Blog
IdentityIQ 8.4p3 is now available
Author
doug_spelce
SailPoint
Note: The downloads for this release have been removed due to improper upgrade behavior, instead please upgrade to IdentityIq 8.4p4. Links to 8.4p3 have been removed from this post, if you have any questions or concerns please create a support ticket for assistance. For more information pleasesee the following blog post.
IdentityIQ 8.4p3 is now available
This release includes security fixes, important server and connectivity enhancements, new connectors, changes in connectivity platform support, documentation updates, and general quality and performance improvements. Additional information can be found in the identityiq-8.4p3-README.txt file accompanying the release.
Highlights
- The 3rd-party libraries in the IdentityIQ Server layer and a subset of connector bundles are updated to newer versions as part of an ongoing commitment to improve the quality and security of the product. The impact on custom connectors, rules, or other customizations which directly or indirectly use these libraries must be validated to ensure compatibility.
- With many IdentityIQ deployments, identity attributes may only be based on one application schema attribute. For environments where 8.4p2 has been applied, it’s very likely an identity attribute will be missing a value for identities that do not have a link on that application even though it had been set previously through other methods. For that reason, we recommend that all customers apply this patch available in the Product Download Center on Compass as soon as possible.
- Addressed multiple issues relating to the BundleProfileRelation service, allowing it to perform and scale better and more accurately in larger, clustered environments. This includes ensuring only one instance at any given time will process Roles, thus avoiding the creation of duplicate entries in the BundleProfileRelation table. Optionally, the mass generation of BundleProfileRelationObjects the first time a BundleProfileRelation service runs can be avoided with the disableInitialDiff system configuration attribute. When this attribute is set to true, BundleProfileRelations will not be evaluated for all Roles in the environment on startup.
- The Java system property org.apache.catalina.connector.RECYCLE_FACADES set to true is now supported to utilize enhanced security settings on Tomcat, preventing the UI errors generated in earlier IdentityIQ versions. This setting is not required but is the default in Tomcat 9.0.90 and later, and it may be optionally set for Tomcat 9.0.89 and earlier. Refer to Tomcat documentation for more information.
- For PostgreSQL, the upgrade process includes converting OID data type values to VARCHAR. If some values were already converted in a previous step, such as when applying an earlier 8.4 patch, the process may generate benign errors such as:
Invalid input syntax for type oid: [current data]
These messages can be safely ignored as they indicate that the values were already handled. These errors do not affect the upgrade process or data integrity. - The IQService version must match the IdentityIQ server version including the major release and patch versions. When one is upgraded, the other must be upgraded as well so that the version and patch levels match. For more information on upgrading the IQService, see the IdentityIQ Installation Guide’s chapter on upgrading.
- If you are leveraging IQService before and after scripts, you must configure the TLS along with the client authentication for IQService to continue execution of these scripts. Before upgrading IQService in your environment, ensure you have completed the necessary prerequisites for TLS and client authentication configuration.
- New Mainframe Connector Gateway version ConnectorGateway-Jun-2025 is released. This release upgrades log4j jar version that the product uses. In addition, it addresses other issues reported since last release. For more details please refer to Mainframe Connectors Downloads.
New Connectivity
- SailPoint is pleased to announce the availability of the new Non-Employee Risk Management (NERM) connector. This connector facilitates the integration between Non-Employee Risk Management (NERM) and IdentityIQ (IdentityIQ) to effectively manage non-employee profiles and their associated assignments. It consolidates profiles, correlates accounts, and access, establishing NERM as the authoritative source of identity data within IdentityIQ.
- The SailPoint SAP Cloud Identity Access Governance (IAG) integration enhances the management of user access and compliance within SAP systems. It allows customers to leverage SailPoint as a central hub for initiating access requests across their SAP landscape, including SAP IAG, ultimately streamlining the request process and strengthening governance.
- The SailPoint Workday Students Connector is now available to help manage student identities by retrieving relevant data for identity governance and access management.
- SailPoint is pleased to announce the availability of the new Webex Control Hub connector. The Webex Control Hub Connector provides governance capabilities for the users of the WebEx Control Hub. Capabilities include aggregation, provisioning users, and adding or removing entitlements at the account level. For more information, please refer to Integrating SailPoint with Webex Control Hub.
Enhanced Connectivity
- The Atlassian Data Center Connector now supports Personal Access Token (PAT) authentication for the service account configured on the application and auto refresh of the tokens when PAT is set as the authentication type. In absence of Atlassian APIs to read all accounts, the connector now supports reading accounts from file exported from the end system for Atlassian Data Center 10.x.
- The Atlassian Data Center for Service Desk Integration now supports Personal Access Token as an authentication method.
- The Cerner Connector now supports Role Profile multiple positions attribute.
- It is now mandatory to configure the TLS and client authentication in order to further enhance the security posture of IQService, especially if you are leveraging IQService before and after scripts.
- The Microsoft Entra ID Connector now supports managing Administrative Units as entitlements and reading LastSuccessfulSigninDateTime sign in activity information for the users.
- The RACF Full Connector now supports to revoke connections instead of removing them when a user is disconnected from a group.
- The SAP Ariba integration now supports SCIM-based aggregation for high data volumes and adds enhancements for supporting Purchasing Unit ID support.
- The SAP BTP Cockpit Cloud Foundry Connector has been enhanced to extend governance support for Cloud Foundry Org and Space entitlements. These entitlements are now visible to platform users at the sub-account level.
- The SAP Identity Directory and BTP integrations have been enhanced to enable filtering of users and related data prior to import into SailPoint, providing greater control and efficiency in data management.
- The SAP GRC integration has been improved to exclude certain systems linked to GRC from user aggregation, provisioning, and attribute update operations, and has been enhanced to support the provisioning and de-provisioning of Fire Fighter IDs (FFID), as user entitlements in SAP GRC.
- The SAP S/4HANA Public Cloud Connector now supports business user creation, aggregate business user roles via SAP standard API, and manage business user attributes.
- The SAP HANA Database Connector now supports multiple SAML (Security Assertion Markup Language) Providers for aggregation and provisioning operations.
- The Workday Connector is now enhanced to support the Pre-Hire record.
- The Workday Accounts Connector now supports managing Student Accounts and now supports addition and removal of active courses.
- The Zendesk Connector now supports the "Bearer Token" authentication type and the "Bearer" authentication type.
New Platform Support
- The SAP Direct Connector now supports SAP S/4HANA 2022 On-Prem SP/FP Stack 04.
- The SAP GRC Connector now supports SAP GRC Access Control 12.0 SP26.
- The SAP Hana DB Connector now supports SAP HANA 2.0 SPS8 version.
- The SailPoint Guidewire Connector now supports the following Guidewire application releases:
- The Niseko release as identified by the 2025.07 release with application version 50.14.x.
- The Mammoth release as identified by the 2025.03 release with application version 50.13.x.
- The Las Leñas release as identified by the 2024.11 release with application version 50.12.x.