Release Name: v2026.07
Latest Hotfix Name: N/A
Release Date: 2026-07-28
Latest Hotfix Date: N/A
These are the release notes of Monosign v2026.07
Monosign is an Identity & Access Management solution for enterprise-level organizations. Monosign has enterprise grade features, and these features help companies to secure their identities and identity related environments.
These release notes contains following information.
-
New Features
-
Improvement
-
Bug Fixes
-
Known Issues
-
Supported Platforms
New Features
In this release 14 New Features published.
|
Key |
Version |
Type Name |
Release Notes |
|---|---|---|---|
|
MSIGN-2885 |
v2026.07 |
New Feature |
You can configure your format to list and show users from "System" => "Configurations" => "User Display". |
|
MSIGN-3246 |
v2026.07 |
New Feature |
A new assignment component with advanced filtering, bulk selection, and an enhanced assignment experience has been added to the Group, Role, Permission, Application, and User Assignment screens. |
|
MSIGN-3292 |
v2026.07 |
New Feature |
Roles, permissions, groups, and applications now support trigger-based provisioning. When a user gains access, they can be automatically added to Active Directory groups or provisioned to external systems via Web Service API (JSON/XML), and automatically deprovisioned when access expires. Configuration: define the entitlement/trigger actions on the relevant role or permission. |
|
MSIGN-3322 |
v2026.07 |
New Feature |
MonoSign now sends system, infrastructure, and health-check metrics to the License Portal, where they can be monitored per customer environment. |
|
MSIGN-3323 |
v2027.07 |
New Feature |
MONOSIGN_INSTANCE_ID environment variable is introduced to track continuous instanse/pod specific metrics. Docker installations should have MONOSIGN_INSTANCE_ID={{.Service.Name}}-{{.Task.Slot}}. For k8s "Deployment" type should be "StatefulSet" and this environment variable should be added. env: - name: MONOSIGN_INSTANCE_ID valueFrom: fieldRef: fieldPath: metadata.name |
|
MSIGN-3344 |
v2026.07 |
New Feature |
You can list / create tenants and tenant host records from master (default) tenant under "System" => "Tenants" page. |
|
MSIGN-3347 |
v2026.07 |
New Feature |
Introduced the Mono AI Copilot module, providing AI-powered query, configuration, and activity management capabilities. |
|
MSIGN-3348 |
v2026.07 |
New Feature |
AI Agents capabilities have been enhanced to provide a more reliable and efficient automation experience. |
|
MSGIN-3350 |
v2026.07 |
New Feature |
The Security Score module, which rates the overall security posture of your users and environment, has been validated end to end for accuracy and reliability in this release. No action or configuration is required on your side. |
|
MSGIN-3351 |
v2026.07 |
New Feature |
Identity Verification and Identity Assurance, the features that confirm users are who they claim to be during sign-in and account recovery, have been validated end to end for reliability in this release. No action or configuration is required on your side. |
|
MSGIN-3352 |
v2026.07 |
New Feature |
The Visibility & Threats screens, which show sign-in activity and potential security threats in your environment, have been validated end to end for reliability in this release. No action or configuration is required on your side. |
|
MSGIN-3353 |
v2026.07 |
New Feature |
Report Studio now lets you build access reports enriched with user profile details such as title, position, job family, and department. You can report which users have access to which applications, filter results by group, role, or permission (including access provisioned to Active Directory through MonoSync), see permissions granted automatically at onboarding, and limit reports to a specific date range. This makes it easy to produce a complete role-and-permission matrix directly from MonoSign. No additional configuration is required. Note that profile-based filters (title, position, etc.) rely on user profile data, so these fields should be populated — for example via your HR or directory sync — for those filters to return results. |
|
MSGIN-3365 |
v2026.07 |
New Feature |
Added support for assigning flags to users. Flags can be assigned, updated, and removed from the user detail page in Management, and the Users list can be filtered by flag. |
|
MSGIN-3373 |
v2026.07 |
New Feature |
Relative dates in Management (such as '2 days ago') now show the full date and time, including timezone offset, in a tooltip. Optional configuration: the tooltip format can be customized with the new 'Date Time Format' setting under System > Configurations > Localization (moment.js format tokens); the default is DD/MM/YYYY HH:mm:ss Z. |
Improvement
In this release 20 Improvements published.
|
Key |
Version |
Type Name |
Release Notes |
|---|---|---|---|
|
MSIGN-3240 |
v2026.07 |
Improvement |
Fixed application password change operations: changing an application password from the SSO portal no longer overwrites the application username with the domain username, and passwords changed through the 'Need Help' flow are now updated in MonoSign as well. |
|
MSIGN-3296 |
v2026.07 |
Improvement |
Offline Windows Passwordless sign-ins (Device PIN) are now audited: once the device reconnects to the internet, these logins appear under Management > User Details > Sign-in Audit. |
|
MSIGN-3311 |
v2026.07 |
Improvement |
Workflow forms are now more flexible. You can add Checkbox fields, show a short description under any field in a color of your choice, validate input with regex patterns (for example an ID number format), and set minimum/maximum dates on date fields. To use these, open your workflow form in the form designer, select a field, and set the new options (Description, Regex Pattern, Min/Max Date) in the field settings. Invalid entries are blocked with a validation message before the request can be submitted. |
|
MSIGN-3319 |
v2026.07 |
Improvement |
You can now remove assigned roles, permissions, and groups in bulk from a user's detail page. Open the user detail page, go to the Roles, Permissions, or Groups tab, select the records you want (Select All, Select Filtered, and Clear Selection are available, and Advanced Filters work with Select Filtered), then choose delete from the Actions menu. Assignments created by automation are protected and cannot be bulk-deleted. |
|
MSIGN-3324 |
v2026.07 |
Improvement |
Triggers are now easier to set up and more reliable. You can create and view triggers directly from the Role, Permission, Group, and Application screens, where related triggers are shown on the detail page. Trigger rules that remove a user from a group when a role, permission, group, or application is assigned now work as expected, the State filter uses the clearer Is operator, and rules based on user profile fields are evaluated correctly. To get started, open a role, permission, group, or application and add a trigger from its detail screen. |
|
MSIGN-3331 |
v2026.07 |
Improvement |
Workflow forms now support an Async Search element: a searchable dropdown that fetches its options from an external API as the user types, so large datasets (for example thousands of groups or records) no longer need to be loaded into a static dropdown. Options can be filtered server-side, and results are labeled and paged automatically. Configuration: in the workflow form designer, add the Async Search element and set the external service URL. Optional settings include the search query parameter name, request headers and extra parameters, a POST request body template, the response data path, label field or label template, page size, and cache duration. Works in both the Management form designer and end-user approval forms; no other setup is required. |
|
MSIGN-3340 |
v2026.07 |
Improvement |
Disable Starter Approval has been extended to delegation scenarios, preventing delegated users from performing actions on behalf of the starter in applicable workflow steps. |
|
MSIGN-3341 |
v2026.07 |
Improvement |
Access Certification is now smoother to use: the Close button on the campaign detail page works, campaigns are no longer listed twice, review progress updates correctly when a reviewer changes a decision, reviewers are kept when you edit the Target/Perspective fields, and a new Search box on the campaign detail page helps you find records quickly. You can find campaigns under Governance > Certifications. No configuration is required. |
|
MSIGN-3343 |
v2026.07 |
Improvement |
UI elements now display the name of the permission that controls them, making it easier to identify which permission is required for each action. |
|
MSIGN-3345 |
v2026.07 |
Improvement |
The 'Unsaved Changes' alert in Management now appears only when there are actual unsaved changes, instead of on every navigation. |
|
MSIGN-3347 |
v2026.07 |
Improvement |
Introduced the Mono AI Copilot module, providing AI-powered query, configuration, and activity management capabilities. |
|
MSIGN-3354 |
v2026.07 |
Improvement |
Finding requests is now much easier. On the My Requests and Approvals screens, type in the search box to find requests by workflow name, request message, or requester details (name, surname, email, employee ID). In Approvals > History you can also filter records by status. These work the same way in both the self-service portal and the management portal, with no setup required. |
|
MSIGN-3355 |
v2026.07 |
Improvement |
Workflow notification emails can now display values from dynamic objects created in your workflow scripts. If a script step returns an object (for example with start date, end date, and requested access), you can reference its properties directly in the email template, e.g. {{context.Data.mailContentInfo.requestStartDate}}. Previously only simple variables could be used; now nested properties work too, making it easy to build rich, personalized emails. |
|
MSIGN-3357 |
v2026.07 |
Improvement |
MagicLink, the passwordless sign-in option that lets users log in via a link sent to them, has received security hardening for safer link-based logins. Existing MagicLink settings keep working; no configuration changes are required. |
|
MSIGN-3358 |
v2026.07 |
Improvement |
The Provision Log module has been reworked as 'Provision', providing a clearer view and management of provisioning operations. |
|
MSIGN-3362 |
v2026.07 |
Improvement |
Fixed: browser autofill and password managers no longer trigger on the page header search box. |
|
MSIGN-3363 |
v2026.07 |
Improvement |
Forms: conditional visibility can now be configured without writing JSON; date/time elements gained minute-level min/max constraints, separate display formats, and an optional timezone suffix. |
|
MSIGN-3372 |
v2026.07 |
Improvement |
Master applications are now treated as trusted on API endpoints with enforced permissions when the tenant's API security is disabled — matching how they already behaved on all other endpoints. Calls from master application keys no longer fail with permission errors in this configuration. No configuration required. |
|
MSIGN-3375 |
v2026.07 |
Improvement |
Signing in with an extremely long username now returns the normal 'invalid username or password' response instead of a server error. No configuration required. |
|
MSIGN-3382 |
v2026.07 |
Improvement |
Disabled users can no longer renew their access with a refresh token. When a refresh token is used, Monosign now checks that the user account is still enabled; if the account has been disabled, the request is rejected and no new access token is issued. No configuration is required — the check is applied automatically after upgrade. |
Bug Fixes
In this release 16 Bug Fixes published.
|
Key |
Version |
Type Name |
Release Notes |
|
MSIGN-3320 |
v2026.07 |
Bug |
When signing in with a one-time code (OTP), pressing Resend Code now automatically clears the code entry boxes so you can type the new code right away, instead of deleting the old one manually. No configuration is required. |
|
MSIGN-3321 |
v2026.07 |
Bug |
In the Notification menu on the user detail page, the User and Channel filter icons now turn blue when a filter is active, so you can see at a glance that the list is filtered. No configuration is required. |
|
MSIGN-3325 |
v2026.07 |
Bug |
When you create an Access Certification campaign with Reviewer Type set to Manager, review tasks are now correctly assigned to each user's manager. User information in the campaign Scope tabs also loads without a manual refresh. To use it, create a campaign under Governance > Certifications and select Manager as the Reviewer Type. |
|
MSIGN-3334 |
v2026.07 |
Bug |
Timeline page improvements: faster loading, a description is now required when pinning an event, and pinned events now show their Correlation and Source details in the Pinned tab. |
|
MSIGN-3338 |
v2026.07 |
Bug |
Form fields that allow multiple selections now also work on the self-service screens (My Requests and Approvals). You can pick several items in one request, and clicking the field again shows search results instead of your previous selection. To enable it, turn on the Multiple option for the field in the form designer. |
|
MSIGN-3346 |
v2026.07 |
Bug |
Fixed an issue where the Identity Matrix could show incorrect resource assignments. Assigned resources are now listed accurately for each user. |
|
MSIGN-3356 |
v2026.07 |
Bug |
When an access request is canceled or rejected during the approval flow, it now shows the correct status on the requester's My Requests screen instead of staying in a pending state. The same correct status is shown on the management flow and step screens. No configuration is required. |
|
MSIGN-3359 |
v2026.07 |
Bug |
Fixed: Access Certification pending list now shows only items the reviewer is authorized to review — manager-type reviewers no longer see items whose decisions silently fail. |
|
MSIGN-3360 |
v2026.07 |
Bug |
Fixed: Access Timeline dates now display in the user's local timezone. |
|
MSIGN-3361 |
v2026.07 |
Bug |
Fixed: workflow and access-certification e-mails no longer show raw profile tokens when a user's profile value is empty. |
|
MSIGN-3369 |
v2026.07 |
Bug |
When an access certification campaign has 'All assignments must be reviewed' enabled, reviewers can no longer complete their task while items are still pending — the rule is now enforced by the server, not just the browser. The SSO portal now shows the same waiting-for-review behavior as Management. No configuration required. |
|
MSIGN-3370 |
v2026.07 |
Bug |
Fixed cases where user logins could be disabled immediately after a temporary license-service outage or restart. The 7-day grace period now starts only from an actually recorded validation error, license hostname checks are deterministic on multi-host environments, and a license problem in one tenant no longer blocks license checks for other tenants. No configuration required. |
|
MSIGN-3371 |
v2026.07 |
Bug |
Fixed two errors in Management: the user 'Sync' button now automatically creates a default profile when the user does not have one (previously it failed with 'Profile Sync got error!'), and Profile Sync no longer fails on profiles that contain values whose property definition was removed. No configuration required. |
|
MSIGN-3374 |
v2026.07 |
Bug |
Fixed workflows whose first step links directly to End (for example Start → Code → End) staying 'In Progress' forever even though the step completed. Required configuration: existing workflow definitions with this shape must be re-saved once in the workflow designer to pick up the fix. |
|
MSIGN-3376 |
v2026.07 |
Bug |
The captcha refresh button on the sign-in page no longer covers the captcha characters; it now sits in its own area next to the image. The account unlock and password reset pages now also include a captcha refresh button. No configuration is required. |
|
MSIGN-3383 |
v2026.07 |
Bug |
Login now enforces the assigned authentication policy and can run an attached workflow before access is granted. If a policy requires MFA, the user completes MFA before signing in; if an approval workflow is attached to login, sign-in stays pending until it is approved. No configuration change is needed for existing setups — logins without a policy or workflow behave as before. To enable it, assign an authentication policy or a login workflow to the user or application in the admin panel. |
Release notes can be download from below link.
Monosign-Release-Notes-v2026.07.pdf