Recommendations for Oracle Authorization Policy Manager

Recommendations for Fusion Middleware Components 2-27 The connectors in Oracle Identity Manager are file-based. They are used to provision or reconcile records from different enterprise applications. Ensure that the connectors are available for Oracle Identity Manager and the applications. Oracle Identity Management is also dependent on the JMS persistence store. For more information, see Recommendations for Oracle WebLogic Server JMS and T-Logs . Synchronization Recommendations The application tier must be manually synchronized with the standby site after making configuration changes and applying patches. Oracle Data Guard should be configured for Oracle database metadata repositories and the data stores. It is recommended that the standby database be synchronized when the application tier synchronization is initiated on the storage. This synchronization occurs automatically because Oracle Data Guard is configured in Managed Recovery mode the recommended configuration for the database. If the standby database is not in Managed Recovery mode, then you should manually synchronize the standby database. For JMS persistence store, see Recommendations for Oracle WebLogic Server JMS and T-Logs . Recovery Recommendations Recover the managed server running the Oracle Identity Manager application, and the associated Oracle Internet Directory instances. The OIM, SOAINFRA, ORASPDM, and MDS schemas must be recovered to the most recent point in time. Oracle Identity Management is dependent on the ODS schema when LDAP sync is enabled, in such cases make sure to recover the ODS to the most recent point in time as well

2.5.9 Recommendations for Oracle Authorization Policy Manager

Oracle Authorization Policy Manager APM is a GUI tool to manage authorization policy for Oracle Platform Security Services based applications. APM is a tool for security administrators and greatly simplifies creation, modification, configuration and administration of application authorization policy by offering the following: ■ User-friendly names and descriptions of security artifacts ■ A way to organize application roles by business, product, or any other parameter specific to an application ■ A uniform graphic interface to search, create, browse, and edit security artifacts ■ A way to specify a subset of applications that a role can manage Artifacts in the Database Oracle Authorization Policy Manager uses the APM and MDS schemas, which are part of the Oracle Identity Management database. Special Considerations Load balancer virtual hosts for Oracle Authorization Policy Manager should be configured on both the production and standby sites. Oracle Authorization Policy Manager is deployed to the Administration Server running in the domain. 2-28 Oracle Fusion Middleware Disaster Recovery Guide Synchronization Recommendations The application tier must be manually synchronized with the standby site after making configuration changes and applying patches. Oracle Data Guard should be configured for Oracle database metadata repositories and the data stores. It is recommended that the standby database be synchronized when the application tier synchronization is initiated on the storage. This synchronization occurs automatically because Oracle Data Guard is configured in Managed Recovery mode the recommended configuration for the database. If the standby database is not in Managed Recovery mode, then you should manually synchronize the standby database. Oracle Identity Navigator is deployed to the Administration Server running in the domain Recovery Recommendations Recover the Administration Server running the Oracle Authorization Policy Manager application. The APM and MDS schemas must be recovered to the most recent point in time.

2.5.10 Recommendations for Oracle Identity Navigator