Attestation Scheduled Task About Attestation

19-14 Oracle Fusion Middleware Users Guide for Oracle Identity Manager

19.2.2 System Control

Attestation has the following dependencies: ■ The User Profile Audit feature must be enabled. ■ Historical data must be collected at least up to the Process Form level. If the auditing level is set below the required levels, then clicking menu item links related to attestation generates the Attestation Feature Not Available page, and prevents the user from defining any attestation processes. Audit levels are controlled by the system property called XL.UserProfileAuditDataCollection and the attestation feature expects this value to be set to at least Resource Form.

19.3 Creating Attestation Processes

To create an attestation process:

1. In the Welcome page of Oracle Identity Manager Advanced Administration, under

Attestation Configuration list, select Create. The Step1: Define Process page is displayed.

2. Enter values for the fields described in the following table, and then click

Continue :

3. On the Step 2: Define User Scope page:

a. Select an attribute from the Attribute list. The Attribute list displays the user

attributes given in the FormMetaData.xml file and the user-defined attributes from the user form. The attribute that you select is used to specify the criteria that must be met by users on whom the attestation process is applied.

b. From the Condition list, select a condition. The Condition list of values will

change based on the type of attribute selected. For example, if you select User ID in the Attribute field, then the conditions displayed are Contains, Does Not Note: Oracle Identity Manager Permission model applies to the procedure described in this section. This model restricts any list of targets for example, users to only those targets for which the logged-in user has read access. Field Description Name A unique name for the attestation process. The name must be unique across system administrator and deleted attestation processes. Code An identifying code up to 32 characters for the process. The code must be unique across system administrator and deleted attestation processes. Note: A code enhances the identification of the attestation process definition. However, if you do not specify a value in the Code field, then the attestation process is identified by the unique name. Description Detailed description of the attestation process.