SaaS

SaaS Release Notes - December 19, 2025

Production release notes - December 19, 2025

Release notes cover new features, enhancements, and fixes that have been released to production.

Identity Security Cloud is SailPoint's next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.

New features

ProductWhat's new

Data Access Security

Data Access Security is now introducing Netapp Activity Monitoring Exclusions. Empower your application configurations by defining exclusions. Exclusions help reduce noise and enables you to focus on important information.

Options for excluding events include by extension type, resource, user, or action type.

Connectivity - SalesForce

Your VA-based Salesforce source can now be migrated to a corresponding SaaS source while ensuring data (users and entitlements) remain intact and maintains your source configurations like access profiles, roles, password settings, and correlation configurations. For more information, refer to Migrate VA-based Source to a SaaS Source.

Connectivity - Quick Compliance

Identity Security Cloud now supports an additional set of Quick Compliance connectors. Now you can expediently configure read-only connections to an additional set of sources for account and entitlement aggregation. For a full list of supported Quick Compliance sources, refer to Quick Compliance.

Identity Security Cloud - Web Services SaaS

The SailPoint Web Services SaaS connector now supports the discovery of Agents from systems which use REST, SOAP, or GraphQL-based APIs. You can configure specific endpoints to aggregate agents and associated properties of agents, as specified in the Agent Schema. For more information, refer to HTTP Operations.

Connectivity - TSS Read Only

SailPoint's new Top Secret (Read-only) connector is used to import and aggregate account and group data exported by the Top Secret TSSCFILE utility. For more information, refer to Integrating SailPoint with Top Secret (Read-only).

Connectivity - OnGuard

The SailPoint integration with OnGuard enables comprehensive management of cardholders directly through the SailPoint Identity Security Cloud and IdentityIQ platform, enabling organizations to streamline their security processes and enhance control over physical access. This integration has capabilities for cardholder management, including the management of access levels, badges, and badge types.

SaaS Connectors - Imprivata VPAM SaaS

SailPoint is pleased to announce the availability of the new Imprivata Vendor Privileged Access management (VPAM) SaaS integration.

The SailPoint Imprivata VPAM SaaS integration provides governance capabilities for Users and Vendor Representatives within the Imprivata VPAM system. Key features include aggregation, provisioning of Users and Vendor Representatives, and managing entitlements at the account level. For more information, refer to Integrating SailPoint with Imprivata Vendor Privileged Access Management (VPAM) SaaS.

Connectivity - Imprivata VPAM

SailPoint is pleased to announce the availability of the new Imprivata Vendor Privileged Access management (VPAM) integration.

The SailPoint Imprivata VPAM integration provides governance capabilities for Users and Vendor Representatives within the Imprivata VPAM system. Key features include aggregation, provisioning of Users and Vendor Representatives, and managing entitlements at the account level. For more information, refer to Integrating SailPoint with Imprivata Vendor Privileged Access Management (VPAM).

Identity Security Cloud - SailPoint application onboarding

You can now configure discovery connectors to discover and aggregate the details of enterprise applications in your system. These connectors provide continuous discovery of applications across your enterprise that you can onboard.

Previously, application discovery was performed on a discovery source connected to an existing connector configured to govern accounts. Existing discovery sources will continue to work.

Enhancements

ProductFeature enhancements

Identity Security Cloud - Shared Signals Framework, Workflows

The Shared Signals Framework Receiver now supports the CAEP Risk Level Change and CAEP Token Claims Change events. When a security event is received, it is enriched with the identity context by automatically correlating it to an identity. This includes two new Workflows triggers and three new Workflows templates:

Data Access Security

The SailPoint Status page now displays the system status of Data Access Security. Follow the Atlassian documentation to manage your subscriptions to system components.

SailPoint Identity Risk

Identity Graph has the following improvements:

  • Entitlement sources are now included in node tooltips.
  • New filter criteria is available for certain attributes and identity types.
  • Includes new deep links to the graph across Identity Security Cloud.
  • Introduces JSON export for graph objects.
  • Includes a new feature to expand all children and parents in the graph.
  • The explorer pane now has a limit of 100 entries.

Data Access Security

To align the Data Access Security product with Identity Security Cloud's domain standards and deliver a unified user experience, all Data Access Security tenants have been migrated to the identitysoon.com domain — e.g., https://[TENANT].identitysoon.com/das

Connectivity

The ability to assign source configurations is now supported by all connectors. Administrators can assign any source type to a user to configure, and end users can reassign sources that have been assigned to them.

Identity Security Cloud - SailPoint application onboarding

Assignees can now reassign source configuration tasks to other users.

Connectivity - SAP Direct

The SAP Direct connector now supports SAP On-Prem S/4HANA 2025 Initial Shipment Stack.

Identity Security Cloud - MySailPoint

Home dashboards have been updated to display up to four default tiles at the top of the page, depending on your licensing. End users can hide these tiles or add additional tiles, so they can customize what they see on their Home dashboard.

SaaS Connectors - Ceridian Dayforce HCM SaaS

The Ceridian Dayforce HCM SaaS connector can now support Additional and Custom Attributes.

Identity Security Cloud - MySailPoint

We've added 4 new widgets that you can add to your MySailPoint dashboards to track and manage API usage.

  • Total API Calls - Displays the total number of API calls that have been made during the current month.
  • Top Requested URIs - Displays the most-requested URIs and the methods used to call them, along with the number of times those URIs have been called in the current month.
  • Top Requested GET URIs - Displays the most-requested URIs that were accessed with the GET method, along with the number of times they were called in the current month.
  • Top Requested UPDATE URIs - Displays the most-requested URIs that were accessed with any method other than GET, along with the number of times they were called in the current month.

Connectivity - Slack

SaaS Connectors - Slack SaaS

The Slack connector can now include Private channels in aggregation processes. For more information, refer to Required Permissions for VA-based connectors, and Required Permissions for SaaS-based connectors.

Identity Security Cloud - Audit Events & Reporting, Password Management, Settings

We've modernized the system settings, admin global reports, and password management features to improve user experience and accessibility. Additionally, the System Settings > System Features page has been renamed to Feature Settings, and a new Product Licenses page has been added for additional clarity on your active licenses.

Identity Security Cloud - Audit Events & Reporting

Audit reports now show more detailed information about account and entitlement schema changes, including attribute additions, removals, and type changes.

Fixes

ProductIssue IDFixes

SaaS Connectors - Microsoft Entra SaaS

CONHOWRAH-6294

The Microsoft Entra SaaS connector is now more resilient when handling timeout errors while fetching Exchange mailbox properties.

Identity Security Cloud - Access Requests

SAASTRIAGE-11619

Previously, when reviewing access requests on the Approvals page, reviewers could quickly approve or deny items by clicking through cards in sequence—sometimes unintentionally. Now, to make this process more intentional and secure, the Approvals page removes an approval item and allows you to proceed to the next item only after the decision fully registers.

SaaS Connectors - Microsoft Entra SaaS

CONHOWRAH-6297

The Microsoft Entra SaaS connector no longer aggregates the signInActivity attribute when the string value is null.

Connectivity - SAP HR/HCM

CONETN-5271

The SailPoint SAP HR/HCM connector now fetches only the Position Description associated with each specific Position, instead of retrieving all Position Descriptions. This optimization significantly improves performance and ensures timely preview generation for /SAILPOIN/SAIL_READ_TABLE_LEG.

Connectivity - SAP GRC

CONETN-5258

The SAP GRC connector has been enhanced to correctly set the attribute level status when a role removal request fails.

Connectivity - UKG Pro

CONETN-5264

Account creation in the UKG Pro connector no longer fails with a NullPointerException when the enabledEmployeesStatusCodes configuration parameter returns a null value.