
Migrating non-human accounts to Machine Identity Security
Source: YouTube · SailPoint · published Jul 1, 2026 · 48:55
Migrating legacy non-human accounts into SailPoint's Machine Identity Security is a low-code process solved by configuring machine account classifications at the source level, eliminating the need to manually break existing correlations 0:05 2:53.
Key Takeaways:
• The core problem is that non-human accounts (bots, RPAs, servers) are buried within human identities due to legacy workarounds like service identities, causing inaccurate counts and audit issues 5:02 6:54.
• Initial ideas like using the "Remove Account" API or deleting identities were overly complex and didn't fully solve the decoupling requirement 11:01.
• The breakthrough solution uses the "Machine Account Classification" feature available in every source configuration once Machine Identity Security is enabled 17:00.
• Classification criteria (e.g., display name starts with "SRV" or name contains "service") can be configured via the UI or REST API, and accounts can be bulk-reclassified without first uncorrelating them 18:00 43:19.
• Once classified, accounts automatically populate the machine accounts list, allowing for owner assignment, succession planning, and subtypes 14:30 23:26.
By leveraging classification configurations and available APIs, organizations can seamlessly transition their non-human populations into proper machine identities and safely retire legacy workarounds 44:42.
Sources:
- 0:05 Introduction to migrating accounts into machine identity security
- 5:02 Context of non-humans buried in human identities
- 11:01 Initial flawed ideas using Remove Account API
- 17:00 Breakthrough: Machine Account Classification feature
- 23:26 Benefits of machine identities (owners, successors, subtypes)
- 43:19 Summary: no need to uncorrelate before reclassifying
- 44:42 Final steps to retire legacy objects and sources
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Identity & Access Management. Commonly maps to: Identity and Access Management (IAM), Security Architecture and Engineering. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Hi everyone. I hope you've been enjoying the session so far. We've got some fantastic topics and fantastic speakers this week and I'm so honored to be among them sharing some of the things that I've learned about migrating accounts into machine identity security. So what migration means in this context, we are going to unpack that in a few minutes. But first, my name is Amy Schillingaw. I am a technical advocate with Salepoint, which means you can find me delivering classes, multi-day classes on all things identity security, cloud, all of the AI bits, machine identity security, agent identity security, little bit of migrations, modernizations, as well as in webinars delivering my own content and also answering your questions in the communities. So where I want to start today is kind of set…