This was changed a long time ago.
You should NOT add security provider inside SA anymore.
Just use the security identity step. Add it after the security restrict step.
Or, you can also just move it to Globals.
Click on the Globals node, and add security identity as a step. Then it will be available as you expect in point 4.
Although this will show up everywhere, it does not cause any issues on non-secure SA.