SailPointIdentityIQ
SailPoint IdentityIQ context pack enables XSOAR customers to utilize the deep, enriched contextual data in the SailPoint predictive identity platform to better drive identity-aware security practices.
- Category
- Identity and Access Management
- Pack
- SailPointIdentityIQ
Configuration parameters
- identityiq_url — IdentityIQ Server URL (e.g. https://identityiq-server.com/identityiq) (required)
- client_id — Client Id (for OAuth 2.0) (required)
- client_secret — Client Secret (for OAuth 2.0) (required)
- isFetch — Fetch incidents
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- incidentType — Incident type
- max_fetch — Maximum number of incidents per fetch
- first_fetch — First fetch time
- incidentFetchInterval — Incidents Fetch Interval
Commands (12)
- identityiq-create-alert — Create an alert using IdentityIQ SCIM API's.
- identityiq-delete-account — Delete account by id using IdentityIQ SCIM API's.
- identityiq-disable-account — Disable account's active status by id using IdentityIQ SCIM API's.
- identityiq-enable-account — Enable account's active status by id using IdentityIQ SCIM API's.
- identityiq-get-accounts — Fetch accounts by search/filter parameters (id, display_name, last_refresh, native_identity, last_target_agg, identity_name & application_name) using IdentityIQ SCIM API's.
- identityiq-get-alerts — Fetch alert by id or all alerts using IdentityIQ SCIM API's.
- identityiq-get-entitlements — Fetch entitlement by id or all entitlements using IdentityIQ SCIM API's.
- identityiq-get-policyviolations — Fetch policy violation by id or all policy violations using IdentityIQ SCIM API's.
- identityiq-get-roles — Fetch role by id or all roles using IdentityIQ SCIM API's.
- identityiq-get-taskresults — Fetch task result by id or all task results using IdentityIQ SCIM API's.
- identityiq-search-identities — Search identities by search/filter parameters (id, email, risk & active) using IdentityIQ SCIM API's.
- identitytiq-get-launched-workflows — Fetch launched workflow by id or all launched workflows using IdentityIQ SCIM API's.