Feature comparison between old and new versions
This document compares the main features of the old and new versions to help you determine if the new version meets your needs.
Background
When planning the new version in 2021, we analyzed the usage frequency of each feature in the old version. The current version includes the most popular features, based on our analysis, product roadmap, and development complexity.
We significantly simplified the top 20% most-used features and also added and standardized more configuration options. We removed the least-used features. Some of these features are no longer supported. Going forward, IDaaS will focus on strengthening its foundational capabilities, supporting more scenarios, and enhancing security.
The new version prioritizes features that meet the following criteria:
-
Commonly used features from the previous version
-
Improvements to identity security
-
Alignment with the long-term product direction
-
General and fundamental identity capabilities
-
Complexity of R&D Support
Feature comparison table
|
Major module |
Functional module |
Sub-module |
Version 1.x |
Version 2.x |
|
Instance |
/ |
Multiple free instances |
Not supported |
Supported. You can create a maximum of 3 instances. Submit a request to create more. |
|
/ |
Instance trial |
Not supported |
Supported. A 15-day trial is available by default. |
|
|
/ |
Instance release |
Supported |
Supported |
|
|
Overview page |
/ |
/ |
Supported |
Supported |
|
Application |
Application Marketplace |
Accumulated application templates |
Not supported |
Supported |
|
Pre-integrated SSO templates |
Not supported |
Supported. The new version greatly simplifies operations. It includes 100 preset templates and over 40 convenient templates. |
||
|
One-to-one configuration documents |
Not supported |
Supported and continuously updated. |
||
|
Application Management |
Application list |
Supported |
Supported |
|
|
Application lifecycle |
Supported |
Supported |
||
|
Application key rotation |
Not supported |
Supports manual rotation. |
||
|
Sub-account management |
Supported |
Supported |
||
|
Single sign-on configuration |
Supported |
Supported |
||
|
Application authorization |
Supported. Available in a separate authorization menu. |
Supported. Available in Application Management. |
||
|
Application synchronization - Self-developed integration |
Supported |
Supported. Uses an event-based synchronization mechanism with asynchronous pushes via internal MQ messages. |
||
|
Application synchronization - Synchronization scope |
Supported. The synchronization scope is determined by application authorization. |
Supported. The synchronization scope is determined by the synchronization scope configuration, separate from application authorization. |
||
|
Application synchronization with the System for Cross-domain Identity Management (SCIM) protocol |
Supports inbound synchronization. |
Standard applications support SCIM export and let you adjust field mappings as needed. |
||
|
Application synchronization - Pre-integrated templates |
Supports RAM sub-account synchronization. |
Includes templates with best practices for RAM and CloudSSO applications. |
||
|
Account |
Account Management |
Account list |
Supported |
Supported |
|
Account lifecycle |
Supported (Create, delete, modify, move, enable/disable, lock, and unlock) |
Supported (Create, delete, modify, move, enable/disable, lock, and unlock) |
||
|
Offboarding operations |
Supported |
Not supported |
||
|
Identity verification |
Supported |
Not supported |
||
|
Dormant accounts |
Supported |
Not supported |
||
|
Account synchronization |
Supported |
Supported |
||
|
Organizational structure |
Tree-based organization management |
Supported |
Supported |
|
|
Organization lifecycle management |
Supported |
Supported |
||
|
Organization synchronization |
Supported |
Supported |
||
|
Accounts in multiple organizations |
Supported |
Not supported yet |
||
|
Group Management |
Group list |
Supported |
Supported |
|
|
Group lifecycle |
Supported |
Supported |
||
|
Group synchronization |
Supported |
Not supported |
||
|
Group member management |
Supported |
Supported |
||
|
Data Dictionary |
User data dictionary |
Supported |
Supported |
|
|
Organization data dictionary |
Supported |
Not supported |
||
|
Group data dictionary |
Supported |
Not supported |
||
|
Data classification |
Assign permissions based on property values |
Supported |
Not supported |
|
|
Authentication |
Logon methods/Authentication sources |
Logon method templates |
Supported |
Supported |
|
View logon method list |
Supported |
Supported |
||
|
Logon method lifecycle management |
Supported |
Supported |
||
|
Authentication methods |
DingTalk |
Supported |
Supported |
|
|
WeCom |
Supported |
Supported |
||
|
AD/LDAP |
Supported. Cannot connect to private networks. |
Supported. You can connect to private networks through dedicated endpoints. |
||
|
Text message |
Supported |
Supported |
||
|
Lark |
Not supported |
In development and not yet supported. |
||
|
TOTP |
Not supported |
Supported |
||
|
WebAuthn |
Not supported |
Supported |
||
|
Third-party logon with OpenID Connect (OIDC) |
Not supported |
Supported. You can use this feature to integrate with Okta and AAD. |
||
|
Security Settings |
Global secondary authentication |
Supported. TOTP and text message. |
Supported. TOTP, email, text message, and WebAuthn. |
|
|
Application secondary authentication |
Supported. TOTP and text message. |
Not supported |
||
|
Logon security |
Supported |
Supported |
||
|
Logon password security |
Supported |
Supported |
||
|
Password policy |
Password security |
Supported |
Supported |
|
|
RADIUS |
/ |
Supported |
Not supported |
|
|
Certificate management |
/ |
Supported |
Not supported |
|
|
Authorization |
Application authorization |
Authorization menu |
Supported |
Not supported. Application authorization is done in Application Management. There is no separate menu. |
|
Authorize by application |
Supported |
Supported |
||
|
Authorize accounts by application |
Supported |
Supported |
||
|
Authorization time limit |
Not supported |
Not supported yet |
||
|
Reverse authorization |
Supported |
Not supported |
||
|
Permission system |
Grant authorization to third-party applications |
Supported |
In development and not yet supported. |
|
|
Audit |
User logs |
View user log list |
Not supported. User and management logs were previously mixed. |
Supported |
|
View synchronization log list |
Supported |
Supported |
||
|
View management log list |
Supported |
Supported |
||
|
Others |
Synchronization center |
DingTalk address book synchronization |
Supported. Only full synchronization is available. |
Supported. You can customize the synchronization scope, and operations are greatly simplified. |
|
AD/LDAP synchronization |
Supported |
Supports inbound synchronization. Outbound synchronization is in development and not yet supported. |
||
|
Network endpoints |
Private network access |
Not supported |
Supported |
|
|
Audit log delivery |
Deliver instance audit logs to customers |
Not supported |
Supported |
|
|
Management operation risk control |
Mandatory verification for critical operations |
Not supported |
Supported |
You can also activate a new version instance for free to experience the new features and capabilities.