SailPoint IdentityIQ (IIQ) Training
Learn SailPoint IdentityIQ the way it is implemented on real IGA projects: applications and aggregation, roles and policies, certifications, lifecycle events, rules and workflows, built live on a real instance.
SailPoint IdentityIQ training teaches you to implement and administer IdentityIQ, SailPoint's on-premise identity governance platform. You work with applications and aggregation, correlation, roles and policies, certifications, lifecycle events, and the rules and workflows that automate joiner, mover and leaver, aligned to the Certified IdentityIQ Associate and Certified IdentityIQ Engineer credentials.
Who this course is for
Prerequisite: No IAM background required. Basic Java or scripting awareness helps for the rules modules but is taught from the ground up.
What makes this different
You build, not just watch
From the first session you are on your own developer instance, configuring, scripting and breaking things safely. That is what makes it stick.
Taught on the current release
No outdated screenshots. Everything maps to the release SailPoint runs today, including current AI and platform features.
One trainer who still implements
One working consultant for the whole batch, no rotation, so the teaching is consistent and grounded in real projects.
Support continues to the offer
Resume review, mock interviews on real scenario questions, and referrals. Support does not stop when the last class ends.

SailPoint IdentityIQ curriculum
9 modules and 3 projects, updated to the current release. Every module maps to real IdentityIQ work and expands into its full topic list, practised on a live developer instance.
SailPoint IdentityIQ (IIQ) Training module list: 9 modules, what each one covers, and how many topics it expands into. Full topic lists are in the accordions below.
| # | Module | What you configure | Topics |
|---|---|---|---|
| 01 | IGA and IdentityIQ foundations5 hours | Explain how IdentityIQ assembles identity data and where each core object fits. | 8 |
| 02 | Applications, aggregation & correlation6 hours | Configure application onboarding, schemas and aggregation so account data loads and correlates cleanly. | 8 |
| 03 | Identity attributes & lifecycle5 hours | Configure identity mappings and refresh so the identity cube reflects authoritative source data. | 7 |
| 04 | Roles & policies6 hours | Model business and IT roles and enforce separation of duties and risk policy. | 8 |
| 05 | Certifications & compliance5 hours | Design and run certification campaigns through to revocation and audit evidence. | 8 |
| 06 | Lifecycle & provisioning6 hours | Build joiner, mover and leaver automation and fulfil provisioning across connected and manual systems. | 8 |
| 07 | Rules & workflows5 hours | Write BeanShell rules and workflows that extend IdentityIQ without blocking upgrades. | 7 |
| 08 | Reporting, tasks & administration4 hours | Administer tasks, reporting, delegated access and environment promotion for day two operations. | 6 |
| 09 | Capstone & CIQ Engineer prep3 hours | Assemble an end to end IdentityIQ build and review the Associate and Engineer exam domains. | 6 |
1IGA and IdentityIQ foundationsModule 1 of 9 · 5 hours
Explain how IdentityIQ assembles identity data and where each core object fits.
- What identity governance (IGA) solves and why enterprises buy it
- access risk and audit drivers
- least privilege and segregation of duties
- governance versus access management
- common compliance frameworks
- IdentityIQ architecture: application server, database, connectors
- application server deployment model
- IdentityIQ database schema
- connector runtime and IQService
- supported platform stack
- The Identity Cube and how it is assembled
- identity cube composition
- links built from account data
- attribute promotion sources
- entitlement and risk views
- Where IIQ fits versus Identity Security Cloud
- on premise versus SaaS deployment models
- administration and customisation differences
- migration considerations
- Core objects: Identity, Link, Application, Bundle, Entitlement
- identity and link relationships
- application definitions and schemas
- bundles as business and IT roles
- managed entitlements and their owners
- object inspection in the debug pages
- Installation and environment overview
- installation prerequisites
- iiq console and deployment steps
- environment sizing considerations
- log and configuration file locations
- IdentityIQ editions, modules and licensing
- Compliance Manager scope
- Lifecycle Manager scope
- optional modules and connector packs
- Navigating the admin and user interfaces
- administrator console layout
- end user request and approval pages
- debug pages and the object browser
- quicklinks and home page cards
2Applications, aggregation & correlationModule 2 of 9 · 6 hours
Configure application onboarding, schemas and aggregation so account data loads and correlates cleanly.
- Onboarding an application (source) and choosing a connector
- connector selection criteria
- direct and read only connectors
- connection parameters and test connection
- service account and credential handling
- Account and group schemas and attribute mapping
- account schema attributes and identity attribute
- group schema and entitlement attributes
- multi valued attribute handling
- customisation of schema discovery
- Account aggregation tasks and options
- aggregation task configuration
- check deleted and detected deletion
- promote managed attributes option
- task results and error review
- Group and entitlement aggregation
- managed attribute creation
- entitlement descriptions and owners
- group hierarchy handling
- entitlement catalog maintenance
- Correlation configuration versus correlation rules
- attribute based correlation configuration
- correlation rule use cases
- correlation order and precedence
- testing correlation results
- Handling uncorrelated and orphan accounts
- uncorrelated account identification
- manual correlation options
- orphan and service account treatment
- uncorrelated account reporting
- Delta versus full aggregation and scheduling
- delta aggregation support by connector
- full aggregation triggers
- scheduling and partitioning options
- aggregation run windows
- Connector troubleshooting and logs
- log4j configuration for connectors
- connection and authentication failures
- schema mismatch symptoms
- task result and stack trace analysis
3Identity attributes & lifecycleModule 3 of 9 · 5 hours
Configure identity mappings and refresh so the identity cube reflects authoritative source data.
- Authoritative sources and identity mappings
- authoritative application designation
- identity attribute source mappings
- searchable and multi valued attributes
- attribute configuration objects
- Attribute promotion and transformations
- attribute promotion during refresh
- identity attribute rules
- transformation and normalisation logic
- derived attribute patterns
- Identity refresh and what it recalculates
- identity refresh task options
- role and entitlement recalculation
- policy scan during refresh
- refresh performance considerations
- Manager and relationship correlation
- manager correlation rules
- hierarchy resolution order
- handling missing manager data
- impact on certifications and approvals
- Identity attribute search and populations
- advanced identity search filters
- saving searches as populations
- population use in campaigns
- group definitions and filters
- Provisioning impact of attribute changes
- attribute change triggers
- role assignment recalculation
- downstream provisioning events
- change tracking and audit records
- Multi-source identity precedence
- source ordering and precedence rules
- conflict resolution between sources
- contractor and employee source blending
- precedence testing approach
4Roles & policiesModule 4 of 9 · 6 hours
Model business and IT roles and enforce separation of duties and risk policy.
- Business roles versus IT roles
- role type definitions
- role hierarchy and inheritance
- required and permitted role relationships
- role ownership and lifecycle
- Role modelling and assignment rules
- assignment rule construction
- detected versus assigned roles
- role profiles and entitlement filters
- role activation conditions
- Role mining from existing entitlements
- entitlement analysis inputs
- role mining task configuration
- candidate role review
- role consolidation and cleanup
- Separation-of-duties (SoD) policy design
- conflicting access identification
- SoD rule construction
- mitigating controls and exceptions
- policy owner assignment
- Account, activity and risk policies
- account policy definitions
- activity policy triggers
- risk scoring configuration
- risk model weighting inputs
- Policy violation detection and handling
- policy scan tasks
- violation work items and notifications
- allow and revoke decisions
- violation history and reporting
- Role and policy governance and ownership
- role certification of role definitions
- policy approval workflow
- ownership and delegation model
- documentation of role intent
- Role change management and impact analysis
- impact analysis before role change
- role versioning and approvals
- bulk membership effects
- rollback and remediation planning
5Certifications & complianceModule 5 of 9 · 5 hours
Design and run certification campaigns through to revocation and audit evidence.
- Manager, application owner and role certifications
- certification type selection
- scope and population definition
- reviewer determination
- self certification controls
- Entitlement owner and targeted campaigns
- entitlement owner assignment
- targeted certification filters
- high risk entitlement focus
- campaign scoping by application
- The reviewer experience and bulk decisions
- certification item presentation
- bulk approve and revoke controls
- delegation and reassignment
- decision comments and evidence
- Revocation and remediation flow
- automatic revocation to connectors
- manual remediation work items
- revocation tracking and closure
- escalation on overdue remediation
- Certification scheduling and reminders
- periodic campaign scheduling
- reminder and escalation rules
- email template configuration
- campaign phases and durations
- Audit configuration and evidence
- audit event configuration
- audit log retention
- evidence extraction for auditors
- sign off records
- Compliance reporting
- certification status reports
- entitlement and access reports
- violation summary reporting
- report scheduling and distribution
- Recertification and continuous certification
- recertification cadence design
- continuous certification triggers
- event based review of changes
- campaign fatigue reduction tactics
6Lifecycle & provisioningModule 6 of 9 · 6 hours
Build joiner, mover and leaver automation and fulfil provisioning across connected and manual systems.
- Joiner, mover, leaver lifecycle events
- lifecycle event configuration
- trigger types and filters
- birthright access on joiner
- transfer and termination handling
- Lifecycle Manager and access requests
- request access quicklinks
- requestable entitlements and roles
- request authority and scope
- shopping cart and request tracking
- Provisioning plans and the provisioning engine
- provisioning plan structure
- account requests and attribute requests
- plan compilation and evaluation
- provisioning project review
- Connectors and provisioning policies
- create and update provisioning policies
- field value rules and defaults
- connector provisioning capabilities
- unstructured target handling
- Approval schemes and work items
- owner, manager and role approval schemes
- parallel and serial approval design
- work item assignment and ownership
- approval notifications
- Manual work items and fulfilment
- manual action work items
- fulfilment queue ownership
- verification of manual completion
- service desk integration options
- Provisioning troubleshooting
- provisioning transaction review
- connector error interpretation
- plan compilation failures
- trace and log analysis
- Retry and error handling
- retry configuration and limits
- failure notification routing
- partial success handling
- reconciliation after failure
7Rules & workflowsModule 7 of 9 · 5 hours
Write BeanShell rules and workflows that extend IdentityIQ without blocking upgrades.
- BeanShell and the SailPoint API basics
- BeanShell syntax and scoping
- SailPointContext and object queries
- common API entry points
- rule arguments and return values
- Rule types: BuildMap, correlation, provisioning, field value
- BuildMap rule for delimited files
- correlation rule signatures
- before and after provisioning rules
- field value rules in provisioning policies
- Business rules and reusable logic
- rule libraries and includes
- shared utility methods
- naming and versioning conventions
- unit testing rule logic
- The workflow engine, steps and transitions
- workflow definition structure
- steps, transitions and variables
- workflow libraries and subprocesses
- workflow case inspection
- Approval and LCM workflows
- LCM provisioning workflow entry points
- approval step customisation
- notification steps and templates
- workflow variable passing
- Debugging with trace, logs and the console
- workflow trace output
- log4j logger configuration
- iiq console object commands
- breakpoint style logging patterns
- Upgrade-safe customisation patterns
- avoiding edits to out of the box objects
- extension via custom objects and rules
- source control of configuration XML
- regression checks after upgrade
8Reporting, tasks & administrationModule 8 of 9 · 4 hours
Administer tasks, reporting, delegated access and environment promotion for day two operations.
- Standard and custom reports
- out of the box report catalog
- custom report definitions
- report arguments and filters
- output formats and distribution
- The task framework, scheduling and partitioning
- task definitions and task results
- schedule configuration
- partitioning across request processors
- concurrency and locking behaviour
- Groups and workgroups
- workgroup creation and membership
- workgroup ownership of objects
- work item routing to workgroups
- notification handling for workgroups
- Capabilities, scope and delegated administration
- capability assignment model
- scope definitions and assigned scope
- controlled scopes and visibility
- least privilege for administrators
- Housekeeping and performance basics
- perform maintenance task
- pruning of task results and history
- database index and growth monitoring
- cache and session considerations
- Backup, export and environment promotion
- object export and import
- deployment accelerator patterns
- environment specific configuration
- promotion checklist and rollback
9Capstone & CIQ Engineer prepModule 9 of 9 · 3 hours
Assemble an end to end IdentityIQ build and review the Associate and Engineer exam domains.
- End-to-end joiner/mover/leaver build on a live instance
- requirement to configuration mapping
- lifecycle event assembly
- approval and fulfilment verification
- build walkthrough and defence
- Application onboarding with cleanup rules
- source data profiling
- cleanup rule design
- correlation validation
- aggregation run review
- A certification campaign end to end
- campaign scoping decisions
- reviewer decision capture
- remediation follow through
- evidence package assembly
- Update-safe deployment and export/import
- artifact inventory for release
- export and import sequencing
- environment variable substitution
- post deployment validation
- Certified IdentityIQ Associate and Engineer exam domains
- domain by domain topic review
- mapping course modules to domains
- official study resources
- gap identification per learner
- Practice questions and mock review
- scenario question technique
- common distractor patterns
- timed practice discipline
- answer review and reasoning
Onboard an application and correlate its accounts, model business and IT roles with an SoD policy, drive joiner, mover and leaver lifecycle events with approvals, then run a manager certification through to revocation and export the whole configuration for promotion.
How this course covers the Certified IdentityIQ Associate & Engineer exam blueprint.
| Exam area | Weight | Covered in |
|---|---|---|
| IdentityIQ architecture and core objects | - | Module 1 |
| Application onboarding, aggregation and correlation | - | Module 2, Module 3 |
| Roles, policies and compliance | - | Module 4, Module 5 |
| Lifecycle management and provisioning | - | Module 6 |
| Rules, workflows and extensibility | - | Module 7 |
| Administration, reporting and deployment | - | Module 8, Module 9 |
Not covered: SailPoint Identity Security Cloud, the SaaS identity security platform; Non SailPoint identity governance products such as Saviynt or Oracle Identity Governance.
Curriculum version 2026-09-01 · approved by mohsin
What you'll be able to do
Real projects you'll build
Interview-ready scenarios on a live instance, not toy demos.
Joiner, mover, leaver automation
Build the full JML flow: lifecycle events that provision on hire, adjust on transfer and revoke on exit, with approvals and notifications.
Access certification campaign
Design and run a manager certification, make decisions and drive revocations to remediation on a live instance.
Application onboarding + rules
Onboard an application, correlate accounts, and write a BuildMap and correlation rule to clean and match the data.
Certification and hands-on
Every session runs on a real SailPoint developer instance, so you configure and build rather than watch. The course maps to the Certified IdentityIQ Associate & Engineer exam and finishes with an IT Canvass certificate plus a certification roadmap. IT Canvass does not issue the official SailPoint credential.
The SailPoint program has two tracks. Knowledge Credentials are training-based and unlock an exam: Identity Security Leader (free, product-agnostic foundation), Identity Security Professional, and Identity Security Expert. Role-based Professional Certifications are proctored and recommend real hands-on experience: for on-premise IdentityIQ, Certified IdentityIQ Associate then Certified IdentityIQ Engineer; for cloud Identity Security Cloud, Certified Identity Security Cloud Engineer then Certified Identity Security Cloud Architect. Exams run about US$300 to US$400.
- 1SailPoint Certified IdentityIQ Associatethis course
- 2SailPoint Certified IdentityIQ Engineer
- 3SailPoint Certified IdentityIQ Architect
Certification facts. Vendor figures change, so confirm against the official SailPoint catalogue before booking.
| Exam code | SailPoint University does not publish short exam codes; the credential name below is the identifier |
|---|---|
| Credential | SailPoint Certified IdentityIQ Associate & Engineer |
| Issued by | SailPoint Technologies (not by IT Canvass) |
| Exam duration | 120 minutes |
| Exam cost | Bundled with SailPoint University training; priced per learning path |
| Prerequisite | Product training through SailPoint University, plus implementation experience. |
| What IT Canvass issues | An IT Canvass course completion certificate and a certification roadmap |
Your IdentityIQ career roadmap
Five stages from first IdentityIQ project to architect, with indicative 2026 bands.
Salary snapshot: SailPoint IdentityIQ Engineer
Indicative ranges aggregated from public salary data. Actual pay varies by location, employer and experience.
How IT Canvass compares
Against a typical training provider, this IdentityIQ course is taught on the current SailPoint release, gives you your own developer instance from day one, and keeps one working consultant for the whole batch instead of rotating trainers. Every module is mapped to the Certified IdentityIQ Associate & Engineer exam, sessions are recorded with lifetime access, and job support (resume review, mock interviews and referrals) is included in one transparent fee. Most providers still teach older release material, run slide-first sessions with limited lab time, and bill support and recordings as add-ons.
Fees and training modes
Choose how you want to learn IdentityIQ. No-cost EMI available on all modes.
Interactive live batches, weekday or weekend, with the full cohort and lifetime recordings.
Private one-on-one coaching at your pace, whether you need interview-ready fast or hands-on help with your current project.
Learn on your own time with recorded sessions, labs and Q&A doubt support.
Train your team on SailPoint IdentityIQ (IIQ) Training
Tailored curriculum, flexible scheduling, a dedicated SailPoint architect, and progress reporting for your managers. Delivered live online or on-site for cohorts of any size.
Your trainer
Neelima, SailPoint Architect, 12+ years
I still deliver SailPoint IdentityIQ and Identity Security Cloud implementations for enterprise clients, so I teach from what is breaking in production this quarter, not from a slide deck. In class I show the connector, rule, workflow and certification patterns that scale and the mistakes that cost teams days.
Learner reviews
The JML capstone is exactly what my interviewer asked me to walk through. Cleared the IdentityIQ Engineer exam a month later.
Aggregation, correlation and rules finally made sense because we broke and fixed a real instance every session.
Came from AD administration and this was the cleanest path into SailPoint. Job-ready projects, not slideware.
Fees, batches and policies
The questions people actually ask before enrolling, answered plainly.