Service Principal Account Management

Which IIQ version are you inquiring about?

8.1p3

Share all details about your problem, including any error messages you may have received.

Hello Team,

We want to aggregate the Service Principals from Azure to SailPoint IIQ 8.1p3

We have the following concerns and require your guidance:

Object Type Configuration:

  1. In the Azure application configuration in IIQ, we are unable to find any specific object type that corresponds to Service Principals. Could you confirm whether Service Principals are supported, and if so, which object type we need to configure to include them?

Additional Configuration Steps:

If applicable, could you provide detailed documentation or guidance on how to enable this functionality?

SailPoint IIQ supports Service Principals as an object type natively. By default, the Service Principal object type should be visible in your settings.

Checkout : Service Principal Management as an Entitlement (sailpoint.com)

SailPoint IIQ does support Service Principals from Azure, starting from version 8.1p4. You can refer to the release notes for more details. Since you are currently on version 8.1p3, this feature is not available to you. Therefore, you will need to apply the patch to upgrade.

I found in the documentation that the Azure Active Directory connector has the capability to manage Service Principals as accounts, which is the recommended approach.

However, even though I already have the configuration for the account schema, it is not fetching the Service Principals.

@Arpitha1 I am not able to access the link receiving below error:

403 ERROR

The request could not be satisfied.


Request blocked. We can’t connect to the server for this app or website at this time. There might be too much traffic or a configuration error. Try again later, or contact the app or website owner.
If you provide content to customers through CloudFront, you can find steps to troubleshoot and help prevent this error by reviewing the CloudFront documentation.

Refer this link

Also, attached a copy 8.1p4 release notes.
s3.distribution.sailpoint.com_IdentityIQ_Releases_8.1_8.1p4_identityiq-8.1p4-README.pdf (465.2 KB)

8.1p3 release notes.
s3.distribution.sailpoint.com_IdentityIQ_Releases_8.1_8.1p3_identityiq-8.1p3-README.pdf (322.6 KB)

I can’t view or download this files.

Re-uploaded. Check now

Hi @Arpitha1 , From the documentation you shared, it shows that they have enhanced the connectivity in the ‘Upgrade Considerations - IdentityIQ 8.1 Patch 1’ section. But as per the above message i could see it does support Service Principals from Azure, starting from version 8.1p4.

Upgrade Considerations - IdentityIQ 8.1 Patch 1:
23/01/2025, 15:49 s3.distribution.sailpoint.com/IdentityIQ_Releases/8.1/8.1p4/identityiq-8.1p4-README.txt
https://s3.distribution.sailpoint.com/IdentityIQ_Releases/8.1/8.1p4/identityiq-8.1p4-README.txt 9/46

  • This patch contains a fix for an important security vulnerability. The
    vulnerability is related to session management and allows under certain
    circumstances for vertical privilege escalation by an authenticated user,
    including obtaining System Administrator privileges.

As with all software vulnerabilities, we recommend that all customers apply
this patch or the e-fix for IIQSAW-2905 available in the Product Download
Center on Compass as soon as possible.

  • A new Rapid Setup feature has been added that provides preconfigured, best
    practice use cases to onboard applications. It reduces deployment time and can
    eliminate many of the complexities typically encountered during implementations,
    especially for business users. Please refer to the Rapid Setup Guide for more
    information.

  • IdentityAI has been rebranded to AI Services in the IdentityIQ user interface.
    There is a new upgrader called AIServicesUpgrader.java to handle all the changes
    needed for the transition from IdentityAI to AI Services.

  • The IQService version must match the IdentityIQ server version including
    the major release and patch versions. When one is upgraded, the other must
    be upgraded as well so that the version and patch levels match. For more
    information on upgrading the IQService, see the IdentityIQ Installation
    Guide’s chapter on upgrading.

  • New Connectivity

  • Slack Connector

  • Net new connector to support aggregation and provisioning of Slack users
    and groups

  • Supports API Rate limiting feature of Slack. Aggregation & provisioning
    operations are now retried and handled gracefully post reaching the API
    rate limit.

  • Atlassian Suite – Cloud Connector

  • Net new connector to manage cloud version of Atlassian Suite. Supports
    User Management in Jira.

  • Zoom Connector

  • Net new connector to support aggregation and provisioning of Zoom users
    and groups along with permission management feature for effective and
    secure transactions.

  • Enhanced Connectivity

  • Active Directory Connector

  • Enhanced to improve the performance during pass-through authentication
    for applications with multiple domains

  • Supports Managed Service Accounts (MSA) and group Managed Service Accounts
    (gMSA)

  • Supports move and rename operations across domains for new applications
    using objectGUID as an identity attribute

  • Azure Active Directory Connector

  • Supports managing Microsoft Teams as Microsoft 365 groups

  • Supports OAuth 2.0 SAML Bearer Assertion flow as additional authentication
    mechanism

  • Supports managing service principal object present in Azure Active Directory

  • Supports ability to configure Azure resource and token endpoints

  • Supports managing Manager attribute of a user

Yes, SailPoint IIQ does support Service Principals from Azure, starting from version 8.1p4.

Sorry to ask again, but from the ‘Upgrade Considerations - IdentityIQ 8.1 Patch 1,’ it mentions that Azure AD connectivity has been enhanced to support Service Principals.

Does this mean Azure Service Principals were not supported in version 8.1p3? I’m asking because the 8.1p3 release notes mention support for managing the Service Principal object in Azure Active Directory. Could you clarify this?

Azure Active Directory Connector

  • Supports managing service principal object present in Azure Active Directory

Got your point Deepak, sorry it was my bad. Yeah., as per it is supported from 8.1p1. And still I don’t see object type of it.

At this moment, I don’t have answer to that weird behaviour, I’ll check and get back to you if I get any details