IBM Support

What's new for IBM Security Verify features in September 2021

News


Abstract

New IBM® Security Verify features that were released in September.

Content

Key updates
These new features might not be available in your location yet.
  • The user interface was reorganized to reduce the need for horizontal scrolling of tabs and to group functions more effectively. Use this table to find the functions that were moved.
    Table 1. Relocated functions
    What's moved
    From
    To
    App role management Main navigation Applications > App Role management
    Admin roles Main navigation Global configuration > Administrator roles
    Certification campaigns Governance Applications > Access certification
    Operation results Governance Applications > Provisioning results
    Account sync Governance Applications > Account synchronization
    Users & Groups Main navigation Directory > Users & groups
    Authentication factors Security Authentication > Authentication factors
    FIDO2 Security Authentication > FIDO2 settings
    Registration profiles Security Authentication > Registration profiles
    Usage dashboard Main navigation Global configuration > Subscriptions & usage
    User flows Main navigation User experience > User registration
    Profile management Main navigation User experience > Profile management
    Configuration Main navigation Global configuration
    Analytics (Verify Bridge for Analytics) Configuration Analytics > Analytics configuration
    Analytics (managing analytics) Main navigation Analytics > Analytics
    API access Configuration Security > API access
    Application profiles Configuration Applications > Application profiles
    Attributes Configuration Directory > Attributes
    Certificates Configuration Security > Certificates
    Customizations Configuration Global configuration > Appearance
    Device managers Configuration Authentication > Device managers
    Identity agents Configuration Integrations > Identity agents
    Identity sources Configuration Authentication > Identity providers
    Integrations Configuration Integrations > Extensions
    Password policies Configuration Security > Password policies
    Subscriptions Configuration Replaced by Global configuration > Subscriptions and usage
  • IBM Security Verify now supports password synchronization for provisioning on some applications, See Applications that support password synchronization and Configuring Cloud Directory.
  • Verify Bridge now enforces LDAP TLS server certificate validation when the host is specified by using an IP address. See IBM Security Verify Bridge.
  • Users are now able to recover their usernames. See Recovering your username and Configuring Cloud Directory.
  • Timestamp functions are now supported for attributes. See Attribute functions.
  • OIDC applications now support PS256, PS384, and PS512 algorithms. See Configuring single sign-on in the OpenID Connect provider, Creating the client secret JWT and private key JWT, and Creating the client secret JWT and private key JWT.
  • IBM Security Verify now supports Client_secret_jwt and private_key_jwt for OIDC applications single sign-on. See Creating the client secret JWT and private key JWT.
  • New RSA and ECDSA certificates are available on 23 September 2021 for *.ice.ibmcloud.com tenants. The current certificates expire on 15 October 2021. See Product requirements.
  • A new public SAML API was added to export metadata. The GET operation supports two federations saml20sp and saml20ip.
    /v1.0/saml/federations/saml20sp/metadata
    /v1.0/saml/federations/saml20ip/metadata
    See IBM Security Verify API Documentation.
Other features, enhancements, and announcements
 
  • With IBM Security Verify, you can now use WS-Federation and WS-Trust for Azure AD Join. You can configure it from the Microsoft 365 application with the WS-Federation Sign-on method. Configuration instructions are provided in the Microsoft 365 application template.
  • Transformation rules can now be applied on the username for the active requestor flow of Microsoft 365 WS-Federation applications.
Notifications
 
  • The TokenExchange API has an optional request parameter, redirect_url. When it is included, the request returns a redirect response to the browser to the redirect_url. For example, /authenticate/v1.0/auth/session?redirect_url=https://some_url.com. In an upcoming version, an error will be returned if the redirect_url is not in the tenant's list of allowed URLs.
    The tenant administrator can set the allowed URLs. The entries in the list are regular expressions, the administrator can match the redirect_url by using the regular expression syntax. For example,
    https://(?:optional_part.)?ibm.com/.*
    The redirect_url will be allowed by default if:
    • It points to the tenant: https://my_tenant.com/....
    • It starts with a "/", a relative URL: /ivcreds.
    A tenant administrator can use the forthcoming Session Exchange API to set the list of allowed URLs. An example of the SessionExchange payload to set the list:
    {
        "redirectUrls": [
           "https://some_url.com.*",
           ...
        ]
     }
  • On 7 October 2021, IBM Security Verify is adding a restriction on concurrent browser login sessions for a user. A typical user will not encounter this limit error. If monitor scripts are simulating a user login, you must modify them to explicitly log out by navigating to:
                                         https://{{tenant}}/idaas/mtfim/sps/idaas/logout
  • IBM Security Verify continually enhances its password security policy. You might encounter some changes in its behavior.
  • Some v1.0 APIs that are related to multi-factor authentication are now deprecated and will be removed after December 2021. Enhanced and easier-to-use replacements are already available. See Deprecated APIs.

Related Information

[{"Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSCT62","label":"IBM Security Verify"},"ARM Category":[{"code":"a8m0z0000001jljAAA","label":"Security Verify"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Version(s)"}]

Product Synonym

IBM Cloud Identity;IBM Security Verify;Verify

Document Information

Modified date:
16 September 2021

UID

ibm16487777