Blog

IdentityIQ 8.2p6 is now available

Author

  • doug_spelce

    SailPoint

IdentityIQ 8.2p6 is now available

This release includes security fixes, important server and connectivity enhancements, new connectors, changes in connectivity platform support, documentation updates, and general quality and performance improvements. Additional information can be found in the identityiq-8.2p6-README.txt file accompanying the release.

Highlights

  • In SailPoint's ongoing commitment to security, this release contains a fix for a previously reported CVE (Common Vulnerabilities and Exposures): CVE-2023-32217. More information about this CVE is located in SailPoint's Security Advisories.
  • 3rd-party libraries in the IdentityIQ Server layer and a subset of connector bundles are updated to newer versions due to vulnerabilities found in older versions of the libraries.
  • Form Beans used to process SailPoint Form submissions must now implement the FormBean interface.
  • The option to view answers to security authentication questions in clear text has been removed. The answer fields are now treated as password values and always masked. Use of the "obscureAuthAnswers" system configuration option is no longer required to mask the answers.
  • This release contains several enhancements to the File Access Manager (FAM) Classification Task in IdentityIQ to improve performance and tolerance. Some of these enhancements are dependent on recent FAM Service Packs.
New Connectivity
  • A new Azure SQL Database Connector is now available.
  • A new IdentityIQ for Ivanti Cherwell ITSM Service Desk integration is now available.
  • A new Ivanti Cherwell Connector is now available.
  • A new Oracle HCM Cloud Connector is now available to govern identities for Oracle Fusion HCM systems.
  • A new Oracle Enterprise Performance Management (EPM) Cloud Governance Connector provides the capability for managing user accounts, and reading and associating of Predefined roles, application roles and groups. The integration supports EPM Cloud Services for Planning, Financial Consolidation and Close Service (FCCS), Account Reconciliation (ARCS), & Narrative Reporting (NR).
  • A new SAP Fieldglass Vendor Management System offers governance capabilities for contingent workers. It offers seamless governance of external user’s management for joiners, movers, leaver workflows, and separation of duty (SOD) checks based on user roles, attributes, and entitlements.
Enhanced Connectivity
  • The Active Directory Connector is enhanced to aggregate domain NetBIOSName as part of account and group aggregation. The Microsoft Exchange management operations with this connector will now work with Exchange server where certificate signing of PowerShell serialization payload is enabled.
  • The Azure Active Directory Connector has the following enhancements new in this release:
    • An enhanced UI for User Filters, Group Filters, User Advanced Filters, and Group Advanced Filters field is now available on the application UI page by default, making entries of these keys in the application xml file through the debug page no longer required.
    • Supports filters for the Directory Roles, Azure AD PIM Active and Eligible Roles, Azure PIM Active and Eligible Roles in the group aggregation.
    • Supports reading and writing Azure Multi-Factor Authentication attributes required for different authentication methods.
    • Supports the PowerShell EXO V3 module for the Exchange Online Management feature. Supports filters for Channels during entitlement aggregation.
    • Supports the aggregation of Azure Active Directory group hierarchy.
    • Supports managing Service Principal for Enterprise Applications as an Account.
    • Supports creating SAML based applications and corresponding Service Principals using the Gallery application templates.
    • Supports creation of Service Principals for already existing Applications (Local/Multi-Tenant Type).
    • Supports managing administrator and user consented permissions for Service Principals.
    • Supports sending customized message in the Invitation Email for B2B Guest User.
    • NOTE: Microsoft Entra ID is the new name for the Azure Active Directory connector. When configuring a new connector, it will still be displayed as Azure Active Directory in the application type list. This is a rebranding effort and connector functionality will remain the same. For more information refer to the following documentation: Integrating SailPoint with Azure Active Directory
  • IdentityIQ for Atlassian Cloud Jira Service Management now populates the Access Request comment on the Jira tickets. Existing ServiceDesk Integration configuration needs to modify the provisioning task definition to include the comments for Access Request. This feature is automatically included for all new configurations.
  • The BMC Helix ITSM Service Desk integration now supports OAuth 2.0 authentication.
  • The Cloud Gateway now supports a load balancer with sticky-bit configuration. Now all operations for target collectors are executed in Cloud Gateway, if configured.
  • The Duo Connector is enhanced to grant specific Administrative Units to DUO administrators.
  • The Epic Connector now supports the user fields "PrimaryManager" and "UsersManagers" as account attributes and provisioning of multivalued attributes. Plan Initialiser Script is now provided out-of-the-box to enable multivalued attribute provisioning. For existing Epic SER Applications, the Epic SER Multivalued Update Plan Initialiser Script needs to be added to the application configuration.
  • The IBM Security Identity Manager now supports Delta Aggregation.
  • Mainframe Connectors (RACF-Full, ACF2-Full, and TopSecret-Full) now support mutual TLS authentication for communication between IdentityIQ, Connector Gateway, and the Mainframe Connector itself. Upgrade to latest Connector Gateway to leverage this feature.
  • The Okta Connector now provides an option for multi-threading when aggregating Groups and Applications connected to Okta Accounts during Okta Account aggregation.
  • The Oracle Identity Manager now supports an enhanced deployment approach for Oracle Identity Manager Web Application. The old approach to deploying Oracle Identity Manager Web Application is now deprecated.
  • The RSA Connector now supports Delta Account Aggregation.
  • The SAP Direct Connector now provides more efficient management of SAP Licenses by utilizing the "License ID" instead of relying solely on the description field. This enhancement is particularly advantageous for SAP systems that offer multiple client language support.
  • The SAP SuccessFactors Connector is enhanced to manage external users and their entitlements who are in the onboarding stage. Supports additional attributes and custom attributes related to user entities via ODATA API. Enhanced to aggregate selective records based on filtering criteria on employee records.
  • The SAP GRC Connector is enhanced to support additional attributes that are now configurable through the provisioning policy. Additional settings on the SAP GRC Source Configuration UI for Access Request Type Mapping, Provisioning Actions for Roles and System sections for ease of configuration and maintenance. Supports Access Management Requests that are configured for Auto-Approval in the SAP GRC system.
  • The Salesforce Connector now supports use of the "Enhanced Domains" option in Salesforce system.
  • The Windows Local Connector now supports adding and removing entitlements for non-local (domain) users.
  • The Workday Accounts Connector now provides an option for multi-threading which will boost the Account Aggregation performance. Enhanced to manage the External learning Users. Enhanced to integrate with Workday Learning Module and aggregate the training information associated with the users. Enhanced to configured to exclude inherited Organization roles associated with the accounts during account aggregation.
  • The Workday Connector now allows adding proxy level parameters in the Workday application.
  • The Zoom Connector no longer supports Authentication Type "API Token".
  • The IBM Tivoli Access Manager Connector is deprecating support for the REST API.
  • The Linux Connector is deprecating support for SCP.
Dropped Connectivity
  • The Atlassian Suite - Server Connector and Atlassian Jira Server SDIM have been deprecated. Atlassian has announced that support for Server will end on February 15, 2024. Refer to this Compass article for more information.
New Platform Support
  • The BMC Helix connector now supports BMC Helix IT Service Management Suite version 22.1.
  • The BMC Helix ITSM Service Desk Integration Module now supports version 22.1.
  • The Cloud Gateway now supports RHEL 9.0 and Windows Server 2022.
  • The Epic Connector now supports the Epic Healthcare May 2023 and Epic Healthcare August 2023 releases.
  • The IBM i Connector now supports the IBM i V7R5 system.
  • IdentityIQ for ServiceNow Service Desk now supports the ServiceNow Vancouver release.
  • The Linux Connector now supports RHEL version 9.2 and 8.8.
  • The Oracle Identity Manager Connector now supports Oracle Identity Manager 12C via the Oracle Client API.
  • The Oracle PeopleSoft HCM Connector now supports PeopleTools version 8.60.05.
  • The PeopleSoft HCM Connector now supports PeopleTools version 8.60.
  • The SAP HANA DB Connector now supports SAP HANA Cloud DB v4.0 application.
  • The SailPoint Identity Governance Connector for ServiceNow now supports the ServiceNow Vancouver release.
Dropped Platform Support
  • The Active Directory Connector no longer supports Microsoft Exchange Server 2013 and Microsoft Lync Server 2013 as Microsoft has ended support.
  • The BMC Helix ITSM Service Desk Integration Module (SDIM) no longer supports BMC Helix ITSM 20.02.
  • The IBM AIX Connector no longer supports IBM AIX 7.1 version.
  • The Oracle Identity Manager Connector no longer supports Oracle Identity Manager 11g R1 and 11g R2 releases.
  • The RSA Connector no longer supports RSA 8.3, 8.4, and 8.5.
  • The Solaris Connector no longer supports Solaris 11.3 SPARC x86, Solaris 11.2 SPARC x86, Solaris 11 SPARC x86, and Solaris 10 SPARC x86.