Administering Cloud EPM: The Platform Beneath the Business Processes · Module 7 · Provisioning at Scale
Password policies
Lesson 84 of 201 · 12 min
Review the default password policy, configure one to match a corporate standard, show multiple policies within a domain and when you would use them, show the policy presented to a user setting a password, and show the interaction with SSO — where the policy is and is not relevant. IN AN SSO-ENABLED ESTATE, THE CORPORATE IDENTITY PROVIDER GOVERNS THE PASSWORD POLICY FOR FEDERATED SIGN-IN. The local policy still matters for accounts that DO NOT federate — typically administrators and service accounts. Be precise about which applies where; this genuinely confuses people. Match the corporate standard rather than inventing one. Security will ask, and "it matches the corporate policy" is a much better answer than a number you chose.
The full lesson is part of the course
The video, the complete written lesson and the module quiz are included in Administering Cloud EPM: The Platform Beneath the Business Processes, with a certificate on completion and a fourteen-day refund window.
In this module: Module 7 · Provisioning at Scale
- 1Why manual provisioning fails
- 2What synchronization does and does not carry
- 3Synchronizing across identity domains
- 4Synchronizing specific users and groups
- 5Synchronizing from an external directory
- 6Groups for application-level role assignment
- 7Password policies
- 8Email notifications and password resets
- 9What breaks
- 10Lab: design the synchronization and test the leaver
