Identity Upgrade Overview

Learn how to prepare for and what to expect before and after the upgrade to Oracle Cloud Infrastructure Identity and Access Management (IAM).

If you received an email with the subject line: Upcoming Exception Migration to Identity and Access Management (IAM), your account has been selected for the upgrade to Oracle Cloud Infrastructure Identity and Access Management (IAM).

If the Fusion Applications environment family and environments were provisioned after April 6, 2025, the Fusion Applications environments are already running with OCI IAM. Identity upgrade isn't required.

What Is Happening?

In an upcoming exception maintenance of Fusion Applications, the user identity service associated with the Fusion environments is upgraded to Oracle Cloud Infrastructure Identity and Access Management (IAM).

The new OCI IAM experience in Oracle Cloud Console provides enhanced capabilities for managing authentication, sign-on policy, single sign-on (SSO), multi-factor authentication (MFA), and identity lifecycle management.

The Identity upgrade process requires a downtime. The duration is specified in the notification when you receive the Identity upgrade schedule.

Upon completion of Identity upgrade, you're notified by means of email. If there are post-upgrade actions for an environment, you can acknowledge that the actions are completed in the Oracle Cloud Console under the Maintenance tab of the Fusion Applications environment family page.

Where can I learn more?

For more information regarding Identity and Access Management using IAM, see IAM with Identity Domains.

If you have concerns, contact Oracle Support by opening a Support Request (SR). Select these options to describe the issues:

  • Service Group: Oracle Cloud Applications
  • Service: Any Fusion Product
  • Service Category: SaaS Console services (Outage, Provision, P2T/T2T, Resize, Environment and User Management)
  • Sub-Category: Fusion Identity Upgrade

Identity Upgrade Cadence

The identity upgrade is scheduled in a non-quarterly update month for the environment family.

Non-production cadence: Identity upgrade of environments on non-production cadence is performed during the second week of the scheduled month at around the same time as the environment's maintenance slot.

Production cadence: Identity upgrade of environments on production cadence is performed during the fourth week of the scheduled month at around the same time as the environment's maintenance slot.

The Identity upgrade is scheduled to match as closely as possible to the same maintenance slot for the Fusion Applications quarterly update, however, the environments might be scheduled a few hours earlier or later.

Note that the "first week of the month" is the week with the first Friday of a month where the week starts from the prior Sunday. For example, the first week of March, 2025 is the week from Sunday, March 2, 2025 to March 8, 2025.

Required Actions

No action required: If the Fusion environment isn't configured with federated SSO or used as the Identity provider for other Oracle application environments, then there are no pre-upgrade or post-upgrade required actions. However, we recommend that you review this document to understand and prepare for this upgrade.

Action required before the Identity upgrade: If the Fusion Applications environments use federated SSO with an Identity provider, you're required to complete the following actions at least 72 hours before the scheduled downtime of the first environment to ensure continued access to your Fusion Applications. Steps for these tasks are detailed in Pre-upgrade tasks for federated SSO environments.

We recommend that you complete the required action as soon as possible, at least 10 days before the scheduled downtime of the first environment, to ensure that you have time for any troubleshooting. If you haven't completed the required action 72 hours before the scheduled upgrade, the Identity upgrade of the entire environment family is automatically canceled. You must then open a Support Request (SR) to reschedule the upgrade.

Action required after Identity upgrade: If you have other Oracle applications (such as Taleo, CPQ (Configure, Price, Quota), and SelectMinds) using a Fusion environment as the federated SSO Identity provider for users to sign in to the applications, you must complete the post-upgrade tasks and test the single sign-on integration to ensure that federated SSO continues to function correctly. Sign in to these other Oracle applications doesn't function until you have completed the post-upgrade actions.

Notification and Scheduling

You're notified by email when the Identity upgrade is scheduled as follows:

  • If you have environments with federated SSO, you're notified about 90 days in advance for the environment family.
  • If you don't have environments with federated SSO, you're notified about 30 days in advance.

After the environments have been scheduled for the upgrade, you can go to the Oracle Cloud Console to view the schedule for the Fusion environments, review the details of required actions (if applicable), and complete the required actions. To view the Identity upgrade schedule:

  1. Sign in to the Oracle Cloud Console and navigate to the Environment family page.
  2. On the Environment families page, select the name of the environment family. If you don't see the resources, ensure that you're in the correct compartment.
  3. On the Environment family details page, select Maintenance tab, and scroll to Identity upgrade section to view the schedule.

The Upgrade status displays one of these values:

  • "-" : The environment requires Identity upgrade, however, it hasn't been scheduled.
  • Scheduled: The environment upgrade has been scheduled.
  • In progress: The environment upgrade is in progress.
  • Succeeded: The environment upgrade has completed.
  • Canceled: The environment upgrade has been canceled. Identity upgrade is rescheduled. As soon as Identity upgrade has been rescheduled, the status is changed to Scheduled with a new scheduled date.
  • Failed: In rare event the environment upgrade has failed. Oracle will keep you updated and resolve the issue.
  • Not required: The environment is already on OCI IAM. It doesn't require Identity upgrade.

The Pre-upgrade actions displays one of these values:

  • "-" : The environment doesn't have Federated SSO. No action is required.
  • Pending: The environment is enabled with Federated SSO. The required actions haven't been completed and acknowledged by administrator.
  • Completed: The required actions have been completed and acknowledged by administrator.

The Post-upgrade actions displays one of these values:

  • "-" : The environment doesn't have other applications using this Fusion Applications environment as Identity provider. No action is required.
  • Pending: The required post-upgrade actions haven't been completed and acknowledged by the administrator.
  • Completed: The required post-upgrade actions have been completed and acknowledged by the administrator.

Identity upgrade schedule

Cancellation and Rescheduling

If there are pre-upgrade required actions for any of the Fusion Application environments, and the required actions aren't completed 72 hours before the scheduled downtime of the first environment, the Identity upgrade for all the Fusion environments in the environment family are automatically canceled.

The canceled Identity upgrade is reflected in the Oracle Cloud Console.

Reschedule Identity Upgrade

To reschedule the Identity upgrade, open a Support Request (SR) to schedule a downtime.

  • You're offered a selection of downtimes as this is a scheduled maintenance.
  • After the reschedule is recorded, it's shown in the Oracle Cloud Console.
  • You're notified as described in Notification and Scheduling.

If you don't open a support request, Oracle will schedule the upgrade to a future date.

What to Expect After the Upgrade

After the Identity upgrade completes successfully, test sign in to the Fusion environments is working as expected. If you encounter any issues, contact Oracle Support by submitting a Support Request (SR).

If you have other Oracle applications (such as Taleo, CPQ (Configure, Price, Quota), SelectMinds, and so on.) that use the Fusion environment to federate SSO, you must complete the Post-Upgrade Tasks and test the SSO integration to ensure that federated SSO continues to function correctly for other Oracle applications. Sign in to these Oracle applications doesn't function until you complete the post-identity upgrade actions.

Changes to Account Sign-In Page

The account sign-in page is different for your applications users. See Changes in Oracle Fusion Cloud Applications sign in page for more details.

Users who select the Sign-in button don't experience any changes. They continue to see the same SSO sign-in page.

Pre-Upgrade Tasks

Tasks that are required pre-upgrade depend on whether you have enabled federated SSO in the environments. How do I know if my environments are federated or not?

In addition to federated SSO, the environments might also have an Identity provider initiated federation flow (an authentication flow that doesn't go through the Fusion Applications sign-in page) that needs to authenticate against a different Identity system. The same pre-upgrade tasks needs to be completed as well.

Pre-upgrade tasks for non-federated SSO environments

If you don't have federated SSO, there are no pre-upgrade tasks for you to complete.

You can monitor the schedule and progress of the upgrade on the details page of the environment family.

Pre-upgrade tasks for federated SSO environments

You must complete the required actions before Identity upgrade if the Fusion Application environments has federated SSO that uses an Identity provider to authenticate the users. You're required to complete the following actions 72 hours before the scheduled downtime of the first environment. If the actions aren't completed, the Identity upgrade of the Fusion environments is canceled and must be rescheduled for another time.

The required actions are:

  1. Download SAML metadata from the Oracle Cloud Console. You must export the SAML metadata file for the environment's associated Identity domain from the Oracle Cloud Console to configure the service provider in the corporate Identity system.
  2. Configure the Service Provider (SP) in the corporate Identity system that federate SSO.
  3. Update and test the Identity providers in the Oracle Cloud Console.
  4. Acknowledge Identity Provider Readiness in the Oracle Cloud Console.

The following sections describes these steps in detail.

Download the SAML Metadata File

When the Fusion environment with federated SSO is scheduled for Identity upgrade, Oracle will automatically create the corresponding Identity provider based on the federated SSO configuration of the Fusion environments.

In this step, you must export (download) the SAML metadata file for the corresponding Fusion environment from the Oracle Cloud Console. The SAML file contains the necessary information to be entered into the corporate identity system. Each SAML metadata file is different and specific to each Fusion Applications environment. Ensure to label the SAML metadata files so they're not mixed up.

Step 1 - Follow these steps to download the SAML metadata file for a Fusion environment:

  1. Sign in to the Oracle Cloud Console and navigate to the Environment family page.
  2. On the Environment families page, select the name of the environment family. If you don't see the resources, ensure that you're in the correct compartment.
  3. On the Environment family details page, select Maintenance tab, and scroll to Identity upgrade section to view the schedule.
  4. Select the Federated SSO environment and select the Pre-upgrade actions button.
  5. In the Pre-upgrade actions panel, select the Download button. This downloads the SAML metadata file (Metadata.xml), representing the Identity domain for the federated SSO environment, to the location selected by the browser setting.
Pre-upgrade actions

Configure and Test the Service Providers

Step 2 - Configure a new service provider for each of the federated Fusion Applications environments in the corporate Identity system. This configuration decides how the Fusion Application environments will federate SSO after the Identity upgrade. Some Identity provider systems use the term Enterprise applications instead of Service provider.

Use a text editor to review the downloaded SAML metadata file to retrieve the data necessary to configure a new service provider.

If you have several Identity providers, you must configure a new service provider for each Identity provider with the information in the downloaded copy of the SAML metadata file. Use the same SAML file for each of the Identity providers for the corresponding Fusion environment.

After the service providers are configured, download the SAML metadata for each of the service providers from the corporate identity system.

Step 3 - Update and test the Identity providers.

To perform step 3 of the pre-upgrade actions, you need:

  1. The SAML metadata for the service provider that you configured in the Identity system.
  2. You must be an Identity domain administrator and tenancy administrator in Oracle Cloud Console to update Identity provider configuration in IAM.
  3. You need the credential to sign in to each of the Identity domain of the Fusion environments.
  4. You have signed in to Oracle Cloud Console as Cloud/Tenancy administrator, and as the Domain administrators for each of the Fusion Identity domains.
  5. You need a valid credential for each of the Service providers configured in the Identity system to test the sign-in page.

The main goal of step 3 is to update the Identity provider configuration in OCI IAM with the SAML metadata file that you downloaded from step 2. Then test the connectivity and authentication between OCI IAM and the corporate Identity system.

Follow these steps to update the Identity providers and test the sign-in process to confirm that integration of federated SSO from OCI IAM to the Identity provider is working:

  1. Sign in to the Oracle Cloud Console and navigate to the Environment family page.
  2. On the Environment families page, select the name of the environment family. If you don't see the resources, ensure that you're in the correct compartment.
  3. On the Environment family details page, select Maintenance tab, and scroll to Identity upgrade section to view the schedule.
  4. Select the Federated SSO environment and select the Pre-upgrade actions button.
  5. In the Pre-upgrade actions panel, select the Identity provider and then select the Update button.
  6. In the Import SAML panel, select the Drop a file or select one area and then select the SAML metadata of the service provider that you downloaded from step 2.
  7. Select Import button. Upon successful import the Success - Import IDP metadata successful message is displayed briefly.
  8. Select the Identity provider that you updated and then select the Test button.
  9. If you haven't signed in to the Identity domain of the Fusion Applications environment in the current browser session, the Oracle Cloud Console presents a sign-in page to ensure you're authorized to test the Identity provider.

    Enter username and password to sign in to the Identity domain. If you're not a member of "Domain_Administrators" or "IDCS_Administrators" group then you get an error message while trying to sign-in.

  10. After successful sign-in to the Identity domain, the Sign In page of the Identity provider appears. Enter the correct credentials to ensure you can be authenticated by the Identity provider. The browser displays "Your connection is successful" if the authentication is successful.
  11. Repeat steps 8 to 10 if you have more identity providers.
  12. Proceed to the next section (step 4) only when all the identity providers test sign-in are successful.

Acknowledge Identity Provider Readiness

Step 4 - Confirm Identity provider readiness.

Note

You must only acknowledge Confirm identity provider readiness step when all the Identity providers are tested.

Continue from the previous section after you verified all the Identity providers test sign-in are successful.

  1. Select the checkbox for I acknowledge and confirm that the task has been completed. Then select the Submit button.
  2. Select Confirm button in the Confirm pre-upgrade actions popup window.
  3. The pre-upgrade actions status for the Fusion Applications environment in the Identity upgrade section displays Completed.

To revert the confirmation:

  1. Clear the checkbox for I acknowledge and confirm that the task has been completed. Then select the Submit button.
  2. Select the Revert button in the Confirm pre-upgrade actions popup window.
  3. The pre-upgrade actions status for the Fusion Applications environment in the Identity upgrade section displays Pending.

The environment Pre-upgrade actions column is updated to Completed.

Pre-upgrade completed

Post-Upgrade Tasks

You're notified when the Identity upgrade is complete for each of the environments.

If the Fusion Applications environment isn't configured with federated SSO, verify that a users can sign in to the Fusion Applications environments successfully.

If the Fusion Applications environment is configured with federated SSO, verify that the users can sign in to the Fusion Applications environments through SSO successfully.

Other Applications Using Fusion Applications Environments as Identity Provider

If you have other Oracle applications (such as Taleo, CPQ (Configure, Price, Quota), SelectMinds, and so on.) that use a Fusion environment to federate SSO for users to sign in to the applications, you must complete the post-identity upgrade actions and test the single sign-on integration to ensure that federated SSO continues to function correctly.

  1. Sign in to the Oracle Cloud Console and navigate to the Environment family page.
  2. On the Environment families page, select the name of the environment family. If you don't see the resources, ensure that you're in the correct compartment.
  3. On the Environment family details page, select Maintenance tab, and scroll to Identity upgrade section to view the schedule.
  4. Select the Fusion Applications environment and select the Post-upgrade actions button.
  5. In the Post-upgrade actions panel, select Download the SAML metadata file. Use the information in this SAML metadata file to create the Identity provider in other Oracle applications.
  6. Test the Identity providers in other Oracle applications to ensure they're working successfully.
  7. Acknowledge Identity provider setup is complete in the other Oracle application.
Post-upgrade actions completed

Planning and Considerations for the Identity Upgrade

Be aware of the following potential impacts before, during, and after the upgrade:

Plan Environment Lifecycle Activities to Avoid Conflicts with the Identity Upgrade

Certain lifecycle activities are impacted during the Identity upgrade:

Refresh

Similar to quarterly update, you can perform self-service refreshes between environments (source and target) that are in the non-production cadence and have been upgraded. You can't perform a refresh that uses an environment mapped to the production cadence (not yet upgraded) as a source to refresh an environment (target) that has already been upgraded.

Install Language

When the Identity upgrade is in progress, you can't install and activate more languages in a Fusion Applications environment. You can install languages when the Identity upgrade completes and the environment Lifecycle state returns to Active.

Enabling Federated Single Sign-On (SSO) Before the Identity Upgrade

If the environments are scheduled for the Identity upgrade and it's less than seven days before the scheduled downtime of the first environment, we recommend that you wait until after the identity upgrade has completed for each of the environments for which you want to enable federated SSO and then follow the instructions in the following section to proceed with enablement.

If you haven't received the Identity upgrade schedule or there isn't enough time (we recommend at least two weeks) before the scheduled downtime of the first environment to receive the identity upgrade, follow the steps documented in Oracle Applications Cloud as the Single Sign-On (SSO) Service Provider to enable federated SSO. After federated SSO is enabled and the environment is scheduled for the identity upgrade, wait 24 to 48 hours for the Action required link to appear in the Pre-upgrade actions column in the identity upgrade schedule. When the Action required link is displayed, follow the instructions in Pre-upgrade tasks for federated SSO environments to complete the required actions at least 72 hours before the scheduled downtime of the first environment that receives the Identity upgrade.

Enabling Federated SSO After the Identity Upgrade

After the environments are upgraded, follow the steps documented in the IAM documentation, Federating with Identity Providers to federate a Fusion Applications environment Identity domain. See also How do I find the Identity domain for a Fusion Applications environment?

FAQs

Get answers to common questions about the identity upgrade.

Why is the upgrade required?

As part of Oracle's efforts to modernize the technology stack for Fusion Applications, this exception maintenance is to upgrade the Identity and Access Management for the Fusion environments to Oracle Cloud Infrastructure Identity and Access Management (OCI IAM). OCI IAM provides the latest features for managing authentication, sign-on policy, single sign-on (SSO), and multi-factor authentication (MFA).

What is the impact of the upgrade?

Downtime is required to perform the Identity upgrade. The environment isn't available or accessible during the upgrade. You're notified when the upgrade completes.

Self-service lifecycle activities can't be performed 72 hours before the upgrade until it completes. The affected activities include: scheduling environment refresh, starting refresh, installing a language pack, setting up customer-managed keys, and so on.

Also, refresh between an environment that has completed the Identity upgrade and another that hasn't completed the upgrade (and vice versa), can't be scheduled or performed. Refresh can only be scheduled and performed when both the source and target environments have the same Identity upgrade status.

How do I find the Identity domain for a Fusion Applications environment?

To find the Identity domain for a Fusion Applications environment:

  1. On the Applications Home of the Console, under My applications, select Fusion Applications to see a list of the environments.
  2. Select an environment.
  3. On the environment details page, on the Environment information panel, select the Associated identity domain. This opens the details page for the Identity domain associated with the environment.
How do I know my environments require Identity upgrade?
  • If your Fusion Applications environment family and environments were provisioned after April 6, 2025, the environments are already running with OCI IAM. These environments don't need the Identity upgrade.
  • You can also check the Fusion Applications sign-in page for one of the environments and compare with the sign-in page in Changes in Oracle Fusion Cloud Applications Sign In Page. If the sign-in page is similar to the page after the upgrade then the environments are already running with OCI IAM. Otherwise, the environments must be upgraded.
Does this applies to all SaaS Applications, such as, Taleo, Enterprise Performance Management (EPM), RightNow, Eloqua, OIC, and Primavera?
  • Identity upgrade only applies to Fusion Applications such as Customer Experience (CX), Human Capital Management (HCM), Enterprise Resource Planning (ERP), and Supply Chain & Manufacturing (SCM).
  • Identity upgrade doesn't apply to other applications such as, Taleo, Enterprise Performance Management (EPM), RightNow, Eloqua, Oracle Integration Cloud (OIC), and Primavera.
Any network setup I must do before Identity upgrade?
  • Ensure the network doesn't block outbound traffic to the Identity Domain URL (without the port number) for each of the Fusion Applications environment. This must be allowed for users to authenticate and sign in to the Fusion Applications environment.
  • The Identity Domain URL can be found in the Identity Domain details with the label Domain URL. From the OCI Cloud Console, follow the navigation: Identity & Security, Domains. Select the identity domain corresponding to each of the Fusion Applications environment where the Domain type is Oracle Apps. Then select the Details tab. Example of an Identity Domain URL excluding the port number (443): https://idcs-7f59093f2f9b42aab80a48b065631d8e.identity.oraclecloud.com.
  • To confirm that the outbound traffic isn't blocked, open a new browser session and sign in to the Oracle Cloud Console, as tenancy administrator or Identity domain administrator with the tenancy/cloud account name, and the corresponding identity domain of a Fusion Applications environment.
Is environment refresh restricted?
  • Any ongoing refresh must be completed before the downtime.
  • Refresh is restricted until both the source Fusion environment and the target Fusion environment have completed the Identity upgrade.
  • Similar to quarterly update, you can perform self-service refreshes between environments (source and target) that are in the non-production cadence and have been upgraded. You can't perform a refresh that uses an environment mapped to the production cadence (not yet upgraded) as a source to refresh an environment (target) that has already been upgraded.

My Fusion Applications environments are on 25C but hasn't been scheduled for Identity upgrade. Can I enable multifactor authentication (MFA) for the environments?
How to ensure you have the correct sign-in to do the required actions?
  • Ensure you're signed in as Tenancy administrator to the Cloud Console using "Default" or "OracleIdentityCloudService" Identity domain
  • Ensure you have created users in all the Fusion Identity domains. If the user is already present in the Fusion Identity domain, to generate password you must select Reset Password as Fusion Application users seeded in the Fusion Identity Domain don't get password for the domain by default.

    User management

How to ensure you have the correct privileges to do the required actions?
  • Ensure you have created the User sign-in in each of the four domains separately. For example, consider a cloud account with three Fusion Identity domains for production, test and development environments. Also a Default domain for signing in to the Cloud Console.

    Identity domain

  • Ensure the user in the four domains has the following permissions:
    • Default domain(this is the primordial domain to sign-in in to the Cloud Console) - User added to "Administrator" group.
    • Fusion production domain - User added to "Domain_Administrators" or "IDCS_Administrators" group.
    • Fusion test domain - User added to "Domain_Administrators" or "IDCS_Administrators" group.
    • Fusion dev1 domain - User added to "Domain_Administrators" or "IDCS_Administrators" group.

Sign-in

Any impact to end users? Is the sign-in URL changing?
  • The Fusion Applications sign-in URL isn't changing. The UI of the sign-in page might vary.

    The correct URL is, https://(DNS_prefix)environment_system_name.fa.ocs.oraclecloud.com/fscmUI/faces/FuseOverview or https://environment_system_name.fa.(data center code).oraclecloud.com/fscmUI/faces/FuseOverview.

  • Don't use the URL, https://login-(environment name)-saasfaprod1.fa.ocs.oraclecloud.com. This URL doesn't work after the Identity upgrade.
How do I get the application URL?

From the Oracle Cloud Console, My applications.

Applications page
Can we still disable the chooser page, so that users can only see the SSO sign-in page?

Yes, you can enable or disable the chooser page in the OCI IAM Console. The environment's chooser page settings isn't changed as part of the Identity upgrade.

Single Sign-On (SSO)

Can I enable federated SSO after I received the Identity upgrade schedule?
  • You can, if you complete the required pre-upgrade actions 72 hrs before the scheduled downtime of the first environment. The Console shows the required actions 24 hrs after the federated SSO is enabled.
  • If you acknowledged pre-upgrade actions and enabled an environment with federated SSO later, then you're notified to again acknowledge the required actions.
  • Don't enable federated SSO for scheduled environments during the two week period between the stage and production waves. Wait until the Identity upgrade is complete and then enable federated SSO.
Does Identity upgrade change the federated SSO configuration?
  • The federated SSO configuration doesn't change. The environment continues to use the same Identity Provider (IdP) (Oracle Identity Access and Management or other third-party identity providers).
  • The configuration remains same after the Identity upgrade.
Do I need to obtain a new certificate for the existing Identity provider?

This depends on the third-party Identity provider that you're using. Most modern cloud-based Identity provider (IdP) includes a new sign-in certificate for a new service provider. In the pre-upgrade actions, you must update the IdP in the Oracle Cloud Console UI with SAML metadata from the Identity provider, and test the connectivity and authentication.

Is it possible to have dual SSO choices in the sign-in page after Identity upgrade?

After Identity upgrade, you can have several SSO choices in the sign-in page.

If the SSO sign-in certificate is set to expire close to the Identity upgrade, is it required to prepone or postpone the upgrade?

You can request postponing the Identity upgrade through Service Request if you prefer not to track two upgrades simultaneously. Also, it could be difficult to debug if SSO isn't working post the changes.

If the required actions are completed ahead, is the existing SSO sign-in impacted until the actual upgrade takes place?

No, the required actions doesn't impact existing SSO sign-in. It's effective only after the Identity upgrade.

Do we need to turn off the existing SSO setup in SAAS when we receive the Identity upgrade?
  • No, you don't need to turn off existing SSO before Identity upgrade as it'll work after the upgrade if you completed the pre-upgrade actions.
  • If you choose to disable SSO you can do so after the Identity upgrade.
Can I remove SSO or not do the required actions for the SSO if we're not using it?

Yes, you can remove the SSO from the Fusion Application Security Console. Required actions disappears after 24 hrs. You can also ignore the required actions but you must acknowledge that you have completed all the required actions.

Reset Password

Is password reset required?
  • A password reset might be required after the Identity upgrade is complete.
  • You must notify the Fusion Applications users that if they have expired password or a weak password, they're asked to reset password when they sign in to the Fusion Applications environment after the upgrade.
  • Accounts used in API integrations might also require a password reset.
  • Passwords for Integration users and other critical accounts can be proactively reset before the Identity upgrade to prevent forced reset later.

User Management

We would like to move our SCIM workflows to OCI IAM for our Fusion instances as a part of this upgrade. Can Fusion consume Identity from OCI IAM going forward?

If you have implemented SCIM workflows for user provisioning into Fusion using FA SCIM REST API, then you must continue to use them post the IAM upgrade, to use the existing user life cycle workflows in Fusion. OCI IAM is the Identity store.

I have IT Security Manager role in my environments. Is the Security Console feature in Fusion Applications environments changed?

The Security Console in Fusion Applications isn't changed. You can continue to use it to add users to FA environments, reset password, and assign application roles. However, after Identity upgrade, you no longer need to use the Single Sign-On (SSO) menu in the Security Console to enable federated SSO. The ability to enable federated SSO for an FA environment is moved to the Oracle Cloud Console. To enable Federated SSO, see Federation with Identity Providers.

Does this mean all Fusion Applications users appear in the OCI IAM Console under the default Identity domain?

No, all the Fusion Applications users don't appear in the Identity domain corresponding to each of the Fusion Applications environment in the OCI IAM Console. These users can't sign in to the Oracle Cloud Console.

Identity Upgrade Schedule

How do I know if my environments are federated or not?
  • When you sign in to a Fusion Applications environment, if you see the Company Single Sign-On button or the company's sign-in page, then the environment has federated single sign-on (SSO).
  • If you have other Oracle Applications (such as Taleo, CPQ (Oracle Configure, Price, Quote), etc.) that use a Fusion Applications environment as the identity provider, then the Fusion Applications environment is federated.
  • If neither of the previous situations apply, the Fusion Applications environment isn't federated.
When is this change happening?

You're notified about the downtime schedule in advance. If any of the environments are enabled with federated SSO, a notification is sent 90 days in advance to you. If none of the environments have federated SSO enabled, a notification is sent 30 days in advance.

How can I find the schedule?

After you receive the notification about the Identity upgrade, you can sign-in to the Oracle Cloud Console and navigate to the Fusion Applications, Environment Families page to view the schedule for the environments:

  1. Sign-in to the Oracle Cloud Console.
  2. In Applications Home in the Console, under Subscriptions, select Go to service on the Fusion Applications tile.
  3. On the environment families details page, select Maintenance tab. Under Identity upgrade section you can view the upgrade schedules for the environments.
Identity upgrade schedule
Are my environments available while the upgrade is in progress?

While the upgrade is occurring, the environments aren't available.

How long is the downtime?

The Identity upgrade is expected to last for up to 3 hours or longer depending on the number of users.

Can I opt out of the upgrade?

All the Fusion Applications environments must complete the Identity upgrade. If the scheduled time doesn't work for you, contact Oracle Support to reschedule the upgrade for a convenient time by submitting a Support Request (SR).

When does the upgrade occur? Does it happen with the quarterly update?
  • The Identity upgrade doesn't occur in the same month as the quarterly update. To avoid multiple downtimes in a month, the upgrade is scheduled in the months after the environments receive a quarterly update.
  • In general, we expect to schedule the Identity upgrade of the environments in the same maintenance time window as when the environments receive a quarterly update. We might schedule the upgrade for a time window that's different from the maintenance time window.
  • At least one of the non-production environments must have completed the upgrade before we perform the Identity upgrade of the production environment. You can see the environments in the non-production cadence scheduled for the upgrade before the environments in the production cadence.
  • If the schedule doesn't work for you, contact Oracle Support to reschedule the upgrade for a convenient time. Contact Oracle Support by submitting a Support Request (SR).
How do I reschedule the upgrade?

To reschedule the upgrade for a convenient time, contact Oracle Support by submitting a Support Request (SR). In the Oracle Cloud Console, use the following selections when submitting the SR:

  • Technical Issues
  • Service Group: Oracle Cloud Applications
  • Service: Any Fusion product
  • Service Category: SaaS Console Services (Outage, Provision, P2T/T2T, Resize, Environment and User Management)
  • Subcategory: Fusion Identity Upgrade
Is there any change in the subscription associated with the Identity upgrade?

There's no change to the Fusion Applications subscriptions.