RSA Cloud Access Service and Authenticators August 2026 Release Notes
13 minutes ago

    We are excited to announce the release of RSA Cloud Access Service August 2026. This release delivers new features, enhancements, and bug fixes to improve your experience with our product.  

      

      

    New Features and Enhancements

    This release includes the following new features and enhancements.

           

    Simplified Authenticator Registration and Authentication with QR Codes 

    Users can now register and authenticate with the RSA Authenticator app directly from the same iOS or Android device. QR codes displayed in My Page > Authenticators and web authentication screens are now tappable, allowing registration or authentication details to be transferred directly to the RSA Authenticator app with a single tap. This eliminates the need to manually copy registration details or switch between apps multiple times, providing a faster and more seamless experience.

     

    Identity Verification Enhancements for Secure Authentication

    Authenticating with Identity Verification is now available as an authentication option in Access Policies. You can use Identity Verification as a primary or step-up authentication method to provide users with an additional way to verify their identity during sign-in. This feature helps you maintain secure access, supports users who cannot complete self-service authentication, enables secure emergency access to web-based resources, and provides a higher-assurance verification option.

         
    Additionally, Identity Verification now supports encrypted Login Hint JWTs to help protect authentication data. To enable this enhancement, select the Login Hint JWT encrypted option in the ID Dataweb Administration Console, generate a public key, and add it to the new Encryption Public Key field in the Identity Verification Provider configuration in the Cloud Administration Console. To enable this feature, contact RSA Customer Support.

      

    Hybrid Domain Join Support for Microsoft Office 365 Direct STS

    You can now use CAS as the identity provider (IdP) for Microsoft Office 365 Direct STS to enable hybrid Microsoft Entra join for devices that are already joined to Active Directory. When you enable the Hybrid Join Devices setting, you can configure applications for hybrid Microsoft Entra joined devices. Optionally, you can upload a trusted certificate from the Connection Profile tab. A trusted certificate is required only when users sign in to Windows devices using the MFA Agent. This enhancement helps users securely access resources and simplifies device management.

    Note: Identity Router (IDR) version 12.26.0.0 is required to use this capability. 

      

    REST Agent Configuration Enhancements 

    REST Agent configuration now supports PEM certificates in addition to the existing DER format, providing better compatibility with different integrations. Certificate upload validation has been improved to ensure that uploaded certificates are currently valid, unexpired, self-signed Root CA certificates with certificate-signing capability. PEM certificates are supported in IDR version 12.26.x. IDR versions earlier than 12.26.x support only DER certificates. 

      

    Fixed Issues

    The following table lists the issues fixed in this release.

    IssueDescription
    NGX-239465
    Resolved an issue where Cloud configuration publishing failed when a custom CNAME was configured. Cloud configuration changes now publish successfully.
    NGX-229057
    Resolved an issue where the corresponding Admin Event Monitor event included the complete API key when a registered device was removed from Authentication Manager (AM). The Admin Event Monitor event no longer displays the complete API key.

     

     

    Identity Router (IDR) 12.26.X Now Available

    The IDR 12.26.x release is now available. RSA recommends that all customers upgrade to this version.

        

    Identity Router Update Schedule    

    Identity routers are updated according to the following schedule. Download the latest identity router image when you deploy new identity routers to benefit from the latest security improvements.

     

    DateDescription

    ANZ: August 24, 2026  
    CA/SG: August 25, 2026
    EU/ JP: August 26, 2026

    NA/GOV/IN: August 27, 2026  
    Updated IDR software is available to all customers.

    Default: October 10, 2026

    Default date when IDRs are scheduled to automatically update to the new version unless you modify the update schedule or update manually.

    Last Permitted: November 11, 2026

    If you have postponed the default date, this is the final day on which updates can be performed.

    Enforced: November 14, 2026

    If the IDR is not upgraded after the last permitted date for any reason, RSA automatically initiates a mandatory upgrade seven days later. You will receive an email notification and a Cloud Administration Dashboard alert with the scheduled update date.

         

    Upcoming End of Primary Support (EOPS) Details

    The following table provides details on RSA products reaching the end of support within the next six months. 

     

    ProductVersionEOPS DateExtended Support Level 1/Level 2
    Authenticator for iOS & Android 
    4.5 
    October 2026 
    MFA Agent for Microsoft Windows 2.3.3/2.3.4/2.3.5 December 2026  
     RSA Authentication Manager  8.7 SP2  January 2027  January 2028 / January 2029 

    For more details, refer to Product Lifecycle.

            

    Product Documentation and Support

    Visit RSA Community to access the latest version of the product documentation, answers to common questions, solutions to known problems, community discussions, and case management.  

             

    Recent Release Notes

      
    Previous Release NotesCloud Access Service and Authenticators Historical Release Notes