Beyond Identity began deployment of a new Secure Work software release on October 7, 2026.
Microsoft Entra External Authentication Method (EAM)
Beyond Identity can now be used as an External Authentication Method in Microsoft Entra ID, so sign-ins to Entra-protected resources can require a Beyond Identity passkey as the additional authentication factor.
| Feature | Feature Description |
|---|---|
| Entra EAM Sign-In | Entra hands the user to Beyond Identity for the additional factor and receives the result back, including for tenants moving to the new platform. |
| Automatic User Matching | The Entra user is matched to their Beyond Identity identity using the login hint Entra sends, resolved once and held for the whole sign-in. |
| Verified Entra Requests | The identity hint Entra sends is verified against the tenant’s configured trust anchor before Beyond Identity accepts it. |
What’s New
| Feature | Feature Description |
|---|---|
| Authenticator Retirement Warning | Users signing in with an authenticator version that is retired or will soon be retired now see a notice during sign-in prompting them to update. |
| New Console Experience | The “Try our new console experience” button signs administrators into the new console without a second login, including tenants that use only Beyond Identity authentication. |
| Device Posture in ID Tokens | Device posture information can now be returned to the relying party as claims in the OIDC ID token on successful authentication. |
| Per-Application Attribute Release | You can now configure which user attributes are released to each OIDC application. |
Enhancements
| Enhancement | Description |
|---|---|
| FIDO2 Access Restrictions | You can now restrict FIDO2 authentication by group, user, and source IP address, the same way roaming authentication can already be restricted. |
| PIN-Less FIDO2 Enrollment | Administrators can configure FIDO2 authenticators so users can enroll a security key without being prompted for a PIN, including from the user portal. FIDO2 settings are now also reflected in exported events. |
| Clearer FIDO2 Button | The FIDO2 option on the “Select another method” screen now names the credential instead of calling it a biometric. |
| Authenticator Type in Events | Authentication events now record whether a platform authenticator or FIDO2 was used. |
| Stronger Certificate Validation | Improved validation of smart card certificate requests, including verifying that the user principal name matches the directory and rejecting requests that ask to become a certificate authority. Certificate lookups are now authenticated and scoped to the tenant. |
| YubiKey Secrets Protected | Improved protection of YubiKey PUK and PIV management key values so they are no longer exposed in plaintext. |
| Sign-In Reliability During Transition | Improved reliability of sign-in for tenants moving to the new platform by caching signing keys instead of fetching them on every request. |
| Tenant Checks on SAML and WS-Fed | Improved tenant verification when completing SAML and WS-Fed sign-ins on the transition path. |
| Transition Default for New Tenants | New Secure Work tenants now default to the transition flow to the new platform. |
| Authenticator Version Collection | Authenticator version is now collected by default for platform authentication, so policies can use it. |
| Updated Minimum OS Versions | The downloads page now lists the updated minimum OS versions for the v3 authenticator (macOS 14 and iOS 26). |
| Token Expiry Enforced | Improved token validation so expiration and not-before times are now enforced. |
| Government Build Key Storage | Improved security for government builds, which no longer fall back to software-backed credential keys. |
| Clearer Sign-In Error Codes | Improved error responses so sign-in problems caused by the user or client no longer report as server errors. |
Bug Fixes
| Bug Fix | Description |
|---|---|
| Smart Card Logon Failures | Resolved an issue where smart card logon could fail because a certificate revocation list had no next-update time and was treated as expired. |
| OIDC Sign-In During Transition | Resolved an issue where PKCE parameters were lost during the move to the new platform, breaking OIDC sign-in with providers such as Google Workspace. |
| Interrupted Authentication | Resolved an issue where repeating a sign-in request could end an authentication already in progress. |
| Blank Activity Page | Resolved an issue where a single unrenderable event could blank the entire Activity page. |
| Internal Events in Activity | Resolved an issue where internal events and fields were visible on the Events page for every tenant. |
| Missing Correlation ID | Resolved an issue where policy events in a Secure Work sign-in showed a correlation ID of N/A. |
| Android In-App Sign-In | Resolved an issue where launching the authenticator from an embedded web view on Android could fail. |
Comments
0 comments
Please sign in to leave a comment.