You are on page 1of 30

Agenda

• Create job role <Insert Picture Here>

• Create data role


• Create role provisioning rules
• Create duty role
• Create test user

1
Steps for creating a new job role

• (1) Create the job role in OIM


– Manage Job Roles task in FSM
– Click on “Adminstration” in top right corner
– Enter role name, display name and select a role category.
The role category must have a name with a suffix of “- Job
Roles”.
• (2) Run process to sync new job role to HR roles table
– Retrieve Latest LDAP Changes
• (3) Add duty roles to the job role in APM
– Manage Duties task in FSM
– Choose the required duty roles (application roles),
remembering to set the application to ‘hcm’ in the search
window if you are searching for an hcm duty role
• (4) Create Data Role
– Manage Data Roles and Security Profiles task

2
Steps for creating a new job role

• (5) Create Role Mapping Rule for new data role


– Manage HCM Role Provisioning Rules task
• (6) Assign data role to user

3
OIM – Create new job role

4
OIM – Create new job role

5
APM – Create new job role

6
APM – Create new job role

7
APM – Create new job role

8
Agenda

• Create job role <Insert Picture Here>

• Create data role


• Create role provisioning rules
• Create duty role
• Create test user

9
Create data role

10
Create data role

11
Create data role

12
Create data role

13
Create data role

14
Create data role

15
Agenda

• Create job role <Insert Picture Here>

• Create data role


• Create role provisioning rules
• Create duty role
• Create test user

16
Create role provisioning rules

17
Agenda

• Create job role <Insert Picture Here>

• Create data role


• Create role provisioning rules
• Create duty role
• Create test user

18
Steps for creating a new duty role

• (1) Create application role in APM


– Select Application “hcm” – very important!!
– Click on New Application Role
– Enter role name, display name description.
– No need for a role category.
• (2) Create Function Security policies
– Click on Create Policy
– Enter policy name and display name
– Add function security privileges (entitlements) in Targets
region

19
Steps for creating a new duty role

• (3) Create Data Security Policies


– Search for reference duty role and press Find Policies
– Select Data Security tab
– Select each data security policy in turn, press Edit, and add
the new duty role to the policy in the Roles tab, press Save
• (4) Add new duty role to role hierarchy
– Use Application Role Hierarchy tab to connect it to another
duty role
– Use External Role Mapping tab to add it to an existing job (or
abstract) role
• (5) (Re)generate data security policies for data roles /
abstract roles that inherit this new duty role, using
HCM Data Roles UI

20
APM – Create new duty role

21
APM – Create new duty role

22
APM – Create new duty role

23
APM – Create function security policy

24
APM – Create function security policy

25
APM – Create data security policies

26
APM – Create data security policies

27
APM – Create data security policies

28
Agenda

• Create job role <Insert Picture Here>

• Create data role


• Create role provisioning rules
• Create duty role
• Create test user

29
Steps for creating a test user

• (1) Create new user using “Manage Users” or “New


Person”
– Enter basic person, assignment information
– Enter dummy email address (Manage Users)
– Enter username (Manage Users)
– Add roles for the user
• (2) Reset password for the user
– Use Manage Job Roles task to get to OIM
– Search for user
– Select “Manually change the Password”
– Uncheck “E-mail the new password to the user”
– This password is temporary, user will be prompted to change
it when they next log in to Fusion Apps
• (3) Log in to Fusion Apps as the test user

30

You might also like