SaaS
SaaS Release Notes - April 3, 2026
Production release notes - April 3, 2026
Release notes cover new features, enhancements, and fixes that have been released to production.
Identity Security Cloud is SailPoint's next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.
New features
| Product | What's new |
|---|---|
Connectivity - LDAP | The SailPoint Lightweight Directory Access Protocol (LDAP) connectors now support account move and rename operations. This capability is supported by the following LDAP connectors: |
Connectivity - Quick Compliance | Identity Security Cloud now supports the following connectors as Quick Compliance connectors: You can now expediently configure read-only connections to these sources for account and entitlement aggregation. For a full list of supported Quick Compliance sources, refer to Quick Compliance. |
Machine Identity Security | Users can now submit requests for the deletion of human, machine, and uncorrelated accounts in Identity Security Cloud. Administrators can configure specific approval settings for account deletions for each source. This feature replaces many custom BeforeProvisioning rules used to remove accounts. For more information on this feature, refer to the product announcement. |
Identity Security Cloud - Harbor Pilot | Harbor Pilot can now be enabled for both admins and end users. End users can use natural language queries to search documentation and submit access requests. Refer to Enabling Harbor Pilot for Admins and End Users for more information. |
Identity Security Cloud - Harbor Pilot | You can now use natural language queries in Harbor Pilot to find and request access items, as well as cancel requests for pending approvals. Admins must enable this feature for end users. Refer to Creating and Managing Access Requests for more information. |
SaaS Connectors - Salesforce SaaS | The SailPoint Salesforce SaaS connector now supports fetching Profiles associated with Agentforce Copilot internal Agents. |
Identity Security Cloud - Identity Graph | Users can now compare two human identities and their access in the Identity Graph. Organizations that have licensed Machine Identity Security and Agent Identity Security can select machine identities, such as AI agents, for these comparisons. |
Connectivity - Delimited File SaaS Connectors - Delimited File | The SailPoint Delimited File connector now has an option for VA-based connectivity. This new connectivity approach supports different file transport mechanisms for reading files from SFTP, FTPS, SCP servers, and Amazon Web Services S3 locations. This also supports encryption, filtering, parsing, and data merging capabilities. For more information, refer to Integrating SailPoint with Delimited File Source. The Delimited File SaaS connector is also enhanced to support various configurations of accounts and groups. For more information, refer to Integrating SailPoint with Delimited File Source SaaS. |
Identity Security Cloud - Identity Graph | You can now submit requests for the revocation of individual access items from within the Identity Graph. |
Connectivity - Quick Compliance | Identity Security Cloud now supports the following connectors as Quick Compliance connectors: You can now expediently configure read-only connections to these sources for account and entitlement aggregation. For a full list of supported Quick Compliance sources, refer to Quick Compliance. |
Enhancements
| Product | Feature enhancements |
|---|---|
Identity Security Cloud - Shared Signals Framework | Shared Signals Framework Receivers now support configuration using OAuth 2.0 authentication with a JWT Client Credentials grant type. This provides additional flexibility to connect with systems that support JWT client credentials grant type. For more information, refer to Configuring a Connection. |
Identity Security Cloud - Shared Signals Framework | You can now customize the format of the Subject ID that Shared Signals Framework receivers expect to see in events from transmitters. |
Identity Security Cloud - Identity Graph | The Identity Graph now displays alerts for partially offboarded human identities, which include identities in inactive lifecycle states that still have active accounts. |
Connectivity - Atlassian Data Center, Atlassian Suite-Cloud , Oracle Database, RACF (Read Only), TSS Read Only | Identity Security Cloud now governs direct account permissions for the following systems:
|
Identity Security Cloud - Provisioning and Task Manager | Starting 12:00 AM CT on May 6, 2026, rule execution will be hardened for new customers. To ensure accidental writes do not occur, new rules will now be executed with a read-only data context. Existing rules will be excluded. |
Connectivity - Microsoft Entra ID | The Microsoft Entra ID connector now supports aggregating and provisioning External Member accounts. For more information, refer to External Member. |
Agent Identity Security | New aggregation, deletion, and schema controls are now available for machine identities. Admins can further manage machine identities by:
For more information, refer to the product announcement. |
SaaS Connectors - Microsoft Entra SaaS | The Microsoft Entra SaaS connector now supports aggregating and provisioning External Member accounts. For more information, refer to External Member. |
Connectivity - UKG Pro, UKG Pro Core HCM SaaS SaaS Connectors - UKG Pro, UKG Pro Core HCM SaaS | The SailPoint UKG Pro connector has been enhanced to include a |
Identity Security Cloud - Workflows | The Manage Accounts action in workflows now supports deletion of accounts from connected sources that support the delete operation. If the account belongs to a flat file source, the account will be deleted from Identity Security Cloud. If the account belongs to a non-flat file source, the account will be requested for deletion via an approval process. If the request is approved, the account will be deleted from the source and also from Identity Security Cloud. For more information, refer to Manage Accounts. |
SaaS Connectors - Microsoft Entra SaaS | The Microsoft Entra SaaS connector now supports aggregation and provisioning of the |
Fixes
| Product | Issue ID | Fixes |
|---|---|---|
SaaS Connectors - Microsoft Entra SaaS | CONHOWRAH-6757 | The delta aggregation in Microsoft Entra SaaS connector now correctly handles group membership changes followed by user deletions without encountering 404 errors. |
SaaS Connectors - Ceridian Dayforce HCM SaaS | CONNAMDANG-6681 | The Ceridian DayForce SaaS connector now preserves the configured values for the Enabled Employee Status field during aggregation. |
SaaS Connectors - Microsoft Entra SaaS | CONHOWRAH-6738 | For the Microsoft Entra SaaS connector, |
Connectivity - SCIM 2.0 | CONETN-5329 | The SailPoint SCIM 2.0 connector now correctly handles complex, multi-valued attributes during an update operation for relaxed configurations, ensuring the payload is formed as expected. |
Connectivity - Amazon Web Services (AWS) IAM Identity Center | CONETN-5345 | The SailPoint Amazon Web Services (AWS) IAM Identity Center connector now correctly processes bulk provisioning operations for Permission sets. |
Connectivity - Snowflake | CONETN-5313 | The SailPoint Snowflake connector now throws an |
Connectivity - IBM Tivoli DS | CONETN-5328 | The SailPoint IBM Tivoli Direct connector now adheres to the |
SaaS Connectors - Microsoft Entra SaaS | CONHOWRAH-6427 | The Microsoft Entra SaaS connector now successfully saves the delta token for group memberships. |