You're viewing OCI IAM documentation for new tenancies in regions that have been updated to use identity domains.

SSO Between OCI and Microsoft Entra ID

In this tutorial, configure SSO between the OCI IAM and Microsoft Entra ID, using Entra ID as the identity provider (IdP).

This 30 minute tutorial shows you how to integrate OCI IAM, acting as a service provider (SP), with Entra ID, acting as an IdP. By setting up federation between Entra ID and OCI IAM, you enable users' access to services and applications in OCI using user credentials that Entra ID authenticates.

This tutorial covers setting up Entra ID as an IdP for OCI IAM.

  1. First, download the metadata from the OCI IAM identity domain.
  2. In the next few steps you create and configure an app in Entra ID.
  3. In Entra ID, set up SSO with OCI IAM using the metadata.
  4. In Entra ID, edit the Attributes and Claims so that the email name is used as the identifier for users.
  5. In Entra ID, add a user to the app.
  6. For the next steps, you return to your identity domain to finish the setup and configuration.In OCI IAM, update the default IdP policy to add Entra ID.
  7. Test that federated authentication works between OCI IAM and Entra ID.
Note

This tutorial is specific to IAM with Identity Domains.