Ideagen Hub 9.0.0 release notes
Who is this article for?
Users looking for more information about the latest changes and updates to the platform.
No special access or permissions are required.
The article outlines the new features and improvements in the Ideagen Hub 9.0.0 release, available from 3 June 2026.
Features
Multi-factor authentication (MFA) via email
Tenant administrators now have the option to enable email-based MFA for their organisation, providing an additional layer of security for users signing in with Hub's internal username and password.
- This applies only to Hub internal authentication, meaning users signing in with a username and password. Users signing in through the corporate IDP SSO will not be affected.
- Tenant administrators can enable or disable email MFA at the organisation level through the Admin Console under Security Center, Authentication settings.
- It's possible for tenant administrators to override this setting for individual users via the Admin Console in User Management.
- When email MFA is enabled, users will be asked to enter a verification code sent to their email after entering their username during sign-in.
- Support role users have the same access to MFA settings as Tenant Administrators.
Launch Hub from your IDP dashboard with IDP-initiated SAML workflow
Users can now log in to Hub directly from your corporate identity provider dashboard, so there's no need to start from the Hub login page. This feature is available for corporate identity providers that support IdP-initiated SAML workflows.
- Tenant Administrators can create, edit, and delete SAML identity providers from the Admin Console, Security Center, and Authentication settings, now with support for IdP-initiated workflows (previously, only SP-initiated workflows were supported).
- When you choose an IdP-initiated workflow as part of the SAML configuration, a single user account is automatically linked to multiple identity providers, allowing both IdP-initiated and SP-initiated login flows. This means users can log in either through the identity provider dashboard or the Hub login page.
Separate login URLs per Authentication Type
Tenant administrators now have the option to use separate login URLs for internal and external users, providing a personalised sign-in experience for each group.
- Tenant administrators can adjust login URL settings at the organisation level through the Admin Console.
- Welcome emails will automatically include the appropriate login URL depending on the user's authentication type. If your organisation is set to send welcome emails automatically, updating the login URL configuration will trigger a new welcome email.
Audit Trail report
Tenant administrators can now generate a PDF report of user activity records to help with compliance checks.
- Tenant administrators can run the report through the Admin Console, under the Security Center and Compliance section.
- The report can be filtered by a date range, with a maximum of one year's records included in each report generation.
- The report includes all user login success, login failed, user created, user updated and user deleted events.
- Once the report is ready, it will be sent to the Tenant administrator's Notification inbox.
Other updates
- Users can now share their thoughts on Mazlan Regulatory Intelligence through written feedback, in addition to the thumbs up or thumbs down options. Please note, Mazlan Regulatory Intelligence is available only if your organisation has not opted out of AI features.
- Leave positive feedback by clicking on the thumbs up.
- Share negative feedback after clicking on the thumbs down.
- Provide any feedback through the generic feedback link.
- When a new user is created the default role is set to "User" in the Create User UI. This ensures least-privilege access from the moment an account is created, reducing the risk of unintentional admin privilege assignment.
- Changes to the selection regarding acceptance of IDP-initiated SAML sign-in are not allowed. This also applies to the signing and encryption settings, as these are not supported by IDP-initiated SAML sign-in. To update any of these settings, please create a new IdP configuration and remove the old one that is no longer valid.
Fixes
Removed signing certificate download from OIDC IdP configuration as it is not required for OIDC configuration.
Users can now clear their Pronouns value from their user profile.