Implications of Allowing Terminated Employees Login Access for Payslips/W2s in Oracle Fusion HCM
Summary:
Hi everyone,
We are evaluating the operational and security implications of allowing terminated employees to log into Oracle Fusion HCM to retrieve their payslips and W2s.
- Security & Authentication: Once corporate SSO is cut off, do you switch them to a local IDCS/OCI IAM login using personal emails, or maintain a restricted SSO path? What are the security risks or support burdens of managing local logins for external alumni?
- Access Duration: Do you keep access open indefinitely, or enforce time-based access? Can Oracle natively send a temporary login link/token, or do you automatically expire their accounts after a set window (e.g., 30/90 days)?
Tagged:
0