Skip to content

Connecting Access Risk Management to Identity Security Cloud

You can connect Access Risk Management to Identity Security Cloud to manage Access Risk Management application entitlement assignments, to automate access to Emergency Access Management (EAM) profiles from Identity Security Cloud, and to allow EAM requests to be made through Identity Security Cloud.

Prerequisites

The following are required before you can connect Access Risk Management to Identity Security Cloud.

Tenant and runtime prerequisites:

  • An Identity Security Cloud tenant where the Access Risk Management SaaS connector is already installed, or permission to upload the connector package.
  • Identity Security Cloud admin or source admin access to create and configure a source.
  • This is a SailPoint SaaS connector using the Identity Security Cloud connector runtime, so no customer-managed VA or node is required for normal use.
  • If building or deploying the package yourself for your tenant, you'll need Node.js 20.x, npm, SailPoint CLI, repo access, and the Identity Security Cloud connector ID with upload permission.

Access Risk Management prerequisites:

  • Access Risk Management tenant.
  • An active user with the following roles:

    • Emergency Access Profile Administrator
    • User Account Administrator
  • Access Risk Management service account credentials, including username, password, and customerId.

  • The service account must be able to authenticate and have view and management permissions for:

    • Access Risk Management users and accounts
    • Roles
    • Reporting groups
    • EAM profiles
    • EAM owners, approvers, reviewers, and requesters
    • ERP system mappings
  • The account also needs write permissions to create, update, delete, enable, and disable users, as well as edit entitlement assignments.

Setting Up the Identity Security Cloud Source

  1. In Identity Security Cloud, go to Admin > Connections > Sources.
  2. Select Create New.
  3. Search for and select the Access Risk Management connector named arm-connector.
  4. Select Configure.
  5. Enter the basic source details:

    • Source name
    • Description
    • Owner, if required by the tenant
    • Select Authoritative Source
  6. Open Source Configuration.

  7. In the Connection Configuration section, enter:

    • Login URL
    • Setup User URL
    • Authentication URL
      • For US tenants: authsvc.erpmaestro.com
      • For EU tenants: authsvc-eu.erpmaestro.com
    • Report Management URL
      • For US tenants: report-management.erpmaestro.com
      • For EU tenants: report-management-eu.erpmaestro.com
    • Emergency Access Management URL
      • For US tenants: eamsvc.erpmaestro.com
      • For EU tenants: eamsvc-eu.erpmaestro.com
    • Dashboard Service URL
      • For US tenants: dashsvc.erpmaestro.com
      • For EU tenants: dashsvc-eu.erpmaestro.com
    • Username
    • Password
    • Customer ID

    Note

    If you are unsure which URL to use, you can ask customer support or check the Network tab on your browser and look at any call to erpmaestro.com.

  8. Select Save.

  9. Go to Review and Test, then select Test Connection to confirm that Identity Security Cloud can authenticate to Access Risk Management.

  10. Once the connection test succeeds, go to Account Management > Account Aggregation on the left navigation to import Access Risk Management accounts. Refer to Manually Aggregating Accounts from a Direct Connect Source.

  11. Select Entitlement Management > Entitlement Aggregation to run an entitlement aggregation. Refer to Aggregating Entitlements for a Direct Connect Source.

    • Select All Types or Specific Types and select the checkbox for the Access Risk Management entitlement types, which may include:

      • Role
      • Reporting Group
      • EAM Requestor
      • EAM Reviewer
      • EAM Owner
      • EAM Approver
    • Select Actions, then Mark as Requestable.

  12. Review the imported accounts and entitlements.

  13. Optional: You can create Identity Security Cloud access profiles from the imported entitlements to bundle entitlements from this new source. Refer to Creating Access Profiles from Sources.
  14. Optional: You can bundle access profiles into Identity Security Cloud roles. Refer to Creating Roles.
  15. Go to Entitlement Management > Entitlements and review access items. Optionally, you can choose to enable the access items so users can request Access Risk Management access through the Identity Security Cloud Request Center. Refer to Making Access Risk Management Access Profiles Requestable.

Configuring a Connected Source

Once the source is connected, you can configure and review the source name, owner, and basic metadata of an Access Risk Management source.

  1. Go to Admin > Connections > Sources.
  2. Open the Access Risk Management source, arm-connector.
  3. Go to Source Setup > Base Configuration.
  4. Confirm the source metadata.
  5. From the left navigation, select Source Setup > Configuration Settings.
  6. Enter or confirm:

    • Login URL
    • Setup User URL
    • Disable an account if it has no access assigned
    • Authentication URL
    • Report Management URL
    • Emergency Access Managements URL
    • Dashboard Service URL
    • Username
    • Password
    • Customer ID
    • Customer IDs for delete
  7. Select Save.

Important

This page only saves source configuration. It does not create, update, disable, enable, or delete Access Risk Management accounts.

Validating the Connector Configuration

Review and test your source configuration.

  1. Go to the arm-connector source page.
  2. On the left navigation, go to Review and Test, then select Test Connection to confirm that Identity Security Cloud can authenticate to Access Risk Management.

Managing Accounts

In addition to the pages detailed in the subsections below, these pages support account management for Access Risk Management aggregated accounts:

  • Uncorrelated Accounts - Review Access Risk Management accounts that did not correlate to ISC identities.
  • Approval Settings - Configure approval behavior where applicable.
  • Attribute Sync - Configure attribute synchronization behavior where applicable.
  • Native Change Detection - Configure or review native change detection behavior where applicable.

Reviewing Account Schema

You can review the Access Risk Management account schema imported into Identity Security Cloud.

  1. From the left navigation on the arm-connector source page, go to Account Management > Account Schema.
  2. Confirm account attributes such as email, username, roles, reportingGroups, and EAM assignment attributes.

Correlating Accounts

Review how Access Risk Management accounts correlate to Identity Security Cloud identities.

  1. From the left navigation on the arm-connector source page, go to Account Management > Account Correlation.
  2. Confirm correlation rules. This connector is configured to correlate by email and display name or full name.

Aggregating Accounts

Use the Account Aggregation page to import Access Risk Management accounts into Identity Security Cloud.

  1. From the left navigation on the arm-connector source page, to to Account Management > Account Aggregation.
  2. Select Start Aggregation.
  3. After the aggregation completes, review aggregation results and account counts.

The connector examines Access Risk Management users and returns accounts to Identity Security Cloud.

Reviewing Imported Accounts

Use the Accounts page to review imported Access Risk Management accounts.

  1. From the left navigation on the arm-connector source page, to to Account Management > Accounts.
  2. Search for an Access Risk Management account.
  3. Select the account name to open the account details page.
  4. Review account attributes and assigned entitlements.

Best-practice

This page should be used primarily to review accounts, not as the normal path for manual access updates.

Creating Account Policy

Use the Create Account page to configure how Identity Security Cloud creates Access Risk Management accounts during provisioning.

  1. From the left navigation on the arm-connector source page, go to Account Management > Create Account.
  2. Confirm that the required create fields are mapped:

    • email
    • firstName
    • lastName
    • username
    • fullName
    • erpUserId
    • preferredLanguage
  3. Select Save.

Identity Security Cloud creates an Access Risk Management account when provisioning requires a new one, for example:

  • A Request Center request for Access Risk Management access where the identity has no Access Risk Management account.
  • Lifecycle provisioning that grants Access Risk Management access.
  • API-driven provisioning.

Best-practice

This page configures account creation. It is not normally the UI path where an admin manually submits a new Access Risk Management account.

Updating Access Risk Management Access

Use the Identity Security Cloud Request Center for manual, UI-driven Access Risk Management access changes.

To configure and complete access requests through the Request Center:

  1. Confirm Access Risk Management entitlements have been aggregated.
  2. Build Access Risk Management-backed access profiles or roles from the imported entitlements.
  3. Publish the access to the Request Center.
  4. From the Identity Security Cloud top navigation, select Request Center.
  5. Select New Requests.
  6. Choose whether to request for yourself, your team, or others.
  7. From the left navigation, select Roles or Access Profiles.
  8. Search for an Access Risk Management role or access profile.
  9. Select a target identity.
  10. Submit the access request or removal request.
  11. Complete any required approvals.
  12. Review the provisioning activity.

Supported Access Risk Management update areas include:

  • Roles
  • Reporting groups
  • EAM Requesters
  • EAM Reviewers
  • EAM Owners
  • EAM Approvers
  • Selected writable account attributes such as erpUserId.

Enabling and Disabling Accounts

You can enable or disable accounts from the following locations depending on your tenant's configuration:

  • Direct disable action from an account detail page, if exposed
  • Lifecycle state change that disables source accounts
  • API-driven provisioning

Caution

Not every tenant exposes a direct disable button in the source account UI.

Deleting Accounts

You can delete accounts from the following locations depending on your tenant's configuration:

  • Direct delete/deprovision action from an account detail page if exposed
  • Lifecycle termination provisioning
  • API-driven provisioning

Important

Use non-production test identities when validating delete behavior.

Managing Entitlements

You can manage the entitlements associated with a source. From the left navigation on the arm-connector source page, go to Entitlement Management > Entitlement Types.

Confirm that the following types of entitlements are available:

  • role
  • reportingGroup
  • EAMRequester
  • EAMReviewer
  • EAMOwner
  • EAMApprover

Aggregating Entitlements

Import Access Risk Management entitlements into Identity Security Cloud.

  1. From the left navigation on the arm-connector source page, go to Entitlement Management > Entitlement Aggregation.
  2. Select Start aggregation.
  3. After the aggregation completes, review totals and sample entitlements.

Reviewing Imported Entitlements

Review the entitlements that you imported from Access Risk Management.

  1. From the left navigation on the arm-connector source page, go to Entitlement Management > Entitlements.
  2. Scroll or filter by entitlement type to locate specific entitlements.
  3. Confirm the entitlement names and IDs.

Note

This page does not write to Access Risk Management. Use these entitlements to build access profiles or roles to be requested via the Identity Security Cloud Request Center.

Making Access Risk Management Access Profiles Requestable

Create access profiles that are requestable in the Identity Security Cloud Request Center.

  1. Confirm account aggregation has completed. Refer to Aggregating Accounts
  2. Confirm entitlement aggregation has completed. Refer to Aggregating Entitlements.
  3. From the left navigation on the arm-connector source page, go to Aggregation History and Connections > Access Profiles.
  4. Create or edit an access profile. For details, refer to Creating Access Profiles from Sources.
  5. Select Enable Access Profile in the top right.
  6. Select Save.
  7. Submit access requests from the Request Center. Refer to Access Requests.

Once a request has been submitted and approved (if configured to require approval) the following takes place:

  • If the identity already has an Access Risk Management account, Identity Security Cloud provisions or deprovisions the requested access.
  • If the identity does not have an Access Risk Management account and account creation is required, Identity Security Cloud first creates an account, then provisions or deprovisions the requested access.

Viewing Aggregation History and Connections

You can view aggregation history and connections for the Access Risk Management source.

To view aggregation history, go to the arm-connector source page and select Aggregation History and Connections > Access Profiles. There, you can review recent account and entitlement aggregations and confirm the status, timestamps, and totals on those aggregations.

To view source connection references and any dependencies that may be applicable, go to the arm-connector source page and select Aggregation History and Connections > Connections.

Documentation Feedback

Feedback is provided as an informational resource only and does not form part of SailPoint’s official product documentation. SailPoint does not warrant or make any guarantees about the feedback (including without limitation as to its accuracy, relevance, or reliability). All feedback is subject to the terms set forth at https://developer.sailpoint.com/discuss/tos.