Skip to content

SailPoint Response and Remediation

SailPoint Response and Remediation is an identity-led incident response capability in Identity Security Cloud. It connects identity governance data to security operations, so teams can investigate identity-related threats, understand blast radius, and contain access from a governed, auditable control point. Response and Remediation includes identity intelligence for security workflows, response actions routed through workflows, and integrations with SIEM and SOAR platforms.

SecOps Identity Intelligence

SailPoint SecOps Identity Intelligence provides identity context into security investigations. Security teams can resolve an identity from an alert, review privilege and access impact, and understand how far a threat might spread before taking action.

Response actions within SecOps Identity Intelligence allow security teams to contain a threat by disabling an identity or a specific account. Actions are submitted from a connected SIEM or SOAR platform and routed through workflow templates so identity teams can apply approvals, notifications, and audit tracking. Refer to SecOps Identity Intelligence for more information.

Workflows

Workflows automate mitigation when a Response and Remediation response action is submitted. The provided workflow template can disable the selected account or accounts, or all accounts for the selected identity, in response to the submitted request.

SIEM and SOAR Integrations

SIEM and SOAR integrations present identity intelligence within the tools security analysts are using.

The SailPoint Identity Security Intelligence CrowdStrike Foundry app enriches CrowdStrike detections with identity context and can initiate response actions from the detection side panel.

Configuring Response and Remediation

Ensure you have completed initial setup within Identity Security Cloud before beginning. Refer to Getting Started in Identity Security Cloud for more information.

Have the following information ready:

  • Administrator access to your Identity Security Cloud tenant.

  • A connected identity source so response actions can disable accounts in the native system.

  • A Personal Access Token API credential for Identity Security Cloud, if you are connecting a SIEM or SOAR integration, including:

    • The sp:identity-sec-intel:read and sp:identity-sec-intel:write API scopes.
    • The Client Id and Secret.

Using Response and Remediation

After configuration is complete, security events and alerts can be correlated to identities in real time. Analysts can review identity intelligence during triage, then submit a response action when containment is required. Identity teams can review the resulting workflow executions and audit events in Identity Security Cloud.

Typical investigation steps include:

  • Confirm the identity type, status, and correlation to the alert.

  • Review privileged access, rare access, and recent access history for human identities.

  • Review ownership, orphaned status, and blast radius for non-human identities.

  • Decide whether to disable a specific account or the identity.

  • Track the response action until it completes, then review workflow execution history.

Documentation Feedback

Feedback is provided as an informational resource only and does not form part of SailPoint’s official product documentation. SailPoint does not warrant or make any guarantees about the feedback (including without limitation as to its accuracy, relevance, or reliability). All feedback is subject to the terms set forth at https://developer.sailpoint.com/discuss/tos.