> For the complete documentation index, see [llms.txt](https://docs.1kosmos.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.1kosmos.com/authentication/admin-portal/release-notes-for-adminx.md).

# Release Notes for AdminX

***

### 2.1.14-r.2

*August 8, 2026*

#### Authentication Features

**Application-Based Routing Policy for External IDP**

Community administrators can now configure routing policies by application type. A new **Application** condition has been added to the external IDP routing policy, alongside the existing Username, Groups, and All Users from External IDP conditions.

This allows administrators to route users to a specific identity provider based on the application they are accessing. For example, users who land on the AdminX login page can be routed directly to Entra ID for authentication, then redirected back to complete enrollment in AdminX. For more information, see [Define Routing Policies](https://1kosmos-3.gitbook.io/productdocs/integrations/authentication/external-identity-provider-sso-federation/microsoft-azure-as-an-external-identity-provider#step-5-define-routing-policies).

**LDAP Group Membership Support for Non-Active Directory Directories**

Group membership now resolves for users connected through standard LDAP directories (e.g., IBM Directory Server, OpenLDAP), not just Active Directory. Organizations using non-AD directories can now apply group-based policies and access controls by mapping their directory's group attribute in the LDAP directory configuration. For more information, see [Mapping Attributes](https://1kosmos-3.gitbook.io/productdocs/authentication/authentication-broker/connect-to-ldap-via-broker#step-3-map-attributes).

**Group-Based User Filtering for Microsoft Entra Directory Integration**

Community administrators can now filter Microsoft Entra directory users by security group using the new **Graph Query Filter** field in AdminX under Directory Integrations. Previously, the platform fetched all users from the Entra tenant with no option to scope by group membership.

By configuring a group filter, administrators can restrict user sync and display to members of a specific Entra security group. If the filter is removed, the directory reverts to fetching all users. For more information, see Graph Query Filter in [Configuring Microsoft Entra ID in AdminX](https://1kosmos-3.gitbook.io/productdocs/authentication/admin-portal/directory-integrations/connect-to-microsoft-entra-id#configuring-microsoft-entra-id-in-adminx).

**In-Flight Enrollment for Typing Pattern and PIN**

In EAM flows where users are pre-authenticated by an external identity provider and redirected to 1Kosmos for a second factor, users who had not previously enrolled in Behavior Auth or PIN were denied access with no option to enroll.

The platform now supports in-flight enrollment. When a user arrives for second-factor authentication without the required factors enrolled, they are guided through typing pattern enrollment and PIN setup as part of the login flow itself. Once enrollment completes, authentication is satisfied without requiring a separate enrollment step. For more information, see [In-Flight Enrollment for EAM (Behavior Auth + PIN)](https://1kosmos-3.gitbook.io/productdocs/authentication/passwordless-for-web-apps/use-cases/in-flight-enrollment-for-eam-behavior-auth-+-pin).

The flow adapts based on the user's existing enrollment status:

* Neither Behavior Auth nor PIN enrolled: user is guided through both.
* Behavior Auth enrolled but not PIN: user is prompted for PIN only.
* PIN enrolled but not Behavior Auth: user is prompted for typing pattern only.
* Both enrolled: user proceeds with standard verification.

> This feature is available in EAM pre-authenticated flows only. Contact your administrator or CS team to enable this for your community.

**Custom Redirect URL Support for SP-Initiated Single Logout**

Community administrators can now configure a custom redirect URL for SP-initiated Single Logout (SLO). Previously, users were always redirected to the 1Kosmos logout page after the IDP session was terminated.

When configured, users are redirected to the specified URL (such as the application's own logout page) after logout completes. If no URL is configured, users continue to land on the 1Kosmos logout page. For more information, see *the Redirect users to a custom URL after single logout (RelayState)* section in [SAML Application Integrations](https://1kosmos-3.gitbook.io/productdocs/integrations/authentication/custom-integrations/saml-application-integrations).

**US State ID Support as Primary Document in Identity Wallet**

US State IDs are now recognized as primary identity documents in the Identity Wallet. Previously, only Driver's License, Passport, Green Card, and Global Entry Card were accepted as primary documents. Users with only a US State ID could not enroll secondary documents such as SSN, blocking their path to IAL2.

With this update, users with a State ID can enroll SSN and achieve IAL2 verification. For more information,see [Managing My Profile](/authentication/admin-portal/dashboard/managing-my-profile.md#primary-documents-and-ial2-eligibility).

**LiveID Selfie Login Event Visibility in AdminX Reports**

LiveID Selfie login failure scenarios, including PIN mismatch and virtual camera detection (suspicious activity), are now captured and visible in AdminX Reports. Previously, these failures did not generate login failure events, leaving administrators with no visibility.

**Miscellaneous**&#x20;

* Upgraded Node.js from v22 to v22.23.1 across all microservices.&#x20;

#### Bug Fixes

* Fixed an issue where the first name and last name were incorrectly swapped during extraction for Philippines driver's licenses, causing Active Directory name validation checks to fail. &#x20;
* Fixed an issue where the Workflow API dataCheck step incorrectly failed for documents that returned a fullName field instead of separate firstName and lastName fields after the IDProofing API update.&#x20;
* Fixed an issue where identity verification failed for US ID Cards due to an incorrect document number field mapping.
* &#x20;Fixed an issue where verification failed for Philippine driving license holders when the document returned only a combined name field instead of separate first and last name fields, causing name matching to fail and blocking legitimate users from completing verification.&#x20;
* Fixed an issue where the Session Result API returned an unexpected PENDING status immediately before expiry when continuously polling a document share session that had not been started. &#x20;
* Fixed an issue where password reset with password history enforcement enabled produced inconsistent results due to an intermediate bind operation failing with LDAP Result Code 49 ("Invalid Credentials"). \
  **Note:** LDAP Result Code 50 ("Insufficient Access Rights") in broker logs relates to AD service account permissions on privileged accounts — no investigation required.

### 2.1.9-r.1

*July 11, 2026*

#### Authentication Features

#### New Features

**Restricting Multi-Device Enrollment for Application Access**

Administrators can now configure device restriction policies to control how many authentication devices per device type a user can enroll, applied by group or individual username.

Enrollment limits are enforced automatically. Users who reach their limit can continue using existing devices, but cannot register new ones until an existing device is removed. Different limits can be set for different user groups, supporting privileged access needs without relaxing controls for everyone.

**Enhanced IdP-Initiated SSO with Direct Application Access**

Building on IdP-initiated SAML SSO support introduced in the previous release, 1Kosmos now provides a static Access URL for applications configured with IdP-initiated SSO. Administrators can view and copy this auto-generated URL from the application configuration and share it with users or embed it in portals, bookmarks, and launch pages, eliminating the need to navigate to My Apps each time.

When a user opens the URL, they are prompted to authenticate if not already signed in and are then redirected directly to the application.

**Configurable Header and Footer for Login Page Branding**

Community administrators can now configure a branded header and footer for their community login page directly within **Settings > Branding**.&#x20;

The header establishes a consistent visual identity at the top of the login experience. The footer supports multiple sections with a flexible column layout and a rich text editor for adding content such as contact information, office addresses, and legal notices.

Both the header and footer are disabled by default, ensuring no impact to existing communities until an administrator actively enables and configures them.

**Android Tablet Login Experience Update**

Users accessing the application from Android tablets will now see the QR Code login option as the default sign-in experience when QR Code authentication is configured as the default login method for their community.

This aligns the Android tablet login experience with the existing desktop and iPad experience, providing a consistent authentication flow across devices.

**Affidavit-Based IAL2 Elevation for LiveID Wallets**

Administrators can now issue affidavits to users with LiveID wallets, enabling those users to reach IAL2 without physically scanning a supported ID document. This is useful when a user presents a state-issued ID that cannot be automatically verified. A trusted administrator can physically verify the document and issue an affidavit on the user's behalf, which counts toward IAL2 calculation.

Users with LiveID wallets can view affidavits added to their profile, including document type, document ID, issue date, and expiry.

**Customizing the Download the App Section on the Login Screen**

Community administrators can now hide the **Download the App** links on the login screen of the AdminX interface using the new **Download the App** section under **Settings > Branding**. When hidden, the entire section, including default iOS and Android app download links and any configured custom hyperlink, is no longer displayed to users.

Existing communities are unaffected by default. The section continues to appear unless explicitly hidden.

**Auth Proxy — Log Rotation Support**

AuthProxy now supports automatic log rotation to prevent uncontrolled log growth and disk exhaustion in high-volume authentication environments. Administrators can configure log rotation settings directly from AdminX under **Authentication > Passwordless Login > \[AuthProxy Community] > Log Settings**, without modifying configuration files.

#### Enhancements

**Enhanced AuthProxy Configuration for RADIUS Push Authentication**

Administrators can now configure the primary and fallback authentication factor for each AuthProxy community directly from AdminX. This controls which method the mobile app uses to authenticate the user during a RADIUS push flow, such as Live ID, Face ID, Touch ID, or PIN. A fallback method can also be set in case the primary is unavailable.

**Enhanced Admin Activity Report Audit Logging**

Report request and generation events are now included in the Admin Activity Report, giving administrators complete visibility into report activity within their community.

#### Bug Fixes

* Fixed an issue where the device\_fingerprint field appears empty when accessing the login events (E\_LOGIN\_VISITED, E\_LOGIN\_SUCCEEDED, and E\_LOGIN\_FAILED) on Internet Explorer.&#x20;
* Fixed an issue where password resets with Enforce Password History Check enabled produced inconsistent results in Active Directory environments, causing some password reset attempts to fail unexpectedly.&#x20;
* Fixed an issue where Admin Activity Report download events were recorded in Event Logs but were not included in the Admin Activity Report, resulting in incomplete audit tracking of report download activities.&#x20;
* Fixed an issue where some users were unable to authenticate due to an error encountered during directory group membership validation.&#x20;
* Fixed an issue where verification key retrieval from the OIDC JWKS endpoint failed because the published RSA n and e values did not match the public key in the x5c certificate. &#x20;
* Fixed an issue where External Authentication Method (EAM) authentication failed for Azure Government Entra ID tenants due to incorrect validation of the id\_token\_hint issuer.&#x20;
* Fixed an issue where users intermittently experience login failures immediately after a successful password reset when password history enforcement was enabled.&#x20;
* Fixed an issue where the ID token generated for Behavioral Authentication failed to include the required amr claim during Microsoft Entra External Authentication Method (EAM) authentication, causing the authentication request to fail. &#x20;
* Fixed an issue where Behavioral Authentication enrollment events were missing from analytics reports despite being successfully recorded. &#x20;
* Fixed an issue where expired Active Directory accounts marked as disabled by the User Transformation Script could still authenticate using QR code or the 1Kosmos app. &#x20;
* Fixed an issue where adding a username alias to a user account in AdminX failed with an operation error. &#x20;
* Fixed an issue where the Completed By filter in **AdminX → Verifications** and the Verification Sessions download report excluded matching sessions when the displayed name was populated from the verified identity document. The filter now returns complete and accurate search results with correct pagination counts and report data.&#x20;
* Fixed an issue where the Okta SSO prebuilt integration logged administrators out when an invalid domain or API token was provided.&#x20;
* Fixed an issue where unsanitized input in the ID Proofing session creation flow could allow an authenticated administrator to inject malicious script code into name fields, which would execute in other users' browsers.&#x20;
* Fixed an issue where Live ID login in AdminX could intermittently become unresponsive after a successful face scan, causing a prolonged wait before displaying an incorrect retry message indicating that no face was detected.&#x20;
* Fixed an issue where the Completed By filter in the Verifications tab returned no results when searching by last name, full name, or partial name — only exact first name matches were previously working.

### 2.1.0-r.3

*June 13, 2026*

#### Authentication Features

**Authenticate into Microsoft Entra via 1Kosmos Browser Extension**

1Kosmos now extends Passkey + LiveID authentication for Microsoft Entra to desktop browsers. Previously available only through the 1Kosmos mobile app on Intune-managed iOS devices, this capability is now delivered through a browser extension on Google Chrome and Microsoft Edge.

On first use, users complete a one-time activation flow through AdminX. Subsequent logins automatically redirect users to the authentication workflow, where identity is verified via LiveID biometric before accessing Entra. The extension is available through the Chrome Web Store. For more information, see [Browser Authentication via Chrome Extension](/authentication/passwordless-for-web-apps/use-cases/entra-passkey-for-frontline-workers/browser-authentication-via-chrome-extension.md)

**Restricting Multi-Device Enrollment for Application Access**&#x20;

1Kosmos now introduces device restriction policies enabling administrators to precisely control over how many authentication devices per device type users can enroll, applied by group or individual username. Enrollment limits are enforced automatically — users who reach their limit can continue using existing devices but cannot register new ones until an existing device is removed. For more information, see [Configure Device Restriction Policy](/authentication/admin-portal/authentication/configure-device-restriction-policy.md).\
&#x20;\
**Benefits**&#x20;

* Set different enrollment limits for different user groups. &#x20;
* Support privileged access needs without relaxing controls for everyone. &#x20;
* Reduce unauthorized device sprawl from a single, centralized interface. &#x20;

**Enhanced IdP-Initiated SSO with Direct Application Access**&#x20;

Building on IdP-initiated SAML SSO support introduced in the previous release, 1Kosmos now provides a static Access URL for applications configured with IdP-initiated SSO. Administrators can view and copy this auto-generated URL from the application configuration and share it with users or embed it in portals, bookmarks, and launch pages — eliminating the need to navigate to **My Apps** each time. \
When a user opens the URL, they are prompted to authenticate if not already signed in and are then redirected directly to the application. If a Relay State is configured, users land at the configured destination after login. If IdP-initiated SSO is disabled or the application is removed, users are redirected to their AdminX profile page.

**Filter Admin Activity Reports by Event**

Community administrators can now filter and download the Admin Activity Report by event name, making it faster to locate and investigate specific activity across the platform.

**Exclude Specific Users from Adaptive Authentication Rules**

Adaptive Authentication now supports an **is not one of** operator for the Username condition. Administrators can define authentication rules by excluding a specific set of users rather than listing every individual the rule should cover — simplifying policy management at scale. For more information, see [Configure Adaptive Authentication Journey](/authentication/admin-portal/authentication/configure-adaptive-authentication.md).

**Configure LiveID as an Authentication Factor in Windows MFA**

The Adaptive Authentication journey for Windows MFA now supports LiveID-based authentication methods. Administrators can configure **LiveID Selfie** and **LiveID Selfie with Push Notification** as authentication factors under MFA Required, enabling stronger biometric-based verification in Windows authentication flows. For more information, see [LiveID Selfie](/authentication/windows-workstation-mfa/authentication-methods/liveid-selfie.md).

**Detect and Investigate SAML Certificate Failures Faster**

1Kosmos now generates an `E_ACCESS_DENIED` audit event when SAML authentication fails due to an expired or invalid certificate. Previously, these failures occurred silently with no audit trail. Audit logging now covers expired IdP signing certificates, SP request signing certificates, and SP encryption certificates, with a `deny_reason` field providing details on the specific failure.

**Track Device Fingerprint Across Login Events**

The `device_fingerprint` parameter is now included in `E_LOGIN_VISITED`, `E_LOGIN_SUCCEEDED`, and `E_LOGIN_FAILED` events, providing richer device-level context for login activity monitoring and investigation.

**Prevent Log Disk Exhaustion with Auth Proxy Log Rotation**

AuthProxy now supports automatic log rotation, preventing uncontrolled log growth and disk exhaustion in high-volume authentication environments.

**Update 1Kosmos Branding Across Default Templates**

Default SMS and email templates have been updated to replace legacy BlockID references with current 1Kosmos branding. Updates include verification code messages, enrollment invitation emails, mobile app references, and email signatures. Customized templates are not affected. Newly provisioned communities will also inherit the latest default templates with refreshed logos and updated content.

### 1.12.08.03

*April 11, 2026*

#### Authentication Features

**Biometric Consent Enforcement for LiveID Authentication**

Introduced a consent framework for biometric authentication (LiveID and fingerprint) to support compliance and user control. Users are prompted for consent during enrollment and login if it was not previously captured, or when consent content is updated.

Admins can enable enforcement and manage consent documents from the Consent Management page in AdminX. For more information, see [Consent Management.](/authentication/admin-portal/settings/consent-management.md)

**Key Capabilities**

* Enable/disable consent enforcement
* Create, preview, and update consent documents
* View active consent details
* Event tracking

**Enhanced Security with Per-User Rate Limiting for OTP and Push Notifications**

Per-user rate limiting has been introduced for OTP and push notification requests to prevent misuse and improve security.

Administrators can now configure limits at the user level, helping to:

* Prevent OTP and push notification flooding
* Reduce the risk of fraudulent login attempts
* Improve overall user experience

New configuration options are available in the AdminX UI for both OTP and push notifications.

**Custom Login Page Hyperlink Configuration in AdminX**

Admins can configure a custom hyperlink on the AdminX login page via Branding settings, replacing the default mobile app download links.

Supports custom display text and an optional URL (http\:// or https\://). Falls back to default behavior if invalid or disabled. For more information, see [Branding](/authentication/admin-portal/settings/branding-customization.md).

**Auth Proxy Support for Capturing Client IP in VPN Authentication Events**

VPN authentication events (E\_LOGIN\_SUCCEEDED, E\_LOGIN\_FAILED) now include the end-user client IP instead of only the Auth Proxy server IP.

Community administrators can now use the AdminX interface to configure the RADIUS attribute (e.g., Calling-Station-Id) to capture the client IP.&#x20;

{% hint style="info" %}
&#x20;Supported version: goauthproxy\_1.00.08&#x20;
{% endhint %}

**Multi-App Push Notification Support**

Push authentication now supports multiple mobile apps per community. Users can approve requests from any enabled app, enabling seamless app migration and improved flexibility.

**Passkey Manager Branding Enhancements**

Passkey Manager now displays application branding for improved usability and trust.

**Improvements**

* Shows organization logo
* Displays usernames instead of IDs
* Displays application name instead of server/tenant URL

#### Identity Verification (IDV) Features

**Secrets Management Support for Workflow Nodes**

Introduced secure secrets management for Workflow Nodes. Secrets are created in the **Secrets Store** in the AdminX interface and referenced in workflows (`{{secrets.$tag}}`). Values are injected at runtime and never exposed in the UI, logs, or execution results. For more information, see [Managing Secrets](/authentication/admin-portal/settings/managing-secrets.md).

{% hint style="info" %}
Secrets can only be added or deleted (not viewed or edited).
{% endhint %}

**Workflow Builder JavaScript Enhancements**

Enhanced Workflow Builder with JavaScript flexibility and control.

* Support for orphan JS nodes with optional handlers (Success/Fail/Error)
* Ability to add JavaScript elements in User Interaction and Outcome nodes

**IAL2 Verification Support for Global Entry and Green Card**

Web Identity Wallet now supports:

* Green Card (May 2010 or later)
* Global Entry Card

These can be used to meet IAL2 requirements. SSN enrollment is enabled once a qualifying document is present.

**Improved Verification Success Rate by Extending Name Matching to Last Names**

The Ignore middle names capability has been enhanced to support last name matching, in addition to its existing support for first name comparison.

When enabled, the system ignores middle names and compares:

* The first word of the first name
* The last word of the last name

Additionally, this setting is now available as a global configuration under the **Data Comparison** section in the AdminX UI, enabling consistent application across all relevant fields.

**Enhanced ID Verification Reports with Additional Fields**

* Reports now include:
  * Region
  * Country
  * Document Types
  * Completed By
* The "Name" column is renamed to "Created For".

**Verification Page Enhancements**

The following table highlights the enhancements made to the Verifications page.

| # | Enhancement                                   | Description                                                                                                                                                                                                                                                                               |
| - | --------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| 1 | Enhanced Journey Name filter with Search      | Enables search-based selection of journeys by typing partial names, displaying matching results dynamically, and reducing reliance on long dropdown lists.\<br>\<br>Additionally, supports an optional query parameter "pattern" (v1 & v2 APIs) for case-insensitive substring filtering. |
| 2 | Enhanced Completed By filter search           | Supports full name search, including names with multiple spaces, ensuring accurate retrieval of transactions.                                                                                                                                                                             |
| 3 | Failure Reason Tooltip on Verification Status | Displays the failure reason on hover for sessions marked as Verification Failed or Verification Not Performed, allowing quick access to details without opening the session.                                                                                                              |

**Workflow Instance Invocation via URL Parameters**

Workflows can now accept input via URL parameters when invoked with an access code. Parameters are automatically processed by the UI.

**Case-Insensitive Filtering on Workflow Instances Page**

Workflow Instance filters now support case-insensitive search, improving result accuracy.

**API Enhancements**

**Backward Compatibility Support for Older Mobile SDKs**

The /assertion/options API now supports an optional dguid fallback when username lookup fails, ensuring compatibility with older SDKs.

**New API for Updating Proofing Templates**

Added an API to update proofing templates using verification flows.

**OAuth 2.0 Client Credentials Support for APIs**

APIs now support OAuth 2.0 client credentials for secure, scoped access.

Supported operations:

* Create workflow instances
* Poll workflow results
* Fetch user and device details

#### Bug Fixes

* Fixed missing error message when saving Reset Password settings fails.
* Fixed duplicate loading of branding images.
* Fixed email template image duplication and layout issues.
* Fixed admin-api security vulnerabilities (including RCE).
* Fixed RD Gateway authentication failure after PUSH approval.
* Fixed transformation script execution across services.
* Fixed an issue where the E\_CA\_STATUSCHANGE event was not triggered when **caStatusChangeNotificationsEnabled** was set to false, even though the CA status changed.
* Fixed OIDC invalid\_grant issue for valid codes.
* Fixed an issue where the Workflow UI appeared broken due to CSS being removed by DOMPurify. Styles are now preserved, ensuring proper UI rendering.
* Fixed magic link failure due to missing URL shortener config.
* Fixed application logout issue with custom domains.
* Fixed an issue where the "Overall Recommendation" (IDV status) was not displayed to Helpdesk Admin users in the AdminX dashboard.
* Fixed pagination issue where deleting the last record did not navigate to the previous page in Verification Flows.
* Fixed an issue where scanned document images and selfies failed to render properly on the Session Details page in Microsoft Edge.

{% hint style="info" %}
Customers using IP-based adaptive authentication policies should validate configurations.&#x20;
{% endhint %}

### 1.12.04.01

*March 14, 2026*

#### Authentication Features

**Prevent Workstation Lockouts with Helpdesk Passcode Fallback**

Users who fail to authenticate via Behavioral Authentication + PIN after a configurable number of attempts can now access a fallback authentication journey to regain access to their Windows workstation. Users can contact the Helpdesk to obtain a temporary passcode, allowing them to securely log in or reset an enrolled authentication factor (Behavioral Auth or PIN) if enabled.

Community administrators must configure the fallback authentication journey and ensure a primary authentication method is set. This helps reduce lockouts and maintain productivity. For more information, see [Fallback Authentication](/authentication/windows-workstation-mfa/authentication-methods/fallback-authentication.md)

{% hint style="info" %}
Supported CP Version: 2.2.0.0
{% endhint %}

**Automatic Push & IVR MFA Triggers for RADIUS Auth Proxy Apps**

**Previous Experience**: Users had to manually type keywords like "push" or "ivr" during login to select their preferred MFA method.

**New Experience**: The system automatically triggers Push notifications or IVR phone calls based on pre-configured settings. Community administrators can now set a default authentication method in the AdminX interface, eliminating the need for users to manually specify their MFA preference during each authentication attempt.

**Benefits**: This update simplifies the login flow for RD Gateway integrations using the 1Kosmos RADIUS Auth Proxy, delivering a faster and more seamless authentication experience.

For more information, see [Auth Proxy for RADIUS Server.](/authentication/authentication-proxy/auth-proxy-for-radius.md)

{% hint style="info" %}
Requires: goauthproxy\_1.00.07&#x20;
{% endhint %}

**Added New Behavior Authentication Events**

Two new events have been added to the AdminX Event Logs to support filtering behavior authentication outcomes:

* **E\_BEHAVIOR\_AUTH\_SUCCESS** – Triggered on successful behavior authentication
* **E\_BEHAVIOR\_AUTH\_FAILED** – Triggered on failed behavior authentication

These events help administrators monitor and troubleshoot authentication activity more effectively. For more information, see [Event Logs](/authentication/admin-portal/monitoring-and-reporting.md#event-logs).

**Prevent Password Reuse During Self-Service Password Reset**

Community administrators can now enforce password history directly from AdminX, preventing users from reusing previously used passwords during self-service password reset. Previously, this configuration had to be managed in the backend and could be overwritten.

This enhancement strengthens security, ensures consistent policies, and simplifies policy enforcement without manual backend updates.

For more information, see [Enabling Password History Enforcement Functionality.](/authentication/admin-portal/getting-started-with-adminx.md#resetting-account-passwords)

{% hint style="info" %}
By default, the **Enforce Password History Check** setting is set to false in the AdminX UI. This feature requires gobroker version 1.09.02 or later.&#x20;
{% endhint %}

**Improved Camera Messaging During LiveID Login**

Camera messaging during LiveID login has been improved to provide clearer guidance when camera-related issues occur. This reduces verification errors, improves user experience, and minimizes support requests, helping users complete authentication more reliably.

The following table provides details of the messages displayed when camera errors occur:

| Scenario                                                                     | Error Message                                                                                                     |
| ---------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------- |
| Camera permission denied                                                     | **Camera Permission Denied** – Please allow camera access in your browser settings and refresh the page           |
| No camera detected                                                           | **Camera Not Found** – No camera detected on your device. Please connect a camera and try again                   |
| Camera currently in use by another application                               | **Camera In Use** – Your camera is being used by another application. Please close other apps and try again.      |
| Camera access blocked due to browser security (e.g., incognito/private mode) | **Security Error** – Camera access is blocked. Please use a standard browser window (not incognito/private mode). |
| Camera does not meet required specifications                                 | **Camera Not Compatible** – Your camera doesn't meet the required specifications. Please try a different device   |
| Camera initialization failure                                                | **Camera Initialization Failed** – Failed to initialize camera. Please refresh the page and try again.            |
| Generic camera access issue                                                  | **Camera Access Error** – We couldn't access your camera. Please try again.                                       |
| Face detection system failed to load                                         | **Face Detection Error** – We couldn't load the face detection system. Please refresh and try again               |

**Enhanced Visibility into Passkey Authentication Activities**

Administrators can now monitor passkey-related events in the AdminX Event dropdown:

* E\_PASSKEY\_REGISTRATION\_FAIL
* E\_PASSKEY\_VERIFICATION\_FAIL
* E\_PASSKEY\_VERIFICATION\_SUCCESS

These events improve visibility and tracking of passkey authentication activities.

**UI/UX Enhancements**

The Adaptive Auth Journey form now includes checkboxes for each authentication method option, improving clarity and usability. Updates are reflected across:

* Adaptive Authentication → Create New Journey
* Add Applications Modal → Choose Applications
* Linux PAM / Windows MFA → Create/Update Page
* Admin Role Assignment Report

These updates improve overall usability and efficiency for administrators.

#### Identity Verification (IDV) Features

**Okta Bring Your Own (BYO) IDV Integration with 1Kosmos**

Organizations can now integrate Okta BYO IDV with 1Kosmos to verify identities during onboarding and Self-Service Password Reset (SSPR).

Users are securely redirected to 1Kosmos workflows configured by their organization and returned to Okta upon completion. This integration strengthens identity assurance and reduces the risk of unauthorized access during sensitive account events. For more information, see [Okta 1Kosmos Identity Verification Integration](broken://spaces/jgyVKgYJP0xNjsiKAcPm/pages/qBU2k7XdFRSr8IaSmtjs).

**Build Your Own Intuitive Workflow for Verification Journeys \[Beta]**

Community administrators can now use a visual, drag-and-drop interface in AdminX to build and customize the sequence of screens users see during identity verification sessions.

The interface allows admins to select nodes, connect them to define verification paths, and preview workflows without backend development. This makes it easier to create secure, customizable identity verification experiences. For more information, see [Workflow Builder.](broken://spaces/jgyVKgYJP0xNjsiKAcPm/pages/UUOi26VQCHWNHujNvnjf)

**Launching Verification Sessions from Workflows \[Beta]**

Community administrators can now launch identity verification sessions directly from configured workflows in AdminX. Each session captures user-specific data, execution status, and results, enabling organizations to track verification progress efficiently and provide a smooth experience for users. For more information, see [Launching Verification Sessions](/identity-verification/core-concepts/session.md).

**Support for High-Resolution Images to Improve Verification Success**

Document capture and image processing now support high-resolution images, improving verification success rates and reducing upload failures during identity verification.

While processing high-resolution images may take slightly longer, they offer better reliability and higher success rates for identity verification. Users see a progress indicator during upload and can retry or end the session if needed. This enhancement minimizes errors caused by poor image quality, incomplete processing, or barcode recognition issues, helping to improve onboarding success and reduce support dependency.&#x20;

**AI-Powered ID Proofing Insights in AdminX \[Beta]**

Community administrators or users with the **ai.chat\_bot.access** permission can now access AI-driven ID Proofing insights via the AdminX chatbot. Using natural language queries, they can:

* Retrieve session summaries, failure rates, and document metrics
* Access regional trends and tenant-specific insights
* Make data-driven decisions without manual reporting

This feature simplifies analytics and improves operational monitoring of identity verification performance. For more information, see [AI-Driven ID Proofing Metrics and Insights.](/identity-verification/core-concepts/ai-analysis-summary.md)

**UI Enhancements for Manual Capture Functionality**

With the introduction of manual capture and manual review functionality in the previous release, 1Kosmos has enhanced the verification filters' UI to improve clarity and usability.

**Changes**:

* The **None** value in the **Capture Type** field on Session Details is now deprecated and removed, showing only "Auto" and "Manual" for clearer session information.
* The **Review Result** and **Capture Type** filters on the verification list page have been deprecated and removed to simplify filtering options.

This enhancement improves the overall usability experience, helping administrators focus quickly on relevant verification data.

**Miscellaneous**

Introduced a new **workflow\.manage** permission to control access to workflow creation and management.

#### Bug Fixes

* Fixed an issue where the SAML consent screen displayed incorrect grammar.
* Fixed an issue where renewing an expired Affidavit (by uploading new DL and Passport documents) did not restore the user's IAL level from IAL1 back to IAL2.
* Fixed an issue where updating an OIDC Service Provider configuration using the PATCH /serviceprovider API temporarily cleared the defined scopes and grant type values in the UI.
* Fixed an issue where failure reasons were not displayed in the exported report when downloading ID Verification (IDV) reports from the Verifications tab.
* Fixed an issue in the ID Proofing selfie liveness capture flow where liveness verification consistently failed when the user was positioned at the farthest point, even after the green guidance circle appeared.
* Fixed an issue where the session status was displayed inconsistently across the Verifications list page, Session Details in the View Results page, and in downloaded reports.
* Fixed an issue where Identity Verification reports could not be downloaded for specific journeys, resulting in the message "No verification sessions found, please refine your search." even when sessions were available.
* Fixed an issue in IDVerification Analytics where chart data was displayed incorrectly in the 7-day view, causing the current day's session count to appear as 0 and other days to show inaccurate data due to time zone difference.

### 1.12.01.01

*February 14, 2026*

#### New Features

**Introduced Expiry Status Indicators for Enrolled Documents**

The AdminX interface now displays expiry status for previously enrolled documents and affidavits in the **Identity Wallet** tab under **My Profile**, allowing users to identify documents that need re-enrollment. Additionally, the text **Currently supports USA & Canada** has now been removed.

Two status indicators are displayed on document cards in the Identity Wallet:

* **Expiring Soon** – Displayed for documents that will expire within 30 days. The corresponding expiry date is shown.
* **Expired** – Displayed for documents that have already expired, prompting the user to re-enroll the document.

For more information, see the *Viewing Expiry Status of Enrolled Documents* section in[ Managing My Profile.](/authentication/admin-portal/dashboard/managing-my-profile.md)

**Ability to Capture Documents Manually When Auto Capture Fails**

1Kosmos introduces a new capability in the ID verification workflow that allows community administrators, or users with permission to configure DVCIDs, to manually capture an identity document and continue the verification process if automatic document capture fails after a timeout.

Depending on backend configuration, users will either see a **Manual Capture** button or a **countdown-based** capture, where the system counts down from a configurable duration and then automatically captures the document image.

This capability is supported in both v1 and v2 verification flows.

For more information, see the *Manual ID Capture Fallback* section in[ Verification Journey](/identity-verification/core-concepts/manual-review-and-manual-capture.md).

**Ability to Review Sessions Manually**

1Kosmos introduces a new capability in the ID verification workflow that allows community administrators, or users with the **idproofing.manual-review** permission, to review certain ID verification sessions at a later time or offline. This enables teams to delay decision-making on specific cases. When this capability is used, the ID verification session moves into a Review state. Entering this state is controlled through a backend bypass configuration.

Additionally, users with permission to view session results can filter sessions in the **Verification List** by status, overall recommendation (including 'review'), review result (approved/rejected/review pending), and fallback capture mode, so that they can efficiently find sessions requiring manual review.

An **E\_IDV\_MANUAL\_REVIEW\_DECISION** event is triggered after the user approves or rejects the idproofing session.

For more information, see the *Manual Review of Verification Sessions* section in[ Verification Journey](/identity-verification/core-concepts/manual-review-and-manual-capture.md).

**Display of Review Status in Usage Analytics**

The **Usage Analytics** page under the **Verification > Analytics** tab of the AdminX interface now displays the Review status in the Verifications Breakdown tile.

**Enhanced Name Matching Functionality for Identity Verification**

Previously, identity verification could fail when government-issued IDs included middle names that were not present in directory records (for example, Workday), resulting in the IDV0010 – First Name Check Fails error. To address this issue, a new **Ignore Middle Names** option has been introduced in the AdminX verification flow configuration. When enabled, middle names are excluded from name comparison during ID proofing.

This enhancement improves match accuracy between directory data and identity documents, reduces false verification failures, and increases success rates for onboarding and SSPR flows. For more information, see [Configuring Verification Flows.](/identity-verification/configurations.md)

**Configuring Data Retention Based on Session Outcome**

1Kosmos now allows administrators to configure data retention policies based on the outcome of ID verification sessions. This enables organizations to reduce privacy risk by keeping results for failed sessions while automatically deleting successful ones according to the configured timeline.

When creating a verification flow using the **KYC with Face Comparison** journey, community administrators can use the **Data Configuration** section to specify how long verification data should be retained for each session outcome, including **Success**, **Failed**, **Not Performed**, **Review**, and **Abandoned**.

For more information, see [Configuring Verification Flows](/identity-verification/configurations.md).

**Certificate Authority Failover Support**

1Kosmos now allows administrators to configure alternate Certificate Authorities (CAs) for certificate issuance and renewal. If the primary CA is unavailable due to maintenance or unexpected outages, certificate generation requests automatically fail over to an alternate CA. This ensures uninterrupted enrollment and certificate lifecycle operations while maintaining seamless passwordless authentication through the Credential Provider, without requiring changes to existing login workflows.

For more information, see [AD Broker](/authentication/authentication-broker/adminx-broker-directory-connector.md).

{% hint style="info" %}
This feature requires Go-Broker version gobroker\_1.09.01 or later.
{% endhint %}

**Password History Enforcement During Reset**

Password history enforcement is now supported during password reset. This applies to all reset methods, including mobile-based password reset, AdminX-initiated reset, and resets completed after identity verification.

During password reset, users are required to choose a password that has not been used recently, ensuring compliance with configured password history policies.

For more information, see the *Enforcing Password History* section in [Resetting Account Passwords.](/authentication/admin-portal/getting-started-with-adminx.md#resetting-account-passwords)

**Enhancement: Password History Enforcement with Minimum Password Age Support**

Password history enforcement during password reset and password change has been enhanced to support environments with a configured minimum password age in Active Directory.

Previously, users in such domains could encounter failures when attempting to change their password immediately after an administrative or self-service reset. With this enhancement:

* Password changes are no longer blocked by Active Directory minimum password age policies.
* Password history enforcement remains intact, preventing reuse of recently used passwords.
* The solution works with existing Active Directory policies and does not require changes to minimum password age settings.

This enhancement applies to all supported reset and change flows, including mobile-based password resets, AdminX-initiated resets, and resets completed after identity verification.

**Miscellaneous**

**Access Control Enhancement**

A new **idproofing.manual-review** permission has been added to control access to the manual review functionality.

**Push Notification Delivery Enhancement**

Android push notifications have been enhanced to improve delivery timeliness. Notifications are now sent with high priority, ensuring faster delivery, including when devices are in Doze mode.

The Firebase SDK has been upgraded to version 9.7.0.

**Messaging Gateway Enhancement**

Admin Console now supports a configurable messaging gateway that enables customers to use their own SMS, Voice, Email, or IVR service providers. This enhancement allows customers to integrate unsupported or custom messaging providers by configuring an endpoint in the Admin Console, without requiring provider-specific integrations.

This improves onboarding flexibility and reduces dependency on built-in messaging providers.

#### Bug Fixes

* Fixed an issue where the selfie\_liveness "skip": true setting in the DVCID face\_liveness configuration was overridden if a user opened and saved the V2 DVCID settings in the UI, even without making any changes.

### 1.12.00.01

*January 10, 2026*

#### New Features

**Login Page Customization Enhancement**

A new branding configuration, **Hide username tab on desktops**, has been introduced under **Settings > Branding** in the AdminX interface. This allows administrators to disable the Username tab on login screens for desktop devices (screen widths greater than 992px).

This enhancement provides greater flexibility in configuring the login experience across devices. For more information, see [Branding Customization](/authentication/admin-portal/settings/branding-customization.md).

{% hint style="info" %}

* The **Username** tab will continue to be displayed on mobile and tablet devices.
* If Username is set as the default branding method, the login method priority will follow this order: QR → LiveID Selfie.&#x20;
  {% endhint %}

**Auth Proxy: Hostname Failover Support**

Admins can now configure Auth Proxy failover with multiple Domain Controllers (DCs), including timeout-based fallback, inactive host suppression with auto-reactivation, and forced retries when all hosts are inactive. Auth Proxy also generates an **E\_HOSTNAME\_STATUSCHANGE** event and sends email notifications when host availability changes. For more information, see the *configuring hostname failover support* section in [Auth Proxy for LDAP Server.](/authentication/authentication-proxy/ldap-setup.md)

**LiveID Performance Optimization**

Improved the performance of LiveID capture and authentication on the AdminX login page, reducing the time required to complete the login process.

**API Enhancements**

* The **Create User** API now returns descriptive error messages – The API provides clear error details, such as "username or email ID already exists", instead of a generic 500 Internal Server Error, helping users identify the cause of registration failures.
* The path of the **Create Workflow Instance** API has now been updated.
  * Current path: /workflowapi/workflow\_instance
  * New path: /workflowapi/workflow\_instance/tenant/{tenantId}/community/{communityId}/create

**Miscellaneous**

* Updated the site description for ID proofing session URLs to **Secure link to complete identity verification.**
* This site description may appear wherever the link is pasted as part of a link preview, depending on how the target application generates previews. For example, in desktop browsers or applications like Slack that use URL descriptions, the description appears in the link preview.&#x20;
* Added a warning message — **Provide another tag, this tag already exists** — to the **Unique Tag** field on the **Create Verification Flow** page to alert community administrators when a new workflow is created with the same tag as an existing workflow.
* Added support for:
  * Manitoba DL variations with new document number formats
  * 2025 Texas DL and 2025 California DL
* The **factsSubmitted** data in the downloaded report is now flattened instead of appearing as a JSON object, improving readability and downstream processing.

  Additionally, the **E\_LOGIN\_SUCCEEDED** and **E\_ACCESS\_DENIED** events now display the distance between the user's trusted locations and the actual location used during login when geo-based restrictions are enforced. A new attribute, **distanceUserTrustedToMobileMeters**, shows this value in meters.

#### Bug Fixes

* Fixed an issue where the Live ID panel would turn blank after a successful face scan, causing a delay before displaying an error.
* Fixed an issue where ID proofing sessions failed with an unsupported document error when the template did not include a consent or Start Now screen.
* Fixed an issue where the QR code in the Admin UI fails to render when the qr\_code\_logo branding setting contains an invalid URL format (e.g., double slashes // in the path), without displaying an expected validation error.
* Fixed an issue where, during LiveID login with a username, the camera would activate, but the video feed failed to display on the screen, preventing the facial scan from proceeding.

### 1.11.09.01

*December 13, 2025*

#### New Features

**Password Login Support for Shared Accounts**

In certain scenarios, users may decline biometric consent and have no alternative method to authenticate on Shared Workstations. To address this, 1Kosmos has introduced a new backup authentication option that allows users to sign in using their primary account password instead of FIDO. After successful password authentication, users are presented with the same list of shared accounts and can select an account to log into the workstation.

To enable this capability, a new authentication method, **Password for Shared Account Login**, has been added under **Windows MFA** in the AdminX interface. When configured, users are first prompted to enter their password as the primary authentication step, after which the shared accounts are displayed for selection.

**Automatic Camera Selection During Document Scan**

Administrators can now use the new **camera\_enforcement** property in the ID proofing template to specify whether the front or back camera should be used during document scanning. You can set this property to front, back, or default. Based on the configured value, the corresponding camera will automatically open during the scanning process.

{% hint style="info" %}

* This configuration is part of the V2 DVCID config.
* This helps in scenarios where the user wants to scan a document from a Tablet.&#x20;
  {% endhint %}

**LiveID Capture Enhancements**

During LiveID capture:

* Users will no longer see the repeated **keep your eyes open** prompts, an issue previously observed under low-light conditions or when wearing glasses.
* LiveID capture time has been reduced to 600 milliseconds, improving overall responsiveness.
* The capture circle now turns red when no face is detected and switches to light green when a face is recognized. A darker green animated ring indicates capture progress and provides clearer visual guidance.
* The following UI messages are now displayed based on user position and movement:
  * "Center your face in the circle"
  * "Move closer"
  * "Move back a little"
  * "Keep your head level"
  * "Face the camera directly"

**Optimized Camera Permissions Overlay During Document Scan**

In the current implementation, during an ID proofing session, if users let the camera permission prompt sit idle for about 40 seconds, they were returned to the document instruction screen. If the user then granted camera permission and tapped "Start Scan", the flow failed to detect the camera, resulting in a "No camera detected" error and preventing the user from continuing. This has now been addressed: once permission is granted, the camera opens correctly, allowing users to proceed with document scanning without interruption.

**Security Fixes**

* Fixed a vulnerability where certain regex replacements could lead to unexpected performance degradation.
* Enhanced Web LiveID security with a new injection-attack detection module capable of identifying virtual camera feeds, screen captures, and synthetic video sources.

#### Bug Fixes

* Fixed an issue where the UI fails to validate the format of email address during reset password flow.
* Fixed an issue where OTPs generated via the generate endpoint did not expire and were still accepted after the configured validity period.
* Fixed an issue where OTPs for Singapore users were processed with a US (+1) ISD code instead of Singapore (+65).
* Fixed an issue where bootstrapping a new community created multiple databases for the default community on repeated requests.
* Resolved an issue where v2 DVCIDs configured with only SSN, Face Compare, or AAMVA checks would trigger errors in the Verify API after migration from v1. These configurations now process correctly without causing API failures.
* Fixed an issue where secondary email and/or phone were not deleted after removing it from the user's profile.
* Resolved intermittent failures that occurred when users attempted to download ID Proofing reports.
* Fixed the error message shown when attempting to create a WFI with an invalid access code.
* Fixed an issue where a WFI could be created with an invalid communityId in the request.
* Corrected the HTTP status code to 404 when attempting to generate a WFI for an invalid or non-existent workflow.
* Fixed an issue where an internal server error was thrown when reloading a WFI on the IDProofing node.
* Fixed an issue where metadata was not passed to the IDProofing session even when person\_info was available in the workflow summary.

### 1.11.08

*November 15, 2025*

#### New Features

**Added PIN Lockout Notifications During LiveID Authentication**

The Login page on the AdminX UI now clearly notifies users when their PIN is temporarily locked due to multiple incorrect PIN attempts with a new error message "Your PIN has been locked due to multiple incorrect PIN attempts. You can attempt using your PIN in x minutes." The PIN is automatically unlocked after the lockout period, allowing users to try again without contacting support.

These updates help users better understand lockouts and reduce login confusion.

Also, the following events are triggered:

* **E\_FACTOR\_LOCKED** – This event is triggered when the PIN is locked after multiple failed attempts.
* **E\_LOGIN\_FAILED** – This event is triggered when the user attempts to log in to an account that is already PIN-locked. In such cases, the reason for the failure is displayed as: "Factor Locked - User PIN".
* **E\_FACTOR\_UNLOCKED** – This event is triggered when the PIN is manually unlocked by an authorized user.

**New Error Message for Virtual Camera Detection**

When a user attempts to authenticate using a virtual camera (e.g., presenting a face through an injection attack), the system now displays a clear error message indicating that suspicious activity has been detected.

**Title**: Suspicious Activity Detected

**Message**: You cannot use LiveID for login. Please try another method.

This update helps improve security and fraud prevention during facial authentication.

**Viewing Passkey Events on AdminX Interface**

Community administrators can now view Passkey-related events generated on mobile devices directly within the AdminX interface under Event Logs. The following events are captured from the Mobile SDK whenever a user registers or authenticates via Passkeys on the mobile app:

* E\_PASSKEY\_REGISTRATION\_FAIL
* E\_PASSKEY\_VERIFICATION\_SUCCESS
* E\_PASSKEY\_VERIFICATION\_FAIL

This enhancement provides better visibility into user authentication activity and improves monitoring of Passkey adoption.

**Enhanced Forgot Password Experience**

The password reset flow has been enhanced to dynamically display either the Username or Email field on the Forgot Password page based on configurations set by community administrators in AdminX under **Authentication > Reset Password > Password Reset Identifier**. In this section, administrators can select Email address or Username as the identifier for password reset.

{% hint style="info" %}
Once the configuration is saved and updated, it may take up to 10 minutes for the change to reflect in the system.
{% endhint %}

**New Error Message for LiveID Enrollment and Authentication Failures**

When LiveID enrollment fails due to a low-risk confidence score, and users attempt to enroll again despite showing their real face, the system now displays the message:

"Suspicious Activity Detected. You cannot register LiveID."

Similarly, if users attempt to log in using a LiveID that is not enrolled, they will now see:

"Suspicious Activity Detected. You cannot use LiveID for login. Please try another method."

These enhancements provide clearer feedback to users and improve transparency during LiveID enrollment and authentication.

**Improved Verification Success Rate for SSN Document Checks**

The verification process has been improved to reduce failures during document capture and SSN data validation. Previously, the system required an exact match between the first name, last name, and date of birth from the SSN and the captured document.

With this enhancement, the name matching requirement has been relaxed — verification will no longer fail due to minor name differences between the SSN data and the ID document, resulting in a smoother and more successful verification experience.

**API Enhancements**

* The `{{tenantDNS}}/api/r1/community/{{community_name}}/userid/johndoe/ial` API now includes the expiry date (YYYYMMDD format) for all documents enrolled in the wallet, regardless of whether the user is IAL1 or IAL2. This allows administrators to easily identify documents that have expired or are nearing expiry.
* A new `{{client_api}}/api/r3/otp/verify` API has been added to verify one-time passcodes (OTPs) provided by users for secure authentication. It ensures consistent handling of outcomes with standardized success and error responses. For more information, see [Verify OTP](https://documenter.getpostman.com/view/50203634/2sB3dHWZ1n#cd724b46-f9ae-466d-8757-c7547f8d3c95).

#### Bug Fixes

* Event log columns in AdminX did not have fixed widths, causing layout issues when usernames were long.
* The "Send Invite" button in the AdminX Invites tab was unresponsive, and the page did not progress after multiple clicks.
* Incorrect error messages were displayed when LiveID enrollment failed due to a low-risk confidence score.
* Resolved an exception error that caused LiveID capture to fail in the workflow.
* Push notifications were not received for AdminX login when configurations were added to the internal database or during bootstrapping.
* LiveID capture failed during identity verification on both Android and iOS devices, displaying a "Face not found" error.
* The SSPR password reset flow failed when run in parallel on the same or different browser instances (for the same or different users) due to session ID validation issues in the poll API.
* The user token for the SSPR session did not expire after 5 minutes as expected.

### 1.11.06.01

*October 10, 2025*

#### New Features

**Ability to Configure Identity Verification Flow Through UI**

Community administrators with the idproofing.add-journey permission can now configure and manage custom ID verification journeys in AdminX under **Verification > Verification Flows**.

This feature enables admins to create a custom workflow according to their regional requirements and reduce fraud risk.

Key capabilities include:

* Creating and managing verification journeys
* Generating and sharing session links
* Editing or deleting journeys
* Defining accepted ID documents by country and region

For more information, see [Configuring Verification Flows.](/identity-verification/configurations.md)

**Granular Document Controls for ID Verification**

Community administrators can now define and control which identity documents are allowed or blocked during the ID Verification journey. Documents can be configured by country, region, and document type, with the ability to allow all by default or apply granular restrictions. When a user scans a document not on the allowed list (or on the blocked list), the system will end the session with a clear failure response and display the "Unsupported" screen. A new event (E\_IDV\_DOCUMENT\_NOT\_ALLOWED) is triggered with full metadata for audit and tracking.

This feature gives organizations greater control and compliance over the types of identity documents accepted, helping to meet regulatory or internal policy requirements.

**Enhanced IAL2 Identity Verification Flow**

In the previous release, users could verify their identity by submitting identity documents, biometric data, and an SSN. In this release, users can enroll their liveid to a wallet, enabling future comparisons against identity documents stored in the wallet for verification purposes.

Community administrators can also configure whether the Liveid capture must appear within the verification flow or in a separate tab, based on the preferred user experience. If the initial selfie session does not start within 2 seconds, a new session is automatically created to avoid delays and ensure a smooth verification process.

**Trigger Password Reset Verification Link via Email or SMS from Workday**

Users will now receive the verification link using the email addresses and phone numbers available on Workday. If Workday is configured as the data source, then the email addresses and phone numbers are retrieved from Workday as well. The UI displays a list of email addresses and phone numbers retrieved from Workday. When the user selects an email/phone, an ID verification link is sent to their email/text message, and the regular SSPR journey continues.

**Login Screen Customizations**

Community Administrators can now use the **Branding** page in the AdminX interface to customize the login screen's appearance and messaging. Admins have the ability to configure the following elements:

* Background image layout
* Sign-in heading text
* App download message

These enhancements allow for a more personalized and brand-aligned user experience.

**Added New Form Input Controls**

A new form step has been introduced in the verification flow, allowing users to enter information through various input types, including text, number, password, email, date, and checkbox fields. This makes it easier to collect structured data directly within the flow.

**Updated Alert Prompt Messages During PIN/Typing Pattern Deletion**

When users attempt to delete the PIN or typing pattern from the AdminX interface, the confirmation prompts have been updated to be more user-friendly.

* When removing a typing pattern, the UI displays: "Are you sure you want to remove \<user>'s typing pattern? \<user> will no longer be able to use this method for authentication."
* When removing a PIN, the UI displays: "Are you sure you want to remove the PIN? \<user> will no longer be able to use this method for authentication."

**New Error Messages Displayed During PIN/Typing Pattern Deletion**

When users attempt to delete the PIN or typing pattern from the AdminX interface, the system now displays user-friendly error messages.

**New messages:**

* When a PIN deletion fails, the UI displays: "Error removing PIN, try again."
* When a typing pattern deletion fails, the UI displays: "Error removing typing pattern, try again."

#### Bug Fixes

* Fixed an issue where messages for deleting PIN/Pattern were inconsistent.
* Fixed an issue where backend error messages were shown; the UI now displays the correct messages during PIN/Pattern deletion.
* Fixed an issue where idvaapi endpoints accepted partially authenticated JWTs; API calls now correctly return 401 with message "failed to verify token".
* Fixed an issue where the banner image in the default Admin Onboard email template appeared oversized on mobile devices.
* IVR calls triggered via RADIUS authentication end prematurely, disconnecting after a few seconds before IVR authentication completes.
* Fixed an issue where events **E\_BEHAVIOR\_AUTH\_UNENROLLED** and **E\_USER\_PIN\_UNENROLLED** were missing the "initiated\_by":"administrator" parameter.

### 1.11.04

*September 5, 2025*

#### New Features

**Support for Workday as Source of Truth in SSPR**

1Kosmos provides community administrators with the ability to configure Workday (WD) as the "source of truth" for retrieving employee details during the Self-Service Password Reset (SSPR) process, based on valid identity proofing. This setup enables end users to reset their passwords through the SSPR workflow without contacting IT, with identity verification handled seamlessly as part of the process. For more information, see the *Resetting Passwords Using Identity Documents* section in [Resetting Account Passwords](/authentication/admin-portal/getting-started-with-adminx.md#resetting-account-passwords).

**Typing Behavior Authentication**

1Kosmos introduces Typing Behavior Authentication, a new capability that leverages behavioral biometrics to make authentication both stronger and more seamless. With this feature, you can analyze the way individuals interact with digital systems — such as how they type on a keyboard, move a mouse, swipe a screen, or handle a device — and compare this activity against their unique behavioral profile.

This innovation is particularly valuable in environments where users must enter PCI DSS–compliant passwords of 14–16 characters, which can be difficult to remember. By registering and verifying a user's typing pattern, organizations can:

* Simplify authentication by reducing the need for frequent password resets
* Enhance security with an additional biometric factor unique to each user
* Provide flexibility with the option to enroll a secure PIN for workstation login

Typing Behavior Authentication is more than just a convenience — it strengthens identity verification by treating the rhythm of typing as a biometric indicator. This makes it ideal for use cases like:

* Secure workstation access
* Real-time user validation
* Fraud mitigation across digital interactions

For more information, see [Behavior Authentication](/authentication/windows-workstation-mfa/authentication-methods/behavior-authentication.md).

**Support for One-Time IAL2 Identity Verification**

Community administrators can now create and manage a one-time Identity Assurance Level 2 (IAL2) verification flow. This new process allows users to verify their identity by submitting two identity documents, biometric data, and an SSN.

**Key Benefits**:

* **Non-Persistent Verification**: User identity data is not stored after verification; no retention of personal information.
* **IAL2 Compliance**: The verification process meets Identity Assurance Level 2 requirements while ensuring no user data is remembered post-verification.
* **One-Time Process**: Unlike the existing flow, data is not deleted or reset after verification.

This update enhances compliance and streamlines the verification process for administrators. For more information, see [Kantara Certified IAL2 Verification.](/identity-verification/ial2-verification/create-and-manage-ial2-verification.md)

**Machine ID Support for Orion in Adaptive Authentication**

Support for using Machine ID from the Orion Authenticator is now available as a condition in adaptive authentication. This allows administrators to identify trusted devices — personal or corporate — by matching the device's Machine ID during login. Machine IDs can be uploaded manually or in bulk via CSV. When a match is found, users are prompted to authenticate using the methods defined in their login journey, enabling a more secure and seamless authentication experience. An E\_ADAPTIVEAUTH\_CREATED event is triggered as part of this flow. For more information, see [Adaptive Authentication](/authentication/passwordless-for-web-apps/adaptive-authentication.md).

**Added Orion Detection Wait Time**

Administrators can now control how long the UI waits for a response from Orion during login through a new setting, **Orion Detection Wait Time**, which defaults to 1500 milliseconds. This value can be adjusted between 0 and 60000 milliseconds via the AdminX UI under **Authentication > Orion Authenticator > Orion Detection Wait Time**. If left unconfigured, the system will use the default wait time. For more information, see the *Configuring Wait Time* section in [Orion Authenticator.](/authentication/orion-desktop-authenticator/overview.md)

**Duplicate Event Insertion Mitigation**

To prevent duplicate event records from being inserted into the database, a unique index has been added on the combination of event\_name and eventData.event\_id. This prevents duplicate records from being inserted. Additionally, a new mechanism has been implemented to detect and suppress duplicate inserts. When a duplicate event is encountered, it is skipped, and an error message "Duplicate record being inserted event\_id and event\_name" is logged for every 100 such occurrences to avoid excessive logging while still providing visibility into the issue.

**Renamed the Devices Tab to Login Options**

The **Devices** tab under **My Profile** has been renamed to **Login Options**.

**Added New Parameter to E\_PWDRESET\_FAILED Events**

The **mode** parameter is now included in E\_PWDRESET\_FAILED events to indicate the method attempted during the password reset process. Supported values include:

* email link with otp
* email link
* idp

**Support for Configurable Profile OTP and TOTP Transition Handling**

This release adds support for separating the profile passcode from the account passcode by introducing a configurable profile\_otp service name in CaaS. When configured, AdminX will use this setting during OTP generation and verification. If not configured, existing behavior remains unchanged. The update is fully backward-compatible and does not impact LDAP, RADIUS, or API integrations.

{% hint style="info" %}
With the latest mobile app update, TOTP has been deprecated. The app now displays only the account OTP. As a result, the **Codes generated by 1Kosmos app** option during login no longer supports TOTP for upgraded users. These users must enter the account OTP. Users on older app versions can continue using TOTP as before.

To ensure a smooth transition, both OTP types — account OTP and TOTP — are currently supported.

In the E\_OTP\_VERIFIED event, the type parameter indicates the OTP type:

* **totp** for time-based OTP
* **user-generated** for account OTP
  {% endhint %}

**New Permission Added to Admin Roles**

A new permission, user.unlink.login\_options, has been added to the admin permission bootstrap for both community\_admin and helpdesk\_admin roles.

**Miscellaneous**

In scenarios where Fortigate VPN clients trigger multiple rapid authentication requests, OTP validation was failing due to duplicate requests being treated as separate attempts. To address this, if multiple OTP validation requests are received with the same request ID within 40 seconds, the system will now treat the OTP as valid, avoiding unnecessary rejection. These changes help prevent premature OTP invalidation during closely timed authentication attempts.

**API Enhancements**

* The adminapi has been updated to include the "mode" parameter in requests to users-management during password reset operations. This parameter indicates the method used to reset the password.
  * Email link
  * ID proofing
  * Mobile app
* The session poll API has been enhanced to include a new response parameter "responseStatus".
* The /api/v3/rest/{community}/pwdreset endpoint has been updated to include event data when calling the Users Management API for password resets. When a password reset is initiated via mobile, the Admin Console will determine the reset mode based on the presence of a personId linked to the did in the request. If a matching personId is found, the reset is classified as coming from an "authenticator"; otherwise, it is labeled as "other." This mode is passed in the eventData field to the Users Management changePassword API, allowing better tracking of how password resets are performed.

**Security Fixes**

**Update to OTP Behavior for app and app\_ext License Keys**

What's Changing: For license keys of type app or app\_ext, the API previously required the caller to send the user's public key in the request. This behavior is being updated with the following changes:

New Behavior:

When using an app or app\_ext license key:

* The API will no longer return the OTP in the response.
* Instead, the caller can request the OTP to be sent via Email, SMS, or Voice, provided the user's profile (retrieved using um/fetch\_single\_user\_by\_username) contains the requested email address or phone number under the appropriate fields (emails or phones).

This change enhances security by restricting direct access to OTPs and enabling secure delivery through verified contact methods.

Additionally, a security check has been added to verify whether the user exists before generating or sending an OTP. This applies to users authenticated using app and app\_ext license keys. If neither of these license keys is present, the check is performed to determine if the user is locked.

**Cryptographic Enhancements**

The LiveID Selfie service has undergone key cryptographic enhancements to strengthen data protection and user authentication.

* **Key Derivation & Encryption:** The service now uses SHA-512 with salted key derivation, and AES-256 with dynamic IVs — enhancing the security of encrypted data.
* **PIN Hashing:** The hashing mechanism for user PINs has been upgraded from MD5 to SHA-512, with added salting using the serviceKey's private key — further reinforcing authentication integrity.

These improvements enhance the overall cryptographic strength and resilience of the service.

**Google Captcha Added to Invite Resend Actions**

To prevent automation attacks such as rapid enumeration and brute-force attempts, this release introduces Google Captcha on the following pages:

* **User Profile > Invites**
* **Users > Invites**

These changes strengthen the security of invite-related functionality by ensuring only legitimate user actions can trigger the resend invite process.

**What is Deprecated?**

The expiry timestamp (expiryTs) has been removed from IDProofing event data. Previously, each event included a default expiration set to 91 days (131,400 minutes) from the time of creation. This change was made because data retention and cleanup for these events will now be handled through dedicated database archiving processes managed by DBAs, making the application-level expiry unnecessary.

#### Bug Fixes

* Resolved an issue where the login page delayed unnecessarily after detecting Orion. The process now proceeds immediately upon a valid response, improving login speed.
* Addressed an issue where HOTP user reports were generated without data.

### 1.11.02

*August 9, 2025*

#### New Features

**Self-Service Password Reset Enhancement**

End users can now reset their passwords by verifying their identity with a valid ID document, in addition to the existing email/SMS OTP method. This feature is disabled by default for all communities.

Additionally, a new configuration has been introduced in DVCID to enable fuzzy matching only when the criteria parameter is explicitly set to "fuzzyMatch". The system compares the first name from the identity document with the session's first name using a configured minMatchScore.

If the names don't meet the score, a secondary dictionary-based check is performed (if matchCommonAliases is true), using name variants defined in the common\_aliases parameter managed in CAAS. Verification succeeds if a match is found; otherwise, it fails.

**Manual Document Capture Support**

The verification UI now supports manual document capture when auto-capture fails, such as with documents like Yukon ID/DL where the front side isn't detected, causing the process to stall. To address this, the UI has been enhanced with fallback options including **Manual Capture** and **Retry Auto** buttons, which appear after a timeout period. These options allow users to either manually upload their document or retry the automatic capture, ensuring the verification process can continue without interruption. For more information, see the *Verifying Identity* section in[ Verification Journey.](/identity-verification/core-concepts/verification-flow.md)

{% hint style="info" %}
The Manual Capture option is controlled via a configuration flag and may not be available in all environments.&#x20;
{% endhint %}

**Enhancements to the V3 Poll API**

The V3 Poll API response has been updated with the following additions:

* Added liveid\_object key containing selfie details.
* Included rawData for session-level raw information.
* Added token, reason, reasonCode, and fuzzyMatchScore to the response.
* Updated resultStatus for sessions where verification was not performed to return NOT\_PERFORMED instead of FAILED.

**Removed the Encrypted Error Code from Unauthorized Error Message**

When a user enters an incorrect username or OTP multiple times, the account is locked. Previously, the UI displayed the message "You are not authorized to access" followed by an encrypted error code. In this release, only the message "You are not authorized" is shown. The encrypted error code has been removed.

**Enhanced Hardware Token Syncing Mechanism**

The hardware token authentication flow has been improved to support a more streamlined and consistent user experience. When a token is used for the first time, the user is prompted to enter three consecutive passcodes to sync the token and set its counter. If the sync is successful, the user is logged into the tenant; if not, the system displays an invalid OTP message and prompts the user to try again.

With this update, syncing is required only once per token, even when the token is shared across multiple users. To support this, a new setting **Hardware Token Sync Window** has been introduced in the AdminX interface, allowing admins to manage and monitor token sync behavior more effectively. For more information, see the *Token Counter Sync on First Use* section in [HOTP Tokens](/authentication/passwordless-for-web-apps/login-methods/hardware-tokens.md).

**Support for Password Reset on LDAP v3 Compliant Directory**

1Kosmos now supports generic password reset operations for users in an LDAP directory.

**Security Fixes**

* The AdminAPI excludes the HTTP header Access-Control-Allow-Origin: \* in responses, which allowed all external domains to make cross-origin requests. Additionally, the OPTIONS method is not supported.
* A signature\_token is added to the response body using the decrypted request\_id as salt, after the body is encrypted. APIs returning JSON objects must include request\_id, and array responses should be logged. This prevents response tampering by tools like Burp Proxy and man-in-the-middle attacks.

**API Enhancements**

The `/password_reset` API has been enhanced to support Self-Service Password Reset (SSPR). As part of this enhancement, both the code and otp parameters are now optional.

**Miscellaneous**

The LDAP Auth Proxy downloaded from AdminX now uses the service\_ext license key, allowing it to function properly.

#### Bug Fixes

* After clicking **Edit Profile** from the Users page and navigating back, "User not Found" is displayed, and the profile information is missing.
* UI does not send the module id into the fetch profile API if the username contains an underscore.
* When downloading a report from the Analytics page, the user\_id parameter is displayed as uid in the E\_REPORT\_REQUESTED and E\_REPORT\_GENERATED events.
* Fixed the issue where alert emails were being sent from the initiating user's email address when downloading event-related reports.
* AdminAPI fails to reject the CORS preflight OPTIONS requests by returning a 200 OK response and exposes supported HTTP methods via the Allow header, leaking implementation details and confirming endpoint existence, violating security best practices for administrative APIs.
* Accessing AdminX on Internet Explorer (Windows) results in a 401 Unauthorized error for the /nonce/sign API call as Internet Explorer does not send the Origin header for same-origin requests, unlike Chrome.
* Importing IDP configuration in External IDP returns a CORS error for 1Kosmos domains.
* Unable to open the user profile if the username contains an underscore (\_) in Entra ID.
* The **Admin Role Assignment Report** fails to include user details like first name, last name, email, and last login in the downloaded file.
* Fetching all users from Azure AD returns an incomplete list, not retrieving the full set of users present in the directory.
* Updating an existing external IDP with a duplicate IDP entity ID incorrectly returns a 200 success response and updates the IDP with the duplicate value.
* **Take Selfie** button remains disabled even when the user's face is correctly positioned within the oval guide, preventing completion of the ID Proofing session.
* "No camera detected" error is displayed if a previous document capture attempt has failed.
* Incorrect error codes are displayed when scanning an expired driver's license or a photo of a document.

### 1.11.00

*July 12, 2025*

#### New Features

**Ability to Export and Download Token Data from Hardware Tokens Dashboard**

Community administrators or users with the **authentication.hardware-tokens.export** permission can now use the new **Export Data** button on the Tokens or **Users** tab to export and download the token data. For more information, see [HOTP Tokens.](/authentication/passwordless-for-web-apps/login-methods/hardware-tokens.md)

{% hint style="info" %}
While provisioning tokens, if any error is detected in the records — whether through CSV upload or manual text input — no tokens will be added.
{% endhint %}

**Added Two New Languages in ID Proofing Templates**

The ID proofing templates have now been enhanced to support multi-language capabilities by adding Simplified Chinese and Spanish, expanding the current support to four languages: English, French, Simplified Chinese, and Spanish.

**Implemented Retry Mechanism for Unsupported Documents**

A retry mechanism has been implemented to improve handling of unsupported documents during the verification process. Two scenarios are supported: In Progress and Abandoned. Retry behavior is governed by a configurable attempt limit.

If the retry count has not been exceeded, a "Retry Required" option is displayed.

Once the retry limit is reached:

* In the **In Progress** scenario, if only unsupported documents are submitted, the verification result is marked as "Verification Not Performed" with the reason "Unsupported document was presented".
* In the **Abandoned** scenario, the final verification status reflects the previous attempt's result.

An E\_IDV\_SESSION\_RETRY event is displayed when a retry attempt is made.

**Display of Passport Instructional Text in Vertical Mode**

The instructional text displayed during passport scanning is now properly aligned and easily readable in both vertical and horizontal orientations.

**Renamed Security Key or FIDO to Passkeys**

The security key has now been renamed to passkeys in the AdminX interface, under the Adaptive Authentication and Sign In screens.

**Renamed BlockID to 1Kosmos**

As part of the rebranding initiative, the term "BlockID" has been updated to "1Kosmos" across the AdminX interface and in messaging templates.

**Enhanced Audit Log Labels on Admin Activity Page**

The Admin Activity page in the AdminX interface now displays user-friendly names for specific audit log events, replacing previously shown raw event codes. This enhancement improves clarity and user understanding of logged actions. Updated event labels include:

* E\_ADAPTIVEAUTH\_CREATED → Adaptive Auth Journey was created
* E\_ADAPTIVEAUTH\_DELETED → Adaptive Auth Journey was deleted
* E\_ADAPTIVEAUTH\_MODIFIED → Adaptive Auth Journey was modified
* E\_SESSIONS\_TERMINATED → User Sessions were terminated
* E\_TOKEN\_LIST\_EXPORTED → Token list was exported
* E\_TOKEN\_ASSIGNMENT\_EXPORTED → Token assignment list was exported

**Improved Messaging on AdminX Dashboard Banner**

As part of ongoing UX and content enhancements, the admin dashboard banner text has been updated for improved clarity and readability.

**Enhanced SSN Behavior During Verification**

Enhanced the SSN verification process to handle cases where multiple records are returned for the same user. When multiple matches share the same DOB, the system now selects the record(s) with the highest idVerificationScore. If a unique match is found, verification proceeds; otherwise, it fails gracefully, maintaining data integrity.

**Security Fixes**

* To mitigate the risk of unauthorized cross-origin requests, the AdminAPI no longer returns the wildcard (\*) in the Access-Control-Allow-Origin HTTP header. This change addresses a potential security vulnerability where untrusted or malicious websites could access sensitive API data on behalf of users.
* Generic error messages are now shown on the UI, preventing unintended disclosure of sensitive internal information.

**Miscellaneous**

**Added New Parameter to E\_ROLE\_CHANGED Event**

The **E\_ROLE\_CHANGED** audit event now displays the role\_changed\_to parameter when a user's role is changed from Community Administrator to Basic User, improving visibility into role transitions in audit logs.

**Logging Behavior Enhancement**

Token verification logging has been updated to improve clarity. Session expiry events, which are expected behavior, are now logged at the INFO level instead of ERROR, reducing false alarms. Unexpected token failures continue to be logged at the ERROR level, and API error responses remain unchanged.

**Support for Object SID in Certificate Requests**

When requesting certificates, the user's unique object SID is now included in the certificate subject name for improved identity tracking. Certificates are properly issued and stored, ensuring seamless authentication and credential management.

#### Bug Fixes

* When multiple users are assigned a token, the AdminX interface bypasses validation for subsequent entries, allowing non-existent usernames to be assigned without error.
* Users with a Custom Role that includes permissions for Authentication and Reports are unable to access the corresponding menu items in the UI.
* The dguid field in the fetch users API response returns the user's actual dguid instead of the mapped email ID, despite dguid being explicitly configured to use the user's email.

### 1.10.19

*June 14, 2025*

#### New Features

**Ability to Support Hardware OTP Tokens**

1Kosmos has now introduced support for **HOTP-based authentication**, enhancing secure access through hardware tokens. Unlike time-based methods, HOTP is event-driven — generating a new one-time password (OTP) only when triggered by a user's action. Each OTP is unique and remains valid until used, offering a reliable and time-independent authentication method.

This feature leverages a shared secret key and counter to ensure strong, consistent authentication, especially useful in environments where time synchronization may be a challenge. This event-driven, time-independent method enhances security, improves reliability in offline or unsynced environments, and offers a simple, scalable solution for secure user access. For more information, see [HOTP Tokens.](/authentication/passwordless-for-web-apps/login-methods/hardware-tokens.md)

**Ability to Encrypt SAML Assertions**

In the current implementation, 1Kosmos only supports signing SAML assertions. To address encryption requirements, a new **Encryption for SAML Assertion** section has been introduced under the **Advanced Options** tab when configuring or modifying SAML applications. This enhancement allows administrators to encrypt SAML assertions before they are transmitted to the service provider, ensuring secure data exchange. For more information, see [SAML Application Integrations.](broken://pages/2GhsERJhvLPuGy2VIGMb)

* The supported Encryption Algorithm: RSA and AES 256 CBC
* The supported Key Transport Algorithm: RSA OAEP

**Implemented WCAG Compliance for ID Proofing Templates**

In this release, 1Kosmos implemented Web Content Accessibility Guidelines (WCAG) compliance for ID Proofing Templates. This enhancement ensures that the templates are accessible to users with disabilities, improving usability for all users, including those relying on assistive technologies. Additionally, Voiceover support has been introduced across all screens to enhance accessibility for visually impaired users. This ensures that key elements and instructions are now fully navigable and readable using the keyboard.

By adhering to WCAG standards, 1Kosmos provides a more inclusive experience, ensuring it meets legal and ethical accessibility requirements. This update enhances both the functionality and accessibility of the ID proofing process.

**Security Fixes**

Insufficient anti-automation allows attackers to automate tasks meant for users, enabling brute-force and enumeration attacks on sensitive endpoints. In this case, it allowed unlimited email invitations after user creation or during passwordless authentication invites. To mitigate this attack, a recaptcha has been integrated on the Invite User (Passwordless) page to enhance security and prevent automated misuse.

{% hint style="info" %}
You cannot use any of the following wildcard characters when fetching user details using the fetch\_single\_user\_by\_username API.

?, %, \*, \[], {}, #, !, ,(comma) , , / , ^, $&#x20;
{% endhint %}

**Added ReCAPTCHA on Verification Journeys**

To enhance security and prevent automated misuse, reCAPTCHA verification has been implemented on the **Verification > Journeys** page when an administrator creates a verification session and sends it via SMS to the user.

**reCAPTCHA UI Enhancements**

As part of reCAPTCHA integration on the Journeys page:

**Token Capture**: After creating a session, when the community administrator clicks "Share via text", the reCAPTCHA token is captured and included in the request payload (captchaToken) for the /idvaapi/proofingsession/session/sms API.

**Missing reCAPTCHA Config**: If the /proofingsession/recaptcha\_config/fetch API returns an error message: "Captcha config not found", the following UI message is shown: "Recaptcha configuration is missing, please contact your administrator." However, the administrator can still create sessions but cannot proceed to send them via text.

**Missing Token Scenario**: If the reCAPTCHA config is missing and the administrator clicks "Share via text", the UI cannot provide a captcha\_token. In such cases, the UI displays the following message: "Recaptcha verification failed. Our security policy does not allow you to send this session via text message."

**Token Validation Failure**: If the /idvaapi/proofingsession/session/sms API returns: "Recaptcha check failed", the UI displays the message: "Recaptcha check failed. Please contact your administrator."

**Miscellaneous**

* The **E\_USER\_CONSENT** event now displays the Consent status irrespective of whether the user accepts or rejects the consent while submitting their document.
* Enhancements have been made to the log structure of the Admin API microservices.
  * When the OTP template is configured in a non-English language, users will now receive the SMS in that specified language.
  * ECDSA has been disabled for the following APIs to facilitate easier integration. This occurs only when the request includes the parameter noecdsa=true. If this parameter is not included, the APIs continue to follow the existing behavior with ECDSA enabled.
    * Generate OTP: /r2/otp/generate
    * Verify OTP: /r2/otp/verify
    * Generate ACR: /api/r2/acr/community/:community/code
    * Redeem ACR: api/r1/acr/community/:community/:code/redeem
* A new /proofingsession/recaptcha\_config/fetch API has been added for recaptcha.

#### Bug Fixes

* The application allows mobile TOTP for authentication despite configuring the adaptive auth journey as **Password + Profile OTP**.
* When logging into the AdminX dashboard, if a user selects the **Profile OTP** option but enters an invalid OTP type (e.g., TOTP), the system displays the error message: "Incorrect OTP. Please try again." However, the event **E\_OTP\_VERIFIED** is still triggered with a success result, despite the failed OTP verification.

### 1.10.18.01

*May 12, 2025*

#### New Features

**Resetting Account Passwords through AdminX without OTP**

Community administrators can now define how end users reset their forgotten passwords — through AdminX or the Mobile App — using the new **Authentication > Reset Password** menu in the AdminX interface.

On the Reset Password page, administrators can configure the following options:

* Enable users to reset passwords through AdminX
* Enable users to reset passwords through Mobile App

{% hint style="info" %}
Although mobile-based password resets are supported in the current implementation, this new feature requires that the **Enable users to reset passwords through Mobile App** setting be explicitly enabled in AdminX for mobile resets to function.&#x20;
{% endhint %}

**Ability to Terminate Users' Active Sessions via AdminX**

Community administrators with the user.revoke-sessions permission can now revoke active sessions — either their own or others' — to enhance security in cases such as password resets, user termination, or potential insider threats.&#x20;

**Added New Authentication Journey to Login through Profile OTP**

A new authentication method, **Password + Profile OTP**, has been added to the Adaptive Authentication Journey page. When a community administrator assigns this journey to a user, the user is first prompted to enter their password, followed by a verification code (Profile OTP). Upon successful authentication, the user is logged in to the AdminX interface.

{% hint style="info" %}

* The **Profile Passcode** option appears on the **Choose an authentication method** screen only when multiple OTP options (e.g., email and SMS) are enabled for the user journey.
* Make sure that the Password + Profile OTP option has been set as the authentication journey.&#x20;
  {% endhint %}

**Implemented Retry Mechanism for ID Proofing Sessions**

Community administrators can now configure the number of retry attempts allowed when users fail to complete the verification process. This is managed in DVCID via a new parameter, maxRetries. In 1Kosmos, the status "Verification Not Performed" indicates that the captured image does not meet the required quality criteria, prompting users to retry document scanning.

By default, the maximum number of retry attempts is set to 2, but administrators can increase it up to 5. If the retry attempt count is set above 4, the UI prompts the administrator to correct the verification configuration before continuing.

If users are unable to complete verification within the allowed attempts, their status remains "Verification Not Performed." The UI also displays a number selector to show how many attempts the user has made. For more information, see the *Viewing Session Results* section in [Verification Journey.](/identity-verification/core-concepts/verification-flow.md)

#### Bug Fixes

* User authentication via password or OTP fails when Kafka pods were down.
* An error message "allowed is not allowed" is displayed when the administrator creates or updates the transformation script.
* When a new broker is added to an existing Active Directory using the same licenseKey as the first broker, the license.json file on the new broker does not contain any licenseKey details. Instead, AdminX generates a new license for each broker/authproxy every time it is downloaded.
* An error is displayed during document enrollment for IAL2 in the SAML/OIDC authentication flow.
* A typo appears in the message shown upon clicking the **Download** button for the Login Activity Report in the **Reports > Login Activity** Reports section of AdminX.

### 1.10.17

*April 12, 2025*

#### New Features

**Restricting Access Based on Geo Location**

This feature is applicable only when end users attempt to authenticate via QR codes or push notifications using their 1Kosmos mobile application.

1Kosmos now offers the ability to restrict user access if they are not within the allowed radius of their trusted locations. Community administrators can configure this new geo-based restriction rule using the **Add New Adaptive Authentication Journey** drop-down menu under **Authentication > Adaptive Authentication**. While configuring the rule, administrators can define the allowed distance between the user's mobile location and their trusted location. During authentication, if the location of the user's device is not within the allowed range of their trusted location, access is denied. For more information, see[ Restricting Access Based on Geolocation](/authentication/admin-portal/authentication/restricting-access-based-on-geolocation.md).

{% hint style="info" %}
Community administrators must ensure that the users' AD attribute which carries the trusted location is mapped to the BlockID attribute (trustedLocation).
{% endhint %}

**Added Expired and Abandoned Statuses in ID Proofing**

1Kosmos now introduces two new statuses in ID proofing: **Expired** and **Abandoned**. These statuses can be viewed in the **Status** drop-down menu of the **Verification** tab in the AdminX interface. Additionally, the following changes have been implemented as part of this enhancement:

* Two new timestamps have been added: **expireSessionInMin** (time to start) and **abandonSessionInMin** (time to complete after starting). These timestamps distinguish between Expired and Abandoned sessions. The default time for the **expireSessionInMin** parameter is set to 7 days, while the **abandonSessionInMin** is set to 1 hour.
* Two new events, **E\_IDV\_SESSION\_EXPIRED** and **E\_IDV\_SESSION\_ABANDONED**, are triggered when the session is marked as Expired or Abandoned, respectively. For more information, see [ID Verification Events.](/identity-verification/core-concepts/event-reference.md)

**Ability to Configure Forced Re-Authentication for Service Provider (SP) Applications**

1Kosmos now provides community administrators with the ability to force re-authentication when accessing specified SAML/OIDC Service Provider (SP) applications. You can enable re-authentication with the introduction of the new **Force Re-authentication** setting in the AdminX interface under the **Applications** tab. By default, this setting is disabled. This feature prompts users to re-enter any required credentials for the relevant authentication journey, regardless of whether they are already logged in with the same authentication factors. The purpose of re-authentication is to ensure continued security and verify the user's identity at specific intervals, preventing unauthorized access by adding an additional layer of protection. For more information, see [SAML Application Integrations.](broken://pages/2GhsERJhvLPuGy2VIGMb)

#### Bug Fixes

* Fixed an issue where users received an 'Access Denied' message when attempting to access applications integrated with SAML SSO, despite the SAMLResponse being marked as Success.

### 1.10.16.01

*March 15, 2025*

#### New Features

**Adding Affidavit on Behalf of a User**

1Kosmos enables community/helpdesk administrators to add an affidavit to a user's web wallet, allowing them to become IAL2 certified users without the need to physically scan their documents, but instead rely on notarized physical copies to assert their identity. An affidavit in 1Kosmos is a declaration made by the administrators certifying the authenticity of another user's passport (PPT), Driving License (DL), or SSN. The administrator who creates the affidavit assumes responsibility for verifying the accuracy of the document. However, only administrators with the following permissions are authorized to add the affidavit. For more information, see [Bypassing Verification Using Notarized Documents.](/identity-verification/verification-methods/notarized-document-bypass.md)

{% hint style="info" %}
New users will no longer be required to enter a PIN.&#x20;
{% endhint %}

* user.affidavit.add
* users.view-user
* users.edit
* users.all-users

**Bypassing Authentication for Specific Applications**

1Kosmos now allows community administrators to configure an adaptive authentication flow that bypasses authentication for specific applications when users are within the designated network range.

As part of this enhancement, a new **Grant access** action has now been added under the Decision section when creating a new adaptive authentication journey. If the community administrator selects this action, it is mandatory to choose an application for which the journey will apply. This option is recommended for use with low-risk applications where the user does not need to be prompted for authentication within a corporate network. For more information, see [Adaptive Authentication.](/authentication/passwordless-for-web-apps/adaptive-authentication.md)

{% hint style="info" %}
Authentication cannot be bypassed for AdminX.&#x20;
{% endhint %}

**Filter Verification Results by Journey Name and UID**

Two new filters, **Journey Name** (DVCID) and **uid** filter, have been added to the **Verification > Verification** page allowing you to filter sessions and download more granular results. For more information, see [Verification Journey.](/identity-verification/core-concepts/verification-flow.md)

**Display of Appropriate Error Message for Missing Email on User Profile**

When a user attempts to download a report from the **Verification > Verification** page without an email address on their profile, the UI will validate the user's email. If no email is found, an error message will be displayed, notifying the user about the missing email address.

**Introduced Standardized Error Responses for User Access**

User enumeration is a security vulnerability that arises when an attacker can identify whether a specific username or account exists in a system based on its responses. To prevent user enumeration, the AdminX interface has now been enhanced to display the appropriate error codes and responses in the following scenarios.

The table below outlines the old and new error codes that will be displayed in the AdminX interface:

| Scenario                         | Old Error Message                                                                                      | New Error Message and Error Code                                                                                                                       |
| -------------------------------- | ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ |
| User is disabled                 | Your account has been disabled. Please contact your administrator                                      | You are not authorized to access. Error code: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX\<br>\<br>Here, XXXX indicates the privately encrypted ECDSA error code. |
| User not found                   | User not Found.                                                                                        | You are not authorized to access. Error code: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX\<br>\<br>Here, XXXX indicates the privately encrypted ECDSA error code. |
| User locked                      | Your account has been locked by an administrator. Please contact your administrator.                   | You are not authorized to access. Error code: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX\<br>\<br>Here, XXXX indicates the privately encrypted ECDSA error code. |
| User not authorized              | You are not authorized to access this page.                                                            | You are not authorized to access. Error code: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX\<br>\<br>Here, XXXX indicates the privately encrypted ECDSA error code. |
| User locked by a particular time | Your account has been temporarily locked for security reasons. Please try again in ${minutes} minutes. | You are not authorized to access. Error code: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX\<br>\<br>Here, XXXX indicates the privately encrypted ECDSA error code. |

### 1.10.15

*February 21, 2025*

#### New Features

**Configuring Authentication Journeys for Windows Workstation MFA Agent in AdminX UI**

The Windows Workstation MFA Agent can now support the creation of adaptive authentication journeys from AdminX. The adaptive authentication journey functionality has been enhanced, allowing administrators to configure (create, edit, or delete) authentication journeys through the AdminX interface under **Authentication > Adaptive Authentication**.&#x20;

The administrator can configure the following types of login journeys for workstation users:

* Password only
* Push
* QR
* FIDO
* Any OTP
* Password + Push
* Password + Any OTP
* Password + FIDO
* FIDO + Shared Account

The following events are captured on the Event Logs page:

* **E\_ADAPTIVEAUTH\_MODIFIED**: This event is triggered when the adaptive auth journey for Windows Workstation is modified.
* **E\_ADAPTIVEAUTH\_CREATED**: This event is triggered when the adaptive auth journey for Windows Workstation is created.
* **E\_ADAPTIVEAUTH\_DELETED**: This event is triggered when the adaptive auth journey for Windows Workstation is deleted.

**Customizing QR Code Design**

The Branding page in the AdminX interface has been enhanced, allowing administrators to customize the QR code design. You can upload a png or jpg file of size less than 10KB. The recommended size is 35px x 35px.&#x20;

**Ability to Download Verification Results**

The community administrator or users with the following permissions can download the report from the AdminX interface under the **Verification > Verification** page.

* idproofing.reports.verification-sessions-download
* idproofing.session-management

Download reports by filtering records based on document type, verification status, and the user who completed the verification process. If the report exceeds 2 million records, users will be prompted to refine their search.&#x20;

#### Bug Fixes

* An invalid Orion authenticator icon is displayed on the other user's profile.

### 1.10.14.01

*January 16, 2025*

#### New Features

**Ability to Authenticate with Kerberos**

Community administrators can now specify which users within a community are permitted to authenticate using Kerberos, granting them access to the AdminX interface. This can be configured through the **Kerberos Single Sign On** setting located under **Directory > Directory Integrations > \<Your AD> Advanced Configuration** to enable the Kerberos configuration. Additionally, the following new options have been introduced to configure the authentication journey.

* Kerberos
* Kerberos + Push
* Kerberos + Any OTP

### 1.10.14

*January 10, 2025*

#### New Features

**Ability to Login to a Tenant Using Passcodes from Other Channels**

When initiating an authentication journey with a Password & any OTP as the authentication methods, a new **Already have a passcode?** link will appear on the **Sign In – Choose an authentication method** page. This feature allows users to bypass generating a new OTP each time they authenticate using their profile OTP.

**IAL2 Device Removal Warning**

When an end user attempts to remove an IAL2 authenticated device from the **Devices** tab under **My Profile**, a warning message is displayed to the user alerting them of the impact of removing the device. This warning is crucial as it ensures uninterrupted access to applications that require higher levels of identity verification.

### 1.10.13.01

*December 14, 2024*

#### New Features

**Enabling End Users to Manage Phone Numbers**

1Kosmos now enables end users to add or remove their phone numbers directly through the AdminX interface. This functionality enables end users to make updates to phone numbers on demand and enables them to receive passcodes to new numbers. To allow end users to link their mobile numbers, community administrators must enable the new **Allow users to enroll mobile / landline number** setting under **Authentication > Multi-factor Authentication > Enroll Phone Number**. After enabling this setting, a new **Add Phone Number** button is displayed under the **My Profile** tab, using which end users can associate their phone numbers.&#x20;

**Ability to Onboard First Time Login Users through BlockID App**

Upon first-time login with a password, users will be prompted to enroll for passwordless access through the BlockID app, allowing them to go passwordless from day one.

**Prerequisite:** Community administrators must have enabled the new **Passwordless Access on BlockID App** setting in the **Initial Sign in MFA Enrollment policy** section under the **Authentication > Enrollment Preferences** tab.

**Generating Onboarding Invite on Behalf of Another User**

Community administrators or helpdesk administrators with the **user.generate.qr** permission can generate a QR code on behalf of another user, enabling them to onboard devices in the user's presence. In addition to the **user.generate.qr** permission, helpdesk administrators will also need the following permissions to generate the QR code. This option is recommended for scenarios where user onboarding needs to be controlled, requiring users to enroll in the presence of an administrator.

* users.all-users
* users.view-user
* users.edit

For more information, see the *Generating Onboarding Invites on Behalf of Another User* section in [User Management](/authentication/admin-portal/user-management.md).

**Introduced Skip MFA for LDAP Service Accounts in Auth Proxy**

With the introduction of the **Skip MFA for Service Accounts** section in Auth Proxy, community administrators can now specify which service accounts for LDAP can bypass MFA. By specifying the accounts that must skip MFA, community administrators can directly grant access to such accounts with just a username and password. For more information, see [Auth Proxy for LDAP Server.](/authentication/authentication-proxy/ldap-setup.md)

**Enhanced the QR Code Design**

The design of the QR code on the following pages has been enhanced for better UX.

* Login Page
* Enrollment on first time login
* Onboarding from My Devices page
* Self-registration

**Onboarding Accounts Via Orion Authenticator for Windows**

1Kosmos has extended its capability of onboarding accounts on Windows machines through the introduction of the new Orion Authenticator for Windows agent. With this enhancement, Windows end users can themselves seamlessly onboard their relevant accounts and generate passcodes, providing a unified behavior for both Windows and Mac users. For more information, see[ Orion Authenticator.](/authentication/orion-desktop-authenticator/overview.md)

**Introduced New Verification Status in ID Proofing**

In certain situations, fraud verification may return a **Not Performed** result. This generally occurs when the user fails to capture clear, high-quality images. To enhance tracking and provide more accurate verification insights, a new status, **Verification Not Performed**, has been introduced. This status helps to distinguish cases where fraud verification could not be completed due to poor image quality and also enables businesses to analyze verification trends more effectively. The **Verification Not Performed** status will appear under the following circumstances:

* When the verification process is partially completed.
* When the front side of the document is processed, but it's unclear whether there is a backside to the document.
* When the document extraction process fails.
* When an unsupported document is submitted for verification.

For more information, see [Verification Journey](/identity-verification/core-concepts/verification-flow.md).

#### What is Deprecated?

* The **Edit Template** button in the **Preview Invitation** section has been removed when sending a passwordless invitation to users.
* The hyperlink with 1Kosmos has been removed from the footer of the login page.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.1kosmos.com/authentication/admin-portal/release-notes-for-adminx.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
