SaaS

SaaS Release Notes - December 12, 2025

Production release notes - December 12, 2025

Release notes cover new features, enhancements, and fixes that have been released to production.

Identity Security Cloud is SailPoint's next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.

New features

ProductWhat's new

Connectivity - SAP Analytics Cloud

Your VA-based SAP Analytics Cloud source can now be migrated to a corresponding SaaS source while ensuring data (users and entitlements) remain intact and maintains your source configurations like access profiles, roles, password settings, and correlation configurations. For more information, refer to Migrate VA-based Source to a SaaS Source.

Data Access Security

Customization of email notifications for Data Access Security is now available through Identity Security Cloud Email Templates. Go to Admin > Global > Email Templates to find your corresponding Data Access Security template and use the Edit option to adjust as desired. For customization details, refer to Using Email Templates.

SaaS Connectors - Express Setup - Deep Governance

Identity Security Cloud now supports Express Setup as an option to configure new SaaS-based deep governance connectors. Using Express Setup enables read-only connections to sources for account and entitlement aggregation. This allows for rapid deployment, requiring minimal configuration to quickly begin gathering user data from source systems and achieve compliance objectives faster. To configure the new connector for full deep governance feature support, you can edit the source after creation.

For a list of deep governance connectors which support Express Setup, refer to Deep Governance, and look for connectors with an asterisk next to their name.

SaaS Connectors - Snowflake SaaS

The SailPoint Snowflake SaaS connector can now aggregate Snowflake Cortex Agents. For more information, refer to Configuring Agent Governance.

Identity Security Cloud - Access Modeling

AI Core Attributes unify how identity attributes are managed across all SailPoint AI products, aligning them with Identity Security Cloud and IdentityIQ to deliver a consistent, streamlined, and scalable AI experience. This enhancement replaces the legacy IAI Field Mappings for new customers, simplifies onboarding, and reduces onboarding error rates.

SaaS Connectors - Quick Compliance

Identity Security Cloud now supports Quick Compliance connectors, enabling read-only connections to sources for account and entitlement aggregation. These connectors are designed for rapid deployment, requiring minimal configuration to quickly begin gathering user data from source systems and achieve compliance objectives faster.

For a list of available Quick Compliance connectors, refer to Quick Compliance.

Connectivity - Dynamics 365 - CRM

Your VA-based Microsoft Dynamics 365 Customer Relationship Management source can now be migrated to a corresponding SaaS source while ensuring data (users and entitlements) remain intact and maintains your source configurations like access profiles, roles, password settings, and correlation configurations. For more information, refer to Migrate VA-based Source to a SaaS Source.

Enhancements

ProductFeature enhancements

Access Risk Management

As part of the migration to a new Access Risk Management reporting infrastructure, the Export Risk Analysis button has been moved from the Online Reports page to the Analyses tab on the Activity History page.

Data Access Security

Data Access Security SharePoint Online connector is offering a new setting "Include Backend System Resources". Enabling this new option will crawl resources which are created and generally maintained by Microsoft. These items are marked as 'hidden' from Microsoft but can be accessible through the SharePoint Online UI. Note that enabling this feature will add additional time for the crawl to complete.

Machine Identity Security - Workflows

Six new workflow event triggers are now available that fire whenever key machine identity and account lifecycle changes occur. Included triggers are:

Machine Identity Triggers

Account Event Triggers

Identity Security Cloud - Sources and Account Management

Users can now select previously uploaded files when running entitlement and account aggregations for delimited file and flat file sources.

SaaS Connectors - Microsoft Entra SaaS

The Microsoft Entra SaaS connector now allows filtering of the Azure resource providing granular control over the scope of account and entitlement aggregation through configured list of Subscription IDs and Management Group IDs. For more information, refer to Azure Resource Filtering: Subscriptions and Management Groups.

Identity Security Cloud - Sources and Account Management

Entitlement types and schemas can now be managed in the user interface for all sources that support entitlements. You can view and edit schema attributes and choose to aggregate all entitlements or select the specific entitlement types you want to include.

Identity Security Cloud - Access Intelligence Center (AIC), User Levels

AIC Author and AIC Reader are available as custom user levels, removing the requirement for default Admin user levels. Additionally, the navigation has moved from the Admin tab to the Home tab.

Fixes

ProductIssue IDFixes

Identity Security Cloud - Core Access Model

IDNPALM-7796

Fixed an issue where the error message was unclear when only include-unsegmented=false was passed for GET APIs of roles, access profiles, and entitlements. The error message now states that a value for for-segment-ids is also required.

Data Access Security

DASDEV-23514

The Solutions Center option for Data Access Security can now only be found from the top left icon. The option to select it has been removed from the Login dropdown menu.

Connectivity - SAP Fieldglass

CONUMSHIAN-10025

The SAP Fieldglass SaaS Connector no longer fails with 404 errors during account aggregation or provisioning operations.

Identity Security Cloud - Core Access Model

IDNPALM-7760

Fixed an issue where Role and Access Profile creation failed if the name contained only Korean, Chinese, or Japanese characters. Names containing only these character sets is now fully supported.

Identity Security Cloud - Access Requests

ISCARP-17812

Fixed an issue where failed access requests for dynamic roles were producing duplicate list entries in the request center because dimensions within dynamic roles were displayed as separate requests. Now, dynamic roles are listed as a single request in the request center.

Identity Security Cloud - Certifications, Core Access Model

ISCCOMPLI-7286

Fixed an issue in a certification where the Permissions tab did not display in the entitlement’s details.

Connectivity - SAP GRC

CONETN-5244

The SAP GRC connector now correctly retrieves the full department value using an alternate delimiter (other than "/") without truncation.

Connectivity - Microsoft Entra ID

CONETN-5239

The Microsoft Entra ID connector no longer logs error messages related to failed XML parsing due to unavailable context during account aggregation.

Connectivity - Microsoft SharePoint Online

CONETN-5120

The Microsoft SharePoint Online connector no longer loses attributes during account aggregation when users have duplicate records.

Connectivity - Active Directory

CONETN-5137

You can now bypass Active Directory schema validation, particularly for non-domain-joined IQService hosts, by configuring "skipADSchemaCheck" = "true" in the source configuration.