Skip to main content

Cumulative changes: 24.04 through 26.0.0

Organizations upgrading from SecureAuth® Identity Platform release 24.04 to 26.0.0 will find substantial improvements in authentication flexibility, security monitoring, and deployment options. This document includes features introduced in patch releases 24.4.1 through 24.5.0, and in releases 26.0.1 through 26.2.0.

The following table maps features from Identity Platform release 24.04 to new and enhanced capabilities in releases 26.0.0 through 26.2.0. If you're upgrading from a patch release (such as 24.4.6), many of these features may already be available in your environment. Entries added after the 26.0.0 base release name the release that introduced them.

For complete list of all updates, see Release Updates 24.04 and Release Updates 26.0.0.

24.04 (base)

26.0.0 through 26.2.0 (cumulative)

Differences

---

Air-gapped deployment: Support for isolated network environments running SecureAuth IdP.

New deployment option for networks without internet connectivity. Supports Windows Server 2022, FIDO2/Passkey authentication, help desk verification, and YubiKey HOTP.

See Air-gapped deployment overview.

---

API data store support: Authenticate users through API-based data stores.

SecureAuth IdP now supports API-based authentication and profile data access, enabling upgrades without additional customization for organizations using API authentication.

---

Identity Pools: Manage temporary or dynamic users without enterprise data stores.

Create cloud-based user directories for contractors or temporary access. Includes group management and direct application linking.

See Add an Identity Pool as an identity source.

---

LOA risk engine dashboard: View and analyze Level of Assurance scores across your organization.

Dashboard displays LOA scores, authentication trends, and geographic login patterns. Administrators can monitor risk scoring and fine-tune LOA rules without searching audit logs.

See SecureAuth Level of Assurance (LOA) Provider settings

LOA confidence scoring: 0-4 scale for confidence levels

LOA confidence scoring: 0-100% scale with customizable ranges.

More granular scoring with configurable thresholds. Default ranges: Low (0-39), Medium (40-79), High (80-100).

User Account page: Basic profile management

User Account page: Enhanced with device management, phone/email verification, and session history

Expanded capabilities include authentication device registration, customizable field labels, and language support. Profile fields set as "Visible (read-only)" only display when populated.

See User Account page configuration

SSO Portal Themes: Theme configuration for SSO Portal only.

Modern Themes: Expanded theming for multiple Identity Management pages

Renamed from "SSO Portal Themes." Now supports User Account page, SSO Portal, and other IdM pages with modern layouts.

Session timeout: Basic timeout configuration.

Session timeout: Enhanced with session expired warnings.

Users receive warnings before session expiration on Modern Theme pages. Option to wait or automatically restart login process.

SAML attributes: Standard attribute set.

SAML attributes: Expanded to include Browser Session ID, Client IP Address, and Authentication Method.

New attributes available in Advanced Settings and New Experience SAML integrations. Also available in OpenID Connect ID Token Claims configuration.

SAML metadata: Manual file management.

SAML metadata: Enhanced with URL import/export and global domain settings.

New capabilities include global domain specification for all SAML applications, import/export Service Provider metadata through URL, and update metadata by importing new files.

Microsoft Conditional Access: Custom Controls only.

Microsoft Conditional Access: Added External Authentication Methods (EAM) support.

Support for external authentication methods in Conditional Access with Microsoft Entra ID, including certificate-based Windows authentication.

See Microsoft Conditional Access External Authentication Method (EAM) integration guide

---

OIDC Manager: OpenID Connect and OAuth management in New Experience.

Early Access feature for managing OIDC and OAuth applications in New Experience interface.

See OIDC Manager

FIDO2 device management: Basic enrollment controls.

FIDO2 device management: Approve devices by AAGUID and validate with FIDO Alliance.

Administrators can approve FIDO Alliance-verified devices using their AAGUID. End users can view approved devices on FIDO enrollment page.

See FIDO2 WebAuthn global MFA settingsFIDO2 WebAuthn global MFA settings

MFA initialization: Redirect to separate enrollment pages.

Inline MFA initialization: Register additional MFA methods during login.

Users can set up mobile Push/TOTP, FIDO2, Yubikey, and HID devices directly in the login flow when methods are required but not enrolled.

Login options: Username and MFA methods.

QR code-only login: Option to hide username field and show only QR code.

New configuration option speeds up authentication and reduces phishing risks using session-based QR codes. Configure in authentication policy on Login Workflow tab.

Transparent SSO: Basic SSO functionality.

Transparent SSO: Enhanced with continuous authentication support.

Added logic to PostAuth pages for continuous authentication. Re-evaluates adaptive policies and group restrictions after login, preventing bypass of restrictions with valid cookie.

A feature flag disables continuous authentication during Transparent SSO flows. Earlier upgrades enabled the behavior by default, which changed authentication prompts in existing environments without a policy reconfiguration. Added in SecureAuth IdP release 26.0.2

Dashboard - User Profile Data: Basic login tracking.

Dashboard - Access History: Detailed view of user login activity.

Administrators can click Access History column numbers to view detailed login records including timestamps and access patterns. Available in cloud deployments only.

Login for Windows: Standard configuration.

Login for Windows: Added Ctrl+Alt+Delete password change option.

Users can update passwords through self-service or must authenticate before password changes. Improved login performance and standardized interface.

See End user login experience on Windows

Help Desk - Password Reset: Manual password creation.

Help Desk - Generate Password: System-generated secure passwords.

New "Generate Password" button creates secure system-generated passwords, ensuring complexity requirements are met.

Policy configuration - Users and groups: Exact name matching.

Policy configuration - Users and groups: Wildcard support for names.

Wildcards now supported in Advanced Settings (Adaptive Authentication > User/Group Restriction) and New Experience (Authentication Policies > Users and groups).

Application URLs: Standard URLs only.

Custom Application URL: Create unique URL aliases for applications.

Create user-friendly URL paths for application logins in New Experience.

Authentication apps - TOTP: Standard TOTP validation.

Authentication apps - TOTP: Prevent re-use of TOTP codes.

New security setting prevents unauthorized use of previously generated TOTP codes.

Regular expressions: Limited set for password deny lists.

Regular expressions: Expanded options with custom expressions.

Extended list of available regular expressions for password deny lists. Administrators can add custom expressions.

User Account page: Standard English only.

User Account page: Customizable field labels with language support.

Configure translations in supported languages including English, Spanish, French (Canadian), and Japanese. Customize field labels to match organizational terminology.

See Customize Content and Localization

TOTP configuration: Global settings only.

Offline TOTP: Individual setting overrides for air-gapped environments.

Configure specific TOTP settings for systems without internet connectivity. Works with SecureAuth Authenticate App, Desktop App, and standard TOTP applications.

Password throttling: Standard configuration.

Password throttling: Enhanced for air-gapped deployments.

Improved brute-force password attack blocking without requiring connectivity.

Risk Engine configuration: Manual updates only.

Risk Engine: Added "Refresh LOA Configuration" option.

New link in LOA provider settings to re-sync configuration with Risk Engine. Use only when instructed by SecureAuth Support.

Authentication waiting page: Always visible during SAML post-auth.

Authentication waiting page: Toggle to show or hide during authentication.

New configuration setting allows choosing whether to display waiting page during authentication process.

SCIM provisioning: Always includes password in payload.

SCIM provisioning: Option to exclude password from payload.

New option excludes user password from SCIM provider payload during provisioning. Some SCIM providers require passwords and may fail without it.

Localization: Limited language support.

Localization: Added French-Canadian language support.

Expanded language support includes French-Canadian.

LOA conditional rules: Require full configuration.

LOA conditional rules: Added "Continue to next rule" option.

New conditional rule for authentication policies supports Risk Engine learning phase.

Audit logs - LOA: No specific LOA event tracking.

Audit logs - LOA: New Event ID for LOA scores and confidence levels.

Dedicated event ID tracks SecureAuth LOA score and Confidence Level for each user authentication attempt.

See View LOA data in the audit logs

Product branding: SecureAuth Identity Platform branding.

Product branding: Updated SecureAuth branding and visual design.

Platform updated with new SecureAuth branding while maintaining familiar layout.

Data store testing: Basic connection testing.

Data store testing: Fixed false negative issues with Test Credentials.

Resolved issue in cloud deployments where Test Credentials button sometimes returned false negatives for valid connections.

Split Profile data stores: Basic configuration.

Split Profile data stores: Improved error handling and creation.

Fixed issues preventing data store selection during creation and errors when editing existing configurations.

Dashboard: Available to administrators inside the admin console.

Dashboard: Publish the Dashboard as a standalone internal application.

Users such as SOC analysts, auditors, and help desk agents sign in to the Dashboard directly and view reports on logins, user profiles, authentications, and deployments without access to the admin console. Administrators control which reports are visible and scope access by data store, policy, and user group.

See Dashboard application. Added in SecureAuth IdP release 26.1.0

---

Session Validation rule: Authentication rule that checks for a valid session from another realm.

Skip re-authentication when a valid session already exists. Use this rule where Transparent SSO enforces continuous authentication and users are prompted for a second factor on every login.

See Policy configuration - Authentication rules. Added in SecureAuth IdP release 26.1.0

OpenLDAP data stores: Connect through the Generic LDAP connection type.

OpenLDAP data stores: Native connection type in the New Experience.

Native support for OpenLDAP directories, including password reset and other identity operations that did not work reliably through the Generic LDAP connection type. Available for hybrid deployments only.

See Add OpenLDAP data store. Added in SecureAuth IdP release 26.1.0

Service disruption handling: Global realm-level settings in the classic experience only.

Service disruption handling: Available in New Experience policy configuration.

The Authentication Rules tab in policy configuration includes a Service Disruption Handling section for IPv6 connectivity issues and service unavailability. Select an action for each scenario: no action, continue adaptive authentication, refuse authentication request, skip to post-authentication, or require two-factor authentication.

See Policy configuration - Authentication rules. Added in SecureAuth IdP release 26.1.0Policy configuration - Authentication rules

---

Air-gapped installer: Installs and configures PostgreSQL automatically.

You no longer need to set up PostgreSQL on a separate server or prepare database connection strings before deployment.

See Air-gapped deployment overview. Added in SecureAuth IdP release 26.1.0

SecureAuth Connector: No cache configuration during installation.

SecureAuth Connector 2.2.1: Cache configuration step during installation and upgrade.

Select a caching mode for the connector service: No Caching, In Memory (the default, which holds user data for 30 minutes and resets the timeout each time the same user authenticates), or Redis (the same behavior, stored in a Redis instance you supply a connection string for). Caching reduces queries to Active Directory and other data stores during authentication.

See SecureAuth Connector installation and SecureAuth Connector update. Added in SecureAuth IdP release 26.1.0

On-premises data store configuration: Requires SecureStorage.

On-premises data store configuration: SecureStorage no longer required.

The Identity Platform stores data store settings directly, which reduces infrastructure complexity. Existing encrypted passwords are decrypted automatically during initialization, so no manual migration is required. Added in SecureAuth IdP release 26.1.0

Microsoft Entra ID data stores: Users redirected to the Microsoft sign-in page.

Microsoft Entra ID data stores: Added Validate user password option.

Use username and password login workflows with Entra ID data stores that are federated to Microsoft applications such as Office 365. The check box in the connection settings sends user credentials directly to Microsoft for verification, using the connection credentials already configured in the data store.

See Add Microsoft Entra ID data store. Added in SecureAuth IdP release 26.1.0

SSO Portal: Applications always open in a new browser tab.

SSO Portal: Added Open application behavior setting.

Choose New tab (the default) or Same tab on the SSO Portal Page configuration page.

See SSO Portal configuration. Added in SecureAuth IdP release 26.1.0

FIDO2 Enrollment application: Managed from the Multi-Factor Methods FIDO2 (WebAuthn) drawer.

FIDO2 Enrollment application: Managed in the Internal Application Manager.

FIDO2 Enrollment appears as an internal application type under the Identity Management (IdM) category. Create multiple FIDO2 Enrollment applications, each with its own data stores, groups, authentication policies, and email notification settings. Existing FIDO2 Enrollment apps appear in the Internal Application Manager list after upgrade.

See FIDO2 enrollment page configuration. Added in SecureAuth IdP release 26.2.0

Dashboard - enrolled devices: Read-only detail views.

Dashboard - enrolled devices: Unenroll devices from the Dashboard.

Select one or more devices in the Enrolled Mobile Devices and Enrolled Authenticator Devices views on the Authentication Types tab and unenroll them in a single operation. A confirmation message appears before the operation completes. The Enrolled Mobile Devices view in the Dashboard application includes the same action. Unenrolling a device is permanent, and users must re-enroll the device before they can use it to authenticate again.

See Dashboard: Authentication Types overview. Added in SecureAuth IdP release 26.2.0

---

YubiKey Enterprise Attestation: Allow only the specific YubiKeys your organization bought.

Keep a list of approved serial numbers, choose how strictly the platform checks serials when users enroll a key and when they sign in, and remove a serial to revoke the credentials registered with that key. Enterprise Attestation is a FIDO2 standard feature, and this release is certified with Yubico YubiKeys.

See Approved YubiKey Inventory and Configure YubiKey Enterprise Attestation. Added in SecureAuth IdP release 26.2.0

Password suppression: Conditions do not include Level of Assurance.

Password suppression: Level of Assurance (LOA) available as a condition.

When you enable Allow password suppression on the Username | MFA Method | Password or (Valid Persistent Token) | MFA Method | Password workflow, LOA appears in the Add condition list on the Login Workflow tab. The condition suppresses the password step when the confidence level of the user identity meets the level you set: Low, Medium, or High.

See Use LOA for password suppression. Added in SecureAuth IdP release 26.2.0

Hybrid deployment platforms: Windows Server 2025 not supported.

Hybrid deployment platforms: Windows Server 2025 supported.

Windows Server 2025 is supported for new installations and upgrades of Identity Platform 26.0.0. Windows Server 2022 remains supported.

See Supported Windows servers for product deployments. Added in SecureAuth IdP release 26.2.0

Unique User ID: Not configurable in the data store properties.

Unique User ID: View and edit the property mapping.

Available for Active Directory, AD LDS, LDAP, OpenLDAP, NetIQ eDirectory, and Microsoft Entra ID data stores. In a Split Profile, choose which member data store provides the Unique User ID, and pick the source that is the most stable identifier for your environment. For Microsoft Entra ID, choose between Id and onPremiseImmutableId.

See Unique User ID mapping. Added in SecureAuth IdP release 26.2.0

Aux IDs: Aux ID 1 through 10.

Aux IDs: Aux ID 1 through 25.

Map Aux IDs 11 through 25 to data store fields the same way as Aux IDs 1 through 10. After you map an Aux ID, you can use it in downstream configurations such as SAML applications.

See List of stored profile field properties. Added in SecureAuth IdP release 26.2.0

Help Desk - user verification: Push to accept, with a single setting for SMS.

Help Desk - user verification: Added Symbol to Accept and separate SMS controls.

With Symbol to Accept, the help desk agent and the end user see the same symbol, and the user taps the matching symbol in the SecureAuth Authenticate app to confirm their identity. This adds an option to the earlier push-to-accept flow, where a user could approve a request without confirming its context. SMS one-time passcode and SMS login request are separate options that you enable or disable independently, and each appears to the help desk agent only when you enable it.

See Help Desk user verification configuration and Help Desk user verification process. Added in SecureAuth IdP release 26.2.0

NovellSSO.aspx page: Present but unused.

NovellSSO.aspx page: Removed.

The page worked only with a legacy Novell ActiveX control in older Internet Explorer versions. Removing it does not affect NetIQ eDirectory, formerly Novell, data store configurations. Added in SecureAuth IdP release 26.2.0

---

Defect fixes: SAML, OIDC, Modern Theme, data store, and email configuration fixes.

Releases 26.0.1 through 26.2.0 fix SP-initiated SAML POST binding when the AuthnRequest signature contains a KeyValue element, SAML assertion pages for embedded browsers that omit a language preference, the Modern Theme browser tab title after sign-in, the OIDC consent screen Approve and Deny actions, the SSL connection mode saved for a Generic LDAP data store, email settings in remote admin sessions, and a cloud broker timeout during login.

For the full list, see Release Updates 26.0.0. Added in SecureAuth IdP releases 26.0.1 through 26.2.0