Virtual Appliance
Virtual Appliance Release Notes - January 8, 2026
Virtual Appliance (VA) release notes might contain references to SailPoint software and Flatcar operating system updates that SailPoint will automatically apply.
SailPoint Software
2026.1.8 - Version 2.19, CCG 1181
New Features
| Product | What's new |
|---|---|
Connectivity - SalesForce | Your VA-based Salesforce source can now be migrated to a corresponding SaaS source while ensuring data (users and entitlements) remain intact and maintains your source configurations like access profiles, roles, password settings, and correlation configurations. For more information, refer to Migrate VA-based Source to a SaaS Source. |
Connectivity - Quick Compliance | Identity Security Cloud now supports an additional set of Quick Compliance connectors. Now you can expediently configure read-only connections to an additional set of sources for account and entitlement aggregation. For a full list of supported Quick Compliance sources, refer to Quick Compliance. |
Connectivity - TSS Read Only | SailPoint's new Top Secret (Read-only) connector is used to import and aggregate account and group data exported by the Top Secret TSSCFILE utility. For more information, refer to Integrating SailPoint with Top Secret (Read-only). |
Connectivity - OnGuard | The SailPoint integration with OnGuard enables comprehensive management of cardholders directly through the SailPoint Identity Security Cloud and IdentityIQ platform, enabling organizations to streamline their security processes and enhance control over physical access. This integration has capabilities for cardholder management, including the management of access levels, badges, and badge types. |
Connectivity - Imprivata VPAM | SailPoint is pleased to announce the availability of the new Imprivata Vendor Privileged Access management (VPAM) integration. The SailPoint Imprivata VPAM integration provides governance capabilities for Users and Vendor Representatives within the Imprivata VPAM system. Key features include aggregation, provisioning of Users and Vendor Representatives, and managing entitlements at the account level. For more information, refer to Integrating SailPoint with Imprivata Vendor Privileged Access Management (VPAM). |
Connectivity - MongoDB Cloud - Atlas | Your VA-based MongoDB Cloud Atlas source can now be migrated to a corresponding SaaS source while ensuring data (users and entitlements) remain intact and maintains your source configurations like access profiles, roles, password settings, and correlation configurations. For more information, refer to Migrate VA-based Source to a SaaS Source. |
Connectivity - SalesForce | The Salesforce VA-based connector now supports Client Credentials as a connection authentication type. |
Connectivity - SAP Analytics Cloud | Your VA-based SAP Analytics Cloud source can now be migrated to a corresponding SaaS source while ensuring data (users and entitlements) remain intact and maintains your source configurations like access profiles, roles, password settings, and correlation configurations. For more information, refer to Migrate VA-based Source to a SaaS Source. |
Connectivity - Dynamics 365 - CRM | Your VA-based Microsoft Dynamics 365 Customer Relationship Management source can now be migrated to a corresponding SaaS source while ensuring data (users and entitlements) remain intact and maintains your source configurations like access profiles, roles, password settings, and correlation configurations. For more information, refer to Migrate VA-based Source to a SaaS Source. |
Enhancements
| Product | Feature enhancements |
|---|---|
Connectivity - Microsoft Entra ID | The Microsoft Entra ID connector now allows filtering of the Azure resource providing granular control over the scope of account and entitlement aggregation through configured list of Subscription IDs and Management Group IDs. For more information, refer to Azure Resource Filtering: Subscriptions and Management Groups. |
Connectivity - Sybase | The SAP Sybase connector now supports SAP ASE 16.0 SP04. |
Connectivity - SAP S/4HANA Cloud | The SAP HR/HCM connector now supports the SAP On-Prem S/4HANA 2025 Initial shipment stack. |
Connectivity - Discovery - ServiceNow CMDB | The SailPoint ServiceNow CMDB Discovery connector fetches the details of applications configured in ServiceNow CMDB. It provides continuous application discovery, revealing inventory and ownership across the enterprise while prioritizing governance efforts on high-impact applications. For more information, refer to Discovering Applications with ServiceNow CMDB. |
Connectivity - Discovery - PingOne SSO | SailPoint’s PingOne SSO Discovery connector fetches the details of applications configured in PingOne. It provides continuous application discovery, revealing inventory and ownership across the enterprise while prioritizing governance efforts on high-impact applications. For more information, refer to Discovering Applications with PingOne SSO. |
Connectivity - Discovery - Okta SSO | The SailPoint Okta SSO Discovery connector retrieves details of applications configured in Okta. It provides continuous application discovery, revealing inventory and ownership across the enterprise. This guides prioritization and focuses governance efforts on the highest-impact applications. For information on creating a Okta SSO discovery connector, refer to Discovering Applications with Okta SSO. |
Connectivity - IBM Security Verify Access | The SailPoint IBM Security Verify Access (IBM Tivoli Access Manager) connector now provides support for partitioning aggregation. |
Connectivity - ServiceNow Identity Governance SaaS Connectors - ServiceNow Identity Governance SaaS | The ServiceNow Identity Governance SaaS and VA connectors now support authentication using Microsoft Entra ID (Azure AD) OAuth 2.0 Client Credentials. |
Connectivity - SAP Direct | The SAP Direct connector now supports SAP On-Prem S/4HANA 2025 Initial Shipment Stack. |
Connectivity - Slack SaaS Connectors - Slack SaaS | The Slack connector can now include Private channels in aggregation processes. For more information, refer to Required Permissions for VA-based connectors, and Required Permissions for SaaS-based connectors. |
Connectivity - SAP GRC | The SAP GRC Connector has been enhanced to handle the |
Fixes
| Product | Issue ID | Fixes |
|---|---|---|
Connectivity - SAP Fieldglass | CONUMSHIAN-10025 | The SAP Fieldglass SaaS Connector no longer fails with 404 errors during account aggregation or provisioning operations. |
Connectivity - SAP GRC | CONETN-5244 | The SAP GRC connector now correctly retrieves the full department value using an alternate delimiter (other than "/") without truncation. |
Connectivity - Microsoft Entra ID | CONETN-5239 | The Microsoft Entra ID connector no longer logs error messages related to failed XML parsing due to unavailable context during account aggregation. |
Connectivity - Microsoft SharePoint Online | CONETN-5120 | The Microsoft SharePoint Online connector no longer loses attributes during account aggregation when users have duplicate records. |
Connectivity - Active Directory | CONETN-5137 | You can now bypass Active Directory schema validation, particularly for non-domain-joined IQService hosts, by configuring |
Connectivity - SAP HR/HCM | CONETN-5271 | The SailPoint SAP HR/HCM connector now fetches only the Position Description associated with each specific Position, instead of retrieving all Position Descriptions. This optimization significantly improves performance and ensures timely preview generation for |
Connectivity - SAP GRC | CONETN-5258 | The SAP GRC connector has been enhanced to correctly set the attribute level status when a role removal request fails. |
Connectivity - UKG Pro | CONETN-5264 | Account creation in the UKG Pro connector no longer fails with a |
Connectivity - Oracle E-Business | CONETN-5270 | The SailPoint Oracle EBS Connector no longer fails with |
Connectivity - SAP Concur | CONETN-5252 | The SailPoint SAP Concur Connector now supports the removal of roles associated with SAP Concur entitlements. |
Connectivity - Workday Accounts | CONETN-5238 | The SailPoint Workday Accounts Connector no longer throws an exception when saving token information during aggregation with the |