MSAMM
Back to course

Administering Cloud EPM: The Platform Beneath the Business Processes · Module 7 · Provisioning at Scale

Groups for application-level role assignment

Lesson 83 of 201 · 11 min

Take a synchronized group and assign an application role to it. Show a synchronized joiner receiving access automatically. Show a synchronized leaver losing it automatically. Show the boundary: role assignment is local, membership is synchronized. And show what happens if a synchronized group is renamed at source. THIS IS THE PAYOFF OF MODULES 6 AND 7 TOGETHER. HR adds somebody to a group in the corporate directory; access appears in three EPM environments; nobody in the EPM team did anything. THE RENAME CASE MATTERS. A group renamed at source can break role assignments. Agree a change process with the identity team. The division of labour, restated for the last time: they own membership, you own capability.

The full lesson is part of the course

The video, the complete written lesson and the module quiz are included in Administering Cloud EPM: The Platform Beneath the Business Processes, with a certificate on completion and a fourteen-day refund window.

Get the free lessons by email

We will email you a link to every free lesson in this course. No account needed, and one message only.

In this module: Module 7 · Provisioning at Scale

  1. 1Why manual provisioning fails
  2. 2What synchronization does and does not carry
  3. 3Synchronizing across identity domains
  4. 4Synchronizing specific users and groups
  5. 5Synchronizing from an external directory
  6. 6Groups for application-level role assignment
  7. 7Password policies
  8. 8Email notifications and password resets
  9. 9What breaks
  10. 10Lab: design the synchronization and test the leaver