AIMS 25.1
Release Highlights
Avatier Identity Anywhere 25.1 Release Highlights
Configuration
- Smarter Mapping: The MapId Collection process now runs faster and provides execution summaries with detailed logs—start/end times, mapping counts, and failed connectors.
- Visual Mapping Transparency: Automatically collected mappings are now visible in the Interactive Management interface, helping admins validate and troubleshoot user-account relationships.
- Active Directory Search Base: Narrow user collection to specific Organizational Units (OUs) for faster, more precise directory syncs.
HR Feed
- Resolved an issue preventing HR Feed connections to Oracle after upgrading to the latest premium version of the Oracle License.
- Addressed an issue where accounts were not automatically provisioned into the AS400 system from HR Feed during Account Creator operations.
Reporting-Auditing
- New HR Lifecycle Reports: Track Provisioning, Termination, Rehire, Leave of Absence, and failure states—all in the Universal UI.
- Cleaner Report Lists: Users now see only downloadable reports, eliminating broken or misleading report entries.
Mobile App UUI
- Customizable Login Screens: Disable “Remember Me,” “Support,” and “What’s New” features per organizational policy.
- Persistent Navigation: The UUI side menu stays expanded after login—no more repeat clicks.
- Faster Logins: Improved authentication speed means users get signed in with less delay.
- MFA Session Storage Options: Store OpenID Connect MFA sessions in SQL instead of Redis for deployment flexibility.
Access Governance (AG3)
-
Launch Access Governance campaigns instantly—no schedules, no delays.
AIMS 25.1 introduces On-Click Campaigns, enabling admins to trigger access reviews on demand with a single action. This enhancement provides:- Greater flexibility in managing reviews outside rigid schedules
- Faster response to audit or compliance requests
- Real-time visibility into user access for dynamic environments
Whether addressing urgent security needs or streamlining governance workflows, one-click campaigns ensure your access data is always current—without waiting for the next scheduled cycle.
Credential Provider
- The Passwordless Avatier Credential Provider for Windows now supports OTP entry during passwordless authentication.
- Added support for multiple user identifiers (beyond DOMAIN\USERID) for greater flexibility and compatibility.
- Upgraded the MSI installer with passwordless authentication, using the latest software for better performance.
- Increased the challenge key length to maximum for enhanced security between the Credential Provider and AIMS server.
- Ensured backward compatibility with older key lengths for smooth deployment and testing.
Self-Service Password Management
- “View My Activity”: Let users see their recent account actions directly from the console—improving transparency and control.
- NIST Password Blocking: Prevent weak passwords with NIST Bad Passwords enforcement built into Password Policies.
- Generate Secure Passwords: Users can now auto-generate strong random passwords during reset workflows in the Universal UI.
- AD Sync Optimized: Faster syncs for deleted accounts in large AD environments with improved processing logic.
- Stricter Auto-Enrollment Validation: Prevents enrolling non-existent AD accounts for better accuracy and reporting.
- Email Login Control: Admins can now disable email-style login detection for enhanced identity policy control.
Password Bouncer
- Performance Boost: Improved efficiency in retrieving and validating password policies, delivering a smoother user experience.
- LDAP Integration: Enhanced support for multiple custom password policies, offering greater flexibility for LDAP environments.
- NIST Compliance: Added a “Bad Passwords” check based on NIST guidelines to strengthen password security.
Passwordless Login
- Universal Integration: Passwordless login is now available across all modules, ensuring a consistent and streamlined experience for users.
- Top MFA Solutions: Leverage industry-leading MFA providers for secure, passwordless access, including options like PingID, OpenID Connect, and more.
- Enhanced Security: Reduce the risk of password-related breaches by replacing traditional passwords with advanced, phishing-resistant authentication methods.
- Improved User Experience: Simplify the login process, reducing friction and saving time for end-users while maintaining robust security.
Help Desk
- New Bypass Option: Added a checkbox to allow Help Desk super users to bypass authentication, ensuring the bypass functionality works seamlessly.
More MFA Options
- Avatier now supports leading MFA providers like CyberArk, DUO, FIDO2, Google Authenticator, Microsoft Authenticator, PingID, RSA SecurID, WhatsApp Magic Link, WeChat QR Code, and more. All MFA providers are free for new Avatier Cloud Hosted customers, offering unmatched flexibility and security at no extra cost.
Lifecycle Management
- Admin Mode + Filters: A redesigned request history interface with admin-specific controls makes tracking changes easier.
- samAccountName Reuse: During testing, LCM now allows reuse of Active Directory usernames—avoiding collisions from deleted accounts.
- Streamlined Provisioning: Built-in support for re-provisioning deleted accounts simplifies test environments and cleanup workflows.