SaaS

SaaS Release Notes - December 18, 2023

Production release notes - December 18, 2023

Release notes might contain references to new features, enhancements, and fixes that will be gradually turned on in production over the next several weeks. See the SaaS Functional End of Life and Major Changes Policy.

Identity Security Cloud is SailPoint's next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.

New features

ProductWhat's new

Connectivity - SIM - ServiceNow

The ServiceNow Service Desk connector has been enhanced to create Incident (INC) tickets, in addition to Request (REQ) and Request Items (RITM) within ServiceNow. For more information on configuring the Incident ticket type, refer to Configuring SailPoint for ServiceNow Service Desk.

SaaS Connectors

The Snowflake SaaS connector now supports the following:

  • Read Group Hierarchy for Roles.
  • Filtering accounts and roles based on aggregation filters. For more information, refer to Aggregation Settings.

Platform

Configuration Hub introduces the new tab "Rules Substitutions" which is available within the Edit Draft of an object. This tab lists the automated attribute value substitutions that were applied to the draft, based on the tenant level Object Mapping & the Global configuration substitution rules.

Refer to Using the Configuration Hub for more information.

Connectivity - SalesForce

The Salesforce connector now supports Salesforce API version 59.0. On existing sources, the connector automatically uses API version 59.0 automatically, regardless of the version in the URL.

SaaS Connectors

SailPoint is pleased to announce the availability of net new Microsoft Entra SaaS connector.

The SailPoint Microsoft Entra SaaS connector can securely connect with the Microsoft Entra system without the need of a Virtual Appliance (VA) and provides a deep level of governance capabilities for the accounts and groups. For more detail, refer to Integrating SailPoint with Microsoft Entra SaaS.

SailPoint CIEM

You can now download the Cloud Resource Access report to view the services and resources identities can access in each of your connected CIEM sources. Reports are divided by service.

Connectivity - EPIC

The Epic SER connector now supports the aggregation of Blueprints as an entitlement type.

Enhancements

ProductFeature enhancements

SaaS Connectors

SailPoint is pleased to announce the following enhancements in the SCIM 2.0 SaaS connector:

The connector now supports Custom Authentication* as a new authentication type. When a specific SCIM server doesn't follow the standard authentication mechanism, you can configure the source using Custom Authentication. For more information, refer to Custom Authentication.

  • For Non-Compliant Settings; The connector now supports provisioning of Multivalued Extended Schema attributes and the Read Only attributes feature using the PUT method. For more information, refer to Non-Compliant Settings.

Connectivity - SAP Portal

SailPoint has applied recent security updates to our SAP Portal integration by upgrading the gson jar in the SDA file. To protect your privacy, using the latest SDA file is highly advised. For more information, refer to Prerequisites.

SaaS Connectors

The Salesforce SaaS connector now supports the following features -

  • Creating Partner User and Portal User.
  • Creating Contacts after create User.
  • Aggregate entitlements (QueueNames, Collaboration Group, PermissionSet, PermissionSetGroup, PermissionSetLicense, ManagedPackage).
  • Add/Remove entitlements (Collaboration Group, PermissionSet, PermissionSetGroup, PermissionSetLicense, ManagedPackage).
  • Aggregate Collaboration Group, PermissionSet, PermissionSetGroup, PermissionSetLicense and ManagedPackage as separate group object.
  • Support for Enhanced Domains.

Connectivity - ServiceNow

The ServiceNow Identity Governance connector now supports OKTA OAuth 2.0 with the Client Credentials grant type, in addition to the Refresh Token grant type. For more information, refer to OAuth 2.0 Authentication.

Connectivity - PeopleSoft HRMS v2

The Oracle PeopleSoft HCM connector has been enhanced to excluded inactive persons from aggregation operations when you select the Exclude Inactive Persons checkbox. For more information, refer to Aggregation Settings.

Connectivity - Oracle HRMS

The Oracle HRMS connector now supports the aggregation of inactive users from the specified date. For more information, refer to Additional Settings.

Connectivity - UKG Pro

The UKG Pro Core HCM connector now supports update operations for employee records, and it can now aggregate employment detail attributes for employees. For more information, refer to Provisioning Employee Attributes and Aggregate Additional Employee Schema Attributes.

Connectivity - Azure AD

The Microsoft Entra ID (Formerly Azure Active Directory) connector now supports the management of Organizational Mail Contacts as accounts. For more information, refer to Azure Mail Contact Management.

Connectivity - Azure AD

The Microsoft Entra ID (Formerly Azure Active Directory) connecter has been enhanced so that Azure Active Directory B2C tenants now support the Add, Set, and Remove operations for the userIdentities and signInNames attributes of social and local user accounts during the Modify and Update provisioning operations. For more information, refer to Provisioning B2C userIdentities and signInNames.

Connectivity - Duo

The Duo connector now supports granting of specific administrative units to DUO administrators.

Connectivity - IQService

IQService now supports the -m parameter. This parameter enables you to pick the best certificate for TLS communication (when there are multiple) from the IQService host personal folder by matching the subject name or serial number. For more information, refer to IQService Commands.

Connectivity - CyberArk-CorePas

The Cyberark Self-Hosted connector now supports CyberArk Privileged Access Manager (PAM) version 13.0, connected using the Identity SCIM Server hosted on the cloud.

Connectivity - SAP GRC

The SAP GRC connector now offers enhanced functionality for modifying attributes associated with a user during the disable operation. This critical enhancement allows Account Disable requests to be distinguished between inactive users (leavers) and active users (leave of absence). The upgrade also ensures a seamless clean exit process by facilitating the removal of:

  • User roles
  • Configuring specific user groups during the disable operation
  • Setting a user's end date
  • Selectively disabling the account on specified systems

In addition to streamlining the account management process, these advanced features provide greater flexibility and precision in handling different scenarios; ultimately enhancing the overall user experience and administrative control within the SAP GRC system.

Connectivity - Windows Local

The Windows Local connector now supports adding and removing entitlements for Non-local (domain) users.

Connectivity - IQService

IQService now supports native PowerShell scripts with version 5.1 and later. For more details, refer to Specifying PowerShell Version for Before/After Scripts.

SailPoint CIEM

You can now add up to 150 AWS cloud trails to connect AWS activity data with SailPoint CIEM.

Connectivity - Siebel

The Oracle ERP Siebel connector now supports Siebel Server Version 23.9.0.0.

SailPoint CIEM

You can now connect Microsoft Entra ID and SailPoint CIEM without needing a virtual appliance.

Fixes

ProductIssue IDFixes

IDN Access Request

UIAO-8450

Fixed an issue where access object counts displayed "null" instead of "0" on landing pages.

Connectivity - Azure AD, IQService

CONETN-4502

The Microsoft Entra ID (Formerly Azure Active Directory) connector now fetches another Group as an owner of Distribution Groups via IQService.

Connectivity - Azure AD

CONETN-4509

The Microsoft Entra ID (Formerly Azure Active Directory) connector now no longer fails while using Advanced Filter options during delta aggregation.

Connectivity - Azure AD

CONETN-4469

The Microsoft Entra ID (Formerly Azure Active Directory) connector now displays a proper error message for the unsupported Get Object operation on AzureADActive and AzureADEligible Roles.

Connectivity - Azure AD

CONETN-4396

The Microsoft Entra ID (Formerly Azure Active Directory) connector now fetches the shared mailbox even if they have the same display name.

Connectivity - IQService

CONETN-4392

The Active Directory connector will now successfully create a contact without displaying an error message in the UI when the setAttributeLevel flag is set to false.

Connectivity - Active Directory, IQService

CONETN-4307

To prevent IQService from creating a broken Logon Name, when the account name has a space in it, the UserPrincipalName on the shadow account should be passed in the provisioning plan using the following format: exch_userPrincipalName. For example, <AttributeRequest name="exch_userPrincipalName" op="Add" value=TestUser@test.lab/>