IT CanvassTalk to an advisor
How-to guides · LessonReviewed by Imran Q, SailPoint Trainer, 7 yrs · Updated · Published · IdentityIQ 8.4 · all levels

SailPoint Create a policy

Step-by-step: create a separation-of-duties policy in SailPoint IdentityIQ and configure violation handling.

Quick answer

Step-by-step: create a separation-of-duties policy in SailPoint IdentityIQ and configure violation handling.

Key takeaways
  • Pick the policy type (usually SoD)
  • Define the conflicting sides
  • Choose block, exception, or remediate
  • Activate, scan, and review violations

1. Choose policy type

Create a new policy and pick the type, most commonly separation of duties (SoD) to prevent conflicting access.

2. Define the rule

For SoD, define the two conflicting sides as sets of roles or entitlements that no single identity should hold together.

3. Set violation handling

Decide whether violations block requests (preventive), require exception approval, or are flagged for remediation.

4. Activate and test

Activate the policy and run identity refresh or a policy scan, then review the violations it surfaces to confirm it behaves as intended.

Want this with a live instructor and a lab tenant?
SailPoint IdentityIQ training →
Already working on SailPoint and stuck on a live ticket?Get an expert SailPoint developer on screen-share to finish your daily tasks with you. Deliver on time, protect your reputation and your job. Monthly support only, no task-wise plans.Task assigned · no idea where to startStill stuck · your job on the lineExpert joins your screenDelivered on timeExplore On Job Support