Skip to content

Latest commit

 

History

History
7108 lines (4207 loc) · 74.5 KB

2022-what-s-new-for-cloud-identity-services-archive-3322427.md

File metadata and controls

7108 lines (4207 loc) · 74.5 KB

2022 What's New for Cloud Identity Services (Archive)

This page lists the release notes of SAP Cloud Identity Services - Identity Authentication for 2022.


Technical Component

Environment

Title

Description

Action

Lifecycle

Type

Line of Business

Modular Business Process

Product

Latest Revision

Valid as Of

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

Cloud Identity Services

2022-12-21

2022-12-21

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Tenant Images

Tenant administrator can upload a file to use a custom favicon for theIdentity Authenticationtenant. See Configure Tenant Images.

Info only

General Availability

New

Technology

Not applicable

Cloud Identity Services

2022-12-21

2022-12-21

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Tenant Settings

Tenant Administrator can change the P-number index by setting a new number from which the P-number to start. See Configure P-User Next Index.

Info only

General Availability

New

Technology

Not applicable

Cloud Identity Services

2022-12-21

2022-12-21

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

User Notifications

User can receive email alerts when the telephone they use is changed. See Send Security Alert Emails.

Info only

General Availability

New

Technology

Not applicable

Cloud Identity Services

2022-12-21

2022-12-21

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

User Authentication

Users can sign in with their telephone number as user identifier. See Configure Allowed Logon Identifiers and Configure User Identifier Attributes.

Info only

General Availability

New

Technology

Not applicable

Cloud Identity Services

2022-12-21

2022-12-21

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Password Policy

Tenant administrator can configure a custom password policy with with an unlimited password locked period. If unlimited period is set, the password can be unlocked only by the tenant administrator. See Configuring Password Policies

Info only

General Availability

New

Technology

Not applicable

Cloud Identity Services

2022-12-21

2022-12-21

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

OpenID Connect

Tenant administrator can configure the rotation lifetime to extend the validity of the refresh token after first successful rotation. See Token Policy Configuration for Applications

Info only

General Availability

New

Technology

Not applicable

Cloud Identity Services

2022-12-21

2022-12-21

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

Cloud Identity Services

2022-12-16

2022-12-16

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

OpenID Connect

Tenant administrator can select client authentication method when configure the OpenID Connect corporate identity provider in the administration console. See Configure Trust with OpenID Connect Corporate Identity Provider.

Info only

General Availability

New

Technology

Not applicable

Cloud Identity Services

2022-12-16

2022-12-16

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

Cloud Identity Services

2022-12-14

2022-12-14

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

Cloud Identity Services

2022-12-07

2022-12-07

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Integration of SAML and OIDC Logout Flows

The service supports OpenID Connect (OIDC) front-channel logout, which is used to logout from OIDC applications. The logout is integrated with the Security Assertion Markup Language (SAML) logout endpoint so that both logout endpoints behave the same way; terminating all SAML, OIDC, Identity Authentication, and corporate identity provider sessions.

For more information, see Logout URI Rules.

Info only

General Availability

New

Technology

Not applicable

Cloud Identity Services

2022-12-07

2022-12-07

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

Cloud Identity Services

2022-11-25

2022-11-24

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Audit Logs

Tenant administrator can choose Cloud Foundry regions for the audit log service configuration. See Access Audit Logs (Audit Log Service in SAP BTP, Cloud Foundry).

Info only

General Availability

New

Technology

Not applicable

Cloud Identity Services

2022-11-25

2022-11-24

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

Cloud Identity Services

2022-11-15

2022-11-14

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Administrators

Tenant administrator can change the name of the system as administrator. See List Administrators.

Info only

General Availability

New

Technology

Not applicable

Cloud Identity Services

2022-11-15

2022-11-14

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

Cloud Identity Services

2022-11-10

2022-11-09

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Two-Factor Authentication

Tenant administrator can set the number of days for which the users can postpone the enabling of second factor for authentication. See Allow Users To Skip Two-Factor Authentication Setup.

Info only

General Availability

New

Technology

Not applicable

Cloud Identity Services

2022-11-10

2022-11-09

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

Cloud Identity Services

2022-10-26

2022-10-26

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Regional Availability

Identity Authentication is now available with a single data center (DC) for the Azure infrastructure in Switzerland (Zürich). See Regional Availability.

Info only

General Availability

New

Technology

Not applicable

Cloud Identity Services

2022-10-26

2022-10-26

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

End-User Screens

The Horizon theme end-user screens are default for the system applications for all tenants, and for all applications (service providers) created via the administration console, SCIM REST API, or by the Identity Authentication operators after Oct 26, 2022. See Configure a Branding Style for an Application.

Info only

General Availability

New

Technology

Not applicable

Cloud Identity Services

2022-10-26

2022-10-26

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Documentation

You can now provide feedback on the Identity Authentication documentation using GitHub and earn credits. See the related Тip at What Are Identity Authentication?.

Info only

General Availability

New

Technology

Not applicable

Cloud Identity Services

2022-10-26

2022-10-26

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Cipher Suites

To further improve security, Identity Authentication is deprecating a number of obsolete and weak cipher suites used for HTTPS communication. As of the planned upgrade of Identity Authentication, scheduled for Nov 9, 2022, only the following list of cipher suites will be supported:

  • ECDHE-RSA-AES256-GCM-SHA384

  • ECDHE-RSA-AES128-GCM-SHA256

  • DHE-RSA-AES256-GCM-SHA384

  • DHE-RSA-AES128-GCM-SHA256

Info only

General Availability

Announcement

Technology

Not applicable

Cloud Identity Services

2022-10-24

2022-10-24

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

End-User Screens

As of the next upgrade of Identity Authentication, the Horizon theme end-user screens will become default for the system applications of all new tenants, and for all new applications (service providers) created via the administration console, SCIM REST API, or by the Identity Authentication operators.

Info only

General Availability

Announcement

Technology

Not applicable

Cloud Identity Services

2022-10-20

2022-10-20

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

 

2022-10-12

2022-10-12

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

User Access

Tenant administrator can set the number of days for which the users won't get prompted for second-factor authentication, if they sign in from the same browser. See Configure Trust this browser Option.

Info only

General Availability

New

Technology

Not applicable

 

2022-10-12

2022-10-12

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

OpenID Connect

Identity Authentication now supports the token_format. See Configure the Client to Call Identity Authentication Token Endpoint for Authorization Code Flow, Configure the Client to Call Identity Authentication Token Endpoint for Client Credentials Flow, Configure the Client to Call Identity Authentication Token Endpoint for Resource Owner Password Credentials Flow, Configure the Client to Call Identity Authentication JWT Bearer Token, and Call Identity Authentication Refresh Token.

Info only

General Availability

New

Technology

Not applicable

 

2022-10-12

2022-10-12

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Availability

Identity Authentication changed the availability monitoring for the service. The current status page statuspage.io is decommission and you can monitor the availability of the service in the Cloud Availability Center CAC/SAP4Me. For that you can see a new T-installation for Identity Services in their support tools. The Identity Authentication tenants of a customer are assigned to this new T-installation. Based on these T-installations you can request outage notifications and see potential RCA information.

Info only

General Availability

Announcement

Technology

Not applicable

 

2022-10-12

2022-10-12

Cloud Identity Services

  • Cloud Foundry
  • Kubernetes
  • Kyma

Authorization Policies

Authorization management enables administrators to use authorization policies throughout multiple environments and assign them to users. Developers have provided applications with authorization policies. They include functional checks, instance-based authorizations, and user attributes. Administrators manage authorization policies in the administration console. See Configuring Authorization Policies.

Note:

This function is only available to applications that integrate SAP Cloud Identity Services – Authorization Management.

Info only

Restricted Availability

New

Technology

Not applicable

 

2022-09-30

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

 

2022-09-28

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

User Management

User UUID is mutable now. Tenant administrator can change the User UUID attribute, initially generated by Identity Authentication, via the administration console. See Create a New User and List and Edit User Details.

Info only

General Availability

New

Technology

Not applicable

 

2022-09-28

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

User Management

Identity Authentication now supports two new user types: External and Onboardee. See Users.

Info only

General Availability

New

Technology

Not applicable

 

2022-09-28

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

User Authentication

Identity Authentication supports X.509 Certificate authentication with Subject Alternative Name (SAN) rfc822 Name. See Configure X.509 Client Certificates for User Authentication.

Info only

General Availability

New

Technology

Not applicable

 

2022-09-28

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

User Access

Tenant administrator can add text on the sign-in screen for the Horizon Standard. See Add Instructions Section on Sign-In Screen.

Info only

General Availability

New

Technology

Not applicable

 

2022-09-28

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

End-User Screens

Tenant administrator can put custom image as background on the forms for sign-in in, registration, upgrade, password update, and account activation for all applications in a tenant. See Configure Tenant Images.

Info only

General Availability

New

Technology

Not applicable

 

2022-09-28

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Availability

Identity Authentication will change the availability monitoring for the service. The current status page statuspage.io will be decommission and you will able to monitor the availability of the service in the Cloud Availability Center CAC/SAP4Me. For that customers will see a new T-installation for Identity Services in their support tools. The Identity Authentication tenants of a customer will be assigned to this new T-installation. Based on these T-installations they can request outage notifications and see potential RCA information.

Info only

General Availability

Announcement

Technology

Not applicable

 

2022-09-28

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

 

2022-09-13

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Corporate IdPs

Identity Authentication supports SHA-512 as option for signing algorithm when configuring trust with a SAML 2.0 corporate identity provider. See Configure Trust with SAML 2.0 Corporate Identity Provider.

Info only

General Availability

New

Technology

Not applicable

 

2022-09-13

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

User Groups

Tenant administrator can create new user groups or update existing ones via a CSV file upload. See Import Groups via CSV File.

Info only

General Availability

New

Technology

Not applicable

 

2022-09-13

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Real-Time Provisioning

Identity Authentication supports X.509 Certificate authentication when Identity Provisioning is configured as target system for real-time provisioning. See Configure Identity Authentication for Real-Time Provisioning.

Info only

General Availability

New

Technology

Not applicable

 

2022-09-13

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Branding Style

Tenant administrator can add text on the sign-in screen for the Horizon Standard. See Add Instructions Section on Sign-In Screen.

Info only

General Availability

New

Technology

Not applicable

 

2022-09-13

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

SAML 2.0 Trust

Tenant administrator can get metadata from the service provider or identity provider via URL. See Configure SAML 2.0 Service Provider. and Configure Trust with SAML 2.0 Corporate Identity Provider

Info only

General Availability

New

Technology

Not applicable

 

2022-09-13

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

OpenID Connect

Identity Authentication supports Revoke and Introspect Endpoints with OpenID Connect. See Call Identity Authentication Revoke Token Endpoint. and Call Identity Authentication Introspect Token Endpoint.

Info only

General Availability

New

Technology

Not applicable

 

2022-09-13

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Regional Availability

Identity Authentication will be available with a new data center for the AWS infrastructure in Brazil. The data center will be located in São Paulo.

Action: We recommend you to add the following IPs to your allowed IP list:

  • LB IP - 54.232.33.83 / 54.207.203.50 / 54.207.116.12
  • NAT IP - 18.228.75.28 / 18.229.85.43 / 54.232.93.209

Recommended

General Availability

Announcement

Technology

Not applicable

 

2022-09-13

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

 

2022-08-24

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

 

2022-08-17

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Password Configuration

Tenant administrator can specify the number of required character groups for the custom password. See Configure Custom Password Policy.

Info only

General Availability

New

Technology

Not applicable

 

2022-08-17

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Password Configuration

The option for maximum failed logon attempts for the custom password is increased to 6 from 5. See Configure Custom Password Policy.

Info only

General Availability

Changed

Technology

Not applicable

 

2022-08-17

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

SAML 2.0 Trust

Identity Authentication supports SHA-512 as option for signing algorithm. See Configure SAML 2.0 Service Provider.

Info only

General Availability

New

Technology

Not applicable

 

2022-08-17

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Corporate IdPs

Configure Trust with SAML 2.0 Corporate Identity Provider.

Info only

General Availability

New

Technology

Not applicable

 

2022-08-17

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Branding Style

Identity Authentication introduced a new branding style theme - Horizon Theme (Beta). See Tenant administrators have the option to sign or not the authentication requests and the single log out messages. See Configure a Branding Style for an Application.

Info only

Beta

New

Technology

Not applicable

 

2022-08-17

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Branding Style

Identity Authentication renamed the Default theme to Quartz. See Configure a Branding Style for an Application.

Info only

General Availability

Changed

Technology

Not applicable

 

2022-08-17

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Regional Availability

The China region will operate with an additional data center in Shanghai.

Action: We recommend you to add the following IPs to your allowed IP list:

  • LB IP - 121.91.104.198
  • NAT IP - 121.91.104.32 / 27

Recommended

General Availability

Announcement

Technology

Not applicable

 

2022-08-17

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

 

2022-08-09

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

SMS Verification

You can use Sinch Verification to enable Phone Verification via SMS or SMS Two-Factor Authentication in the administration console. See Configure Sinch Service in Administration Console.

Info only

General Availability

New

Technology

Not applicable

 

2022-08-09

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

 

2022-07-26

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

 

2022-07-21

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

OpenID Connect

Identity Authentication now supports the refresh_expiry parameter to reduce the expiration of a refresh token. See Configure the Client to Call Identity Authentication Token Endpoint for Authorization Code Flow, Configure the Client to Call Identity Authentication Token Endpoint for Resource Owner Password Credentials Flow, Configure the Client to Call Identity Authentication JWT Bearer Token, Call Identity Authentication Refresh Token, and Configure the Client to Call Identity Authentication Authorize Endpoint for Authorization Code Flow with PKCE.

Technology

Not applicable

 

2022-07-21

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Rate Limiting for OIDC Endpoints

To ensure the safe and stable operation of the service, we have introduced rate limiting on the OpenID Connect (OIDC) endpoints of the service.

For more information, see Rate Limiting and Throttling.

Info only

General Availability

Changed

Technology

Not applicable

 

2022-07-21

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Russia (Moscow) Region

Russia (Moscow) (neo-ru1) region is decommissioned as of July 13th. See Regions and Hosts Available for the Neo Environment.

Info only

Deleted

Changed

Technology

Not applicable

 

2022-07-14

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

 

2022-07-11

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

OpenID Connect

The Discovery Endpoint support is extended with private_key_jwt value for the token_endpoint_auth_methods_supported. See Call Identity Authentication Discovery Endpoint.

Info only

General Availability

New

Technology

Not applicable

 

2022-07-11

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

OpenID Connect

The list of the claims that can't be set via the default attribute configuration is extended with ias_iss. See Configuring Attributes Based on Flexible Expressions.

Info only

General Availability

New

Technology

Not applicable

 

2022-07-11

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

OpenID Connect

Tenant administrator can define the allowed grant types in the applications via the administration for Identity Authentication. See Configure OpenID Connect Application for Authorization Code Flow, Configure OpenID Connect Application for Client Credentials Flow, Configure OpenID Connect Application for Resource Owner Password Credentials Flow, Using JWT Bearer Flow, and Create OpenID Connect Application.

Info only

General Availability

New

Technology

Not applicable

 

2022-07-11

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

OpenID Connect

To improve security, Identity Authentication has stopped adding the client IDs of dependent services to tokens that have been requested using PKCE without client authentication. An application that receives a token based on a public client flow can't forward the token to a reuse service or exchange the token with the Authorization and Trust Management service of SAP BTP. Dependencies are declared in the identity service of SAP BTP. For more information, see Reference Information for the Identity Service of SAP BTP.

Info only

General Availability

Changed

Technology

Not applicable

 

2022-07-11

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

 

2022-06-22

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

 

2022-06-15

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

 

2022-05-25

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

OpenID Connect

The number of tokens that can be issued for the same session in parallel were increased to 10 from 5. See Tenant OpenID Connect Configurations and Token Policy Configuration for Applications.

Info only

General Availability

New

Technology

Not applicable

 

2022-05-25

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

 

2022-05-11

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Real-Time Provisioning

Identity Authentication source system can use the Identity Directory SCIM API (in short, SCIM API version 2). See Configure Identity Authentication for Real-Time Provisioning.

Info only

General Availability

New

Technology

Not applicable

 

2022-05-11

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Two-Factor Authentication

You can protect applications with two-factor authentication via a code sent to the user's email. See Configure Risk-Based Authentication for an Application and Configure Default Risk-Based Authentication for All Applications in the Tenant.

Info only

General Availability

New

Technology

Not applicable

 

2022-05-11

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

OpenID Connect

Tenant administrator can manually refresh the OpenID Connect metadata of the corporate identity provider. See Configure Trust with OpenID Connect Corporate Identity Provider.

Info only

General Availability

New

Technology

Not applicable

 

2022-05-11

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

 

2022-04-27

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Regional Availability

The Saudi Arabia region will operate with an additional data center in Dammam.

Action: We recommend you to add the following IPs to your allowed IP list:

  • LB IP - 130.214.248.94
  • NAT IP - 130.214.248.32 / 27

Recommended

General Availability

Announcement

Technology

Not applicable

 

2022-04-27

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

 

2022-04-13

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Corporate IdPs

Identity Authentication supports corporate identity providers using OpenID Connect. Applications that use OpenID Connect can direct users to your corporate identity provider for authentication. See Configure Trust with OpenID Connect Corporate Identity Provider.

Info only

New

Technology

Not applicable

 

2022-04-13

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

 

2022-04-08

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Regional Availability

The Europe region will operate in high availability (HA) mode with an additional data center in Frankfurt.

Action: We recommend you to add the following IPs to your allowed IP list:

  • LB IP - 130.214.144.214
  • NAT IP - 130.214.228.32 / 27

See Regional Availability.

Recommended

General Availability

Announcement

Technology

Not applicable

 

2022-04-08

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

 

2022-03-31

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Configure Applications

Tenant administrator can configure an application as a parent or child one. See Create SAML 2.0 Application and Create OpenID Connect Application.

Info only

General Availability

New

Technology

Not applicable

 

2022-03-31

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

 

2022-03-22

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

 

2022-03-16

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Corporate IdPs

Tenant administrator can configure how the AllowCreate attribute is sent to the corporate identity provider. See (Optional) Configure the Name ID Format Attribute Sent to the SAML 2.0 Corporate IdP.

Info only

General Availability

New

Technology

Not applicable

 

2022-03-16

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

 

2022-03-08

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

SMS Verification

Tenant administrator can clear the Sinch Authentication 365 configuration in the administration console for Identity Authentication. See Configure Sinch Service in Administration Console.

Info only

General Availability

New

Technology

Not applicable

 

2022-03-08

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

 

2022-03-01

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Source Systems

Identity Authentication supports certificate authentication for API calls to external source systems - SAP SuccessFactors, SAP Learning Management. See Configure Authentication Provider To Migrate User Passwords from SAP SuccessFactors Systems to Identity Authentication and Configure Authentication Provider To Migrate User Passwords fromSAP Learning Management System to Identity Authentication.

Info only

General Availability

New

Technology

Not applicable

 

2022-03-01

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Password Policies

Tenant administrator can create more than one custom password policy in the administration console. See Configure Custom Password Policy.

Info only

General Availability

New

Technology

Not applicable

 

2022-03-01

Cloud Identity Services

  • Neo
  • Kyma
  • Cloud Foundry

Corporate IdPs

Tenant administrator can include or exclude Scoping element in the SAML 2.0 request. See Configure Trust with SAML 2.0 Corporate Identity Provider.

Info only

General Availability

New

Technology

Not applicable

 

2022-03-01

Cloud Identity Services

  • Neo
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

 

2022-02-17

Cloud Identity Services

  • Neo
  • Cloud Foundry

Risk-Based Authentication

Tenant administrator can use Corporate Attribute to create rules for risk-based authentication for all applications in the tenant. See Create a New Rule for Risk-Based Authentication on Tenant Level.

Info only

General Availability

New

Technology

Not applicable

 

2022-02-17

Cloud Identity Services

  • Neo
  • Cloud Foundry

Risk-Based Authentication

Tenant administrator can use Corporate Attribute to create rules for risk-based authentication for a specific application in the tenant. See Create a New Rule.

Info only

General Availability

New

Technology

Not applicable

 

2022-02-17

Cloud Identity Services

  • Neo
  • Cloud Foundry

Assertion Attributes

Identity Authentication added locale as assertion attribute. See Configuring User Attributes from the Identity Directory.

Info only

General Availability

New

Technology

Not applicable

 

2022-02-17

Cloud Identity Services

  • Neo
  • Cloud Foundry

User Profile

The profile page has a new design.

Info only

General Availability

New

Technology

Not applicable

 

2022-02-17

Cloud Identity Services

  • Neo
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

 

2022-02-02

Cloud Identity Services

  • Neo
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

 

2022-01-26

Cloud Identity Services

  • Neo
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

 

2022-01-19

Cloud Identity Services

  • Neo
  • Cloud Foundry

Multi-Factor Authentication

Tenant administrator can deactivate the second factor (passcode or security key) if the user has activated it via the profile page. See Deactivate Two-Factor Authentication.

Info only

General Availability

New

Technology

Not applicable

 

2022-01-19

Cloud Identity Services

  • Neo
  • Cloud Foundry

End-User Screens

Tenant administrator can enable CAPTCHA protection for the login page of the application. See Enable Google reCAPTCHA for Application Forms and Enable MTCaptcha for Application Forms.

Info only

General Availability

New

Technology

Not applicable

 

2022-01-19

Cloud Identity Services

  • Neo
  • Cloud Foundry

Privacy Policy Documents

Tenant administrator can delete privacy policy documents. See (Optional) Delete a Privacy Policy Document.

Info only

General Availability

New

Technology

Not applicable

 

2022-01-19

Cloud Identity Services

  • Neo
  • Cloud Foundry

Terms of Use Documents

Tenant administrator can delete terms of use documents. See (Optional) Delete a Terms of Use Document.

Info only

General Availability

New

Technology

Not applicable

 

2022-01-19

Cloud Identity Services

  • Neo
  • Cloud Foundry

Password Policies

Identity Authentication added new options for maximum password lifetime: 1 year, 2 years, 3 years, and unlimited. See Configuring Password Policies.

Info only

General Availability

New

Technology

Not applicable

 

2022-01-19

Cloud Identity Services

  • Neo
  • Cloud Foundry

User Export

Tenant administrator can download a CSV file containing information of all tenant users in Identity Authentication by filtering the user attributes that will be included in the downloaded file. See Export Existing Users of a Tenant of Identity Authentication.

Info only

General Availability

New

Technology

Not applicable

 

2022-01-19

Cloud Identity Services

  • Neo
  • Cloud Foundry

System Upgrade

Identity Authentication has been upgraded.

Info only

General Availability

New

Technology

Not applicable

 

2022-01-06

Cloud Identity Services

  • Neo
  • Cloud Foundry

Email Notifications

Identity Authentication can send emails with information about expiring certificates, system notifications, and new administrators to the tenant administrators. The notifications are also visible at the top-right corner of the administration console. See Send System Notifications via Emails.

Info only

General Availability

New

Technology

Not applicable

 

2022-01-06