SailPoint Identity Security for the cloud enterprise manages risk from the explosion of technology access. The solution gives businesses visibility while automating and accelerating the management of all user identities, entitlements, systems, data and cloud services.
N/A
SAP NW Identity Management
Score 8.2 out of 10
N/A
SAP NetWeaver Identity Management is the software acquired by SAP from MaXware for identity management (IdM).
The customer was already using SailPoint Access Risk Management (ERP Maestro) and doesn't want to bring in SAP AC for the SOD topic. So it was easy to decide to go with SailPoint Access Risk Management (ERP Maestro).
SailPoint is a more customizable solution than Okta, it is also not just a cloud application. Our use of IIQ to manage external suppliers via Azure AD guest accounts was not available on other platforms at the point of deployment. The integration with SAP and other Microsoft …
The on-prem SailPoint IdentityIQ platform provides the necessary customization that is required in our dynamic environment. Although we may look at a cloud-based Identity Management service again in the future, (there are many advantages), our identity management, …
SailPoint and Oracle were selected for the RFP from a field of over 10 companies. SailPoint was much more mature and stable during our evaluation in 2015 and continues to lead the pack. We're confident we made the correct decision and work closely with our success team at …
I think SailPoint Identity Platform stacks better than most IAM tools and solution though a lot of SaaS IAM solutions are already available, can compete and are at par with its features and capabilities.
IdentityIQ provides a more complete solution for a fraction of the cost of other solution providers. It is easy to work with and provided very effective management of all aspects of the access management process.
All these products are really good at some key areas. They are all different and solve different parts of the puzzle. IIQ is more of a centric focal point that manages and maintains access in a vendor-agnostic way. It helps bridge the gap at the identity layer for different …
Compared to other solutions, IdentityIQ provides the best identity governance for your organization. Custom workflows and automation processes make this product more attractive to business rather than its competitors. IdentityIQ is a united, user-friendly platform to perform …
SAP IDM offers a great deal of benefits/features compared to conventional access provisioning with SAP.
1. Conventional SAP user administration solution like CUA has great limitations. e.g. only SAP systems can be managed. Low-performance issues, unreliable access provisioning, …
We are happy with the management of the Id, accounts where the user can request any access easily. Also the many connector which Sailpoint is offering in order to onboard lots of applications is quite helpful. The access review module has also have been improve so that large campaigns can we work out easily.
Where we see some improvement is on the UI as here it is not so intuitive for the end user, so that we need to make lots of communications and training so that the user is able to understand how to use it.
For the administration and creation of roles it also would be great to have some improvements here to make it more easily its management.
SAP Identity Management manages organization identities centrally with a great amount of flexibility and efficiency. Compared to the conventional SAP solution of central user administration (CUA), SAP IDM (version 7.2/8.0) delivers a great number of benefits like: 1. Availability of connectors for non-SAP application identity management,
2. Modular/granular access management in the form of context-based business role definition.
3. It can be integrated with the SAP HR system for making entire user identity management automatic.
The access request work flow and back end process is exceptional. It effectively manages all of the various pieces of a request and presents the completed request to the provisioning agent as a single record. This is very helpful to the efficiency of the process since the provisioning agent only sees the completed request rather than seeing each component as it is approved. Other systems deliver the various request components to provisioning as they are approved but cannot be provisioned without all the components. Thus creating complexity for the provisioning agent and impacting the SLAs with what looks like a delay with the provisioning process.
The system is robust enough to effectively handle the scale that we need. With 750+ applications, 24,304 individual entitlements to select from, and an average of 10,200 request transactions per month. We have never had any performance issues.
The system flexible enough to accommodate our complex business needs without needing to customize the base system. We have been able to add significant functionality to the system in order to support the business needs by extending the code rather than altering the base code. This has enabled a simple upgrade of the system without having to re-apply code enhancements.
In my previous organization, to achieve the granularity of access based on organization restrictions, we implemented enabler role-based security roles. Provisioning the enabler roles through the SAP GRC was a great challenge (realistically improbable). Here came the SAP IDM to our rescue. It has a peculiar feature of context-based business role provisioning feature.
Customized context & its association with security roles & user HR attributes, give us unique ability to achieve granularity of access provisioning.
SAP IDM integrates with the SAP HR system and identity management becomes automatic.
Technical adoption requires a high level of training and experience by the implementing teams.
SailPoint and partners offers very good training courses which I think are very good. An area of improvement can be in providing cloud VMs that users can work with to learn the IIQ tool more effectively at their own pace.
SAP Identity management should come up with connectors for almost all not SAP applications, which will enable the use of SAP IDM as a one-stop solution for organizations' identity management.
As IDM heavily relies on JAVA/SQL as a development language, finding skills resources sometimes becomes challenging. But SAP has strong support available for this product which makes it reliable for long term use within an organization.
SailPoint is a more customizable solution than Okta, it is also not just a cloud application. Our use of IIQ to manage external suppliers via Azure AD guest accounts was not available on other platforms at the point of deployment. The integration with SAP and other Microsoft services is also second to none.
SAP IDM offers a great deal of benefits/features compared to conventional access provisioning with SAP.
1. Conventional SAP user administration solution like CUA has great limitations. e.g. only SAP systems can be managed. Low-performance issues, unreliable access provisioning, and risk analysis were missing.
2. SAP IDM integrates with SAP GRC solution to perform the reliable risk analysis before access provisioning. Its context feature allows granular access provisioning.
SAP IDM has the huge potential to minimize risks arising out of disorganized identity management within an organization. As all identities are managed centrally, there is very little room for manipulation of an identity.
As this solution has the ability to integrate with SAP GRC, risk analysis becomes mandatory before any access provisioning takes place.
As the solution is automatic, hiring to employee exits is managed with a minimal margin of error.