Oracle 1Z0-1046-26 · Exam domain 3 of 8
Managing HCM Security and Users
Oracle HCM security is layered, and exam questions almost always turn on which layer a scenario is describing. Function security controls what a user can do; data security controls which records they can do it to. Roles combine the two, and security profiles narrow a role down to a specific population of workers. Marks are lost here by reaching for role types when the scenario is really about data scope, or by forgetting that customising a predefined role directly will not survive an upgrade.
What this domain covers
Data vs. function security, HCM role types, Person Security Profiles, Security Console administration, and monitoring/troubleshooting security.
This site has 25 free practice questions and 9 deep-dive concept cards for this domain.
Core concepts explained
What is a Role Mapping?
Defines conditions under which a role is auto-provisioned to a worker. Conditions: job, grade, location, person type, HR relationship. When an HR transaction (hire, transfer) matches conditions, roles are assigned automatically.
What is the Send Pending LDAP Requests process?
Synchronizes HCM user and role changes to Oracle Internet Directory (LDAP / IDCS). Must be run after user creation or role changes for them to take effect in authentication and SSO.
What is Transaction Design Studio (TDS)?
Tool in HCM Experience Design Studio to configure field-level visibility and editability on HCM transaction pages by role. No sandbox needed. Common use: hiding salary fields from non-payroll roles.
What is the Security Diagnostic Report?
A Security Console report that shows all assigned roles, inherited privileges, and security profiles for a specific user. Key troubleshooting tool when a user reports missing access.
What is the difference between a Data Security Policy and a Function Security Policy?
Function Security controls which actions, pages, or menu items a user can access. Data Security controls which specific records (rows of data) they can see or act on within that functional access.
Where can an administrator review security audit logs in Oracle HCM?
Through the Security Console's audit/reporting capabilities, which track changes made to security configurations (roles, profiles, mappings) and user permissions over time — the key tool for investigating unauthorized or unexpected security changes.
Key points the exam tests
- Data Security via Security Profiles (Person, Organization, etc.) restricts which records a user can see at row level.
- Oracle upgrades overwrite predefined roles. Always copy a predefined role, then customize the copy to survive upgrades.
- Data Role = Job Role (function access) + Security Profile (data restriction). It grants specific functions but limits them to defined data scope.
- Run after major role mapping changes to re-evaluate all workers and ensure everyone has correct roles per current conditions.
- Field-level hiding is configured in Transaction Design Studio (HCM Experience Design Studio). A rule may be hiding the field for that user's role.
- Function Security controls which actions/pages a user can access; Data Security (via security profiles) controls which records; Row-level filters records further; Field-level (via Transaction Design Studio) controls individual field visibility.
- Oracle upgrades can overwrite predefined roles. Copying the role first and customizing the copy ensures your changes survive future upgrades.
- A Data Role bundles a Job Role (defines what actions are available) with a Security Profile (defines which records those actions can be performed on).
- Person Security Profiles support multiple scoping options — manager hierarchy, organization, position hierarchy, or custom-defined combinations — to precisely control worker visibility.
- Role Mappings define auto-provisioning logic — when an HR transaction results in a worker matching specified conditions, the mapped role is automatically granted.
- Role and user changes in HCM don't take effect for authentication/SSO purposes until synchronized to the identity directory — this process performs that sync.
- TDS is specifically for field-level behavior — e.g., hiding the salary field from non-payroll roles — configured directly without requiring sandbox activation.
- The Security Diagnostic Report is the key troubleshooting tool for access issues — it shows a specific user's full role assignments, inherited privileges, and security profiles in one place.
- Duty Roles are building blocks — collections of privileges — composed together to form Job Roles, which are the roles actually assigned to individual users.
- Abstract Roles represent broad categories (Employee, Line Manager, Contingent Worker) used to grant general self-service access, independent of a person's specific job.
- Role Mappings evaluate conditions (like job or position) at the moment of an HR transaction and automatically provision the matching role — enabling exactly this kind of automatic assignment.
- Field-level security operates at a finer grain than Function or Data Security — it can hide or restrict individual fields (like salary) even when the user otherwise has record-level access.
- Role Mapping changes only apply going forward for new transactions by default. Running this process retroactively re-evaluates the entire existing workforce against the new conditions.
- Function Security governs access to functionality (menus, pages, actions), while Data Security governs which specific data rows a user with that functional access can actually view or act on.
- The Security Console includes an administration area for configuring console-wide options, in addition to its role and user management capabilities.
- User account status can be linked to HCM employment events — a termination event can automatically trigger role deprovisioning and account suspension through role mapping conditions.
- Security audit logs specifically capture who changed what within security configuration (roles, profiles, mappings) and when — the correct place to investigate suspected unauthorized changes.
- OTBI and other HCM reporting tools should be configured to honor the same data security profiles as transactional access, preventing users from seeing report data beyond their authorized scope.
- Intermittent access to specific records often traces back to hierarchy-based security profiles (manager hierarchy, organization) where the visible population changes as underlying org/reporting relationships change.
- A Data Role bundles a Job Role (defines available functions) with a Security Profile (defines the data scope those functions apply to) — the other options are unrelated Security objects.
Frequently asked questions
What are the four layers of Oracle HCM Cloud security?
(1) Function Security — what actions/pages the user can access; (2) Data Security — which records they can view (via security profiles); (3) Row-level Security — filtered via Person/Org security profiles; (4) Field-level Security — field visibility via Transaction Design Studio.
What is the difference between Job Role, Duty Role, Abstract Role, and Data Role?
Job Role: assigned to users, represents their position (e.g., HR Specialist). Duty Role: groups privileges, inherited by Job Roles. Abstract Role: general category (Employee, Line Manager) for self-service. Data Role: Job Role + Security Profile (restricts data access).
What is a Person Security Profile?
Defines which worker records a user can view. Options: All Workers, Workers in their Manager Hierarchy (direct/indirect reports), by Organization, by Position hierarchy, or a custom combination. Part of data role or standalone assignment.
Practise this domain
Work through 25 Managing HCM Security and Users practice questions, with an explanation after every answer. Free question bank, no sign-up needed to start.
Start practising