SaaS
SaaS Release Notes - September 12, 2025
Production release notes - September 12, 2025
Release notes cover new features, enhancements, and fixes that have been released to production.
Identity Security Cloud is SailPoint's next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.
New features
| Product | What's new |
|---|---|
SaaS Connectors - Okta SaaS | The Okta SaaS connector can now be configured for Activity Insights. For more information, refer to Activity Insights Settings. |
Machine Identity Security | Machine Identity Security now includes machine identity subtypes and ownership: Subtypes - Application identities have been introduced as a subtype of machine identities. Existing machine identities have been migrated to the application identity subtype to set the foundation for future subtypes. For more information about machine identity subtypes, refer to the product announcement and documentation. Owners - Multiple owners can now be assigned to machine identities to create automated succession plans that reduce the risk of orphaned application identities. For more information, refer to the product announcement and documentation. |
Enhancements
| Product | Feature enhancements |
|---|---|
Access Risk Management | Performance improvements in the Access Risk Management legacy Provisioning Request dashboard. |
Identity Security Cloud - Core Access Model | The Applications tab has been moved under the Access Model menu to better align with how applications represent access. |
Identity Security Cloud - Access Requests | The Approvals overlay no longer shows a Last Approver field. Prior to this change, Last Approver was only naming the currently assigned approver, which was self-evident to the logged-in user viewing their own approvals. |
Connectivity - UKG Pro | The UKG Pro connector can now aggregate Job attributes in the Additional Employee Schema using UKG Pro's V2 API instead of the deprecated V1 API. |
SaaS Connectors - Tableau | The Tableau Online connector now has a default correlation mapping for the newly created sources. You can modify the mapping as per your requirements. |
SaaS Connectors - Lucidchart | The Lucidchart connector now has a default correlation mapping for the newly created sources. You can modify the mapping as per your requirements. |
Identity Security Cloud - Access Requests | Admins can now run predefined reports on access requests for entitlements marked as Privileged. One report lists all access requests for privileged entitlements and one report lists access requests for privileged entitlements that do not include an end date for automatic revocation. |
Identity Security Cloud - Access Requests | Approvals generated for access requests for entitlements that are marked Privileged in ISC now support more informed decision making by including a Privileged badge on the request card. |
SaaS Connectors - SAP SuccessFactors SaaS | The SuccessFactors SaaS connector now supports delta aggregation. |
Fixes
| Product | Issue ID | Fixes |
|---|---|---|
Connectivity - SAP SuccessFactors | CONETN-5195 | The SuccessFactors connector can now provide consistent label mapping for FO objects, with improved pagination support for large datasets. |
Identity Security Cloud - SOD | ISCCOMPLI-6569 | The separation of duties policy violation report downloaded from Search > Policies for multiple policies is now generated with a single header. |
Identity Security Cloud - CyberArk Privileged Cloud Shared Services | CONETN-5145 | The SailPoint CyberArk Privilege Cloud Shared Services connector now successfully displays Direct Permissions. |
Identity Security Cloud - Workflows | PLTWRKFLW-9218 | Workflows has made the following changes to our Templates and Template Categories:
|
Connectivity - JDBC | CONETN-5113 | The JDBC connector now supports stored procedures for |
Connectivity - SCIM 2.0 | CONETN-5119 | The SCIM 2.0 connector can now properly encode the URL while performing update operations using PUT. |
Connectivity - Oracle HCM Cloud | CONETN-5091 | The Oracle HCM Cloud connector now throws the proper exception for person number not having worker data. |