2.2 Installation Steps and Procedures

Key Takeaways

  • Expand identityiq.war into a staging directory (identityiq_home) before changing any configuration files.

  • Change the .hbm.xml extended attribute mappings and run iiq schema before you create the database, because iiq schema regenerates the DDL scripts.

  • Database connection details for the IdentityIQ and plugin databases go in WEB-INF/classes/iiq.properties, and iiq encrypt produces an encrypted password for that file.

  • Load the base configuration by running iiq console and then import init.xml; Lifecycle Manager objects come from init-lcm.xml.

  • The default login is spadmin with password admin, and the installation guide says to change it immediately.

Last updated: September 2026

Installation Steps and Procedures

Objective 1.2 asks you to demonstrate knowledge of the IdentityIQ installation steps and procedures. DOMC items often describe one step and ask whether it is valid at that point, so learn the order and which file or command belongs to each step.

Step-by-Step Installation

1. Stage the Application

Download the installation zip from SailPoint. It contains identityiq.war and the database, doc, and integration folders. Create a staging directory and expand the WAR into it, for example with jar -xvf identityiq.war. The installation guide calls this directory identityiq_home. On UNIX, make the launcher executable with chmod +x WEB-INF/bin/iiq.

2. (Optional) Change Extended Attribute Columns, Then Run iiq schema

If you need more searchable or extended attributes than the default mapping files provide, edit the .hbm.xml files in WEB-INF/classes/sailpoint/object now (section 2.3). Then run:

cd identityiq_home/WEB-INF/bin
./iiq schema

iiq schema regenerates the database creation scripts from your changed mappings. This is why extended-attribute planning happens before you create the database.

3. Create the Databases and Tables

The DDL scripts are in identityiq_home/WEB-INF/database. Two naming patterns matter:

  • create_identityiq_tables-<version>.<db> (for example, create_identityiq_tables-8.1.mysql) matches the default extended attribute layout.
  • create_identityiq_tables.<db>, without a version number, is the script iiq schema generates after you change the mapping files.

The scripts create the application database, the plugin database, their tables and indexes, and database users with the right privileges. From 8.4, they also create the Access History database. You can change names and passwords, but you must keep table names, column names, and column types. The Oracle script must be edited to set the DATAFILE location and uncomment the database creation commands. For SQL Server, Aurora, and Azure SQL, the guide requires a case-insensitive collation. Run the script with a database client, for example:

mysql -u root -p
mysql> source create_identityiq_tables-8.4.mysql;

4. Create Site-Specific Encryption Keys

A default encryption key is compiled into the product for demonstration environments. SailPoint strongly recommends a site-specific key so that secrets cannot be decrypted outside your installation. Run iiq keystore, then addKey, to create the file-based keystore. By default this is WEB-INF/classes/iiq.dat, with the master password file iiq.cfg. Then restart the application server. Every instance in a multi-host installation needs the same iiq.dat and iiq.cfg, either in WEB-INF/classes or at the path set in iiq.properties (keyStore.file, keyStore.passwordFile).

5. Configure iiq.properties

Edit identityiq_home/WEB-INF/classes/iiq.properties and set the host name, database type, database name, user, and password for both the IdentityIQ and plugin databases. A clear-text password works, but SailPoint recommends an encrypted one. Generate it from WEB-INF/bin:

./iiq encrypt MyDbPassword

Paste the output into the property. If the JDBC driver for your database is not bundled, copy it into WEB-INF/lib.

6. Import the Initial Configuration Objects

Start the console from WEB-INF/bin and import the base objects:

./iiq console
> import init.xml
> import init-lcm.xml
> quit

init.xml loads the system configuration, default task definitions, rules, workflows, and other base objects. init-lcm.xml adds the Lifecycle Manager objects. Lifecycle Manager is a separately licensed module, and the installation guide points LCM customers to its activation steps. The console tries the default spadmin/admin credentials first and prompts you if they fail.

7. Deploy and Start the Application Server

Copy the staged directory into the application server, for example tomcat/webapps/identityiq, or package it as a WAR. If you deploy a WAR file instead of an expanded directory, set resources.checktimestamps=false in WEB-INF/classes/packtag.properties. IdentityIQ also needs class loader isolation so that its bundled libraries win over the application server's copies. WebSphere, JBoss, and WebLogic each have extra steps in the guide.

8. Log In and Secure the Default Account

Browse to the application, for example http://localhost:8080/identityiq on a default Tomcat install. Log in as spadmin with the password admin. Change that password right away under Identities > Identity Warehouse > spadmin > Change Password. spadmin is a protected user, so authorization lockout does not apply to it unless you enable protected-user lockout.

StepKey file or commandCommon mistake
Stageidentityiq.war → identityiq_homeEditing files inside the zip instead of the staging directory
Schema.hbm.xml + iiq schemaRunning it after the database already exists
DatabaseWEB-INF/database/create_identityiq_tables*Using the versioned script after regenerating a custom one
Keysiiq keystore → iiq.dat, iiq.cfgKeeping the demo key in production, or keys that differ between hosts
ConnectionWEB-INF/classes/iiq.properties, iiq encryptConfiguring only the main database and forgetting the plugin database
Objectsiiq console → import init.xml, init-lcm.xmlStarting to configure the UI before init.xml is imported
Accessspadmin / adminLeaving the default password unchanged

Why the Order Matters

Authentication is disabled while there are no identities. The documentation notes that this situation exists during setup, before init.xml is imported. After the import, spadmin exists and normal authentication applies. If you start using the UI against an empty database, core objects such as the system configuration are missing, and pages fail.

Test Your Knowledge

An engineer must add five extra searchable identity attributes before go-live. At what point in a new installation should the engineer edit IdentityExtended.hbm.xml and run iiq schema?

A

After importing init.xml, so the new columns are populated right away

B

Before creating the database, so the regenerated DDL script builds the extra columns

C

After starting Tomcat for the first time, from the Identity Mappings page

D

Only during the next patch, because iiq schema is a patch-time command

Test Your Knowledge

Which file tells a new IdentityIQ instance how to connect to its IdentityIQ and plugin databases?

A

WEB-INF/config/init.xml

B

WEB-INF/classes/packtag.properties

C

WEB-INF/classes/iiq.properties

D

WEB-INF/database/create_identityiq_tables.mysql

Test Your Knowledge

What is the purpose of running import init.xml from the IdentityIQ console during installation?

A

It creates the database tables and indexes.

B

It generates a site-specific encryption key.

C

It copies the web application into the Tomcat webapps directory.

D

It loads the base configuration objects, such as system configuration, tasks, rules, and workflows, into the new database.

Test Your Knowledge

A team deploys IdentityIQ as a packaged WAR file rather than an expanded directory. Which extra configuration change does the installation guide require?

A

Set plugins.enabled=false in iiq.properties.

B

Rename create_identityiq_tables-8.4.mysql to remove the version number.

C

Import init-lcm.xml before init.xml.

D

Set resources.checktimestamps=false in WEB-INF/classes/packtag.properties.

Sections you finish are checked off in the contents.