We are migrating from IdentityIQ to Identity Security Cloud and trying to find the equivalent of the Account Group Permissions Certification type in ISC.
How it works in IIQ
In IIQ, Account Group Permissions Certification allows an entitlement/group owner to certify the permissions that a group holds — not who is a member of the group, but what the group itself is entitled to. The certifier reviews and approves or revokes the permissions assigned to the group.
The Question
In ISC, all certification campaigns appear to be identity-centric — they certify what a user has access to. We cannot find a way to certify what a group itself holds as permissions.
Is there a native ISC certification type that supports this? Or is there a recommended approach to replicate this use case during migration?
What i am looking for
A way for an entitlement owner to certify the permissions belonging to a group
Ideally a native ISC feature rather than a workaround
Has anyone solved this during their IIQ to ISC migration? Any input from the would be very helpful.
Based on my understanding, ISC does not currently provide a native equivalent to IIQ’s Account Group Permissions Certification.
ISC certifications are primarily focused on accounts, roles, access profiles and entitlements assigned to users. I haven’t come across a certification type that allows a group or entitlement owner to directly certify the permissions assigned to a group itself.
During IIQ to ISC migrations, the typical alternatives are to certify the resulting user access granted through those groups or use reporting/custom governance processes to review group-to-permission relationships.
Unless I’m missing a recent enhancement, I believe this use case is not natively supported in ISC today. It would be great if others could share how they have addressed this requirement in their migrations.
Hey @malarvanan12 I think there is no Entitlement owner certification in ISC as of now.
Please refer to the below post for more clarity and workarounds.
Like others have mentioned, this feature is not in ISC as of yet.
I’ve had this same use case before and used a powershell script to automatically reassign users based off of the ownership details, but this comes with some quirks you’ll have to fix. For example, disabling notifications and explaining why things are reassigned on the logs instead of being set there by default.
I think the easiest solution for you would be to wait for the upcoming Next Generation Certifications release that is set to come out here in the new few weeks. You’ll need to contact your CSM to have your tenant enrolled early. This solution is out of the box and handles the requirement like IIQ. See the product news updates below for up to date release details.