<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
    <channel>
        <title>Regular channel changelog | PingOne Advanced Identity Cloud</title>
        <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html</link>
        <description>Regular channel changelog</description>
        <lastBuildDate>Fri, 17 Jul 2026 15:02:52 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <ttl>5</ttl>
        <copyright>Copyright 2026 Ping Identity. All rights reserved.</copyright>
        <item>
            <title><![CDATA[08 Jul 2026]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#08_jul_2026</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#08_jul_2026</guid>
            <pubDate>Wed, 08 Jul 2026 16:20:57 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 22170.18</strong></p>
</div>
<div class="paragraph">
<p>No customer-facing features, enhancements, or fixes released.<sup class="footnote" id="_footnote_fn-no-customer-tickets">[<a id="_footnoteref_1" class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_1" title="View footnote.">1</a>]</sup></p>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[06 Jul 2026]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#06_jul_2026</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#06_jul_2026</guid>
            <pubDate>Mon, 06 Jul 2026 16:40:57 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 22170.17</strong></p>
</div>
<div class="paragraph">
<p>No customer-facing features, enhancements, or fixes released.<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_1" title="View footnote.">1</a>]</sup></p>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[02 Jul 2026]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#02_jul_2026</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#02_jul_2026</guid>
            <pubDate>Fri, 03 Jul 2026 05:20:57 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 22170.16</strong></p>
</div>
<div class="paragraph">
<p>No customer-facing features, enhancements, or fixes released.<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_1" title="View footnote.">1</a>]</sup></p>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[01 July 2026]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#01_july_2026</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#01_july_2026</guid>
            <pubDate>Wed, 01 Jul 2026 18:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 22170.14</strong></p>
</div>
<div class="sect3">
<h4 id="key_features"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#key_features"></a>Key features</h4>
<div class="dlist">
<dl>
<dt class="hdlist1">Identity Governance role LCM (IGA-4265)<sup class="footnote" id="_footnote_fn-iga">[<a id="_footnoteref_2" class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_2" title="View footnote.">2</a>]</sup></dt>
<dd>
<p>The new role lifecycle management (LCM) feature lets designated end users create, update, and delete roles on behalf of others without full administrative access. All changes are submitted as workflow-driven requests, maintaining governance and security while delegating role management to business owners.</p>
</dd>
<dt class="hdlist1">Identity Governance for AI agents (IGA-4223)<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_2" title="View footnote.">2</a>]</sup></dt>
<dd>
<p>Agent Governance lets you detect, onboard, and govern AI agents the same way you govern human identities, accounts, and roles.
This brings them under the governance umbrella alongside human identities.</p>
<div class="paragraph">
<p>Agent Governance provides application templates to discover AI agents in the following agentic platforms:</p>
</div>
<div class="ulist">
<ul>
<li>
<p>AWS Bedrock</p>
</li>
<li>
<p>AWS Bedrock AgentCore</p>
</li>
<li>
<p>Azure AI Foundry</p>
</li>
<li>
<p>Microsoft Copilot Studio</p>
</li>
<li>
<p>Google Vertex AI</p>
</li>
</ul>
</div>
<div class="paragraph">
<p>Find more information in <a href="https://docs.pingidentity.com/pingoneaic/identity-governance/administration/iga-agent-governance.html" class="xref page">Agent Governance</a> and <a href="https://docs.pingidentity.com/pingoneaic/identity-governance/end-user/iga-agent-governance-enduser.html" class="xref page">Agent Governance: custodian and reviewer tasks</a>.</p>
</div>
</dd>
</dl>
</div>
</div>
<div class="sect3">
<h4 id="enhancements"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#enhancements"></a>Enhancements</h4>
<div class="ulist">
<ul>
<li>
<p>AME-28187: You can now set a <strong class="label">Metadata URL</strong> in your remote consent agent. Advanced Identity Cloud retrieves the remote consent server’s (RCS) metadata from this URL.
When configured, the OIDC <code>.well-known</code> endpoint includes the <code>authorization_details_types_supported</code> field, populated from the authorization detail types advertised by the RCS.</p>
</li>
<li>
<p>AME-33781: Advanced Identity Cloud now supports the <a href="https://docs.pingidentity.com/pingoneaic/am-authentication/authn-mfa-webauthn.html#webauthn-conditional-ui" class="xref page">WebAuthn conditional UI</a>, also known as passkey autofill. This lets your end users sign in with a passkey if they’ve previously saved one in their browser.</p>
</li>
<li>
<p>AME-34458: Enhanced the output when you test the connection in the PingOne Worker service to display the values used in the connection test to make them easier to verify. These details are extracted from the credential JWT or derived from the worker service configuration.</p>
</li>
<li>
<p>AME-34513: Added support for the <code>_queryFilter</code> parameter on the <code>realm-config/services/pingOneWorkerService/workers</code> endpoint. Use this to query the configured worker services.
For example, you can filter by credential type or by a property value such as the API URL.</p>
</li>
<li>
<p>IAM-1478: Autofill is now disabled for fields on pages where you add identities.</p>
</li>
<li>
<p>IAM-4646: Tenant administrators registered through federation no longer have the option to update their username and password on the sign-on screen.</p>
</li>
<li>
<p>IAM-8699: Advanced Identity Cloud now supports <a href="https://docs.pingidentity.com/pingoneaic/journeys/node-versions.html" class="xref page">node versioning</a>. When we make changes to a node in the future, we’ll create a new version of the node.</p>
<div class="paragraph">
<p>This release introduces new node versions for the following nodes:</p>
</div>
<table class="tableblock frame-all grid-all stretch">
<colgroup>
<col style="width: 33.3333%;">
<col style="width: 66.6667%;">
</colgroup>
<thead>
<tr>
<th class="tableblock halign-left valign-top">Node</th>
<th class="tableblock halign-left valign-top">Description of change</th>
</tr>
</thead>
<tbody>
<tr>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><a href="https://docs.pingidentity.com/auth-node-ref/latest/page.html">Page node</a></p>
</div></div></td>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p>Adds support for standalone nodes within a Page node. Standalone nodes are self-contained and can be included after the final multiple outcome node.</p>
</div></div></td>
</tr>
<tr>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><a href="https://docs.pingidentity.com/auth-node-ref/latest/platform-username.html">Platform Username node</a></p>
</div></div></td>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p>Adds an option to prepopulate the username if it’s available in the shared state.</p>
</div></div></td>
</tr>
<tr>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><a href="https://docs.pingidentity.com/auth-node-ref/latest/webauthn-authentication.html">WebAuthn Authentication node</a></p>
</div></div></td>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p>Adds support for the WebAuthn conditional UI, also known as passkey autofill, and removes the ability to return the challenge as JavaScript.</p>
</div></div></td>
</tr>
<tr>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><a href="https://docs.pingidentity.com/auth-node-ref/latest/webauthn-registration.html">WebAuthn Registration node</a></p>
</div></div></td>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p>Removes the ability to return the challenge as JavaScript.</p>
</div></div></td>
</tr>
</tbody>
</table>
<div class="paragraph">
<p>Other node versioning changes include:</p>
</div>
<div class="dlist">
<dl>
<dt class="hdlist1">Resource version <code>3.0</code> for <code>authenticationtrees</code> REST endpoint</dt>
<dd>
<p>We’ve added a version-aware <code>3.0</code> resource to the <code>realm-config/authentication/authenticationtrees</code> endpoint.
When sending a request to this endpoint, set the <code>Accept-API-Version</code> header to <code>protocol=2.1,resource=3.0</code>.</p>
<div class="paragraph">
<p>Resource versions 1.0 and 2.0 are deprecated.</p>
</div>
</dd>
<dt class="hdlist1">Versioned node endpoints</dt>
<dd>
<p>The <code>realm-config/authentication/authenticationtrees/nodes</code> endpoint is now versioned.
Specify the version of the node in the request URL, for example: <code>https://<span class="var"><em>&lt;tenant-env-fqdn&gt;</em></span>/am/json/realms/root/realms/alpha/realm-config/authentication/authenticationtrees/nodes/UsernameCollectorNode/2.0</code>.</p>
<div class="paragraph">
<p>Versionless node endpoints are deprecated.</p>
</div>
</dd>
<dt class="hdlist1">Audit logging</dt>
<dd>
<p>The node version is logged in the <a href="https://docs.pingidentity.com/pingoneaic/tenants/audit-debug-log-sources.html#am-sources" class="xref page">am-authentication</a> source under the <code>AM-NODE-LOGIN-COMPLETED</code> event for node versions greater than <code>1.0</code>.</p>
</dd>
</dl>
</div>
</li>
<li>
<p>IAM-9002: The <strong class="label">Journeys</strong> page now has an <strong class="label">Add journey</strong> button that opens a modal for creating or importing a journey.
This makes the available journey options easier to find.</p>
</li>
<li>
<p>IAM-9608: You can now assign an authorization policy to a SAML or OIDC application. This lets you restrict who can access an application to a subset of end users who have authenticated through a specific journey.
Find more information in <a href="https://docs.pingidentity.com/pingoneaic/app-management/configure-app-authorization-policy.html" class="xref page">Configure an application authorization policy</a>.</p>
</li>
<li>
<p>IAM-9937: The <a href="https://docs.pingidentity.com/pingoneaic/app-management/applications/saas-rest.html" class="xref page">SaaS REST</a> and <a href="https://docs.pingidentity.com/pingoneaic/app-management/applications/saas-rest-rcs.html" class="xref page">SaaS REST (connector server)</a> applications now let you add filter policies to object types when you configure provisioning. Adding filters at the API level reduces network overhead, boosts synchronization performance, and prevents unwanted data from entering your identity pipeline.</p>
</li>
<li>
<p>IAM-10132: The Advanced Identity Cloud admin console is now fully accessible using keyboard controls.</p>
</li>
<li>
<p>IAM-10625: The Custom WS-Fed application now includes logout mode, always authenticate user, and multi-valued claim support for SSO.
Find more information in <a href="https://docs.pingidentity.com/pingoneaic/app-management/register-a-custom-application.html#sso-config-custom-wsfed-app" class="xref page">Configure the custom WS-Fed application</a>.</p>
</li>
<li>
<p>IAM-10626: The Microsoft 365 application now includes logout mode and always authenticate user settings for WS-Trust SSO.
Find more information in <a href="https://docs.pingidentity.com/pingoneaic/app-management/register-a-custom-application.html#sso-microsoft-365-settings" class="xref page">Microsoft 365 Sign On settings</a>.</p>
</li>
<li>
<p>IAM-10810: The PingOne worker service now lets you configure the connection to PingOne using a credential JWT.</p>
</li>
<li>
<p>OPENAM-25759: The <code>jwtValidator</code> script binding now supports configurable clock skew for <code>expirationTime</code> and <code>issuedAt</code> claim validation.</p>
</li>
<li>
<p>OPENAM-25910: The OAuth 2.0 introspection endpoint now supports an RFC 9701-compliant JWT response format. When enabled, token introspection claims are nested under a top-level <code>token_introspection</code> claim, which separates the <code>aud</code> claim of the introspection response from the <code>aud</code> claim of the token itself. The token’s <code>aud</code> claim is also now correctly included for all token types, including stateless tokens.</p>
</li>
<li>
<p>OPENAM-25936: Next-generation scripts now support the <code>utils.crypto.checkBcrypt(bcryptHash, password)</code> method for bcrypt hash verification.</p>
</li>
<li>
<p>OPENAM-25957: All next-generation OAuth 2.0 scripts now have access to the <code>identity</code>, <code>session</code>, <code>clientProperties</code>, and <code>requestProperties</code> bindings.</p>
</li>
<li>
<p>OPENAM-27540: You can now configure a trusted CA certificate for each OAuth 2.0 client using the <code>tls_client_auth</code> authentication method, instead of relying only on realm-wide CAs.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="fixes"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#fixes"></a>Fixes</h4>
<div class="ulist">
<ul>
<li>
<p>AME-34254: Added support for next-generation SAML SP account mapper scripts to the Advanced Identity Cloud admin console.</p>
</li>
<li>
<p>FRAAS-29198: Fixed an issue where promotions that failed due to the encrypted secrets verification check were not listing the configuration paths that needed updating.</p>
</li>
<li>
<p>IAM-5003: Fixed an issue where changing the locale on the terms and conditions creation page didn’t change the text in the editor.</p>
</li>
<li>
<p>IAM-9751: Fixed an accessibility issue where the VoiceOver screen reader was not vocalizing UI text correctly.</p>
</li>
<li>
<p>IAM-10040: Fixed an issue where the browser was incorrectly using autofill if a KBA Definition Node was within a Page node. The issue prevented use of tab and arrow functionality for that node.</p>
</li>
<li>
<p>IAM-10087: Fixed an issue where the password policy on a hosted pages sign-on screen disappeared on a window refresh when the <strong class="label">Access Management</strong> &gt; <strong class="label">Authentication</strong> &gt; <strong class="label">Settings</strong> &gt; <strong class="label">Trees</strong> &gt; <strong class="label">Enable Allowlisting</strong> setting was enabled.</p>
</li>
<li>
<p>IGA-4139<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_2" title="View footnote.">2</a>]</sup>: Updated the access filter component in the IGA access graph to accept dynamic filter options. This lets you use different UI components to customize the available filter options, based on context.</p>
</li>
<li>
<p>IGA-4275<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_2" title="View footnote.">2</a>]</sup>: Fixed a pagination issue in the <span class="label">Direct Reports</span> view by removing sortable columns and default sort from the <span class="label">Direct Reports</span> and <span class="label">Delegates</span> pages.</p>
</li>
<li>
<p>OPENAM-25543: Allowing a SAML authentication flow to continue when a circle of trust (CoT) is inactive is now deprecated.
Review your SAML configurations and ensure that any CoTs used for authentication are active before Advanced Identity Cloud begins enforcing CoT status after the end-of-life date.</p>
</li>
<li>
<p>OPENAM-26359: Added a new configuration option, <span class="label">Enable Rich Authorization Requests with RCS</span>, to the <code>OAuth2 Provider</code> service. This resolves an issue with remote consent where authorize requests with <code>authorization_details</code> would fail with an <code>invalid_request</code> error if an RCS was not configured.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[17 June 2026]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#17_june_2026</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#17_june_2026</guid>
            <pubDate>Wed, 17 Jun 2026 14:19:36 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 21659.11</strong></p>
</div>
<div class="paragraph">
<p>No customer-facing features, enhancements, or fixes released.<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_1" title="View footnote.">1</a>]</sup></p>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[4 June 2026]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#4_june_2026</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#4_june_2026</guid>
            <pubDate>Fri, 05 Jun 2026 08:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 21659.8</strong></p>
</div>
<div class="sect3">
<h4 id="fixes_2"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#fixes_2"></a>Fixes</h4>
<div class="ulist">
<ul>
<li>
<p>FRAAS-32554: Addressed a security issue.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[18 May 2026]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#18_may_2026</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#18_may_2026</guid>
            <pubDate>Tue, 19 May 2026 13:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 21659.7</strong></p>
</div>
<div class="sect3">
<h4 id="enhancements_2"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#enhancements_2"></a>Enhancements</h4>
<div class="ulist">
<ul>
<li>
<p>OPENAM-26335<sup class="footnote" id="_footnote_fn-hotfix">[<a id="_footnoteref_3" class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_3" title="View footnote.">3</a>]</sup>: The <a href="https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-verify-evaluation.html">PingOne Verify Evaluation node</a> now lets you suppress the display of the verification code in the PingOne Verify web UI.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="fixes_3"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#fixes_3"></a>Fixes</h4>
<div class="ulist">
<ul>
<li>
<p>OPENAM-26326<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_3" title="View footnote.">3</a>]</sup>: Added a new configuration option, <span class="label">Enable Rich Authorization Requests with RCS</span>, to the <code>OAuth2 Provider</code> service. This resolves an issue with remote consent where authorize requests with <code>authorization_details</code> would fail with an <code>invalid_request</code> error if an RCS was not configured.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[15 May 2026]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#multi_region_ha_15_may_2026</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#multi_region_ha_15_may_2026</guid>
            <pubDate>Fri, 15 May 2026 15:30:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version N/A</strong></p>
</div>
<div class="sect3">
<h4 id="key_features_2"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#key_features_2"></a>Key features</h4>
<div class="dlist">
<dl>
<dt class="hdlist1">Multi-region high availability (FRAAS-17848)</dt>
<dd>
<p>Advanced Identity Cloud now offers a multi-region high availability deployment option as an <a href="https://docs.pingidentity.com/pingoneaic/product-information/add-on-capabilities.html" class="xref page">add-on capability</a>.
This deployment option hosts identity-related services across both a primary and a secondary region, with data replicated in near real-time.
It allows for rapid failover to the secondary region in the event of a failure in the primary region, with a significantly better recovery time objective (RTO) and recovery point objective (RPO) compared to the default single-region deployment option.</p>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingoneaic/tenants/environments-architecture-availability-disaster-recovery.html" class="xref page">Architecture, availability, and disaster recovery</a>.</p>
</div>
</dd>
</dl>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[08 May 2026]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#08_may_2026</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#08_may_2026</guid>
            <pubDate>Mon, 11 May 2026 09:15:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 21478.4</strong></p>
</div>
<div class="sect3">
<h4 id="key_features_3"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#key_features_3"></a>Key features</h4>
<div class="dlist">
<dl>
<dt class="hdlist1">Snowflake connector (OPENIDM-21957)</dt>
<dd>
<p>The <a href="https://docs.pingidentity.com/openicf/connector-reference/snowflake.html" target="_blank" rel="noopener">Snowflake connector</a> is now bundled with Advanced Identity Cloud.
This new connector allows you to manage users, grant and revoke roles and database roles, and synchronize data between Advanced Identity Cloud and Snowflake.</p>
<div class="paragraph">
<p>Learn more about the <a href="https://docs.pingidentity.com/openicf/connector-release-notes/connectors.html#1_5_20_33_connectors" target="_blank" rel="noopener">1.5.20.33 Connector changes</a>.</p>
</div>
</dd>
<dt class="hdlist1">Identity Governance Access Modeling<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_2" title="View footnote.">2</a>]</sup> (IGA-3696)</dt>
<dd>
<p>Advanced Identity Cloud Identity Governance introduces a new feature called Access Modeling (role mining) that analyzes existing user-to-entitlement assignments to discover potential access roles that reflect how people use access in your environment.
Using advanced machine learning, it examines current roles and entitlements across your access landscape to propose new role candidates and suggest changes to existing ones.</p>
<div class="paragraph">
<p>Access Modeling is an Advanced Identity Cloud add-on capability that integrates with the Identity Governance add-on capability.</p>
</div>
</dd>
</dl>
</div>
</div>
<div class="sect3">
<h4 id="enhancements_3"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#enhancements_3"></a>Enhancements</h4>
<div class="ulist">
<ul>
<li>
<p>IAM-1715: Improve messaging on back button for 404 pages in the Advanced Identity Cloud admin console.</p>
</li>
<li>
<p>IAM-3829: You can now perform dry-run promotions in the Advanced Identity Cloud admin console.</p>
</li>
<li>
<p>IAM-3834: Distinguish between dry-run and actual promotions in the promotion report in the Advanced Identity Cloud admin console.</p>
</li>
<li>
<p>IAM-8149, IAM-8275, IAM-8988: Added the following configuration options to the Advanced Identity Cloud admin console when you create or edit a journey:</p>
<div class="openblock">
<div class="content">
<div class="ulist">
<ul>
<li>
<p><code>Override authenticated session timeout</code>, <code>Maximum Session Time</code>, and <code>Maximum Idle Time</code></p>
</li>
<li>
<p><code>Transactional Only</code></p>
</li>
<li>
<p><code>No Session</code></p>
</li>
</ul>
</div>
<div class="paragraph">
<p>Previously, these settings could only be configured over REST.</p>
</div>
</div>
</div>
</li>
<li>
<p>IAM-8972: You can now configure managed objects and relationships in the Advanced Identity Cloud admin console.</p>
</li>
<li>
<p>IAM-9819<sup class="footnote" id="_footnote_fn-ar">[<a id="_footnoteref_4" class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_4" title="View footnote.">4</a>]</sup>: Added the ability to export custom reports.</p>
</li>
<li>
<p>IAM-9822: You can now perform promotion rollbacks in the Advanced Identity Cloud admin console.</p>
</li>
<li>
<p>IAM-9903<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_4" title="View footnote.">4</a>]</sup>: Added the ability to import custom reports.</p>
</li>
<li>
<p>IAM-9960: Added a wider scope to the monitoring search feature by being able to search on <code>/payload/message</code> and just <code>/payload</code> in cases where the monitoring record’s payload is a string.</p>
</li>
<li>
<p>OPENIDM-22009: All connectors included with Advanced Identity Cloud were upgraded. Learn more in <a href="https://docs.pingidentity.com/openicf/connector-release-notes/connectors.html#1_5_20_34_connectors" target="_blank" rel="noopener">1.5.20.34 Connector changes</a>.</p>
</li>
<li>
<p>IGA-4036: Added the ability to add and remove members of an entitlement directly from the entitlement LCM users tab.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="fixes_4"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#fixes_4"></a>Fixes</h4>
<div class="ulist">
<ul>
<li>
<p>FRAAS-31613: Fixed an issue where password policy updates weren’t properly replicating to the datastore in mutable environments.</p>
</li>
<li>
<p>IAM-1907: Fixed an issue where custom endpoint search showed an incorrect message.</p>
</li>
<li>
<p>IAM-2537: Fixed an issue where non-dashboard URLs didn’t show a 404 page.</p>
</li>
<li>
<p>IAM-2615: Fixed an issue where border radius settings affected the hosted pages editor preview.</p>
</li>
<li>
<p>IAM-3453: Fixed styling issues with the back button.</p>
</li>
<li>
<p>IAM-5439: Fixed an issue where an ESV couldn’t be updated after its last value was deleted.</p>
</li>
<li>
<p>IAM-7502: Fixed an issue where the color in the <code>Card Input Border Focus Color</code> hosted pages setting wasn’t applied to the search field in the <strong class="label">My Applications</strong> hosted account page.</p>
</li>
<li>
<p>IAM-9475: Fixed an issue in the hosted journey pages where a journey was allowed to continue in the event of a password mismatch when a message node was on the same page.</p>
</li>
<li>
<p>IAM-9752: Fixed an issue where VoiceOver gestures didn’t work on drop-down lists.</p>
</li>
<li>
<p>IAM-9842: Fixed an issue where VoiceOver didn’t announce text for some page elements.</p>
</li>
<li>
<p>IAM-9936: Fixed an issue with the query operation in the SaaS REST application where setting the type select field prevented the method select field from being cleared, and the other way around.</p>
</li>
<li>
<p>IAM-9952: Fixed an issue where the table header for the action column was empty on several pages in the hosted account pages.</p>
</li>
<li>
<p>IAM-9958: Fixed an issue where the table header for the action column was empty on several pages in the Advanced Identity Cloud admin console.</p>
</li>
<li>
<p>IAM-10056: Fixed an issue on the <strong class="label">Auth Scripts</strong> page where the modal body failed to load after clicking <strong class="label"><span class="icon"><span class="material-icons-outlined mi-inline">add</span></span> New Script</strong>.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[28 Apr 2026]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#28_apr_2026</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#28_apr_2026</guid>
            <pubDate>Wed, 29 Apr 2026 10:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 21182.12</strong></p>
</div>
<div class="sect3">
<h4 id="enhancements_4"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#enhancements_4"></a>Enhancements</h4>
<div class="dlist">
<dl>
<dt class="hdlist1">New binding for next-generation SP adapter scripts (OPENAM-26050)</dt>
<dd>
<p>A new <code>authnRequestHelper</code> binding has been added for next-generation SP adapter scripts. This binding lets you retrieve and modify the destination property of the <code>AuthnRequest</code>.</p>
<div class="paragraph">
<p>Find more information in <a href="https://docs.pingidentity.com/pingoneaic/am-scripting/saml2-sp-adapter-api.html" class="xref page">SP adapter scripting API</a>.</p>
</div>
</dd>
</dl>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[23 Apr 2026]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#23_apr_2026</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#23_apr_2026</guid>
            <pubDate>Fri, 24 Apr 2026 10:30:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 21182.10</strong></p>
</div>
<div class="paragraph">
<p>No customer-facing features, enhancements, or fixes released.<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_1" title="View footnote.">1</a>]</sup></p>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[14 Apr 2026]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#14_apr_2026</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#14_apr_2026</guid>
            <pubDate>Mon, 20 Apr 2026 09:00:06 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 21182.9</strong></p>
</div>
<div class="sect3">
<h4 id="key_features_4"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#key_features_4"></a>Key features</h4>
<div class="dlist">
<dl>
<dt class="hdlist1">Partial support for Rich Authorization Requests (RAR) (AME-28325)</dt>
<dd>
<p>The <code>/authorize</code> and <code>/par</code> endpoints now optionally accept the <code>authorization_details</code> parameter from the RAR (Rich Authorization Requests) specification RFC 9396, allowing clients to specify fine-grained authorization requirements.</p>
</dd>
<dt class="hdlist1">App Policy Decision node (AME-30063)</dt>
<dd>
<p>A new <a href="https://docs.pingidentity.com/auth-node-ref/latest/app-policy-decision.html">App Policy Decision node</a> is a specialized
policy node that lets you enforce OIDC and SAML application access policies in journeys. You can use
the node to filter access by group, organization, and more.</p>
</dd>
<dt class="hdlist1">Support for audience parameter in token exchange (AME-33970)</dt>
<dd>
<p>A client can now specify audience parameters in OAuth 2.0 Token Exchange requests. These parameters can be allowlisted and, if valid, are included in the audience claim of the resulting token.</p>
</dd>
<dt class="hdlist1">Next-generation scripted JWT operations (OPENAM-25836)</dt>
<dd>
<p>The <code>jwtValidator</code> and <code>jwtAssertion</code> bindings are now available in all next-generation scripts.</p>
</dd>
</dl>
</div>
</div>
<div class="sect3">
<h4 id="enhancements_5"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#enhancements_5"></a>Enhancements</h4>
<div class="ulist">
<ul>
<li>
<p>AME-33573: Next-generation scripts now include <code>utils.base64url.encode()</code> and <code>utils.base64url.decodeToBytes()</code> for Base64URL encoding and decoding.</p>
</li>
<li>
<p>AME-33971: Added a new <span class="label">Save and Test Connection</span> button to the PingOne worker configuration screen allowing you to validate the connection.</p>
</li>
<li>
<p>AME-33973: You can now configure the PingOne Worker Service connection using a credential JWT.</p>
</li>
<li>
<p>AME-34248: You can now use next-generation scripts in the Social Provider Handler node to transform normalized profile data into identities or managed users.</p>
</li>
<li>
<p>AME-34249: You can now use next-generation scripts in the OIDC ID Token Validator node. The <code>jwtClaims</code> binding now behaves as a native JavaScript object.</p>
</li>
<li>
<p>AME-34540: You can now specify autocomplete attributes for username nodes.</p>
</li>
<li>
<p>OPENAM-21474: A new <code>Minimum max_age for Authorize Requests</code> property is now available in the advanced OIDC settings of the OAuth 2.0 provider service.</p>
</li>
<li>
<p>OPENAM-24523: You can now dynamically modify the scopes of a refresh token during the refresh flow with the new next-generation scope validation script binding, <code>scopeValidatorHelper</code>, and its method, <code>inheritAccessTokenScopesOnRefresh()</code>. This is useful when scope validation scripts alter access token scopes and you need the refresh token to inherit those changes.</p>
</li>
<li>
<p>OPENAM-25901: Next-generation OAuth 2.0 scope validation scripts now have access to the <code>availableScopes</code> binding, which lists all scopes configured for the client. A new <code>throwInvalidScope()</code> method is also available to simplify error handling.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="fixes_5"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#fixes_5"></a>Fixes</h4>
<div class="ulist">
<ul>
<li>
<p>AME-34216, AME-34398: When using an SSO token as the subject for a policy with an <code>IDM user</code> environment condition,
it now correctly resolves to the IDM <code>_id</code> instead of the user’s AM universal ID.</p>
<div class="paragraph">
<p>You can temporarily revert this behavior by setting the ESV <code>esv.am.policy.condition.idm.universalId</code> to <code>true</code> to let you update policies to use another property.</p>
</div>
</li>
<li>
<p>AME-34329: By default, parallel updates can no longer be made for CTS sessions. You can revert this behavior by setting the ESV <code>esv.cts.use.etag.assertion.on.updates</code> to <code>false</code>.</p>
</li>
<li>
<p>FRAAS-31318: Fixed an issue where setting certain special characters in an ESV prevented the ESV from being interpreted correctly.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[10 Apr 2026]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#10_apr_2026</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#10_apr_2026</guid>
            <pubDate>Tue, 14 Apr 2026 07:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 21027.5</strong></p>
</div>
<div class="paragraph">
<p>No customer-facing features, enhancements, or fixes released.<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_1" title="View footnote.">1</a>]</sup></p>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[01 April 2026]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#01_april_2026</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#01_april_2026</guid>
            <pubDate>Wed, 08 Apr 2026 11:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 21027.2</strong></p>
</div>
<div class="sect3">
<h4 id="key_features_5"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#key_features_5"></a>Key features</h4>
<div class="dlist">
<dl>
<dt class="hdlist1">Policy Decision node (AME-28779)</dt>
<dd>
<p>A new <a href="https://docs.pingidentity.com/auth-node-ref/latest/policy-decision.html">Policy Decision node</a> lets you evaluate an authorization policy against resources within an authentication journey.</p>
</dd>
<dt class="hdlist1">Backchannel Notification node (AME-32579)</dt>
<dd>
<p>Introduced a new <a href="https://docs.pingidentity.com/auth-node-ref/latest/backchannel-notification.html">Backchannel Notification node</a> that allows a backchannel journey to send real-time status updates to the main authentication journey.</p>
</dd>
</dl>
</div>
</div>
<div class="sect3">
<h4 id="enhancements_6"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#enhancements_6"></a>Enhancements</h4>
<div class="ulist">
<ul>
<li>
<p>FRAAS-28387: Invites for Advanced Identity Cloud tenant registration now use a one-time passcode (OTP) instead of a magic link.
This change prevents email scanners from accidentally invalidating single-use links.</p>
</li>
<li>
<p>AME-29745: Improved the certificate validation process in the Certificate Collector and Certificate Validation nodes. By default, Advanced Identity Cloud collects the <em>first</em> certificate in a certificate chain (the user certificate). You can now create an ESV named <code>esv-am-nodes-certificatechain-validation-enforced</code> and set its value to <code>true</code> to collect the chain of certificates.</p>
</li>
<li>
<p>AME-33851: You can now use next-generation scripts for social identity provider transformation scripts.</p>
</li>
<li>
<p>OPENAM-23610: The default value for the <span class="label">Return challenge as JavaScript (Legacy)</span> property on the WebAuthn Authentication and WebAuthn Registration nodes is now not enabled. Ping Identity recommends that you keep this setting.</p>
</li>
<li>
<p>OPENAM-25329: The PingOne Protect Initialize node now includes an <code>Additional Signals SDK Initialization Options</code> attribute. This allows you to configure options that aren’t already defined in the node. The <code>PingOneProtectInitializeCallback</code> has been updated with new fields to support this.</p>
</li>
<li>
<p>OPENAM-25677: The <code>PingOneProtectInitializeCallback</code> now includes a <code>universalDeviceIdentification</code> field, which replaces the deprecated <code>enableTrust</code> field. The <code>enableTrust</code> field is still returned for backward compatibility.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="fixes_6"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#fixes_6"></a>Fixes</h4>
<div class="ulist">
<ul>
<li>
<p>IGA-4186<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_2" title="View footnote.">2</a>]</sup>: Fixed an issue for user LCM in the hosted account pages where large user populations weren’t correctly sorted and paginated.</p>
</li>
<li>
<p>OPENAM-22698: Fixed a bug that caused duplicate URIs in WS-Federation responses.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[31 Mar 2026]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#31_mar_2026</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#31_mar_2026</guid>
            <pubDate>Wed, 01 Apr 2026 10:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 20814.9</strong></p>
</div>
<div class="sect3">
<h4 id="enhancements_7"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#enhancements_7"></a>Enhancements</h4>
<div class="ulist">
<ul>
<li>
<p>The following OAuth 2.0 scripts can now use the next-generation scripting engine, which gives them access to common bindings such as <code>utils</code> and <code>openidm</code>:</p>
<div class="ulist">
<ul>
<li>
<p>AME-33228: OIDC claims</p>
</li>
<li>
<p>AME-33846: Scripted JWT validator</p>
</li>
<li>
<p>AME-33847: Scope validation</p>
</li>
<li>
<p>AME-33848: Authorize endpoint data provider</p>
</li>
<li>
<p>AME-33849: Scope evaluation</p>
</li>
<li>
<p>AME-33850: May act</p>
</li>
</ul>
</div>
</li>
<li>
<p>The following SAML 2.0 scripts can now use the next-generation scripting engine, which gives them access to common bindings such as <code>utils</code> and <code>openidm</code>:</p>
<div class="ulist">
<ul>
<li>
<p>AME-32919: SP adapter</p>
</li>
<li>
<p>AME-32920: IDP adapter</p>
</li>
<li>
<p>AME-32921: IDP attribute mapper</p>
</li>
</ul>
</div>
</li>
<li>
<p>AME-32969: You can now make sure the <code>samlApplication</code> binding is available for all SAML flows by enabling the application context in the hosted IdP or remote SP entity configuration.  Previously this was only added in certain situations such as when using an application journey or IdP-initiated integrated mode.</p>
</li>
<li>
<p>AME-32997: Added an <code>Allow Retry</code> option to the Backchannel Initialize node that lets end users retry a failed backchannel authentication journey.</p>
</li>
<li>
<p>AME-33430: You can now include remote consent agent credentials in a <code>Basic Authentication</code> header for pushed consent requests.</p>
</li>
<li>
<p>AME-33930: A new <code>testConnection</code> action on the <code>realm-config/services/pingOneWorkerService/workers/<span class="var">pingone-worker-service-name</span></code> endpoint lets you test the connection from Advanced Identity Cloud to PingOne.</p>
</li>
<li>
<p>AME-33939: A new <code>listLatestNodeDefinitions</code> action on the <code>realm-config/authentication/authenticationtrees/nodes</code> endpoint provides a list of node definitions for the <em>latest</em> version of each node.</p>
<div class="paragraph">
<p>This action combines the responses from the following separate actions into a single response:</p>
</div>
<div class="ulist">
<ul>
<li>
<p><code>getAllTypes</code> action on the <code>realm-config/authentication/authenticationtrees/nodes</code> endpoint</p>
</li>
<li>
<p><code>schema</code>, <code>template</code> and <code>listOutcomes</code> actions on the <code>realm-config/authentication/authenticationtrees/nodes/<span class="var">node-name</span></code> endpoint</p>
</li>
</ul>
</div>
</li>
<li>
<p>ANALYTICS-1383<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_4" title="View footnote.">4</a>]</sup>: The new historical change report feature provides a complete audit trail of changes to your managed identities. It tracks all modifications to user profiles, roles, accounts, and applications. You can easily generate reports to see what changed, who made the change, and when it happened, which gives you clear insights for compliance and security monitoring.</p>
</li>
<li>
<p>FRAAS-29084: Custom domains are now restricted to a maximum of 63 characters in the Advanced Identity Cloud admin console. This restriction has always existed on the system backend.</p>
</li>
<li>
<p>OPENAM-22125: A new <span class="label">Proxy Configuration</span> tab in the <span class="label">Http Client Service</span> configuration lets you use separate proxy configurations per HTTP Client instance.</p>
</li>
<li>
<p>OPENAM-24476: Added <code>java.util.zip</code> classes to the allowlist for the Scripted Decision node scripting context.</p>
</li>
<li>
<p>The following enhancements have been made to the nodes provided with Advanced Identity Cloud:</p>
<div class="ulist">
<ul>
<li>
<p>AME-33009: Enhanced the RADIUS Decision node to capture Vendor-Specific Attributes (VSA) returned by the RADIUS server during authentication.</p>
</li>
<li>
<p>Enhancements to the PingOne Protect Evaluation node:</p>
<div class="ulist">
<ul>
<li>
<p>AME-33807: Fixed an issue where a default value was sent for the flow subtype. Previously, the node would fall back to using the value configured in <span class="label">Authentication Flow Subtype</span>  or <span class="label">Authorization Flow Subtype</span>. Now, if nothing is found in the node state, the node doesn’t send a value to PingOne Protect.</p>
</li>
<li>
<p>OPENAM-24557: Added a configuration property that lets you specify a custom session ID in the node state.</p>
</li>
<li>
<p>OPENAM-24562: Added two configuration properties that let you include a custom browser cookie and any externally maintained <code>deviceId</code> in the request sent to PingOne.</p>
</li>
<li>
<p>OPENAM-25553: Added a configuration property that lets you include user group information as part of a risk evaluation.</p>
</li>
</ul>
</div>
</li>
<li>
<p>The following nodes now let you set custom headers on journey success, failure, and error:</p>
<div class="ulist">
<ul>
<li>
<p>AME-33813: Set Success Details node</p>
</li>
<li>
<p>AME-33874: Set Failure Details node</p>
</li>
<li>
<p>AME-33873: Set Error Details node</p>
</li>
</ul>
</div>
</li>
<li>
<p>OPENAM-24401: The CAPTCHA node now prevents submission after expiry.</p>
</li>
<li>
<p>OPENAM-24419: Added a new <a href="https://docs.pingidentity.com/auth-node-ref/latest/rsa-securid.html">RSA SecurID</a> node. This node replaces the Marketplace RSA SecurID node, which is now deprecated.</p>
</li>
<li>
<p>OPENAM-24489: The Device Binding and Device Signing Verifier nodes now let you specify a clock skew between the client device and AIC. This helps prevent binding failures caused by clocks being out of sync.</p>
</li>
<li>
<p>OPENAM-24546: Removed certain unused and unsupported configuration properties from the PingOne Protect Initialize node and its associated callback (<code>PingOneProtectInitializeCallback</code>).</p>
</li>
<li>
<p>OPENAM-25372: Added a <a href="https://docs.pingidentity.com/auth-node-ref/latest/jwt-password-replay.html">JWT Password Replay</a> node to secure the user’s password within an encrypted JSON Web Token (JWT). This node is used by PingGateway and replaces the old Password Replay scripting functionality.</p>
</li>
</ul>
</div>
</li>
<li>
<p>OPENAM-25371: Added a configuration property to the PingOne Verify Evaluation node to enable automatic redirection to the journey after an end user completes verification (when using the <code>Redirect</code> delivery mode).</p>
</li>
<li>
<p>OPENAM-25618: The new <code>locales</code> binding lets you return the localized version of a string from a translation map. It is available to next-generation Configuration Provider node, Journey Decision node, and Device Match node scripts.</p>
</li>
<li>
<p>OPENIDM-21493: You can now cancel a clustered reconciliation even when a route associated with the source or target system is unavailable.</p>
</li>
<li>
<p>AME-34191: You can now override the HTTP binding used to redirect users to the SAML error page. To do this, configure an <a href="https://docs.pingidentity.com/pingoneaic/tenants/esvs.html#variables" class="xref page">ESV variable</a> named <code>esv-global-saml-error-page-http-binding</code> and set its value to <code>HTTP-POST</code> or <code>HTTP-Redirect</code>. If you don’t set this variable, Advanced Identity Cloud uses the default value of <code>HTTP-POST</code>.</p>
</li>
<li>
<p>IAM-6546: End users now have more options to manage their devices in the hosted account pages.
For each device, they can view when it was last used for sign on, view when it was added, edit its name, and delete it.</p>
</li>
<li>
<p>IAM-9672: In the advanced sync <strong class="label">Mapping</strong> tab, if no properties have been mapped, it now shows a more accurate description of the target and source identity objects whose properties can be mapped.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="fixes_7"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#fixes_7"></a>Fixes</h4>
<div class="ulist">
<ul>
<li>
<p>AME-33653: Custom nodes now work with the Configuration Provider node.</p>
</li>
<li>
<p>AME-33808: If <span class="label">Node State Attribute For User ID</span> is provided in the PingOne Protect Evaluation node, but the corresponding attribute is missing from the node state, the node triggers the failure outcome rather than using the user ID associated with the AM identity.</p>
</li>
<li>
<p>AME-34217: Added a version setting to the Configuration Provider node. This update provides the underlying infrastructure for a node versioning feature in an upcoming release.</p>
</li>
<li>
<p>AME-34034: Fixed an issue where omitting a shared secret label in the RADIUS Decision node caused Prometheus metrics to become unavailable.</p>
</li>
<li>
<p>ANALYTICS-1326<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_4" title="View footnote.">4</a>]</sup>: Fixed an issue in custom reports caused by relationships between custom identities that contain multiple underscores.</p>
</li>
<li>
<p>ANALYTICS-1367<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_4" title="View footnote.">4</a>]</sup>: Fixed an issue in custom reports caused by IP addresses in journey events.</p>
</li>
<li>
<p>OPENAM-23918: Resolved a race condition in the OATH Registration node and OATH Device Storage node where recovery codes could potentially be lost.</p>
</li>
<li>
<p>OPENAM-24065: Improved consistency for error responses across realms when processing illegal arguments. The <code>/authenticate</code> call now correctly returns a 400 (Bad Request) instead of a 500 (Internal Server Error) for invalid arguments.</p>
</li>
<li>
<p>OPENAM-25406: Added an <code>identity.exists()</code> method to next-generation objects returned by <code>idRepository.getIdentity()</code>. This lets scripts verify an identity’s existence in the identity store before further processing.</p>
</li>
<li>
<p>OPENAM-25646: For backward compatibility, we’ve restored the following deprecated fields sent to PingOne Protect by the PingOne Protect Initialize node (in the <code>PingOneProtectInitializeCallback</code>):</p>
<div class="openblock">
<div class="content">
<div class="ulist">
<ul>
<li>
<p><code>consoleLogEnabled</code></p>
</li>
<li>
<p><code>deviceAttributesIgnored</code></p>
</li>
<li>
<p><code>customHost</code></p>
</li>
<li>
<p><code>lazyMetadata</code></p>
</li>
<li>
<p><code>deviceKeyRsyncIntervals</code></p>
</li>
<li>
<p><code>disableHub</code></p>
</li>
</ul>
</div>
</div>
</div>
<div class="admonitionblock note">
<table>
<tbody><tr>
<td class="icon">
<i class="fa icon-note" title="Note"></i>
</td>
<td class="content">
These fields are deprecated and no longer supported in PingOne. This fix restores the fields but you should update your clients and scripts to remove the unsupported fields as soon as possible.
</td>
</tr>
</tbody></table>
</div>
</li>
<li>
<p>OPENAM-25779: Deletion of the <code>samlApplication</code> object is now deferred for unsuccessful authentication journeys so that the object is still available for subsequent sign-on attempts in the same session.</p>
</li>
<li>
<p>IAM-6640: Fixed an issue in the hosted pages theme preview where clicking <strong class="label">Edit Personal Info</strong> opened two instances of the modal.</p>
</li>
<li>
<p>IAM-8221: Fixed an issue in the terms &amp; conditions live preview where interactive elements weren’t disabled.</p>
</li>
<li>
<p>IAM-9620<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_2" title="View footnote.">2</a>]</sup>: Fixed an Identity Governance issue where clicking <strong class="label">Save</strong> in the certification template creation wizard didn’t disable the button after submission, which could result in the creation of unintended duplicate templates.</p>
</li>
<li>
<p>IAM-9786: Fixed an issue where ESV placeholders manually entered into a field were always treated as strings, regardless of whether they were an array, list, or string.</p>
</li>
<li>
<p>IAM-9886: Fixed a display issue on the <strong class="label">Reports Run History</strong> tab where the pop-up menu items weren’t displayed correctly.</p>
</li>
<li>
<p>FRAAS-29855<sup class="footnote" id="_footnote_fn-norapid">[<a id="_footnoteref_5" class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_5" title="View footnote.">5</a>]</sup>: Fixed an issue where OTLP log streaming reported all Advanced Identity Cloud logs with <code>am-core</code> or <code>idm-core</code> as the source and omitted custom IDM event-hook logs.
Logs streamed via OTLP now preserve their correct source (for example, <code>am-authentication</code>, <code>am-access</code>, <code>idm-access</code>) and include custom IDM event-hook messages.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="changed_functionality"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#changed_functionality"></a>Changed functionality</h4>
<div class="ulist">
<ul>
<li>
<p>OPENIDM-21718: The <code>maxQueueSize</code> for <a href="https://docs.pingidentity.com/pingoneaic/idm-synchronization/chap-implicit-live-sync.html#queued-sync" class="xref page">queued synchronization</a> now defaults to <code>1000</code> and can’t be configured to a value higher than <code>1000</code> or lower than <code>100</code>. The previous default was <code>20000</code>.</p>
<div class="paragraph">
<p>The <code>pageSize</code> still defaults to <code>100</code>, but now can’t be configured to a value higher than <code>100</code> or lower than <code>10</code>. If the configured <code>pageSize</code> is greater than <code>maxQueueSize / 10</code>, Advanced Identity Cloud uses <code>maxQueueSize / 10</code> for the page size.</p>
</div>
<div class="paragraph">
<p>If you have any configuration outside of these bounds, Advanced Identity Cloud automatically adjusts the values to the nearest bound.</p>
</div>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[26 Mar 2026]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#rcs_1_5_20_34</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#rcs_1_5_20_34</guid>
            <pubDate>Thu, 26 Mar 2026 16:23:42 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version N/A</strong></p>
</div>
<div class="sect3">
<h4 id="related_product_changes"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#related_product_changes"></a>Related product changes</h4>
<div class="admonitionblock note">
<table>
<tbody><tr>
<td class="icon">
<i class="fa icon-note" title="What are related releases?"></i>
</td>
<td class="content">
<div class="paragraph">
<p>This section contains information about other Ping Identity products that are often deployed as part of an Advanced Identity Cloud implementation.</p>
</div>
</td>
</tr>
</tbody></table>
</div>
<div class="ulist">
<ul>
<li>
<p>RCS 1.5.20.34 is now available to <a href="https://backstage.pingidentity.com/downloads/browse/identity-cloud/all/productId:idm-connector-servers/minorVersion:1.5/version:1.5.20.34/language:java" target="_blank" rel="noopener">download</a>. To take advantage of these updates, you must manually upgrade your RCS implementation.
Learn more in <a href="https://docs.pingidentity.com/openicf/connector-release-notes/preface.html" target="_blank" rel="noopener">ICF release notes</a>.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[17 Mar 2026]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#deprecation-non-persisted-schedules-2026-03-17</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#deprecation-non-persisted-schedules-2026-03-17</guid>
            <pubDate>Tue, 17 Mar 2026 08:15:16 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version N/A</strong></p>
</div>
<div class="sect3">
<h4 id="deprecations"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#deprecations"></a>Deprecations</h4>
<div class="dlist">
<dl>
<dt class="hdlist1">Non-persisted schedules deprecated</dt>
<dd>
<p>Non-persisted (in memory) schedules are now deprecated. Update your tenants to use <a href="https://docs.pingidentity.com/pingoneaic/idm-schedules/persistent-schedules.html" class="xref page">persisted schedules</a>. You can continue to use non-persisted schedules in the short term, but they will be removed on the <a href="https://docs.pingidentity.com/pingoneaic/product-information/deprecation-notices.html#deprecation-non-persisted-schedules" class="xref page">end-of-life date</a>.</p>
</dd>
</dl>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[10 Mar 2026]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#rcs_1_5_20_33</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#rcs_1_5_20_33</guid>
            <pubDate>Tue, 10 Mar 2026 22:24:36 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version N/A</strong></p>
</div>
<div class="sect3">
<h4 id="related_product_changes_2"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#related_product_changes_2"></a>Related product changes</h4>
<div class="admonitionblock note">
<table>
<tbody><tr>
<td class="icon">
<i class="fa icon-note" title="What are related releases?"></i>
</td>
<td class="content">
<div class="paragraph">
<p>This section contains information about other Ping Identity products that are often deployed as part of an Advanced Identity Cloud implementation.</p>
</div>
</td>
</tr>
</tbody></table>
</div>
<div class="ulist">
<ul>
<li>
<p>RCS 1.5.20.33 is now available to <a href="https://backstage.pingidentity.com/downloads/browse/identity-cloud/all/productId:idm-connector-servers/minorVersion:1.5/version:1.5.20.33/language:java" target="_blank" rel="noopener">download</a>. To take advantage of these updates, you must manually upgrade your RCS implementation.
Learn more in <a href="https://docs.pingidentity.com/openicf/connector-release-notes/preface.html" target="_blank" rel="noopener">ICF release notes</a>.</p>
</li>
<li>
<p>Support for using older versions of the web agent with Advanced Identity Cloud is now deprecated.
If you have web agents in your deployment, you should upgrade to 2024.11.2 or 2025.9 and later to ensure you remain compatible in the future.
Learn more in <a href="https://docs.pingidentity.com/web-agents/latest/release-notes/changes.html">Incompatible changes</a>.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[26 Feb 2026]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#26_feb_2026</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#26_feb_2026</guid>
            <pubDate>Fri, 27 Feb 2026 06:49:37 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 20512.6</strong></p>
</div>
<div class="sect3">
<h4 id="changed_functionality_2"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#changed_functionality_2"></a>Changed functionality</h4>
<div class="dlist">
<dl>
<dt class="hdlist1">Connector server access configuration now added to all tenants (OPENIDM-21744)</dt>
<dd>
<p>Ping Identity previously introduced access configuration that lets you lock down Advanced Identity Cloud connector servers so that each connector server can be accessed only by an RCS connector using that connector server’s designated OAuth 2.0 client.
This prevents an RCS connector associated with a particular connector server from gaining unauthorized access to the resources of other connector servers.</p>
<div class="paragraph">
<p>When this access configuration was introduced, it was added to new tenants by default, but needed to be manually added to existing tenants.
With this change, the access configuration has been added to all existing tenants too.</p>
</div>
<div class="paragraph">
<p>The access configuration adds access rules for connector servers using the <code>RCSClient</code> OAuth 2.0 client.
If you have connector servers that use a specific OAuth 2.0 client, and you haven’t already added this access configuration to your tenant configuration, you need to check or modify the configuration as described in <a href="https://docs.pingidentity.com/pingoneaic/product-information/migration-dependent-features/rcs-configuration-migration-faq.html#connector-servers-using-specific-oauth2-clients" class="xref page">Connector servers using specific OAuth 2.0 clients</a>.</p>
</div>
</dd>
</dl>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[23 Feb 2026]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#ws_trust_ms365_upn_23_feb_2026</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#ws_trust_ms365_upn_23_feb_2026</guid>
            <pubDate>Tue, 24 Feb 2026 20:24:36 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version N/A</strong></p>
</div>
<div class="sect3">
<h4 id="key_features_6"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#key_features_6"></a>Key features</h4>
<div class="dlist">
<dl>
<dt class="hdlist1">User Principal Name (UPN) mapping available for Microsoft 365 WS-Trust SSO applications (IAM-9896<sup class="footnote" id="_footnote_addon_footnote_ig_requires">[<a id="_footnoteref_6" class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_6" title="View footnote.">6</a>]</sup>)</dt>
<dd>
<p>Microsoft 365 SSO applications that use the WS-Trust protocol can now map an attribute to the UPN.
Learn more in <a href="https://docs.pingidentity.com/pingoneaic/app-management/register-a-custom-application.html#ws-trust-config" class="xref page">Configure WS-Trust</a>.</p>
<div class="admonitionblock note">
<table>
<tbody><tr>
<td class="icon">
<i class="fa icon-note" title="Note"></i>
</td>
<td class="content">
This feature requires Advanced Identity Cloud version 20512.5 or later.
</td>
</tr>
</tbody></table>
</div>
</dd>
</dl>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[17 Feb 2026]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#17_feb_2026</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#17_feb_2026</guid>
            <pubDate>Tue, 24 Feb 2026 13:24:36 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 20512.5</strong></p>
</div>
<div class="sect3">
<h4 id="key_features_7"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#key_features_7"></a>Key features</h4>
<div class="dlist">
<dl>
<dt class="hdlist1">Identity Governance user-access graph (IGA-4051<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_5" title="View footnote.">5</a>]</sup><sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_2" title="View footnote.">2</a>]</sup>)</dt>
<dd>
<p>The user-access graph provides a graphical view of an end user’s access.
It visualizes the links between an end user and their types of access, such as roles, applications, or entitlements.
Identity Governance administrators can view graphs in the Advanced Identity Cloud admin console, and end users can view their own graph in the hosted account pages.</p>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingoneaic/identity-governance/administration/view-access-graph.html" class="xref page">View the user-access graph</a>.</p>
</div>
</dd>
<dt class="hdlist1">Two-factor authentication report <sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_5" title="View footnote.">5</a>]</sup><sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_4" title="View footnote.">4</a>]</sup></dt>
<dd>
<p>Advanced Reporting now lets you include information in your reports about the two-factor authentication (2FA) configurations of your end users.
This includes the specific authentication methods each end user has registered and when each method was last used.
This provides administrators with greater insight into second-factor adoption and helps ensure compliance with security policies.</p>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingoneaic/reports/administration/reports-2FA-profile-attributes.html" class="xref page">Report for two-factor authentication</a>.</p>
</div>
</dd>
</dl>
</div>
</div>
<div class="sect3">
<h4 id="enhancements_8"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#enhancements_8"></a>Enhancements</h4>
<div class="ulist">
<ul>
<li>
<p>FRAAS-23284: RCS connections to Advanced Identity Cloud now have a default timeout value of <code>10000</code> (10 seconds) for new tenants. Existing tenants retain the default timeout value of <code>-1</code> (no timeout).</p>
</li>
<li>
<p>FRAAS-29829: Removed a reference to "PingOne Advanced Identity Cloud" from the <code>404 Not Found</code> error page.</p>
</li>
<li>
<p>IAM-4464: Next-generation configuration provider scripts created through the journey editor now contain the default config for the selected node type.</p>
</li>
<li>
<p>IAM-9709: Updated the journey editor to make fewer network calls when saving a journey that contains page nodes.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="fixes_8"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#fixes_8"></a>Fixes</h4>
<div class="ulist">
<ul>
<li>
<p>IAM-4345: Fixed an issue where vertical tabs were missing a hover state.</p>
</li>
<li>
<p>IAM-8033: Journey name field did not have a length check in place.</p>
</li>
<li>
<p>IAM-8226: When importing a journey, if you skip the download backup option but then return to it using the <strong class="label">Previous</strong> link, it now completes the backup before offering the download.</p>
</li>
<li>
<p>IAM-9590: The message shown in the hosted pages for an unauthorized access attempt is now correctly centered on a single page.</p>
</li>
<li>
<p>IAM-9687: When you enter a valid ESV placeholder in the URL field of a bookmark application, the field is now immediately disabled and shows a delete icon to remove the placeholder.</p>
</li>
<li>
<p>IGA-4085<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_2" title="View footnote.">2</a>]</sup><sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_5" title="View footnote.">5</a>]</sup>: Fixed an Identity Governance access request issue where glossary schema properties displayed an extra space for nonexistent icons.</p>
</li>
<li>
<p>IGA-3980<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_2" title="View footnote.">2</a>]</sup><sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_5" title="View footnote.">5</a>]</sup>: Fixed an Identity Governance certification issue where the certification count on the <strong class="label">Summary</strong> page didn’t include the <code>certificationType</code> query parameter.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[11 Feb 2026]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#11_feb_2026</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#11_feb_2026</guid>
            <pubDate>Thu, 12 Feb 2026 19:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 20340.8</strong></p>
</div>
<div class="sect3">
<h4 id="fixes_9"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#fixes_9"></a>Fixes</h4>
<div class="ulist">
<ul>
<li>
<p>OPENAM-25702: The <a href="https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-protect-evaluation.html">PingOne Protect Evaluation node</a> again supports a <span class="label">Node State Attribute For Username</span> setting. PingOne Protect risk evaluation calls can depend on the username.</p>
</li>
<li>
<p>OPENIDM-21776: The Advanced Identity Cloud identity management service now uses synchronous HTTP client requests to connect to external identity management, REST, and token introspection services. This change prevents connection closure exceptions from terminating reconciliation.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[03 Feb 2026]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#03_feb_2026</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#03_feb_2026</guid>
            <pubDate>Tue, 03 Feb 2026 16:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 20340.5</strong></p>
</div>
<div class="sect3">
<h4 id="fixes_10"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#fixes_10"></a>Fixes</h4>
<div class="ulist">
<ul>
<li>
<p>FRAAS-13233: AM script validation now ignores ESV placeholders in commented-out code.</p>
</li>
<li>
<p>IAM-9803: The link to the access management native console from the Advanced Identity Cloud admin console now always correctly links to the Alpha or Bravo realm.</p>
</li>
<li>
<p>OPENAM-25707: Fixed <a href="https://docs.pingidentity.com/pingoneaic/am-authentication/callbacks-interactive.html#PingOneProtectInitializeCallback" class="xref page">PingOneProtectInitializeCallback</a> processing to prevent unwarranted HTTP 4xx and 5xx errors.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[27 Jan 2026]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#27_jan_2026</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#27_jan_2026</guid>
            <pubDate>Tue, 27 Jan 2026 17:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 20133.10</strong></p>
</div>
<div class="sect3">
<h4 id="fixes_11"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#fixes_11"></a>Fixes</h4>
<div class="ulist">
<ul>
<li>
<p>OPENDJ-11576<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_5" title="View footnote.">5</a>]</sup>: Empty user attribute values are no longer considered when evaluating password policies.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[21 Jan 2026]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#21_jan_2026</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#21_jan_2026</guid>
            <pubDate>Fri, 23 Jan 2026 15:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 20133.8</strong></p>
</div>
<div class="sect3">
<h4 id="key_features_8"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#key_features_8"></a>Key features</h4>
<div class="dlist">
<dl>
<dt class="hdlist1">AD Decision node to authenticate against Active Directory identity stores (AME-14959)</dt>
<dd>
<p>The new <a href="https://docs.pingidentity.com/auth-node-ref/latest/ad-decision.html">AD Decision node</a> verifies that the provided username and password exist in the specified Active Directory data store.
The node also checks whether the user account is locked, disabled, or has expired.</p>
</dd>
<dt class="hdlist1">Cache management service (AME-32248, AME-32285)</dt>
<dd>
<p>A new scripted cache management service lets you create and use caches in Scripted Decision nodes. This can improve performance for slow tasks, such as fetching access tokens for third party services that can be reused between journeys. The service has its own metrics.</p>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingoneaic/am-scripting/cache-manager.html" class="xref page">Cache script values</a>.</p>
</div>
</dd>
<dt class="hdlist1">SAML 2.0 SP account mapper (OPENAM-23986)</dt>
<dd>
<p>A new SAML 2.0 SP account mapper script type enables dynamic modification of SAML assertion data before it’s used to identify local users.</p>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingoneaic/am-saml2/custom-sp-account-mapper.html" class="xref page">SP account mapper</a>.</p>
</div>
</dd>
<dt class="hdlist1">Support for SAML 2.0 IdP-initiated flows in integrated mode (AME-29258)</dt>
<dd>
<p>You can now configure the hosted SP to redirect to a journey when a response is received from the IdP.</p>
<div class="paragraph">
<p>Use the new configuration option to check that the IdP entity ID in the incoming SAML assertion matches the IdP entity ID configured for the node.</p>
</div>
<div class="paragraph">
<p>A new method has also been added to the <code>samlApplication</code> script binding that returns the assertion as a JSON map.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingoneaic/am-saml2/configure-providers.html#config-redirect-journey" class="xref page">Redirect to a journey on the hosted SP</a>.</p>
</div>
</dd>
<dt class="hdlist1">RADIUS authentication nodes (AME-32871)<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_5" title="View footnote.">5</a>]</sup></dt>
<dd>
<p>The new <a href="https://docs.pingidentity.com/auth-node-ref/latest/radius-decision.html">RADIUS Decision node</a> and <a href="https://docs.pingidentity.com/auth-node-ref/latest/radius-challenge-collector.html">RADIUS Challenge Collector node</a> provide <a href="https://docs.pingidentity.com/pingoneaic/am-authentication/radius-authentication.html" class="xref page">RADIUS authentication</a> functionality from within a journey, where Advanced Identity Cloud is acting as the RADIUS client.</p>
</dd>
<dt class="hdlist1">Set Logout Details node (OPENAM-24505)<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_5" title="View footnote.">5</a>]</sup></dt>
<dd>
<p>The new <a href="https://docs.pingidentity.com/auth-node-ref/latest/set-logout-details.html">Set Logout Details node</a> lets you add details to the JSON response when a journey ends with the user logging out.</p>
</dd>
<dt class="hdlist1">Identity Governance reports (ANALYTICS-1307)<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_2" title="View footnote.">2</a>]</sup><sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_5" title="View footnote.">5</a>]</sup></dt>
<dd>
<p>Advanced Identity Cloud now provides pre-built reports for the Identity Governance service.
These reports help you understand and manage your identity governance data.
Learn more in <a href="https://docs.pingidentity.com/pingoneaic/identity-governance/administration/iga-reports.html" class="xref page">Identity Governance Reports</a>.</p>
</dd>
</dl>
</div>
</div>
<div class="sect3">
<h4 id="enhancements_9"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#enhancements_9"></a>Enhancements</h4>
<div class="ulist">
<ul>
<li>
<p>AME-31153: Consent request data can now be pushed via backchannel.</p>
</li>
<li>
<p>AME-31429: A new field on the remote consent agent lets you include properties from the resource owner’s session as part of the consent request.</p>
</li>
<li>
<p>AME-31846: Next-generation Config Provider Node scripts can now access the following additional scripted node bindings:</p>
<div class="ulist">
<ul>
<li>
<p><code>callbacks</code></p>
</li>
<li>
<p><code>callbacksBuilder</code></p>
</li>
<li>
<p><code>jwtAssertion</code></p>
</li>
<li>
<p><code>jwtValidator</code></p>
</li>
<li>
<p><code>resumedFromSuspend</code></p>
</li>
<li>
<p><code>requestCookies</code></p>
</li>
<li>
<p><code>samlApplication</code></p>
</li>
<li>
<p><code>oauthApplication</code></p>
</li>
</ul>
</div>
</li>
<li>
<p>AME-32064: The <a href="https://docs.pingidentity.com/auth-node-ref/latest/saml2.html">SAML2 Authentication node</a> includes a new configuration option,<span class="label">Validate IdP Entity ID</span>. When enabled, the node validates that the IdP entity ID from the SAML assertion is the same as the IdP entity ID configured on the node.</p>
</li>
<li>
<p>AME-32970: You can now access the application context for <em>all</em> OAuth 2.0 / OIDC flows through the <code>oauthApplication</code> binding by setting <code>Enable Application Context</code> in the OAuth 2.0 provider or at the client level. Previously, you could only use this binding when using an application journey.</p>
</li>
<li>
<p>IAM-8244: Adds support for bidirectional mappings in synchronization configuration.</p>
</li>
<li>
<p>IAM-8497: Added a brand administrator role to the Advanced Identity Cloud admin console. Brand administrators only have access to change hosted pages themes.</p>
</li>
<li>
<p>IAM-9484: Added ability to provide translation overrides for the <span class="label">Waiting Message</span> field in the Polling Wait node and the <span class="label">Email Suspend Message</span> field in the Email Suspend node. This lets you provide translations when the <code>PollingWaitCallback</code> or the <code>SuspendedTextOutputCallback</code> callbacks are added using scripts.</p>
</li>
<li>
<p>OPENAM-23711: Adds a <span class="label">Detect Connection Time Out</span> option to the <a href="https://docs.pingidentity.com/auth-node-ref/latest/social-provider-handler.html">Social Provider Handler node</a>. When enabled, connection timeouts from social identity providers result in the journey following the  <span class="label">Timeout</span> outcome.</p>
</li>
<li>
<p>OPENAM-24059: Adds support for the <code>android-key</code> WebAuthn attestation format.</p>
</li>
<li>
<p>OPENAM-24130: The <a href="https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-protect-evaluation.html">PingOne Protect Evaluation node</a> now lets you set the flow subtype that’s sent to PingOne Protect.</p>
</li>
<li>
<p>OPENAM-24137: You can now configure the <a href="https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-verify-evaluation.html">PingOne Verify Evaluation node</a> to obtain biographic matching data from the node state.</p>
</li>
<li>
<p>OPENAM-24350: Cryptographic keys can now be derived in next-generation scripts using the PBKDF2 algorithm.</p>
</li>
<li>
<p>OPENAM-24548: The <a href="https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-protect-initialize.html">PingOne Protect Initialize node</a> now lets you obtain PingID Device Trust Agent attributes when going through a PingOne Protect flow.</p>
</li>
<li>
<p>OPENAM-24552: The <a href="https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-protect-evaluation.html">PingOne Protect Evaluation node</a> now lets you send a target application name in addition to the existing target application ID, in the PingOne Protect evaluation request</p>
</li>
<li>
<p>OPENAM-24554: The <a href="https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-protect-evaluation.html">PingOne Protect Evaluation node</a> now lets you use  targeted PingOne policies.</p>
</li>
<li>
<p>OPENAM-24560: Removed the <span class="label">User Type</span> and <span class="label">User Name</span> fields from the PingOne Protect Evaluation node. The user type is always <code>EXTERNAL</code> and the user name is not applicable to external user types. Only the <code>User ID</code> is sent in the PingOne Protect evaluation request.</p>
</li>
<li>
<p>OPENAM-24587: You can now override the default Google Secret Manager key ID (<code>kid</code>) values with human-readable values. Find more information in <a href="https://docs.pingidentity.com/pingoneaic/am-oidc1/managing-jwk_uri.html#override-default-kid-values" class="xref page">Override default <code>kid</code> values</a>.</p>
</li>
<li>
<p>OPENAM-25327: Next-generation OAuth 2.0 scripts can now access the <code>redirectUris</code> property on the <code>clientProperties</code> binding.</p>
</li>
<li>
<p>OPENAM-25417: You can now configure the <span class="label">SameSite attribute</span> for cookies in the <a href="https://docs.pingidentity.com/auth-node-ref/latest/set-persistent-cookie.html">Set Persistent Cookie node</a> and the <a href="https://docs.pingidentity.com/auth-node-ref/latest/persistent-cookie-decision.html">Persistent Cookie Decision node</a>.</p>
</li>
<li>
<p>OPENAM-25418: The attestation <code>fmt</code> type is now included in the transient state data of the WebAuthn nodes.</p>
</li>
<li>
<p>OPENAM-24309: The PingOne Verify Evaluation node now supports biographic matching using multiple user attributes.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="fixes_12"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#fixes_12"></a>Fixes</h4>
<div class="ulist">
<ul>
<li>
<p>AME-32307: Fixed an issue where end users weren’t able to continue a PingOne Verify journey that requested a QR code if they didn’t have a separate device to scan the code.</p>
</li>
<li>
<p>AME-32513: Added the <code>suspend</code> action to <a href="https://docs.pingidentity.com/pingoneaic/journeys/node-designer.html" class="xref page">Custom nodes</a>.</p>
</li>
<li>
<p>AME-32979: The Core Token Service (CTS) now stores <code>AUTHENTICATION_WHITELIST</code> tokens with millisecond-level precision for the expiry timestamp. This minimizes contention in indexes.</p>
</li>
<li>
<p>IAM-8766: Fixed an issue with <a href="https://docs.pingidentity.com/pingoneaic/am-authentication/configure-authentication-trees.html#enable-journey-completion" class="xref page">mustRun</a> journeys and query parameters such as <code>forceAuth=true</code>, where end users were authenticated then immediately unauthenticated.</p>
</li>
<li>
<p>IAM-9430: A warning is now displayed in the Advanced Identity Cloud admin console when a promotion would cause a deferred release tenant to be upgraded at the same time.</p>
</li>
<li>
<p>OPENAM-20582: Lets you configure a list of accepted JWT issuers for OAuth 2.0 clients. These are now accepted in addition to the OAuth 2.0 client ID for private key JWT authentication.</p>
</li>
<li>
<p>OPENAM-23929: Fixed a performance issue related to schema caching.</p>
</li>
<li>
<p>OPENAM-24297: Fixed an issue where the PingOne Verify Evaluation node incorrectly returned a failure outcome when the PingOne environment timed out during the identity verification process. This could happen if an end user didn’t engage with the QR code or selfie capture. The update correctly detects the <code>TRANSACTION_TIMED_OUT</code> status in PingOne responses and returns the timeout outcome, letting journeys handle timeouts distinctly from failures.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[19 Jan 2026]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#19_jan_2026</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#19_jan_2026</guid>
            <pubDate>Tue, 20 Jan 2026 14:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 19722.13</strong></p>
</div>
<div class="sect3">
<h4 id="fixes_13"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#fixes_13"></a>Fixes</h4>
<div class="ulist">
<ul>
<li>
<p>OPENIDM-21664: Fixed a provisioning issue where application assignment was failing to create local accounts when the user count exceeded 1000.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[12 Dec 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#12_dec_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#12_dec_2025</guid>
            <pubDate>Mon, 15 Dec 2025 09:35:19 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 19722.12</strong></p>
</div>
<div class="sect3">
<h4 id="fixes_14"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#fixes_14"></a>Fixes</h4>
<div class="ulist">
<ul>
<li>
<p>IGA-4071<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_2" title="View footnote.">2</a>]</sup><sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_5" title="View footnote.">5</a>]</sup>: Fixed an issue with dataflow job failures.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[12 Dec 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#12_dec_2025_2</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#12_dec_2025_2</guid>
            <pubDate>Mon, 15 Dec 2025 09:35:19 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 19722.11</strong></p>
</div>
<div class="paragraph">
<p>No customer-facing features, enhancements, or fixes released.<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_1" title="View footnote.">1</a>]</sup></p>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[10 Dec 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#10_dec_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#10_dec_2025</guid>
            <pubDate>Thu, 11 Dec 2025 16:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 19722.10</strong></p>
</div>
<div class="sect3">
<h4 id="enhancements_10"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#enhancements_10"></a>Enhancements</h4>
<div class="ulist">
<ul>
<li>
<p>IAM-9663<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_5" title="View footnote.">5</a>]</sup>: The admin console now displays the <code>useInPlaceholders</code> and <code>encoding</code> attributes for existing ESV secrets.</p>
</li>
<li>
<p>IAM-9664<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_5" title="View footnote.">5</a>]</sup>: The admin console now defaults the <code>useInPlaceholders</code> attribute to <code>true</code> when creating new ESV secrets.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[09 Dec 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#ws_trust_ms365_x509_12_dec_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#ws_trust_ms365_x509_12_dec_2025</guid>
            <pubDate>Tue, 09 Dec 2025 13:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version N/A</strong></p>
</div>
<div class="sect3">
<h4 id="key_features_9"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#key_features_9"></a>Key features</h4>
<div class="dlist">
<dl>
<dt class="hdlist1">x.509 certificate authentication for Microsoft 365 WS-Trust SSO applications (IAM-9212)</dt>
<dd>
<p>Microsoft 365 SSO applications that use the WS-Trust protocol can use x.509 authentication. Trusted certificates are accessible to all your Microsoft 365 applications. WS-Trust is included with the WS-Federation<sup class="footnote" id="_footnote_addon_footnote_ws">[<a id="_footnoteref_7" class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_7" title="View footnote.">7</a>]</sup> add-on.</p>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingoneaic/app-management/register-a-custom-application.html#sso-manage-ms-365-x509-certs" class="xref page">Manage Microsoft 365 application trusted certificates</a>.</p>
</div>
<div class="admonitionblock note">
<table>
<tbody><tr>
<td class="icon">
<i class="fa icon-note" title="Note"></i>
</td>
<td class="content">
This feature requires Advanced Identity Cloud version 19722.7 or later.
</td>
</tr>
</tbody></table>
</div>
</dd>
</dl>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[03 Dec 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#03_dec_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#03_dec_2025</guid>
            <pubDate>Fri, 05 Dec 2025 16:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 19722.7</strong></p>
</div>
<div class="sect3">
<h4 id="key_features_10"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#key_features_10"></a>Key features</h4>
<div class="dlist">
<dl>
<dt class="hdlist1">Entitlement composition certification (IGA-3827<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_5" title="View footnote.">5</a>]</sup><sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_2" title="View footnote.">2</a>]</sup>)</dt>
<dd>
<p>Entitlement composition certification provides a review mechanism that allows certifiers to evaluate, review, and modify the definition of entitlements within the certification process.
This capability enables reviewers to submit requests to change the entitlement definition, even independently of the certification decision, with options for drafting and deferring modification requests until sign off.</p>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingoneaic/identity-governance/administration/template-entitlement-composition.html" class="xref page">Create an entitlement composition certification template</a>.</p>
</div>
</dd>
<dt class="hdlist1">Accounts page (IGA-3960<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_5" title="View footnote.">5</a>]</sup><sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_2" title="View footnote.">2</a>]</sup>)</dt>
<dd>
<p>The accounts page gives application owners and application administrators a single place to manage all user accounts without granting them full application configuration permissions.</p>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingoneaic/identity-governance/administration/governance-accounts.html" class="xref page">Accounts</a>.</p>
</div>
</dd>
</dl>
</div>
</div>
<div class="sect3">
<h4 id="enhancements_11"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#enhancements_11"></a>Enhancements</h4>
<div class="ulist">
<ul>
<li>
<p>IAM-9395: Table columns are now resized uniformly across the Advanced Identity Cloud admin console.</p>
</li>
<li>
<p>IAM-9429: If your production environment is configured for deferred release, you can use the new <code>/environment/promotion/promote</code> endpoint to check if running a promotion will trigger a release upgrade.</p>
</li>
<li>
<p>IAM-9516: The tenant administrator profile page now prompts for re-authentication when adding or removing an MFA device.</p>
</li>
<li>
<p>OPENIDM-19400: New Prometheus metric for the availability of connector servers, for example:</p>
<div class="paragraph">
<p><code>idm_icf_connector_server_availability{name="<span class="var">system-id</span>",type="<span class="var">connector-server-type</span>",} 1.0</code>.</p>
</div>
</li>
<li>
<p>OPENIDM-20341: Identity management scripts now natively support Base64 encoding using the <code>btoa</code> (encode) and <code>atob</code> (decode) <a href="https://docs.pingidentity.com/pingoneaic/idm-scripting/scripting-func-engine.html#global-utility-functions" class="xref page">global script</a> bindings.</p>
</li>
<li>
<p>OPENIDM-20790: The <code>openidm/sync/mappings</code> endpoint now <a href="https://docs.pingidentity.com/pingoneaic/idm-synchronization/mappings.html#sync-mapping-paging" class="xref page">supports paging</a> using either offsets or cookies.</p>
</li>
<li>
<p>OPENIDM-20933: Improved task scanner exception handling. If the task scanner encounters a task that results in an exception, it now aborts only that task and continues processing the remaining tasks. Previously, the scanner would abort the entire process when any task caused an exception.</p>
</li>
<li>
<p>OPENIDM-20937: New provisioner metric <code>idm_icf_pending</code>. Includes all the same tags as <code>idm_icf*</code>.</p>
</li>
<li>
<p>OPENIDM-21170: Metrics for router filters now use <code>router_filter</code> for the metric name and include a <code>name</code> tag to identify the specific filter.</p>
</li>
<li>
<p>OPENIDM-21171: Metrics for managed identity script hooks now use <code>managed-script-hook</code> for the metric name, <code>object</code> to tag the identity object, and <code>script-hook</code> to tag the script hook.</p>
</li>
<li>
<p>OPENIDM-21172: Metrics for custom endpoints now use the new <code>custom_endpoint</code> metric name and include a <code>name</code> tag based on the custom endpoint configuration name after the hyphen. For example, a custom endpoint configuration <code>endpoint-onboardCustomer.json</code> will generate metrics with a name tag/label of "onboardCustomer". The policy service makes use of an internal scripted endpoint based on the file <code>policy.js</code>, and its metric name is <code>policy-js</code>.</p>
</li>
<li>
<p>OPENIDM-21233: The <code>openidm/health/ready</code> endpoint has been enhanced to include the number of waiting requests. A new set of metrics have been added to provide a historical accounting of IDM health.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="fixes_15"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#fixes_15"></a>Fixes</h4>
<div class="ulist">
<ul>
<li>
<p>FRAAS-28885<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_5" title="View footnote.">5</a>]</sup>: ESV secret <code>useInPlaceholders</code> attribute is now taken into account by promotion integrity checks.</p>
</li>
<li>
<p>IAM-9466: Annotation comments added to sub-nodes are now saved correctly.</p>
</li>
<li>
<p>IAM-9496: The tooltip in journey comments now correctly displays the creator’s name without overflow.</p>
</li>
<li>
<p>IAM-9527: The hosted account pages logo now correctly uses the height specified in the theme.</p>
</li>
<li>
<p>OPENICF-3277: The SaaS REST connector no longer throws a <code>NullPointerException</code> when attributes are missing in the request payload.</p>
</li>
<li>
<p>OPENIDM-20525: The <code>cn</code> and <code>telephoneNumber</code> schema for <code>alpha_user</code> and <code>bravo_user</code> are now <code>scope: public</code> and <code>searchable: true</code>. This schema change applies to tenants created on or after December 3, 2025. Existing tenants are unchanged.</p>
</li>
<li>
<p>OPENIDM-20863: Default values for multivalue mappings are now copied by value to prevent unintended mutations during runtime.</p>
</li>
<li>
<p>OPENIDM-21421: Updating the configuration of an inactive provisioner no longer throws an <code>IllegalStateException</code>.</p>
</li>
<li>
<p>OPENIDM-21454: Every failed record from a live sync is now stored in the dead-letter queue with a unique entry ID.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="changed_functionality_3"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#changed_functionality_3"></a>Changed functionality</h4>
<div class="dlist">
<dl>
<dt class="hdlist1">Default API version for unversioned requests to <code>openidm/*</code> endpoints (OPENIDM-21191)</dt>
<dd>
<p>Previously, REST API requests made to <code>openidm/*</code> endpoints without an <code>Accept-API-Version</code> header defaulted to the latest available API version for the resource.
These unversioned requests now default to API version <code>1.0</code> for most resources.
However, the <code>consent</code>, <code>scheduler/job</code>, <code>scheduler/trigger</code>, and <code>schema</code> endpoints default to API version <code>2.0</code>.</p>
</dd>
</dl>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[20 Nov 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#ws_trust_20_nov_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#ws_trust_20_nov_2025</guid>
            <pubDate>Mon, 24 Nov 2025 13:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version N/A</strong></p>
</div>
<div class="sect3">
<h4 id="key_features_11"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#key_features_11"></a>Key Features</h4>
<div class="dlist">
<dl>
<dt class="hdlist1">WS-Trust for Microsoft 365 SSO applications (IAM-8263)</dt>
<dd>
<p>Microsoft 365 SSO applications can now use the WS-Trust protocol for legacy rich applications and hybrid joined devices. WS-Trust is included with the WS-Federation<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_7" title="View footnote.">7</a>]</sup> add-on.</p>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingoneaic/app-management/register-a-custom-application.html#sso-microsoft-365" class="xref page">Register an SSO application &gt; Microsoft 365</a>.</p>
</div>
<div class="admonitionblock note">
<table>
<tbody><tr>
<td class="icon">
<i class="fa icon-note" title="Note"></i>
</td>
<td class="content">
This feature requires Advanced Identity Cloud version 19521.3 or later.
</td>
</tr>
</tbody></table>
</div>
</dd>
</dl>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[11 Nov 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#11_nov_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#11_nov_2025</guid>
            <pubDate>Fri, 14 Nov 2025 15:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 19521.3</strong></p>
</div>
<div class="sect3">
<h4 id="enhancements_12"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#enhancements_12"></a>Enhancements</h4>
<div class="ulist">
<ul>
<li>
<p>FRAAS-28370: Fixed an issue where requests to the <code>/monitoring/prometheus/am</code> and <code>/monitoring/prometheus/idm</code> endpoints occasionally didn’t return timely responses.</p>
</li>
<li>
<p>IAM-1709: Exposed <code>useInPlaceholders</code> and <code>encoding</code> attributes when creating ESV secrets in the admin console.</p>
</li>
<li>
<p>IAM-9312: Table columns are now resized uniformly across the following Advanced Identity Cloud admin console pages:</p>
<div class="ulist">
<ul>
<li>
<p><strong class="label">Tenant settings</strong></p>
</li>
<li>
<p><strong class="label">Scripts</strong></p>
</li>
<li>
<p><strong class="label">Security</strong></p>
</li>
<li>
<p><strong class="label">Terms &amp; Conditions</strong></p>
</li>
</ul>
</div>
</li>
<li>
<p>IAM-9323: Added <strong class="label">Metadata</strong> tab to user resource page to display properties such as <code>createDate</code> and <code>loginCount</code>.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="fixes_16"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#fixes_16"></a>Fixes</h4>
<div class="ulist">
<ul>
<li>
<p>IAM-9217: Fixed cron schedule validation for new jobs.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[28 Oct 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#28_oct_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#28_oct_2025</guid>
            <pubDate>Fri, 31 Oct 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 19379.7</strong></p>
</div>
<div class="sect3">
<h4 id="key_features_12"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#key_features_12"></a>Key features</h4>
<div class="dlist">
<dl>
<dt class="hdlist1">Audit logging of modifications to environments (FRAAS-17087)</dt>
<dd>
<p>You can now use the <code>/monitoring</code> endpoints and <a href="https://docs.pingidentity.com/pingoneaic/tenants/audit-debug-logs-push.html" class="xref page">log streaming</a> to track configuration changes made to your environments. The new <a href="https://docs.pingidentity.com/pingoneaic/tenants/audit-debug-log-sources.html#environment-access" class="xref page">environment-access</a> log source captures environment changes as audit events.</p>
<div class="paragraph">
<p>This enhancement improves visibility and observability for environment updates, helping teams monitor configuration activity, identify unexpected changes, and support troubleshooting or alerting workflows.</p>
</div>
</dd>
</dl>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[21 Oct 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#21_oct_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#21_oct_2025</guid>
            <pubDate>Wed, 22 Oct 2025 08:08:01 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 19190.10</strong></p>
</div>
<div class="sect3">
<h4 id="key_features_13"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#key_features_13"></a>Key features</h4>
<div class="dlist">
<dl>
<dt class="hdlist1">Create custom authentication nodes (IAM-5759)</dt>
<dd>
<p>Advanced Identity Cloud lets you create your own nodes to reuse common functionality in authentication journeys.
Define properties and run custom server-side scripts in these nodes to dynamically set values and decide the outcome of journeys.</p>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingoneaic/journeys/node-designer.html" class="xref page">Custom nodes</a>.</p>
</div>
</dd>
<dt class="hdlist1">Next-generation OAuth 2.0 access token modification scripts (AME-31083)</dt>
<dd>
<p>You can now create next-generation access token modification scripts that can use next-generation common bindings, such as <code>httpClient</code>, <code>openidm</code>, and <code>utils</code>.</p>
</dd>
<dt class="hdlist1">Ability to configure journeys as <em>transactional only</em> (AME-31843)</dt>
<dd>
<p>A transactional authentication journey only runs when Advanced Identity Cloud starts a transaction, which happens when Advanced Identity Cloud does one of the following:</p>
<div class="openblock">
<div class="content">
<div class="ulist">
<ul>
<li>
<p>Initializes <a href="https://docs.pingidentity.com/pingoneaic/am-authentication/backchannel-authentication.html" class="xref page">backchannel authentication</a> using either the <code>/authenticate/backchannel/initialize</code> endpoint or the <a href="https://docs.pingidentity.com/auth-node-ref/latest/backchannel-initialize.html">Backchannel Initialize node</a>.</p>
</li>
<li>
<p>Runs a <a href="https://docs.pingidentity.com/pingoneaic/am-saml2/configure-providers.html#samlapp-journey" class="xref page">SAML 2.0 app</a> journey for a remote SP.</p>
</li>
<li>
<p>Runs an <a href="https://docs.pingidentity.com/pingoneaic/am-oauth2/oauth2-register-client.html" class="xref page">OAuth 2.0 app</a> journey when Advanced Identity Cloud is acting as an authorization server.</p>
</li>
<li>
<p>Enforces a <a href="https://docs.pingidentity.com/pingoneaic/am-authorization/transactional-authorization.html" class="xref page">transactional authorization</a> policy.</p>
</li>
</ul>
</div>
</div>
</div>
<div class="paragraph">
<p>You can only configure transactional authentication journeys using the REST API. Set the <code>transactionalOnly</code> property to <code>true</code> in the journey configuration.</p>
</div>
</dd>
<dt class="hdlist1">Mapping custom key IDs to secrets (AME-31380)</dt>
<dd>
<p>You can now map custom <code>kid</code> header values for JWTs signed with the signing key to a specific ESV secret.</p>
</dd>
<dt class="hdlist1">Nodes to support backchannel authentication journeys (AME-31636 and AME-31635)</dt>
<dd>
<p>The new <a href="https://docs.pingidentity.com/auth-node-ref/latest/backchannel-initialize.html">Backchannel Initialize node</a> and <a href="https://docs.pingidentity.com/auth-node-ref/latest/backchannel-status.html">Backchannel Status node</a> let you implement backchannel authentication from within a journey.</p>
</dd>
<dt class="hdlist1">Journey binding for scripted nodes (OPENAM-23127)</dt>
<dd>
<p>The new <code>journey</code> binding for scripted nodes lets you obtain details of the current journey, including inner or child journeys.</p>
</dd>
</dl>
</div>
</div>
<div class="sect3">
<h4 id="enhancements_13"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#enhancements_13"></a>Enhancements</h4>
<div class="ulist">
<ul>
<li>
<p>AME-30984 and AME-30609: Enhanced authentication audit logging to include the SAML Identity Provider (IdP) and Service Provider (SP) entity IDs during SAML flows. This information lets you report on the SAML applications users are accessing, supporting analytics and dashboarding efforts.</p>
</li>
<li>
<p>AME-30985: In SAML v2.0 single sign-on (SSO) flows, the JSON web token (JWT) created in the browser’s session storage no longer expires.</p>
</li>
<li>
<p>AME-31082 and SDKS-3681: Added support for device token refreshing to the Push Notification Service endpoint, enabling the reception of new tokens from mobile devices.</p>
</li>
<li>
<p>AME-31351 and AME-31471: Improvements to the Device Code flow mean that end users are now prompted to reauthenticate even when there’s an existing session for must-run and app journeys.</p>
</li>
<li>
<p>AME-31398: The <a href="https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-protect-evaluation.html">PingOne Protect Evaluation node</a> has been enhanced to support custom attributes. To specify custom attributes to be used in PingOne Protect for custom predictors, set the <code>Node State Attribute For Custom Attributes</code> in the node configuration. The node retrieves a map of custom attributes from the node state to be used in the evaluation request to PingOne Protect.</p>
</li>
<li>
<p>AME-31656 and AME-31468: The <a href="https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-protect-evaluation.html">PingOne Protect Evaluation node</a> has been enhanced to support dynamic risk policy IDs and target app IDs. To set the risk policy set ID dynamically, enable <code>Use Node State Attribute For Risk Policy Set ID</code> in the node configuration. To set the target app ID dynamically, enable <code>Use Node State Attribute For Target App ID</code> in the node configuration. This instructs the node to obtain these IDs from the node state.</p>
</li>
<li>
<p>AME-31487: Improvements to SAML v2.0 standalone mode include replacing legacy JSPs with URL endpoints.</p>
<div class="paragraph">
<p>You can still invoke the JSPs because they’re mapped to URLs for backward compatibility, but any customizations to these JSPs will be lost.</p>
</div>
<div class="paragraph">
<p>The following URLs supersede SAML v2.0 JSPs:</p>
</div>
<div class="openblock">
<div class="content">
<details>
<summary class="title">URLs</summary>
<div class="content">
<table class="tableblock frame-all grid-all stretch">
<colgroup>
<col style="width: 50%;">
<col style="width: 50%;">
</colgroup>
<thead>
<tr>
<th class="tableblock halign-left valign-top">Old URL</th>
<th class="tableblock halign-left valign-top">New URL</th>
</tr>
</thead>
<tbody>
<tr>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/saml2/jsp/exportmetadata.jsp</code></p>
</div></div></td>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/ExportSamlMetadata</code></p>
</div></div></td>
</tr>
<tr>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/saml2/jsp/idpSingleLogoutInit.jsp</code></p>
</div></div></td>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/IDPSloInit</code></p>
</div></div></td>
</tr>
<tr>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/saml2/jsp/idpSingleLogoutRedirect.jsp</code></p>
</div></div></td>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/IDPSloRedirect</code></p>
</div></div></td>
</tr>
<tr>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/saml2/jsp/idpSingleLogoutPOST.jsp</code></p>
</div></div></td>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/IDPSloPOST</code></p>
</div></div></td>
</tr>
<tr>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/saml2/jsp/idpMNIRedirect.jsp</code></p>
</div></div></td>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/IDPMniRedirect</code></p>
</div></div></td>
</tr>
<tr>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/saml2/jsp/idpMNIRequestInit.jsp</code></p>
</div></div></td>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/IDPMniInit</code></p>
</div></div></td>
</tr>
<tr>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/saml2/jsp/idpSSOFederate.jsp</code></p>
</div></div></td>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/idpSSOFederate</code></p>
</div></div></td>
</tr>
<tr>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/saml2/jsp/spAssertionConsumer.jsp</code></p>
</div></div></td>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/Consumer</code></p>
</div></div></td>
</tr>
<tr>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/saml2/jsp/saml2AuthAssertionConsumer.jsp</code></p>
</div></div></td>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/AuthConsumer</code></p>
</div></div></td>
</tr>
<tr>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/saml2/jsp/spSingleLogoutInit.jsp</code></p>
</div></div></td>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/SPSloInit</code></p>
</div></div></td>
</tr>
<tr>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/saml2/jsp/spSingleLogoutRedirect.jsp</code></p>
</div></div></td>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/SPSloRedirect</code></p>
</div></div></td>
</tr>
<tr>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/saml2/jsp/spSingleLogoutPOST.jsp</code></p>
</div></div></td>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/SPSloPOST</code></p>
</div></div></td>
</tr>
<tr>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/saml2/jsp/spMNIRedirect.jsp</code></p>
</div></div></td>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/SPMniRedirect</code></p>
</div></div></td>
</tr>
<tr>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/saml2/jsp/spMNIPOST.jsp</code></p>
</div></div></td>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/SPMniPOST</code></p>
</div></div></td>
</tr>
<tr>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/saml2/jsp/spMNIRequestInit.jsp</code></p>
</div></div></td>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/SPMniInit</code></p>
</div></div></td>
</tr>
<tr>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/saml2/jsp/spSSOInit.jsp</code></p>
</div></div></td>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/spssoinit</code></p>
</div></div></td>
</tr>
<tr>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/saml2/jsp/idpSSOInit.jsp</code></p>
</div></div></td>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/idpssoinit</code></p>
</div></div></td>
</tr>
<tr>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/saml2/jsp/idpSSOFederate.jsp</code></p>
</div></div></td>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/idpSSOFederate</code></p>
</div></div></td>
</tr>
<tr>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/saml2/jsp/SA_IDP.jsp</code></p>
</div></div></td>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/idpsaehandler</code></p>
</div></div></td>
</tr>
<tr>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/saml2/jsp/SA_SP.jsp</code></p>
</div></div></td>
<td class="tableblock halign-left valign-top"><div class="content"><div class="paragraph">
<p><code>/spsaehandler</code></p>
</div></div></td>
</tr>
</tbody>
</table>
</div>
</details>
</div>
</div>
</li>
<li>
<p>OPENAM-23051 and AME-31918: A new ESV, <code>esv.oauth2.request.object.restrictions.enforced</code> lets you enforce stricter adherence to the <a href="https://www.rfc-editor.org/rfc/rfc9126.html">PAR</a> and <a href="https://www.rfc-editor.org/rfc/rfc9101.html#section-5.2">JAR</a> specifications.</p>
<div class="paragraph">
<p>Setting the value of this ESV to <code>true</code> enforces the following:
<strong> The authorization server ignores authorize parameters outside the <code>request_uri</code>.
</strong> When sending a JWT-Secured Authorization Request (JAR), the <code>request_uri</code> <em>must</em> be an <code>https</code> URI.</p>
</div>
</li>
<li>
<p>IAM-8236: The ability to edit journeys from the AM native admin console has been removed. Use the Advanced Identity Cloud admin console to edit journeys.</p>
</li>
<li>
<p>IAM-9000, IAM-9001: Add annotations and sticky notes to journeys to assist learning and collaboration.</p>
</li>
<li>
<p>IAM-9237: Allow ESVs to be embedded in URL fields for federation IdPs. This lets you set up federation IdPs with fewer ESVs because you can define a single ESV containing a UUID shared by multiple URL fields.</p>
</li>
<li>
<p>IAM-9246: Table columns are now resized uniformly across all table views.</p>
</li>
<li>
<p>OPENAM-20776: A new OIDC client configuration option, <code>Private Key JWT Audience</code>, lets you configure and override the audience (<code>aud</code>) claim of a Private Key JWT.</p>
</li>
<li>
<p>OPENAM-21783: Improved token management for OAuth 2.0 client applications.</p>
</li>
<li>
<p>OPENAM-23669: <em>Full</em> scopes (scopes ending in <code>*</code>) can now be used by service accounts in all cases where more specific scopes (for example, <code>:read</code>) are used.</p>
</li>
<li>
<p>OPENAM-23710: The <code>httpClient</code> binding is now available to legacy SAML 2.0 IdP adapter scripts.</p>
</li>
<li>
<p>OPENAM-23850: Enhanced the <a href="https://docs.pingidentity.com/auth-node-ref/latest/pingone/pingone-verify-evaluation.html">PingOne Verify Evaluation node</a> with an <code>Allow same device verification</code> option that lets end users continue verification on their current device.</p>
</li>
<li>
<p>OPENAM-23867: The <a href="https://docs.pingidentity.com/auth-node-ref/latest/ldap-decision.html">LDAP Decision node</a> no longer logs credential failures as errors. It now logs them at the <code>info</code> level.</p>
</li>
<li>
<p>OPENAM-24062: Added support for the <code>ECDSA</code> algorithm to the <code>utils.crypto.subtle</code> next-generation  binding. This algorithm is supported for key generation, signing, and verification.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="fixes_17"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#fixes_17"></a>Fixes</h4>
<div class="ulist">
<ul>
<li>
<p>AME-31351 and AME-31471: Improvements to the Device Code flow mean that end users are now prompted to reauthenticate even when there’s an existing session for must-run and app journeys.</p>
</li>
<li>
<p>AME-31481: Validation around policy creation has been improved. If you’re using the legacy "Policy" environment condition (or a custom environment condition), you’ll need to add that to the list of allowed environment conditions for your policy set to create or update policies that use that condition type.</p>
</li>
<li>
<p>IAM-9153: Password validation now works correctly when pasting a value that matches the existing value.</p>
</li>
<li>
<p>OPENAM-20749: A new ESV, <code>esv-enable-oauth2-sync-refresh-token-issuer</code> causes a stateful OAuth 2.0 introspect response to overwrite the <code>iss</code> claim of the introspectable token. To enable this behavior, set this ESV to <code>false</code>.</p>
</li>
<li>
<p>OPENAM-23770: Canceling a WebAuthn flow now results in a <code>Client Error</code> outcome, rather than an internal failure.</p>
</li>
<li>
<p>OPENAM-24159: Fixed an issue that prevented multiple <a href="https://docs.pingidentity.com/auth-node-ref/latest/identity-assertion-node.html">Identity Assertion</a> nodes from being used in a single journey.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[09 Oct 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#09_oct_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#09_oct_2025</guid>
            <pubDate>Fri, 10 Oct 2025 11:41:13 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 19054.10</strong></p>
</div>
<div class="paragraph">
<p>No customer-facing features, enhancements, or fixes released.<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_1" title="View footnote.">1</a>]</sup></p>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[30 Sept 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#30_sept_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#30_sept_2025</guid>
            <pubDate>Mon, 06 Oct 2025 14:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 19054.9</strong></p>
</div>
<div class="sect3">
<h4 id="enhancements_14"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#enhancements_14"></a>Enhancements</h4>
<div class="ulist">
<ul>
<li>
<p>OPENAM-24486: Improved performance when creating large numbers of OAuth 2.0 clients simultaneously.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="fixes_18"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#fixes_18"></a>Fixes</h4>
<div class="ulist">
<ul>
<li>
<p>OPENDJ-11486: Fixed an exception caused when identity management queries for users with a filter containing wildcards and specific object classes.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="related_releases"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#related_releases"></a>Related releases</h4>
<div class="admonitionblock note">
<table>
<tbody><tr>
<td class="icon">
<i class="fa icon-note" title="What are related releases?"></i>
</td>
<td class="content">
<div class="paragraph">
<p>This section contains information about releases of other Ping Identity products that are often deployed as part of an Advanced Identity Cloud implementation.
To take advantage of these updates, you must manually upgrade your RCS implementation.</p>
</div>
</td>
</tr>
</tbody></table>
</div>
<div class="ulist">
<ul>
<li>
<p>RCS 1.5.20.32 is now available to <a href="https://backstage.pingidentity.com/downloads/browse/identity-cloud/all/productId:idm-connector-servers/minorVersion:1.5/version:1.5.20.32/language:java" target="_blank" rel="noopener">download</a>.
Learn more in <a href="https://docs.pingidentity.com/openicf/connector-release-notes/preface.html" target="_blank" rel="noopener">ICF release notes</a>.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[26 Sept 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#26_sept_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#26_sept_2025</guid>
            <pubDate>Wed, 01 Oct 2025 14:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 18842.11</strong></p>
</div>
<div class="sect3">
<h4 id="fixes_19"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#fixes_19"></a>Fixes</h4>
<div class="ulist">
<ul>
<li>
<p>IAM-9374: Fixed an issue where managed identity searches were querying all properties, causing slow performance.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[25 Sept 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#25_sept_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#25_sept_2025</guid>
            <pubDate>Tue, 30 Sep 2025 14:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 18842.10</strong></p>
</div>
<div class="paragraph">
<p>No customer-facing features, enhancements, or fixes released.<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_1" title="View footnote.">1</a>]</sup></p>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[22 Sept 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#log_event_exporter_22_sept_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#log_event_exporter_22_sept_2025</guid>
            <pubDate>Mon, 22 Sep 2025 18:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version N/A</strong></p>
</div>
<div class="sect3">
<h4 id="key_features_14"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#key_features_14"></a>Key Features</h4>
<div class="dlist">
<dl>
<dt class="hdlist1">Log event exporter (FRAAS-19963)</dt>
<dd>
<p>Advanced Identity Cloud now lets you export log event data to an external monitoring tool, such as an OpenTelemetry-compatible SIEM or Splunk.
This helps you monitor events and troubleshoot issues in near real time.</p>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingoneaic/tenants/audit-debug-logs-push.html" class="xref page">Export log events to an external monitoring tool</a>.</p>
</div>
<div class="admonitionblock note">
<table>
<tbody><tr>
<td class="icon">
<i class="fa icon-note" title="Note"></i>
</td>
<td class="content">
This feature requires Advanced Identity Cloud version 18842.8 or later.
</td>
</tr>
</tbody></table>
</div>
</dd>
</dl>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[17 Sept 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#17_sept_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#17_sept_2025</guid>
            <pubDate>Mon, 22 Sep 2025 14:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 18842.8</strong></p>
</div>
<div class="sect3">
<h4 id="enhancements_15"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#enhancements_15"></a>Enhancements</h4>
<div class="ulist">
<ul>
<li>
<p>ANALYTICS-582<sup class="footnote" id="_footnote_fn-noregular">[<a id="_footnoteref_8" class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_8" title="View footnote.">8</a>]</sup><sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_4" title="View footnote.">4</a>]</sup>: Custom objects can now be used as data sources for reporting. The system uses an object’s configured title for the data source name, makes its properties available as attributes, and represents all object relationships.</p>
</li>
<li>
<p>ANALYTICS-1165<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_8" title="View footnote.">8</a>]</sup>: Added the capability to change a report name.</p>
</li>
<li>
<p>ANALYTICS-1195<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_8" title="View footnote.">8</a>]</sup>: Added the ability to import and export report templates using reports API endpoints.</p>
</li>
<li>
<p>FRAAS-25919: You can now use the API to configure custom domains for the Advanced Identity Cloud admin console.</p>
</li>
<li>
<p>IAM-8922: The Advanced Identity Cloud admin console now accepts ESV placeholders for the following federation fields:</p>
<div class="ulist">
<ul>
<li>
<p>Application ID</p>
</li>
<li>
<p>Application Secret</p>
</li>
<li>
<p>Well-Known Endpoint</p>
</li>
<li>
<p>Authorization Endpoint</p>
</li>
<li>
<p>User Info Endpoint</p>
</li>
<li>
<p>Token Endpoint</p>
</li>
<li>
<p>Issuer</p>
</li>
</ul>
</div>
</li>
<li>
<p>IAM-8982<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_2" title="View footnote.">2</a>]</sup>: Add event function for setting the query filter/select options of a select field.</p>
</li>
<li>
<p>IAM-9066: Added <strong class="label">Tenant Auditor</strong> option to Advanced Identity Cloud admin console federation groups claim.</p>
</li>
<li>
<p>IAM-9099, IAM-9146, IAM-9167: Many table views now support column resizing and customization.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="fixes_20"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#fixes_20"></a>Fixes</h4>
<div class="ulist">
<ul>
<li>
<p>IAM-5488: Terms and Conditions now respects target attribute in anchor tags.</p>
</li>
<li>
<p>IAM-6588: The Advanced Identity Cloud admin console now correctly displays journey status for journeys disabled and enabled using ESVs.</p>
</li>
<li>
<p>IAM-8887: Prevent browsers auto-filling passwords in user registration journeys.</p>
</li>
<li>
<p>IAM-8940: Managed identity number property now accepts float values.</p>
</li>
<li>
<p>IAM-8956: Deselecting the <strong class="label">Personal Information</strong> option now disables the section containing the user avatar in hosted account pages.</p>
</li>
<li>
<p>IAM-9169: Fixed styling for responsive table layouts with sticky action column in <strong class="label">Identities</strong> table views.</p>
</li>
<li>
<p>OPENIDM-21372: Advanced Identity Cloud now prevents access to the identity repository endpoint, <code>/openidm/repo</code>. This prevents uncontrolled and potentially incompatible schema changes.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="additional_information"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#additional_information"></a>Additional information</h4>
<div class="paragraph">
<p>The new <a href="https://docs.pingidentity.com/pingoneaic/integrations/pingone.html" class="xref page">PingOne integration guide</a> helps you configure Advanced Identity Cloud to use PingOne products such as PingOne Protect and PingOne Verify.
The guide covers the following topics:</p>
</div>
<div class="ulist">
<ul>
<li>
<p>Best practices for naming and arranging PingOne environments.</p>
</li>
<li>
<p>Best practices for configuring PingOne workers and Advanced Identity Cloud worker services when integrating with PingOne products.</p>
</li>
<li>
<p>How to configure, test, and optimize PingOne Protect.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[16 Sept 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#16_sept_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#16_sept_2025</guid>
            <pubDate>Wed, 17 Sep 2025 16:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 18712.11</strong></p>
</div>
<div class="paragraph">
<p>No customer-facing features, enhancements, or fixes released.<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_1" title="View footnote.">1</a>]</sup></p>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[12 Sept 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#12_sept_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#12_sept_2025</guid>
            <pubDate>Tue, 16 Sep 2025 09:32:51 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 18712.10</strong></p>
</div>
<div class="sect3">
<h4 id="enhancements_16"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#enhancements_16"></a>Enhancements</h4>
<div class="ulist">
<ul>
<li>
<p>OPENAM-24476<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_3" title="View footnote.">3</a>]</sup>: Added <code>java.util.zip.Deflater</code>, <code>java.util.zip.Inflater</code>, <code>java.util.zip.DeflaterOutputStream</code>, and <code>java.util.zip.InflaterInputStream</code> to the allowlist for Scripted Decision nodes.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[10 Sept 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#10_sept_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#10_sept_2025</guid>
            <pubDate>Thu, 11 Sep 2025 11:41:13 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 18712.8</strong></p>
</div>
<div class="paragraph">
<p>No customer-facing features, enhancements, or fixes released.<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_1" title="View footnote.">1</a>]</sup></p>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[03 Sept 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#03_sept_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#03_sept_2025</guid>
            <pubDate>Thu, 04 Sep 2025 09:32:51 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 18712.7</strong></p>
</div>
<div class="sect3">
<h4 id="enhancements_17"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#enhancements_17"></a>Enhancements</h4>
<div class="ulist">
<ul>
<li>
<p>FRAAS-24857: CNAME verification is no longer required when creating a custom domain.</p>
</li>
<li>
<p>FRAAS-25547: The sender address for emails sent to Advanced Identity Cloud tenant administrators is now <code>saas@pingidentity.com</code>.</p>
</li>
<li>
<p>FRAAS-26063: You can now override the <code>samlErrorPageUrl</code>. To do so, configure an <a href="https://docs.pingidentity.com/pingoneaic/tenants/esvs.html#variables" class="xref page">ESV variable</a> named <code>esv-global-saml-error-page-url</code> and set its value to your SAML error page URL. If you don’t set this variable, Advanced Identity Cloud uses the default value of <code>/saml2/jsp/saml2error.jsp</code>.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="fixes_21"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#fixes_21"></a>Fixes</h4>
<div class="ulist">
<ul>
<li>
<p>FRAAS-25734: Exception stacktraces in access management and identity management logs are now truncated to approximately 300-400 lines.</p>
</li>
<li>
<p>FRAAS-25821<sup class="footnote" id="_footnote_addon_footnote_pc">[<a id="_footnoteref_9" class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_9" title="View footnote.">9</a>]</sup>: Fixed an issue that prevented IP rules in Proxy Connect from being disabled.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[01 Sept 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#01_sept_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#01_sept_2025</guid>
            <pubDate>Mon, 01 Sep 2025 17:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 18368.14</strong></p>
</div>
<div class="sect3">
<h4 id="fixes_22"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#fixes_22"></a>Fixes</h4>
<div class="ulist">
<ul>
<li>
<p>AME-32756: Fixed an issue with policy evaluation returning results from a stale policy index cache.</p>
</li>
<li>
<p>OPENDJ-11634: Advanced Identity Cloud now prevents searches with many results and no applicable index from overloading the system.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[19 Aug 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#19_aug_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#19_aug_2025</guid>
            <pubDate>Wed, 20 Aug 2025 17:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 18368.10</strong></p>
</div>
<div class="sect3">
<h4 id="enhancements_18"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#enhancements_18"></a>Enhancements</h4>
<div class="ulist">
<ul>
<li>
<p>OPENAM-24384: Added <code>javax.crypto.SecretKeyFactory</code>, <code>javax.crypto.spec.PBEKeySpec</code>, and <code>com.sun.crypto.provider.PBKDF2KeyImpl</code> classes to the allowlist for the <code>OAUTH2_ACCESS_TOKEN_MODIFICATION</code> scripting context.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="fixes_23"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#fixes_23"></a>Fixes</h4>
<div class="ulist">
<ul>
<li>
<p>OPENAM-24393<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_3" title="View footnote.">3</a>]</sup>: Fixed an issue where the InnerTreeEvaluator node failed for authentication journeys initially accessed using REST without an <code>authId</code>.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[12 Aug 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#12_aug_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#12_aug_2025</guid>
            <pubDate>Wed, 13 Aug 2025 13:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 18368.8</strong></p>
</div>
<div class="sect3">
<h4 id="key_features_15"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#key_features_15"></a>Key features</h4>
<div class="dlist">
<dl>
<dt class="hdlist1">Policy binding for next-generation scripting (AME-26150)</dt>
<dd>
<p>The next-generation <code>policy</code> binding lets you access the policy engine API and evaluate policies from within scripts. The <code>policy</code> binding works in a similar way to the <a href="https://docs.pingidentity.com/pingoneaic/am-authorization/rest-api-authz-policy-decisions.html#rest-api-authz-policy-decision-concrete" class="xref page">Request policy decisions for a specific resource</a> API call.</p>
</dd>
<dt class="hdlist1">Set Error Details node (AME-30968)</dt>
<dd>
<p>The <a href="https://docs.pingidentity.com/auth-node-ref/latest/set-error-details.html">Set Error Details node</a> adds details to the JSON response when a journey ends in an error.</p>
</dd>
<dt class="hdlist1">Monitor log entries in the admin console (FRAAS-25665)</dt>
<dd>
<p>Advanced Identity Cloud now provides a console for monitoring log entries in development and sandbox<sup class="footnote" id="_footnote_addon_footnote_sandbox">[<a id="_footnoteref_10" class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_10" title="View footnote.">10</a>]</sup> environments. You can view, filter, and search log entries for specific log sources within a timeframe to quickly identify issues, track events, and ensure system security.</p>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingoneaic/tenants/audit-debug-logs-monitoring.html" class="xref page">Monitor log entries in the admin console</a>.</p>
</div>
<div class="admonitionblock note">
<table>
<tbody><tr>
<td class="icon">
<i class="fa icon-note" title="Note"></i>
</td>
<td class="content">
This is a <a href="https://docs.pingidentity.com/pingoneaic/product-information/release-lifecycle.html#beta" class="xref page">beta</a> feature and is limited to development and sandbox<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_10" title="View footnote.">10</a>]</sup> environments. It’s not available in production environments.
</td>
</tr>
</tbody></table>
</div>
</dd>
<dt class="hdlist1">Custom WS-Fed applications (IAM-8261)</dt>
<dd>
<p>You can now create custom WS-Fed<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_7" title="View footnote.">7</a>]</sup> applications for single sign-on (SSO).</p>
</dd>
<dt class="hdlist1">Try In SDK button (IAM-8618)</dt>
<dd>
<p>A <strong class="label">Try In SDK</strong> button has been added to the <strong class="label">Details</strong> page for Native / SPA applications. This lets developers quickly test SDKs with dynamic configuration code snippets.</p>
</dd>
</dl>
</div>
</div>
<div class="sect3">
<h4 id="enhancements_19"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#enhancements_19"></a>Enhancements</h4>
<div class="ulist">
<ul>
<li>
<p>AME-31372<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_5" title="View footnote.">5</a>]</sup>: An <strong class="label">Agent</strong> journey is now available by default in both Alpha and Bravo realms.
The <code>Agent</code> journey makes it easier to integrate with Ping Identity agents and gateways. It validates the agent credentials with an
<a href="https://docs.pingidentity.com/auth-node-ref/latest/agent-data-store-decision.html">Agent Data Store Decision</a> node.</p>
</li>
<li>
<p>AME-30050: You can now enable a next-generation script in the AM native admin console native console to run after a Dynamic Client Registration request is processed.</p>
</li>
<li>
<p>AME-30716: Removed <code>Failed to create SSO Token</code> from logs at warning level. To observe these warnings, increase the log level to debug.</p>
</li>
<li>
<p>AME-30801: The <a href="https://docs.pingidentity.com/auth-node-ref/latest/inner-tree-evaluator.html">Inner Tree Evaluator node</a>
now has an optional <strong class="label">Error Outcome</strong> that lets you capture exception details if an exception occurs during the evaluation of the child journey.</p>
</li>
<li>
<p>FRAAS-25818: The built-in SMTP server in new tenants now has a limit of 10 emails per minute and a fixed email sender address with the format <code>noreply@&lt;tenant-fqdn&gt;</code>.</p>
</li>
<li>
<p>IAM-7581: Text wrapping in table views has been improved for readability.</p>
</li>
<li>
<p>IAM-8573: IDM now includes an endpoint to retrieve individual themes from the <code>/themerealm</code> configuration using either an <code>ID</code> or a <code>_queryFilter</code> by name. This improves performance and ensures reliable theme loading, even on slow networks.</p>
</li>
<li>
<p>IAM-8610: When you create an SSO application for Microsoft 365, the application now generates a signing certificate, which you can download or rotate as needed.</p>
</li>
<li>
<p>IAM-8633: You can now add, remove, and rearrange table columns for managed identities and application provisioning tables.</p>
</li>
<li>
<p>IAM-8925<sup class="footnote" id="_footnote_addon_footnote_iga">[<a id="_footnoteref_11" class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_11" title="View footnote.">11</a>]</sup>: In Identity Governance, you can now configure actions that trigger automatically when a form first loads or when a user changes the value of a specific field.</p>
</li>
<li>
<p>OPENAM-22467: Customers can now provide any value in the <code>typ</code> header in JWTs.</p>
</li>
<li>
<p>Greater control over journey session duration and authenticated session timeouts:</p>
<div class="ulist">
<ul>
<li>
<p>OPENAM-23265: The <a href="https://docs.pingidentity.com/auth-node-ref/latest/set-session-properties.html">Set Session Properties node</a> now lets you customize the <strong class="label">Maximum Session Time</strong> and <strong class="label">Maximum Idle Time</strong> of the session granted at the end of the journey.</p>
</li>
<li>
<p>OPENAM-23290: The new <a href="https://docs.pingidentity.com/auth-node-ref/latest/update-journey-timeout.html">Update Journey Timeout node</a> lets you update the timeout of the journey.</p>
</li>
<li>
<p>OPENAM-23291: The <a href="https://docs.pingidentity.com/auth-node-ref/latest/email-suspend.html">Email Suspend node</a> now lets you configure the <strong class="label">Suspend Duration</strong> in minutes. This duration overrides existing global or realm settings.</p>
</li>
<li>
<p>OPENAM-23515: You can now set the suspend duration in next-generation scripted decision nodes when suspending the journey.</p>
</li>
</ul>
</div>
</li>
<li>
<p>OPENAM-23438: Following WebAuthn registration and authentication, new information is added to the transient state.</p>
</li>
<li>
<p>OPENAM-20709: On successful authentication, the <a href="https://docs.pingidentity.com/auth-node-ref/latest/webauthn-authentication.html">WebAuthn Authentication node</a> now adds the UUID of the device (<code>webauthnDeviceUuid</code>) and the name of the device (<code>webauthnDeviceName</code>) to the shared state. This lets you track the use of biometric authentication and the device used to authenticate.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="fixes_24"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#fixes_24"></a>Fixes</h4>
<div class="ulist">
<ul>
<li>
<p>AME-30969: If the <strong class="label">OIDC Claims Plugin Type</strong> in the OAuth 2.0 provider is set to <code>SCRIPTED</code> but no script is selected, the <code>userinfo</code> endpoint now returns the <code>sub</code> claim, in compliance with the OIDC specification. Previously, the <code>userinfo</code> endpoint returned an empty JSON object. If you still require this behavior, set the <code>esv-scripting-legacynulloidcclaimsscriptbehaviour</code> ESV to <code>true</code>.</p>
</li>
<li>
<p>IAM-4397: Fixed an issue in the hosted journey pages where the prompt text for the Choice Collector node wasn’t fully visible and the default option wasn’t visible at all.</p>
</li>
<li>
<p>IAM-8632: Fixed an issue where validation errors were incorrectly displayed for pre-populated fields.</p>
</li>
<li>
<p>IAM-8789: Managed identity modals now correctly handle both single-value and array-based enum types.</p>
</li>
<li>
<p>IAM-8871: The hosted account pages no longer freeze and throw an error when editing details if there are empty custom enum array values.</p>
</li>
<li>
<p>IAM-8902: The application username field in SAML 2.0 NameID flows is now correctly set to <code>uid</code> instead of <code>username</code>.</p>
</li>
<li>
<p>IAM-8933: Fixed an issue in the Advanced Identity Cloud admin console when creating or modifying identity objects with a required boolean property. You can now set the value of the required boolean property to <code>false</code>.</p>
</li>
<li>
<p>IAM-9062: Hosted pages themes no longer continuously refresh when trying to set up or confirm two-factor authentication (2FA).</p>
</li>
<li>
<p>OPENAM-20749: For server-side OAuth 2.0 tokens, the <a href="https://docs.pingidentity.com/pingoneaic/am-oauth2/oauth2-introspect-endpoint.html" class="xref page">/oauth2/introspect</a> response can now overwrite the <code>iss</code> claim of the introspectable token. To enable this behavior, set the <code>esv-enable-oauth2-sync-refresh-token-issuer</code> ESV to <code>false</code>.</p>
</li>
<li>
<p>OPENAM-22928: When agents authenticate to Advanced Identity Cloud, the session created no longer expires.</p>
</li>
<li>
<p>OPENAM-23303<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_5" title="View footnote.">5</a>]</sup>: Fixed an issue where access management scripts were failing to load because they contained strings that resembled configuration placeholders.
The code that parses these scripts now correctly ignores configuration placeholders and any strings that resemble them.</p>
<div class="admonitionblock important">
<table>
<tbody><tr>
<td class="icon">
<i class="fa icon-important" title="Important"></i>
</td>
<td class="content">
If you have access management scripts that reference ESVs, ensure that they use the correct syntax for ESVs.
For example, for a script that references an ESV named <code>esv-my-variable</code>, use the syntax <code>systemEnv.getProperty("esv.my.variable")</code>.
</td>
</tr>
</tbody></table>
</div>
</li>
<li>
<p>OPENAM-23334: You can now use the <code>mergeShared</code> and <code>mergeTransient</code> methods to add nested objects to <code>ObjectAttributes</code>.</p>
</li>
<li>
<p>OPENAM-23519: Improved error handling during WebAuthn registration when the Android lock screen isn’t enabled.</p>
</li>
<li>
<p>OPENAM-24159: Fixed an issue with Identity Assertion nodes failing if there are more than one in a journey.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="removed"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#removed"></a>Removed</h4>
<div class="dlist">
<dl>
<dt class="hdlist1">Modules and chains (AME-30762)</dt>
<dd>
<p>The legacy PingAM authentication mechanism using modules and chains is enabled by default in Advanced Identity Cloud but has never been supported. Modules and chains remain enabled but have been removed from the Advanced Identity Cloud admin console.</p>
<div class="paragraph">
<p>Modules and chains will be removed entirely in the near future. If you’re using them for authentication, you must migrate to nodes and journeys as soon as possible.</p>
</div>
<div class="paragraph">
<p>Advanced Identity Cloud provides default journeys that replace the corresponding <em>default</em> modules and chains. Any default authentication processes that relied on modules and chains are unaffected by their removal.</p>
</div>
</dd>
</dl>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[16 Jul 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#16_jul_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#16_jul_2025</guid>
            <pubDate>Thu, 17 Jul 2025 08:48:13 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 18076.4</strong></p>
</div>
<div class="paragraph">
<p>No customer-facing features, enhancements, or fixes released.<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_1" title="View footnote.">1</a>]</sup></p>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[08 Jul 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#08_jul_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#08_jul_2025</guid>
            <pubDate>Fri, 11 Jul 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 18076.3</strong></p>
</div>
<div class="sect3">
<h4 id="enhancements_20"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#enhancements_20"></a>Enhancements</h4>
<div class="ulist">
<ul>
<li>
<p>AME-31379: Setting the new ESV <code>esv-oauth2-provider-request-object-processing-enforced</code> to <code>true</code> now lets admins enforce which validation rules are applied when processing OAuth 2.0 request objects.</p>
</li>
<li>
<p>FRAAS-25437: Tenant administrators with the <code>tenant-auditor</code> role can now use federated access to authenticate to Advanced Identity Cloud.</p>
</li>
<li>
<p>IAM-3441: Added pagination to all list views.</p>
</li>
<li>
<p>IAM-7265: You can now right-click a node in the journey editor to access a context menu.</p>
</li>
<li>
<p>IAM-7266: Added an action bar to the journey editor that lets you deselect or delete currently selected nodes.</p>
</li>
<li>
<p>IAM-7580: Pages now span the full width of the screen, improving navigation and usability.</p>
</li>
<li>
<p>IAM-8260: Advanced Identity Cloud now supports multiple WS-Fed<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_7" title="View footnote.">7</a>]</sup> applications.</p>
</li>
<li>
<p>IAM-8640: The <strong class="label">Release Notes</strong> link in <strong class="label">Tenant Settings</strong> now opens the release notes for the tenant’s specific version.</p>
</li>
<li>
<p>IAM-8714<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_2" title="View footnote.">2</a>]</sup>: You can now configure columns in the Identity Governance access review page.</p>
</li>
<li>
<p>OPENIDM-21206: Usernames and application names must now be unique, as enforced by the datastore.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="fixes_25"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#fixes_25"></a>Fixes</h4>
<div class="ulist">
<ul>
<li>
<p>IAM-7413: The reCAPTCHA Enterprise node is now fully supported.</p>
</li>
<li>
<p>IAM-8489: Fixed an issue with the display of application logos in the hosted account pages.</p>
</li>
<li>
<p>IAM-8770: Fixed an issue with the calendar icon position in date fields.</p>
</li>
<li>
<p>IAM-8773: Fixed an issue where key actions such as realm login were blocked in older tenants with an unmodified original theme.</p>
<div class="admonitionblock important">
<table>
<tbody><tr>
<td class="icon">
<i class="fa icon-important" title="Impact of the fix for IAM-8773"></i>
</td>
<td class="content">
<div class="paragraph">
<p>The impact of the fix for IAM-8773 is that unmodified original themes in older tenants have been purposefully updated to add any missing theme properties that are present on the latest themes.
This has been done to make them compatible with recent efficiency improvements to themes in the hosted account pages, but without changing their appearance.</p>
</div>
<div class="paragraph">
<p>The missing properties will appear in your promotion reports, but this is expected and does not require you to take any action.</p>
</div>
</td>
</tr>
</tbody></table>
</div>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="related_releases_2"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#related_releases_2"></a>Related releases</h4>
<div class="admonitionblock note">
<table>
<tbody><tr>
<td class="icon">
<i class="fa icon-note" title="What are related releases?"></i>
</td>
<td class="content">
<div class="paragraph">
<p>This section contains information about releases of other Ping Identity products that are often deployed as part of an Advanced Identity Cloud implementation.
To take advantage of these updates, you must manually upgrade your RCS and PingGateway implementations.</p>
</div>
</td>
</tr>
</tbody></table>
</div>
<div class="ulist">
<ul>
<li>
<p>The RCS 1.5.20.30 release is now available to
<a href="https://backstage.pingidentity.com/downloads/browse/identity-cloud/all/productId:idm-connector-servers/minorVersion:1.5/version:1.5.20.30/language:java" target="_blank" rel="noopener">download</a>.
Learn more in <a href="https://docs.pingidentity.com/openicf/connector-release-notes/preface.html" target="_blank" rel="noopener">ICF release notes</a>.</p>
</li>
<li>
<p>The PingGateway 2025.6.1 release is now available to
<a href="https://backstage.forgerock.com/downloads/browse/identity-cloud/all/productId:ig/minorVersion:2025.6/version:2025.6.1/releaseType:full" target="_blank" rel="noopener">download</a>.
Learn more in <a href="https://docs.pingidentity.com/pinggateway/release-notes/whats-new.html#pinggateway_2025_6_1" target="_blank" rel="noopener">PingGateway 2025.6.1</a>.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[03 Jul 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#03_jul_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#03_jul_2025</guid>
            <pubDate>Fri, 04 Jul 2025 11:30:32 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 17889.11</strong></p>
</div>
<div class="sect3">
<h4 id="fixes_26"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#fixes_26"></a>Fixes</h4>
<div class="ulist">
<ul>
<li>
<p>IAM-8314<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_3" title="View footnote.">3</a>]</sup>: Fixed an issue where setting ESVs in connector or provisioner configuration stops the Advanced Identity Cloud admin console from being able to update connectors or run a liveSync operation.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[29 Jun 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#29_jun_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#29_jun_2025</guid>
            <pubDate>Tue, 01 Jul 2025 15:57:22 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 17889.10</strong></p>
</div>
<div class="paragraph">
<p>No customer-facing features, enhancements, or fixes released.<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_1" title="View footnote.">1</a>]</sup></p>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[24 Jun 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#24_jun_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#24_jun_2025</guid>
            <pubDate>Tue, 24 Jun 2025 16:02:04 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 17889.7</strong></p>
</div>
<div class="sect3">
<h4 id="key_features_16"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#key_features_16"></a>Key features</h4>
<div class="dlist">
<dl>
<dt class="hdlist1">Tenant auditors (IAM-8086)</dt>
<dd>
<p>Advanced Identity Cloud now lets you invite tenant auditors to access the Advanced Identity Cloud admin console. Tenant auditors
can view settings, configuration, and data but cannot modify them.</p>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingoneaic/tenants/tenant-administrator-settings.html#tenant-administrator-groups" class="xref page">Tenant administrator groups</a>.</p>
</div>
</dd>
</dl>
</div>
</div>
<div class="sect3">
<h4 id="enhancements_21"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#enhancements_21"></a>Enhancements</h4>
<div class="ulist">
<ul>
<li>
<p>FRAAS-25155: Increased log batching size to avoid truncation of large JSON log entries.</p>
</li>
<li>
<p>ANALYTICS-868: The <strong class="label">Tenant Admin Activity</strong> report has been changed to the <strong class="label">Tenant Admin Initiated Entity Type Changes</strong> report. The new report provides more detailed and business-friendly insights into changes made by tenant administrators:</p>
<div class="openblock">
<div class="content">
<div class="ulist">
<ul>
<li>
<p>Field names added, deleted, or modified.</p>
</li>
<li>
<p>Before and after values of changed attributes (if applicable).</p>
</li>
<li>
<p>Business-friendly entity name and entity type changes to custom attributes and custom objects.</p>
</li>
</ul>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingoneaic/reports/administration/analytic-reports.html#tenant-admin-initiated-entity-type-changes-report" class="xref page">Tenant admin initiated entity type changes report</a>.</p>
</div>
</div>
</div>
</li>
<li>
<p>IAM-8405: You can now duplicate out-of-the-box reports.</p>
</li>
<li>
<p>IAM-8591: Dynamic sorting for report results. You can now sort report results directly in the Advanced Identity Cloud admin console after running a report.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="fixes_27"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#fixes_27"></a>Fixes</h4>
<div class="ulist">
<ul>
<li>
<p>FRAAS-25142: Fixed a memory issue in the ESV service.</p>
</li>
<li>
<p>FRAAS-25434: Fix issue causing source to sometimes be defined as <code>unknown</code> in <code>/monitoring/logs/*</code> endpoints.</p>
</li>
<li>
<p>FRAAS-25226: Allow a higher threshold for large JSON log entries before splitting them into smaller plaintext log entries.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="deprecations_2"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#deprecations_2"></a>Deprecations</h4>
<div class="ulist">
<ul>
<li>
<p>FRAAS-23329: Access to ESV REST API endpoints using the fr:idm:* scope is now deprecated.</p>
</li>
<li>
<p>FRAAS-23330: Access to ESV REST API endpoints using resource version 1.0 is now deprecated.</p>
</li>
<li>
<p>FRAAS-25269: The IDC.CLI OAuth 2.0 client is now deprecated in existing tenants and no longer provisioned in new tenants.</p>
</li>
</ul>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingoneaic/product-information/deprecation-notices.html" class="xref page">Deprecation notices</a>.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[17 Jun 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#17_jun_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#17_jun_2025</guid>
            <pubDate>Wed, 18 Jun 2025 13:01:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 17713.10</strong></p>
</div>
<div class="paragraph">
<p>No customer-facing features, enhancements, or fixes released.<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_1" title="View footnote.">1</a>]</sup></p>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[16 Jun 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#16_jun_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#16_jun_2025</guid>
            <pubDate>Mon, 16 Jun 2025 18:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 17713.9</strong></p>
</div>
<div class="sect3">
<h4 id="fixes_28"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#fixes_28"></a>Fixes</h4>
<div class="paragraph">
<p>FRAAS-25514: Addressed a security issue.</p>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[12 Jun 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#12_jun_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#12_jun_2025</guid>
            <pubDate>Mon, 16 Jun 2025 13:01:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 17713.8</strong></p>
</div>
<div class="paragraph">
<p>No customer-facing features, enhancements, or fixes released.<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_1" title="View footnote.">1</a>]</sup></p>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[10 Jun 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#10_jun_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#10_jun_2025</guid>
            <pubDate>Mon, 16 Jun 2025 13:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 17713.5</strong></p>
</div>
<div class="sect3">
<h4 id="key_features_17"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#key_features_17"></a>Key features</h4>
<div class="dlist">
<dl>
<dt class="hdlist1">Akamai Account Protector node (TNTP-227)<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_5" title="View footnote.">5</a>]</sup></dt>
<dd>
<p>Use the Akamai Account Protector node to inject the Akamai risk score into your authentication journey. When the Akamai Account Protector feature is enabled for your application, the Akamai Edge service provides the risk score in an HTTP header, which is consumed by the Akamai Account Protector node.</p>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingoneaic/release-notes/rapid-channel/akamai-acc-protect-node.html" class="xref page">Akamai Account Protector node</a>.</p>
</div>
</dd>
</dl>
</div>
</div>
<div class="sect3">
<h4 id="enhancements_22"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#enhancements_22"></a>Enhancements</h4>
<div class="ulist">
<ul>
<li>
<p>FRAAS-25205: Consolidated <code>End User UI</code>, <code>Login UI</code>, <code>Administrator Registration UI</code>, and <code>Administrator UI</code>
status page components into a single <code>Administrator UI</code> component as they were all reporting the same service.</p>
</li>
<li>
<p>IAM-2453<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_5" title="View footnote.">5</a>]</sup>: Hosted pages themes now show the loading spinner until they are fully loaded.</p>
</li>
<li>
<p>IAM-4769<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_5" title="View footnote.">5</a>]</sup>: Hosted journey pages now fall back to the default theme if a journey is configured with a deleted theme.</p>
</li>
<li>
<p>IAM-6781<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_5" title="View footnote.">5</a>]</sup>: Password policy hints now show all policy conditions when creating a new user identity in the Advanced Identity Cloud admin console.</p>
</li>
<li>
<p>IAM-7615<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_5" title="View footnote.">5</a>]</sup>: The Certificate Collector node now validates the value set in the <strong class="label">HTTP Header Name for Client Certificate</strong> field based on the value selected in the <strong class="label">Certificate Choice Method</strong> field.</p>
</li>
<li>
<p>IAM-8358<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_5" title="View footnote.">5</a>]</sup><sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_2" title="View footnote.">2</a>]</sup>: Hosted account pages now display a <strong>New User</strong> button in the <strong>Users</strong> list view for delegated administrators.</p>
</li>
<li>
<p>OPENIDM-15771: You can now set locales in identity management scripts with the <a href="https://docs.pingidentity.com/pingoneaic/tenants/email-send.html#email-send-post-params" class="xref page"><code>_locale</code> parameter</a>.</p>
</li>
<li>
<p>OPENIDM-17680: Advanced Identity Cloud now supports enumerations in string and number attributes of its identity schema. To make an attribute an enumeration, add <code>"enum" : [ "one", "two", "three" ]</code> to the attribute. Advanced Identity Cloud requires create and update privileges to use one of the enumerated values.</p>
</li>
<li>
<p>OPENIDM-19918: You can now choose whether synchronization detects identity array changes using <em>ordered</em> or <em>unordered</em> comparisons. Set the <a href="https://docs.pingidentity.com/pingoneaic/idm-synchronization/chap-implicit-live-sync.html#array-comparison" class="xref page"><code>comparison</code></a> configuration property in the schema. Unordered JSON array comparison ignores the order of elements and can negate the need for certain custom scripts within mappings. Relationship and virtual property array fields default to unordered comparisons. All other fields default to ordered comparisons.</p>
</li>
<li>
<p>OPENIDM-20023: RCS communication with Advanced Identity Cloud can now use stricter authorization. Learn more in <a href="https://docs.pingidentity.com/pingoneaic/idm-auth/authorization-and-roles.html#secure-openicf-access" class="xref page">Secure RCS access</a> and <a href="https://docs.pingidentity.com/pingoneaic/product-information/migration-dependent-features.html" class="xref page">Migration dependent features</a>.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="fixes_29"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#fixes_29"></a>Fixes</h4>
<div class="ulist">
<ul>
<li>
<p>FRAAS-25256: Fixed an issue that was causing missing data in analytics dashboards.</p>
</li>
<li>
<p>IAM-1479<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_5" title="View footnote.">5</a>]</sup>: Email field validation in the Advanced Identity Cloud admin console now runs only when typing stops or the field is unfocused.</p>
</li>
<li>
<p>IAM-7858<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_5" title="View footnote.">5</a>]</sup>: Hosted account pages now use the access management <code>maxIdleExpirationTime</code> value to prompt the <strong class="label">You will be signed out soon</strong> modal.</p>
</li>
<li>
<p>IAM-8382<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_5" title="View footnote.">5</a>]</sup>: Fixed an issue in the bookmark app where the <strong class="label">URL</strong> field validation stopped the <strong class="label">Create Application</strong> button working the first time it was clicked.</p>
</li>
<li>
<p>IAM-8383<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_5" title="View footnote.">5</a>]</sup>: Fixed an issue in the bookmark app where the <strong class="label">URL</strong> field accepted ESV secrets.</p>
</li>
<li>
<p>IAM-8398<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_5" title="View footnote.">5</a>]</sup>: Field labels positioned above a field now remain left aligned when autofill is triggered.</p>
</li>
<li>
<p>IAM-8441<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_5" title="View footnote.">5</a>]</sup>: Fixed a display issue in the Advanced Identity Cloud admin console where connector servers and connector server clusters with long names went off the edge of the screen.</p>
</li>
<li>
<p>OPENAM-21783: Improved token management for OAuth 2.0 clients that override the <strong class="label">Use Client-Side Access &amp; Refresh Tokens</strong> setting. The OAuth 2.0 <code>applications</code> endpoint now correctly shows all tokens issued to these clients. Additionally, administrators can now successfully revoke any of the tokens issued to these clients.</p>
</li>
<li>
<p>OPENDJ-11486<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_5" title="View footnote.">5</a>]</sup>: Fixed an exception caused by identity management user queries with a filter containing wildcards and specific object classes.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[27 May 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#27_may_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#27_may_2025</guid>
            <pubDate>Wed, 28 May 2025 14:33:44 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 17584.6</strong></p>
</div>
<div class="sect3">
<h4 id="enhancements_23"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#enhancements_23"></a>Enhancements</h4>
<div class="ulist">
<ul>
<li>
<p>ANALYTICS-1004<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_4" title="View footnote.">4</a>]</sup>: Support for custom attributes and relationships in the organization entity for advanced reports.</p>
</li>
<li>
<p>OPENAM-23218: Legacy SAML 2.0 IDP attribute mapper scripts now have access
to the <code>httpClient</code> binding.</p>
</li>
<li>
<p>OPENAM-23710: Legacy SAML 2.0 IDP adapter scripts now have access to the
<code>httpClient</code> binding.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="fixes_30"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#fixes_30"></a>Fixes</h4>
<div class="ulist">
<ul>
<li>
<p>OPENIDM-20995: Fixed an issue that prevented error reports during certain operations on groups or users. For example, trying to remove a non-existing attribute or null value now correctly results in an exception message to the client if these operations are not supported by the target system.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[16 May 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#ws_fed_16_may_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#ws_fed_16_may_2025</guid>
            <pubDate>Fri, 16 May 2025 12:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version N/A</strong></p>
</div>
<div class="sect3">
<h4 id="key_features_18"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#key_features_18"></a>Key features</h4>
<div class="dlist">
<dl>
<dt class="hdlist1">Integrate with Microsoft 365 (FRAAS-21607)</dt>
<dd>
<div class="openblock">
<div class="content">
<div class="paragraph">
<p>Ping Identity introduces Microsoft 365 integration, a new <a href="https://docs.pingidentity.com/pingoneaic/product-information/add-on-capabilities.html" class="xref page">add-on capability</a>
for Advanced Identity Cloud. The new Microsoft 365 application lets you set up SSO using the WS-Federation identity protocol.</p>
</div>
<div class="paragraph">
<p>Learn more in <a href="https://docs.pingidentity.com/pingoneaic/app-management/register-a-custom-application.html#register-SSO-application" class="xref page">Register an SSO application</a>.</p>
</div>
</div>
</div>
</dd>
</dl>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[13 May 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#13_may_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#13_may_2025</guid>
            <pubDate>Fri, 16 May 2025 11:00:00 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 17436.7</strong></p>
</div>
<div class="sect3">
<h4 id="enhancements_24"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#enhancements_24"></a>Enhancements</h4>
<div class="ulist">
<ul>
<li>
<p>IAM-987: Added support for <a href="https://docs.pingidentity.com/pingoneaic/idm-objects/creating-modifying-managed-objects.html#enum-managed-object" class="xref page">enums</a> (drop-down lists) to hosted account pages.</p>
</li>
<li>
<p>IAM-1116: Added support for <a href="https://docs.pingidentity.com/pingoneaic/idm-objects/creating-modifying-managed-objects.html#enum-managed-object" class="xref page">enums</a> (drop-down lists) to the Advanced Identity Cloud admin console.</p>
</li>
<li>
<p>IAM-2103: Added support for <a href="https://docs.pingidentity.com/pingoneaic/idm-objects/creating-modifying-managed-objects.html#enum-managed-object" class="xref page">enums</a> (drop-down lists) to hosted journey pages.</p>
</li>
<li>
<p>IAM-6822: Added the ability to manage cookie domains in the Advanced Identity Cloud admin console.</p>
</li>
<li>
<p>IAM-7412: Updated the password policy feature in the Advanced Identity Cloud admin console. Added the ability to specify a minimum substring length between 3 - 64 to use when validating passwords against user attribute values. The default is still 5 characters, but can now be reduced to as few as 3 characters to catch shorter string matches.</p>
</li>
<li>
<p>IAM-7794<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_2" title="View footnote.">2</a>]</sup>: Added support for using custom identity objects in the form builder.</p>
</li>
<li>
<p>IAM-7919: Improved color contrast ratio of the <strong class="label">Delete Account</strong> button text when focused.</p>
</li>
<li>
<p>IAM-7934: Improved color contrast ratio of date fields when focused.</p>
</li>
<li>
<p>IAM-7957: Improved color contrast ratio of the <strong class="label">Deselect</strong> button text when focused.</p>
</li>
<li>
<p>IAM-7966: Improved color contrast ratio of <strong class="label">In Progress</strong> text.</p>
</li>
<li>
<p>IAM-8016<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_2" title="View footnote.">2</a>]</sup>: Allow form authors to specify a user filter when dynamic enums are selected.</p>
</li>
<li>
<p>IAM-8085: Updated the <strong class="label">Add a Parameter</strong> reports modal to use entity attributes for input.</p>
</li>
</ul>
</div>
</div>
<div class="sect3">
<h4 id="fixes_31"><a class="anchor" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#fixes_31"></a>Fixes</h4>
<div class="ulist">
<ul>
<li>
<p>FRAAS-15518: Fixed issue that prevented localization of <strong class="label">Session timed out</strong> message in certain locales.</p>
</li>
<li>
<p>FRAAS-24449: Enhanced the reliability of metrics collection under high-load conditions.</p>
</li>
<li>
<p>FRAAS-24990: Fixed an issue where requests to the <code>/monitoring/logs</code> and <code>/monitoring/logs/tail</code> endpoints timed out after 15 seconds rather than the expected 60 seconds.</p>
</li>
<li>
<p>IAM-5834: Fixed a double-encoding issue in the SAML app that affected IdP-initiated sign on.</p>
</li>
<li>
<p>IAM-6796: Jobs are now prevented from being scheduled with frequencies that cause invalid date errors.</p>
</li>
<li>
<p>IAM-7855: Fixed a typo in the help text returned when there are no results to display.</p>
</li>
<li>
<p>IAM-8237: Corrected floating labels in the date picker in the hosted journey pages.</p>
</li>
<li>
<p>IAM-8361: The <strong class="label">Save</strong> button in the <strong class="label">Edit Bookmark</strong> application is now inactive while checking if the ESV exists.</p>
</li>
<li>
<p>IAM-8364: Fixed issues in SAML end-to-end scenarios.</p>
</li>
<li>
<p>IAM-8378: Fixed an issue that stripped HTML elements from email templates.</p>
</li>
<li>
<p>IAM-8403: Fixed border focus location and floating label issues in <strong class="label">Tag</strong> fields.</p>
</li>
<li>
<p>IAM-8434: Fixed an issue that prevented duplication of new themes that contain special characters.</p>
</li>
</ul>
</div>
</div>
]]></description>
        </item>
        <item>
            <title><![CDATA[03 May 2025]]></title>
            <link>https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#03_may_2025</link>
            <guid isPermaLink="false">https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#03_may_2025</guid>
            <pubDate>Tue, 06 May 2025 09:16:59 GMT</pubDate>
            <description><![CDATA[

<div class="paragraph">
<p><strong>Version 17274.5</strong></p>
</div>
<div class="paragraph">
<p>No customer-facing features, enhancements, or fixes released.<sup class="footnoteref">[<a class="footnote" href="https://docs.pingidentity.com/pingoneaic/release-notes/regular-channel-changelog.html#_footnotedef_1" title="View footnote.">1</a>]</sup></p>
</div>
]]></description>
        </item>
    </channel>
</rss>