Blog

Driving smarter, more flexible identity security: What’s new in SailPoint Identity Security Cloud

Author

  • jerryaubel12

    SailPoint

We’re excited to announce a series of powerful enhancements to SailPoint Identity Security Cloud that directly address some of the most common challenges our customers face today. These new features are designed to give admins more control, reduce complexity, and expand the ways enterprises can streamline identity operations at scale.

Custom User Levels

Custom user levels provide for more flexible choices to meet the operational and security needs of our customers. Admins can now define their own named user levels and configure exactly what rights those levels grant. This provides greater precision, security, and flexibility, ensuring users get the right level of access for their responsibilities—no more, no less. 

The result: simplified governance, reduced risk of over-privileged access, and improved user experience for both admins and end users. General availability currently planned for Q4 2025.

Support for account deletion

Account lifecycle management is at the heart of identity security. Support for account deletion enables customers to delete accounts at the appropriate point in the identity lifecycle, such as when a person leaves the organization.

Admins can now configure account deletion directly within policies, ensuring that when an identity leaves the organization, their accounts are fully removed across connected systems.

Time bound access

Privileged access now extends well beyond traditional IT infrastructure, creating constant exposure and audit gaps due to persistent, always-on access. Time bound access in SailPoint Identity Security Cloud enables organizations to grant elevated permissions only when needed and for a defined duration—minimizing risk and supporting compliance. With this feature, customers can adopt a just-in-time access model for privileged access and take a major step toward achieving a zero standing privilege environment. 

Account and entitlement rename and move

Changes within Active Directory are a fact of life, especially when groups are reorganized or moved. Historically, when an AD group’s Distinguished Name (DN) changed, Identity Security Cloud treated it as an entirely new entitlement—causing existing entitlements to be deleted, new ones created, and breaking any references in Access Profiles or roles.

With account and entitlement rename & move support, the solution can now intelligently correlate these changes. That means entitlements retain their continuity even when AD groups are renamed or moved, preserving references and avoiding disruption.

These new features share a common goal: making identity security more flexible, automated, and aligned with how modern enterprises operate. Whether it’s giving admins the ability to tailor user levels, enabling full account deletion for stronger compliance, or enabling time bound access, we’re focused on removing roadblocks and delivering real-world impact.

Make sure you visit the Release Notes to get up to speed on these new features!