JavaScript is required to for searching.
Skip Navigation Links
Exit Print View
Oracle Identity Analytics Business Administrator's Guide 11g Release 1
search filter icon
search icon

Document Information

Preface

1.  Oracle Identity Analytics Identity Warehouse

2.  Oracle Identity Analytics Importing

3.  Oracle Identity Analytics ETL Process

4.  Oracle Identity Analytics Data Correlation

5.  Oracle Identity Analytics Role Engineering and Management

6.  Oracle Identity Analytics Workflows

7.  Oracle Identity Analytics Identity Certifications

Creating New Certifications

To Create a User Entitlement Certification

To Create a Role Entitlement Certification

To Create a Resource Entitlement Certification

To Create a Data Owner Certification

Understanding the Incremental Certification Option

Scheduling Certifications

To Schedule a Certification

To Delete a Certification Job

Understanding Closed-Loop Remediation and Remediation Tracking

Configuring Closed-Loop Remediation

To Select Provisioning Mode

To Select Remediation Start Date

To Track Remediation

8.  Oracle Identity Analytics Identity Audit

9.  Oracle Identity Analytics Reports

10.  Oracle Identity Analytics Scheduling

11.  Oracle Identity Analytics Configuration

12.  Oracle Identity Analytics Access Control

13.  Audit Event Log and Import-Export Log

Creating New Certifications

Four types of certifications can be created in Oracle Identity Analytics.

Identity Certification Type
Description
User Entitlement Certification
Allows managers to certify employee access to roles and other related entitlements
Role Entitlement Certification
Allows role owners to certify roles and role content
Resource Entitlement Certification
Allows resource owners to certify user access to resources
Data Owner Certification
Allows data owners to certify users

To Create a User Entitlement Certification

  1. Log in to Role Manger.

  2. Choose Identity Certifications > My Certifications.

  3. Click New Certification.

    The Create Certification window opens.

  4. Complete the form as follows, then click Next:

    • Certification Name - Type a name for the certification.

    • Type - Select User Entitlement from the drop-down menu.

    • Incremental - This setting enables certifiers to certify or revoke only changes or inclusions made to a certification. It eliminates the need to review the access of users who have been certified. See To Understand And Work With The Incremental Certification Option for more information.

  5. Select a user selection strategy from the drop-down menu, then click Next:

    • All business structures - Selects all business structures created in Oracle Identity Analytics.

    • Selected business structures - Allows you to manually select the business structures. Click Next.

    • All users - Selects all the users in the system.

    • Users criteria - Selects all the users that meet the given search condition. For help with search, see Searching for a User. You can preview the results of this selection.

    • Selected users - Allows you to manually select the users in the system. Click Next.

  6. Complete the Period and Certifier form as follows, then click Next:

    • Certifier - You can select a Business Structure Manager, a User Manager, or an authorized user as the certifier.

    • Start Date - Enter the start date. The certification is valid as of the start date.

    • End Date - Enter the end date. The certification expires after the end date. Managers cannot review certifications after the expiration date.

    • Configuration Details - Select the check box to change the configuration of the certification you are creating. For detailed instructions on customizing configuration settings, see Identity Certification Configuration.

      After clicking Next, the summary page opens. Click Back if you want to modify any selection.

  7. Select one of the following options:

    • To Run Certification immediately, select Run.

    • To schedule a certification job, select Later.

      Refer to Scheduling Certifications for instructions.

  8. Click Create.

To Create a Role Entitlement Certification

  1. Log in to Role Manger.

  2. Choose Identity Certifications > My Certifications.

  3. Click New Certification.

    The Create Certification window opens.

  4. Complete the form as follows, then click Next:

    • Certification Name - Type a name for the certification.

    • Type - Select Role Entitlement from the drop-down menu.

    • Incremental - This setting enables certifiers to certify or revoke only changes or inclusions made to a certification. It eliminates the need to review the role content, which has been certified. See To Understand And Work With The Incremental Certification Option for more information.

  5. Select a role selection strategy from the drop-down menu, then click Next:

    • All business structures - Selects all business structures created in Oracle Identity Analytics.

    • Selected business structures - Allows you to manually select the business structures.

    • All roles - Selects all of the roles in the system.

    • Roles criteria - Selects all of the roles that meet the given search condition. You can preview the results of this selection.

    • Selected roles - Allows you to manually select the roles in the system.

  6. Complete the Period and Certifier form as follows, then click Next:

    • Certifier - You can select the Business Structure Manager, Role Owner, or an authorized user as the certifier.

    • Start Date - Enter the start date. The certification is valid as of the start date.

    • End Date - Enter the end date. The certification expires after the end date. Managers cannot review certifications after the expiration date.

    • Configuration Details - Select the check box to change the configuration of the certification you are creating. For detailed instructions on customizing configuration settings, see Identity Certification Configuration.

      After clicking Next, the summary page opens. Click Back if you want to modify any selection.

  7. Select one of the following options:

    • To Run Certification immediately, select Run.

    • To schedule a certification job, select Later.

      Refer to Scheduling Certifications for instructions.

  8. Click Create.

To Create a Resource Entitlement Certification

  1. Log in to Role Manger.

  2. Choose Identity Certifications > My Certifications.

  3. Click New Certification.

    The Create Certification window opens.

  4. Complete the form as follows, then click Next:

    • Certification Name - Type a name for the certification.

    • Type - Select Resource Entitlement from the drop-down menu.

    • Incremental - This setting enables certifiers to certify or revoke only changes or inclusions made to a certification. It eliminates the need to review the access of users who have been certified. See To Understand And Work With The Incremental Certification Option for more information.

  5. Select a user selection strategy from the drop-down menu, then click Next:

    • All business structures - Selects all business structures created in Oracle Identity Analytics.

    • Selected business structures - Allows you to manually select the business structures.

    • All users - Selects all the users in the system.

    • Users criteria - Selects all the users that meet the given search condition.

      For help with search, see Searching for a User. You can preview the results of this selection.

    • Selected users - Allows you to manually select the users in the system.

  6. Click Add Resource.

    The Select Resource(s) window opens.

  7. Select the desired resource and click OK.

  8. Click Next.

  9. Complete the Period and Certifier form as follows, then click Next:

    • Certifier - Select the Business Structure Manager, User Manager, or an authorized user as the certifier.

    • Start Date - Enter the start date. The certification is valid as of the start date.

    • End Date - Enter the end date. The certification expires after the end date. Managers cannot review certifications after the expiration date.

    • Configuration Details - Select the check box to change the configuration of the certification you are creating. For detailed instructions on customizing configuration settings, see Identity Certification Configuration.

      After clicking Next, the summary page opens. Click Back if you want to modify any selection.

  10. Select one of the following options:

    • To Run Certification immediately, select Run.

    • To schedule a certification job, select Later.

      Refer to Scheduling Certifications for instructions.

  11. Click Create.

To Create a Data Owner Certification

  1. Log in to Role Manger.

  2. Choose Identity Certifications > My Certifications.

  3. Click New Certification.

    The Create Certification window opens.

  4. Complete the form as follows, then click Next:

    • Certification Name - Type a name for the certification.

    • Type - Select Resource Entitlement from the drop-down menu.

    • Incremental - This setting enables certifiers to certify or revoke only changes or inclusions made to a certification. It eliminates the need to review the access of users who have been certified. See To Understand And Work With The Incremental Certification Option for more information.

  5. Select a selection strategy from the drop-down menu, then click Next:

    • By Data Owner - Creates a certification for the attribute values for which the selected user is designated as the data owner.

      1. Click Add Data Owner, select the user, and click OK.

        For help using search, see Searching for a User.

    • By Attribute - Creates a certification for data owners of the selected attribute values.

      1. Click the Add Attributes button.

        The Attribute Selection table appears.

      2. Select the resource type, resource, and attributes, and click OK.

  6. Click Next.

  7. Complete the Period and Certifier form as follows, then click Next:

    • Certifier - Select the data owner or an authorized user as the certifier.

    • Start Date - Enter the start date. The certification is valid as of the start date.

    • End Date - Enter the end date. The certification expires after the end date. Managers cannot review certifications after the expiration date.

    • Configuration Details - Select the check box to change the configuration of the certification you are creating. For detailed instructions on customizing configuration settings, see Identity Certification Configuration.

      After clicking Next, the summary page opens. Click Back if you want to modify any selection.

  8. Select one of the following options:

    • To Run Certification immediately, select Run.

    • To schedule a certification job, select Later.

      Refer to Scheduling Certifications for instructions.

  9. Click Create.

Understanding the Incremental Certification Option

Incremental certification is a setting that allows managers to certify only those changes that are new since the last certification was created. This option is available if the certifier and certification type have not changed since the last certification. Enabling this setting saves time during the certification process.

The following options are available when the incremental certification option is selected:

Note - Incremental certification requires that the certifier and certification type remain the same. Also, incremental certification is valid only for completed certifications. Incremental certification does not apply for expired or incomplete certifications.