Skip to Content

September 2025

30 September 2025 by
September 2025
Kiran Seehra
Brought to you by Third Wave Identity

🔐 SailPoint ISC – September 2025 Highlights

Machine Identity Subtypes & Ownership

SailPoint ISC now supports application identity subtypes under machine identities, along with multiple owner assignments to reduce orphaned accounts and improve succession planning.

Execute PowerShell Scripts in Workflows

Admins can now securely execute PowerShell scripts in Windows Server actions within ISC Workflows — without requiring standing admin rights.

Access Intelligence Center: Data Model Expansion

The AIC now visualizes entitlement, role, and profile relationships — improving access governance transparency and oversight.

Simplifying PTA with Parameter Storage

ISC now allows credential/config storage directly within workflows — starting with AD/Windows Server integrations — eliminating the need for a credential provider.

🔐 CyberArk – September 2025 Highlights

CA25-31 Security Bulletin

CyberArk disclosed a high-severity vulnerability in Secrets Manager – Self-Hosted (Conjur Enterprise), potentially enabling remote code execution. Patch versions 13.5.3 and 13.6.3 have been released.

Certification Policy Update – In-Person Exams

Effective 1st November 2025, all Defender, Sentry, Guardian, and CDE certifications must be taken in-person at PearsonVue. Virtual exams only allowed until 31 October.

CyberArk Leadership Update

Omer Grossman is now Chief Trust Officer & Head of CYBR Unit; Ariel Pisetzky is named CIO. This marks a strategic move to strengthen global trust and leadership.

GigaOm Radar Recognition

CyberArk was named a Leader & Outperformer for enterprise password management, praised for SSO/MFA integration, session security, and risk-based access.

🌐 StrongDM – September 2025 Highlights

Custom TCP for Kubernetes

StrongDM now supports secure proxying to internal Kubernetes workloads via Custom TCP, enabling access to private endpoints and non-standard ports.

Expanded Terraform Support

Terraform can now manage grants for more resource types like Kubernetes and SSH. This enhances automation and RBAC enforcement at scale.

Credential Injection Audit-Only Mode

Credential injection now includes an "Audit-Only" mode for logging access events without executing actions — ideal for dry runs and policy validation.

Strong Vault – Auto Expiry for Certificates

Strong Vault can now set expiry dates on TLS certs, with automated rotation or alerting on expiry — reducing risk from forgotten credentials.

Start writing here...

September 2025
Kiran Seehra 30 September 2025
Share this post
Archive