Regular channel changelog
| This is a changelog entry for version 22555.17. You can review the changelog for all versions in Regular channel changelog. |
31 Jul 2026
Version 22555.17
Key features
- Identity for AI (IAM-9357)
-
You can now use AI agent identities to secure your organization’s AI-driven solutions. AI agent identities are specialized OAuth 2.0 clients that are onboarded with their own identities. They can securely perform tasks on behalf of end users through a delegated token exchange process, ensuring distinct accountability and granular access control.
You can use AI agent identities to securely build digital assistants that operate on behalf of end users, such as a chatbot on a retail website helping a user navigate products, or an internal workforce assistant acting on behalf of an employee to access enterprise tools like Salesforce.
Find more information in Secure your AI-driven solutions using AI agent identities.
- Proxy Connect UI (AM-9628)
-
You can now configure and manage Proxy Connect network security settings directly in the Advanced Identity Cloud admin console. Tenant administrators can manage HTTP header rulesets, IP address filtering (CIDR ranges), and toggle environment filtering statuses. Pending changes are staged and validated automatically before being applied to the load balancer.
Find more information in Manage Proxy Connect using the admin console.
Enhancements
-
AME-34566: The Evaluator Version selector is now available in the Advanced Identity Cloud admin console for all remaining next-generation script types, including OIDC node, Social Provider Handler node, OAuth2 scripts, and Policy Condition scripts.
-
FRAAS-33086: You can now migrate user accounts from the deprecated PKCS5S2 password hashing scheme to a more secure algorithm.
-
IAM-2333: The Identities page now includes an Account Status column that shows whether each user account is Active or Inactive. This column is display-only and is not intended for search or sort operations.
-
IAM-3671, IAM-9388, IAM-10148, IAM-10174, IAM-10548: Improved accessibility across hosted journey pages and the admin console, including context-sensitive page titles, form field labels, and
aria-describedbyattributes for the Attribute Collector node. -
IAM-8200: You can now use an environment secret or variable (ESV) to configure the
fromaddress for email providers. -
IAM-9953: The Advanced Identity Cloud admin console now supports light and dark display themes. You can switch between themes to match your preference or your system’s display settings.
-
IAM-10069: Hosted journey pages now display hCaptcha text and challenges in the end user’s configured locale.
-
IAM-10536, IAM-10553, IAM-10558, IAM-10559: Improved color contrast for active UI components across multiple areas of the admin console to meet accessibility standards.
-
IAM-10595: Updated the column picker component for consistent behavior across data tables in the admin console and hosted account pages.
-
IAM-10596, IAM-10597, IAM-10598: Column visibility preferences for data tables in the admin console and hosted account pages are now customizable and saved between sessions.
-
IAM-10796: Super administrators can now configure the redirect URI field to use a custom domain when setting up federated administrator access.
-
IAM-10952: The Identities page now displays a loading spinner while identity data is being fetched.
-
IGA-3141[1]: Added a configurable option to control which user attributes are displayed in the user information panel, with all attributes shown by default when none are configured.
-
IGA-3267, IGA-4140[1]: Improved certification management with configurable expiration and escalation settings that enable automatic reassignment, and a new access filter in the certification items table to help reviewers narrow results more efficiently.
-
IGA-4215[1]: Improved the manual fulfillment task view to display user, account, and entitlement details and added the ability to mark a fulfillment task as complete.
-
IGA-4224[1]: Added the ability to design custom lifecycle management forms for entitlements, enabling administrators to configure fields from glossary and schema attributes for create and modify operations.
-
IGA-4293[1]: Added support for granting and revoking roles, entitlements, and app access to AI agents from the agent console and custodian view.
-
IGA-4295[1]: Added the ability to update an AI agent’s custodians, including adding or removing custodians as needed.
-
IGA-4299[1]: Added an Activity tab for AI agents.
-
IGA-4333[1]: Added a sidebar filter to requests to make it easier to find and work with specific requests.
-
IGA-4381[1]:Improved the request type filter to dynamically retrieve available request types, so new and custom request types appear as filter options.
-
IGA-4382[1]: Improved the display of account and entitlement properties to use friendly labels from the object type schema instead of raw property keys.
-
IGA-4417, IGA-4418[1]: Added column customization to LCM table views. The entitlement LCM view now supports glossary attributes as selectable column options, and the user LCM table includes a column selector based on available schema fields and user permissions.
-
IGA-4433, IGA-4434[1]: Added support for unmanaged applications, including an Unmanaged Applications tab on the Applications page, create and edit flows, glossary management, and CSV import with upload history.
-
IGA-4438[1]: Improved access catalog role search so users can find roles by more than just role name, including role descriptions and related application or entitlement details.
-
OPENAM-27489: You can now create and edit social identity providers in the Advanced Identity Cloud admin console.
-
OPENAM-27492: You can now configure self-service journey mappings directly in the Advanced Identity Cloud admin console.
Fixes
-
FRAAS-31319: Fixed an issue where the log-streaming service relied on the
sourcefield for the original log source, which can conflict with Splunk’s reservedsourcefield. Splunk log streaming now includesstream_sourceto preserve the original Advanced Identity Cloud log source.No additional Advanced Identity Cloud or Splunk configuration is required. If the log streaming-service is already configured, the
stream_sourcefield is included automatically. -
IAM-4875: Fixed an issue where ESV values couldn’t be entered as the well-known endpoint URL when setting up Microsoft Entra ID as a federation IdP.
-
IAM-5457: Fixed an issue where using an ESV in the Password Policy page caused the page to freeze.
-
IAM-6374: Fixed an issue where journeys could be imported even when their referenced ESVs were not published.
-
IAM-8313: Fixed an issue where setting a managed object property to nullable caused it to disappear from the Password Policy attribute validation list.
-
IAM-10593: Fixed a layout issue on the Journeys page where journey counts for category tags were obscured for locales with longer words.
-
IAM-10776: Fixed an issue where the stored username was overwritten with an OTP value when Remember Me was enabled during MFA sign-on.
-
IAM-10833: Fixed an issue where the admin console incorrectly displayed "Rollback in progress" during a standard environment promotion.
-
IAM-10836: Fixed a regression where
TextOutputCallbackmessages containing custom HTML were rendered with unexpected line breaks. -
IGA-4304[1]: Fixed several disconnected application UI issues, including improvements to entitlement visibility, request handling, and error behavior in related views.
-
IGA-4388[1]: Fixed an error in the default LCM modify user form that prevented changes from being saved when a custom integer field contained a value of zero.
-
IGA-4426[1]: Fixed an issue where the Direct Reports and Delegates tables displayed an inflated record count and showed empty pages at the end of the list.
-
IGA-4441[1]: Fixed an issue where the Add button from the certification filters sidebar incorrectly appeared in other views that use the dynamic filter.
-
IGA-4452[1]: Fixed an issue where the export items action did not work for certification access reviews.
-
IGA-4516[1]: Fixed an issue where a glossary attribute update applied to an entitlement was not propagated to all accounts that held the entitlement.
Changed functionality
-
OPENIDM-22404[2]: Fixed a user enumeration vulnerability in the managed object
?_action=patchendpoint that didn’t enforce authorization before evaluating query filters. Query authorization on the target resource collection is now required and is granted through access rules or delegated admin rules. This change can affect custom integrations (like password plugins) that patch resource collections by query. -
PF-39499[3]: Microsoft 365 SSO applications now use the selected UPN Attribute Name setting for WS-Trust username authentication. Existing applications must be resaved for this change to take effect. Find more information in Configure WS-Trust.