SaaS
SaaS Release Notes - September 18, 2026
Release notes cover new features, enhancements, and fixes that have been released to production.
Identity Security Cloud is SailPoint’s next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.
New features
| Product | What’s new |
|---|---|
SaaS Connectors - TeamCity SaaS | The TeamCity SaaS connector is now available for Identity Security Cloud. The connector aggregates users as accounts, groups and roles as entitlements, and access tokens and SSH keys as non-human identities. The connector is read-only and does not provision access. For more information, refer to Integrating SailPoint with TeamCity. |
SaaS Connectors - Quick Compliance | Identity Security Cloud now supports the following connectors as Quick Compliance connectors: You may now expediently configure read-only connections to these sources for account and entitlement aggregation. For a full list of supported Quick Compliance sources, refer to Quick Compliance. |
SaaS Connectors - Oracle Cloud Infrastructure SaaS | The Oracle Cloud Infrastructure SaaS connector is now available for Identity Security Cloud. The connector aggregates OCI IAM users as accounts, OCI Generative AI Agents as machine identities, and OCI IAM API keys as credentials. For more information, refer to Integrating SailPoint with Oracle Cloud Infrastructure SaaS. |
SaaS Connectors - Delinea Platform SaaS | The Delinea Platform SaaS connector is now available in Identity Security Connectivity. For more information, refer to Integrating SailPoint and Delinea Platform. |
Enhancements
| Product | Feature enhancements |
|---|---|
Identity Security Cloud - Provisioning and Task Manager | Internal provisioning history records now limit the size of stored error and warning text to prevent large or repeated messages from consuming excessive storage before periodic pruning begins. |
Identity Security Cloud - Harbor Pilot | When requesting access through Harbor Pilot, if the request requires a form to be completed first, Harbor Pilot will prompt the user to enter the required information before submitting the access request on their behalf. Refer to Creating and Managing Access Requests for more information. |
Connectivity - Active Directory | The Active Directory connector now supports moving and renaming user accounts across domains within the same forest when TLS is enabled. |
SaaS Connectors | The SailPoint product display name has been updated from Identity Security Cloud Governance to SailPoint Identity Security Cloud Governance to better reflect brand alignment and improve product discoverability. This update applies to new sources only, existing sources are unchanged and will continue to display the previous name. For more information, refer to SailPoint Identity Security Cloud Governance. |
Identity Security Cloud - Access Requests | Audit events are now available for changes to access request end dates, including adding a new date, modifying the schedule, and removing an end date. Admins may use these audit events to verify that scheduled access revocations were completed or to troubleshoot if they did not occur as expected. |
Connectivity - Snowflake | The Snowflake connector now supports connecting to Snowflake databases in a virtual private cloud using private links for secure connectivity. |
Fixes
| Product | Issue ID | Fixes |
|---|---|---|
Identity Security Cloud - Provisioning and Task Manager | ISCRP-7993 | Fixed an issue in Search where provisioning failure events for a SDIM-managed source included error messages from other sources on the same request. Each source now only displays its own provisioning failures. |
Identity Security Cloud - Search, User Levels | IDNARC-7596 | Administrative user levels that were previously missing from the source entitlements in search have been added. |
Identity Security Cloud - Sources and Account Management | ISCRP-7610 | When a source is renamed in Identity Security Cloud, the “Create Account Failed” event now displays the current source name. |
Connectivity - Google Workspace | CONETN-5653 | The Google Workspace connector no longer repeatedly updates phones, addresses, and organizations during Attribute Sync when the data has not changed. For single-valued account attributes, the connector now stores JSON values as a comma-joined string to match identity attributes. Multi-valued schema attributes remain as a list. |
SaaS Connectors - Google Workspace SaaS | CONETN-5653 | The Google Workspace SaaS connector no longer repeatedly updates phones, addresses, and organizations during Attribute Sync when the data has not changed. For single-valued account attributes, the connector now stores JSON values as a comma-joined string to match identity attributes. Multi-valued schema attributes remain as a list. |
Connectivity - SCIM 2.0 | CONETN-5599 | The SCIM 2.0 connector now includes a path for complex core sub-attributes in PATCH operations when running in relax configuration with |
SaaS Connectors - Workday SaaS | CONETN-5595 | Fixed an issue where the Workday SaaS connector nullified account attributes missing from future-effective termination delta aggregation responses, causing Access History values to flip. Set |
Connectivity - Coupa | CONETN-5527 | Fixed an issue where the Coupa connector failed |
Connectivity - Linux | CONETN-5515 | Fixed an issue where the Linux connector failed test connection on Red Hat Enterprise Linux (RHEL) 9.0 and above when bracketed paste mode was enabled on the target system. |
Connectivity - Virtual Appliance | PLTCONN-10960 | Fixed an issue where importing a VA-based delimited file source configuration incorrectly set the source’s |
SaaS Connectors - JDBC SaaS | CONETN-5591 | The JDBC SaaS connector now marks an account request as failed when all related attribute requests fail while using provisioning query settings in Identity Security Connectivity. |
Connectivity - JDBC | CONETN-5591 | The JDBC connector now marks an account request as failed when all related attribute requests fail while using provisioning query settings in Identity Security Connectivity. |
Connectivity - EPIC | CONETN-5639 | The Epic connector now prevents partitioned account aggregation failures by skipping null user IDs during partitioned account aggregation. |
Connectivity - SCIM 2.0 | CONETN-5545 | The SCIM 2.0 connector now supports the extension schema Uniform Resource Name (URN) in the path of PATCH remove operations for simple attributes. |
Connectivity - SAP Fieldglass | CONETN-5606 | Fixed an issue where the SAP Fieldglass connector failed during access request provisioning when an identity had a Primary Role assigned but no Additional Roles. |
Connectivity - REST WebServices Connector | CONJUBILEE-5017 | The Web Services connector now preserves literal text surrounding placeholders in form-data request values. Operations like |