Policy management
Quick answer
Configuring SoD, account and activity policies in SailPoint IdentityIQ, and how violations are detected and handled.
Key takeaways
- SoD, account, activity, risk and advanced policies
- SoD prevents toxic access combinations
- Evaluated at refresh, request and certification
- Violations block, require exceptions, or are remediated
Policy types
IdentityIQ supports separation-of-duties (SoD), account, activity, risk and advanced policies. SoD is the most common, preventing toxic combinations of access.
SoD policies
An SoD policy defines conflicting entitlements or roles. When an identity holds both sides, a violation is raised for review or remediation.
Detection
Policies are evaluated during identity refresh, access request (preventive) and certification, so violations surface both before and after access is granted.
Handling violations
Violations can block a request, require an exception approval, or be remediated by revoking access, all recorded for audit.
Want to learn this properly?
Our live, instructor-led SailPoint Training covers this hands-on, with real projects and a certification path.
Check your understanding
What does an SoD policy prevent?
- A. Slow aggregation
- B. Toxic combinations of access
- C. Connector timeouts
- D. Duplicate identities
Show answer
B. Toxic combinations of access
Separation-of-duties policies stop an identity holding conflicting access.