Virtual Appliance

Virtual Appliance Release Notes - September 4, 2025

Virtual Appliance (VA) release notes might contain references to SailPoint software and Flatcar operating system updates that SailPoint will automatically apply.

SailPoint Software

2025.09.04 - Version 2.12, CCG 1120, charon 3082

New features

ProductWhat's new

Connectivity - SalesForce

The Salesforce VA-based connector now supports the next-generation Salesforce infrastructure architecture, Hyperforce.

Connectivity - EPIC

The Epic EMP connector now supports proxy authentication.

Connectivity - BeyondTrust Password Safe OnPremise

SailPoint Identity Security Cloud now supports the BeyondTrust Password Safe On-Premise (Secrets Management) credential provider, which provides credential cycling functionality to fetch credentials from BeyondTrust Password Safe (On-Premise).

Enhancements

ProductFeature enhancements

Connectivity - Guidewire

The SailPoint Guidewire connector now supports the following Guidewire application releases:

  • The Niseko release is identified by the 2025.07 release number, with application version 50.14.x
  • The Mammoth release is identified by the 2025.03 release number, with application version 50.13.x
  • The Las Leñas release is identified by the 2024.11 release number, with application version 50.12.x

Connectivity - Virtual Appliance

When the customer-provided operating system (CPOS) flag is enabled on your tenant, admins can now designate virtual appliances (VA) as CPOS when adding new VAs to a cluster.

Fixes

ProductIssue IDFixes

Connectivity - Workday

CONETN-5116

The SailPoint Workday Connector will no longer add a blank line to Custom ID when updating workers without existing Custom IDs in the Workday Managed System.

Connectivity - SAP GRC

CONETN-5110

The SAP GRC connector now correctly displays provisioning results for roles with colons(:) in their names.

Connectivity - Snowflake

CONETN-5141

In the Snowflake connector, Entitlement Aggregation now fetches privileges for roles only if the Role and Privilege attributes are included in the Role schema.

Connectivity - Snowflake

CONETN-5126

The Snowflake Connector can now configure the default_secondary_roles attribute to an empty value if you pass the value as () during provisioning. This update follows a recent update to the way Snowflake handles the default_secondary_roles attribute. For more information, refer to Troubleshooting.

Connectivity - Microsoft Entra ID

CONETN-5103

The Microsoft Entra ID connector now ensures that the group filter is processed during delta aggregation.

VA Platform

SAASVA-698

Security fixes and system fixes.