Create Application Policies

  1. Log in to Oracle Fusion Middleware Control Enterprise Manager.
  2. Go to WebLogic Domain > Security > Application Policies.

    The Application Policies screen appears.

  3. To create a new application policy, click Create.

    The Create Application Grant dialog box appears.

  4. From the Grantee section, click +Add.

    The Add Principal dialog box appears.

  5. From the Type drop-down, select Application Role and click SearchSearch icon.
  6. From the list of Searched Principals, select FARAdminRole and click OK.
  7. From the Permissions section, click +Add.

    The Add Permission dialog box appears.

  8. Select the Resource Types radio button.
  9. From the Resource Type drop-down, select oracle.bi.publisher.permission and click Search.
  10. From the Search Results, select oracle.bi.publisher.permission (Oracle Analytics Publisher Administer Server) and click Continue.

    The Add Permission dialog box appears.

  11. For Permission Actions, select All (_all_) and click Select.
  12. Add Resource Name as oracle.bi.user with Impersonate permission.

    The new FAR Admin policy has all the permissions.

    Note:

    Make sure all the fields are either selected or entered manually.

  13. Repeat from Step 4 to Step 12, to add the following:
    Policy Name/Principal Resource Type Resource Name Permission Actions

    FARAdminRole

    oracle.bi.user

    oracle.bi.user

    impersonate

    --

    oracle.bi.publisher.permission

    oracle.bi.publisher.administerServer

    _all_

    FARSafetyAuthorRole

    oracle.bi.publisher.permission

    oracle.bi.publisher.developDataModel

    _all_

    --

    oracle.bi.publisher.permission

    oracle.bi.publisher.developReport

    _all_

    FARConsumerRole

    oracle.bi.publisher.permission

    oracle.bi.publisher.accessExcelReportAnalyzer

    _all_

    --

    oracle.bi.publisher.permission

    oracle.bi.publisher.accessReportOutput

    _all_

    --

    oracle.bi.publisher.permission

    oracle.bi.publisher.accessOnlineReportAnalyzer

    _all_

    --

    oracle.bi.publisher.permission

    oracle.bi.publisher.scheduleReport

    _all_

  14. Similarly, create roles and policies for Expedited Reports for the following groups:
    • EXPAdminRole
    • EXPSafetyAuthorRole
    • EXPSafetyConsumerRole

Note:

For more details, refer to Section 2.8.3.2 Creating Application Policies Using Fusion Middleware Control from https://docs.oracle.com/middleware/1221/bip/BIPAD.pdf