Create User Access Review Campaigns
As a user with the Administrator or Campaign Administrator application role, you can create access review campaigns from the Oracle Access GovernanceConsole. You can define selection criteria for access reviews based on users (who has access), applications (what are they accessing), permissions (which permissions), and roles (which roles). You can also define the workflow for the review in terms of the number of review levels, duration, and who performs the review.
To create an access review campaign using Oracle Access Governance Console:
Selection Criteria
By default, all identity data ingested from the connected system is available to the access review campaign. This may be a large amount of data, so selection criteria allow you to narrow the criteria available for the campaign:
- Who has access: Selecting review criteria to filter users based on standard (Organization, Job, Location), or custom attributes.
- What they are accessing: Selecting review criteria to filter users based on resources they have access to
- Which permissions: Selecting review criteria to filter users based on permissions such as create, update, terminate, approve, and so on.
- Which roles: Selecting review criteria to filter users based on application roles.
- Which cloud providers
Note:
- The selection criteria vary based on the ingested data from the connected system and a few tiles listed above may not be available for selection. For example, if no roles are available in the connected system schema definition, then you won't see the Which roles tile.
- If you select any of the identity parameters above, policy criteria selection (which policies?) is no longer applicable and is disabled.
These criteria can be chosen and edited in any order before moving on to the next step. If you do not need to update each dimension, you can select any number from those above, and leave the remaining unchanged. If you do not need to narrow the criteria for your enterprise, then you can choose to move to the next step without adding any selection criteria. All criteria can be searched by name
Note:
The following combinations are not supported and are mutually exclusive, that is you can select only one of the two while creating a campaign:- Which permissions and Which roles
For example, you can create a campaign by selecting Who has access?, What are they accessing?, and Which roles? but you cannot create a campaign with the combination of Who has access?, Which roles?, and Which permissions?
Assign Workflow
The Assign Workflow step is where the approval workflow for your access reviews is defined. Oracle Access Governance will provide a suggested optimal workflow based on your selection criteria.
Add Details
With the Add Details step, you can define the frequency (one-time or periodic) at which to run an access review campaign, give a meaningful name to your campaign, add a supporting description, and assign values to additional attributes, such as who owns it and when the campaign should start or end.