Administering Cloud EPM: The Platform Beneath the Business Processes · Module 7 · Provisioning at Scale
Groups for application-level role assignment
Lesson 83 of 201 · 11 min
Take a synchronized group and assign an application role to it. Show a synchronized joiner receiving access automatically. Show a synchronized leaver losing it automatically. Show the boundary: role assignment is local, membership is synchronized. And show what happens if a synchronized group is renamed at source. THIS IS THE PAYOFF OF MODULES 6 AND 7 TOGETHER. HR adds somebody to a group in the corporate directory; access appears in three EPM environments; nobody in the EPM team did anything. THE RENAME CASE MATTERS. A group renamed at source can break role assignments. Agree a change process with the identity team. The division of labour, restated for the last time: they own membership, you own capability.
The full lesson is part of the course
The video, the complete written lesson and the module quiz are included in Administering Cloud EPM: The Platform Beneath the Business Processes, with a certificate on completion and a fourteen-day refund window.
In this module: Module 7 · Provisioning at Scale
- 1Why manual provisioning fails
- 2What synchronization does and does not carry
- 3Synchronizing across identity domains
- 4Synchronizing specific users and groups
- 5Synchronizing from an external directory
- 6Groups for application-level role assignment
- 7Password policies
- 8Email notifications and password resets
- 9What breaks
- 10Lab: design the synchronization and test the leaver
