Training and preparatory resources
Training covers every ICAM enablement activity an application owner or stakeholder performs, from first orientation through acceptance testing. Launch and Learn attendance is required before enablement begins.
Training catalog
| Session | Audience | What it covers |
|---|---|---|
| DAF ICAM Launch and Learn | Application owners | Required orientation covering the solution, its benefits, and the integration process, with time for questions. Attendance is a prerequisite for enablement. |
| DoW ICAM Huddle | All stakeholders | Monthly session on ICAM fundamentals, the implementation framework, and the future of system access. Held in Eastern Time. |
| Self-enablement preparation | Technical owners | What to have ready before starting the AOB tool: redirect URIs, claim requirements, test accounts, and an authorization model decision. |
| Assisted enablement working sessions | Technical owners | Hands-on sessions with an enablement engineer for applications with legacy federation, custom claims or machine-to-machine access. |
| Security and compliance briefing | ISSMs and ISSOs | Control inheritance, audit evidence, and what changes in an application's ATO package after enablement. |
| Capability demonstration | All stakeholders | Recorded walkthrough of single sign-on, access request and certification as an end user experiences them. |
| Acceptance testing workshop | Application owners | How to plan, run and record user acceptance testing against the DAF ICAM integration before cutover. |
The enablement process
-
Step 1
Register
Submit the registration questionnaire. The routing engine decides your enablement path immediately and tells you why.
-
Step 2
Prepare
Complete Launch and Learn, confirm your protocol, redirect URIs and claims, and identify test users for each role your application serves.
-
Step 3
Enable
Accelerated applications configure themselves through the AOB tool. Assisted applications work through discovery, design and build with an enablement engineer.
-
Step 4
Test
Run user acceptance testing against the integration and record the outcome. The program publishes a UAT pass rate from these results.
-
Step 5
Cut over
Schedule cutover, verify access in SailPoint, and retire legacy authentication.
-
Step 6
Sustain
Governance continues: access is certified periodically and changes are tracked against your application in the registry.
User acceptance testing
- Scope
- Test every role your application serves, one account per role, plus a user who should be denied access. Include any service or machine-to-machine credential.
- Entry criteria
- The application is configured in Okta, entitlements are aggregated in SailPoint, and test accounts exist for each role.
- What to verify
- Single sign-on succeeds from a cold browser; group and claim values arrive as expected; authorization decisions match the previous system; sign-out ends the session everywhere; denied users are refused.
- Recording the result
- Report the outcome to your enablement engineer, who records it against your application. Passed, failed and waived outcomes all feed the published UAT pass rate.
- If UAT fails
- The application stays in testing and a blocker is opened against it. Re-test after the fix; only the final outcome counts toward the pass rate.
Content last reviewed 17 September 2026. Next review due 16 December 2026.