
Extending ISC using Azure functions - Even for LDAP user OU moves
Source: YouTube · SailPoint · published Jul 1, 2026 · 26:09
This session demonstrates how Azure Functions can serve as a powerful extensibility enabler for Identity Security Cloud (ISC) workflows, compensating for the reduced customization options when migrating from Identity IQ 2:13-2:27.
Key Takeaways:
• ISC's multi-tenant nature restricts inline coding, leaving teams to ask "where did the code go?" when migrating from IIQ 3:00-3:11.
• Serverless functions offer benefits like language flexibility, version control via Git pipelines, serverless execution, and workflow abstraction 5:05-7:13.
• While powerful, implementation requires significant upfront coordination for WAFs, DNS, and on-prem access, though the resulting flexibility is worth the effort 8:44-9:45.
• Practical use cases include resolving identity types via JSON payloads, moving LDAP accounts between OUs for terminations/rehires, and generating sequential numbers 10:32-11:00.
• The LDAP move function integrates with CyberArk using client certificate authentication to automate credential retrieval, avoiding hardcoded passwords 19:12-20:22.
Serverless functions provide a reliable back pocket option for unlimited extensibility, ensuring teams can meet new requirements without outgrowing their ISC environment 25:16-25:55.
Sources:
- 2:13-2:27 Migration from IIQ to ISC and loss of coding freedom
- 5:05-7:13 Overview of serverless function benefits
- 8:44-9:45 Implementation challenges and setup caution
- 10:32-11:00 Resolving identity types use case
- 19:12-20:22 CyberArk integration for automated credential retrieval
- 25:16-25:55 Conclusion on unlimited extensibility options
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Identity & Access Management. Commonly maps to: Identity and Access Management (IAM), Security Architecture and Engineering. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
[music] >> Good morning, good afternoon, and good evening everyone. Hope you're having a good time at Dev Days. Uh today I want to present something that I have found to be very useful on on our team and for our company and I just want to share that with you here. So, I'm an engineer in the identity space. Uh I'm working for a mid-sized insurance company based in the US. And a little bit about me, um I implemented helped implement IIQ uh o- over 10 years ago and we have been moving to ISC in the in the past number of months here. Um in the past just been with IIQ we extensively built that out of course with uh forms and workflows, uh joiner remover leaver, attribute sync, password interception, certifications, the whole just all of all of the pieces that you would normally expect. So, we'r…