OCI IAM
- AuthN – Who is allowed to login
- AuthZ – what all resources can be accessed by logged user
- Identity Domain: is a container for managing user, group, roles, federation etc.
- User creation and configuration in OCI
- 5 domains
- Free
- Oracle apps – for oci apps
- Oracle apps premium
- Premium domain
- external user – for non employee use cases e.g contractor
- 5 domains
- User creation and configuration in OCI
- Identity Federation
- IdP- Identity provider
- Service provider – connects to Idp For AuthN
- SAML 2.0 – xml based metadata used to exchange the identitfy information among inter platforms.
OCI IAM policies

- Subject – group to whom access is granted
- verb – what type is access is granted – read,write etc.