Adding Oracle CASB Cloud Service Administrators

Add an administrator, with an assigned role and application instances.

Note:

A primary tenant administrator can be set up automatically, by having that person be the first to log in to Oracle CASB Cloud Service after that person receives the welcome email:

  1. Create the user in MyServices by following steps 1-13 in Adding an Administrator through Oracle Cloud MyServices Dashboard.

  2. Send email to that user with instructions to log in to the Oracle Cloud MyServices dashboard.

    On the first login, the user may be prompted to change the password.

  3. While logged in to Oracle Cloud MyServices, on the dashboard, click the Customize Dashboard tile.

  4. In the Customize Dashboard dialog box:

    1. Scroll down to the Security section.

    2. Next to Oracle CASB, click Show.

    3. Close the Customize Dashboard dialog box.

      An Oracle CASB tile now appears on the dashboard.



  5. In the Oracle CASB tile, click the menu icon and select Open Service Console to access the Oracle CASB Cloud Service console.

    That user is now created as a tenant administrator in both the Oracle CASB Cloud Service console and in the MyServices dashboard.

In all other cases, all types of administrators must be created manually in both environments. See:

Only a tenant administrator role can add and remove other Oracle CASB Cloud Service administrators. A tenant administrator can add other administrators, by using both the Oracle Cloud MyServices dashboard and the Oracle CASB Cloud Service console.

Note:

Always have at least one backup tenant administrator role assigned, in addition to the original (root) tenant administrator.

Caution:

You must add an administrator through both the Oracle Cloud MyServices dashboard and the Oracle CASB Cloud Service console. If you skip either task, the new administrator will not be able to log in to Oracle CASB Cloud Service.

Adding an Administrator through Oracle Cloud MyServices Dashboard

Add an administrator, with an assigned role, through Oracle Cloud MyServices dashboard.

  1. Log in to the Oracle Cloud MyServices dashboard.
    1. To log in from Oracle CASB Cloud Services administrative console:
      1. Click MyServices from the Navigation menu. If the Navigation Menu is not displayed, click the Navigation Menu icon Image of the Navigation Menu icon. to display it.

        If you don't see the MyServices menu option, you are not subscribed to Oracle CASB Cloud Service through universal credit model (UCM). To start subscribing, see Accessing Oracle CASB Cloud Service Using Universal Credits

        Note:

        To open MyServices console in a new browser window or tab, right-click My Services and select Open Link in a New Window or Open Link in a New Tab.
      2. If you were not already logged into Oracle Identity Cloud Service, enter your credentials when prompted.
    2. To log in to directly through your browser:
      1. Navigate to https://cloud.oracle.com.
      2. Click Sign In.
      3. On the Cloud Account page, enter your cloud account name and click MyServices.
      4. At the Oracle Cloud Account Signin prompt, enter your User Name and Password, then click Sign In.
  2. Log in to your Oracle Cloud MyServices dashboard.
    1. Navigate to https://cloud.oracle.com.
    2. Click Sign In.
    3. On the Cloud Account page, enter your cloud account name and click MyServices.
    4. At the Oracle Cloud Account Signin prompt, enter your User Name and Password, then click Sign In.
  3. On the Dashboard, click Users at the top right.
  4. On the User Management page, click Add at the top right.
  5. On the Add User page, (User Details section):
    1. Enter First Name, Last Name, and Email.
    2. Leave Use Email as User Name selected.
    3. Click Next.
  6. In the Service Accounts section of the Add User page:
    1. Enter Oracle CASB in the search box, to the left of the Search icon Image of the Search icon. .
    2. Click in the empty box below to show search results.
    3. In the search results, select CASB_Administrator.
    4. Click Finish at the top right.
    Your Oracle Cloud user is now created. Next, you will use the Oracle Identity Cloud Service console to add the CASB application to this new user.
  7. On the User Management page, click Dashboard at the top right.
  8. On the Dashboard, click the Identity Cloud link.
  9. On the Service: Oracle Identity Cloud Service page, in the Service Instances section, click Open Service Console.
  10. In the Identity Cloud Service console, locate the Users tile and click its icon.
  11. On the Users page, click the row for the Oracle Cloud user you just added to display Details for that user.
  12. Click the Access tab, and then click Assign.
  13. In the Assign Applications dialog box, select casb-sso-idcs-app and then click OK.
  14. To return to the Dashboard, select MyServices from the Navigation menu. If the Navigation Menu is not displayed, click the Navigation Menu icon Image of the Navigation Menu icon. to display it.
  15. On the Dashboard, locate the Oracle CASB tile, click the menu icon in the lower right corner, and select Open Service Console.

    This takes you to the Oracle CASB Cloud Service console.

  16. If you see a "Welcome to Oracle CASB Cloud Service" page, click Skip This.

    This page only appears if you have never registered an application or accessed Oracle CASB Cloud Service — Discovery.

  17. Continue with Adding an Administrator through the Oracle CASB Cloud Service Console.

    Next you will configure this OCI user as an administrator in the Oracle CASB Cloud Service console.

Adding an Administrator through the Oracle CASB Cloud Service Console

Add an administrator, with an assigned role, through the Oracle CASB Cloud Service administrative console.

  1. Select Configuration, Admin Management from the Navigation menu. If the Navigation Menu is not displayed, click the Navigation Menu icon Image of the Navigation Menu icon. to display it.
  2. Click New Admin.
  3. In the New Admin dialog box, enter the administrator's first name, last name, and email address.

    Note:

    The email address must not contain the percent sign character (“%”).
  4. Select a Role for the administrator.

    For descriptions of the roles available, see Managing Oracle CASB Cloud Service Administrators.

    For information on what policy alert features are accessible by different administrator roles, see Oracle CASB Cloud Service Administrator Roles and Policies.

  5. If you didn’t select the tenant administrator role, in the Application instance box, select the instances this administrator is permitted to monitor:
    • Any (the default): Lets the administrator monitor all application instances

    • One or more individual instances: Lets the administrator monitor just those instances

  6. Click Save.
    The new administrator receives email with login instructions.