Professional Documents
Culture Documents
R12 Surprises in User Management: Susan Behn
R12 Surprises in User Management: Susan Behn
Management
Revised July, 2014
Susan Behn
Agenda
Understanding User Management Principles
Surprises
Gold
Partner
Gold
Partner
4
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Components by Responsibility
System Administrator Responsibility
Manage responsibilities and menus; Create users
User Management Layers 3 and up
Gold
Partner
6
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
FND_FORM_FUNCTIONS_TL
7
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
FND_MENU_ENTRIES, FND_MENU_ENTRIES_TL
8
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Grantee
Who gets the grant
A role or group
A specific user
All Users
Gold
Partner
appropriate users
Step 2 Identify or create permissions/permission sets
that group functions (function security)
Step 3 Identify or create product seeded objects /
object instance sets (data security)
Step 4 Identify seeded grants / create grants
Step 5 Assign role
11
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
12
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Management
Assign a user management role to the appropriate user
Search
for user
13
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Click
pencil to
edit
Gold
Partner
14
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
customer
Partner Administrator manage users with party type =
partner
Other seeded security roles
include Customer
Administrator and Partner
Administrator
15
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
User Management
responsibility is inherited
by assigning this role
16
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
17
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
STEP 2
IDENTIFY SEEDED
PERMISSIONS
CREATE PERMISSIONS
Permissions
To demonstrate function security, Approvals
19
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Permissions
There are 16
permissions
available for
AME
Click the
update
button to
examine the
AME Action
Create
Permission
20
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Permissions
This permission belongs to one permission set with the
21
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Permission Set
In our example, we want the user to have access to
sets
Other
Permission
sets
included in
set
22
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
STEP 3
SEEDED OBJECTS
Seeded Objects
To demonstrate data security, Approvals Management
24
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Seeded Objects
Tip: Query by
responsibility to get
familiar with what is
seeded
Click update to
view details but
avoid changing
seeded objects
25
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Seeded Objects
Two columns are included which can be used to limit
access
26
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Seeded Objects
Click on the Object Instance Set tab for this object to
27
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
STEP 4
IDENTIFY SEEDED GRANTS
CREATE GRANTS
Grants
Create the grant to allow sbehn to perform all AME
Notice this takes you to the same form as you see in the
29
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Grants
Enter name,
description,
grantee
type,
grantee
Enter the
object name
Click Next
30
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Grants
Choose the context to limit rows
For this example, choose instance set
31
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Grants
We already determined there was an AME Transaction
32
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Grants
Now enter the values for
for reference
Parameter 1 is the
application
Parameter 2 is the AME
transaction type
33
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Grants
Scroll down and choose the functions the grantee will
34
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Grants
The final page is a review page
Click finish and the confirmation page will appear
Now you have access to data and functions you can
35
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
management
In step 2, we identified the AME All Permission Sets
to provide function security
In step 3 we identified the AME Transaction Types
object to provide data security
In step 4 we joined the function and data security
together in a grant to allow SBEHN to perform all
functions for AME for Payables Invoice Approvals
Butthe user still doesnt have access yet to the
responsibility used to manage AME
36
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
STEP 5
ASSIGN RESPONSIBILITIES
TO ROLES
Assign Roles
Assign AME roles to SBEHN the same way we
38
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Assign Roles
Click the Assign Roles button
39
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Seeded Roles
Choose the Approvals Management Administrator role
Responsibility
40
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Seeded Roles
Below is a partial list of products with seeded roles; This
changes frequently
Approvals Management
Diagnostics
Learning Management
Territory Management
User Management
Integration Repository
iReceivables
iSetup
Integrated SOA Gateway (New)
Gold
Partner
R12 Surprises
42
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Read-Only Diagnostics
43
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
44
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
45
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Integration Repository
46
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Early R12
Assign Responsibility Integrated SOA Gateway
Release 12.1+
Assign one of following roles
47
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
48
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Click Worklist
Access link
To limit security
risk request
this
functionality
from system
administrators
From
Functional
Administrator
Responsibility
Grants Tab
Create Grant
49
49
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
specific user
Data Security
object is
Notifications
50
50
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Seeded instance
Set
User that
Grantee can see
Abstract
Functions
51
51
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Results
52
52
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
notifications are
limited to active
workflows or those
in Lookup type
WF_RR_ITEM_TY
PES
To limit this access
to specific
workflow types,
enter in
parameter2
(hidden
parameter)
Note: Predicate
does not list
Parameter2
Parameter2
stores specific
workflows
53
53
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Cash Management
Security Wizard
54
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
55
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
responsibility
56
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Security Wizard
57
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
58
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
59
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
View Concurrent
Requests
60
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
obsolete in 12.1
Allowed users to see all concurrent requests in a
responsibility
Except for View Own and System Administrator View
61
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
62
62
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
63
63
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
64
64
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
parameter 2
65
65
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
66
66
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
responsibility
Exact replacement of obsolete profile option
MOS ID 804296.1 R12: How To Configure Access To
67
67
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
68
68
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Gold
Partner
AccesstotoAll
Allto
Access
Requests
to
Specific
User
Specific User
70
70
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
71
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
72
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Security Hole
74
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
75
75
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Flexfield Security
Required in 12.2
76
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
FinancialsF
lexfieldsVal
idationValu
es
77
77
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
queried
Affects Independent and Dependent value sets.
Affects what privileges users have in the Segment
Values form.
Note: Even if you create a new value set, you still wont
be able to assign values to that set until security is set
up
78
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
79
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
80
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
81
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
82
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
83
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Results
Now I have access to all the value sets for the
accounting flexfield
84
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
85
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Where is UMX
Applicable?
86
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Oracle defined
87
87
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
by
88
88
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
89
89
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
90
90
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Security Reports
91
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Security Reports
From User Management, Security Reports
Choose Report Type - Remaining screen repaints based
on Type
MUST specify
Role/Resp
Example
Select Output
format
Choose Offline to
get underlying SQL
92
92
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Security Reports
Report Status
93
93
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Security Reports
For Log (and
query), click
Details, then
View Log
Partial log
shown
94
94
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Security Reports
List of Users w/access to key User Management
function
95
95
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Security Reports
List of users
with access
to view all
concurrent
requests
List of users
with access
to the user
management
role
96
96
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Real error:
The rule function for the subscription to this event,
AMW_VIOLATION_PVT.Do_On_Role_Assigned, is a
non-existent package
Cause:
AMW-Internal Controls Manager has been replaced by
GRC-Governance Risk and Compliance in 12.2
MOS note 1303189.1
97
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
References
Oracle Applications System Administrator's Guide
Security
See Oracle User Management Developer Guide
My Oracle Support ID: 553547.1 Data Security
Terminology
My Oracle Support ID: 553290.1 Introduction to the
Grants Security System and Data Security
E-Business Suite User Management SIG
http://ebsumx.oaug.org/
98
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Other Presentations
Create a role to administer a specific organization
Collaborate 2009: From Responsibilities to Roles: Moving
Toward the Role Based Access Control (RBAC) Model
Marquette University
99
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Collaborate 2014
UMX Sig Presentation
15330 - E-Business Suite User Management SIG at
Collaborate 14 on April 7th at 3:20 PM PST in Level 3,
San Polo 3401
Sara Woodhull - How to secure flexfields and value
100
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
About Infosemantics
Established in 2001
Customer Focused
People First
Global
Shared Expertise
For more information, go to
101
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner
Questions?
Comments
Thank You!!!
Susan Behn
Susan.Behn@Infosemantics.com
102
Copyright 2014 Infosemantics, Inc. All Rights Reserved . Any other commercial product names herein are trademark, registered trademarks or service marks of their respective owners.
Gold
Partner