Hybrid architecture SailPoint

Taha 80 Reputation points
2023-03-06T20:27:53.5433333+00:00

Hello experts:

We've an identity governance solution in the org and we're now in the process of integrating with Azure. I've following questions that I'm hoping you'd be able to help me with:

  1. What's the best recommendation for SailPoint to be implemented in the hybrid architecture (Local AD + Azure AD?
    Should we configure provisioning/deprovisioning of accounts/groups on local AD and let it sync with Azure AD OR should we integrate with Azure AD as well and provision/deprovision users/groups independently from both AD and Azure AD ?
  2. Is there a need to integrate SailPoint with M365 applications (Teams, Exchange online, SharePoint, etc.) as well or should Azure AD integration be sufficient ?
  3. What are the use-cases I can achieve by having Azure AD integration with Sailpoint that I cannot achieve with just local AD integration (esp. for write operations)?

Thanks much,

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,063 questions
0 comments No comments
{count} votes

Accepted answer
  1. JamesTran-MSFT 36,631 Reputation points Microsoft Employee
    2023-03-10T00:46:31.68+00:00

    @Taha

    Thank you for your post and I apologize for the delayed response! From your issue, I'll do my best to point you in the right direction and will summarize your issue below for my understanding.


    Summary:

    • SailPoint Identity IQ (on-prem) is currently used for Identity Governance - on/offboarding, transferring, etc.
    • You have your own 3rd party SSO/MFA solution and aren't looking for Azure AD SSO integration with SailPoint.
    • When it comes to Azure AD synchronization, you plan to keep Privileged accounts and groups within your local on-prem Active Directory, which is why integration between SailPoint and your on-prem AD is required.
    • Currently, you only have Azure AD for Microsoft Apps, and your local AD for on-prem apps.

    Issue:

    Since you have SailPoint as your Identity Governance solution, you're now in the process of integrating SailPoint with Azure AD and have the questions below.

    What's the best recommendation for SailPoint to be implemented in the hybrid architecture (Local AD + Azure AD? Should we configure provisioning/deprovisioning of accounts/groups on local AD and let it sync with Azure AD OR should we integrate with Azure AD as well and provision/deprovision users/groups independently from both AD and Azure AD?

    • I'm not familiar with SailPoint but I found some integration docs, and referencing the SailPoint IIQ integration with Azure AD article - it looks like the architecture points to configuring the provisioning of accounts/groups within your local AD and syncing those to SailPoint Azure Active Directory via the SailPoint Azure Active Directory connector.
    • The SailPoint Azure Active Directory connector should automatically aggregate user accounts, group permissions, and Microsoft Access Panel tiles, and maps each of these to the SailPoint Identity Cube. For more info - Identity Governance for Microsoft Azure Active Directory Customers.User's image

    Is there a need to integrate SailPoint with M365 applications (Teams, Exchange online, SharePoint, etc.) as well or should Azure AD integration be sufficient?

    • From the SailPoint documentation, there's a list of M365 Applications that're supported and it looks like they might need to be configured separately when configuring the SailPoint Azure AD connector.
    • For example, you'll need to ensure the "Manage Microsoft/Office 365 Groups" checkbox is checked when configuring Microsoft Teams, since it's aggregated as Microsoft 365 Groups. For more info - SailPoint Microsoft Teams.User's image

    What're the use-cases I can achieve by having Azure AD integration with SailPoint that I cannot achieve with just local AD integration (esp. for write operations)?

    • One benefit you can achieve by integrating SailPoint with Azure AD, is that the integration adds support for self-service access requests and approvals. Additionally, the integration propagates access changes based on employee lifecycle events like join, move, or leave across all applications (cloud or on-premises) to ensure that access is granted according to business policy. For more info - Azure AD and SailPoint.

    Links:


    I hope the information I provided is useful, and since the documentation for integration seems to be primarily on the SailPoint side, I'd also recommend reaching out to the SailPoint Support team via their Support Portal or Compass - SailPoint Community, so their experts can look into your issue as well.

    If you have any other questions, please let me know. Thank you for your time and patience throughout this issue.


    I also noticed that your recent experience was not helpful, and to better improve our processes and learn from our customers, I'm eager to know what could have been done better. Please also feel free to take a re-survey on the relevant answer and help us further improve by leaving feedback verbatim as needed.


1 additional answer

Sort by: Most helpful
  1. JimmySalian-2011 42,146 Reputation points
    2023-03-06T20:44:43.4866667+00:00

    Hi Taha,

    If there is no requirement for Onpremise AD + Sailpoint I will prefer you integrate directly with Azure AD.

    So within Azure AD you ca integrate Sailpoint as a SSO application and detailed steps are listed here in Azure Docs - https://learn.microsoft.com/en-us/azure/active-directory/saas-apps/sailpoint-identitynow-tutorial

    Answer to your Ques 2 - There is no need for other integration AAD should be enough to cover all other aspects.

    Also if you check Sailpoint docs they refer and prefer Azure AD integration and moving away from duplicating efforts in Onpremise , infact you manage mostly all the attributes and provision users via Azure AD - https://documentation.sailpoint.com/connectors/microsoft/azure_ad/help/integrating_azure_active_directory/create_account_policy.html

    Hope this helps.

    JS

    ==

    Please accept as answer and do a Thumbs-up to upvote this response if you are satisfied with the community help. Your upvote will be beneficial for the community users facing similar issues.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.