The following lists hotfixes for the Identity Platform release 20.06.

20.06 hotfixes

Release No.

Release Date

Ref ID

Issue / Description




Hard Token Enrollment Support – Updated logic to enroll Hard Tokens by means of the Assign HID device field on the Self Service and Help Desk pages.




Unhandled SecurePortal Error – Anonymous users landing on the SecurePortal would encounter an on-screen error instead of being redirected to login screen.


AD-LDS Password Validation Issue – Addressed issue with AD-LDS connections that use user + password workflows in the Advanced Settings (formerly Classic Experience).


FIPS Compliance on User Handler Web Service Page – Added logic to make EncryptUser.aspx page compliant with FIPS.


Configuration Setting for ACS URL Restriction – Added a configuration setting to turn ON or OFF the ACS URL whitelist enforcement.


Before you install this hotfix, see this KB article: How to establish trust for ACS redirects in SP-initiated SAML requests




EncryptUser Issue – Addressed issue with a truncated URL in EncryptUser.aspx.


SAML Post Issue – Added logic to support SAML Post workflow redirects through adaptive auth (group restriction).


LDAP Authentication Improvement – Added logic to make LDAP authentication over SSL/TLS more secure.


Unhandled SecurePortal Error – Anonymous users landing on the SecurePortal would encounter an on-screen error instead of being redirected to login screen.


OATH Tokens Bulk Upload Support – Added logic to support bulk uploads of OATH tokens (TOTP and HOTP tokens).

For more information, see Bulk upload hardware OATH tokens using CSV file




Passcode App Update – Supports the ability to register on more than one computer.

This requires an updated version of Passcode for Windows or Passcode for Mac.


Email Template Save Issue – Addressed issue with updating and saving the OTP Email Template on the Overview tab in full cloud instances.


API Update – Update compatibility between newer Identity Platform enrollment data and existing APIs.


OIDC Enhancements – Enhancements to OpenID Connect (OIDC) include the following updates:

  • Ability to add custom claims to OAuth2 access tokens

  • For all custom claims, you can define a scope relationship to dynamically include in the tokens

  • Client scope deny list can be inverted to an allow list

  • Configurable nbf (not before) claim time offset

  • Ability to make the claim with group values as an string array instead of a comma delimited string




Firefox Login Issue – Addressed issue with Submit button in Firefox when user selects an autofill login option.


Skip to Post Authentication Issue – Addressed issue with an incorrect skip to post authentication page using an invalid password.


OIDC Issue – Added logic to better handle the post logout redirect URI.


Digital Fingerprint (DPF) in 2019 Theme Issue – Addressed issue with browser device fingerprint sometimes not pushing out MFA.




Proof Key for Code Exchange (PKCE) Improvement – Improve PKCE support to revoke access tokens without a client secret.


QR Enrollment Page Improvement – Added new help text for end users on the QR enrollment page.


Digital Fingerprint Issue – Addressed issue with user agent string picking up identical digital fingerprint settings in Google Chrome and Microsoft Edge.

After applying the hotfix, this issue can still occur for a specific configuration. See this KB article for a workaround: Workaround for digital fingerprint hotfix


Push-to-Accept in L4W Issue – Addressed issue with Push-to-Accept not working consistently in Login for Windows (L4W).


One-Time-Passcode (OTP) App Default Theme Issue – Addressed an issue when a Classic Experience realm MFA is set to use "One-Time Passcode via Phone Call and SMS". The MFA displayed to the end user does not show an option to select SMS.


Enhanced SAML Consumer – Added the ability to integrate the Identity Platform as a SAML SP with Arculix or any third-party IdP.

For information about setting up the Identity Platform and Arculix integration, see SecureAuth IdP and Arculix integration.


Air-Gapped QR Code Support – Added support for QR enrollments for time-based one-time passcodes (TOTP) in an air-gapped environment.


Air-Gapped Identity Platform Issue – Added logic to ignore unavailable hosts in an air-gapped environment.




RBAC Configuration Issue – Addressed an issue with saving configuration changes to the role-based access control (RBAC) on the UI.


Adaptive Auth Redirect Issue – Addressed issue with signature validation in SP-init redirect to a different realm.


CyberArk SDK Integration Support – Backported CyberArk SDK updates.


AppPool Performance Improvement – Improve AppPool performance with Identity Platform call to SecureAuth cloud services.


Country Code Lookup Issue – Addressed issue with the default country code issue on the Classic Multi-Factor Methods tab.


Audit Log Update – Update in the Auth API to mask knowledge-based answers (KBA) in the Audit logs.


Session URL Issue – EncryptUser.aspx has a ReturnURL to send the encrypted user cookie after authentication. This fix allows a dynamic ReturnURL, if it is provided and our ReturnURL is left blank.




Custom Token Value Support – New option to Base64 encode the custom token value.


Webservice Profile Lookup Issue – Addressed issue causing removal of profile data. The following describes this issue in more detail.

A rare scenario occurs in the web service when the lookup for a user's membership succeeds, and in the same request, the profile lookup times out. The user does not receive an error and it allows the user to proceed in the login workflow.

If the login workflow included a multi-factor method (MFA), a different error message would display, related to not finding any MFA in the user's profile.

If the login workflow is only username and password, then the login would succeed and save an empty profile for the user. This issue clears all writable values in the user profile.

This issue first occurred after a previous hotfix (EE-2253) to reduce the web service timeout to a reasonable value (5 seconds).

Web service timeouts usually occur when the login to a realm has been idle for too long and suspends itself.

The hotfix prevents the user profile from clearing out by not allowing the user to continue in the current login request during a timeout. If the timeout is due to an idle realm, the second attempt normally succeeds and the user can continue the login workflow.


Azure AD Password Reset Support – Added inline support for password reset of Azure AD synced users.


Adaptive Group Check Issue – Addressed issue to ensure that the adaptive group check is correctly performed after an invalid password attempt.


Proof Key for Code Exchange (PKCE) Improvement – Improve PKCE support to allow Refresh Token use without the client_secret.


SQL Database Log Improvement – Improve null handling for SQL database logs.


2019 Theme Issue – Addressed display issue in 2019 Theme for the OIDCEndSession.aspx page.


Public / Private Mode Issue – Addressed an issue to ensure the system honors a change to the public/private mode setting in the Classic Experience.




Password Reset Improvement – Improvement to to self-service password reset functionality for a specific use case.

For more information, see this knowledge base article: Self-service password reset hotfix update


Web Admin Issue – Addressed issue with missing KBA/KBQ settings in the web.config in the Classic Experience.


Email Template Support – Reinstate support to customize email templates in the Identity Platform for cloud deployments.


OIDC Issue – Added logic to better handle double logins in use cases where the user clicks Submit, and presses Enter.

Install this hotfix if you have:

  • OIDC / OAuth2 integrations


Web Admin UI Issue – Addressed issue with the Test Connection button on the Data tab.


JSON Web Token Support – Added support for iat (issued at) attribute.


URL Enrollment Issue – Addressed issue to enable biometric push notification using URL enrollment.




Mobile Authentication – Fixed issue where an extra comma was incorrectly added to a payload file.


Account Update Issue – Addressed an issue that affected the Account Update page when using a Web Service (Multi-Datastore) with Windows SSO.


International Phone Format Issue – Addressed an issue that affected some international phone number formats.


Password Reset Support – Added support to unlock account first on the Password Reset page and then redirect users to reset their password.


2019 Theme Issue – Reinstate support in the Classic Experience Web Admin for the URL links to Forgot Username, Forgot Password, and Restart Login pages for the 2019 Theme.


Web Service (Multi-Datastore) Realm Issue – Addressed login issues using TOTP OATH token with Google Authenticator.


This is an update to the following issue reported under EE-2120 in hotfix 20.06-9.

OIDC Issue – Added logic to better handle login prompts.

Install this hotfix if you have:

  • OIDC / OAuth2 integrations




Password Throttling API Response Message – Added additional clarification to password throttling AP response message.


Device Fingerprint Optimization – Device fingerprint profile (DFP) optimized when realm is configured in Private Mode only.


SAML OneTimeUse Condition Support – Added support for the SAML OneTimeUse condition.


QR Enrollment Issue – Addressed issue when using an email address during login to the QR enrollment page. 

Install this hotfix you have:

  • Multi-Factor App Enrollment – QR Code realm


SAML Assertion Update – Added support for FriendlyName user attribute.

To use the FriendlyName user attribute, it requires the following application setting in the web.config:

<add key=“ExtendedSAMLAttrXXFriendlyName” value=“YourFriendlyName” />

Where XX is a number between 1-10 associated with the attribute.

For Identity Platform cloud deployments, contact Support to update your web.config.


Content and Localization Issue – Addressed issue where edits in the verbiage editor did not show up on the Logout.aspx page.


IPv6 Address Handling Improvement – Enhanced ability to better manage IPv6 addresses.


Added New Response Times to Audit Logs – Addressed issue to include OTP response times in audit logs.


Default MFA Delivery Options Improvement – Added logic so that the first MFA option on the list is always selected by default.


OpenID Connect Scopes Issue – Resolved an issue with OpenID scope values not rendering correctly for OIDC Authorizations.

Install this hotfix if you have:

  • OIDC / OAuth2 integrations


OIDC Issue – Added logic to better handle login prompts.

Install this hotfix if you have:

  • OIDC / OAuth2 integrations


WebServices Timeout Issue – Added logic to optimize timeout values for profile lookups.


This is an update to the following issue reported under EE-1967 in hotfix 20.06-8.

Data Store Connection Issue – Addressed an issue causing intermittent problems in the Identity Platform when the connected data store is slow or unreliable.




Maximum Device Count – Resolved an issue where, when users reached the maximum limit of registered devices, no warnings were displayed.


Error Handling Improvement – Added additional logic to better manage errors that occur when using the API OTP validate endpoint.

Install this hotfix if you have:

  • Authentication API enabled


Security Optimization – JQuery.js file optimized for security best practices.

This hotfix is required for 20.06 deployments.


Data Store Connection Issue – Addressed an issue causing intermittent problems in the Identity Platform when the connected data store is slow or unreliable.


Adaptive Endpoint Issue – Resolved an issue causing the endpoint to incorrectly prompt for 2FA for users in an allowed group.


AD LDS Account Unlocking Issue – Addressed an issue causing the Identity Platform to incorrectly see accounts locked that had been previously unlocked by (AD LDS).

Install this hotfix if you have:

  • AD LDS data store integration


A fallback xml attribute for the lockout duration was added to the web.config. Contact Support for more information.


Security Optimization – Angular.js library optimized for security best practices.

This hotfix is required for 20.06 deployments.


Web Service Realm Issue – Resolved an issue that caused disabled WebService realm to continue to function if the username and password existed.

Install this hotfix if you have:

  • Web Service (Multi-Datastore) integration disabled on the Data tab


Login Delay Issue – Resolved an issue resulting in potential delays for the login page when using IWA or Transparent SSO.

Install this hotfix if you have:

  • IWA workflow

  • Transparent SSO workflow


Security Optimization – Redirect pages optimized for security best practices.

This hotfix is required for 20.06 deployments.


2019 Theme Issue – Fixed an issue causing the login page in 2019 theme to not load when using Internet Explorer 11 browser.

Install this hotfix if you have:

  • 2019 Theme selected on the Overview tab




2019 Theme Issue - Password Inline Warning – Resolved an issue where users couldn't bypass the prompt to optionally change their password.

Install this hotfix if you have:

  • 2019 Theme selected on the Overview tab


2019 Theme Issue - Profile Missing page – Resolved an issue where the Restart Login link didn't display on the profilemissing.aspx page.

Install this hotfix if you have:

  • 2019 Theme selected on the Overview tab


FIDO2 Authentication Issue – FIDO2 authentication ignores proxy settings.

Install this hotfix if you have:

  • FIDO2 WebAuthn enabled as MFA method


FIDO2 Authentication Improvement – Error handling improvements to user login when user does not have a registered FIDO2 security key.

Install this hotfix if you have:

  • FIDO2 WebAuthn enabled as MFA method


FIDO2 Authentication Improvements – Improvements related to FIDO2 authentication include:

  • Added audit logging to all FIDO2 calls with response times

  • Update issue with not loading New Experience data stores behind a proxy

  • Disabling login call to FIDO2 when this MFA is not applicable

Install this hotfix if you have:

  • FIDO2 WebAuthn enabled as MFA method




Web Admin Optimization – Removal of unused code and subfolder from the SecureAuth Identity Platform Web Admin project folder.


WS-Federation Update – In realms that use WS-Federation, this update requires allow-listing of URLs for the wreply field.

If a wreply setting is configured, the hotfix will use the host of this setting for the new allow-list.

There is also a new optional setting to support allow-listing of more than one URL by using a comma-delimited list.

Install this hotfix if you have:

  • WS-Federation integrations


Performance Enhancements – Update exception handling to improve system performance during login and enrollment workflows.


Updates to Audit Logging for SQL – Audit logging updates for SQL data store response times. 

Install this hotfix if you have: 

  • SQL data store integration


SAML Request Signature Validation Certificate Issue – In certain SAML workflows, signature validation was not successful.

Install this fix if you have:

  • SAML applications configured in the Application Manager

  • SAML applications configured in the Post Authentication tab


By installing this hotfix, any expired signing certificate is now enforced by the certificate expiration date.

To override this setting to allow expired certificates, set the following application setting in the web.config:

<add key="BlockSAMLRequestCertExpiration" value="False" />


Self-Service Account Update Theme Issue – There were some missing labels on the AccountUpdate.aspx page using 2016 or 2019 Themes.

Install this hotfix if you have:

  • Self-service Account Update page configured

  • 2016 or 2019 Theme selected in the Overview tab


Security Optimization – OIDC authorization with PKCE optimized for security best practices.

This hotfix is required for 20.06 deployments.


Hotfix Installer Update – Hotfix installer updates the cloud certificate URL to use https.


Hotfix Installer Update – Hotfix installer uninstalls Metricbeat.




Biometric Support – Re-enrollment in the Authenticate app in order to use biometric identification is no longer required.

Install this hotfix if you have:

  • Enabled the Authentication app previously and now want to use Biometric identification in the login workflow without users re-enrolling.

For more information, see Support biometric options in login workflow with Authenticate app.


Submit Form Post Issue – The Submit Form Post realm incorrectly removes password data following certain special characters.

Install this fix if you have:

  • Submit Form Post configurations


Transformation Engine Support for OIDC / OAuth2 Workflows – Transformation Engine now supports OIDC / OAuth2 workflows.

Install this fix if you have:

  • OIDC / OAuth2 integrations


Multiple Workflow Configuration Issues – Resolved issues with setting up a Multiple Workflow Configuration and password throttling validation issue.

Install this hotfix if you have:

  • Multiple Workflow Configuration enabled and configured in the Workflow tab

  • Password Throttling enabled and configured in the Workflow tab


Service Provider Metadata XML Issue – In the New Experience, the metadata XML exports in the wrong format.


2019 Theme Issue with Login Workflow – Users can't login with the 2019 theme in Internet Explorer 11 or Office 365 using embedded browser controls. The Submit button stays disabled at login.

Install this hotfix if you have:

  • 2019 Theme selected in the Overview tab


SAML Request Signature Validation Certificate Issue – In certain SAML workflows, signature validation was not successful.

Install this fix if you have:

  • SAML applications configured in the Application Manager

  • SAML applications configured in the Post Authentication tab


By installing this hotfix, any expired signing certificate is now enforced by the certificate expiration date.

Contact Support to override this setting to allow expired certificates. It requires the following application setting in the web.config:

<add key="BlockSAMLRequestCertExpiration" value="False" />




2016 Theme Support for Biometric MFA – The new Biometric MFA option was not available for use in the 2016 theme option.

Install this hotfix if you have:

  • 2016 Theme selected in the Overview tab

  • Biometric identification enabled as an authentication option in the Multi-Factor Methods settings > Authentication Apps OR

  • Mobile Login Requests (Push Notifications) enabled in the Multi-Factor Methods tab


OIDC Claim Format Issue – The email_verified claim should be sent as a boolean value.

Install this hotfix if you have:

  • OIDC / OAuth2 integrations


Performance Optimizations – Realms created in the Classic UI are now optimized to reduce latency.

Install this hotfix if you have:

  • Realms created using the Classic UI experience


OIDC Issue – The OIDC algorithm header reverted back to HS256 during product upgrade.

Install this hotfix if you have:

  • OIDC / OAuth2 integrations


Security Optimization – Admin API update to data store optimized for security best practices.

This hotfix is required for 20.06 deployments.


Redirect with Token Issue – Redirect with token workflows were intermittently unsuccessful under certain conditions.

Install this hotfix if you have:

  • Redirect with Token configurations in the Workflow and / or Adaptive Authentication tab


Additional logging enhancements and updated SecureAuth branding




This hotfix includes a file correction to a previous 20.06-2 hotfix addressing this issue:

Certificate Issue – For customers upgrading from Identity Platform release 19.07.01 to 20.06, the SHA-1 assertion now verifies correctly.

This hotfix is required for 20.06 deployments.




OIDC / OAuth2 Workflow Session Issue – OIDC queries in OAuth workflows now read correctly when a user has two browser tabs open when authenticating into a resource.

Install this fix if you have:

  • OIDC / OAuth2 integrations


Certificate Issue – For customers upgrading from Identity Platform release 19.07.01 to 20.06, the SHA-1 assertion now verifies correctly.

This hotfix is required for 20.06 deployments.


OIDC / OAuth 2 Issue – Fixes an issue with scope values not rendering correctly on the Post Auth tab for OpenID Connect/OAuth 2.0.

Install this fix if you have: 

  • OIDC / OAuth2 integrations


Authentication API Improvement – The Authentication API now supports Link-to-Accept via SMS and email as an available multi-factor method MFA option.

Install this hotfix if you have:

  • Authentication API enabled in the API tab

  • Link-to-Accept enabled in the Classic UI experience




Realm List Display Issue – Classic administration realm navigation bar repositions incorrectly after save.


Azure AD UPN Domain Check – Resolves issue with unnecessary uppercase and lowercase domain name check in username.

Install this hotfix if you have:

  • Azure AD integrated with the Identity Platform


Push Notification Company Name – In the SecureAuth Authenticate app login request UI, the configured company name was not accurately displaying.

Install this hotfix if you have:

  • Authentication Apps enabled in a Policy OR

  • Mobile Login Requests enabled in the Multi-Factor Methods tab

  • Users employing the SecureAuth Authenticate app for authentication


Redirect with Token Issue – Redirect with token workflows were unsuccessful.

Install this hotfix if you have:

  • Redirect with Token configurations in the Workflow and / or Adaptive Authentication tab


International Phone Number Issue – Ten-digit International phone numbers were automatically being prepended with “1”, making those numbers unusable for MFA.

Install this hotfix if you have:

  • Phone MFA methods enabled in a Policy

  • Phone MFA methods enabled in the Registration Methods tab


Password Throttling Validation Issue – Users passwords not always validated when using Password Throttling feature.

Install this hotfix if you have:

  • Password Throttling enabled and configured in the Workflow tab


Database Logging Issue – Database logs experiencing a table lock stopped writing new log entries.

Install this hotfix if you have:

  • Database logging enabled in the Logs tab


Chrome 404 Error on Manage Accounts Page – Chrome browser would give a 404 error to users on the Manage Accounts (help desk) page if the page timed out and user logs back in, whereas other browsers would redirect them back to the page after authentication.

Install this hotfix if you have:

  • Manage Accounts page configured in the Post Authentication tab

  • Users employing Chrome browser


Corrupted CyberArk Username – When using CyberArk for the directory credentials, the username would become corrupted during simultaneous connections.

Install this hotfix if you have:

  • CyberArk integration for the directory integration credentials on the Data tab


2019 Theme Not Rendering Correctly – Pages in the realm root were not rendering correctly when using the 2019 theme.

Install this hotfix if you have:

  • 2019 Theme selected in the Overview tab

  • Realm root pages configured in the Post Authentication tab


Admin Console Issue – Admin console may not load after reboot.

  • This hotfix is required for 20.06 deployments.


Error Verbiage Improvements – In OAuth flow, if the authorization code ID and saved code ID do not match, it displayed the error message, "this code has already been used" which is misleading. Error message now reads as "Authorization Code does not match or has already been used".

Install this hotfix if you have:

  • OIDC / OAuth2 integrations


Biometric Method Issue – For a Mobile Login (Push Notification) method involving any biometric as the Request Type in the Classic Experience, some configuration fields are greyed out.

Install this hotfix if you have:

  • Mobile Login (Push Notification) MFA method set up to use any Biometric as the Request Type in the Multi-Factor Methods tab


Transformation Engine Issue – Resolves issue in which the Transformation Engine did not work correctly when used with WS-Federation.

Install this hotfix if you have:

  • Transformation Engine enabled and configured


Resetting IIS Settings – After making changes to IIS and then changes to the SecureAuth Web Admin, the changes made in IIS were reverted to the previous configuration.

Install this hotfix if you have:

  • Windows Auth IIS settings changed from the SecureAuth default


Invalid SQL Password Issue – Password data was cut off in the database when using encrypted password format, resulting in an invalid user password at login.

Install this hotfix if you have:

  • SQL data store integration

  • Password format as encrypted


Debug Log Cleanup – Debug logs required changes.

This hotfix is required for 20.06 deployments.


SecureAuth Identity Platform was not able to effectively retrieve the email address from the Azure AD data store.

Install this hotfix if you have:

  • Azure AD integrated in the Data tab

  • Email 1 property mapped to an Azure AD attribute