Create a policy
Quick answer
Step-by-step: create a separation-of-duties policy in SailPoint IdentityIQ and configure violation handling.
Key takeaways
- Pick the policy type (usually SoD)
- Define the conflicting sides
- Choose block, exception, or remediate
- Activate, scan, and review violations
1. Choose policy type
Create a new policy and pick the type, most commonly separation of duties (SoD) to prevent conflicting access.
2. Define the rule
For SoD, define the two conflicting sides as sets of roles or entitlements that no single identity should hold together.
3. Set violation handling
Decide whether violations block requests (preventive), require exception approval, or are flagged for remediation.
4. Activate and test
Activate the policy and run identity refresh or a policy scan, then review the violations it surfaces to confirm it behaves as intended.
Want to learn this properly?
Our live, instructor-led SailPoint Training covers this hands-on, with real projects and a certification path.
Check your understanding
What defines an SoD policy?
- A. A single entitlement
- B. Two conflicting sets that should not be held together
- C. A connector
- D. A report
Show answer
B. Two conflicting sets that should not be held together
SoD policies define conflicting sides no single identity should hold together.