Release Notes<\/a>.<\/p>\n\n\n\n2024-12-11 ADI Release Notes<\/h2>\n\n\n\nAD Import Agent v3.10.0<\/h3>\n\n\n\n
Bug Fix<\/strong><\/p>\n\n\n\n\n- The ADI import agent no longer queries AD for the additional attributes if the SyncAdditionalAttributes<\/kbd> setting is false<\/kbd>.\n
\n- The ADI import agent was querying AD for the additional attributes even though it was not syncing those attributes to JC when the the SyncAdditionalAttributes setting is false.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n
<\/p>\n\n\n\n
2024-12-10 ADI Release Notes<\/h2>\n\n\n\nAD Import Agent v3.9.0<\/h3>\n\n\n\n
Bug Fix<\/strong><\/p>\n\n\n\n\n- The ADI import agent jspasswordfilter.dll no longer causes the DC to crash when a password with the maximum characters supported by Windows is set in AD.\u00a0<\/li>\n<\/ul>\n\n\n\n
Note<\/strong>: Maximum password length supported in 黑料海角91入口 is 64 characters. Any password longer than 64 characters will result in a password update failure.<\/p>\n\n\n\n2024-11-19 ADI Release Notes<\/h2>\n\n\n\nAD Sync Agent v4.20.0<\/h3>\n\n\n\n
Rollback of v4.19.0 changes<\/p>\n\n\n\n
Bug Fix <\/p>\n\n\n\n
\n- The AD sync agent logs no longer include the 502 unexpected content-type error \u201cerror: code = Unavailable desc = unexpected HTTP status code received from server: 502 (Bad Gateway); transport: received unexpected content-type\u201d<\/kbd><\/li>\n<\/ul>\n\n\n\n
2024-11-11 ADI Release Notes<\/h2>\n\n\n\nRe-release of AD Sync Agent v4.17.0 <\/h3>\n\n\n\n
Bug Fixes<\/p>\n\n\n\n
\n- In the Manage users and passwords in 黑料海角91入口, AD or both<\/strong> (bi-directional sync) and Manage users and passwords in 黑料海角91入口<\/strong> (one-way sync from 黑料海角91入口 to AD) deployment configurations, users that are in a nested OU can now be added to security groups in AD from 黑料海角91入口. These users can only be removed from an ADI specific security group named \u201c黑料海角91入口\u201d and security groups nested underneath that security group.<\/li>\n<\/ul>\n\n\n\n
2024-11-07 ADI Release Notes<\/h2>\n\n\n\nRollback of ADI Sync Agent v4.19.0<\/h3>\n\n\n\n
The Active Directory Integration (ADI) sync agent v4.19.0 was rolled back and v4.15.0 was re-released. The roll back is due to users being removed from all groups in AD that are not associated (bound) to the ADI integration in 黑料海角91入口. This behavior can cause these users to lose access to some AD managed resources. <\/p>\n\n\n\n
We rolled back to 4.15.0 to remove all group syncing related changes. We did this out of an abundance of caution. <\/p>\n\n\n\n
If you are using v4.17.0 and are not experiencing issues, you do not need to roll back. We will re-verify v4.17.0 and release it again, as long as the behavior that resulted in this rollback does not exist.<\/p>\n\n\n\n
To downgrade from v4.19.0 to 4.15.0 do the following:<\/p>\n\n\n\n
\n- Log in to the 黑料海角91入口 admin portal and navigate to the ADI configuration for your AD domain.<\/li>\n\n\n\n
- From the Download section, select Install New Agent<\/strong> in the sync agent row and click Download Sync Agent<\/strong>.<\/li>\n\n\n\n
- Either leave the window with the connect key open or copy and store the connect key.<\/li>\n\n\n\n
- Log in to the AD server where the sync agent is installed<\/li>\n\n\n\n
- Upload the sync agent you downloaded<\/li>\n\n\n\n
- Stop the AD sync service, \u201c黑料海角91入口 AD Integration Sync Agent\u201d<\/li>\n\n\n\n
- Uninstall the AD sync agent<\/li>\n\n\n\n
- Run the 4.15.0 sync agent installer<\/li>\n\n\n\n
- Paste in the connect key <\/li>\n\n\n\n
- Repeat this on all servers where the 4.19.0 sync agent is installed <\/li>\n<\/ul>\n\n\n\n
<\/p>\n\n\n\n
2024-10-29 ADI Release Notes<\/h2>\n\n\n\nAD Import Agent v3.7.0<\/h3>\n\n\n\n
New configuration setting, SyncAdditionalAttributes<\/strong>, enables the syncing of additional user attributes from AD to 黑料海角91入口:<\/p>\n\n\n\n<\/p>\n\n\n\n
The new setting, SyncAdditionalAttributes<\/strong>, has been added to the jcadimportagent.config file which controls whether or not additional user attributes sync from AD to 黑料海角91入口. <\/p>\n\n\n\n\n- The additional attributes<\/strong> that can now optionally sync<\/strong> from AD to 黑料海角91入口<\/strong> are: \n
\n- Display Name<\/li>\n\n\n\n
- Description<\/li>\n\n\n\n
- JobTitle<\/li>\n\n\n\n
- Department<\/li>\n\n\n\n
- Company<\/li>\n\n\n\n
- Location<\/li>\n\n\n\n
- EmployeeType<\/li>\n\n\n\n
- PhoneNumbers<\/li>\n\n\n\n
- Addresses<\/li>\n\n\n\n
- Manager<\/li>\n<\/ul>\n<\/li>\n\n\n\n
- This setting is automatically added to the jcadimportagent.config file for both net new ADI import agent installations and upgrades of existing ADI import agents<\/li>\n\n\n\n
- For net new ADI import agent installations<\/strong>, the default<\/strong> value for this setting is true<\/strong>, meaning the additional attributes will sync<\/li>\n<\/ul>\n\n\n\n
<\/p><\/div>
Important:<\/strong> \nIf you are adding a new AD server to an existing AD environment with 黑料海角91入口 ADI installed, you will need to make sure this setting matches across your existing servers and this new server.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n
\n- For existing ADI import agent installations<\/strong>, the default<\/strong> value for this setting is false<\/strong>, meaning the additional attributes will not sync\n
\n- This default value ensures there is no unexpected change in behavior for existing installations<\/li>\n<\/ul>\n<\/li>\n\n\n\n
- If the setting is not present in the jcadimportagent.config file, the value will be considered false<\/strong><\/li>\n\n\n\n
- If you have existing ADI import agent installations and want to sync these additional attributes, you will need to edit the jcadimportagent.config file and manually set the value to true<\/li>\n\n\n\n
- When SyncAdditionalAttributes<\/strong> is set to true<\/strong>, any values that exist in 黑料海角91入口 for these additional attributes will be overwritten<\/li>\n<\/ul>\n\n\n\n
<\/p><\/div>
Tip:<\/strong> \nTo avoid any access disruption when SyncAdditionalAttributes<\/strong> is set to true<\/strong>, update your dynamic group rules to include values that will come from AD.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n2024-10-03 ADI Release Notes<\/h2>\n\n\n\nAD Sync Agent v4.19.0<\/h3>\n\n\n\n
Bug Fix<\/p>\n\n\n\n
\n- In the Manage users and passwords in 黑料海角91入口, AD or both<\/strong> (bi-directional sync) and Manage users and passwords in 黑料海角91入口<\/strong> (one-way sync from 黑料海角91入口 to AD) deployment configurations, users can now be removed from any security group except the main ADI group (e.g., \u201c黑料海角91入口\u201d or \u201c黑料海角91入口 (mydomain1)\u201d)<\/li>\n<\/ul>\n\n\n\n
<\/p>\n\n\n\n
2024-09-20 ADI Release Notes<\/h2>\n\n\n\nAdmin Portal<\/strong><\/h3>\n\n\n\nUsers page<\/p>\n\n\n\n
\n- Password status is \u201cDelegated\u201d with sub-text \u201cManaged by AD\u201d when the user\u2019s delegated authority is set to Active Directory<\/li>\n<\/ul>\n\n\n\n
<\/figure>\n\n\n\n2024-09-04 ADI Release Notes<\/h2>\n\n\n\nAdmin Portal<\/h3>\n\n\n\n
Bug Fixes<\/p>\n\n\n\n
\n- Delete confirmation is shown after clicking the delete button for an ADI domain configuration:
<\/li>\n\n\n\n - Delete button on the ADI domain configuration screen was updated to have a red outline<\/li>\n\n\n\n
- Users page More Actions menu option for setting the delegated authority on a user record was renamed to Set Delegated Authority<\/li>\n<\/ul>\n\n\n\n
ADI Service<\/h3>\n\n\n\n\n- User login no longer fails once the user is disassociated (unbound) all but one delegation-enabled ADI domain<\/li>\n<\/ul>\n\n\n\n
AD Sync Agent v4.17.0<\/h3>\n\n\n\n
Bug Fixes<\/p>\n\n\n\n
\n- In the Manage users and passwords in 黑料海角91入口, AD or both<\/strong> (bi-directional sync) and Manage users and passwords in 黑料海角91入口<\/strong> (one-way sync from 黑料海角91入口 to AD) deployment configurations, users that are in a nested OU can now be added to security groups in AD from 黑料海角91入口. These users can only be removed from an ADI specific security group named \u201c黑料海角91入口\u201d and security groups nested underneath that security group<\/li>\n<\/ul>\n\n\n\n
2024-08-19 ADI Release Notes<\/h2>\n\n\n\nAdmin Portal<\/h3>\n\n\n\n\n- New UI and experience for adding, managing, and using the ADI:\n
\n- Provides guidance through the installation process, better visibility into the configuration settings, and greater prominence of the information needed to monitor and manage the integration<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n
\n
<\/figure><\/div>\n\n\n
<\/figure><\/div>\n\n\n
<\/figure><\/div>\n\n\n
<\/figure><\/div>\n\n\n
<\/figure><\/div>\n\n\n\n- New ADI configuration settings:\n
\n- Delegated Password Validation<\/strong> – default setting for enabling and disabling delegated authentication to AD for users imported from AD to 黑料海角91入口 (applicable in the Manage users and passwords in either system or both<\/strong> and Manage users and passwords in Active Directory <\/strong>deployment <\/strong>configurations)<\/li>\n\n\n\n
- Externally Managed Password and Attributes<\/strong> – default setting for restricting and unrestricting changes to ADI synced user attributes and user password within the 黑料海角91入口 Admin Portal and the 黑料海角91入口 User Portal. This is a read-only setting<\/li>\n\n\n\n
- Enable groups and memberships management<\/strong> – default setting controlling whether a groups and group memberships are synced from 黑料海角91入口 to AD when a sync agent is installed on an AD server (applicable in the Manage users and passwords in either system or both<\/strong> and Manage users and passwords in 黑料海角91入口 <\/strong>deployment <\/strong>configurations). This is a read-only setting<\/li>\n\n\n\n
- Provision Staged Users<\/strong> – default setting controlling whether a staged user is synced from 黑料海角91入口 to AD when a sync agent is installed on an AD server (applicable in the Manage users and passwords in either system or both<\/strong> and Manage users and passwords in 黑料海角91入口<\/strong> deployment configurations). This is a read-only setting<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n
\n
<\/figure><\/div>\n\n\n\n- Option to automatically update the delegated authority setting for user(s).\n
\n- This option is presented when the following actions are taken and includes a list of important factors to consider when making your selection:\n
\n- on save after delegated authentication is enabled or disabled in the ADI configuration<\/li>\n\n\n\n
- when an ADI AD domain is deleted<\/li>\n\n\n\n
- when a user has direct access granted to or removed from a delegation-enabled AD domain<\/li>\n\n\n\n
- when a user has access granted to or removed from a user group that has access to a delegation-enabled AD domain<\/li>\n\n\n\n
- when a user group has access granted to or removed from a delegation-enabled AD domain<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n
\n
Option When Connecting (Binding) or Disconnecting (Unbinding) Users or User Groups<\/strong><\/figcaption><\/figure><\/div>\n\n\n
Option When Enabling Delegation on ADI Config<\/strong><\/figcaption><\/figure><\/div>\n\n\n
Option When Enabling Delegation on ADI Config<\/strong><\/figcaption><\/figure><\/div>\n\n\n\n- Agent download options in the ADI Configuration:\n
\n- Update Existing Agent<\/strong> downloads the agent installer without generating a new agent connect key <\/li>\n\n\n\n
- Install New Agent<\/strong> downloads the agent installer and provides a new connect key which must be used within 7 days<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n
\n
<\/figure><\/div>\n\n\n\n- Ability to set a delegated authentication Delegated Authority<\/strong> for an individual user.\n
\n- New Delegated Authentication<\/strong> section with a Delegated Authority<\/strong> setting in the User Security Settings and Permissions section on the Details tab of the User page<\/li>\n\n\n\n
- Confirmation modal explaining the implication of the change shows when the Delegated Authority is changed.<\/li>\n\n\n\n
- Delegated Authentication shows under Security status in the left pane of the User panel when the Delegated Authority setting is Active Directory<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n
\n
<\/figure><\/div>\n\n\n
<\/figure><\/div>\n\n\n
<\/figure><\/div>\n\n\n
<\/figure><\/div>\n\n\n\n- Ability to set a delegated authentication Delegated Authority<\/strong> for multiple users at once:\n
\n- New Set Delegated Password Authority<\/strong> option in the More Actions menu on the Users Page<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n
\n
<\/figure><\/div>\n\n\n
<\/figure><\/div>\n\n\n\n- Visibility into which users have delegated authentication enabled from the Users page:\n
\n- Password status shows \u201cDelegated\u201d for users that have a Delegated Authority<\/strong> set to Active Directory<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n
\n- New Delegation ENABLED<\/strong> label added when delegation is enabled and active for an ADI AD Domain:\n
\n- Directories List – Label added to the AD domain name in Directories lists<\/li>\n\n\n\n
- User groups – Resources list in the User group drop down in Users page<\/li>\n\n\n\n
- Staged user – resources section showing AD delegation enabled label<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n
\n
Directories List<\/strong><\/figcaption><\/figure><\/div>\n\n\n
Expanded User Group in User Groups Tab of a User Record <\/strong><\/figcaption><\/figure><\/div>\n\n\n
Staged User Resource Summary<\/strong><\/figcaption><\/figure><\/div>\n\n\n\n- New and updated DI events<\/li>\n<\/ul>\n\n\n\n
\n
\n\n \n \n Event <\/th>\n | \n Description <\/th>\n | \n Change <\/th>\n <\/tr>\n |
\n \n user_login_attempt <\/td>\n | \n Logs every time a user tries to log in to a 黑料海角91入口 managed resources <\/td>\n | \n JSON includes a new field \u201cpassword_delegated_authority\u201d in the auth_context when the user\u2019s login is delegated to AD for authentication <\/td>\n <\/tr>\n |
\n \n \"auth_context\": {<\/span><\/p>\n \"auth_methods\": {<\/span><\/p>\n \"password\": {<\/span><\/p>\n \"success\": true<\/span><\/p>\n }<\/span><\/p>\n },<\/span><\/p>\n \"password_delegated_authority\": \"ActiveDirectory\"<\/span><\/p>\n <\/p>\n },<\/span><\/p><\/div> <\/td>\n <\/tr>\n \n \n association_change <\/td>\n | \n Logs every time two resources are associated (bound) or disassociated (unbound). <\/td>\n | \n Logged when a user is associated (bound) to or disassociated (unbound) from a delegation-enabled AD domain. <\/td>\n <\/tr>\n | \n \n Logged when a user group is associated (bound) to or disassociated (unbound) from a delegation-enabled AD domain. <\/td>\n <\/tr>\n | \n \n user_delegated_authority_update <\/td>\n | \n Logs when a change is made to the Delegated Authority setting on the User record. <\/td>\n | \n New DI event <\/td>\n <\/tr>\n | \n \n activedirectory_domain_delegated_password_change <\/td>\n | \n Logs when the delegated authentication setting Delegated Password Validation in the ADI configuration is changed <\/td>\n | \n New DI event <\/td>\n <\/tr>\n <\/table>\n<\/div>\n\n\n\n | |