Account Group Permissions Certification in ISC — Migration from IIQ

Hi ,

We are migrating from IdentityIQ to Identity Security Cloud and trying to find the equivalent of the Account Group Permissions Certification type in ISC.

How it works in IIQ

In IIQ, Account Group Permissions Certification allows an entitlement/group owner to certify the permissions that a group holds — not who is a member of the group, but what the group itself is entitled to. The certifier reviews and approves or revokes the permissions assigned to the group.

The Question

In ISC, all certification campaigns appear to be identity-centric — they certify what a user has access to. We cannot find a way to certify what a group itself holds as permissions.

Is there a native ISC certification type that supports this? Or is there a recommended approach to replicate this use case during migration?

What i am looking for

  • A way for an entitlement owner to certify the permissions belonging to a group
  • Ideally a native ISC feature rather than a workaround

Has anyone solved this during their IIQ to ISC migration? Any input from the would be very helpful.

Thanks

Hi @malarvanan12 ,

Based on my understanding, ISC does not currently provide a native equivalent to IIQ’s Account Group Permissions Certification.

ISC certifications are primarily focused on accounts, roles, access profiles and entitlements assigned to users. I haven’t come across a certification type that allows a group or entitlement owner to directly certify the permissions assigned to a group itself.

During IIQ to ISC migrations, the typical alternatives are to certify the resulting user access granted through those groups or use reporting/custom governance processes to review group-to-permission relationships.

Unless I’m missing a recent enhancement, I believe this use case is not natively supported in ISC today. It would be great if others could share how they have addressed this requirement in their migrations.

Thank you.

Hey @malarvanan12 I think there is no Entitlement owner certification in ISC as of now.
Please refer to the below post for more clarity and workarounds.

Hi @malarvanan12

Like others have mentioned, this feature is not in ISC as of yet.

I’ve had this same use case before and used a powershell script to automatically reassign users based off of the ownership details, but this comes with some quirks you’ll have to fix. For example, disabling notifications and explaining why things are reassigned on the logs instead of being set there by default.

I think the easiest solution for you would be to wait for the upcoming Next Generation Certifications release that is set to come out here in the new few weeks. You’ll need to contact your CSM to have your tenant enrolled early. This solution is out of the box and handles the requirement like IIQ. See the product news updates below for up to date release details.

Enhancement: Next Generation Certifications - Limited Availability Details & FAQ - Announcements / Product News - SailPoint Developer Community

Hi @malarvanan12 ,
First i would like to understand how the permissions are assigned to your Governance group in ISC?

This is currently not supported in ISC.