Administering Cloud EPM: The Platform Beneath the Business Processes · Module 6 · Users, Groups and the Role Model
What breaks
Lesson 75 of 201 · 2 min
Sequence first. "A user has the wrong access." Check in this order. One. Which groups are they in? Two. What roles are assigned to those groups, on which environments? Three. Is there an individual assignment overriding or adding to that? Four. Are they in the right identity domain for that environment? Five. Has the assignment taken effect — have they signed out and in? Six. Is a policy or sign-on restriction involved? Then eight cases. One. "Five thousand individual grants and every access change is manual." Nobody decided. It accumulated. The failure this module exists to prevent. Two. "A leaver still has access three months later." Per-user assignment, incomplete offboarding, no review. This is an audit finding, and occasionally worse. Three. "Twelve service administrators." Granted for convenience, never reviewed. Every one has full control of the data. Four. "Access review is impossible." Individual grants across five environments. Nobody can attest…
The full lesson is part of the course
The video, the complete written lesson and the module quiz are included in Administering Cloud EPM: The Platform Beneath the Business Processes, with a certificate on completion and a fourteen-day refund window.
In this module: Module 6 · Users, Groups and the Role Model
- 1What we are building
- 2The decision that does not feel like oneFree preview
- 3The access object model
- 4Predefined application roles
- 5Roles by business process
- 6Domain-level administrator roles
- 7Designing the group model
- 8Creating users
- 9Creating groups
- 10Policies for users and groups
- 11Assigning roles to groups
- 12Unassigning and offboarding
- 13Proving the model works
- 14What breaks
- 15Lab briefing: a role model for eight environments
- 16Lab solution walkthrough
