Zum Inhalt springen

Auth0 Release Notes

613 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Angaben zum Datum

Datum aus der Quelle.

Aufgenommen am .

Auth0

Auth0: Curated Blocklists in Tenant ACLs jetzt allgemein verfügbar

Curated Blocklists in Tenant Access Control Lists sind jetzt allgemein verfügbar und erlauben es, per auth0_managed-Matcher dynamisch aktualisierte Threat-Intel-Kategorien wie auth0.low_reputation, auth0.tor, auth0.proxy, auth0.vpn und auth0.icloud_relay_proxy in ACL-Regeln zu blockieren.

### Overview Curated Blocklists extend Auth0 Tenant Access Control Lists (ACLs) by integrating dynamically updated threat intelligence directly into your Tenant ACL rules. Instead of manually tracking and updating individual IP ranges or ASNs, Attack Protection customers can delegate IP risk management to Auth0 Threat Intel, ensuring continuous, automated protection against evolving threat vectors. ### Available Categories Referencing curated categories using the `auth0.<category>` prefix allows precise blocking based on traffic origin: * `auth0.low_reputation`: High-risk IP addresses identified as active threat vectors or origin points. * `auth0.tor`: Active TOR exit nodes. * `auth0.proxy`: Residential, data center, or public proxies. * `auth0.vpn`: Commercial Virtual Private Network (VPN) providers. * `auth0.icloud_relay_proxy`: Egress nodes for Apple iCloud Private Relay traffic. ### API Request Structure To configure curated lists, pass the desired identifiers in the `auth0_managed` array within the `match` object of your rule definition: ```json POST /api/v2/network-acls { "description": "Block low-reputation IPs", "active": true, "priority": 1, "rule": { "action": { "block": true }, "match": { "auth0_managed": [ "auth0.low_reputation" ] }, "scope": "authentication" } } ``` ### Configuration & Exception Handling Configure curated blocklists via the Network ACLs Management API inside the `auth0_managed` matcher block. We recommend te…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Aufgenommen am .

Auth0

Auth0: Enterprise Connect als Beta verfügbar

Enterprise Connect ist als Beta verfügbar und ermöglicht es, Auth0 als modulare B2B-Identitätsschicht zu nutzen, mit Federation über SAML oder OIDC, Enterprise SSO, SCIM-Provisionierung und Self-Service-Onboarding; Interessenten wenden sich an das Sales-Team.

Enterprise Connect is now in Beta. It lets you use Auth0 as a modular B2B identity layer. You can federate your existing SAML or OIDC capable authorization server to Auth0 and layer on enterprise SSO, user provisioning, and self-service onboarding / setup capabilities for B2B use cases. A guided setup walks you through federating over OIDC or SAML, including Okta as a connection strategy, configuring the integration, self-service onboarding, adding user profile claims into ID tokens using Actions code, and wiring up outbound SCIM user provisioning. Connection lifecycle events (connection.created, connection.updated, connection.deleted) keep your local domain map in sync as customers onboard. Please contact the Sales team if you would like to evaluate Enterprise Connect Beta.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Aufgenommen am .

Auth0

Auth0: Token Vault Privileged Worker jetzt im Early Access

Token Vault Privileged Worker ermöglicht in Early Access autonomen Agents ohne Nutzersitzung den Abruf von Drittanbieter-Tokens aus Token Vault, authentifiziert per Private Key JWT oder mTLS und auf bestimmte Connections und Scopes beschränkbar.

We're thrilled to announce __Token Vault Privileged Worker__ is now in __Early Access__, letting your autonomous agents pull a user's third-party tokens - Gmail, Drive, Slack, and more - from Token Vault with no user session required. Token Vault today assumes a human is actively logged in to hand over their token; if your agent runs on a schedule, in CI, or wakes up at 2am with no one signed in, there may not always be a user signed in. Privileged Worker gives your background agents their own strong credential to authorize that exchange directly. With privileged worker, you can register a trusted worker identity, authenticate it with Private Key JWT or mTLS, and it can request a specific user's third-party token directly from Token Vault. We give you the ability to pin each worker credential to specific connections and scopes, so a compromised credential can only reach what it was actually authorized for. To enable the Privileged Worker Early Access release in your Auth0 tenant once available in your environment, please contact your Auth0 Account Team. Learn more in the [documentation](https://auth0.com/docs/secure/call-apis-on-users-behalf/token-vault/privileged-worker-token-exchange-with-token-vault#privileged-worker-token-exchange-with-token-vault).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Aufgenommen am .

Auth0

Auth0: Organization-Level Roles im Early Access

Organization-Level Roles sind im Early Access und ermöglichen Rollen mit eigenen Berechtigungen und Zuweisungen pro Organisation, verwaltbar über Management API oder Dashboard, während das bestehende tenantweite RBAC unverändert bleibt.

You can now create roles scoped to individual organizations — without metadata workarounds or custom Actions logic. __What's new__ Auth0 Organizations previously required you to share tenant-wide roles across all your customer organizations. With org-scoped roles, each organization gets its own role definitions, independent permissions, and user assignments. __What you can do in EA__ - Create, update, and delete roles within a specific organization via the Management API or Dashboard - Assign org-scoped roles to users and enterprise groups - Pre-assign a role when inviting a user to an organization __What stays the same__ Existing tenant-level RBAC is unchanged. Tenants not using org-scoped roles are unaffected. To learn more, review [Organization Roles](https://auth0.com/docs/manage-users/organizations/organization-roles "Organization Roles"). By using Organization-to-Application Entitlement, you agree to the applicable Free Trial terms in Okta’s Master Subscription Agreement and Okta’s Privacy Policy during use of the Early Access feature. The Free Trial terms can be found within the Master Subscription Agreement at [https://www.okta.com/agreements\](https://www.okta.com/agreements.).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Aufgenommen am .

Auth0

Auth0: Organization-to-Application Entitlement im Early Access

Organization-to-Application Entitlement ist im Early Access und steuert nativ, auf welche Anwendungen die Mitglieder einer Organisation zugreifen dürfen, wobei die Durchsetzung standardmäßig deaktiviert und pro Organisation aktivierbar ist.

**Organization-to-App Entitlement** lets you control which applications the members of an organization can access - natively, without custom code. If you sell multiple products and different customers have purchased different combinations, you can now enforce those boundaries directly in Auth0. When a member of an org tries to log in to an app they're not entitled to, Auth0 denies access automatically. No Actions. No metadata checks. No custom logic to maintain. **Opt-in, per org.** Entitlement enforcement is disabled by default - existing orgs and login flows are unaffected until you explicitly enable it. You can roll out to one org at a time, making it safe to adopt incrementally. **Safe to configure before you go live.** You can set up all your entitlements first, then enable enforcement when you're ready. There's no risk of locking members out during configuration. ![org-to-app](//images.ctfassets.net/kbkgmx9upatd/rUfIbrGmUfR5DgFtEtZXB/2bae811541e02ba9905a790e4d1648cf/dbf50f9c-b7c6-474a-98e4-34c90d325c83.png) To learn more, review [Grant Per-Application Access to an Organization](https://auth0.com/docs/manage-users/organizations/configure-organizations/grant-application-access "Grant Per-Application Access to an Organization"). By using Organization-to-Application Entitlement, you agree to the applicable Free Trial terms in Okta’s Master Subscription Agreement and Okta’s Privacy Policy during use of the Early Access feature. The Free Trial terms can be fou…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Aufgenommen am .

Auth0

Auth0: Dashboard-Suche für Organization-Mitglieder in der Beta

Die Dashboard-Suche für Organization-Mitglieder ist als Public Beta verfügbar und erlaubt die Echtzeitsuche nach Name, E-Mail und ID sowie das Filtern nach Sperrstatus, schrittweise ausgerollt für Public-Cloud-Tenants.

__Dashboard Search for Organization members is now available in Public Beta!__ Find your organization members faster without scrolling through paginated lists. Users can now __search Organization Members in real time by name, email, ID and filter by blocked status.__ Rolling out progressively to Public Cloud tenants starting this week, with broader availability in the coming weeks. For detailed documentation on search capabilities, visit our [Product documentation](https://www.auth0.com/docs/get-started/auth0-overview/dashboard/search-and-filter-auth0-dashboard).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Aufgenommen am .

Auth0

Auth0: Cross App Access (XAA) für Resource Applications im Open Early Access

Cross App Access (XAA) für Resource Applications ist im Open Early Access und erlaubt es, MCP-Server und APIs ohne Codeänderung per Tenant-Konfiguration für KI-Agenten und andere Unternehmensanwendungen mit zentraler Richtliniendurchsetzung bereitzustellen.

We're excited to announce that __Cross App Access (XAA) for Resource Applications is now in Open Early Access__. You can use this feature in production today at no additional cost through Auth0 Enterprise Connections, available to __Enterprise, B2B Pro, and B2B Essential__ customers, or test it during the __trial period on Free tenants__. Cross App Access (XAA) is a __new open standard for passing authorization across domains, built for the emerging Enterprise AI landscape, enabling seamless agent-to-app and app-to-app connections__. Connecting AI Agents and Third-Party Apps in an enterprise introduces two key challenges: poor IT visibility into data sharing, and repetitive user consent flows. XAA solves this by centralizing IT control over these connections, eliminating consent fatigue while improving governance and visibility into data sharing. This release is for the Resource App side: any __Auth0 customer looking to expose their MCP servers and APIs to AI Agents and other enterprise applications. No code changes are needed__: simply configure the feature on your Auth0 tenant to instantly support central policy enforcement and a seamless user experience. XAA supports both SAML and OIDC enterprise IdPs, with specific support for Okta. ![Activation-toggle](https://cdn.auth0.com/blog/xaa-ea-conn-activation.png) To learn more, read our [documentation](https://auth0.com/docs/ai-agents-mcp/cross-app-access).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Aufgenommen am .

Auth0

Auth0: Kunden-Admins konfigurieren Drittanbieter-Zugriff beim SSO-Setup

Bei Self-Service Enterprise Configuration Tickets kann die Entscheidung über den Zugriff durch Drittanwendungen nun an den Kunden-Admin delegiert werden, der dazu im Setup-Wizard einen neuen Schritt sieht.

When generating a Self-Service Enterprise Configuration ticket, you can now delegate the third-party application access decision to your customer's customer admin — rather than setting it yourself at ticket creation time. Enable third-party access delegation on the ticket, and the customer admin will see a new step in the setup wizard where they can choose to allow third-party applications to use their SSO connection. If they enable it, the connection is configured for third-party application access. If they skip it, the setting is not applied. When the option is omitted, the wizard experience is unchanged. This option is mutually exclusive with setting domain connection access directly on the ticket — you either set the value directly or delegate it to the customer admin, not both. **Note:** If the connection is associated with an Auth0 Organization and you want third-party applications to authenticate users through that organization, you must separately configure the organization to allow third-party client access after setup is complete. [Learn more](https://auth0.com/docs/authenticate/enterprise-connections/self-service-enterprise-configuration/manage-self-service-enterprise-config)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Aufgenommen am .

Auth0

Auth0: Anonymous Sessions jetzt in der Beta

Anonymous Sessions sind für zahlende Auth0-Kunden als Beta verfügbar und ermöglichen zustandslose Sitzungen für nicht angemeldete Nutzer über den neuen Endpoint POST /anonymous/token samt Verknüpfung mit dem Profil nach dem Login.

We are excited to announce that Anonymous Sessions is now available in Beta for Auth0 customers with paid plans. This feature enables applications to create and manage stateless sessions for unauthenticated users, supporting use cases like guest checkout, shopping cart persistence, and pre-login personalization. ### What's in the beta: - __A new Core Endpoint:__ POST /anonymous/token – Create sessions, refresh sessions, request access tokens - __Seamless Session Linking:__ Link anonymous sessions to authenticated users through pre-registration and post-login actions. - __Activity Preservation:__ All anonymous session data from different devices can follow the authenticated user profile upon login. #### ✨ New configuration options - **Configure your anonymous sessions length** - Anonymous Sessions length configuration is now available as a tenant setting - **Configure your clients and APIs to allow for anonymous sessions** - Anonymous Sessions configuration is now available in Applications and APIs #### 🚀 Use Cases: - Guest checkout flows in e-commerce applications - Pre-login personalization and recommendations - Seamless user onboarding with continuity on known data - Cross-device continuity ## Documentation Links [Anonymous sessions documentation](https://auth0.com/docs/manage-users/sessions/anonymous-sessions) ## Join the beta! If you're interested in joining the anonymous sessions beta program, please send a request through the [Auth0 Support Cente…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Aufgenommen am .

Auth0

Auth0: Dashboard-Suche für Roles jetzt in der Beta

Die Dashboard-Suche für Roles ist als Public Beta verfügbar und ermöglicht die Echtzeitsuche nach ID und Name, schrittweise ausgerollt für Public-Cloud-Tenants.

__Dashboard Search for Roles is now available in Public Beta!__ Find your Roles faster without scrolling through paginated lists. Dashboard users can now __search Roles in real time by ID and name.__ Rolling out progressively to Public Cloud tenants starting this week, with broader availability in the coming weeks. For detailed documentation on search capabilities, visit our [Product documentation](https://www.auth0.com/docs/get-started/auth0-overview/dashboard/search-and-filter-auth0-dashboard).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Aufgenommen am .

Auth0

Auth0: Third-Party Apps für Organizations allgemein verfügbar

Third-Party Apps für Organizations sind allgemein verfügbar, sodass Tenant-Admins den Zugriff von Drittanbieter-Apps pro Organisation erlauben oder blockieren können, wobei er standardmäßig blockiert ist und die Zustimmung pro Organisation gilt.

Third-party applications now work with Auth0 Organizations. Tenant admins can allow or block third-party app access on a per-organization basis — access is blocked by default, so existing organizations are unaffected until you explicitly opt in. - To authenticate users within an organization, a third-party app's connection must be promoted to domain level (`is_domain_connection: true`). - User consent is scoped per organization — granting access in one organization does not carry over to another. ![Third-party-app-org-toggle](https://cdn.auth0.com/blog/third-party-apps-orgs.png) To learn more, read [Enable third-party application access for an Organization](https://auth0.com/docs/manage-users/organizations/configure-organizations/enable-third-party-application-access).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Aufgenommen am .

Auth0

Auth0: Google One Tap für Universal Login im Early Access

Google One Tap wird im Universal Login jetzt im Early Access unterstützt und ermöglicht die Anmeldung per Fingertipp über ein Overlay ohne Formulare und Weiterleitungen.

Bring frictionless, one-tap authentication to your users! Auth0 now supports Google One Tap within the Universal Login prompt for Early Access. Users are greeted with a secure, non-intrusive identity overlay that lets them sign in instantly with a single tap, completely eliminating manual forms and page redirects. Check out the [Auth0 Google Social Connection documentation](https://auth0.com/docs/authenticate/identity-providers/social-identity-providers/google-one-tap) to learn how to enable it for your web applications!

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Aufgenommen am .

Auth0

Auth0: IPSIE session_expiry Claim für Okta- und OIDC-Verbindungen

Auth0 unterstützt für Okta- und OIDC-Enterprise-Connections den session_expiry-Claim gemäß IPSIE SL1, sodass die Auth0-Sitzung nicht länger dauert als vom Upstream-IdP vorgegeben; SAML-Connections werden nicht unterstützt.

Auth0 now supports the session_expiry claim for Okta and OIDC-based Enterprise connections, in alignment with the IPSIE SL1 profile. When your upstream identity provider includes a session_expiry value in the ID token, Auth0 uses it to enforce the ceiling on the Auth0 session lifetime — evaluated as the minimum of the IdP claim, your tenant's absolute session expiration, and any expiry set via Actions. This closes a real gap in federated sessions: when a federated user's access expires at their IdP, their Auth0 session terminates accordingly — no stale sessions, no residual access. Enable it on any Okta/OIDC Enterprise connection via the Dashboard or Management API. For end-to-end enforcement down to your downstream applications, deploy a Post-Login Action to inject the final session_expiry value as a custom claim in the Auth0-issued ID token. Note: Supported on Okta/OIDC Enterprise connections only. SAML connections are not supported. This feature implements the evolving IPSIE SL1 open standard. See the [product documentation](https://auth0-feat-session-expiry-oidc-ipsie.auth0-mintlify.app/docs/authenticate/enterprise-connections/session-expiry-enterprise-connections)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Aufgenommen am .

Auth0

Auth0: Outbound SCIM für Benutzer über Event Streams

Ein neues Outbound-SCIM-Action-Template für Event Streams überträgt user.created-, user.updated- und user.deleted-Ereignisse ohne eigene Infrastruktur als SCIM-2.0-Requests an nachgelagerte Anwendungen und lässt sich per Skript anpassen.

We are excited to announce the release of our new __Outbound SCIM Action template for Event Streams__! This new capability delivers an infrastructure-free way to push `user.created`, `user.updated`, and `user.deleted` events directly from Auth0 to any `SCIM 2.0`-compliant downstream application, making it easier than ever to automate your user provisioning workflows. __Key Highlights:__ - __Infrastructure-free provisioning__: Use our ready-to-copy [Outbound SCIM Action template](https://github.com/auth0/opensource-marketplace/tree/main/templates/outbound-scim-EVENT\_STREAM) to translate Auth0 user events into standard `SCIM 2.0 REST` requests (`POST`, `PUT`, and `DELETE`). This eliminates the need to build, host, or maintain custom webhook consumers. - __Template-driven customization__: You retain full control over your provisioning logic. Edit the script to map specific Auth0 attributes to your downstream `SCIM` schema, or enable opt-in behaviors like `UPSERT` (create-on-update) for trickling in users. - __Built-in fault tolerance__: The template script handles API timeouts and retries for transient failures natively. __How to get started:__ To use this feature, navigate to __Event Streams__ in the Auth0 Dashboard, create a new stream with __Auth0 Actions__ as the destination, and apply the __Outbound SCIM provisioning template__. *Note: Because the Event Stream only reacts to new events, we recommend performing a on…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Aufgenommen am .

Auth0

Auth0: Refresh Token Metadata allgemein verfügbar

Refresh Token Metadata ist für Enterprise-Kunden allgemein verfügbar und erlaubt, bis zu 25 eigene Schlüssel-Wert-Paare an Refresh Tokens zu hängen, die sich per Action und Management API lesen und ändern lassen.

We're excited to announce that **Refresh Token Metadata** is now **Generally Available** for Enterprise customers. Refresh Token Metadata allows you to attach custom key-value pairs to refresh tokens, enabling richer context storage and more personalized authentication experiences. ### What's included in the feature **Store Custom Data on Refresh Tokens** You can now attach up to 25 custom key-value pairs to each refresh token. This metadata persists throughout the token's lifecycle and can be accessed or modified via the Management API. ```javascript // In Post-Login Action exports.onExecutePostLogin = async (event, api) => { api.refreshToken.setMetadata('deviceName', event.request.user_agent); api.refreshToken.setMetadata('loginRegion', event.request.geoip?.countryCode); api.refreshToken.setMetadata('orgContext', event.organization?.id); }; ``` **Management API Support** Access and manage refresh token metadata programmatically: - `GET /api/v2/refresh-tokens/{id}` - Retrieve token with metadata - `PATCH /api/v2/refresh-tokens/{id}` - Update token metadata - `DELETE /api/v2/refresh-tokens/{id}` - Revoke token Learn more about Refresh Token Metadata in our [documentation](https://auth0.com/docs/secure/tokens/refresh-tokens/refresh-token-metadata) and our [blog](https://auth0.com/blog/auth0-session-refresh-token-metadata-guide/)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Aufgenommen am .

Auth0

Auth0: Google Workspace Directory Sync für Gruppen ohne Anmeldung nutzbar

Google Workspace Directory Sync für Gruppen ist im Early Access ohne Enrolment verfügbar, und synchronisierte Gruppen lassen sich nun Auth0-Rollen auf Tenant- und Organisationsebene zuweisen.

We are happy to share that Google Workspace Directory Sync for Groups is now available in Early Access without enrolment! All [previously announced](https://auth0.com/changelog#3sQ4fmmnZQuIAu9jZBoBOS) Early Access capabilities including automated group synchronization, "Sync all" functionality, and partial group selection are now available out-of-the-box without enrolment. Additionally, you can now natively assign groups synced through Google Workspace to Auth0 tenant-level RBAC roles and Auth0 organization-specific roles, allowing group members to automatically inherit correct permissions when they log in. This update is available to all customers in public cloud today, and will be gradually rolling out to private cloud environments in the coming weeks. To get started, navigate to your Google Workspace enterprise connection in the Auth0 Dashboard and configure your group synchronization preferences. Learn more in our public documentation: - [How to Sync Google Workspace Users and Groups to Auth0 with Directory Sync](https://auth0.com/docs/authenticate/identity-providers/enterprise-identity-providers/google-directory-sync) - [Assign Roles for Enterprise Groups](https://auth0.com/docs/manage-users/access-control/configure-core-rbac/rbac-users/assign-roles-to-groups)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Aufgenommen am .

Auth0

Auth0: Dashboard-Suche für APIs in der Beta

Im Dashboard lassen sich APIs nun in der Public Beta in Echtzeit nach ID, Identifier oder Name durchsuchen, der Rollout in Public-Cloud-Tenants erfolgt schrittweise.

__Dashboard Search for APIs is now available in Public Beta!__ Find your API faster without scrolling through paginated lists. Dashboard users can now __search APIs in real time by ID, identifier or name.__ Rolling out progressively to Public Cloud tenants starting this week, with broader availability in the coming weeks. For detailed documentation on search capabilities, visit our [Product documentation](https://www.auth0.com/docs/get-started/auth0-overview/dashboard/search-and-filter-auth0-dashboard).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Aufgenommen am .

Auth0

Auth0: Verbesserte Refresh-Token-Verwaltung im Early Access

Zwei neue Endpunkte, GET api/v2/refresh-tokens und POST api/v2/refresh-tokens/revoke, ermöglichen gezieltere Suche und das Widerrufen von Refresh Tokens (bis zu 100 IDs gleichzeitig) und sind im Early Access auf Anfrage aktivierbar.

We're excited to announce the addition of two new endpoints for refresh token management, introducing granularity in search and revocation capabilities, as well as bulk revocation of refresh tokens (up to 100 individual IDs at a time): - A new GET api/v2/refresh-tokens endpoint which allows retrieving refresh tokens for a user_id or a user_id + client_id combination - A new POST api/v2/refresh-tokens/revoke endpoint which allows RT revocation: - by ids (up to 100 at a time) - by user_id (remove all refresh tokens for a given user) - by user_id + client_id (remove all refresh tokens bound to a client for a given user) - by user_id + client_id + audience (remove all refresh bound to a client and a resource server for a given user) The new endpoints are in __Early Access__. Please contact your TAM or open a support ticket to get this feature enabled in your tenant

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Aufgenommen am .

Auth0

Auth0: Verbesserte Bot-Erkennung im Signup-Flow

Ein aktualisiertes Machine-Learning-Modell erkennt im Signup-Flow mehr automatisierten Traffic bei weiterhin wenigen Fehlalarmen und wird automatisch für Enterprise-Tenants mit Attack Protection ausgerollt.

We have updated the machine learning model driving Bot Detection during the Signup Flow. This update lowers false-negative rates to intercept more automated traffic while keeping false-positive rates low for valid users. __What's New:__ __Smarter Signup Security:__ Optimized thresholds catch advanced bot behaviors while preserving a seamless registration experience for legitimate users. __Consistent Protection at Scale:__ The model now delivers uniform detection accuracy across tenants of all sizes, regardless of your baseline traffic volumes. __Note:__ This model optimization specifically targets the signup flow and rolls out automatically to Enterprise tenants utilizing Attack Protection with no customer action or migration steps required. To learn more about Bot Detection check out our online docs [here]("https://auth0.com/docs/secure/attack-protection/bot-detection)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Aufgenommen am .

Auth0

Auth0: Inbound SCIM Groups für Enterprise Connections allgemein verfügbar

Gruppen in Inbound SCIM für Enterprise Connections sind allgemein verfügbar, sodass synchronisierte Gruppen Auth0-Rollen auf Tenant-Ebene oder organisationsbezogen zugewiesen werden können und Enterprise-Kunden SCIM-Provisioning für Gruppen selbst konfigurieren können.

We’re pleased to announce that support for Groups within Auth0’s [Inbound SCIM](https://auth0.com/docs/authenticate/protocols/scim/configure-inbound-scim) for Enterprise Connections capability is now Generally Available (GA)! This release closes the loop between identity provisioning and access control by allowing you to natively map synced groups to Auth0 roles at two levels: globally at the tenant level, or scoped specifically to an organization based on the user’s login context. Additionally, developers can now accelerate B2B onboarding by empowering their enterprise customers to self-configure SCIM provisioning for groups directly. __What’s new in GA:__ Building on our [Early Access](https://auth0.com/changelog#6osxJFJUB5gsCePUpSanRQ) capabilities, this release introduces the following enhancements to deliver out-of-the-box B2B delegated administration: - __Associate tenant-level RBAC roles with Enterprise Groups__: For global access, you can assign Auth0 tenant-level roles directly to SCIM-provisioned groups. Any member of the synced group will automatically inherit these roles globally. - __Assign Organization scoped roles to Enterprise Groups__: You can now assign organization scoped roles to SCIM-provisioned groups. In tandem with [Auto-Membership](https://auth0.com/docs/manage-users/organizations/configure-organizations/grant-just-in-time-membership), your customers' users will automatically inherit workspace-scoped permissions the moment they log i…

Originalquelle(öffnet in neuem Tab)Problem melden