Administering Cloud EPM: The Platform Beneath the Business Processes · Module 3 · Cloud Account, Identity Domains and Regions
Enabling multifactor authentication
Lesson 33 of 201 · 9 min
Navigate to the identity domain's security settings, enable multifactor authentication, choose the factors to permit, set the enrolment policy, and enrol one account to show the user-side experience. Then verify by signing in. Do this before you create users, not after. Retrofitting MFA onto a populated domain means chasing enrolment across a population that has already learned to sign in without it. Have a documented recovery path before you enforce. An administrator who loses their factor and has no bypass has locked the estate — and it is the administrator, not the ordinary user, who is exposed here, because there is nobody above them to reset it. Where MFA sits when SSO is in play is a Module 8 question. Enable it here regardless — a federated estate still has break-glass local accounts, and those are exactly the ones worth protecting.
The full lesson is part of the course
The video, the complete written lesson and the module quiz are included in Administering Cloud EPM: The Platform Beneath the Business Processes, with a certificate on completion and a fourteen-day refund window.
In this module: Module 3 · Cloud Account, Identity Domains and Regions
- 1What we are building
- 2The decisions you cannot undo
- 3The identity object model
- 4Identity domains — the central decision
- 5Regions and data residency
- 6Compartments
- 7Running the estate design workshop
- 8Four worked estate structures
- 9Activating: creating a new cloud account
- 10Activating: adding to an existing account
- 11Touring the Oracle Cloud Console
- 12Enabling multifactor authentication
- 13Subscribing to and replicating regions
- 14Creating a compartment
- 15Creating an identity domain
- 16Identity domain administrators
- 17What breaks
- 18Lab briefing: Northwind Group
- 19Lab solution walkthrough
