Release Notes Version 8.3.2
Posted June 2026
Features and Enhancements
Infrastructure and Security:
- This release includes infrastructure updates and security patches, including security updates for Microsoft SQL Server and updates to support the realignment of the TPR service. No customer-facing features were introduced.
Resolved Issues
- Certificate Login Failure for Canada DND Users: Fixed an issue where users authenticating with Canada Department of National Defense certificates received a blank login error screen and were unable to login to MAG.
Release Notes Version 8.3.1
Posted May 2026
Features and Enhancements
Infrastructure and Security:
- This release includes infrastructure updates and security patches, including an upgrade of the NokNok FIDO server from version 9.2 to version 9.5 to address vulnerabilities. No customer-facing features were introduced.
Release Notes Version 8.3
Posted April 2026
Features and Enhancements
USPV Proofing Workflow:
- FedRAMP / Non-FedRAMP USPV Verification Tabs: The proofing request workflow has been updated to display separate Verify USPV MAG/FedRAMP and Verify USPV Other/Non-FedRAMP tabs in the webcam proofer queue. An Approve USPV action has also been added for USPV proofers in the onboarding team view.
Release Notes Version 8.2
Posted April 2026
Features and Enhancements
OTP Administration:
- FedRAMP / Non-FedRAMP OTP Tab Separation: The MAG UI now features dedicated FedRAMP and Non-FedRAMP OTP tabs for Exostar administrators. The previous View OTP, Proof OTP, and Proof USPV tabs have been replaced with four new tabs: View MAG OTP – FedRAMP, View Other OTP – Non-FedRAMP, Proof MAG OTP – FedRAMP, and Proof Other OTP – Non-FedRAMP, enabling support admins and EPAs to clearly distinguish between MAG users (FedRAMP) and non-MAG users.
USPV / IEW Workflow:
- Approve IEV for USPV Administrators: The MAG Requests tab now includes an Approve IEV option for USPV administrators. Clicking Approve IEV opens the IEV request inbox, allowing administrators to review and action pending IEV requests.
- Webcam Requests Tab – Proof IEV: The MAG Requests tab now includes a Webcam Requests tab with a
Proof IEV option for Webcam proofers supporting USPV reviews.
Resolved Issues
- Teams Invitation Self-Registration Error: Fixed an issue where users registering via a Microsoft Teams invitation link incorrectly received an opt-out error during the self-registration flow. The error was caused by a navigation bug on the Organization Match Found page. The opt-out message now only appears when the backend explicitly returns the DUPLICATE_ORGN error code.
- Dashboard Tile Misalignment in Microsoft Edge: Fixed an issue where application dashboard tiles were
misaligned in Microsoft Edge after an Angular framework upgrade. The layout now renders correctly
across supported browsers. - Missing Column Headers in Connected Accounts (Chrome): Fixed a display issue on the Connected
Accounts login page where the account selection table was missing its column headers (User
ID/Nickname, Company, Active Applications, Last Accessed) in Google Chrome after an Angular
framework update. - Role Management Icon Alignment: Fixed a UI alignment issue in Role Management where the remove (×)
icon for selected Service Providers was displayed below the Service Provider name instead of inline,
following an Angular framework upgrade. - Sponsor Codes Not Visible in Approval Queue: Fixed an issue where sponsor codes entered by an
Application Administrator during the access request process were not carried through to the Service
Provider Administrator approval queue. Sponsor codes are now consistently visible at all approval
stages. - Proofing Level Upgrade Blank Screen: Fixed an issue where users were unable to complete a proofing
level upgrade due to a blank screen or error page during the purchase and activation flow.
FedRAMP MAG Release Notes 1.0
Posted December 2025
These release notes are specific to FedRAMP mode in MAG. To learn more, click the link to view the release notes – FedRAMP MAG Release Notes 1.0
Release Notes Version 8.1
Posted August 2025
Features and Enhancements
Organization Management:
- SP Admin Org Unsuspend: Service Provider Admins can now unsuspend organizations for their applications, except when the suspension was applied by an Exostar Portal Administrator (EPA). Note: This feature is only available to EPAs.
Request Approval:
- Export Results to Excel: The requests approval UI now allows exporting results to Excel, with options to download page results (25/50/100) or all results (up to 5,000).
SCIM Provisioning:
- Region Code Format Update: SCIM provisioning now strips the country prefix from region codes (e.g.,
US-CA → CA).
Resolved Issues
- Role Management Service Provider Name Overlap: Fixed a UI display issue in Role Management where
Service Provider names overlapped when an Admin had multiple applications assigned (no functional
impact).
Release Notes Version 8.0
Posted July 2025
Features and Enhancements
Security and Authentication:
- FIDO2 FIPS Certified Security Key Support: MAG now supports FIDO2 FIPS certified security keys (such as a YubiKey with FIPS validation) as a second factor for authentication and credential elevation.
- Phone OTP Security Notice: A security notice has been added to the verification method selection screen informing users that phone-based OTPs are less secure than other available options.
Branding:
- Login Page Rebrand: The login page has been updated to reflect the latest Exostar branding, including an updated layout and styling of the Acceptable Use Policy banner.
- Header and Footer Rebrand: The MAG header and footer have been updated to reflect the latest Exostar branding.
- Email Template Rebrand: System-generated email templates now align with 2025 branding standards, featuring the new Exostar logo, brand colors, and standardized layout.
Resolved Issues
- Subscription Notification Email Fix: Fixed the approval instructions included in the user subscription notification email sent to Application Admins and Service Provider Admins.
- Duplicate Backup OTP Credentials: Fixed the issue where multiple backup OTP credentials were shown as duplicate rows; now a single row is displayed per credential type.
- Request Inbox Pagination After Approve/Deny: Fixed an issue in the new Request Inbox where approving or denying a request did not load the next 100 requests in the queue for Admins.
- Acceptable Use Policy Not Visible on Login Page: Fixed an issue where the Acceptable Use Policy was not visible on the MAG login page.
- SP Admins Tab Performance: Fixed a performance issue causing delays of up to 30 seconds when accessing the SP Admins tab.
To see an overview of the upcoming changes, click here for MAG 8.0 Overview.
Release Notes Version 7.10 Available
Posted May 2025
Features and Enhancements
- Improved Org Admin Add User Guidance: Updated text guidance when an org admin adds a user without subscribing them to any applications, to clarify next steps.
- Security Questions No Longer Required for Account Setup: The user activation process has been updated so that security questions are no longer required to set up a new account.
Resolved Issues
- SP Admin Approval Requirement Removed: Removed the additional questions that SP admins were required to answer before approving a request.
- Deny Text Box Character Limit Increased: Increased the character limit on the deny text box when rejecting a request.
- Role Management Issues Resolved: Resolved multiple issues that prevented successful role management through the new role management feature.
- Account Connections Link Updated: Updated the “Read more about account connections” link so it points to the correct page.
Release Notes Version 7.9 Available
Posted March 2025
Features and Enhancements
- Terms and Conditions Review Requirement: Org Admins and Org Stewards are now required to review and agree to Exostar’s General Terms and Conditions, MAG service agreement, Privacy policy, and Terms of access at least once every 5 years.
- FedRAMP Rules of Behavior Annual Review: Exostar employees in MAG organizations with FedRAMP mode enabled are now required to review and accept the FedRAMP Rules of Behavior at least once a year.
- Hardware Authentication Account Lockout: User accounts will be locked after 100 consecutive failed hardware authentication attempts.
- Request Inbox Batch Size Options: In the new request inbox, users can now view requests in batches of 100, 50, or 25.
- No Results Message in Request Inbox: In the new request inbox, if there are no pending requests or a search returns no results, a “No results found” message is now displayed.
Release Notes Version 7.8.3 Available
Posted January 2025
Features and Enhancements
Reporting:
- FIS Daily Certificate Report Optional Columns: First Name, Last Name, Email, Phone Number, User Status, Cert Profile Type, and Cert Create Time are now optional columns when generating an FIS Daily Certificate Report.
- External Org ID in Daily Organization Report: The External Org Id field has been added to the Daily Organization Report.
Security:
- Security Questions Removed from Password Reset: Answering security questions is no longer an allowed option for resetting a password.
Administration:
- New Role Management UI for EPAs: The new role management UI has been enabled for Exostar Portal Admins (EPAs).
- Return to Login from Logout Page: Users can now navigate back to the login screen from the updated logout page.
Resolved Issues
- Bulk Delete Application Display Error: Resolved an interface error where some applications the organization is subscribed to were not displayed when an org admin attempted to bulk delete applications.
- Legacy Self-Registration Skipping SP Admin Approval: Resolved an issue where subscription requests originating from the legacy self-registration process skipped the SP admin approval step.
- EPA Unable to Revoke FIS Certificates: Resolved the issue where Exostar Portal Admins were unable to revoke a user’s FIS certificates.
- EPA Can Now Revoke In-Process FIS Certificates: Exostar Portal Admins can now revoke a user’s FIS certificate that is stuck in the in-process status.
Release Notes Version 7.8 Available
Posted September 2024
Features and Enhancements
FedRAMP Mode:
- FedRAMP-Compliant Mode for Service Provider Applications: Service Provider Applications can now switch to a FedRAMP-compliant standard upon request, enforcing PII controls and FIPS 140-2 compliant authenticators for users, admins, EPAs, SP Admins, Adoption Admins, and Org Stewards.
Request Inbox Enhancements:
- Enhanced Org Steward Terms & Conditions UX: Org Stewards can now accept terms and conditions on behalf of organizations they manage via an enhanced user experience.
- Enhanced Org Steward Application Access Authorization: Org Stewards can now authorize users for application access via an enhanced user experience.
- Enhanced App Admin Request Authorization: App Admins can now authorize user requests for application access via an enhanced user experience.
- Enhanced SP Admin Request Approval: Service Provider Admins can now approve user requests via an enhanced user experience.
- Enhanced EPA Organization Approval: Exostar Portal Admins (EPAs) can now approve organizations for application access via an enhanced user experience.
Other Improvements:
- OTP Policy Link on Login Page: A link to the Exostar OTP policy has been added to the login page for easy reference.
- CAPTCHA for Self-Registration: The self-registration process has been re-enabled with a CAPTCHA challenge required on each registration attempt.
- Bulk Upload Enhancement: The bulk upload (beta) has been enhanced to make it easier to access the upload template and user guide.
- Help Link Relabeled: The “Go to MyExostar” help link has been relabeled to “Get Help”.
Resolved Issues
- Self-Registration Opt-Out Error Message Improved: Improved the error message shown when a user tries to self-register to an existing organization that has opted out of the invitation process.
- Identity Proofing Invalid Data Error Message Improved: Improved the error message shown during the self-service identity proofing process when a user’s profile contains invalid data.
- Deactivated Org Admins Excluded from Emails: Deactivated organization admins are no longer included in notification emails.
- Duplicated Web Page When Adding User: Resolved an error causing a duplicated web page when an organization admin tries to add a new user with access to some service provider applications.
- EPA Role Assignment Issue: Resolved an issue preventing Exostar Portal Admins (EPAs) from assigning administrative roles to users.