TrustRadius: an HG Insights company

SailPoint Identity Security Cloud

Score6.8 out of 10

38 Reviews and Ratings

Top Performing Features

  • ID Management Workflow Automation

    Automated sequence of tasks to simplify processes

    Category average: 8.2

  • ID-Management Access Control

    Authorization or restriction of access to information depending on role

    Category average: 8.9

  • Account Provisioning and De-provisioning

    Capabilities for creating user accounts based on roles, group memberships and business processes

    Category average: 8.4

Areas for Improvement

  • Password Management

    Self-help capabilities the help users recover forgotten passwords, etc.

    Category average: 8.4

  • Multi-Factor Authentication

    Using multiple, independent components to gain access

    Category average: 8.8

  • ID Risk Management

    Identification, evaluation, and prioritization of risks with procedures to minimize, impacts of unplanned consequences

    Category average: 8.3

Why to and Why Not to Use SailPoint

Use Cases and Deployment Scope

SailPoint IIQ is used for identity governance and to understand who has access to what and whether that access should be granted or not. We also use it for access to recertification automation which provides a complete report of who has what access in the organization at the press of a button. We are able to automate the entire process of joiners, movers, leavers and the provisioning and de-provisioning of identities. When someone joins any organization, all their roles and access are provided at the click of a button. When they move from one department to the other, the accesses which are not required are revoked, and the ones which are necessary are provisioned. SailPoint offers complete automation of the lifecycle of any user. We are able to offer on-prem on cloud-based deployments, depending on our customer's requirements.

Pros

  • Identity Governance
  • Access Reviews (Certification)
  • Audit and Compliance
  • Risk and Policies
  • SOD Policies

Cons

  • More Out of the Box Connectors
  • Support for Customizations
  • Improved UI

Most Important Features

  • JML
  • RBAC
  • Certification

Return on Investment

  • Positive Impact

Alternatives Considered

Oracle Identity Management

Other Software Used

Oracle Identity Management

Usability

Great IAM solution

Use Cases and Deployment Scope

We use currently SailPoint in our company as a self-service platform for the whole management and lifecycle for the joiner mover leavers of all our employees IDs, Accounts as well for the whole management of the access right, roles and the access reviews. Also for the management for more than 200 applications that are connected to the system.

Pros

  • Management of User ID
  • Management of accounts
  • Management of access reviews
  • Management of applications

Cons

  • UI should be more user friendly
  • Management of roles

Most Important Features

  • Lifecycle management of the employees with their access and password
  • Connection of applications
  • Access reviews

Return on Investment

  • Positive impact as a self service plattform

Other Software Used

ServiceNow Now Platform

SailPoint IdentityIQ - Rolls Royce of a platform if used correctly and truely invested in

Use Cases and Deployment Scope

We have the IdentityIQ platform implemented within my organization, and its main benefit (although not it's only one) is the automation it brings to the Provisioning of user accounts/profiles and the automation of access via its roles functionality. Through this automation, LCM is also controlled by IdentityIQ, where people joining, moving, and Leaving the organization have their accounts subsequently amended or removed. This mechanism saves countless hours across our organization both in Technology and Business support departments. The product ties all our employee's access to our critical Applications and enables them to access them at the right time, and in the right place.

Pros

  • Brings users access, profiles and accounts all into one place
  • Manages the Life Cycle Management process across ALL identities, permanent and Temporary
  • Secures and manages access to critical applications and resources across the group
  • Enables Info. Security to customise, share and delegate authority across the group
  • Single version of the truth across our technology platform

Cons

  • The use of a Distinguished name and the lack of a clear support model for the task that is necessary for this process to work is not a good idea.
  • In a hybrid model where application automation is not fully rolled-out, means that there can be inconsistency in the process, which leads to duplicate accounts.
  • Certification: The functionality is a bit clunky and could be designed with the end-user experience in mind (Although this might be due to our version of IIQ)

Most Important Features

  • Life cycle management
  • Access Management
  • Automation of role assignment
  • Account Provisioning in other Applications

Return on Investment

  • Seamlessly manages the disablement of account access for users leaving the business. Our company has approx. 200 leavers a week, which before IIQ was managed primarily manually.
  • Conversely, IIQ automates the creation of 200 new starters a week, which again used to be fuelled by manual Service Requests.
  • The Information Security of this platform is endless. From LCM to Application assignment and removal

Alternatives Considered

The Okta Identity Cloud

Other Software Used

Microsoft Azure Active Directory, Microsoft 365, Ivanti Service Manager (powered by Heat)

SailPoint IdentityIQ Implementation in a Dynamic Healthcare Environment

Use Cases and Deployment Scope

We utilize the SailPoint IdentityIQ platform to build and manage employee identities which include various types of user accounts, birthright access, and application assignment. IdentityIQ is also used for self-service account registration, password/account management, and automating several employee onboarding and offboarding workflows. By interfacing with our company's HR system, IdentityIQ allows us to quickly build and modify employee identities, reduce the required time for application assignments, and allow our hospital staff to begin working without any delays in a dynamic healthcare environment.

Pros

  • Role & Entitlement Management
  • Platform Scalability and High Availability
  • Robust Capabilities for Application and Systems Integration

Cons

  • The development process for managing and Debugging rules could use some Enhancements
  • Auditing and logging capabilities are limited
  • Documentation regarding the specific process, programming details, and system limitations are missing

Most Important Features

  • Identity creation and management
  • The ability to customize various workflows
  • Automation capabilities

Return on Investment

  • The ability to automate the employee onboarding processes greatly reduces the staffing requirements for account creation and access assignment
  • The self-service capabilities for the account registration and password management tasks have greatly reduced the number of calls to our Help Desk
  • The role mining capabilities have reduced the amount of time required to assign and update our user application set mapping

Alternatives Considered

Microsoft Identity Manager and The Okta Identity Cloud

SailPoint IdentityIQ Review

Use Cases and Deployment Scope

We use On-Premise IdentityIQ product with all functionalities that are LCM, SOD Controls, BirthRight Roles, different types of Certification, custom Access Requests Workflows, custom role and service account create, update, delete request forms and workflows, custom reports, etc. Before SailPoint implementation, we had some pain points about Access Governance functionalities. So we have solved most of the painpoints.

Pros

  • Well Engineering, robust, highly capable about all departments of Access Governance
  • User Friendly, comprehensible, easy UI
  • Easy development, integration and deployment processes

Cons

  • Easier upgrade processes
  • More Country Spesific Education Opportunities
  • Adding Firewall rules management modules or connectors
  • Adding Create Access Request over voice command

Most Important Features

  • LCM Capabilities
  • Certification Functionalities
  • BirthRight Functionalities

Return on Investment

  • Good Auditing Results (Positive)
  • Reduce Operational Costs (Positive)
  • Increase visibility of Company's Access Governance picture

Alternatives Considered

Oracle Identity Management

Other Software Used

CyberArk Privileged Account Security, ArcSight Logger (formerly HPE Arcsight Logger)