SaaS

SaaS Release Notes - September 30, 2024

Production release notes - September 30, 2024

Release notes might contain references to new features, enhancements, and fixes that will be gradually turned on in production over the next several weeks. See the SaaS Functional End of Life and Major Changes Policy.

Identity Security Cloud is SailPoint's next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.

New features

ProductWhat's new

Data Access Security

Data Access Security is pleased to announce Activity Monitoring capabilities for Box, designed to capture and understand identities’ behavior when accessing data, both in real-time and historically. This advanced features provide Administrators and Data Owners with a single, comprehensive view of access activities, ensuring robust security and compliance.

See the Box documentation for more details.

Data Access Security

Data Access Security is pleased to announce Activity Monitoring capabilities for Dropbox, designed to capture and understand identities’ behavior when accessing data, both in real-time and historically. This advanced features provide Administrators and Data Owners with a single, comprehensive view of access activities, ensuring robust security and compliance.

See the Dropbox documentation for more details.

Data Access Security

Data Access Security is pleased to announce Activity Monitoring capabilities for Google Drive, designed to capture and understand identities’ behavior when accessing data, both in real-time and historically. This advanced features provide Administrators and Data Owners with a single, comprehensive view of access activities, ensuring robust security and compliance.

See the Google Drive documentation for more details.

Data Access Security

Data Access Security is pleased to announce Activity Monitoring capabilities for Exchange Online, designed to capture and understand identities’ behavior when accessing data, both in real-time and historically. This advanced features provide Administrators and Data Owners with a single, comprehensive view of access activities, ensuring robust security and compliance.

When enabling Exchange Online Activity Monitoring, we will collect User and Shared Mailbox events as well as Admin events which are logged from Microsoft by default. Additional Mailbox events can also be collected. See the Exchange Online documentation for more details.

SaaS Connectors - Workiva

SailPoint is pleased to announce the availability of the new Workiva SaaS connector.

The SailPoint Workiva SaaS connector securely connects with the Workiva system and provides governance capabilities for the Workiva users. For more information, refer to Integrating SailPoint with Workiva.

Enhancements

ProductFeature enhancements

SaaS Connectors - Microsoft Entra

The Microsoft Entra SaaS connector now supports managing custom security attributes for Microsoft Entra ID users. For more information, refer to Custom Security Attributes.

Connectivity - Microsoft Entra ID

The Microsoft Entra ID connector now supports aggregating risk related information for Service Principals accounts. For more information, refer to Risky Service Principal Alert Feature.

SaaS Connectors - Microsoft Entra

The Microsoft Entra SaaS connector now supports delta aggregation. For more information, refer to Aggregation and Filter Settings.

SaaS Connectors - Microsoft Entra

The Microsoft Entra SaaS connector now supports aggregating risk specific information for Service Principal accounts. For more information, refer to Risky Service Principal Alert Feature.

Connectivity - IQService

SailPoint Integration Service (IQService) now supports communicating over Internet Protocol version 6 (IPv6).

Connectivity - SAP GRC

The SAP GRC connector has been enhanced to integration with SAP IAG. This configuration helps you to request user and entitlement provisioning, remove user access, and perform risk analysis of user requests in IAG for connected SAP Cloud systems, using the SAP GRC system as a bridge.

SaaS Connectors - Workday Accounts SaaS

The Workday Accounts SaaS connector now supports the management of Workday Integration system accounts. For more information, refer to Workday Accounts SaaS.

Data Access Security

Data Access Security has rolled out a modernized Resource Permissions Tree View screen. The Resource Permissions Tree View enables SailPoint users viewing the access rights of users and groups to organizational resources using tree visualization. The screen was previously built using an earlier JS version that is no longer supported and is susceptible to potential security risks. The new screen version uses newer Angular technology based on the Armada UI framework, is consistent with SailPoint's screen experience, and reduces operational costs.

Connectivity - IBM Lotus Domino

The HCL Domino connector now supports the HCL Domino 14.0 version.

Connectivity - SAP Concur

The SAP Concur connector has been enhanced to support Test Employees and BI Managers attributes. For more information, refer to Account Attributes.

Connectivity - Workday Accounts

The Workday Accounts connector is now enhanced to aggregate Integration Users accounts. For more information, refer to Workday Accounts.

SailPoint Cloud Infrastructure Entitlement Management (CIEM)

SailPoint now populates the External ID for the CIEM AWS connector to provide a more secure and simpler connection configuration to AWS IaaS.

Fixes

ProductIssue IDFixes

Identity Security Cloud - Sources and Account Management

SAASTRIAGE-4657

Fixed an issue in the Identity Profiles Configuration UI where switching the source used for the Directory Connection sign-in method was not saving the new selection.

Identity Security Cloud - Configuration Hub

PLTCONFHUB-2412

When applying take-from-target rules, Configuration Hub would sometimes read a null array as an empty array. The service that imports source objects, would compare the existing password policies (null) against the incoming password policies (empty array) and display an error.

A check has been added to the take-from-target rules evaluator to ensure this no longer happens.

SailPoint Cloud Infrastructure Entitlement Management (CIEM)

Fixed an issue where the table for a user's Azure privileges displayed more effective access than they had. The table now only displays privileges with existing cloud resources.

Connectivity - Microsoft Azure SQL Database

CONETN-4839

The Microsoft Azure SQL Database connector now supports provisioning and de-provisioning database roles when the database name matches the server name.

Connectivity - Snowflake

CONETN-4907

The Snowflake connector no longer aggregates duplicate roles in double quotes (“ “) after the entitlement aggregation.

Connectivity - Delimited File

CONETN-4896

The Delimited File connector no longer throws an NPE during aggregation with partitioning for CSV files with no data.

Identity Security Cloud - Configuration Hub

PLTCONFHUB-2550

When an ‘objects’ property is missing from a file that is being uploaded to Configuration Hub, a new error message displays. It reads, “The current file does not have an 'objects' property which is needed for this upload."

Connectivity - IQService

CONETN-4551

IQService certificate based client authentication by UpdateService now adheres to the provided list of trusted certificate names for Subject Alternative Name (SAN) and Subject match flow.