IT CanvassTalk to an advisor
Installation · LessonBy , SailPoint Architect · Published · IdentityIQ 8.4 · all levels

Azure

Deploying IdentityIQ on Azure: VMs/AKS, Azure SQL and Application Gateway.

Quick answer

On Azure, run IdentityIQ on VMs or AKS with Azure SQL/managed database behind Application Gateway, using Key Vault for secrets.

Key takeaways
  • Prerequisites for Azure
  • Step-by-step install path
  • Common pitfalls and fixes
  • Verification after install

On Microsoft Azure, IdentityIQ runs on virtual machines or an AKS cluster, backed by Azure SQL (or a managed database), fronted by Application Gateway, with secrets in Azure Key Vault and access governed by network security groups and Azure identity. The pattern mirrors AWS using Azure equivalents.

Reference architecture

  • Compute: Azure VMs or AKS pods running Tomcat + the IdentityIQ WAR.
  • Database: Azure SQL or a managed database offering backups and HA.
  • Load balancing: Application Gateway (with WAF where required) in front of the nodes.
  • Secrets: Azure Key Vault for database and integration credentials.

Step by step

  • 1. Provision compute, VMs or AKS, sized for UI and task workloads.
  • 2. Create the managed database and run the IdentityIQ DDL.
  • 3. Configure the datasource to the database endpoint, retrieving credentials from Key Vault.
  • 4. Front with Application Gateway and health probes.
  • 5. Secure networking with NSGs and least-privilege identities.
  • 6. Deploy and verify, then run a test aggregation.

Azure best practice

  • Choose a database tier with built-in HA and backups.
  • Keep all secrets in Key Vault.
  • Use NSGs to restrict access to the database and management ports.
  • Distribute nodes across availability zones.

Common pitfalls

  • Secrets outside Key Vault.
  • Open NSGs exposing the database.
  • No zone redundancy for the database.

Practice challenge

+0 XPStreak ×0
Question 1 of 3
What are the prerequisites for Azure?

Frequently asked questions

What else is worth knowing about Azure?
Compute: Azure VMs or AKS pods running Tomcat + the IdentityIQ WAR. Database: Azure SQL or a managed database offering backups and HA. Load balancing: Application Gateway (with WAF where required) in front of the nodes.
What is the practical takeaway on Azure?
1. Provision compute, VMs or AKS, sized for UI and task workloads. 2. Create the managed database and run the IdentityIQ DDL. 3. Configure the datasource to the database endpoint, retrieving credentials from Key Vault.
What tends to go wrong with Azure?
Secrets outside Key Vault. Open NSGs exposing the database. No zone redundancy for the database.
Want this with a live instructor and a lab tenant?
SailPoint Architect training →
Already working on SailPoint and stuck on a live ticket?Get an expert SailPoint developer on screen-share to finish your daily tasks with you. Deliver on time, protect your reputation and your job. Monthly support only, no task-wise plans.Task assigned · no idea where to startStill stuck · your job on the lineExpert joins your screenDelivered on timeExplore On Job Support