In a nutshell, you'll create it in a LDAP - external, or the embedded one. When done, you may have to assign roles to your user (see e.g. Managing Business Role Pages - 11g Release 1 (18.104.22.168.0))
We've installed OAM/OID but how do we create users/groups since we no longer using the internal LDAP directory with WebLogic? We are currently using Portal 11g with SSO/OID and the DAS is a user friendly way to provision user and we do not have to have a technical person do administer new users. What is the replacement then to DAS? We do not see it in OAM and since we are now using the external LDAP (OID) we can't even provision users in WebLotic? So other than the command line what is the GUI so we can still have our non-tech person create users for WebCenter?
a) internal LDAP in Weblogic should not be used for any, but development or demo purposes
b) DAS is best available under Directory Service Plus SKU
c) you can use any other 3rd party LDAP as well
d) one Weblogic domain can have several LDAPs against which it authenticates users. It only requires the proper configuration of the Security Realm
e) if you want a non-tech person manage user accounts (other than self-service), get in touch with experts in the Identity Management forums - see Identity Management