Airlock IAM 8.7
Greater control over administration and authentication
Airlock IAM 8.7 expands the options for secure and targeted user management. New realms create clearly separated administrative areas, while push notifications via Airlock 2FA deliver security-relevant information directly to registered devices. Further enhancements simplify OAuth/OIDC scenarios, support regional language variants, and improve day-to-day administration.
Deliver security-relevant information directly through Airlock 2FA
The new event subscriber enables organizations to send push notifications directly to the Airlock 2FA app and to apps based on a current Airlock 2FA SDK. Users can therefore be notified about security-relevant actions or transactions through an already established and trusted channel.
The feature is supported from version 3.1.5 of the Airlock 2FA app.
A new cleanup task also helps keep the inventory of registered devices up to date. It can be configured to remove devices that have never been used or have not been used for a defined period. The Adminapp now also shows when an Airlock 2FA app was last used.
Separate users and delegate administrative rights with realms
The new realm administration makes it possible to assign users to clearly separated areas within an IAM instance. Roles determine which permissions administrators have in each realm. Administrative rights can therefore be delegated selectively without granting unrestricted access to all users.
One possible scenario is a bank working with external wealth managers. Each wealth manager can administer only the customers assigned to them, while higher-level administrators can manage multiple realms. Airlock IAM thus supports flexible organizational models with fine-grained access control.
Use additional parameters in OAuth/OIDC processes
Airlock IAM can now accept additional parameters from OAuth/OIDC authorization requests and use them in the authentication and consent process. This allows clients to pass application-specific information to Airlock IAM and incorporate it into subsequent processes.
One specific use case is bLink Consent Management 2.0: The service user submits their username so that it can be displayed by the service provider, confirmed, and subsequently validated. The implementation in Airlock IAM is deliberately generic and is not limited to the username parameter. This makes it possible to support additional custom OAuth and consent scenarios.
Use regional language variants consistently
Airlock IAM improves support for locales with country codes, such as de_CH or zh_TW. The Loginapp now matches the browser’s language settings against the languages available in IAM in accordance with RFC 4647, taking the country code into account.
Regional locales can also be used for maintenance messages and translations of the terms of service. This allows regional language variants to be used more consistently throughout the Loginapp.
Various features
More options for administration and flowsAirlock IAM 8.7 introduces further improvements for user management and the design of custom processes:
- Search user activities: Entries in the Activities tab of the Adminapp can now be searched. Successful user identification is also logged together with the flow ID and user agent.
- Find users based on token information: The advanced user search can be configured to search for users by information associated with a token, such as the mobile phone number linked to an mTAN token.
- Use cookie values in flows: The new Cookie Value Provider reads the value of an HTTP cookie and makes it available for further processing.
- Reset device tokens in any flow: The new Device Token Reset Step deletes all device tokens belonging to a user within any flow, for example as part of a password reset.
Looking ahead to the new Loginapp Design Kit and Airlock IAM 9.0
With Airlock IAM 9.0, the Loginapp will move to a new technological foundation. The new Loginapp Design Kit will be implemented as a standalone web application based on standard web technologies, providing a more flexible and sustainable foundation for designing the user interface.
Existing UI customizations cannot be transferred unchanged and must be reimplemented on the new foundation. As this transition affects most IAM projects, we ask customers and partners to familiarize themselves with the implications early and plan the necessary work.
The new Loginapp Design Kit will be released with version 8.8 in the spring of 2027 and will become mandatory starting with IAM 9.0. IAM 9.0 is scheduled for release in the fall of 2027 and will include additional important changes.
Learn more about the new Loginapp Design Kit and Airlock IAM 9.0
Release video
English version
Release video
German version
