SaaS

SaaS Release Notes - March 27, 2026

Production release notes - March 27, 2026

Release notes cover new features, enhancements, and fixes that have been released to production.

Identity Security Cloud is SailPoint's next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.

New features

ProductWhat's new

Connectivity - Quick Compliance

Identity Security Cloud now supports the following connectors as Quick Compliance connectors:

You can now expediently configure read-only connections to these sources for account and entitlement aggregation. For a full list of supported Quick Compliance sources, refer to Quick Compliance.

SaaS Connectors - Discovery - Browser Extension

The SailPoint Application Visibility browser extension discovery connector is now available to continuously discover the applications accessed by users across your organization. It identifies the applications being used and provides a clear view of the software landscape within your environment.

Connectivity - Amazon Web Services (AWS)

Your VA-based Amazon Web Services (AWS) source can now be migrated to a corresponding SaaS source while ensuring data (users and entitlements) remain intact and maintains your source configurations like access profiles, roles, password settings, and correlation configurations. For more information, refer to Migrate VA-based Source to a SaaS Source.

Enhancements

ProductFeature enhancements

Identity Security Cloud - Core Access Model

The Applications modernization has been re-released to production, which brings an improved user experience and accessibility. It was previously rolled back on March 2nd due to a translation issue, which has now been resolved in this release.

Connectivity - Express Setup - Deep Governance

For connectors with express setup, the welcome screen now lists all the authentication prerequisites. This helps you gather the necessary information before you begin the configuration process.

Identity Security Cloud - Core Access Model

Roles, access profiles, and entitlements can now have more than one owner!

Identity Security Cloud access items can now have a primary owner and optional, additional owners with the following considerations:

  • A single primary owner is required for roles and access profiles, but is optional for entitlements.
  • Additional owners are always optional and may be comprised of up to 10 identities or a single governance group.
  • Access request reviews may now be performed by an access item’s primary owner, additional owners, or all owners. When an item's additional owners or all owners are selected as reviewers, all owners are notified, but only one of the owners is required to approve the request.

Connectivity - SAP SuccessFactors

The SailPoint SuccessFactors Connector now supports MDF Picklists in alignment with SAP’s deprecation of Legacy Picklists. Remaining Legacy Picklists should be migrated to MDF Picklists to ensure compatibility. For more details, refer to the SAP documentation: Field Mapping from Legacy to MDF Picklists

Identity Security Cloud - Shared Signals Framework, Workflows

Shared Signals Framework and Workflows now support CAEP Session Revoked and CAEP Credential Change events. When these security events are received, they are automatically correlated to an identity.

This support includes two Workflow triggers and two Workflows templates:

Connectivity - SAP Identity Directory

The SailPoint SAP Identity Directory connector is enhanced to support additional (custom) SAP CIS (Cloud Identity Directory) attributes.

SailPoint Accelerated Application Management - Application Visibility

SailPoint Accelerated Application Management customers can configure the new browser extension discovery connector in Identity Security Cloud to automatically locate and monitor enterprise and shadow applications applications throughout their organisation. This allows admins to:

  • View SaaS application risk details, such as risk scores, MFA gaps, and exposed accounts, in a single location within Identity Security Cloud.
  • View new dashboard and widgets to gain a snapshot of which applications are onboarded, which need attention, and your overall SaaS risk posture.

Connectivity - Okta

The Okta connector now skips API calls when provisioning accounts that are already deprovisioned and displays a connector-specific error message.

Identity Security Cloud - Parameter Storage, Workflows

The Workflows HTTP Request action adds integration with SailPoint Parameter Storage, allowing workflow authors to use parameters for HTTP request authentication configuration and credentials. Parameters can be shared by multiple Workflows Actions, and can be easily managed via the Parameter Storage admin interface.

Workflows using the previous version of the HTTP Request action will continue to function as expected. To use Parameter Storage in existing workflows, you must edit your workflow and replace the existing action.

For more information, refer to Managing Parameters and the HTTP Request Action documentation.

Identity Security Cloud - Workflows

Workflows data returned in the WorkflowExecutionCompleted event has been refined to reduce redundancy and improve efficiency. The WorkflowExecutionCompleted event will include only the minimal metadata necessary to mark the workflow's completion. Detailed step output data is maintained and remains fully accessible from corresponding task completion events.

Fixes

ProductIssue IDFixes

Identity Security Cloud - MySailPoint

PLTUI-14247

Corrected a configuration to ensure that MySailPoint appears as the leftmost home bar navigation menu option for all customers.

SaaS Connectors - Microsoft SharePoint Online SaaS

CONHOWRAH-6806

The SailPoint SharePoint connector can now perform account aggregation without any errors.

SaaS Connectors - MongoDB Cloud Database SaaS

CONNAMDANG-6828

Resolved ClassNotFoundException errors in the MongoDB Cloud SaaS Connector.

Connectivity - Active Directory

CONETN-5303

The Active Directory connector now creates a mailbox during account modification only if the account includes Exchange attributes, regardless of whether Exchange is enabled on the source.

Connectivity - Oracle HCM Cloud

CONETN-5327

The SailPoint Oracle HCM Cloud connector now skips the get object call after provisioning if the flag skipGetObjectAfterUpdate is set to true in the application.