Restricting Access to OCI (Gen2)Environments Using Sign-On Policies

The default sign-on policy in Oracle Identity Cloud Service allows all users assigned to predefined roles to sign in to an Oracle Enterprise Performance Management Cloud environment by supplying their credentials (user name and password). Identity Domain Administrators may configure a custom sign-on policy to determine whether a user is allowed to access OCI (Gen2) EPM Cloud environments. For example, you may configure a policy that allows only users assigned to the Service Administrator role to access environments.

If you configure a custom sign-on policy, ensure that it allows all EPM Cloud users to sign in. For detailed information on setting sign-on policy, see these topics in Administering Oracle Identity Cloud Service:

Troubleshooting

See Troubleshooting Issues with Sign-On Policies in Oracle Enterprise Performance Management Cloud Operations Guide.