Blog

IdentityIQ 8.3p4 is now available

Author

  • doug_spelce

    SailPoint

IdentityIQ 8.3p4 is now available

This release includes security fixes, important server and connectivity enhancements, new connectors, changes in connectivity platform support, documentation updates, and general quality and performance improvements. Additional information can be found in the identityiq-8.3p4-README.txt file accompanying the release.

Highlights

  • In SailPoint's ongoing commitment to security, this release contains fixes for previously reported CVEs (Common Vulnerabilities and Exposures): CVE-2024-1714, CVE-2024-2227, CVE-2024-2228. More information about the CVEs in IdentityIQ is located in SailPoint's Security Advisories.
  • The 3rd-party libraries in the IdentityIQ Server layer and a subset of connector bundles are updated to newer versions as part of an ongoing commitment to improve the quality and security of the product. The impact on custom connectors, rules, or other customizations which directly or indirectly use these libraries must be validated to ensure compatibility.
  • The option to view answers to security authentication questions in clear text has been removed. The answer fields are now treated as password values and always masked. Use of the "obscureAuthAnswers" system configuration option is no longer required to mask the answers.
  • This release contains several enhancements to the File Access Manager (FAM) Classification Task in IdentityIQ to improve performance and tolerance. Some of these enhancements are dependent on recent FAM Service Packs.
New Connectivity
  • A new Ivanti Cherwell Connector is now available.
  • A new IdentityIQ for Ivanti Cherwell ITSM Service Desk integration is now available.
  • New Connectors for the following Guidewire systems are now available, supporting aggregation, provisioning users, and adding or removing entitlements at the account level:
    • Guidewire BillingCenter
    • Guidewire ClaimCenter
    • Guidewire ContactManager
    • Guidewire PolicyCenter
  • A new Atlassian Data Center Connector is now available, providing governance capabilities for users and groups.
  • A new Atlassian Data Center Jira Service Management integration is now available.
  • A new Oracle HCM Cloud Connector is now available to govern identities for Oracle Fusion HCM systems.
  • A new SAP Analytics Cloud Identity Governance integration is now available, supporting security and compliance of systems and data by providing efficient management of user access, roles, and entitlements.
  • A new SAP Fieldglass Vendor Management System integration is now available, providing governance capabilities for contingent workers, governance of external users management for joiners, movers, leaver workflows, and separation of duty (SOD) checks based on user roles, attributes, and entitlements.
  • A new SuccessFactors LMS Connector is now available which integrates SailPoint IdentityIQ with SAP SuccessFactors Learning Management Systems to aggregate and provision user training information for user access governance.
  • A new UKG Pro Core HCM Connector is now available which provides the capability for seamless and secure connection to UKG Pro Core HCM Module which will be used as an authoritative source and act as a source of employee records.
Enhanced Connectivity
  • The Active Directory Connector now supports Exchange management operations where certificate signing of PowerShell serialization payload is enabled. Please refer to Certificate signing of PowerShell serialization payload in Exchange Server - Microsoft Support for more information about this Microsoft feature. The TLS option is now enabled by default during creation of new application to enforce the secure communication over network.
  • The Atlassian Suite - Cloud Connector now supports Enable and Disable account operations. Refer to the documentation for additional configuration required to use this feature. For leveraging this feature with existing applications, refer to the Upgrade Considerations section of the README. The connector now uses the latest Atlassian API to allow users created by the connector to have product access, per the Default Product Access defined in Atlassian.
  • The AWS Connector now requires an IdentityIQ Cloud Governance license to enable cloud governance features. Refer to IdentityIQ documentation for more information.
  • Microsoft Entra ID Connector
    • The Azure Active Directory Connector is now renamed to Microsoft Entra ID Connector. However, when configuring a new connector, it will still be displayed as Azure Active Directory in the application type list. This is a rebranding effort and connector functionality will remain the same. For more information, refer to: Integrating SailPoint with Microsoft Entra ID
    • Improved the delta aggregation performance.
    • Supports the management of Organizational Mail Contacts as accounts.
    • Enhanced so that Azure Active Directory B2C tenants now support the Add, Set, and Remove operations for the userIdentities and signInNames attributes of social and local user accounts during the Modify and Update provisioning operations.
    • Supports the aggregation of Azure Active Directory group hierarchy.
    • Supports managing Service Principal for Enterprise Applications as an Account.
    • Supports creating SAML based applications and corresponding Service Principals using the Gallery application templates.
    • Supports creation of Service Principals for already existing Applications (Local / Multi-Tenant Type).
    • Supports managing administrator and user consented permissions for Service Principals.
    • Supports sending customized message in the Invitation Email for B2B Guest User.
    • Supports filters for the Directory Roles, Azure AD PIM Active and Eligible Roles, Azure PIM Active and Eligible Roles in the group aggregation.
  • All operations for target collectors are now executed in Cloud Gateway, if configured.
  • The Duo Connector is enhanced to grant specific Administrative Units to Duo administrators and to aggregate multiple Aliases.
  • The Epic Connectors (EMP & SER) are now delivered as a single jar file with dependencies bundled. More information is available in the Upgrade Considerations section of the README.
  • The Epic SER Connector now supports provisioning of multivalued attributes. A Plan Initializer Script is now provided out-of-the-box to enable multivalued attribute provisioning. For existing Epic SER Applications, the "Epic SER Multivalued Update" Plan Initializer Script needs to be added to the application configuration. The connector now supports the aggregation of Blueprints as a group object, and provides a togglable option to overwrite the existing values in provider records that conflict with the Blueprint value updates. The Epic SER "identifierTypeValue" configuration item is no longer needed.
  • The IBM Security Identity Manager Connector now supports Delta Aggregation.
  • The IdentityIQ for Atlassian Cloud Jira Service Management integration now populates the Access Request comment on the Jira tickets. Existing ServiceDesk Integration configuration needs to modify the provisioning task definition to include the comments for Access Request. This feature is automatically included for all new configurations.
  • The IQService now supports native PowerShell scripts with version 5.1 and later. It now supports the -m parameter to store x509 subject and serial number to look for the best match in case of multiple certificates present in the IQService personal certificate store.
  • The Microsoft SQL Server Connector is enhanced to aggregate the Windows AD groups created on the MS SQL server, aggregate Service account connected to Login Users as accounts, and is now certified to utilize Windows gMSA as the service account while configuring MS SQL applications.
  • The Okta Connector no longer encodes the special characters "?, =, &" in the API request.
  • The Oracle HRMS Connector now allows Inactive Users to be included in account aggregation.
  • The Oracle PeopleSoft HCM Connector now allows Inactive Users to be excluded in account aggregation, and supports the Provisioning of additional attributes for Badge Details.
  • The Oracle NetSuite ERP Integration now supports aggregation and provisioning of location attribute.
  • The Oracle NetSuite Connector now supports aggregation and provisioning of DepartmentID attribute.
  • The RSA Authentication Manager Connector now supports delta aggregation.
  • SAP Direct Connector
    • Provides more efficient management of SAP Licenses by utilizing the 'License ID' instead of relying solely on the description field. This enhancement is particularly advantageous for SAP systems that offer multiple client language support.
    • Now manages indirect roles by leveraging SAP HR Organization data. This upgraded connector is capable of consolidating Organization Data associated with SAP employees, such as their position, job, or organization unit.
    • Now has the ability to differentiate between TCodes added through menu, TCodes added directly, and other menu items. This enhancement is made possible by the introduction of three new attributes in the role schema, and provides users with greater flexibility and control over their SAP Direct Connector experience.
    • Now supports S/4HANA Private Cloud on AWS, a managed service offering included within SAP RISE.
  • SAP GRC Connector/Integration
    • Added additional settings on the SAP GRC Source Configuration UI for Access Request Type Mapping, Provisioning Actions for Roles and System sections for ease of configuration and maintenance.
    • Supports user IDs with mixed-case and special characters, along with the support for custom delimiter characters, making it even more resilient and adaptable to a wide range of customer use cases.
    • Supports Access Management Requests that are configured for Auto-Approval in the SAP GRC system.
    • Supports SAP Enterprise Portal Integration.
    • Has introduced a new capability allowing users to update the 'Valid From' or 'Valid To' date when enabling or disabling an account. This feature empowers customers to streamline user de-provisioning processes, making it easier to manage scenarios such as temporary leaves of absence.
    • Provides enhanced visibility by displaying the actual requester details for associated tickets. This valuable enhancement equips approvers with comprehensive context and specific information regarding the request's purpose and origin. Consequently, this improvement streamlines the approval process, empowering approvers to make more informed and efficient decisions.
    • Enhanced and is fully compatible with another non-ABAP system; SAP Process Orchestration.
    • Enhanced functionality for modifying attributes associated with a user during the disable operation. This critical enhancement allows Account Disable requests to be distinguished between inactive users (leavers) and active users (leave of absence). The upgrade also ensures a seamless clean exit process by facilitating the removal of:
      • User roles
      • Configuring specific user groups during the disable operation
      • Setting a user's end date
      • Selectively disabling the account on specified systems
      • In addition to streamlining the account management process, these advanced features provide greater flexibility and precision in handling different scenarios; ultimately enhancing the overall user experience and administrative control within the SAP GRC system.
  • The SAP HR/HCM Connector is enhanced to configure with load balancer parameters when the SAP system is configured with a load balancer at the customer end.
  • The Salesforce Connector now supports Delegate Group and bi-directional role hierarchy for 1 level.
  • For the ServiceNow Service Desk Integration Module (SDIM), ticket resolution comments (close_notes) from ServiceNow are now provided on Identity Request.
  • The Siebel Connector now supports aggregation of responsibilities and assigning Dummy Primary Position ID to user (Leaver use case).
  • The SuccessFactors Connector now provides write-back abilities for SuccessFactors and OData Attributes, and can now aggregate selective records based on filtering criteria on employee records.
  • The Windows Local Connector now supports adding and removing entitlements for non-local (domain) users.
  • The Workday Accounts Connector is enhanced to manage the External learning Users, can be configured to exclude inherited Organization roles associated with the accounts during account aggregation, and can integrate with Workday Learning Module to aggregate the training information associated with the users.
Dropped Connectivity
  • The Atlassian Suite - Server Connector and Atlassian Jira Server SDIM have been deprecated. Atlassian has announced that support for Server will end on February 15, 2024. Refer to this Compass article for more information.
  • The IBM Tivoli Access Manager Connector is deprecating support for the REST API.
  • For the Linux Connector, Red Hat Enterprise Linux (RHEL) 9 has deprecated SCP support.
  • The Zoom Connector no longer supports Authentication Type "API Token".
End of Life Connectivity
  • The VMS Connector reached its EOL in March 2024 and is no longer supported. SailPoint previously announced the deprecation and EOL dates for the VMS Connector in January 2023 in this Compass article.
New Platform Support
  • The Salesforce Connector now supports Salesforce API version 59.0. On existing sources, the connector automatically uses API version 59.0, regardless of the version in the URL.
  • The BMC Helix Connector now supports BMC Helix IT Service Management Suite version 22.1.
  • The Cloud Gateway now supports Windows Server 2022.
  • The IBM i Connector now supports IBM i V7R5 system.
  • The SailPoint Identity Governance Connector for ServiceNow now supports the ServiceNow Washington DC and Vancouver releases.
  • The IdentityIQ for Service Desk now supports the ServiceNow Washington DC and Vancouver releases.
  • The SailPoint IdentityIQ for Service Catalog now supports the ServiceNow Washington DC and Vancouver releases.
  • The PeopleSoft HCM Connector now supports PeopleTools version 8.60, 8.60.05.
  • The RACF-Full Connector now supports z/OS 3.1.
  • The Linux Connector now supports Red Hat Enterprise Linux 8.8 and 9.2.
  • The SAP HR/HCM Connector now supports SAP S4Hana 2022 version.
  • The Epic Connectors now support Epic versions May 2023, November 2023, and May 2024.
Dropped Platform Support
  • The IBM AIX Connector has deprecated IBM AIX 7.1 version.
  • The Solaris Connector has depreciated Solaris 11.3 SPARC x86, Solaris 11.2 SPARC x86, Solaris 11 SPARC x86 and Solaris 10 SPARC x86 versions.
  • The RSA Connector has deprecated RSA 8.3, 8.4, and 8.5 versions.
  • The Microsoft Active Directory Connector no longer supports Microsoft Exchange Server 2013 and Microsoft Lync Server 2013 as Microsoft has ended support.
  • The BMC Helix ITSM Service Desk Integration Module (SDIM) no longer supports BMC Helix ITSM 20.02 version.