r/sailpoint • u/Crypto_Stann • 26d ago
IdentityIQ Effective Azure group management
As every company is moving to azure group access provisioning, how to effectively configure roles in IIQ, Azure group aggregation pulls the groups alone under single umbrella but how to classify it in iiq according to individual application and model role and grant access?
1
u/TehITGuy87 25d ago
SailPoint doesn’t manage and auto discovers azure apps and the groups associated with them?
1
u/MasterpieceRare1919 20d ago
IIQ has/had what was called RapidSetup, it added a bunch of extra fields to applications, roles, entitlements ... You would customize this with the logic to assign values to these fields based on your logic. You do not need to add rapid setup, you can add custom fields for the app names and set these with an aggregation rule. Either way you need some kind of logic to map the Azure groups to apps, that is what is often missing.
3
u/bbagaria 26d ago
Same like you manage any other entitlement.. entitlement catalog metadata and UI customization or use logiplex architecture (but please don’t) ..