Skip to content
Back to release notes

OKIOK announces the availability of RAC/M Identity 3.11.0

RAC/M Identity

RAC/M Identity™ is our simple and effective identity governance and administration (IGA) solution that enables large and small enterprises to understand and manage the complex relationships between users and their access to physical and digital resources, on-premise or SaaS.

Major New Feature

Detailed contextual information in all types of Review Campaigns

Review Campaign: Modal detail window for review elements such as identities, groups, roles and accounts.

Each modal window displays different information depending on the context in which it is opened. You can see information about identities, groups, roles, accounts, entitlements, compliance, hierarchical structures of groups and roles, and differences in incremental review campaigns.

A Review Identity modal on its Primary Details tab, showing the person’s title and location, employee number, associated person, supervisor, reviewer, organization, department, hire date and termination date, with an Active badge.

A Review Role modal on its Groups and Members tab: a matrix with identities as columns and the role’s groups as rows, a tick where the group is included in that member, and a warning that the maximum number of member results has been reached. An account review modal on its Entitlements tab: the identity under review at the top, an entitlement tree on the left running from the account down through asset grouping to Active Directory groups, the account’s own fields on the right with most of them empty, and a legend for the role, account, asset grouping, asset, group and item icons.

Minor Improvements

Review Campaign

Changed the review campaign types labels to make them clearer. The Campaign Type and Scope panel with its type list open, grouped under Identity Review, Role Content Review and Technical Account Review, with options such as all entitlements, roles and excess entitlements, and only segregation of duty conflicts.

Added conditional approval in review campaigns. A More Actions menu open on a review row, with Conditionally Approve outlined among the other choices: approve with comments, revoke with comments, temporarily approve, comment and reset.

Identity list

In the identity list, it is now possible to filter identities by supervisor or by reviewer. The identity list with the Supervisor and Reviewer columns outlined, each carrying its own filter box above the rows so the list can be narrowed to one supervisor or one reviewer.

Sequence execution

When executing a sequence, it is now possible to configure it to continue its execution if an error occurs in the execution of a block. The details of a sequence operation, with the Behaviour in case of errors group outlined at the foot: stop the sequence, skip the remaining operations in this block and continue with the next block, or continue with the next operation.

Other minor improvements

  • Added ModuleSystemEventAuditIntegrityCheck module to validate audit integrity
  • Added multiple indexes in the database tables related to the campaigns
  • Added an configuration in the Account Policies to determine what is done with the groups assigned to the accounts when they are completed.
  • Added a control to adapt the subject when sending a written request email. This control allows to indicate that at least one access has been removed in the request.
  • Improved labels in the role modeling session at the role mining level. Labels determining what is done with static member assignment are clearer.
  • Improvement of provsioning requests. Added an option to override the account selection strategy.
  • Changed the default settings for the SSL protocol. Changed from TLS to TLS v1.2. This does not affect the configuration file currently deployed in client environments.
  • Increase the speed of loading campaigns

Corrections

  • It is now possible to complete a campaign containing rejected accounts that have been deleted from RAC/M Identity
  • Error of review campaign extension. The email are no longer sent to reviewers who have completed their tasks related to this review campaign.
  • Added missing MS SQL stored procedure for “Azure” support
  • Fixed ModuleCreatePersonByKeyV2, the SRC_EMPTY_OVERRIDE_BY_NULL parameter was ignored.
  • Fixed ModuleDeleteNonUpdatedSinceDate module failing to execute.
  • Correction of the “…supervises…” button in the identity screen.
  • Fixed when there was an error executing an ICF connector. All subsequent tests failed.
  • Fixed the Approve button during an incremental review campaign with pre-approved items. Now it confirms the pre-approval instead of cancelling it.
  • Correction of role modeling sessions. When role mining, an error was occurring.
  • Fixed an error that occurred when duplicating a role.
  • Correction of account review campaigns. Completed accounts were included by error.
  • When a change is made to an identity associated to the person making the change in the interface, these changes will take effect immediately in the session.
  • Correction to the hierarchical group structure automatic update in the logical application integrity service.
  • Corrected inconsistencies in indicators related to active accounts matched to inactive identities.
  • Fixed the completion of a review campaign when it includes an identity or group deleted from RAC/M Identity.
  • fixed the status of reuqests in the self-service portal.
  • Corrected links in the notification emails of the review campaigns. The links now lead to the campaign details associated with this email.
  • Correction in the list of operational issues in the home page. If a sequence execution involves an ICF connector and if it causes an error, this error will be displayed in the list in addition to the sequence failure error.
  • Fixed the review campaign reminder. The email are now sent to the all the members of a delegation group.
  • The completed button no longer remains available after the approver’s completion of a role review campaign type.
  • Corrected the confirmation of a reset of the reviewed elements of a campaign
  • Corrected the display of a review campaign in the list when saved in “preview” mode. It is no longer displayed at the end of the list now.

Breaking changes

  • The ModuleDeleteNonUpdateDataInLastDay has been removed and is replaced by the ModuleDeleteNonUpdatedSinceDate module.

Known problems

  • When a role is saved, all members of the parent roles are removed from the role.
  • Sub-roles are not given when assigning a role in the identity details screen.

Send us a message

Only your email is required. Pick a subject, add a note, and send.

Incident in progress? Call the 24/7 line instead of waiting for a reply: +1 450 681-1681, extension 277