---
title: "Axiad Conductor Release Notes"
slug: "axiad-conductor-release-notes"
updated: 2026-06-09T02:42:36Z
published: 2026-06-09T02:42:36Z
canonical: "docs.axiad.com/axiad-conductor-release-notes"
stale: true
---

> ## Documentation Index
> Fetch the complete documentation index at: https://docs.axiad.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Axiad Conductor Release Notes

## June 5th 2026

### AirLock 2.5

#### Features

**PM-13505** – Direct users to enroll a FIDO2 security key after weak authentication

When a user signs in to Windows with a weaker authentication method (such as a password), AirLock can now redirect them to the user portal to enroll a FIDO2 security key. This helps organizations move users onto phishing-resistant credentials automatically at the point of login.

**PM-11360** – Certificate filtering

AirLock can now be configured to evaluate only the certificates that are relevant for smart card logon, rather than every certificate present on the device. This prevents users who hold extra, unrelated, or expired certificates from being caught in unnecessary renewal or authentication prompts. Filtering is off by default and can be scoped using any combination of the options below.

**PM-13102** – Filter certificates by issuer

Adds a new policy option that lets administrators specify which certificate issuers AirLock should consider, using pattern matching. Disabled by default.

**PM-13103** – Filter certificates by Authority Key Identifier (AKID)

Adds a new policy option to include only certificates that match a specified Authority Key Identifier. Disabled by default.

**PM-13104** – Filter certificates by Enhanced Key Usage (EKU)

Adds a new policy option to include only certificates that carry a specified Enhanced Key Usage. Disabled by default.

**PM-11077 / PM-13108** – Configurable grace delay for network connectivity at login

AirLock can now wait a configurable period for network connectivity before launching the portal browser, instead of failing immediately when a device is briefly offline at login (for example, while a VPN or proxy is still starting). Administrators set the maximum number of seconds to wait; AirLock proceeds as soon as connectivity is detected. The default is zero (disabled).

#### Enhancements

**PM-8687** – Idle timeout now respects in-progress card issuance

AirLock no longer ends a session for inactivity while a credential or card issuance is still in progress, preventing interruptions during issuance operations that run longer than the configured idle limit.

**PM-17879** – Visual C++ Redistributable bundled in the kiosk installer

The Microsoft Visual C++ Redistributable is now included in the AirLock kiosk installer, so administrators no longer need to install it separately as a prerequisite.

**PM-9860** – Removed the deprecated kioskLogicCard=Always setting

The unused kioskLogicCard=Always option has been removed. No action is required for existing deployments.

#### Bug Fixes

**PM-19299** – Kiosk now auto-exits on idle as configured

Resolved an issue where the configured KioskIdleExitSeconds timeout was ignored, causing the kiosk not to exit automatically after the idle period. Idle auto-exit now behaves as configured.

**PM-13988** – Kiosk enforcement no longer applied to exempt local accounts

Resolved an issue where AirLock incorrectly applied kiosk enforcement to local non-administrator accounts that should have been exempt.

**PM-10610** – Customized branding/splash message now displays correctly

Resolved an issue where a customized "Checking Policy" splash message did not reflect the administrator-configured wording. Custom branding messages now display as configured.

## June 2th 2026

### **Conductor HI**

***UCMS 4.31.4***

#### **Enhancements**

**PM-19136 – New "Offline unlock key" option for VSC credential profiles.** Added a new **Offline unlock key** option to the VSC (virtual smart card) credential profile that controls which master customer admin key is used to generate the PUK during offline unlock. Previously, when both TDES and AES master customer admin keys were configured, the offline unlock always selected the AES key. Administrators can now explicitly choose **AES** (default, preserves existing behavior) or **TDES** when both keys are present. The option is only shown when both keys are configured.

#### **Bug Fixes**

**PM-19530 – DPC CSR did not include all values when a DN attribute appeared more than once.** Resolved an issue where, when a PIV Distinguished Name contained multiple instances of the same attribute (for example, two OU fields), only the second value was pulled into the Derived PIV Credential (DPC) CSR. All values for repeated attributes are now retrieved correctly.

**PM-18207 – Unsupported key algorithm on a Microsoft CA certificate template.** Resolved an issue with the handling of Microsoft Certificate Authority (MSCA) certificate templates configured with a key algorithm that UCMS did not previously support.

**PM-19509 – UCMS healthcheck intermittently reported a CA-server connection failure.** Resolved an issue where the UCMS healthcheck call occasionally returned *"Unable to connect to CA server. Key not found"* even when the CA connection was healthy.

**PM-19384 – HSM invalid-credential warning counter now decrements correctly.** Resolved an issue where the warning message shown while editing an HSM configuration with an invalid Partition User continued to display the same remaining-attempts count instead of decrementing after each failed authentication attempt. The counter now decrements correctly on repeated failures. This was previously listed as a Known Limitation in UCMS 4.31.3.

## **May 22, 2026**

### **Conductor HI**

***U******CMS 4.31.3***

This hotfix release resolves an IdenTrust certificate lifecycle issue that was preventing certificate renewals on cards holding an expired IdenTrust certificate. No Unified Portal update is required; this release pairs with the currently published UP 2.26.1.

#### **Bug Fixes**

PM-19328 – Expired IdenTrust certificate could not be revoked, blocking renewal of other certificates on the card. Resolved an issue where an IdenTrust certificate that had reached its expiration date could not be suspended or revoked from the Conductor portal. Because the expired certificate remained associated with the card in an unrevoked state, subsequent attempts to renew other certificates on the same card failed. Administrators and end users can now revoke expired IdenTrust certificates and complete card certificate renewals as expected.

## May 21, 2026

### Conductor Browser Extension 1.9.0

#### **Prerequisites**

- Axiad Conductor UCMS 4.31 or later (for Virtual Smart Card minimum PIN length below 8 characters)
- Axiad Conductor OS Bridge 1.9.0 or later (for Virtual Smart Card minimum PIN length below 8 characters)

#### **Enhancements**

**PM-16556 / PM-16557 – Support for Virtual Smart Card minimum PIN lengths of 6 or 7 characters.** Aligned with the Windows OS Bridge, the macOS OS Bridge now supports Virtual Smart Card profiles configured for PINs as short as 6 characters in Conductor (UCMS 4.31 or later).

## **May 15, 2026**

## **Conductor HI**

***UCMS 4.31.2, UP 2.26.1***

This release introduces globally unique smart-card identification for IDEMIA OCSv8 cards, expands Derived PIV Credential (DPC) issuance with sponsor-device certificate attributes, and lowers the minimum Virtual Smart Card (VSC) PIN length to 6 characters. It also adds an administrator-selectable master key for VSC offline PUK generation, extends AWS CloudHSM v5 support with configurable connection modes, and ships several third-party dependency updates that resolve security findings, alongside targeted bug fixes for Mobile PKI, FIDO, audit logging, DPC workflows, and EJBCA configuration.

#### **Features**

**PM-18314 – Globally Unique Card Identification (CUUID) for IDEMIA OCSv8**

IDEMIA OCSv8 cards can now be identified using **CUUID** (a globally unique identifier per physical card) instead of the legacy **CUID** derived from CPLC. Because CUID is not guaranteed to be unique across cards, customers issuing IDEMIA OCSv8 at scale could occasionally encounter collisions during enrollment; CUUID eliminates this class of issue.

A new **Legacy Unique Identifier (CUID)** checkbox has been added to the OCSv8 Credential Profile configuration:

- For **existing** Credential Profiles, the checkbox is **checked by default** — legacy CUID behavior is preserved with no change in behavior.
- For **new** OCSv8 Credential Profiles, the checkbox is **unchecked by default** — new enrollments use CUUID.
- The toggle is **one-way**: once a Credential Profile is saved in CUUID mode, it cannot be reverted to legacy CUID mode.

When CUUID mode is enabled, card-present interactions perform CUUID-first resolution with CUID fallback to preserve compatibility with existing inventory.

**PM-17838 – Sponsor Device Certificate Attributes as Mobile PKI Inputs**

Administrators can now reference **sponsor device certificate attributes** in certificate templates used for Mobile PKI Derived PIV Credential (DPC) issuance. Workflow and certificate-template fields (SAN and Subject DN/RDN) accept a new `sponsor.&lt;element&gt;.&lt;sub-element&gt;[.&lt;qualifier&gt;][index]` syntax that resolves at issuance time from the sponsor device’s certificate.

This unblocks Derived PIV Credential use cases that require the **derived PIV Authentication SAN** to include the `uniformResourceIdentifier` UUID encoded as a URN per RFC 4122, and reduces configuration errors across DPC workflows. Saving a workflow that contains a `sponsor.*` variable but has no sponsor configured is blocked with a clear validation error.

**PM-16556 – Virtual Smart Card 6-Character Minimum PIN**

The Virtual Smart Card (VSC) Credential Profile now supports a minimum PIN length of **6** characters (previously restricted to 8), aligning VSC PIN policy with other device types and supporting Windows compatibility scenarios.

> [!NOTE]
> **Prerequisites:** Conductor OS Bridge **v1.9.0** or later **and** Conductor Browser Extension **v1.9.0** or later. Both components must be upgraded for 6-digit PIN issuance to work end-to-end. Existing Credential Profiles configured with PIN length 8 or above are unaffected. These components will be available by the time of the release.

#### **Enhancements**

**PM-17945 – Always Redirect to IdP on Expired SSO Session**

When a user’s SSO session expires inside the Unified Portal, UP now consistently redirects them to the configured Identity Provider for re-authentication and returns them to the screen they were on. This applies to GET, POST, PATCH, and GraphQL calls (including credential search), removing prior cases where an expired session surfaced as an error or stale state instead of a clean re-auth.

**PM-19136 – Configurable master key for Virtual Smart Card offline PUK generation**

The Virtual Smart Card (VSC) Credential Profile now exposes a new **Offline unlock key** option that controls which master customer-admin key is used to generate the PUK for the offline unlock challenge/response flow. Previously, when both a TDES master key label and an AES master key label were configured on the Credential Profile, the offline unlock always defaulted to AES, which did not match every customer's key-management policy.

The new option is only presented and applied when **both** a TDES master customer-admin key **and** an AES master customer-admin key are configured on the Credential Profile. It accepts two values:

- **AES** (default) — preserves the existing offline-unlock behavior.
- **TDES** — uses the TDES-derived customer-admin key to generate the PUK.

Credential Profiles configured with only one master key are unaffected, and existing Credential Profiles continue to behave as before until the new option is set.

PM-19162 – AWS CloudHSM v5 client supports explicit or implicit connection modes

UCMS configuration for AWS CloudHSM (client v5) now supports both explicit and implicit connection modes, selectable through configuration. Axiad will adjust this setting to run in the most optimized way for each customer.

#### **Bug Fixes**

**PM-17937 –** Resolved an issue where Mobile PKI certificates revoked manually in the Unified Portal were not being written to the published Certificate Revocation List (CRL). Revocations triggered by device updates were correctly captured; manual revocations are now also included.

**PM-17849 –** Restored audit logging for Mobile PKI certificate update operations. Update actions now produce audit entries containing user ID, device information, timestamp, and operation outcome.

**PM-18043 –** Restored audit logging for MDM enforcement actions (Enable, Disable, and Secret Rotation), which were previously not captured in the audit trail.

**PM-17674 –** Resolved an issue where FIDO2 credential issuance failed with the error “The Identity Provider was unable to process the request,” preventing the credential from appearing under the user’s identities even when the underlying registration in Entra ID had completed.

**PM-17594 –** When a Derived PIV Credential (DPC) issuance failed at WidePoint due to workflow configuration, the failure now surfaces a clear error message in the Unified Portal and Axiad ID instead of completing silently with only a backend stack trace.

**PM-17851 –** Added a clear UI error message when an operator attempts to issue a Derived Credential using the same PIV card (or a new card) for a user whose mobile already has an assigned credential.

PM-19029 – Resolved an issue where `UPN` and other `otherName` SAN attributes read from a sponsor device's PIV certificate could not be used for evaluation or matching in a Derived PIV Credential workflow. Workflow expressions of the form `sponsor.auth.san.(&lt;OID&gt;)` now resolve correctly during issuance.

PM-19109 – Resolved an issue where the **Authority ID** value was not preserved when editing an EJBCA Credential Server configuration, and could appear pre-populated when creating a new EJBCA Credential Server. The Authority ID now persists exactly as entered and is empty by default for new configurations.

PM-19017 – Restored the *Get prepared* screen prompt during Derived PIV Credential enrollment and update, which now correctly indicates that a PIV card must be inserted and available before the user can continue. This addresses a regression introduced in UCMS 4.31.

#### **Security Fixes**

**PM-18471 –** Addressed vulnerabilities: [CVE-2026-29145](https://www.cve.org/CVERecord?id=CVE-2026-29145), [CVE-2026-34500](https://www.cve.org/CVERecord?id=CVE-2026-34500), [CVE-2026-29129](https://www.cve.org/CVERecord?id=CVE-2026-29129), [CVE-2026-24880](https://www.cve.org/CVERecord?id=CVE-2026-24880).

**PM-18084 / PM-18085 –** Addressed vulnerability: [CVE-2026-22733](https://www.cve.org/CVERecord?id=CVE-2026-22733).

**PM-18825 –** Addressed vulnerabilities: [CVE-2026-34478](https://www.cve.org/CVERecord?id=CVE-2026-34478), [CVE-2026-40973](https://www.cve.org/CVERecord?id=CVE-2026-40973), [CVE-2026-34480](https://www.cve.org/CVERecord?id=CVE-2026-34480).

**PM-18478 –** Addressed vulnerabilities: [CVE-2026-40477](https://www.cve.org/CVERecord?id=CVE-2026-40477), [CVE-2026-2332](https://www.cve.org/CVERecord?id=CVE-2026-2332).

**PM-18269 –** Addressed vulnerability: [CVE-2026-4800](https://www.cve.org/CVERecord?id=CVE-2026-4800).

**PM-18206 –** Addressed vulnerability: [CVE-2025-8671](https://www.cve.org/CVERecord?id=CVE-2025-8671).

**PM-18145 –** Addressed vulnerability: [CVE-2026-22732](https://www.cve.org/CVERecord?id=CVE-2026-22732).

**PM-18826** **–** Addressed vulnerability: [CVE-2026-34477](https://www.cve.org/CVERecord?id=CVE-2026-34477).

**PM-19159 –** Addressed vulnerability: [CVE-2026-41284](https://www.cve.org/CVERecord?id=CVE-2026-41284).

**PM-18951, PM-18205, PM-18268 –** Upgraded additional UCMS and Unified Portal dependencies to address issues identified through routine security scanning for which CVE identifiers had not yet been assigned at the time of release.

#### **Known Limitations**

**PM-18472 –** Credential issuance using YubiKey 4 with IdenTrust CA fails during the certificate import phase. The CSR is generated and submitted successfully, but the process fails with an error indicating the CSR/PKCS#10 is invalid and the certificate cannot be imported. YubiKey 5 and YubiKey 5.7.1 devices are not affected.

**PM-18948 –** When MDM eligibility validation blocks a Derived Credential issuance (for example, due to an invalid or missing shared secret), the backend correctly stops the issuance, but no email notification is sent and the mobile app shows only a generic error.

**PM-18923 –** When a user already has an active Mobile PKI / DPC device and an issuance is attempted again, the resulting error message is inconsistent between the Help Desk view and the end-user *My Identities* view.

**PM-18645 –** In some flows, the Mobile PKI issuance UI may display a success state before the QR code has actually been scanned by the device.

**PM-17351 –** Certificates listed under a DPC device (PIV or Mobile PKI) are not sorted by default; active and revoked certificates may appear interleaved.

### OS Bridge 1.9.0 for Windows

#### **Prerequisites**

- Axiad Conductor UCMS 4.31 or later (for Virtual Smart Card minimum PIN length below 8 characters)
- The Microsoft Visual C++ Redistributable is no longer a prerequisite — it is now bundled with the OS Bridge installer (see Enhancements)

#### **Enhancements**

**PM-17518 – Microsoft Visual C++ Redistributable now bundled with the OS Bridge installer.** The Axiad Virtual Smart Card service depends on the Microsoft Visual C++ runtime libraries. These libraries are now installed automatically alongside the OS Bridge service, so customers no longer need to install the Visual C++ Redistributable separately on the endpoint. The installer runs cleanly on a Windows machine that does not have the runtime pre-installed.

**PM-16556 / PM-16557 – Support for Virtual Smart Card minimum PIN lengths of 6 or 7 characters.** OS Bridge for Windows now supports the issuance of Virtual Smart Cards with a minimum PIN length below the previous 8-character floor, enabling administrators to align Virtual Smart Card PIN policy with other token types. The minimum PIN length is configured in the Credential Profile in Conductor (UCMS 4.32 or later); existing profiles and already-issued credentials retain their current PIN policy.

#### **Bug Fixes**

*None reported in this release.*

### **OS Bridge 1.9.0 for macOS**

#### **Prerequisites**

- Axiad Conductor UCMS 4.31 or later (for Virtual Smart Card minimum PIN length below 8 characters)

#### **Enhancements**

**PM-16556 / PM-16557 – Support for Virtual Smart Card minimum PIN lengths of 6 or 7 characters.** Aligned with the Windows OS Bridge, the macOS OS Bridge now supports Virtual Smart Card profiles configured for PINs as short as 6 characters in Conductor (UCMS 4.31 or later).

#### **Bug Fixes**

*None reported in this release.*

## **April 21, 2026**

### **Conductor HI**

***UCMS 4.30.4***

This release introduces FIPS 140-3 Level 3 HSM compliance for Thales IDPrime MD 830/MD831 and Virtual Smart Card operations, along with security dependency upgrades and targeted bug fixes.

#### **Features**

**PM‑18624 – FIPS 140-3 Level 3 HSM Support for Thales IDPrime MD 830/MD831 and Virtual Smart Card Operations**

Axiad Conductor now supports FIPS 140-3 Level 3 Hardware Security Modules (HSMs) for Thales IDPrime MD 830/MD831 and Virtual Smart Card credential flows. Legacy 3DES/TDES cryptographic operations on Axiad hosted HSM have been eliminated and replaced with AES-based key derivation, bringing these card types into compliance with current FIPS standards.

Existing Thales IDPrime MD 830/MD831 and Virtual Smart Card devices remain fully operational through a backward-compatible fallback mechanism. New Virtual Smart Cards will use AES-based key derivation and are fully FIPS 140-3 compliant. However, Thales IDPrime MD 830/MD831 hardware does not support AES, and issuance of new cards of this type will no longer be supported after the migration is complete (early May 2026).

A one-time backend key migration will be performed by Axiad for all existing device inventories — no customer action is required.

- Virtual Smart Cards in the FedRAMP environment will be migrated during Friday’s April 24th 2026 maintenance window.
- Thales IDPrime MD 830/MD831 and remaining Virtual Smart Card migrations will follow in the coming weeks.

#### **Enhancements**

*(No bug fixes included in this release.)*

#### **Bug Fixes**

*(No bug fixes included in this release.)*

#### **Security Fixes**

**PM‑18450 –** Upgraded dependencies to address the following vulnerabilities:

- CVE-2026-22733 (Spring Boot Actuator)
- CVE-2026-29145, CVE-2026-34500, CVE-2026-29129, CVE-2026-24880 (Apache Tomcat)

#### **Known Limitations**

**PM‑18472 –** Credential issuance using YubiKey 4 with IdenTrust CA fails during the certificate import phase. The CSR is generated and submitted successfully, but the process fails with an error indicating the CSR/PKCS#10 is invalid and the certificate cannot be imported. YubiKey 5 and YubiKey 5.7.1 devices are not affected.

## **March 30, 2026**

### **Conductor HI**

***UCMS 4.30.2, UP 2.25.2***

This release focused on security compliance updates, log data protection, and third-party dependency updates. This release resolves a credential profile save error and upgrades several backend libraries to address known issues.

This update addresses the following Common Vulnerabilities and Exposures (CVEs):

- **CVE-2026-22737** – A medium-severity path traversal vulnerability in Spring Framework that could allow an attacker to read arbitrary files accessible to the application
- **CVE-2026-22732** – A vulnerability in Spring Security that causes certain HTTP response headers to not be delivered to the client, potentially undermining security policies
- **CVE-2026-33871** – A high-severity Denial of Service vulnerability in Netty that allows a remote attacker to exhaust server resources via a flood of HTTP/2 frames

### **Features**

*(No new features introduced in this release)*

### **Bug Fixes**

**PM‑18041 –** Users were unable to save the "Axiad ID iOS" Credential Profile due to a permission validation failure and a duplicate name conflict occurring simultaneously.

### **Known Limitations**

*(No known limitations reported for this release)*

## **March 24, 2026**

### **Conductor HI**

***UCMS 4.30.1, UP 2.25.1***

This release focused on security compliance updates, PKI client improvements, and targeted bug fixes.

### **Features**

*(No new features introduced in this release)*

### **Bug Fixes**

**PM‑17814 –** Resolved an issue where the Back button on the Mobile PKI PIV card PIN entry screen was visually rendered but not clickable, preventing users from navigating back to cancel or correct a prior step.

**PM‑17596 –** Resolved an issue where FIDO2/Passkey registration failed with the error "The Identity Provider was unable to process the request," even when the passkey was successfully registered in Entra ID. The credential was not being reflected in the UP (My Identities) view.

**PM‑17866 –** We upgraded our internal logging component to a newer, more secure version. This update strengthens overall system security and helps protect customers.

**PM‑18013 –**The link to the help documentation displayed during Mobile PKI issuance was previously hardcoded. It is now configurable, allowing customers to override the link to point to their own or localized documentation resources.

### **Known Limitations**

*(No known limitations reported for this release)*

## **March 6, 2026**

### **Conductor HI**

  

***UCMS 4.29, UP 2.24***

This release introduces significant enhancements to role management, identity verification, HSM support, and portal customization. These updates improve administrative control, strengthen security governance, and increase flexibility across the Axiad platform.

Major highlights include:

- Unified Portal branding configuration for default table column visibility
- Comprehensive improvements aligned with the Role Management modernization initiative

### **Features**

- **PM-16894 — Dynamic Role Management with Fine-Grained Access Control**

The Axiad Conductor Role Management framework now supports fine-grained access control with dynamic, rule-based role assignment and context-aware scoping using attribute-driven logic. This enables organizations to automate role assignment, enforce consistent governance, and define sophisticated access boundaries.
  - **Administrators can now define:**
    - **Role Mapping Rules** — Determine which users receive a given role based on SCIM attributes, directory attributes, or group membership.
    - **Scope Rules** — Define which users an operator role grants access to manage.
    - **Priority** — Control evaluation order when multiple rules apply; the highest-priority matching rule is applied.
  - **Key capabilities include:**
    - Logical AND/OR operators for complex rule criteria
    - Automatic rule evaluation at login for accurate, real-time role and scope assignment
    - Manual assignments that override rule-based assignments
    - Updated permission model preventing self-privileged actions
    - Migration support for existing manual "bindings" to rules for Axiad Conductor SaaS

### **Enhancements**

- **PM-17425 — Default Country Fallback for Identity Verification**

*Configuration > Verification Server*

A new **Default Country** field has been added to the Verification Server configuration. Administrators can now define an organization-wide fallback country using a 3-letter ISO 3166-1 alpha-3 country code (e.g., `USA`, `GBR`, `DEU`).

This eliminates identity verification failures for users who are missing a country attribute in their profile.

- **PM-17220 — Branding-Based Table Column Visibility**

The Unified Portal now supports configuring default table column visibility through `branding.json`. Administrators can define which columns are shown or hidden by default for each table across the portal, enabling a tailored interface experience aligned with organizational preferences.

### **Bug Fixes**

*(No bug fixes included in this release.)*

### **Known Limitations**

- Role mapping rules support logical AND/OR operators; parentheses are required for complex rule expressions.
- Role evaluation occurs at login; changes to rules take effect upon the user's next login session.
- Reports page crashes on refresh with "Cannot read properties of undefined (reading 'find')" error.
- Confirm: Email verification fails silently; modal remains open with buttons disabled after submission.

# **January 27, 2026**

### UP 2.21.1

#### **Features**

*(No new features introduced in this release)*

#### Bug Fixes

**PM‑17153 –** We fixed an issue in the Help Desk Portal where some expected UI elements were missing, and others appeared unexpectedly, ensuring the page now displays clearly and works as intended.

**PM-17150** **–** We resolved an issue where refreshing the Help Desk page incorrectly showed a “Forbidden” error, ensuring the page now reloads smoothly and works as expected.

#### **Known Limitations**

*(No known limitations reported for this release)*

## January 20 2026

### Conductor HI

*UP 2.21/UCMS 4.26*

#### Features

This release significantly advances Axiad’s identity assurance and recovery capabilities by tightly integrating **identity verification, self-service recovery, directory integration, and operator controls** directly into Axiad Conductor workflows. Together, these enhancements reduce help desk dependency, improve security posture, and give administrators fine-grained control over how identity verification drives access recovery and onboarding outcomes.

At a high level, the release delivers four major value pillars:

1. **Secure, Privacy-Preserving Self-Service Account Recovery**

This release introduces a **public, unauthenticated recovery entry point** that allows users to securely initiate account recovery without revealing whether an account exists.

Users submit a configured identifier and, if valid, receive an email that triggers a standard Axiad Confirm identity verification flow. The experience is intentionally privacy-preserving: the same response is shown regardless of identifier validity, preventing account enumeration or data leakage.

Upon successful identity verification, users can recover access through administrator-defined mechanisms (such as temporary access credentials or password resets), with all expiration, retry limits, and verification rules enforced by existing Confirm configurations.

**Customer impact:**

- Reduces help desk load for lost authenticators, forgotten PINs, and similar events
- Preserves zero-trust and privacy principles even on public recovery pages
- Delivers a consistent, policy-driven recovery experience across environments

1. **Full Active Directory Parity for Axiad Confirm**

Axiad Confirm now supports **Active Directory as a first-class identity source**, achieving functional parity with Entra ID wherever technically feasible.

Administrators can configure AD as a direct datasource integration, map attributes, and use AD-sourced users seamlessly across Confirm onboarding, verification, and recovery workflows. Where permitted, workflows can generate Temporary Access Passes for Entra-synced users and reset Active Directory passwords, including enforcing password policy and “change at next logon” behavior.

**Customer impact:**

- Extends Confirm to hybrid and AD-centric environments without compromise
- Eliminates directory-driven gaps between cloud and on-prem identity verification
- Enables consistent recovery and verification experiences across identity sources

1. **Help Desk Visibility and Control Over Identity Verification State**

This release gives Help Desk operators **clear, actionable visibility into a user’s identity verification (IDV) status** directly from the Unified Portal’s User Details page.

Operators can view current IDV state, initiation and completion timestamps, and—based on permissions—take controlled actions such as initiating verification, reconfirming identity, or deleting confirmation data. All actions are fully audited.

**Customer impact:**

- Improves operational clarity and reduces ambiguity during user support interactions
- Enables controlled exception handling without bypassing audit requirements
- Aligns Help Desk tooling with real-world identity recovery workflows

1. **Workflow-Driven Identity Verification Outcomes in Conductor**

Axiad Conductor workflows can now **natively incorporate Axiad Confirm with configurable post-verification outcomes**, turning identity verification into an enforceable, reusable workflow primitive rather than a one-off step.

Administrators can enable Confirm per workflow, define success/failure messaging, and configure post-verification actions such as generating Temporary Access Credentials or issuing initial Active Directory passwords. These actions can be combined and tailored per workflow type, allowing identity verification to directly drive secure onboarding, recovery, and access enablement.

**Customer impact:**

- Makes identity verification an integral part of workflow execution, not an external dependency
- Reduces manual steps and operator intervention after verification
- Provides consistent, repeatable enforcement of identity assurance across use cases

#### **Bug Fixes**

- **PM-16667** – Fixed issue where users could enter PINs exceeding the maximum length defined in the PIN Policy, causing verification failures.
- **PM-15972** – Resolved IDEMIA Legible ID mismatch that caused enrollment failures.

#### **Known Issues**

- **PM-16907** – Confirm step configuration is not copied when duplicating a credential workflow.
- **PM-16841** – No UI error message displayed when a user has no active workflow; system returns a 500 Internal Server Error.
- **PM-16671** – Email verification fails silently if email server configuration is incorrect; modal remains open with disabled buttons.
- **PM-16274** – Legible ID not displayed for fresh devices on the scanner page.
- **PM-17150** – Refreshing the Unified Portal may occasionally trigger a 403 error; if it occurs, close the tab and reopen the portal—we are actively working on a fix.
- **PM-17153** – We are aware of the regression affecting the display of certain user details in the UI. Engineering has identified the root cause and is working on a fix.
- ID Confirmation status may appear even when Axiad Confirm is not enabled. We are aware of this issue, and engineering is actively working on a fix.

## January 13 2026

### Conductor HI

*UCMS 4.25.4*

#### **Features**

*(No new features introduced in this release)*

#### **Enhancements**

- **PM-16924** – Improved CRL number handling: The system now ensures CRL numbers are correctly incremented, preventing inconsistencies during CRL generation.
- **PM-16923** – Enhanced CRL generation process: CRLs are now generated in a temporary location and moved to the target directory only after completion, reducing the risk of incomplete files being picked up by automation scripts.

#### **Bug Fixes**

- **PM-16936** – Fixed issue where editing or deleting roles caused the page to remain stuck in a loading state due to a 403 error.
- **PM-16832** – Resolved intermittent problem which previously led to NullPointerExceptions during certificate issuance.

#### **Security Fixes**

- **PM-16661** – Addressed the vulnerability described in CVE-2025-12383.

#### **Known Limitations**

*(No known limitations reported for this release)*

## November 21 2025

### Conductor HI

*UP 2.20.1/UCMS 4.25.2*

#### Axiad Confirm Now Included in Conductor HI Package

Axiad Confirm is now available as part of the Conductor HI package. Existing Conductor customers automatically receive the following annual allocations at no additional cost:

- 50 Confirm-Onboard transactions
- 500 Identity Verification transactions

**Activation**

Confirm is ready for you, but it’s not enabled by default. Simply reach out to Axiad Customer Success at [customer.success@axiad.com](mailto:customer.success@axiad.com), and we’ll be happy to turn it on and help you get started.

#### **Enhancements**

**PM-16148** – Improved efficiency of Conductor PKI Certificate Revocation List (CRL) generation by introducing batch processing to reduce memory usage.

**PM-16181 – Selective SID/Custom SID per Certificate Type** It is now possible to configure, for each certificate type, whether to include the SID X.509 extension, which directory/SCIM attribute to use for its value, and whether that attribute is mandatory or optional.

#### **Bug Fixes**

**PM-16420** – Corrected the format of Subject Distinguished Name (DN) to match workflow configuration during certificate generation from Conductor PKI.

**PM-16261** – Fixed malformed CRL publish date when issued via Conductor PKI.

**PM-16164** – Resolved issue where Active Devices search using Conductor PKI returned no results.

#### **Security Fixes**

*None identified in this release.*

#### **Known Limitations**

**PM-16223** – CRL creation does not generate audit logs.

## November 10, 2025

#### Axiad ID Android 2.1.4

#### Bug Fixes

**PM-16437 – Settings icon partially hidden on Android devices** Resolved a layout issue on certain Android devices where key interface elements like the Settings icon and Accounts section were partially hidden behind system UI components**.**

**PM-16442 – Potential crash due to race condition** Fixed a crash affecting the Axiad ID Android app that occurred during startup due to a timing issue in the camera module

## October 29, 2025

#### Axiad ID Android 2.1.3

#### Enhancements

**Android 15 support**

This release adds support for Android 15 (API level 35) to ensure compatibility with the latest Google Play requirements.

> [!WARNING]
> Known Issues in This Release
> 
> We are currently aware of the following issues affecting this version:
> 
> - PM-16437 – Settings icon partially hidden on Android devices On certain Android devices, the settings icon may appear partially obscured behind the time display. Workaround: Swipe right to reveal the settings menu.
> - PM-16442 – Potential crash due to race condition Under specific timing conditions, concurrent operations may conflict, potentially causing the application to crash.
> 
> The above issues have been addressed in version 2.1.4.

## October 28, 2025

### Conductor HI

*UP 2.20.1/UCMS 4.25.0*

#### Features

**New Native Public Key Infrastructure (PKI)**

In this release, Axiad is introducing a new PKI developed in-house as part of our Credential Management System (CMS). Previously, certificate issuance was handled by third-party software integrated into our technology stack.

This transition brings a range of benefits, including:

- Stronger alignment with industry best practices
- Improved performance and reliability
- Enhanced security posture
- Greater control and flexibility
- Support for future product innovations and tailored features

*Impact on Existing Customers:*

This change will not affect existing customers currently using the legacy PKI component. You will continue to operate without interruption, and migrations to the new Axiad PKI will be carefully planned and communicated in advance.

*For Customers Using Their Own PKI:*

If your environment uses your own enterprise PKI, this change does not impact your current configuration. However, the new native PKI lays the groundwork for future enhancements and optional features that may benefit your deployment.

This evolution reflects our continued commitment to delivering a streamlined, secure, and modern credential issuance platform fully managed within the Axiad ecosystem.

**New Device Support: Thales SafeNet eToken Fusion NFC PIV**

Axiad Conductor now supports the Thales SafeNet eToken Fusion NFC (PIV), expanding the range of strong authenticators available to customers. This addition gives organizations more flexibility when selecting phishing-resistant authentication methods that align with their security and deployment needs.

After enrollment, this device will appear in the portal as shown below

![](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/image(51).png)

#### Security Fixes

As part of this release, Axiad has addressed several security vulnerabilities across the Axiad Conductor platform.

**PM-14593** Missing Security Header – Implemented HTTP Strict Transport Security (HSTS) to enforce secure connections.

**PM-14716** Weak Cryptographic Padding – Updated encryption padding scheme to meet modern security standards and prevent cryptographic weaknesses.

**PM-15198** Uncontrolled Recursion – Addressed a vulnerability that could lead to application instability when processing certain inputs. (CVE-2025-48924)

**PM-15657** Resource Handling Risk – Fixed an issue that could allow denial-of-service attacks under specific conditions. (CVE-2025-48989)

**PM-15658** Resource Exhaustion – Mitigated a vulnerability that could lead to excessive resource consumption and service disruption. (CVE-2025-55163)

**PM-15737** Path Traversal – Resolved a flaw that could allow unauthorized access to files outside the intended directory. (CVE-2025-41242)

**PM-15861** HTTP Request Smuggling – Corrected a vulnerability that could enable attackers to bypass request validation and inject malicious requests. (CVE-2025-58056)

**PM-16080** Authorization Bypass – Fixed an issue where improper validation could allow unauthorized access to sensitive operations. (CVE-2025-41249)

#### Known Limitations

**Supported Certificate Types:** The Axiad Conductor native PKI supports only certificates without key escrow.

---

## September 8, 2025

### OS Bridge 1.8.1.1 (Mac)

#### Enhancements

- Added support for provisioning FIDO2 security keys (passkeys) for Microsoft Entra ID in conjunction with Axiad Conductor platform and Axiad Conductor Browser Extension
- Conductor OS Bridge for Mac is now signed with a publicly-trusted code signing certificate

---

## August 7, 2025

### OS Bridge 1.8.1 (Windows)

> [!WARNING]
> Prerequisites
> 
> Install the latest version of [Microsoft Visual C++ Redistributable downloads](https://learn.microsoft.com/en-us/cpp/windows/latest-supported-vc-redist?view=msvc-170)

#### Enhancements

Conductor OS Bridge for Windows is now signed with a publicly-trusted code signing certificate, preventing security alerts.

#### Bug Fixes

**PM-14989** FIDO2 Issuance was displaying a security alert stating that the request comes from an untrusted app. Conductor OS Bridge for Windows is now signed with a publicly-trusted code signing certificate. The Windows Security dialog now displays *This request comes from the app "native.exe" by "AXIAD IDS INC".*

**PM-14991** When performed over Remote Desktop Protocol, the issuance of a PKI device was hanging at the Stage “PKI Start”. This problem has been resolved.

**PM-15118** Conductor OS Bridge was still appearing as WebPCSC (former name) in Programs and Features. It now displays “Axiad Conductor OS Bridge” to align with the new naming.

---

## June 30, 2025

### Confirm

*UP 2.18.0/UCMS 4.23.0*

#### Introducing Axiad Confirm

**Identity Assurance for Credential Issuance**

We’re excited to announce the launch of **Axiad Confirm**, a powerful new identity verification solution built into the Axiad Conductor platform. Axiad Confirm protects the “front door” to your enterprise credentials by ensuring that every credential—whether a smart card, certificate, or passkey—is issued *only after* the user’s identity has been verified with confidence.

**Why it matters**

Most identity attacks don’t start at login, but instead they start when credentials are issued or reset. Axiad Confirm stops these threats at the source by verifying user identity before any credential is created or reissued. It uses biometric liveness detection, government-issued ID validation, and identity attribute matching to ensure the right person is behind every request.

**Seamless experience on any device**

Axiad Confirm delivers a browser-based, mobile-friendly workflow that works across both professional and personal devices—no app installation required. It integrates directly with your existing infrastructure, including Microsoft Entra ID for Temporary Access Pass (TAP) issuance.

**Built for trust**

Whether onboarding new employees, resetting credentials, or verifying help desk callers, Axiad Confirm ensures you can confidently answer: **“Who is this person, and can we trust them?”**

#### Features

- Operators can confirm an employee’s identity before granting secure access to Axiad Conductor for phishing-resistant authenticator enrollment

![](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/image(35).png)

- Help Desk operators can verify an employee’s identity with confidence before assisting with credentialing or access issues

![](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/image(36).png)

- A new user status now tracks identity confirmation state, showing whether a user is *unconfirmed*, *confirmed*, or *failed verification*

![](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/image(37).png)

- Browser-based identity verification workflows enable users to confirm their identity using a government-issued ID or a selfie matched against a previously captured facial hash and obtain an Entra ID Temporary Access Pass (TAP)

![](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/image(38).png)

- During identity verification, the system extracts key attributes—such as name, date of birth, and postal code—from the scanned government-issued ID and compares them against the corresponding identity attributes configured in the system (e.g., Entra ID) to ensure consistency and to validate the claimed identity

#### Known Limitations

- **Entra ID Only:** Axiad Confirm currently supports only Microsoft Entra ID. Support for additional identity providers (IdPs) will be introduced in future versions.
- **Active Directory Not Supported:** Deployments relying solely on Active Directory are not supported. Our Customer Success team can assist you in migrating to SCIM to take advantage of Axiad Confirm’s capabilities.
- **Cloud Edition Required:** Axiad Confirm is designed for Axiad Conductor Cloud. It can technically be used with Axiad Conductor for Airgap, but this requires enabling external access to the Conductor instance, as identity verification relies on a cloud-hosted service.
- **TAP Support Only:** Axiad Confirm currently supports the issuance of Microsoft Entra ID Temporary Access Pass (TAP) following a successful identity verification. Additional outcomes will be supported in upcoming releases.
- **Confirm Again**: The *Confirm Again* action is available but will not succeed until the current confirmation transaction expires. By default, transactions expire after **5 days for Onboard** and **15 minutes for Verify**, though these durations can be configured.
- **Mobile OS Requirements:**
  - iOS 17 or later is required for the identity verification process on iPhones.
  - Android 15 or later is required for identity verification on Android devices.
- **TAP Display Timeout:** If a user leaves the Temporary Access Pass (TAP) screen open for more than 10 minutes, an error message may appear.
- **Address Matching:** When address matching is enabled between the government-issued ID and Axiad Confirm, only the postal code is used for validation.
- **Post-Verification Message:** If the identity verification process has already been completed, clicking the “Confirm Identity” link again will display the message: “*Success. Thank you. You may now close your browser**.”*

[Learn more about Axiad Confirm](/v1/docs/axiad-confirm)

> [!TIP]
> Get Axiad Confirm Today!
> 
> **Axiad Confirm** is an optional add-on to **Axiad Conductor** and requires a separate license to activate. For more details, please contact your Axiad reseller or your Axiad representative.
> 
> 
> 
> If you have any further questions, feel free to reach out to us at [productmanagement@axiad.com](mailto:productmanagement@axiad.com).

---

## June 17, 2025

### Conductor Human Identities (HI)

*UP 2.16.0/UCMS 4.21.0*

#### Features

**Support for Provisioning FIDO2 Security Keys (passkeys) for Microsoft Entra ID**

With this enhancement, Entra ID customers can now manage a broad range of authentication credentials—including passkeys and PKI-based X.509 certificates—through a single unified platform. By consolidating credential management and streamlining onboarding and self-service workflows, Axiad Conductor empowers organizations to deploy phishing-resistant authentication across their entire Microsoft Entra ID environment.

> [!WARNING]
> Important
> 
> To enable this functionality, version 1.8.0+ of both the **Axiad Conductor Browser Extension** and **Axiad Conductor OS Bridge** binaries is required
> 
> For more information, please refer to the following links:
> 
> - [Axiad Conductor Browser Extension (Previously Axiad Portal Extension)](/v1/docs/axiad-portal-extension-home)
> - [Axiad Conductor OS Bridge (Previously WebPCSC)](/v1/docs/axiad-webpcsc-overview)

Included as part of the feature:

- New option for end users to [register a Passkey](/v1/docs/enroll-a-fido2-identity-device) in Microsoft Entra ID via the Axiad Conductor Unified Portal
- Users can view all Passkeys registered to their Microsoft Entra ID account in the Axiad Conductor Unified Portal
- Operators can view all the Passkeys associated with their organization's Microsoft Entra ID user accounts via the Axiad Conductor Unified Portal

> [!TIP]
> Coming Soon
> 
> A new version of Axiad Conductor OS Bridge (previously WebPCSC) will allow Passkey registration capabilities on Apple macOS. Currently Passkey registration is only available on Microsoft Windows.

#### Known limitations

- **PM-8754** A future release will introduce support for FIDO2 Enterprise Attestation
- **PM-8754** A future release will include support for displaying the serial number of the device associated with the registered Passkey, provided the device supports FIDO2 Enterprise Attestation
- **PM-8856** A future release will enable automatic removal of FIDO2 credentials when a device is repurposed for another user
- **PM-7663** A future release will introduce user-initiated passkey revocation capabilities
- **PM-13905** When an operator unassigns a user's passkey, it is removed from Entra ID and marked as revoked in the Axiad Conductor portal; however, the associated passkey device remains listed in the user's account within the portal
- **PM-13903** When a Passkey is deleted in Entra ID, its automatic revocation in Axiad Conductor may not occur reliably
- **PM-13902** The Revoked Devices report does not display Passkeys that have been revoked
- Maximum number of active devices does not apply to Passkeys
- **PM-14572** A future release will introduce support for Platform-bound FIDO2 Passkeys on macOS

### Browser Extension 1.8.0

> [!NOTE]
> Availability
> 
> Axiad Conductor Browser Extension 1.8.0 has been published to both the Google Chrome and Microsoft Edge Add-ons Web Stores and will update automatically or can be updated manually, depending on your browser settings.

#### Enhancements

Added support for provisioning FIDO2 security keys (passkeys) for Microsoft Entra ID in conjunction with Axiad Conductor platform and Axiad Conductor OS Bridge.

### OS Bridge 1.8.0

> [!WARNING]
> Prerequisites
> 
> Install the latest version of [Microsoft Visual C++ Redistributable downloads](https://learn.microsoft.com/en-us/cpp/windows/latest-supported-vc-redist?view=msvc-170)

#### Enhancements

- Added support for provisioning FIDO2 security keys (passkeys) for Microsoft Entra ID in conjunction with Axiad Conductor platform and Axiad Conductor Browser Extension
- Official support of Windows 11

#### Bug Fixes

**PM-12998** NPE on GlobalPlatformCard.loadGlobalPlatformKeySet

---

## May 1, 2025

### Conductor HI

#### Enhancements

**PM- 13596** Axiad Conductor now supports YubiKey 5 Series devices with firmware versions up to 5.7.4.

### ADFS Adapter 1.3

#### Bug Fixes

**PM-13782** Following the upgrade of the Axiad Conductor Authentication service, an error occured in PINless Mobile Authentication with the message: *Failed to login. Please try again.*

#### Known Limitations

**PM-13866** If a user has both an HOTP token and an Axiad ID assigned, then ignoring a push notification on Axiad ID increments the failed attempt counter of the HOTP token

---

## April 15, 2025

### Conductor HI

#### Enhancements

**PM-13546 / TUTI-12954** When fetching users, SCIM APIs can now optionally return membership information, i.e what SCIM group(s) the user belongs to. The following settings are available:

- **None** (default): The SCIM API `User/get Users` does not return any membership information (this is the historical behavior)
- **Direct:** The SCIM API `User/get Users` returns direct membership information
- **All:** The SCIM API `User/get Users` returns all direct and indirect (nested) membership information
  - Axiad recommends evaluating the performance when enabling this setting to ensure it satisfies your requirements

> [!NOTE]
> Configuration
> 
> Please reach out to the [Technical Support team](mailto:support@axiad.com) or your Customer Success representative to enable this option.

**PM-13636** The `/saml/sso` endpoint for accessing the Axiad Conductor portal is now deprecated. End-users should now use one of the following supported endpoints to log in: `/` or `/user`

If any users or systems are experiencing issues, please verify they are using one of the supported endpoints: `/` or `/user`

---

## March 21, 2025

### Conductor HI

#### Features

**PM-1380** Axiad Operators can configure an HTML template to use for all outgoing email notifications. Learn more about how to update your notification templates [here](/v1/docs/update-axiad-notification-template).

**PM-10467** Added support for SafeNet eToken Fusion 5300

**PM-10193** Added support for Gemalto IDPrime MD930 cards with custom manufacturer key

#### Enhancements

**PM-2788** When an Operator attempts to revoke a user’s device or credential, they are prompted to confirm the action before it is revoked.

**New UI:**

![](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/Screenshot 2025-01-09 at 10.33.53 AM.png)

**PM-9360** Expanded and clarified the language presented to users when creating a PIN

**Before:**

![](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/image-20240914-173212.png)

**After:**

![](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/image-20240914-173545.png)

**PM-10171** Customers can include custom links in end-of-lifecycle operation messages

> [!NOTE]
> Note
> 
> To update your operation messages, reach out to [Axiad Customer Success](mailto:customer.success@axiad.com)

**PM-7653** New option allows a user to replace a device without reissuing certificates that are both escrowed and still valid

**PM-11431** Each user project now has a Group attribute included when querying users through the SCIM endpoint

#### Security Fixes

**PM-11246** Addressed vulnerabilities: CVE-2024-38819, CVE-2024-38820

**PM-9936** Addressed vulnerabilities: CVE-2024-38809, CVE-2024-38808

**PM-9347** Addressed vulnerabilities: CVE-2024-38816

**PM-13182** Addressed vulnerabilities: CVE-2024-38828

**PM-10194** Addressed vulnerabilities: CVE-2024-38821

**PM-13236 / PM-13246** Addressed vulnreabilities: CVE-2025-24813

#### Known Limitations

**PM-13076** Revoke confirmation message (PM-2788) does not display for imported service type credentials. Planned to resolve in future release.

**PM-13368** Logging into UP does not work with `/saml/sso` as Axiad has deprecated this endpoint with this new version. Log in using `/` instead

---

## January 28, 2025

### Conductor HI

#### Security Fixes

**PM-11175** Addressed the following security issues: CVE-2024-50379 / CWE-367, CVE-2024-56337 / CWE-367, CVE-2024-52316 / CWE-248

#### Bug Fixes

**PM-11424** LDAPS now works with UCMS in FIPS mode

---

## December 10, 2024

### Conductor NHI 2.6

#### Enhancements

- Support for pagination on search SOAP API
- Support for Microsoft SID extension
- Enhanced SCEP server capabilities to support the "POST" method, the SHA0256 has algorithm, and the AES encryption
- Support for linking multiple workflows to a single profile

> [!WARNING]
> Upgrade Note
> 
> After this upgrade, you may need to clear the browser cache to access the Axiad Conductor NHI portal.

---

## December 2, 2024

### AirLock 2.4.0

#### Features

**PM-8591** Operators can now define which authentication methods can bypass AirLock. By default, AirLock lets users in if they authenticated using Axiad ID (Push/OTP), a certificate, Windows Hello for Business, or the Microsoft Authenticator.

#### Enhancements

**PM-8592** Users are automatically redirected to AirLock if any of the certificates on any of their authentication devices are within the renewal period and must be updated. Devices that contain multiple certificates can now be recognized and prompted for update via AirLock.

This applies to ANY inserted device, even if the user is not employing it for authentication. If the certificate is within the renewal window or expired, then the user will be redirected to AirLock to update it.

**PM-8940** Operators can now allow specific users (in addition to groups) to bypass AirLock enforcement

**PM-9942** All deployed executables are digitally signed

#### Bug Fixes

**PM-7300** The correct AirLock version displays in Windows Program list

**PM-6779** AirLock checks the Windows edition to ensure that it has the required features to work and will cancel installation if unsupported to avoid user errors after a failed installation

AirLock requires the Enterprise edition, and Axiad supports all versions of Windows currently supported by Microsoft

**PM-4090** An empty "Immune Security IDs" list is allowed and will enforce AirLock for all users, as expected

**PM-7949** AirLock successfully detects smartcard login over RDP

#### Known Limitations

**PM-10109** WHFB login may fail if an empty VSC is present on the system. You can remove the empty VSC as a workaround.

---

## November 19, 2024

### Conductor HI

#### Enhancements

**PM-10337** Update logging to show ERROR message instead of WARN when the connection to Luna 7 HSM Client becomes stale

#### Security Fixes

**PM-10375** Addressed vulnerabilities: CVE-2023-44487, CWE-79, CVE-2024-4067, CVE-2024-52316

#### Bug Fixes

**PM-10346** Local logout setting respected when portal.timeout.idle is hit

**PM-10154** User is able to reauthenticate with UP after session times out

**PM-9858** Users are no longer presented with a spinning wheel when accessing UP without using the login URL first

**PM-8081** "Unassign" option appears only once for devices on UP

---

## October 8, 2024

### Conductor HI

#### Features

**PM-8580** Users can log out of the Axiad Unified Portal without losing their IdP session

#### Enhancements

**PM-7033** Add session identifier in logger extension for easier log traceability

**PM-7697** On the **Helpdesk > Users** page, when opening the user **Details**, the field **Username (UPN)** is changed to **Username**

**PM-8115** Login and logout events added to the audit log

#### Bug Fixes

**PM-7576** CA connects successfully when configured with FIPS LunaHSM with updated Java version

**PM-8125** Error message updated when issuance fails due to unsupported device or invalid PIN to be more helpful

**Before**

![](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/image-20240604-230456.png)

**After**

![](https://cdn.document360.io/eaa8d9cb-3eef-4690-8447-5bcaa4f4afb2/Images/Documentation/image-20240923-071405.png)

**PM-7813** Updated notification verbiage if one of the credentials on an enrolled device has expired

**Before**: "Your device has expired, please renew now."

**After**: "One of the credentials mapped to device is expired, please renew now."

**PM-8544** Enrolling a virtual smart card when there are no existing devices enrolled no longer leads to a loading loop

---

## August 30, 2024

### Axiad ID Mobile Application 2.1.2

#### Enhancements

**Android Library Updates for Google Play API**

Axiad completed various backend library updates to meet the necessary target API level requirements. This ensures the security and efficiency of the app usage.

> [!TIP]
> No User Impact
> 
> This change is fully transparent to the user experience and does not include any functional changes in the mobile application.

**Security and Performance Updates**

This version includes maintenance updates to continually improve the security and performance of the Android and iOS Axiad ID mobile application.

### Browser Extension 1.5.5

#### Enhancements

**Support for Manifest v3.0**

To support Google's deprecation of browser extensions using the Manifest v2.0 format, we've updated the Axiad Portal Extension to support this new Manifest v3.0 format.

> [!TIP]
> WebPCSC Backward Compatibility
> 
> This version of the browser extension **does not require** a new version of Axiad WebPCSC. You can use this extension version with **any** version of the WebPCSC component, including the latest 1.5.5 version.

---

## August 18, 2024

### OS Bridge 1.5.5

> [!WARNING]
> Release Prerequisites
> 
> Install the latest version of [Microsoft Visual C++ Redistributable downloads](https://learn.microsoft.com/en-us/cpp/windows/latest-supported-vc-redist?view=msvc-170)

#### Enhancements

**Support for Manifest v3.0**

To support Google's deprecation of browser extensions using the Manifest v2.0 format, we've updated WebPCSC to support the Axiad Portal Extension in this new Manifest v3.0 format. This will be the baseline version for all Windows and macOS endpoints going forward.

---

## July 17, 2024

### Conductor HI

#### Features

**Support for YubiKey Firmware 5.7**

The YubiKey firmware version 5.7 brings a number of significant changes and improvements that are now supported by the personalization process that Axiad Conductor / UCMS uses to enable secure lifecycle management of the devices.

Axiad continues to support older YubiKey versions alongside the newer versions and this does not bring any breaking changes to your YubiKey experience.

> [!WARNING]
> Supported Versions
> 
> Currently, Axiad supports YubiKey firmware **up to 5.7.1**. Axiad will support newer versions of YubiKey in subsequent releases.

#### Enhancements

**Device Expiration Notifications Options**

Operators can now choose if they want Axiad to send notifications to expired devices or not.

> [!NOTE]
> Configuration Change
> 
> To disable Device Expiration Notifications, you must request the change. Please contact your Customer Service Representative or email [customer.success@axiad.com](mailto:customer.success@axiad.com).

#### Bug Fixes

**PM-7334** Errors returned by an IdenTrust CA during issuance or revocation will now produce a more explicit message

**PM-7495** You can now edit a workflow even if there is not an active credential profile is associated to it

**PM-7497 / PM-7582** Migrating a user and renewing one of their devices will no longer result in duplicated device records

**PM-7586** After upgrading from UCMS 4.13 to 4.17, searching for a user in the helpdesk or scanner will no longer result in UCMS.devices.internalError error

**PM-7704** The UPN can now be included as a SAN extension in encryption certificates issued by MSCA

**PM-7617 / PM-7321 / PM-7513** Update PIN settings to meet MD930 requirements

**PM-7672** UCMS Operator email address can now include “-” and “_” following “@”

**PM-7898** Reset PIN supported for Gemalto cards

**PM-6594** SMTP support enhancements

**PM-7335 / PM-7787 / PM-7788** Axiad displays a meaningful error message if backend services are unreachable

**PM-7905** When configuration leads to a mismatch, Axiad fails the issuance and displays necessary information for the user

**PM-8125** Error message updated when issuance fails due to unsupported device or invalid PIN to be more helpful

---

## April 2, 2024

### Conductor HI

#### Features

**Support for Multiple AD Identities Mapped to a Single Authenticator**

Axiad Conductor now supports the issuance of certificate-based authenticators mapped to multiple AD identities. This change allows Active Directory customers to issue multiple identities (for instance a regular and a privileged account) to a single device, while remaining compliant with the security requirements introduced by Microsoft in their KB5014754 patch.

Please contact your customer success representative or [customer.success@axiad.com](mailto:customer.success@axiad.com) if you’d like to use to this feature, and read more about the experience [here](/v1/docs/multiple-account-authentication-on-a-single-device).

#### Bug Fixes

**PM-6010** API endpoint GET /api/v3/users/{uid}/notifications updated to support group transition. Return message displays “renewTransition” upon completion.

**PM-6857** NULL pointer exception no longer displays during PIN reset and card details retrieval

**PM-6803** User can successfully update existing Windows Hello for Business certificates via Axiad

**PM-6801** User can revoke Windows Hello for Business credential from Unified Portal

**PM-7152** Username data consistently updated in Axiad via SCIM

**PM-5643** User stays on logout page or is redirected to configured logout page when they click “logout” from the UP
