Viewing Cloud Access
After connecting your cloud service providers and marking the cloud-enabled entitlement types, SailPoint CIEM can display the effective access that accounts associated with human identities have to your cloud infrastructure.
You can search on cloud resources or use the Access Intelligence Center (AIC) and your MySailPoint dashboard to view customized visualizations to more easily analyze and explore your identity and cloud data.
Note
Non-admin users must have the Cloud Gov User permission to view and approve SailPoint CIEM account entitlements. Refer to User Level Permissions and User Level Matrix.
Viewing Effective Access
To view the cloud resources and privileges users can access through their assigned entitlements:
- Go to Admin > Identity Management > Identities.
- Select an identity.
- Select Accounts and choose an account.
-
The entitlements assigned to the user through their account on the source are displayed in Entitlement Assignments. If the entitlements were marked as cloud enabled and grant access to cloud resources, select Yes in the Cloud Enabled column to display the effective access.
Notes
You can also access an identity's entitlement assignments by going to the source configuration and choosing their account from the Accounts section.
If you select Yes and receive a message that the user does not have effective access, this indicates the identity has an entitlement that grants cloud access, but they do not have access to any cloud resources.
-
In the effective access view, select the cloud account from the left side to see the account access granted through the set entitlement. The resources and privileges the user can access are displayed, as well as their access level and history. Cloud resource tags that were applied in your cloud environment are also shown.
To view the resources associated with other entitlements, select the Entitlement field and choose a new entitlement to display.
-
If the entitlement is on an AWS source and grants access to an AWS resource, you can select Assumable Roles. If the identity can assume AWS IAM roles, including roles that can be indirectly reached through role chaining, they can be selected from the Role field to display the associated resources and privileges.
-
For a visual representation of how the user can access the specified role through the chosen entitlement, or all entitlements, select View Access Paths above the table. You can switch between viewing the entitlement role path or all role paths.
To see the access paths the role has to a specific resource, select View in the Access Paths column of the table.
-
For all source types, you can view a visual representation of the account access granted to each resource by selecting View Access in the Access Paths column.
When you include cloud-enabled entitlements in certification campaigns, your certifiers can view this information, as well as the access paths. Refer certifiers to Viewing Cloud Access Details in the User Help for guidance on reviewing cloud-enabled entitlements.
AWS Permissions on Resources
AWS resources in the effective access view display permissions as Read, Write, or Admin. These levels summarize the IAM actions granted to the identity for that resource.
Refer to Mapping AWS Permissions on Resources for more information.
AWS CloudTrail Limitations
Some CloudTrail entries delivered by AWS services do not contain the Resource attribute, which is used to display the last activity on an AWS resource in a certification campaign. Your certifiers will still see how the resource was accessed, but might not have full activity data details.
Excluded GCP Asset Types
SailPoint CIEM displays the effective and last access data for supported GCP asset types except:
anthos.googleapis.com/ConnectedCluster |
dlp.googleapis.com/DlpJob |
networkconnectivity.googleapis.com/PolicyBasedRoutes |
bigquerymigration.googleapis.com/MigrationWorkflow |
firebase.googleapis.com/FirebaseAppInfo |
networkservices.googleapis.com/EdgeCacheKeyset |
compute.googleapis.com/RegionDisk |
firestore.googleapis.com/Database |
networkservices.googleapis.com/EdgeCacheOrigin |
containerregistry.googleapis.com/Image |
identity.accesscontextmanager.googleapis.com/AccessLevel |
networkservices.googleapis.com/EdgeCacheService |
dialogflow.googleapis.com/KnowledgeBase |
identity.accesscontextmanager.googleapis.com/AccessPolicy |
sqladmin.googleapis.com/Instance |
dialogflow.googleapis.com/LocationSettings |
identity.accesscontextmanager.googleapis.com/ServicePerimeter |
Viewing Access Paths
Access paths display between scoped objects like groups, policies, and projects granting the user access to the selected resource. This includes the direct access granted by the entitlement or all access paths to the resource. The access granted by the entitlement is highlighted.
If you are viewing access paths for AWS assumable roles, you can switch between viewing the entitlement role path and all role paths provided by the entitlement.
If a user has multiple of the same type of access at the same scope, such as multiple role assignments that lead to the same management group, you can select the node
to display the access leading to the resource. Use the Collapse icon to collapse all nodes.
Note
If your organization has licensed Machine Identity Security, you can also view the effective access for machine identities that use Microsoft Azure Service Principles and Google Cloud Infrastructure Service Accounts.
Viewing Cloud Resource Tags
The effective access view displays the native AWS tags, Microsoft Azure tags, and GCP labels associated with the cloud resources. If multiple tags or labels are associated with a resource, you can select the number in the Cloud Resource Tags column to view them.
Tip
You can use this information to validate that permissions align with your tag-based policies.
Cloud resource tags are also displayed when searching for cloud resource access.
Searching for Cloud Resource Access
You can use Search to find cloud resources, review which identities and accounts can access them, and check when that access was last used. You can search by resource name or by a tag or label applied to the resource in your cloud environment.
To search by resource name:
- Go to Search.
- Enter the name of the cloud resource, such as an S3 bucket or database.
- Select Cloud Resources from the search results table and choose a resource to view the identities and accounts with access to the resource, along with their access level (Read, Write, or Admin).
To search by tag or label:
Tags and labels are defined in your cloud environment and do not have set values. You can search by tag or label key and value, such as attributes.Name:defaultVPC, or search by value alone, such as defaultVPC.
- Go to Search.
- Enter the tag or label associated with your cloud resource. Search returns matching cloud resources for that tag or label.
Refer to Searching Cloud Resources for more information.
Viewing SailPoint CIEM Event Logs
When your cloud access data is pulled into Identity Security Cloud, you can use Search to view logs about SailPoint CIEM events. You can use these error logs to troubleshoot your GCP, AWS, Microsoft Entra ID, and Okta configurations.
-
actor.name:CIEM_SYSTEM- Allows you to view events generated by the SailPoint CIEM system. -
type:CIEM_SOURCE_MANAGEMENT- Allows you to view events related to SailPoint CIEM source management. -
type:CIEM_TEST_CONNECTION- Allows you to view logs of test connection successes and failures.
Viewing CIEM Reports in the Access Intelligence Center
If your organization has licensed the Access Intelligence Center (AIC), you can use SailPoint CIEM data to create powerful visualizations that track how human identities are using entitlements to access cloud resources and services.
For example, you can view cloud resources with large numbers of entitlements or entitlements with large numbers of resources to right-size your access model. Or you can discover departments with administrative cloud access that might be candidates for least privilege adjustments.
Go to Home > Access Intelligence Center > SailPoint CIEM. You can filter your view to focus on specific cloud providers, departments, entitlements, resource type, and more.
Notes
- To view CIEM reports in AIC, you must be assigned either the Admin or Report Admin user level with the Access Intelligence Center Reader or Author user level.
- Due to data sizing concerns, machine identities are not displayed in AIC reports.
Finding Resources and Identities with Access
- Go to Home > Access Intelligence Center > SailPoint CIEM.
- (Optional) Filter by cloud provider.
- (Optional) Filter by source name.
-
Select Resources by # of Identities to view resources and identities with access.
5.(Optional) Add additional filters to dynamically refine your view by resource types, entitlements, or access levels.
Finding Unused Access
- Go to Home > Access Intelligence Center > SailPoint CIEM.
- Filter by Entitlement Usage and select Unused to find entitlements that have not been used to access a cloud resource for 90 or more days.
Viewing Cloud Scope Status
The Cloud Infrastructure Entitlement Management (CIEM) Source Scope Insights widget on the MySailPoint dashboard provides high-level information about the status of your sources and associated scopes, the number of discovered and included scopes, and scopes with connection errors.
Refer to Managing Dashboards to learn how to add widgets to personal and shared dashboards.
Documentation Feedback
Feedback is provided as an informational resource only and does not form part of SailPoint’s official product documentation. SailPoint does not warrant or make any guarantees about the feedback (including without limitation as to its accuracy, relevance, or reliability). All feedback is subject to the terms set forth at https://developer.sailpoint.com/discuss/tos.


