6.1 Configuring and Scheduling Certification Campaigns

Key Takeaways

  • Certification types include Targeted, Manager, Application Owner, Entitlement Owner, Advanced, Account Group Membership and Permissions, Role Membership, Role Composition, Identity, and Event-based.

  • Certifications can be periodic, triggered by certification events, or one-off; Identity certifications are launched from identity risk, search, or policy violation pages.

  • The phases are Staging (optional), Active, Challenge (optional), Revocation (optional), and End, plus optional automatic closing.

  • Revocations are sent when the review is signed off unless Process Revokes Immediately is set; with a challenge period, they wait for the challenge to be accepted or expire.

  • Every Primary Certifier choice except Single Certifier requires a Backup Certifier for identities whose certifier cannot be found.

Last updated: September 2026

Configuring and Scheduling Certification Campaigns

Objective 3.1 is configure and schedule certification campaigns. A certification (campaign) generates access reviews, one per reviewer, in which reviewers approve or revoke access. Schedules and certifications are managed on Setup > Certifications. Global defaults for them are on gear icon > Compliance Manager.

Certification Types

TypeReviewer certifies…
TargetedThe most flexible type: chosen identities' roles, entitlements, accounts, and permissions, with configurable who, what, certifier, and schedule
ManagerThe access of a manager's direct reports, for all managers or selected ones, and for selected applications
Application OwnerEveryone's access to the applications they own
Entitlement OwnerEveryone who holds the entitlements they own
AdvancedEntitlements and roles for identities in a population or group factory
Account Group MembershipThat the right accounts are in an account group. Groups without owners go to the application owner.
Account Group PermissionsThe permissions granted to an account group
Role MembershipThat the roles they own are assigned to the right identities
Role CompositionThat the roles they own contain the right entitlements and permissions
IdentityOne-off reviews of selected identities, launched from Identity Risk Scores, Identity Search Results, or Policy Violations
Event-basedIdentities selected by a certification event

Three Ways to Schedule

  1. Periodic. Recurring daily, weekly, monthly, quarterly, or annually from New Certification on Setup > Certifications. Periodic certifications can use multi-level sign-off.
  2. Event-based. A certification event (Create, Manager Transfer, Attribute Change, Rule, Native Change, or Alert) generates a review when refresh detects the event, for example certifying a mover's access. Event certifications appear as Identity certifications, so give them a Custom Name.
  3. One-off. From risk scores, search results, or policy violations, or a standard certification scheduled to run once.

Setting Up a Targeted Certification

  • Who to certify: attribute filters, a population from Advanced Analytics, or a rule of type CertificationScheduleEntitySelector, plus Exclude Inactive Identities. Multiple values for one filter act as OR, and multiple filters act as AND. With no criteria, everyone is included.
  • What to certify: roles, Additional Entitlements (not in a role), accounts without entitlements, Target Permissions, policy violations, IdentityIQ capabilities, and scopes, each with optional filters.
  • Certifier: Manager, Owner (role owner, or application or entitlement owner for additional entitlements), Rule (type Certifier), or Single Certifier. Every option except Single Certifier needs a Backup Certifier.
  • Schedule: frequency, start date and time (at least one minute from now), Run Now, and Enable Staging Period.

The Phases

PhaseWhat happens
Staging (optional)Reviews are generated but not sent, so the owner can verify the result, then activate or cancel it
ActiveReviewers decide and can change decisions until the period ends or they sign off
Challenge (optional)Users losing access get a work item and email and can accept or challenge each revocation
Revocation (optional)Revocations are carried out automatically (connector or help desk) or manually (work items). Completion is tracked, by default checked daily, and can be escalated.
EndThe review is complete. Without a revocation phase, revocations still happen but are not tracked.

Process Revokes Immediately sends each revocation when the decision is saved. Without it, revocations wait for sign-off, and with a challenge period, they wait until the challenge is accepted or expires. Revocations are processed by the Perform Maintenance task through the Remediation Manager, or directly when Process Revokes Immediately is set. Automatic closing runs after the other phases. It applies an action (revoke, approve, or allow exception) to undecided items, optionally runs a closing rule, signs with the Automatic Closing Signer, and adds comments.

Loading diagram...
Certification phases

Maintenance That Moves Certifications Forward

Certifications do not advance on their own. The Perform Maintenance system task has options that do the work behind the phases:

  • Transition certifications phases moves certifications whose phase end date has passed to the next phase, for example from Active to the next configured phase.
  • Scan for completed revocations checks revoked items and marks whether the remediation actually happened. By default this is scanned once per day.
  • Finish certifications runs final validations after sign-off and generates any needed remediation work items.
  • Automatically close certifications closes certifications whose automatic closing date has passed.
  • Archive and prune certifications follows the expiration days on the Miscellaneous tab. SailPoint discourages certification archives and recommends certification reports to preserve evidence.

If a certification seems stuck in Active after its end date, check that Perform Maintenance is scheduled and succeeding.

Reviewer Decisions and Delegation

Reviewers Approve, Revoke, or Allow Exception. An exception keeps access for a limited time and can deprovision it automatically when it expires. With Enable Account Revocation, reviewers can also revoke a whole account. Work can be delegated, where the original reviewer keeps responsibility and may have to review it, or reassigned, where the new reviewer owns and signs off the items. Forwarding moves the whole review.

Behavior Options Worth Memorizing

  • Require Electronic Signature, using the meanings defined in Global Settings > Electronic Signatures.
  • Require Subordinate Completion, Require Reassignment Completion, and Return Reassignments to Original Access Review.
  • Automatically Sign Off When Nothing to Certify and Suppress Notification When Nothing to Certify.
  • Require Comments for approval, exceptions, or revocation.
  • Bulk approve, revoke, allow exceptions, reassign, account revocation, and clear decisions.
  • Self-certification allowed for All certifiers, Certification and System Administrators, or System Administrators only, with a Self Certification Violation Owner who receives items reviewers may not certify for themselves.
  • Reminders and escalations during the Active and Revocation periods, with templates and extra recipients from an EmailRecipient rule.

Manager and Targeted certification generation can be partitioned for large populations.

Test Your Knowledge

A compliance team wants to preview exactly which access reviews a new quarterly certification will create, without notifying any reviewers. What should they enable?

A

Process Revokes Immediately

B

The staging period

C

Automatically Sign Off When Nothing to Certify

D

The challenge period

Test Your Knowledge

A targeted certification uses Manager as the primary certifier. Some identities have no manager. What configuration prevents their reviews from being lost?

A

A Single Certifier backup is optional and can be left blank.

B

An Exclusion rule that removes identities without managers

C

A Backup Certifier, which is required for every primary certifier type except Single Certifier

D

The Self Certification Violation Owner

Test Your Knowledge

A reviewer revokes an entitlement during the active period of a certification that has a challenge period and does not use Process Revokes Immediately. When is the revocation request sent?

A

The moment the reviewer clicks Revoke

B

After sign-off, and only once the affected user accepts the revocation or the challenge period expires

C

Only when automatic closing runs

D

Only if the revocation period is disabled

Test Your Knowledge

What is the effect of disabling the revocation period on a certification?

A

Revoked access is never removed.

B

Reviewers can no longer choose Revoke.

C

The certification cannot be signed off.

D

Remediation still happens, but IdentityIQ does not scan for or track whether revocations were completed.

Sections you finish are checked off in the contents.