IT CanvassTalk to an advisor
Connectors · LessonBy , SailPoint Trainer, 7 yrs · Published · IdentityIQ 8.4 · intermediate

Active Directory

How IdentityIQ integrates with Active Directory to aggregate accounts and groups and provision access through IQService.

Quick answer

The Active Directory connector lets IdentityIQ read AD users and groups (aggregation) and create, modify, enable, disable and delete accounts (provisioning). Because AD is a Windows service, IdentityIQ reaches it through IQService, a small agent installed near the domain.

Key takeaways
  • Reads AD users and groups; provisions account changes
  • Requires IQService, the Windows agent
  • Correlates AD accounts to cubes on a stable attribute
  • memberOf drives group (entitlement) membership
  • Most first failures are IQService or service-account issues

Active Directory is almost always the first and most important target in a SailPoint deployment, because so much other access depends on AD accounts and group membership. Governing AD cleanly, correct correlation and automated account and group lifecycle, is foundational to the whole programme.

Connector type and how it connects

The Active Directory integration is a directory connector. It connects to AD over LDAP/LDAPS (and uses the appropriate APIs for password and group operations) with a service account. As with every connector, the flow is the same: authenticate to Active Directory, read accounts and entitlements during aggregation, and write changes during provisioning.

Onboarding the source

  • 1. Configure the connection and credentials for Active Directory.
  • 2. Map the account schema, mapping AD account attributes (such as sAMAccountName, userPrincipalName) and memberOf group memberships to SailPoint accounts and entitlements.
  • 3. Set the correlation logic so Active Directory accounts attach to the right identities (typically on a stable key such as employee ID or email).
  • 4. Run account aggregation and confirm accounts and entitlements load.
  • 5. Verify correlation, watching for uncorrelated/orphan accounts.

Provisioning capabilities

SailPoint can create, modify, enable and disable AD accounts and add or remove group memberships, driven by birthright roles, requests and lifecycle events. Immediate disable on leaver is a critical control.

Entitlements and what to govern

AD group memberships are the entitlements to govern; model important groups as roles or Managed Attributes with owners and descriptions so certifications are meaningful.

Troubleshooting

When Active Directory aggregation or provisioning fails, work through the usual causes in order:

  • Verify the service account bind and LDAPS trust.
  • Confirm the service account has rights to manage the OUs, accounts and groups in scope.
  • Check network/port access (389/636) to domain controllers.
  • Validate the search base, correlation key and group membership mapping.

Common pitfalls

  • Credential expiry (tokens/secrets/certs) silently breaking the connector.
  • Insufficient rights on the Active Directory service account for the operations you need.
  • Schema or correlation misconfiguration leaving accounts uncorrelated.

Practice challenge

+0 XPStreak ×0
Question 1 of 3
IdentityIQ reaches Active Directory through?

Frequently asked questions

What does the term Active Directory connector refer to in SailPoint?
Active Directory is almost always the first and most important target in a SailPoint deployment, because so much other access depends on AD accounts and group membership. Governing AD cleanly, correct correlation and automated account and group lifecycle, is foundational to the whole programme.
What else is worth knowing about Active Directory connector?
The Active Directory integration is a directory connector. It connects to AD over LDAP/LDAPS (and uses the appropriate APIs for password and group operations) with a service account.
What is the practical takeaway on Active Directory connector?
As with every connector, the flow is the same: authenticate to Active Directory, read accounts and entitlements during aggregation, and write changes during provisioning.
What tends to go wrong with Active Directory connector?
Credential expiry (tokens/secrets/certs) silently breaking the connector. Insufficient rights on the Active Directory service account for the operations you need. Schema or correlation misconfiguration leaving accounts uncorrelated.
Want this with a live instructor and a lab tenant?
SailPoint IdentityIQ training →
Already working on SailPoint and stuck on a live ticket?Get an expert SailPoint developer on screen-share to finish your daily tasks with you. Deliver on time, protect your reputation and your job. Monthly support only, no task-wise plans.Task assigned · no idea where to startStill stuck · your job on the lineExpert joins your screenDelivered on timeExplore On Job Support