EPM · Fusion · Intermediate
Administering Cloud EPM: The Platform Beneath the Business Processes
Nineteen modules on the platform layer almost nobody teaches — identity, security, recovery and the estate
A practical administration course for Cloud EPM service administrators, cloud and identity teams inheriting an EPM estate, Center of Excellence leads, and consultants who keep getting handed the platform work nobody scoped. IT DOES NOT TEACH HOW TO CONFIGURE PLANNING, FINANCIAL CONSOLIDATION AND CLOSE, ACCOUNT RECONCILIATION OR ANY OTHER INDIVIDUAL BUSINESS PROCESS — each of those is its own implementation and its own course. This teaches how to run the platform they live on: cloud accounts, identity domains and regions; creating, sizing and retiring environments; a role model that survives growth; single sign-on and directory synchronization; network perimeter, managed provider access and customer-managed encryption keys; clients and automation; backups, disaster recovery and the restore you have never actually performed; the operating calendar; monitoring and the evidence an auditor asks for; and the Center of Excellence that holds all of it. Every module ends with a failure segment and a diagnostic sequence.
SAR 1,800
201 lessons · 1,361 min
What you will be able to do
- Design the identity and infrastructure structure an EPM estate will live in for a decade — cloud account, identity domains, regions, compartments — and defend the parts you can never change
- Treat region selection as the legal decision it is, and get a residency constraint in writing before provisioning anything
- Create, name, document, hand over and retire environments, and read any EPM URL to say which environment it is before you act on it
- Put a business process into an environment and move one between environments, knowing what migrates and what does not
- Design a role model that works at five hundred users as well as at five — roles to groups, never to people
- Connect the estate to the corporate directory so joiners, movers and leavers happen once, in one place
- Federate the estate to a corporate identity provider without locking yourself out, and know what SSO does to Smart View and automation before your users find out
- Restrict the network perimeter, control what the provider itself can access, hold your own encryption keys, and answer a security questionnaire without guessing
- Choose the right automation tool for each task and build automation that reports its own failures
- Distinguish the three different things called "backup", restore an environment, and state how long it actually took
- Run the operating calendar — maintenance windows, patch readiness, appearance, email deliverability — so the platform runs quietly
- Build a monitoring routine that finds problems before users report them and an evidence pack that turns an audit from a week into an afternoon
- Assess an organization against the capability inventory of a Center of Excellence, and make the case for one to a sceptical sponsor
What you should know first
- General cloud and identity literacy. Nothing about Cloud EPM specifically is assumed.
- THIS COURSE DOES NOT TEACH BUSINESS PROCESS CONFIGURATION. If you want to learn how to build a Planning application, configure a consolidation, or set up reconciliations, this is not that course — those are separate implementations and separate courses. This is the platform underneath them.
- ACCESS: three levels, and which you have determines how much you can do hands-on. Service administrator on ONE environment is enough for the orientation, operations and enablement phases — most of the course. Building the estate and securing it needs CLOUD ACCOUNT AND IDENTITY DOMAIN ADMINISTRATION, which most learners will not have and should not request on a production tenant.
- Follow-along mode is a legitimate primary path here, not a consolation. Every privileged lesson ships a screenshot-complete guide, and the labs assess your design reasoning — which is the part that is actually hard, and which is graded equally.
- NEVER practise identity, security or network perimeter configuration in a live tenant. Locking yourself out of a production EPM estate is possible, unglamorous and career-adjacent. Use a disposable or non-production tenant.
- This is the fastest-dating course in the catalogue — the platform layer changes monthly. Every module carries a recorded-against date, concepts are taught ahead of click paths, and the course teaches you to read release readiness notes yourself, which is the durable skill.
What you will cover
1. Module 0 · Orientation
What this course is and — just as important — what it is not. The access levels each phase needs, so you know before you start which parts you can do hands-on. The shape of the platform administrator's job, which in most organizations nobody ever wrote a description for. And the three modules that carry the decisions worth taking slowly.
- 1How this course works3 min
- 2What access you will need2 min
- 3The platform administrator's job2 min
- 4Your setup checklist1 min
2. Module 1 · The Cloud EPM and EDM Landscape
Cloud EPM names a family of about eleven business processes plus a data management capability — and an environment hosts exactly one of them. That single rule determines estate size and therefore workload, and it is why platform administration is a job. This module names every business process, groups them into families, and draws the platform layer underneath all of them that the rest of the course is about.
- 1A suite, not a productFree preview2 min
- 2The planning family2 min
- 3The close and consolidation family2 min
- 4The analysis and reporting family2 min
- 5Enterprise Data Management and Cloud EDM2 min
- 6The platform underneathFree preview2 min
- 7Navigating an environment10 min
- 8Where the Center of Excellence fits2 min
- 9Lab: name the suite, scope three clients, draw the platform2 min
3. Module 2 · Subscriptions and Licensing
Licensing looks like a procurement problem and is repeatedly an administrator problem, because the person who discovers the entitlement gap is almost always the one trying to create an environment or add a user. This module teaches you to read a client's subscription, say what it does and does not entitle them to, and raise the surprise in week one rather than month six.
- 1Why an administrator needs to understand licensing2 min
- 2EPM Standard and EPM Enterprise2 min
- 3Subscriptions per business process2 min
- 4Cloud EDM subscriptions1 min
- 5Metrics: hosted employee, named user, records2 min
- 6Ordering and the activation checklist11 min
- 7What breaks2 min
- 8Lab: build an entitlement register and find the risks3 min
4. Module 3 · Cloud Account, Identity Domains and Regions
THE FIRST FLAGSHIP. Every environment lives inside an identity domain, inside a cloud account, in a region — and those three facts determine who can sign in, where the data physically resides, and what it costs to change your mind. Restructuring after environments exist is a migration with downtime, and region selection is a data residency commitment with legal weight. The module's argument: design the identity structure before you create anything, because the first environment you create fixes it. The build is ninety minutes; the design should take days.
- 1What we are building1 min
- 2The decisions you cannot undo2 min
- 3The identity object model2 min
- 4Identity domains — the central decision2 min
- 5Regions and data residency2 min
- 6Compartments1 min
- 7Running the estate design workshop3 min
- 8Four worked estate structures2 min
- 9Activating: creating a new cloud account12 min
- 10Activating: adding to an existing account11 min
- 11Touring the Oracle Cloud Console11 min
- 12Enabling multifactor authentication9 min
- 13Subscribing to and replicating regions10 min
- 14Creating a compartment8 min
- 15Creating an identity domain12 min
- 16Identity domain administrators10 min
- 17What breaks3 min
- 18Lab briefing: Northwind Group4 min
- 19Lab solution walkthrough20 min
5. Module 4 · Creating and Managing Environments
Creating, naming, documenting, handing over and retiring environments — and giving users a URL they can actually remember. It also teaches the habit that prevents a category of bad afternoons: read any EPM URL before you act on it, and confirm which environment it actually is.
- 1What an environment is1 min
- 2Test and production2 min
- 3Creating an environment13 min
- 4Viewing and documenting the estate11 min
- 5URL patterns: classic and OCIFree preview2 min
- 6Vanity URLs11 min
- 7Granting console access to service administrators10 min
- 8Retiring environments12 min
- 9What breaks2 min
- 10Lab: build the estate and give it a register2 min
6. Module 5 · Business Processes and Migration
Putting a business process into an environment, moving one between environments, and knowing what the migration paths are before somebody asks you to move something that cannot be moved. The rule to carry out of it: never plan a migration you have not tested, and the answer to "can we move this?" is never a flat yes.
- 1One environment, one business process2 min
- 2Creating from the Standard landing page12 min
- 3Creating from the Enterprise landing page13 min
- 4Switching business processes11 min
- 5Migration: the concepts2 min
- 6Migration paths by business process2 min
- 7Performing a migration14 min
- 8Transitioning the data management business process to standalone11 min
- 9Essbase in Cloud EPM1 min
- 10What breaks2 min
- 11Lab: create, migrate, and write the plan3 min
7. Module 6 · Users, Groups and the Role Model
THE SECOND FLAGSHIP, and the only one where the wrong decision does not feel like a decision at all. Nobody chooses per-user role assignment — they just start, and then they have five hundred users and five thousand individual grants, each of which must be created on joining, changed on moving and removed on leaving. The module's argument: assign roles to groups, never to people, and decide that before the eleventh user. This phase is roughly a quarter of the job and it is routinely scoped as half a day.
- 1What we are building1 min
- 2The decision that does not feel like oneFree preview2 min
- 3The access object model2 min
- 4Predefined application roles1 min
- 5Roles by business process2 min
- 6Domain-level administrator roles1 min
- 7Designing the group model2 min
- 8Creating users11 min
- 9Creating groups11 min
- 10Policies for users and groups10 min
- 11Assigning roles to groups13 min
- 12Unassigning and offboarding11 min
- 13Proving the model works10 min
- 14What breaks2 min
- 15Lab briefing: a role model for eight environments3 min
- 16Lab solution walkthrough18 min
8. Module 7 · Provisioning at Scale
Connecting the estate to the corporate directory so joiners, movers and leavers happen once, in one place, by people who already do it for a living. The group model makes provisioning survivable; synchronization makes it correct — and the division of labour it creates is the reason the group design mattered so much.
- 1Why manual provisioning fails2 min
- 2What synchronization does and does not carry1 min
- 3Synchronizing across identity domains14 min
- 4Synchronizing specific users and groups12 min
- 5Synchronizing from an external directory15 min
- 6Groups for application-level role assignment11 min
- 7Password policies12 min
- 8Email notifications and password resets10 min
- 9What breaks2 min
- 10Lab: design the synchronization and test the leaver2 min
9. Module 8 · Single Sign-On and Federation
Federating the estate to the corporate identity provider, handling the multi-domain and multi-account cases, and knowing what SSO does to your clients before your users find out. The security argument that carries it: without SSO, disabling someone's corporate account does nothing to their EPM access — with it, it does.
- 1What SSO changes2 min
- 2The sign-in experience under SSO1 min
- 3Configuring an external identity provider16 min
- 4Completing configuration in the console14 min
- 5Multiple identity providers in one domain11 min
- 6SSO across domains in one cloud account13 min
- 7SSO across different cloud accounts12 min
- 8Logout URL and credential management11 min
- 9Making clients work after SSO12 min
- 10What breaksFree preview2 min
- 11Lab: federate without locking yourself out2 min
10. Module 9 · Securing the Perimeter
Restricting who can reach the estate and from where, controlling what the provider itself can access, holding your own encryption keys, and answering a security questionnaire without guessing. The proportionality point runs through it: not every estate needs customer-managed keys and approval-gated provider access, and a perimeter so tight that legitimate users cannot work produces workarounds that are worse than the original risk.
- 1Defence in depth for an EPM estate1 min
- 2Network perimeter14 min
- 3Migrating from per-environment IP allowlists11 min
- 4Sign-on policies12 min
- 5Break Glass: managed provider access11 min
- 6Approving access requests10 min
- 7Customer-managed keys: the concepts2 min
- 8Configuring customer-managed keys15 min
- 9Compliance reports and the security capability set2 min
- 10Answering a security questionnaireFree preview2 min
- 11What breaks2 min
- 12Lab: proportionate security, and ten questionnaire answers3 min
11. Module 10 · Clients and Tools
Users experience the platform through clients, which means a Smart View problem is your problem regardless of whose laptop it is. Which client every user needs, how to get it to them, how to connect it, and what to check before you change anything upstream that might break it. This phase describes the job as it is actually lived: the earlier phases happen once, and this happens every day.
- 1The client landscape2 min
- 2Clients by business process2 min
- 3Smart View and its variants2 min
- 4Prerequisites and version support1 min
- 5Downloading and installing12 min
- 6Connection types and URL syntax11 min
- 7Financial Reporting Web Studio and Calculation Manager10 min
- 8Browser configuration and support11 min
- 9What breaks2 min
- 10Lab: inventory, connect, and plan the deployment2 min
12. Module 11 · Automation
Automating the recurring work — backups, loads, refreshes, exports — with the right tool for each job, and building a runbook someone else could operate. Automation is not about saving time; it is about reliability, auditability and a task that runs correctly whether or not the person who normally does it is available. And the governance point that matters more than the tooling: automation nobody monitors is worse than manual work, because manual work fails visibly.
- 1Three tools, one questionFree preview2 min
- 2Job Scheduler12 min
- 3Installing and configuring the automation utility13 min
- 4Authentication and credential handling14 min
- 5The command surface11 min
- 6Scripting patterns: backup and export14 min
- 7Scripting patterns: data load and refresh13 min
- 8Error handling and logging14 min
- 9Scheduling and service accounts12 min
- 10REST APIs and when to reach for them2 min
- 11The integration agent1 min
- 12What breaks2 min
- 13Lab: automate it, and write the runbook2 min
13. Module 12 · Business Continuity and Recovery
THE THIRD FLAGSHIP, and a different kind of risk from the other two. Those are decisions you cannot undo; this is the one where being wrong is UNRECOVERABLE — and unlike the others the failure is invisible until the day it matters. Nothing tells you your recovery plan does not work. You find out. The module's argument: a backup you have never restored is not a backup, it is a belief. By the end of it you will have restored an environment and timed it.
- 1What we are building1 min
- 2The belief problemFree preview2 min
- 3Three things called backupFree preview2 min
- 4What is in each, and what is not1 min
- 5Version compatibility1 min
- 6Managing daily backups12 min
- 7Archival, retention and retrieval12 min
- 8Data size and its limits12 min
- 9Restoring an environment15 min
- 10Self-service disaster recovery10 min
- 11Capacity scaling9 min
- 12Writing and testing a recovery plan2 min
- 13What breaks2 min
- 14Lab briefing: objectives, a real restore, and the gap3 min
- 15Lab solution walkthrough18 min
14. Module 13 · Running the Environment
The operating rhythm — maintenance windows, update handling, appearance, session timeout, email deliverability and announcements — set so the platform runs quietly and nobody has to think about it. A platform administrator without a calendar is a platform administrator reacting; the work is predictable, and the calendar is what makes it manageable.
- 1The operating calendar1 min
- 2Daily maintenance13 min
- 3Feature updates and readiness10 min
- 4Content update scheduling10 min
- 5Configuring appearance11 min
- 6Session timeout and environment description9 min
- 7Email: sender, SPF, DKIM, DMARC14 min
- 8Announcements9 min
- 9What breaks2 min
- 10Lab: build the calendar and set the rhythm2 min
15. Module 14 · Monitoring the Estate
The reports exist, they are comprehensive, and almost nobody reads them until something has already gone wrong. This module builds the routine that finds problems before users report them and produces the evidence auditors ask for without a scramble. The routine is the deliverable, not the reports — and most of what matters is a trend rather than a value.
- 1Monitoring as a routine, not a reaction1 min
- 2The activity report: environment and users14 min
- 3The activity report: usage and performance14 min
- 4The activity report: application and Essbase14 min
- 5Business-process-specific metrics13 min
- 6Access logs11 min
- 7Automating report download11 min
- 8The role assignment report12 min
- 9Audit, login and usage reporting13 min
- 10Building the routine, and what breaks3 min
- 11Lab: read a report, then build the routine2 min
16. Module 15 · User Enablement and Support
A platform administrator with two hundred users and no support model becomes a helpdesk, and everything else in this course stops happening. This module builds the tiers that keep a user base productive without consuming your week — guidance inside the product, a working feedback loop, and users who can help themselves.
- 1The support model2 min
- 2Guided learning14 min
- 3Context-based activation10 min
- 4The feedback utility13 min
- 5Feedback notifications and triage10 min
- 6Help Center, Learning Library and Customer Connect11 min
- 7Translation, accessibility and what breaks2 min
- 8Lab: build the support model and use the feedback loop properly2 min
17. Module 16 · AI Agent Studio and EPM Assistants
What EPM Assistants actually are — downloadable, preconfigured TEMPLATES for creating agents, not agents you turn on — how to assemble the prerequisite stack they need, and how to give a client an honest assessment of whether it is worth it yet. This is the fastest-dating module in the course and everything in it must be verified against current documentation. It is worth learning anyway, because the prerequisite stack is identity work and identity work is durable.
- 1What EPM Assistants are2 min
- 2Scope and requirements1 min
- 3The prerequisite stack2 min
- 4Configuring authentication and federation15 min
- 5Configuring user access11 min
- 6Downloading and importing assistants14 min
- 7Running and validating agents12 min
- 8An honest assessment, and what breaks2 min
- 9Lab: scope it honestly and place it in the role model2 min
18. Module 17 · The EPM Center of Excellence
The module that assembles the course. The source material opens with this topic and this course closes with it deliberately, because governance is a set of capabilities and you cannot define capabilities you do not understand. A Center of Excellence is not a governance committee bolted onto a technology — it is the standing team that holds the capabilities the preceding sixteen modules taught.
- 1Why the last module and not the first1 min
- 2What a Center of Excellence is1 min
- 3The capability inventory2 min
- 4Staffing and roles2 min
- 5Standards and governance2 min
- 6The operating model1 min
- 7Making the case2 min
- 8What breaks2 min
- 9Lab: assess the capability and write the one-page proposal2 min
19. Module 18 · Full Platform Capstone
A brief and an estate to assess, secure, operate and recover. A manufacturing group whose EPM estate has grown without a plan across two cloud accounts and three identity domains, with 340 individual role assignments, no single sign-on, a residency violation confirmed in writing, a nightly load running from an analyst's laptop under her personal account, and three internal audit findings due in ninety days. Eight deliberate ambiguities to resolve and justify. The graded centrepiece is the recovery exercise, which has no partial credit for intent.
- 1How the capstone works1 min
- 2The client brief3 min
- 3Building your plan14 min
- 4Submission and grading2 min
- 5Solution walkthrough55 min
- 6Common submission mistakes3 min
