Knowledge Article
Tenant connectivity
Author
ryan_cutter
SailPoint
Tenant Connectivity is an expert-guided engagement included with all SailPoint Success Acceleration Service packages. It ensures your Identity Security Cloud (ISC) tenant is securely connected to key identity systems and that identity data flows correctly into the platform.
Through this engagement, SailPoint establishes the foundational configuration required to operate Identity Security Cloud, including connecting authoritative and authentication sources and validating identity correlation.
By completing Tenant Connectivity, organizations can later enable Access Insights/Modeling and Cloud Infrastructure Entitlement Management (CIEM) through separate engagements.

Delivery timeline
Tenant Connectivity is delivered through a series of expert-led working sessions designed to establish a production-ready environment. To maintain momentum and accelerate your time-to-value, working sessions are scheduled at a minimum cadence of one session per week.
Under this updated delivery model, the Tenant Connectivity engagement is typically completed within approximately three weeks following the readiness and kick-off session, depending on your team's readiness and scheduling availability.
Prerequisites for Tenant Connectivity
Before initiating Tenant Connectivity, complete the steps and form outlined in the Identity Security Cloud readiness planning page to ensure the following:
Tenant Readiness
- Finalized URLs: Confirm both Sandbox and Production tenant URLs.
- Emergency Access: Designate a Break-Glass Administrator for emergency access scenarios.
Virtual Appliance (VA) Planning
- Deployment Plans: Outline plans for deploying Virtual Appliances to securely bridge on-premises and cloud systems.
- Network Setup: Configure network settings, including firewall rules and port configurations necessary for secure communication.
Source Configuration
- Identify Sources: Determine authoritative and authentication sources (e.g., HR systems, Active Directory).
- Stakeholder Engagement: Involve relevant stakeholders, including application owners and administrators, to ensure proper configuration and support.
Form Submission
- Documentation: Provide details on your readiness, preferred start date, and necessary selections to initiate scheduling.
Scope of Tenant Connectivity
The Tenant Connectivity engagement focuses on establishing the technical groundwork for your SailPoint Identity Security Cloud environment. During this engagement, SailPoint experts guide your team through connecting key identity systems, validating secure connectivity, and ensuring identity data flows correctly into the platform.
This setup enables Identity Security Cloud to begin governing identities and preparing your environment for advanced capabilities such as automation, analytics, and cloud entitlement governance
Base Configuration (Included for all suite customers)
- Virtual Appliance Setup: SailPoint assists in configuring Virtual Appliances (VAs) to securely bridge on-premises systems with Identity Security Cloud.
- Source configuration:
- Connect one authoritative source (e.g., HR system).
- Connect one authentication source (e.g., Active Directory), ensuring at least one source is on-premises.
- Identity Security Cloud Base Configuration:
- Configure the identity profile with standard attributes and lifecycle sttes (active/inactive).
- Validate identity correlation and data aggregation.
- Promote configurations from Sandbox to Production.
- Ensure the environment is ready to support governance and automation use cases.
Post-tenant connectivity capabilities
Once your technical foundation is established via Tenant Connectivity, your organization is positioned to enhance its identity program by enabling additional capabilities including Cloud Infrastructure Entitlement Management (CIEM) or AI-powered Access Insights, Access Modeling, and Access Recommendations.
These advanced capabilities are delivered through separate engagements that can be requested through the SailPoint Success Acceleration Services catalogue when your organization is ready to activate them.
Guided working sessions
Through a series of focused working sessions, we will guide your team in configuring connectivity, validating identity data, and preparing your environment to begin governing identities quickly.
1
Readiness validation & architecture alignment
Prerequisites:
- Completion of Tenant and Virtual Appliance readiness.
- Identification of authoritative and authentication sources
- Access to required infrastructure and systems
Attendees:
- Core Team (including Implementation partner, if applicable)
- SailPoint Implementation Engineer
- Identity / IAM Administrators
In-Scope Tasks
- Configure VAs to securely communicate with the Identity Security Cloud.
- Generate VA tokens and troubleshoot any configuration issues.
- Set up two VAs in Sandbox and up to four VAs in Production.
2
Infrastructure Setup (Virtual Appliance Configuration)
Prerequisites:
- Virtual Appliance installation completed
- Network connectivity requirements validated
Attendees:
- Core project Team
- Network / firewall representatives (on call)
- Virtual appliance / infrastructure team
- SailPoint Implementation Engineer
In-Scope Tasks
- Validate Virtual Appliance installation and prerequisites
- Configure secure communication between VAs and Identity Security Cloud
- Generate and validate VA tokens
- Pair sandbox and production virtual appliances
- Stage supporting services (e.g., IQService if required)
3
Source Connectivity & Identity Data Validation (Sandbox)
Prerequisites:
- Completion of Source Readiness.
- Connector configuration details confirmed
Attendees:
- Core Team (including Implementation Partner, if applicable)
- Application Owners (technical and business process owners)
- SailPoint Implementation Engineer
In-Scope Tasks
- Configure authoritative source connector (e.g., HR system)
- Map identity attributes and manager relationships
- Configure authentication source connector (e.g., Active Directory)
- Aggregate and validate identity data
- Review identity correlation and resolve initial data issues
4
Production Activation & Validation
Prerequisites:
- Successful sandbox validation and connectivity testing
Attendees:
- Core project team
- SailPoint administrators
- Application owners (technical and business process owners)
In-Scope Tasks
- Promote validated configurations from Sandbox to Production
- Securely configure credentials and secrets
- Validate connectiovity and production data aggregation
- Review identity correlations and resolve exceptions
- Provide configuration summary and operational guidance
Ready to Get Started?
Please reach out to your Customer Onboarding Manager or Customer Success Manager. Let’s get started on your Identity Security Cloud journey!