Create Identity Access Review Campaigns
As an Administrator or Campaign Administrator, certify identity accesses by creating on-demand Identity Access Review campaigns from the Oracle Access Governance Console. These can be one-time or periodic access review campaigns.
Prerequisites
Before you create identity access review campaigns, consider the following:
- To create campaigns for access reviews, you must have Oracle Access Governance Administrator or Campaign Administrator role assigned to you.
- Enable the identity attributes (core and custom), and affiliations, from the Identity Attributes page. For example, you may need to define the campaigns based on Project Code or Cost Center. See View and Configure Custom Identity Attributes.
- You must select at least one selection criteria to run Campaigns to avoid significant resource consumption.
- Select the Oracle Access Governance system to run identity access reviews based on the permissions ingested directly from the Orchestrated systems.
- For the Oracle Access Governance system, select permissions assigned directly (
DIRECT) or Access Bundles granted through request from the Which Permissions? tile. Permissions or accounts provisioned through policy aren't eligible in this review. - You can't select specific permissions and roles in the same campaign as campaign as Which permissions? and Which roles? are mutually exclusive. This means that you can select either of the two when creating a campaign. However, you can review all the available permissions and roles when you select Who has access? and What are they accessing?.
For more information on Campaigns, see Best Practices to work with Campaigns.
Navigate to Campaigns
Campaigns are created from the Oracle Access Governance Console. Go to Campaigns page to launch the on-demand access review process.
Select Criteria for your Access Reviews
In the Selection criteria dimension, you select appropriate criteria for your Identity Access Review Campaigns. The attributes configured in the Identity Attributes page are available as the selection criteria. All criteria can be searched by name.
Add Access Reviewers by Selecting Approval Workflow
In the Assign Workflow dimension, you select the approval workflow for your access review.
Add Owners
You can add primary and secondary owners to the campaigns. For existing campaigns, primary owner is selected as the campaign owner, with no secondary owners.
- Select an Oracle Access Governance active user in the Who is the primary owner field.
- Select one or more users in the Who else owns it? field. You can add up to 20 additional owners.
The Primary Owner is displayed in the campaign list. All assigned owners can view and manage campaigns they own.
If the primary owner isn't a valid campaign owner, fallback mechanism is auto triggered to assign a new owner. See Understanding Fallback Mechanism: Methods to Prevent Campaign Termination.
Add Campaign Details
In the Add details dimension, select campaign schedule cycle, give a meaningful name to your campaign, add a supporting description, and assign values to additional attributes, such as primary and secondary owner, and when the campaign must start or end.
Review and Submit the Campaign
In the Review and submit dimension, review the campaign details and create the campaign.
- Review the campaign information. For any changes, select the Back button.
- Select Create. The campaign is successfully scheduled.
Navigation Menu, select Access Reviews, and then Campaigns. From the Campaigns page, select Create a campaign.
Access Bundle through Request within Oracle Access Governance . The permissions vary based on the orchestrated system.