SailPoint Identity Governance & Administration (IGA) Training
SailPoint IGA training teaches identity governance and administration as a discipline and on SailPoint's platforms.
What you get
- Explain identity governance and administration end to end
- Design the joiner, mover and leaver lifecycle
- Model roles and RBAC and control role explosion
- Write separation-of-duties and risk policies
Who this course is for
Great fit if you are new
Great fit if you are working
Prerequisites
- No IAM or coding background required.
- This is the entry point into SailPoint and identity governance.
What you will be able to do
- Explain identity governance and administration end to end
- Design the joiner, mover and leaver lifecycle
- Model roles and RBAC and control role explosion
- Write separation-of-duties and risk policies
- Configure access requests, approvals and provisioning
- Run access certifications and produce audit evidence
- Administer SailPoint and choose your certification path
Salary range
- India
- 5-14 LPA
- United States
- 80k-120k
Market ranges for IGA Analyst / Administrator, not a guarantee. Actual pay depends on experience, location and employer.
Curriculum
Identity governance and administration fundamentals
9 topics
Set the vocabulary and the business case for IGA before you touch a product, so every later module has context.
- What IGA is and the business problems it solves
- Governance versus administration versus broader IAM
- The cost of poor access governance: breaches, audit findings, failed controls
- Regulatory drivers: SOX, GDPR, HIPAA, ISO 27001
- Core objects: identities, accounts, entitlements, roles
- The identity cube and the single source of truth
- Where SailPoint fits: IdentityIQ versus Identity Security Cloud
- Build versus buy and the IGA vendor landscape
- The IGA maturity model and program goals
The identity lifecycle (joiner, mover, leaver)
9 topics
Follow a worker from hire to exit and see exactly what identity governance must automate at each step.
- Authoritative sources and HR-driven identity creation
- Joiner: onboarding and birthright access
- Mover: transfers, promotions and access recalculation
- Leaver: deprovisioning and clean offboarding
- Rehire and leave-of-absence edge cases
- Lifecycle states, events and triggers
- Correlating accounts to identities
- Time-bound, emergency and break-glass access
- Contractors, service and shared accounts
Access model: entitlements, roles and RBAC
9 topics
Turn thousands of raw entitlements into a role model people can actually request and govern.
- How entitlements are aggregated and owned
- Entitlement descriptions and business-friendly naming
- Role-based access control (RBAC) explained
- Business roles versus IT / technical roles
- Role mining and top-down versus bottom-up role design
- Birthright versus requestable access
- ABAC and policy-based access alongside RBAC
- Role ownership and governance
- Avoiding role explosion
Policies: separation of duties and risk
9 topics
Encode the controls auditors care about and decide what to block, detect and mitigate.
- Separation-of-duties (SoD) concepts
- Preventive versus detective controls
- Toxic-combination examples across finance and IT
- Building SoD policies and rulesets
- Risk scoring of identities and access
- Simulation and what-if before enforcing a policy
- Detecting and handling policy violations
- Mitigating controls and sign-off
- Continuous policy monitoring
Access requests and approvals
9 topics
Design the self-service experience that replaces email and ticket-driven access.
- The access request catalog
- The shopping-cart request experience
- Cart validation and policy checks at request time
- Approval workflows and multi-level approvals
- Automated versus manual fulfilment
- Bulk and on-behalf-of requests
- Delegation and escalation
- Request policies and pre-approval
- Notifications, reminders and SLAs
Access certifications and reviews
9 topics
Run the periodic reviews that prove access is still appropriate, without reviewer fatigue.
- Why periodic access reviews matter
- Manager, application-owner and role certifications
- Targeted and event-based micro-certifications
- The reviewer experience and bulk decisions
- Reducing rubber-stamping with recommendations
- Revocation and remediation flow
- Closed-loop verification of revocations
- Certification scheduling and reminders
- Producing evidence for auditors
Provisioning and fulfilment
9 topics
Connect governance decisions to real accounts across connected and manual systems.
- The provisioning model and provisioning plans
- Connected versus disconnected applications
- Provisioning policies and forms
- Approval-gated provisioning
- Manual work items and fulfilment
- Retry, error and partial-failure handling
- Fulfilment SLAs and escalation
- Password management and self-service reset
- Troubleshooting provisioning failures
Audit, compliance and reporting
9 topics
Produce the evidence and metrics that keep auditors and leadership satisfied.
- The audit trail and what is captured
- Standard governance reports
- Separation-of-duties attestation reporting
- Custom reports and dashboards
- Compliance evidence and attestation
- Continuous compliance monitoring
- Dashboards for identity risk posture
- Metrics and KPIs for an IGA program
- Preparing for an external audit
Administering SailPoint and capstone
8 topics
Operate the platform day to day, then pull the whole course together in a live end-to-end build.
- Administering IdentityIQ versus Identity Security Cloud
- Day-two operations and housekeeping
- Backup, upgrade and patch awareness
- Delegated administration and least privilege
- An end-to-end JML build on a live environment
- Running a certification campaign end to end
- Identity Security Leader credential domains
- Choosing your next path: Associate, Engineer or Administrator
Projects you will build
Joiner, mover, leaver blueprint
Design and build the full JML lifecycle with birthright access, transfer recalculation and clean offboarding on a live environment.
Access certification campaign
Configure and run a manager certification, make decisions and drive revocations through to remediation.
SoD policy and risk model
Build a separation-of-duties policy with mitigating controls and a simple identity risk model, then handle violations.
Certification
- Code
- Identity Security Leader + IGA foundations
- Exam fee
- Free (Leader credential)
What learners say
I came in with zero IAM background and left able to talk lifecycle, roles, SoD and certifications with confidence. The perfect on-ramp.
The JML and certification projects are exactly what my first SailPoint interview covered. I got the role.
Finally understood governance versus administration and how it maps to IIQ and ISC. The best foundations course I have taken.
Fees and training modes
Choose how you want to learn. No-cost EMI is available on the live and 1-to-1 modes.
Most popular
Live Online Training
Talk to us
Contact for current batch fee
Interactive live batches, weekday or weekend, with the full cohort and lifetime recordings.
Fastest
1-to-1 Training
₹49,000
Fixed for every course, no-cost EMI
Private one-on-one coaching at a pace and schedule you set.
Affordable
Self-paced Training
₹9,000
One-time fee, lowest-cost option
Learn on your own time with recorded sessions and the same materials.
Refunds and cancellations are covered in our refund policy.
Training a team?
We run this course as private corporate training, tailored to your systems and scheduled around your team. Tell us your group size and what you need to cover.
Request a corporate quoteFrequently asked questions
Is this IdentityIQ or Identity Security Cloud?
Do I need any IAM or coding experience?
Which certification does this map to?
Should I take this before the Engineer courses?
Will I practise on a real environment?
Is it live?
Ready to start?
Tell us what you need and an advisor will call you back. Or reach us directly.