nerdexam
Oracle

1Z0-1072 · Question #128

A company currently uses Microsoft Active Directory as its identity provider. The company recently subscribed to Oracle Cloud Infrastructure (OCI) to leverage the cloud platform for test and…

The correct answer is A. Create a group for developers on OCI and map the group to a similar group in Microsoft Active. When working with your IdP, your administrator defines groups and assigns each user to one or more groups according to the type of access the user needs. Oracle Cloud Infrastructure also uses the concept of groups (in conjunction with IAM policies) to define the type of access…

Identity and Access Management (IAM)

Question

A company currently uses Microsoft Active Directory as its identity provider. The company recently subscribed to Oracle Cloud Infrastructure (OCI) to leverage the cloud platform for test and development. As the administrator, you configured the OCI tenancy to be federated with Microsoft Active Directory. Now you need to give access to developers so that they can start creating resources in their OCI accounts. Which step will you perform to make sure you are not duplicating user creation inside of OCI tenancy?

Options

  • ACreate a group for developers on OCI and map the group to a similar group in Microsoft Active
  • BCreate a new user account in OCI for each user, and then create policies to provide access to
  • CCreate a group for developers on OCI, export all the developers from Microsoft Active Directory,
  • DCreate a single user account in OCI, and then create policies to provide access to developers to

How the community answered

(25 responses)
  • A
    80% (20)
  • B
    4% (1)
  • C
    4% (1)
  • D
    12% (3)

Explanation

When working with your IdP, your administrator defines groups and assigns each user to one or more groups according to the type of access the user needs. Oracle Cloud Infrastructure also uses the concept of groups (in conjunction with IAM policies) to define the type of access a user has. As part of setting up the relationship with the IdP, your administrator can map each IdP group to a similarly defined IAM group, so that your company can re-use the IdP group definitions when authorizing user access to Oracle Cloud Infrastructure resources.

Topics

#identity federation#Active Directory#IAM group mapping#federated access

Community Discussion

No community discussion yet for this question.

Full 1Z0-1072 Practice