SaaS

SaaS Release Notes - September 18, 2026

Release notes cover new features, enhancements, and fixes that have been released to production.

Identity Security Cloud is SailPoint’s next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.

New features

ProductWhat’s new

SaaS Connectors - TeamCity SaaS

The TeamCity SaaS connector is now available for Identity Security Cloud. The connector aggregates users as accounts, groups and roles as entitlements, and access tokens and SSH keys as non-human identities. The connector is read-only and does not provision access. For more information, refer to Integrating SailPoint with TeamCity.

SaaS Connectors - Quick Compliance

Identity Security Cloud now supports the following connectors as Quick Compliance connectors:

You may now expediently configure read-only connections to these sources for account and entitlement aggregation. For a full list of supported Quick Compliance sources, refer to Quick Compliance.

SaaS Connectors - Oracle Cloud Infrastructure SaaS

The Oracle Cloud Infrastructure SaaS connector is now available for Identity Security Cloud. The connector aggregates OCI IAM users as accounts, OCI Generative AI Agents as machine identities, and OCI IAM API keys as credentials. For more information, refer to Integrating SailPoint with Oracle Cloud Infrastructure SaaS.

SaaS Connectors - Delinea Platform SaaS

The Delinea Platform SaaS connector is now available in Identity Security Connectivity. For more information, refer to Integrating SailPoint and Delinea Platform.

Enhancements

ProductFeature enhancements

Identity Security Cloud - Provisioning and Task Manager

Internal provisioning history records now limit the size of stored error and warning text to prevent large or repeated messages from consuming excessive storage before periodic pruning begins.

Identity Security Cloud - Harbor Pilot

When requesting access through Harbor Pilot, if the request requires a form to be completed first, Harbor Pilot will prompt the user to enter the required information before submitting the access request on their behalf. Refer to Creating and Managing Access Requests for more information.

Connectivity - Active Directory

The Active Directory connector now supports moving and renaming user accounts across domains within the same forest when TLS is enabled.

SaaS Connectors

The SailPoint product display name has been updated from Identity Security Cloud Governance to SailPoint Identity Security Cloud Governance to better reflect brand alignment and improve product discoverability. This update applies to new sources only, existing sources are unchanged and will continue to display the previous name. For more information, refer to SailPoint Identity Security Cloud Governance.

Identity Security Cloud - Access Requests

Audit events are now available for changes to access request end dates, including adding a new date, modifying the schedule, and removing an end date. Admins may use these audit events to verify that scheduled access revocations were completed or to troubleshoot if they did not occur as expected.

Connectivity - Snowflake

The Snowflake connector now supports connecting to Snowflake databases in a virtual private cloud using private links for secure connectivity.

Fixes

ProductIssue IDFixes

Identity Security Cloud - Provisioning and Task Manager

ISCRP-7993

Fixed an issue in Search where provisioning failure events for a SDIM-managed source included error messages from other sources on the same request. Each source now only displays its own provisioning failures.

Identity Security Cloud - Search, User Levels

IDNARC-7596

Administrative user levels that were previously missing from the source entitlements in search have been added.

Identity Security Cloud - Sources and Account Management

ISCRP-7610

When a source is renamed in Identity Security Cloud, the “Create Account Failed” event now displays the current source name.

Connectivity - Google Workspace

CONETN-5653

The Google Workspace connector no longer repeatedly updates phones, addresses, and organizations during Attribute Sync when the data has not changed. For single-valued account attributes, the connector now stores JSON values as a comma-joined string to match identity attributes. Multi-valued schema attributes remain as a list.

SaaS Connectors - Google Workspace SaaS

CONETN-5653

The Google Workspace SaaS connector no longer repeatedly updates phones, addresses, and organizations during Attribute Sync when the data has not changed. For single-valued account attributes, the connector now stores JSON values as a comma-joined string to match identity attributes. Multi-valued schema attributes remain as a list.

Connectivity - SCIM 2.0

CONETN-5599

The SCIM 2.0 connector now includes a path for complex core sub-attributes in PATCH operations when running in relax configuration with includePathForCoreAttributes set to true.

SaaS Connectors - Workday SaaS

CONETN-5595

Fixed an issue where the Workday SaaS connector nullified account attributes missing from future-effective termination delta aggregation responses, causing Access History values to flip. Set markPartialRO to true in the source configuration to preserve existing attribute values.

Connectivity - Coupa

CONETN-5527

Fixed an issue where the Coupa connector failed UPDATE_USER provisioning when the invoicing-user attribute was set because the connector sent null instead of false.

Connectivity - Linux

CONETN-5515

Fixed an issue where the Linux connector failed test connection on Red Hat Enterprise Linux (RHEL) 9.0 and above when bracketed paste mode was enabled on the target system.

Connectivity - Virtual Appliance

PLTCONN-10960

Fixed an issue where importing a VA-based delimited file source configuration incorrectly set the source’s connectorClass to the default SaaS-based connector instead of the VA-based connector. The VA connector class is now correctly detected and applied.

SaaS Connectors - JDBC SaaS

CONETN-5591

The JDBC SaaS connector now marks an account request as failed when all related attribute requests fail while using provisioning query settings in Identity Security Connectivity.

Connectivity - JDBC

CONETN-5591

The JDBC connector now marks an account request as failed when all related attribute requests fail while using provisioning query settings in Identity Security Connectivity.

Connectivity - EPIC

CONETN-5639

The Epic connector now prevents partitioned account aggregation failures by skipping null user IDs during partitioned account aggregation.

Connectivity - SCIM 2.0

CONETN-5545

The SCIM 2.0 connector now supports the extension schema Uniform Resource Name (URN) in the path of PATCH remove operations for simple attributes.

Connectivity - SAP Fieldglass

CONETN-5606

Fixed an issue where the SAP Fieldglass connector failed during access request provisioning when an identity had a Primary Role assigned but no Additional Roles.

Connectivity - REST WebServices Connector

CONJUBILEE-5017

The Web Services connector now preserves literal text surrounding placeholders in form-data request values. Operations like add($plan.nativeIdentity$) retain the add(...) operation after the placeholder is resolved instead of sending only the resolved value. This prevents form-data updates from being interpreted incorrectly by target systems.