SaaS
SaaS Release Notes - December 19, 2025
Production release notes - December 19, 2025
Release notes cover new features, enhancements, and fixes that have been released to production.
Identity Security Cloud is SailPoint's next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.
New features
| Product | What's new |
|---|---|
Data Access Security | Data Access Security is now introducing Netapp Activity Monitoring Exclusions. Empower your application configurations by defining exclusions. Exclusions help reduce noise and enables you to focus on important information. Options for excluding events include by extension type, resource, user, or action type. |
Connectivity - SalesForce | Your VA-based Salesforce source can now be migrated to a corresponding SaaS source while ensuring data (users and entitlements) remain intact and maintains your source configurations like access profiles, roles, password settings, and correlation configurations. For more information, refer to Migrate VA-based Source to a SaaS Source. |
Connectivity - Quick Compliance | Identity Security Cloud now supports an additional set of Quick Compliance connectors. Now you can expediently configure read-only connections to an additional set of sources for account and entitlement aggregation. For a full list of supported Quick Compliance sources, refer to Quick Compliance. |
Identity Security Cloud - Web Services SaaS | The SailPoint Web Services SaaS connector now supports the discovery of Agents from systems which use REST, SOAP, or GraphQL-based APIs. You can configure specific endpoints to aggregate agents and associated properties of agents, as specified in the Agent Schema. For more information, refer to HTTP Operations. |
Connectivity - TSS Read Only | SailPoint's new Top Secret (Read-only) connector is used to import and aggregate account and group data exported by the Top Secret TSSCFILE utility. For more information, refer to Integrating SailPoint with Top Secret (Read-only). |
Connectivity - OnGuard | The SailPoint integration with OnGuard enables comprehensive management of cardholders directly through the SailPoint Identity Security Cloud and IdentityIQ platform, enabling organizations to streamline their security processes and enhance control over physical access. This integration has capabilities for cardholder management, including the management of access levels, badges, and badge types. |
SaaS Connectors - Imprivata VPAM SaaS | SailPoint is pleased to announce the availability of the new Imprivata Vendor Privileged Access management (VPAM) SaaS integration. The SailPoint Imprivata VPAM SaaS integration provides governance capabilities for Users and Vendor Representatives within the Imprivata VPAM system. Key features include aggregation, provisioning of Users and Vendor Representatives, and managing entitlements at the account level. For more information, refer to Integrating SailPoint with Imprivata Vendor Privileged Access Management (VPAM) SaaS. |
Connectivity - Imprivata VPAM | SailPoint is pleased to announce the availability of the new Imprivata Vendor Privileged Access management (VPAM) integration. The SailPoint Imprivata VPAM integration provides governance capabilities for Users and Vendor Representatives within the Imprivata VPAM system. Key features include aggregation, provisioning of Users and Vendor Representatives, and managing entitlements at the account level. For more information, refer to Integrating SailPoint with Imprivata Vendor Privileged Access Management (VPAM). |
Identity Security Cloud - SailPoint application onboarding | You can now configure discovery connectors to discover and aggregate the details of enterprise applications in your system. These connectors provide continuous discovery of applications across your enterprise that you can onboard. Previously, application discovery was performed on a discovery source connected to an existing connector configured to govern accounts. Existing discovery sources will continue to work. |
Enhancements
| Product | Feature enhancements |
|---|---|
Identity Security Cloud - Shared Signals Framework, Workflows | The Shared Signals Framework Receiver now supports the CAEP Risk Level Change and CAEP Token Claims Change events. When a security event is received, it is enriched with the identity context by automatically correlating it to an identity. This includes two new Workflows triggers and three new Workflows templates:
|
Data Access Security | The SailPoint Status page now displays the system status of Data Access Security. Follow the Atlassian documentation to manage your subscriptions to system components. |
SailPoint Identity Risk | Identity Graph has the following improvements:
|
Data Access Security | To align the Data Access Security product with Identity Security Cloud's domain standards and deliver a unified user experience, all Data Access Security tenants have been migrated to the identitysoon.com domain — e.g., https://[TENANT].identitysoon.com/das |
Connectivity | The ability to assign source configurations is now supported by all connectors. Administrators can assign any source type to a user to configure, and end users can reassign sources that have been assigned to them. |
Identity Security Cloud - SailPoint application onboarding | Assignees can now reassign source configuration tasks to other users. |
Connectivity - SAP Direct | The SAP Direct connector now supports SAP On-Prem S/4HANA 2025 Initial Shipment Stack. |
Identity Security Cloud - MySailPoint | Home dashboards have been updated to display up to four default tiles at the top of the page, depending on your licensing. End users can hide these tiles or add additional tiles, so they can customize what they see on their Home dashboard. |
SaaS Connectors - Ceridian Dayforce HCM SaaS | The Ceridian Dayforce HCM SaaS connector can now support Additional and Custom Attributes. |
Identity Security Cloud - MySailPoint | We've added 4 new widgets that you can add to your MySailPoint dashboards to track and manage API usage.
|
Connectivity - Slack SaaS Connectors - Slack SaaS | The Slack connector can now include Private channels in aggregation processes. For more information, refer to Required Permissions for VA-based connectors, and Required Permissions for SaaS-based connectors. |
Identity Security Cloud - Audit Events & Reporting, Password Management, Settings | We've modernized the system settings, admin global reports, and password management features to improve user experience and accessibility. Additionally, the System Settings > System Features page has been renamed to Feature Settings, and a new Product Licenses page has been added for additional clarity on your active licenses. |
Identity Security Cloud - Audit Events & Reporting | Audit reports now show more detailed information about account and entitlement schema changes, including attribute additions, removals, and type changes. |
Fixes
| Product | Issue ID | Fixes |
|---|---|---|
SaaS Connectors - Microsoft Entra SaaS | CONHOWRAH-6294 | The Microsoft Entra SaaS connector is now more resilient when handling timeout errors while fetching Exchange mailbox properties. |
Identity Security Cloud - Access Requests | SAASTRIAGE-11619 | Previously, when reviewing access requests on the Approvals page, reviewers could quickly approve or deny items by clicking through cards in sequence—sometimes unintentionally. Now, to make this process more intentional and secure, the Approvals page removes an approval item and allows you to proceed to the next item only after the decision fully registers. |
SaaS Connectors - Microsoft Entra SaaS | CONHOWRAH-6297 | The Microsoft Entra SaaS connector no longer aggregates the |
Connectivity - SAP HR/HCM | CONETN-5271 | The SailPoint SAP HR/HCM connector now fetches only the Position Description associated with each specific Position, instead of retrieving all Position Descriptions. This optimization significantly improves performance and ensures timely preview generation for |
Connectivity - SAP GRC | CONETN-5258 | The SAP GRC connector has been enhanced to correctly set the attribute level status when a role removal request fails. |
Connectivity - UKG Pro | CONETN-5264 | Account creation in the UKG Pro connector no longer fails with a |