SaaS

SaaS Release Notes - September 25, 2026

Release notes cover new features, enhancements, and fixes that have been released to production.

Identity Security Cloud is SailPoint’s next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.

New features

ProductWhat’s new

SaaS Connectors - UiPath SaaS

SailPoint introduces the UiPath SaaS connector for Identity Security Connectivity. This connector supports the aggregation of UiPath robot accounts and groups and uses the SailPoint Agentic Fabric to discover machine identities. For more information, refer to Integrating SailPoint with UiPath.

SaaS Connectors - Oracle Access Governance SaaS

The Oracle Access Governance SaaS connector is now available for Identity Security Cloud. The connector aggregates:

  • Identities as accounts
  • Roles and access bundles as entitlements

The connector also supports entitlement grants and revocations, and enabling and disabling account operations. For more information, refer to Integrating SailPoint with Oracle Access Governance.

SaaS Connectors - GitLab SaaS

The GitLab SaaS connector is now available in Identity Security Cloud. The connector extends visibility into GitLab.com and self-managed GitLab instances by aggregating users, groups, and projects, and by discovering non-human identities including personal, group, and project access tokens, the bot users behind those tokens, group and project service accounts, and security policy bots. This connector is read-only and does not support provisioning. For more information, refer to Integrating SailPoint with GitLab.

SaaS Connectors - JFrog SaaS

The JFrog SaaS connector is now a deep governance connector for Identity Security Cloud. It also gains visibility into Docker image layers in local Artifactory repositories to detect leaked secrets, and aggregates long-lived access tokens as credentials. For more information, refer to Integrating SailPoint with JFrog.

SaaS Connectors - Quick Compliance

Identity Security Cloud now supports the following connectors as Quick Compliance connectors:

You can now expediently configure read-only connections to these sources for account and entitlement aggregation. For a full list of supported Quick Compliance sources, refer to Quick Compliance.

Access Risk Management

Access Risk Management’s new agent version, ARM AGENT 2026.08.24.2, supports enhanced Fiori functionality including expanded Fiori role metadata and Fiori intent utilization telemetry. Refer to Updating the Agent for additional information.

Identity Security Cloud - Response and Remediation

The SailPoint Identity Security Intelligence CrowdStrike Foundry app adds an Identity Security Intelligence panel to CrowdStrike Falcon Endpoint Security detections. Analysts can review SailPoint identity context for the subject of a detection in the detection side panel, without switching tools.

For a human identity, the panel shows lifecycle status, correlated accounts, privileged and outlier access, recent access and account-status changes, and recent certification history.

For a non-human identity, application, or AI agent, the panel shows identity type, source-native identity, human owners, linked machine accounts, orphaned status, and match confidence (Exact, Partial, or Ambiguous).

When Response Actions are available, analysts can start Disable Identity and Disable Account requests from the same panel. Analysts can also search by email or SailPoint identity ID from Identity Intelligence in the app navigation.

Refer to Integrating SailPoint with CrowdStrike Foundry for SecOps Identity Intelligence for more information.

Identity Security Cloud - Response and Remediation

Security analysts can now contain a compromised human identity from their security tool, with the request processed by Identity Security Cloud using the SecOps Identity Intelligence Response Action workflow template.

Two actions are available:

  • Disable Identity - Disables the identity’s accounts in Identity Security Cloud.
  • Disable Account - Disables one or more selected accounts in Identity Security Cloud.

Requests are tracked as Submitted, In Progress, and Completed or Failed, and are recorded as a Request Response Action Submitted audit event.

Identity Security Cloud - Response and Remediation

Security operations teams can now retrieve SailPoint identity context from Identity Security Cloud without leaving their security tooling. SecOps Identity Intelligence returns a curated view of the identity associated with an alert, for both human and non-human identities.

For a human identity, the response includes lifecycle status, correlated accounts, privileged and outlier access, recent access and account-status changes, and recent certification history.

For a non-human identity, application, or AI agent, the response includes identity type, source-native identity, human owners, linked machine accounts, and whether the identity is orphaned.

Refer to Get identity intelligence for request and response details and SailPoint SecOps Identity Intelligence for more information.

Enhancements

ProductFeature enhancements

SaaS Connectors - Workday SaaS

The Workday SaaS connector now supports Event Lite transaction types in delta aggregation. Enable Delta Aggregation Lite Events and enter Event Lite Types to include lightweight Event Lite records that do not require a business process or approval chain. For more information, refer to Delta Aggregation Settings.

SaaS Connectors - AWS SaaS

The AWS SaaS connector now supports the discovery of Amazon Quick agents and action connectors, including their permission-grant relationships.

Connectivity - SAP Sybase ASE

The SAP Sybase ASE connector now supports SAP Sybase 16.1 as a certified managed system. For more information, refer to Supported Managed Systems.

SaaS Connectors - Salesforce SaaS

The Salesforce SaaS connector now supports Secrets and Non-Human Identity (NHI) discovery, including Salesforce Connected Apps and External Client Apps (ECAs), and discovery of exposed credentials across Salesforce objects and records. For configuration and required permissions, refer to Integrating SailPoint with Salesforce SaaS.

SaaS Connectors - Oracle Cloud Infrastructure SaaS

The Oracle Cloud Infrastructure SaaS connector now aggregates auth tokens, customer secret keys, and SMTP credentials with API keys in the OCI IAM Credentials dataset, and OCI Vault secret metadata in the OCI Vault Secrets dataset. Secret values are not collected. For more information, refer to Integrating SailPoint with Oracle Cloud Infrastructure SaaS.

Identity Security Cloud - Platform

Dark mode support has been expanded to more areas across Identity Security Cloud, including custom branding.

Fixes

ProductIssue IDFixes

Connectivity - SAP HR/HCM

CONETN-5528

Fixed an issue where the SAP HR/HCM connector intermittently returned future-dated position descriptions instead of the currently active value during aggregation.

Connectivity - Workday Accounts

CONETN-5546

Fixed an issue where the Workday Accounts connector aggregated past-effective organization roles for terminated workers. Set skipRolesForTerminatedWorker to true in the application configuration to skip organization roles during terminated account aggregation.

SaaS Connectors - Microsoft Entra SaaS

CONHOWRAH-7572

The Microsoft Entra SaaS connector now supports the accountFilterString attribute for delta aggregation, allowing you to apply custom filter criteria when aggregating incremental account changes.

SaaS Connectors - Successfactors SaaS

CONETN-5612

The SuccessFactors SaaS connector no longer fails during full account aggregation with a StackOverflowError when the account schema includes multi-valued custom navigation attributes.

SaaS Connectors - ISC Cloud Governance Connector

CONETN-5638

The SailPoint Identity Security Cloud Governance connector no longer times out during single account aggregation and UserLevels provisioning when Enable User Level Caching is enabled. Full account aggregation remains unaffected.

Connectivity - Oracle EPM Cloud - FCCS

CONETN-5554

Fixed an issue where the Oracle EPM Cloud FCCS connector reported Delete Account as successful when the IDCS user was not deleted. Set enableEnhancedAccountDelete to true in the application configuration to validate IDCS responses and confirm the account is removed before returning success.

SaaS Connectors - Ceridian Dayforce HCM SaaS

CONETN-5641

The Ceridian Dayforce HCM SaaS connector now retries configured retryable errors during aggregation operations. HTTP 429 is the default retryable error. For more information, refer to Additional Settings.

SaaS Connectors - Microsoft Entra SaaS

CONETN-5645

The Microsoft Entra SaaS connector no longer times out during long-running aggregations.

Connectivity - Cerner

CONETN-5626

The Cerner connector no longer shifts effective dates by one day during Create, Update, and Enable provisioning, and Enable for rehire now moves Suspended accounts to Active. To use this fix, set enableDateFix to true and set cernerTimeZone to your Cerner facility timezone.

For more information, refer to Integrating SailPoint with Cerner Healthcare.

Connectivity - Imprivata EAM

CONETN-5643

The Imprivata Enterprise Access Management connector no longer encounters out-of-memory errors, as it now properly closes HTTP connections after each operation.

SaaS Connectors - Workday Accounts SaaS

CONETN-5546

Fixed an issue where the Workday Accounts SaaS connector aggregated past-effective organization roles for terminated workers. Set skipRolesForTerminatedWorker to true in the application configuration to skip organization roles during terminated account aggregation.

SaaS Connectors - Oracle EPM Cloud - FCCS SaaS

CONETN-5554

Fixed an issue where the Oracle EPM Cloud FCCS SaaS connector reported Delete Account as successful when the IDCS user was not deleted. Set enableEnhancedAccountDelete to true in the application configuration to validate IDCS responses and confirm the account is removed before returning success.

Identity Security Cloud - Search

ISCRP-4726

Fixed an issue where the IP Address field for the Change Identity Lifecycle Passed event in Search was not appearing as expected.

Access Risk Management

TRIAGE-17650

Fixed an issue where bulk user import failed with “Completed with error” when a user already has an SSO identity mapping. Imports will now be completed even if the spreadsheet includes a username or claim value that is already linked in Access Risk Management.