Take Control of HR Talent Access: New Features from Infor’s April CU

Managing menu security and web app access across different HR teams can quickly become complicated, especially when custom configurations pile up over time. Fortunately, the latest enhancements delivered in Infor’s April CU introduce UI Access Control for a simpler way to manage menu visibility and streamline the user experience.

With the introduction of consolidated web apps, streamlined menus, and new role-based access policies, HR teams can easily configure security and maintain cleaner environments.

To find out how to use these new enhancements, join RPI’s HCM Consultant Hannah Alt on Friday, May 9 at 11:00 AM EST for a walkthrough of what’s new in Infor HCM and how to make the most of the new April enhancements. Session attendees will learn how to:

  • Explore new streamlined menus and consolidated web apps in HR Talent
  • Create UI Access Control policies and manage menu/web app access by role
  • Prepare your organization to adopt the new tools before the trial period concludes in April 2026

If your team manages HR Talent security configurations, this session is for you. Complete the form below to save your seat.

Transcript

Hannah Alt
Hello, and thank you for joining us today for our webinar, Take Control of HR Talent Access: New Features from Infor’s April CU. I’m Hannah Alt. I’m a consultant here at RPI. I specialize in HR Talent and payroll implementations and like to get my hands dirty with configuration and security — which is also what we’re going to talk about today, specific to the HR Talent world.

Our agenda: I’m going to go over some of the new feature toggles from the recent Infor CUs, specifically related to the consolidated web apps, demo some of those web apps so you know what to expect if you haven’t seen them yet, and then we’ll jump into the new UI Access Control tool, talk through configuring menus using that tool, and do a live demo in the system.

Let’s talk about consolidated web apps. What are they? The new web apps are part of Infor’s new feature toggles that they’ve been rolling out over the last year or so. In System Administrator, you can find these feature toggles. If you filter them down to just the web app versions, you’ll see there are many consolidated web apps specific to HR Talent. They’ve been rolling them out in waves, module by module, but at this point the majority of the modules are available and you can see them all at once rather than piecing them together. The important note is that Infor has updated their timeline: all web app trial periods will end next April — April 2026. So you have just under a year to turn these on, test them, and get comfortable with them before you no longer have a choice. They’re really easy to enable — just click the Enable button. Once you’ve selected the web app and enabled it in the feature toggle, it’s available across the organization to users with access to those web apps.

When we say consolidated web app, what does that mean? I want to highlight a couple of different roles and show you what the new structure looks like. All the content is the same — it’s the look, feel, and menu structure that Infor’s changing. My first example is the Absence Management role. This is the before view — what you might have today if you’re using the traditional menu. The most notable thing is that the left side menu has lots of nested items. If I open Maintain Absences, there are items below that, and even sub-items that expand further. The menu structure is deeply nested throughout the roles.

Here is the new role and new menu. The biggest change is the simplified left side menu — much more consolidated. Infor has taken these processes and created menu structures around them that are not nested. Instead of drilling many layers deep into a Processing menu, those items are now presented as horizontal tabs. You also have detailed card views that group related items — primary processing, process monitor, analytics, and so on. All the same items, just reorganized to be more user-friendly. It takes a little getting used to when finding things in the new structure.

Here’s another example. Today you might have the Administrator web app. If you enable the new version, it’s called HR Administration — so in your web app selector, it will appear under H for HR rather than A for Administrator. The left side menu has been simplified: instead of digging through a Setup menu to find Jobs and Positions, it’s right there at the top. You’ll again see the horizontal tab structure and the detailed card view. This structure is consistent across modules as you enable the new consolidated web apps.

Most recently, Infor rolled out the consolidated web apps for Employee and Manager space in this past month’s April CU. The look and feel has been consistent for a while, but the menu structure has changed. The Team naming convention, for example, is new — it’s how Infor is grouping things like Time and Attendance that are pervasive across the system. Everything is highly integrated in HR Talent and they’re trying to make the menus reflect that.

Those are the web apps. There are a lot of them — I just wanted to give you a couple of highlights. Now let’s talk about UI Access Control, which is how you actually configure these new web app menus for your different users and roles in HR Talent.

What is UI Access Control? It’s a tool for creating role-based access policies for both navigation and reports. Today we’re focusing on navigation — your menus. The process for configuring report access is similar, but we won’t cover that today. If that’s something you’re interested in, send us a message — maybe we can do a future webinar on it. The idea is that you create policies based on your security roles, and it provides a simple checkbox interface for denying access. Writing LPL is no longer required to configure menu access, which is a really nice improvement.

One important concept: you are removing access, not granting it. By default, users get access to everything in the menu, and you use UI Access Control to hide specific items from specific roles. This is just one piece of your holistic security design — it doesn’t replace security class configuration or other types of data-level security. But it does make the system more user-friendly for people in your security roles. And it’s part of the Security Administration web app, so your security administrator doesn’t need any extra access — it’s already included in that role.

Let’s dive in and look at what this looks like in the system. I’m in the Security Administration web app, and I now have the option to select UI Access Control. This is the main homepage of your access control. You’ll see a Navigation tab and a Delivered Reports tab — we’re focusing on Navigation today. Within the navigation access control, there are two main components: the web app you’re selecting from the dropdown, and the role — the security role of whoever is accessing that web app.

As an example, let’s search for the Benefits web app. By searching for the web app, I can see which security roles have policies for it: Actor Org Unit Benefit Admin, AdminST, Benefits Administrator, and a couple of generalist roles. These are the roles that currently see Benefits in their web application list. You can also flip it and search by role — for example, what web apps does the standard template HR Generalist have access to? I can see Absence, Admin, Benefits, Comp, Performance, Recruiter, and Succession — all the apps that role has policies for.

We do still recommend configuring custom roles if you want to make changes to your menus. You can configure the standard template policies, but as Infor rolls out updates or as your organization grows and adjusts security, it’s helpful to keep those delivered standard templates intact. That way your super users don’t end up with limited access because your downstream users need it restricted. We tend to suggest creating custom underscore templates for your organization.

There are a couple of ways to do that. The most important thing to know is that if you create a custom security role, no access policies exist by default. In today’s demo, I’ve created an HR Generalist Underscore RPI role. I’ve copied the generalist role’s security, but no policies exist by default — which means if I assigned this role to a bunch of users and they logged in, they would have no web apps to see. So we have to create policies for our custom roles.

There are two ways to do that. First, you can click Create Policy, choose your web app and role combination, set it to Active, and hit Submit — creating a new policy from scratch. But what you’ll more often want to do is mimic one of the standard templates. If I search the standard template generalist, I can see the delivered policies and copy them to my custom role. I’ll copy the absence and compensation policies to HR Generalist Underscore RPI. Now when I search for my custom role, it has three policies assigned — and if a user logs in with that role, they’ll actually see web apps.

Now, the whole point of a custom role is to give those users a different menu than the standard template generalist. So we need to configure those policies. A couple of things worth pointing out about the copy approach: it tells you which template you copied from and whether your policy is still in sync with that delivered version. For web apps where you want your custom role to match the standard template exactly — and stay current as Infor updates that template — you can enable Auto Update. For other web apps where you want to customize, you configure them manually. This lets you keep certain menus in sync while customizing others.

Let’s get into the actual configuration. I have my Absence Management policy selected and I’ll click Configure. This opens the accessibility screen, where I can see the web app and role combination. I select the menu I’m configuring — we’ll use the Absence Management Consolidated. On the right side, I can see all the menu items: Resources, Plans, Enrollment, Processing. Over in the Absence Consolidated web app itself, I can see those same items along the left side — and the checkboxes in the configuration screen directly correspond to those menu items. If I expand Processing in the app, I see tabs for Cycle Processing and Process Monitor — and expanding Processing in the configuration shows those same items.

In this case, I’m going to hide Plans entirely from my generalist — they don’t need to set up plans, they’re just maintaining. I can also open items and hide specific sub-items. For example, under Maintenance, my generalists can manage leaves but don’t need some of the other options, so I’ll hide those submenus and hide Administration. My generalist can access Resources, Enrollment, and Processing, but they’re not doing any setup.

Once I’m happy with my selections, I’ll hit OK and save. You can now see it no longer matches the version I copied it from, and I can compare differences if needed. I also get a full list of inaccessible items — everything I’ve hidden from this role. It really is as simple as that: go in, hide what you don’t want, and save.

Let’s do one more. For the Benefits web app and my custom role, I’ll click Configure, select Benefits Consolidated, and hide Plans, Cobra, Administration, and ACA — my generalists don’t do any plan setup or compliance administration. Hit OK, save. I’ve got my list of inaccessible items, and since I created this one from scratch rather than copying, there’s nothing to compare it to.

Now I’ve hidden those menu items — let’s log in as someone with this custom role and see what it looks like from their perspective. I gave my generalist access to Compensation, Benefits, and Absence web apps, so we should see access to those in the system.

My test user has limited web application access. With the Generalist Underscore RPI role, I can see Absence, Benefits, and Compensation. Starting with Absence: the menu is smaller — no Plans, no Administration. Under Maintenance, I only see a couple of tabs. The menu has been configured down to fit what this role needs.

To show that this is role-specific and not global: switching back to the system admin account, I still see my full menu — Administration, Plans, a much more complete Maintenance screen. And looking at Benefits for the generalist: much more limited. No Plans, no Administration, no Cobra. Very consolidated to the needs of that user.

A few follow-up points about using UI Access Control: it’s still recommended to configure custom roles. You’re probably already using some — you just need to create policies for them. Important reminder: when you create a custom security role, navigation policies do not exist by default. You’ll need to go create those policies, most likely based on something that already exists rather than starting from scratch.

Data-level security configurations are still required. Hiding a menu item doesn’t prevent someone from accessing that screen through search or another path. If there are things your users truly shouldn’t have access to, you still need those security class configurations on your custom roles. UI Access Control is part of your holistic security design — it’s not a one-stop shop.

Also worth considering: does your organization have a lot of configured menus already? If you’ve been live on Talent for a while and have done significant menu configuration, you should get started on this soon. When you enable the consolidated web apps, you are pointing the system to new menus. Benefits Consolidated is a new menu — so if you’ve configured the old Benefits menu, those configurations are still there but aren’t doing anything for you anymore because that menu is no longer in use. This is your opportunity to review, consolidate, or ideally find that the new menus work well as-is and you can just use access control to hide a few things. Either way, start thinking about this now — that April deadline will come faster than you expect.

We have time for a couple of questions. First: can I still configure or add custom pages to the consolidated menu? Yes. Configuration Console is still applicable for the new menus. If you want to add a custom page, you can go into Configuration Console and modify the LPL to add a new item — everyone in that web app would see it. UI Access Control can then hide it from specific roles. Once a page is in the menu LPL, it will show up in UI Access Control. So this doesn’t stop you from configuring — just remember to make those configurations on the new consolidated menus, which are built a bit differently.

One more question: how do I give users access to these new menu items? The simple answer is the feature toggles. Enable the consolidated web apps from that list I showed at the beginning. Once enabled, any security roles that point to Benefits, Compensation, Administration, Absence, or Payroll will use those consolidated web apps and your users will see the new menus. The key question is: do you need to modify those menus at all? That’s where you go into UI Access Control and remove what doesn’t apply. By default, everyone has everything within their web app — it’s about determining what to hide for which users.

That’s what we have for today. If we didn’t get to a question you have, or something comes up later, please feel free to email us at questions@rpic.com — we’d love to help. We’re really excited about this new feature and hope you are too. Hopefully we’ll see you again for a new webinar in the future. Thanks again for your time.

More Webinars