Administering Cloud EPM: The Platform Beneath the Business Processes · Module 6 · Users, Groups and the Role Model
Domain-level administrator roles
Lesson 67 of 201 · 1 min
Administration of the identity domain itself — creating users, managing groups, configuring security. Distinct from anything inside a business process. The main administrator roles, and what each permits, at the level a platform administrator needs. And now the segregation of duties question, properly. Whoever can create identities, grant themselves roles, and administer the business process has unconstrained access to the data. In a large organization these are different people. IN A SMALL ONE THEY ARE NOT — AND THAT SHOULD BE A DOCUMENTED ACCEPTED RISK WITH A COMPENSATING CONTROL, typically periodic review by somebody outside the function. The failure is not the concentration of privilege. The failure is the concentration of privilege that nobody wrote down. The minimum count rule, restated from Module 3: never fewer than two domain administrators with working MFA. And the review obligation. Domain administration is the highest-privilege grant in the estate. Review it quarterly at…
The full lesson is part of the course
The video, the complete written lesson and the module quiz are included in Administering Cloud EPM: The Platform Beneath the Business Processes, with a certificate on completion and a fourteen-day refund window.
In this module: Module 6 · Users, Groups and the Role Model
- 1What we are building
- 2The decision that does not feel like oneFree preview
- 3The access object model
- 4Predefined application roles
- 5Roles by business process
- 6Domain-level administrator roles
- 7Designing the group model
- 8Creating users
- 9Creating groups
- 10Policies for users and groups
- 11Assigning roles to groups
- 12Unassigning and offboarding
- 13Proving the model works
- 14What breaks
- 15Lab briefing: a role model for eight environments
- 16Lab solution walkthrough
