IT CanvassTalk to an advisor
Troubleshooting · LessonBy , SailPoint Architect · Published · IdentityIQ 8.4 · all levels

Identity refresh failed

An identity refresh task failed or produced wrong results.

Quick answer

Refresh problems usually come from rule errors, bad attribute mappings or policy evaluation failures. The task result and logs pinpoint the step.

Key takeaways
  • Symptom: An identity refresh task failed or produced wrong results.
  • Most likely causes
  • Step-by-step fixes
  • How to prevent recurrence

An identity refresh task failed, or completed but produced wrong results, incorrect attributes, missing role assignments, unfired lifecycle events. Because refresh is where data becomes governance outcomes, refresh problems have wide downstream impact.

Start here: read the evidence

Read the refresh task result to find which step failed, then check whether any rules or mappings changed recently. Refresh runs correlation, attribute mapping, role assignment and policy, so identifying the failing step is key.

Likely causes, in order

  • Error in a refresh or correlation rule, often a null-pointer on a missing attribute.
  • Bad or missing attribute mapping, so identity attributes are wrong.
  • Policy evaluation failure during refresh.
  • Stale source data, a missed aggregation means refresh works on old data.

How to fix it

  • Read the task result to locate the failing step.
  • Review any recently changed rules for null-safety and logic errors.
  • Verify identity attribute mappings against the authoritative source.
  • Re-aggregate sources if the underlying data is stale.
  • Re-run refresh and validate a sample identity end to end.

Preventing recurrence

Test rule changes in a lower environment, add null-safety to every rule, and sequence aggregation before refresh so cubes are always computed from current data.

Common pitfalls

  • Guessing instead of reading the task/transaction result, which usually names the cause.
  • Fixing the symptom, not the root cause, so it returns.
  • Changing several things at once, so you cannot tell what worked.

Practice challenge

+0 XPStreak ×0
Question 1 of 3
What commonly breaks refresh?

Frequently asked questions

What does the term Identity refresh failed refer to in SailPoint?
An identity refresh task failed, or completed but produced wrong results, incorrect attributes, missing role assignments, unfired lifecycle events. Because refresh is where data becomes governance outcomes, refresh problems have wide downstream impact.
What is worth checking first with Identity refresh failed?
Error in a refresh or correlation rule, often a null-pointer on a missing attribute. Bad or missing attribute mapping, so identity attributes are wrong. Policy evaluation failure during refresh.
What is another point to note about Identity refresh failed?
Test rule changes in a lower environment, add null-safety to every rule, and sequence aggregation before refresh so cubes are always computed from current data.
What tends to go wrong with Identity refresh failed?
Guessing instead of reading the task/transaction result, which usually names the cause. Fixing the symptom, not the root cause, so it returns. Changing several things at once, so you cannot tell what worked.
Want this with a live instructor and a lab tenant?
SailPoint Architect training →
Already working on SailPoint and stuck on a live ticket?Get an expert SailPoint developer on screen-share to finish your daily tasks with you. Deliver on time, protect your reputation and your job. Monthly support only, no task-wise plans.Task assigned · no idea where to startStill stuck · your job on the lineExpert joins your screenDelivered on timeExplore On Job Support