You're viewing OCI IAM documentation for new tenancies in regions that have been updated to use identity domains.

SSO Between OCI and ADFS

In this tutorial, configure SSO between the OCI IAM and ADFS, using ADFS as the identity provider (IdP).

This 30 minute tutorial shows you how to integrate OCI IAM, acting as a service provider (SP), with ADFS, acting as an IdP. By setting up federation between ADFS and OCI IAM, you enable users' access to services and applications in OCI using user credentials that ADFS authenticates.

This tutorial covers setting up ADFS as an IdP for OCI IAM.

OCI IAM provides integration with SAML 2.0 IdPs. This integration:

  • Works with federated Single Sign-On (SSO) solutions that are compatible with SAML 2.0 as an IdP, such as ADFS.
  • Lets users sign in to OCI using their ADFS credentials.
  • Lets users sign in to end applications.
  1. First, download the metadata from the OCI IAM identity domain.
  2. In the next few steps you create and configure a relying party in ADFS.
  3. In ADFS, set up SSO with OCI IAM using the metadata.
  4. In ADFS, edit the Attributes and Claims so that the email name is used as the identifier for users.
  5. In ADFS, add a user to the app.
  6. For the next steps, you return to the identity domain to finish the setup and configuration. In OCI IAM, update the default IdP policy to add ADFS.
  7. Test that federated authentication works between OCI IAM and ADFS.
Note

This tutorial is specific to IAM with Identity Domains.