Highlights
- Informative Enrollment Failure Messages
Enhancements
Informative Enrollment Failure Messages
- When a user enrolls a mobile app or a desktop agent by completing an Identity Verification Workflow, there are times when enrollment fails due to policy. In the past, we used a single, generic message for all failure cases to prevent providing information that might help a threat actor to impersonate a user. However, there are times when enrollment fails due to policy violation where this generic message is not helpful to the end user. Making this messaging more specific would not make things easier for a threat actor to cause harm. With this release (and the upgrade of the Identity Server to 24.155, or higher), we give more informative error messages when enrollment fails due to one of the following policy violations:
- Biometrics are required but are not available on device.
- Private app is required but user tries to enroll with public app.
- Device must be managed but user tries to enroll an unmanaged device.
- Enrolling the device would violate the device limit policy.
Bug Fixes
- We have fixed an issue where IP address and location information was missing in some events in the Events table.
- We have improved error reporting to differentiate between a failed authentication attempt from an enrolled vs an unenrolled FIDO key.
- We have fixed an issue that prevented sms messages from being sent if phone number in directory had invalid characters (e.g., spaces are removed so numbers conform to E.164 standard).
- We have fixed an issue where failed registrations (where certificates were not being provisioned to computers) appeared as successful registrations.
Known Issues
PLAT 24.157 Release Notes PLAT 24.153 Release Notes

