What are best practices for provisioning applications, configuring SSO and administering permissions
We are a new Oracle customer working with an implementation partner to configure ERP, CRM, WACS EPM and OIC. Based on research, it appears that users and single sign on can be configured at the Default \ root cloud level but it can also be configured at the individual application level. I'm trying to find out which method represents best practices. It makes the most sense to me to set the user up once, authenticate the user once using sso and grant the singular user access to their applications. Which method would be best practice?
The second question is related to provisioning. We have a Default domain where we find most of our applications. However, our individual ERP domains (Dev, Test and Prod) are separate. This will make the users, SSO and other configurations separate for each domain. Could these domains have been provisioned as part of the Default domain so we can manage a single user per employee in Oracle?