Identity security · SailPoint migration

SailPoint IdentityIQ to Identity Security Cloud migration

Moving from IdentityIQ to Identity Security Cloud is a redesign, not a copy. We inventory what your IIQ estate really does, decide what to move, rebuild or retire, and move sources in waves so joiner-mover-leaver and certifications keep working the whole way through.

IIQ + ISC
Hands-on on both platforms
5
Published SailPoint case studies
UK · US · UAE
SailPoint implementation regions
In short

MappOptimist offers SailPoint IdentityIQ to Identity Security Cloud (ISC) migration planning and delivery for enterprises and IT consultancies. We inventory the IIQ estate, decide what moves, what is redesigned and what is retired, rebuild rules, workflows and connectors on ISC's configuration-first model, then move sources in waves with both platforms reconciled until cut-over. Our engineers have implemented IdentityIQ for clients in the UAE and ISC for clients in the UK and US.

01

Problems we solve

Years of custom code nobody has mapped

BeanShell rules, custom workflows, tasks and plugins have piled up across upgrades. Before anyone can estimate a move to ISC, someone has to read what is there and work out which of it still matters.

IIQ customisations do not carry over

Guidance on SailPoint's developer community is that IdentityIQ rules, workflows and tasks are not portable. Each one has to be re-expressed as ISC configuration, a transform, a workflow or a rule that SailPoint reviews, or dropped.

Cut-over puts lifecycle and audit at risk

If provisioning stops or doubles up during the move, joiners wait for access and leavers keep it. Certification campaigns and SoD evidence also have to keep running while two platforms are live.

Connectors behave differently in the cloud

On-premise applications are reached through the SailPoint virtual appliance, aggregation and provisioning timing change, and applications built on custom JDBC or web-service logic need their connector design revisited.

02

What we build

IdentityIQ estate inventory and migration assessment

We catalogue applications and connectors, BeanShell rules, workflows, tasks, roles, SoD policies, certification definitions and reports, note which are still used, and mark each one: move as configured, redesign for ISC, or retire. The result is a scoped plan with waves and dependencies.

Rule and workflow redesign

IIQ logic is rebuilt the ISC way: identity attribute transforms and ISC workflows first, and rules only where the platform has no other option. Cloud-executed rules are prepared for SailPoint's review; connector-executed rules run on the virtual appliance.

Source and connector migration

Directory, HR and application sources are re-onboarded through ISC connectors (Active Directory, Microsoft Entra ID, JDBC, Web Services, SCIM 2.0 and REST), with virtual appliances for on-premise systems and a fresh look at applications that relied on custom IIQ connector code.

Identity profiles and lifecycle parity

Authoritative sources such as Workday, Oracle HRMS or Active Directory are mapped into ISC identity profiles and lifecycle states, and joiner-mover-leaver behaviour is tested against real HR scenarios so ISC grants and removes the same access IIQ did, or better.

Roles, SoD and certifications carried forward

Role models are cleaned up before they move rather than after, SoD policies are rebuilt and tested against current entitlements, and certification campaigns are re-created so audit evidence continues across the change of platform.

Parallel run, reconciliation and cut-over

Both platforms run side by side for each wave. We compare identities, accounts and entitlements between IIQ and ISC, fix differences before provisioning is switched over, and stay on for production support after IdentityIQ is switched off.

03

How an engagement runs

1

Assess the IdentityIQ estate

Inventory every application, rule, workflow, role, policy and campaign, check which are still in use, and agree what moves, what is redesigned and what is retired. Estimates are given at this point, based on what the estate actually contains.

2

Design the ISC target

Identity profiles, lifecycle states, source and connector design, transforms, workflows and the few rules that are really needed, plus the wave plan and the reconciliation checks each wave must pass.

3

Migrate in waves

Authoritative sources first, then applications in groups, each built and tested in a non-production ISC tenant, then run in parallel with IdentityIQ until identities, accounts and entitlements reconcile.

4

Cut over and support

Provisioning and certifications switch to ISC one wave at a time. After the final wave IdentityIQ is retired, with its audit data archived for your retention needs, and production support continues on ISC.

04

Ways to work with us

Migration project

A managed team runs the assessment, design and waves against a scope and exit criteria you agree up front. We handle delivery management; your IAM team owns decisions and sign-off.

Dedicated SailPoint engineers

IdentityIQ and ISC engineers who join your IAM team for the migration, working in your tools and ceremonies on a monthly rolling basis. You interview and approve everyone before they start.

White-label delivery for consultancies

If you have won an IIQ to ISC programme and need engineers, our SailPoint team delivers under your brand and delivery lead, either filling roles or running a workstream such as connector migration or reconciliation.

Need individual engineers rather than a project? See the roles you can hire and their rates.

05

Technology we work with

Source and target platforms
SailPoint IdentityIQ 8.xSailPoint Identity Security CloudVirtual appliance
ISC target components
Identity profilesLifecycle statesTransformsISC workflowsCloud-executed rulesConnector-executed rules
Identity sources and targets
Active DirectoryMicrosoft Entra IDWorkdayOracle HRMSEnterprise applications
Connectors and customisation
JDBCWeb Services connectorSCIM 2.0REST APIsBeanShellPowerShell
07

Frequently asked questions

Can IdentityIQ rules and workflows be moved to ISC as they are?

No. Guidance on SailPoint's developer community is that IdentityIQ rules, workflows and tasks are not portable. In ISC, logic is expressed as configuration, transforms and ISC workflows where possible. Rules are a last resort: cloud-executed rules are reviewed by SailPoint before deployment, and connector-executed rules run on the virtual appliance. Deep Java customisations and IIQ plugins have to be redesigned or retired.

What carries over more directly from IdentityIQ?

Identity and role models, SoD policies, access requests, certifications and email templates map closely to ISC and can often be migrated in bulk with SailPoint's tooling, though role and policy logic still needs redesign rather than a straight copy. Accounts and entitlements are re-aggregated from sources in ISC. IIQ audit history does not move into ISC, so plan how it will be archived and kept for your retention period.

Do we have to move everything to ISC at once?

No. We plan a phased migration in which IdentityIQ and ISC run side by side. Authoritative sources move first, then applications in waves. Each wave is reconciled between the two platforms before provisioning and certifications switch to ISC, so there is a way back if a wave does not reconcile.

How does this fit with SailPoint's own migration tooling?

In June 2026 SailPoint announced Agentic Acceleration, AI-assisted tooling delivered through its forward deployed engineers to convert IdentityIQ configurations for ISC. Tooling speeds up conversion. The work around it still has to be done: deciding what should move, testing lifecycle behaviour against real HR data, onboarding custom applications and reconciling access before cut-over. We do that work alongside whatever SailPoint provides.

What is SailPoint Human Fabric, and does it change the plan?

In August 2026 SailPoint introduced Human Fabric, which it describes as the evolution of Identity Security Cloud. The target is still SailPoint's SaaS platform, so the migration approach on this page applies: inventory the IIQ estate, redesign for configuration first, move in reconciled waves. We confirm current product names and features with you during the assessment.

Have you migrated IdentityIQ to ISC before?

We have no published migration case study. Our published SailPoint work is implementation and enhancement on each platform: IdentityIQ 8.x for a healthcare provider and a bank in the UAE, and Identity Security Cloud for a global miner in the UK and a Fortune 500 distributor and a cybersecurity firm in the US. A migration needs exactly that depth on both sides.

How is an IdentityIQ to ISC migration priced?

The assessment and each wave can be quoted as a scoped project, or you can bring in engineers billed per person on a monthly rolling basis. Our 2026 rate card lists an Identity & Access Management (IAM) Consultant at $46/hr (2-3 years), $54/hr (4-6 years) and $62/hr (6+ years). Rates are indicative and confirmed per engagement scope, duration and resource availability.

Plan your IdentityIQ to ISC migration

Tell us what your IdentityIQ estate looks like today: version, number of applications, custom rules and where you are with SailPoint. We will come back within one business day with how we would assess it.