Prepare Oracle Fusion Cloud Applications for Integration

Before you install and configure an Oracle Fusion Cloud Applications orchestrated system, complete the following prerequisites and tasks.

Certification

You must certify the Oracle Fusion Cloud Applications system to access Oracle Access Governance. See Certified Components for information about supported versions.

Enable HCM Atom Feeds for Partial Data Load

To enable incremental data load change for your orchestrated system, enable User Requests HCM Atom Feed in Oracle Fusion Cloud Applications. This option is valid only when the orchestrated system is configured as HCM or Both.

  1. Enable User Requests HCM Atom Feed. See Manage HCM Atom Feeds. The following atom feed collections are used by Oracle Access Governance
    • newhire
    • empupdate
    • empassignment
    • termination
    • cancelworkrelship
    • workrelshipupdate
    For more information, see Employee Feeds.
  2. Configure Partial Data Load settings from the Oracle Access Governance Console. See Configure Partial Data Load Settings.

Create FA HCM Data Roles and Security Profiles

Before configuring the orchestrated system you must set up either an HCM or ERP service account and grant permissions required to integrate with Oracle Access Governance.

To view a list of Default Roles or permissions, see Grant Default Roles or Permissions.

Required Roles:
  • IT Security Manager Job role (ORA_FND_IT_SECURITY_MANAGER_JOB)
  • Human Capital Management Integration Specialist (ORA_HRC_HUMAN_CAPITAL_MANAGEMENT_INTEGRATION_SPECIALIST_JOB)
  1. Sign in to Oracle Fusion Cloud Applications.
  2. Go to My Enterprise > Setup and Maintenance.
  3. Select the Tasks icon on the right side of the page.
  4. Select Search and select Manage Data Role and Security Profiles.
  5. Search for Human Capital Management Integration Specialist job role that doesn't have a security profile.
  6. Select +Create:
    • Enter a data role name. For example, <ServiceAccountName>-DataRole.
    • Select Human Capital Management Integration Specialist job role to inherit.
    • Select OK.
  7. Select Next.
  8. On the Security Context page, select View All in the list across security profile configurations.
  9. Select Next to review and Submit.
  10. Search for the data role that you created. Verify that the Security Profile Assigned column is selected.
  11. Select Done.

You must create a service account and assign this data role to the service account.

Create a Service Account and Grant Default Roles

Use the service account when you configure the connection in the orchestrated system. You can configure this service account by using default Oracle Fusion Cloud Applications roles and permissions, or using a custom role.

Create a Service Account in Oracle Fusion Cloud Applications

You must have the IT Security Manager Job role (ORA_FND_IT_SECURITY_MANAGER_JOB).

  1. Sign in to Oracle Fusion Cloud Applications.
  2. From the Navigator, go to Tools > Security Console.
  3. Select Users > Add User Account.
  4. Enter the required user information.
  5. Select Save and Close. Ensure the status is Active.
  6. Select the user, and then select Edit.

Add Roles to Service Account

  1. Select the Add Role button.
  2. For HCM, assign the default roles one at a time to the account. See Grant Default Roles or Permissions.
  3. For ERP, assign the default roles one at a time to the account. See Grant Default Roles or Permissions.
    Note

    If you configure both HCM and ERP, you must assign all default roles for both application types.
    Note

    You must add the required Look up Types for the Access Request Security Administrator. See Add Lookup Types.
  4. Assign the data role that you created in the previous task. See Create FA HCM Data Roles and Security Profiles.
  5. Select Save and Close.
  6. Search for the account and verify that the required roles are assigned.
  7. Sign in to verify the creation of the new service account.

Grant Permissions Using a Custom Role - Least Privilege Principle

Use privileges instead of the default Oracle Fusion Cloud Applications roles and permissions to set up a custom role for the service user. This configuration follows the principle of least privilege because it grants only the fine-grained privileges required by the service user.

Create the custom role as follows:
  1. Create an Oracle Fusion Cloud Applications role of category Common - Job Roles.
  2. Add the privileges to the function security policies. See the list: Grant Privileges.
  3. Add the aggregated privileges as roles in the role hierarchy. See the list: Grant Privileges Grant Aggregated Privileges.
  4. Grant Data Security Policies for the appropriate dataset to the custom role. If you don't grant the correct data security policies, some data might not be returned. The API calls return a 200 OK response, but the count is 0 when the data security policies are omitted.
  5. Assign the custom role to the Service Account. See Add Role to Service Account.

Run Refresh Access Control Data Job

You must run the Access Control Data Job after configuring the service account. By default, this job runs every hour, or you can run it manually.

To run the job:

  1. Navigate to ToolsScheduled Processes.
  2. Search for Refresh Access Control Data.
  3. Select Schedule New Process.
  4. Select Refresh Access Control Data as the job name and enter a meaningful description.
  5. Select Full Refresh or Incremental Refresh, as required to run the job.
  6. Select OK.
  7. Select Submit. Copy the process ID number.
  8. Run User and Roles Synchronization Process to retrieve the latest users and role definitions. For more information, see Run User and Roles Synchronization Process.

Add Lookup Types for Access Request Security Administrator

Grant the following lookup type permission to the Access Request Security Administrator role type.

  1. Sign in to Oracle Fusion Cloud Applications.
  2. Go to My Enterprise > Setup and Maintenance.
  3. Select Tasks icon on the right side of the page.
  4. Select Search and select Manage Standard Lookups.
  5. Add the new lookup type FUN_DS_OPTIN_OPTIONS by using the lookup code FUN_DS_GET_BOOKCODE.
  6. In the Module list, select Application Core.
  7. In the REST Access Secured list, select Authenticated.
  8. Select Save and Close.

Configure Business Unit for Procurement Agent (PO Agent) in Oracle Fusion Cloud Applications

Before creating or managing a Procurement Agent (PO Agent), the selected Business Unit must be configured as a Procurement Business Unit in Oracle Fusion Cloud Applications.

Verify the business unit configuration:

  1. Sign in to the Oracle Fusion Cloud Applications application.
  2. Go to My Enterprise → Setup and Maintenance.
  3. Under Functional Areas, select Organization Structures.
  4. Open the task Assign Business Unit Business Function.
  5. Select the relevant business unit.
  6. Select the Procurement checkbox under Business Unit Functions.
  7. Save the changes.
  8. After you save the changes, run a Full Data Load from the Orchestrated System page to refresh Business Unit data in Oracle Access Governance.

Result: Access Bundle displays all available business units. When managing select Business Units configured with the Procurement business unit function when managing Procurement Agents. Selecting a business unit that isn't configured for procurement causes an Add Permission operation failed error.

AOR Template-Based Provisioning

To enable provisioning of Area of Responsibility (AOR) assignments using AOR templates, the user account must be linked to a person.

Required Roles and Privileges
  • Human Capital Management Application Administrator

    (ORA_HRC_HUMAN_CAPITAL_MANAGEMENT_APPLICATION_ADMINISTRATOR_JOB)

  • Areas of Responsibility (AOR) using REST services PER_REST_SERVICE_ACCESS_AREAS_OF_RESPONSIBILITY_PRIV

Create AoR Template in Oracle Fusion HCM

You can create an Area of Responsibility (AOR) template for responsibilities that need to be assigned often.
  1. Sign in to Oracle Fusion Cloud Applications.
  2. Go to My Client Groups.
  3. Search Area of Responsibility Templates.
  4. In the Area of Responsibility Templates page, select + Add.
  5. In the What info do you want to manage? field, select Assign to People.
  6. Select Continue.
  7. Enter basic information to create a template.
  8. Select Continue.
  9. Attach scope attributes such as Legal Employer, Business Unit, and Department.
  10. Select Submit.

This template is ingested as a permission in Oracle Access Governance during the data load and lookup activity. See AOR Integration Settings.

Configure OCI OAuth and OCI Vault for Fusion Cloud Integration

Use OAuth to authenticate and authorize Oracle Fusion Cloud Applications with Oracle Access Governance.

OAuth Prerequisites

The following prerequisites must be met to authorize Oracle Fusion Cloud Applications using OAuth.
  • Create a Service Account and grant permissions required to integrate with Oracle Access Governance.
  • Ensure configuration is performed in the same Identity domain that hosts Oracle Fusion Cloud Applications.

Access Certificates and Keys

Use a certificate issued by a trusted Certificate Authority (CA) in the PEM format for secure authentication and compatibility, or use OCI Certificate Service to generate and manage certificates.

  1. Use a trusted certificate authority in the PEM format.
  2. To retrieve the public certificate, ensure that the Identity Domain is configured to issue and sign tokens.
    1. In the Identity & Security, select Domains.
    2. From the Settings tab, enable Access signing certificate.

Import Certificate as the Trusted Partner Certificate to the FA instance's OCI IAM Domain

  1. Navigate to Identity & Security, and select Domains.
  2. Find and select compartment for the Oracle Fusion Cloud Applications services instance, and then select the domain.
  3. Select the Security tab.
  4. Go to the Trusted partner certificates section and then select Import certificate.
  5. Enter the alias name that you used when you generated the keystore certificate.
  6. Import the .cer file.
  7. Select Import.

Result: Verify that the correct details are displayed, including the SHA-1 Thumbprint, SHA-256 Thumbprint, Certificate Start Date, and Certificate End Date.

Create an Integrated Confidential Type Application

  1. Navigate to Identity & Security, and select Domains.
  2. Select the required domain.
  3. Select the Integrated applications tab.
  4. Select Add application.
  5. Select Confidential Application tile, and then select Launch workflow.
  6. In the Details page, enter the following:
    1. Enter a name and description for the confidential application.
    2. Select Submit.

Edit OAuth configurations

  1. Select the OAuth configuration tab.
  2. Select Edit OAuth configuration.
  3. Client Configuration: Select Configure this application as a client now.
  4. Enable Grant Types: Select Client Credentials, JWT assertion and Refresh token grant types.
  5. Select Trusted as the Client type option.
  6. Import the certificate used earlier.
  7. Select On behalf of as the Allowed operations.
  8. Select network perimeter to restrict sign-in attempts to specific IPs or ranges. Otherwise, select Anywhere.
  9. Under the Token Issuance Policy, select All.
  10. Scope Configuration:
    1. Enable Add Resources toggle
    2. Select Add Scopes
    3. Select the Oracle Fusion Cloud Applications application references.
      Note

      If scopes aren't listed, verify from the Oracle Cloud Services tab, if Oracle Fusion Cloud Applications instance is registered in this domain.
  11. Select Submit.
  12. Activate the application: select the Actions icon and then select Activate. The status must change from Inactive to Active.

Fetch Confidential OAuth Application Details for Authorization

  1. Open the Confidential OAuth integrated application that you created.
  2. Select the OAuth configuration tab.
  3. Under the General Information section, copy and save Client ID and Client Secret.
  4. Under the Resources section, copy and save the application scope.

Create an OCI Vault to Store Credentials

Oracle Access Governance uses OCI Vault and Secret Management service to store sensitive values such as passwords, client secrets, and private keys.

Create an Oracle Cloud Infrastructure (OCI) vault, an encryption key, and secrets for Basic Authentication or OAuth credentials where the Oracle Access Governance instance is configured.

Ensure you have the required access:
  • Permission to create vaults, keys, and secrets in the target compartment.
  • Permission to use keys to encrypt secrets.
  1. Create a vault.
  2. Create an encryption key when the vault is in active state. See Creating a Master Encryption Key.
  3. From the navigation menu , select Identity & Security, then Secret Management.
  4. Select Create secret.
  5. Select the compartment in which to create the secret.
  6. Enter a meaningful secret name. For example, agcs-fa-oauth.
  7. Select the Vault compartment and Vault name.
  8. Select the Encryption key compartment.
  9. In the Encryption key field, select the key that you created.
  10. Select Manual secret generation.
  11. In the secret contents:
    • If you use Basic Auth, enter:
      {
        "adminUser": "<your-admin-username>",
        "adminPassword": "<your-admin-password>"
      }
    • For OAuth, perform the OAuth prerequisites, and enter the details:
      {
        "adminUser": "admin@example.com",
        "domainURL": "https://idcs-<tenant>.example.com",
        "clientId": "xxxxxxxxxxxxxxxxxxxxxxxx",
        "clientSecret": "xxxxxxxxxxxxxxxxxxxxxxxx",
        "privateKey": "-----BEGIN PRIVATE KEY-----\n<your-key>\n-----END PRIVATE KEY-----\n",
        "alias": "my-signing-key",
        "scope": "urn:opc:idm:__myscopes__"
      }
      Parameters Details
  12. Select Create secret.
  13. Enter the tenancy OCID and secret OCID in the Integration settings. This generates the required IAM policy on the Console. To find secret details, see Viewing Secret Details.
  14. Copy the exact statements in the root compartment of the Oracle Access Governance tenancy where you have created the vault.