How to enable IdentityIQ Cloud Governance for AWS?

IIQ Version

8.4p2

Hi All,

We are configuring the AWS connector in IIQ, but we’re unable to aggregate AWS Accounts, AWS Managed Policy, etc. the attributes that “are only functional when you purchase Cloud Access Management or or IdentityIQ Cloud Governance.”

The client has purchased the license for IdentityIQ Cloud Governance, but I’m not sure how to enable this functionality and I haven’t been able to find IIQ-specific information about this.

This thread: How to enable IdentityIQ Cloud Governance functionality? mentioned the CSM provided initial steps, but in our case the CSM hasn’t provided any details.

I’d suggest reaching out to your CSM again to clearly outline the requirement, and opening a support ticket with SailPoint in parallel. I’m confident they will address it for you.

BTW, have you tried aggregating to see if you are getting AWS Managed Policy in the aggregation or not?

Hi @camila_ronderos,

The AWS attributes you mentioned, such as AWS Accounts and AWS Managed Policies, are part of the additional functionality available with IdentityIQ Cloud Governance for supported cloud connectors.

You can review the following documentation for more information:

  1. Supported Connectors for IdentityIQ, which includes details about IdentityIQ Cloud Governance support
  2. Integrating SailPoint and Amazon Web Services (IIQ 8.5)
  3. Integrating SailPoint with Google Workspace (IIQ 8.5)
  4. Integrating SailPoint with Microsoft Entra ID (IIQ 8.5)

Also, the thread you referenced includes guidance from Dinesh, who is a SailPoint Product Manager and not a CSM.

Since the customer has already purchased the IdentityIQ Cloud Governance license, I recommend reaching out to your SailPoint Customer Success Manager (CSM) or emailing customersuccess@sailpoint.com for assistance with enabling or validating the functionality in the environment.

You can also review the SailPoint Digital Customer Success guide for additional information about the Digital Customer Success team and engagement process.

Thank you!

Hi @sa8173 we have run the aggregation, and it doesn’t bring any of the additional objects.

We finally got the configuration flag we need to add to the Application XML from support, and we are able to aggregate AWS Accounts, AWS Managed Policy, etc.

Not sure why this was so complicated. But if anyone needs to enable this feature, my advice is: Create a ticket with both support and CSM at the same time.