What's New in Imprivata Enterprise Access Management 26.2
Imprivata Enterprise Access Management with MFA 26.2 contains the following new features and technology updates.
New Features
The Verify Identity feature in each user record provides an authentication workflow when your IT service desk must confirm a caller's identity before providing support. This protects against social engineering attacks where a bad actor impersonates a legitimate user. See Service Desk Verification.
Risk-Based Access (RBA) allows authentication requirements to change dynamically based on the risk level of an authentication attempt. Risk evaluation is performed by Imprivata EAM's integration with Imprivata Identity Threat Detection and Response (ITDR). The Advanced Passwordless Access license is required.
Imprivata EAM 26.1 introduced RBA for Desktop Access. In Imprivata EAM 26.2, RBA evaluation and enforcement is extended to Remote Access, Web SSO, and Self-Service Password Reset.
In addition, RBA supports Authentication Strength Map Management for each workflow - Administrators can now create, edit, save, and validate custom Authentication Strength Maps. See Risk-Based Access.
Risk-Based Access (RBA) allows authentication requirements to change dynamically based on the risk level of an authentication. Risk evaluation is performed by Imprivata EAM's integration with Imprivata Identity Threat Detection and Response (ITDR).
Imprivata 26.2 ensures that when Remote Access users authenticate through VPAM tunnels (rather than directly on your enterprise network), RBA assesses risk based on the user’s true network context, not the tunneled or abstracted network address.
When a user cannot authenticate during Self-Service Password Reset (SSPR) — because they have no enrolled device or cannot remember their credentials — Imprivata presents a "Verify Identity" option. The user scans a government-issued ID and takes a live selfie. Imprivata validates the match using the Persona ID proofing service, Persona issues a verified claim to Imprivata, then Imprivata permits a password reset. All attempts are logged in the audit log. See Imprivata Self-Service Password Reset.
This feature enables automatic user lifecycle management in Imprivata Cloud Platform through Active Directory and EAM appliance integration with SCIM (System for Cross-domain Identity Management), eliminating the requirement for Microsoft Entra ID when using Face authentication. EAM automatically synchronizes user lifecycle events (create, update, enable/disable, delete) with the Imprivata Cloud Platform.
Configure an Azure File Share and specify a folder where audit records are automatically uploaded.
This configuration uses Microsoft Entra ID service principal authentication and Azure role-based access control to write audit export files to the file share.
For more information, see Configure Azure Files for Audit Record Archiving.
Beginning with 26.1, the Classic Windows login has reached end of life and is no longer supported. The Classic Windows login provides desktop access on Windows endpoints.
After upgrading the Imprivata appliance to 26.1, the Windows desktop authentication experience automatically transitions from the Classic Windows login to the Imprivata login. Consider the following:
-
This behavior occurs the first time the Imprivata agent syncs with an upgraded appliance.
-
This behavior occurs regardless of the version of the Imprivata agent. For example, the first time a 25.4 agent syncs with a 26.1 appliance, users will see the Imprivata login when authenticating to Windows desktops.
-
You cannot revert to the Classic Windows login. Choosing which login experience to use is no longer configurable using computer policy customization (Computer policy > Customization tab).
Imprivata has prepared sample messaging that you can use to inform your users of this change. For more information, see this sample email template.
This release introduces Imprivata virtual appliance support for Google Cloud Platform.
A new report dedicated to Epic-related events makes it easy to browse, filter, and group events generated by the Imprivata Connector for Epic Hyperdrive, as well as other Epic-related events.
A new deployment report shows the version of Imprivata Connector for Epic Hyperdrive installed on managed endpoints, making it easy to identify endpoints that require an update.
In addition, the Computers list now supports filtering by Imprivata Connector for Epic Hyperdrive version.
Added support for the non-LDAP passive Narrator workflow, enabling environments where the Epic username differs from the EAM username.
A new enterprise-specific SAML certificate for passive Narrator is also available, providing enhanced security.
This feature requires the Imprivata Connector for Epic Hyperdrive 26.6 or later.
Computer Policies can now define settings for Imprivata Connector for Epic Hyperdrive directly, eliminating the need to manage the connector’s XML configuration file.
This feature requires the Imprivata Connector for Epic Hyperdrive 26.6 or later.
Epic is a registered trademark of Epic Systems, Inc.
Ecosystem Integrations and Qualifications
Schiller CardioVit FT Series ECG Devices
Clinical users can badge into these ECG devices, ensuring that each ECG measurement is associated with, and transmitted alongside, the username of the clinician who performed it.
Mindray TEX20 Point-Of-Care Ultrasound
Clinical users, predominantly physicians, can now securely log in to mobile ultrasound devices using their Imprivata-enrolled badges. This integration simplifies authentication, reduces reliance on manual password entry, and helps protect Protected Health Information (PHI) without disrupting clinical workflows.
Technology Updates
The Imprivata EAM Self-Service Password Reset application has been updated with a design that aligns with the interface users are familiar with from Web SSO authentications. The authentication methods required before resetting a user password can include face biometric, SMS, email, Imprivata ID, and Imprivata PIN. This updated feature is not available for the Imprivata agent on thin clients. The legacy application that enables self-service password reset with security questions is still available when the new feature is not enabled. See Self-Service Password Reset.
This is a reminder that Internet Explorer is not supported. Any functionality related to Internet Explorer or IE mode will be deprecated as of December 2026.
While Microsoft has not announced a release date for their planned update to LDAP channel binding and LDAP signing requirements, it is recommended that Imprivata administrators verify that their Imprivata directory (domain) connections are configured for SSL. When the update is applied, any directory connection that is not configured for SSL may fail.
To verify the connection settings, go to the Directories page (Users menu > Directories) and open the required domain. Verify that Use TLS for secure communication is selected.
As part of Imprivata's continuing effort to increase our security posture, beginning with the 7.4 release, Imprivata disables the use of older TLS versions 1.0 and 1.1 for all appliance communications.
For more information on TLS usage, see the "About TLS Communication" topic in the Imprivata Online Help.
As part of Imprivata's continuing effort to increase our security posture, this release includes two modes of API access through the Confirm ID and ProveID APIs:
-
Full
Full access enables the ability to use the Confirm ID COM interface. Full access is required in the following areas because of the reliance on the COM interfaces:
-
Clinical Workflows
-
EPCS
-
Imprivata Connector for Epic Hyperdrive
-
When EAM for MFA (formerly Confirm ID) needs a password.
-
-
Restricted
In restricted mode, access to
PasswordandUserAppCredsresources are disabled. AResourceRequestthat includes an attribute id ofPasswordorUserAppCredsreturns a response with a message stating that access is restricted and status code403.
By default, Confirm ID access is disabled and ProveID API access is set to restricted. The settings to manage API access are on the API access page in the Imprivata Admin Console.
Considerations
The following sections describe changes in behavior in Imprivata Enterprise Access Management
Enterprises who have clinicians' faces enrolled for authentication in Mobile EPCS must migrate those enrollments to the new Imprivata Cloud Platform (ICP) Face Recognition support. This is accomplished with a custom migration tool. For more information, see Mobile EPCS — Face Migration.
Does not apply to customers whose end-users have faces enrolled only for Desktop Authentication.
Face authentication is a new authentication method and is supported on Windows.
-
If your enterprise uses mixed endpoints (thin clients, medical devices, etc.), test to verify that they continue to work after enabling Face recognition.
-
If you encounter issues on non-Windows platforms, disable multiple second factors using computer policy overrides and reach out to your vendor and Imprivata representative.
Imprivata has identified limited cases where Imprivata agents running on non-Windows platforms are unable to authenticate depending on user policy configuration. Limiting the second factor options in your environment is recommended to resolve this.
Beginning with 25.2, you can no longer directly run the Imprivata agent installer. This includes:
-
Double-clicking the MSI.
-
Right-clicking the MSI and running as an administrator.
Launching the installer directly requires you to execute the MSI from an elevated command prompt. Directly running the MSI results in an error message stating that you do not have the required permissions. This behavior occurs even if you are logged into the Windows endpoint with administrator credentials.
This requirement does not affect deployments performed through Microsoft Endpoint Configuration Manager (SCCM) or any other third-party software deployment tool.
Imprivata's Secure Walk Away added support for a Nordic Bluetooth Low Energy (BLE) receiver in Imprivata OneSign and Imprivata Confirm ID 7.11. The Bluetooth receiver sensitivity may vary for different mobile devices. If your users report that their workstations lock because Secure Walk Away does not detect their mobile devices, adjust the Secure Walk Away – Imprivata ID Sensitivity slider control in the computer policy assigned to those workstations.
For more information, see Configuring Imprivata Secure Walk Away
Upgrade Considerations
For more information on upgrading Enterprise Access Management, see the Imprivata Upgrade portal.