Knowledge Article
The Connectivity Workstream
Author
ryan_cutter
SailPoint
A robust connectivity workstream is essential for integrating SailPoint’s identity security platform seamlessly into an organization’s diverse technical environment. The connectivity workstream focuses on establishing connections between SailPoint and various systems to gain visibility into user accounts, access levels, and activity patterns.
This article outlines a strategic approach for building a connectivity workstream, from integrating foundational systems to connecting with advanced cloud infrastructure and IT operations.

Introduction to the Connectivity Workstream
The Connectivity Workstream is pivotal in ensuring that SailPoint solutions are seamlessly integrated into an organization's existing infrastructure. It focuses on:
- Understanding user accounts: Gaining insights into the current state of user accounts across various systems.
- Assessing associated access: Evaluating the permissions and access levels associated with each account.
- Monitoring detected activity: Tracking user activities to identify anomalies and potential security threats.
By integrating this information, organizations can maintain a holistic view of their identity landscape, enhancing security and compliance.
Step 1: Integrate core systems – directories and single sign-on
The first step in the connectivity workstream is integrating key foundational systems beyond your Authoritative Source, like directories and single sign-on (SSO) solutions. These systems serve as central access points within an organization, making them high-value targets for identity security initiatives.
- Active Directory and similar directories: Directories such as Active Directory are common across organizations and often serve as authoritative sources for identity data. Integrating with these directories provides a foundational layer of connectivity, enabling SailPoint to manage user accounts and synchronize identity information effectively.
- Single sign-on (SSO) systems: SSO solutions streamline access management and provide a centralized point of authentication. Integrating SailPoint with SSO systems ensures that access controls are consistent across the organization, enhancing the user experience while improving security.
Best practices:
- Prioritize high-value systems: Focus on integrating systems that are critical to your operations and hold significant access controls.
- Utilize SailPoint connectors: Leverage SailPoint's enterprise-grade connectors for seamless integration with directories and SSO systems.
- Ensure data accuracy: Verify that the data from these systems is accurate and up-to-date to avoid discrepancies in identity management.
Step 2: Develop a strategic application onboarding plan
After integrating key systems, the next step is to strategically onboard applications. This involves understanding all applications within the organization and systematically integrating them into SailPoint's solution. A phased approach is recommended to enhance efficiency and alignment with strategic goals.
A phased approach
SailPoint recommends building the application onboarding process into manageable phases. By breaking larger initiatives into smaller, more manageable phases, organizations can:
- Prioritize resources: Allocate time and effort to the most critical applications first.
- Adapt to changing circumstances: Adjust plans based on evolving business needs or technical challenges.
- Incorporate stakeholder feedback: Engage with application owners and users to refine the onboarding process.
- Facilitate continuous improvement: Assess progress at each phase and make necessary adjustments before moving forward.
- Enhance communication and collaboration: Ensure all stakeholders are aligned with the goals and understand their roles in the process.
It's important to note that there is flexibility in the order in which applications are onboarded. The suggestions here offer a common and logical approach, but organizations should tailor the process to meet their specific priorities and needs.
Best practices:
- Integrate app onboarding with your identity strategy: All new applications, system developments or vendor purchases should require an IAM review process. For more insights, refer to the article "IAM Best Practices Blog Series: Making IAM an Integral Part of Application Onboarding and Major Changes" by the Identity Defined Security Alliance.
- Start early: Begin the application onboarding process as soon as possible due to its iterative nature.
- Assess and prioritize applications: Evaluate applications based on priority, impact, and readiness for integration.
- Use fit-for-purpose connectors: SailPoint offers a variety of connectors, including standards-based and generic options, to facilitate integration.
- Collaborate with stakeholders: Engage application owners, IT teams, and other stakeholders to gather necessary information and ensure smooth onboarding.
- Document the process: Maintain detailed records of onboarding steps for future reference and compliance purposes.
Step 3: Incorporate high-value activity data streams
As you onboard applications, it's beneficial to connect to high-value activity data streams. Consuming activity information allows SailPoint to monitor account usage and access patterns, enhancing threat detection and response capabilities through the Identity Risk solution.
Best practices:
- Integrate activity monitoring early: Align activity data integration with application onboarding to maximize insights.
- Leverage identity risk solutions: Utilize SailPoint's tools to analyze activity data for potential risks and compliance issues.
- Optimize access reviews: Use activity insights to inform and improve access review processes, reducing unnecessary permissions and accounts.
- Cost reduction: Identify and eliminate unused accounts or excessive access to reduce operational costs.
Step 4: Deepen ecosystem integrations
Expanding integrations beyond core systems enhances the overall user experience and operational efficiency.
Best practices:
- Integrate with ITSM systems: Connect SailPoint with IT Service Management platforms like ServiceNow for streamlined access requests and manual fulfillment processes.
- Leverage MFA and password management: Integrate Multi-Factor Authentication providers to enhance security during password resets and authentication processes.
- Adopt collaboration tools: Incorporate platforms like Slack and Microsoft Teams to facilitate communication and workflow within SailPoint processes.
- Enhance user experience: Focus on integrations that improve usability and accessibility for end-users and administrators.
Step 5: Expand into cloud and on-premise systems
Connectivity extends into both cloud and on-premise infrastructures. Using SailPoint's Cloud Infrastructure Entitlement Manager (CIEM) solution, organizations can gain deeper insights and control over cloud resources and on-premise systems alike.
Best practices:
- Adopt CIEM for cloud governance: Manage and govern access to cloud resources on platforms like AWS, Microsoft Azure, and Google Cloud Platform.
- Integrate on-premise systems: Connect SailPoint to on-premise servers, operating systems, databases, and other key technologies to ensure comprehensive governance.
- Ensure consistent policies: Apply uniform access policies across cloud and on-premise environments to maintain compliance and security standards.
- Monitor underlying infrastructure: Keep track of access at the operational levels to prevent unauthorized access and potential breaches.
Additional considerations: address challenges proactively
During the connectivity workstream, organizations may face challenges such as unknown application ownership or lack of information. SailPoint recommends following these best practices to help reduce potential risks to your connectivity workstream.
Best practices:
- Establish clear ownership: Identify and document ownership for all applications and systems to streamline the onboarding process.
- Conduct readiness assessments: Evaluate the organization's preparedness for integration activities and address gaps proactively.
- Engage cross-functional teams: Collaborate with various departments to gather necessary information and foster a culture of shared responsibility.
- Continuous improvement: Regularly review and refine processes to adapt to new technologies and changing organizational needs.
In a nutshell
Optimizing the connectivity workstream is essential for effective identity management. By following these best practices, SailPoint customers can:
- Enhance security: Achieve a comprehensive view of identities and access across all systems.
- Improve compliance: Maintain consistent policies and meet regulatory requirements.
- Increase efficiency: Streamline processes through integrations and reduce manual efforts.
- Support business goals: Enable agility and scalability by integrating new technologies seamlessly.
Final recommendations:
Begin your connectivity initiatives early and approach them methodically. Embrace a phased approach to manage the complexity and scale of application onboarding effectively. Leverage SailPoint's expertise and resources to guide you through the process, ensuring that your organization maximizes the benefits of a robust identity management system.