Article 15 – OCI Console Navigation & Administrative Workflows: Mastering the IAM Web Interface

1. Introduction to the OCI Console IAM Interface

The Oracle Cloud Infrastructure (OCI) Web Console provides a unified graphical interface for managing tenancy administration, identity directories, policy documents, and governance guardrails.

While command-line tools (OCI CLI) and SDKs are used for automation, day-to-day identity governance, user onboarding, emergency break-glass procedures, and security audits are conducted primarily inside the Console GUI.

Mastering the layout, domain pickers, compartment selectors, and policy builder tools inside the OCI Console is essential for efficient cloud administration.

2. Key Administrative Control Centers in the Console GUI

The OCI Console organizes IAM administration into four main sub-modules located under Identity & Security:

  1. Domains: The Identity-as-a-Service (IDaaS) management portal. Used for managing users, groups, dynamic groups, sign-on policies, MFA enforcement, and SAML/SCIM identity federation.
  2. Compartments: The logical resource hierarchy portal. Used for creating nested compartment trees, viewing child hierarchies, and moving live resources between compartments.
  3. Policies: The access control policy management portal. Features an interactive GUI Policy Builder and raw text editor for authoring declarative IAM rules.
  4. Network Sources: The location-based security portal. Used for defining public IP ranges and private VCN subnet boundaries referenced in policy conditions.
3. OCI Web Console (GUI) Masterclass Walkthrough

Below are the step-by-step GUI workflows for standard daily IAM administration tasks.

Workflow 1: Switching Between Identity Domains

When managing multi-domain tenancies (e.g., Default Domain vs Partner Domain):

  1. Open Navigation Menu (≡) ➔ Identity & Security ➔ Domains.
  2. On the Domains list page, click the name of the domain you wish to inspect (e.g., Partner-Domain).
  3. Notice the Domain Context Header at the top of the screen displaying Domain: Partner-Domain. All subsequent user, group, and sign-on policy actions are executed strictly within this selected domain.
Workflow 2: Utilizing the GUI Policy Builder

When authoring policies without memorizing syntax:

  1. Navigate to Identity & Security ➔ Policies.
  2. In the left-hand Compartment Selector, select the target location (e.g., Dev-Compartment).
  3. Click Create Policy.
  4. In the creation wizard:
  5. Keep Show manual editor toggled OFF to use the interactive dropdown builder.
  6. Group: Select Dev-Engineers-Group.
  7. Verb: Select manage.
  8. Resource Type: Select instance-family.
  9. Location: Select Dev-Compartment.
  10. The Console automatically formats the syntax string:
    text
    Allow group Dev-Engineers-Group to manage instance-family in compartment Dev-Compartment
  11. Click Create.
Workflow 3: Configuring User Security Profile Options

Administrators or individual users managing security credentials (API keys, Auth Tokens, Passwords):

  1. Click the Profile Icon in the top-right corner of the OCI Console header ➔ Click User Settings.
  2. Under Resources in the left-hand panel:
  3. API Keys: Upload RSA 2048-bit public keys for OCI CLI/SDK authentication.
  4. Auth Tokens: Generate secret tokens required for Docker CLI login (docker login) to OCI Container Registry (OCIR).
  5. MFA: Register TOTP authenticator apps or FIDO2 hardware security keys.
4. Common Architectural Misconceptions & Pitfalls
Misconception 1: “Policies Created in the Console Are Tied to the Selected Compartment View”
  • Reality: Selecting a compartment in the left-hand menu filters which policy documents are displayed. The actual resource location scope is determined by the in compartment <Name> clause written inside the policy statement itself.
Misconception 2: “Tenancy Home Region Is Irrelevant for IAM Administration”
  • Reality: IAM identity operations (creating users, updating policies, managing identity domains) are executed in your tenancy’s designated Home Region. While OCI replicates IAM changes globally to all regions automatically, identity domain administrative writes route through the Home Region.
5. OCI Web Console vs. Google Cloud (GCP) Console

For cloud architects familiar with Google Cloud, the following table compares web console GUI workflows:

Console FeatureGoogle Cloud (GCP)Oracle Cloud Infrastructure (OCI)Key Technical Difference
Project / Location PickerTop header Project Dropdown barLeft-hand Compartment Selector dropdownGCP filters by Project ID; OCI filters views by hierarchical Compartment trees.
Identity Management GUIManaged via Google Admin Console (admin.google.com) or GCP IAMManaged directly inside OCI Console ➔ Identity DomainsOCI integrates full IDaaS directory management natively into the cloud console interface.
Policy CreationCheckbox role selection on IAM binding tableGUI Policy Builder or raw text editor for plain-text policy statementsOCI supports editing plain-text declarative policy statements directly in the Console GUI.