New York
Released April, 2024
Dashboard
https://docs.strivacity.com/docs/dashboard-overview
Our reimagined dashboard ensures brands get the data they need to make informed decisions about how to configure the product to achieve business outcomes. In this release you will see:
- Login and registration successes, failures, and abandonment metrics as trends over time, rather than single counts
- A list of failure reasons and the screen name of step the failure occurred
- The median duration per step in a login/registration flow
- Trends over time for forgotten username request (requests vs. failures), password resets, MFA authentications and MFA registrations
- Detailed Adaptive Access statistics, showing authentication step-up, step-down, and blocking action trends
- Tracking of identity verification transactions
- Tracking of SMS and SES email resend requests
- Ability to create multiple custom dashboards
- Ability to create multiple widgets of the same metric filtered differently
- Ability to filter per-widget by dates and application clients
- Easy PDF export of dashboards
These dashboard updates come with the added benefit of having more verbose account events, including more information about failure reasons, drop-off steps, and adaptive access outcomes.
Journey builder
https://docs.strivacity.com/docs/journey-builder
We continue to add new features and capabilities to our journey builder to make it easy to drop custom journeys into our existing policy-driven configuration.
New journey steps:
- Password authentication step
- Persist data collected to the users account
- Identity verification - insert any identity verification policy workflow as a journey step and branch based on the verification outcome.
Journeys can now be launched from additional hooks
Lifecycle event hook context can now be passed to a custom journey for use in conditions.
Local variables can be collected as data input and be used in conditional statements.
Condition statements now have a preview on the condition list screen.
Email and physical address risk
https://docs.strivacity.com/docs/email-and-physical-address-risk
Fraudulent accounts can costs brands money. Account onboarding is your first line of defense against fraudsters using false information to create accounts for nefarious purposes.
Strivacity’s email and physical address risk step allows brands to evaluate information submitted during onboarding for risk signals. Higher risk accounts can either then be blocked or further vetted to ensure authenticity.
Strivacity Bridge for on-premises directories
Brands can now connect to an on premises LDAP connector to sync identities into the Strivacity identity store. Much like our Bridge for headers-based authentication, Strivacity’s Bridge for on-premises directories provides a path for organizations with legacy systems to adopt modern authentication approaches before they’ve shed their dependancies these older technologies.
Account impersonation
https://docs.strivacity.com/docs/account-impersonation
Sometimes, the easiest way for a customer service representative to help a customer is to log in on their behalf and see exactly what the customer is seeing. With Strivacity’s Account Impersonation feature, customer service can temporarily login as the customer using a time-limited access link.
Physical document verification updates
https://docs.strivacity.com/docs/document-verification
Brand admins can now map attributes captured from a physical documents into native claims, allowing storage of that information in the user’s account, which can improve the customer onboarding experience.
Support for Web Application Firewalls
Brands can now put their own web application firewall in front of the Strivacity product to augment Strivacity security features and provide deeper control over access to the Strivacity product.
Account events updates
https://docs.strivacity.com/docs/account-events
More Account Event detail
Account events now contain:
- Adaptive MFA results
- Account locks that appear as failed authentications
- Information received from external identity providers
Organization admin portal
https://docs.strivacity.com/docs/delegated-administration
B2B administrators can now view per-user account events so B2B administrators can monitor access and troubleshoot issues.
Clear session of account after admin delete
Now when an administrator deletes an account, the users sessions are cleared automatically, ensuring deleted accounts lose access immediately after deletion.
External login provider experiences
We’ve added external login buttons to the password screen so the external identity users can quickly login if they have a remember account
We’ve also added a pre-external registration hook to allow customization and orchestration during external login registrations
Developer experience
We’ve added character counters to all IDEs so developers can keep an eye on their character limits for code editors
You can also now view a 10 minute/5000 line subset of lifecycle event hook logs by specifying a time stamp at the time of the log request.
Email sender address override for admin console notifications
You can now override the local-part of the sender email address for admin notifications.
Token lifespan and type configuration for OIDC clients
Each application client can now have its own, configurable, refresh, ID, and access token lifespans. You can also choose whether the access token format is opaque or uses JWT.
Other stories
- Support for failover SMS/Telephony providers
- Alphabetical organization and group ordering
- Deploy "Password requirements indicator" as a default setting
- Small table performance optimizations
- Updated default Adaptive Access policy setting
- Added monthly query option for existing statistic APIS
- Custom upstream server path for bridge clients
- Detect blocked cookies in login page