8.2 Leveraging Advanced Analytics
Key Takeaways
Advanced Analytics search types include Identity, Access Review, Role, Entitlement, Account, Activity, Audit, Process Metrics, Access Requests, and Syslog.
Basic criteria fields are ANDed together and use starts-with matching; Advanced Search adds operators such as "is like" and grouped AND/OR filters.
Identity search results can be saved as a search, a report, or a population, and can launch an identity certification.
Saved searches are private; saving a search as a report makes it available to users with report access and lets it be scheduled.
Populations saved from Identity Search are reused in QuickLink populations, certifications, policies, lifecycle events, and Rapid Setup trigger filters.
Leveraging Advanced Analytics
Objective 3.6 asks you to leverage Advanced Analytics. Advanced Analytics (Intelligence > Advanced Analytics) answers questions such as "who has X?", "which reviews are overdue?", and "what errors happened last night?" Its most important outputs are populations that other features reuse.
The Search Types
| Search type | Finds… | Typical question |
|---|---|---|
| Identity | Identities by attributes, manager, applications, roles, entitlements, and risk | "Everyone in Finance with SAP access and a composite score over 700" |
| Access Review | Certifications and access reviews by certifier, type, phase, completion percentage, dates, and tags | "Manager reviews below 50 percent complete" |
| Role | Roles by attributes, profile, extended attributes, and dates | "Business roles owned by Jane with no description" |
| Entitlement | Entitlements (account groups and application objects) by attribute, owner, value, application, type, and target | "All AD groups owned by nobody" |
| Account | Accounts by application, display name, owner, native identity, and instance | "Accounts on App X whose native identity starts with svc" |
| Activity | Application and target activity by time period, identities, and populations | "Logins to the payroll app outside business hours" |
| Audit | Audit records by action, source, target, and date | "Who changed this role last week?" |
| Process Metrics | Business process (workflow) metrics, by participants and success or failure | "How long does LCM Provisioning take, and where does it fail?" |
| Access Requests | Current and archived access requests | "All requests pending approval for more than 5 days" |
| Syslog | Technical error records (section 14.2) | "Look up incident code 123456" |
Audit Search returns data only for actions that auditing is configured to capture (section 8.3). Activity Search needs activity data sources.
How Criteria Combine
- Different fields are ANDed. First Name John plus Last Name Doe returns only people who match both.
- Text fields use starts-with matching. "ro" in Last Name finds Roberts and Rowen but not Brown. For a contains search, use Advanced Search with the is like operator.
- Blank fields include everything.
- The Manager criterion returns everyone who reports to managers matching the value. Is Manager and Is Inactive are true/false filters. Type covers Employee, Contractor, External Partner, RPA/Bots, and Service Accounts.
- Entitlement metadata filters find identities with uncertified entitlements, entitlements pending certification, entitlements that were not requested, pending requests, or entitlements that are assigned but not detected.
- Risk attributes include composite, role, entitlement, policy, and certification scores.
- Fields to Display chooses the result columns.
Advanced Search
Choose Advanced Search, then add filters one at a time (Field, Search Type or operator, and Value) and group them with AND/OR. The view/edit filter source link shows the generated filter string, which you can edit directly. Note that OR conditions across more than one multi-valued attribute cannot use indexes and may be slow.
Result Options
Available options depend on the search type:
| Option | Effect |
|---|---|
| Save Search | Saved for your own use only. It appears at the top of the search page. |
| Save Search As Report | Added to reports, so it can be scheduled and shared with users who have report access |
| Save Search As Identity Search | Converts an entitlement or account group search into an identity search that returns the identities holding those items |
| Save Identities as Population | Creates a reusable population |
| Show Entitlements | Lists entitlements across the results by application, with a Percent of Population column |
| Schedule Certification | From Identity Search results, launches an identity certification for selected identities. These are extra reviews, not a replacement for regular cycles. |
| Export | Writes the results to a file |
Why Populations Matter
A population saved from Identity Search becomes a building block elsewhere:
- QuickLink population membership (section 5.2)
- Targeted certification "who to certify" (section 6.1)
- Advanced policy rules and lifecycle event Include Identities (sections 7.1 and 5.1)
- Rapid Setup trigger filters and account-only identity selection (section 5.4)
- LCM "search by population" when requesting access, and role mining input
Advanced Analytics vs. Reports vs. the Console
Several tools can answer "who has what," and the exam expects you to pick the right one:
- Advanced Analytics is interactive and business-friendly. It supports saved searches, populations, and certifications launched from results. Choose it for ad hoc questions, and when the result must become a population.
- Reports are repeatable, schedulable, and support sign-off, PDF or CSV output, and email distribution. Choose them for recurring evidence. A search saved as a report bridges the two.
- The IdentityIQ console (
search,list,count) is for administrators and developers troubleshooting on the server (section 14.3), not for business users.
Scenario Practice
- "Find how many people report to Maria Lopez." Use Identity Search with the Manager criterion set to Maria Lopez. The results are her reports, and you can save them as a population.
- "Prove who approved access for a contractor last quarter." Use Access Requests search, or Audit search if approval actions are audited.
- "Find entitlements with no owner, then list who holds them." Use Entitlement Search with no owner, then Save Search As Identity Search.
- "A user reports incident code 20A7." Use Syslog search on the incident code to get the stack trace.
A searcher types "ro" into the Last Name field of Identity Search and wants results to include Brown as well as Roberts. What must change?
Nothing; basic search already uses contains matching.
Use Advanced Search with the "is like" operator, because basic text fields use starts-with matching.
Save the search as a population first.
Switch to Account Search.
A manager saves a useful Identity search, but colleagues with report access cannot see it. What should the manager do?
Save it again with a different name.
Mark the search as Searchable.
Use Save Search As Report, which makes it available to users with report access and allows scheduling.
Export it and email the file.
Which Advanced Analytics result option creates a reusable group of identities that can later be used as a targeted certification's "who to certify" criteria?
Show Entitlements
Save Search
Save Identities as Population
Export
An auditor runs Audit Search for role edits last month and gets no results, although roles were changed. What is the most likely cause?
Audit Search only covers the last 24 hours.
Role changes can only be found with Role Search.
The auditor lacks the Syslog capability.
Auditing was not configured to capture the relevant class actions, so no audit records exist.
Sections you finish are checked off in the contents.