<span class="ping_product">PingOne MFA</span>
<span class="ping_product">PingID</span></p>
</div>
<div class="paragraph">
<p>We’ve added the ability to create a new PingID account and manage it from a PingOne environment. Many features that were previously managed by the legacy PingID admin portal (on the <strong class="uicontrol">Configuration</strong> tab and the <strong class="uicontrol">Device and Pairing</strong> tab) can now be managed in PingOne.</p>
</div>
<div class="paragraph">
<p>Administrators can also take advantage of additional functionality available in PingOne including:</p>
</div>
<div class="ulist">
<ul>
<li>
<p>PingID accounts in PingOne can now configure the full range of authentication methods from PingOne’s MFA policy.</p>
</li>
<li>
<p>All application-specific configurations can be done from the relevant application on the PingOne  <strong class="uicontrol">Applications</strong> tab. A PingID mobile application and a PingID desktop application appear in the <strong class="uicontrol">Applications</strong> list by default.</p>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/strong_authentication_mfa/p1_configuring_pid_mobile_application.html" class="xref page">Configuring the PingID mobile application settings</a> and <a href="https://docs.pingidentity.com/pingone/strong_authentication_mfa/p1_pid_desktop_app_start.html" class="xref page">Configuring the PingID desktop application</a>.</p>
</div>
</li>
<li>
<p>PingID’s email, SMS, and voice providers can now be configured from PingOne.</p>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/settings/p1_sender.html" class="xref page">Senders</a>.</p>
</div>
</li>
<li>
<p>You can now edit and customize PingID notification templates from PingOne.</p>
</li>
<li>
<p>You can view MFA dashboards and reporting in PingOne. PingID reports are still available in the legacy PingID admin portal.</p>
</li>
</ul>
</div>
<div class="paragraph">
<p>A small number of features are still managed by the legacy PingID admin console, such as PingID policy.</p>
</div>
</div>
<div class="sect3">
<h4 id="early-access-to-manage-pingid-out-of-pingone"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#early-access-to-manage-pingid-out-of-pingone"></a>Early access to manage PingID out of PingOne</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">Strong Authentication</span>
<span class="ping_product">PingID</span></p>
</div>
<div class="paragraph">
<p>We’ve provided a limited number of existing customers with the ability to migrate the management of their PingID account to PingOne.</p>
</div>
<div class="paragraph">
<p>To help administrators who are familiar with specific fields for specific features in the legacy PingID admin portal to find the equivalent fields in PingOne, in the legacy PingID admin portal for all relevant fields we’ve added a link to the equivalent field in PingOne.</p>
</div>
<div class="admonitionblock note">
<table>
<tbody><tr>
<td class="icon">
<i class="fa icon-note" title="Note"></i>
</td>
<td class="content">
<div class="ulist">
<ul>
<li>
<p>For customers with early access, it is important to read <a href="https://docs.pingidentity.com/pingone/strong_authentication_mfa/p1_what_to_know_before_integrating_existing_pid_account_to_p1.html" class="xref page">What you need to know before integrating or migrating a PingID account into a PingOne environment</a> before migrating your account.</p>
</li>
<li>
<p>Customers who want to join the early access track should contact their Ping Identity representative.</p>
</li>
</ul>
</div>
</td>
</tr>
</tbody></table>
</div>
</div>
<div class="sect3">
<h4 id="bypass-mfa-for-a-specific-user"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#bypass-mfa-for-a-specific-user"></a>Bypass MFA for a specific user</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">Strong Authentication</span>
<span class="ping_product">PingOne MFA</span>
<span class="ping_product">PingID</span></p>
</div>
<div class="paragraph">
<p>It’s now possible to bypass MFA for a specific user for a specific time period or for an unlimited time. When bypass is enabled, the user is able to access their account or application without authenticating using MFA.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/directory/p1_pid_bypass_mfa.html" class="xref page">Bypass MFA for a specific user</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="documentation-improvements"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#documentation-improvements"></a>Documentation improvements</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">Strong Authentication</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>PingOne MFA documentation has been improved and is now included as part of a single section, <em>Strong authentication</em>. The new section includes a dedicated page for each authentication method, outlining the features of that authentication method, and various configuration options. It also indicates which authentication methods are supported by the use case (workforce, customer, or both), and includes details of requirements and limitations for each authentication method.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingone/strong_authentication_mfa/p1_strong_authentication_start.html" class="xref page">Strong Authentication (MFA)</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[December 16]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#december-16</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#december-16</guid>
            <pubDate>Mon, 16 Dec 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="device-authorization-app-restored-to-pingid-policy"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#device-authorization-app-restored-to-pingid-policy"></a>Device Authorization app restored to PingID policy</h4>
<div class="paragraph">
<p><span class="ping_changetype-fixed">Fixed</span>
<span class="ping_ticket">STAGING-25145</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>For PingID accounts that are integrated with PingOne environments, we’ve fixed an issue in the legacy PingID admin portal that was preventing the Device Authorization app from showing in the PingID policy applications list.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[December 10]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#december-10</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#december-10</guid>
            <pubDate>Tue, 10 Dec 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="population-alternative-identifiers-and-theme"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#population-alternative-identifiers-and-theme"></a>Population alternative identifiers and theme</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We’ve added the ability to configure <strong class="uicontrol">Alternative Identifiers</strong> for <strong class="uicontrol">Populations</strong>, making it easier to determine a user’s population based on an identifier value in a DaVinci flow. Additionally, populations can now specify a <strong class="uicontrol">Theme</strong>, making it easier to determine the preferred branding for a user when building authentication experiences in PingOne DaVinci. Learn more in <a href="https://docs.pingidentity.com/pingone/directory/p1_manage_populations.html" class="xref page">Managing populations</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="add-custom-attributes-from-workday-into-pingone"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#add-custom-attributes-from-workday-into-pingone"></a>Add custom attributes from Workday into PingOne</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>You can add custom attributes from Workday into PingOne. Learn more in <a href="https://docs.pingidentity.com/pingone/integrations/p1_create_workday_connection.html#p1_workday_system_field" class="xref page">integrations:p1_create_workday_connection.adoc#p1_workday_system_field</a>, <a href="https://docs.pingidentity.com/pingone/integrations/p1_create_workday_connection.html#p1_workday_system_ids" class="xref page">Workday system Ids</a>, and <a href="https://docs.pingidentity.com/pingone/integrations/p1_create_workday_connection.html#p1_sync_workday_attribute" class="xref page">Syncing custom attributes from Workday into PingOne</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[December 9]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#december-9</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#december-9</guid>
            <pubDate>Mon, 09 Dec 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="define-the-user-presence-timeout-for-fido-devices"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#define-the-user-presence-timeout-for-fido-devices"></a>Define the user presence timeout for FIDO devices</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne MFA</span></p>
</div>
<div class="paragraph">
<p>You can now define a user presence timeout value for FIDO2 devices. The <strong class="uicontrol">User Presence Timeout</strong> field defines the amount of time the user has to perform a user presence gesture with their FIDO device before the request expires. Learn more in <a href="https://docs.pingidentity.com/pingone/authentication/p1_creating_a_fido_policy.html" class="xref page">Adding a FIDO policy</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[November 20]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#november-20</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#november-20</guid>
            <pubDate>Wed, 20 Nov 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="added-active-directory-compatibility-to-the-reset-password-capability"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#added-active-directory-compatibility-to-the-reset-password-capability"></a>Added Active Directory compatibility to the Reset Password capability</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>The <strong class="uicontrol">Reset Password</strong> capability in the DaVinci LDAP connector is now compatible with Active Directory. Learn more in <a href="https://docs.pingidentity.com/connectors/ldap_connector.html#reset-password">LDAP Connector</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[November 19]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#november-19</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#november-19</guid>
            <pubDate>Tue, 19 Nov 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="user-demographic-dashboard"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#user-demographic-dashboard"></a>User demographic dashboard</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>The User demographic dashboard shows a summary of user demographic profiles and activity for the selected environment. Learn more in <a href="https://docs.pingidentity.com/pingone/monitoring/p1_user_demographic_dashboard.html" class="xref page">User Demographics Dashboard</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[November 18]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#november-18-2</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#november-18-2</guid>
            <pubDate>Mon, 18 Nov 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="simplified-oidc-application-configuration-and-integration"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#simplified-oidc-application-configuration-and-integration"></a>Simplified OIDC application configuration and integration</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>We’ve enhanced the application configuration process for OpenID Connect (OIDC) applications. The new <strong class="uicontrol">Integrate</strong> tab provides access to prefilled code examples, instructions, and sample apps for testing connections. Initial support is available for Node.js Express and the Ping SDK for JavaScript. Learn more in <a href="https://docs.pingidentity.com/pingone/pingone_tutorials/p1_tutorial_integrate_nodejs_express_app.html" class="xref page">Integrate PingOne with a Node.js Express app</a> or <a href="https://docs.pingidentity.com/sdks/latest/sdks/tutorials/javascript/pingone/index.html">Integrate Ping SDK for JavaScript with PingOne</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[November 14]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#november-14</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#november-14</guid>
            <pubDate>Thu, 14 Nov 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="manually-approve-a-users-id"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#manually-approve-a-users-id"></a>Manually approve a user’s ID</h4>
<div class="paragraph">
<p><span class="ping_changetype-improved">Improved</span>
<span class="ping_product">PingOne Verify</span></p>
</div>
<div class="paragraph">
<p>You can now manually approve a user’s ID from the transaction log. Learn more in <a href="https://docs.pingidentity.com/pingone/identity_verification_using_pingone_verify/p1_verify_manually_approve_id.html" class="xref page">Manually approving a user’s ID</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[November 13]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#november-13</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#november-13</guid>
            <pubDate>Wed, 13 Nov 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="specifying-authentication-policy-for-saml-applications-using-flowpolicyid"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#specifying-authentication-policy-for-saml-applications-using-flowpolicyid"></a>Specifying authentication policy for SAML applications using <code class="parmname">flowPolicyId</code></h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>PingOne now supports using the <code class="parmname">flowPolicyId</code> HTTP request parameter to indicate the authentication policy for PingOne to use when authenticating users to a SAML application. You can include the <code class="parmname">flowPolicyId</code> HTTP request parameter in the <strong class="uicontrol">Initiate Single Sign-On URL</strong> to specify a PingOne authentication policy or a DaVinci flow policy. Learn more in <a href="https://docs.pingidentity.com/pingone/applications/p1_edit_application_saml.html" class="xref page">Editing an application - SAML</a>.</p>
</div>
</div>
<div class="sect3">
<h4 id="amazon-api-gateway-integration-kit-retries-for-client-network-errors"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#amazon-api-gateway-integration-kit-retries-for-client-network-errors"></a>Amazon API Gateway integration kit retries for client network errors</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne Authorize</span></p>
</div>
<div class="paragraph">
<p>We’ve released Amazon API Gateway integration kit version 1.3.0. This version includes a retry mechanism to improve the handling of client network errors caused by connection resets. Use the <code class="codeph">maxRetries</code> setting in <code class="filepath">config.js</code> to set the maximum number of retries you want before returning a failed response to the client. The default is <code class="codeph">1</code>. Learn more in <a href="https://docs.pingidentity.com/pingone/authorization_using_pingone_authorize/p1az_configuring_amazon_for_p1az_integration.html" class="xref page">Configuring Amazon API Gateway for PingOne Authorize integration</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[November 12]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#november-12</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#november-12</guid>
            <pubDate>Tue, 12 Nov 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="language-localization"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#language-localization"></a>Language localization</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne Verify</span></p>
</div>
<div class="paragraph">
<p>Use language localization to configure one or more languages and modify text fields of PingOne Verify text that is presented to end users in notification and agreements. Learn more in <a href="https://docs.pingidentity.com/pingone/identity_verification_using_pingone_verify/p1_verify_language_localization.html" class="xref page">Configuring PingOne Verify language localization</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[November 11]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#november-11-2</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#november-11-2</guid>
            <pubDate>Mon, 11 Nov 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="deletion-of-staging-policies-when-promoting-to-production"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#deletion-of-staging-policies-when-promoting-to-production"></a>Deletion of staging policies when promoting to production</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne Protect</span></p>
</div>
<div class="paragraph">
<p>When you promote a staging policy to production, the staging policy will now be automatically deleted from your list of risk policies. You can no longer unlink PingOne Protect staging policies from a production policy. Learn more in <a href="https://docs.pingidentity.com/pingone/threat_protection_using_pingone_protect/p1_protect_creating_managing_staging_policies.html" class="xref page">Creating and managing staging policies</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[November 6]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#november-6</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#november-6</guid>
            <pubDate>Wed, 06 Nov 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="pingone-protect-signals-sdk-new-versions-3"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#pingone-protect-signals-sdk-new-versions-3"></a>PingOne Protect (Signals) SDK - new versions</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne Protect SDK</span></p>
</div>
<div class="paragraph">
<p>We’ve released new versions of the PingOne Protect (Signals) SDK:</p>
</div>
<div class="ulist">
<ul>
<li>
<p>iOS - 5.2.8</p>
</li>
<li>
<p>Android - 5.1.5</p>
</li>
<li>
<p>Web - 5.4.0</p>
</li>
</ul>
</div>
<div class="paragraph">
<p>You can find details in the <a href="https://developer.pingidentity.com/pingone-api/native-sdks/pingone-risk-sdks/protect_sdk_changelog.html">SDK Changelog</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[November 5]]></title>
            <link>https://docs.pingidentity.com/pingone/release_notes/index.html#november-5-2</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingone/release_notes/index.html#november-5-2</guid>
            <pubDate>Tue, 05 Nov 2024 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="sect3">
<h4 id="support-for-offline_access-scope-in-oidc-applications"><a class="anchor" href="https://docs.pingidentity.com/pingone/release_notes/index.html#support-for-offline_access-scope-in-oidc-applications"></a>Support for <code class="parmname">offline_access</code> scope in OIDC applications</h4>
<div class="paragraph">
<p><span class="ping_changetype-new">New</span>
<span class="ping_product">PingOne</span></p>
</div>
<div class="paragraph">
<p>PingOne now supports the <code class="parmname">offline_access</code> scope for OIDC-based applications. Add <code class="parmname">offline_access</code> as an allowed scope to enable an application to use the Refresh Token grant type to access previously approved resources when the user is not present and on a per-request basis. This allows the application to drive the decision to request a refresh token based on whether or not it needs a refresh token. Learn more in <a href="https://docs.pingidentity.com/pingone/applications/p1_editing_applications.html" class="xref page">Editing an application</a>.</p>
</div>
</div>
]]></description>
        </item>
    </channel>
</rss>