Knowledge Article

Getting Ready for Identity Security Cloud: Tenant Connectivity Readiness

Author

  • ryan_cutter

    SailPoint

Begin Your Identity Security Cloud Journey

Accelerating your deployment starts with a solid foundation. Here's how to get your environment ready for Tenant Connectivity.

Meet Your Guide: The Customer Onboarding Manager (COM)

You won't be doing this alone. You will partner with a dedicated Customer Onboarding Manager (COM) who specializes in orchestrating this foundational phase.

Through a series of collaborative working sessions and touchpoint calls, your COM will lead you through critical early milestones and help you navigate the essential prerequisites, ensuring you avoid common deployment pitfalls.

Ultimately, their primary goal is to help you build a strong technical and program foundation that sets you up for rapid time-to-value and long-term success.

The Readiness Call: Preparing for Tenant Connectivity

This working session is designed to align our teams and create a clear, actionable plan for your Tenant Connectivity engagement.

What we'll discuss:

  • Preparing your tenants: Ensuring you’ve selected your tenant URLs and break-glass administrators.
  • Preparing your sources: A detailed review of the prerequisites for your specific HR and Directory sources.
  • Preparing your infrastructure: A clear walkthrough of the network and infrastructure requirements.
  • Planning the engagement: Identifying key contacts for working sessions and agreeing on target schedules.

Who should attend:

Please include your technical decision-makers and system owners:

  • HR System Owners
  • Authentication / Directory / Entitlement Source Owners
  • Identity Architects & Cloud / IAM Engineers
  • Network Engineers & Firewall Administrators
  • Infrastructure Team Members or System Administrators

Before the Call: Quick Checklist

To accelerate your time-to-value, please complete these steps before our meeting:

  1. Forward this guide to your network and system administrators.
  2. Identify your source owners for both HR and Directory systems.
  3. Review the Virtual Appliance (VA) sizing table below if you have any on-premises systems.

Post-Call Next Steps

1. Follow-up

After the call, your COM will send a detailed email defining the exact prerequisites required for your specific infrastructure and sources.

2. Support

We will check in frequently to see how your prerequisites are coming along and provide assistance if you get stuck.

3. Kick-off

Once your prerequisites are complete, we will officially schedule your first Tenant Connectivity working session!

Prepare your Identity Security Cloud Tenants

Once you receive your Tenant & Account Setup form, you will have the opportunity to select and document your Org name and break-glass administrators.

Org Name Selection & URLs

This is the unique identifier (3-13 characters) for your sandbox and production tenants. We recommend using your current domain name for consistency.

Production: orgname.identitynow.com
Sandbox: orgname-sb.identitynow.com

Break-Glass Admin Assignment

Break-glass (emergency) administrators must be assigned for both sandbox and production environments. They will receive critical notifications and retain specialized access permissions in emergency situations.

Resources to Prepare your Sources

  • Use our documentation to search connectors & integrations to confirm requirements for your specific Authoritative (HR) Source and Authentication (Directory/Entitlement) Source. Tenant Connectivity will cover connecting to and configuring these two sources.
  • If using Active Directory, please review the IQ Service prerequisites and required permissions.
  • IQ Service is a native Windows service designed to enable SailPoint Identity Security Cloud to interact with Windows environments and access information through Windows APIs.

Note: We highly encourage you to engage your source owners early and bring them to your Readiness call. This gives them an opportunity to review the prerequisites and permissions needed for a smooth connection process.

Resources to Prepare your Infrastructure

Consider your source selections when preparing your Infrastructure.

Cloud-only sources (SaaS)

If you are connecting ONLY cloud-based sources (SaaS applications):

Review SaaS Connectors

️ On-premises sources

If you are connecting ANY on-premises sources (like Active Directory):

You will need to deploy Virtual Appliances (VAs). Virtual Appliances are a security best practice and bridge your internal systems with Identity Security Cloud. Please follow the Virtual Appliance Readiness Guide below.

Virtual Appliance Readiness Guide

Follow these three steps to plan, deploy, and configure your Virtual Appliances.

A. Plan Your Virtual Appliance Deployment

Crucial Best Practice: High Availability (HA)

SailPoint strongly recommends deploying at least two Virtual Appliances per cluster to ensure high availability and proper load balancing. If a customer only deploys one before the call, it will delay their production readiness.

Use the table below to choose the right Virtual Appliance image size and virtualization environment for your organization. For more details, refer to the VA best practices and VA requirements documentation.

B. Deploy the Virtual Appliance

Follow the specific deployment guide for your chosen environment. After deployment, complete the steps in starting a new virtual machine.

Virtualization EnvironmentVA Sizing (Processors, Memory, Storage)Deployment Guide

Local vSphere/ESXi

2-4 CPU, 16-32 GB RAM, 128 GB Disk

Local Hyper-V

2-4 CPU, 16-32 GB RAM, 128 GB Disk

Amazon Web Services (AWS)

M5.xlarge or equivalent

Microsoft Azure

Standard_B4ms or equivalent

Google Cloud Platform (GCP)

n2-standard-4 or equivalent

C. Configure the Virtual Appliance

Review the considerations for each configuration method and complete any required network setup.

Configuration MethodDescription

Standard VA (Recommended)

The VA connects directly to SailPoint and other required endpoints through your firewall. Review Standard VA Considerations.

HTTP Proxy VA

The VA connects to SailPoint through a pre-configured proxy service. Review HTTP Proxy VA Considerations.

Network Tunnel VA\*

Recommended if your firewall requires adding outbound traffic to an allow list but does not support domain entries. Review Network Tunnel VA Considerations.

\*Note: Network Tunnel is not available for FedRAMP environments.

Note: SailPoint recommends taking a snapshot of the Virtual Appliance after configuration. Once the VA is successfully integrated into its cluster during Tenant Connectivity, the snapshot can be safely deleted.