Article

    Cyber News / Article / Bringing Oracle Cloud Identity to Wiz

    Bringing Oracle Cloud Identity to Wiz
    Om
    Omer Mesika-2025-12-22

    Bringing Oracle Cloud Identity to Wiz

    Unified visibility into OCI identities, permissions, and policies — mapped into Wiz’s Security Graph.

    Identity is the backbone of cloud security. It defines who can access what, and it’s often the difference between a secure environment and an open door. Until now, organizations running workloads in Oracle Cloud Infrastructure (OCI) lacked a way to see its unique IAM model side-by-side with AWS, Azure, and GCP.

    Wiz now supports OCI IAM, giving customers visibility into OCI identities, permissions, and policies — all normalized into Wiz’s unified security graph.Why It Matters

    OCI introduces a distinct identity and access management model, with constructs like Identity Domains, Compartments, and natural-language policies. While powerful for operators, these differences have made it hard for security teams to consistently assess permissions, enforce guardrails, and reduce risk across clouds.

    The result: OCI often became a blind spot inmulti-cloudidentity governance.

    With Wiz, that blind spot disappears. We translate OCI’s IAM into the same model we already use for AWS, Azure, and GCP. Security teams can:

    Detects excessive permissions andtoxic combinations.

    Analyze access consistently across all four major clouds.

    Run unified controls and threat analysis without juggling cloud-specific tools.

    OCI IAM in Wiz unlocks new visibility and control for customers:

    Complete visibility into OCI identitiesSee every user, group, and service principal, including the domains or compartments they belong to and the exact permissions they inherit.

    Understand access paths and risksVisualize how a user reaches a resource through groups, policies, and compartments. Easily spot overly broad groups or missing MFA.

    Track keys and service accountsIdentify unrotated or unused OCI API keys and customer secret keys before they become hidden risks.

    Ensure cross-cloud consistencyBecause permissions are normalized, OCI entitlements appear alongside AWS, Azure, and GCP. You can finally answer critical questions like:“Which identities have admin rights across all four clouds?”

    Bringing OCI into Wiz required solving several unique challenges. Here’s how we made it simple for customers — without losing the depth of OCI’s IAM model:

    Identity Domains → Wiz OrganizationsOCI domains isolate users, groups, and apps. We map them into Wiz’s organization layer to preserve isolation while making them visible in context.

    Compartments → Wiz SubscriptionsOCI resources live in nested compartments, which complicates permission evaluation. We flatten and analyze the full hierarchy so you see the true scope of access.

    Policies Written in Natural Language → Structured RulesOCI policies read like plain English (“Allow group Admins to manage all-resources in compartment Finance”). Wiz parses these into structured rules for consistent analysis across clouds.

    Permissions Tied to Verbs → Wiz Access TypesOCI’s verbs (inspect, read, use, manage) bundle many actions. We normalize them into Wiz’s access categories (List, Read, Write, High Privilege, Admin), enabling toxic combo checks and threat analysis.

    Resource Types → Wiz ObjectsBuckets, instances, and other OCI services are mapped into Wiz objects, so you can compare them side-by-side with AWS, Azure, and GCP.

    This launch is just the start. We’re continuing to expand our OCI coverage:

    Dynamic Groups and federation support.

    Deeper integration into Wiz’s cross-cloud policies.

    Continued alignment of OCI features with AWS, Azure, and GCP.

    With OCI support, Wiz gives you one identity model, one graph, and one place to see and secure access everywhere. OCI IAM is no longer a blind spot — it’s part of the same unified experience you already use for AWS, Azure, and GCP.

    ZDC awarded hackers $320,000 and uncovered a record‑breaking tally of critical CVEs for core cloud infrastructure, underscoring the scale and urgency of securing the open‑source software that underpins the modern cloud.

    Wiz Threat Research has observed exploitation in-the-wild of CVE-2025-8110

    How attackers are leveraging compromised employee GitHub Personal Access Tokens to compromise cloud environments.

    Get a personalized demo

    ©2026Wiz, Inc.

    StatusPrivacy PolicyTerms of UseModern Slavery StatementCookie Settings

    Original source