MSAMM
Back to course

Administering Cloud EPM: The Platform Beneath the Business Processes · Module 8 · Single Sign-On and Federation

Configuring an external identity provider

Lesson 90 of 201 · 16 min

The split of work: steps in the identity provider, steps in the cloud console. In the identity provider: create the application, configure the assertion, set attributes, download metadata. Configure user and group assignment at the provider end. Note the username attribute specifically, and its match to Module 7's mapping. Then export what the console will need. THIS IS JOINT WORK WITH THE IDENTITY TEAM. Book it as a session with them, not as a task you will do and tell them about. THE USERNAME ATTRIBUTE IS THE SINGLE MOST COMMON FAILURE POINT. What the provider asserts must match what the identity domain expects. Confirm it explicitly before testing. Take notes as you go; you will do this again for the second environment.

The full lesson is part of the course

The video, the complete written lesson and the module quiz are included in Administering Cloud EPM: The Platform Beneath the Business Processes, with a certificate on completion and a fourteen-day refund window.

Get the free lessons by email

We will email you a link to every free lesson in this course. No account needed, and one message only.

In this module: Module 8 · Single Sign-On and Federation

  1. 1What SSO changes
  2. 2The sign-in experience under SSO
  3. 3Configuring an external identity provider
  4. 4Completing configuration in the console
  5. 5Multiple identity providers in one domain
  6. 6SSO across domains in one cloud account
  7. 7SSO across different cloud accounts
  8. 8Logout URL and credential management
  9. 9Making clients work after SSO
  10. 10What breaksFree preview
  11. 11Lab: federate without locking yourself out