JavaScript is required to for searching.
Skip Navigation Links
Exit Print View
Oracle Identity Analytics User's Guide 11g Release 1
search filter icon
search icon

Document Information

Preface

1.  Oracle Identity Analytics Overview

2.  Using the Oracle Identity Analytics User Interface

3.  The Home Page

4.  My Settings

5.  My Requests

6.  Identity Warehouse

What Is the Identity Warehouse?

Understanding the Identity Warehouse User Interface

Business Structures

Users

Roles

Policies

Applications

Resources

Working With Users

To Create a User

To Rename a User

To Delete a User

Searching for a User

To Search for a User (Quick Search)

To Search for a User (Advanced Search)

Viewing User Details

To View User Accounts (Entitlements)

To View a User's Account Type

Working With Business Structures

To Delete a Business Structure

To Create a Business Structure Hierarchy

Associating Users With Roles and Business Structures

To Associate a User With a Role

To Associate a User With a Business Structure

Setting User Status

To Set User Status

Working With Policies

To Create a Policy

To Delete or Rename Policies

To Associate Policies With Resources

To Add Policies To Roles

To Associate Policy Owners With Policies

To Approve Policy Change Requests

To Manage Lifecycle of Policies

Working With Roles

To Search for a Role

Creating Roles

To Create Roles Manually

To Create Roles From Existing Roles

To Create Roles Based On an Existing User

To Rename, Modify, or Decommission (Delete) a Role

To Associate Roles With Business Units

To Associate Role Owners With Roles

To Create a Role Hierarchy

To Approve Role Change Requests

To Manage the Lifecycle of Roles

Setting the Segregation of Duties at the Role and Policy Levels

To Define Segregation of Duties at the Role Level

To Define Segregation of Duties at the Policy Level

7.  Identity Certification

8.  Identity Audit

9.  Reports

Working With Policies

Policies are templates that define the various access levels that a user has on the target systems. Policies are individually defined for each resource. Roles are made up of policies.

The polices component displays all available policies that exist for the organization categorized according to resource type. Resources are depicted as ALT TEXT . The available policies are shown under each resource type.

To Create a Policy

  1. Log in to Oracle Identity Analytics.

  2. Choose Identity Warehouse > Policies.

  3. Click New Policy.

    The Policy Wizard window opens.

  4. Select the resource type for which you are creating the policy and click Next.

  5. Select the resource for which access needs to be defined and click Next.

  6. Click Select Owners to search for the owners for this policy and click Next.

    For help using Search, see Searching For a User.

  7. When the Policy Property window opens up, complete the form:

    • Name - Type the name of the policy.

    • Comments - Type any additional comments about the policy.

    • Service Desk Ticket # - Add the helpdesk system reference number, if relevant to your organization. 

  8. Click the Entitlements tab and complete the form:

    • Value - Enter the value of the attribute defined for the resource.

    • Required - Selecting this means the value is mandatory and needs to be assigned to the role. This value cannot be excluded.

    • Risk Level - Signifies whether a given policy is low, medium, high, critical, or none. These risk levels are flagged during Identity Audit Exceptions or while performing Certifications.

    • + / - - Use these to add or delete an attribute value.

  9. Click Finish.

The new policy is displayed under the resource type on the Policies page.

To Delete or Rename Policies

  1. Log in to Oracle Identity Analytics.

  2. Choose Identity Warehouse > Policies.

    • To rename a policy, do the following:

      1. Select the policy by clicking on the policy name.

      2. Change the name of the policy and click Save.

    • To delete a policy, do the following:

      1. Select the policy by clicking on the policy name.

      2. Click the Delete Policy button.

To Associate Policies With Resources

  1. Log in to Oracle Identity Analytics.

  2. Choose Identity Warehouse > Policies.

    Policies are listed by resource type on the left side of the page.

  3. Click to select the desired policy.

  4. Click the Resources tab in the panel on the right.

  5. Click the Add Resources button.

  6. Select one or more resources from the list and click OK.

    Hold down the Control key while clicking to select multiple items. Click an item again while holding down Control to clear that item.

  7. Click Save.

    The resource will not be associated with the policy until it has been approved by the policy owner.

  8. Click Send For Approval.

Once the policy owner approves it, the resource is associated with the policy.

To Add Policies To Roles

  1. Log in to Oracle Identity Analytics.

  2. Choose Identity Warehouse > Roles.

  3. Select a role and click the Policies tab on the right side of the page to add policies to (or remove policies from) the role.

  4. Choose one of the following tasks:

    • Click Add Policies to assign the selected policies to the role.

    • Click Remove Policies to remove the selected policies from the role.

  5. Click Save.

    The policies associated with a role will display on the Policies tab for the role.

To Associate Policy Owners With Policies

  1. Log in to Oracle Identity Analytics.

  2. Choose Identity Warehouse > Policies.

    Policies are listed by resource type on the left side of the page.

  3. Click a policy and click the Ownership tab on the right side of the page.

  4. Click Add Owner.

  5. Select one or more user(s) and click OK.

    For help using Search, see Searching For a User.

  6. Click Save.

To Approve Policy Change Requests

Modifications to a policy are activated only after the approval of the policy owner.

To approve a policy change request, see My Requests Tab in the My Requests chapter.

To Manage Lifecycle of Policies

The lifecycle of a policy is managed by out-of-the-box workflows. Workflows are step-by-step explanations (flowcharts) that Oracle Identity Analytics follows to complete a selected set of tasks. The workflows can be modified to suit the requirements of your organization.

Oracle Identity Analytics has the following policy workflows:

  1. Policy creation workflow

  2. Policy modification workflow

The default policy creation and policy modification workflows each have three steps:

To understand or change policy workflows, refer to the Oracle Identity Analytics Workflows chapter in the Business Administrator's Guide.