IDN: Source Entitlement filtering only sometimes works?

We have contacted SailPoint directly and did not get a resolution. We have been told it is possible to filter if we were using IIQ but does not look to be possible in IDN even with the assistance of SailPoint professional services.

We are a relatively smaller organization and only have about ~3000 AD entitlements that would be replicated into AAD; we also use an on-premises dynamic groups engine that recalculates groups multiple times a day.

As others have noted, the lack of this IDN capability adds significant noise and confusion to our Access History, and Certifications when the AAD/Entra source is added.

So, we have currently stopped our plans to use IDN for AAD/Entra IAM.

As we have a lot on premise, but some critical things in Azure/Entra we were hoping to manage with IDN, this has caused some negative IDN sentiment.

The simple design assumption/shortcut that every entitlement from a source can be mastered in that source is false. :frowning:

We need to be able to configure entitlement filtering on the account aggregation feed.

1 Like