IT CanvassTalk to an advisor
Real projects · LessonBy , SailPoint Trainer, 7 yrs · Published · IdentityIQ 8.4 · all levels

AD integration

Governing Active Directory accounts and groups.

Quick answer

This project connects Active Directory to SailPoint to govern accounts and group memberships as the core directory.

Key takeaways
  • Aggregate AD accounts and groups
  • Correlate to identities
  • Govern group membership via roles
  • Automate AD provisioning

Active Directory is almost always the first and most important target in a SailPoint deployment, because so much other access depends on AD accounts and group membership. This project brings AD accounts and groups under clean correlation and automated lifecycle.

The goal

Aggregate AD accounts and groups, correlate them reliably to identities, govern group membership through roles, and automate account creation, disable and group changes across the lifecycle.

How to build it

  • Configure the AD connector and aggregate accounts and groups.
  • Establish reliable correlation on a stable key so no accounts are orphaned.
  • Model important AD groups as entitlements/roles with owners and descriptions.
  • Automate account create/enable on joiner and disable on leaver.
  • Govern group membership through requests, roles and certifications.

Design considerations

AD is foundational, so get correlation right first, orphaned or mis-correlated AD accounts undermine every downstream control. Pay attention to nested groups and to service/shared accounts, which are common in AD and often ungoverned. Because AD underpins so much, immediate disable on leaver here is one of your highest-value controls.

Common pitfalls

  • Weak correlation leaving orphaned AD accounts.
  • Ungoverned service/shared accounts.
  • Ignoring nested group effective membership.

Practice challenge

+0 XPStreak ×0
Question 1 of 3
Why is AD a priority target?

Frequently asked questions

What does the term AD integration refer to in SailPoint?
Active Directory is almost always the first and most important target in a SailPoint deployment, because so much other access depends on AD accounts and group membership. This project brings AD accounts and groups under clean correlation and automated lifecycle.
What is the role of aggregation in AD integration?
Aggregate AD accounts and groups, correlate them reliably to identities, govern group membership through roles, and automate account creation, disable and group changes across the lifecycle.
What is worth remembering about AD integration in practice?
AD is foundational, so get correlation right first, orphaned or mis-correlated AD accounts undermine every downstream control.
What tends to go wrong with AD integration?
Weak correlation leaving orphaned AD accounts. Ungoverned service/shared accounts. Ignoring nested group effective membership.
Want this with a live instructor and a lab tenant?
SailPoint IdentityIQ training →
Already working on SailPoint and stuck on a live ticket?Get an expert SailPoint developer on screen-share to finish your daily tasks with you. Deliver on time, protect your reputation and your job. Monthly support only, no task-wise plans.Task assigned · no idea where to startStill stuck · your job on the lineExpert joins your screenDelivered on timeExplore On Job Support