SaaS
SaaS Release Notes - December 12, 2025
Production release notes - December 12, 2025
Release notes cover new features, enhancements, and fixes that have been released to production.
Identity Security Cloud is SailPoint's next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.
New features
| Product | What's new |
|---|---|
Connectivity - SAP Analytics Cloud | Your VA-based SAP Analytics Cloud source can now be migrated to a corresponding SaaS source while ensuring data (users and entitlements) remain intact and maintains your source configurations like access profiles, roles, password settings, and correlation configurations. For more information, refer to Migrate VA-based Source to a SaaS Source. |
Data Access Security | Customization of email notifications for Data Access Security is now available through Identity Security Cloud Email Templates. Go to Admin > Global > Email Templates to find your corresponding Data Access Security template and use the Edit option to adjust as desired. For customization details, refer to Using Email Templates. |
SaaS Connectors - Express Setup - Deep Governance | Identity Security Cloud now supports Express Setup as an option to configure new SaaS-based deep governance connectors. Using Express Setup enables read-only connections to sources for account and entitlement aggregation. This allows for rapid deployment, requiring minimal configuration to quickly begin gathering user data from source systems and achieve compliance objectives faster. To configure the new connector for full deep governance feature support, you can edit the source after creation. For a list of deep governance connectors which support Express Setup, refer to Deep Governance, and look for connectors with an asterisk next to their name. |
SaaS Connectors - Snowflake SaaS | The SailPoint Snowflake SaaS connector can now aggregate Snowflake Cortex Agents. For more information, refer to Configuring Agent Governance. |
Identity Security Cloud - Access Modeling | AI Core Attributes unify how identity attributes are managed across all SailPoint AI products, aligning them with Identity Security Cloud and IdentityIQ to deliver a consistent, streamlined, and scalable AI experience. This enhancement replaces the legacy IAI Field Mappings for new customers, simplifies onboarding, and reduces onboarding error rates. |
SaaS Connectors - Quick Compliance | Identity Security Cloud now supports Quick Compliance connectors, enabling read-only connections to sources for account and entitlement aggregation. These connectors are designed for rapid deployment, requiring minimal configuration to quickly begin gathering user data from source systems and achieve compliance objectives faster. For a list of available Quick Compliance connectors, refer to Quick Compliance. |
Connectivity - Dynamics 365 - CRM | Your VA-based Microsoft Dynamics 365 Customer Relationship Management source can now be migrated to a corresponding SaaS source while ensuring data (users and entitlements) remain intact and maintains your source configurations like access profiles, roles, password settings, and correlation configurations. For more information, refer to Migrate VA-based Source to a SaaS Source. |
Enhancements
| Product | Feature enhancements |
|---|---|
Access Risk Management | As part of the migration to a new Access Risk Management reporting infrastructure, the Export Risk Analysis button has been moved from the Online Reports page to the Analyses tab on the Activity History page. |
Data Access Security | Data Access Security SharePoint Online connector is offering a new setting "Include Backend System Resources". Enabling this new option will crawl resources which are created and generally maintained by Microsoft. These items are marked as 'hidden' from Microsoft but can be accessible through the SharePoint Online UI. Note that enabling this feature will add additional time for the crawl to complete. |
Machine Identity Security - Workflows | Six new workflow event triggers are now available that fire whenever key machine identity and account lifecycle changes occur. Included triggers are: Machine Identity Triggers Account Event Triggers |
Identity Security Cloud - Sources and Account Management | Users can now select previously uploaded files when running entitlement and account aggregations for delimited file and flat file sources. |
SaaS Connectors - Microsoft Entra SaaS | The Microsoft Entra SaaS connector now allows filtering of the Azure resource providing granular control over the scope of account and entitlement aggregation through configured list of Subscription IDs and Management Group IDs. For more information, refer to Azure Resource Filtering: Subscriptions and Management Groups. |
Identity Security Cloud - Sources and Account Management | Entitlement types and schemas can now be managed in the user interface for all sources that support entitlements. You can view and edit schema attributes and choose to aggregate all entitlements or select the specific entitlement types you want to include. |
Identity Security Cloud - Access Intelligence Center (AIC), User Levels | AIC Author and AIC Reader are available as custom user levels, removing the requirement for default Admin user levels. Additionally, the navigation has moved from the Admin tab to the Home tab. |
Fixes
| Product | Issue ID | Fixes |
|---|---|---|
Identity Security Cloud - Core Access Model | IDNPALM-7796 | Fixed an issue where the error message was unclear when only |
Data Access Security | DASDEV-23514 | The Solutions Center option for Data Access Security can now only be found from the top left icon. The option to select it has been removed from the Login dropdown menu. |
Connectivity - SAP Fieldglass | CONUMSHIAN-10025 | The SAP Fieldglass SaaS Connector no longer fails with 404 errors during account aggregation or provisioning operations. |
Identity Security Cloud - Core Access Model | IDNPALM-7760 | Fixed an issue where Role and Access Profile creation failed if the name contained only Korean, Chinese, or Japanese characters. Names containing only these character sets is now fully supported. |
Identity Security Cloud - Access Requests | ISCARP-17812 | Fixed an issue where failed access requests for dynamic roles were producing duplicate list entries in the request center because dimensions within dynamic roles were displayed as separate requests. Now, dynamic roles are listed as a single request in the request center. |
Identity Security Cloud - Certifications, Core Access Model | ISCCOMPLI-7286 | Fixed an issue in a certification where the Permissions tab did not display in the entitlement’s details. |
Connectivity - SAP GRC | CONETN-5244 | The SAP GRC connector now correctly retrieves the full department value using an alternate delimiter (other than "/") without truncation. |
Connectivity - Microsoft Entra ID | CONETN-5239 | The Microsoft Entra ID connector no longer logs error messages related to failed XML parsing due to unavailable context during account aggregation. |
Connectivity - Microsoft SharePoint Online | CONETN-5120 | The Microsoft SharePoint Online connector no longer loses attributes during account aggregation when users have duplicate records. |
Connectivity - Active Directory | CONETN-5137 | You can now bypass Active Directory schema validation, particularly for non-domain-joined IQService hosts, by configuring |