Service Account Permission

This document will list the Min permission for the Service account need to connect to OIM server as per new Design.

Operation

Capabilities

Account Aggregation

User - View / Search

Account Aggregation

View Account Entitlements

Account Aggregation( If Target account is selected)

View Provisioned Accounts

Group Aggregation

Role - View / Search

Create User

User - Create

Create User With Password

User - Create

User - Change Password

Grant Account Entitlements

Modify User

User - Modify

Enable User

User - Enable

Disable User

User - Disable

Lock User

User - Lock

Unlock User

User - Unlock

Delete User

User - Delete

Target Account Provisioning

  • Deprovision Accounts

  • Disable Provisioned Accounts

  • Enable Provisioned Accounts

  • Grant Account Entitlements

  • Modify Account Entitlements

  • Modify Provisioned Accounts

  • Provision Accounts

  • Revoke Account Entitlements

Below are the steps to create Role.

  1. Navigate to Administration Roles.

  2. Click on Create Button.

  3. Add Name as per requirement.

  4. Add Capabilities as per the table specified above.

  5. Assign service account as member and Scope as per requirement.

  6. Click on Save.

Note: Filtering in Oracle Identity Manager can be achieved by restricting scope at permission level.
For example, Scope can be assigned to a role to restrict to fetch the data to a particular organization.