Azure IAM, LLC has published a practitioner guide answering a question that comes up on nearly every MIM to SailPoint project: how to configure separation of duties policies in SailPoint IdentityIQ so they catch toxic access combinations and survive an audit.
-- Azure IAM, LLC, an identity and access management consultancy founded in 2013, has released a guide on configuring separation of duties policies in SailPoint IdentityIQ. The guide is written for organizations moving off Microsoft Identity Manager (MIM) and discovering that SoD enforcement, which MIM never offered natively, is now expected to be in place before the first access certification campaign runs.
Separation of duties, also called segregation of duties, is the control that keeps one person from holding two entitlements that together create fraud or error risk. The classic example is a user who can both create a vendor and approve payments to that vendor. Auditors working under SOX, NIST 800-53, CMMC, and PCI DSS all look for evidence that such combinations are detected and either prevented or documented with a business justification.
According to the guide, SailPoint IdentityIQ enforces SoD through policies, and each policy contains one or more rules. IdentityIQ supports several policy types, but two carry most of the workload.
Role SoD policies flag identities that hold two conflicting business or IT roles. They are the simplest to build and the easiest to explain to an auditor, because the conflict is expressed in business language such as Accounts Payable Clerk versus Vendor Master Administrator.
Entitlement SoD policies flag conflicts at the raw entitlement level, such as two SAP transaction codes or two Active Directory groups. They catch access that arrived outside the role model, which is common in the first year after a MIM migration when legacy group memberships are still being cleaned up.
The guide walks through the configuration sequence inside IdentityIQ: create the policy under Setup, choose the policy type, define each rule with its left and right conflict sets, set the severity, assign a policy owner and a violation owner, and decide whether the rule runs in detective mode (report the violation) or preventive mode (block the access request). It then covers how violations surface in access requests, certifications, and the Policy Violations report, and how a compensating control or mitigation record is attached when the business insists on an exception.
Azure IAM highlights three mistakes that cause SoD programs to stall after a MIM migration. First, teams try to write entitlement policies before the entitlement catalog has business descriptions, so reviewers cannot tell what they are approving. Second, MIM group nesting is carried straight into IdentityIQ, which hides the real access behind layers of indirect membership and defeats the conflict check. Third, every rule is set to preventive mode on day one, requests start failing, and the business asks for the policies to be switched off. The guide recommends a detective-first rollout, a small set of high-impact rules, and a weekly violation review until the noise settles.
For teams still on MIM, the timing matters. Microsoft extended support for MIM 2016 SP2 to January 10, 2029, but the MIM Portal depends on SharePoint 2019, which reaches end of life on July 14, 2026. Azure IAM notes that most clients treat the SharePoint date as the practical deadline and use the migration itself to design the SoD model, rather than bolting it on afterward.
The company offers fixed fee MIM to SailPoint IdentityIQ migrations that include translation of MIM sync rules and workflows, a role model built from cleaned MIM groups, and an initial SoD policy set aligned to the client's compliance framework. Details on the migration approach are available at https://azureiam.com/mim-to-sailpoint
Azure IAM, LLC is based in Las Cruces, New Mexico, and serves corporate, defense, intelligence, and education clients across the United States. The consultancy specializes in Entra ID, SailPoint IdentityIQ, Okta, and Microsoft Identity Manager.
Contact Info:
Name: Robin Lilly
Email: Send Email
Organization: Azure IAM, LLC
Address: 2521 North Main Unit 1-276, Las Cruces, New Mexico 88001, United States
Website: https://azureiam.com
Source: NewsNetwork
Release ID: 89203135
If you encounter any issues, discrepancies, or concerns regarding the content provided in this press release that require attention or if there is a need for a press release takedown, we kindly request that you notify us without delay at error@releasecontact.com (it is important to note that this email is the authorized channel for such matters, sending multiple emails to multiple addresses does not necessarily help expedite your request). Our responsive team will be available round-the-clock to address your concerns within 8 hours and take necessary actions to rectify any identified issues or guide you through the removal process. Ensuring accurate and reliable information is fundamental to our mission.


