8.2 Leveraging Advanced Analytics

Key Takeaways

  • Advanced Analytics search types include Identity, Access Review, Role, Entitlement, Account, Activity, Audit, Process Metrics, Access Requests, and Syslog.

  • Basic criteria fields are ANDed together and use starts-with matching; Advanced Search adds operators such as "is like" and grouped AND/OR filters.

  • Identity search results can be saved as a search, a report, or a population, and can launch an identity certification.

  • Saved searches are private; saving a search as a report makes it available to users with report access and lets it be scheduled.

  • Populations saved from Identity Search are reused in QuickLink populations, certifications, policies, lifecycle events, and Rapid Setup trigger filters.

Last updated: September 2026

Leveraging Advanced Analytics

Objective 3.6 asks you to leverage Advanced Analytics. Advanced Analytics (Intelligence > Advanced Analytics) answers questions such as "who has X?", "which reviews are overdue?", and "what errors happened last night?" Its most important outputs are populations that other features reuse.

The Search Types

Search typeFinds…Typical question
IdentityIdentities by attributes, manager, applications, roles, entitlements, and risk"Everyone in Finance with SAP access and a composite score over 700"
Access ReviewCertifications and access reviews by certifier, type, phase, completion percentage, dates, and tags"Manager reviews below 50 percent complete"
RoleRoles by attributes, profile, extended attributes, and dates"Business roles owned by Jane with no description"
EntitlementEntitlements (account groups and application objects) by attribute, owner, value, application, type, and target"All AD groups owned by nobody"
AccountAccounts by application, display name, owner, native identity, and instance"Accounts on App X whose native identity starts with svc"
ActivityApplication and target activity by time period, identities, and populations"Logins to the payroll app outside business hours"
AuditAudit records by action, source, target, and date"Who changed this role last week?"
Process MetricsBusiness process (workflow) metrics, by participants and success or failure"How long does LCM Provisioning take, and where does it fail?"
Access RequestsCurrent and archived access requests"All requests pending approval for more than 5 days"
SyslogTechnical error records (section 14.2)"Look up incident code 123456"

Audit Search returns data only for actions that auditing is configured to capture (section 8.3). Activity Search needs activity data sources.

How Criteria Combine

  • Different fields are ANDed. First Name John plus Last Name Doe returns only people who match both.
  • Text fields use starts-with matching. "ro" in Last Name finds Roberts and Rowen but not Brown. For a contains search, use Advanced Search with the is like operator.
  • Blank fields include everything.
  • The Manager criterion returns everyone who reports to managers matching the value. Is Manager and Is Inactive are true/false filters. Type covers Employee, Contractor, External Partner, RPA/Bots, and Service Accounts.
  • Entitlement metadata filters find identities with uncertified entitlements, entitlements pending certification, entitlements that were not requested, pending requests, or entitlements that are assigned but not detected.
  • Risk attributes include composite, role, entitlement, policy, and certification scores.
  • Fields to Display chooses the result columns.

Advanced Search

Choose Advanced Search, then add filters one at a time (Field, Search Type or operator, and Value) and group them with AND/OR. The view/edit filter source link shows the generated filter string, which you can edit directly. Note that OR conditions across more than one multi-valued attribute cannot use indexes and may be slow.

Result Options

Available options depend on the search type:

OptionEffect
Save SearchSaved for your own use only. It appears at the top of the search page.
Save Search As ReportAdded to reports, so it can be scheduled and shared with users who have report access
Save Search As Identity SearchConverts an entitlement or account group search into an identity search that returns the identities holding those items
Save Identities as PopulationCreates a reusable population
Show EntitlementsLists entitlements across the results by application, with a Percent of Population column
Schedule CertificationFrom Identity Search results, launches an identity certification for selected identities. These are extra reviews, not a replacement for regular cycles.
ExportWrites the results to a file

Why Populations Matter

A population saved from Identity Search becomes a building block elsewhere:

  • QuickLink population membership (section 5.2)
  • Targeted certification "who to certify" (section 6.1)
  • Advanced policy rules and lifecycle event Include Identities (sections 7.1 and 5.1)
  • Rapid Setup trigger filters and account-only identity selection (section 5.4)
  • LCM "search by population" when requesting access, and role mining input

Advanced Analytics vs. Reports vs. the Console

Several tools can answer "who has what," and the exam expects you to pick the right one:

  • Advanced Analytics is interactive and business-friendly. It supports saved searches, populations, and certifications launched from results. Choose it for ad hoc questions, and when the result must become a population.
  • Reports are repeatable, schedulable, and support sign-off, PDF or CSV output, and email distribution. Choose them for recurring evidence. A search saved as a report bridges the two.
  • The IdentityIQ console (search, list, count) is for administrators and developers troubleshooting on the server (section 14.3), not for business users.

Scenario Practice

  • "Find how many people report to Maria Lopez." Use Identity Search with the Manager criterion set to Maria Lopez. The results are her reports, and you can save them as a population.
  • "Prove who approved access for a contractor last quarter." Use Access Requests search, or Audit search if approval actions are audited.
  • "Find entitlements with no owner, then list who holds them." Use Entitlement Search with no owner, then Save Search As Identity Search.
  • "A user reports incident code 20A7." Use Syslog search on the incident code to get the stack trace.
Test Your Knowledge

A searcher types "ro" into the Last Name field of Identity Search and wants results to include Brown as well as Roberts. What must change?

A

Nothing; basic search already uses contains matching.

B

Use Advanced Search with the "is like" operator, because basic text fields use starts-with matching.

C

Save the search as a population first.

D

Switch to Account Search.

Test Your Knowledge

A manager saves a useful Identity search, but colleagues with report access cannot see it. What should the manager do?

A

Save it again with a different name.

B

Mark the search as Searchable.

C

Use Save Search As Report, which makes it available to users with report access and allows scheduling.

D

Export it and email the file.

Test Your Knowledge

Which Advanced Analytics result option creates a reusable group of identities that can later be used as a targeted certification's "who to certify" criteria?

A

Show Entitlements

B

Save Search

C

Save Identities as Population

D

Export

Test Your Knowledge

An auditor runs Audit Search for role edits last month and gets no results, although roles were changed. What is the most likely cause?

A

Audit Search only covers the last 24 hours.

B

Role changes can only be found with Role Search.

C

The auditor lacks the Syslog capability.

D

Auditing was not configured to capture the relevant class actions, so no audit records exist.

Sections you finish are checked off in the contents.