Knowledge Article
Identity Foundations Milestone
Author
ryan_cutter
SailPoint
The Identity Foundation milestone is critical for establishing a robust and secure identity management system within your organization. These guidelines provide a comprehensive roadmap to ensure the successful setup and configuration of your infrastructure, system settings, key sources/applications, identity mappings, account correlation, and provisioning processes. By following these best practices and avoiding common pitfalls, you can lay a solid foundation for effective identity governance and administration, paving the way for future scalability and security.
Note: All Success Acceleration Service customers will have the Identity Foundations Milestone completed as part of Tenant Connectivity.
1
Setup infrastructure
Resources:
Identity Security Cloud
IdentityIQ
- IdentityIQ Installation Guide
- IQService
- IdentityIQ Performance Resources
- IdentityIQ Secure Deployment Guide
Advice:
Set up the necessary infrastructure, including:
Pitfalls:
- Not involving the relevant IT teams for configuration, deployment, support, and maintenance can delay the project and impact future viability.
- Improperly sizing and allocating resources can degrade performance.
- Lack of clear requirements may result in missed expectations or increased timelines due to rework.
- Failing to meet prerequisites and follow documentation can lead to errors.
2
Configure system settings
Resources:
Identity Security Cloud
IdentityIQ
- IdentityIQ System Configuration Guide
- IdentityIQ Essentials Training
Advice:
Configure basic system settings for the platform (Identity Security Cloud or IdentityIQ).
Pitfalls:
- Not configuring or understanding system settings can result in unexpected behavior or errors.
3
Onboard key sources/applications
Resources:
Identity Security Cloud
IdentityIQ
- Managing Extended Attributes
- Delimited File Application Configuration
- BeanShell Developer's Guide
- Reporting Task Throughput
Advice:
Onboard key sources/applications, including:
- Authoritative source(s) like Workday
- Authentication/Authorization source(s) like Entra ID or Active Directory
- Business-critical source(s) like SAP or Salesforce
Pitfalls:
- Onboarding too many sources/applications initially can delay time to value. Consider starting with one authoritative source, an enterprise directory, and a few key systems.
4
Configure identity mappings
Resources:
Identity Security Cloud
IdentityIQ
Advice:
Configure identity attribute mappings and data transformations to support governance and administration. Try to identify and define the identity model schema for your organization.
Note: This work may be iterative or ongoing, but ensure the minimal identity mappings necessary for identification and account correlation (as outlined in the next guideline) are completed.
Pitfalls:
- Inadequate identity mappings can negatively impact account correlation and identity governance.
5
Configure correlation and aggregation
Resources:
Identity Security Cloud
IdentityIQ
- Account Aggregations Data Flow
- Group Aggregations Data Flow
- Application Management
- Using Rapid Setup
- Partitioning Best Practices
Advice:
Configure account correlation and aggregation for each onboarded source/application. Make sure to configure partitioning and delta aggregations for all sources that may apply.
Pitfalls:
- Incorrectly correlated accounts can create governance blind spots and security risks.
- Poor data quality can impact automated account correlation.
- Infrequent aggregation of sources/applications can result in outdated identity and access data.
- Lack of setting aggregation and partitioning tuning parameters can affect performance on task-related jobs.
6
Consider configuring account provisioning
Resources:
Identity Security Cloud
IdentityIQ
Advice:
Evaluate the need for automated account provisioning to streamline the creation, management, and deactivation of user accounts across systems.
Pitfalls:
- Not setting up automated provisioning can lead to inefficiencies and increased manual workload.
- Failing to properly define provisioning rules and workflows can result in incorrect or incomplete account setups.
- Lack of monitoring and maintenance of provisioning processes can lead to security risks and compliance issues.