SailPoint Identity Governance & Administration (IGA) Training
Learn identity governance and administration end to end: the identity lifecycle, access requests, roles and RBAC, separation of duties, access certifications, provisioning and audit, then how each is delivered in SailPoint IdentityIQ and Identity Security Cloud.
SailPoint IGA training teaches identity governance and administration as a discipline and on SailPoint's platforms. You learn the identity lifecycle (joiner, mover, leaver), access requests and approvals, role-based access control, separation-of-duties policy, access certifications, provisioning, and audit and compliance reporting, then see how each is delivered in IdentityIQ and Identity Security Cloud. It aligns to SailPoint's free Identity Security Leader credential and sets up the role-based Associate and Administrator paths.
Who this course is for
Prerequisite: No IAM or coding background required. This is the entry point into SailPoint and identity governance.
What makes this different
You build, not just watch
From the first session you are on your own developer instance, configuring, scripting and breaking things safely. That is what makes it stick.
Taught on the current release
No outdated screenshots. Everything maps to the release SailPoint runs today, including current AI and platform features.
One trainer who still implements
One working consultant for the whole batch, no rotation, so the teaching is consistent and grounded in real projects.
Support continues to the offer
Resume review, mock interviews on real scenario questions, and referrals. Support does not stop when the last class ends.

SailPoint Identity Governance & Administration curriculum
9 modules and 3 projects, updated to the current release. Every module maps to real IGA work and expands into its full topic list, practised on a live developer instance.
SailPoint Identity Governance & Administration (IGA) Training module list: 9 modules, what each one covers, and how many topics it expands into. Full topic lists are in the accordions below.
| # | Module | What you configure | Topics |
|---|---|---|---|
| 01 | Identity governance and administration fundamentals | What IGA is and the business problems it solves; Governance versus administration versus broader IAM; The cost of poor access governance: breaches, audit findings, failed controls | 9 |
| 02 | The identity lifecycle (joiner, mover, leaver) | Authoritative sources and HR-driven identity creation; Joiner: onboarding and birthright access; Mover: transfers, promotions and access recalculation | 9 |
| 03 | Access model: entitlements, roles and RBAC | How entitlements are aggregated and owned; Entitlement descriptions and business-friendly naming; Role-based access control (RBAC) explained | 9 |
| 04 | Policies: separation of duties and risk | Separation-of-duties (SoD) concepts; Preventive versus detective controls; Toxic-combination examples across finance and IT | 9 |
| 05 | Access requests and approvals | The access request catalog; The shopping-cart request experience; Cart validation and policy checks at request time | 9 |
| 06 | Access certifications and reviews | Why periodic access reviews matter; Manager, application-owner and role certifications; Targeted and event-based micro-certifications | 9 |
| 07 | Provisioning and fulfilment | The provisioning model and provisioning plans; Connected versus disconnected applications; Provisioning policies and forms | 9 |
| 08 | Audit, compliance and reporting | The audit trail and what is captured; Standard governance reports; Separation-of-duties attestation reporting | 9 |
| 09 | Administering SailPoint and capstone | Administering IdentityIQ versus Identity Security Cloud; Day-two operations and housekeeping; Backup, upgrade and patch awareness | 8 |
1Identity governance and administration fundamentals
- What IGA is and the business problems it solves
- Governance versus administration versus broader IAM
- The cost of poor access governance: breaches, audit findings, failed controls
- Regulatory drivers: SOX, GDPR, HIPAA, ISO 27001
- Core objects: identities, accounts, entitlements, roles
- The identity cube and the single source of truth
- Where SailPoint fits: IdentityIQ versus Identity Security Cloud
- Build versus buy and the IGA vendor landscape
- The IGA maturity model and program goals
2The identity lifecycle (joiner, mover, leaver)
- Authoritative sources and HR-driven identity creation
- Joiner: onboarding and birthright access
- Mover: transfers, promotions and access recalculation
- Leaver: deprovisioning and clean offboarding
- Rehire and leave-of-absence edge cases
- Lifecycle states, events and triggers
- Correlating accounts to identities
- Time-bound, emergency and break-glass access
- Contractors, service and shared accounts
3Access model: entitlements, roles and RBAC
- How entitlements are aggregated and owned
- Entitlement descriptions and business-friendly naming
- Role-based access control (RBAC) explained
- Business roles versus IT / technical roles
- Role mining and top-down versus bottom-up role design
- Birthright versus requestable access
- ABAC and policy-based access alongside RBAC
- Role ownership and governance
- Avoiding role explosion
4Policies: separation of duties and risk
- Separation-of-duties (SoD) concepts
- Preventive versus detective controls
- Toxic-combination examples across finance and IT
- Building SoD policies and rulesets
- Risk scoring of identities and access
- Simulation and what-if before enforcing a policy
- Detecting and handling policy violations
- Mitigating controls and sign-off
- Continuous policy monitoring
5Access requests and approvals
- The access request catalog
- The shopping-cart request experience
- Cart validation and policy checks at request time
- Approval workflows and multi-level approvals
- Automated versus manual fulfilment
- Bulk and on-behalf-of requests
- Delegation and escalation
- Request policies and pre-approval
- Notifications, reminders and SLAs
6Access certifications and reviews
- Why periodic access reviews matter
- Manager, application-owner and role certifications
- Targeted and event-based micro-certifications
- The reviewer experience and bulk decisions
- Reducing rubber-stamping with recommendations
- Revocation and remediation flow
- Closed-loop verification of revocations
- Certification scheduling and reminders
- Producing evidence for auditors
7Provisioning and fulfilment
- The provisioning model and provisioning plans
- Connected versus disconnected applications
- Provisioning policies and forms
- Approval-gated provisioning
- Manual work items and fulfilment
- Retry, error and partial-failure handling
- Fulfilment SLAs and escalation
- Password management and self-service reset
- Troubleshooting provisioning failures
8Audit, compliance and reporting
- The audit trail and what is captured
- Standard governance reports
- Separation-of-duties attestation reporting
- Custom reports and dashboards
- Compliance evidence and attestation
- Continuous compliance monitoring
- Dashboards for identity risk posture
- Metrics and KPIs for an IGA program
- Preparing for an external audit
9Administering SailPoint and capstone
- Administering IdentityIQ versus Identity Security Cloud
- Day-two operations and housekeeping
- Backup, upgrade and patch awareness
- Delegated administration and least privilege
- An end-to-end JML build on a live environment
- Running a certification campaign end to end
- Identity Security Leader credential domains
- Choosing your next path: Associate, Engineer or Administrator
What you'll be able to do
Real projects you'll build
Interview-ready scenarios on a live instance, not toy demos.
Joiner, mover, leaver blueprint
Design and build the full JML lifecycle with birthright access, transfer recalculation and clean offboarding on a live environment.
Access certification campaign
Configure and run a manager certification, make decisions and drive revocations through to remediation.
SoD policy and risk model
Build a separation-of-duties policy with mitigating controls and a simple identity risk model, then handle violations.
Certification and hands-on
Every session runs on a real SailPoint developer instance, so you configure and build rather than watch. The course maps to the Identity Security Leader + IGA foundations exam and finishes with an IT Canvass certificate plus a certification roadmap. IT Canvass does not issue the official SailPoint credential.
The SailPoint program has two tracks. Knowledge Credentials are training-based and unlock an exam: Identity Security Leader (free, product-agnostic foundation), Identity Security Professional, and Identity Security Expert. Role-based Professional Certifications are proctored and recommend real hands-on experience: for on-premise IdentityIQ, Certified IdentityIQ Associate then Certified IdentityIQ Engineer; for cloud Identity Security Cloud, Certified Identity Security Cloud Engineer then Certified Identity Security Cloud Architect. Exams run about US$300 to US$400.
Certification facts. Vendor figures change, so confirm against the official SailPoint catalogue before booking.
| Exam code | SailPoint University does not publish short exam codes; the credential name below is the identifier |
|---|---|
| Credential | SailPoint Identity Security Leader + IGA foundations |
| Issued by | SailPoint Technologies (not by IT Canvass) |
| Exam duration | 120 minutes |
| Exam cost | Bundled with SailPoint University training; priced per learning path |
| Prerequisite | Product training through SailPoint University, plus implementation experience. |
| What IT Canvass issues | An IT Canvass course completion certificate and a certification roadmap |
Your IGA career roadmap
Five stages from your first governance role to program lead, with indicative 2026 bands.
Salary snapshot: IGA Analyst / Administrator
Indicative ranges aggregated from public salary data. Actual pay varies by location, employer and experience.
How IT Canvass compares
Against a typical training provider, this IGA course is taught on the current SailPoint release, gives you your own developer instance from day one, and keeps one working consultant for the whole batch instead of rotating trainers. Every module is mapped to the Identity Security Leader + IGA foundations exam, sessions are recorded with lifetime access, and job support (resume review, mock interviews and referrals) is included in one transparent fee. Most providers still teach older release material, run slide-first sessions with limited lab time, and bill support and recordings as add-ons.
Fees and training modes
Choose how you want to learn IGA. No-cost EMI available on all modes.
Interactive live batches, weekday or weekend, with the full cohort and lifetime recordings.
Private one-on-one coaching at your pace, whether you need interview-ready fast or hands-on help with your current project.
Learn on your own time with recorded sessions, labs and Q&A doubt support.
Train your team on SailPoint Identity Governance & Administration (IGA) Training
Tailored curriculum, flexible scheduling, a dedicated SailPoint architect, and progress reporting for your managers. Delivered live online or on-site for cohorts of any size.
Your trainer
Neelima, SailPoint Architect, 12+ years
I still deliver SailPoint IdentityIQ and Identity Security Cloud implementations for enterprise clients, so I teach from what is breaking in production this quarter, not from a slide deck. In class I show the connector, rule, workflow and certification patterns that scale and the mistakes that cost teams days.
Learner reviews
I came in with zero IAM background and left able to talk lifecycle, roles, SoD and certifications with confidence. The perfect on-ramp.
The JML and certification projects are exactly what my first SailPoint interview covered. I got the role.
Finally understood governance versus administration and how it maps to IIQ and ISC. The best foundations course I have taken.
Fees, batches and policies
The questions people actually ask before enrolling, answered plainly.