↳ GitHub sourceConnector

SailPoint Identity Security Cloud (via Codeless Connector Framework)

Description

The [SailPoint](https://www.sailpoint.com/) Identity Security Cloud data connector provides the capability to ingest search events into Microsoft Sentinel through the REST API. The connector provides customers the ability to extract audit information from their Identity Security Cloud tenant. It supports connecting multiple SailPoint Identity Security Cloud tenants simultaneously - each identified by its unique Tenant ID and domain - making it easy to monitor multiple environments (production, demo, partner) from a single Microsoft Sentinel workspace. Refer to [SailPoint Developer Documentation](https://developer.sailpoint.com/docs/api/authentication/) for API authentication details.
Declared status
1
Declared author / publisher
Microsoft

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

Read and Write permissions are required.
Workspace
Workspace
SailPoint Identity Security Cloud OAuth2 Client Credentials
An OAuth2 **Client ID** and **Client Secret** with the `sp:search:read` scope are required. Create a Personal Access Token(PAT) in your SailPoint Tenant. Kindly refer to documentation on our Compass Community for step-by-step instructions.

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

Prerequisites
SailPoint Identity Security Cloud Connections
Add and manage connections to your SailPoint Identity Security Cloud tenants. You can connect multiple tenants simultaneously.
Add Connection
Add SailPoint Identity Security Cloud Connection
Tenant ID
Identity Security Cloud Domain
Client ID
Client Secret

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
SailPointIdentityNowConnector
Additional source files 2Solutions/SailPointIdentityNow/Data Connectors/SearchEvent_CCF/SailPointIdentityNow_ConnectorDefinition.jsonsource ↗Solutions/SailPointIdentityNow/Data/Solution_SailpointIdentityNow.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.