Virtual Appliance

Virtual Appliance Release Notes - January 06, 2025

SailPoint Software

2025.01.06 - Version 1.1, CCG 1033

New features

ProductWhat's new

Connectivity - Workday Accounts

The Workday Accounts connector now supports managing Student Accounts. For more information, refer to Additional Settings.

Enhancements

ProductWhat's new

Connectivity - Microsoft Entra ID

The Microsoft Entra ID connector now supports managing Administrative Units as entitlements. For more information, refer to Administrative Units.

Connectivity - Zendesk SDIM

The Zendesk for Service Desk Integration now supports the “Bearer“ authentication type.

Connectivity - Zendesk

The Zendesk connector now supports the “Bearer“ authentication type.

Connectivity - IBMi

The jt400.jar JAR file has been upgraded to a newer version 20.0.7 as part of the regular development cycle. Ensure to check the impact on custom connectors, rules, or any other customization, that directly or indirectly uses this JAR file.

Connectivity - EPIC

The Epic EMP & SER connectors can now refresh passwords managed within a credential provider.

Connectivity - UKG Pro

The UKG Pro connector no longer experiences aggregation issues which result from duplicate entries.

Connectivity - SAP Direct

The SAP Direct connector has been improved to provide more granular governance over user authorization by extending visibility into both direct and indirect PD Profiles linked to each user. For more information, refer to Enabling PD Profiles.

Connectivity - PeopleSoft Direct

SailPoint's Oracle PeopleSoft ERP connector now supports PeopleSoft ERP version 8.61. This integration has been tested with the latest application version to ensure seamless compatibility. Support for TLS certificates is now included to align with the mandatory security requirements introduced in PeopleSoft ERP v8.61.

Connectivity - CyberArk-CorePas

The CyberArk (Self-Hosted) Connector now supports Version 14.0.1 of the CyberArk Privilege Access Manager - Self-Hosted architecture when connecting via the SCIM Server hosted on the Cloud.

Connectivity - SCIM 2.0

The SCIM 2.0 connector can now send the attribute path when provisioning complex core attributes using the PATCH method.

ACF2, RACF Connector, TSS

The RACF-Full, ACF2-Full, and TopSecret-Full connectors can now read the prependBeforeVal or the appendAfterVal attributes from the Attributes map in AttributeRequest in the provisioning plan. The connectors can prefix or append it to the value of an attribute before passing it to the SailPoint connector for ACF2, RACF, or Top Secret. This allows the pre/post scripts to access the meta data of the provisioning request for each attribute.

Connectivity - SuccessFactor

The SuccessFactors connector can now aggregate labels linked to codes for additional attributes. The codes used to aggregate the labels must be associated with picklists or foundation objects from the source which relate to the additional attributes. For more information, refer to Advanced Settings.

Fixes

ProductIssue IDFixes

Connectivity - Jack Henry

CONJUBILEE-3058

The Jack Henry Symitar connector now supports custom SOAPAction headers in request execution. For more information, refer to the Troubleshooting page in the Jack Henry connector documentation.

Connectivity - Google Apps

CONETN-4952

The entitlement aggregation of the iamResourcePermission object type to the Google Workspace connector no longer fails due to projects/service accounts in a pending deletion state.

Connectivity - LDAP

CONETN-4901

The LDAP Connector now supports search filter with negation appropriately.

Connectivity - Tivoli Access Manager

CONETN-4958

The Tivoli Access Manager now uses the Source Name to differentiate multiple IBM SVA sources on the same virtual appliance if the cloudExternalId value is set to ccDecommissionId.

Connectivity - Microsoft SharePoint Online

CONETN-4962

The Microsoft Sharepoint Online connector no longer fails during aggregation using authentication of type JWT Certificate Credentials.

Connectivity - REST WebServices Connector

CONETN-4961

The Web Services connector now supports generating a new refresh token in cases where the oauth_token_info parameter stored in the application config is corrupted. This functionality also extends to forced Test Connection operations that are initiated from the connector configuration interface.

Connectivity - Microsoft Entra ID

CONETN-4950

The Microsoft Entra ID connector now supports configuring the number of retries for a PIM cache request using the maxRetryCount attribute.

Connectivity - Active Directory

CONETN-4940

The Active Directory connector now allows bulk user creation using gMSA service account.

Connectivity - SAP GRC

CONETN-4979

For the SAP GRC connector, the warning log statement has been changed to a debug level.

Connectivity - Microsoft SharePoint Online

CONETN-4974

The Microsoft SharePoint Online connector now retrieves the AdminOfSites during account aggregation.

Connectivity - Google Apps

CONHOWRAH-5379

The Google Workspace SaaS connector no longer fails with a Null Pointer Exception during group delta aggregation.

Connectivity - SAP Direct

CONETN-4899

The SAP Direct connector now fails when connecting to an application with a service account that has a username longer than 12 characters.

Connectivity - Dynamics 365 - F&O

CONETN-4923

The Microsoft Dynamics 365 for Finance and Operations connector no longer fails during test connections with the error message, “Unable to parse additional config attributes to an Integer value”.

Connectivity - ACF2, RACF Connector, TSS

CONCHORDS-2288

SailPoint no longer supports DES and 3DES encryption on Mainframe connectors, so existing integrations using DES or 3DES will no longer function. Instead, SailPoint recommends using TLS encryption to secure communication between Mainframe integration components.

Connectivity - MS SQL Server

CONETN-4981

The Microsoft SQL Server no longer fails during the aggregation of server roles.