SaaS

SaaS Release Notes - July 24, 2026

Release notes cover new features, enhancements, and fixes that have been released to production.

Identity Security Cloud is SailPoint's next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.

New features

ProductWhat's new

Identity Security Cloud - Shared Signals Framework

You can now see activity from Shared Signals Framework transmitters and receivers on the MySailPoint home page. Add these new widgets to a dashboard to track the total number of configured receivers and transmitters, the number of events, the top identities associated with events, and more.

Enhancements

ProductFeature enhancements

Non-Employee Risk Management

In Non-Employee Risk Management tenants with core attributes and forms enabled, admins can now remove optional core attributes from core forms. This matches the add and remove behavior already available for custom forms. Removing these attributes does not delete them from the tenant. For more information, refer to Creating and Editing Forms.

Identity Security Cloud - Certifications

Certification reviews are now supported on tablets.

Machine Identity Security

SailPoint MCP Server now supports a global endpoint URL and OAuth 2.1 with PKCE for Access Requests, simplifying setup across MCP clients including Cursor. Users can connect with a single URL, authenticate with ISC/SSO, and benefit from automatic token refresh for a more secure experience. For more information, refer to the product announcement.

Machine Identity Security

To provide a more consistent and scalable source subtype API experience across supported versions, the legacy source subtype API endpoints in v2025 and v2026 that use the sources/{sourceId}/subtypes pattern are deprecated as of June 10, 2026, and are scheduled for removal on September 8, 2026.

If your integrations call these endpoints, migrate to the v1 /source-subtypes endpoints before the removal date. The replacement endpoints support the same core use cases with improved consistency for listing, filtering, and subtype lifecycle operations.

  • To retrieve a subtype by source ID and technical name, use a filters query on GET /source-subtypes/v1.
  • For update and delete operations, use {subtypeId} in the new endpoint paths.

For migration details and replacement endpoints, refer to Machine Account Subtypes API documentation.

Fixes

ProductIssue IDFixes

Access Risk Management

ARM-41024

Fixed an issue in Access Risk Management’s User Risk History report where some previously remediated risks’ details were being overwritten in the Remediated Date and Last Updated columns. Now, these columns reflect the correct remediation dates.

SaaS Connectors - Microsoft Entra SaaS

CONETN-5451

The Microsoft Entra SaaS connector now supports eligibleRoleExpiresAfter and activeRoleExpiresAfter to set PIM role assignment durations for Azure PIM role provisioning.

SaaS Connectors - Workday SaaS

CONETN-5443

Fixed a timezone issue in the Workday SaaS connector that prevented delta aggregation from capturing same-day worker terminations.

Connectivity - SAP S/4HANA Cloud

CONETN-5459

The SAP S/4HANA Cloud connector now retrieves all accounts during account aggregation, resolving account count mismatches between Identity Security Cloud and the managed system.

Connectivity - Credential Provider

CONJUBILEE-5067

The Credential Provider now passes retrieved credentials to downstream Service Desk integrations instead of null values, allowing ticket creation to complete successfully.

Connectivity - ServiceNow Service Catalog

SNOWCAT-2358

The ServiceNow Service Catalog integration now correctly populates u_identity_external_id in the Request Item (RITM) when users submit access requests through the Record Producer page, ensuring Identity Security Cloud routes approvals to the correct approver.