SaaS
SaaS Release Notes - July 4, 2025
Production release notes - July 4, 2025
Release notes cover new features, enhancements, and fixes that have been released to production.
Identity Security Cloud is SailPoint's next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.
New features
| Product | What's new |
|---|---|
SaaS Connectors - Microsoft Entra SaaS | The Microsoft Entra SaaS connector now supports managing system-assigned managed identities. For more information, refer to System-Assigned Managed Identities. |
Identity Security Cloud - Provisioning and Task Manager | Administrators can now configure a lifecycle state to automatically remove all access from a terminated user. When the Remove All Access option is enabled, the system revokes all requested and detected access, including roles, access profiles, and entitlements. This removal excludes access provisioned by the current lifecycle state or birthright roles and bypasses any required approvals. For more information about this feature, refer to the product announcement and documentation. |
Connectivity - Microsoft Entra ID | The Microsoft Entra ID connector now supports managing system-assigned managed identities. For more information, refer to System-Assigned Managed Identities. |
Non-Employee Risk Management - MySailPoint Identity Security Cloud - MySailPoint | We've added two new widgets to the Home page to allow you to track Non-Employee Risk Management activity. These widgets allow you to track pending requests, as well as completed and failed requests. You can select these widgets to go to Non-Employee Risk Management for more details. |
Enhancements
| Product | Feature enhancements |
|---|---|
Identity Security Cloud - Provisioning and Task Manager | Within Lifecycle states, the 40 source limit for Enable and Disable actions through the user interface has been removed, allowing Admins to select any number of sources. |
Identity Security Cloud - Certifications | Improved the report generation time for large certification campaigns. |
Connectivity - SAP Direct | The SAP Direct connector now supports SAP S/4HANA 2023 On-Premises SP/FP Stack 03. |
Identity Security Cloud - Core Access Model | All entitlements in an access profile are now revoked when the access profile is revoked through an access request, even if the entitlements were previously assigned directly to a member identity. |
Connectivity - SAP GRC | The SAP GRC connector now supports SAP GRC Access Control 12.0 SP28, ensuring reliable integration and functionality. |
Identity Security Cloud - Access Requests | Access revocation request approvals now show account details to the approver when the request included account information. |
Identity Security Cloud - Access Requests | When administrators have not configured applications for access requests, the Request Center now presents the Access Items view to the requester instead of the empty Applications page. (The Recommended page is still the default access items page when there are access request recommendations available for the user.) |
Identity Security Cloud - Virtual Appliance | Older virtual appliances will now be automatically migrated to CGroupsV2 when restarting a VA cluster. |
SaaS Connectors - Ceridian Dayforce HCM SaaS | The Ceridian Dayforce HCM SaaS connector now has a default correlation mapping for newly created sources. You can update the mapping as required for your organization. |
SaaS Connectors - Box SaaS | The Box SaaS connector now has a default correlation mapping for newly created sources. You can update the mapping as required for your organization. |
Identity Security Cloud - Sources and Account Management | We've modernized the identity profile administration to improve user experience and accessibility. |
Identity Security Cloud - Multi-Host | The SailPoint Multi-Host integrations now supports centralized Classification and Mapping of Machine Accounts. For more information, refer to Managing Multi-Host Machine Accounts. |
Fixes
| Product | Issue ID | Fixes |
|---|---|---|
SaaS Connectors - Microsoft Entra SaaS | CONHOWRAH-5741 | The Microsoft Entra SaaS connector now aggregates all the subscriptions during entitlement aggregation. |
Identity Security Cloud - SoD | ISCCOMPLI-5537 | When a governance group’s name is updated, the Separation of Duties policy now correctly updates the governance group name displayed in the Policy Owner and Violation Owner fields. |
Connectivity - IBM DB2 | CONETN-5077 | IBM DB2 Connector will no longer fail when deleting a user. |
IdentityIQ - JDBC | CONETN-5078 | The JDBC Exception Handler now handles |
Connectivity - Workday | CONETN-5062 | Workday Connector now sets the start of aggregation date as the |
Connectivity - Connector Gateway | CONCHORDS-3135 CONDOCS-6822 CONCHORDS-2269 CONCHORDS-3186 | The Mainframe Connector Gateway version |