If you configure single sign-on (SSO) with your Fusion Application and need a user to access FDI who isn't available in the source Fusion Application, what is the recommended approach?

Prepare for the Oracle FDI 1Z0-1128-24 Test. Enhance your skills with an extensive range of questions and in-depth explanations. Achieve your certification with confidence and join a community of professionals!

Multiple Choice

If you configure single sign-on (SSO) with your Fusion Application and need a user to access FDI who isn't available in the source Fusion Application, what is the recommended approach?

Explanation:
When using SSO, authentication is handled by the identity provider, but access rights are controlled within each product’s own identity domain. FDI uses its own identity domain for authorization, so a user must exist there to receive FDI privileges. If a needed user isn’t present in the source Fusion Application, provisioning a dedicated user in the identity domain that serves the FDI instance ensures the user can be authenticated via SSO and granted the correct FDI access. Creating a Fusion user and hoping it carries FDI rights won’t place that user in the FDI domain and could leave them without the necessary permissions. Disabling SSO is not appropriate; the correct approach is to create a user with the required FDI access in the FDI identity domain to align provisioning, authentication, and authorization properly.

When using SSO, authentication is handled by the identity provider, but access rights are controlled within each product’s own identity domain. FDI uses its own identity domain for authorization, so a user must exist there to receive FDI privileges. If a needed user isn’t present in the source Fusion Application, provisioning a dedicated user in the identity domain that serves the FDI instance ensures the user can be authenticated via SSO and granted the correct FDI access. Creating a Fusion user and hoping it carries FDI rights won’t place that user in the FDI domain and could leave them without the necessary permissions. Disabling SSO is not appropriate; the correct approach is to create a user with the required FDI access in the FDI identity domain to align provisioning, authentication, and authorization properly.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy