Beyond Identity has released version 2.114.0 of the Commercial Cloud, covering Secure Work and Secure Access.
Secure Work
Early Access: Workspace ONE and CrowdStrike On-Demand Device Posture at Enrollment
Device-posture data from MDM and endpoint-security partners can now be fetched live at enrollment rather than only from the background polling cache. This capability is not available for all customer tenants; our support team can help you determine if your tenant is compliant should you choose to enable this.
Previously, a brand-new device that the poller had not yet picked up read as missing or stale, so posture rules evaluated against absent or outdated data. Enrollment now requests a fresh read, and the service fetches that single device directly from the provider, stores the result, and returns it.
This feature is opt-in only. Please contact support if you would like it turned on for your tenant.
| Feature | Description |
|---|---|
| Fresh Posture at Enrollment | Enrollment and add-device requests read device posture directly from the partner integration instead of relying on whatever the background poll had already collected. A device enrolled minutes after it appears in the MDM is now evaluated against its real posture rather than against a missing record. |
| Supported Integrations: Workspace ONE and CrowdStrike Only | VMware Workspace ONE and CrowdStrike only. An integration must expose a single-device lookup for on-demand reads; where it does not, posture continues to be served from the cache exactly as before. |
Early Access: FIDO2 / WebAuthn Security Keys — Improvements
Follow-up work on the FIDO2 / WebAuthn early-access feature introduced in 2.113.0.
| Improvement | Description |
|---|---|
| Security-Key Sign-In Works from More Places | We fixed an issue where security key logins were not working to the Beyond Identity Admin Console and certain protected resources. |
| More Reliable Sign-In Completion | Improved consistency of the FIDO2 challenge across every sign-in path, resolving intermittent failures at the final step — including for tenants mid-transition between platform versions. |
| Roaming Settings Honored During Transition | Resolved an issue where an application’s roaming authentication configuration was not applied for tenants mid-transition, affecting self-remediation on Platform Authenticator + FIDO2 configurations. |
| Policy Requirements Fail Closed | Resolved an issue where a policy requirement that could not be evaluated was reported as satisfied. It is now treated as unmet. |
What’s New
| Feature | Description |
|---|---|
| Read Scopes for Client Credentials | Secure Work client-credential tokens can now be issued with read scopes. |
Bug Fixes
| Bug Fix | Description |
|---|---|
| Faster User and Group Lists | Improved directory query performance so user lists, counts, and paging stay responsive on large tenants. |
| Passkey Enrollment Email | Resolved an issue where sending a passkey enrollment email failed for tenants without an Admin Console application configured. |
| Inbound OIDC Configuration List | Resolved an issue where the inbound OIDC configuration list returned an error on tenants with an incomplete configuration. |
| Authenticator Version Control | Resolved an issue where 3.x authenticator releases appeared in the version-control dropdown for tenants on the 2.x authenticator. |
| Banner Removed | Removed the Ceros promotional banner from the Secure Work Console. |
Secure Access
Bug Fixes
| Bug Fix | Description |
|---|---|
| Certificate Revocation Checking | Resolved an issue where the certificate authority’s feature configuration was not supplied in any environment, leaving revocation-list behavior stuck on its fallback rather than the configured setting. |
| Event History No Longer Shows False Timeouts | Resolved an issue where successful authentications could also emit a timeout event, so exported events and dashboards reported failures that did not occur. |
| More Reliable Event Export | Improved event delivery so a slow downstream consumer no longer holds up the services producing events, and copy jobs recover automatically from an interrupted connection. |
| Clearer API Error Responses | Resolved an issue where requests that failed for a specific, reportable reason returned a generic server error instead. Callers now receive the accurate status code. |
| Inactive Users Correctly Refused | Resolved an issue where the inactive-user rule was not enforced on secure-customer realms. |
| Slow Downloads Complete | Resolved an issue where a slow download from the downloads page could be cancelled before it finished. |
| Correct Regional Endpoint | Resolved an issue where the console used a single shared gateway address across production US and EU rather than the correct regional one. |
| Certificate Renewal Without Interruption | Improved TLS certificate handling so renewals are picked up without restarting the service. |
| Filters and Page Size | Resolved an issue in the Secure Access Admin Console where resetting filters did not clear all applied criteria, and aligned page-size behavior across list pages. |
Comments
0 comments
Please sign in to leave a comment.