Blog
From Feature Parity to Unlocking the Future for IIQ Customers
Author
parminder_kocher
SailPoint
Viewpoints from Identity Security engineers
Author: Parminder Kocher, with contribution from Hari Patel
Introduction
In my role as an Engineering leader at SailPoint, I often encounter requests for feature parity between IdentityIQ (IIQ) and Identity Security Cloud (ISC). Business leaders frequently inquire, "Does ISC match IIQ's feature set? Can we access a feature comparison document?" These are valid inquiries. However, before I address these questions in this document, let us delve into the following key considerations
- Replica or Evolution: Should ISC merely replicate IIQ, given that IIQ was developed over 15 years ago?
- Fresh Appeal: Shouldn't ISC, as a more recent development, naturally be more appealing, aligned with contemporary industry needs?
- Technological Leap: How has the technological evolution of the past 15 years, including AI/ML advancements, influenced our new ISC product?
- Feature Parity vs Problem Parity: Instead of a 1:1 feature comparison chart for IIQ vs ISC, how about let's focus on the problem-solving capabilities and do more with less?
- Speed and Agility: Too much consumerization comes at the cost of speed and agility. What if you can make this your last upgrade and adopt new features right away?
- Innovation Over Imitation: Given the above, would it be a missed opportunity to copy IIQ feature by feature and label it ISC? Our goal is to provide innovation, not imitation.
I believe you grasp the direction we are heading. Still, let us start with some foundational concepts.
The Current Scenario with IIQ
SailPoint's IdentityIQ (IIQ) has served as a dependable on-premises solution. However, the evolving industry necessitates a more adaptive approach, especially when considering the cost-effective technological advancements available in the cloud. I will not delve into the intricacies of on-premise versus SaaS models; we understand that, and the information is readily available.
Here is a snapshot of IIQ's current state:
- Annual releases: Like any other on-premise solution, IIQ operates on a yearly release cycle, making it challenging to keep up with rapidly changing technology and security advancements.
- Upgrade: upgrade often requires 3rd party consulting companies and can be expensive and IIQ customers will not benefit from new features and capabilities unless they upgrade to the latest version.
- Maintenance: Frequent maintenance, often 1-2 times per quarter, can be demanding.
- Customer responsibility: IIQ places significant responsibilities on customers for security and infrastructure management.
- Customization: While customization is possible in IIQ, it requires a deep understanding of the system, presenting challenges during upgrades. Customers are responsible for ensuring upgrades and testing their customizations.
Nevertheless, we acknowledge that some of our customers may prefer to remain on on-premises solutions due to their specific business needs. In fact, we wholeheartedly support such customers and continue to provide top-tier service and feature enhancements. For customers not bound by these specific needs and genuinely concerned about feature parity, read on to discover how Identity Security Cloud leverages the power of cutting-edge AI and ML technology to enhance your Identity Security.
The Way Forward - SailPoint Identity Security Cloud
Once again, we assume that the advantages of moving from any on-premise solution to a SaaS model are well understood, such as no more software upgrades needed and the quick ROI. These advantages are applicable in SailPoint's case as well. In addition, SailPoint's Identity Security Cloud (ISC) represents a substantial leap forward from traditional on-premise systems. With Artificial Intelligence and machine learning at its core, SailPoint's Identity Security Cloud delivers unmatched intelligence, frictionless automation, and comprehensive integration that allow enterprises to manage access across the most complex cloud environments. When IIQ customers are ready to migrate to cloud, why should they choose SailPoint ISC vs other Identity cloud solutions?
- Multi-Tenant SaaS architecture: ISC adopts a multi-tenant architecture, offering scalability and reducing the need for on-premise infrastructure. Think of the scalability, performance, and multi-region availability that brings us closer to our customers, all while benefiting from our partner-built, scalable SaaS features and applications.
- Agility: With swift provisioning, onboarding, a microservices architecture, and an event-driven approach, ISC offers rapid adaptability and innovation. By decentralizing the platform from a monolithic structure, ISC allows us to rapidly innovate where needed without introducing breaking changes to unrelated areas of the platform.
- Security and compliance: ISC puts security and compliance under your control, boasting certifications including ISO 27001, SOC2 Type 2, and FedRAMP.
- Frequent releases: ISC ensures you are consistently equipped with the latest features and security enhancements through multiple weekly releases.
- Flexibility through extensibility: Customizations are achieved through our extensibility features: APIs, forms, and workflows. Together, these features provide the same level of flexibility as IIQ's plugin framework, but because they are delivered as first-class capabilities within ISC, customers can tailor to specific requirements without upgrade and backward-compatibility headaches.
- Advanced AI: ISC offers robust and cost-effective AI capabilities, eliminating data transfer costs and limitations. We continue to embed machine learning and AI into every aspect of our service to facilitate well-informed business decisions. Notably, much of the AI-related enhancements are more easily delivered to ISC due to the commonality of data models; IIQ capabilities are often several quarters delayed by comparison, if they're available at all.
- User-friendly workflows & forms: ISC simplifies workflows and forms, making them intuitive and straightforward, reducing the need for extensive training. Custom flows triggered by well-defined events throughout our application can be built to fit customers' needs without requiring engineer-level skills.
- Event-based architecture: ISC employs event-based refreshes and aggregations, aligning with the latest design and engineering best practices. Goodbye to legacy batch processes and welcome to the future of Identity Security in real-time. Processes that used to take hours now get completed in seconds to minutes with no impact to any part of the applications like other vendors have.
- Seamless connectivity: By offering a SaaS-based connectivity layer, ISC reduces training requirements, cuts costs, and adheres to industry best practices.
Trusting SailPoint's Identity Security Cloud
In the early 2000s, SaaS was not the norm. The competition revolved around who had more features, and every vendor was busy developing new features. Fast forward to 2020, the game has evolved to focus on vendor-provided extensibility. Customers now demand the power to differentiate their needs against those of their peers.
SailPoint's Identity Security Cloud provides state-of-the-art and industry-leading IAM and IGAS solutions, empowering customers to creatively solve their business-specific problems. This approach offers substantial benefits and a forward-looking solution, as evidenced by its impressive availability, growing customer base, and public usage metrics.
Building the case for Flexibility over Parity:
- Fine-Grained Access Certifications: Customers often need to exclude certain identities from a certification campaign, a capability which is readily available in IIQ through "Skip Membership Certification," selections or via Certification Exclusion Rules. While ISC lacks this specific feature, it offers a superior alternative to solving the same business problem. Users can create search-based campaigns, specifying query filters with various conditions to achieve more flexible and efficient identity exclusion. Now with the release of ISC's low touch automation like workflows and forms, you gain unlimited power to build a multitude of new features and custom capabilities.
- Native Change Detection: Both ISC and IIQ offer native change detection as a setting on individual source applications. However, within ISC, the ability to act based on the detected change is a mere point-and-click configuration with little to no additional work needed – event processing is handled by out-of-the-box workflows. By contrast, in IIQ, multiple additional tasks and settings need to be configured before native change detection can be utilized. In this case, both products solve the same problem, but the implementation is far more elegant within ISC.
- AI-driven Activity and Access Insights: ISC's deep integration with SailPoint's AI capabilities allows it to natively and easily surface access history, usage information, and access modeling recommendations without any additional effort or configuration. When the data is there, it automatically shows up in the user interface. This hands-free capability only exists within ISC; we might be able to surface some of that information in IIQ, but doing so would require customers to navigate through a full update cycle to do so.
- Dynamic Access Roles: This feature in ISC allows admins to define policy that can change or provide access based on policy configuration like location, time, and the application or asset itself. SailPoint is leveraging an innovative way to tie identity and access metadata through a flexible role model which can satisfy both access request and access certification requirements. IIQ does not have this flexibility at all, and given its highly embedded role model, is not likely to achieve this capability anytime soon.
- Reporting and business intelligence: Customers will always need advanced reporting around their governance tool – whether for audit attestations or simply for internal business intelligence and analytics. For IIQ, these needs are often solved through the development of custom reports, which require extensive knowledge of the IIQ data persistence layer and at least a moderate knowledge of Java. ISC handles the business need differently – suggestion-based querying through Search with autocomplete for tabular data needs, and Secure Data Share for more advanced Business Intelligence use cases like time-series analysis and charting.
- Data Access Governance: Identity security is not just about controlling access to systems and applications, which, it is also about access to business critical data and how it is being used (e.g., network shares, file-level permissions, etc.). On-premises solutions rely upon SailPoint's File Access Manager product to solve this use case, but that entails complex setup and configuration, with oftentimes multiple attempts at access discovery. Within ISC, customers can deploy Data Access Security on top of their existing identity models which are already built within the governance part of the platform. The result is a much faster onboarding and implementation timeline – hours, not months – and with far greater stability.
This document does not aim to cover all value-added use cases from ISC. There are other SaaS-based add-on capabilities such as like CIEM, NERM that can enhance your identity security experience. This document conveys a vital message: Do not limit your transition to ISC by merely seeking feature parity. As a SaaS offering, the goal is to provide complex features that can be utilized by most if not all the customers and for customer specific items, that's where extensibility comes into picture. ISC offers a wealth of features in the realms of ML, AI, and forward-looking capabilities. These are beyond the scope of IIQ due to its on-premises nature, and any potential cost constraints related to data transfer, especially concerning ML and AI.
Conclusion
In the ever-changing world of Identity Security, agility, scalability, and innovation are not optional - they are paramount. SailPoint's Identity Security Cloud (ISC) does not just meet these demands; it transcends them. ISC empowers your organization not merely to keep pace but to take the lead in the rapidly evolving Identity Security landscape.
Today, I urge you to shift your focus. Embrace the transition to ISC with a different mindset. Rather than dwelling on feature-by-feature comparisons, direct your gaze towards simplicity, the flexibility of SaaS, and, above all, the tangible business outcomes that ISC unlocks for you to differentiate yourself. Your destination is not merely an elevation; it is a complete transformation. The future of Identity Security is here, and it is embodied by SailPoint's Identity Security Cloud. It is not just a transition; it is a revolution waiting for your enterprise to claim it.