- Introduced Identity Activity Center, automatic access request reviews, multi‑session MFA for databases, RBAC/device‑trust for SAML apps, database health checks, and Kubernetes CRD enhancements.
- Added security hardenings such as removal of insecure TLS cipher suites, PKCE support for OIDC, disallowing TOTP for per‑session MFA, and raising the Linux kernel minimum to 3.2.
- Breaking changes include removal of legacy ALPN upgrade mode, AWS endpoint URL mode, altered Terraform provider role defaults, and deprecation of several TLS cipher suites.