7.2 Responding to Policy Violations

Key Takeaways

  • The main decisions are Allow (mitigate for a set period), Revoke, Delegate, and Certify, with comments where required.

  • Only SOD and entitlement-based violations can be revoked; Account, Activity, Risk, and Advanced violations offer Allow and Certify.

  • To clear an SOD violation by revocation, at least one complete side of the conflicting set must be revoked, and bulk revocation is not allowed.

  • An allowed violation reappears on the Policy Violations page and in certifications when its allowed period ends.

  • Users cannot act on their own violations, and certifications show violations only when Include Policy Violations is selected.

Last updated: September 2026

Responding to Policy Violations

Objective 3.4 asks you to understand different responses to policy violations. A policy violation is created when an active policy finds a condition on an identity. The policy violation owner must decide what to do: a specific identity or workgroup, the identity's manager, or an identity chosen by a rule, falling back to the policy owner. You cannot take action on your own violations.

Where Violations Show Up

  1. The Policy Violations page (My Work > Policy Violations, or the QuickLink). The Open tab lists active violations you or your workgroups own. The Complete tab lets you view or edit past decisions. System and Policy Administrators see every violation from My Work, but only their own from the QuickLink.
  2. Violation work items, if the policy's Send Alerts and Open Work Item options are set, or if a violation business process, rule, or alert creates them. Work items created by a business process can include decision buttons (Allow, Revoke, Certify) directly in the work item.
  3. Certifications, if Include Policy Violations is selected. You can build a certification of only violations by including violations and clearing roles, additional entitlements, target permissions, and accounts without entitlements.
  4. Preventively in access requests, through the LCM policy settings (section 7.1).

The Decisions

DecisionWhat it does
Allow (mitigate)Lets the identity keep working in violation until an end date, without affecting compliance or risk. You add a comment and a date, and whether you can edit the date depends on Compliance Manager settings. When the date passes, the violation reappears in the list and in certifications.
RevokeOpens the detail view so you can choose which access to remove. You must revoke one complete set of the offending items, or the violation remains. Removal happens automatically through a connector, through a help desk ticket, or manually through a work request. Bulk revocation of violations is not allowed.
DelegateSends the violation to someone else as a work item for corrective action. Available only when Enable Line Item Delegation is on in Compliance Manager.
Certify (Bulk Decisions menu)Opens Schedule Certification to launch a full certification for the selected identities
Bulk DecisionsApplies Allow or Certify to many violations at once
DetailsShows rule, description, compensating control, and correction advice

Which Decisions Each Policy Type Supports

Policy typeOptions
SOD (role)Allow, Certify, Revoke
EntitlementAllow, Certify, Revoke
Advanced EntitlementAllow, Certify, Revoke
AccountAllow, Certify
ActivityAllow, Certify
RiskAllow, Certify
AdvancedAllow, Certify

Revocation needs specific offending items. That is why only SOD and entitlement-type violations can be corrected by revoking. A risk-score or multiple-account violation has no single item to remove.

Violations Inside Certifications

In an access review, a violation appears as its own line item. The certifier can allow it with an exception period, or revoke one of the conflicting items. The rule's correction advice appears when the violation is selected for revocation. Revocations from certifications are processed with other certification remediations by the Perform Maintenance task, or immediately with Process Revokes Immediately. Remediations taken on the Policy Violations page are not part of that maintenance processing.

Keeping Violations Current

  • Allowed violations expire. When the allowed period ends, the violation comes back for a new decision. The Mitigation Expiration Scanner is one of IdentityIQ's system maintenance tasks.
  • Violations resolve themselves when later refreshes with Check active policies find the condition gone. Use Keep previous violations to retain their history.
  • Escalations transfer ownership. With Reminders then Escalation or Escalation Only, an Escalation Owner Rule moves an ignored violation, for example to the owner's manager.
  • Risk scores include open violations. The work item shows each violation's score weight, which feeds identity risk scoring configured in the Identity Risk Model.

Automating Responses with a Violation Business Process

Instead of waiting for someone to open the Policy Violations page, a policy or policy rule can name a violation business process. When a violation is detected, that workflow can create a customized work item with Allow, Revoke, and Certify decisions built in. It can route the item by department, open a ticket in an external system, or notify security for high-risk rules. A business process set on a rule overrides one set on the policy. Combine it with Send Alerts escalation settings so that ignored violations are transferred to someone else instead of aging silently.

Scenario Walk-Through

A nightly refresh finds that a buyer also holds the Vendor Master Update entitlement, which breaks an Entitlement SOD rule. The violation owner (the buyer's manager) receives a work item. The options:

  • Revoke Vendor Master Update. One complete side of the conflict is removed, a provisioning request goes to the ERP connector, and the next refresh clears the violation.
  • Or Allow it for 30 days, citing a documented compensating control such as dual approval on vendor changes. The violation returns after 30 days.
  • Or Delegate it to the ERP application owner, who knows which entitlement is legitimate.

What the manager cannot do: select this and 40 other SOD violations and bulk-revoke them. Bulk revocation of violations is not supported.

Test Your Knowledge

A violation owner reviews a Risk policy violation for an identity whose composite risk score is above the threshold. Which decisions are available on the Policy Violations page?

A

Allow, Certify, and Revoke

B

Allow and Certify

C

Revoke and Delegate only

D

Revoke only

Test Your Knowledge

An identity has roles A and B on the left of an SOD rule and role C on the right. The owner revokes role A only. What happens to the violation?

A

It is cleared because at least one conflicting role was revoked.

B

It remains, because a complete set of the offending items (A and B, or C) must be revoked to clear it.

C

It is automatically allowed for 30 days.

D

It is converted into a certification item.

Test Your Knowledge

A violation was allowed until March 31. What happens on April 1?

A

The access is revoked automatically.

B

The violation is deleted from the system.

C

The policy is set to inactive.

D

The violation reappears on the Policy Violations page and in certifications for a new decision.

Test Your Knowledge

A manager wants to forward a single SOD violation to the application owner, but the Delegate option is not shown. What is the likely cause?

A

Enable Line Item Delegation is not enabled in the Compliance Manager global settings.

B

The manager is not the policy owner.

C

Delegation is only possible for Activity policies.

D

The policy has no observers configured.

Sections you finish are checked off in the contents.