SaaS

SaaS Release Notes - January 16, 2023

Production release notes - January 16, 2023

Release notes might contain references to new features, enhancements, and fixes that will be gradually turned on in production over the next several weeks. See the SaaS Functional End of Life and Major Changes Policy.

Identity Security Cloud is SailPoint's next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.

New features

ProductWhat's new

SaaS Connectors

SailPoint is pleased to announce the availability of net new “Axosoft” SaaS Connector.

The SailPoint Axosoft SaaS connector can securely connect with the Axosoft system and provides governance capabilities for the users of the Axosoft system.

Platform

When creating API clients, users can now select scopes (groups of API access permissions) to provide more granular API access. For more information, refer to Managing API Keys.

Platform

When creating personal access tokens (PATs), users can now select scopes (groups of API access permissions) to provide more granular API access. For more information, refer to Managing Personal Access Tokens.

Enhancements

ProductFeature enhancements

Platform

The sp-config import API now automatically creates a backup of the tenant’s existing configuration objects (for the sp-config supported objects) prior to executing the import and provides the id for the backup to the customer. SailPoint stores the backup for 7 days. In case of an accidental configuration loss or mis-configuration, contact SailPoint Support for assistance in retrieving the backup to use in re-importing the prior configurations. If you do not need the backup (for example, in a non-production environment), you can disable that step by specifying the parameter “excludeBackup”:true in the API call.

IDN Provisioning

When an administrator selects Apply Changes for roles, access profiles or applications, they are now offered the option to review recent configuration changes prior to initiating identity processing, giving them a clearer understanding of the access model changes that will be applied to their identities.

Refer to Updates to Apply Changes: Able to Review Recent Configuration Changes for the full announcement.

IDN Provisioning

Aggregation jobs no longer block administrators from selecting Apply Changes to initiate identity processing and apply access model updates to their identities. As a safeguard against repeated and unnecessary sequential executions of identity processing, IdentityNow will still prevent administrators from using Apply Changes when an identity processing job is already running.

IDN Provisioning

Real-time attribute sync events are now distinguishable in Search from scheduled attribute sync events. Both are recorded as ModifyAccount events, but real-time sync events show an "interface" value of "Attribute Sync" while scheduled syncs show "Attribute Synchronization Refresh."

Connectivity - IBM Lotus Domino

The HCL Domino connector now supports HCL Domino version 12.0.2.

Platform

When an identity has been disabled, the associated user's personal access tokens (PATs) will now be added to a block list to prevent their active access tokens from making API calls.

Connectivity

The Oracle ERP Cloud connector is enhanced to support aggregation of data access information (security context and security context values) even when not assigned to a role.

Connectivity - Oracle HRMS

The Oracle HRMS connector now supports supervisor and person type aggregation filters and enables you to configure the update mode while updating an email address. For more information, refer to Oracle HRMS – Additional Settings.

IDN Provisioning

When a user request to download a source’s accounts as a CSV file fails, IdentityNow now displays an error message instead of failing silently.

Connectivity - SAP GRC

The SAP GRC Connector is enhanced to support account partitioning for the GRC module running on SAP Basis versions 751 and later.

Fixes

ProductIssue IDFixes

AI Recommendation Engine

IDNPUG-4512

Fixed an issue where certification recommendations were enabled by default for all new certifications created with IdentityNow Search from November 7, 2022, to December 14, 2022. There should be no adverse effects to certifications created during this time. Now, certification recommendations are enabled by default only for organizations with the Recommendations service.

AI Access Modeling

SAASCOMS-560

IDNPUG-4581

Fixed an issue on IdentityNow role configuration pages where making any changes to role configuration would also automatically enable the Common Access checkbox.

Users who adjusted any roles in IdentityNow on December 12, 2022, through Jan 10, 2023, should review those roles to determine whether the common access designation is justified.

Connectivity - Azure AD

CONETN-4023

The Azure Active Directory connector now fetches all the Resource Groups during entitlement aggregation.

Connectivity - Azure AD

CONETN-4021

The Azure Active Directory connector no longer calls the IdentityIQ database while fetching the Exchange Online attributes.