SaaS

SaaS Release Notes - April 3, 2026

Production release notes - April 3, 2026

Release notes cover new features, enhancements, and fixes that have been released to production.

Identity Security Cloud is SailPoint's next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.

New features

ProductWhat's new

Connectivity - LDAP

The SailPoint Lightweight Directory Access Protocol (LDAP) connectors now support account move and rename operations. This capability is supported by the following LDAP connectors:

Connectivity - Quick Compliance

Identity Security Cloud now supports the following connectors as Quick Compliance connectors:

You can now expediently configure read-only connections to these sources for account and entitlement aggregation. For a full list of supported Quick Compliance sources, refer to Quick Compliance.

Machine Identity Security

Users can now submit requests for the deletion of human, machine, and uncorrelated accounts in Identity Security Cloud. Administrators can configure specific approval settings for account deletions for each source. This feature replaces many custom BeforeProvisioning rules used to remove accounts. For more information on this feature, refer to the product announcement.

Identity Security Cloud - Harbor Pilot

Harbor Pilot can now be enabled for both admins and end users. End users can use natural language queries to search documentation and submit access requests. Refer to Enabling Harbor Pilot for Admins and End Users for more information.

Identity Security Cloud - Harbor Pilot

You can now use natural language queries in Harbor Pilot to find and request access items, as well as cancel requests for pending approvals. Admins must enable this feature for end users. Refer to Creating and Managing Access Requests for more information.

SaaS Connectors - Salesforce SaaS

The SailPoint Salesforce SaaS connector now supports fetching Profiles associated with Agentforce Copilot internal Agents.

Identity Security Cloud - Identity Graph

Users can now compare two human identities and their access in the Identity Graph. Organizations that have licensed Machine Identity Security and Agent Identity Security can select machine identities, such as AI agents, for these comparisons.

Connectivity - Delimited File

SaaS Connectors - Delimited File

The SailPoint Delimited File connector now has an option for VA-based connectivity. This new connectivity approach supports different file transport mechanisms for reading files from SFTP, FTPS, SCP servers, and Amazon Web Services S3 locations. This also supports encryption, filtering, parsing, and data merging capabilities. For more information, refer to Integrating SailPoint with Delimited File Source.

The Delimited File SaaS connector is also enhanced to support various configurations of accounts and groups. For more information, refer to Integrating SailPoint with Delimited File Source SaaS.

Identity Security Cloud - Identity Graph

You can now submit requests for the revocation of individual access items from within the Identity Graph.

Connectivity - Quick Compliance

Identity Security Cloud now supports the following connectors as Quick Compliance connectors:

You can now expediently configure read-only connections to these sources for account and entitlement aggregation. For a full list of supported Quick Compliance sources, refer to Quick Compliance.

Enhancements

ProductFeature enhancements

Identity Security Cloud - Shared Signals Framework

Shared Signals Framework Receivers now support configuration using OAuth 2.0 authentication with a JWT Client Credentials grant type. This provides additional flexibility to connect with systems that support JWT client credentials grant type.

For more information, refer to Configuring a Connection.

Identity Security Cloud - Shared Signals Framework

You can now customize the format of the Subject ID that Shared Signals Framework receivers expect to see in events from transmitters.

Identity Security Cloud - Identity Graph

The Identity Graph now displays alerts for partially offboarded human identities, which include identities in inactive lifecycle states that still have active accounts.

Connectivity - Atlassian Data Center, Atlassian Suite-Cloud , Oracle Database, RACF (Read Only), TSS Read Only

Identity Security Cloud now governs direct account permissions for the following systems:

  • Atlassian Suite (Cloud)
  • RACF (read-only)
  • Top Secret (read-only)
  • Oracle DB
  • Atlassian - Data Center

Identity Security Cloud - Provisioning and Task Manager

Starting 12:00 AM CT on May 6, 2026, rule execution will be hardened for new customers. To ensure accidental writes do not occur, new rules will now be executed with a read-only data context. Existing rules will be excluded.

Throughout May, this change will gradually be enabled for existing tenants for rules that do not modify objects. SailPoint Support will contact the owners of rules that are identified as performing modifications to discuss transitioning them to read-only behavior.

Connectivity - Microsoft Entra ID

The Microsoft Entra ID connector now supports aggregating and provisioning External Member accounts. For more information, refer to External Member.

Agent Identity Security

New aggregation, deletion, and schema controls are now available for machine identities.

Admins can further manage machine identities by:

  • Using machine identity aggregations, the successor to AI agent aggregations, to govern an increasing number of machine identities available for collection.
  • Setting automated deletion thresholds and managing the removal of machine identities for specific schemas.
  • Reviewing and editing the schemas associated with machine identities at the source.

For more information, refer to the product announcement.

SaaS Connectors - Microsoft Entra SaaS

The Microsoft Entra SaaS connector now supports aggregating and provisioning External Member accounts. For more information, refer to External Member.

Connectivity - UKG Pro, UKG Pro Core HCM SaaS

SaaS Connectors - UKG Pro, UKG Pro Core HCM SaaS

The SailPoint UKG Pro connector has been enhanced to include a partner-id HTTP header in every API request, improving traceability, governance, and partner identification.

Identity Security Cloud - Workflows

The Manage Accounts action in workflows now supports deletion of accounts from connected sources that support the delete operation.

If the account belongs to a flat file source, the account will be deleted from Identity Security Cloud.

If the account belongs to a non-flat file source, the account will be requested for deletion via an approval process. If the request is approved, the account will be deleted from the source and also from Identity Security Cloud.

For more information, refer to Manage Accounts.

SaaS Connectors - Microsoft Entra SaaS

The Microsoft Entra SaaS connector now supports aggregation and provisioning of the sponsors attribute. For more information, refer to Configuring Sponsors for B2B users.

Fixes

ProductIssue IDFixes

SaaS Connectors - Microsoft Entra SaaS

CONHOWRAH-6757

The delta aggregation in Microsoft Entra SaaS connector now correctly handles group membership changes followed by user deletions without encountering 404 errors.

SaaS Connectors - Ceridian Dayforce HCM SaaS

CONNAMDANG-6681

The Ceridian DayForce SaaS connector now preserves the configured values for the Enabled Employee Status field during aggregation.

SaaS Connectors - Microsoft Entra SaaS

CONHOWRAH-6738

For the Microsoft Entra SaaS connector, customSecurityAttributes attribute will now be created exactly as provided.

Connectivity - SCIM 2.0

CONETN-5329

The SailPoint SCIM 2.0 connector now correctly handles complex, multi-valued attributes during an update operation for relaxed configurations, ensuring the payload is formed as expected.

Connectivity - Amazon Web Services (AWS) IAM Identity Center

CONETN-5345

The SailPoint Amazon Web Services (AWS) IAM Identity Center connector now correctly processes bulk provisioning operations for Permission sets.

Connectivity - Snowflake

CONETN-5313

The SailPoint Snowflake connector now throws an ObjectNotFoundException if a role does not exist on the target system during a getObject Operation for a Role.

Connectivity - IBM Tivoli DS

CONETN-5328

The SailPoint IBM Tivoli Direct connector now adheres to the disableDefaultGroupClassFilter: true setting in source configuration, skipping default group search filter creation during membership aggregation.

SaaS Connectors - Microsoft Entra SaaS

CONHOWRAH-6427

The Microsoft Entra SaaS connector now successfully saves the delta token for group memberships.