
Beyond the lift-and-shift: Architecting success in the IIQ to ISC migration
Source: YouTube · SailPoint · published Jul 1, 2026 · 57:02
This session provides a practical playbook for migrating from SailPoint Identity IQ (IIQ) to Identity Security Cloud (ISC), emphasizing that the goal is to migrate business outcomes and governance controls, not simply lift and shift old configurations 2:17-2:37.
Key Takeaways:
• Classify your objects: Categorize IIQ configurations into four buckets—Native (lift-and-shift like sources), Refactor (minor code/config tweaks like rules), Reimagine (custom workflows/UX needing redesign), and Retire (junk data or defunct artifacts) 6:19-8:10.
• Expect an operating model shift: IIQ acts as a flexible "Swiss Army knife" relying heavily on custom code, whereas ISC focuses on native configuration, though it still offers robust APIs and workflows for extensibility 4:02-6:00.
• Decouple monolithic workflows: Lifecycle events like joiner/mover/leaver processes must be broken apart in ISC, utilizing native features like lifecycle states, transforms, and birthright roles instead of a single large workflow 12:36-13:42.
• Improve security practices: Use the migration to fix bad processes, such as replacing plain-text password emails to managers with secure self-service activation links sent to new hires' personal emails 36:02-42:46.
• Execute a low-risk go-live: Deploy ISC in read-only mode alongside IIQ, validate production data via side-by-side comparison, and freeze IIQ provisioning during the cutover to ensure an easy rollback path if needed 48:16-50:47.
By focusing on native ISC constructs first and leveraging LLMs to inventory XML and draft configurations, organizations can successfully modernize their identity governance platform while reducing technical debt.
Sources:
- 2:17-2:37 Core philosophy: migrate outcomes, not nostalgia
- 6:19-8:10 The four-part classification framework for IIQ objects
- 12:36-13:42 Differences in lifecycle state and workflow handling
- 36:02-42:46 Reimagining insecure joiner workflows for the cloud
- 48:16-50:47 Go-live strategy and read-only deployment for safe cutover
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
[music] Hello everyone, my name is Ryan Willen. I am a managing consultant at Guidepoint Security. On today's session, we are going to discuss migrating from on-prim identity IQ to cloud identity security cloud. A little bit more about my background. So, I have done about three of these migrations. So, I have a lot of lessons learned that I would love to share with the community. [clears throat] So, I like to joke with my firm that, you know, I'm Cassian from Rogue One. I went to Scarif. I stole the Death Star plans. Uh, so, and I be honest, I actually had a full head of hair before I started these migrations. I'm kidding. They're not that bad. Um, but I just, you know, I'm hoping to share some tips, tricks, advice to the community to hopefully make your migrations a little bit more smooth…