Integrating SailPoint with CrowdStrike Foundry for SecOps Identity Intelligence
SailPoint SecOps Identity Intelligence enriches CrowdStrike Falcon detections and investigations with identity context from SailPoint Identity Security Cloud. Security operations teams can investigate human users, non-human identities, and AI agents directly from the CrowdStrike tools where they already triage incidents.
By combining CrowdStrike security detections with Identity Security Cloud identity and access data, analysts can determine who or what is involved, understand the affected access, identify ownership and blast radius, and take governed containment actions without having to work in each native source.
In this architecture:
-
CrowdStrike Falcon - Provides the security detection and the analyst experience.
-
SailPoint Identity Security Intelligence for CrowdStrike Foundry - Resolves the detected subject and retrieves current identity context.
-
Identity Security Cloud - Provides identity, account, access, ownership, governance, workflow, and audit capabilities.
This allows SecOp teams to:
-
Investigate identity risk without leaving CrowdStrike Falcon.
-
Correlate detections to both human identities and non-human identities, including AI agents and applications.
-
See governed access, privilege, ownership, source, and recent activity in the context of an incident.
-
Initiate governed containment for human identities through Identity Security Cloud workflows.
-
Preserve identity-team visibility with Identity Security Cloud audit events instead of making untracked changes directly in native sources.
-
Identity Graph customers can use links to investigate relationships and potential blast radius.
Prerequisites
-
An Identity Security Cloud tenant provisioned with SecOps Identity Intelligence with a Response and Remediation license.
-
A Personal Access Token API credential for Identity Security Cloud with Identity Security Intelligence read permissions, including the
sp:identity-sec-intel:readandsp:identity-sec-intel:writeAPI scopes. -
A CrowdStrike Falcon tenant with the SecOps Identity Security Intelligence CrowdStrike Foundry app installed.
-
Applicable SailPoint Agentic Fabric capabilities and connected sources, for non-human identity and AI agent context.
-
For Response Actions:
- Identity Security Intelligence write permissions, including the
sp:identity-sec-intel:writeAPI scope. - Configured SecOps Identity Intelligence Response Action workflow template.
- Identity Security Intelligence write permissions, including the
Understanding Identity Correlation
The SailPoint SecOps Identity Security Intelligence CrowdStrike Foundry app resolves the subject from a CrowdStrike detection and requests the matching identity from Identity Security Cloud. The response identifies the subject type so the app can display the correct human or non-human identity information.
-
Human identities are resolved by work email, UPN, or Identity Security Cloud identity ID. When no UPN is present, the app can use the detected username with the configured email-domain fallback.
-
Non-human identities and agents are resolved by Identity Security Cloud ID or by source-native identifiers such as an ARN, distinguished name, service-account name, application name, or agent runtime name.
Non-human identity correlation can return a match-confidence value:
-
Exact - The source-native identifier or exact name matched. The result can be used with greater confidence.
-
Partial - A name-based result matched in part. Confirm the identity before taking action.
-
Ambiguous or conflicting - Multiple identities might match. Select the correct candidate using the detection context. Do not automate containment until the subject is confirmed.
Integrating the SecOps Identity Security Intelligence CrowdStrike Foundry App
To integrate the SecOps Identity Security Intelligence CrowdStrike Foundry app, first configure the SailPoint CrowdStrike Foundry app within CrowdStrike, and then configure the Intel Response Action workflow template within SailPoint.
Configuring the SecOps Identity Security Intelligence CrowdStrike Foundry App
Open the Identity Security Intelligence app in CrowdStrike and complete the configuration before using identity enrichment.
To configure the SecOps Identity Security Intelligence CrowdStrike Foundry App:
-
Open the SailPoint SecOps Identity Security Intelligence app in CrowdStrike.
-
In the API settings section, complete the following:
- In the Name field, enter the name of the API.
- In the Host field, enter the base URL for your Identity Security Cloud tenant API. For example 'name.api.cloud.sailpoint.com'.
- In the Client ID field, enter the client ID of the PAT created in Identity Security.
- In the Client Secret field, enter the client secret of the PAT created in Identity Security.
-
Select Save to save the configuration.
Configuring the SecOps Identity Intelligence Response Action Workflow Template
The SecOps Identity Intelligence Response Action workflow template is the default flow for the initial human containment actions. It receives the submitted response action from the Intel Response Actions trigger and routes execution according to the requested action type.
To configure the Intel Response Action workflow template:
-
Go to Admin > Workflows.
-
Select Create Workflow.
-
Select Start with a Template.
-
Locate the SecOps Identity Intelligence Response Action template.
-
Configure the template to meet your needs:
-
Add or update approval, pre-check, and notification steps to match your incident-response policy.
-
Confirm the identity lifecycle-state behavior and connected-source provisioning behavior used by each branch.
-
-
Test your workflow to ensure it works as expected.
-
Activate the workflow.
-
On the Workflows page, enable the workflow by setting the Status toggle to Enabled.
Refer to Building a Workflow from a Template for more information.
The workflow receives identity and incident context such as the target identity ID, selected account IDs, source system, external alert ID, reason, and operator. Keep those values available in approvals and notifications so reviewers can make an informed decision.
Caution
Disabling an identity or account can interrupt business operations. Add approvals or policy checks for high-impact identities and production accounts, and validate connector support before relying on account disablement.
Investigating a Detection
To investigate a detection:
-
Open an Endpoint Security detection in CrowdStrike Falcon.
-
Locate the Identity Security Intelligence panel in the detection side panel.
-
Review the resolved identity and its Identity Security Cloud context.
-
Select Refresh in the CrowdStrike detection panel to request the latest identity data from Identity Security Cloud.
-
Identity Graph customers can follow the graph link to investigate relationships and potential blast radius in Identity Security Cloud.
You can also open Identity Intelligence from the app navigation and search directly by email or Identity Security Cloud identity ID. Expand a result to inspect the available identity details.
Human Identity Capabilities
For a resolved person, the SecOps Identity Security Intelligence CrowdStrike Foundry app can provide:
- Display name, email, login alias, lifecycle status, and manager status.
- Correlated accounts, their sources, and enabled, disabled, or locked state.
- Privileged access and effective privilege level.
- Rare or outlier access for Identity Data Analysis customers.
- Recent access grants, removals, and account status changes.
- Recent certification history and governance context.
- Source-native account identifiers for correlation with CrowdStrike entities.
- Owned agents and applications for SailPoint Agentic Fabric customers.
- A link to the identity in Identity Graph for Identity Graph customers.
Non-human Identity and AI Agent Capabilities
For a resolved non-human identity, application, or AI agent, the SecOps Identity Security Intelligence CrowdStrike Foundry app can provide:
- Identity type and subtype, such as AI agent or application.
- Source-native identity, connected source, dataset, and runtime or connector attributes.
- Primary and secondary human owners.
- Human entitlements that authorize the use of the agent or application.
- Linked accounts, their environment, enabled state, and source-specific attributes.
- Whether the non-human identity is orphaned because it has no valid active primary owner.
- Authorized humans and non-human identity blast-radius summary, including impacted sources, accounts, and people.
- A match-confidence indicator for opaque or name-based correlation.
- A link to the identity in Identity Graph for Identity Graph customers.
Response Actions for Human Identities
Response actions allow a security analyst to contain a confirmed threat from the CrowdStrike detection side panel. The request is sent to Identity Security Cloud and routed through a workflow allowing approvals, pre-checks, notifications, and tenant-specific controls to be applied before execution.
Supported Actions
-
Disable Identity - Disables the human identity in Identity Security Cloud to contain access across its correlated accounts according to the configured workflow and lifecycle behavior.
-
Disable Account - Disables one or more selected accounts through Identity Security Cloud account and provisioning capabilities, limiting containment to the affected accounts.
Running a Response Action from CrowdStrike
Before initiating an action, verify the identity match, account target, and incident scope.
Important
Partial or ambiguous matches require analyst confirmation.
To run a response action:
-
Open a detection in the CrowdStrike UI and confirm that the subject resolved to the correct human identity.
-
In the Identity Security Intelligence panel, select Disable Identity or Disable Account.
-
For account disablement, select the accounts to disable.
-
Track the request in the SecOps Identity Security Intelligence CrowdStrike Foundry app. A request can move through Submitted, In Progress, and a terminal state such as Completed or Failed. If the workflow requires approval, it will remain In Progress until approved or rejected.
-
Review workflow execution history and Identity Security Cloud audit activity for the final outcome.
Response Action API and Status
Custom integrations can submit the same actions through the response actions API. The submitted request identifies the action, target human identity, optional account IDs, and source context. The context.source attribute is required and can identify CrowdStrike or another supported integration.
Submission is asynchronous. The service returns a request ID, and the caller uses the status endpoint to track progress. This allows the workflow to pause for approval, notification, provisioning, or other customer-configured steps without holding the original request open.
Refer to Intelligence API Documentation in the Developer Community for more information.
Auditing and Traceability
When a response action is submitted, Identity Security Cloud emits the Request Response Action Submitted audit event with event key INTEL_RESPONSE_ACTION_REQUESTED.
The event can include:
- Initiating actor or service and operator.
- Submission status and unique request ID.
- Target identity name, alias, ID, and identity type.
- Source integration, such as CrowdStrike.
- Action type, external alert ID, and reason.
The underlying lifecycle or provisioning operation also produces its native Identity Security Cloud audit activity. Together, these records connect the CrowdStrike alert and operator intent to the resulting identity change.
For additional guidance on the available event schema attributes, refer to the Intel Response Actions trigger.
Reviewing Function Execution Logs
Use Function Execution Logs in the SecOps Identity Security Intelligence CrowdStrike Foundry app to troubleshoot calls to Identity Security Cloud.
- Filter by status, source type, handler, or date range.
- Expand a row to inspect request and response details and errors.
- Copy the request ID to correlate the app entry with App Manager, workflow, response action, and audit records.
Troubleshooting Response Action Issues
No Data Appears in the Detection Panel
Confirm that the credentials were saved, the OAuth client has the required PAT API scope, and Email Domain Fallback is configured when detections contain bare usernames.
No Human Identity Is Found
Verify that the person exists in Identity Security Cloud and that the detection email or UPN matches the authoritative identity data.
Search by Identity Security Cloud identity ID to isolate an email correlation issue.
No Non-human Identity or Agent Identity Is Found
Use the full ARN, distinguished name, service account native identity, agent name, application name, or Identity Security Cloud identity ID.
Identifiers that exist inside connector-specific attributes might not be searchable in the current release.
Multiple Non-human Identity Candidates Are Returned
Compare the candidate source, native identity, environment, owner, and runtime attributes with the CrowdStrike detection.
Do not select a response action based on a partial or ambiguous match.
Data Appears Stale
Select Refresh in the CrowdStrike detection panel to request the latest identity data from Identity Security Cloud.
A Response Action Remains In Progress
Review workflow execution history for an outstanding approval, pre-check, provisioning request, or connector delay. Use the response action request ID to correlate the CrowdStrike entry, workflow execution, and Identity Security Cloud audit event.
A Response Action Fails
Confirm that the target is a human identity, the selected account supports disablement through its connector, the workflow is enabled, and the OAuth client has the required response action permissions. Review function logs, workflow history, and audit activity for the reason for failure.
Documentation Feedback
Feedback is provided as an informational resource only and does not form part of SailPoint’s official product documentation. SailPoint does not warrant or make any guarantees about the feedback (including without limitation as to its accuracy, relevance, or reliability). All feedback is subject to the terms set forth at https://developer.sailpoint.com/discuss/tos.