IT CanvassTalk to an advisor
Administration · LessonReviewed by Imran Q, SailPoint Trainer, 7 yrs · Updated · Published · IdentityIQ 8.4 · all levels

SailPoint Policy management

Configuring SoD, account and activity policies in SailPoint IdentityIQ, and how violations are detected and handled.

Quick answer

Configuring SoD, account and activity policies in SailPoint IdentityIQ, and how violations are detected and handled.

Key takeaways
  • SoD prevents toxic access combinations
  • Evaluated at refresh, request and certification
  • Violations block, require exceptions, or are remediated

Policy types

IdentityIQ supports separation-of-duties (SoD), account, activity, risk and advanced policies. SoD is the most common, preventing toxic combinations of access.

SoD policies

An SoD policy defines conflicting entitlements or roles. When an identity holds both sides, a violation is raised for review or remediation.

Detection

Policies are evaluated during identity refresh, access request (preventive) and certification, so violations surface both before and after access is granted.

Handling violations

Violations can block a request, require an exception approval, or be remediated by revoking access, all recorded for audit.

Want this with a live instructor and a lab tenant?
SailPoint IdentityIQ training →
Already working on SailPoint and stuck on a live ticket?Get an expert SailPoint developer on screen-share to finish your daily tasks with you. Deliver on time, protect your reputation and your job. Monthly support only, no task-wise plans.Task assigned · no idea where to startStill stuck · your job on the lineExpert joins your screenDelivered on timeExplore On Job Support