Administering Cloud EPM: The Platform Beneath the Business Processes · Module 8 · Single Sign-On and Federation
What SSO changes
Lesson 88 of 201 · 2 min
Four things SSO gives you. Users sign in with corporate credentials. The corporate identity provider governs authentication policy. Password resets largely disappear. And disabling a corporate account disables EPM access. WITHOUT SSO, DISABLING SOMEBODY'S CORPORATE ACCOUNT DOES NOTHING TO THEIR EPM ACCESS. With it, it does. That is the argument to make to a security function — not the convenience, not the password resets. That one sentence. What SSO does not do. It handles AUTHENTICATION — who you are. It does not handle AUTHORIZATION — what you can do. Application roles remain yours (Module 6). People conflate these constantly, and the conflation shows up as an expectation that federating will somehow sort out access. What SSO breaks, if you are not ready. Client components that authenticate differently. Automation running under accounts that now federate. And administrator access, if the identity provider becomes unavailable. THE ADMINISTRATOR ESCAPE HATCH. In SSO-enabled environments,…
The full lesson is part of the course
The video, the complete written lesson and the module quiz are included in Administering Cloud EPM: The Platform Beneath the Business Processes, with a certificate on completion and a fourteen-day refund window.
In this module: Module 8 · Single Sign-On and Federation
- 1What SSO changes
- 2The sign-in experience under SSO
- 3Configuring an external identity provider
- 4Completing configuration in the console
- 5Multiple identity providers in one domain
- 6SSO across domains in one cloud account
- 7SSO across different cloud accounts
- 8Logout URL and credential management
- 9Making clients work after SSO
- 10What breaksFree preview
- 11Lab: federate without locking yourself out
