by SailPointTechBag Intel Page

IdentityIQ

IdentityIQ is SailPoint’s on-premises identity governance platform — running in your own data centre, which answers residency and processing by construction. And the correction worth making: there is no announced end-of-life, whatever you have been told.

Data residency & processing

IdentityIQ runs on infrastructure you own, which answers residency and processing together by construction — there is no region to confirm and no sub-processor list to negotiate, because the software never leaves your building. That is the cleanest possible answer where a regulator specifies where the SYSTEM runs rather than only where data rests, and it is a genuine advantage over any SaaS deployment including SailPoint’s own. The trade is that you own the infrastructure, upgrades, tuning and disaster recovery— real cost that belongs in the comparison.

On CERT-In: the 180-day ICT log duty applies to you as the regulated entity, not to SailPoint. CERT-In’s own FAQ permits storage outside India provided logs are producible to the authorities in reasonable time — but if you are IRDAI-regulated, the 2023 audit annexure asks as a plain yes/no whether ICT logs are stored in India, and that is where an offshore region actually costs you.

NO announced end-of-lifeResidency by construction⚠️ You own the operations

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
The category
on-premises
IGA
End of life
still supported
None announced
Residency
your DC
By construction
The trade
upgrades, tuning
You run it

Quick answer

IdentityIQ is SailPoint's on-premises identity governance product, and the most useful thing this page can do is correct the thing the industry keeps telling you about it. There is no announced end-of-life for IdentityIQ. Thousands of enterprises still run it, SailPoint still sells and supports it, and a typical migration to the cloud platform takes two to three years with both systems running in parallel throughout. This is a decade-scale transition, not a cliff, and anyone presenting it as urgent is selling you a project rather than answering a requirement. What IdentityIQ actually is: the full identity governance capability set — access certification campaigns, joiner-mover-leaver provisioning, role modelling and mining, segregation-of-duties policy and the attestation evidence trail — running inside your own data centre on infrastructure you control. That last part is the reason it still matters in India. For a public-sector body, a defence-adjacent contractor or a bank whose regulator has been explicit about where systems may run, on-premises is not a legacy preference; it is the requirement, and it satisfies both data residency and data processing by construction because the software never leaves your building. There is a second, less obvious reason organisations stay: IdentityIQ's rules and workflow engine is genuinely more flexible than Identity Security Cloud's. The cloud platform trades some of that granularity for configuration-driven simplicity, which suits most organisations and occasionally frustrates the ones with genuinely unusual requirements. If your governance logic is complex enough that you write rules rather than configure policies, that flexibility is a feature you would lose. The honest counterweights. You own the infrastructure, the upgrades, the database tuning and the availability — all real operational cost that the cloud platform absorbs on your behalf. New capability tends to land in Identity Security Cloud first. And the same category economics apply: implementation typically runs two to three times licence cost, and below roughly a thousand identities an enterprise IGA programme is hard to justify in any form. Pricing is quote-only. TechBag scopes the migration question honestly — including the option of not migrating yet — and invoices in INR with GST. Read more ↓ Show less ↑
Part 01 · Orient

The SailPoint platform family

This page covers IdentityIQ — the on-premises line. The rest of the portfolio:

Quick facts

30-second orientation
Product
IdentityIQ — SailPoint's ON-PREMISES IGA
Vendor
SailPoint (Nasdaq: SAIL)
✅ End of life
NONE ANNOUNCED — still sold and supported
Migration reality
2–3 YEARS, both platforms in parallel
Where it runs
Your data centre, your infrastructure
Residency
Satisfies storage AND processing by construction
The other reason to stay
Rules engine MORE flexible than the cloud's
The trade
You own upgrades, tuning, availability
New capability
Tends to land in Identity Security Cloud first
Pricing
QUOTE-ONLY — and services are 2–3× licence
Upgrade path
Free assessment; connectors and rules carry across
In India via
TechBag — honest migration scoping, INR, GST
Part 02 · Learn

Understand identity governance before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is IdentityIQ?

SailPoint’s on-premises identity governance platform — certification, provisioning, role mining, SoD and the evidence trail, running in your own data centre. No end-of-life has been announced.

A forced migration vs a decision you time — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionA migration you did not need yetIdentityIQ (SailPoint)
Where it runs(cloud: a region you confirm)Your data centre
ResidencyA vendor commitment about storageBy construction — no region to ask about
Processing locationOften unanswered separatelySame building as storage
Rules & workflow(cloud: configuration-driven)You can write the logic
Infrastructure(cloud: absorbed by the vendor)⚠️ Yours — upgrades, tuning, DR
New capability(cloud: lands here first)Follows later
End of life(the claim you keep hearing)NONE announced
Migration(framed as urgent)2–3 years, when YOU choose

On-premises identity governance that answers residency AND processing by construction — and a rules engine more flexible than the cloud platform’s. The correction that matters: no end-of-life has been announced, and migrations take 2–3 years in parallel, so anyone using a date to create urgency is selling a project. Honest trade: you own infrastructure, upgrades, tuning and DR, and new capability lands in the cloud first.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
The foundation

It Runs In Your Data Centre

The whole point

IdentityIQ is installed on infrastructure you own and control. For an organisation whose regulator has been explicit about where systems may run, that is not a preference — it is the requirement, and it answers both storage and processing questions by construction because the software never leaves your building. No region to confirm, no sub-processor list to negotiate.

02
The flexibility

The Rules Engine

Where it beats the cloud

IdentityIQ's rules and workflow engine is more flexible than Identity Security Cloud's. The cloud platform trades granularity for configuration-driven simplicity, which suits most organisations well. If your governance logic is genuinely unusual — the kind where you write rules rather than select policies — that flexibility is something you would give up by moving, and it is the second most common reason estates stay.

03
The scope

Full Governance Capability

Not a cut-down edition

Access certification campaigns, joiner-mover-leaver provisioning, role modelling and mining, segregation-of-duties policy and the attestation evidence trail. This is not a lesser product than the cloud platform — it is the same discipline delivered differently, and for years it was the product that made SailPoint the category leader.

04
The honest trade

The Operational Burden

What you take on

You own the infrastructure, the upgrade cycle, the database tuning, the availability and the disaster recovery. All of that is real cost and real staffing that the cloud platform absorbs on your behalf. Weigh it honestly: on-premises is cheaper on paper and rarely cheaper in total unless residency or rules flexibility genuinely require it.

05
The option

The Path To Cloud, When You Want It

Not a deadline

SailPoint runs an upgrade programme with a free assessment that typically takes four weeks, and configured connectors, objects and rules can carry across because both platforms share an identity model and connectivity framework. The path exists and is reasonably well trodden. What does not exist is a date by which you must take it.

One telemetry fabric across endpoint, cloud, and network — threats correlated once, not chased console to console.

Part 03 · Evaluate

Twelve capabilities. Deploy, govern, own.

IdentityIQ runs identity governance inside your own data centre — no region to confirm, no processing question left open — the on-premises line of portfolio, and paired with the human firewall.

Monitor
On-premises

Runs On Your Infrastructure

Installed in your data centre, on servers you control, inside your network. The answer to a residency requirement that a SaaS region cannot fully satisfy — because there is no region to ask about. Your building, your rules.

Monitor
Entitlement discovery

Entitlement Discovery & Correlation

Finding granular permissions inside each application and correlating them to the people holding them. The foundation of governance, and usually the moment an organisation learns how much access it could not account for. The inventory nobody had.

Monitor
Reporting

Governance Reporting

Reporting on entitlements, campaign progress and policy violations — running against a database you own, which for some auditors is itself the point. Query it directly if you need to.

Manage
Certification

Access Certification Campaigns

Scheduled reviews where managers and application owners confirm access is still appropriate, with the evidence trail an auditor asks for. The same discipline as the cloud platform, delivered on your own infrastructure. The review, on your kit.

Manage
Provisioning

Lifecycle Provisioning

Accounts created on joining, updated on role change and revoked on departure, driven by HR or directory events rather than by a ticket somebody remembers. Day one, and the last day.

Manage
Rules engine

Rules & Workflow — The Flexible One

More flexible than Identity Security Cloud's, which is precisely why complex estates stay. If your governance logic needs writing rather than configuring, this is the capability you would lose by migrating. Write the logic, do not select it.

Manage
Role management

Role Modelling & Mining

Deriving roles from actual entitlement data and managing them as the organisation changes. A genuine analytical project in either deployment model — and a substantial part of why implementation costs what it does. Real work, not configuration.

Automate
SoD policy

Segregation-Of-Duties Rules

Detecting and preventing toxic combinations of access — raising a purchase order and approving it, creating a vendor and paying it. The question regulated Indian auditors ask most directly. The combination, not the permission.

Automate
Access requests

Self-Service Access Requests

Requests through a catalogue, approvals routed by policy, provisioning on approval — and a record of why each grant was made. Requests with a reason attached.

Automate
Connectors

Connectors To Your Applications

Including the legacy and in-house systems that are often the reason an estate is on-premises in the first place. Scope this list before anything else — it predicts your timeline more reliably than any other factor. The connector list IS the plan.

Automate
Upgrade path

Migration To Identity Security Cloud

A free assessment taking around four weeks, with configured connectors, objects and rules able to carry across since both platforms share an identity model. Available when you want it — and there is no date by which you must. The option, not the deadline.

Automate
⚠️ You run it

Infrastructure, Upgrades, Availability

The database, the servers, the upgrade cycle, the tuning, the DR plan — all yours. Real cost and real staffing that the cloud platform would absorb. On-premises is cheaper on paper and rarely cheaper in total unless residency or rules flexibility genuinely require it. Be honest in the business case.

See it, don’t just read it

Watch the SailPoint platform in action

The platform this sits alongside.

SailPoint (official)·Overview

SailPoint Identity Security Cloud Overview

The cloud platform IdentityIQ sits alongside.

SailPoint (official)·Guide

A guide to SailPoint Identity Security Cloud

What the migration target actually looks like.

SailPoint (official)·NERM

SailPoint Non-Employee Risk Management Overview

The contractor and partner add-on.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why IdentityIQ

Migrate on their timetable. Or on yours.

Here’s what genuinely justifies staying on-premises — and when it does not.

01

There is no end-of-life, and you are probably being told there is

This is the correction worth making, because a great deal of noise in this market says otherwise and that noise has a commercial motive. The facts: SailPoint has announced no end-of-life for IdentityIQ. It still sells it, still supports it, and thousands of enterprises still run it in production. A typical migration to Identity Security Cloud takes two to three years, with both platforms running in parallel for most of that period. Industry commentary describes this as a decade-scale transition rather than a cliff, and skills in IdentityIQ remain in demand accordingly. Why the noise exists: a migration is a large services engagement. Systems integrators and consultancies have an entirely rational interest in framing it as urgent, and the framing is often sincere — cloud genuinely is where new capability lands first. But urgency and benefit are different arguments, and only one of them is being made when someone tells you the clock is running. What that means for your planning: treat migration as a roadmap decision you time against your own drivers — a hardware refresh, a data-centre exit, a capability you actually need that only exists in the cloud platform. Not as a deadline someone else set. If none of those drivers is present this year, staying is a legitimate answer and not technical debt. What we will not do: pretend there is no case for moving. New capability does land in Identity Security Cloud first, the operational burden of running IdentityIQ yourself is real, and for most organisations the cloud platform is where they will end up. The point is that you choose when. The value: a fully supported on-premises governance platform with no forced end date. TechBag scopes the migration honestly, including the option of not doing it yet.

02

On-premises answers the residency question completely

Every cloud identity governance evaluation in India eventually reaches the same conversation about data regions, and IdentityIQ sidesteps it entirely. The problem it solves: for a SaaS product, residency is a question you have to ask, get answered in writing, and then keep checking. Even where the answer is good — SailPoint's own Identity Security Cloud runs in AWS Mumbai with explicit isolation language, which is the strongest documented position in this category — you are relying on a vendor commitment about storage, and processing location is typically a separate question that often goes unanswered. What on-premises gives you: the software runs on servers in your building, on infrastructure you own. There is no region to confirm, no sub-processor list to negotiate, no distinction between where data is stored and where it is processed, because both are simply where you put the machine. For a public-sector body, a defence-adjacent contractor, or a bank whose regulator has been explicit about system location, that is not a preference — it is the requirement. Who this genuinely matters for: organisations under a regulator that names system location rather than data location; estates where an air-gapped or network-isolated deployment is mandated; and buyers whose own clients impose residency terms they must be able to evidence rather than assert. What it costs you: you own the infrastructure, the upgrades, the tuning, the availability and the disaster recovery. That is real money and real staffing, and it is why on-premises is cheaper on paper and rarely cheaper in total. The honest test: if residency or rules flexibility do not genuinely require on-premises, the cloud platform will probably cost you less overall. The value: residency and processing answered by construction rather than by contract. TechBag will tell you when you do not actually need that.

03

The rules engine is more flexible — and that is a real reason to stay

The less-discussed reason complex estates remain on IdentityIQ has nothing to do with residency. It is that the on-premises rules and workflow engine bends further than the cloud platform's. What the difference is: IdentityIQ lets you write governance logic. Identity Security Cloud favours configuration — you select and parameterise policies rather than author them. For the large majority of organisations that trade is a clear win: configuration is faster to implement, easier to hand over, less fragile across upgrades, and does not require someone on staff who understands the rules language. That is exactly why SailPoint made it. Where it bites: estates whose governance logic is genuinely unusual. Approval chains that depend on conditions the platform does not model natively. Certification scoping driven by business rules specific to your organisation. Provisioning logic that has to reconcile systems nobody else has. If your current IdentityIQ implementation contains rules that took real engineering to write, the honest question in any migration assessment is whether those rules can be expressed as configuration — and sometimes the answer is no, or not without changing the process they encode. How to test it before deciding: take your three most complex governance rules and ask specifically how each would be implemented in Identity Security Cloud. Not whether the platform 'supports' the requirement in general terms — how those three would actually be built. That conversation tells you more about your migration than any feature comparison. The value: flexibility that is genuinely lost in the move, and worth knowing about before somebody assures you the migration is like-for-like. TechBag runs that three-rules test as part of any migration assessment.

04

The same category economics still apply

Nothing about on-premises deployment changes the fundamental cost shape of an identity governance programme, and it is worth saying so because the licence sometimes looks cheaper and misleads people. What stays the same: implementation typically runs two to three times licence cost, in either deployment model. The work is connectors to your applications, role modelling against real entitlement data, and designing certification campaigns that managers complete meaningfully rather than rubber-stamp. None of that gets cheaper because the software runs in your building. And below roughly a thousand identities, the fixed programme cost is difficult to justify against the benefit regardless of where it runs. What is different, and worse: you add the infrastructure, the upgrade cycle, the database administration, the availability engineering and the disaster-recovery plan. Those are ongoing costs with names and salaries attached, and they do not appear on the licence quote. A business case that compares an on-premises licence against a SaaS subscription without pricing the operational side is comparing two different things. What is different, and better: no per-identity subscription growing every year, and no renegotiation at renewal. For a large, stable identity population over a long horizon, that can genuinely work out. The honest arithmetic: model both over five years including staff time, not three years including licence only. Most organisations that do this properly find the cloud platform wins unless residency or rules flexibility force the issue — and the ones for whom it does not win usually know exactly why. The value: a clear-eyed comparison rather than a licence-line one. TechBag builds the five-year model with the operational cost included, and will tell you when it does not favour us.

05

The honest scope

IdentityIQ is SailPoint's on-premises identity governance platform: access certification, lifecycle provisioning, role modelling and mining, segregation-of-duties policy and the attestation evidence trail, running on infrastructure you own. Where it genuinely wins: residency and processing answered by construction rather than by contract, which for regulated public-sector, defence-adjacent and some BFSI buyers is the requirement rather than a preference; and a rules engine more flexible than the cloud platform's, which matters for estates whose governance logic is genuinely unusual. Both are real advantages and neither is nostalgia. Where the cloud platform fits better, plainly: SailPoint Identity Security Cloud absorbs the infrastructure, upgrades, tuning and availability burden, gets new capability first, and runs in the AWS Mumbai region with documented isolation — which satisfies most Indian residency obligations without you owning a data centre. For the majority of organisations, that is the better answer, and we would rather say so than sell you infrastructure you did not need. Where something else fits better: if your driver is provisioning speed rather than audit evidence, a lighter product costs far less. If your estate is SAP-heavy and segregation-of-duties analysis is the point, look at Saviynt's Application Access Governance. And below roughly a thousand identities, an enterprise IGA programme is hard to justify in any deployment model. The limits to weigh: you own the operational burden and it is not small; new capability lands in the cloud platform first; implementation still runs two to three times licence; and pricing is quote-only. So the honest positioning: IdentityIQ remains a fully supported, capable product with no end-of-life, and it is the right answer when residency or rules flexibility genuinely require on-premises. When they do not, the cloud platform usually costs less in total. TechBag models both over five years, in INR with GST.

No end-of-life
None announced — still supported
Residency
By construction, not by contract
⚠️ The trade
You own upgrades and availability
Proof, not promises

The numbers behind the platform

0 announced end-of-life
IdentityIQ is still sold and supported
SailPoint
2–3 years
A typical migration, both platforms in parallel
Industry reporting
100% in your DC
Storage AND processing, by construction
Deployment model
~4 weeks
SailPoint's free upgrade assessment
SailPoint
up to 3× licence
⚠️ Implementation — same in either model
Third-party reported
5-year model
Include staff time, or the comparison misleads
TechBag method

What your IdentityIQ evaluation looks like

Day 0

Establish whether you actually need on-premises

Does your regulator specify where the SYSTEM runs, or only where data rests? If it is the latter, SailPoint's AWS Mumbai region probably satisfies it and the cloud platform will cost you less in total. On-premises earns its operational burden when the requirement is genuinely about system location, or when you are air-gapped.

Phase 1

Run the three-rules test

If you are weighing a migration, take your three most complex governance rules and ask specifically how each would be built in Identity Security Cloud — not whether the platform 'supports' the requirement, but how those three would actually be implemented. That conversation tells you more than any feature comparison, and it is where the rules-engine difference becomes concrete.

Phase 2

Model five years, with staff time in it

Compare on-premises licence plus infrastructure, DBA time, upgrade cycles, availability engineering and DR against the SaaS subscription. Three years and licence-only is the comparison that misleads. Scope the connector list in this phase too — it drives implementation cost in either model.

OngoingOptimise

Migrate when a driver appears, not on a rumour

A hardware refresh, a data-centre exit, or a capability that only exists in the cloud platform — those are drivers. 'It is end-of-life' is not, because it is not true. TechBag reviews the position annually and invoices in INR with GST.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.2
800+ reviews*
84% would recommend
Residency by construction4.9
Rules & workflow flexibility4.7
Governance capability4.5
Operational burden on you2.9
5
48%
4
31%
3
13%
2
5%
1
3%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Public Sector
Our regulator asks where the system runs, not where the data rests. On-premises answers that in one sentence and no cloud region does. That is the entire reason we are still here.
Head of IT
Public Sector
Banking
We were told three times that IdentityIQ was end-of-life. It is not, and SailPoint confirmed as much. We planned a migration on our own timetable instead of somebody else's.
Identity Architect
Banking
Insurance
The three-rules test was the useful part of our migration assessment. Two of our complex approval rules translated cleanly to configuration. The third did not, and knowing that changed the plan.
IAM Lead
Insurance
Manufacturing
Honest warning: the licence looked cheaper than the SaaS subscription and the total was not. Once we costed the DBA time, the upgrade cycle and the DR plan, the gap closed almost entirely.
Infrastructure Manager
Manufacturing
Defence
New capability shows up in the cloud platform first. We accepted that trade for residency reasons, but it is a real trade and worth going in with your eyes open.
Security Architect
Defence
Financial Services
TechBag modelled both options over five years with our staff costs included. It did not favour the on-premises option for us and they said so, which is why we trusted the rest of the analysis.
IT Director
Financial Services
Conglomerate
The rules engine is why we stayed. Our certification scoping logic is genuinely unusual and it took real engineering to write. Nobody has yet shown us how to express it as configuration.
GRC Manager
Conglomerate
Healthcare
Connector work dominated the project, exactly as we were warned. Two legacy in-house applications took longer than everything else combined.
Programme Manager
Healthcare
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the identity governance market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Identity Governance Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
IdentityIQThis page

On-premises governance. This page's product.

Grid 02 · The architecture

Flexibility × Operational burden

The grid nobody publishes — how far the rules engine bends vs how much you must run yourself.

Point toolsBest-of-breed platformLegacy AV/appliancesHeavy suites
IdentityIQThis page

Deep and flexible; you own the operations.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

IdentityIQ vs the field — starting with its own cloud sibling

Identity Security Cloud, One Identity Manager, Saviynt, ManageEngine and Omada — honest lanes. The first comparison is against SailPoint’s OWN cloud platform: if you have no hard on-premises requirement, it costs less in total and we will say so.

DimensionIdentityIQIdentity Security CloudOne Identity ManagerSaviyntManageEngine AD360Omada
PositionSailPoint on-premisesSailPoint's cloud platformEstablished, on-prem heritageConverged IGA+PAM+AAGAD-centric governance modulesPure IGA, European
Runs on-premisesYes — the whole pointNo — SaaS onlyYesSaaSYesCloud Private in your Azure tenant
Residency answeredBy construction — both storage and processingAWS Mumbai, documented for STORAGEBy construction if on-premIndia tenants, regions unnamedBy construction if on-premNo India region
Rules flexibilityWrite the logic — more flexibleConfiguration-drivenHighly customisableConfiguration-drivenLimitedConfig over code by design
Who runs the infrastructure⚠️ You do — real costSailPointYou doSaviyntYou do (on-prem)Omada (standard cloud)
New capability firstFollows the cloud platformLands here firstSteadyCloud-pacedSteadyCloud-paced
Best fitRegulators that name system LOCATION; unusual rules logicMost organisations — less to run, Mumbai regionOn-prem heritage estatesSAP-heavy estates needing ERP SoDAD-centric estates wanting lighter governancePure IGA where India presence is not a constraint
Strong Partial / add-on Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which cybersecurity approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose IdentityIQ if…

  • Your regulator specifies where the SYSTEM runs, not just where data rests — on-prem answers storage and processing together
  • You are air-gapped or network-isolated, and SaaS is not on the table at all
  • Your governance logic genuinely needs writing rather than configuring — the rules engine bends further than the cloud's
  • You already run it: there is NO announced end-of-life, and migration is a decision you time

Identity Security Cloud if…

  • You do not have a hard on-prem requirement — it absorbs the infrastructure, upgrades and availability burden, gets new capability first, and the AWS Mumbai region satisfies most Indian residency obligations

Saviynt if…

  • Your estate is SAP-heavy and ERP segregation-of-duties analysis is the driver — its Application Access Governance module goes further

Something lighter if…

  • Your real problem is provisioning speed rather than audit evidence, or you are under ~1,000 identities

Do NOT migrate just because…

  • Somebody told you IdentityIQ is end-of-life. It is not. Migrate when a real driver appears — a hardware refresh, a data-centre exit, a capability you actually need

IdentityIQ is one of 16 identity governance products TechBag carries. The Identity Governance guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does a premature migration cost you?

Drag the sliders (identity count; IT hourly cost as a loaded rate). Estimates contrast manual access reviews against automated certification. NB: this models the REVIEW effort saved, and for on-premises there are two costs it does NOT model — implementation at 2–3× licence, and the infrastructure, upgrade, DBA and DR burden you take on. Model five years with staff time included before comparing against a SaaS subscription. Illustrative.

300
2510,000
800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual cost of running it yourself
₹3,60,000
Estimated annual savings
₹2,52,000
₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote-only, with no published rate card. Two cost layers for on-premises. The same category economics apply — implementation typically runs 2–3× licence, because connectors, role modelling and certification design are the real work in either deployment model. AND you own infrastructure, upgrades, database administration, availability and DR — ongoing costs with salaries attached that never appear on a licence quote. Model FIVE years with staff time included; three years licence-only favours on-premises misleadingly. TechBag builds that model and will tell you when it does not favour us.

IdentityIQ

Best when system location is mandated

  • QUOTE-ONLY — no published rate card
  • Runs in YOUR data centre — storage and processing answered together
  • NO announced end-of-life; migration is a decision you time

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

+ what you own

Best costed before you compare

  • Infrastructure, upgrades, DBA time, availability, DR — all yours
  • Implementation still 2–3× licence, same as the cloud platform
  • TechBag models five years with staff time in it

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
The requirement

Does your regulator name where the SYSTEM runs, or only where data rests? Only the first genuinely requires on-premises.

2
The end-of-life claim

Have you been told IdentityIQ is end-of-life? It is not — no EOL has been announced. Ask whoever told you where they got the date.

3
The three rules

Can your three most complex governance rules be expressed as configuration in the cloud platform? Ask HOW, not WHETHER.

4
Five-year model

Does your comparison include DBA time, upgrade cycles, availability and DR? Licence-only comparisons favour on-prem misleadingly.

5
The connector list

Have you scoped and priced every application needing a connector? This drives implementation cost in either deployment model.

6
Capability lag

Are you comfortable that new features land in Identity Security Cloud first? That trade is real and permanent.

7
Size threshold

More than roughly a thousand identities? Below that an enterprise IGA programme is hard to justify however it is deployed.

8
Staffing

Do you have the DBA and infrastructure capability in-house, or would you be buying it? That cost belongs in the business case.

FAQ

Questions buyers ask

No. SailPoint has announced no end-of-life for IdentityIQ. It is still sold, still supported, and still running in production at thousands of enterprises. We are leading with this because a great deal of market noise says otherwise, and that noise has a commercial motive: a migration is a large services engagement, so systems integrators and consultancies have an entirely rational interest in framing one as urgent. What is actually true about migration: a typical move to SailPoint Identity Security Cloud takes two to three years, with both platforms running in parallel for most of that period. Industry commentary describes this as a decade-scale transition rather than a cliff, and IdentityIQ skills remain in demand accordingly. SailPoint does run an upgrade programme — a free assessment taking around four weeks — and configured connectors, objects and rules can carry across because both platforms share an identity model and connectivity framework. So the path exists and is reasonably well trodden. What that means for your planning: treat migration as a roadmap decision timed against your own drivers — a hardware refresh, a data-centre exit, or a capability you genuinely need that only exists in the cloud platform. Not as a deadline someone else set. If none of those is present this year, staying is a legitimate answer rather than technical debt. And to be fair to the other side of the argument: new capability does land in Identity Security Cloud first, and the operational burden of running IdentityIQ yourself is real. For most organisations the cloud platform is where they will eventually end up. The point is that you choose when, and nobody can currently point to a date that forces you.

Ready to test whether you actually need on-premises?

Start with the requirement: does your regulator specify where the SYSTEM runs, or only where data rests? If the latter, the AWS Mumbai region probably satisfies it and the cloud platform costs less. If you are weighing a migration, run the three-rules test first. Or let a TechBag advisor model both options over five years with your staff costs included.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.