PingOne Advanced Identity Cloud

Regular channel changelog

This is a changelog entry for version 22170.14. You can review the changelog for all versions in Regular channel changelog.

01 July 2026

Version 22170.14

Key features

Identity Governance role LCM (IGA-4265)[1]

The new role lifecycle management (LCM) feature lets designated end users create, update, and delete roles on behalf of others without full administrative access. All changes are submitted as workflow-driven requests, maintaining governance and security while delegating role management to business owners.

Identity Governance for AI agents (IGA-4223)[1]

Agent Governance lets you detect, onboard, and govern AI agents the same way you govern human identities, accounts, and roles. This brings them under the governance umbrella alongside human identities.

Agent Governance provides application templates to discover AI agents in the following agentic platforms:

  • AWS Bedrock

  • AWS Bedrock AgentCore

  • Azure AI Foundry

  • Microsoft Copilot Studio

  • Google Vertex AI

Enhancements

  • AME-28187: You can now set a Metadata URL in your remote consent agent. Advanced Identity Cloud retrieves the remote consent server’s (RCS) metadata from this URL. When configured, the OIDC .well-known endpoint includes the authorization_details_types_supported field, populated from the authorization detail types advertised by the RCS.

  • AME-33781: Advanced Identity Cloud now supports the WebAuthn conditional UI, also known as passkey autofill. This lets your end users sign in with a passkey if they’ve previously saved one in their browser.

  • AME-34458: Enhanced the output when you test the connection in the PingOne Worker service to display the values used in the connection test to make them easier to verify. These details are extracted from the credential JWT or derived from the worker service configuration.

  • AME-34513: Added support for the _queryFilter parameter on the realm-config/services/pingOneWorkerService/workers endpoint. Use this to query the configured worker services. For example, you can filter by credential type or by a property value such as the API URL.

  • IAM-1478: Autofill is now disabled for fields on pages where you add identities.

  • IAM-4646: Tenant administrators registered through federation no longer have the option to update their username and password on the sign-on screen.

  • IAM-8699: Advanced Identity Cloud now supports node versioning. When we make changes to a node in the future, we’ll create a new version of the node.

    This release introduces new node versions for the following nodes:

    Node Description of change

    Adds support for standalone nodes within a Page node. Standalone nodes are self-contained and can be included after the final multiple outcome node.

    Adds an option to prepopulate the username if it’s available in the shared state.

    Adds support for the WebAuthn conditional UI, also known as passkey autofill, and removes the ability to return the challenge as JavaScript.

    Removes the ability to return the challenge as JavaScript.

    Other node versioning changes include:

    Resource version 3.0 for authenticationtrees REST endpoint

    We’ve added a version-aware 3.0 resource to the realm-config/authentication/authenticationtrees endpoint. When sending a request to this endpoint, set the Accept-API-Version header to protocol=2.1,resource=3.0.

    Resource versions 1.0 and 2.0 are deprecated.

    Versioned node endpoints

    The realm-config/authentication/authenticationtrees/nodes endpoint is now versioned. Specify the version of the node in the request URL, for example: https://<tenant-env-fqdn>/am/json/realms/root/realms/alpha/realm-config/authentication/authenticationtrees/nodes/UsernameCollectorNode/2.0.

    Versionless node endpoints are deprecated.

    Audit logging

    The node version is logged in the am-authentication source under the AM-NODE-LOGIN-COMPLETED event for node versions greater than 1.0.

  • IAM-9002: The Journeys page now has an Add journey button that opens a modal for creating or importing a journey. This makes the available journey options easier to find.

  • IAM-9608: You can now assign an authorization policy to a SAML or OIDC application. This lets you restrict who can access an application to a subset of end users who have authenticated through a specific journey. Find more information in Configure an application authorization policy.

  • IAM-9937: The SaaS REST and SaaS REST (connector server) applications now let you add filter policies to object types when you configure provisioning. Adding filters at the API level reduces network overhead, boosts synchronization performance, and prevents unwanted data from entering your identity pipeline.

  • IAM-10132: The Advanced Identity Cloud admin console is now fully accessible using keyboard controls.

  • IAM-10625: The Custom WS-Fed application now includes logout mode, always authenticate user, and multi-valued claim support for SSO. Find more information in Configure the custom WS-Fed application.

  • IAM-10626: The Microsoft 365 application now includes logout mode and always authenticate user settings for WS-Trust SSO. Find more information in Microsoft 365 Sign On settings.

  • IAM-10810: The PingOne worker service now lets you configure the connection to PingOne using a credential JWT.

  • OPENAM-25759: The jwtValidator script binding now supports configurable clock skew for expirationTime and issuedAt claim validation.

  • OPENAM-25910: The OAuth 2.0 introspection endpoint now supports an RFC 9701-compliant JWT response format. When enabled, token introspection claims are nested under a top-level token_introspection claim, which separates the aud claim of the introspection response from the aud claim of the token itself. The token’s aud claim is also now correctly included for all token types, including stateless tokens.

  • OPENAM-25936: Next-generation scripts now support the utils.crypto.checkBcrypt(bcryptHash, password) method for bcrypt hash verification.

  • OPENAM-25957: All next-generation OAuth 2.0 scripts now have access to the identity, session, clientProperties, and requestProperties bindings.

  • OPENAM-27540: You can now configure a trusted CA certificate for each OAuth 2.0 client using the tls_client_auth authentication method, instead of relying only on realm-wide CAs.

Fixes

  • AME-34254: Added support for next-generation SAML SP account mapper scripts to the Advanced Identity Cloud admin console.

  • FRAAS-29198: Fixed an issue where promotions that failed due to the encrypted secrets verification check were not listing the configuration paths that needed updating.

  • IAM-5003: Fixed an issue where changing the locale on the terms and conditions creation page didn’t change the text in the editor.

  • IAM-9751: Fixed an accessibility issue where the VoiceOver screen reader was not vocalizing UI text correctly.

  • IAM-10040: Fixed an issue where the browser was incorrectly using autofill if a KBA Definition Node was within a Page node. The issue prevented use of tab and arrow functionality for that node.

  • IAM-10087: Fixed an issue where the password policy on a hosted pages sign-on screen disappeared on a window refresh when the Access Management > Authentication > Settings > Trees > Enable Allowlisting setting was enabled.

  • IGA-4139[1]: Updated the access filter component in the IGA access graph to accept dynamic filter options. This lets you use different UI components to customize the available filter options, based on context.

  • IGA-4275[1]: Fixed a pagination issue in the Direct Reports view by removing sortable columns and default sort from the Direct Reports and Delegates pages.

  • OPENAM-25543: Allowing a SAML authentication flow to continue when a circle of trust (CoT) is inactive is now deprecated. Review your SAML configurations and ensure that any CoTs used for authentication are active before Advanced Identity Cloud begins enforcing CoT status after the end-of-life date.

  • OPENAM-26359: Added a new configuration option, Enable Rich Authorization Requests with RCS, to the OAuth2 Provider service. This resolves an issue with remote consent where authorize requests with authorization_details would fail with an invalid_request error if an RCS was not configured.


1. This change applies to a feature only available in PingOne Identity Governance, which is an add-on capability and must be purchased separately.