Changelog
Deprecated: built-in Azure AD target system
The built-in Azure AD target system is deprecated. It is no longer possible to create new Microsoft Azure AD target systems. For new implementations, use the Entra ID (PowerShell v2) connector, which offers full cloud support and more flexibility. Existing systems will continue to work and remain supported for now. Before deleting any Azure AD target system, review dependencies carefully. Deletion is permanent and cannot be undone.
Release: 2026.01
Modules: Provisioning
Multi Checkbox can be set as required
It is now possible to make an entire Multi Checkbox element required on forms. When enabled, users must select at least one option before submitting.

Watch the feature demo in the HelloID Service Automation Product Update January 2026.
Release: 2026.01
Modules: Service Automation
Fixed General 2026.01
Moved external JavaScript libraries to cdn.helloid.cloud (like cdn.jsdelivr.net) instead of using third party CDNs.
Release: 2026.01
Modules: Provisioning , Service Automation , Access Management
Fixed Provisioning 2026.01
Source, target, or notification system names that are unusually long can overflow their designated UI containers in several areas, causing layout issues and reducing readability.

In the target systems configuration, correlation fields appear duplicated. This can lead to confusion during mapping altough both options lead to the same configuration.

The Account tab in Active Directory Built-in target systems displays an unnecessary vertical scrollbar at certain screen resolutions, even though there is sufficient space for the content.
Release: 2026.01
Modules: Provisioning
Rule mining: minimum group size set as percentage
The minimum group size for a condition to appear in a Rule mining report is now defined as a percentage of active persons. Any condition that applies to a group smaller than the calculated minimum is excluded from the results. The calculated minimum is rounded up and always at least 2. Watch the feature demo: HelloID Provisioning Product Update January 2026.
Release: 2026.01
Modules: Provisioning , Governance
Milestones: Rule mining
Direct link to request a product for a user
You can now generate a direct link that opens the page to request a specific product for a specific user. This link can be shared with a manager or product owner so they can request the product for that user. Simply navigate to the user’s product request screen via the User dashboard (Management > Managed products or Managed users) and copy the URL. Watch the feature demo in the HelloID Service Automation Product Update January 2026.
Release: 2026.01
Modules: Service Automation
Products API end-points extended to return access groups
The GET /products and GET /products/{id} API endpoints now also return the groups linked to each product (ID and name), providing a clear overview of group–product relationships. This makes administration, reporting, and audits faster and easier, and reduces the need for manual work, custom scripts, or inefficient API workarounds.
Release: 2026.01
Modules: Service Automation
Fixed Service Automation 2026.01
- Improved the datasource deletion confirmation to also check for usage on the right side of dual-list configurations.
- Fixed an issue where custom-entered self-service product SKUs (codes) were not tracked by the user interface.
- Ensured that markdown in product descriptions is rendered correctly within the product card.
- Resolved loading issues for image assets that were still referencing the legacy CDN in Admin screens
Release: 2026.01
Modules: Service Automation
Preview Changes 2026.01
Provisioning
- Exclude persongroups based on percentage
- Use combined values id <-> name as attributes
- Deprecate: Built-in Azure AD Target system
Service Automation
- Removed HelloID theme support except HelloID theme
- Change default local SA agent script execution duration to 30 minutes
- Add Required Field Option to Multi-checkbox in Dynamic Forms
- Routing URL to managed users and managed product request
- Show the number of (selected) items in each side of the dual list
- Add Access Groups to product(s) API v1 end-points
General
- Moved external javascript libraries to cdn.helloid.cloud like (cdn.jsdelivr.net) instead of using cdn of third party.
Release: 2026.01
Modules:
Item counts added to dual lists
Dual lists in forms now show the total number of items on both the left and right sides. These numbers update automatically as items are selected and moved, making large lists easier to work with.
Release: 2026.01
Modules: Service Automation
Improved readability in Rule mining reports
In Rule mining reports, fields that have both an ID and a display name now show the display name in the list of conditions. When you hover over the field name, the field ID is shown. This ID is used in calculations, since field names may not be unique.
In addition, the Details window (Condition sets tab) now displays both the display name and the ID of each field.
See the HelloID documentation for a list of fields to which this applies.
Release: 2026.01
Modules: Provisioning , Governance
Milestones: Rule mining
PowerShell target system migration to v2
The December 2025 release introduces the ability to migrate a PowerShell target system to PowerShell v2. PowerShell v1 target systems were deprecated in March 2025, and this option makes it easier to transition existing PowerShell v1 target systems to PowerShell v2. If you are unsure whether your system is PowerShell v1 or v2, open the target system in HelloID; PowerShell v1 systems display a deprecation message at the top of the page and have a Migrate button on the General tab. The migration process preserves the target system’s configurations, and ensures that business rules granting entitlements in the target system will continue to work. However, to complete the migration, target mappings must be recreated using the PowerShell v2 graphical interface, as v1 scripted mappings are not supported in a v2 system. In addition, all account, permission, and resource scripts must be manually updated to comply with the PowerShell v2 script format. Note that the migration is irreversible and that the system will be temporarily disabled during the process.
Watch the feature walkthrough in the HelloID Product Update December 2025.
Release: 2025.12
Modules: Provisioning
Return date in product request details
A product’s return date is now visible in the request details. An icon indicates when a product is set to expire for a user. Hover over the icon to view the date. 
Release: 2025.11
Modules: Service Automation
Comment and tags on excluded issues
You can now add a comment and tags when excluding an issue from the Reconciliation report. This helps to document the reason for exclusion and makes it easier to find and filter excluded issues later.
Release: 2025.11
Modules: Provisioning , Governance
Milestones: Reconciliation
Status indicators on product request timeline
New icons on product request timeline entries make it easier to quickly understand the status of a product request and the actions linked to it.
Any actions linked to the Approved state will be executed
Any actions linked to the Returned state will be executed
The product request’s time limit has been set or reset
The request was handled outside the configured approval workflow
Release: 2025.11
Modules: Service Automation
Beta: Rule mining
Rule mining is now available as part of the Governance module, upon request. This feature helps create the most efficient set of Business Rules by automatically identifying shared characteristics among persons in HelloID Provisioning who share the same entitlements in connected target systems. It is especially useful when onboarding new target systems, as it only includes entitlements not yet managed within HelloID.
Administrators can configure rule mining by selecting target systems, up to five relevant source data fields, and the minimum group size for matching persons. Next, a rule mining report can be generated. The report lists condition sets ranked by efficiency, showing how many entitlements are shared among persons who meet the condition, as well as the number of exceptions. Potentially redundant condition sets are flagged.
For each condition set, you can view entitlement details, the matching persons (starting with those missing any entitlements), and any alternative condition sets.
Rule mining is available on the Provisioning dashboard under Business > Rule mining.
Watch the feature walkthrough in the HelloID Product Update November 2025.
Release: 2025.11
Modules: Provisioning , Governance
Milestones: Rule mining
Product actions optional on denied recertification requests
Administrators can now choose whether to execute product return actions when denying a recertification request through the Recertification administration page. Audit messages include this information.
Release: 2025.11
Modules: Service Automation , Governance
Milestones: Recertification
Link an unmanaged account to a person
An unmanaged account in a target system can now be linked manually to a person in HelloID via the Import entitlements report.
Accounts and permissions can be imported from a target system if they are not yet managed in HelloID, but users are entitled to them according to the business rules. The Import entitlements report provides an overview of such accounts and permissions in a target system and now also allows to manually link accounts to persons before the import. Once imported, accounts and permissions are granted to the respective persons in HelloID, and any manually linked accounts are updated with the person’s correlation value.
This enhancement replaces functionality previously provided by the Correlation report for Active Directory (AD) and Azure AD target systems. The Correlation report has been removed.
You can find the Import entitlements report in the Provisioning dashboard: go to Business > Entitlements > Import. To manually link an account, select the target system, click the link button next to the person, and then find and link the account.

Release: 2025.10
Modules: Provisioning
Recertification request history
A complete history of all handled and pending recertification requests is now available through the Recertification request history page. The page provides a clear overview of historical data, and makes it easy to follow up on specific recertification tasks, troubleshoot issues, and run audits. Filter and search options make it quick to locate specific requests. New search options include the ID of the user the product was requested for, product ID, request ID, and recertification request ID. Two new rights have been added for this page:
- Recertification Management - View request history: allows viewing the page.
- Recertification Management - Manage request history: required to retry failed product actions or mark actions as succeeded.
To access the page, go to Recertification > Request history in the Admin dashboard.
*Note: *Recertification is part of the Governance module.

Release: 2025.10
Modules: Service Automation , Governance
Milestones: Recertification
June 2025
Provisioning
Changed:
- Reconciliation for PowerShell v2 target system. With this you can create a reconciliation report and take action for Powershell v2 target systems. Assuming the target system has the capabilitie to read all accounts & permissions. Currently we support the processing of up to 3 million records for reconciliation. This limit includes records from all configured systems (Powershell v2 and Active Directory).
Fixed:
- Reconciliation when starting an exclude action with the exclude related permissions toggle enabled could result in duplicate actions and exclusions
- Reconciliation when starting an exclude action on account issues with the exclude related permissions toggle enabled will now display the correct number of actions
- Reconciliation when starting a bulk action for actions that are already locked the bulk action will never finish and show incorrect counts
- Reconciliation when retrieving account data for an issue results in an error the old account data is shown
- Filtering on date account field in reconciliation report or excludes doesn’t work
- Reconciliation when there are multiple persons with the same reference for an account, the permission issues where not always checked against the correct person
Service Automation
Changed:
- Display campaign iteration progression information
- Distinguishing recertification campaign types in UI
- Recertification request state filter in Insights details overview
Fixed:
- Icons do not render in GitHub readme
- Can not approve a recertification as a delegated approver
- PowerShell Script editor not shown when creating or editing a Delegated Form (hotfix)
Release: 2025.06
Modules:
Milestones: Reconciliation , Recertification