Certify IIQ Native Access

Which IIQ version are you inquiring about?

Version 8.2

Share all details related to your problem, including any error messages you may have received.

As part of quarterly access reviews for SOX applications, I have been informed that IIQ is now considered a SOX application. As such, I need to ensure periodic user access reviews of elevated access in the IIQ application and server. I have searched Compass and the Developer Community for any previous posts related to this topic but was unsuccessful. I am looking for the community’s guidance and best practices on reviewing elevated access in IIQ, specifically reviewing who has elevated access to both the IIQ application and server.

@adomolol
How is your current server access managed, is it through role based or are you managing this servers as separate applications within IIQ, without this we cannot comment much on sever access part

Coming to any admin rights or capabilities within IIQ, you can have role based model to assign the rights/ workgroups/ capabilities so that these capabilities or rights will be assigned only through roles and role access can be reviewed quarterly so that any revocation should remove the role and subsequently underlying admin rights or capabilities

1 Like

The servers are not managed via IIQ today. We are looking for an approach to manage via IIQ.

We are also not using RBAC to manage admin rights into SailPoint.

It’s actualy quite simple

2 Likes

Hello @adomolol ,

Certification can be done in IIQ for roles, entitlements, accounts. We cannot certify IIQ capability normally. But there is a work around, Use a loopback connector so IIQ considers itself as a target application and Identity cubes as account and capabilities as entitlements.

Now certification for capabilities is possible.

For OS Level server access, you can use OS Direct connectors as Kamil Mentioned above.

Thanks,
Balaji

1 Like

Even without the Loopback Connector, capabilities can be certified:


This is a manager certification, where the Advanced tab has the option to include capabilities.
–Menno

1 Like

Hi @menno_pieters ,

I was not aware of this feature. Its good to know this.
Is this feature available in IdentityIQ Version 8.2?

I think it’s been around like forever, or at least as long as I’ve worked with IdentityIQ… I’ve worked with every version since 5.1, since 2011.

1 Like

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.