MSAMM
Back to course

Administering Cloud EPM: The Platform Beneath the Business Processes · Module 7 · Provisioning at Scale

Password policies

Lesson 84 of 201 · 12 min

Review the default password policy, configure one to match a corporate standard, show multiple policies within a domain and when you would use them, show the policy presented to a user setting a password, and show the interaction with SSO — where the policy is and is not relevant. IN AN SSO-ENABLED ESTATE, THE CORPORATE IDENTITY PROVIDER GOVERNS THE PASSWORD POLICY FOR FEDERATED SIGN-IN. The local policy still matters for accounts that DO NOT federate — typically administrators and service accounts. Be precise about which applies where; this genuinely confuses people. Match the corporate standard rather than inventing one. Security will ask, and "it matches the corporate policy" is a much better answer than a number you chose.

The full lesson is part of the course

The video, the complete written lesson and the module quiz are included in Administering Cloud EPM: The Platform Beneath the Business Processes, with a certificate on completion and a fourteen-day refund window.

Get the free lessons by email

We will email you a link to every free lesson in this course. No account needed, and one message only.

In this module: Module 7 · Provisioning at Scale

  1. 1Why manual provisioning fails
  2. 2What synchronization does and does not carry
  3. 3Synchronizing across identity domains
  4. 4Synchronizing specific users and groups
  5. 5Synchronizing from an external directory
  6. 6Groups for application-level role assignment
  7. 7Password policies
  8. 8Email notifications and password resets
  9. 9What breaks
  10. 10Lab: design the synchronization and test the leaver