Virtual Appliance
Virtual Appliance Release Notes - March 19, 2026
Virtual Appliance (VA) release notes might contain references to SailPoint software and Flatcar operating system updates that SailPoint will automatically apply.
SailPoint Software
2026.3.19 - Version 2.23, CCG 1212
New features
| Product | What's new |
|---|---|
Connectivity - RPA Connector | SailPoint now supports the Robotic Process Automation connector, which provides connectivity via RPA platforms for systems that lack APIs or direct ways for account and access management. Initially the RPA connector supports UiPath as an RPA platform. For more information, refer to the product documentation: Integrating SailPoint with Robotic Process Automation Platforms. |
Connectivity - Quick Compliance | Identity Security Cloud now supports the following connectors as Quick Compliance connectors: Avaza Chatwork Cybozu.com Dato CMS Desknet's NEO Liferay LINE WORKS Productive Respond.io Timeneye WildApricot You can now expediently configure read-only connections to these sources for account and entitlement aggregation. For a full list of supported Quick Compliance sources, refer to Quick Compliance. |
Connectivity - SAP Concur | Your VA-based SAP Concur source can now be migrated to a corresponding SaaS source while ensuring data (users and entitlements) remain intact and maintains your source configurations like access profiles, roles, password settings, and correlation configurations. For more information, refer to Migrate VA-based Source to a SaaS Source. |
Connectivity - Quick Compliance | Identity Security Cloud now supports the following connectors as Quick Compliance connectors: Baserow Chatwoot Memberful Redis Resource Guru Sendgrid You can now expediently configure read-only connections to these sources for account and entitlement aggregation. For a full list of supported Quick Compliance sources, refer to Quick Compliance. |
Enhancements
| Product | Feature enhancements |
|---|---|
Connectivity - PeopleSoft Direct | The PeopleSoft Direct Connector now retries entitlement aggregation upon connectivity failures, such as SocketTimeOutException and UnknownHostException. The process terminates only after the maximum number of retry attempts is reached. |
Connectivity - ServiceNow Identity Governance | The SailPoint ServiceNow Identity Governance Connector now has a default classification criteria for classifying machine accounts, based on the Machine Identity type. Also, two new attributes identity_type and web_service_access_only are added in the account schema that specifies the user's identity type and indicates if the user has only web service access respectively. For more information, refer to Classifying Machine Accounts and Account Attributes. |
Connectivity - Active Directory | The Active Directory connector now retrieves cross-domain group memberships for group objects during entitlement aggregation and represents these relationships in a hierarchical view. For more information, refer to Aggregation Settings. |
Fixes
| Product | Issue ID | Fixes |
|---|---|---|
Connectivity - SCIM 2.0 | CONETN-5288 | The SCIM 2.0 VA-based connector now regenerates the token if it expires during account aggregation. |
Connectivity - Oracle HCM Cloud | CONETN-5312 | The Oracle HCM Cloud connector no longer throws "Object Not Found" error during single account aggregation. |
Connectivity - Microsoft Entra ID | CONETN-5305 | The Microsoft Entra ID connector now optimizes Admin Unit membership caching to prevent redundant cache rebuilds. This significantly reduces API calls and improves aggregation performance for large user sets. |
Connectivity - Connector Infrastructure | CONHOWRAH-5796 | Updated commons-lang dependency from 2.6 to commons-lang3 3.18.0.jar file. |
Connectivity - Duo, Duo SaaS SaaS Connectors - Duo, Duo SaaS | CONCHENAB-7944 | The SailPoint Duo SaaS and Duo VA connectors are now not impacted by the Duo Certificate Authority (CA) Bundle configuration. |
Connectivity - Slack | CONETN-5261 | The Slack connector now updates phoneNumbers.mobile.value when the updateMobilePhoneViaWork attribute is set to true. |
Connectivity - RACF LDAP | CONETN-5311 | Fixed an issue where the RACF LDAP connector created duplicate entitlement objects in Identity Security Cloud after account and group aggregation when attribute values differed only by case. The connector now handles case variations correctly and avoids duplication. |
Connectivity - PeopleSoft Direct | CONETN-5335 | The PeopleSoft Direct connector now supports multi-valued complex attributes, ensuring they appear accurately in the Identity Security Cloud interface. |
Connectivity - Web Services SaaS | CONSEALINK-8507 | The Web Services SaaS connector now correctly processes responses from customized operations configured for the Account Aggregation:after endpoint. |
Connectivity - Google Apps | CONETN-5307 | The Google Workspace connector now correctly clears givenName and familyName attributes during Set or Remove operations by sending a null value, rather than the literal string 'null'. |
Connectivity - Microsoft Entra ID | CONETN-5309 | The Microsoft Entra ID connector now prevents duplicate aggregation of single users during delta aggregation in multi-threaded environments. |