In Oracle EPM Cloud, an identity domain is the Oracle Identity Cloud Service (IDCS) tenant that governs authentication and identity management for all Oracle Cloud services provisioned to the organisation. When an enterprise subscribes to Oracle EPM Cloud — PBCS, FCCS, ARCS, or Narrative Reporting — an IDCS identity domain is provisioned as the authentication authority for that EPM subscription. All EPM Cloud users must exist as identities in the IDCS domain and must be granted the appropriate EPM Cloud service entitlements within that domain before they can access the EPM application. The identity domain is the replacement for Hyperion Shared Services in the cloud model — where Shared Services was the on-premise authentication and provisioning hub, the IDCS identity domain fulfils that function in Oracle Cloud.
Identity Domain Architecture
| Identity Domain Component | Function | Admin Interface |
|---|---|---|
| User store | Maintains user accounts; email, username, password (if native auth) | IDCS Admin Console → Users |
| Groups | Collections of users; used for bulk EPM role assignment | IDCS Admin Console → Groups |
| Application integration | Links the IDCS domain to specific Oracle Cloud applications | IDCS Admin Console → Applications |
| Authentication policy | MFA requirements; password policy; session timeout | IDCS Admin Console → Security |
| Identity provider (IdP) federation | SAML 2.0 or OIDC federation to enterprise IdP (Azure AD, Okta) | IDCS Admin Console → Identity Providers |
| Provisioning connector | SCIM-based synchronisation from enterprise HR or IAM system | IDCS Admin Console → Applications → Provisioning |
Identity Domain Federation to Enterprise SSO
Most GCC enterprises with Oracle EPM Cloud deployed in a mature IT environment integrate the IDCS identity domain with their enterprise identity provider — Microsoft Azure Active Directory, Okta, or an on-premise Active Directory Federation Services (ADFS) — through SAML 2.0 federation. This integration enables EPM Cloud users to authenticate with their enterprise corporate credentials (the same username and password used for Microsoft 365, the ERP, and other enterprise systems) without maintaining a separate set of credentials in IDCS. When SAML federation is configured, IDCS acts as the service provider (SP) and the enterprise IdP acts as the identity provider — authentication occurs at the enterprise IdP and the resulting SAML assertion is passed to IDCS to establish the EPM Cloud session.
GCC Context: MFA Requirements
Saudi Arabia’s NCA (National Cybersecurity Authority) and SAMA (Saudi Central Bank) cybersecurity frameworks require multi-factor authentication for access to financial systems and sensitive data. Oracle IDCS supports MFA configuration at the identity domain level — requiring a second authentication factor (OTP via mobile app, SMS, or email) for all users or for specific user groups accessing the EPM application. For GCC financial institutions and regulated enterprises, IDCS MFA configuration is a compliance requirement, not an optional security enhancement. Finance leaders of SAMA-regulated entities should confirm with their IT security team that MFA is enabled for all EPM Cloud users, not only for administrators.
What Goes Wrong in Practice
The most common identity domain configuration failure in Oracle EPM Cloud deployments is the loss of identity domain administrator access — where the email address of the original identity domain administrator is a personal email of a contractor who has left, or a project email that is no longer monitored. Without an identity domain administrator account, no new users can be provisioned to the EPM environment, no security changes can be made, and no federation configuration can be modified. Every Oracle EPM Cloud deployment should have at least two identity domain administrator accounts assigned to named, current employees with monitored email addresses — and those accounts should be reviewed as part of the periodic access review process.
How Loop Wise Solutions Approaches Identity Domain Configuration
In Oracle EPM Cloud implementations, identity domain setup — including federation configuration, MFA policy, and administrator account governance — is a Day 1 deliverable, not a post-go-live activity. We deliver identity domain documentation alongside the application configuration — including the SAML metadata exchange records, the group-to-role mapping, and the MFA policy settings — as a governed configuration record that the client’s IT security team can use for audit evidence and ongoing maintenance.