Skip to content

KC-1441: Restrict SailPoint integration to documented capabilities only - #2338

Merged
craiglurey merged 1 commit into
releasefrom
fix/sailpoint-security-remediation
Sep 1, 2026
Merged

KC-1441: Restrict SailPoint integration to documented capabilities only#2338
craiglurey merged 1 commit into
releasefrom
fix/sailpoint-security-remediation

Conversation

@amangalampalli-ks

Copy link
Copy Markdown
Contributor

Restrict SailPoint integration to documented capabilities only

Summary

Closes security findings where SailPoint integration key could perform undocumented dangerous operations beyond what setup toggles advertise. Integration now enforces least-privilege: only documented operations are allowed.

Changes

  • Remove enterprise-role — Unused by the integration; eliminates privilege escalation vector
  • Restrict enterprise-user — Block --disable-2fa and --expire flags (security policy mutations)
  • Prevent ownership transfer — Block --action owner in share-record and nsf-share-record

…ly (#2333)

* Restrict SailPoint integration to documented capabilities only

* Add er to ban list for existing installs
@amangalampalli-ks amangalampalli-ks self-assigned this Sep 1, 2026
@amangalampalli-ks
amangalampalli-ks marked this pull request as ready for review September 1, 2026 06:19
@craiglurey
craiglurey merged commit c350791 into release Sep 1, 2026
4 checks passed
@sk-keeper
sk-keeper deleted the fix/sailpoint-security-remediation branch September 1, 2026 15:49
sk-keeper pushed a commit that referenced this pull request Sep 2, 2026
…ly (#2333) (#2338)

* Restrict SailPoint integration to documented capabilities only

* Add er to ban list for existing installs
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants