PingOne Advanced Identity Cloud

Migration dependent features

Certain PingOne Advanced Identity Cloud features require changes to your tenant environments before they can be introduced. In such cases, Ping Identity defines a migration strategy for the feature. Some examples of feature migration strategies are:

  • Updating the format of your static configuration

  • Updating the way your automated applications are configured

  • Restricting the new feature only to tenants built after the feature is introduced

xref:#current_migration_dependent_features

Summary of migration dependent features

Feature Effective date Summary

Secure RCS access

2025-06-10

Ping Identity has introduced the ability to secure the openicf WebSocket endpoint used for communication between Advanced Identity Cloud and RCS client mode. This feature is enabled by default in tenants created on or after June 10, 2025. Learn how to enable in tenants created before that date in Secure RCS access.

Two-factor authentication (2FA) profile attributes

2025-01-09

Ping Identity has introduced five multivalue (array) string attributes which can be used to store references to a user’s associated two-factor authentication (2FA) devices.

  • deviceProfiles

  • devicePrintProfiles

  • webauthnDeviceProfiles

  • oathDeviceProfiles

  • pushDeviceProfiles

These five attributes are enabled by default in tenants created on or after January 09, 2025. Learn how to enable them in tenants created before that date in 2FA profile attributes.

Additional indexed string attributes

2024-11-12

Ping Identity has introduced 15 additional indexed string attributes which can be used as general purpose extension attributes. These 15 attributes are enabled by default in tenants created on or after November 12, 2024. Learn how to enable them in tenants created before that date in Additional indexed string attributes.

Password timestamp attributes

2024-02-06

Ping Identity has introduced two indexed string attributes which can be used to query when a user password was last changed and when it is set to expire:

  • passwordLastChangedTime

  • passwordExpirationTime

These two attributes are enabled by default in tenants created on or after February 06, 2024. Learn how to enable them in tenants created before that date in Password timestamp attributes.

Outbound static IP addresses

2023-04-18

ForgeRock has introduced outbound static IP addresses to each of your tenant environments. Outbound static IP addresses are enabled by default in tenants created on or after April 18, 2023. To enable in tenants created before that date, you can raise a support ticket.

Tenant administrator mandatory 2-step verification

2023-02-03

ForgeRock has deprecated the option to let Advanced Identity Cloud tenant administrators skip 2-step verification. Customers can continue to use the skip option in their tenants, but this functionality will be removed from Advanced Identity Cloud on April 2, 2024.

Application management

2023-01-12

ForgeRock has introduced an improved application management UI to Advanced Identity Cloud. The UI is only available in tenants created on or after January 12, 2023.

Event hooks

2023-01-12

ForgeRock has introduced event hooks to Advanced Identity Cloud. This feature is only available in tenants created on or after January 12, 2023.

Learn more in Event hooks migration FAQ.

Group identity

2022-11-29

ForgeRock has introduced a group identity to simplify the management of permissions and authorizations for collections of users. The group identity is enabled by default in tenants created on or after November 29, 2022. Tenants created before that date can follow an upgrade path to enable it.