Provisioning BI Users with Duty Roles

To provision a BI User with a Duty Role, you first assign the User to an Enterprise Role/Group in LDAP, then make sure that the Enterprise Role/Group is associated with the appropriate Duty Role in the Policy Store.

BI Users are provisioned with BI Duty Roles using Enterprise Roles in the LDAP. To provision users, you typically use either Oracle Fusion Middleware, or RPD initialization blocks. If you are using the default embedded Enterprise Roles in Oracle WebLogic Server LDAP, then these Enterprise Roles are associated with the appropriate Duty Roles by default, and no further configuration is required.

If you are using a different LDAP with your own set of Enterprise Roles, then you need to make sure that these are associated with the appropriate Duty Roles, by following the steps below.

  1. Log in to Oracle Enterprise Manager Fusion Middleware Control as an administrator.
  2. Expand Business Intelligence, right-click coreapplication, and select Security, then Application Roles.
    A list of available Duty Roles is displayed.
  3. Provision a BI User with a Duty Role.
    1. Select the Duty Role that a BI User requires access to.
    2. Click Edit to display the Edit Application Role dialog.
    3. In the Member list, click Add to display the Add Principal dialog.
    4. Use the Search area to locate and select the Enterprise Role/Group that the BI User has.
      For example, User Fred has Enterprise Role 'Fixed Asset Accounting Manager EBS'. To provision Fred with security access for Fixed Assets Accounting reporting for EBS, you edit the BI Duty Role 'Fixed Asset Accounting Manager EBS' and add Enterprise Role 'Fixed Asset Accounting Manager EBS' as a Member.
    5. Click OK.