SaaS

SaaS Release Notes - July 4, 2025

Production release notes - July 4, 2025

Release notes cover new features, enhancements, and fixes that have been released to production.

Identity Security Cloud is SailPoint's next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.

New features

ProductWhat's new

SaaS Connectors - Microsoft Entra SaaS

The Microsoft Entra SaaS connector now supports managing system-assigned managed identities. For more information, refer to System-Assigned Managed Identities.

Identity Security Cloud - Provisioning and Task Manager

Administrators can now configure a lifecycle state to automatically remove all access from a terminated user. When the Remove All Access option is enabled, the system revokes all requested and detected access, including roles, access profiles, and entitlements. This removal excludes access provisioned by the current lifecycle state or birthright roles and bypasses any required approvals. For more information about this feature, refer to the product announcement and documentation.

Connectivity - Microsoft Entra ID

The Microsoft Entra ID connector now supports managing system-assigned managed identities. For more information, refer to System-Assigned Managed Identities.

Non-Employee Risk Management - MySailPoint

Identity Security Cloud - MySailPoint

We've added two new widgets to the Home page to allow you to track Non-Employee Risk Management activity. These widgets allow you to track pending requests, as well as completed and failed requests. You can select these widgets to go to Non-Employee Risk Management for more details.

Enhancements

ProductFeature enhancements

Identity Security Cloud - Provisioning and Task Manager

Within Lifecycle states, the 40 source limit for Enable and Disable actions through the user interface has been removed, allowing Admins to select any number of sources.

Identity Security Cloud - Certifications

Improved the report generation time for large certification campaigns.

Connectivity - SAP Direct

The SAP Direct connector now supports SAP S/4HANA 2023 On-Premises SP/FP Stack 03.

Identity Security Cloud - Core Access Model

All entitlements in an access profile are now revoked when the access profile is revoked through an access request, even if the entitlements were previously assigned directly to a member identity.

Connectivity - SAP GRC

The SAP GRC connector now supports SAP GRC Access Control 12.0 SP28, ensuring reliable integration and functionality.

Identity Security Cloud - Access Requests

Access revocation request approvals now show account details to the approver when the request included account information.

Identity Security Cloud - Access Requests

When administrators have not configured applications for access requests, the Request Center now presents the Access Items view to the requester instead of the empty Applications page. (The Recommended page is still the default access items page when there are access request recommendations available for the user.)

Identity Security Cloud - Virtual Appliance

Older virtual appliances will now be automatically migrated to CGroupsV2 when restarting a VA cluster.

SaaS Connectors - Ceridian Dayforce HCM SaaS

The Ceridian Dayforce HCM SaaS connector now has a default correlation mapping for newly created sources. You can update the mapping as required for your organization.

SaaS Connectors - Box SaaS

The Box SaaS connector now has a default correlation mapping for newly created sources. You can update the mapping as required for your organization.

Identity Security Cloud - Sources and Account Management

We've modernized the identity profile administration to improve user experience and accessibility.

Identity Security Cloud - Multi-Host

The SailPoint Multi-Host integrations now supports centralized Classification and Mapping of Machine Accounts. For more information, refer to Managing Multi-Host Machine Accounts.

Fixes

ProductIssue IDFixes

SaaS Connectors - Microsoft Entra SaaS

CONHOWRAH-5741

The Microsoft Entra SaaS connector now aggregates all the subscriptions during entitlement aggregation.

Identity Security Cloud - SoD

ISCCOMPLI-5537

When a governance group’s name is updated, the Separation of Duties policy now correctly updates the governance group name displayed in the Policy Owner and Violation Owner fields.

Connectivity - IBM DB2

CONETN-5077

IBM DB2 Connector will no longer fail when deleting a user.

IdentityIQ - JDBC

CONETN-5078

The JDBC Exception Handler now handles NullPointerException.

Connectivity - Workday

CONETN-5062

Workday Connector now sets the start of aggregation date as the lastAggregationDate.

Connectivity - Connector Gateway

CONCHORDS-3135 CONDOCS-6822 CONCHORDS-2269 CONCHORDS-3186

The Mainframe Connector Gateway version ConnectorGateway-Jun-2025 is released. This version works only with a customer provided (external) encryption key when AT-TLS is enabled. If you're currently using a default encryption key (no custom key), you can externalize the key using the recycleencryptionkey command. This release upgrades the log4j jar version that the product uses, in addition to minor updates and fixes. For more information, refer to Mainframe Connectors Downloads.