How-to guides · LessonReviewed by Imran Q, SailPoint Trainer, 7 yrs · Updated · Published · IdentityIQ 8.4 · all levels
SailPoint Create a policy
Step-by-step: create a separation-of-duties policy in SailPoint IdentityIQ and configure violation handling.
Quick answer
Step-by-step: create a separation-of-duties policy in SailPoint IdentityIQ and configure violation handling.
Key takeaways
- Pick the policy type (usually SoD)
- Define the conflicting sides
- Choose block, exception, or remediate
- Activate, scan, and review violations
1. Choose policy type
Create a new policy and pick the type, most commonly separation of duties (SoD) to prevent conflicting access.
2. Define the rule
For SoD, define the two conflicting sides as sets of roles or entitlements that no single identity should hold together.
3. Set violation handling
Decide whether violations block requests (preventive), require exception approval, or are flagged for remediation.
4. Activate and test
Activate the policy and run identity refresh or a policy scan, then review the violations it surfaces to confirm it behaves as intended.
Want this with a live instructor and a lab tenant?