Create an Access Bundle
An Access Bundle is a collection of permissions that package access to resources, application features, and functionality into a requestable unit. A specific access bundle will be associated with a single target.
Overview
With Access Bundles, you need not grant access to each permission individually but can request the access bundle for that resource. This simplifies the process of provisioning accounts with resource permissions.
Manage Accesses using Oracle Access Governance Access Bundles
You can manage groups for Microsoft Entra ID (formerly Azure Active Directory) and Microsoft Active Directory.
- Group Assignment: Bundle OCI IAM groups in an access bundle, which can then be assigned to identities through a policy or an access request.
- Application Role Assignment: Bundle OCI cloud services application roles in an access bundle, which can then be assigned to identities through a policy or an access request.
Navigate to Access Bundle
To navigate to the Access Bundle page:
Bundle Settings
In the Bundle settings task, you can enter general settings about your access bundle. You are also able to add user friendly tags that can be used in a search for this access bundle when creating policies.
Select Permissions
In the Select Permissions task, you can select permissions to include in this access bundle. Based on the orchestrated system, you may see additional attributes required for account provisioning. Refer to the specific orchestrated system articles to know more about the default attributes. For OCI, you can select OCI IAM groups or application roles.
- Select one or more permissions associated with the target application. Alternatively, you can use the Search field to locate the required permission or role.
- Once permissions are selected, click Next to go to the Add Details task.
Add Primary and Additional Owners
You can associate resource ownership by adding primary and additional owners. This drives self-service as these owners can then manage (read, update or delete) the resources that they own. By default, the resource creator is designated as the resource owner. You can assign one primary owner and up to 20 additional owners for the resources.
Time Limit Access
Set an expiration period to limit access by days or hours. You can also allow users to request an extension before access is revoked upon expiry. Time-bound access ensures identities have access only for the required period, enhancing security.
Add Details
In this Add Details task, you can give a name to your access bundle, add a supporting description, and attach an account profile.
- Enter name for your access bundle in the Name field.
- Add a description for your access bundle in the Description field.Note
The other fields on the screen depends on the target type and permissions selected in the previous tasks. - Select one of the following actions for the Do you want to use an account profile? field. For more information see, Setting Up Account Profiles in Oracle Access Governance.
- Yes: Select an account profile from the Which account profile? list.
- No: Enter values in the other fields that appear depending on the managed system.
- Click Next to go to the Review and submit task.
Review and Submit
The Review and Submit task displays the information you have added in the previous tasks.
- Cancel: To cancel the process.
- Back: To go back to the previous step.
- Save as draft: To save the access bundle as a draft copy. This will display the access bundle on the Access Bundle screen with the status 'Draft'.
navigation menu icon, and select
action menu for the orchestrated system you want to configure. This displays the manage integration page for the
selected orchestrated system.