To ensure that questions get required attention from community members and are NOT left unanswered, it’s important for the author to indicate (by selecting “Yes” or “No” when prompted) whether the question was answered. (newly added) Please note that it is also important to respond to EACH comment your question receives. Your Yes or No response ensures an accurate status for your question.
For more information, please refer to this announcement explaining best practices for getting answers to questions.
For more information, please refer to this announcement explaining best practices for getting answers to questions.
Applications Security
Discussion List
-
Need help finding Custom Supplier Role Code and extracting 8,000 assigned usersSummary: Hello Experts, My manager requested that I remove a custom supplier role from 8,000+ users in our Development instance using HCM Data Loader (HDL via User.dat).… -
IAM upgrade - Relay stateSummary: IAM upgrade — where does relay state get configured post-upgrade? We have our Fusion IAM upgrade scheduled shortly and are planning SSO reconfiguration for non-… -
Locking Down Set-Up and MaintenanceSummary: As a part of establishing User Security, Data Security and Plant Profiles our UAA team needs access limited in Setup & Maintenance. We've tried to create a cust… -
How to Identify Historical User Role Assignment Changes When the Role Has Already Been Removed?We are currently investigating a security access issue where we believe a user may have been assigned an incorrect role in the past. The challenge is that the role has a… -
SQL report for SSO and Non SSO loginSummary SQL report for SSO and Non SSO loginContent Team, Is there a way we can pull the list of users by writing SQL BI report to find who use password or non sso login… -
By pass SSO url for Supplier Portal no longer supported by Oracle???Content Hello, in the past, we were able to create an SR with Oracle to have them enable the by pass SSO signon page for Supplier (vendor) Portal. Once enabled, the url … -
SailPoint IIQ with Fusion ERP RefreshesSummary: How are customers using SailPoint IIQ with Fusion ERP for identity management & provisioning managing refreshes to lower environments? Content (please ensure yo… -
Cookie List for Oracle HCMSummary: Does a comprehensive list of cookies used by Oracle HCM Cloud exist, including their purpose and retention period? If so, where can we find it? Content: We are … -
How to migrate AI Agent Studio custom roles and enabled Permission Groups via FSMSummary: Hi everyone, We are currently working with AI Agent Studio and have created two custom roles: AI Agent Admin AI Agent Explorer For these custom roles, we have e… -
Need a password expiry Notification for Specific Users who use Inline Passwords to Sign-inWe would like to enable Password Expiry Notifications in oracle so users are notified in advance of password expiry to update there passwords. Please advise if we enable… -
Create role for Manage CarriersSummary: Hi all, I have a requirement to create a new role that provides access to Manage Carriers. I created a custom role and assigned the Carrier Management role to i… -
ADFdi Excel templates could represent any risk vector or vulnerabilityOur Environment: Oracle ERP Cloud (Fusion Applications – SaaS) Usage of ADF Desktop Integration (ADFdi) Excel templates for data import/export We would like to confirm w… -
Oracle SSO keeps on logging out after 30 minutes & logs user out of all other SSO's sessionsSummary: Oracle SSO logs users out after approximately 30 minutes of inactivity, and the logout also terminates all other active SSO sessions in the browser (e.g. Micros… -
What to do with fusion_console_upgrade_admin_role and planning_Console_Upgrade_Service_Admin_GroupHello Oracle Community! Our domain has the below Oracle generated roles: planning_Console_Upgrade_Service_Admin_Group fusion_console_upgrade_admin_role I understand that… -
Is Employee role cost license? Is there a document that list all the roles that may consume license?Summary: We are finalizing our security matrix and making sure we will not exceed the number of license available for different roles. One thing we want to know if Emplo… -
In a threat actor situation, is there an alternative path for limited access to fusion applications?Summary: In a scenario where an employee turns into a threat actor and hacks the network blocking normal access to Oracle Fusion HCM Payroll, can Oracle provide an alter… -
what are the privileges required to access My Client GroupsSummary: Content (please ensure you mask any confidential information): Version (include the version you are using, if applicable): Code Snippet (add any code snippets t… -
HCM Reasons for Send Prorated LDAP Changes to ErrorSummary: After 26B, I made some security updates in a non-production pod, and when I run the Send Pending LDAP Requests process, I'm getting errors in most of the subpro… -
Concurrent SSO and Direct login ability for a userSummary: Oracle documentation isnt really clear. SSO enabled as well as chooser page. Can a user have login via SSO and also optionally with the direct login via chooser… -
Oracle Fusion MFA Enforcement — PROD options for automation/service accountsHello Everyone, We are reviewing the upcoming Oracle-enforced MFA change for Fusion Applications after OCI IAM migration. Oracle documentation appears to state that MFA … -
Critical Security Vulnerabilities (CVSS > 9.5) – Impact on ERP Cloud, OCI, OIC and ADFdi (July 2026Summary: Dear Community, we received a security alert for following relevant CVEs. CVE-2026-60880 (Oracle E-Business Suite – Work in Process) CVE-2026-60198 (Oracle WebL… -
SAML Metadata file details change after refresh?Summary: We are in the process of configuring Okta-based SSO for our Fusion ERP environments. After completing our first refresh (T2T | Dev > Test), it looks as though o… -
Region/Country-Based Geo-Fencing Support for Oracle EPM CloudSummary: Region/Country-Based Geo-Fencing Support for Oracle EPM Cloud Content (please ensure you mask any confidential information): We have a query regarding access re… -
How to hide Forgot Password link in the login pageSummary Hide Forgot Password link in the login pageContent Hi, In the development/test instances, we are planning to restrict users to use the Forgot password functional… -
Representatives can see employees in all organizations the employee is assigned toOur person security profiles are secured by Area of Responsibility. The Scope of Responsibility is "Organization hierarchy for department" and we have an organization hi… -
Convert to Federated UsersSummary: we have users setup to allow both user name-password and single sign-on in the Sign-on Policies under Domain Policies. We want to convert these users to federat… -
Not able to remove privilege from a custom job role created as part of migration in security consoleSummary: We have a custom job role for procurement which is created in production as part of migration and not in security console. Recently we have been trying to remov… -
HCM Ideas that are essential for security and compliance – Ideas that desperately NEED your votesContent There are a few Ideas (Enhancement Requests) that we and others have logged that are critical for SOX compliance, Data Privacy, Security, and for the implementat… -
Request for Oracle Fusion Audit Report DetailsHi Oracle Team, We need your assistance in confirming whether Oracle Fusion provides audit reporting/logging capabilities for tracing below user account activities. Plea… -
Restrict Chart of Account Segment Access from One Entity, While Allowing access on different entityIs there a way to restrict access at the COA segment combination? For example, can you restrict access for users on reporting/transactional access from Account 1000 with…