SaaS

SaaS Release Notes - October 2, 2023

Production release notes - October 2, 2023

Release notes might contain references to new features, enhancements, and fixes that will be gradually turned on in production over the next several weeks. See the SaaS Functional End of Life and Major Changes Policy.

Identity Security Cloud is SailPoint's next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.

New features

ProductWhat's new

Connectivity - UKG Pro

SailPoint is pleased to announce the availability of a net new UKG Pro Core HCM connector. The SailPoint UKG Pro Core HCM connector securely connects with your UKG Pro system and aggregates real-time employee data from the UKG Pro Core Module. For more information, refer to Integrating SailPoint with UKG Pro Core HCM.

AI Access Insights

Organizations with Access Insights can now view outlier score factor details for identity outliers. Admins can select a factor on the Identity Outliers Contextual Insights page to view how the outlier compares to peers, why the factor matters, and a searchable list of the identity’s access items that contribute to the outlier score. Refer to Viewing Outlier Score Factor Details for more information.

SaaS Connectors

SailPoint is pleased to announce the following enhancements in the Web Services SaaS Connector.

  • SOAP Protocol - The SailPoint Web Services SaaS connector now supports SOAP Web Services protocol with XML response format.
  • Evaluation Pattern - Now data can be send for multiple users in a single API call. If the managed system supports sending data for multiple users in single call, the single API call can be enabled or configured in the Web Services SaaS connector by adding the evalPattern. For more information, refer to Single API Calls.
  • SAML Bearer Assertion as an OAuth 2.0 Grant Type - The OAuth 2.0 SAML bearer assertion flow is introduced in the Web Services SaaS Connector that allows you to request an OAuth access token using an SAML assertion when a client needs to use an existing trust relationship. The signature applied to the SAML assertion provides authentication of the authorized application. For more information, refer to SAML Bearer Assertion.
  • Client Certificate for OAuth 2.0 Password Grant Type - Now there is ability for providing the Client Certificate and Client Private key for SSL handshake. For more information, refer to Password.

SaaS Connectors

SailPoint is pleased to announce the availability of net new feature Non-Compliant Settings for the SCIM 2.0 SaaS Connector.

The SailPoint SCIM 2.0 SaaS Connector can now be connected to a SCIM managed system that does not adhere to SCIM RFC’s by enabling the option for Non-Complaint Settings from the source. For more information, refer to Non-Compliant Settings.

Connectivity - EPIC

The Epic SER Connector now supports provisioning of multivalued attributes. A Before Provisioning Rule is now provided out-of-the-box to enable multivalued attribute provisioning. For existing Epic SER Sources, the “Epic SER Multivalued Update” Before Provisioning Rule needs to be added to the source configuration.

Enhancements

ProductFeature enhancements

IDN Provisioning

Users now receive a more informative error message when they try to create an identity profile while an aggregation is running.

Connectivity - NetSuite

The Oracle NetSuite Connector now supports the aggregation and provisioning of the “Location” attribute.

Connectivity - Linux

The Linux connector now supports Ubuntu version 22.04.

Connectivity - Duo

The Duo connector is now enhanced to support aggregation of more than four aliases that are present on the managed system.

Connectivity - SAP GRC

The SAP GRC connector has been enhanced to handle user provisioning operations to SAP GRC, for supporting sources like LDAP where the user names contain mixed-cases and special characters.

Platform

IdentityNow admins now have enhanced entitlement administration capabilities. This release includes the ability to:

  • Perform bulk entitlement updates for entitlement owner, privileged status, and requestable status.
  • View total counts of access profiles that include an entitlement and identities that have an entitlement assigned.
  • Update an entitlement’s privileged and requestable status from the Entitlements page.
  • View lists of access profiles that include an entitlement and identities that have an entitlement assigned.
  • Revoke a directly assigned entitlement from an identity.

For more information, refer to Managing Entitlements.

IDN Provisioning

The display names of the following identity attributes have changed on the Identity Profile Mappings and Identity Details pages:

  • "User Name" is now "Username"
  • "Last Name" is now "Family Name"
  • "First Name" is now "Given Name"

Connectivity - Azure AD

The Azure Active Directory connector now supports managing Admin and User consented permissions for Service Principals.

Connectivity - SAP HR/HCM

The SAP HR/HCM connector is now certified with SAP S4/HANA 2022.

Connectivity - SuccessFactor

The SuccessFactors connector is now enhanced with write-back abilities for SuccessFactor and ODATA attributes. For more information, refer to Provisioning Additional Attributes Using the ODATA API.

Connectivity - SAP GRC

The SAP GRC Connector is undergoing expansion to encompass non-ABAP SAP systems. In this latest release, we have achieved full compatibility between SAP GRC integration and SAP Enterprise Portal.

Connectivity - CyberArk-PCloud

The CyberArk Privilege Cloud Connector now supports CyberArk Privilege Cloud Shared Services Architecture. With this release, we are announcing the deprecation of the existing CyberArk Privilege Cloud Connector.

Connectivity - Jira Service Desk

The IdentityNow for Atlassian Cloud Jira Service Desk Integration now populates the Access Request comment in the Jira Ticket.

The IdentityNow for Atlassian Server Jira Service Desk Integration now populates the Access Request comment in the Jira Ticket.

Fixes

ProductIssue IDFixes

IDN Provisioning

IDNHUSKY-3343

Fixed an issue where the selection option did not work correctly on the Account Schema page.

IDN Provisioning

IDNHUSKY-3906

Fixed an issue in the updated Identity Profiles List where, when a user downloaded an identity exception report, the last report in the list downloaded instead of the correct one.

Connectivity - Azure AD

CONETN-4303

The Azure Active Directory Connector now correctly displays the “displayName” attribute of custom AzureADActive and AzureADEligible roles assigned to the user after Account Aggregation.

Connectivity - SAP Fieldglass

CONETN-4260

The SAP Fieldglass connector now aggregates all the accounts correctly when the Page Size field is configured up to a value of 350 in the IdentityNow application.

Connectivity - LDAP

CONETN-4287

The LDAP Connector no longer throws an error when the value of the attribute is null or empty for SET and REMOVE operations.

Connectivity - Slack

CONETN-4197

The Slack connector now overrides the existing phone number value when the phone number attribute from the provisioning plan is set to null or no value.