IAM / Oracle

Oracle OCI IAM / Identity Governance

Oracle Cloud Infrastructure Identity and Access Management provides identity domains for single sign-on, multifactor authentication, and lifecycle in Oracle Cloud. Oracle Identity Governance remains the adjacent on-premises heritage product for entitlements, with Access Governance for reviews.

Cloud IAM and identity governanceResearch reviewed

What you are evaluating

This profile covers native Oracle Cloud identity domains plus adjacent identity governance. It is not a generic customer-identity suite for non-Oracle applications unless those connections are in scope. Confirm identity-domain versus Identity Governance packaging on the quote.

A useful evaluation context

This can be evaluated by an Oracle application and Oracle Cloud-centric estate that needs native identity domains plus entitlement reviews.

Documented capabilities

The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.

  • Oracle Cloud Infrastructure identity domains provide single sign-on, multifactor authentication, and lifecycle for cloud and connected applications.
  • Oracle Identity Governance manages entitlements in the on-premises and hybrid heritage line.
  • Access Governance supports access reviews so standing Oracle application privileges can be certified rather than only authenticated.

Where it fits in the work

  1. Create a lab identity domain in an Oracle Cloud test tenancy and add synthetic users with multifactor authentication.
  2. Connect one Oracle application and, if in scope, one Identity Governance connector, then run a small access review.
  3. Disable a synthetic user in the identity domain and confirm both the cloud console and the connected application refuse the next session.

APPLY THE IDEA / ILLUSTRATIVE EXERCISE

Make the outcome observable.

In an Oracle Cloud test tenancy, create a synthetic administrator in an identity domain, require multifactor authentication to the console, then revoke the user and retry the console URL.

Evidence to look for

The revoked user cannot sign in, and the identity-domain audit log shows the disablement event for that synthetic account.

Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.

Questions for your evaluation

  1. Does the quote cover Oracle Cloud identity domains, Oracle Identity Governance, Access Governance, or a combination, and which tenant uses which?
  2. Which non-Oracle applications will actually federate to the identity domain in the lab?
  3. How does historical Identity Cloud Service naming map to the identity-domain SKU you would operate today?

Names you may encounter: Oracle Identity Cloud Service. Historical names do not establish current availability or feature equivalence.

Find your next idea.

Tip: press / to open search. Escape closes this window.