IT CanvassTalk to an advisor
Best practices · LessonBy , SailPoint Architect · Published · IdentityIQ 8.4 · intermediate

Security

Securing IdentityIQ itself: service accounts, secrets, capabilities and scopes, encryption and audit.

Quick answer

Because IdentityIQ can change access everywhere, it must be locked down hard: least-privilege service accounts, protected secrets, tightly scoped capabilities for administrators, encrypted sensitive data, and a complete audit trail. The governance tool must be governed too.

Key takeaways
  • IdentityIQ is high-value; secure it hard
  • Least-privilege, protected service accounts
  • Scope admin capabilities tightly
  • Encrypt secrets and sensitive attributes
  • Keep a complete, reviewed audit trail

Securing the SailPoint platform itself matters as much as the governance it delivers, because SailPoint holds highly sensitive access data and can change access everywhere. This page covers hardening the deployment and protecting its powerful capabilities.

Protect the data and the database

  • The database holds all identity and access data, protect it with encryption, tight access and secure backups.
  • Restrict who can reach the database and application servers.

Secure access to SailPoint

  • Front login with your identity provider and enforce MFA there.
  • Apply least privilege to SailPoint’s own administrative capabilities and scopes.
  • Keep a controlled break-glass admin path for IdP outages.

Protect integrations

  • Store connector and API credentials in a secrets manager, never in config or images.
  • Grant connector service accounts only the rights they need.
  • Enforce TLS for the UI and for connector traffic; manage certificates and rotate before expiry.

Protect the powerful capabilities

SailPoint can provision and deprovision access across the enterprise, so its administrative and API access is itself high-value. Govern it as carefully as any crown-jewel system, with least privilege, monitoring and audit.

Common pitfalls

  • Over-privileged SailPoint admins.
  • Secrets stored in config or images.
  • Neglecting TLS and certificate lifecycle.

Practice challenge

+0 XPStreak ×0
Question 1 of 3
IdentityIQ service accounts should have?

Frequently asked questions

What does the term security refer to in SailPoint?
Securing the SailPoint platform itself matters as much as the governance it delivers, because SailPoint holds highly sensitive access data and can change access everywhere. This page covers hardening the deployment and protecting its powerful capabilities.
Which systems are connected to security?
Store connector and API credentials in a secrets manager, never in config or images. Grant connector service accounts only the rights they need.
What is another point to note about security?
SailPoint can provision and deprovision access across the enterprise, so its administrative and API access is itself high-value.
What tends to go wrong with security?
Over-privileged SailPoint admins. Secrets stored in config or images. Neglecting TLS and certificate lifecycle.
Want this with a live instructor and a lab tenant?
SailPoint IdentityIQ training →
Already working on SailPoint and stuck on a live ticket?Get an expert SailPoint developer on screen-share to finish your daily tasks with you. Deliver on time, protect your reputation and your job. Monthly support only, no task-wise plans.Task assigned · no idea where to startStill stuck · your job on the lineExpert joins your screenDelivered on timeExplore On Job Support