SaaS

SaaS Release Notes - October 14, 2024

Production release notes - October 14, 2024

Release notes might contain references to new features, enhancements, and fixes that will be gradually turned on in production over the next several weeks. See the SaaS Functional End of Life and Major Changes Policy.

Identity Security Cloud is SailPoint's next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.

New features

ProductWhat's new

Identity Security Cloud - Segmentation

A new Data Segmentation feature enables Org Admins to create security policies that will affect non-org administrator record-level access to view and administrate entitlements. You’ll know this is available in your tenant when you see the Data Segmentation option under Admin > Global. Refer to Data Segmentation for details about using this feature.

Identity Security Cloud - Forms, Platform, Workflows

SailPoint now supports Privileged Task Automation. Privileged Task Automation helps organizations enhance IT operations’ efficiency, security and governance by automating and delegating the execution of repeatable privileged tasks using Identity Security Cloud's Workflows and Forms engines. This feature includes:

  • Privilege Gateway - A new type of virtual appliance that enables Privileged Tasks to interact with on premises and SaaS targets.
  • Active Directory Action - A new Workflow action that enables workflow admins to define commands that can be executed against Active Directory targets accessible by the Privilege Gateway.
  • Windows Server Action - A new Workflow action that enables workflow admins to define commands that can be executed against Windows Server targets accessible by the Privilege Gateway.
  • Launchpad - A new user interface located under MySailPoint where users can launch entitled orchestrations, view in-progress orchestrations, and view completed orchestrations.
  • Launchers - Launchers are a workflow or automation process that has been delegated. Launchers are linked to entitlements and can be governed through existing access request and certification tools.
  • Launchers page - A new user interface for org_admins to create and manage launchers, including creating and editing launchers.
  • Interactive Trigger - A new workflow trigger tied to Launchers. This trigger initiates a workflow execution when an entitled user launches the task from the LaunchPad.
  • Interactive Form Action - A new action that presents an interactive form to collect user input as part of the interactive process.
  • Interactive Message Action - a new action that enables workflow admins to pass categorized Info, Warning, and Error messages into the interactive process to display to the user.
  • Create a Security Group in Active Directory - This interactive workflow creates a new Active Directory security group. You will be asked to provide some group details using an interactive form.
  • Update an Inbound Firewall Rule State on a Windows Server - This interactive workflow allows you to enable or disable an inbound firewall rule on a Windows server. You will be asked to choose whether to enable or disable a rule, then select the rule to update.
  • Update the State of a Windows Service - This privileged interactive workflow allows you to stop, start, or restart a Windows service. You will be asked to choose the service and operation using an interactive form.

For more information, refer to the Privileged Task Automation documentation.

Identity Security Cloud - Forms, Platform, Workflows

Workflows now supports Delegated Interactive Workflows. This feature allows admins to delegate specific orchestration flows to users within their organization using existing Governance processes. The orchestration is an interactive process that guides non-technical users through a dedicated orchestration flow, passing forms and messages to the user as designed in the interactive workflow. This feature includes:

  • Launchpad - A new user interface located under MySailPoint where users can launch entitled orchestrations, view in-progress orchestrations, and view completed orchestrations.
  • Launchers - Launchers are, at their core, a workflow or automation process that has been delegated. Launchers are linked to entitlements and can be governed through existing access request and certification tools.
  • Launchers page - A new user interface for org_admins to create and manage launchers, including creating and editing launchers.
  • Interactive Trigger - A new workflow trigger tied to Launchers. This trigger initiates a workflow execution when an entitled user launches the task from the LaunchPad.
  • Interactive Form Action - A new action that presents an interactive form to collect user input as part of the interactive process.
  • Interactive Message Action - a new action that enables workflow admins to pass categorized Info, Warning, and Error messages into the interactive process to display to the user.

For more information, refer to the Interactive Process documentation.

Identity Security Cloud - Workflows

SaaS Workflows now supports error handling and branching in executions, allowing admins to select a workflow path if an action returns an error. Instead of exiting automatically, workflows can now follow a new path or exit as before. You can enable or disable error handling on an existing branch. When error handling is enabled, you can use a new branch within the workflow to:

  • Send notifications
  • Initiate another workflow
  • Use any Operator
  • Use any Action

For more information, refer to the Managing Error Handling documentation.

SaaS Connectors - Dynamics 365 - BC

SailPoint is pleased to announce the availability of the new Microsoft Dynamics 365 Business Central Online SaaS connector. The SailPoint Microsoft Dynamics 365 Business Central Online SaaS connector securely connects with the Dynamics 365 Business Central Online system and provides governance capabilities for the users. For more information, refer to Integrating SailPoint with Microsoft Dynamics 365 Business Central Online SaaS

Enhancements

ProductFeature enhancements

Identity Security Cloud - Virtual Appliance

The Cluster Type field on the Edit Virtual Appliance Cluster page is now disabled after the cluster has been created.

SaaS Connectors - MongoDB Atlas

You can now configure the SailPoint MongoDB Cloud - Atlas SaaS connector for both identity governance and Activity Insights. For more information, refer to Activity Insights.

SaaS Connectors - Aha

You can now configure the SailPoint Aha SaaS connector for both Identity Governance and Activity Insights. For more information, refer to Activity Insights Settings.

Identity Security Cloud - Identities

The IdentityAttributesChangedEvent trigger will now process incoming changes for identities in the Inactive (long-term) state if the event contains the transition to this identity state.

Identity Security Cloud - Access Requests

The Identity details within the Approval overlay now contain the user's email address to facilitate communications between the approver and the requested-for user.

Identity Security Cloud - Identities

Identities in the Inactive (long-term) identity state are now excluded from the attribute sync process. If an identity in this state requires synchronization, an administrator can synchronize its attributes by:

For more information, refer to the product documentation or Developer Community.

Fixes

ProductIssue IDFixes

Identity Security Cloud - Password Management

UIGOV-482

The message displayed when changing the password for a password sync group has been updated to say "It's time to set your new password."

SaaS Connectors - SAP Ariba

CONDOCS-4802

To align with updates in the SAP Ariba GA APIs, the SailPoint SAP Ariba SaaS integration now links the user enable/disable feature directly with Ariba's user lock/unlock functionality. This change replaces the previous approach of activating/deactivating existing user accounts, and aggregation of deactivated users ensuring alignment with the SAP Ariba API.

Identity Security Cloud - Core Access Model

UIAO-9056

Fixed an issue where it took two clicks to delete an access profile in cards view instead of one.

Identity Security Cloud - Snowflake SaaS

CONNAMDANG-5091

During entitlement aggregation in Snowflake SaaS connector, roles and privileges will only be aggregated if the corresponding attributes are defined in the group schema.

Identity Security Cloud - Configuration Hub

PLTCONFHUB-2464

Configuration Hub has updated the submit and denial messages when submitting an approval in order to clarify the result of these actions.

Connectivity - REST WebServices Connector

CONETN-4892

The Web Services connector can now parse Byte-Order-Mark (BOM) characters while utilizing XML parsing.

Identity Security Cloud - Virtual Appliance

SAASVA-268

Changes have been made to the Flatcar OS update process to increase efficiency.

Identity Security Cloud - Ceridian Dayforce HCM

CONNAMDANG-5128

The Ceridian Dayforce HCM SaaS connector can configure custom string values for EmploymentStatusXRefCode in the aggregation API for Active, Inactive, Prestart and Terminated users. To enable custom values, the following attributes should be set in the Source Configuration:

  • customActiveStatus- For Active users.
  • customInActiveStatus- For InActive users.
  • customPrestartStatus- For Prestart users.
  • customTerminatedStatus- For Terminated users.

Connectivity - SAP Direct

CONETN-4900

SAP Direct no longer fails with the OPTION_NOT_VALID error when the role name has a trailing white space.

Identity Security Cloud - Configuration Hub

PLTCONFHUB-2410

In Configuration Hub, warnings have been added to the draft and import results screens when the system cannot select a reference from a pool of multiple candidates.

SaaS Connectors - Web Services SaaS

CONSEALINK-5785

The Web Services SaaS connector has been enhanced to automatically eliminate an attribute’s placeholder from the payload if it is not included in the provisioning request.

Connectivity - Oracle HCM Cloud

CONETN-4874

Oracle HCM Cloud now displays the file name along with its path when exceptions occur during full aggregation.

Connectivity - REST WebServices Connector

CONETN-4872

The REST WebServices connector now supports the getBaseURL() method for requestEndpoint in Before and After rules.

Connectivity - Workday

CONETN-4833

The Workday connector displays a relevant error message when a provisioning operation is attempted with an unsupported operation or value.