2026.05.0 (2026-05-29)

RapidIdentity Platform Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Updated 11 June 2026

Added the Unified Authentication Methods, Flexible Forgot Password Policy, and WCAG 2.2 Accessibility Improvements sections to provide additional context for major feature updates.

Seamless Learning Access

Seamless Learning Access is a new single sign-on capability that silently authenticates students and educators into learning applications on managed iPad devices. The capability is delivered through a Seamless Learning Access single sign-on extension which integrates Jamf Pro with RapidIdentity.

By deploying Seamless Learning Access with Jamf Pro, you can reduce login time for students, minimize password fatigue, and strengthen security in your environment.

For more information, see Seamless Learning Access.

Unified Authentication Methods

Unified authentication methods are a new capability that lets end users on unified tenants manage all of their sign-in methods from a single, consistent interface. The Authentication Methods panel replaces the previous method-specific profile actions and gives users one place to see which methods are configured, which require setup, and which actions are available.

By providing a single authentication management experience, you can reduce password fatigue, help users keep their sign-in methods current, and simplify self-service for your environment. The following changes are available alongside the unified authentication methods:

  • All methods, including SMS, TOTP, WebAuthn, mobile, pictograph, QR code, and password, display a consistent Enroll, Manage, or Active state based on enrollment status and delegation settings.

  • During the login process, users see a reminder window that displays any authentication methods they can enroll in before logging in.

  • When a user does not have the appropriate self-service delegation, enrollment is hidden or replaced with an Active indicator.

Flexible Forgot Password Policy

A more flexible forgot password policy gives administrators on unified tenants control over the default policy without disrupting authentication or enrollment. You can now disable the policy and the platform no longer requires at least one forgot password policy to remain enabled.

By disabling the default policy, you can manage password resets entirely through your IT help desk or an external identity provider while maintaining a stable experience for end users.

Standard login and claim or enroll flows continue to work normally when the forgot password policy is disabled. When no is active and a user selects Forgot Password, RapidIdentity displays the following error: "No reset password policies enabled". To restore password recovery for users, enable a forgot password policy.

WCAG 2.2 Accessibility Improvements

RapidIdentity now supports WCAG 2.2 accessibility criteria across the primary user-facing modules. These improvements strengthen support for users who rely on screen readers, magnification, keyboard navigation, and assistive input devices. These improvements include:

  • Reflow (1.4.10): Users can zoom to 400% without two-dimensional scrolling.

  • Text spacing (1.4.12): Adjusting line height, letter spacing, and word spacing no longer breaks the layout or hides content.

  • Content on hover or focus (1.4.13): Tooltips and overlaid content are dismissible, hoverable, and persistent.

  • Status messages (4.1.3): Screen readers announce success and error messages without requiring a focus change.

  • Pointer cancellation (2.5.2) and label in name (2.5.3): These criteria reduce accidental activations and improve speech input compatibility.

Other Changes and Improvements

  • A new Jamf School source adapter allows users to import user and group data from Jamf School into RapidIdentity and ID Hub for account setup and access management.

  • Three new mapping rule language functions are available when working with multi-valued attributes, which allow rules to evaluate whether a list contains values and determine the number of items in a list.

    • isListEmpty()

    • isListNotEmpty()

    • listCount

  • Default mappings for the Jamf Pro source adapter prioritize rostered Managed Apple Accounts when available. Jamf integer IDs are added to usernames to prevent duplicates, and a fixed student role is automatically assigned.

  • When using Go! view, the permission label that was previously Classic is now Enterprise.

  • Mobile device registration no longer supports using a username and password, instead requiring mobile authorization code flow to improve security for all RapidIdentity users.

Resolved Issues

  • [RIC-7197] Fixed: The identity provider redirect bypasses the password screen when the mobile app enrollment is deleted from RapidIdentity Mobile.

  • [RIC-7234] [IDH-2323] Fixed: Diacritic characters incorrectly display as corrupted text in both the user interface and ID Hub reports. Additionally, diacritic characters in Active Directory usernames import as Base64-encoded values.

  • [RIC-7257] [RIC-7364] Fixed: RapidIdentity incorrectly marks valid LDAP filters as invalid in authentication policy, group, and delegation configurations.

  • [RIC-7405] Fixed: The SMS enrollment method fails after a successful authentication, producing a 403 error.

  • [RIC-7654] Fixed: The QR Code and Pictograph sign-in methods prompt for a local encryption password on Chromebook devices.

  • [RIC-7707] Fixed: Custom email servers that do not require authentication are unable to send emails and display the following error: "javax.mail.AuthenticationFailedException: failed to connect, no password specified".

  • [IDH-2282] Fixed: Move a group actions are incorrectly recorded as Move an account events in reports.

  • [IDH-2290] [IDH-2316] Fixed: Users remain in a Remove Pending state when a dynamic include filter is removed while an exclude filter is in place.

  • [IDH-2291] Fixed: The Password Sync Options page displays an incorrect radio button selection which can cause unintended mass password resets.

  • [IDH-2324] Fixed: Active Directory adapter initialization fails when the service account resides in a parent domain targeting a child domain. Additionally, Active Directory adapter imports fail when the value for CN=System contains 1000 or more entries.

  • [IDH-2326] Fixed: When a rename is processed and the idautoPersonRenameUsername value already contains the value being written, the LDAP modification fails with a duplicate value error and the rename fails.