SaaS

SaaS Release Notes - December 19, 2022

Production release notes - December 19, 2022

Release notes might contain references to new features, enhancements, and fixes that will be gradually turned on in production over the next several weeks. See the SaaS Functional End of Life and Major Changes Policy.

Identity Security Cloud is SailPoint's next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.

New features

ProductWhat's new

Connectivity - CyberArk-CorePas

SailPoint introduces the new CyberArk Self-Hosted connector for IdentityNow.

Connectivity - Coupa

SailPoint is pleased to announce a new IdentityNow source for connecting to your Coupa system. For more information, refer to Integrating SailPoint with Coupa.

SaaS Connectors

SailPoint is pleased to announce the availability of net new “SCIM 2.0 SaaS” Connector.

The SailPoint SCIM 2.0 SaaS connector can securely connect with the SCIM 2.0 compliant system and provides governance capabilities for the users of the SCIM 2.0 compliant system.

For more information, refer to https://community.sailpoint.com/t5/Connector-Directory/SCIM-2-0-SaaS-Connector/ta-p/220541

Connectivity - ServiceNow Service Catalog

Approval Flexibility

Ability to configure Approval Rules and arrange them in multiple levels ( sequential and parallel )

Keeps the approval history in ServiceNow for audit and reporting purposes

The following types Approval Rules are supported

  • ServiceNow User - assign the selected ServiceNow User as approver for the access request
  • ServiceNow Group - assign anyone/all ServiceNow Users from the selected ServiceNow Group as approvers for the access request
  • ServiceNow Role - assign anyone/all ServiceNow Users from the selected ServiceNow Role as approvers for the access request
  • ServiceNow Manager - assign the direct manager as per ServiceNow as approver for the access request
  • ServiceNow Script - assign all ServiceNow Users returned from ServiceNow GlideRecord query as approvers for the access request
  • IdentityNow Workflow - It replicates in ServiceNow the same approvals as they are configured in SailPoint IdentityNow for the access request. Once approved or rejected in ServiceNow they get approved or rejected in SailPoint IdentityNow allowing us to maintain approval history​

Connectivity - Azure AD

The Azure Active Directory connector now supports Continuous Access Evaluation (CAE), which leverages the Azure Active Directory real-time enforcement of conditional access location and risk policies along with instant enforcement of token revocation event for an enterprise application (service principal). For more information, refer to Continuous Access Evaluation.

Connectivity

The Oracle E-Business connector now supports the 12.2.11 Oracle EBS environment.

Enhancements

ProductFeature enhancements

Connectivity - ServiceNow

The SailPoint Identity Governance connector now supports the option to improve delta aggregation performance by selecting the Improve Delta Aggregation checkbox. This pulls information on the deleted events of a user’s connection from a custom table instead of the sys_audit_delete table. For more information, refer to Aggregation Settings.

Connectivity - REST WebServices Connector

The Web Services connector now supports adding or removing entitlements when you enable or disable an account. Using provisioning plan entries, you can configure the connector to add certain entitlements to an account when you enable it or remove certain entitlements from an account when you disable it.

Connectivity - REST WebServices Connector

In the Web Service connector, the No/Custom Authentication Authentication Type option in the connection settings has been renamed to Custom Authentication, and additional configuration parameters were added to support numerous configuration requirements. This change doesn’t affect existing connector configurations.

Access Insights

SailPoint is making updates to Access History for IdentityNow users. When these updates are enabled in your production tenant, you will notice the following changes:

  • Faster event-driven updates.
  • The identity list is displayed in alphabetical order instead of by most recently updated.
  • The View Profile page for an identity displays only IdentityNow attributes.

Fixes

ProductIssue IDFixes

Connectivity

IDNHUSKY-2033

Test Connection is now disabled for direct-connect sources where no VA Cluster has been specified.

Connectivity - REST WebServices Connector

CONJUBILEE-1604

The Web Services connector's Custom Authentication operation now supports XPath Namespace mappings.

Connectivity - Connector Infrastructure

CONJUBILEE-1454

The following JAR files were upgraded to newer versions due to vulnerabilities identified within them. Check how this impacts any custom connectors, rules, or other customizations, which are directly or indirectly using these JAR files.

  • Old JAR File -> New JAR File
  • jersey/hk2-api-2.6.1.jar -> jersey/hk2-api-3.0.3.jar
  • jersey/hk2-locator-2.6.1.jar -> jersey/hk2-locator-3.0.3.jar
  • jersey/hk2-utils-2.6.1.jar -> jersey/hk2-utils-3.0.3.jar

Connectivity - Connector Infrastructure

CONJUBILEE-1495

Java Validation API library has been removed (Package: javax.validation) from the latest Jersey library. If required, Bean Validation API (validation-api-2.0.1.Final.jar) should be added separately for customization.

JAR files have been upgraded to newer versions due to vulnerabilities found in the older versions. Please check the impact on custom connectors, rules, or any other customization, which are directly or indirectly using these jar files.

The following lists the outdated versions followed by the upgraded version:

  • jersey/jakarta.annotation-api-1.3.5.jar -> jersey/jakarta.annotation-api-2.1.0.jar
  • jersey/jakarta.validation-api-2.0.2.jar -> jersey/jakarta.validation-api-3.0.1.jar
  • jersey/jersey-hk2-2.31.jar -> jersey/jersey-hk2-3.0.4.jar
  • jersey/jakarta.ws.rs-api-2.1.6.jar -> jersey/jakarta.ws.rs-api-3.1.0.jar
  • jersey/jersey-client-2.31.jar -> jersey/jersey-client-3.0.4.jar
  • jersey/jersey-common-2.31.jar -> jersey/jersey-common-3.0.4.jar
  • jersey/jersey-container-servlet-core-2.31.jar -> jersey/jersey-container-servlet-core-3.0.4.jar
  • jersey/jersey-media-jaxb-2.31.jar -> jersey/jersey-media-jaxb-3.0.4.jar
  • jersey/jersey-media-multipart-2.31.jar -> jersey/jersey-media-multipart-3.0.4.jar
  • jersey/jersey-server-2.31.jar -> jersey/jersey-server-3.0.4.jar
  • scim-sdk-1.8.18.01/jersey-apache-connector-2.22.2.jar -> scim-sdk-1.8.18.01/jersey-apache-connector-3.0.4.jar