Upcoming: Minor Version 7.2

We are pleased to announce the upcoming updates to Netwrix Identity Manager (NIM). This release focuses on making day-to-day governance work faster, with a redesigned, action-oriented dashboard, bulk actions for certification reviews, and finer control over what reviewers can do in certification campaigns.

Want the full details? Click the link below!


Important Dates

  • The update is scheduled to be released to the preproduction environment on 2026-10-12T14:00:00Z→2026-10-12T16:00:00Z
  • The update is scheduled to be released to the production environment on 2026-10-26T16:00:00Z→2026-10-26T18:00:00Z

New Features and Enhancements

New dashboard (Preview)

A new Identity Manager dashboard is available as a preview feature. Administrators can choose to activate access to this dashboard in the ActivatePreviewPages setting. When enabled, the new dashboard is shown by default, with a toggle in the top navigation bar to switch to the old dashboard for the current session. When disabled, the new dashboard is not visible or browsable.

The dashboard is built from widgets that show the tasks assigned to you and let you act on them directly:

  • My tasks — your most recent pending workflow requests and approvals
  • Review roles and risks — approve or deny access requests, including risk-flagged ones, without leaving the dashboard
  • Reconcile non-conforming roles — keep or delete access detected outside policy
  • Access certification — open campaigns with pending items, with links straight into each campaign

Widgets appear only for actions you have permission to perform. Users with no widget access are not given an empty dashboard — their landing page is My access, the self-service page.

New persistent left-hand navigation bar (part of the dashboard preview)

  • Groups Governance, Identities, Operations, and Configuration, and shows only the items you have permission to use. Pending counts appear as badges.
  • Header controls let you scope the dashboard to a population (such as Users or Guests) and use client-configurable quick-action links.
  • A search bar is included for easy navigation.

Other UI enhancements

Resource links across the application now consistently use one of two affordances: an id-card icon that opens a side details panel without leaving the page, or an arrow icon that navigates to the resource’s full page. Icon usage is now standardized so the same visual cue always triggers the same behavior.

Bulk actions in certification reviews

Reviewers get a single Bulk actions menu on the campaign review table, listing only the actions valid for the current tab and selection:

  • My items: Approve, Refuse, Forward, Delegate, Not for me
  • Delegated to me: Approve, Refuse, Not for me
  • Delegated to others: Forward, Delegate, Revoke delegation
  • Reset: appears only when the selection contains a decision that can be reset

Every bulk action opens a confirmation dialog first, showing the action, the number of items, and any filters in effect. Refusals require a comment, and applying an action to every item in a campaign requires typing a confirmation phrase. Campaign authors can turn bulk actions on or off per campaign when creating it, and completed bulk actions are recorded in the audit log.

Certification campaign action controls

Campaign authors can now choose, per campaign, whether reviewers get the Not for me and Forward actions, alongside the existing Delegate option. Approve, Deny, and Reset remain always available.

This replaces the previous site-wide setting (AccessCertificationOnlyApproveDeny), which applied to every campaign and is removed in this release. If that setting was previously set to true, existing campaigns will continue to have only Approve and Deny options; the setting is now configurable per campaign for better granularity.

Special Handling is deprecated and is no longer shown in new campaigns. Existing campaigns continue to show it.

SCIM 2.0 connector: now generally available

The SCIM 2.0 connector, introduced in Preview in version 7.1, is now generally available. It provides bidirectional identity synchronization with any RFC 7643/7644-compliant endpoint.

Key capabilities:

  • Export— reads users and groups from a SCIM endpoint into NIM for synchronization, with support for incremental (delta) exports.
  • Provisioning— creates, updates, and deletes accounts and group memberships. Supports a “deactivate instead of delete” mode to preserve accounts for reactivation.
  • Password reset— updates passwords directly on the managed system via SCIM.
  • Flexible authentication— OAuth2 client credentials, static bearer token, or HTTP Basic.
  • Schema auto-discovery— automatically detects the target system’s attribute schema at connection setup.

For complete documentation on this new connector go here.

PowerShell connector: PowerShell 7 support

The PowerShell connector (Export, Fulfill, and Sync) now supports PowerShell 7 in addition to Windows PowerShell 5.1. Administrators choose between Desktop (PowerShell 5.1, Windows only) and Core (PowerShell 7, cross-platform) in the agent settings of the PowerShell connector. Existing connections default to Desktop and are unaffected.

Bug Fixes and Miscellaneous Updates

New

Component Description
Certifications and Risks In Access Certification campaigns, the “Not For Me” and “Forward” reviewer actions are now configurable per campaign at campaign creation via new settings. They appear alongside the existing Allow Delegation setting, replacing the global AccessCertificationOnlyApproveDeny setting. Existing campaigns that had the global setting enabled continue to offer only Approve and Deny. NOTE: Special Handling has been deprecated and is no longer shown.
Configuration DateOnly properties used in C# expressions could not call common arithmetic methods such as AddDays, AddMonths, AddYears, or FromDateTime, forcing integrators to route calculations through DateTime instead. These methods are now authorized and can be called directly on DateOnly properties.
Connectors and Integrations The PowerShell connector (Export, Fulfill, and Sync) now supports PowerShell 7 in addition to Windows PowerShell 5.1. A new setting on the PowerShell connection allows the choice of Desktop (PowerShell 5.1, Windows-only) or Core (PowerShell 7, cross-platform); existing connections default to Desktop and are unaffected.
UI / UX Resource links across the application now consistently use one of two affordances: an id-card icon that opens a side details panel without leaving the page, or an arrow icon that navigates to the resource’s full page. Icon usage is now standardized so the same visual cue always triggers the same behavior.
UI / UX The navigation sidebar is now persistently visible while browsing the application and can be collapsed, listing all items previously available from the Home page. Pending-item badges show counts up to 99+, with a red indicator when new entries are available since the user’s last visit.
UI / UX A new preview setting, ActivatePreviewPages, controls visibility of the new dashboard page. When enabled, the new dashboard is shown by default, with a toggle in the top navigation bar to switch to the old dashboard for the current session; when disabled, the new dashboard is not visible or browsable.

Bug Fixes

Component Description
Access Control and Workflows When a workflow field was gated by a post-condition AccessControlRule filter, the picker modal correctly filtered suggestions but the inline autocomplete input did not, allowing the selection of values outside the filter and causing the workflow submission to fail with an HTTP 400 error. The autocomplete input now applies the same post-condition filter as the picker, so only valid values are suggested and submitted.
Access Control and Workflows Viewing an Assigned Resource Type’s details from the Permission Overview list on the Workflow Overview page failed with an internal error (“Unknown property: OwnerAssignedResourceTypes”) because the query binding was computed as if a direct navigation existed from the workflow instance, which is not the case for this view. Assigned Resource Type details now load correctly from the Workflow Overview.
Access Control and Workflows In a multi-step manual approval workflow, the review comment entered at step 2 overwrote the comment entered at step 1. Each step’s review comment is now stored and displayed independently.
Access Control and Workflows For reduced-permission users, the Workflow Overview returned a 403 (Forbidden) error even when the user did have permission to access it. This error no longer occurs.
Certifications and Risks In an Access Certification campaign running in Multiple Reviewers mode, the Set Access Certification Reviewer job failed with a primary key violation when a user was eligible as a reviewer for the same certification item through more than one profile, or through a single profile matching more than one context. The job now assigns the user as reviewer only once for that item in this case.
Certifications and Risks Recipient eligibility for delegating or forwarding access certification items was enforced only by UI picker filtering, and bulk delegation/forward used an unscoped user list with no eligibility filtering at all, allowing items to be delegated or forwarded to users without the required reception permission. Recipient eligibility is now validated server-side for both single-item and bulk delegate and forward actions, and the recipient picker for bulk actions is scoped to eligible users for the campaign’s owner entity type.
Configuration No validation error was raised when an AccessControlRule’s EntityType was “Resource” but its Filter binding targeted a different entity type, allowing silent misconfigurations that could return unintended data. A validation error is now raised identifying the rule, the conflicting binding, and the expected entity type.
Configuration A configuration item based on a Dimension (for example, ProfileContext.Dimension6) could lose track of its configuration when the same Dimension was declared in more than one configuration source that are then merged. Dimension-based configuration items are now tracked correctly when merged from multiple sources, so database upgrades complete successfully.
Configuration Configuration checks did not validate the Binding path on Access Control Filters, allowing an unresolvable or invalid navigation binding to pass silently. Configuration checks now validate this binding and raise a warning when it cannot be resolved or has no items.
Configuration Exporting a configuration with MarkForExport and MarkRoleModelForExport enabled failed with an error. The export now completes successfully; environments affected by this issue require a configuration import to pick up the fix.
Connectors and Integrations Creating a local NIM connector with the NIM Profile Template failed with an internal error (“Parent menu item is not a node”) when the Parent Menu Item was set to an entry menu item such as Nav_Connectors_AD_Entry. The connector is now created successfully in this case.
Connectors and Integrations Some icons on connector packages did not display correctly. These icons now render correctly across all connector package types.
Jobs and Policy When a user-requested composite role inferred a single role already flagged as non-conforming, validating the composite role could leave it marked as “Denied” instead of “Approved”, with the inferred single role incorrectly kept as “Non-conforming” and in cancellation. The composite role now reaches “Approved” and the inferred single role correctly shows as “Given by a Role”.
Jobs and Policy Modifying a resource type rule failed with a collation conflict error when the tempdb database used a different collation than the tenant database. Resource type rule modifications now use the tenant database’s collation for temporary tables, avoiding the conflict.
Jobs and Policy Confirming a Keep or Delete action with a comment on a composite-role reconciliation failed when the assignment’s owner ID was 65536 or higher. The action now completes successfully for any owner ID, recording the comment and the reconciliation time.
Jobs and Policy When a role with a configured grace period reached its Prolonged state, approving the renewal kept the role active through the grace period end date but failed to create the follow-up request to continue the assignment afterward, so downstream provisioning for the next period never fired. The continuation request is now created correctly, starting from the grace period end date, and goes through the normal approval process.
Logs / Performance / Security SaaS tenant responses now include an X-Robots-Tag: noindex, nofollow header on every HTTP request, preventing search engines from indexing tenant URLs even when a crawler disregards robots.txt.
Logs / Performance / Security Rebuilding configuration-dependent indexes could hold a schema-modification lock on the resources table for the full duration of the index build, causing deadlocks under concurrent load. Indexes are now created online on SQL Server editions that support it, avoiding the blocking lock.
Logs / Performance / Security Performance improvements for loading the Policies list on tenants with many dimensions configured, achieved by requesting only the dimension columns shown in the list (up to 5) instead of all configured dimensions.
Logs / Performance / Security An internal change had reused the Allowed Navigations exemption key to also exempt nested navigations reaching an entity type, diverging from the documented (Permission Path, Root Entity Type) model. This reuse is reverted, restoring exemptions to the root-entity-type model; since Allowed Navigations runs in LogOnly mode, this change has no effect on enforced authorization.
Logs / Performance / Security Audit log entries for reads performed on the Workflow Overview page recorded Performer=0 instead of the authenticated user, breaking audit traceability. These audit log entries now record the real authenticated user.
Logs / Performance / Security Progress and cancellation logs for in-process jobs, such as Apply Naming Convention, were written to the server log instead of the job’s own log file. These logs are now correctly written to the job’s log file.
Other When a query defined a custom entity type for WorkflowInstance, the inherited Identifier, IsCompleted, and WhenCompleted properties were not selectable. These inherited properties are now available on custom WorkflowInstance entity types.
UI / UX The “+CC” button on the workflow finalization screen was visible even when the workflow was not configured to send a notification email, letting a user select a recipient for an email that was never generated. The button is now only displayed when the workflow is configured to send a notification.
UI / UX The “Arguments Expression” option on the ResourceType configuration screen did not make clear what it controlled or when to use it. The option now has a clearer label with an explanatory tooltip and is listed after the more commonly used options.
UI / UX On the classification, correlation, and pending approval rule configuration screens, searching on a second column discarded the search criteria entered for the first column, so results reflected only the most recent search. Searches across multiple columns are now cumulative.
UI / UX On the classification, correlation, and automation rule configuration screens, a searched term in a text column was not highlighted immediately after a search, and the highlighting could persist or disappear incorrectly when switching tabs or canceling the search. Searched terms are now highlighted consistently and the highlighting is cleared correctly when the search is canceled.
UI / UX When a user’s photo was deleted during a workflow and the workflow was saved, the photo remained on the user record. The photo is now removed correctly, whether deleted from a workflow or directly from an existing user.
UI / UX When a workflow required approval, the approver was not displayed in the Progression section on My Tasks, making it unclear who had acted on the request. The approver is now displayed correctly.
UI / UX Notification email templates were not available in all languages supported by the product, and some interface labels displayed placeholder text instead of a translation. Notification templates and labels are now fully translated in all supported languages (Chinese, Italian, German, Korean, and Spanish).
UI / UX Corrected a regression where viewing an entry’s sources no longer showed the Owner line, with its link to the owner, in the Assigned Resource Type view even when the entry had an owner. The Owner line is now shown again.

Need help with this update?

There are many different ways to get help with our products!

Situation Action
If you feel the product is broken and not working as intended… Contact Support
If you have a question you’d like to ask other experts… Create a discussion in the community: Identity Manager > Identity Manager Discussions & Questions
If you have a feature request… Let our product team know directly: Identity Manager > Identity Manager Ideas
If you have something cool to show… Show everyone what you built: Identity Manager > Identity Manager Show & Tell

What are your thoughts?

We are always happy to hear from our users on what you like, and what you hope to see in the future. Please, share your thoughts below!

4 Likes