Knowledge Article

Identity Foundations Milestone

Author

  • ryan_cutter

    SailPoint

The Identity Foundation milestone is critical for establishing a robust and secure identity management system within your organization. These guidelines provide a comprehensive roadmap to ensure the successful setup and configuration of your infrastructure, system settings, key sources/applications, identity mappings, account correlation, and provisioning processes. By following these best practices and avoiding common pitfalls, you can lay a solid foundation for effective identity governance and administration, paving the way for future scalability and security.

Note: All Success Acceleration Service customers will have the Identity Foundations Milestone completed as part of Tenant Connectivity.

 

1

Setup infrastructure

Resources:

Identity Security Cloud

IdentityIQ

Advice:

Set up the necessary infrastructure, including:

    Pitfalls:

    • Not involving the relevant IT teams for configuration, deployment, support, and maintenance can delay the project and impact future viability.
    • Improperly sizing and allocating resources can degrade performance.
    • Lack of clear requirements may result in missed expectations or increased timelines due to rework.
    • Failing to meet prerequisites and follow documentation can lead to errors.

     

    2

    Configure system settings

    Resources:

    Identity Security Cloud

    IdentityIQ

    • IdentityIQ System Configuration Guide
    • IdentityIQ Essentials Training

    Advice:

    Configure basic system settings for the platform (Identity Security Cloud or IdentityIQ).

    Pitfalls:

    • Not configuring or understanding system settings can result in unexpected behavior or errors.

     

    3

    Onboard key sources/applications

    Resources:

    Identity Security Cloud

    IdentityIQ

    Advice:

    Onboard key sources/applications, including:

    • Authoritative source(s) like Workday
    • Authentication/Authorization source(s) like Entra ID or Active Directory
    • Business-critical source(s) like SAP or Salesforce

    Pitfalls:

    • Onboarding too many sources/applications initially can delay time to value. Consider starting with one authoritative source, an enterprise directory, and a few key systems.

     

    4

    Configure identity mappings

    Resources:

    Identity Security Cloud

    IdentityIQ

    Advice:

    Configure identity attribute mappings and data transformations to support governance and administration. Try to identify and define the identity model schema for your organization.

    Note: This work may be iterative or ongoing, but ensure the minimal identity mappings necessary for identification and account correlation (as outlined in the next guideline) are completed.

    Pitfalls:

    • Inadequate identity mappings can negatively impact account correlation and identity governance.

     

    5

    Configure correlation and aggregation

    Resources:

    Identity Security Cloud

    IdentityIQ

    Advice:

    Configure account correlation and aggregation for each onboarded source/application. Make sure to configure partitioning and delta aggregations for all sources that may apply.

    Pitfalls:

    • Incorrectly correlated accounts can create governance blind spots and security risks.
    • Poor data quality can impact automated account correlation.
    • Infrequent aggregation of sources/applications can result in outdated identity and access data.
    • Lack of setting aggregation and partitioning tuning parameters can affect performance on task-related jobs.

     

    6

    Consider configuring account provisioning

    Resources:

    Identity Security Cloud

    IdentityIQ

    Advice:

    Evaluate the need for automated account provisioning to streamline the creation, management, and deactivation of user accounts across systems.

    Pitfalls:

    • Not setting up automated provisioning can lead to inefficiencies and increased manual workload.
    • Failing to properly define provisioning rules and workflows can result in incorrect or incomplete account setups.
    • Lack of monitoring and maintenance of provisioning processes can lead to security risks and compliance issues.