Search code examples
multi-factor-authenticationoracle-cloud-infrastructure

I can't enable MFA for Oracle Identity Cloud Service user


I just sign-up an account of Oracle Cloud

After I logged in, It seem the system automatically created a tenancy for me and added me to an Identity Providers named oracleidentitycloudservice.

They also create one more user starts with oracleidentitycloudservice/username.
This is identity user page, both 2 of them is me. One of them is federated with oracleidentitycloudservice which is created automatically.
enter image description here

I can enable MFA for the second account.
But I can not enable MFA account for oracleidentitycloudservice/username:
enter image description here

When I want to login to Identity Console page, I need to use this SSO method:
enter image description here

It seem risky if Identity Console page doesn't provide MFA feature. That's what I worry about.

Question is:

  1. Is it safe if I delete oracleidentitycloudservice/username?
  2. How can I enable MFA for oracleidentitycloudservice/username from Oracle Infastructure page?
  3. If Oracle is providing a complicated way to enable MFA for oracleidentitycloudservice/username, could it be a security issue?

Solution

  • For those who are in the same situation, here is step to Enable MFA for Oracle Identity cloud service user:

    1. Sign in by this SSO method at this screen:
      enter image description here

    2. Go to Service User Console on top-right screen
      List item

    3. Go to Admin Console of Identity
      enter image description here

    4. Go to My profile on top-right screen enter image description here

    5. Go to Security tab, our goal is to give the account permissions so that MFA item shows on this screen. At this moment MFA is not yet enabled, move to next step enter image description here

    6. Go to Admin console at top-right screen enter image description here

    7. Go to Security -> MFA at left side panel, check the box Mobile App Passcode enter image description here

    8. Go to Security -> Sign-On Policies, edit the Default Policy enter image description here

    9. Edit Default Sign-on Rule enter image description here

    10. Select the option that you prefer. It's upto you.
      enter image description here

    11. Go to Security tab and here you can enable MFA for your IDCS account enter image description here

    12. Sign-out and Sign-in again. Now you can use MFA to login. enter image description here