Administering Cloud EPM: The Platform Beneath the Business Processes · Module 8 · Single Sign-On and Federation
Configuring an external identity provider
Lesson 90 of 201 · 16 min
The split of work: steps in the identity provider, steps in the cloud console. In the identity provider: create the application, configure the assertion, set attributes, download metadata. Configure user and group assignment at the provider end. Note the username attribute specifically, and its match to Module 7's mapping. Then export what the console will need. THIS IS JOINT WORK WITH THE IDENTITY TEAM. Book it as a session with them, not as a task you will do and tell them about. THE USERNAME ATTRIBUTE IS THE SINGLE MOST COMMON FAILURE POINT. What the provider asserts must match what the identity domain expects. Confirm it explicitly before testing. Take notes as you go; you will do this again for the second environment.
The full lesson is part of the course
The video, the complete written lesson and the module quiz are included in Administering Cloud EPM: The Platform Beneath the Business Processes, with a certificate on completion and a fourteen-day refund window.
In this module: Module 8 · Single Sign-On and Federation
- 1What SSO changes
- 2The sign-in experience under SSO
- 3Configuring an external identity provider
- 4Completing configuration in the console
- 5Multiple identity providers in one domain
- 6SSO across domains in one cloud account
- 7SSO across different cloud accounts
- 8Logout URL and credential management
- 9Making clients work after SSO
- 10What breaksFree preview
- 11Lab: federate without locking yourself out
