Azure AD Enterprise Application for Oracle Fusion ERP lacks cache-clearing capabilities

Danny Y 1 Reputation point
2021-11-27T00:23:19.163+00:00

The Oracle Fusion ERP enterprise app lacks one important feature.

The way the enterprise app works, it maintains a mapping between the Azure UPN and the Oracle user account GUID (target identity).

In the event that there is an inadvertent deletion of the Oracle user account, that user ID will forever be "broken".

For example, if Azure AD user ******@mydomain.com is provisioned to Oracle, the enterprise app will maintain a mapping of ******@mydomain.com to Oracle GUID 12345. If the Oracle account is deleted, Azure will forever think that there should be an Oracle user account with GUID 12345.

If someone tries to recreate the Oracle account with the same user name ******@mydomain.com, the GUID will actually be different and Azure will not recognize that UPN = Oracle user name.

There is no way to restore the UPN so that it will work in Oracle. The only recourse is to delete the Enterprise App and recreate it from scratch.

One step further, if for whatever reason the user name in Oracle is changed (******@mydomain.com), because the GUID is still the same, Azure will RENAME the Oracle user name back to ******@mydomain.com.

There should be a way to dissociate the UPN and the Target Identity on a per-UPN basis.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.