1. Introduction to OCI Group-Based Governance
In Oracle Cloud Infrastructure (OCI), administrative permissions are granted strictly to Groups, never directly to individual human user accounts.
This group-based governance model enforces the principle of Least Privilege and simplifies security auditing. When an employee joins a team, changes roles, or leaves the organization, security administrators update group memberships inside an Identity Domain rather than modifying dozens of individual policy documents.
Understanding how to construct scalable group architectures is foundational to operating an enterprise OCI footprint.
2. Standard Enterprise Group Architectures
To maintain clean separation of duties, tenancies should implement standardized group functional roles.
Below is an enterprise-grade group architecture pattern:
Identity Domain (Default-Domain)
│
├── SecOps-Admins-Group ────► Grants: manage all-resources in Security-Compartment
│ Grants: read all-resources in tenancy
│
├── Network-Admins-Group ───► Grants: manage virtual-network-family in Network-Compartment
│
├── DB-Admins-Group ────────► Grants: manage database-family in Production-Compartment
│
├── Dev-Engineers-Group ────► Grants: manage instance-family in Dev-Compartment
│ Grants: use virtual-network-family in Dev-Compartment
│
└── FinOps-Auditors-Group ──► Grants: inspect all-resources in tenancy
Grants: read usage-budgets in tenancy
Key Governance Benefits:
- Zero Direct User Binding: Individual users inherit permissions dynamically based on active group membership.
- Blast Radius Limitation: Developers in
Dev-Engineers-Grouphave full compute access insideDev-Compartment, but cannot modify production databases or network security lists. - Auditable Membership: Security auditors can inspect identity domain group rosters to verify compliance without parsing raw policy statements.
3. OCI Web Console (GUI) Step-by-Step Walkthrough
User provisioning, group creation, and membership assignment are managed directly in the OCI Web Console GUI.
Step 1: Navigating to Identity Domain Groups
- Log in to the Oracle Cloud Console (
https://cloud.oracle.com). - Open the Navigation Menu (
≡) ➔ Identity & Security ➔ Domains. - Select the target domain (e.g.,
Default). - Click Groups in the domain left-hand navigation panel.
Step 2: Creating an Administrative Group
- On the Groups page, click Create Group.
- Enter:
- Name:
SecOps-Admins-Group - Description:
Security operations team with audit and vault management rights. - Click Create.
Step 3: Provisioning Users and Assigning Group Membership
- Click Users in the domain left-hand panel.
- Click Create User.
- Enter user details:
- First Name:
Alex - Last Name:
Smith - Username / Email:
[email protected] - Click Create.
- On the User Details page, scroll down to Groups under Resources.
- Click Add User to Group.
- Select
SecOps-Admins-Groupfrom the dropdown list and click Add.
Alex now automatically inherits all IAM policies associated with SecOps-Admins-Group across the tenancy.
4. Common Architectural Misconceptions & Pitfalls
Misconception 1: “OCI Supports Nested Groups (Groups Inside Groups)”
- Reality: OCI IAM does not support nested group hierarchies (adding a Group as a member of another Group). Group membership is flat: users belong directly to groups.
Misconception 2: “Users in the Administrators Group Require Separate Policy Statements”
- Reality: The tenancy
Administratorsgroup is bound to a built-in root policy (Allow group Administrators to manage all-resources in tenancy). Adding a user toAdministratorsgrants unrestricted root-level power over the entire account.
5. OCI Group Governance vs. Google Cloud (GCP) Groups
For cloud architects familiar with Google Cloud, the following table compares group management features:
| Governance Metric | Google Cloud (GCP) | Oracle Cloud Infrastructure (OCI) | Key Technical Difference |
|---|---|---|---|
| Directory Authority | Google Workspace / Cloud Identity Groups | OCI Identity Domain Groups | OCI manages groups natively inside Identity Domains without requiring external Google Workspace directories. |
| Permission Binding | IAM Roles bound to Users, Service Accounts, or Groups | IAM Policies bound strictly to Groups or Dynamic Groups | OCI enforces group-level policy assignment exclusively. |
| Nested Groups | Supported via Google Groups | Not Supported (Flat membership model) | OCI requires assigning users directly to functional groups. |

