3.1.1-Beta
New Features
Framework Upgrade: Java-based services are updated for spring framework, spring boot, and updated utility libraries. Please note it may impact several functionalities: a. Access Review b. Risk Engine c. Data Logger d. Reports e. Webhook Sample
Provision rule module updated to support (type: user type and Converter Type: String ) custom attributes as condition parameters.
Support added for address1 and address2 field in user for the following: a) User Import via CSV File b) Reconciliation Application c) Amaya Application d) JIT e) Workflow - Inbox > user details, should address fields be visible Pending workflow > user details, should address fields be visible Archive > user details, should address fields be visible f) In the SSO profile mapping drop-down these fields should be visible.
Workflow: a. Menu Action: Update the topic of the workflow request for menu action. b. My Request: In My Workspace ➝ Inbox ➝ My Request, we show a list of requests that are requested for logged-in users. Now we provide support to show a list of requests which is requested by logged-in users. So now we are showing both requests which are requested and requests for logged-in users.
360 Degree Reconciliation: a. Migrated APIs from Python to Java, since it was a major roadblock for performance.
Webhook sample API details a. Added remark of appId in URL
UI improvement - Global search bar (ctrl + k) search result improvement
Screenshot Removed right side panel in my workspace dashboard which previously showed no. of pending workflow requests with the user
Cymmetri Verify App - A sync service will run to check the pending notification actions that did not take place because the app was in a closed-on-background state and will sync the data based on the notifications
Cymmetri Self-Service App - Earlier to register a tenant in cymmetri self-service we used to scan from our app to register a tenant but now you can use any camera or any scanner of that sort to register a tenant
UI Improvement - "Test Connection" should be prevented when an operation is not configured
SLO- Reverted as business case gap in the developed feature
Breached Password (Pwned Password 98crores+) Integration with Password policy.
Common adaptive data moved to master db: a. ipreputation b. short-lived domain c. breached password
MFA: Encrypt userName(login) in the request of API user behavior initiateKeystrokeCheck.
Suspend Resume: a. After the resume of the user's end date is clear and the user acts as a fresh user
Fixes
PAM Workflow- Meta condition workflow for devices is not getting triggered.
The dashboard count is mismatched.
Policy Map- Cymmetri field dropdown should contain Address1 and Address2 fields
Autofill API sorts in alphabetic order for JSON objects for create/update
Onboarding || User should be able to unselect an application
Add and Edit password policy-need to g\show exact labels for the fields
Identity hub>User create- When importing users space should get eliminated
ServiceNow CURL Import not working
"Test Connection" should be prevented when an operation is not configured
TEAMS-Users profile pic not showing
My workspace- Teams- Showing processing please wait validation message
creating the user through the JIT Message was rejected due to the issue of instant expiration
Campaign- The Google Workspace application name is not visible in the campaign
AD application New bundle- Showing error while importing group having special symbol(-) for recon
Application recon pull configuration-recon pull configuration vanished suddenly
login with domain admin-need to provide Adaptive menu access
AD recon user push- When recon is executed in exist on Cymmetri and does not exist in target = Unlink, the operation should have been executed in Ignore case
AD Application new bundle- Group recon pull operation is showing in ignore state but still, groups are imported in Cymmetri
AD New Bundle>Address Field- Not able to add AD application when address fields are mapped, showing error
AD new bundle- When an AD application is assigned to a remote group, the application is highlighted
Cymmetri Verify App - While deleting the account from Cymmetri authenticator, TOTP is not getting
Custom attribute- Even when a custom attribute is disabled from the configuration, it remains visible
Cymmetri Verify App- For old tenants before env was considered if that totp is used for auto-verified
Custom Attribute-Provision- When a custom attribute with special characters is created and applied
Grade workflow- When workflow over workflow is assigned and is approved by the approver, still workflow is still not updated
Cymmetri Self-service App - Once we click on the web link from the scanner, it should show confirmation
Self-service Mobile App - When an app is in a Quit state and the app is via a scanner(camera), it is not redirected to the login page of the website
JIT- Once the default value is set, the user is unable to edit it, and when attempting to edit, the default toggle is shown as disabled
API SSO- Profile mapping configuration is not working
Provision Rule - Custom Attribute - Value field is not accepting space
AD Application New bundle- The "Application assigned successfully" message should not be shown when the test provision has failed and the application is assigned to a remote group
Azure authorization curl is mis-imported
Provision Rule - The existing rule configuration with the custom attribute is not working.
Audit log-for-date filter add default date is Today
User import-file size upload issue
Cymmetri Verify App - While deleting the account from Cymmetri authenticator, TOTP is not getting removed automatically
Cymmetri Verify App - While authenticating automatically via cymmetri authenticator, the "user not found" message comes twice in the iOS device.
Cymmetri Verify App- For old tenants before env was considered if that totp is used for auto verification it shows the user has not found the need to add that compatibility as well, via Passwordless (TOTP)
AD authentication- Showing invalid token error
Tenant creation not working
MFA- Factors showing empty
Breach password- Asking webauth, this factor is only for passwordless
MFA- The user, is not able to login when the user is trying to login using the normal password flow
Teams config- When the team configuration is inactive or does not match the conditions, an error message is displayed after logging in from the user account, yet all data is still shown
Adaptive service responding slow in load testing
AD Application new bundle- When the Unassign/Deprovision reconciliation is executed for group pull/push, the group should not be deleted from Active Directory
Provision rule - The application is not getting configured for the second condition present in the OR condition
SAML- Showing saml type mismatch error when the user is trying to click on Gmail via SP-initiated process
when the user creates via JIT then the user creation workflow should be skipped
PAM-Vaulting Configuration-AD test showing route issue
Login page- The user is not able to login when MFA is enabled( Prod issue)
Reports- When the report is scheduled, Scheduler history shows content not found and the execution status is aborted
AD Application new Bundle- Audit log for pending records should be shown when executing recon user push for failed provision test
Grade workflow- When workflow over workflow is assigned and is approved by the approver, still workflow is still not updated
Time-based application- Scheduler is executed even when a user is moved to suspended
Workflow- User creation using JIT(external IDP Azure)- Workflow is not getting triggered
Password policy- password rule updated with contains instead of exact match
Self-service-My request takes time to load if more data present
Teams config- When the team configuration is inactive or does not match the conditions, an error message is displayed after logging in from the user account, yet all data is still shown
FIDO-On push approve showing message something went wrong
User lock- When a user account is active, and the same account is logged in through another browser, and by any means, the account gets locked, the first session should get terminated.
Workflow Application Deprovision- Workflow is applied for (Role1) but when removing role 2 still workflow is getting initiated.
JIT- Once the default value is set, the user is unable to edit it, and when attempting to edit, the default toggle is shown as disabled
Recon Group PUSH- When recon is executed for both existing Deprovision, then the group should be deleted from the Target application and not from Cymmetri
PAM-Add/Edit vault user showing error
MFA push location showing unknown
/mfasrvc/userbehaviour/initiateKeystrokeCheck in this API login going in plain text expected encrypted.
MFA- Factors showing empty
AD New Bundle- Available Records should be synced when recon is executed for the first time after executing recon in the ignore case
Audit- Change archive to Suspend when user is deleted and moved to suspend users
AD application new bundle - When SAMaccount name is set to false in the Group policy map, members are not assigned in the group when recon Pull is executed for both exist=Update
Recon Group PUSH- When recon is executed for both existing Deprovision, then the group should be deleted from the Target application and not from Cymmetri
Identity Hub-Group- Change Audit log message
AD Application- When the group is unassigned via recon, users, and applications are deleted but the group is not
File Uploads, Filename length validation should be inclusive of the file name and extensions
User import-file size upload issue
AD Recon group Push- When recon is executed for a group that exists in Cymmetri and does not exist in the target system Operation should be shown in Ignore case as no action is performed on Groups
Remote Group- When the user is added to the remote group, the count should be increased automatically or after changing tabs
Recon Push Users- Multiple entries for the same users are visible in Recon History.
MFA- When push authentication is enabled and MFA rules are saved, but then Push auth is disabled from MFA factors, users are still prompted for push authentication when attempting to log in
Deprovision: After resuming a user from the suspended user list and applying deprovisioning via a scheduler with no end date, the user is still being deprovisioned again
Workflow metacondition- The Metacondition name is getting reset after selecting
AD group attribute- When the member attribute is clicked, it redirects to the assignment page
While creating the custom attribute with the same name as the provision rule options, the application is not getting assigned
External IDP Rule- When the external IDP authentication rule condition matches the user details, the user is unable to log in to the external IDP. Additionally, when that user is locked, an 'Invalid Auth Config' error message is shown.
Provision Rule - Custom Attribute - If the list of custom attributes is more than 10 records while selecting and saving the 11 key, it is not getting saved
When the user deletes, add more information in the audit log under the event attribute
Amaya-On update token screen getting blank
Known Bugs
Manager notification: receiving user name required manager name
In the application setting if to user flag is off then the also application shows in the recent application.
Unable to identify application properties data type where value is empty