Octopus Authentication Server version 6.8.8 - Release announcements

Announcements

Dear Customers,

We are pleased to announce that Octopus Authentication Server version 6.8.8 is now available. This release focuses on securing access to the Octopus Management Console (MC), adds standards-based programmatic API access, and improves Entra ID Staged Rollout support.

Highlights

New Security menu in the Management Console

MC access controls are now grouped in one place. The existing IP Allowlist has moved here from System Settings.

Option to block direct Management Console login

A new Allow Management Console login page setting lets admins block the MC Login screen and its login API, so administrators sign in to the MC through the User Portal instead. This also closes a potential push bombing vector.

Programmatic access with OAuth2 clients

Integrations can now call the Management API using OAuth2 client credentials, each with an assigned MC role (Admin, Helpdesk or Auditor) and support for zero-downtime secret rotation.

Short-lived access token for Remote AD Agent installation

Agent registration no longer uses Super Admin credentials. A short-lived MC access token is used instead (Remote AD Agent installer version 3.2).

Email as login hint for Entra ID Staged Rollout

For environments where the email address is the source anchor and differs from the UPN.

What existing customers should know

Before disabling direct MC login: For existing customers, Allow Management Console login page remains enabled by default, so nothing changes on upgrade. We recommend disabling it once you have:

  • Moved any integrations that call the Management API with MC login credentials to OAuth2 clients. Integrations that are not updated will stop working once the setting is disabled.
  • Familiarized your administrators with signing in to the MC through the User Portal.
  • Planned to use Remote AD Agent installer version 3.2 or later for any new Agent installations. Agents that are already installed are not affected.

Behavior change: QR Code Authentication toggle

When the QR Code Authentication toggle is disabled, the Authentication Server now rejects all QR login requests for that service. Previously, QR logins could still be processed with the toggle off. Please review this setting on your services if your users rely on QR login.

Known issue: blank page after upgrade

If signing in to the MC from the User Portal shows a blank page after the upgrade, clear the browser cache and reload the page (in Chrome or Edge: open Developer Tools, right-click Reload and select Empty Cache and Hard Reload).

Learn more

For full details, including all bug fixes, see the Octopus Authentication Server 6.8.8 Release Notes.

If you have any questions or need help planning the move to OAuth2 clients, please contact Secret Double Octopus Support at support.doubleoctopus.com or reach out to your Customer Success engineer.

Thank you,
The Secret Double Octopus Team

Footer - Secret Double Octopus