•   Next SailPoint IIQ Batch Starts June 1st, 2026 — Limited to 25 Seats. Register for Free Demo.   •   100% Live Online — Zero Recordings   •   Batch Capped at 25 Students   •   LMS Portal Access Included   •   Placement Assistance Provided   •   Next SailPoint IIQ Batch Starts June 1st, 2026 — Limited to 25 Seats. Register for Free Demo.   •   100% Live Online — Zero Recordings   •   Batch Capped at 25 Students   •   LMS Portal Access Included   •   Placement Assistance Provided
SailPoint Academy Logo
Technical  •  8 min read

SailPoint IIQ Access Certification Explained — How Enterprise Compliance Reviews Actually Work

The 7 certification types, the 4 campaign phases, and a step-by-step walkthrough of how a real quarterly access review runs inside an enterprise — explained in plain English for IT professionals.

SailPoint Academy Team June 7, 2026 8 min read
7
Certification Types
4
Campaign Phases
Module 11
Of 14 in Our Curriculum
₹25K
Program Fee
Register for Free Demo
60 minutes. Live on Zoom. No payment required.

Successfully Registered!

Our team will reach you on WhatsApp within 2 hours.

No spam. No payment required. 100% free demo.
SailPoint IIQ Access Certification Explained [2026 Guide]

What Is Access Certification in SailPoint IIQ?

Access certification in SailPoint IIQ is an automated review process where designated reviewers — typically managers or application owners — examine what access users currently hold and formally approve or revoke it. IdentityIQ generates the review lists, routes them to the right certifiers, records every decision, and executes the revocations.

Think of it as the enterprise equivalent of an audit roll-call. Over time, employees accumulate access: a developer who moved from the payments team to the lending team eighteen months ago may still hold payments database entitlements nobody remembered to remove. Access certification is the structured process that catches exactly this kind of access creep before an auditor — or an attacker — does.

One terminology point trips up almost every learner. In IIQ, a certification is the overall campaign — the scheduled event defining what gets reviewed, by whom, and by when. An access review is the individual work item a single reviewer receives within that campaign. One quarterly manager certification can generate hundreds of separate access reviews, one per manager. SailPoint's official Certifications and Access Reviews documentation uses this distinction consistently, and so do interviewers.

Quick answer: Access certification = a scheduled, audited review where managers and application owners confirm or revoke user access. It is the single most audit-visible capability in SailPoint IIQ, and it is covered as Module 11 of 14 in the SailPoint Academy curriculum.

Why Do Enterprises Run Access Certification Campaigns?

Enterprises run access certification campaigns because regulators and auditors require documented, periodic proof that user access is reviewed and excess access is removed. This is not an optional hygiene practice — for regulated companies it is mandated, which is precisely why certification skills are tested in nearly every SailPoint IIQ interview.

Three regulatory drivers dominate in the enterprises that hire SailPoint professionals in India:

SOX & SOC 2

US-listed companies and BFSI GCCs in Hyderabad and Bangalore must show auditors periodic access attestation and segregation-of-duties enforcement on financial systems.

RBI IT Governance

India's Reserve Bank requires financial institutions to run periodic access reviews for employees and contractors as part of identity lifecycle controls.

DPDP Act 2023

India's data protection law pushes enterprises to prove who can access personal data — driving recurring certification of data-touching entitlements.

In practice, this means a BFSI GCC will run manager certifications every quarter, application owner certifications on critical financial apps every half-year, and event-based certifications whenever someone changes departments. Each completed campaign becomes audit evidence. When an external auditor asks "prove that access to your payments platform was reviewed this year," the IAM team exports the campaign decision history from IIQ. That export is the deliverable the entire process exists to produce.

The 7 Certification Types in SailPoint IIQ

SailPoint IIQ supports seven certification approaches, and a working consultant is expected to know when to use each. These map exactly to what Module 11 (Access Certification) of the SailPoint Academy 14-module curriculum covers:

1. Entitlement Certification

Reviews individual entitlements — the granular permissions users hold on applications. The most fine-grained review and the foundation of access governance.

2. Role Certification

Reviews role assignments and role composition — does this business role still contain the right IT entitlements, and should this user still hold it?

3. Advance Certification

Targeted, filtered certifications scoped to a precise population or access slice — for example, only privileged entitlements on a specific application.

4. Manager Certification

Each manager reviews their direct reports' access. The most commonly scheduled certification in production — usually quarterly in BFSI environments.

5. App Owner Certification

The owner of an application reviews everyone who has access to it. Standard for critical financial and customer-data systems.

6. Certification Rule

BeanShell rules that customize certification behaviour — pre-delegation, exclusion logic, escalations, and decision automation hooks.

7. Event-Based Certification

Triggered automatically by identity changes — a manager change or department move can launch an immediate review routed to the new manager.

The combination interviewers probe

Event-based certification is where Module 11 meets Module 12 (Lifecycle Events). A mover event — someone changing departments — can trigger a certification routed to the new manager automatically. Interviewers love this question because it tests whether you understand how IIQ modules connect, not just their definitions. Read our Lifecycle Events explainer for the other half of that answer.

Want to configure a real certification campaign yourself?

Attend a free 60-minute live demo before you decide — no payment, no commitment.

Attend Free Demo

The 4 Phases of a Certification Campaign

Every IIQ certification moves through up to four phases: Active, Challenge (optional), Revocation, and End. Knowing the order and what happens in each phase is one of the most reliably asked SailPoint IIQ interview questions — and the source of most real-world campaign configuration mistakes.

1

Active Phase

The review period. Certifiers work through their access reviews and make approve or revoke decisions. Decisions can be changed as often as needed until the active period expires.

Always present
2

Challenge Phase

Users marked for revocation receive a work item and email with the details. They can accept the loss of access or challenge the decision — and the certifier must respond to each challenge.

Optional
3

Revocation Phase

Approved revocations are executed. Where provisioning is connected, IIQ removes access automatically; for disconnected systems, manual work items go to application revokers.

Configurable
4

End Phase

The campaign closes and the audit record is finalized. If no revocation phase was enabled, outstanding revocations are processed during the end period.

Always present

The phase definitions above follow SailPoint's official Phases of a Certification documentation. Two details separate candidates who have actually configured campaigns from those who memorized definitions: the challenge phase is optional and frequently disabled in fast-cycle environments, and revocation can be fully automatic only where IIQ has a provisioning connection to the target application.

How a Real Quarterly Certification Campaign Runs — Step by Step

A quarterly manager certification at a typical BFSI GCC follows six steps from planning to audit sign-off. This is the workflow you would own as a SailPoint IIQ consultant or IAM engineer:

  1. Define scope and schedule. The IAM team decides what is certified (entitlements, roles, or full identity access), which applications and populations are in scope, who certifies, and the phase durations. The certification is scheduled in IIQ.
  2. Generate reviews and notify certifiers. At launch, IIQ creates one access review work item per certifier and emails them. A 400-manager organisation gets 400 access reviews in one campaign.
  3. Review during the active phase. Managers work through their lists, approving access that matches the person's current job and revoking what does not. The IAM team chases completion — in real deployments, reminder escalations are configured because managers procrastinate.
  4. Handle challenges. If enabled, users disputing a revocation raise challenges, and certifiers must resolve each one before the item proceeds.
  5. Execute revocations. Connected applications get automatic deprovisioning; disconnected ones generate manual work items that must be tracked to closure — unclosed revocation work items are a classic audit finding.
  6. Sign off and export evidence. Certifiers sign off, the campaign closes, and completion reports plus decision histories are exported as audit evidence.

What the documentation doesn't tell you: the hardest part of running certifications in production is not configuration — it is certifier behaviour. Reviewers bulk-approving everything without reading ("rubber-stamping") is the number one reason auditors reject certification evidence. Real campaigns counter this with smaller scoped reviews, exclusion rules that remove noise, and escalation reminders — all configured through the Certification Rules covered in Module 11.

How Access Certification Shows Up in SailPoint IIQ Interviews

Access certification is one of the three most-tested IIQ topics in enterprise interviews, alongside lifecycle events and application onboarding. Consultant and developer candidates at Big 4 firms and BFSI GCCs should be ready for these recurring questions:

  • Name the certification types in IIQ and explain when you would use manager certification versus application owner certification.
  • Walk through the phases of a certification campaign in order — and explain what happens if the challenge phase is disabled.
  • What happens technically when a reviewer revokes an entitlement on a connected application versus a disconnected one?
  • How would you configure an event-based certification when an identity's manager changes?
  • How do you reduce rubber-stamping in a manager certification campaign?

The pattern across all five: interviewers reward answers grounded in campaign behaviour, not definitions. Saying "the challenge phase is optional and adds a dispute window between decision and revocation" signals hands-on exposure. For the broader question bank, see our SailPoint IIQ interview questions guide, and for where certification skills fit in the larger career ladder, our IAM career paths page maps the roles that test them.

How SailPoint Academy Teaches Access Certification (Module 11)

SailPoint Academy covers access certification as Module 11 of its 14-module live online program — and it is taught hands-on, with every student configuring and running campaigns in a live IIQ environment rather than watching slides.

Module 11: Access Certification — Full Topic List

  • Entitlement Certification
  • Role Certification
  • Advance Certification
  • Manager Certification
  • App Owner Certification
  • Certification Rule
  • Event-based Certification

What You Practice Live

  • Scheduling a manager certification campaign end-to-end
  • Configuring challenge and revocation phase durations
  • Writing a certification exclusion rule in BeanShell
  • Triggering an event-based certification from a mover event
  • Reading campaign reports the way an auditor does

The program is 100% live on Zoom, capped at 25 students per batch, runs 2 months, and costs Rs. 25,000. Because the training is live online, it is accessible to IT professionals anywhere — India, the US, the UK, or the Middle East. SailPoint Academy is an independent training provider and is not affiliated with SailPoint Technologies; students receive a SailPoint Academy certificate of completion along with placement assistance, resume support, and mock interviews. Full details are on the SailPoint IIQ course page.

Frequently Asked Questions

Access certification in SailPoint IIQ is an automated review process where designated reviewers — typically managers or application owners — examine what access users currently hold and approve or revoke it. IIQ generates the review lists, routes them to the right certifiers, tracks every decision, and executes revocations. Enterprises run these reviews on a quarterly or half-yearly cycle to satisfy audit requirements like SOX and RBI IT governance guidelines.
In SailPoint IIQ terminology, a certification is the overall campaign — the scheduled event that defines what access is reviewed, by whom, and by when. An access review is the individual work item a specific reviewer receives within that campaign. One quarterly manager certification campaign might generate hundreds of separate access reviews, one for each manager certifying their direct reports.
SailPoint IIQ supports seven certification approaches covered in enterprise deployments: Entitlement Certification, Role Certification, Advanced Certification, Manager Certification, Application Owner Certification, rule-driven certifications using Certification Rules, and Event-based Certification triggered by identity changes such as a manager change or department transfer. Manager and Application Owner certifications are the two most commonly scheduled types in production environments.
A SailPoint IIQ certification moves through up to four phases: the Active phase, where reviewers make approve/revoke decisions; the optional Challenge phase, where affected users can dispute a revocation; the Revocation phase, where approved revocations are executed automatically or through manual work items; and the End phase, which closes the campaign and finalizes the audit record. Challenge and Revocation phases are configurable and not always enabled.
When the challenge phase begins, every user whose access is marked for revocation receives a work item and email with the revocation details and reviewer comments. The user can either accept the loss of access or challenge the decision within the challenge period. If they challenge it, the certifier must respond — either upholding the revocation or reversing the decision — before the campaign can move to the revocation phase for that item.
Yes — access certification is one of the most heavily tested topics in SailPoint IIQ interviews, especially for consultant and developer roles at BFSI GCCs and Big 4 consulting firms. Common questions include naming the certification types, explaining the campaign phases in order, describing what happens when a user challenges a revocation, and explaining how event-based certifications are triggered. Hands-on experience configuring a campaign is what separates strong candidates.
Best practices for enterprise access certification campaigns: scope by risk (start with privileged and SoD-sensitive access), assign reviews to the right approver (manager plus application owner), and automate reminders, escalations and revocation. Avoid rubber-stamping with smaller batches and clear remediation SLAs. Run periodic campaigns plus event-based reviews for joiners, movers and leavers — the SailPoint IdentityIQ Module 11 approach.
Hands-On IIQ Training

Learn Access Certification by Actually Running Campaigns

Attend a free 60-minute live demo — see a real certification campaign configured in a live IIQ environment, meet the trainer, and decide with complete clarity. No payment. No commitment.

Explore More from SailPoint Academy

SailPoint Academy Home SailPoint IIQ Course Full IIQ Curriculum IAM Career Paths Training in Hyderabad Training in Bangalore IIQ Lifecycle Events Explained IIQ Interview Questions IIQ Curriculum: 14 Modules
Book A Free Demo Call Now WhatsApp