How-to guides · LessonBy Imran Q, SailPoint Trainer, 7 yrs · Published · IdentityIQ 8.4 · all levels
Create a policy
Step-by-step: create a separation-of-duties policy in SailPoint IdentityIQ and configure violation handling.
Quick answer
Step-by-step: create a separation-of-duties policy in SailPoint IdentityIQ and configure violation handling.
Key takeaways
- Pick the policy type (usually SoD)
- Define the conflicting sides
- Choose block, exception, or remediate
- Activate, scan, and review violations
1. Choose policy type
Create a new policy and pick the type, most commonly separation of duties (SoD) to prevent conflicting access.
2. Define the rule
For SoD, define the two conflicting sides as sets of roles or entitlements that no single identity should hold together.
3. Set violation handling
Decide whether violations block requests (preventive), require exception approval, or are flagged for remediation.
4. Activate and test
Activate the policy and run identity refresh or a policy scan, then review the violations it surfaces to confirm it behaves as intended.
Practice challenge
+0 XPStreak ×0
Question 1 of 1
What defines an SoD policy?
Frequently asked questions
What does the term How to Create a Policy in SailPoint refer to in SailPoint?
Create a new policy and pick the type, most commonly separation of duties (SoD) to prevent conflicting access.
What is worth remembering about How to Create a Policy in SailPoint in practice?
For SoD, define the two conflicting sides as sets of roles or entitlements that no single identity should hold together.
What is another point to note about How to Create a Policy in SailPoint?
Decide whether violations block requests (preventive), require exception approval, or are flagged for remediation.
Want this with a live instructor and a lab tenant?