Community Announcements

lorrin_minton
Community Manager
Community Manager

Impacted Products: IdentityIQ, File Access Manager, and IdentityNow Cloud Connector Gateway deployments where customers have modified out of the box log4j2 configuration to use a JDBC Appender with a data source referencing a JNDI URI.

SailPoint has analyzed the recently-identified Remote Code Execution (RCE) vulnerability (CVE-2021-44832) and has determined that since SailPoint products, other than instances of IdentityIQ, File Access Manager, and IdentityNow Cloud Connector Gateway where the customer has made certain modifications to the default Log4j configuration, do not use the JDBC Appender and are not impacted by this vulnerability

IdentityIQ, File Access Manager, and IdentityNow Cloud Connector Gateway do not use the JDBC Appender out of the box, however customers have the ability to modify the out of the box appenders in log4j2.properties which might render them susceptible to this vulnerability. As documented in the CVE and guidance from the Apache Logging Services Project, JNDI URIs should not be used in the data source configuration for a JDBC Appender as a mitigation for this vulnerability. 

SailPoint plans to upgrade IdentityIQ, File Access Manager, and IdentityNow Cloud Connector Gateway to Log4J 2.17.1 in January 2022.

Read more
13 0 1,127
lorrin_minton
Community Manager
Community Manager

Impacted Products: IdentityIQ and File Access Manager deployments where customers have modified out of the box log4j2 configuration to allow context lookups

SailPoint has analyzed the recently-identified DoS vulnerability in Log4J (CVE-2021-45105) and has determined that since SailPoint products, other than instances of IdentityIQ and File Access Manager where the customer has made certain modifications discussed in the next sentence, do not allow context lookups, this vulnerability does not impact SailPoint products.

IdentityIQ and File Access Manager do not use context lookups out of the box, however customers have the ability to modify the out of the box pattern layouts in log4j2.properties to use context lookups which might render them susceptible to this vulnerability. As documented in the CVE and guidance from the Apache Logging Services Project, context lookups using the pattern ${ctx: should be removed or replaced with Thread Context Map patterns (%X, %mdc, or %MDC).  

SailPoint plans to upgrade IdentityIQ and File Access Manager to Log4J 2.17.0 in January 2022. 

Read more
11 0 1,625
lorrin_minton
Community Manager
Community Manager

Impacted Products: IdentityIQ and File Access Manager deployments where customers have modified out of the box pattern layouts in log4j2.properties.

SailPoint is aware of the recently-identified DoS vulnerability in Log4J (CVE-2021-45105) and have reviewed the vulnerability information provided by the Apache Logging Services Project. Based on our initial analysis, we do not believe this vulnerability impacts SailPoint products, with the exception of IdentityIQ or File Access Manager customers that have modified the out of the box pattern layouts in log4j2.properties to include the tokens identified in the CVE.

We will continue to analyze this issue and provide further guidance in the next few days.

Read more
9 0 2,074
lorrin_minton
Community Manager
Community Manager

Impacted products: IdentityAI

SailPoint has deployed the latest release of IdentityIQ harvester for IdentityAI which addresses the Log4J Remote Code Execution (RCE) and Denial of Service (DoS) vulnerabilities (CVE-2021-44228CVE-2021-45046) by upgrading to Log4J 2.16.0. No action is needed.

 

Read more
0 0 339
lorrin_minton
Community Manager
Community Manager

Impacted products: IdentityNow, IdentityIQ, File Access Manager, and IdentityAI

SailPoint has addressed the Log4J RCE and DoS vulnerabilities (CVE-2021-44228CVE-2021-45046) by upgrading to Log4J 2.16.0.

IdentityIQ and File Access Manager customers can refer to latest IdentityIQ and File Access Manager blog posts for instructions on how to deploy the latest releases. IdentityIQ harvester is still being upgraded, and we expect the upgrade to be deployed later today (Friday, December 17, Central Time).  We will issue further communications once the updated IdentityIQ harvester has been deployed. 

IdentityNow and IdentityAI have also upgraded to Log4J 2.16.0 and Cloud Connector Gateway (CCG) version 658 has been automatically deployed. For customers who have not received the automatic CCG update, SailPoint customer service is reaching out in order to upgrade those instances.  The CCG version is visible to customer admins in the IdentityNow UI.

Read more
6 0 729
lorrin_minton
Community Manager
Community Manager

Impacted products: IdentityNow, IdentityIQ, File Access Manager, and IdentityAI

SailPoint has mitigated the Log4J RCE vulnerability (CVE-2021-44228) in all impacted products per the recommendations provided by the Apache Logging Services Project. We are aware of newly-released analysis stating that the previously-provided recommendation does not fully mitigate the RCE vulnerability. We are also aware of the recently-identified Log4J DoS vulnerability (CVE-2021-45046) that is applicable to the impacted products.

We are actively working on fully addressing both vulnerabilities by upgrading to Log4J 2.16.0. We expect product releases that include the updated library to be available by the end of day (CST) Friday 12/17/2021.

We will be issuing further communications once new releases are available. No action is needed at this time.

Read more
12 0 1,634
lorrin_minton
Community Manager
Community Manager

Impacted products: IdentityNow, IdentityIQ, File Access Manager, and IdentityAI

SailPoint has fully mitigated the Log4J RCE vulnerability (CVE-2021-44228) in all impacted products.

We are aware of the recently-identified Log4J DoS vulnerability (CVE-2021-45046) that is also applicable to the impacted products. While this new DoS vulnerability has a low severity (CVSS score of 3.7 per NVD), we are actively working on addressing this vulnerability by upgrading to Log4J 2.16.0 and expect product releases that include the updated library to be available in the coming days.

We will be issuing further communications once this issue has been addressed. No action is needed at this time.

Read more
11 0 1,297
lorrin_minton
Community Manager
Community Manager

Impacted products: IdentityNow, IdentityIQ, File Access Manager, and IdentityAI

SailPoint is aware of the recently-identified log4j DoS vulnerability (CVE-2021-45046) that is related to the log4j critical RCE vulnerability (CVE-2021-44228). We are actively investigating the impact of that vulnerability, however preliminary analysis using information provided by the Apache Logging Services project and the CVE project seems to indicate that it is not a critical vulnerability (CVSS score of 3.7). 

We will be issuing further communications on our remediation plans once they become available. No action is needed at this time.

Read more
3 0 986
lorrin_minton
Community Manager
Community Manager

SailPoint has reproduced the recently-identified log4j critical vulnerability (CVE-2021-44228) in IdentityNow and has since released a patch to address this vulnerability. A new version of the Cloud Connector Gateway (CCG) has been also released to address this issue. Customers using CCG version 654 or later are no longer vulnerable and have no further action to take. The CCG version is visible to customer admins in the IdentityNow UI.

Customers should expect contact from SailPoint Support to assist with vulnerability mitigation.

Read more
3 0 711
lorrin_minton
Community Manager
Community Manager

The SailPoint team has identified some issues with the VA's updating properly in certain customer’s environments and is currently working with those customers to ensure the update happens correctly.

Additional information can be located here: https://community.sailpoint.com/t5/SaaS-Updates/IdentityNow-log4j-Remote-Code-Execution-Vulnerabilit...

Read more
0 0 373
lorrin_minton
Community Manager
Community Manager

IdentityIQ

This vulnerability can and should be immediately mitigated by introducing a JVM system property to the application server environment that is hosting IdentityIQ.

Detailed information on action needed can be located here: https://community.sailpoint.com/t5/IdentityIQ-Blog/IdentityIQ-log4j-Remote-Code-Execution-Vulnerabil...

 

File Access Manager

This vulnerability can and should be immediately mitigated by updating the log4j library in the Elasticsearch instance that is part of the File Access Manager deployment as documented in the content for the CVE referenced above.

Detailed information on action needed can be located here: https://community.sailpoint.com/t5/File-Access-Manager-Blog/File-Access-Manager-log4j-Remote-Code-Ex...

Read more
0 0 1,264
lorrin_minton
Community Manager
Community Manager

SailPoint SaaS Services Response to log4j Remote Code Execution Vulnerability

 

The critical vulnerability announced yesterday in the log4j library used in several SailPoint SaaS solutions (IdentityNow and IdentityAI) being tracked by CVE-2021-44228 has been mitigated in all SailPoint SaaS environments. All SailPoint SaaS services are now safe from the log4j exploit. 

 

Read more
10 0 3,605
lorrin_minton
Community Manager
Community Manager

Stay up to date on all the community announcements and updates herehttps://community.sailpoint.com/t5/Community-Announcements/bg-p/community-announcements

 

IdentityNow/IdentityAI:

log4j Remote Code Execution Vulnerability


SailPoint SaaS Services Response to log4j Remote Code Execution Vulnerability

Earlier today, a critical vulnerability in the log4j library used in several SailPoint SaaS solutions (IdentityNow and IdentityAI) was announced and is being tracked by CVE-2021-44228.

SailPoint is actively tracking this vulnerability and has implemented mitigating controls in our SaaS edge services. Teams are actively working to complete additional mitigations and remediations associated with on-premise services. Estimated completion for internal services is tomorrow, Dec 11th.

Cloud Access Manager:

log4j Remote Code Execution Vulnerability

Earlier today, a critical vulnerability in the log4j library was announced and is being tracked by CVE-2021-44228.

SailPoint has investigated this critical severity vulnerability and has determined that the CAM environments, which do not use the log4j library, are not impacted by this vulnerability.

The entire SailPoint team is available to answer any question you may have about this vulnerability. If you have questions, please contact your Customer Success Manager, Engagement Manager, or Partner Manager.

SaaS Management:

log4j Remote Code Execution Vulnerability

Earlier today, a critical vulnerability in the log4j library was announced and is being tracked by CVE-2021-44228.

SailPoint has investigated this critical severity vulnerability and has determined that the SaaS Management environments, which do not use the log4j library, are not impacted by this vulnerability.

The entire SailPoint team is available to answer any question you may have about this vulnerability. If you have questions, please contact your Customer Success Manager, Engagement Manager, or Partner Manager.

Access Risk Management:

log4j Remote Code Execution Vulnerability

Earlier today, a critical vulnerability in the log4j library was announced and is being tracked by CVE-2021-44228.

SailPoint has investigated this critical severity vulnerability and has determined that the ARM environments, which do not use the log4j library, are not impacted by this vulnerability.

The entire SailPoint team is available to answer any question you may have about this vulnerability. If you have questions, please contact your Customer Success Manager, Engagement Manager, or Partner Manager.

Read more
3 0 3,586
lorrin_minton
Community Manager
Community Manager

This issue is now resolved. We have confirmed that all services are operational. Please reach out to SailPoint Support for assistance if you are experiencing any further issues with your tenants.

Read more
0 0 85
lorrin_minton
Community Manager
Community Manager

We are experiencing an issue with our cloud provider disrupting our SaaS services.  We are monitoring the situation and working closely with our cloud provider to recover our services as soon as possible.

Please visit status.sailpoint.com for the latest updates or contact SailPoint support if you have any questions or concerns.

Read more
0 0 155
rose_cobb
SailPoint Employee
SailPoint Employee

SailPoint single access is live! After signing in through single access, click "sign in" on any of the other portals and you will automatically be logged in. Get started today by learning how to sign in for the first time.

The following websites are available through single access, with more to come soon: 

 

If you have any issues, please reach out to the team at login-help@sailpoint.com. Note that the new login does not include your IdentityNow account. Check out the Guide and FAQ for more information.

Read more
10 0 1,783
rose_cobb
SailPoint Employee
SailPoint Employee

Single access to all of SailPoint's websites launches on October 15! There will be downtime on Friday, October 15, from 5 - 11 p.m. Central Standard Time for Compass and Identity University. You will not be able to sign in during the update window, but you can still browse content that does not require signing in.

The following sites will be available through SailPoint single access, with more to come soon:

 

Learn how to sign in for the first time with single access and subscribe to Compass Announcements to receive a notification when the feature goes live. Please note that the new login does not include your IdentityNow account. Check out the Guide and FAQ for more information.

Read more
3 0 634
lorrin_minton
Community Manager
Community Manager

Please join us in welcoming, Skipper, our new automated chat bot! You can find Skipper hanging out at the bottom right-hand side of all pages and is here to provide you yet another way to gain assistance.

Screen Shot 2021-08-17 at 8.46.47 AM.png

Skipper is a little shy at first but the more you interact, the better it gets!

Screen Shot 2021-08-17 at 8.47.44 AM.png

If you have any questions, please reach out to compass-help@sailpoint.com.

Read more
0 0 390
lorrin_minton
Community Manager
Community Manager

The Compass Team will conduct platform maintenance on TODAY, August 16, from 9 - 11 p.m. central standard time. There will be a possible downtime of 30 minutes during this time-frame.

If you encounter any issues with your account after the maintenance window, please try logging out and logging back in. For any errors that don't resolve, reach out to us at compass-help@sailpoint.com for troubleshooting.

Read more
0 0 288
rose_cobb
SailPoint Employee
SailPoint Employee

On July 13, 2021, Microsoft made the following announcement: “Microsoft has detected a 0-day remote code execution exploit being used to attack SolarWinds Serv-U FTP software in limited and targeted attacks. The Microsoft Threat Intelligence Center (MSTIC) attributes this campaign with high confidence to DEV-0322, a group operating out of China, based on observed victimology, tactics, and procedures.”

SailPoint does not use SolarWinds products or services and is not impacted by the vulnerability outlined above. If you have any further questions please reach out to your sales team or Customer Success Manager. If you are not sure who to contact, please send an email to compass-help@sailpoint.com and we will connect you with your representative.

Read more
1 0 448
rose_cobb
SailPoint Employee
SailPoint Employee

Between 800 and 1,500 businesses around the world have been affected by a ransomware attack centered on U.S. information technology firm Kaseya, its chief executive said on Monday.

SailPoint does not use Kaseya’s products or services and is not impacted by the July 2 Supply-Chain Ransomware attack. In addition, our 3rd party Threat Hunting service has confirmed to have found no indication that the activity outlined in the discussed research has affected our organization.

If you have any further questions please reach out to your sales team or Customer Success Manager. If you are not sure who to contact, please send an email to compass-help@sailpoint.com and we will connect you with your representative. 

Read more
4 0 582
meredith_blanchar
SailPoint Employee
SailPoint Employee

Hi All!

 

For the second year in row, SailPoint has received Gartner’s ‘Customers’ Choice’ designation for the Identity Governance & Administration (IGA) market and inclusion in the Voice of the Customer Report for IGA. We’re proud and thrilled to be recognized as a preferred identity security company and wouldn’t be where we are today without you.

 

So, thank you – thank you for your partnership, your dedication to identity security, your drive for innovation and using your voice to share that to those of you that reviewed and rated us. We’re proud to be on this journey with you, testing the limits of what we can achieve together. Your success is our success, and these moments of celebration are a reminder of where we started 15 years ago, and how this community and industry has grown to what it is today.

 

Check out the 2021 ‘Voice of the Customer’ report based on Gartner Peer Insights IGA market reviews. If you want to make sure your voice is heard, leave us a review!

 

Meredith Blanchar

SVP, Customer Success

Read more
4 0 605
rose_cobb
SailPoint Employee
SailPoint Employee

The user interface for private messages has been updated. The new design includes threaded messages for a more streamlined view, and search capabilities so you can search your inbox.

Keep reading for a quick overview about the new version of private messages. 

 

Click Search and type in a query to look through your messages. Select the green pen and paper icon to compose a new message. 

Private Messages v3 005.png

 

Navigate to the Options menu above the search bar to view overall inbox options. 

Private Messages v3 002.png

 

Toggle between Inbox for all messages, and Sent for sent messages, by selecting the dropdown icon on "Inbox".

Private Messages v3 001.png

 

Change how you interact with the sender - Ignore User or Add Friend - by going to the Options menu to next to the trashcan icon. The trashcan icon is to delete messages. 

Private Messages v3 003.png

 

Report messages to a moderator by selecting the options menu within the message and clicking on Report To Moderator

Private Messages v3 004.png

 

The updated How To: Private Messages tutorial is coming soon! In that tutorial we will take a closer look at the features available. If you have any questions, feedback, or errors with the Private Messages interface update please reach out to the team at compass-help@sailpoint.com

Read more
2 0 671
rose_cobb
SailPoint Employee
SailPoint Employee

The updated Compass navigation is now live! The new menu might feel familiar because it uses the same styling from SailPoint's main site.

The links that appear in the menu are dependent on: 

  • Your logged in/ logged out status
  • If you are partner or customer 
  • What type of product you own

 

Compass Menu 001.png


SaaS and software information, as well as downloads and integrations, can be found under the Products tab. 

Compass Menu 002_edited menu.png

 

Resources is where you will find community shortcuts, network opportunities, the customer newsletter and recommended community pages. 

Compass Menu 003.png

 

Under Community is where you go to ask a question in the forum, subscribe to a blog, check out the product wikis, submit an idea and more. 

Compass Menu 004.png

 

Head over to Support for new customer and partner resources, the Support Portal, training through Identity University, developer information and links for partners. 

Compass Menu 005.png

The updated menu incorporates links from the community and other SailPoint websites. We placed icon identifiers next to any outbound link, so you know when you are leaving the community. Note that some of these sites may require that you register or login. 

Compass Menu 006.png

 

The final change is the way messages and notifications appear. A red dot will show next to your profile image when you have a message. Click on your profile to expand the menu, and select the bell for notifications or the envelope for private messages. 

Compass Menu 007-01.png

 


This is a big shift from the previous version! The goal is to make it easier for you to find community pages and links to other SailPoint portals. If you have any questions or feedback, please reach out to the team at compass-help@sailpoint.com

Read more
4 0 739
rose_cobb
SailPoint Employee
SailPoint Employee

The new community search is live! With federated search you can retrieve results from Compass, Identity University, the SaaS document sites and Support Portal.

The new search is capable of:

  • Exact phrase searching
  • Auto-suggestions as you type
  • Serving similar searches for more results
  • Two different views (list and grid)
  • A preview panel that opens within the search results page
  • Granularity through a variety of scoping options

 

Search Page 005.png

 

The new search engine’s algorithm will learn what is relevant and prioritize results over time. Take a closer look at the new search capabilities, and if you have any suggestions or feedback regarding the results please send us a message at compass-help@sailpoint.com.

Read more
3 0 870
meredith_blanchar
SailPoint Employee
SailPoint Employee

Well, we are certainly off to a busy and exciting start to 2021 at SailPoint as I’m reconnecting with each of you to share some more exciting news.

 

Yesterday we closed on another acquisition – this time with a company called ERP Maestro which is a SaaS governance, risk and compliance (GRC) solution. With ERP Maestro, SailPoint will unite identity security with ERP Maestro’s Separation-of-Duty (SoD) controls monitoring for your organizations’ most critical applications, like SAP. This will provide an integrated approach for effective identity security controls and SoD oversight.  This type of oversight is critical spot and stop risks posed by potential insider SoD conflicts before they become a crisis of fraud or breach of sensitive data.

 

ERP Maestro brings an experienced team with a rich heritage in ERP-focused audit and compliance.  Tapping their deep domain expertise combined with our comprehensive approach to managing and securing workforce access across all critical business systems and applications makes for a natural pairing, one that will help to shut down the siloed approach that many companies typically find themselves in – managing SoD monitoring and controls for sensitive business systems separately from their identity security program. By uniting the two, we’ll soon be able to help you reduce and eliminate gaps in visibility across the entirety of your workers’ access needs across all applications and data.

 

We’ll be sharing much more about this product and our integration approach in the coming weeks, but for now you can find more information in this press release.

 

We look forward to bringing new value to you through this acquisition as well as the recent acquisition of Intello as we help you continue to navigate your identity journey with SailPoint.

 

Take care,

 

Meredith

SVP, Customer Success

Read more
1 0 831
rose_cobb
SailPoint Employee
SailPoint Employee

Search is about to get a major update. Based on your feedback we are implementing a new search page and more features to help you find what you’re looking for.

With federated search you will be able to find content from SailPoint’s ecosystem for customers and partners. At launch that will include the Community, Identity University, the document web pages and Support Portal - with more sites to be added soon.

 

Search Features:

  • Auto-suggestions of content as you search.
  • Multiple ways to filter results into areas that are relevant to you. That includes the ability to filter by labels and tags!
  • Preview panel to show you the page without having to click the link.
  • Advanced options like search with exact phrase.  
  • List and grid views.
  • An improved algorithm that learns what is relevant and prioritizes results over time.

 

You may notice some small menu changes as well. We are exposing more sub-categories and boards in the navigational structure as we work on updates. The team is transitioning to a new menu arrangement that will highlight key sections and pages of the community. Make sure you are subscribed to the Community Announcements blog! A separate post will go out the closer we get to launching the new menu. 

We want to hear from you! If you have any questions about this update please reach out at compass-help@sailpoint.com.

Read more
0 0 754
rose_cobb
SailPoint Employee
SailPoint Employee

Delivering on our vision to embed identity into the cloud enterprise’s digital fabric, SailPoint announced additional extensibility functionality to our platform. SailPoint also introduced the new SailPoint Developer Community to help developers move quickly and with less effort.

 

The new extensibility features, coupled with the SailPoint Developer Community, enables you to infuse the SailPoint Identity platform’s core functionalities within your workflows, reducing integration development from months to days or even hours. This allows the opportunity to make identity security decisions with greater ease, creating workflows that fit within your company’s existing business processes and infrastructure. For example, when an identity change occurs, administrators are automatically notified via a collaboration tool like Slack or Microsoft Teams to take action. There is no longer a need to schedule frequent reviews in other systems to identify and make important identity decisions as workforce access needs evolve to meet business demands.

 

For additional information on this exciting news, please see the following press release and blog.

Read more
0 0 954
meredith_blanchar
SailPoint Employee
SailPoint Employee

As we kick-off 2021, I have some exciting news to share from SailPoint! 

 

Today we closed on an exciting acquisition of Intello, a SaaS application management platform that helps customers get their arms around the massive amount of SaaS app sprawl happening across businesses. With Intello, our customers can easily discover and manage all of their SaaS applications, even uncovering those outside of IT’s purview.

 

This acquisition addresses a major security challenge for businesses that has become increasingly more complex and impactful with this massive shift to remote working. The notion of “Shadow Access,” or the growing lack of visibility into what SaaS apps exist across the business and who, or what, has access to them, represents a major area of risk to most businesses today.

 

With Intello, we’ll soon be able to help you quickly discover, control access, track usage, and enforce security policies for all SaaS applications across your business. Intello is complementary to our already robust suite of products and once fully integrated, will provide you with a seamless process of discovery through governance of all of SaaS applications in your ecosystem.

 

We’ll be sharing much more about this product and our integration approach in the coming weeks, but for now you can find more information in this press release.

 

This is a very exciting acquisition for us and one that furthers our commitment of enabling our customers to protect their businesses at scale. 

 

As always, thank you for being our valued customer.

 

Take care,

Meredith Blanchar

SVP, Customer Success

Read more
0 0 797
rose_cobb
SailPoint Employee
SailPoint Employee

We are excited to announce that the new portal for ideas and voting goes live Friday, February 12.

The team is currently at work moving forum topics with the idea tag into the current idea exchange and preparing posts to migrate to the new portal. Ideas will still be attributed to the original submitter; however, followers will need to re-subscribe to their saved ideas after the migration.

 

Idea Portal features include:

  • Search and vote for an existing idea or add your own.
  • Subscribe to an idea and receive a notification when the status changes.
  • Quick response times from the SailPoint team.
  • Enhanced transparency. Not all ideas will be selected for development but all ideas will be responded to with a status update and comments.

 

Keep an eye on your inbox! Later this week Compass users will receive an invitation for the new portal. Please note that this is a separate portal, it is not a part of Compass. Users who do not receive an invitation can still register by visiting the portal after it goes live.

 

For questions about the Idea Portal contact idea-help@sailpoint.com

Read more
4 0 1,175