6.1 Configuring and Scheduling Certification Campaigns
Key Takeaways
Certification types include Targeted, Manager, Application Owner, Entitlement Owner, Advanced, Account Group Membership and Permissions, Role Membership, Role Composition, Identity, and Event-based.
Certifications can be periodic, triggered by certification events, or one-off; Identity certifications are launched from identity risk, search, or policy violation pages.
The phases are Staging (optional), Active, Challenge (optional), Revocation (optional), and End, plus optional automatic closing.
Revocations are sent when the review is signed off unless Process Revokes Immediately is set; with a challenge period, they wait for the challenge to be accepted or expire.
Every Primary Certifier choice except Single Certifier requires a Backup Certifier for identities whose certifier cannot be found.
Configuring and Scheduling Certification Campaigns
Objective 3.1 is configure and schedule certification campaigns. A certification (campaign) generates access reviews, one per reviewer, in which reviewers approve or revoke access. Schedules and certifications are managed on Setup > Certifications. Global defaults for them are on gear icon > Compliance Manager.
Certification Types
| Type | Reviewer certifies… |
|---|---|
| Targeted | The most flexible type: chosen identities' roles, entitlements, accounts, and permissions, with configurable who, what, certifier, and schedule |
| Manager | The access of a manager's direct reports, for all managers or selected ones, and for selected applications |
| Application Owner | Everyone's access to the applications they own |
| Entitlement Owner | Everyone who holds the entitlements they own |
| Advanced | Entitlements and roles for identities in a population or group factory |
| Account Group Membership | That the right accounts are in an account group. Groups without owners go to the application owner. |
| Account Group Permissions | The permissions granted to an account group |
| Role Membership | That the roles they own are assigned to the right identities |
| Role Composition | That the roles they own contain the right entitlements and permissions |
| Identity | One-off reviews of selected identities, launched from Identity Risk Scores, Identity Search Results, or Policy Violations |
| Event-based | Identities selected by a certification event |
Three Ways to Schedule
- Periodic. Recurring daily, weekly, monthly, quarterly, or annually from New Certification on Setup > Certifications. Periodic certifications can use multi-level sign-off.
- Event-based. A certification event (Create, Manager Transfer, Attribute Change, Rule, Native Change, or Alert) generates a review when refresh detects the event, for example certifying a mover's access. Event certifications appear as Identity certifications, so give them a Custom Name.
- One-off. From risk scores, search results, or policy violations, or a standard certification scheduled to run once.
Setting Up a Targeted Certification
- Who to certify: attribute filters, a population from Advanced Analytics, or a rule of type CertificationScheduleEntitySelector, plus Exclude Inactive Identities. Multiple values for one filter act as OR, and multiple filters act as AND. With no criteria, everyone is included.
- What to certify: roles, Additional Entitlements (not in a role), accounts without entitlements, Target Permissions, policy violations, IdentityIQ capabilities, and scopes, each with optional filters.
- Certifier: Manager, Owner (role owner, or application or entitlement owner for additional entitlements), Rule (type Certifier), or Single Certifier. Every option except Single Certifier needs a Backup Certifier.
- Schedule: frequency, start date and time (at least one minute from now), Run Now, and Enable Staging Period.
The Phases
| Phase | What happens |
|---|---|
| Staging (optional) | Reviews are generated but not sent, so the owner can verify the result, then activate or cancel it |
| Active | Reviewers decide and can change decisions until the period ends or they sign off |
| Challenge (optional) | Users losing access get a work item and email and can accept or challenge each revocation |
| Revocation (optional) | Revocations are carried out automatically (connector or help desk) or manually (work items). Completion is tracked, by default checked daily, and can be escalated. |
| End | The review is complete. Without a revocation phase, revocations still happen but are not tracked. |
Process Revokes Immediately sends each revocation when the decision is saved. Without it, revocations wait for sign-off, and with a challenge period, they wait until the challenge is accepted or expires. Revocations are processed by the Perform Maintenance task through the Remediation Manager, or directly when Process Revokes Immediately is set. Automatic closing runs after the other phases. It applies an action (revoke, approve, or allow exception) to undecided items, optionally runs a closing rule, signs with the Automatic Closing Signer, and adds comments.
Maintenance That Moves Certifications Forward
Certifications do not advance on their own. The Perform Maintenance system task has options that do the work behind the phases:
- Transition certifications phases moves certifications whose phase end date has passed to the next phase, for example from Active to the next configured phase.
- Scan for completed revocations checks revoked items and marks whether the remediation actually happened. By default this is scanned once per day.
- Finish certifications runs final validations after sign-off and generates any needed remediation work items.
- Automatically close certifications closes certifications whose automatic closing date has passed.
- Archive and prune certifications follows the expiration days on the Miscellaneous tab. SailPoint discourages certification archives and recommends certification reports to preserve evidence.
If a certification seems stuck in Active after its end date, check that Perform Maintenance is scheduled and succeeding.
Reviewer Decisions and Delegation
Reviewers Approve, Revoke, or Allow Exception. An exception keeps access for a limited time and can deprovision it automatically when it expires. With Enable Account Revocation, reviewers can also revoke a whole account. Work can be delegated, where the original reviewer keeps responsibility and may have to review it, or reassigned, where the new reviewer owns and signs off the items. Forwarding moves the whole review.
Behavior Options Worth Memorizing
- Require Electronic Signature, using the meanings defined in Global Settings > Electronic Signatures.
- Require Subordinate Completion, Require Reassignment Completion, and Return Reassignments to Original Access Review.
- Automatically Sign Off When Nothing to Certify and Suppress Notification When Nothing to Certify.
- Require Comments for approval, exceptions, or revocation.
- Bulk approve, revoke, allow exceptions, reassign, account revocation, and clear decisions.
- Self-certification allowed for All certifiers, Certification and System Administrators, or System Administrators only, with a Self Certification Violation Owner who receives items reviewers may not certify for themselves.
- Reminders and escalations during the Active and Revocation periods, with templates and extra recipients from an EmailRecipient rule.
Manager and Targeted certification generation can be partitioned for large populations.
A compliance team wants to preview exactly which access reviews a new quarterly certification will create, without notifying any reviewers. What should they enable?
Process Revokes Immediately
The staging period
Automatically Sign Off When Nothing to Certify
The challenge period
A targeted certification uses Manager as the primary certifier. Some identities have no manager. What configuration prevents their reviews from being lost?
A Single Certifier backup is optional and can be left blank.
An Exclusion rule that removes identities without managers
A Backup Certifier, which is required for every primary certifier type except Single Certifier
The Self Certification Violation Owner
A reviewer revokes an entitlement during the active period of a certification that has a challenge period and does not use Process Revokes Immediately. When is the revocation request sent?
The moment the reviewer clicks Revoke
After sign-off, and only once the affected user accepts the revocation or the challenge period expires
Only when automatic closing runs
Only if the revocation period is disabled
What is the effect of disabling the revocation period on a certification?
Revoked access is never removed.
Reviewers can no longer choose Revoke.
The certification cannot be signed off.
Remediation still happens, but IdentityIQ does not scan for or track whether revocations were completed.
Sections you finish are checked off in the contents.