Problem
How to Migrate the Packages of SailPoint ISC from Lower Tenants to High Tenants of SailPoint ISC using Configuration Hub. (Greenfield Implementation)
Diagnosis
- While initially using configuration hubs, faced a lot of referencing issues due to dependency of the artifacts on each other.
- Hence, having a structured approach will help you to reduce the dependency issues and perform the migration/deployment of artifacts in much faster rate.
Solution
The high level steps which you can perform in order to perform migration of artifacts from lower instance to higher ISC instance (specially for a green field implementation) is as follows.
- Migration of Transforms (Least Dependent artifacts) - Using Configuration Hub
- Migration of Connector Rules - Using Configuration Hub
- Migration of Cloud Rules (In case cloud rules does not have any APIs used in which Source IDs were used as inputs) - Using Configuration Hub
- Manual changes in Transforms wherever required. Specifically for transforms which uses the “identity” APIs in which Source IDs and Source Names are used to extract certain details such as Manager DN (In AD), Manager Username (in SNOW), etc. - Manual
- Raising the SailPoint ISC - Expert Services Tickets for CLOUD RULE deployment (where changes in code was performed specific to PROD tenant) - Through SailPoint
- Search Attributes Migration. - Using Configuration Hub
- Identity Attribute Migration. - Using Configuration Hub
- Source Migration. - Using Configuration Hub
- Setup the VA Cluster of respective tenant and re-enter the source credentials. - Manual
- Test connections of each source and perform entitlement/account aggregations to test it. - Manual
- Migration of Access Profiles - Using Configuration Hub
- Migration of Roles - Using Configuration Hub
- Migration of Workflows/Forms - Using Configuration Hub
- Deletion of all Accounts and Entitlements from each source - Manual
- Migration of Identity Profiles. - Using Configuration Hub
- Perform Authoritative Source account aggregation - Manual
- Perform Authoritative Source entitlement aggregation - Manual
- Validate the Identity Creations and account correlations - Manual
- Enable the access profiles and roles in a structured manner - Manual
- Validate the provisioning to downstream systems - Manual