Training and preparatory resources

Training covers every ICAM enablement activity an application owner or stakeholder performs, from first orientation through acceptance testing. Launch and Learn attendance is required before enablement begins.

Training catalog

Training sessions and who they are for
SessionAudienceWhat it covers
DAF ICAM Launch and Learn Application owners Required orientation covering the solution, its benefits, and the integration process, with time for questions. Attendance is a prerequisite for enablement.
DoW ICAM Huddle All stakeholders Monthly session on ICAM fundamentals, the implementation framework, and the future of system access. Held in Eastern Time.
Self-enablement preparation Technical owners What to have ready before starting the AOB tool: redirect URIs, claim requirements, test accounts, and an authorization model decision.
Assisted enablement working sessions Technical owners Hands-on sessions with an enablement engineer for applications with legacy federation, custom claims or machine-to-machine access.
Security and compliance briefing ISSMs and ISSOs Control inheritance, audit evidence, and what changes in an application's ATO package after enablement.
Capability demonstration All stakeholders Recorded walkthrough of single sign-on, access request and certification as an end user experiences them.
Acceptance testing workshop Application owners How to plan, run and record user acceptance testing against the DAF ICAM integration before cutover.

The enablement process

  1. Step 1

    Register

    Submit the registration questionnaire. The routing engine decides your enablement path immediately and tells you why.

  2. Step 2

    Prepare

    Complete Launch and Learn, confirm your protocol, redirect URIs and claims, and identify test users for each role your application serves.

  3. Step 3

    Enable

    Accelerated applications configure themselves through the AOB tool. Assisted applications work through discovery, design and build with an enablement engineer.

  4. Step 4

    Test

    Run user acceptance testing against the integration and record the outcome. The program publishes a UAT pass rate from these results.

  5. Step 5

    Cut over

    Schedule cutover, verify access in SailPoint, and retire legacy authentication.

  6. Step 6

    Sustain

    Governance continues: access is certified periodically and changes are tracked against your application in the registry.

User acceptance testing

Scope
Test every role your application serves, one account per role, plus a user who should be denied access. Include any service or machine-to-machine credential.
Entry criteria
The application is configured in Okta, entitlements are aggregated in SailPoint, and test accounts exist for each role.
What to verify
Single sign-on succeeds from a cold browser; group and claim values arrive as expected; authorization decisions match the previous system; sign-out ends the session everywhere; denied users are refused.
Recording the result
Report the outcome to your enablement engineer, who records it against your application. Passed, failed and waived outcomes all feed the published UAT pass rate.
If UAT fails
The application stays in testing and a blocker is opened against it. Re-test after the fix; only the final outcome counts toward the pass rate.

See the published UAT pass rate

Content last reviewed 17 September 2026. Next review due 16 December 2026.