Administration
Quick answer
Administering IdentityIQ means configuring applications and their schemas, managing identities and capabilities (the IdentityIQ equivalent of roles for the tool itself), scheduling tasks like aggregation and refresh, and using the console and debug pages to inspect objects.
Key takeaways
- Configure applications, schemas and correlation
- Manage identities, capabilities and scopes
- Schedule tasks: aggregation, refresh, certifications
- Use the iiq console and debug pages to inspect objects
- Control access to IdentityIQ itself with capabilities
Administration covers the day-to-day running of SailPoint, the tasks, monitoring, configuration and housekeeping that keep governance flowing reliably. It is less glamorous than design but is where a deployment either stays healthy or quietly degrades.
What administrators do
- Schedule and monitor tasks, aggregation, refresh, certification generation.
- Watch task results and act on failures before they compound.
- Manage sources/applications, connectors and their credentials.
- Configure system settings, capabilities, scopes and notifications.
- Maintain data quality, correlation, orphan accounts, stale identities.
Operational rhythm
A healthy deployment runs a predictable cadence: authoritative aggregation, target aggregation, identity refresh, then governance activities, all on schedule and monitored. Administration is largely about keeping this rhythm reliable and catching deviations early.
Monitoring and hygiene
The most valuable administrative habit is watching task results and key metrics (account counts, orphan counts, failed provisioning) so problems are caught while small. Combined with good backup, capacity and certificate management, this is what keeps governance trustworthy.
Common pitfalls
- Ignoring task-result errors until they cascade.
- Letting orphan accounts and stale data accumulate.
- No monitoring of the operational rhythm.
Want to learn this properly?
Our live, instructor-led SailPoint Training covers this hands-on, with real projects and a certification path.
Check your understanding
In IdentityIQ, what a user can do inside the tool is controlled by?
- A. Debug pages / console. Debug pages and the iiq console show objects as XML.
- B. Scheduled tasks. They are tasks run on the IdentityIQ scheduler.
- C. Capabilities. Capabilities define a user's rights within IdentityIQ itself.
Show answer
C. Capabilities. Capabilities define a user's rights within IdentityIQ itself.
Capabilities. Capabilities define a user's rights within IdentityIQ itself.
Aggregation and refresh are run as?
- A. Scheduled tasks. They are tasks run on the IdentityIQ scheduler.
- B. Debug pages / console. Debug pages and the iiq console show objects as XML.
- C. Capabilities. Capabilities define a user's rights within IdentityIQ itself.
Show answer
A. Scheduled tasks. They are tasks run on the IdentityIQ scheduler.
Scheduled tasks. They are tasks run on the IdentityIQ scheduler.
Objects can be inspected as XML using the?
- A. Debug pages / console. Debug pages and the iiq console show objects as XML.
- B. Capabilities. Capabilities define a user's rights within IdentityIQ itself.
- C. Scheduled tasks. They are tasks run on the IdentityIQ scheduler.
Show answer
A. Debug pages / console. Debug pages and the iiq console show objects as XML.
Debug pages / console. Debug pages and the iiq console show objects as XML.