SaaS

SaaS Release Notes - May 22, 2023

Production release notes - May 22, 2023

Release notes might contain references to new features, enhancements, and fixes that will be gradually turned on in production over the next several weeks. See the SaaS Functional End of Life and Major Changes Policy.

Identity Security Cloud is SailPoint's next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.

New features

ProductWhat's new

Connectivity - SalesForce

The SailPoint Salesforce Connector supports use with Enhanced Domains.

Connectivity - IQService

SailPoint is happy to announce the latest version of IQService (IQService-May-2023). This release includes UpdateService (this service is required for automatic updates), bug fixes, and improvements. For more information on checking your IQService version, as well as how to upgrade to the latest version, refer to the IQService documentation. For more information on configuring the UpdateService, refer to Updating IQService. SailPoint strongly recommends upgrading to the latest version before the end of Q3 2023 to take advantage of automatic updates and continuous support.
Upgrade Consideration: As a prerequisite, the latest version of IQService requires that you use .Net Framework version 4.8 or later.

Enhancements

ProductFeature enhancements

IDN Access Request

The width, margin, and alignment of the fields for configuring Access Profiles have been updated.

Platform

The sp-config API export operation has been expanded to include these additional objects types:

  • CAMPAIGN_FILTER
  • PASSWORD_POLICY
  • PASSWORD_SYNC_GROUP
  • ATTR_SYNC_SOURCE_CONFIG

IDN Provisioning

The name constraint has been removed from the pre-defined search initiated by the Attribute Sync View Events button. This broadens the search results to all attribute sync events, including those initiated manually for an identity or a source.

Connectivity - Active Directory, IQService

For the Active Directory source, incoming provisioning plans that are sent to IQService with blank values in the Attribute Description tags are no longer removed from the original plan sent between the Before Provisioning and After Modify Rule.

Connectivity - Active Directory, IQService

When connecting IQService and the Active Directory source over TLS, IQService now uses the skipDNSLookup application config to skip the DNS lookup for the Exchange server.

Fixes

ProductIssue IDFixes

IDN Provisioning

IDNARSENAL-17573

Fixed an issue that was causing slow responses in the Export, List, and Get (single) Identity Profile API endpoints.

Connectivity - Active Directory, IQService

CONETN-4125

In the Active Directory managed system, IQService won’t log any error messages during provisioning if any custom attribute is provisioned for an object which already contains custom schema attributes. Examples in the user object can include caemployeetype, castartdate, caenddate, caorgunitcode, and caorgunitname.

Connectivity - IQService

CONETN-4135

IQService client authentication will now use the system default logon provider.

Connectivity - Azure AD, IQService

CONETN-4064

The Azure Active Directory connector now fetches the Exchange Online attributes for all the accounts in the source.

Connectivity - Azure AD, IQService

CONETN-4012

The Azure Active Directory Source now also fetches the Exchange Online custom attributes.

Connectivity - Azure AD, IQService

CONETN-3903

The Azure Active Directory source now fetches all the shared mailboxes during account aggregation using IQService.

Connectivity - Azure AD, IQService

CONETN-3923

The Azure Active Directory source no longer displays the following error when managing the mail-enabled security groups or distribution groups using IQService: The state of the current PowerShell instance is not valid for this operation.