Virtual Appliance

Virtual Appliance Release Notes - January 8, 2026

Virtual Appliance (VA) release notes might contain references to SailPoint software and Flatcar operating system updates that SailPoint will automatically apply.

SailPoint Software

2026.1.8 - Version 2.19, CCG 1181

New Features

ProductWhat's new

Connectivity - SalesForce

Your VA-based Salesforce source can now be migrated to a corresponding SaaS source while ensuring data (users and entitlements) remain intact and maintains your source configurations like access profiles, roles, password settings, and correlation configurations. For more information, refer to Migrate VA-based Source to a SaaS Source.

Connectivity - Quick Compliance

Identity Security Cloud now supports an additional set of Quick Compliance connectors. Now you can expediently configure read-only connections to an additional set of sources for account and entitlement aggregation. For a full list of supported Quick Compliance sources, refer to Quick Compliance.

Connectivity - TSS Read Only

SailPoint's new Top Secret (Read-only) connector is used to import and aggregate account and group data exported by the Top Secret TSSCFILE utility. For more information, refer to Integrating SailPoint with Top Secret (Read-only).

Connectivity - OnGuard

The SailPoint integration with OnGuard enables comprehensive management of cardholders directly through the SailPoint Identity Security Cloud and IdentityIQ platform, enabling organizations to streamline their security processes and enhance control over physical access. This integration has capabilities for cardholder management, including the management of access levels, badges, and badge types.

Connectivity - Imprivata VPAM

SailPoint is pleased to announce the availability of the new Imprivata Vendor Privileged Access management (VPAM) integration.

The SailPoint Imprivata VPAM integration provides governance capabilities for Users and Vendor Representatives within the Imprivata VPAM system. Key features include aggregation, provisioning of Users and Vendor Representatives, and managing entitlements at the account level. For more information, refer to Integrating SailPoint with Imprivata Vendor Privileged Access Management (VPAM).

Connectivity - MongoDB Cloud - Atlas

Your VA-based MongoDB Cloud Atlas source can now be migrated to a corresponding SaaS source while ensuring data (users and entitlements) remain intact and maintains your source configurations like access profiles, roles, password settings, and correlation configurations. For more information, refer to Migrate VA-based Source to a SaaS Source.

Connectivity - SalesForce

The Salesforce VA-based connector now supports Client Credentials as a connection authentication type.

Connectivity - SAP Analytics Cloud

Your VA-based SAP Analytics Cloud source can now be migrated to a corresponding SaaS source while ensuring data (users and entitlements) remain intact and maintains your source configurations like access profiles, roles, password settings, and correlation configurations. For more information, refer to Migrate VA-based Source to a SaaS Source.

Connectivity - Dynamics 365 - CRM

Your VA-based Microsoft Dynamics 365 Customer Relationship Management source can now be migrated to a corresponding SaaS source while ensuring data (users and entitlements) remain intact and maintains your source configurations like access profiles, roles, password settings, and correlation configurations. For more information, refer to Migrate VA-based Source to a SaaS Source.

Enhancements

ProductFeature enhancements

Connectivity - Microsoft Entra ID

The Microsoft Entra ID connector now allows filtering of the Azure resource providing granular control over the scope of account and entitlement aggregation through configured list of Subscription IDs and Management Group IDs. For more information, refer to Azure Resource Filtering: Subscriptions and Management Groups.

Connectivity - Sybase

The SAP Sybase connector now supports SAP ASE 16.0 SP04.

Connectivity - SAP S/4HANA Cloud

The SAP HR/HCM connector now supports the SAP On-Prem S/4HANA 2025 Initial shipment stack.

Connectivity - Discovery - ServiceNow CMDB

The SailPoint ServiceNow CMDB Discovery connector fetches the details of applications configured in ServiceNow CMDB. It provides continuous application discovery, revealing inventory and ownership across the enterprise while prioritizing governance efforts on high-impact applications. For more information, refer to Discovering Applications with ServiceNow CMDB.

Connectivity - Discovery - PingOne SSO

SailPoint’s PingOne SSO Discovery connector fetches the details of applications configured in PingOne. It provides continuous application discovery, revealing inventory and ownership across the enterprise while prioritizing governance efforts on high-impact applications. For more information, refer to Discovering Applications with PingOne SSO.

Connectivity - Discovery - Okta SSO

The SailPoint Okta SSO Discovery connector retrieves details of applications configured in Okta. It provides continuous application discovery, revealing inventory and ownership across the enterprise. This guides prioritization and focuses governance efforts on the highest-impact applications. For information on creating a Okta SSO discovery connector, refer to Discovering Applications with Okta SSO.

Connectivity - IBM Security Verify Access

The SailPoint IBM Security Verify Access (IBM Tivoli Access Manager) connector now provides support for partitioning aggregation.

Connectivity - ServiceNow Identity Governance

SaaS Connectors - ServiceNow Identity Governance SaaS

The ServiceNow Identity Governance SaaS and VA connectors now support authentication using Microsoft Entra ID (Azure AD) OAuth 2.0 Client Credentials.

Connectivity - SAP Direct

The SAP Direct connector now supports SAP On-Prem S/4HANA 2025 Initial Shipment Stack.

Connectivity - Slack

SaaS Connectors - Slack SaaS

The Slack connector can now include Private channels in aggregation processes. For more information, refer to Required Permissions for VA-based connectors, and Required Permissions for SaaS-based connectors.

Connectivity - SAP GRC

The SAP GRC Connector has been enhanced to handle the SocketTimeoutException that occurs while checking the access request status.



Fixes

ProductIssue IDFixes

Connectivity - SAP Fieldglass

CONUMSHIAN-10025

The SAP Fieldglass SaaS Connector no longer fails with 404 errors during account aggregation or provisioning operations.

Connectivity - SAP GRC

CONETN-5244

The SAP GRC connector now correctly retrieves the full department value using an alternate delimiter (other than "/") without truncation.

Connectivity - Microsoft Entra ID

CONETN-5239

The Microsoft Entra ID connector no longer logs error messages related to failed XML parsing due to unavailable context during account aggregation.

Connectivity - Microsoft SharePoint Online

CONETN-5120

The Microsoft SharePoint Online connector no longer loses attributes during account aggregation when users have duplicate records.

Connectivity - Active Directory

CONETN-5137

You can now bypass Active Directory schema validation, particularly for non-domain-joined IQService hosts, by configuring "skipADSchemaCheck" = "true" in the source configuration.

Connectivity - SAP HR/HCM

CONETN-5271

The SailPoint SAP HR/HCM connector now fetches only the Position Description associated with each specific Position, instead of retrieving all Position Descriptions. This optimization significantly improves performance and ensures timely preview generation for /SAILPOIN/SAIL_READ_TABLE_LEG.

Connectivity - SAP GRC

CONETN-5258

The SAP GRC connector has been enhanced to correctly set the attribute level status when a role removal request fails.

Connectivity - UKG Pro

CONETN-5264

Account creation in the UKG Pro connector no longer fails with a NullPointerException when the enabledEmployeesStatusCodes configuration parameter returns a null value.

Connectivity - Oracle E-Business

CONETN-5270

The SailPoint Oracle EBS Connector no longer fails with ClassCastException for entitlement aggregation.

Connectivity - SAP Concur

CONETN-5252

The SailPoint SAP Concur Connector now supports the removal of roles associated with SAP Concur entitlements.

Connectivity - Workday Accounts

CONETN-5238

The SailPoint Workday Accounts Connector no longer throws an exception when saving token information during aggregation with the Manage Implementer User option enabled.