Phased Availability
Functionality available to select customers. Visit New Capability: SailPoint next generation certification for more information.
Using Campaign Filters
Use a campaign filter to create a certification campaign that includes a subset of your entitlements or users.
Creating Campaign Filters
-
Go to Search.
-
From the vertical toolbar, select the Certification Campaigns icon.
-
Select View previewed/Active in the top right.
-
From the left panel, select Campaign Filters.
-
Select Create Filter.
-
In Details, enter a name and description for the campaign filter.
-
Select Continue.
-
In Builder, select Exclusion or Inclusion.
-
Exclusion filters exclude entitlements or identities from the campaign if they meet any of the criteria listed in the Filter Builder.
-
Inclusion filters include the entitlements or identities from the campaign if they meet any of the criteria listed in the Filter Builder.
-
-
Select + Add Group to add a criteria group.
-
Configure the campaign filter criteria. Refer to Types of Campaign Filters for guidance and examples.
Notes
- Filter criteria are connected by OR operators, so identities and entitlements are filtered based on a match to any individual criteria you select.
- The Value field is not case sensitive, so words like "Eng" and "eng" are treated as the same value.
-
Select Create Filter.
Note
Campaign filters were previously called exclusion rules and were created by SailPoint. If you have exclusion rules in your org, they will still appear in your list of campaign filters.
Updating Campaign Filters
-
Go to Search.
-
From the vertical toolbar, select the Certification Campaigns icon.
-
Select View previewed/Active in the top right.
-
From the left panel, select Campaign Filters.
-
Select the campaign filter you want to update.
-
Make the edits, then select Continue.
-
Select Save Filter.
Deleting Campaign Filters
-
Select Search from the navigation menu.
-
From the vertical toolbar, select the Certification Campaigns icon.
-
Select View previewed/Active in the top right.
-
From the left panel, select Campaign Filters.
-
Select the checkbox beside the name of the campaign you want to delete.
-
Select Delete.
-
Select Delete Campaign Filter.
Types of Campaign Filters
You can filter campaigns by access profiles, identity attributes, roles, and more.
Access Profile
This criteria type includes or excludes access profiles from a campaign
Examples:
An exclusion campaign filter is created with an operation of Equals and an Access Profile value of Base Building Access. All access profiles and entitlements appear in the certification campaign except for the access profile Base Building Access.
An inclusion campaign filter is created with an operation of Contains and an Access Profile value of Engineering. All access profiles whose name contains the word "Engineering" are included in the campaign.
Notes
- Access profiles that are granted by roles or lifecycle states are not included in certification campaigns.
- If an entitlement is part of an access profile, create an access profile campaign filter to include or exclude users with that access profile.
Account Attribute
This criteria type includes or excludes certification items that match a specified value in an account attribute.
Example: To exclude people whose Box account ID includes the numbers 123, select Account Attribute as the Criteria Type, Box as the source, Account ID as the attribute, Contains as the operation, and type 123 in the text field.
Entitlement
This criteria type includes or excludes entitlements from a campaign.
Examples:
An inclusion campaign filter is created with a source of Source 1, an operation of Equals, and an entitlement of Entitlement 1. When this filter is selected, only users who have Entitlement 1 are included in the campaign, and only Entitlement 1 is shown in the certification.
An exclusion campaign filter is created with a source of Source 1, an operation of Equals, and an entitlement of Entitlement 1. When this filter is selected, all users are included in the campaign, but Entitlement 1 is excluded from all certifications and can't be approved or revoked.
An inclusion campaign filter is created with a source of Source 1, an operation of Contains, and an entitlement value of Basic. When this filter is selected, only entitlements that contain the word "Basic" appear in certifications, and only users who have those entitlements are included for review.
Notes
- Entitlements are filtered based on their display names.
- When someone is granted the Cert Admin user level, they are also granted a related entitlement. However, you cannot filter on this entitlement.
- If an entitlement is part of an access profile, only users who have the entitlement but not the access profile associated with it will be filtered by campaign filters based on that entitlement.
Identity
This criteria type includes or excludes specific identities from your campaign.
Examples:
An inclusion campaign filter is created with an operation of equals and a name of John Smith. When the filter is selected, only that identity is included in the campaign.
An exclusion campaign filter is created with an operation of equals and a name of John Smith. When the filter is selected, all applicable identities are included in the campaign except John Smith.
Identity Attribute
This criteria type includes or excludes identities based on whether they have an identity attribute that matches criteria you've chosen.
Examples:
An exclusion campaign filter is created with an attribute of Manager, an operation of Equals, and a value of john.smith, which is the account ID of John Smith. All identities with john.smith as a manager will be excluded from campaigns that use this filter.
An inclusion campaign filter is created with an attribute of Phone, an operation of Starts With, and a value of 555. Only identities with phone numbers starting with the numbers 555 are included in the campaign.
Role
This criteria type includes or excludes roles, as opposed to identities.
Examples:
An exclusion campaign filter is created with an operation of Equals and the Role Name of Role 1. Identities that are members of Role 1 do not appear in the certification campaign.
An inclusion campaign filter is created with an operation of Equals and the Role Name of Role 2. Only identities that are members of Role 2 are included in the campaign.
Source
This criteria type includes or excludes entitlements from a source you select.
Example: An inclusion campaign filter is created with an operation of Equals and a source name of Source1. Only entitlements and access profiles that appear on Source1 appear in the campaign.
Documentation Feedback
Feedback is provided as an informational resource only and does not form part of SailPoint’s official product documentation. SailPoint does not warrant or make any guarantees about the feedback (including without limitation as to its accuracy, relevance, or reliability). All feedback is subject to the terms set forth at https://developer.sailpoint.com/discuss/tos.