Knowledge Article
Access Insights Milestone
Author
ryan_cutter
SailPoint
Access Insights is a crucial milestone in the identity security journey, providing enhanced visibility and control over user access within your organization. To ensure a seamless and efficient implementation, we have compiled a set of guidelines designed to help you navigate and optimize your Access Insights setup, mitigate common pitfalls, and achieve quicker time to value.
1
Access Intelligence Center
Resources:
Identity Security Cloud
Note: To access AIC, make sure to grant either Access Intelligence Author or Access Intelligence Reader user level permissions. AIC Reader user rights can view public sheets, whereas AIC Author, in addition to AIC Reader user rights, can bookmark filters, view and create public and private sheets, along with customizing them.
Advice:
The Access Intelligence Center (AIC) helps in visualizing key aspects of your identity program. AIC relies on developing dashboard sheets for data visualization, that can be explored and analyzed for an identity program's effectiveness.
- Prioritize data quality and data hygiene; before deploying AIC or any AI-driven service, ensure that the identity data is clean, well-organized, and free of errors. AIC is only as good as the data it analyzes which is a critical step in achieving meaningful results.
- Use AIC's sheet-building functionality to create custom dashboards that can tell the story of your identity data. Work with an Insight Advisor or create metrics to help visualize the data effectively.
- Ensure that the team understands how to use and interpret AIC's visualizations and insights. SailPoint recommends knowledge-transfer sessions and training during implementation.
Pitfalls:
- Lack of visibility and control over who has access to what makes it difficult to evaluate and manage access risks effectively and in identifying data quality issues.
- Lack of reviewing identity data can cause missed opportunities in addressing compliance gaps and inefficient access governance processes.
2
Identity Outliers
Resources:
Identity Security Cloud
Advice:
To manage identity outliers effectively, first ensure a clear understanding of your organization’s objectives, requirements, and prerequisites from security, compliance, and risk perspectives. Identifying outliers is essential for detecting over-provisioned access and ensuring rights align with policies and regulatory obligations.
Configure alerts for specific outlier behaviors to enable timely responses; when an alert triggers, investigate thoroughly by reviewing access logs, recent role changes, and, if needed, interviewing the user to understand context. If an outlier is confirmed as a risk, promptly adjust access; revoking permissions where appropriate or adding safeguards such as multi-factor authentication.
Pitfalls:
- Failing to establish a clear baseline of normal user behavior can make it difficult to identify outliers effectively causing organizations to overlook significant over-provisioned access risks.
- Delaying adjustments to access rights for users exhibiting outlier behavior can cause users to have access to sensitive information longer than necessary, increasing the risk of data breaches.
3
Access History
Resources:
Identity Security Cloud
IdentityIQ
- IdentityIQ Access History
- Access History Overview
- IdentityIQ Access History Database Sizing Guidelines
Note: This guideline may not apply to Identity Security Cloud customers who have already deployed their tenant.
Advice:
Ensure a thorough understanding of your organization’s objectives, requirements, and prerequisites for monitoring, auditing, and reporting on identity access changes, and conduct scheduled compliance reviews and audits of access history to verify adherence to security and regulatory policies—setting an appropriate cadence (e.g., quarterly, semiannual, or annual) based on your organization’s risk profile and policy.
Pitfalls:
- Not having consistent access history reviews, can lead to excessive time wastage in investigating access history incidents and missing on audit requirements/issues.