Blog
New Capability: Privilege Classification in Identity Security Cloud
Author
Sesche2
SailPoint
Description
SailPoint is proud to present the new Privilege Classification feature in Identity Security Cloud (ISC). This features allows customers to use new classifications levels to assign privilege indicators on entitlements. These new levels will replace the existing privilege boolean flag on entitlements, providing more granular insight into risk on entitlements.
New Capabilities
Privilege Classification introduces new levels of privilege that can be assigned to entitlements. Assigning High, Medium or Low level of Privilege allows a more granular approach to privilege classification within ISC. This allows more focus on High privilege access first, then followed by medium and low risk entitlements etc.These privilege levels can be assigned automatically through building criteria. Criteria can be configured for each of the High, Medium and Low levels. The privilege level can also be manually overwritten on individual entitlements, allowing the level to be increased, decreased or set to none, allowing complete control.
Problem
- The current entitlement boolean flag is no longer adequate reflection of privilege in the current complex world of privileged entitlements. Also, the boolean flag can only be set manually which is a huge manual effort to utilize.
- Many source vendors publish lists of privilege entitlements. These aggregated entitlements are not automatically set to privileged in ISC, which causes significant friction.
- Classification of entitlements as privileged is a manual process in both the UI and API.
Solution
The privilege boolean flag on entitlements will be replaced with a new Direct Privilege Classification level. These privilege levels can be assigned automatically through building criteria. Criteria can be configured for each of the High, Medium and Low levels. The privilege level can also be manually overwritten on individual entitlements, allowing the level to be increased, decreased or set to none, allowing complete control.
Below is a screenshot of a source with the setting selected to assign the High privilege level to all entitlements on that source.
Below is a screenshot of custom criteria defined to assign the High privilege level based on admin defined criteria:
Manually overriding the direct privilege for a single entitlement:
Who is affected?
All IdentityNow and ISC suites customers will have access to Privilege Classification
Pending final packaging decisions. Post will be updated once final decisions are confirmed.
Action Required
No action is required. The migration from the existing boolean flag to leverage the new classification capability will be seamless. All existing boolean flagged entitlements will automatically set to High.
Important Dates
Rollout will begin in early Feb 2026 and will end in March 2026.
To ask questions and learn more please visit the Developer Community.