We’re sorry. We could not find a match for your search.

We suggest you try the following to help find what you're looking for:

  • Check the spelling of your keyword search.
  • Use synonyms for the keyword you typed, for example, try “application” instead of “software.”
  • Start a new search.
Contact Us Sign in to Oracle Cloud

Access Governance FAQ

Service functionality

What is Oracle Access Governance?

Oracle Access Governance is a cloud native identity governance and administration service that provides insight-based access reviews, identity analytics, and intelligence capabilities for businesses. More specifically, it provides

  • Visibility into enterprise compliance by providing details on who has access to what
  • The ability for reviewers to rightsize user privileges through intelligent access review campaigns
  • Visibility into actionable identity intelligence by building deep insights into potential security violations, which enables the rapid remediation of identity and access issues
  • The ability to enable continuous compliance to meet broader organizational needs

Please refer to the Oracle Access Governance web page for more details about the service.

What are some key features of Oracle Access Governance?

Oracle Access Governance provides the following key features and functionalities:

  • Identity orchestration with Oracle Cloud Infrastructure (OCI) and Oracle Identity Governance/Oracle Identity Management
  • Continuous discovery of users, groups, roles, applications, permissions, and policies
  • Visibility into user access privileges to any resource across the organization
  • Cross-cloud and cross-enterprise access correlation
  • Ad hoc, periodic, and event-based access review campaigns to govern the access privileges assigned to users (including employees, contractors, and partners)
  • Prescriptive analytics and recommendations, enabling access reviewers to efficiently review and limit user access
  • An easy-to-comprehend view and simplified access reviews of OCI policies
  • Automated fulfillment of access decisions

How can I start using Access Governance?

To start using Access Governance, follow these steps:

Which identity management systems can be integrated with Access Governance?

Access Governance can be integrated with Oracle Identity Governance and Oracle Cloud Infrastructure (OCI) to load identity data. We will eventually continue to add other identity management systems. Please refer to the following product documentation for more details: Access Governance Integration with Connected Systems.

How does Access Governance connect with on-premises Oracle Identity Governance?

Access Governance offers a containerized agent for on-premises integrations, including Oracle Identity Governance. This agent is customized and configured to work with a specific instance of Access Governance and a specific setup of Oracle Identity Governance over a secure channel. The agent’s purpose is to facilitate the secure transfer of data between Access Governance and the customer’s on-premises source of identity and access data.

Can Access Governance be used with Oracle Identity Governance in hybrid mode to perform identity governance and administration?

As an Oracle Identity Governance customer, you can use Oracle Access Governance to perform intelligent access reviews and keep using Identity Governance for identity lifecycle management, access control, access requests, and user provisioning.

Can the Access Governance service be integrated with multiple Oracle Cloud Infrastructure (OCI) tenancies?

Yes, Access Governance can be integrated with multiple OCI tenancies, thus providing cross-cloud access correlation of identities' access privileges. We will eventually continue to add other cloud service providers, such as AWS, Azure, and Google Cloud Platform.

How does Access Governance connect with cloud applications and OCI?

Access Governance connects with cloud applications and cloud service providers through cloud application programming interfaces (APIs). No containerized agent is required to connect.

How can users who are synchronized in Access Governance access its service console?

Users who are synchronized in Access Governance should be onboarded in Oracle Cloud Infrastructure Identity and Access Management (OCI IAM) so they can access the Access Governance console. These users can be onboarded in OCI IAM using one of the following approaches:

  • Configure Oracle Identity Governance provisioning with OCI IAM using the Oracle Identity Cloud Service (IDCS) connector.
  • Set up federation with an external identity provider and enable Security Assertion Markup Language (SAML) just-in-time provisioning.
  • Build a self-registration profile.

Please refer to the following product documentation and tutorials for more details:

How can I select a subset of identities in my enterprise to govern their access privileges in Oracle Access Governance?

If you want to govern access privileges assigned to a subset of identities belonging to a defined location, department, organization, or any other user attribute, you can mark those users as ACTIVE in Oracle Access Governance. In Oracle Access Governance

  • Access review tasks will be generated for the identities marked as ACTIVE.
  • Only users marked as ACTIVE can log in to the Oracle Access Governance console and review their and their directs’ access privileges.

Please refer to this documentation for more details: Activate/Inactivate Identities for License Management.

How do access reviews work in Oracle Access Governance?

Oracle Access Governance is used to execute intelligent access review campaigns with prescriptive analytics–based identity insights to help access reviewers make informed decisions quickly. It supports event-driven, periodic, and on-demand access review campaigns. The access reviewers can review user permissions, role memberships, and OCI policies in a single dashboard view, ensuring that users only have the access privileges they need to complete their tasks.

How do event-based access reviews work in Access Governance?

An event-based access review is triggered for a user when their attributes, such as organization, manager, location, employment status, and so on, get updated in Access Governance.

Does Access Governance provide identity intelligence (analytics, artificial Intelligence/machine learning–based insights, and so on)?

Access Governance provides AI/ML-driven insights, such as peer group analysis, outlier detection, and recommendations, enabling reviewers to take suggested actions to complete access review tasks.

How does Access Governance help maintain the identity security posture in Oracle Cloud Infrastructure (OCI)?

Oracle Access Governance helps an organization maintain the security posture for their OCI workloads by providing

  • Visibility into who has access to what for any cloud resource
  • An easy-to-comprehend view and simplified access reviews of OCI policies
  • Identity orchestration and automated fulfillment based on OCI best practices

Can a user’s custom attributes be used in Access Governance?

Custom attributes of a user’s schema defined in Oracle Identity Governance can be used in Access Governance to

  • Mark identities as ACTIVE
  • Define user selection criteria in access review campaigns
  • Define event-based access reviews

Please refer to the following product documentation for more details: View and Configure Custom Identity Attributes.

Can an access reviewer delegate a review task in Oracle Access Governance?

Yes, an access reviewer can delegate an access review task to another individual or an identity collection (user group) by defining the delegation policy for themselves in the Oracle Access Governance console.

Are access review decisions recorded for auditing and compliance purposes?

Yes. For each decision made in an access review campaign, the following information is stored for auditing or compliance purposes:

  • What is decided
  • Who decided it
  • Why (justification)
  • When it was decided

What reporting and analytics functionality does the product provide?

Access Governance provides intelligent reporting for access reviews using graphs and charts that are easy to use and interpret. It also provides a detailed report of the access review campaign in CSV format.

Does the solution provide workflows for access reviews?

Access Governance provides multiple workflows for access reviews out of the box. Workflows automatically perform the series of actions associated with the access review campaign.

Does Access Governance provide a web-based and mobile-friendly administration and self-service console?

Oracle Access Governance is a smart device–optimized, web-based console designed to perform seamlessly from any device—computer, tablet, or smartphone.

Which identity providers does Access Governance support for user login?

Access Governance supports Oracle Cloud Infrastructure Identity and Access Management as its identity provider for user login and authorization. To log in using an external identity provider, configure OCI IAM to use that external identity provider for federated authentication.

Please refer to the following product documentation for instructions on how to set up federation with an external identity provider: Manage Identity Providers.

Service management

How can I get Access Governance in Oracle Cloud?

Access Governance is available as part of Oracle Universal Credits. When you order Oracle Access Governance through Universal Credits, you automatically get access to Oracle Cloud Infrastructure and other required services. For details, please refer to the following product documentation: Before You Begin.

How do I create an Access Governance instance?

You create an Access Governance instance in the Oracle Cloud Infrastructure Console. For details, please refer to the following product documentation: Set Up Service Instance.

How do I manage an Access Governance instance?

You can manage an Access Governance instance in the Oracle Cloud Infrastructure Console. For details, please refer to the following product documentation: Manage Service Instance.

How can I launch an Access Governance instance once it's created?

It’s accessible from the Oracle Cloud Infrastructure Console. You can navigate to the Access Governance page, select the service instance you want to access, and then click the Access Governance URL.

How can I get support for Access Governance?

Go to My Oracle Support and create a service request.

Is there a charge for Oracle Support in addition to my subscription fee?

No. Support is included in the subscription fee.

How can I patch or upgrade my service?

Access Governance is a cloud native service. Oracle takes care of patching and upgrading the service.

Where can I get more information about the service level agreement?

Please refer to the SLA documentation (PDF).

Licensing and pricing

What license types can I use to buy Access Governance?

Oracle Access Governance comes with two SKUs, and each SKU has different tiers. The two SKUs are

  • Oracle Access Governance for Oracle Cloud Infrastructure—Workforce User
    Oracle Access Governance for Oracle Cloud Infrastructure provides comprehensive and granular visibility into who has access to what and how that access is granted across an OCI tenancy. It addresses the need to eliminate excessive privileges and reduce access risk and cost across Oracle Cloud Infrastructure resources and services. It’s designed to review policies and govern access privileges assigned to identities across multiple OCI environments.
  • Oracle Access Governance for Oracle Workloads—Workforce User
    Oracle Access Governance for Oracle Workloads—Workforce User provides a single pane of glass to govern and manage the access privileges of workforce users for Oracle workloads running anywhere. It also empowers business and security owners to run access certification campaigns to review user access privileges across cloud resources and enterprise applications and remediate high-risk access appropriately.

For more details, please refer to the Oracle Access Governance pricing.

What integrations are supported by each SKU

The integrations supported by each of the two Access Governance SKUs are

  • Oracle Access Governance for Oracle Cloud Infrastructure—Workforce User
    - Supported integrations: Oracle Cloud Infrastructure
  • Oracle Access Governance for Oracle Workloads—Workforce User
    - Supported integrations: Oracle Cloud Infrastructure, Oracle Identity Governance

What is the unit metric for each license?

"Workforce user per month" is the unit metric for each license in Access Governance. Please refer to the following documentation for more details: Oracle PaaS and IaaS Universal Credits Service Descriptions (PDF).

Will I be charged for all identities synchronized in Access Governance?

By default, all identities synchronized from connected systems, such as Oracle Identity Management, Oracle Cloud Infrastructure, and so on, into Access Governance will have NULL status. You can mark only the identities you want to govern in Access Governance as ACTIVE. Only the identities marked as ACTIVE in Access Governance will be considered for billing, starting from the hour in which those identities are marked as ACTIVE.

If you have marked a set of ACTIVE identities as INACTIVE, then those identities will not be considered for billing starting from the hour in which they are marked as INACTIVE.

Even though the metric for Access Governance SKUs is per month, Oracle is passing benefits on to the customer by calculating the number of ACTIVE identities on an hourly basis and generating the bill for the entire month.

How can I mark identities as ACTIVE or INACTIVE in Access Governance?

Access Governance provides identity filtering or marking functionality based on which identities can be marked as ACTIVE. An administrator may use identity attributes to define such rules.

Can I run campaigns on identities marked as INACTIVE?

No, you can’t run access review campaigns on identities marked as INACTIVE in Access Governance.

Can identities marked as INACTIVE access the Access Governance console?

No, identities marked as INACTIVE can’t access the Access Governance console.

I want to review the access privileges of disabled identities. How can I do so in Access Governance?

A disabled identity can be marked as an ACTIVE identity in Access Governance so you can review its access privileges. An administrator may set rules to mark those disabled identities as ACTIVE in Access Governance.

Will I be charged for disabled identities?

For billing, Access Governance will include only those disabled identities marked as ACTIVE.

How can I stop billing and keep the Access Governance instance?

If you mark all identities as INACTIVE, then the bill generated for your Access Governance instance will be null.

Can the licensing model of my Access Governance service instance be upgraded if the current license type is Oracle Access Governance for Oracle Cloud Infrastructure—Workforce User?

The Access Governance license type can be upgraded without any service disruption. So, you may upgrade the license type from Oracle Access Governance for Oracle Cloud Infrastructure—Workforce User to Oracle Access Governance for Oracle Workloads—Workforce User. You can do it manually from the Access Governance page in the Oracle Cloud Infrastructure Console.

I have 22,000 users in Oracle Identity Governance/Oracle Identity Management integrated with Access Governance. I want to run access reviews for only 10,000 users who belong to a specific user organization. How can I do so and for how many users will I be billed?

By default, all 22,000 users synchronized from Oracle Identity Management into Access Governance will have NULL status. You may mark the required 10,000 users as ACTIVE based on their user-organization attribute. You will be billed for users who are marked as ACTIVE in Access Governance.

I have two Identity Access Management domains in my Oracle Cloud Infrastructure tenancy with 1,000 users in each domain, and each OCI user is distinct. For how many users will I be billed?

If you want to review the access privileges of all users in this OCI tenancy, then you may mark all users as ACTIVE in Access Governance. You will be billed for 2,000 (2 × 1,000) users in this case.

If you want to review the access privileges of users belonging to only one of the two domains, then you may define a rule to mark only users of that domain as ACTIVE in Access Governance. You will be billed for 1,000 (1 × 1,000) users in this case.

How are the workforce users metered during a billing cycle?

You will be metered on an hourly basis and billed monthly for active workforce users. The bill amount is calculated based on the metered usage and your rate card.

If I upgrade from Oracle Access Governance for Oracle Cloud Infrastructure—Workforce User to Oracle Access Governance for Oracle Workloads—Workforce User, how does the metering work for the month when the conversion takes place?

Access Governance is metered hourly. Before the service instance is upgraded, you will be billed for Oracle Access Governance for Oracle Cloud Infrastructure—Workforce User on an hourly basis. After the license upgrade, you will be billed for Oracle Access Governance for Oracle Workloads—Workforce User. In effect, you would see billing for both line items throughout the month, but they will be charged for the number of hours each license type was active.

How does the billing amount change based on the number of active users during a billing cycle?

The workforce users are metered on an hourly basis and only active users are billed for. So, if the number of active users changes during the billing cycle, your bill is prorated accordingly.

How can I estimate the cost of the service usage?

Please refer to the cost estimator to estimate the cost of service usage by following these steps: