IdentityIQ Certification Discrepancy – Users Missing in 2025 but Present in 2026

Sailpoint IIQ 8.3 p3

We are observing an issue with Targeted Identity Certification in SailPoint IdentityIQ 8.3 and would appreciate guidance on debugging and identifying the root cause.

  1. Certification type: Targeted Identity Certification
  2. Scope: Single application
  3. Template: Same certification template (copied, no modifications)
  4. Execution:
    • Certification run in 2025

    • Certification run in 2026

    • 50 some users appeared in the 2026 certification, and work items were generated (assigned to spadmin). However, the same 50 users were NOT present in the 2025 certification results, even though:

      • No changes were made to the certification template

      • The same application scope was used. Need help to understand the issue

      • Identify the root cause for why these 80 users were excluded in the 2025 certification run

Hi @Nara , do you have any snapshots of the users from 2025 to compare to their current state?

How to generate them. could you help me out

Hi Nara,

In the 2025 certification run, the affected users may not have had access to the specific application at the time the certification was launched. Since Targeted Identity Certifications evaluate identities based on their current state at runtime, users without an active account or entitlement for the scoped application would not have been included.

Additionally, some of these users could be new joiners who did not exist in the system in 2025. As a result, they were not eligible for inclusion in the 2025 certification run.

For users who did exist in 2025, it is also possible that they were excluded due to the filtering criteria such has filters, population or rule

Hi @Nara ,This would cause multiple scenarios, if you configure the inactive flag, it will be excluded from the certificate. Another scenario: if the manager is not configured properly, it will go to the backup manager. If you configure spadmin as the backup manager, it will go to spadmin. Validate the identity, if possible, share the template here.

Thanks,

PVR.

Like @naveenkumar3 and @Peddapolu mentioned, there are numerous scenarios where this could occur. It does not necessarily mean that something is wrong with your certification, but possible those users did not “qualify” for the cert due to normal reasons.

Hey @Nara I have pinged you regarding this issue. Whenever you get some time, please respond back. Some times the issues are not with certification, instead it could be associated with identities or assignments or something else.

Hi @Nara

The users were excluded in 2025 because they did not meet the certification scope at that time (may be missing links/inactive/aggregation issue), but re-aggregation in 2026, they qualified and appeared.