
Automated identity quarantine using SailPoint
Source: YouTube · SailPoint · published Jul 1, 2026 · 57:45
This session demonstrates how to automate the quarantining of compromised identities using SailPoint's Shared Signal Framework (SSF) and Continuous Access Evaluation Protocol (CAEP) to achieve zero-lag, event-driven security responses 0:21-0:27.
Key Takeaways:
• Event-driven security proactively responds to suspicious identity behavior (like lateral movement) without manual lag time, a significant upgrade over traditional ticket-based remediation 2:07-2:52.
• SSF is an OpenID framework for transmitting security events, while CAEP defines specific event types (e.g., token claim changes, session revocations) that systems can send and receive 2:55-3:24.
• When a simulated threat is detected, SailPoint automatically places the identity into a custom "quarantine" lifecycle state—disabling access to sensitive apps like Active Directory while leaving HR access intact 10:46-11:20.
• After quarantining the user, SailPoint acts as a transmitter, pushing a "session revoked" event to downstream systems (like Azure) to immediately kill active tokens and stop lateral movement 13:00-13:30.
• The automation is built using a SailPoint workflow triggered by CAEP events, which extracts the subject ID, looks up the Identity ID, and sets the quarantine lifecycle state via API 28:59-34:00.
This approach drastically reduces the window of opportunity for an attacker by eliminating the human delay between detection and access removal.
Sources:
- 0:21-0:27 Introduction to automating quarantining with SSF
- 2:07-2:52 Explanation of event-driven security vs manual response
- 2:55-3:24 Definition of SSF framework and CAEP event types
- 10:46-11:20 Demo of automatic quarantine lifecycle state
- 13:00-13:30 SailPoint transmitting session revocation to Azure
- 28:59-34:00 Building the workflow to handle CAEP triggers
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Identity & Access Management. Commonly maps to: Identity and Access Management (IAM), Security Architecture and Engineering. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Hi there, my name is Bkari Burrell. I am a senior identity security engineer with instrumental identity and today we're going to discuss automating the quarantining of compromised identities using eventdriven security with salepoint. Uh please someone clip that because wow that is going to be like put some autotune and AI on it and send it to me because that's great. I love that. There's something there. Uh anyway so a little bit about instrumental identity. uh you can see on the screen we're a small company that we all offer a range of AM services and we assist teams with architecting and providing implementation resources designing and building custom plugins uh working with IC IQ you know the whole spectrum um and assisting with defining the you know AM programs requirements for people …