New Capability: Auto-Discovery of Privileged Entitlements

Description

SailPoint is introducing automatic discovery of privileged entitlements to help customers find potentially risky access that may not be captured by vendor-published lists or broad custom criteria. This enhancement helps administrators identify the needle-in-the-haystack entitlements that could grant privileged access, review SailPoint recommendations, and make more informed classification decisions.

AND

This release communication explains how SailPoint will surface potentially privileged entitlement recommendations, how customers can review and accept or reject those recommendations, and how this capability supports better privileged access governance over time.

Problem

Customers need help discovering privileged entitlements that are not already identified through out-of-the-box privilege lists or custom criteria. Automating discovery and classification of privileged items helps customers guard against costly security breaches, but the first feasible step toward a broader AI-based solution is a rule-based approach that uses popularity as the primary determinant.

As privilege classification expands with out-of-the-box and custom criteria, customers need a more targeted way to find potentially privileged entitlements that may otherwise go undiscovered.

Solution

SailPoint will recommend entitlements that may grant privileged access based on analysis of aggregate privilege classification patterns. Customers can review these recommendations, accept or reject them, and assign a privilege level when marking an entitlement as privileged.

Recommendations will be surfaced in familiar product workflows, including entitlement and source pages. Customers can also assign recommendations to subject matter experts for review, using the existing approvals flow, and SailPoint will maintain an auditable record of classification decisions.

Who is affected?

Customers using SailPoint Identity Security Cloud privilege classification capabilities are the primary audience. The most affected users are administrators, sub-administrators, source owners, application owners, entitlement owners, and reviewers responsible for identifying and governing privileged access.

Action Required

Customers:

Customers should review newly surfaced privileged entitlement recommendations and either accept or reject them. When accepting a recommendation, customers should assign the appropriate privilege level. Customers may also assign recommendations to the right entitlement owner, source owner, governance group, or other subject matter expert for review.

Important Dates

Available Now!

1 Like

Was this link intentional? It looks like it leads to a SailPoint Confluence location

3 Likes

This sounds cool, being able to assign entitlements to SMEs would definitely make handling privilege classification easier, but I don’t know what this looks like or how to enable it. It says available now, but I don’t see it in sandbox and definitely not in PROD. Is there documentation or further clarification on this?

1 Like

Is this feature available to all license types?

Sorry Dan, it was unintentional. It has been removed.

If you are familiar with GenAI Entitlement Descriptions and how the descriptions can be routed for approval, AI Privilege Discovery is very similar to that functionality.

1 Like

Good morning @rlw1210 ,

I have another question. Is there a way to proactively generate these privilege suggestions like the descriptions? In reading through the documentation, it sounds like this feature can only be utilized when, and if, the system generates suggestions. It’s a cool feature for sure, but I feel like it’d provide way more value if we didn’t need to rely on the system generating suggestions.