To ensure that questions get required attention from community members and are NOT left unanswered, it’s important for the author to indicate (by selecting “Yes” or “No” when prompted) whether the question was answered. (newly added) Please note that it is also important to respond to EACH comment your question receives. Your Yes or No response ensures an accurate status for your question.
For more information, please refer to this announcement explaining best practices for getting answers to questions.
For more information, please refer to this announcement explaining best practices for getting answers to questions.
Applications Security
Discussion List
-
AI Security Messaging for Oracle SaaS Cloud Security CustomersPosition on AI-Accelerated Security Oracle views AI-accelerated vulnerability discovery and exploitation as a current security reality. As AI shortens the time between d…
-
Securing Oracle Fusion Cloud Supplier Portal with IAM Domains and MFAOne of the most common security challenges in Oracle Fusion Cloud is enabling Supplier Portal access for external users without disrupting existing workforce authenticat…
-
Oracle Fusion Cloud Audit StreamingExcited to share a new two-part series on streaming Oracle Fusion Cloud audit events to SIEM platforms such as Splunk. The series outlines an event-driven pattern using …
-
Introducing the CIS Oracle SaaS BenchmarkWe’re excited to announce the upcoming launch of the first-ever Center for Internet Security (CIS) Benchmark for Oracle SaaS - focused on Oracle Fusion and Oracle Enterp…
-
Oracle Go – See Beyond the Logs: AI-Driven IAM Audit Analysis for Oracle SaaS with OCI Log AnalyticsI’m excited to invite you to our upcoming webinar with my colleague Ranveer Tiwari and myself “See Beyond the Logs – AI-Driven IAM Audit & Analysis for Oracle SaaS with …
-
By pass SSO url for Supplier Portal no longer supported by Oracle???Content Hello, in the past, we were able to create an SR with Oracle to have them enable the by pass SSO signon page for Supplier (vendor) Portal. Once enabled, the url … -
Guidance about reviewing July 2026 Critical Patch UpdateWe are reviewing the July 2026 Critical Patch Update and the following CVEs: CVE-2026-60880 (Oracle E-Business Suite – Work in Process) CVE-2026-60198 (Oracle WebLogic S… -
Need to display consolidated Salary Budget and Salary Spend on the Compensation WorksheetSummary: We need to configure a unified Salary Budget vs. Salary Spend view in the Oracle Fusion Compensation Allocation Worksheet. We want an analytical banner, dashboa… -
SailPoint IIQ with Fusion ERP RefreshesSummary: How are customers using SailPoint IIQ with Fusion ERP for identity management & provisioning managing refreshes to lower environments? Content (please ensure yo… -
Cookie List for Oracle HCMSummary: Does a comprehensive list of cookies used by Oracle HCM Cloud exist, including their purpose and retention period? If so, where can we find it? Content: We are … -
Oracle Fusion MFA Enforcement - Toggling MFA On and Off before Enforcement Date in non ProductionHi all, Our enforcement date for Oracle Fusion MFA is coming up soon, and we would like to test this out in one of our non-production environments. If we enable MFA proa… -
How to migrate AI Agent Studio custom roles and enabled Permission Groups via FSMSummary: Hi everyone, We are currently working with AI Agent Studio and have created two custom roles: AI Agent Admin AI Agent Explorer For these custom roles, we have e… -
Need a password expiry Notification for Specific Users who use Inline Passwords to Sign-inWe would like to enable Password Expiry Notifications in oracle so users are notified in advance of password expiry to update there passwords. Please advise if we enable… -
Create role for Manage CarriersSummary: Hi all, I have a requirement to create a new role that provides access to Manage Carriers. I created a custom role and assigned the Carrier Management role to i… -
26B- Security Console-Configure MFA ExclusionSummary: 26B- Security Console-Configure MFA Exclusion Content (please ensure you mask any confidential information): After 26B is applied we are seeing an option "Confi… -
ADFdi Excel templates could represent any risk vector or vulnerabilityOur Environment: Oracle ERP Cloud (Fusion Applications – SaaS) Usage of ADF Desktop Integration (ADFdi) Excel templates for data import/export We would like to confirm w… -
Oracle SSO keeps on logging out after 30 minutes & logs user out of all other SSO's sessionsSummary: Oracle SSO logs users out after approximately 30 minutes of inactivity, and the logout also terminates all other active SSO sessions in the browser (e.g. Micros… -
What to do with fusion_console_upgrade_admin_role and planning_Console_Upgrade_Service_Admin_GroupHello Oracle Community! Our domain has the below Oracle generated roles: planning_Console_Upgrade_Service_Admin_Group fusion_console_upgrade_admin_role I understand that… -
How to Identify Historical User Role Assignment Changes When the Role Has Already Been Removed?We are currently investigating a security access issue where we believe a user may have been assigned an incorrect role in the past. The challenge is that the role has a… -
Is Employee role cost license? Is there a document that list all the roles that may consume license?Summary: We are finalizing our security matrix and making sure we will not exceed the number of license available for different roles. One thing we want to know if Emplo… -
In a threat actor situation, is there an alternative path for limited access to fusion applications?Summary: In a scenario where an employee turns into a threat actor and hacks the network blocking normal access to Oracle Fusion HCM Payroll, can Oracle provide an alter… -
what are the privileges required to access My Client GroupsSummary: Content (please ensure you mask any confidential information): Version (include the version you are using, if applicable): Code Snippet (add any code snippets t… -
HCM Reasons for Send Prorated LDAP Changes to ErrorSummary: After 26B, I made some security updates in a non-production pod, and when I run the Send Pending LDAP Requests process, I'm getting errors in most of the subpro… -
Concurrent SSO and Direct login ability for a userSummary: Oracle documentation isnt really clear. SSO enabled as well as chooser page. Can a user have login via SSO and also optionally with the direct login via chooser… -
Oracle Fusion MFA Enforcement — PROD options for automation/service accountsHello Everyone, We are reviewing the upcoming Oracle-enforced MFA change for Fusion Applications after OCI IAM migration. Oracle documentation appears to state that MFA … -
Critical Security Vulnerabilities (CVSS > 9.5) – Impact on ERP Cloud, OCI, OIC and ADFdi (July 2026Summary: Dear Community, we received a security alert for following relevant CVEs. CVE-2026-60880 (Oracle E-Business Suite – Work in Process) CVE-2026-60198 (Oracle WebL… -
SAML Metadata file details change after refresh?Summary: We are in the process of configuring Okta-based SSO for our Fusion ERP environments. After completing our first refresh (T2T | Dev > Test), it looks as though o… -
Region/Country-Based Geo-Fencing Support for Oracle EPM CloudSummary: Region/Country-Based Geo-Fencing Support for Oracle EPM Cloud Content (please ensure you mask any confidential information): We have a query regarding access re… -
Critical Security Vulnerabilities (CVSS > 9.5) – (July 2026 CPU)Problem Description: We have received an official security alert from Costa Rica CSIRT (MICITT) regarding multiple critical vulnerabilities affecting Oracle products, pu… -
Custom Role to view Schedule process is not coming under ToolsSummary: In Fusion HCM, my requirement is to view the scheduled process only, no other action can be performed. So I created a Custom abstract role , as Role Category: C… -
How to hide Forgot Password link in the login pageSummary Hide Forgot Password link in the login pageContent Hi, In the development/test instances, we are planning to restrict users to use the Forgot password functional… -
Representatives can see employees in all organizations the employee is assigned toOur person security profiles are secured by Area of Responsibility. The Scope of Responsibility is "Organization hierarchy for department" and we have an organization hi… -
Convert to Federated UsersSummary: we have users setup to allow both user name-password and single sign-on in the Sign-on Policies under Domain Policies. We want to convert these users to federat… -
Not able to remove privilege from a custom job role created as part of migration in security consoleSummary: We have a custom job role for procurement which is created in production as part of migration and not in security console. Recently we have been trying to remov… -
HCM Ideas that are essential for security and compliance – Ideas that desperately NEED your votesContent There are a few Ideas (Enhancement Requests) that we and others have logged that are critical for SOX compliance, Data Privacy, Security, and for the implementat…