Application Onboarding Introduction
Application Onboarding Introduction
Identity Attributes
are sourced from Authoritative
Sources or by Rules
Copyright ©© SailPoint
Copyright SailPoint Technologies,
Technologies, Inc.
Inc. 2017.
2017. All
All rights
rights reserved.
reserved. 8
Configuring Authoritative
Applications
Application Meta
Information
Authoritative
Application Type =
Indicator
Connector
Authoritative Applications
• Manager Correlation Rule (when simple matching is not enough)
• Build and maintain manager hierarchy
• Creation Rule
• Perform customizations at cube creation time
Example: Set default IdentityIQ password
• Can be shared between applications
Copyright ©© SailPoint
Copyright SailPoint Technologies,
Technologies, Inc.
Inc. 2017.
2017. All
All rights
rights reserved.
reserved. 17
Identity Attributes and
Mappings
Value to display –
can be a message
key for localization
support
String or Identity
Read only or
editable attribute
Source of Attribute:
Application Attribute
or Rule
• Searchable
• Correlation
• Analytics, Reporting, etc.
• Multi-valued
Example: User may belong to more than one cost center
• Group factory
• Support dynamically generated groupings of identities based on the attribute
Example: All users in each region become a group
• Groups used to filter cubes included in actions
Example: Refresh only identities from a particular region
Copyright ©© SailPoint
Copyright SailPoint Technologies,
Technologies, Inc.
Inc. 2017.
2017. All
All rights
rights reserved.
reserved. 23
Aggregation and
Refresh Tasks
Application
Schema Authoritative Resources
----
----- ---------
Rules
---- ---------
----- ---------
----- ---------- Creation ---------
----
----- --------- Aggregation Task
---- ---------
----- ---------
----- ----------
Copyright ©© SailPoint
Copyright SailPoint Technologies,
Technologies, Inc.
Inc. 2017.
2017. All
All rights
rights reserved.
reserved. 28
Managing IdentityIQ
User Access
• Capabilities
• Define what additional rights a user
has within IdentityIQ
• Control which menu options are
available
Bob
authorized
Bill Americas Europe John
Scope Scope
App 1 App 3
App 2
Notification Parameters
Email Address and Settings
Add/Remove Identities
Copyright ©© SailPoint
Copyright SailPoint Technologies,
Technologies, Inc.
Inc. 2017.
2017. All
All rights
rights reserved.
reserved. 39
Next Step?
Practice
Exercises
Section 1, Exercise 4
Systems of Record
• Installed and configured IdentityIQ
Employee • Populating Identity Cubes
• Loading authoritative data
• Define Identity Mappings
File
(HR)
Contractor
File
(Contractor Maintenance)