SailPoint is a leading Identity Governance and Administration (IGA) solution that automates user provisioning, access control, compliance, and lifecycle management. It helps enterprises ensure “the right people have the right access to the right resources at the right time.”
SailPoint offers two major products:
IdentityNow – SaaS-based identity governance (cloud)
IdentityIQ (IIQ) – On-premises identity governance solution
Used by organizations globally for SOX compliance, zero trust architecture, and automated access reviews, SailPoint is a critical tool in modern enterprise security.
High-demand IAM tool in banking, healthcare, telecom
Supports automated provisioning/de-provisioning
Integrates with Active Directory, Workday, SAP, Azure, AWS
Reduces compliance risks
High-paying roles: IAM Analyst, SailPoint Engineer, Identity Architect
Connector Layer: Connects to external systems (e.g., AD, Azure, Salesforce)
IdentityNow Core: Manages governance, certifications, approvals
UI/API Layer: Web interface and REST APIs
Data Layer: Stores user identity data, entitlements, roles
Java-based platform deployed on Apache Tomcat
Uses relational databases (Oracle, MySQL, SQL Server)
Custom workflows and tasks via XML, BeanShell scripting
SOAP/REST APIs for integration
Term | Description |
---|---|
Identity Cube | Core user object representing a user’s access and attributes |
Entitlements | Specific access rights or permissions within an application |
Authoritative Source | Primary system for user data (e.g., HR, Workday) |
Connector | Integration method to external applications |
Certification | Access review process |
Policy Violation | Breach of defined access control policy |
Role | A group of entitlements mapped to a user’s job function |
Lifecycle Events | Joiner, mover, leaver scenarios |
Define source of truth (e.g., Workday, AD)
Configure identity attributes like email
, employeeType
, location
Map these to identity schema
Connect to authoritative sources (LDAP, HRMS)
Use out-of-the-box connectors or build custom using SailPoint IdentityNow IdentityNow Connector SDK
Pull user accounts from connected systems
Reconcile attributes (email, title, department)
IdentityNow builds identity cubes
Define rules for account creation, update, disable
Trigger provisioning events for:
New hires (Joiners)
Transfers (Movers)
Resignations (Leavers)
Users request access via IdentityNow Portal
Access governed by policies, manager approvals
Automated or manual provisioning based on role/entitlement
Periodic reviews of user access by managers or app owners
Ensure least privilege and compliance
Types of certifications:
Manager Certification
Application Owner Certification
Role Certification
Event | Action Taken |
---|---|
Joiner | Provision new accounts and entitlements |
Mover | Modify access based on role or department change |
Leaver | Revoke access and disable accounts |
Workflows are configured to automate these processes and reduce human error.
SailPoint allows you to define and enforce policies:
Separation of Duties (SoD): Prevent conflicting roles (e.g., create + approve invoice)
Password Policies: Enforce strength and reset frequency
Access Reviews: Detect orphan accounts and over-provisioned users
Handles user account creation and deactivation across systems.
Certifications with electronic sign-off for audit tracking.
Suggests roles based on access patterns (role suggestion engine).
Tracks policy violations, audit logs, and remediation steps.
Use Case: Automate provisioning for a new employee
HR adds a new hire in Workday
SailPoint aggregates identity from Workday
Based on job title/location, assigns role
Automatically provisions:
AD account
Office 365 mailbox
SAP access
Sends welcome email + access summary
Starts 30-day certification workflow
Application | Connector Type |
---|---|
Active Directory | Standard Connector |
Azure AD | Cloud Connector |
SAP | SAP GRC Connector |
ServiceNow | REST API Connector |
Workday | Authoritative Source |
Salesforce | OAuth2 API |
Rules extend platform behavior using BeanShell:
Pre-provisioning Rule: Modify data before provisioning
Correlation Rule: Match accounts to identities
Policy Rule: Define custom SoD logic
BuildMap Rule: Format attribute mapping for target app
Feature | IdentityNow (Cloud) | IdentityIQ (On-prem) |
---|---|---|
Deployment | SaaS | Customer-managed |
Customization | Limited | Highly customizable |
Updates | Automatic (cloud) | Manual patching |
Cost | Subscription-based | License + infra cost |
Suitable for | Cloud-first orgs | Enterprises with strict compliance |
Use roles for entitlement bundling
Implement access request policies with approval workflows
Automate certifications quarterly
Regularly review SoD violations
Integrate with SIEM tools for audit trails
Configure real-time alerts for risky access assignments
What is IdentityNow? How is it different from IdentityIQ?
Explain identity cube.
What are access certifications and how are they triggered?
What is SoD and how is it enforced in SailPoint?
How does SailPoint handle lifecycle events?
What is a correlation rule?
How do you onboard a new application into SailPoint?
Explain Joiner-Mover-Leaver automation.
What are provisioning policies in IdentityIQ?
How do you integrate SailPoint with Active Directory?
Also Read: SailPoint Interview Questions
IAM Analysts
IT Security Engineers
Identity Architects
DevOps & Cloud Engineers
Compliance Officers
SailPoint Administrators
Role | Responsibilities |
---|---|
SailPoint Developer | Build workflows, rules, and connectors |
IAM Analyst | Design IAM policies and lifecycle |
SailPoint Architect | Define IAM strategy and integration design |
IAM Admin | Monitor and manage IAM environment |
Compliance Manager | Handle access reviews and audit trails |
Java/BeanShell scripting
REST/SOAP API integration
LDAP/AD knowledge
SQL for reporting
IdentityNow CLI or APIs
Azure/AWS IAM (for hybrid cloud setups)
SailPoint is a critical tool in enterprise IAM ecosystems, enabling governed access, automated provisioning, and compliance reporting. Whether you’re targeting IdentityNow (cloud) or IdentityIQ (on-prem), mastering SailPoint positions you for high-paying roles in cybersecurity, GRC, and cloud access control.
eLearnCourses is a trusted destination for high-quality, industry-relevant online IT training. We are committed to empowering learners and professionals with the practical skills and knowledge they need to succeed in the digital era.
Training Delivered In Cities/Countries: Hyderabad, Bangalore, Mumbai, Delhi, Chennai, Pune, Texas, California, New Jersey, Virginia, London, Dubai (UAE), Toronto, Melbourne, Sydney, Singapore, and many more.
Powered by eLearnCourses. All rights reserved.