To provisioning... and beyond! Expanding identity automation with ISC workflows

To provisioning... and beyond! Expanding identity automation with ISC workflows

Source: YouTube · SailPoint · published Jul 1, 2026 · 48:08

Identity & Access Management
No ratings yet Log in to rate
Transcript Available
Description

This presentation demonstrates how to extend SailPoint Identity Security Cloud (ISC) beyond basic provisioning by automating the creation of personal privileged accounts in Active Directory and their management in CyberArk Privilege Cloud using modular workflows and SCIM APIs 0:25.

Key Takeaways:
• Traditional ISC provisioning often stops at account creation, but workflows can handle complex, "beyond provisioning" tasks like vaulting and credential rotation 1:32.
• The use case involves creating a personal privileged account in AD, establishing a corresponding personal safe in CyberArk, and onboarding the account for secure credential management 3:02.
• Modular workflows are preferred over monolithic ones, allowing external tools like ServiceNow to orchestrate specific steps such as safe creation and user provisioning 9:30.
• ISC roles are utilized to automatically detect when a user needs a CyberArk license, triggering the creation of a user account in Privilege Cloud if one does not exist 12:20.
• The solution leverages CyberArk SCIM APIs to dynamically create personal safes, assign permissions, and onboard accounts, ensuring proper naming conventions and access controls 8:13.
• A wait step is critical in the user provisioning workflow to ensure the CyberArk account ID is available before attempting to assign safe access permissions 30:00.

By breaking down processes into reusable API-driven components, organizations can fully automate the lifecycle of privileged accounts while maintaining strict security and operational flexibility.

Sources:

  • 0:25 Introduction to going beyond basic provisioning in SailPoint ISC.
  • 3:02 Definition of the personal privileged account use case.
  • 8:13 Explanation of using SCIM APIs for safe creation.
  • 12:20 Using ISC roles to manage CyberArk licenses.
  • 9:30 Benefits of modular workflows for external orchestration.
  • 30:00 Importance of wait steps in provisioning workflows.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Identity & Access Management. Commonly maps to: Identity and Access Management (IAM), Security Architecture and Engineering. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

[music] >> Hello and welcome everybody to Developer Days 2026. My name is Mark Chick and I am an identity governance solutions architect. Today we'll be talking about going beyond your basic provisioning in SailPoint ISC. Some may say to provisioning and beyond. So let's get started. Just a quick agenda here. Um Essentially, we're going to be explaining the use case that we're going through today. We'll be talking through the technical discovery of like how exactly we're going to do these things. A little information about how the workflows themselves will be constructed. Some more information about integrating exist or external systems such as ServiceNow to be a um orchestration layer on top of these underlying workflows. And finally, a live demo. That's what we're here to do. So let's ge…