1. Oracle Identity Analytics Overview
2. Using the Oracle Identity Analytics User Interface
What Is the Identity Warehouse?
Understanding the Identity Warehouse User Interface
To Search for a User (Quick Search)
To Search for a User (Advanced Search)
To View User Accounts (Entitlements)
Working With Business Structures
To Delete a Business Structure
To Create a Business Structure Hierarchy
Associating Users With Roles and Business Structures
To Associate a User With a Role
To Associate a User With a Business Structure
To Associate Policies With Resources
To Associate Policy Owners With Policies
To Approve Policy Change Requests
To Manage Lifecycle of Policies
To Create Roles From Existing Roles
To Create Roles Based On an Existing User
To Rename, Modify, or Decommission (Delete) a Role
To Associate Roles With Business Units
To Associate Role Owners With Roles
Setting the Segregation of Duties at the Role and Policy Levels
To Define Segregation of Duties at the Role Level
Oracle Identity Analytics administers role-based access controls. Roles make it easier to assign access levels to users and to audit those assignments on an ongoing basis. Rather than assigning access levels to users directly, access levels are assigned to a role. Roles are assigned to users, and a user's access level is determined by the roles assigned to that user.
Role-based administration typically grows and expands as new situations occur. The main advantage of using this approach is ease of implementation. Role-based administration can be established in a centralized fashion, distributed throughout your network, or hybridized. Oracle Identity Analytics can be configured to match the unique structure and needs of your organization. Roles can be defined in a hierarchical format, and Segregation of Duties (SOD) can be administered through a role.
Log in to Oracle Identity Analytics.
Choose Identity Warehouse > Roles.
To use quick search, use the Search panel at the top of the page and choose an option from the drop-down menu.
Commonly populated fields are available to be searched on.
Enter a value to search for.
Wildcards can be used (for example, a* , j*n*).
Click Search to search the selected field for the value specified.
Search results are displayed in the Search panel on the left side of the screen.
Double-click a role to select it.
There are three ways to create roles in Oracle Identity Analytics:
Manually
From existing roles
From a global user
Log in to Oracle Identity Analytics.
Choose Identity Warehouse > Roles.
Choose New Role > Create Role Manually.
The Create Role pop-up window opens.
Complete the form:
Name - Type a name for the role.
Parent Role - Click the button to open the Select Role window, select the role that you want to designate as the parent role for the role you are creating, and click OK.
High Privileged - Select the check box to make this a high privileged role.
Start Date - Enter the start date. The role will be active on this date.
End Date - Enter the end date. The role will be inactive after this date.
Service Desk Ticket - Add the helpdesk system reference number, if relevant to your organization.
Click Save to create the role.
The role is available in the Roles view under the Identity Warehouse tab.
Log in to Oracle Identity Analytics.
Choose Identity Warehouse > Roles.
Choose New Role > Create Role Using an Existing Role as Template.
The Create Role pop-up window opens.
Complete the form:
Name - Type a name for the role.
Template Role - Click Select Template Role, search for the role that you want to use as a template for the new role, select the role, and click OK.
Click Save to create the role.
The role is available in the Roles view under the Identity Warehouse tab.
You can create a role based on an existing user. All of the entitlements that the selected user has are used to create corresponding policies that are assigned to the new role.
Log in to Oracle Identity Analytics.
Choose Identity Warehouse > Roles.
Choose New Role > Create Role From Existing User.
The Create Role pop-up window opens.
Type a name for the role and click Select User.
The Search window opens.
Use either the user quick search or advanced search feature to search for the user whose entitlements will be used to create policies for the new role.
For help using the search feature, see Working With Roles.
Select the user and click OK.
Click Save to create the role.
The role is available in the Roles view under the Identity Warehouse tab.
Log in to Oracle Identity Analytics.
Choose Identity Warehouse > Roles.
Search for a role, or select a role from the Roles panel on the left side of the screen.
For help using the search feature, see Working With Roles.
Do one of the following tasks:
To rename a role, click the General tab, type the new role name in the Name field, and click Send for Approval or Save.
To modify a role, type or select the new role properties, and click Send for Approval or Save.
To delete a role, click the Decommission Role button.
Decommissioning a role removes all role-user associations. The role itself, however, is not truly deleted. Instead, the role is made inactive and stored in Oracle Identity Analytics. The role cannot be made active again, and it cannot be modified in any way or assigned to users.
Log in to Oracle Identity Analytics.
Choose Identity Warehouse > Roles.
Click a role and click the Business Structures tab.
Click the Add Business Structures button and select the desired business units.
Click Save or Send for Approval.
Log in to Oracle Identity Analytics.
Choose Identity Warehouse > Roles.
Click a role and click the Ownership tab.
Click the Add Owners button and search for the user (or users) to add.
For help searching for users, see Searching For a User.
Select one or more users.
Click Save or Send for Approval.
Similar to a business unit hierarchy, an n-level role hierarchy can be defined in Oracle Identity Analytics. A role can have various "child roles" under it. To define a role hierarchy, add a new child role to it. When a child role is added to a user, the parent role is also automatically assigned to the user. The role hierarchy defines an organized structure of roles. Roles defined in an organization may have a hierarchy associated with them. In addition, enterprise-level roles and application-level roles can be defined.
Log in to Oracle Identity Analytics.
Choose Identity Warehouse > Roles.
The role hierarchy is defined when a new Role is created manually.
To change a role hierarchy, follow these steps:
Select the role and click the button located next to the Parent Role field on the General tab.
From the list of roles that appear, select the role that you want to designate as the parent role.
To select the child role for a user, follow these steps:
Choose Identity Warehouse > Users and search for the user that you want to assign to a role.
Select the user and click the Role tab.
Click the Add Roles button.
The parent Role is automatically assigned to the user. If the parent role is removed, the child role is automatically removed from the user.
Modifications to a role are activated only after the approval of the role owner.
To approve a role change request, see My Requests Tab in the My Requests chapter.
The lifecycle of a role is managed by out-of-the-box workflows. Workflows are step-by-step explanations (flowcharts) that Oracle Identity Analytics follows to complete a selected set of tasks. The workflows can be modified to suit the requirements of your organization.
Oracle Identity Analytics has the following role workflows:
Role creation workflow
Role modification workflow
Role membership workflow
The default role creation, role modification, and role membership workflows each have four steps:
Start workflow: This steps kicks-off once a role is created, modified, or a member is added or removed.
Policy Owner Approval: If a policy owner approves the request, the workflow proceeds to the next step. Otherwise, the role is rejected.
Role Owner Approval: If a role owner approves the request, the workflow proceeds to the next step. Otherwise, the role is rejected.
Finish: The role is created or modified.
To understand or change role workflows, refer to the Oracle Identity Analytics Workflows chapter in the Business Administrator's Guide.