Separation Of Duties In SailPoint IdentityIQ: A Setup Guide After MIM
Azure IAM, LLC, an identity and access management consultancy founded in 2013, has released a guide on configuring separation of duties policies in SailPoint IdentityIQ. The guide is written for organizations moving off Microsoft Identity Manager (MIM) and discovering that SoD enforcement, which MIM never offered natively, is now expected to be in place before the first access certification campaign runs. Separation of duties, also called segregation of duties, is the control that keeps one person from holding two entitlements that together create fraud or error risk. The classic example is a user who can both create a vendor and approve payments to that vendor. Auditors working under SOX, NIST 800-53, CMMC, and PCI DSS all look for evidence that such combinations are detected and either prevented or documented with a business justification. According to the guide, SailPoint IdentityIQ enforces SoD through policies, and each policy contains one or more rules. IdentityIQ supports severa...