SaaS

SaaS Release Notes - September 19, 2025

Production release notes - September 19, 2025

Release notes cover new features, enhancements, and fixes that have been released to production.

Identity Security Cloud is SailPoint's next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.

New features

ProductWhat's new

Identity Security Cloud - DPR

SailPoint introduces Desktop Password Reset (DPR) for macOS, enabling password management for users linked with AD accounts, mobile network accounts, and FileVault. The enhanced configurator simplifies DPR setup, and supports JAMF. For more information, refer to Desktop Password Reset for macOS Release Notes.

Identity Security Cloud - SailPoint MCP Server

The SailPoint Model Context Protocol (MCP) Server is now available to use natural language requests to list, initiate, query, and cancel access requests using the industry standard MCP protocol. Refer to Model Context Protocol Server for more information.

Identity Security Cloud - SailPoint application onboarding

Admins can now assign source configuration tasks to subject matter experts. The assignee and admin can collaborate through comments on assigned sources. When the assignee has completed their configurations, the admin will review the settings before committing them to the live source. Refer to Assigning Source Configurations for more information.

SaaS Connectors

SaaS connectors now use the tenant’s time zone for aggregation scheduling.

Enhancements

ProductFeature enhancements

Identity Security Cloud - Parameter Storage

Parameter Storage allows any customer to store connection, authentication, and authorization credentials and configuration information. The first integration with Parameter Storage will be Active Directory and Windows Server Privileged Actions within a Privileged Task Automation workflow. Customers using these actions no longer need a Credential Provider to be setup in Identity Security Cloud. For more information, refer to the Parameter Storage documentation.

Identity Security Cloud - Core Access Model

Access Model Metadata now includes the ability to add valuable business context to access profiles with predefined and custom metadata attributes. With this addition, Access Model Metadata now supports all ISC access items: entitlements, roles, and access profiles.

SailPoint Cloud Infrastructure Entitlement Management (CIEM)

SailPoint CIEM has added a new Cloud Privilege Heat Map widget to the Access Intelligence Center. Additionally, all SailPoint CIEM widgets have been widened for better visibility.

SailPoint Cloud Infrastructure Entitlement Management (CIEM)

You can now use SailPoint CIEM and lifecycle management to remove AWS Identity Center accounts from the AWS IAM Identity Center Identity Store. Refer to Configuring Lifecycle States for more information.

Identity Security Cloud - Access Intelligence Center (AIC)

The Access Intelligence Center now includes access item relationships. This allows for more specific and detailed charting related to entitlements, roles, and access profiles.

Identity Security Cloud - Sources and Account Management

The account aggregation process now performs additional checks to better handle account changes due to OU moves or account renames in Active Directory. The new behavior preserves provisioning history, reduces unnecessary events, and eliminates the need for manual work to restore provisioning history.

Connectivity - RSA

Identity Security Cloud - RSA

The SailPoint RSA Authentication Manager connector now supports versions 8.8 and related patches.

Data Access Security

A major performance effort took place to redesign and modernize the Data Access Security OneDrive Crawl and Permission Collection tasks. The outcome of this effort decreases the time it takes for the Crawl and Permissions Collection tasks to complete while also improving stability and scalability.

To accomplish this, new API's were implemented which requires adjusting permissions in your existing OneDrive Azure Application Registration. Without these changes applied, both the Crawl and Permission Collection task will no longer run successfully. You can apply these permissions without breaking the current runs.

IMPORTANT: Ensure your prerequisites permissions are updated by Sept. 25th.

At your earliest convenience, please update your OneDrive Azure Application API permissions to reflect the following:

Microsoft Graph (new!)

  • Files.Read.All (new!)
  • Sites.Read.All (new!)
  • User.Read.All (new!)
  • Domain.Read.All (new!)

Office 365 Management APIs

  • ActivityFeed.Read

SharePoint

  • Sites.Fullcontrol.All

For more details, please refer to the permission changes to enjoy faster task times.

Fixes

ProductIssue IDFixes

Identity Security Cloud - Sources and Account Management

PLTCONN-8946

Updated the cloudIdentityProfileName attribute to be immutable in the put-source and update-source APIs.

SaaS Connectors - Microsoft Entra SaaS

CONHOWRAH-5962

The Microsoft Entra SaaS connector no longer fails with “v.get is not a function” error during role provisioning.

SaaS Connectors - ISC Cloud Governance Connector

CONCHENAB-7485

The Identity Security Cloud Governance connector now allows you to set a custom delay before performing the read user (get object) operation for create and update account operations. For more information, refer to the troubleshooting page.

SaaS Connectors - Atlassian Suite SaaS

CONCHORDS-3489

The Atlassian Suite SaaS connector now has a default page size as 100 while aggregating ProjectRole entitlements, as per the maximum allowed page size value from Atlassian.

Connectivity - Snowflake

CONETN-5192

The Snowflake account creation no longer throws a NullPointerException (NPE) when default_secondary_role is not provided.

SaaS Connectors - GitHub SaaS

CONSEALINK-7766

The GitHub SaaS connector now aggregates entitlements of type Role correctly.

IdentityIQ - Linux

CONETN-5174

The SailPoint Linux Connector now displays the lastLogin date correctly.

Access Risk Management

SAASTRIAGE-9974

Fixed an issue where customers using the Identity Security Cloud to Access Risk Management integration for separation of duties (SoD) checks as part of the ISC access request process received an "Unable to execute request" error over the weekends when the functionality had not been used for more than 24 hours.

Connectivity - SAP Fieldglass

CONETN-5132

The SAP Fieldglass connector can now remove single additional entitlements (roles) without experiencing unspecified errors.