Blog

IdentityIQ 8.4p1 is now available

Author

  • doug_spelce

    SailPoint

IdentityIQ 8.4p1 is now available

This release includes security fixes, important server and connectivity enhancements, new connectors, changes in connectivity platform support, documentation updates, and general quality and performance improvements. Additional information can be found in the identityiq-8.4p1-README.txt file accompanying the release.

Highlights

  • In SailPoint's ongoing commitment to security, this release contains fixes for previously reported CVEs (Common Vulnerabilities and Exposures): CVE-2023-46604, CVE-2024-1714, CVE-2024-2227, CVE-2024-2228. More information about the CVEs in IdentityIQ is located in SailPoint's Security Advisories.
  • 3rd-party libraries in the IdentityIQ Server layer and a subset of connector bundles are updated to newer versions due to vulnerabilities found in older versions of the libraries.
  • This release contains several enhancements to the File Access Manager (FAM) Classification Task in IdentityIQ to improve performance and tolerance. Some of these enhancements are dependent on recent FAM Service Packs.
  • This patch contains general accessibility compliance improvements, which includes improvements to the Access History pages.
  • This patch includes updates to the translated message files to support new features and bug fixes released in 8.4 GA.
New Connectivity
  • A new UKG Pro Core HCM connector is now available with provides the capability for seamless and secure connection to UKG Pro Core HCM Module which will be used as an authoritative source and act as a source of employee records.
  • A new SuccessFactors LMS connector is now available which integrates SailPoint IdentityIQ with SAP SuccessFactors Learning Management Systems to aggregate and provision user training information for user access governance.
Enhanced Connectivity
  • The Active Directory Connector now supports Exchange management operations where certificate signing of PowerShell serialization payload is enabled. Please refer to Certificate signing of PowerShell serialization payload in Exchange Server - Microsoft Support for more information about this Microsoft feature.
  • The AWS Connector now requires an IdentityIQ Cloud Governance license to enable cloud governance features. Refer to IdentityIQ documentation for more information.
  • Microsoft Entra ID Connector
    • The Azure Active Directory Connector is now renamed to Microsoft Entra ID Connector. However, when configuring a new connector, it will still be displayed as Azure Active Directory in the application type list. This is a rebranding effort and connector functionality will remain the same. For more information, refer to: Integrating SailPoint with Microsoft Entra ID
    • Supports the management of Organizational Mail Contacts as accounts.
    • Enhanced so that Azure Active Directory B2C tenants now support the Add, Set, and Remove operations for the userIdentities and signInNames attributes of social and local user accounts during the Modify and Update provisioning operations.
    • Supports managing administrator and user consented permissions for Service Principals.
    • Now improved the delta aggregation performance.
    • Supports sending customized message in the Invitation Email for B2B Guest User.
  • The Epic SER Connector now supports provisioning of multivalued attributes. A Plan Initializer Script is now provided out-of-the-box to enable multivalued attribute provisioning. For existing Epic SER Applications, the "Epic SER Multivalued Update" Plan Initializer Script needs to be added to the application configuration. The connector now provides a togglable option to overwrite the existing values in provider records that conflict with the Blueprint value updates. The Epic SER "identifierTypeValue" configuration item is no longer needed.
  • IBM Tivoli Access Manager Connector (a.k.a., IBM Security Verify Access) is deprecating support for the REST API.
  • IdentityIQ for Atlassian Cloud Jira Service Management now populates the Access Request comment on the Jira tickets. Existing ServiceDesk Integration configuration needs to modify the provisioning task definition to include the comments for Access Request. This feature is automatically included for all new configurations.
  • The IQService now supports native PowerShell scripts with version 5.1 and later.
  • The Duo Connector is enhanced to grant specific Administrative Units to Duo administrators and to aggregate multiple Aliases.
  • The Linux Connector is deprecating support for SCP.
  • The Microsoft SQL Server Connector is enhanced to aggregate Service account connected to Login Users as accounts, and now certified to utilize Windows gMSA as the service account while configuring MS SQL applications.
  • The Salesforce connector now supports Salesforce API version 59.0. On existing sources, the connector automatically uses API version 59.0 automatically, regardless of the version in the URL.
  • SAP GRC Connector/Integration
    • Enhanced to support user IDs with mixed-case and special characters, along with the support for custom delimiter characters, making it even more resilient and adaptable to a wide range of customer use cases.
    • Support for SAP Portal as connected systems.
    • Has introduced a new capability, allowing users to update the 'Valid From' or 'Valid To' date when enabling or disabling an account. This feature empowers customers to streamline user de-provisioning processes, making it easier to manage scenarios such as temporary leaves of absence.
    • Now provides enhanced visibility by displaying the actual requester details for associated tickets. This valuable enhancement equips approvers with comprehensive context and specific information regarding the request's purpose and origin. Consequently, this improvement streamlines the approval process, empowering approvers to make more informed and efficient decisions.
    • Enhanced and is fully compatible with another non-ABAP system; SAP Process Orchestration.
    • Enhanced functionality for modifying attributes associated with a user during the disable operation. This critical enhancement allows Account Disable requests to be distinguished between inactive users (leavers) and active users (leave of absence). The upgrade also ensures a seamless clean exit process by facilitating the removal of:
      • User roles
      • Configuring specific user groups during the disable operation
      • Setting a user's end date
      • Selectively disabling the account on specified systems
      • In addition to streamlining the account management process, these advanced features provide greater flexibility and precision in handling different scenarios; ultimately enhancing the overall user experience and administrative control within the SAP GRC system.
  • The SAP Direct Connector is enhanced to provide more efficient management of SAP Licenses by utilizing the 'License ID' instead of relying solely on the description field. This enhancement is particularly advantageous for SAP systems that offer multiple client language support.
  • The SAP HR/HCM connector is enhanced to configure with load balancer parameters when SAP system is configured with load balancer at customer end.
  • The SuccessFactors connector is enhanced with the write-back abilities for SuccessFactors and OData Attributes.
  • The Workday Accounts Connector is enhanced to manage the External learning Users and can now be configured to exclude inherited Organization roles associated with the accounts during account aggregation.
  • The Windows Local Connector now supports adding and removing entitlements for Non-local (domain) users.
Dropped Connectivity
  • The Atlassian Suite - Server Connector and Atlassian Jira Server SDIM have been deprecated. Atlassian has announced that support for Server will end on February 15, 2024. Refer to this Compass article for more information.
End of Life Connectivity
  • The VMS Connector reached its EOL in March 2024 and is no longer supported. SailPoint previously announced the deprecation and EOL dates for the VMS Connector in January 2023 in this Compass article.
New Platform Support
  • The IBM i Connector now supports IBM i V7R5 system.
  • The RACF-Full connector now supports z/OS 3.1.
  • The Linux Connector now supports Red Hat Enterprise Linux 9.2.
  • The SAP HR/HCM connector now supports SAP S4Hana 2022 version.
  • The SailPoint Identity Governance Connector for ServiceNow now supports the ServiceNow Vancouver release.
  • The IdentityIQ for Service Desk now supports the ServiceNow Vancouver release.
Dropped Platform Support
  • The Microsoft Active Directory Connector no longer supports Microsoft Exchange Server 2013 and Microsoft Lync Server 2013 as Microsoft has ended support.
  • The BMC Helix ITSM Service Desk Integration Module (SDIM) no longer supports BMC Helix ITSM 20.02 version.