SaaS

SaaS Release Notes - March 20, 2026

Production release notes - March 20, 2026

Release notes cover new features, enhancements, and fixes that have been released to production.

Identity Security Cloud is SailPoint's next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.

New features

ProductWhat's new

Connectivity - Quick Compliance

Identity Security Cloud now supports the following connectors as Quick Compliance connectors:

You can now expediently configure read-only connections to these sources for account and entitlement aggregation. For a full list of supported Quick Compliance sources, refer to Quick Compliance.

Connectivity - ServiceNow Identity Governance

The SailPoint VA-based ServiceNow source can now be migrated to a corresponding SaaS source while ensuring data (users and entitlements) remains intact and maintains your source configurations like access profiles, roles, password settings, and correlation configurations. For more information, refer to Migrate VA-based Source to a SaaS Source.

Identity Security Cloud - Privilege Classification

SailPoint introduces Privilege Classification, a feature within Identity Security Cloud that enables the classification and assignment of direct privilege levels to entitlements. This feature includes the following:

  • A new classification method to automatically assign a privilege level to an entitlement using multiple methods:
    • Assigning a single privilege level to all entitlements on a source.
    • Assigning the recommended privilege level.
    • Defining custom privilege level criteria.
  • The ability to classify an entitlement’s direct privilege level as high, medium, or low.
  • New actions to manually override and remove an entitlement's direct privilege level.
  • Existing APIs and Search configurations are backwards compatible. They return privilege = true when the direct privilege level is set to high.

The method of assigning direct privilege classification level for entitlements replaces the method to mark an entitlement as privileged or not. However, existing APIs and Search configurations are still supported, so no additional configuration is required for those. For existing privileged entitlements (where privilege = true), the direct privilege level is automatically migrated to high in the updated privilege classification system. Note, this migration is achieved using an override. Following the migration, the override must be removed to support automatic privilege level adjustments.

For more information, refer to the Privilege Classification documentation.

Enhancements

ProductFeature enhancements

Identity Security Cloud - Access Requests

The overlay used in the Request Center now displays the Comments text field before the Access End Date and Time field, making it easier for users to distinguish an item that can be submitted without a required access end date.

SaaS Connectors - Snowflake SaaS

The SailPoint Snowflake SaaS connector now supports database roles as an entitlement type.

Agent Identity Security - Agent Identity Security

Machine Identity Security - Agent Identity Security

The businessApplication attribute in Machine Identity Security and Agent Identity Security has been updated with the following changes:

  • The attribute can now only be updated for machine identities with source values of IdentityNow or null.
  • When the attribute is updated, the changes are now propagated to the nativeIdentity attribute.

Connectivity - SAP GRC

The SailPoint SAP GRC Connector can now ignore SocketTimeoutException and UnknownHostException during polling to prevent premature failure of IdentityRequests.

Connectivity - DPR

With the Desktop Password Reset for Windows 21.1.0 enhancement, you can now update the Bouncy Castle cryptography library without reinstalling the application.

The DPR Configurator allows administrators to download and apply the latest or a specific release of the Bouncy Castle library. It also performs preliminary checks to ensure these updates do not introduce breaking changes.

Additionally, this release supports newer versions of the .NET Desktop Runtime and addresses some known issues. For more information, refer to Desktop Password Reset Release Notes.

Fixes

ProductIssue IDFixes

Access Risk Management

ARM-36779

Fixed an issue with the Disable Block List checkbox on the Schedule Jobs > Risk Analysis page. The checkbox now disables block lists for a single ad-hoc Risk Analysis job so you can analyze all users, roles and profiles, including those that are blocked.

Access Risk Management

ARM-37239

When mitigating controls are identified as available during an Access Risk Management User What If simulation, they will now correctly account for the applicable systems in all cases.

Identity Security Cloud - Identity Graph

DZ-2295

Fixed an issue where incorrect account information displayed for roles that contained entitlements from multiple sources. Only account information related to the specific access object now displays.

Access Risk Management

ARM-35708

Access Risk Management customers using the new Mitigating Controls feature will now see the correct value for IsMitigated in the User Risk History report when the mitigation has been revoked for a user-risk that was previously mitigated.

Identity Security Cloud - Sources and Account Management

PLTCONN-9813

Fixed the sources list timeout by batching workgroup lookups via list API. GET /v3/sources no longer times out for tenants with a large number of sources when workgroup names were loaded with one WGMS call per workgroup.